Transmission method, communication device, communication system and storage medium

By protecting the MAC CE and generating a second MAC CE, the problems of unencrypted and unprotected MAC CEs are solved, improving its security and reliability and enhancing the performance of the communication system.

WO2026090876A1PCT designated stage Publication Date: 2026-05-07BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
BEIJING XIAOMI MOBILE SOFTWARE CO LTD
Filing Date
2024-10-29
Publication Date
2026-05-07

AI Technical Summary

Technical Problem

In existing technologies, MAC CE lacks encryption and integrity protection, posing a security risk of tampering or attack, which affects the performance and reliability of communication systems.

Method used

The MAC CE is protected by generating a second MAC CE. The security and reliability of the MAC CE are ensured through integrity and encryption protection, including the use of keys, counter values, and transmission direction parameters.

Benefits of technology

It improves the security and reliability of MAC CE, prevents tampering and attacks, and enhances the performance of the communication system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024128304_07052026_PF_FP_ABST
    Figure CN2024128304_07052026_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the present application are a transmission method, a communication device, a communication system and a storage medium. The method comprises: performing protection processing on a first media access control (MAC) control element (CE) to obtain a second MAC CE; and sending the second MAC CE. Therefore, the problem of a MAC CE possibly being attacked or tampered with is avoided to some extent.
Need to check novelty before this filing date? Find Prior Art

Description

Transmission methods, communication equipment, communication systems and storage media Technical Field

[0001] This disclosure relates to the field of communication technology, and in particular to a transmission method, communication device, communication system and storage medium. Background Technology

[0002] The relevant protocols propose to encrypt and protect the integrity of Radio Resource Control (RRC) messages in order to prevent the content transmitted through RRC messages from being attacked.

[0003] Summary of the Invention

[0004] This disclosure provides a transmission method, communication device, communication system, and storage medium.

[0005] A first aspect of this disclosure provides a transmission method, which is executed by a communication device, and the method includes:

[0006] The first media access control (MAC) control unit CE is protected to obtain the second MAC CE;

[0007] Send the second MAC CE.

[0008] A second aspect of this disclosure provides a communication device, which includes:

[0009] The processing module is used to perform protection processing on the first media access control (MAC) control unit (CE) to obtain the second MAC CE;

[0010] The transceiver module is used to send the second MAC CE.

[0011] A third aspect of this disclosure provides a communication device, which includes one or more processors;

[0012] The processor is used to execute the method described in the first aspect above.

[0013] A communication system, comprising terminals and network devices, wherein the terminals and network devices are respectively used to perform the method described in the first aspect above.

[0014] A fourth aspect of this disclosure provides a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform the method described in the first aspect above.

[0015] A sixth aspect of this disclosure provides a computer program product including a computer program that, when executed by a processor, implements the method described in the first aspect above.

[0016] The solution proposed in this disclosure protects the first Media Access Control (MAC) unit CE to obtain a second MAC CE, and then transmits the second MAC CE. This, to a certain extent, avoids the problem of MAC CE being tampered with or attacked, improves the security and reliability of the MAC CE, and provides conditions for improving the performance of the communication system. Attached Figure Description

[0017] To more clearly illustrate the technical solutions in the embodiments or background art of this disclosure, the accompanying drawings used in the embodiments or background art of this disclosure will be described below.

[0018] Figure 1 is a schematic diagram of the architecture of a communication system provided in an embodiment of this disclosure;

[0019] Figures 2A-2C are interactive schematic diagrams of the transmission method provided in the embodiments of this disclosure;

[0020] Figure 3 is a schematic diagram of the structure of a terminal provided in an embodiment of this disclosure;

[0021] Figure 4A is a schematic diagram of the structure of a communication device provided in an embodiment of this disclosure;

[0022] Figure 4B is a schematic diagram of the structure of a chip provided in an embodiment of this disclosure. Detailed Implementation

[0023] This disclosure presents a transmission method, a communication device, a communication system, and a storage medium.

[0024] In a first aspect, embodiments of this disclosure propose a transmission method, the method comprising: performing protection processing on a first media access control (MAC) control unit CE to obtain a second MAC CE; and sending the second MAC CE.

[0025] In the above embodiments, the first Media Access Control (MAC) unit CE is protected to obtain a second MAC CE, which is then transmitted. This, to a certain extent, avoids the problem of MAC CE being tampered with or attacked, improves the security and reliability of the MAC CE, and provides conditions for improving the performance of the communication system.

[0026] In conjunction with some embodiments of the first aspect, in some embodiments, the above-described protection processing of the first media access control (MAC) control unit CE includes: performing integrity protection processing on the first MAC CE based on one or more of the following first parameters: first MAC CE key, first count value, and transmission direction parameter.

[0027] In the above embodiments, the communication device can perform integrity protection processing on the MAC PDU based on one or more parameters, thereby ensuring the integrity of the MAC CE and further improving the security and reliability of MAC layer transmission.

[0028] In conjunction with some embodiments of the first aspect, in some embodiments the above method further includes:

[0029] The first algorithm and key K based on MAC CE association gNB Generate the first MAC CE key.

[0030] In the above embodiments, a key for integrity protection of the MAC CE is derived based on the security key between the terminal and the network device and the first algorithm, thereby ensuring that the terminal and the network device have a consistent understanding of the first MAC CE key and ensuring the reliable transmission of the MAC CE with integrity protection.

[0031] In conjunction with some embodiments of the first aspect, in some embodiments, the above-described protection processing of the first media access control (MAC) control unit CE includes: performing encryption protection processing on the first MAC CE based on one or more of the following second parameters: a second MAC CE key, a second count value, a transmission direction parameter, and a length value.

[0032] In the above embodiments, the communication device can perform encryption protection processing on the MAC PDU based on one or more parameters, thereby ensuring that the MAC CE is not leaked, and further improving the security and reliability of MAC layer transmission.

[0033] In conjunction with some embodiments of the first aspect, in some embodiments the above method further includes:

[0034] The second algorithm and key K based on MAC CE association gNB Generate the second MAC CE key.

[0035] In the above embodiments, a key for encrypting and protecting the MAC CE is derived based on the security key between the terminal and the network device and the second algorithm, thereby ensuring that the terminal and the network device have a consistent understanding of the second MAC CE key and ensuring the reliable transmission of the encrypted MAC CE.

[0036] In conjunction with some embodiments of the first aspect, in some embodiments, the above-described protection processing of the first media access control (MAC) control unit CE to obtain the second MAC CE includes: using a third algorithm to perform protection processing on the first MAC CE to obtain the second MAC CE.

[0037] In conjunction with some embodiments of the first aspect, in some embodiments, the third algorithm described above is any one of the following: an algorithm associated with Radio Resource Control (RRC) messages, or an algorithm configured by the network device for protecting MAC CE.

[0038] In the above embodiments, by employing a dedicated protection algorithm or reusing the RRC-associated algorithm to protect the MAC CE, the understanding of the third algorithm between the terminal and the network device is consistent, thus ensuring the reliable transmission of the protected MAC CE.

[0039] In conjunction with some embodiments of the first aspect, in some embodiments, the above-described protection processing of the first MAC CE includes one or more of the following:

[0040] The packet body of the first MAC CE is protected;

[0041] The header and body of the first MAC CE are both protected.

[0042] In the above embodiments, the communication device may protect only the packet body of the first MAC CE, or it may protect both the packet header and the packet body of the first MAC CE, which improves the flexibility of protecting the MAC CE and provides conditions for reducing the difficulty of protecting the MAC CE.

[0043] In conjunction with some embodiments of the first aspect, in some embodiments, the aforementioned first MAC CE is at least one of the following:

[0044] All MAC CEs in a MAC Packet Data Unit (PDU);

[0045] Each MAC CE in a MAC PDU;

[0046] All MAC CEs in a MAC PDU after removing one or more specified MAC CEs;

[0047] One or more specified MAC CEs in a MAC PDU;

[0048] Each MAC CE in one or more specified MAC CEs within a MAC PDU.

