Security protection method and apparatus

By broadcasting security capability information and generating a shared key, the lack of security protection in connectionless communication is solved, enabling secure session communication and protecting user privacy.

WO2026103539A1PCT designated stage Publication Date: 2026-05-21HUAWEI TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
HUAWEI TECH CO LTD
Filing Date
2025-10-31
Publication Date
2026-05-21

AI Technical Summary

Technical Problem

In connectionless communication scenarios, communication and data interaction lack security protection, leading to risks to user privacy and security.

Method used

The broadcast end sends information about its supported security capabilities through broadcast frames. The responding end generates a shared key based on the received information, establishes a secure session communication, and uses the shared key to scramble, descramble, encrypt, decrypt, and protect the integrity of signals and data.

Benefits of technology

It enables secure communication with the responding end in the absence of a connection, protects user privacy and security, and improves the security of underlying physical signals and upper-layer interactive data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025131594_21052026_PF_FP_ABST
    Figure CN2025131594_21052026_PF_FP_ABST
Patent Text Reader

Abstract

The present application provides a security protection method and apparatus. The method comprises: a broadcast end sends a broadcast frame, wherein the broadcast frame comprises security capability information of the broadcast end; a response end receives the broadcast frame, selects a cryptographic algorithm on the basis of the security capability information, and sends the cryptographic algorithm to the broadcast end by means of a response frame; the broadcast end and the response end generate the same shared key and a derived key thereof on the basis of the selected cryptographic algorithm; and the broadcast end and the response end can use the shared key and the derived key thereof to perform security protection on a signal and data. The method solves the problem of the lack of security protection for communication and data interaction in a connectionless communication scenario, and protects the privacy security of a user. The present application supports IEEE protocols, such as IEEE 802.11be / WiFi 7 / EHT protocols, IEEE 802.11bn / UHR / WiFi 8 protocols, IEEE integrated mmWave / integrated millimeter wave / IMMW protocols, IEEE 802.15 / UWB protocols, or IEEE 802.11bf / sensing protocols. The present application can also support SparkLink / NearLink / Bluetooth standard protocols.
Need to check novelty before this filing date? Find Prior Art

Description

A safety protection method and device

[0001] This application claims priority to Chinese Patent Application No. 202411613664.5, filed on November 12, 2024, entitled "A Security Protection Method and Device", the entire contents of which are incorporated herein by reference. Technical Field

[0002] This application relates to the field of wireless technology, and in particular to a security protection method and device. Background Technology

[0003] With the continuous development of wireless technology, smart cars, smart homes, smart terminals, and other devices are gradually permeating people's daily lives. Technologies based on wireless communication, such as sensing, measurement, and positioning, are also being applied to various aspects of life, such as keyless entry and start (PESP) for smart cars, indoor positioning, and asset management.

[0004] In PESP (Powered Electronic Stability Program) applications for keyless entry and start, users do not need to use a key. The car can locate the user's car key or mobile phone through the vehicle's wireless positioning system, enabling automatic locking or unlocking of the doors. This is a connectionless measurement technology, used when two unfamiliar devices cannot establish a connection or cannot establish a connection in a timely manner for various reasons, but measurement is still required.

[0005] Because this connectionless measurement technology lacks security protection during the measurement process and the measurement results are sent in plaintext, attackers can easily obtain various parameters and measurement results during the measurement process, posing a risk to users' privacy and security. Summary of the Invention

[0006] This application provides a security protection method and apparatus that solves the problem of lack of security protection for communication and data interaction in connectionless communication scenarios, thereby protecting user privacy and security.

[0007] In a first aspect, embodiments of this application provide a security protection method. The method is applied to a broadcast terminal, which may include the broadcast terminal device itself, or may include a chip or functional module disposed within the broadcast terminal device. For example, the broadcast terminal may be a chip or functional module within a G-node after a G-node in the StarSpark standard; or the broadcast terminal may be a T-node or a chip or functional module within a T-node in the StarSpark standard. The method includes:

[0008] Send a broadcast frame, the broadcast frame including first information, the first information being used to indicate the security capability information supported by the broadcasting end;

[0009] Receive a response frame from the response, the response frame including second information and a second public key, the second information being used to indicate the security capability information selected by the responding end based on the first information, and the second public key being the public key of the responding end;

[0010] Based on the second information and the first private key, a first public key is generated, wherein the first private key is the private key of the broadcasting end;

[0011] Send the first public key to the responding end;

[0012] Based on the second information, the first private key, and the second public key, a first shared key is generated;

[0013] The first shared key is used to securely protect the session between the broadcaster and the responder.

[0014] In this embodiment, the broadcast end broadcasts its supported security capabilities to the response end via broadcast frames, enabling the response end to know the security capabilities of the broadcast end, thereby establishing secure session communication with the broadcast end in the absence of a connection and protecting the security of the interactive data.

[0015] In one possible implementation, the session is a connectionless communication, which includes at least one of the following: connectionless measurement, connectionless bus access;

[0016] The connectionless measurement refers to the communication between the broadcast end and the response end for measurement in the absence of a connection.

[0017] The connectionless bus access refers to communication where the responding end accesses the bus in the absence of a connection.

[0018] In one possible implementation, the first shared key securely protects the session between the broadcasting end and the responding end by including:

[0019] The signal sent from the broadcasting end to the responding end is scrambled using the first shared key or a derived key of the first shared key; or

[0020] The signal received by the broadcast terminal from the response terminal is descrambled using the first shared key or a derived key of the first shared key.

[0021] In this embodiment, the broadcast end can encrypt the transmitted physical signal using the first shared key or its derived key, thereby improving the security of the underlying physical signal.

[0022] In one possible implementation, the first shared key securely protects the session between the broadcasting end and the responding end by including:

[0023] Using the first shared key or a derived key of the first shared key, perform at least one of the following operations on the data sent from the broadcast end to the response end: encryption, integrity protection; or

[0024] Using the first shared key or a derived key of the first shared key, perform at least one of the following operations on the data received by the broadcast end from the response end: decryption and integrity verification.

[0025] In this embodiment, the broadcast end can encrypt and protect the integrity of the transmitted data using the first shared key or a derived key of the first shared key, thereby improving the security of upper-layer interactive data and protecting user privacy.

[0026] In one possible implementation, the first information includes at least one of the following:

[0027] Key negotiation algorithm capability, encryption algorithm capability, integrity protection algorithm capability, authentication encryption algorithm capability, key derivation function capability;

[0028] The key negotiation algorithm capability is used to indicate one or more key negotiation algorithms supported by the broadcast end;

[0029] The encryption algorithm capability is used to indicate one or more encryption algorithms supported by the broadcast end;

[0030] The integrity protection algorithm capability is used to indicate one or more integrity protection algorithms supported by the broadcast end;

[0031] The authentication encryption algorithm capability is used to indicate one or more authentication encryption algorithms supported by the broadcast end;

[0032] The key derivation function capability is used to indicate one or more key derivation functions supported by the broadcast end.

[0033] In this embodiment, the broadcasting end informs the responding end of its specific security capabilities through broadcasting, so that the responding end can select according to its own capabilities, thus providing a flexible security communication construction mechanism.

[0034] In one possible implementation, the second information includes at least one of the following:

[0035] Key negotiation algorithm indication, encryption algorithm indication, integrity protection algorithm indication, authentication encryption algorithm indication, key derivation function indication;

[0036] The key negotiation algorithm indicator is used to instruct the responding end to select a key negotiation algorithm;

[0037] The encryption algorithm indicator is used to indicate an encryption algorithm selected by the responding end;

[0038] The integrity protection algorithm indicator is used to indicate an integrity protection algorithm selected by the response end;

[0039] The authentication encryption algorithm indicator is used to indicate an authentication encryption algorithm selected by the responding end;

[0040] The key derivation function indicates a key derivation function selected by the responder.

[0041] In one possible implementation, the broadcast frame further includes a first random number.

[0042] The first random number is used to generate the derivation key of the first shared key.

[0043] In one possible implementation, the response frame further includes a second random number.

[0044] The second random number is used to generate the derivation key of the first shared key.

[0045] In this embodiment of the application, the broadcast end improves the security of the derivation key of the first shared key by using the first random number and the second random number, thereby avoiding replay attacks.

[0046] Secondly, embodiments of this application provide a security protection method, which is applied to a response end. The response end device may include the response end device itself, or may include a chip or functional module disposed in the response end device. For example, the response end may be a G node or a chip or functional module in a G node in the StarSpark standard; or the response end may be a T node or a chip or functional module in a T node in the StarSpark standard; the method includes:

[0047] Receive a broadcast frame from a broadcasting end, the broadcast frame including first information, the first information being used to indicate security capability information supported by the broadcasting end;

[0048] Based on the first information, second information is generated, which is used to instruct the response end to select security capability information;

[0049] A second public key is generated based on the second information and the second private key; the second private key is the private key of the responding end.

