Count value processing method, communication device, communication system, and storage medium

By encrypting and protecting the integrity of MAC CEs and determining their associated counter values, the vulnerability of MAC CEs to attacks is resolved, improving the security and reliability of communication systems and reducing resource waste.

WO2026090875A1PCT designated stage Publication Date: 2026-05-07BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
BEIJING XIAOMI MOBILE SOFTWARE CO LTD
Filing Date
2024-10-29
Publication Date
2026-05-07

AI Technical Summary

Technical Problem

In existing technologies, MAC CE lacks encryption and integrity protection, making it vulnerable to attacks and tampering, which affects the security and reliability of communication systems.

Method used

Encryption and integrity protection are achieved by determining the count value associated with MAC CE protection, including determining all bits or least significant bits of the count value, employing multiple types of MAC CE transmission, and updating the count value as necessary, ensuring that MAC CE is protected before transmission.

Benefits of technology

It improves the security and reliability of MAC CE, enhances the transmission security and reliability of communication systems, reduces the waste of transmission resources, and improves resource utilization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024128303_07052026_PF_FP_ABST
    Figure CN2024128303_07052026_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure disclose a count value processing method, a communication device, a communication system, and a storage medium. The method comprises: determining a count value associated with medium access control (MAC) control element (CE) protection. Thus, by maintaining a count value associated with MAC CE protection, conditions are provided for implementing MAC CE protection, avoiding the problem of MAC CE being attacked or tampered with.
Need to check novelty before this filing date? Find Prior Art

Description

Counting methods, communication equipment, communication systems and storage media Technical Field

[0001] This disclosure relates to the field of communication technology, and in particular to a counting value processing method, communication device, communication system and storage medium. Background Technology

[0002] The relevant protocols propose to encrypt and protect the integrity of Radio Resource Control (RRC) messages in order to prevent the content transmitted through RRC messages from being attacked.

[0003] Summary of the Invention

[0004] This disclosure provides a counting value processing method, a communication device, a communication system, and a storage medium.

[0005] A first aspect of this disclosure provides a counting value processing method, which is executed by a communication device, and the method includes:

[0006] Determine the count value associated with the Media Access Control (MAC) unit CE protection.

[0007] A second aspect of this disclosure provides a communication device, which includes:

[0008] The processing module is used to determine the count value associated with the Media Access Control (MAC) control unit CE protection.

[0009] A third aspect of this disclosure provides a communication device, which includes one or more processors;

[0010] The processor is used to execute the method described in the first aspect above.

[0011] A communication system, comprising terminals and network devices, wherein the terminals and network devices are respectively used to perform the method described in the first aspect above.

[0012] A fourth aspect of this disclosure provides a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform the method described in the first aspect above.

[0013] A sixth aspect of this disclosure provides a computer program product including a computer program that, when executed by a processor, implements the method described in the first aspect above.

[0014] The solution proposed in this disclosure allows the communication device to determine the count value associated with MAC CE protection, thereby providing conditions for implementing MAC CE protection and avoiding the problem of MAC CE being attacked or tampered with. Attached Figure Description

[0015] To more clearly illustrate the technical solutions in the embodiments or background art of this disclosure, the accompanying drawings used in the embodiments or background art of this disclosure will be described below.

[0016] Figure 1 is a schematic diagram of the architecture of a communication system provided in an embodiment of this disclosure;

[0017] Figures 2A-2B are schematic diagrams of the counting value processing method provided in the embodiments of this disclosure;

[0018] Figure 3 is a schematic diagram of the structure of a terminal provided in an embodiment of this disclosure;

[0019] Figure 4A is a schematic diagram of the structure of a communication device provided in an embodiment of this disclosure;

[0020] Figure 4B is a schematic diagram of the structure of a chip provided in an embodiment of this disclosure. Detailed Implementation

[0021] This disclosure provides a counting value processing method, a communication device, a communication system, and a storage medium.

[0022] In a first aspect, embodiments of this disclosure provide a count value processing method, the method comprising: determining a count value associated with MAC CE protection.

[0023] In this embodiment of the disclosure, the communication device can determine the count value associated with MAC CE protection, thereby improving the security and reliability of MAC CE, enhancing the security and reliability of information transmitted based on MAC CE, and improving the performance of the communication system.

[0024] In conjunction with some embodiments of the first aspect, in some embodiments, the above-described determination of the count value associated with MAC CE protection includes one or more of the following:

[0025] Determine the count value associated with the uplink MAC CE encryption protection;

[0026] Determine the count value associated with downlink MAC CE encryption protection;

[0027] Determine the count value associated with uplink MAC CE integrity protection;

[0028] Determine the count value associated with downlink MAC CE integrity protection.

[0029] In this embodiment of the disclosure, the communication device can determine the corresponding encryption protection association count value and integrity protection association count value for the uplink and downlink MAC CE respectively, thereby improving the security and reliability of the MAC CE in each transmission direction.

[0030] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes:

[0031] Receive or send count values.

[0032] In this embodiment of the disclosure, the communication device can send a determined count value to the receiving end, thereby ensuring that the sending end and receiving end of the MAC CE have a consistent understanding of the count value associated with MAC CE protection, thus providing conditions for realizing MAC CE protection.

[0033] In conjunction with some embodiments of the first aspect, in some embodiments, the above-described received or transmitted count value includes any one of the following:

[0034] Receive or send all bits of the count value;

[0035] The least significant bit of the received or transmitted count value.

[0036] In this embodiment of the disclosure, the communication device can transmit all bits of the count value or only the least significant bits, providing flexibility in the transmission method and enabling a reduction in the transmission resources used to transmit the count value.

[0037] In conjunction with some embodiments of the first aspect, in some embodiments, the determination of the count value associated with MAC CE protection as described above includes:

[0038] The value of the most significant bit of the count value is determined based on the value of the least significant bit of the received count value.

[0039] In this embodiment of the present disclosure, the communication device can calculate the value of the most significant bit based on the value of the least significant bit when only the least significant bit of the count value is received, thereby providing conditions for reducing the transmission resources used to transmit the count value while ensuring that the count value can be accurately determined.

[0040] In conjunction with some embodiments of the first aspect, in some embodiments, the determination of the count value associated with MAC CE protection as described above includes:

[0041] Determine all bits of the count value associated with the MAC CE protection; or,

[0042] Determine the least significant bit of the count value associated with the MAC CE protection.

[0043] In this embodiment of the disclosure, the communication device can determine all bits of the count value or only the least significant bits of the technical value, which provides flexibility and allows for reducing the resources used for counting and determining the count value.

[0044] In conjunction with some embodiments of the first aspect, in some embodiments, the determination of the count value associated with MAC CE protection as described above includes:

[0045] The count value is determined to be the first value if one or more of the following conditions are met:

[0046] The terminal enters the connected state;

[0047] Enable MAC CE protection;

[0048] The terminal enters an inactive state;

[0049] The terminal enters an inactive state and is configured with Small Data Transmission Technique (SDT).

[0050] The terminal is inactive and has been reselected to a new cell; and,

[0051] The inactive terminal is reselected to a new cell, and the terminal is configured with Small Data Transmission Techniques (SDT).

[0052] In this embodiment of the disclosure, the communication device can initialize the count value to a first value when one or more conditions are met, thereby minimizing the counting and transmission costs associated with MAC CE protection while ensuring MAC CE protection is achieved.

[0053] In conjunction with some embodiments of the first aspect, in some embodiments, the determination of the count value associated with MAC CE protection as described above includes:

[0054] The count value is determined to be the first value if one or more of the following conditions are met: the terminal performs a cell handover, the terminal performs a connection reconstruction, the terminal's secondary cell group (SCG) changes, and the key parameters associated with the MAC CE are changed.

[0055] In this embodiment of the disclosure, the communication device can reset the count value to a first value when one or more conditions are met, thereby minimizing the calculation and transmission costs of the count value associated with MAC CE protection while ensuring MAC CE protection is achieved.

[0056] In conjunction with some embodiments of the first aspect, in some embodiments the above method further includes:

[0057] Once a protection process for the MAC CE is completed, the counter value is incremented by one.

[0058] In conjunction with some embodiments of the first aspect, in some embodiments, the above-mentioned count values ​​are not protected.