[0049] In the above embodiments, various forms of protection processing can be used to protect the MAC CE, further improving the flexibility of MAC CE protection processing and reducing the difficulty of MAC CE protection processing.

[0050] In conjunction with some embodiments of the first aspect, in some embodiments the above method further includes:

[0051] Send or receive indication information, wherein the indication information is used to indicate whether to enable or disable the function of protecting the MAC CE.

[0052] In the above embodiments, the function of protecting the MAC CE can be dynamically turned on or off, so that the MAC CE protection is only required when communication needs to be protected. This ensures the security and integrity of important MAC CEs while avoiding the waste of resources caused by unnecessary MAC CE protection.

[0053] In conjunction with some embodiments of the first aspect, in some embodiments, the second MAC CE described above includes a protection tag, which is used to assist the receiving end in performing integrity verification on the second MAC CE.

[0054] In the above embodiments, by sending the protection tag together with the second MAC CE to the receiving end, the receiving end can accurately verify the integrity of the received second MAC CE.

[0055] In conjunction with some embodiments of the first aspect, in some embodiments the aforementioned protective label is not encrypted.

[0056] In the above embodiments, since the leakage of the protection tag will not affect the normal operation of communication services, the protection tag is not encrypted, thus reducing resource waste.

[0057] Secondly, embodiments of this disclosure provide a communication device, the communication device comprising:

[0058] The processing module is used to perform protection processing on the first media access control (MAC) control unit (CE) to obtain the second MAC CE;

[0059] The transceiver module is used to send the second MAC CE.

[0060] In conjunction with some embodiments of the second aspect, in some embodiments, the above-described processing module is further configured to perform integrity protection processing on the first MAC CE based on one or more of the following first parameters: first MAC CE key, first count value, and transmission direction parameter.

[0061] In conjunction with some embodiments of the second aspect, in some embodiments, the above-described processing module is further used to perform a first algorithm and key K associated with MAC CE. gNB Generate the first MAC CE key.

[0062] In conjunction with some embodiments of the second aspect, in some embodiments, the above-described processing module is further configured to perform encryption protection processing on the first MAC CE based on one or more of the following second parameters: second MAC CE key, second count value, transmission direction parameter, and length value.

[0063] In conjunction with some embodiments of the second aspect, in some embodiments, the above-described processing module is further used to perform a second algorithm and key K associated with MAC CE. gNB Generate the second MAC CE key.

[0064] In conjunction with some embodiments of the second aspect, in some embodiments, the above-mentioned processing module is further configured to employ a third algorithm to perform protection processing on the first MAC CE to obtain the second MAC CE.

[0065] In conjunction with some embodiments of the second aspect, in some embodiments, the third algorithm described above is any one of the following: an algorithm associated with Radio Resource Control (RRC) messages, or an algorithm configured by the network device for protecting MAC CE.

[0066] In conjunction with some embodiments of the second aspect, in some embodiments, the above-described processing module is further configured to perform one or more of the following:

[0067] The packet body of the first MAC CE is protected;

[0068] The header and body of the first MAC CE are both protected.

[0069] In conjunction with some embodiments of the second aspect, in some embodiments, the aforementioned first MAC CE is at least one of the following:

[0070] All MAC CEs in a MAC Packet Data Unit (PDU);

[0071] Each MAC CE in a MAC PDU;

[0072] All MAC CEs in a MAC PDU after removing one or more specified MAC CEs;

[0073] One or more specified MAC CEs in a MAC PDU;

[0074] Each MAC CE in one or more specified MAC CEs within a MAC PDU.

[0075] In conjunction with some embodiments of the second aspect, in some embodiments, the above-described transceiver module is further used for:

[0076] Send or receive indication information, wherein the indication information is used to indicate whether to enable or disable the function of protecting the MAC CE.

[0077] In conjunction with some embodiments of the second aspect, in some embodiments, the second MAC CE mentioned above includes a protection tag, which is used to assist the receiving end in performing integrity verification on the second MAC CE.

[0078] In conjunction with some embodiments of the second aspect, in some embodiments, the aforementioned protective label is not encrypted.

[0079] Thirdly, embodiments of this disclosure provide a communication device, which includes one or more processors; wherein the communication device is used to execute the first aspect and optional implementations of the first aspect.

[0080] Fourthly, embodiments of this disclosure provide a communication system comprising: a terminal and a network device; wherein the terminal and the network device are configured to perform the methods described in the first aspect and optional implementations thereof.

[0081] Fifthly, embodiments of this disclosure provide a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform the method described in the first aspect and its optional implementations.

[0082] In a sixth aspect, embodiments of this disclosure provide a program product that, when executed by a communication device, causes the communication device to perform the method as described in the first aspect and its optional implementations.

[0083] In a seventh aspect, embodiments of this disclosure provide a computer program that, when run on a computer, causes the computer to perform the methods described in the first aspect and optional implementations of the first aspect.

[0084] Eighthly, embodiments of this disclosure provide a chip or chip system. The chip or chip system includes processing circuitry configured to perform the methods described according to the first aspect and optional implementations thereof.

[0085] It is understood that the aforementioned terminals, network devices, access network devices, core network devices, communication devices, communication systems, storage media, program products, computer programs, chips, or chip systems are all used to execute the methods proposed in the embodiments of this disclosure. Therefore, the beneficial effects that can be achieved can be referred to the beneficial effects in the corresponding methods, and will not be repeated here.

[0086] This disclosure provides a transmission method, a communication device, a communication system, and a storage medium. In some embodiments, the terms "transmission method" and "information processing method," "communication method," etc., can be used interchangeably; the terms "message transmission device" and "information processing device," "communication device," etc., can be used interchangeably; and the terms "message transmission system" and "information processing system," "communication system," etc., can be used interchangeably.

[0087] This disclosure is not exhaustive, but merely illustrative of some embodiments, and is not intended to limit the scope of protection of this disclosure. Unless otherwise specified, each step in a particular embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a particular embodiment can also be implemented as an independent embodiment, and the order of the steps in a particular embodiment can be arbitrarily interchanged. Furthermore, the optional implementation methods in a particular embodiment can be arbitrarily combined; moreover, the embodiments can be arbitrarily combined, for example, some or all steps of different embodiments can be arbitrarily combined, and a particular embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.

[0088] In each of the disclosed embodiments, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of the embodiments are consistent and can be referenced by each other. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.

[0089] The terminology used in the embodiments of this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the scope of this disclosure.

[0090] In this disclosure, unless otherwise stated, elements expressed in the singular form, such as "a," "an," "the," "the," "the aforementioned," "the," "this," etc., can mean "one and only one," or "one or more," "at least one," etc. For example, when using articles such as "a," "an," "the," etc. in translation, the noun following the article can be understood as either a singular or a plural expression.

[0091] In the embodiments disclosed herein, "multiple" refers to two or more.

[0092] In some embodiments, the terms “at least one of”, “one or more”, “a plurality of”, “multiple”, etc., may be used interchangeably.

[0093] In some embodiments, the notation "at least one of A and B", "A and / or B", "A in one case, B in another", "in response to one case A, in response to another case B", etc., may include the following technical solutions depending on the situation: in some embodiments, A (execute A regardless of B); in some embodiments, B (execute B regardless of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); in some embodiments, A and B (both A and B are executed). The same applies when there are more branches such as A, B, C, etc.

[0094] In some embodiments, the notation "A or B" may include the following technical solutions, depending on the situation: in some embodiments, A (execution of A regardless of B); in some embodiments, B (execution of B regardless of A); in some embodiments, execution is selected from A and B (A and B are selectively executed). The same applies when there are more branches such as A, B, C, etc.