[0050] Send a response frame to the broadcasting end, the response frame including second information and a second public key;

[0051] Receive the first public key from the broadcaster;

[0052] Based on the second information, the second private key, and the first public key, a second shared key is generated;

[0053] The second shared key is used to secure the session between the responding end and the broadcasting end.

[0054] In this embodiment, the responding end informs the broadcasting end of the selected security capability information, thereby enabling secure session communication with the broadcasting end in the absence of a connection and protecting the interactive data.

[0055] In one possible implementation, the session is a connectionless communication, which includes at least one of the following:

[0056] Connectionless measurement, connectionless bus access;

[0057] The connectionless measurement refers to the communication between the broadcast end and the response end for measurement in the absence of a connection.

[0058] The connectionless bus access refers to communication where the responding end accesses the bus in the absence of a connection.

[0059] In one possible implementation, the second shared key securely protects the session between the responding end and the broadcasting end by including:

[0060] The signal sent from the responding end to the broadcasting end is scrambled using the second shared key or a derived key of the second shared key; or

[0061] The signal received by the response end from the broadcast end is descrambled using the second shared key or the derivation key of the second shared key.

[0062] In this embodiment of the application, the responding end can encrypt the sent physical signal using a second shared key or its derived key, thereby improving the security of the underlying physical signal.

[0063] In one possible implementation, the second shared key securely protects the session between the responding end and the broadcasting end by including:

[0064] Using the second shared key or a derived key of the second shared key, perform at least one of the following operations on the data sent from the responding end to the broadcasting end: encryption, integrity protection; or

[0065] Using the second shared key or a derived key of the second shared key, perform at least one of the following operations on the data received by the response end from the broadcast end: decryption and integrity verification.

[0066] In this embodiment, the responding end can encrypt and protect the integrity of the sent data using the second shared key and its derived key, thereby improving the security of upper-layer interactive data and protecting user privacy.

[0067] In one possible implementation, the first information includes at least one of the following:

[0068] Key negotiation algorithm capability, encryption algorithm capability, integrity protection algorithm capability, authentication encryption algorithm capability, key derivation function capability;

[0069] The key negotiation algorithm capability is used to indicate one or more key negotiation algorithms supported by the broadcast end;

[0070] The encryption algorithm capability is used to indicate one or more encryption algorithms supported by the broadcast end;

[0071] The integrity protection algorithm capability is used to indicate one or more integrity protection algorithms supported by the broadcast end;

[0072] The authentication encryption algorithm capability is used to indicate one or more authentication encryption algorithms supported by the broadcast end;

[0073] The key derivation function capability is used to indicate one or more key derivation functions supported by the broadcast end.

[0074] In one possible implementation, the second information includes at least one of the following:

[0075] Key negotiation algorithm indication, encryption algorithm indication, integrity protection algorithm indication, authentication encryption algorithm indication, key derivation function indication;

[0076] The key negotiation algorithm indicator is used to instruct the responding end to select a key negotiation algorithm;

[0077] The encryption algorithm indicator is used to indicate an encryption algorithm selected by the responding end;

[0078] The integrity protection algorithm indicator is used to indicate an integrity protection algorithm selected by the response end;

[0079] The authentication encryption algorithm indicator is used to indicate an authentication encryption algorithm selected by the responding end;

[0080] The key derivation function indicates a key derivation function selected by the responder.

[0081] In this embodiment, the responding end informs the broadcasting end of the security capability information it has selected, so that the first shared key generated by the broadcasting end is the same as the second shared key generated by the responding end, thereby protecting subsequent session communication.

[0082] In one possible implementation, the broadcast frame further includes a first random number.

[0083] The first random number is used to generate the derivation key for the second shared key.

[0084] In one possible implementation, the response frame further includes a second random number.

[0085] The second random number is used to generate the derivation key for the second shared key.

[0086] In this embodiment of the application, the responding end improves the security of the derivation key of the second shared key by using the first random number and the second random number, thereby avoiding replay attacks.

[0087] Thirdly, embodiments of this application provide a communication device, which is a broadcasting end or applied to a broadcasting end, for executing any possible implementation of the first aspect described above.

[0088] Fourthly, embodiments of this application provide a communication device, which is a response end or applied to a response end, for executing any possible implementation of the second aspect described above.

[0089] Fifthly, embodiments of this application provide a chip, the chip including at least one processor and an interface, the at least one processor being used to read and execute instructions stored in a memory, and when the processor executes the instructions, causing the chip to execute any possible implementation of the first to second aspects described above.

[0090] Sixthly, embodiments of this application provide a computer-readable storage medium storing a computer program, which, when executed by a computer, causes the computer to perform any possible implementation of the first to second aspects described above.

[0091] In a seventh aspect, embodiments of this application provide a computer program product, which, when executed, causes the methods shown in any possible implementation of the first to second aspects to be performed. Attached Figure Description

[0092] Figure 1 is a schematic diagram of the communication protocol architecture of a star-flash communication technology;

[0093] Figure 2 is a schematic diagram of a communication architecture provided in an embodiment of this application;

[0094] Figure 3 is a schematic diagram of a connectionless measurement process provided in an embodiment of this application;

[0095] Figure 4 is a flowchart illustrating a security protection method provided in an embodiment of this application;

[0096] Figure 5 is a flowchart illustrating another security protection method provided in an embodiment of this application;

[0097] Figure 6 is a flowchart illustrating the application of a security protection method in the measurement process according to an embodiment of this application;

[0098] Figure 7 is a schematic diagram of the Starlight Broadcast frame structure;

[0099] Figure 8 is a schematic diagram of the extended broadcast frame resource configuration information structure in the Star Flash Broadcast Frame;

[0100] Figure 9 is a flowchart illustrating the application of a security protection method using a StarScan communication system according to an embodiment of this application.

[0101] Figure 10a is a schematic diagram of a type of security capability information given by the Starflash standard;

[0102] Figure 10b is a schematic diagram of a type of security capability information given by the Starflash standard;

[0103] Figure 11 is a flowchart illustrating another security protection method provided in this application for application in the bus access process;

[0104] Figure 12 is a schematic diagram of the structure of a security protection communication device provided in an embodiment of this application;

[0105] Figure 13 is a schematic diagram of another security protection communication device provided in an embodiment of this application;

[0106] Figure 14 is a schematic diagram of a chip structure provided in an embodiment of this application. Detailed Implementation

[0107] To facilitate understanding of the technical solution of this application, the application will be further described below with reference to the accompanying drawings.

[0108] The terms "first" and "second," etc., used in the specification, claims, and drawings of this application are used only to distinguish different objects and not to describe a specific order. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or apparatuses.

[0109] The term "embodiment" as used herein means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.

[0110] In this application, "at least one (item)" refers to one or more, "more than one" refers to two or more, "at least two (items)" refers to two or three or more, and "and / or" is used to describe the relationship between related objects, indicating that there can be three relationships. For example, "A and / or B" can mean: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. "Or" indicates that there can be two relationships, such as only A exists and only B exists; when A and B are not mutually exclusive, it can also mean that there are three relationships, such as only A exists, only B exists, and both A and B exist simultaneously. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items. For example, at least one (item) of a, b, or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c".

[0111] In this application, "instruction" can include direct instruction, indirect instruction, explicit instruction, and implicit instruction. When describing a certain instruction information for the purpose of instructing A, it can be understood that the instruction information carries A, directly instructs A, or indirectly instructs A.

[0112] In this application, the information indicated by the instruction information is called the information to be instructed. In specific implementations, there are many ways to indicate the information to be instructed, such as, but not limited to, directly indicating the information to be instructed, such as the information to be instructed itself or its index. It can also indirectly indicate the information to be instructed by indicating other information, where there is a relationship between the other information and the information to be instructed. It can also indicate only a part of the information to be instructed, while the other parts are known or pre-agreed upon. For example, the instruction of specific information can be achieved by using a pre-agreed (e.g., protocol-defined) arrangement of various pieces of information, thereby reducing instruction overhead to some extent. Furthermore, the information to be instructed can be sent as a whole or divided into multiple sub-information pieces, and the sending period and / or timing of these sub-information pieces can be the same or different.

[0113] In this application, "send" and "receive" indicate the direction of signal transmission. For example, "send information to XX" can be understood as the destination of the information being XX, which can include direct transmission via the air interface or indirect transmission via the air interface from other units or modules. "Receive information from YY" can be understood as the source of the information being YY, which can include direct reception from YY via the air interface or indirect reception from YY via the air interface from other units or modules. "Send" can also be understood as the "output" of a chip interface, and "receive" can also be understood as the "input" of a chip interface. In other words, sending and receiving can occur between devices, such as between network devices and terminal devices, or within a device, such as between components, modules, chips, software modules, or hardware modules within the device via buses, traces, or interfaces.