[0059] In this embodiment of the disclosure, the communication device can send the count value directly without performing protection processing, thereby minimizing the transmission and decoding costs of the count value associated with MAC CE protection while ensuring MAC CE protection is achieved.

[0060] In conjunction with some embodiments of the first aspect, in some embodiments the above method further includes:

[0061] Sending or receiving count values ​​via one or more of the following:

[0062] The first MAC CE contains only a packet header and no packet body;

[0063] The second MAC CE includes a header and a body, wherein the body is used to carry the count value;

[0064] The third MAC CE has only a header and no body, and the third MAC CE also includes a protective tag;

[0065] The fourth MAC CE consists of a header and a body, with the body carrying the counter value and a protective tag.

[0066] In this embodiment of the disclosure, the communication device can transmit MAC CE protection associated counter values ​​using various types of MAC CE, thereby improving the flexibility of transmitting counter values.

[0067] In conjunction with some embodiments of the first aspect, in some embodiments, the logical channel priority (LCP) of the MAC CE containing the count value is the same as the priority of the protected and highest-priority MAC CE.

[0068] In this embodiment of the disclosure, by setting the priority of the MAC CE that sends the count value to a higher priority, the probability of successful transmission of the count value is guaranteed.

[0069] In conjunction with some embodiments of the first aspect, in some embodiments the above method further includes:

[0070] If the uplink authorized resource size is greater than the second value, the padding information, the MAC CE to be protected, and the count value are sent together, wherein the second value is determined by at least two of the following: the logical channel identifier, the count value, and the protection tag.

[0071] In this embodiment of the disclosure, based on the size of the uplink authorized resource, it is determined whether to send the padding information, the MAC CE that needs to be protected, and the count value together. This ensures that the count value is sent reliably, avoids the waste of uplink resources, and improves the utilization rate of uplink resources.

[0072] In conjunction with some embodiments of the first aspect, in some embodiments the above method further includes:

[0073] Whether to send a padding BSR simultaneously depends on whether the size of the padding bits is greater than the sum of the MAC CE containing the Buffer Status Report (BSR) and a third value, wherein the third value is determined by one or more of the following: a count value, a protection tag.

[0074] In this embodiment of the disclosure, the size of the padding bit is determined to be greater than the sum of the size of the MAC CE containing the BSR and the size of the count value (and / or the protection tag), thereby determining whether to send padding information simultaneously. This ensures reliable transmission of the count value while avoiding waste of uplink resources and improving the utilization rate of uplink resources.

[0075] Secondly, embodiments of this disclosure provide a communication device, which includes: a processing module and a transceiver module, wherein...

[0076] The processing module is used to determine the count value associated with MAC CE protection.

[0077] In conjunction with some embodiments of the first aspect, in some embodiments, the above-described processing module is further configured to perform one or more of the following:

[0078] Determine the count value associated with the uplink MAC CE encryption protection;

[0079] Determine the count value associated with downlink MAC CE encryption protection;

[0080] Determine the count value associated with uplink MAC CE integrity protection;

[0081] Determine the count value associated with downlink MAC CE integrity protection.

[0082] In conjunction with some embodiments of the second aspect, in some embodiments, the above-described transceiver module is used for:

[0083] Receive or send count values.

[0084] In conjunction with some embodiments of the second aspect, in some embodiments, the above-described transceiver module is further configured to perform any of the following:

[0085] Receive or send all bits of the count value;

[0086] The least significant bit of the received or transmitted count value.

[0087] In conjunction with some embodiments of the second aspect, in some embodiments, the above-described processing module is further used for:

[0088] The value of the most significant bit of the count value is determined based on the value of the least significant bit of the received count value.

[0089] In conjunction with some embodiments of the second aspect, in some embodiments, the above-described processing module is further used for:

[0090] Determine all bits of the count value associated with the MAC CE protection; or,

[0091] Determine the least significant bit of the count value associated with the MAC CE protection.

[0092] In conjunction with some embodiments of the second aspect, in some embodiments, the above-described processing module is further used for:

[0093] The count value is determined to be the first value if one or more of the following conditions are met:

[0094] The terminal enters the connected state;

[0095] Enable MAC CE protection;

[0096] The terminal enters an inactive state;

[0097] The terminal enters an inactive state and is configured with Small Data Transmission Technique (SDT).

[0098] The terminal is inactive and has been reselected to a new cell; and,

[0099] The inactive terminal is reselected to a new cell, and the terminal is configured with Small Data Transmission Techniques (SDT).

[0100] In conjunction with some embodiments of the second aspect, in some embodiments, the above-described processing module is further used for:

[0101] The count value is determined to be the first value if one or more of the following conditions are met: the terminal performs a cell handover, the terminal performs a connection reconstruction, the terminal's secondary cell group (SCG) changes, and the key parameters associated with the MAC CE are changed.

[0102] In conjunction with some embodiments of the second aspect, in some embodiments, the above-described processing module is further used for:

[0103] Once a protection process for the MAC CE is completed, the counter value is incremented by one.

[0104] In conjunction with some embodiments of the second aspect, in some embodiments, the count value is not protected.

[0105] In conjunction with some embodiments of the second aspect, in some embodiments, the above-described transceiver module is further used for:

[0106] Sending or receiving count values ​​via one or more of the following:

[0107] The first MAC CE contains only a packet header and no packet body;

[0108] The second MAC CE includes a header and a body, wherein the body is used to carry the count value;

[0109] The third MAC CE has only a header and no body, and the third MAC CE also includes a protective tag;

[0110] The fourth MAC CE consists of a header and a body, with the body carrying the counter value and a protective tag.

[0111] In conjunction with some embodiments of the second aspect, in some embodiments, the logical channel priority (LCP) of the MAC CE containing the count value is the same as the priority of the protected and highest-priority MAC CE.

[0112] In conjunction with some embodiments of the second aspect, in some embodiments, the above-described processing module is further used for:

[0113] If the uplink authorized resource size is greater than the second value, the padding information, the MAC CE to be protected, and the count value are sent together, wherein the second value is determined by at least two of the following: the logical channel identifier, the count value, and the protection tag.

[0114] In conjunction with some embodiments of the second aspect, in some embodiments, the above-described processing module is further used for:

[0115] Whether to send a padding BSR simultaneously depends on whether the size of the padding bits is greater than the sum of the MAC CE containing the Buffer Status Report (BSR) and a third value, wherein the third value is determined by one or more of the following: a count value, a protection tag.

[0116] Thirdly, embodiments of this disclosure provide a communication device, which includes one or more processors; wherein the communication device is used to execute the first aspect and optional implementations of the first aspect.

[0117] Fourthly, embodiments of this disclosure provide a communication system comprising: a terminal and a network device; wherein the terminal and the network device are configured to perform the methods described in the first aspect and optional implementations thereof.

[0118] Fifthly, embodiments of this disclosure provide a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform the method described in the first aspect and its optional implementations.

[0119] In a sixth aspect, embodiments of this disclosure provide a program product that, when executed by a communication device, causes the communication device to perform the method as described in the first aspect and its optional implementations.

[0120] In a seventh aspect, embodiments of this disclosure provide a computer program that, when run on a computer, causes the computer to perform the methods described in the first aspect and optional implementations of the first aspect.

[0121] Eighthly, embodiments of this disclosure provide a chip or chip system. The chip or chip system includes processing circuitry configured to perform the methods described according to the first aspect and optional implementations thereof.

[0122] It is understood that the aforementioned terminals, network devices, access network devices, core network devices, communication devices, communication systems, storage media, program products, computer programs, chips, or chip systems are all used to execute the methods proposed in the embodiments of this disclosure. Therefore, the beneficial effects that can be achieved can be referred to the beneficial effects in the corresponding methods, and will not be repeated here.

[0123] This disclosure provides a counting value processing method, a communication device, a communication system, and a storage medium. In some embodiments, the terms "counting value processing method" and "information processing method," "communication method," etc., can be used interchangeably; the terms "counting value processing device" and "information processing device," "communication device," etc., can be used interchangeably; and the terms "message transmission system" and "information processing system," "communication system," etc., can be used interchangeably.

[0124] This disclosure is not exhaustive, but merely illustrative of some embodiments, and is not intended to limit the scope of protection of this disclosure. Unless otherwise specified, each step in a particular embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a particular embodiment can also be implemented as an independent embodiment, and the order of the steps in a particular embodiment can be arbitrarily interchanged. Furthermore, the optional implementation methods in a particular embodiment can be arbitrarily combined; moreover, the embodiments can be arbitrarily combined, for example, some or all steps of different embodiments can be arbitrarily combined, and a particular embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.