[0095] The prefixes "first," "second," etc., used in the embodiments of this disclosure are merely for distinguishing different descriptive objects and do not impose restrictions on the position, order, priority, quantity, or content of the descriptive objects. The description of the descriptive objects is found in the claims or the context of the embodiments, and the use of prefixes should not constitute unnecessary restrictions. For example, if the descriptive object is a "field," the ordinal numbers preceding "field" in "first field" and "second field" do not restrict the position or order of the "fields." "First" and "second" do not restrict whether the "fields" they modify are in the same message, nor do they restrict the order of "first field" and "second field." Similarly, if the descriptive object is a "level," the ordinal numbers preceding "level" in "first level" and "second level" do not restrict the priority between "levels." Furthermore, the number of descriptive objects is not limited by ordinal numbers and can be one or more. For example, in "first device," the number of "devices" can be one or more. Furthermore, the objects modified by different prefixes can be the same or different. For example, if the object being described is "device", then "first device" and "second device" can be the same device or different devices, and their types can be the same or different. Similarly, if the object being described is "information", then "first information" and "second information" can be the same information or different information, and their content can be the same or different.

[0096] In some embodiments, “including A,” “containing A,” “for indicating A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.

[0097] In some embodiments, the terms “in response to…”, “in response to determining…”, “in the case of…”, “when…”, “if…”, “if…”, etc., can be used interchangeably.

[0098] In some embodiments, the terms “greater than,” “greater than or equal to,” “not less than,” “more than,” “more than or equal to,” “not less than,” “higher than,” “higher than or equal to,” “not lower than,” and “above” can be used interchangeably, as can the terms “less than,” “less than or equal to,” “not greater than,” “less than,” “less than or equal to,” “not more than,” “lower than,” “lower than or equal to,” “not higher than,” and “below”.

[0099] In some embodiments, the apparatus and device may be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments. In some cases, they may also be understood as "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "body", etc.

[0100] In some embodiments, "network" can be interpreted as devices included in the network, such as access network devices, core network devices, etc.

[0101] In some embodiments, "access network device (AN device)" may also be referred to as "radio access network device (RAN device)," "base station (BS)," "radio base station," or "fixed station." In some embodiments, it may also be understood as "node," "access point," "transmission point (TP)," "reception point (RP)," "transmission / reception point (TRP)," "panel," "antenna panel," "antenna array," "cell," "macro cell," "small cell," "femto cell," "pico cell," "sector," "cell group," "serving cell," "carrier," "component carrier," or "bandwidth part (BWP)."

[0102] In some embodiments, "terminal" or "terminal device" may be referred to as "user equipment (UE)," "user terminal," "Narrow Band-Internet of Things (NB-IoT) device," "mobile station (MS)," "mobile terminal (MT)," "subscriber station," "mobile unit," "subscriber unit," "wireless unit," "remote unit," "mobile device," "wireless device," "wireless communication device," "remote device," "mobile subscriber station," "access terminal," "mobile terminal," "wireless terminal," "remote terminal," "handset," "user agent," "mobile client," "client," etc.

[0103] In some embodiments, access network devices, core network devices, or network devices can be replaced by terminals. For example, embodiments of this disclosure can also be applied to structures where communication between access network devices, core network devices, or network devices and terminals is replaced by communication between multiple terminals (e.g., device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, the structure can also be configured such that the terminal has all or part of the functions of the access network device. Furthermore, terms such as "uplink" and "downlink" can be replaced with terms corresponding to communication between terminals (e.g., "sidelink"). For example, uplink channel, downlink channel, etc., can be replaced with sidelink channel, and uplink link, downlink, etc., can be replaced with sidelink link.

[0104] In some embodiments, the terminal may be replaced by an access network device, a core network device, or a network device. In this case, the access network device, core network device, or network device may also be configured to have all or some of the functions of the terminal.

[0105] In some embodiments, the acquisition of data, information, etc., may comply with the laws and regulations of the country where the location is situated.

[0106] In some embodiments, data, information, etc., may be obtained with the user's consent.

[0107] Figure 1 is a schematic diagram of the architecture of a communication system according to an embodiment of the present disclosure.

[0108] As shown in Figure 1, the communication system 100 includes a terminal 101 and a network device 102.

[0109] In some embodiments, terminal 101 includes, but is not limited to, at least one of the following: mobile phone, wearable device, Internet of Things device, car with communication function, smart car, tablet computer, computer with wireless transceiver function, virtual reality (VR) terminal device, augmented reality (AR) terminal device, wireless terminal device in industrial control, wireless terminal device in self-driving, wireless terminal device in remote medical surgery, wireless terminal device in smart grid, wireless terminal device in transportation safety, wireless terminal device in smart city, and wireless terminal device in smart home.

[0110] In some embodiments, network device 102 may include at least one of access network device and core network device.

[0111] In some embodiments, the access network device is, for example, a node or device that connects a terminal to a wireless network. The access network device may include, but is not limited to, at least one of the following in a 5G communication system: evolved Node B (eNB), next-generation eNB (ng-eNB), next-generation Node B (gNB), node B (NB), home node B (HNB), home evolved node B (HeNB), radio backhaul device, radio network controller (RNC), base station controller (BSC), base transceiver station (BTS), base band unit (BBU), mobile switching center, base station in a 6G communication system, open RAN, cloud RAN, base station in other communication systems, and access node in a Wi-Fi system.

[0112] In some embodiments, the technical solutions of this disclosure can be applied to the Open RAN architecture. In this case, the interfaces between or within access network devices involved in the embodiments of this disclosure can be transformed into internal interfaces of Open RAN. The processes and information interactions between these internal interfaces can be implemented by software or programs.

[0113] In some embodiments, the access network device may be composed of a central unit (CU) and a distributed unit (DU). The CU may also be called a control unit. The CU-DU structure can separate the protocol layer of the access network device. Some of the protocol layer functions are centrally controlled by the CU, while the remaining part or all of the protocol layer functions are distributed in the DU and centrally controlled by the CU. However, this is not the only possibility.

[0114] In some embodiments, a core network device may be a single device comprising one or more network elements, or it may be multiple devices or a group of devices, each comprising all or part of the aforementioned one or more network elements. Network elements may be virtual or physical. The core network may include, for example, at least one of an Evolved Protocol Core (EPC), a 5G Core Network (5GCN), or a Next Generation Core (NGC).

[0115] It is understood that the communication system described in this disclosure is for the purpose of more clearly illustrating the technical solutions of this disclosure, and does not constitute a limitation on the technical solutions proposed in this disclosure. As those skilled in the art will know, with the evolution of system architecture and the emergence of new business scenarios, the technical solutions proposed in this disclosure are also applicable to similar technical problems.

[0116] The following embodiments of this disclosure can be applied to the communication system 100 shown in FIG1, or to some of the main bodies, but are not limited thereto. The main bodies shown in FIG1 are illustrative. The communication system may include all or some of the main bodies in FIG1, or may include other main bodies outside of FIG1. ​​The number and form of each main body are arbitrary. Each main body may be physical or virtual. The connection relationship between the main bodies is illustrative. The main bodies may not be connected or may be connected. The connection may be in any way, such as direct connection or indirect connection, wired connection or wireless connection.

[0117] The embodiments disclosed herein can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), and IEEE 802.20, Ultra-Wideband (UWB), Bluetooth (a registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X) systems, systems utilizing other transmission methods, and next-generation systems built upon them, etc. Furthermore, multiple systems can be combined (e.g., a combination of LTE or LTE-A with 5G).

[0118] The relevant protocols propose to encrypt and protect the integrity of Radio Resource Control (RRC) messages in order to prevent the content transmitted through RRC messages from being attacked.

[0119] Optionally, RRC messages can be classified into P-type RRC messages, AI-type RRC messages, and AC-type RRC messages according to the protection strategy.

[0120] Among them, P-class RRC messages are messages that can be sent (unprotected) before AS security is activated; A–I-class RRC messages are messages that can be sent without integrity protection after the Access Stratum (AS) security is activated; and A–C-class RRC messages are messages that can be sent without encryption after the AS security is activated.