[0114] 1. The following describes the communication system architecture involved in the embodiments of this application.

[0115] It should be noted that these descriptions are for the purpose of facilitating understanding by those skilled in the art and are not intended to limit the scope of protection claimed in this application.

[0116] Currently, the SparkLink Alliance provides the communication protocol architecture for SparkLink communication technology. This architecture offers access technologies including SparkLink Basic (SLB) access technology and SparkLink Low Energy (SLE) access technology. Figure 1 is a schematic diagram of the communication protocol architecture of the SparkLink communication technology involved in this application embodiment. Referring to Figure 1, the protocol architecture includes a basic application layer, a basic service layer, and a SparkLink access layer (also referred to as the access layer). The basic application layer and the basic service layer can be collectively referred to as the SparkLink upper layer.

[0117] (1) Basic Application Layer

[0118] The basic application layer includes various general frameworks. In order to enable communication between different devices on different platforms, the basic application layer has defined frameworks for various possible and universally applicable application scenarios.

[0119] (2) Basic Service Layer

[0120] The basic service layer comprises the control plane and the data plane. The control plane primarily provides services such as device discovery and management. The data plane includes channel control data, broadcast data, service management data, real-time data, and reliable data, as well as transmission control adaptation protocols, transmission control protocol / internet protocol (TCP / IP), and transparent transmission protocols.

[0121] (3) Starlight Access Layer

[0122] The StarFlash access layer includes an SLB module and an SLE module. The SLB module can also be referred to as the SLB access layer, and the SLE module as the SLE access layer. The SLB module communicates via SLB access technology. SLB access technology has high bandwidth communication capabilities and can support high-bandwidth services such as wireless screen projection and video calls. It offers high data throughput and fast data transmission speeds during communication. However, SLB access technology has relatively high power consumption and a longer access process.

[0123] In SLB access technology, communication equipment includes grant node devices (G-node devices or G nodes) and terminal node devices (T-node devices or T nodes). A G-node represents a node that sends data scheduling information at the access layer, while a T-node represents a node that receives data scheduling information and sends data according to that information. It is also specified that G-node devices can send broadcasts, and T-node devices can scan for information. During the establishment of an SLB connection between G-node devices and T-node devices, T-node devices are allowed to scan for and discover G-node devices and send connection requests to connect to them.

[0124] For example, when a large-screen device (such as a smart TV) is a G-node device and a mobile phone is a T-node device, the large-screen device will automatically broadcast basic SLB connection information after enabling SLB communication. When the mobile phone needs to cast its screen, it starts scanning for surrounding G-node devices, receiving their broadcast SLB connection information, and displaying the device scan results (such as device model and name) based on the SLB connection information. In response to the user selecting a large-screen device from the scan results, the mobile phone sends a connection request to the large-screen device, thereby establishing an SLB connection with the large-screen device.

[0125] The SLE module communicates via SLE access technology. SLE features low-power communication capabilities; when the SLE module is idle (i.e., not connected to other devices), it can broadcast device information and data on three fixed broadcast channels, enabling rapid discovery and connection, thus saving device power. However, SLE access technology supports relatively small bandwidth and has a slower data transmission speed. Therefore, it is typically used for services with low bandwidth requirements, such as audio playback via wireless headphones or mobile phone control of smart home devices.

[0126] It is understood that the communication protocol architecture shown above is only one possible example, and other possible protocol layers may also be included in the communication protocol architecture. This application embodiment does not limit this.

[0127] The following explanations address the relevant terminology involved in StarScan communication technology. Unless otherwise specified, these explanations are provided to support the meaning of the relevant terminology and to facilitate the understanding of the embodiments of this application, and should not be construed as strict limitations on the terminology within the scope of protection claimed in this application.

[0128] 1) Event: The smallest basic process of data transmission. For example, the process of two devices sending and receiving data one after another is an event, or the process of a broadcast device sending data is an event.

[0129] 2) Intra-event interval: In an event, the time difference between the end time of transmission of the first node and the start time of transmission of the subsequent node is defined as the intra-event interval.

[0130] 3) Inter-event interval: The time difference between the end time of the transmission of the preceding event and the start time of the transmission of the following event in two adjacent events within an event group is defined as the inter-event interval.

[0131] 4) Event group: The process of data transmission consisting of multiple events.

[0132] 2. The following describes the network architecture and apparatus involved in the embodiments of this application.

[0133] To facilitate understanding of the communication scheme provided in the embodiments of this application, the network architecture shown in Figure 2 is used as an example to describe in detail the network architecture applicable to the embodiments of this application. As shown in Figure 2, the network architecture may include multiple communication devices (broadcast end and access end). Both the broadcast end and the access end are configured with the above-mentioned StarSpark communication protocol architecture and can communicate with each other using StarSpark communication technology based on the communication protocol architecture.

[0134] The communication devices (such as broadcasting terminals and access terminals) in this application embodiment can be devices from various fields. For example, in the smart home field, there are large-screen devices, artificial intelligence (AI) speakers, high fidelity (HiFi) speakers, temperature sensors, or humidity sensors; or in the smart terminal field, there are mobile phones, tablets, wearable devices, augmented reality (AR) / virtual reality (VR) devices, laptops, ultra-mobile personal computers (UMPCs), netbooks, or personal digital assistants (PDAs); or in the smart manufacturing field, there are robotic arms, cameras, joysticks, monitors, logistics vehicles, or smart shelves; or in the smart car field, there are in-vehicle devices or other devices. This application embodiment does not limit the specific type of communication device.

[0135] For example, the broadcast end is a G-node device or a T-node device, and the access end is a G-node device or a T-node device. In one possible implementation, the role of the communication device can be determined based on its input and output conditions, including whether the communication device supports inputting information via a mouse, keyboard, or screen, and whether it supports outputting information via a screen or speaker. For example, for devices such as mobile phones and tablets that facilitate user input, their role is typically a T-node, and they default to acting as a T-node device during SLB connection. Conversely, for devices such as large-screen devices and smart speakers that are not convenient for user input, their role is typically a G-node, and they default to acting as a G-node device during SLB connection.

[0136] It is understood that the communication method provided in this application embodiment is applicable to communication between G node devices and T node devices, and can also be applied to communication between G node devices, or between T node devices, or between G node devices, without any specific limitation.

[0137] The network architecture and business scenarios described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.

[0138] Although the embodiments of this application are primarily illustrated using the deployment of a Starlight communication network, particularly an SLB communication network, those skilled in the art will readily understand that the various aspects involved in the embodiments of this application can be extended to other networks employing various standards or protocols, such as high-performance radio local area networks (HIPERLANs), wireless wide area networks (WWANs), wireless personal area networks (WPANs), or other networks now known or developed in the future. Therefore, regardless of the coverage area and wireless access protocol used, the various aspects provided in the embodiments of this application can be applied to any suitable wireless network.

[0139] The technical solutions of this application embodiment can also be applied to various communication systems or networks, such as: WLAN communication systems, Wireless Fidelity (Wi-Fi) systems, Long Term Evolution (LTE) systems, LTE Frequency Division Duplex (FDD) systems, LTE Time Division Duplex (TDD) systems, Universal Mobile Telecommunication System (UMTS) systems, Worldwide Interoperability for Microwave Access (WiMAX) communication systems, 5th Generation (5G) systems or New Radio (NR) systems, Future Communications systems, Internet of Things (IoT) networks or Vehicle-to-Everything (V2X) networks, Bluetooth systems, etc. The communication systems applicable to this application described above are merely illustrative examples; the application is not limited to these examples. These examples are uniformly described here and will not be repeated below.

[0140] This application supports IEEE protocols, such as IEEE 802.11be / Wi-Fi 7 / EHT, IEEE 802.11bn / UHR / Wi-Fi 8, IEEE Integrated mmWave / IMMW, IEEE 802.15 / UWB, or IEEE 802.11bf / sensing; this application may also support Spark Link / NearLink / Bluetooth standard protocols.

[0141] 3. The following describes the process involved in the embodiments of this application.

[0142] Connectionless communication is a data exchange process between two unfamiliar devices in a connectionless environment. For example, when two unfamiliar devices approach each other, they need to measure and obtain one or more physical quantities such as distance, Channel State Information (CSI), Received Signal Strength Indicator (RSSI), and Angle of Arrival (AOA) to determine whether to initiate a pre-connection. Pre-connection refers to the partial steps of establishing a connection between two or more devices. For instance, a device might receive broadcast information to obtain information about the other device, such as the communication domain name, and present this information to the user through an interface or application. After obtaining user authorization, the device can quickly establish a connection with the other device and begin subsequent communication.