[0125] In each of the disclosed embodiments, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of the embodiments are consistent and can be referenced by each other. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.

[0126] The terminology used in the embodiments of this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the scope of this disclosure.

[0127] In this disclosure, unless otherwise stated, elements expressed in the singular form, such as "a," "an," "the," "the," "the aforementioned," "the," "this," etc., can mean "one and only one," or "one or more," "at least one," etc. For example, when using articles such as "a," "an," "the," etc. in translation, the noun following the article can be understood as either a singular or a plural expression.

[0128] In the embodiments disclosed herein, "multiple" refers to two or more.

[0129] In some embodiments, the terms “at least one of”, “one or more”, “a plurality of”, “multiple”, etc., may be used interchangeably.

[0130] In some embodiments, the notation "at least one of A and B", "A and / or B", "A in one case, B in another", "in response to one case A, in response to another case B", etc., may include the following technical solutions depending on the situation: in some embodiments, A (execute A regardless of B); in some embodiments, B (execute B regardless of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); in some embodiments, A and B (both A and B are executed). The same applies when there are more branches such as A, B, C, etc.

[0131] In some embodiments, the notation "A or B" may include the following technical solutions, depending on the situation: in some embodiments, A (execution of A regardless of B); in some embodiments, B (execution of B regardless of A); in some embodiments, execution is selected from A and B (A and B are selectively executed). The same applies when there are more branches such as A, B, C, etc.

[0132] The prefixes "first," "second," etc., used in the embodiments of this disclosure are merely for distinguishing different descriptive objects and do not impose restrictions on the position, order, priority, quantity, or content of the descriptive objects. The description of the descriptive objects is found in the claims or the context of the embodiments, and the use of prefixes should not constitute unnecessary restrictions. For example, if the descriptive object is a "field," the ordinal numbers preceding "field" in "first field" and "second field" do not restrict the position or order of the "fields." "First" and "second" do not restrict whether the "fields" they modify are in the same message, nor do they restrict the order of "first field" and "second field." Similarly, if the descriptive object is a "level," the ordinal numbers preceding "level" in "first level" and "second level" do not restrict the priority between "levels." Furthermore, the number of descriptive objects is not limited by ordinal numbers and can be one or more. For example, in "first device," the number of "devices" can be one or more. Furthermore, the objects modified by different prefixes can be the same or different. For example, if the object being described is "device", then "first device" and "second device" can be the same device or different devices, and their types can be the same or different. Similarly, if the object being described is "information", then "first information" and "second information" can be the same information or different information, and their content can be the same or different.

[0133] In some embodiments, “including A,” “containing A,” “for indicating A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.

[0134] In some embodiments, the terms “in response to…”, “in response to determining…”, “in the case of…”, “when…”, “if…”, “if…”, etc., can be used interchangeably.

[0135] In some embodiments, the terms “greater than,” “greater than or equal to,” “not less than,” “more than,” “more than or equal to,” “not less than,” “higher than,” “higher than or equal to,” “not lower than,” and “above” can be used interchangeably, as can the terms “less than,” “less than or equal to,” “not greater than,” “less than,” “less than or equal to,” “not more than,” “lower than,” “lower than or equal to,” “not higher than,” and “below”.

[0136] In some embodiments, the apparatus and device may be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments. In some cases, they may also be understood as "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "body", etc.

[0137] In some embodiments, "network" can be interpreted as devices included in the network, such as access network devices, core network devices, etc.

[0138] In some embodiments, "access network device (AN device)" may also be referred to as "radio access network device (RAN device)," "base station (BS)," "radio base station," or "fixed station." In some embodiments, it may also be understood as "node," "access point," "transmission point (TP)," "reception point (RP)," "transmission / reception point (TRP)," "panel," "antenna panel," "antenna array," "cell," "macro cell," "small cell," "femto cell," "pico cell," "sector," "cell group," "serving cell," "carrier," "component carrier," or "bandwidth part (BWP)."

[0139] In some embodiments, "terminal" or "terminal device" may be referred to as "user equipment (UE)," "user terminal," "Narrow Band-Internet of Things (NB-IoT) device," "mobile station (MS)," "mobile terminal (MT)," "subscriber station," "mobile unit," "subscriber unit," "wireless unit," "remote unit," "mobile device," "wireless device," "wireless communication device," "remote device," "mobile subscriber station," "access terminal," "mobile terminal," "wireless terminal," "remote terminal," "handset," "user agent," "mobile client," "client," etc.

[0140] In some embodiments, access network devices, core network devices, or network devices can be replaced by terminals. For example, embodiments of this disclosure can also be applied to structures where communication between access network devices, core network devices, or network devices and terminals is replaced by communication between multiple terminals (e.g., device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, the structure can also be configured such that the terminal has all or part of the functions of the access network device. Furthermore, terms such as "uplink" and "downlink" can be replaced with terms corresponding to communication between terminals (e.g., "sidelink"). For example, uplink channel, downlink channel, etc., can be replaced with sidelink channel, and uplink link, downlink, etc., can be replaced with sidelink link.

[0141] In some embodiments, the terminal may be replaced by an access network device, a core network device, or a network device. In this case, the access network device, core network device, or network device may also be configured to have all or some of the functions of the terminal.

[0142] In some embodiments, the acquisition of data, information, etc., may comply with the laws and regulations of the country where the location is situated.

[0143] In some embodiments, data, information, etc., may be obtained with the user's consent.

[0144] Figure 1 is a schematic diagram of the architecture of a communication system according to an embodiment of the present disclosure.

[0145] As shown in Figure 1, the communication system 100 includes a terminal 101 and a network device 102.

[0146] In some embodiments, terminal 101 includes, but is not limited to, at least one of the following: mobile phone, wearable device, Internet of Things device, car with communication function, smart car, tablet computer, computer with wireless transceiver function, virtual reality (VR) terminal device, augmented reality (AR) terminal device, wireless terminal device in industrial control, wireless terminal device in self-driving, wireless terminal device in remote medical surgery, wireless terminal device in smart grid, wireless terminal device in transportation safety, wireless terminal device in smart city, and wireless terminal device in smart home.

[0147] In some embodiments, network device 102 may include at least one of access network device and core network device.

[0148] In some embodiments, the access network device is, for example, a node or device that connects a terminal to a wireless network. The access network device may include, but is not limited to, at least one of the following in a 5G communication system: evolved Node B (eNB), next-generation eNB (ng-eNB), next-generation Node B (gNB), node B (NB), home node B (HNB), home evolved node B (HeNB), radio backhaul device, radio network controller (RNC), base station controller (BSC), base transceiver station (BTS), base band unit (BBU), mobile switching center, base station in a 6G communication system, open RAN, cloud RAN, base station in other communication systems, and access node in a Wi-Fi system.

[0149] In some embodiments, the technical solutions of this disclosure can be applied to the Open RAN architecture. In this case, the interfaces between or within access network devices involved in the embodiments of this disclosure can be transformed into internal interfaces of Open RAN. The processes and information interactions between these internal interfaces can be implemented by software or programs.

[0150] In some embodiments, the access network device may be composed of a central unit (CU) and a distributed unit (DU). The CU may also be called a control unit. The CU-DU structure can separate the protocol layer of the access network device. Some of the protocol layer functions are centrally controlled by the CU, while the remaining part or all of the protocol layer functions are distributed in the DU and centrally controlled by the CU. However, this is not the only possibility.

[0151] In some embodiments, a core network device may be a single device comprising one or more network elements, or it may be multiple devices or a group of devices, each comprising all or part of the aforementioned one or more network elements. Network elements may be virtual or physical. The core network may include, for example, at least one of an Evolved Protocol Core (EPC), a 5G Core Network (5GCN), or a Next Generation Core (NGC).

[0152] It is understood that the communication system described in this disclosure is for the purpose of more clearly illustrating the technical solutions of this disclosure, and does not constitute a limitation on the technical solutions proposed in this disclosure. As those skilled in the art will know, with the evolution of system architecture and the emergence of new business scenarios, the technical solutions proposed in this disclosure are also applicable to similar technical problems.