[0121] Currently, the Media Access Control (MAC) layer control element (CE) is not encrypted or protected for integrity. As a type of control signaling, the MAC CE may pose security risks if not encrypted and protected for integrity.

[0122] For example, if the MAC CE of the L1 / L2 Triggered Mobility (LTM) cell switch command received by the terminal is tampered with, the terminal may switch to an illegal cell, thereby affecting the execution of terminal services.

[0123] Alternatively, if the terminal receives the attacked GNSS measurement command MAC CE, it will retune to the GNSS frequency to measure GNSS, thereby affecting the terminal's normal communication.

[0124] Alternatively, the terminal's private data may be tampered with. For example, if the terminal's report of the remaining validity period of the Global Navigation Satellite System (GNSS) data to the network device is altered, it may lead to the early or delayed release of the RRC. Or, if the terminal's private Timing Advance (TA) Command MAC CE is obtained by a third party, that third party can identify the terminal's location range relative to the network device, and so on.

[0125] This disclosure proposes a method for protecting MAC CEs. Before sending a MAC CE, the communication device can first protect the MAC CE, thereby improving the security and integrity of MAC CE transmission and providing conditions for avoiding the leakage of private data and improving the security and reliability of transmission.

[0126] The transmission method, communication equipment, communication system, and storage medium provided in this disclosure will be described in detail below with reference to the accompanying drawings.

[0127] Figure 2A is a flowchart illustrating a transmission method according to an embodiment of the present disclosure. As shown in Figure 2A, the transmission method involved in this embodiment is executed by a communication device, which can be a terminal or a network device. The method is described below using a terminal as an example. As shown in Figure 2A, the method includes:

[0128] Step S2101, based on the first algorithm and key K gNB Generate the first MAC CE key.

[0129] In some embodiments, the first algorithm is associated with MAC CE.

[0130] In some embodiments, the first algorithm may be a method for calculating the integrity key corresponding to the MAC CE, as agreed upon by the protocol or instructed by the network device.

[0131] In some embodiments, the first algorithm may be a key derivation function (KDF).

[0132] In some embodiments, the protocol or network device may indicate the index (or sequence number) of the first algorithm to the communication device, and then the communication device may query the list of key derivation functions based on the determined index or sequence number to determine the first algorithm currently used to generate the first MAC CE key.

[0133] In some embodiments, the list of key derivation functions may be as shown in Table 1:

[0134] Table 1

[0135] As shown in Table 1, the list of key derivation functions can include key derivation function identifiers (indexes) associated with various messages, which are used to distinguish the association between different key derivation functions (or function values) and messages.

[0136] For example, "N-NAS-enc-alg" indicates that the algorithm (alg) (value) can be used for encryption (enc) protection of Non-Access Stratum (NAS) messages; "N-NAS-int-alg" indicates that the algorithm (value) can be used for integrity (int) protection of NAS messages. "N-RRC-enc-alg" indicates that the algorithm (value) can be used for encryption protection of RRC messages; "N-RRC-int-alg" indicates that the algorithm (value) can be used for integrity protection of RRC messages. "N-UP-enc-alg" indicates that the algorithm (value) can be used for encryption protection of User Plane (UP) messages; "N-UP-int-alg" indicates that the algorithm (value) can be used for integrity protection of UP messages. “N-MAC-CE-enc-alg” is used to identify that the algorithm (value) can be used for encryption protection of MAC CE; “N-MAC-CE-int-alg” is used to identify that the algorithm (value) can be used for integrity protection of MAC CE.

[0137] It should be noted that 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, etc. in Table 1 above are only for illustrative purposes. The algorithms (values) used for encryption and / or integrity protection of different information may be different and should not be taken as specific limitations on different algorithms (values).

[0138] In some embodiments, the first algorithm associated with the MAC CE can be fixed. That is, the same first algorithm is used to derive the first MAC CE key for all communication devices.

[0139] In some embodiments, the first algorithm associated with different terminals may be different. For example, the network device may configure or update the first algorithm in real time, so that different terminals may use different first algorithms, which further provides conditions for improving the privacy of MAC CE sent or received by the terminal.

[0140] In some embodiments, when different terminals are associated with different first algorithms, the network device will use different first algorithms for different terminals when communicating with different terminals to obtain the corresponding first MAC CE key, thereby ensuring that the first key used by the terminal and the network device is the same.

[0141] In some embodiments, K gNB K is a key used to protect the security of communication between terminals and access network equipment (such as gNBs). gNBIt can be used to derive other keys, based on K. gNB Derived keys can be used to ensure the confidentiality and integrity of the content transmitted between terminals and network devices (such as user data and / or signaling), thereby ensuring the security and reliability of the communication process.

[0142] In some embodiments, K gNB It can be generated in accordance with the agreement or in a manner based on the agreement; this disclosure does not limit this.

[0143] In some embodiments, for dual-connectivity scenarios, the terminal can use the same first MAC CE key for either the primary or secondary cell.

[0144] In some embodiments, the length of the first MAC CE key can be any number of bits, such as 64 bits, 128 bits, 256 bits, etc., and this disclosure does not limit it.

[0145] Step S2102, based on the second algorithm and key K gNB Generate a second MAC CE key.

[0146] In some embodiments, the second algorithm is associated with MAC CE.

[0147] In some embodiments, the second algorithm may be a method for calculating the encryption key corresponding to the MAC CE, as agreed upon by the protocol or instructed by the network device.

[0148] In some embodiments, the second algorithm can be two key derivation functions (KDFs).

[0149] In some embodiments, the protocol or network device may indicate the index (or sequence number) of the second algorithm to the communication device, which may then query the list of key derivation functions based on the determined index or sequence number to determine the second algorithm currently used to generate the second MAC CE key.

[0150] In some embodiments, the method for determining the second algorithm can refer to the detailed description of the first algorithm section above, and will not be repeated here.

[0151] In some embodiments, the second algorithm associated with the MAC CE can be fixed. That is, the same second algorithm is used to derive the second MAC CE key for all communication devices.

[0152] In some embodiments, the second algorithm associated with different terminals may be different. For example, the network device may configure or update the second algorithm in real time, so that different terminals may use different second algorithms, which further provides conditions for improving the privacy of MAC CE sent or received by the terminal.

[0153] In some embodiments, when different terminals are associated with different second algorithms, the network device will use different second algorithms for different terminals when communicating with different terminals to obtain the corresponding second MAC CE key, thereby ensuring that the second key used by the terminal and the network device is the same.

[0154] In some embodiments, the first algorithm and the second algorithm may be the same or different.

[0155] In some embodiments, the first algorithm and the second algorithm corresponding to the same terminal may be the same or different.

[0156] In some embodiments, for dual-connectivity scenarios, the terminal can use the same second MAC CE key for either the primary or secondary cell.

[0157] In some embodiments, the length of the second MAC CE key can be any number of bits, such as 64 bits, 128 bits, 256 bits, etc., and this disclosure does not limit it.

[0158] In some embodiments, steps S2101 and S2102 can be executed simultaneously, or S2102 can be executed first and then S2101 can be executed. This disclosure does not limit this.

[0159] Step S2103: Send instruction information, wherein the instruction information is used to instruct the function of protecting the MAC CE to be enabled.

[0160] In some embodiments, the network device may send instruction information to the terminal.

[0161] In some embodiments, the communication device is a terminal, which can receive instruction information, which may be sent by the network side.

[0162] In some embodiments, the communication device is a network device, which can send instruction information. For example, the network device can send instruction information to a terminal.

[0163] In some real-time examples, the indication information can also be used to indicate the function of disabling protection processing for MAC CE.

[0164] In some embodiments, indication information can be sent or received via RRC messages.

[0165] In some embodiments, instruction information can be sent or received via broadcast messages.

[0166] In some embodiments, different indication information can be used to indicate whether to enable or disable the encryption and / or integrity protection functions for the MAC CE for different MAC entities. In other words, enabling or disabling the encryption and / or integrity protection functions for the MAC CE can be configured individually for each MAC.