[0143] The following section will introduce the specific process of connectionless communication, namely connectionless measurement, as shown in Figure 3.

[0144] 1) The access end or response end scans and receives broadcast information sent by the broadcast end, and obtains one or more types of information such as the broadcast end's measurement capabilities and equipment information;

[0145] 2) The responding end sends one or more types of information, such as its measurement capabilities and equipment information, to the broadcasting end via response frames;

[0146] 3) The broadcast and / or response terminals configure measurement parameters based on one or more types of information, such as measurement capabilities and equipment information;

[0147] 4) The broadcast end and / or the response end perform the measurement, and the measurement results may include one or more of the following: channel state information (CSI), measurement frame arrival time, measurement frame departure time, and received signal strength indication (RSSI).

[0148] 5) The broadcast or response end sends some intermediate measurement results, such as Channel State Information (CSI), measurement frame arrival time, measurement frame departure time, and Received Signal Strength (RSSI), to the peer end so that the peer end can calculate the final measurement result, such as ranging or angle measurement.

[0149] In the aforementioned connectionless communication, the measurement process is not protected by security, and the measurement results are sent in plaintext. This means that when faced with an attacker, there are no security measures available to protect user privacy, thus creating a security risk.

[0150] To address this, this application provides a security protection method that broadcasts security capability information to the responding end, enabling the broadcasting end to quickly establish a security mechanism with the responding end. This solves the security problem in connectionless scenarios, provides security protection for subsequent sessions, and safeguards user privacy.

[0151] Figure 4 is a flowchart illustrating a security protection method provided in an embodiment of this application. It consists of five steps: the broadcast end broadcasts security capability information, the responding end selects a secure cryptographic algorithm, the broadcast end generates a shared key, the responding end generates the shared key, and the session is secured. These will be described in detail below.

[0152] 1) Broadcast security capability information

[0153] The broadcasting end sends a broadcast frame, which includes first information. The first information is used to indicate the security capabilities supported by the broadcasting end, so that the responding end can know the security capabilities supported by the broadcasting end, thereby establishing a secure communication mechanism to protect subsequent sessions.

[0154] For example, the broadcast frame may adopt the broadcast frame format in the Starlight standard, as detailed in the following embodiments.

[0155] For example, the first information may include at least one of the following: key negotiation algorithm capability, encryption algorithm capability, integrity protection algorithm capability, authentication encryption algorithm capability, and key derivation function capability.

[0156] The key negotiation algorithm capability indicates the one or more key negotiation algorithms supported by the broadcaster. A key negotiation algorithm, also known as a key exchange algorithm, defines how, in insecure communication, the two communicating parties (such as the broadcaster and the responder) negotiate a shared key through information exchange for security protection of subsequent sessions. For example, the DH (Diffie-Hellman) algorithm is a key negotiation algorithm that allows the two communicating parties to exchange keys without directly transmitting them. Simply put, the DH algorithm essentially involves both parties generating their own private and public keys. The private key is only visible to themselves, and by exchanging public keys, both parties can generate a shared key based on their own private key and the other party's public key. The DH algorithm mathematically ensures that the shared key calculated by both parties is identical, thus achieving security protection for subsequent sessions. In addition, there are other key negotiation algorithms, such as the ECDH (Elliptic Curve Diffie-Hellman) algorithm, a variant of the DH algorithm that uses elliptic curve cryptography to enhance security. The broadcaster can support one or more different key negotiation algorithms, allowing the responder to flexibly choose according to its own security capabilities or actual needs, resulting in good scalability.

[0157] Key negotiation algorithm capabilities can be represented in different forms. For example, key negotiation algorithm capabilities can be represented using 2 bits, where a value of 1 indicates support for the DH algorithm, a value of 2 indicates support for the ECDH algorithm, a value of 3 indicates support for both the DH and ECDH algorithms, and a value of 0 is a reserved value or indicates no support for key negotiation algorithms. As another example, key negotiation algorithm capabilities can also be represented using a 4-bit bitmap, where "0001" indicates support for the DH algorithm, "0010" indicates support for the ECDH algorithm, "0011" indicates support for both the DH and ECDH algorithms, and the remaining values ​​are reserved. These are merely examples, and the embodiments of this application do not limit the types, number, or specific representations of algorithms indicated by key negotiation algorithm capabilities.

[0158] Encryption algorithm capability indicates the one or more encryption algorithms supported by the broadcaster. An encryption algorithm processes plaintext data into ciphertext, protecting data security and preventing unauthorized reading or modification. Encryption algorithms can include various algorithms, such as DES (Data Encryption Standard), AES (Advanced Encryption Standard), and RSA (Rivest–Shamir–Adleman algorithm).

[0159] Encryption algorithm capabilities can also be represented in different forms. For example, encryption algorithm capabilities can be represented using 4 bits, where a value of 1 indicates support for the DES algorithm, a value of 2 indicates support for the AES algorithm, a value of 3 indicates support for the RSA algorithm, a value of 4 indicates support for both DES and AES algorithms, ..., a value of 8 indicates support for DES, AES, and RSA algorithms, with the remaining values ​​reserved. Alternatively, encryption algorithm capabilities can also be represented using a bitmap, such as using 4 bits where "0001" represents the DES algorithm, "0010" represents the AES algorithm, "0100" represents the RSA algorithm, "0011" indicates support for both DES and AES algorithms, ..., "0111" indicates support for DES, AES, and RSA algorithms, with the remaining values ​​reserved. These are merely examples; the embodiments of this application do not limit the types, number, or specific representations of encryption algorithm capabilities indicated.

[0160] Integrity protection algorithm capability indicates the one or more integrity protection algorithms supported by the broadcaster. An integrity protection algorithm is an algorithm that ensures data integrity by preventing unauthorized modification, deletion, or damage during transmission, storage, and processing. Integrity protection algorithms can include various algorithms, such as one-way hash functions, message authentication codes, and digital signatures. Integrity protection algorithm capability can also be represented in different forms, as detailed in the descriptions of key negotiation algorithm capability or cryptographic capability above.

[0161] The authentication encryption algorithm capability indicates the one or more authentication encryption algorithms supported by the broadcaster. An authentication encryption algorithm is an algorithm that can simultaneously protect data confidentiality and integrity, such as EtM (Encrypt-then-MAC), E&M (Encrypt-and-MAC), and MtE (MAC-then-Encrypt(MtE)). Authentication encryption algorithm capabilities can also be represented in different forms; please refer to the relevant descriptions of key negotiation algorithm capabilities or encryption capabilities mentioned above for details.

[0162] Key derivation function capability indicates the number of key derivation functions supported by the broadcaster. A key derivation function is an algorithm that uses a pseudo-random function to derive one or more keys from a master key or shared key, such as SHA-1, SHA-256, or SHA-512. Key derivation function capability can also be represented in different forms, as detailed in the descriptions of key negotiation algorithm capabilities or cryptographic capabilities mentioned above.

[0163] It is worth noting that the various algorithms given in the above embodiments are merely examples and should not be construed as limiting the embodiments of this application. Similarly, the names of the various pieces of information given in the embodiments of this application are merely examples and should not be construed as limiting the embodiments of this application. Likewise, the number of bits used for each piece of information and the meaning of different values ​​are also merely examples and may increase or decrease with actual applications; the embodiments of this application do not limit this.

[0164] For example, the broadcast frame may also include a first random number, which is generated by the broadcasting end itself. For instance, the broadcasting end randomly generates a 128-bit sequence as the first random number. The first random number can be used to generate a derivation key for a first shared key, or it can be used to generate a derivation key for a second shared key. This application does not limit the specific generation method or length of the first random number in its embodiments.

[0165] 2) The response end selects a cryptographic algorithm.

[0166] When the responding end receives the broadcast frame sent by the broadcast frame, it can select a cryptographic algorithm based on the first information in the broadcast frame, and use the selected cryptographic algorithm as the second information to feed back to the broadcasting end through the response frame.

[0167] Specifically, the broadcasting end can extract the first information from the broadcast frame to determine the security capabilities it supports. The responding end then selects a matching cryptographic algorithm based on its own security capabilities or actual application requirements. For example, the first information carried in the broadcast frame includes key negotiation algorithm capabilities, represented by a 4-bit bitmap with a value of "0011," indicating that the broadcasting end supports both the DH and ECDH algorithms. If the responding end only supports the DH algorithm, it can choose DH as the key negotiation algorithm for both parties. If the responding end supports both DH and ECDH, it can choose one of them, such as DH or ECDH. If the responding end supports both DH and ECDH, it can choose the algorithm with higher priority. Assuming ECDH takes precedence over DH, the responding end can choose ECDH as the key negotiation algorithm for both parties. If the responding end does not support the key negotiation algorithms supported by the broadcasting end, it has no selectable key negotiation algorithm.