[0153] The following embodiments of this disclosure can be applied to the communication system 100 shown in FIG1, or to some of the main bodies, but are not limited thereto. The main bodies shown in FIG1 are illustrative. The communication system may include all or some of the main bodies in FIG1, or may include other main bodies outside of FIG1. ​​The number and form of each main body are arbitrary. Each main body may be physical or virtual. The connection relationship between the main bodies is illustrative. The main bodies may not be connected or may be connected. The connection can be in any way, it can be a direct connection or an indirect connection, it can be a wired connection or a wireless connection.

[0154] The embodiments disclosed herein can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), and IEEE 802.20, Ultra-Wideband (UWB), Bluetooth (a registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X) systems, systems utilizing other communication methods, and next-generation systems built upon them, etc. Furthermore, multiple systems can be combined (e.g., a combination of LTE or LTE-A with 5G).

[0155] The relevant protocols propose to encrypt and protect the integrity of Radio Resource Control (RRC) messages in order to prevent the content transmitted through RRC messages from being attacked.

[0156] Optionally, RRC messages can be classified into P-type RRC messages, AI-type RRC messages, and AC-type RRC messages according to the protection strategy.

[0157] Among them, P-class RRC messages are messages that can be sent (unprotected) before AS security is activated; A–I-class RRC messages are messages that can be sent without integrity protection after the Access Stratum (AS) security is activated; and A–C-class RRC messages are messages that can be sent without encryption after the AS security is activated.

[0158] Currently, the Media Access Control (MAC) layer control element (CE) is not encrypted or protected for integrity. As a type of control signaling, the MAC CE may pose security risks if not encrypted and protected for integrity.

[0159] For example, if the MAC CE of the L1 / L2 Triggered Mobility (LTM) cell switch command received by the terminal is tampered with, the terminal may switch to an illegal cell, thereby affecting the execution of terminal services.

[0160] Alternatively, if the terminal receives the attacked GNSS measurement command MAC CE, it will retune to the GNSS frequency to measure GNSS, thereby affecting the terminal's normal communication.

[0161] Alternatively, the terminal's private data may be tampered with. For example, if the terminal's report of the remaining validity period of the Global Navigation Satellite System (GNSS) data to the network device is altered, it may lead to the early or delayed release of the RRC. Or, if the terminal's private Timing Advance (TA) Command MAC CE is obtained by a third party, that third party can identify the terminal's location range relative to the network device, and so on.

[0162] This disclosure proposes a method for protecting MAC CEs. Before sending a MAC CE, the communication device can first protect the MAC CE, thereby improving the security and integrity of MAC CE transmission and providing conditions for avoiding the leakage of private data and improving the security and reliability of transmission.

[0163] The following description, in conjunction with the accompanying drawings, details the counting method, communication equipment, communication system, and storage medium provided in this disclosure.

[0164] Figure 2A is a schematic diagram of a counting value processing method according to an embodiment of the present disclosure. As shown in Figure 2A, the counting value processing method according to the embodiment of the present disclosure is executed by a communication device, which can be a terminal or a network device. As shown in Figure 2A, the above method includes:

[0165] Step S2101: Determine the count value associated with the uplink MAC CE protection.

[0166] In some embodiments, MAC CE protection includes MAC CE encryption protection and / or MAC CE integrity protection.

[0167] In some embodiments, MAC CE integrity protection includes performing integrity protection on the MAC CE based on integrity protection parameters, such as keys, integrity protection associated count (COUNT) values, transmission direction parameters, etc., to obtain a protection tag.

[0168] In some embodiments, the integrity protection associated count value is used to characterize the number of times integrity protection processing is performed on the MAC CE, and the count value is incremented by 1 each time integrity protection is completed.

[0169] In some embodiments, a transmission direction parameter is used to describe the transmission direction of the MAC CE. For example, it may be downlink (DL) and / or uplink (UL), etc.

[0170] In some embodiments, a protection tag is used to assist the receiving end in verifying the integrity of the received MAC CE after receiving it.

[0171] In some embodiments, terms such as “protection tag”, “message authentication code-integrity (MAC-I)”, “message integrity verification identifier”, “message integrity authentication code”, “information integrity verification identifier”, and “information integrity authentication code” can all indicate auxiliary information used to verify the integrity of a message (or information). In some scenarios, the above terms can be used interchangeably.

[0172] In some embodiments, the receiving end (such as a terminal or network device) can perform integrity calculations on the received MAC CE based on the same logic as the sending end (such as a network device or terminal) to obtain a new protection tag. If the protection tag obtained by the receiving end is the same as the received protection tag, it can be determined that the MAC CE has not been tampered with. This ensures the reliability and security of the received MAC CE and avoids service anomalies caused by the receiving end responding to information contained in a tampered MAC CE.

[0173] In some embodiments, the count value associated with MAC CE protection includes the count value associated with MAC CE integrity protection.

[0174] In some embodiments, MAC CE encryption protection can be achieved by encrypting the MAC CE based on encryption protection parameters, such as keys, counter values, transmission direction parameters, length values, etc., resulting in an encrypted MAC CE. By encrypting the MAC CE, it is possible to prevent third parties from illegally obtaining the information contained in the MAC CE, thus avoiding the leakage of private information.

[0175] In some embodiments, the length value is used to characterize the length of the MAC CE that needs to be encrypted.

[0176] In some embodiments, if multiple MAC CEs need to be encrypted as a whole, the length value can be the total length of the multiple MAC CEs.

[0177] In some embodiments, the count value associated with MAC CE protection includes the count value associated with MAC CE encryption protection.

[0178] In some embodiments, MAC CE includes UL MAC CE and DL MAC CE, MAC CE protection associated count values, including uplink MAC CE protection associated count values, and / or downlink MAC CE protection associated count values.

[0179] In some embodiments, the count value associated with MAC CE protection includes one or more of the following: the count value associated with UL MAC CE encryption protection, the count value associated with UL MAC CE integrity protection, the count value associated with DL MAC CE encryption protection, and the count value associated with DL MAC CE integrity protection.

[0180] In some embodiments, the terminal can increment the counter value by 1 after completing a protection operation for the uplink MAC CE.

[0181] In some embodiments, if multiple MAC CEs are encrypted and / or protected for integrity as a whole, the COUNT value is incremented by 1 after encryption and / or integrity protection is completed. If a single MAC CE is encrypted and / or protected for integrity, the COUNT value is incremented by 1 after each MAC CE is encrypted and / or protected for integrity.

[0182] In some embodiments, if each time the terminal performs encryption protection on the MAC CE, it is concurrent with integrity protection, then the count value associated with the encryption protection of the UL MAC CE is the same as the count value associated with the integrity protection.

[0183] In some embodiments, if each time the network device performs encryption protection for the MAC CE, it does so simultaneously with integrity protection, then the count value associated with the encryption protection of the DL MAC CE is the same as the count value associated with the integrity protection.

[0184] In some embodiments, determining the count value associated with MAC CE protection includes determining all bits of the count value associated with MAC CE protection. That is, determining the least significant bit (LSB) value, the least significant bit sequence (LSBs), the most significant bit (MSB), the most significant bit sequence (LSBs), and so on, of the count value associated with MAC CE protection.

[0185] In some embodiments, determining the count value associated with MAC CE protection includes determining the least significant bit of the count value associated with the MAC CE protection. The terminal can then update the most significant bits based on changes in the least significant bit of the count value. For example, if the LSB changes from 1 to 0, the bit adjacent to the LSB in the count value can be incremented by 1.

[0186] In some embodiments, if the terminal has just entered the connected state, then the corresponding count value of the terminal can be determined to be the first value.

[0187] In some embodiments, the first value is the initial value of the counter, which may be configured by the network device or agreed upon by the protocol.

[0188] In some embodiments, the first value can be any numerical value, such as 0 or 1. It should be noted that if the first value is non-zero, the terminal needs to subtract the first value from the current count value when determining the number of times to protect the MAC CE.

[0189] In some embodiments, when the terminal enables the MAC CE protection function, it can determine that the count value is the first value.

[0190] In this embodiment of the disclosure, the terminal can enable or disable the MAC CE protection function. When the MAC CE protection function is disabled, the count value can be cleared to zero; when the MAC CE protection function is enabled, the count value can be set to the first value, thereby reducing the resources required for the terminal to store and calculate the count value.