[0167] In some embodiments, RRC can be used to configure MAC CE encryption and / or integrity protection features to be enabled or disabled.

[0168] In some embodiments, encryption and / or integrity protection functions can also be dynamically activated or deactivated via MAC CE. For example, the initial state of MAC CE encryption and / or integrity protection functions can be configured via RRC, the activated / deactivated state can be configured, or the default state can be used, and then MAC CE can be used to dynamically activate or deactivate the encryption and / or integrity protection functions.

[0169] Step S2104: Perform protection processing on the first MAC CE to obtain the second MAC CE.

[0170] In some embodiments, the communication device (such as a terminal or network device) may only perform protection processing on the first MAC CE when MAC CE protection is enabled.

[0171] In some embodiments, the first MAC CE is protected, including performing integrity protection on the first MAC CE.

[0172] In some embodiments, integrity protection processing is performed on the first MAC CE, including integrity protection processing of the first MAC CE based on integrity protection parameters, such as the first MAC CE key, the first count value, the transmission direction parameters, etc.

[0173] In some embodiments, the first count value is used to characterize the number of times the communication device performs integrity protection processing on the MAC CE, and the first count value is incremented by 1 each time integrity protection is completed.

[0174] In some embodiments, the transmission direction parameter is used to describe the transmission direction of the MAC CE corresponding to the current protection parameter.

[0175] In some embodiments, the transmission direction parameter can be represented by a 1-bit parameter. For example, a transmission direction parameter value of 1 indicates that the transmission direction of the corresponding MAC CE is downlink (DL); a transmission direction parameter value of 0 indicates that the transmission direction of the corresponding MAC CE is uplink (UL). Or, a transmission direction parameter value of 0 indicates that the transmission direction of the corresponding MAC CE is downlink (DL); a transmission direction parameter value of 1 indicates that the transmission direction of the corresponding MAC CE is uplink (UL), and so on. This disclosure does not limit this.

[0176] In some embodiments, integrity protection processing is performed on the first MAC CE to obtain a protection tag.

[0177] In some embodiments, a protection tag is used to assist the receiving end in verifying the integrity of the received second MAC CE after receiving it.

[0178] In some embodiments, terms such as “protection tag”, “message authentication code-integrity (MAC-I)”, “message integrity verification identifier”, “message integrity authentication code”, “information integrity verification identifier”, and “information integrity authentication code” can all indicate auxiliary information used to verify the integrity of a message (or information). In some scenarios, the above terms can be used interchangeably.

[0179] In some embodiments, the second MAC CE includes a protection tag, which assists the receiver in performing integrity verification on the second MAC CE.

[0180] In some embodiments, the protection tag is not encrypted.

[0181] In some embodiments, the protection tag is carried by a MAC CE, or not carried by a MAC CE.

[0182] In some embodiments, the receiving end (such as a terminal or network device) can perform integrity calculations on the received MAC CE based on the same logic as the sending end (such as a network device or terminal) to obtain a new protection tag. If the protection tag obtained by the receiving end is the same as the received protection tag, it can be determined that the MAC CE has not been tampered with. This ensures the reliability and security of the received MAC CE and avoids service anomalies caused by the receiving end responding to information contained in a tampered MAC CE.

[0183] In some embodiments, the first MAC CE is protected, including by encrypting the first MAC CE.

[0184] In some embodiments, the first MAC CE is encrypted. This encryption can be based on encryption parameters, such as the second MAC CE key, a second counter value, transmission direction parameters, length values, etc., to obtain an encrypted second MAC CE. By encrypting the first MAC CE, it is possible to prevent a third party from illegally obtaining the information contained in the MAC CE after it has been acquired, thus avoiding the leakage of private information.

[0185] In some embodiments, the length value is used to characterize the length of the MAC CE that needs to be encrypted.

[0186] In some embodiments, if multiple MAC CEs need to be encrypted as a whole, the length value can be the total length of the multiple MAC CEs.

[0187] In some embodiments, the terminal can perform protection processing on the uplink (UL) MAC CE, determine encryption protection parameters, such as a counter value, and place the protection parameters in the uplink MAC protocol data unit (PDU).

[0188] In some embodiments, the network device can perform protection processing on the downlink (DL) MAC CE, determine integrity protection parameters, such as protection tags, and place the protection parameters in the downlink MAC PDU.

[0189] In some embodiments, the protection parameters are obtained after protecting the MAC CE in the MAC PDU. The protection parameters can be one or more of the following: count value, protection tag.

[0190] In some embodiments, the MAC PDU may contain only a single count value. For example, if only the MAC CE is encrypted, the MAC PDU may only include the count value corresponding to the encryption protection. Alternatively, if only the MAC CE is protected by integrity, the MAC PDU may only include the count value corresponding to the integrity protection. Or, if both encryption and integrity protection are applied to the MAC CE, but the count value corresponding to the encryption protection is the same as the count value corresponding to the integrity protection, the MAC PDU may also contain only a single count value.

[0191] In some embodiments, the MAC PDU may contain two count values. For example, if the MAC CE is subjected to both encryption protection and integrity protection, then the MAC PDU may include a count value corresponding to encryption protection and a count value corresponding to integrity protection.

[0192] In some embodiments, the protection parameters are carried by the MAC CE, or not by the MAC CE.

[0193] In some embodiments, if the protection parameters are carried by a MAC CE and there are multiple protection parameters, the multiple protection parameters can be carried by a single MAC CE, or different protection parameters can be carried by different MAC CEs.

[0194] In some embodiments, the protection parameters corresponding to encryption protection are carried by one MAC CE, and the protection parameters corresponding to integrity protection are carried by another MAC CE.

[0195] In some embodiments, the communication device may employ a third algorithm to protect the first MAC CE and obtain the second MAC CE.

[0196] In some embodiments, the third algorithm may be an encryption protection algorithm and / or an integrity protection algorithm.

[0197] In some embodiments, the communication device may determine the third algorithm based on protocol agreements or network-side configuration (instructions).

[0198] In some embodiments, a third algorithm can be configured for the terminal via the SecurityModeCommand.

[0199] In some embodiments, different MAC entities may use different third algorithms. That is, the third algorithm may be configured individually for each MAC entity.

[0200] In some embodiments, the third algorithm can be an algorithm associated with RRC messages.

[0201] In some embodiments, the algorithm associated with the RRC message is an algorithm agreed upon in the protocol for encrypting and / or protecting the integrity of the RRC message.

[0202] In some embodiments, only the body of the first MAC CE may be protected.

[0203] In this embodiment, since some private or critical information is carried by the body of the MAC CE, only the body of the first MAC CE is protected in this embodiment. This reduces the processing burden of the communication device as much as possible while ensuring information security, and improves the efficiency and speed of protecting the first MAC CE.

[0204] In some embodiments, both the header and body of the first MAC CE may be protected.

[0205] In this embodiment, the security and reliability of the MAC CE are further improved by protecting both the header and body of the first MAC CE.

[0206] In some embodiments, the first MAC CE can be any of the MAC CEs in a MAC Packet Data Unit (PDU). That is, the communication device can protect all the MAC CEs in a MAC PDU as a whole.

[0207] In some embodiments, the first MAC CE can be each MAC CE in a MAC PDU. That is, the communication device can perform individual protection processing on each MAC CE in a MAC PDU. For example, if a MAC PDU has 3 MAC CEs, the communication device can perform protection processing on each of the 3 MAC CEs separately to obtain three second MAC CEs.

[0208] In some embodiments, the first MAC CE can be all MAC CEs in a MAC PDU after removing one or more specified MAC CEs.

[0209] In some embodiments, the MAC CE can be specified by protocol convention or network configuration.

[0210] In some embodiments, the communication device can protect all MAC CEs in a MAC PDU except for the specified MAC CE as a whole.

[0211] In some embodiments, the first MAC CE can be one or more designated MAC CEs in a MAC PDU.