[0168] Similarly, the responding end can select other cryptographic algorithms in a similar way, such as encryption algorithms, integrity protection algorithms, authentication encryption, or key derivation functions, so that the responding end can flexibly choose according to actual needs and has good scalability.

[0169] It is worth noting that the authentication encryption algorithm can achieve both encryption and integrity protection functions. Therefore, if the responding end selects an encryption algorithm and / or an integrity protection algorithm, it does not need to select an authentication encryption algorithm. Similarly, if the responding end selects an authentication encryption algorithm, it does not need to select an encryption algorithm and an integrity protection algorithm.

[0170] Once the responding end selects a cryptographic algorithm, it can send a response frame to the broadcasting end. The response frame can carry a second piece of information to indicate the cryptographic algorithm selected by the responding end.

[0171] For example, the second information may include at least one of the following: key negotiation algorithm indication, encryption algorithm indication, integrity protection algorithm indication, authentication encryption algorithm indication, and key derivation function indication.

[0172] The key negotiation algorithm indicator is used to indicate the key negotiation algorithm selected by the responding end. This key negotiation algorithm is one supported by both the broadcasting and responding ends. The key negotiation algorithm indicator can be represented in different forms; for example, it can be represented using a 4-bit bitmap, where a value of "0001" indicates that the responding end selects the DH algorithm as the key negotiation algorithm for both parties, or a value of "0010" indicates that the responding end selects the ECDH algorithm as the key negotiation algorithm for both parties. The above are merely examples, and the specific representation of the key negotiation algorithm indicator is not limited in this application.

[0173] Similarly, the encryption algorithm indicator is used to indicate the encryption algorithm selected by the responding end. This encryption algorithm is supported by both the broadcasting and responding ends. The integrity protection algorithm indicator is used to indicate the integrity protection algorithm selected by the responding end. This integrity protection algorithm is supported by both the broadcasting and responding ends. The authentication encryption algorithm indicator is used to indicate the authentication encryption algorithm selected by the responding end. This authentication encryption algorithm is supported by both the broadcasting and responding ends. The key derivation function indicator is used to indicate the key derivation function selected by the responding end. This key derivation function is supported by both the broadcasting and responding ends. The specific representation of the above indication information can be found in the relevant description of the key negotiation algorithm indication above.

[0174] Once the responding end selects a cryptographic algorithm, it can generate a second public key based on the selected cryptographic algorithm and the second private key; the second private key is the private key generated by the responding end itself, and the second public key is the public key of the responding end.

[0175] For example, the second private key may be randomly generated by the responding end, or generated by processing a user-specified string. This application does not limit the method of generating the second private key or its length.

[0176] For example, the responding end can generate a second public key based on the key negotiation algorithm and the second private key selected in the cryptographic algorithm. For instance, if the responding end selects the DH algorithm as the key negotiation algorithm and the second private key is denoted as P2, then the responding end uses the second private key P2 as a parameter to generate a second public key Q2 using the DH algorithm. The specific generation process can be found in publicly available DH algorithms.

[0177] After the responding end selects a cryptographic algorithm and generates a second public key, it can send a response frame to the broadcasting end. The response frame includes the second information and the second public key, so that the broadcasting end knows the cryptographic algorithm selected by the responding end and the public key of the responding end. Based on the selected cryptographic algorithm and the public key of the responding end, the broadcasting end can generate the same shared key to protect the security of subsequent sessions.

[0178] For example, the response frame may adopt the response frame format in the Starflash standard, and a detailed description can be found in the following embodiments.

[0179] For example, the response frame may also include a second random number, which is generated by the responding end itself. Specifically, the responding end may randomly generate a 128-bit sequence as the second random number, and the specific generation method and length are not limited in this application. The second random number can be used to generate the derivation key of the second shared key of the responding end, or it can be used to generate the derivation key of the first shared key of the broadcasting end. For details, please refer to the following description related to shared key generation.

[0180] 3) The broadcast end generates a shared key.

[0181] The broadcast end receives a response frame from the responding end and can obtain the second information and the second public key from it.

[0182] The broadcaster can generate a first shared key based on the first private key, the second information in the response frame, and the second public key.

[0183] For example, the broadcaster can generate a first shared key based on the key negotiation algorithm selected in the second information, the first private key, and the second public key. For instance, if the key negotiation algorithm indicated in the second information is the DH algorithm, the first private key is P1, and the second public key is Q2, then the broadcaster can use the first private key P1 and the second public key Q2 as parameters to generate a first shared key K1 using the DH algorithm. The specific generation process can be found in publicly available DH algorithms. The first shared key generated by the broadcaster can be used for the generation of subsequent derivation keys and for the protection of subsequent sessions.

[0184] The broadcaster can generate a first public key, i.e. the broadcaster's public key, based on the first private key and the second information in the response frame, where the first private key is the private key generated by the broadcaster itself.

[0185] For example, the broadcaster can generate a first public key based on the key negotiation algorithm selected in the second information and the first private key. For instance, if the selected key negotiation algorithm is the DH algorithm and the first private key is denoted as P1, the broadcaster can use the first private key denoted as P1 as a parameter to generate a first public key Q1 using the DH algorithm. The specific generation process can be found in publicly available DH algorithms.

[0186] After generating the first public key, the broadcaster can send the first public key to the responder so that the responder can obtain the first public key, generate the same shared key, and achieve security protection for subsequent sessions.

[0187] 4) The responding end generates a shared key.

[0188] The responding end receives the first public key from the broadcasting end, and then generates a second shared key based on the second information and the second private key.

[0189] For example, the responding end can generate a second shared key based on the key negotiation algorithm selected in the second information, the second private key, and the first public key. For instance, if the selected key negotiation algorithm is the DH algorithm, the second private key is P2, and the first public key is Q1, then the responding end can use the second private key P2 and the first public key as parameters to generate a second shared key K2 using the DH algorithm. The specific generation process can be found in publicly available DH algorithms. The second shared key generated by the responding end can be used for the generation of subsequent derivation keys and for the protection of subsequent sessions.

[0190] It is worth noting that the first shared key generated by the broadcaster and the second shared key generated by the responder are the same shared key, thus ensuring that the broadcaster and responder can conduct normal and secure communication. Specifically, the broadcaster can use the first shared key to encrypt the transmitted signal or data, and the responder can use the second shared key to decrypt it, obtaining the correct and complete signal or data. Similarly, the responder can use the second shared key to encrypt the transmitted signal or data, and the broadcaster can use the first shared key to decrypt it, obtaining the correct and complete signal or data.

[0191] 5) Session security protection

[0192] The broadcaster can use the first shared key or a derived key of the first shared key to secure subsequent sessions.

[0193] For example, the broadcaster can use the key derivation function selected in the second information to derive other keys, such as session keys, encryption keys, and integrity protection keys, based on the first shared key. For instance, when the broadcaster determines to use the authentication encryption algorithm selected in the second information to securely protect the transmitted signal or data, the broadcaster can derive a session key based on the first shared key, the first random number, and the second random number. The broadcaster then uses this session key to encrypt and protect the transmitted signal or data. Specifically, the first shared key can be represented as K1, the first random number as R1, and the second random number as R2. Then, the session key SK derived from the first shared key is SK = KDF(K1, R1||R2, len), where KDF is the selected key derivation function, len is the length of the session key, and "||" indicates a concatenation operation. For the specific generation process, refer to the publicly available key derivation functions.

[0194] When the broadcaster determines to use the encryption algorithm selected in the second information, it can derive an encryption key based on the first shared key, the first random number, and the second random number. The broadcaster then uses this encryption key to encrypt and protect the transmitted signal or data. Specifically, the first shared key can be represented as K1, the first random number as R1, and the second random number as R2. The encryption key EnK derived from the first shared key is then Enk = KDF(K1, keyID1||R1||R2, len), where KDF is the selected key derivation function, keyID1 is the ASCII value of the string "enk", len is the length of the encryption key, and "||" indicates a concatenation operation. For the specific generation process, please refer to the publicly available key derivation functions.

[0195] When the broadcaster determines to use the integrity protection algorithm selected in the second information, it can derive an integrity protection key based on the first shared key, the first random number, and the second random number. The broadcaster then uses this integrity protection key to protect the integrity of the transmitted signal or data. Specifically, the first shared key can be represented as K1, the first random number as R1, and the second random number as R2. The integrity protection key InK derived from the first shared key is then InK = KDF(K1, keyID2||R1||R2, len), where KDF is the selected key derivation function, keyID2 is the ASCII value of the string "ink", len is the length of the integrity protection key, and "||" indicates a concatenation operation. For the specific generation process, please refer to the previously disclosed key derivation function.