[0191] In some embodiments, when the terminal enters an inactive state, it can determine that the count value is a first value.

[0192] In some embodiments, when the terminal enters an inactive state and is configured for Small Data Transmission (SDT), the count value is determined to be the first value.

[0193] In some embodiments, when the terminal is in an inactive state and has been reselected to a new cell, the count value is determined to be the first value.

[0194] In some embodiments, the terminal in the inactive state is reselected to a new cell, and the terminal is configured to transmit small data, and the count value is determined to be the first value.

[0195] In this embodiment of the disclosure, when the terminal status is updated, or the cell where the terminal is located changes, or the terminal status is updated and SDT is configured, the count value can be determined as the first value. This achieves the initialization of the count value and reduces the resources required for the terminal to store and calculate the count value.

[0196] In some embodiments, the terminal may initialize the count values ​​associated with UL and / or DL ​​MAC CE protection to a first value when one or more of the above conditions are met.

[0197] In some embodiments, the network device may initialize the count values ​​associated with the terminal's UL and / or DL ​​MAC CE protection to a first value when the terminal meets one or more of the above conditions.

[0198] In some embodiments, terms such as "initialize", "reset", "configure", "set to", etc. can be used interchangeably in certain scenarios.

[0199] In some embodiments, the count value is determined to be the first value if one or more of the following conditions are met: the terminal performs cell handover, the terminal performs connection reconstruction, the terminal's secondary cell group (SCG) changes, and the key parameters associated with the MAC CE are changed.

[0200] In this embodiment of the disclosure, when the terminal performs cell handover, connection reconstruction, changes the SCG, or changes the key parameters associated with the MAC CE, the count value can be reset to the first value. This achieves the reset of the count value, reducing the resources required for the terminal to store and calculate the count value.

[0201] In some embodiments, the terminal may receive a downlink DL MAC CE protection associated count value sent by the network device.

[0202] In some embodiments, the terminal may receive all bits of the count value associated with the DL MAC CE protection sent by the network device.

[0203] In some embodiments, the terminal may only receive the least significant bits of the count value associated with the DL MAC CE protection sent by the network device, for example, by receiving the least significant bits and then calculating the most significant bits of the count value associated with the DL MAC CE protection based on the changes in the least significant bits.

[0204] Step S2102: Send the uplink MAC CE protection associated count value.

[0205] In some embodiments, the terminal may send a count value associated with UL MAC CE protection to the network device.

[0206] In some embodiments, the terminal may send all bits of the counter value associated with the UL MAC CE protection to the network device.

[0207] In some embodiments, the terminal may send only the least significant bit of the count value associated with UL MAC CE protection to the network device, such as sending only the least significant bit of the count value associated with UL MAC CE protection, etc., and this disclosure does not limit this.

[0208] In some embodiments, since the leakage of the count value will not affect the reliable operation of the service, the count value may not be protected when it is sent. This minimizes the cost and complexity of MAC CE protection.

[0209] In some embodiments, the terminal may send the UL MAC CE protection associated count value through one or more of the following: a first MAC CE, which has only a header and no body; a second MAC CE, which includes a header and a body, and the body is used to carry the count value; a third MAC CE, which has only a header and no body, and the third MAC CE also includes a protection tag; and a fourth MAC CE, which includes a header and a body, and the body is used to carry the count value and the protection tag.

[0210] In some embodiments, the first MAC CE, second MAC CE, third MAC CE or fourth MAC CE mentioned above can be newly defined MAC CE; or, they can be reused MAC CEs in MAC Protocol Data Units (PDUs), which is not limited in this disclosure.

[0211] In this embodiment of the disclosure, the count value associated with MAC CE protection can be sent or received through various forms of MAC CE, which improves the flexibility of sending or receiving the count value and ensures the consistency of the understanding of the count value associated with MAC CE protection between the terminal and the network device.

[0212] In some embodiments, the MAC CE carrying the COUNT value can be sent together with the intact or encrypted MAC CE in a MAC PDU. This allows the receiving end to decode the intact or encrypted MAC CE based on the COUNT value carried in the MAC PDU after receiving it, quickly obtaining the decoded MAC CE, thus improving the decoding speed and efficiency of the intact or encrypted MAC CE.

[0213] In some embodiments, the logical channel priority (LCP) of the MAC CE containing the count value is the same as the priority of the protected and highest priority MAC CE.

[0214] In this embodiment of the disclosure, the LCP of the MAC CE containing the count value has the same priority as the protected and highest priority MAC CE, thereby ensuring the probability that the count value is reliably sent or received, and providing conditions for ensuring the reliable transmission or reception of the MAC CE.

[0215] In some embodiments, the uplink grant resource size is greater than the second value, and padding, the MAC CE to be protected, and the count value are sent together, wherein the second value is determined by at least two of the following: the Logical Channel Identifier (LCID), the count value, and the protection tag.

[0216] In some embodiments, LCID is typically used to distinguish or identify different logical channels. Different logical channels correspond to different LCIDs.

[0217] In some implementations, the LCID is typically 8 bytes in size, while if an Enhanced Logical Channel Identifier (eLCID) is used, it is typically 10 bytes in size. eLCID can be used to support the differentiation or identification of more logical channels.

[0218] In some embodiments, technical terms such as "extension" and "enhancement" can be used interchangeably in certain scenarios.

[0219] In some embodiments, if only the MAC CE is encrypted, the second value can be determined based on the size occupied by the LCID and the size occupied by the count value.

[0220] In some embodiments, if the MAC CE is protected by encryption and integrity, the second value can be determined based on the size occupied by the LCID, the size occupied by the count value, and the size occupied by the protection tag.

[0221] In some embodiments, if neither the count value nor the protection tag is carried by a MAC CE, then the size occupied by the count value and the protection tag is determined by their own size.

[0222] In some embodiments, if the count value and protection tag are carried by a MAC CE, then the size of the count value and protection tag needs to include the size of the entire MAC CE.

[0223] In this embodiment of the disclosure, if the uplink grant resource size is greater than the second value, the terminal can send padding and the MAC CE that needs protection simultaneously when sending the count value. This ensures reliable transmission of the count value while avoiding waste of uplink resources and improving the utilization rate of uplink resources.

[0224] In some embodiments, the padding information can be any content that can be used to fill a MAC Protocol Data Unit (PDU) to meet the length requirements. For example, it can be a Buffer Status Reporting (BSR) or other content.

[0225] In some embodiments, it is determined whether to send the padding BSR simultaneously based on whether the size of the padding bits is greater than the sum of the MAC CE containing the buffer status report BSR and a third value, wherein the third value is determined by one or more of the following: a count value, a protection tag.

[0226] In some embodiments, if the padding bits of the multiplexed MAC PDU contain a count value, then when determining whether to add a padding BSR to the MAC PDU, it is necessary to consider whether the size of the padding bits is greater than the sum of the size of the padding BSR and the size occupied by the count value (and / or the protection tag). This ensures that the count value associated with MAC CE protection is reliably transmitted while minimizing the waste of padding bits, thus improving the utilization rate of the MAC PDU.

[0227] In some embodiments, if only the MAC CE is encrypted, the third value can be determined based on the size occupied by the count value.

[0228] In some embodiments, if the MAC CE is protected by encryption and integrity, the third value can be determined based on the size occupied by the count value and the size occupied by the protection tag.

[0229] For example, if the size of the padding bits is greater than the sum of the MAC CE and the third value containing the BSR, then the padding BSR can be sent simultaneously; otherwise, the padding BSR cannot be sent simultaneously.

[0230] In some embodiments, the network device receives a count value associated with the uplink MAC CE protection.

[0231] Step S2103: The network device determines the count value associated with downlink MAC CE protection.

[0232] The specific implementation of step S2103 can be found in the detailed description of step S2101 above, and will not be repeated here.

[0233] Step S2104: Send the downlink MAC CE protection associated count value.

[0234] In some embodiments, the network device sends a count value associated with downlink MAC CE protection to the terminal.

[0235] The specific implementation of step S2104 can be found in the detailed description of step S2102 above, and will not be repeated here.

[0236] In some embodiments, S2103 and S2104 may be executed first, followed by S2101 and S2102. This disclosure does not limit this.

[0237] In some embodiments, when the terminal interacts with the network device, only the uplink MAC CE may need protection, while the downlink MAC CE may not require protection. In this case, the terminal and the network device only need to determine and record the count value associated with the uplink MAC CE protection. That is, in some embodiments, only steps S2101 and S2102 are executed.