[0212] In some embodiments, the first MAC CE can be each of one or more designated MAC CEs in a MAC PDU. That is, the communication device can perform individual protection processing on each of the designated MAC CEs in the MAC PDU.

[0213] Step S2105: Send the second MAC CE.

[0214] The transmission method involved in the embodiments of this disclosure may include at least one of steps S2101 to S2105. For example, step S2101 may be implemented as a separate embodiment, step S2102 may be implemented as a separate embodiment, step S2103 may be implemented as a separate embodiment, steps S2104+S2105 may be implemented as separate embodiments, etc., but is not limited thereto.

[0215] In the embodiments disclosed herein, some or all of the steps and their optional implementations may be arbitrarily combined with some or all of the steps in other embodiments, or may be arbitrarily combined with the optional implementations in other embodiments.

[0216] In the embodiments disclosed herein, each step and its optional implementation can also be carried out independently.

[0217] In this embodiment, the communication device first performs protection processing on the first MAC CE to obtain the second MAC CE, and then sends the second MAC CE, thereby improving the security and reliability of the MAC CE, avoiding the leakage and tampering of private information, and providing conditions for further improving the security and reliability of the communication system.

[0218] Figure 2B is a schematic flowchart illustrating a transmission method according to an embodiment of the present disclosure. As shown in Figure 2B, the transmission method involved in this embodiment is executed by a communication device, which can be a terminal or a network device. The method will be described below using a network device as an example. As shown in Figure 2B, the method includes:

[0219] Step S2201, the network device, based on the first algorithm and key K gNB Generate the first MAC CE key.

[0220] Step S2201, the network device, based on the second algorithm and key K gNB Generate a second MAC CE key.

[0221] In step S2103, the network device sends an instruction message to the terminal, wherein the instruction message is used to instruct the activation of the function to protect the MAC CE.

[0222] In step S2204, the network device performs protection processing on the first MAC CE to obtain the second MAC CE.

[0223] In step S2205, the network device sends a second MAC CE to the terminal.

[0224] The specific implementation methods of each of the above steps can be found in the detailed description of the corresponding steps in Figure 2A above, and will not be repeated here.

[0225] The transmission method involved in the embodiments of this disclosure may include at least one of steps S2201 to S2205. For example, step S2201 may be implemented as a standalone embodiment, step S2202 may be implemented as a standalone embodiment, step S2203 may be implemented as a standalone embodiment, steps S2204+S2205 may be implemented as standalone embodiments, etc., but is not limited thereto.

[0226] In the embodiments disclosed herein, some or all of the steps and their optional implementations may be arbitrarily combined with some or all of the steps in other embodiments, or may be arbitrarily combined with the optional implementations in other embodiments.

[0227] In the embodiments disclosed herein, each step and its optional implementation can also be carried out independently.

[0228] In this embodiment, the communication device first performs protection processing on the first MAC CE to obtain the second MAC CE, and then sends the second MAC CE, thereby improving the security and reliability of the MAC CE, avoiding the leakage and tampering of private information, and providing conditions for further improving the security and reliability of the communication system.

[0229] Figure 2C is a schematic flowchart illustrating a transmission method according to an embodiment of the present disclosure. As shown in Figure 2C, the transmission method involved in this embodiment is executed by a communication device, which can be a terminal or a network device. The method is described below using a terminal as an example. As shown in Figure 2C, the method includes:

[0230] Step S2301: Perform protection processing on the first MACCE to obtain the second MACCE.

[0231] Step S2302: Send the second MAC CE.

[0232] In some embodiments, the above-described protection processing for the first media access control (MAC) control unit CE includes:

[0233] Integrity protection processing is performed on the first MAC CE based on one or more of the following first parameters: first MAC CE key, first count value, and transmission direction parameter.

[0234] In some embodiments, the above method further includes:

[0235] The first algorithm and key K based on MAC CE association gNB Generate the first MAC CE key.

[0236] In some embodiments, the above-described protection processing for the first media access control (MAC) control unit CE includes:

[0237] The first MAC CE is encrypted based on one or more of the following second parameters: second MAC CE key, second counter value, transmission direction parameter, and length value.

[0238] In some embodiments, the above method further includes:

[0239] The second algorithm and key K based on MAC CE association gNB Generate the second MAC CE key.

[0240] In some embodiments, the above-described protection processing of the first media access control (MAC) control unit CE to obtain a second MAC CE includes:

[0241] A third algorithm is used to protect the first MAC CE, resulting in the second MAC CE.

[0242] In some embodiments, the third algorithm described above is any one of the following: an algorithm associated with Radio Resource Control (RRC) messages, or an algorithm configured by the network device for protecting MAC CE.

[0243] In some embodiments, the protection processing for the first MAC CE described above includes one or more of the following:

[0244] The packet body of the first MAC CE is protected;

[0245] The header and body of the first MAC CE are both protected.

[0246] In some embodiments, the first MAC CE described above is at least one of the following:

[0247] All MAC CEs in a MAC Packet Data Unit (PDU);

[0248] Each MAC CE in a MAC PDU;

[0249] All MAC CEs in a MAC PDU after removing one or more specified MAC CEs;

[0250] One or more specified MAC CEs in a MAC PDU;

[0251] Each MAC CE in one or more specified MAC CEs within a MAC PDU.

[0252] In some embodiments, the above method further includes:

[0253] Send or receive indication information, wherein the indication information is used to indicate whether to enable or disable the function of protecting the MAC CE.

[0254] In some embodiments, the second MAC CE includes a protection tag, which is used to assist the receiver in performing integrity verification on the second MAC CE.

[0255] In some embodiments, the aforementioned protective label is not encrypted.

[0256] The transmission method provided in this disclosure will be further explained below with reference to the following embodiments, taking the terminal side as an example.

[0257] When sending the UL MAC CE, the terminal encrypts and / or protects the integrity of the MAC CE before sending it.

[0258] Optionally, integrity protection is performed on the MAC CE, including integrity protection based on one or more of the following input parameters:

[0259] Based on K gNB Derived 128-bit integrity key K MAC_CE-int For both primary and secondary cells, the terminal can use the same integrity key.

[0260] The count value per direction.

[0261] 1 bit transmission direction, where whether this parameter is needed depends on whether the terminal protects only the uplink, or protects both DL and / or UL.

[0262] And MAC CEs that need protection.

[0263] In some embodiments, the COUNT value is used to count the number of MAC CE integrity protections performed, and the COUNT value is incremented by 1 for each integrity protection completed.

[0264] Optionally, via K gNB Generate K MAC_CE-int At that time, the input parameters include the MAC CE integrity protection key derivation algorithm (first algorithm) identifier (algorithm distinguisher).

[0265] In one implementation, the integrity protection key derivation algorithm identifier of MAC CE can be referred to as shown in Table 1 above, and this disclosure does not limit it.

[0266] Optionally, integrity protection for MAC CE can include one or more of the following methods:

[0267] Integrity protection is applied only to the MAC CE package body.

[0268] Integrity protection is applied to both the header and body of the MAC CE packet.

[0269] Optionally, integrity protection for MAC CE can include one or more of the following methods:

[0270] Protect the integrity of all MAC CEs in a MAC PDU as a whole.

[0271] Each MAC CE in a MAC PDU is individually protected for integrity.

[0272] All MAC CEs in a MAC PDU (excluding one or more specific MAC CEs) are treated as a whole for integrity protection.

[0273] Protect the integrity of one or more specific MAC CEs in a MAC PDU as a whole.

[0274] Integrity protection is applied to one or more specific MAC CEs within a MAC PDU.

[0275] In some embodiments, the specific MAC CE mentioned above is determined by protocol agreement or network configuration.

[0276] Optionally, the MAC CE is encrypted, including encryption based on one or more of the following input parameters:

[0277] Based on K gNB Derived 128-bit integrity key K MAC_CE-enc For both primary and secondary cells, the terminal can use the same integrity key.