[0196] For example, after the broadcaster derives the session key SK from the first shared key, it can encrypt and protect the transmitted data using the authentication encryption algorithm selected in the second information, such as the AES-CMAC algorithm, as shown in the formula C = AES-CMAC(SK, M, len), where SK is the session key, M is the transmitted data, len is the length of the transmitted data, and C is the output ciphertext. The above is merely an example; the broadcaster can also use other encryption algorithms or integrity protection algorithms to protect the transmitted signals or data.

[0197] For example, the broadcasting end can use the first shared key or a derived key of the first shared key, such as the session key or encryption key mentioned above, to scramble the signal sent to the responding end in order to protect the signal sent by the broadcasting end. For instance, the broadcasting end can use the derived session key to perform an XOR operation on the sent signal to achieve scrambling and provide high signal security. This application embodiment does not limit the specific process of using the first shared key or a derived key of the first shared key to protect the signal.

[0198] Accordingly, the broadcasting end can use the first shared key or a derived key of the first shared key to descramble the signal received from the responding end in order to securely and accurately obtain the signal from the responding end.

[0199] For example, the broadcaster can use a derived key from the first shared key, such as a session key, encryption key, or integrity protection key, to encrypt and / or protect the integrity of the data sent to the responder, ensuring the security and integrity of the data sent by the broadcaster. For instance, the broadcaster can use the derived encryption key and a selected encryption algorithm to encrypt the sent data, outputting ciphertext to achieve data security protection.

[0200] Accordingly, the broadcaster can use the derivation key of the first shared key to decrypt and / or verify the integrity of the data received from the responder, so as to securely and accurately obtain the data from the responder.

[0201] The responding end can use the second shared key or a derived key of the second shared key to protect subsequent sessions.

[0202] For example, the responding end can use a selected key derivation function to deduce other keys, such as session keys, encryption keys, and integrity protection keys, based on the second shared key. The specific generation process can be referenced from the key generation process described above for the first shared key.

[0203] For example, the responding end may use a second shared key or a derived key of the second shared key, such as a session key or an encryption key, to scramble the signal sent to the broadcasting end in order to protect the signal sent by the responding end and improve security.

[0204] Accordingly, the responding end can use the second shared key or a derived key of the second shared key to descramble the signal received from the broadcasting end in order to securely and accurately obtain the signal from the broadcasting end.

[0205] For example, the responding end may use a derived key of the second shared key, such as a session key, an encryption key, an integrity protection key, etc., to perform at least one of the following operations on the data sent to the broadcasting end: encryption, integrity protection, to ensure the security and integrity of the data sent by the responding end.

[0206] Accordingly, the responding end can use the derivation key of the second shared key to perform at least one of the following operations on the data received from the broadcasting end: decryption, integrity verification, so as to securely and accurately obtain the data from the broadcasting end.

[0207] It is worth noting that the first shared key generated by the broadcaster and the second shared key generated by the responder are the same shared key, and the derived key of the first shared key is also the same as the derived key of the second shared key, thus ensuring that the broadcaster and responder can conduct normal and secure communication. Specifically, the broadcaster can use the derived key of the first shared key to encrypt the transmitted signal or data, and the responder can use the derived key of the second shared key to decrypt it, obtaining the correct and complete signal or data. Similarly, the responder can use the derived key of the second shared key to encrypt the transmitted signal or data, and the broadcaster can use the derived key of the first shared key to decrypt it, obtaining the correct and complete signal or data.

[0208] The above describes the specific process of establishing secure communication between the broadcast end and the response end. If the broadcast end and the response end have already established a security context, that is, if the broadcast end and the response end have been paired before, the broadcast end and the response end can use the existing security context to conduct secure communication.

[0209] As shown in Figure 5, this application embodiment provides a flowchart of another security protection method. The broadcast frame sent by the broadcasting end further includes a first identifier, which is used to identify the broadcasting end.

[0210] For example, the first identifier can uniquely identify the broadcasting end, and can be the media access layer identifier of the broadcasting end, or the device identifier, or the MAC address. This application does not limit this.

[0211] The responding end receives a broadcast frame and can determine whether it has been paired with the broadcasting end based on the first identifier in the broadcast frame. If paired, the responding end can protect subsequent sessions based on the paired security context, namely the second shared key and the selected cryptographic algorithm, avoiding the need to re-establish the secure communication process and reducing communication overhead and latency; if not paired, the responding end can establish secure communication according to the above embodiment.

[0212] The response frame sent by the responding end may also include second identification information, which is used to identify the responding end.

[0213] For example, the second identifier can uniquely identify the responding end, and can be the media access layer identifier, device identifier, or MAC address of the responding end. This application does not limit this.

[0214] The broadcast end receives a response frame and can determine whether it has been paired with the response frame based on the second identifier in the response frame. If paired, the broadcast end can protect subsequent sessions based on the paired security context, namely the first shared key and the selected cryptographic algorithm, avoiding the need to re-establish the secure communication process and reducing communication overhead and latency; if not paired, the broadcast end can establish secure communication according to the above embodiment.

[0215] 4. The following will describe the application of the embodiments of this application to the star flash system.

[0216] Figure 6 is a flowchart illustrating the application of a security protection method in a measurement process according to an embodiment of this application. It includes a G node and a T node, where the G node is the broadcast end and the T node is the response end. The specific process is as follows:

[0217] 1) G node sends broadcast frames

[0218] As a broadcaster, the G node can send multiple broadcast frames, each carrying the G node's measurement capability information and security capability information.

[0219] For example, as shown in Figure 7, the broadcast frame can be a Starlight broadcast frame, which includes a broadcast frame structure indication field, a local media access layer identifier type field, a peer media access layer identifier type field, a local media access layer identifier field, an identity resolving key (IRK) ID field, a peer media access layer identifier field, an extended broadcast frame resource configuration information field, a data type field, a data length field, and a data content field. Specific descriptions of each field are shown in Table 1. This embodiment reuses Starlight broadcast frames, reducing the overhead and latency of secure communication.

[0220] Table 1. Description of Starlight Broadcast Frame Fields

[0221] The specific descriptions of the data type fields are shown in Table 2.

[0222] Table 2 Data Type Field Descriptions

[0223] The extended broadcast frame resource configuration information includes fields as shown in Figure 8, and the descriptions of each field are shown in Table 3.

[0224] Table 3 Explanation of Extended Broadcast Frame Resource Configuration Information Fields

[0225] For example, a broadcast frame can select a value from 0x08 to 0xFE reserved in the data type field, such as 0x08, to indicate measurement capability information and security capability information, as shown in Table 4.

[0226] Table 4. Example of data type fields for measurement capability information and safety capability information.

[0227] For example, the broadcast frame can also select two values ​​from the reserved data type field (0x08 to 0xFE) to indicate measurement capability information and security capability information, respectively. For instance, the broadcast frame can select 0x08 to indicate measurement capability information and 0x09 to indicate security capability information, as shown in Table 5. This embodiment uses a reserved value specifically to indicate security capability information, making it applicable not only to the measurement process but also to other processes, thus improving the flexibility of practical applications. This application does not limit how the broadcast frame indicates measurement capability information and security capability information.

[0228] Table 5. Another example of data type fields for measurement capability information and safety capability information.

[0229] For example, as shown in Figure 9, the G node can send basic broadcast frames on three different broadcast channels: basic broadcast frame 1 on broadcast channel A, basic broadcast frame 2 on broadcast channel B, and basic broadcast frame 3 on broadcast channel C. Each basic broadcast frame carries the G node's measurement capability information and security capability information. In addition, the G node can also send extended broadcast frames on the data channel, which also carry measurement capability information and security capability information. The basic broadcast frames and extended broadcast frames are star-flash broadcast frames. The G node broadcasts security capability information on different channels, improving the efficiency of establishing secure communication between the responding end and the broadcasting end.

[0230] For example, taking the bidirectional measurement process in the connectionless state of Star Flash SLE as an example, the measurement capability information carried by the broadcast frame may include at least one of the following: measurement mode, SLE measurement bandwidth, measurement frame type, and SLP capability information.

[0231] The measurement mode indicates the supported measurement modes and may include at least one of the following: SLE measurement sub-mode, SLP measurement sub-mode, and SLE&SLP measurement sub-mode. The SLE measurement sub-mode supports bidirectional SLE measurement (SLEM, or DDR, dual direction ranging); the SLP measurement sub-mode supports SLP measurement; and the SLE&SLP measurement sub-mode supports both SLEM and SLP measurement simultaneously. The SLE measurement sub-mode can be further divided into phase-based modes and time-of-flight (TOF) based modes; the SLP measurement sub-mode can be further divided into single-channel measurement modes and multi-channel splicing (frequency hopping) modes.