[0238] In some embodiments, when the terminal interacts with the network device, only the downlink MAC CE may need protection, while the uplink MAC CE does not. In this case, the terminal and the network device only need to determine and record the count value associated with the downlink MAC CE protection. That is, in some embodiments, only steps S2103 and S2104 are executed.

[0239] In some embodiments, when the terminal interacts with the network device, both uplink and downlink MAC CE protection may need to be performed. In this case, the count values ​​associated with uplink and downlink MAC CE protection need to be determined and recorded by both the terminal and the network device. That is to say, in some embodiments, steps S2101-S2104 above need to be performed.

[0240] The counting value processing method involved in the embodiments of this disclosure may include at least one of steps S2101 to S2104. For example, step S2101 may be implemented as an independent embodiment, step S2102 may be implemented as an independent embodiment, step S2101+S2102 may be implemented as an independent embodiment, step S2103 may be implemented as an independent embodiment, step S2104 may be implemented as an independent embodiment, step S2103+S2104 may be implemented as an independent embodiment, etc., but not limited thereto.

[0241] In the embodiments disclosed herein, some or all of the steps and their optional implementations may be arbitrarily combined with some or all of the steps in other embodiments, or may be arbitrarily combined with the optional implementations in other embodiments.

[0242] In the embodiments disclosed herein, each step and its optional implementation can also be carried out independently.

[0243] In this embodiment, the terminal and network device can respectively determine the uplink and downlink MAC CE protection association count values ​​and send them to each other. This ensures the consistency of the terminal and network device's understanding of the uplink and downlink MAC CE protection association count values, improves the security and reliability of MAC CE, and provides conditions for avoiding the leakage and tampering of private information, further improving the security and reliability of the communication system.

[0244] Figure 2B is a schematic diagram of a counting value processing method according to an embodiment of the present disclosure. As shown in Figure 2B, the counting value processing method according to the embodiment of the present disclosure is executed by a communication device, which can be a terminal and / or a network device. As shown in Figure 2B, the above method includes:

[0245] Step S2201: Determine the count value associated with MAC CE protection.

[0246] In some embodiments, the count values ​​described above for determining the association with MAC CE protection include one or more of the following:

[0247] Determine the count value associated with the uplink MAC CE encryption protection;

[0248] Determine the count value associated with downlink MAC CE encryption protection;

[0249] Determine the count value associated with uplink MAC CE integrity protection;

[0250] Determine the count value associated with downlink MAC CE integrity protection.

[0251] In some embodiments, the method further includes:

[0252] Receive or send count values.

[0253] In some embodiments, the above-described receive or transmit count value includes any of the following:

[0254] Receive or send all bits of the count value;

[0255] The least significant bit of the received or transmitted count value.

[0256] In some embodiments, the determination of the count value associated with MAC CE protection includes:

[0257] The value of the most significant bit of the count value is determined based on the value of the least significant bit of the received count value.

[0258] In some embodiments, the determination of the count value associated with MAC CE protection includes:

[0259] Determine all bits of the count value associated with the MAC CE protection; or,

[0260] Determine the least significant bit of the count value associated with the MAC CE protection.

[0261] In some embodiments, the determination of the count value associated with MAC CE protection includes:

[0262] The count value is determined to be the first value if one or more of the following conditions are met:

[0263] The terminal enters the connected state;

[0264] Enable MAC CE protection;

[0265] The terminal enters an inactive state;

[0266] The terminal enters an inactive state and is configured with Small Data Transmission Technique (SDT).

[0267] The terminal is inactive and has been reselected to a new cell; and,

[0268] The inactive terminal is reselected to a new cell, and the terminal is configured with Small Data Transmission Techniques (SDT).

[0269] In some embodiments, the determination of the count value associated with MAC CE protection includes:

[0270] The count value is determined to be the first value if one or more of the following conditions are met: the terminal performs a cell handover, the terminal performs a connection reconstruction, the terminal's secondary cell group (SCG) changes, and the key parameters associated with the MAC CE are changed.

[0271] In some embodiments, the above method further includes:

[0272] Once a protection process for the MAC CE is completed, the counter value is incremented by one.

[0273] In some embodiments, the above-mentioned count values ​​are not protected.

[0274] In some embodiments, the above method further includes:

[0275] Sending or receiving count values ​​via one or more of the following:

[0276] The first MAC CE contains only a packet header and no packet body;

[0277] The second MAC CE includes a header and a body, wherein the body is used to carry the count value;

[0278] The third MAC CE has only a header and no body, and the third MAC CE also includes a protective tag;

[0279] The fourth MAC CE consists of a header and a body, with the body carrying the counter value and a protective tag.

[0280] In some embodiments, the logical channel priority (LCP) of the MAC CE containing the count value is the same as the priority of the protected and highest-priority MAC CE.

[0281] In some embodiments, the above method further includes:

[0282] If the uplink authorized resource size is greater than the second value, the padding information, the MAC CE to be protected, and the count value are sent together, wherein the second value is determined by at least two of the following: the logical channel identifier, the count value, and the protection tag.

[0283] In some embodiments, the above method further includes:

[0284] Whether to send a padding BSR simultaneously depends on whether the size of the padding bits is greater than the sum of the MAC CE containing the Buffer Status Report (BSR) and a third value, wherein the third value is determined by one or more of the following: a count value, a protection tag.

[0285] The following embodiments, using a communication device as an example, will further illustrate the counting value processing method provided in this disclosure.

[0286] The terminal (UE) maintains a COUNT value for UL / DL for MAC CE encryption and / or integrity protection.

[0287] In some embodiments, the UE may maintain a COUNT value for each direction, such as UL or DL.

[0288] In some embodiments, the COUNT value can be maintained separately for encryption protection and integrity protection, or it can be maintained as a single value.

[0289] Optionally, for encryption and / or integrity protection of the uplink / downlink MAC CE, the UE carries the COUNT value in the MAC CE or receives the COUNT value carried in the MAC CE.

[0290] Optionally, the COUNT value can be the complete COUNT value or the least significant bit sequence (LSBs) of the COUNT value.

[0291] Optionally, the UE initializes the uplink and / or downlink COUNT values ​​in one or more of the following ways:

[0292] When the UE enters the connected state (or after entering the connected state), the COUNT value is initialized to 0.

[0293] When encryption and / or integrity protection are enabled, initialize the COUNT value to 0.

[0294] When the UE enters the inactive state (optionally, the UE is configured with SDT), the initial COUNT value is 0.

[0295] When an inactive UE reselects to a new cell (optionally, the UE is configured with SDT), the initial COUNT value is 0.

[0296] Optionally, the UE resets the uplink and / or downlink COUNT values ​​in one or more of the following ways:

[0297] When switching, reset the COUNT value to 0.

[0298] During reconstruction, the COUNT value is reset to 0.

[0299] When SCG changes, reset the COUNT value of PSCell to 0.

[0300] When the key parameters of a MAC CE change, the COUNT value is reset to 0.

[0301] In some embodiments, for uplink transmission, the terminal increments the COUNT value by one after each UL MAC CE encryption and / or integrity protection operation.

[0302] In some embodiments, if multiple MAC CEs are encrypted or protected for integrity as a whole, the COUNT value is incremented by 1 after encryption or integrity protection is completed. If a single MAC CE is encrypted or protected for integrity, the COUNT value is incremented by 1 after each MAC CE is encrypted or protected for integrity.

[0303] In some embodiments, for downlink reception, if the MAC CE only carries the low-order bits of the COUNT value, then the terminal is responsible for maintaining the high-order bits of the COUNT value.

[0304] For example, when the received COUNT value LSB changes from its maximum value to 0, the terminal will increment the high-order bits of the maintained COUNT value by 1.

[0305] Optionally, the COUNT value is not encrypted / protected for integrity.

[0306] Optionally, the UL / DL COUNT value may be transmitted in one or more of the following ways:

[0307] Define a new MAC CE for sending the COUNT value. This MAC CE has only a header and no body.

[0308] Define a new MAC CE for sending the COUNT value. This MAC CE has a header and a body, with the COUNT value carried in the body.

[0309] Define a new MAC CE to send the COUNT value and MAC-I. This MAC CE has only a header and no body.