[0278] The count value per direction.

[0279] 1 bit transmission direction, where whether this parameter is needed depends on whether the terminal protects only the uplink, or protects both DL and / or UL.

[0280] Length value (LENGTH).

[0281] In some embodiments, the COUNT value is used to count the number of MAC CE encryptions, incrementing by 1 for each encryption operation.

[0282] In some embodiments, LENGTH is the length of the MAC CE to be encrypted.

[0283] Optionally, via K gNB Generate K MAC_CE-enc At that time, the input parameters include the MAC CE encryption key derivation algorithm (second algorithm) identifier (algorithm distinguisher).

[0284] In one implementation, the encryption protection key derivation algorithm identifier of MAC CE can be referred to as shown in Table 1 above, but this disclosure does not limit it.

[0285] Alternatively, encrypting a MAC CE can be achieved using one or more of the following methods:

[0286] Encrypt only the body of the MAC CE packet.

[0287] Both the header and body of the MAC CE packet are encrypted.

[0288] Alternatively, encrypting a MAC CE can be achieved using one or more of the following methods:

[0289] Encrypt all MAC CEs in a MAC PDU as a whole.

[0290] Each MAC CE in a MAC PDU is encrypted individually.

[0291] Encrypt all MAC CEs in a MAC PDU (excluding one or more specific MAC CEs) as a whole.

[0292] Encrypt one or more specific MAC CEs in a MAC PDU as a whole.

[0293] Encrypt one or more specific MAC CEs in a MAC PDU.

[0294] In some embodiments, a specific MAC CE is defined by protocol or network configuration.

[0295] Optionally, the UE receives configuration information from the network device, which is used to enable or disable MAC CE encryption and / or integrity protection functions.

[0296] In some embodiments, the terminal enables the UL MAC CE encryption and / or integrity protection function only when the network device is configured to enable the MAC CE encryption and / or integrity protection function.

[0297] In some embodiments, the enabling or disabling of MAC CE encryption and / or integrity protection functions is configured per MAC entity.

[0298] In some embodiments, the MAC CE encryption and / or integrity protection functions can be configured to be enabled or disabled via RRC. Furthermore, the encryption / integrity protection functions can be dynamically activated / deactivated via MAC CE, and RRC can configure the initial state, activated / deactivated state, or default state of the MAC CE encryption and / or integrity protection functions.

[0299] Optionally, the encryption and / or integrity protection algorithms employed by MAC CE may be implemented in one or more of the following ways:

[0300] It uses the same encryption and / or integrity protection algorithms as RRC.

[0301] The encryption and / or integrity protection algorithms used by the MAC CE are configured separately for the network.

[0302] In some embodiments, the network uses SecurityModeCommand to configure the encryption and / or integrity protection algorithms employed by the MAC CE.

[0303] In some embodiments, the algorithm for MAC CE encryption and / or integrity protection is configured per MAC entity.

[0304] Optionally, MAC-I, which is generated for integrity protection, is carried in MAC CE.

[0305] Optionally, MAC-I is not encrypted.

[0306] Optionally, MAC-I can be carried using a MAC CE or a non-MAC CE.

[0307] This disclosure also provides an apparatus for implementing any of the above methods. For example, an apparatus is provided that includes units or modules for implementing the steps performed by the terminal in any of the above methods. Alternatively, another apparatus is provided that includes units or modules for implementing the steps performed by a network device (e.g., an access network device, a core network functional node, a core network device, etc.) in any of the above methods.

[0308] It should be understood that the division of units or modules in the above device is only a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, the units or modules in the device can be implemented by a processor calling software: for example, the device includes a processor connected to a memory containing instructions. The processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of the units or modules in the above device. The processor can be, for example, a general-purpose processor, such as a Central Processing Unit (CPU) or a microprocessor, and the memory can be internal or external to the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits. The functionality of some or all of the units or modules can be achieved through the design of these hardware circuits, which can be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC). The functionality of some or all of the units or modules is achieved through the design of the logical relationships between the components within the circuit. In another implementation, the hardware circuit can be implemented using a programmable logic device (PLD). Taking a field-programmable gate array (FPGA) as an example, it can include a large number of logic gates. The connection relationships between the logic gates are configured through configuration files, thereby achieving the functionality of some or all of the units or modules. All units or modules of the above device can be implemented entirely through processor-called software, entirely through hardware circuits, or partially through processor-called software with the remaining parts implemented through hardware circuits.

[0309] In this embodiment, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction read and execute capabilities, such as a Central Processing Unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationships of hardware circuits. The logical relationships of the aforementioned hardware circuits are fixed or reconfigurable. For example, the processor is a hardware circuit implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and configuring the hardware circuit can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. Furthermore, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a Neural Network Processing Unit (NPU), a Tensor Processing Unit (TPU), or a Deep Learning Processing Unit (DPU).

[0310] Figure 3 is a schematic diagram of the structure of a communication device proposed in an embodiment of this disclosure. As shown in Figure 3, the communication device 3100 may include at least one of a transceiver module 3101, a processing module 3102, etc. In some embodiments, the processing module is used to perform protection processing on the first media access control (MAC) control unit CE to obtain a second MAC CE; the transceiver module is used to transmit the second MAC CE.

[0311] In some embodiments, the above-described processing module is further configured to perform integrity protection processing on the first MAC CE based on one or more of the following first parameters: first MAC CE key, first count value, and transmission direction parameter.

[0312] In some embodiments, the above-described processing module is further configured to perform a first algorithm and key K associated with MAC CE. gNB Generate the first MAC CE key.

[0313] In some embodiments, the above-described processing module is further configured to perform encryption protection processing on the first MAC CE based on one or more of the following second parameters: second MAC CE key, second count value, transmission direction parameter, and length value.

[0314] In some embodiments, the above-described processing module is further configured to perform a second algorithm and key K associated with MAC CE. gNB Generate the second MAC CE key.

[0315] In some embodiments, the above-described processing module is further configured to employ a third algorithm to perform protection processing on the first MAC CE to obtain the second MAC CE.

[0316] In some embodiments, the third algorithm described above is any one of the following: an algorithm associated with Radio Resource Control (RRC) messages, or an algorithm configured by the network device for protecting MAC CE.

[0317] In some embodiments, the above-described processing module is further configured to perform one or more of the following:

[0318] The packet body of the first MAC CE is protected;

[0319] The header and body of the first MAC CE are both protected.

[0320] In some embodiments, the first MAC CE described above is at least one of the following:

[0321] All MAC CEs in a MAC Packet Data Unit (PDU);

[0322] Each MAC CE in a MAC PDU;

[0323] All MAC CEs in a MAC PDU after removing one or more specified MAC CEs;

[0324] One or more specified MAC CEs in a MAC PDU;

[0325] Each MAC CE in one or more specified MAC CEs within a MAC PDU.

[0326] In some embodiments, the transceiver module described above is further used for:

[0327] Send or receive indication information, wherein the indication information is used to indicate whether to enable or disable the function of protecting the MAC CE.

[0328] In some embodiments, the second MAC CE includes a protection tag, which is used to assist the receiver in performing integrity verification on the second MAC CE.

[0329] In some embodiments, the aforementioned protective label is not encrypted.

[0330] Optionally, the transceiver module described above is used to perform at least one of the communication steps such as sending and / or receiving performed by the terminal in any of the above methods, which will not be elaborated here.

[0331] Optionally, the above processing module is used to perform at least one of the other steps executed by the terminal in any of the above methods, which will not be elaborated here.

[0332] Figure 4A is a schematic diagram of the structure of the communication device 4100 proposed in an embodiment of this disclosure. The communication device 4100 can be a network device (e.g., access network device, core network device, etc.), a terminal (e.g., user equipment, etc.), a chip, chip system, or processor that supports the network device in implementing any of the above methods, or a chip, chip system, or processor that supports the terminal in implementing any of the above methods. The communication device 4100 can be used to implement the methods described in the above method embodiments; for details, please refer to the descriptions in the above method embodiments.