[0232] SLE measurement bandwidth is used to indicate the supported measurement bandwidth, such as 1MHz, 2MHz, 4MHz, etc.

[0233] The measurement frame type is used to indicate the supported measurement frame types. For example, there are two types of measurement frame types: measurement frame type 1 is used to indicate the length of the measurement signal and the interval between events, and measurement frame type 2 is used for initialization time or measurement event group.

[0234] SLP capability information is used to indicate supported SLP capabilities, such as bandwidth (500MHz, 1.3GHz), synchronization length, number of fragments, fragment length, etc.

[0235] The measurement capability information included in the above broadcast frames is only an example. In actual applications, it may include some or all of the above information, or other information not described. This application embodiment does not limit this.

[0236] For example, security capability information, i.e., the first information, is used to indicate the security capabilities supported by the G node, which may include at least one of the following: key negotiation algorithm capability, encryption algorithm capability, integrity protection algorithm capability, authentication encryption algorithm capability, and key derivation function capability. Its specific representation can be referred to the above embodiments. The specific form of security capability information in StarScan will be given below.

[0237] For example, security capability information may include four cryptographic algorithm capabilities: encryption algorithm capability, integrity protection algorithm capability, key derivation function capability, and key negotiation algorithm capability. Each cryptographic algorithm capability can be represented by 1 byte, as shown in Figure 10a. Among them, the encryption algorithms defined by the StarSpark standard are shown in Table 6, the integrity protection algorithms are shown in Table 7, the key derivation functions are shown in Table 8, and the key negotiation algorithms are shown in Table 9.

[0238] Encryption algorithms defined in Table 6

[0239] Table 7 defines the integrity protection algorithms.

[0240] Table 8 defines the key derivation functions.

[0241] Key negotiation algorithms defined in Table 9

[0242] The four algorithm capabilities mentioned above can be represented using a bitmap. For example, 1 byte corresponds to 8 bits, and each bit corresponds to one algorithm, resulting in 8 possible algorithms. A bit value of 0 indicates that the algorithm is not supported, while a value of 1 indicates that the algorithm is supported. As shown in Figure 10b, encryption algorithm capabilities can be represented using 8 bits. Bit 0 indicates whether the AC1 algorithm is supported, with a value of 0 indicating that the AC1 algorithm is not supported and a value of 1 indicating that the AC1 algorithm is supported. Similarly, bit 1 indicates whether the AC2 algorithm is supported, bit 2 indicates whether the EA1 algorithm is supported, and bit 3 indicates whether the EA2 algorithm is supported. The remaining bits, i.e., bits 4 to 7, are reserved bits. For example, an encryption algorithm capability value of "00000101" indicates that the G node supports the AC1 and EA1 encryption algorithms.

[0243] Similarly, the integrity protection algorithm capability, key derivation function capability, and key negotiation algorithm capability can also be represented in a similar way.

[0244] For example, Table 10 provides another representation of security capability information, where key negotiation algorithm capabilities can be represented using a 4-bit bitmap. Each bit corresponds to a key negotiation algorithm, with "0" indicating that the algorithm is not supported and "1" indicating that the algorithm is supported. If a G node supports multiple key negotiation algorithms, the corresponding bit in the bitmap can be set to "1" and the remaining bits can be set to "0". For example, if a G node supports the DH algorithm and the ECDH algorithm, the corresponding 4th and 3rd bits can be set to "1", meaning the key negotiation algorithm capability can be represented as "0011". Similarly, encryption algorithm capabilities, integrity protection algorithm capabilities, authentication encryption algorithm capabilities, and key derivation function capabilities can all be represented using a 4-bit bitmap. For details, please refer to the description of key negotiation algorithm capabilities above.

[0245] Table 10 Another form of representing security capability information

[0246] For example, the broadcast frame sent by node G may also include a random number generated by node G, i.e., a first random number, which can be used to generate the derivation key for the shared key between node G and node T. Specifically, node G may randomly generate a 128-bit sequence as the first random number, denoted as R1.

[0247] 2) Node T sends a response frame

[0248] After receiving the broadcast frame, node T obtains measurement capability information and security capability information from it. Based on the measurement capability and security capability supported by node G, node T sends back a response frame.

[0249] For example, node T can feed back its measurement capability information to node G via a response frame, allowing node G to know the measurement capabilities supported by node T. The measurement capability information carried in the response frame may include at least one of the following: measurement mode, SLE measurement bandwidth, measurement frame type, and SLP capability information. Specific measurement capability information can be found in the measurement capability information carried in the broadcast frame described above.

[0250] For example, node T selects a matching cryptographic algorithm based on its own security capabilities, which can be represented by the second information. The cryptographic algorithm may include at least one of the following: key negotiation algorithm, encryption algorithm, integrity protection algorithm, authentication encryption algorithm, and key derivation function.

[0251] For example, the cryptographic algorithm selected by node T can be represented in the forms shown in Tables 6 to 9. For instance, if node G supports the AC1 and EA1 encryption algorithms, and node T itself supports the AC1 encryption algorithm, then node T selects AC1 as its encryption algorithm, which can be represented using the value "0x01" shown in Table 6. Similarly, the key negotiation algorithm, integrity protection algorithm, authentication encryption algorithm, and key derivation function selected by node T are also represented in a similar form.

[0252] For example, Table 11 gives another representation of the cryptographic algorithm selected by node T, where the key negotiation algorithm indicator can be represented using 4 bits, with each bit corresponding to a key negotiation algorithm. When node T selects a key negotiation algorithm, the corresponding bit is set to "1". Specifically, assuming node G supports both DH and ECDH algorithms, the key negotiation algorithm capability is represented as "0011"; if node T only supports the DH algorithm, then the key negotiation algorithm indicator can be represented as "0001", meaning node T selects the DH algorithm; if node T also supports both DH and ECDH algorithms, then node T can select the higher-priority ECDH algorithm, and the key negotiation algorithm indicator can be represented as "0010"; if node T does not support either DH or ECDH algorithms, then the key negotiation algorithm indicator can be represented as "0000", indicating that no key negotiation algorithm is supported. Similarly, the encryption algorithm indicator, integrity protection indicator, authentication encryption algorithm indicator, and key derivation function indicator can all be represented using a 4-bit bitmap, as detailed in the description of the key negotiation algorithm indicator above.

[0253] Table 11 Representations of Selected Cryptographic Algorithms

[0254] After node T determines the cryptographic algorithm, the response frame sent to node G may also include information indicating the selected cryptographic algorithm, which is used to inform the broadcasting node T of the selected cryptographic algorithm.

[0255] When node T selects a key negotiation algorithm, such as the DH algorithm, it can generate a public key based on its own private key. The private key of node T itself is the second private key, and the generated public key is the second public key. For a specific generation method, please refer to the above embodiment.

[0256] After node T generates its public key, the response frame sent to node G may also include node T's public key so that node G can generate a shared key.

[0257] For example, the response frame may also include a random number generated by the T node, i.e., a second random number, which can be used to generate a derivation key for the shared key between the G node and the T node.

[0258] 3) G node generates shared key

[0259] Node G receives a response frame from Node T, from which it obtains the selected measurement parameters, the selected cryptographic algorithm, and Node T's public key.

[0260] The G node can configure the selected measurement parameters and send the configuration to the T node. For example, configuring SLEM measurement link parameters may include logical link identifier (LLID), synchronization signal field, measurement frame type, measurement signal length, measurement signal interval, measurement signal period, etc. This application embodiment does not limit how to configure the measurement parameters or the specific measurement parameters.

[0261] Node G can generate its own shared key, i.e., the first shared key, based on the selected cryptographic algorithm, Node T's public key, and its own private key. The specific generation method can be found in the above embodiment.

[0262] In addition, the G node can generate its own public key, i.e., the first public key, based on its private key and the selected key negotiation algorithm. The specific generation method can be found in the above embodiment.

[0263] While sending measurement parameter configurations, node G can also send the generated public key to node T. Node T can generate a shared key based on node G's public key for the protection of subsequent sessions, reducing communication overhead and latency.

[0264] 4) Node T generates a shared key

[0265] When node T receives the measurement parameter configuration, it executes the measurement process.

[0266] After receiving the public key from node G, node T can generate a second shared key based on the selected cryptographic algorithm and its own private key. The specific generation method can be found in the above embodiment.

[0267] 5) Protect the measurement process and results

[0268] Nodes G and T can use their respective shared keys and derived keys to protect the measurement process and results. The derived keys of the shared keys may include session keys, encryption keys, and integrity protection keys; their specific generation process can be found in the embodiments described above.