[0310] Define a new MAC CE to send the COUNT value and MAC-I. The MAC CE has a header and a body, and carries the COUNT value and MAC-I through the body.

[0311] Among them, MAC-I is the integrity protection content generated for integrity protection, such as protection tags.

[0312] In some embodiments, the MAC CE carrying the COUNT value needs to be sent together with the MAC CE with integrity or encryption in a MAC PDU, and cannot be sent separately in different MAC PDUs.

[0313] Optionally, the LCP priority of the COUNT value MAC CE is the same as the priority of the highest priority MAC CE in encryption / or integrity protection.

[0314] In some embodiments, if the size of the UL Grant is greater than X+COUNT+MAC-I (if integrity protection is applied) or the size of X+COUNT, the UE cannot simply transmit the padding BSR and / or padding. It also needs to transmit the MAC CE, which requires encryption / integrity protection.

[0315] For example, when eLCID is not used, the size X of LCID is 8 bytes; when eLCID is used, the size X of eLCID is 10 bytes. If MAC CE only needs encryption, it determines the relationship between UL Grant and X + COUNT; if encryption and integrity protection are required, it determines the relationship between UL Grant and X + COUNT + MAC-I.

[0316] In some embodiments, when calculating the size of COUNT / MAC-I, if COUNT / MAC-I is sent using MAC CE, the size of the entire MAC CE needs to be included in the calculation.

[0317] Optionally, when considering whether to add padding BSR, it is necessary to determine whether the padding bit size is greater than BSR MAC CE+COUNT / MAC-I.

[0318] Optionally, the UE carries the COUNT values ​​for MAC CE encryption and integrity protection in the UL MAC CE, or the UE receives the COUNT values ​​for MAC CE encryption and integrity protection in the DL MAC CE.

[0319] This disclosure also provides an apparatus for implementing any of the above methods. For example, an apparatus is provided that includes units or modules for implementing the steps performed by the terminal in any of the above methods. Alternatively, another apparatus is provided that includes units or modules for implementing the steps performed by a network device (e.g., an access network device, a core network functional node, a core network device, etc.) in any of the above methods.

[0320] It should be understood that the division of units or modules in the above device is only a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, the units or modules in the device can be implemented by a processor calling software: for example, the device includes a processor connected to a memory containing instructions. The processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of the units or modules in the above device. The processor can be, for example, a general-purpose processor, such as a Central Processing Unit (CPU) or a microprocessor, and the memory can be internal or external to the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits. The functionality of some or all of the units or modules can be achieved through the design of these hardware circuits, which can be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC). The functionality of some or all of the units or modules is achieved through the design of the logical relationships between the components within the circuit. In another implementation, the hardware circuit can be implemented using a programmable logic device (PLD). Taking a field-programmable gate array (FPGA) as an example, it can include a large number of logic gates. The connection relationships between the logic gates are configured through configuration files, thereby achieving the functionality of some or all of the units or modules. All units or modules of the above device can be implemented entirely through processor-called software, entirely through hardware circuits, or partially through processor-called software with the remaining parts implemented through hardware circuits.

[0321] In this embodiment, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction read and execute capabilities, such as a Central Processing Unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationships of hardware circuits. The logical relationships of the aforementioned hardware circuits are fixed or reconfigurable. For example, the processor is a hardware circuit implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and configuring the hardware circuit can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. Furthermore, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a Neural Network Processing Unit (NPU), a Tensor Processing Unit (TPU), or a Deep Learning Processing Unit (DPU).

[0322] Figure 3 is a schematic diagram of the structure of a communication device according to an embodiment of this disclosure. As shown in Figure 3, the communication device 3100 may include at least one of a transceiver module 3101, a processing module 3102, etc. In some embodiments, the processing module is used to determine a count value associated with MAC CE protection.

[0323] In some embodiments, the above-described processing module is further configured to perform one or more of the following:

[0324] Determine the count value associated with the uplink MAC CE encryption protection;

[0325] Determine the count value associated with downlink MAC CE encryption protection;

[0326] Determine the count value associated with uplink MAC CE integrity protection;

[0327] Determine the count value associated with downlink MAC CE integrity protection.

[0328] In some embodiments, the transceiver module described above is used for:

[0329] Receive or send count values.

[0330] In some embodiments, the transceiver module described above is further configured to perform any of the following:

[0331] Receive or send all bits of the count value;

[0332] The least significant bit of the received or transmitted count value.

[0333] In some embodiments, the above-described processing module is further configured to:

[0334] The value of the most significant bit of the count value is determined based on the value of the least significant bit of the received count value.

[0335] In some embodiments, the above-described processing module is further configured to:

[0336] Determine all bits of the count value associated with the MAC CE protection; or,

[0337] Determine the least significant bit of the count value associated with the MAC CE protection.

[0338] In some embodiments, the above-described processing module is further configured to:

[0339] The count value is determined to be the first value if one or more of the following conditions are met:

[0340] The terminal enters the connected state;

[0341] Enable MAC CE protection;

[0342] The terminal enters an inactive state;

[0343] The terminal enters an inactive state and is configured with Small Data Transmission Technique (SDT).

[0344] The terminal is inactive and has been reselected to a new cell; and,

[0345] The inactive terminal is reselected to a new cell, and the terminal is configured with Small Data Transmission Techniques (SDT).

[0346] In some embodiments, the above-described processing module is further configured to:

[0347] The count value is determined to be the first value if one or more of the following conditions are met: the terminal performs a cell handover, the terminal performs a connection reconstruction, the terminal's secondary cell group (SCG) changes, and the key parameters associated with the MAC CE are changed.

[0348] In some embodiments, the above-described processing module is further configured to:

[0349] Once a protection process for the MAC CE is completed, the counter value is incremented by one.

[0350] In some embodiments, the count value is not protected.

[0351] In some embodiments, the transceiver module described above is further used for:

[0352] Sending or receiving count values ​​via one or more of the following:

[0353] The first MAC CE contains only a packet header and no packet body;

[0354] The second MAC CE includes a header and a body, wherein the body is used to carry the count value;

[0355] The third MAC CE has only a header and no body, and the third MAC CE also includes a protective tag;

[0356] The fourth MAC CE consists of a header and a body, with the body carrying the counter value and a protective tag.

[0357] In some embodiments, the logical channel priority (LCP) of the MAC CE containing the count value is the same as the priority of the protected and highest-priority MAC CE.

[0358] In some embodiments, the above-described processing module is further configured to:

[0359] If the uplink authorized resource size is greater than the second value, the padding information, the MAC CE to be protected, and the count value are sent together, wherein the second value is determined by at least two of the following: the logical channel identifier, the count value, and the protection tag.

[0360] In some embodiments, the above-described processing module is further configured to:

[0361] Whether to send a padding BSR simultaneously depends on whether the size of the padding bits is greater than the sum of the MAC CE containing the Buffer Status Report (BSR) and a third value, wherein the third value is determined by one or more of the following: a count value, a protection tag.

[0362] Optionally, the transceiver module described above is used to perform at least one of the communication steps such as sending and / or receiving performed by the terminal in any of the above methods, which will not be elaborated here.

[0363] Optionally, the above processing module is used to perform at least one of the other steps executed by the terminal in any of the above methods, which will not be elaborated here.

[0364] Figure 4A is a schematic diagram of the structure of the communication device 4100 proposed in an embodiment of this disclosure. The communication device 4100 can be a network device (e.g., access network device, core network device, etc.), a terminal (e.g., user equipment, etc.), a chip, chip system, or processor that supports the network device in implementing any of the above methods, or a chip, chip system, or processor that supports the terminal in implementing any of the above methods. The communication device 4100 can be used to implement the methods described in the above method embodiments; for details, please refer to the descriptions in the above method embodiments.

[0365] As shown in Figure 4A, the communication device 4100 includes one or more processors 4101. The processor 4101 can be a general-purpose processor or a dedicated processor, such as a baseband processor or a central processing unit (CPU). The baseband processor can be used to process communication protocols and communication data, while the CPU can be used to control communication devices (e.g., base stations, baseband chips, terminal devices, terminal device chips, DUs or CUs, etc.), execute programs, and process program data. The communication device 4100 is used to execute any of the above methods.

[0366] In some embodiments, the communication device 4100 further includes one or more memories 4102 for storing instructions. Optionally, all or part of the memories 4102 may also be located outside the communication device 4100.