[0333] As shown in Figure 4A, the communication device 4100 includes one or more processors 4101. The processor 4101 can be a general-purpose processor or a dedicated processor, such as a baseband processor or a central processing unit (CPU). The baseband processor can be used to process communication protocols and communication data, while the CPU can be used to control communication devices (e.g., base stations, baseband chips, terminal devices, terminal device chips, DUs or CUs, etc.), execute programs, and process program data. The communication device 4100 is used to execute any of the above methods.

[0334] In some embodiments, the communication device 4100 further includes one or more memories 4102 for storing instructions. Optionally, all or part of the memories 4102 may also be located outside the communication device 4100.

[0335] In some embodiments, the communication device 4100 further includes one or more transceivers 4103. When the communication device 4100 includes one or more transceivers 4103, the transceivers 4103 perform at least one of the communication steps such as sending and / or receiving in the above method (e.g., step S2103), and the processor 4101 performs at least one of the other steps (e.g., steps S2101, S2102, S2104).

[0336] In some embodiments, a transceiver may include a receiver and / or a transmitter, which may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, transceiver circuit, etc., may be used interchangeably; the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc., may be used interchangeably; and the terms receiver, receiving unit, receiver, receiving circuit, etc., may be used interchangeably.

[0337] In some embodiments, the communication device 4100 may include one or more interface circuits 4104. Optionally, the interface circuit 4104 is connected to the memory 4102, and the interface circuit 4104 can be used to receive signals from the memory 4102 or other devices, and can be used to send signals to the memory 4102 or other devices. For example, the interface circuit 4104 can read instructions stored in the memory 4102 and send the instructions to the processor 4101.

[0338] The communication device 4100 described in the above embodiments may be a network device or a terminal, but the scope of the communication device 4100 described in this disclosure is not limited thereto, and the structure of the communication device 4100 may not be limited by FIG4A. The communication device may be a standalone device or may be part of a larger device. For example, the communication device may be: (1) a standalone integrated circuit IC, or chip, or chip system or subsystem; (2) a collection of one or more ICs, optionally, the IC collection may also include storage components for storing data and programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, terminal device, smart terminal device, cellular phone, wireless device, handheld device, mobile unit, vehicle device, network device, cloud device, artificial intelligence device, etc.; (6) others, etc.

[0339] Figure 4B is a schematic diagram of the structure of chip 4200 according to an embodiment of this disclosure. For cases where the communication device 4100 can be a chip or a chip system, please refer to the schematic diagram of chip 4200 shown in Figure 4B, but it is not limited thereto.

[0340] Chip 4200 includes one or more processors 4201, which are used to perform any of the above methods.

[0341] In some embodiments, chip 4200 further includes one or more interface circuits 4202. Optionally, the interface circuit 4202 is connected to memory 4203, and the interface circuit 4202 can be used to receive signals from memory 4203 or other devices, and the interface circuit 4202 can be used to send signals to memory 4203 or other devices. For example, the interface circuit 4202 can read instructions stored in memory 4203 and send the instructions to processor 4201.

[0342] In some embodiments, the interface circuit 4202 performs at least one of the communication steps such as sending and / or receiving in the above method, and the processor 4201 performs at least one of the other steps.

[0343] In some embodiments, the terms interface circuit, interface, transceiver pin, transceiver, etc., can be used interchangeably.

[0344] In some embodiments, chip 4200 further includes one or more memories 4203 for storing instructions. Optionally, all or part of the memories 4203 may be located outside of chip 4200.

[0345] This disclosure also proposes a storage medium storing instructions that, when executed on the communication device 4100, cause the communication device 4100 to perform any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but not limited thereto; it may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but not limited thereto; it may also be a temporary storage medium.

[0346] This disclosure also provides a program product that, when executed by the communication device 4100, causes the communication device 4100 to perform any of the above methods. Optionally, the program product is a computer program product.

[0347] This disclosure also proposes a computer program that, when run on a computer, causes the computer to perform any of the above methods.

[0348] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer programs. When the computer program is loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this disclosure are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer program can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program can be transferred from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., high-density digital video discs (DVDs)), or semiconductor media (e.g., solid-state disks (SSDs)).

[0349] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this disclosure.

[0350] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0351] The above description is merely a specific embodiment of this disclosure, but the scope of protection of this disclosure is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this disclosure should be included within the scope of protection of this disclosure. Therefore, the scope of protection of this disclosure should be determined by the scope of the claims.

Claims

1. A transmission method, characterized in that, The method includes: The first media access control (MAC) control unit CE is protected to obtain the second MAC CE; Send the second MAC CE.

2. The method as described in claim 1, characterized in that, The protection process for the first media access control (MAC) control unit CE includes: The first MAC CE is subjected to integrity protection processing based on one or more of the following first parameters: first MAC CE key, first count value, and transmission direction parameter.

3. The method as described in claim 2, characterized in that, The method further includes: The first algorithm and key K based on MAC CE association gNB Generate the first MAC CE key.

4. The method according to any one of claims 1-3, characterized in that, The protection process for the first media access control (MAC) control unit CE includes: The first MAC CE is encrypted based on one or more of the following second parameters: second MAC CE key, second counter value, transmission direction parameter, and length value.

5. The method as described in claim 4, characterized in that, The method further includes: The second algorithm and key K based on MAC CE association gNB Generate the second MAC CE key.

6. The method as described in any one of claims 1-5, characterized in that, The step of performing protection processing on the first media access control (MAC) control unit CE to obtain the second MAC CE includes: A third algorithm is used to protect the first MAC CE, resulting in the second MAC CE.

7. The method as described in claim 6, characterized in that, The third algorithm is any one of the following: an algorithm associated with Radio Resource Control (RRC) messages, or an algorithm configured by the network device for protecting MAC CE.

8. The method according to any one of claims 1-7, characterized in that, The protection process for the first MAC CE includes one or more of the following: The packet body of the first MAC CE is protected; The header and body of the first MAC CE are both protected.

9. The method according to any one of claims 1-8, characterized in that, The first MAC CE is at least one of the following: All MAC CEs in a MAC Packet Data Unit (PDU); Each MAC CE in a MAC PDU; All MAC CEs in a MAC PDU after removing one or more specified MAC CEs; One or more specified MAC CEs in a MAC PDU; Each MAC CE in one or more specified MAC CEs within a MAC PDU.

10. The method according to any one of claims 1-9, characterized in that, The method further includes: Send or receive indication information, wherein the indication information is used to indicate whether to enable or disable the function of protecting the MAC CE.

11. The method according to any one of claims 1-10, characterized in that, The second MAC CE includes a protection tag, which is used to assist the receiver in performing integrity verification on the second MAC CE.

12. The method as described in claim 11, characterized in that, The protection label is not encrypted.

13. A communication device, characterized in that, The communication device includes: The processing module is used to perform protection processing on the first media access control (MAC) control unit (CE) to obtain the second MAC CE; The transceiver module is used to send the second MAC CE.

14. A communication device, characterized in that, include: One or more processors; The processor is used to execute the transmission method according to any one of claims 1-12.

15. A communication system, characterized in that, It includes a terminal and a network device, wherein the terminal and the network device are respectively used to perform the transmission as described in any one of claims 1-12.

16. A storage medium storing instructions, characterized in that, When the instruction is executed on the communication device, the communication device performs the transmission method as described in any one of claims 1-12.

17. A computer program product, characterized in that, It includes a computer program that, when executed by a processor, implements the transmission method according to any one of claims 1-12.

Citation Information

Patent Citations

  • Communication method and device

    CN115696319A

  • Method and apparatus for enhancing security of MAC layer entity in next generation mobile communication system

    CN116762378A

  • Layer-2 security enhancements

    US20240244424A1

  • A method of joining a communication network

    WO2023217685A1

  • Devices and methods of communication

    WO2024152308A1