[0367] In some embodiments, the communication device 4100 further includes one or more transceivers 4103. When the communication device 4100 includes one or more transceivers 4103, the transceivers 4103 perform at least one of the communication steps such as sending and / or receiving in the above method (e.g., steps S2101, S2104), and the processor 4101 performs at least one of the other steps (e.g., steps S2101, S2103).

[0368] In some embodiments, a transceiver may include a receiver and / or a transmitter, which may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, transceiver circuit, etc., may be used interchangeably; the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc., may be used interchangeably; and the terms receiver, receiving unit, receiver, receiving circuit, etc., may be used interchangeably.

[0369] In some embodiments, the communication device 4100 may include one or more interface circuits 4104. Optionally, the interface circuit 4104 is connected to the memory 4102, and the interface circuit 4104 can be used to receive signals from the memory 4102 or other devices, and can be used to send signals to the memory 4102 or other devices. For example, the interface circuit 4104 can read instructions stored in the memory 4102 and send the instructions to the processor 4101.

[0370] The communication device 4100 described in the above embodiments may be a network device or a terminal, but the scope of the communication device 4100 described in this disclosure is not limited thereto, and the structure of the communication device 4100 may not be limited by FIG4A. The communication device may be a standalone device or may be part of a larger device. For example, the communication device may be: (1) a standalone integrated circuit IC, or chip, or chip system or subsystem; (2) a collection of one or more ICs, optionally, the IC collection may also include storage components for storing data and programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, terminal device, smart terminal device, cellular phone, wireless device, handheld device, mobile unit, vehicle device, network device, cloud device, artificial intelligence device, etc.; (6) others, etc.

[0371] Figure 4B is a schematic diagram of the structure of chip 4200 according to an embodiment of this disclosure. For cases where the communication device 4100 can be a chip or a chip system, please refer to the schematic diagram of chip 4200 shown in Figure 4B, but it is not limited thereto.

[0372] Chip 4200 includes one or more processors 4201, which are used to perform any of the above methods.

[0373] In some embodiments, chip 4200 further includes one or more interface circuits 4202. Optionally, the interface circuit 4202 is connected to memory 4203, and the interface circuit 4202 can be used to receive signals from memory 4203 or other devices, and the interface circuit 4202 can be used to send signals to memory 4203 or other devices. For example, the interface circuit 4202 can read instructions stored in memory 4203 and send the instructions to processor 4201.

[0374] In some embodiments, the interface circuit 4202 performs at least one of the communication steps such as sending and / or receiving in the above method (e.g., steps S2102, S2104), and the processor 4201 performs at least one of the other steps (e.g., steps S2101, S2103).

[0375] In some embodiments, the terms interface circuit, interface, transceiver pin, transceiver, etc., can be used interchangeably.

[0376] In some embodiments, chip 4200 further includes one or more memories 4203 for storing instructions. Optionally, all or part of the memories 4203 may be located outside of chip 4200.

[0377] This disclosure also proposes a storage medium storing instructions that, when executed on the communication device 4100, cause the communication device 4100 to perform any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but not limited thereto; it may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but not limited thereto; it may also be a temporary storage medium.

[0378] This disclosure also provides a program product that, when executed by the communication device 4100, causes the communication device 4100 to perform any of the above methods. Optionally, the program product is a computer program product.

[0379] This disclosure also proposes a computer program that, when run on a computer, causes the computer to perform any of the above methods.

[0380] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer programs. When the computer program is loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this disclosure are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer program can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program can be transferred from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., high-density digital video discs (DVDs)), or semiconductor media (e.g., solid-state disks (SSDs)).

[0381] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this disclosure.

[0382] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0383] The above description is merely a specific embodiment of this disclosure, but the scope of protection of this disclosure is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this disclosure should be included within the scope of protection of this disclosure. Therefore, the scope of protection of this disclosure should be determined by the scope of the claims.

Claims

1. A method for processing count values, characterized in that, The method includes: Determine the count value associated with the Media Access Control (MAC) unit CE protection.

2. The method as described in claim 1, characterized in that, The determination of the count value associated with the Media Access Control (MAC) unit CE protection includes one or more of the following: Determine the count value associated with the uplink MAC CE encryption protection; Determine the count value associated with downlink MAC CE encryption protection; Determine the count value associated with uplink MAC CE integrity protection; Determine the count value associated with downlink MAC CE integrity protection.

3. The method as described in claim 1 or 2, characterized in that, The method further includes: Receive or send the count value.

4. The method as described in claim 3, characterized in that, Receiving or sending the count value includes any one of the following: Receive or send all bits of the count value; Receive or transmit the least significant bit of the count value.

5. The method as described in claim 4, characterized in that, The determination of the count value associated with the Media Access Control (MAC) unit CE protection includes: The value of the most significant bit of the count value is determined based on the value of the least significant bit of the received count value.

6. The method according to any one of claims 1-5, characterized in that, The determination of the count value associated with the Media Access Control (MAC) unit CE protection includes: Determine all bits of the count value associated with the MAC CE protection; or, Determine the least significant bit of the count value associated with the MAC CE protection.

7. The method according to any one of claims 1-6, characterized in that, The determination of the count value associated with the Media Access Control (MAC) unit CE protection includes: The count value is determined to be a first value if one or more of the following conditions are met: The terminal enters the connected state; Enable MAC CE protection; The terminal enters an inactive state; The terminal enters an inactive state and is configured with Small Data Transmission Technique (SDT). The terminal is inactive and has been reselected to a new cell; and, The inactive terminal reselects to a new cell, and the terminal is configured with Small Data Transmission Techniques (SDT).

8. The method according to any one of claims 1-7, characterized in that, The determination of the count value associated with the Media Access Control (MAC) unit CE protection includes: The count value is determined to be a first value if one or more of the following conditions are met: the terminal performs a cell handover, the terminal performs a connection reconstruction, the terminal's secondary cell group (SCG) changes, and the key parameters associated with the MAC CE are changed.

9. The method according to any one of claims 1-8, characterized in that, The method further includes: After completing one protection process for the MAC CE, increment the count value by one.

10. The method according to any one of claims 1-9, characterized in that, No protection is applied to the count value.

11. The method according to any one of claims 1-10, characterized in that, The method further includes: The count value is sent or received through one or more of the following: The first MAC CE contains only a packet header and no packet body; The second MAC CE includes a header and a body, wherein the body is used to carry the count value; The third MAC CE has only a header and no body, and also includes a protective tag; The fourth MAC CE includes a header and a body, the body of which carries the count value and the protection tag.

12. The method as described in claim 11, characterized in that, The logical channel priority (LCP) of the MAC CE containing the count value is the same as the priority of the protected MAC CE with the highest priority.

13. The method as described in claim 11, characterized in that, The method further includes: If the uplink authorized resource size is greater than the second value, the padding information, the MAC CE to be protected, and the count value are sent together, wherein the second value is determined by at least two of the following: the logical channel identifier, the count value, and the protection tag.

14. The method as described in claim 13, characterized in that, The method further includes: Whether to send a padding BSR simultaneously depends on whether the size of the padding bits is greater than the sum of the MAC CE containing the Buffer Status Report (BSR) and a third value, wherein the third value is determined by one or more of the following: a count value, a protection tag.

15. A communication device, characterized in that, The communication device includes: The processing module is used to determine the count value associated with the Media Access Control (MAC) control unit CE protection.

16. A communication device, characterized in that, include: One or more processors; The processor is used to perform count value processing according to any one of claims 1-14.

17. A communication system, characterized in that, It includes a terminal and a network device, wherein the terminal and the network device are respectively used to perform the transmission as described in any one of claims 1-14.

18. A storage medium storing instructions, characterized in that, When the instruction is executed on the communication device, it causes the communication device to perform count value processing as described in any one of claims 1-15.

19. A computer program product, characterized in that, It includes a computer program that, when executed by a processor, performs the counting value processing according to any one of claims 1-14.

Citation Information

Patent Citations

  • Method and apparatus for signaling protection symbols in integrated access and backhaul

    CN115606114A

  • Protection symbol configuration method and communication device

    CN115733597A

  • Security enhancement method for radio resource control (RRC) connection resumption, and communication apparatus

    WO2023010531A1

  • Devices and methods of communication

    WO2024152308A1