[0269] For example, during the measurement process, node G can send a measurement signal to node T. Node G can scramble the sent measurement signal using a shared key. Specifically, node G XORs the measurement signal with the shared key before sending it to node T. Upon receiving the scrambled measurement signal, node T uses the same shared key to descramble it, thereby obtaining the correct measurement signal.

[0270] Similarly, during measurement, node T can use a shared key to scramble the measurement signal sent to node G. Node G can then use the same shared key to descramble the signal and obtain the correct measurement signal. This prevents other nodes from obtaining the measurement signal and protects user privacy.

[0271] For example, G nodes and T nodes can also use a derivation key of a shared key to protect the measurement signal, and the specific process is consistent with the description in the above embodiments.

[0272] For example, when node G reports measurement results to node T, node G can use a session key derived from the shared key for encryption and integrity protection. First, node G derives the session key based on the shared key and the selected key negotiation algorithm; the specific derivation process can be found in the above embodiment. Node G uses the selected authentication encryption algorithm and session key to encrypt and protect the measurement results, and outputs the encrypted measurement results. Finally, node G sends the encrypted measurement results to node T.

[0273] Node T derives a session key based on the shared key and the selected key negotiation algorithm. This session key is the same as the session key derived by Node G. After receiving the encrypted measurement result, Node T uses the session key to decode and verify its integrity. If decryption is successful and data integrity verification passes, Node T obtains a correct and complete measurement result. If decryption fails or data integrity verification fails, Node T can discard the received measurement result and request Node G to resend it.

[0274] For example, when node G reports measurement results to node T, node G can use an encryption key derived from the shared key for encryption protection. The specific protection process can be referenced from the session key protection process described above.

[0275] For example, when node G reports measurement results to node T, node G can use the integrity protection key derived from the shared key for integrity protection. The specific protection process can be referenced from the session key protection process described above.

[0276] Similarly, when node T reports measurement results to node G, it can also be protected using a session key, encryption key, or integrity protection key. The specific protection process can refer to the session key protection process described above.

[0277] Figure 11 is a flowchart illustrating a security protection method applied to a bus access process according to an embodiment of this application. By sending security capability information along with bus access configuration information to the responding end, the security problem in a connectionless bus access scenario is solved, protecting user privacy. Figure 11 includes a G node and a T node. The G node is the broadcast end and can be a management device or other device already connected to the bus; the T node is the access end or responding end, and is a device waiting to connect to the bus; the G node and T node are unrelated devices, meaning they have not established a communication link. The specific process shown in Figure 11 is as follows:

[0278] 1) G node sends broadcast frames

[0279] As a broadcaster, the G node can send multiple broadcast frames, each carrying bus access configuration information and security capability information.

[0280] For example, the broadcast frame may be a star flash broadcast frame, the specific format of which can be referred to the description of the relevant embodiments of the above measurement process.

[0281] For example, a broadcast frame can select a value from the 0x08 to 0xFE reserved in the data type field, such as 0x0A, to indicate bus access configuration information and security capability information; or it can select two values, such as 0x0A and 0x0B, to indicate bus access configuration information and security capability information, respectively.

[0282] For example, a G node can send basic broadcast frames on three different broadcast channels: basic broadcast frame 1 on broadcast channel A, basic broadcast frame 2 on broadcast channel B, and basic broadcast frame 3 on broadcast channel C. Each basic broadcast frame carries bus access configuration information and security capability information. In addition, the G node can also send extended broadcast frames on the data channel, which also carry bus access configuration information and security capability information. The basic broadcast frames and extended broadcast frames are broadcast frames specified by the StarSpark standard.

[0283] For example, bus access configuration information is used to indicate the empty event groups that the access terminal needs to access the bus. An empty event group is an unallocated or unused event group on the bus, indicating the resources required for the access terminal to access the bus. The bus access configuration information may include one or more empty event group identifiers, each corresponding to one empty event group, with different identifiers corresponding to different empty event groups. Empty event group identifiers can be identified using event group identifiers.

[0284] The bus access configuration information may also include at least one of the following: number of empty event groups, event group interval, and time offset.

[0285] The number of empty event groups indicates the number of empty event group identifiers in the bus access configuration information. The event group interval indicates the time difference between the start times of two adjacent event groups. The time offset indicates the time difference between the start time of the broadcast frame transmission and the start time of the first empty event group. The access end can calculate the start time of the empty event group based on the event group interval, time offset, and empty event group identifier to perform the bus access process.

[0286] For example, the information and representation of the security capability information can be referred to the description of the above measurement process embodiments.

[0287] The G node informs the T node of its security capabilities, enabling the T node to know the security capabilities supported by the G node and thus select the appropriate cryptographic algorithm based on its own capabilities to protect the security of subsequent bus access processes.

[0288] 2) Node T sends a bus access request frame.

[0289] After receiving the broadcast frame, the T node obtains the bus access configuration information and security capability information from it.

[0290] Based on the bus access configuration information, the T node selects an empty event group and sends a bus access request frame to request access to the bus.

[0291] The T node selects a cryptographic algorithm based on the security capability information. The information and representation of the algorithm can be found in the description of the relevant embodiments of the measurement process described above.

[0292] The T node generates a public key based on the selected cryptographic algorithm. The specific generation process can be found in the description of the relevant embodiments of the measurement process above.

[0293] The bus access request frame sent by node T may also include the cryptographic algorithm selected by node T and node T's public key, so that node G can generate a shared key.

[0294] Node T selects a cryptographic algorithm and sends it back to Node G via a bus access response frame, enabling Node G to learn of the selected cryptographic algorithm and generate the same shared key as Node T. Reusing the bus access request frame reduces communication overhead.

[0295] 3) G node generates shared key

[0296] Node G receives a bus access request frame from Node T, from which it obtains Node T's request to access the bus and the selected cryptographic algorithm.

[0297] The G node sends back a bus access frame based on the bus access request from the T node, indicating whether the T node has successfully accessed the bus.

[0298] Node G generates a shared key based on the cryptographic algorithm selected by Node T. The specific generation process can be found in the description of the relevant embodiments of the measurement process above.

[0299] Node G generates a public key based on the cryptographic algorithm selected by Node T. The specific generation process can be found in the description of the relevant embodiments of the measurement process above.

[0300] The bus access response frame fed back by the G node may also include the G node's public key, so that the T node can generate the same shared key as the G node, establish secure communication, and achieve security protection for subsequent sessions.

[0301] 4) Node T generates a shared key

[0302] The T node receives a bus access response frame from the G node, from which it obtains whether the bus access was successful and the G node's public key.

[0303] If node T successfully connects to the bus, a shared key can be generated based on node G's public key and the selected key algorithm. The specific generation process can be found in the description of the relevant embodiments of the above measurement process.

[0304] If node T has successfully connected to the bus, the bus connection process can be re-initiated.

[0305] 5) Protect the session between the G node and the T node

[0306] If node T successfully connects to the bus, nodes G and T can use the shared key and its derived key to protect the signals and data sent by both parties in communication. For details, please refer to the description of the relevant embodiments of the above measurement process.

[0307] In this embodiment of the application, by reusing the broadcast frame, bus access request frame and bus access response frame in the bus access process, the security capability information of the G node, the cryptographic algorithm selected by the T node, the public key of the T node, the public key of the G node, the random number of the T node and the random number of the G node are carried, thereby reducing communication overhead and latency on the basis of building secure communication.

[0308] The following will describe the security protection communication device provided in the embodiments of this application.

[0309] This application divides the security protection communication device into functional modules according to the above-described method embodiments. For example, each function can be divided into its own functional modules, or two or more functions can be integrated into one processing module. The integrated modules can be implemented in hardware or as software functional modules. It should be noted that the module division in this application is illustrative and only represents one logical functional division; in actual implementation, there may be other division methods. The security protection communication device of this application embodiment will be described in detail below with reference to Figures 12 to 14.

[0310] Figure 12 is a schematic diagram of a security protection communication device provided in an embodiment of this application. As shown in Figure 12, the communication device includes a processing module 1201 and a transceiver module 1202. The transceiver module 1202 can implement corresponding communication functions, and the processing module 1201 is used to implement corresponding processing functions. For example, the transceiver module 1202 can also be referred to as an interface, a communication interface, or a communication module, etc.

[0311] In some embodiments of this application, the communication device can be used to perform the actions performed by the broadcast end in the above method embodiments. In this case, the communication device can be the broadcast end device itself or a chip or functional module configurable in the device. The transceiver module 1202 is used to perform the transmission and reception related operations of the broadcast end in the above method embodiments, and the processing module 1201 is used to perform the processing related operations of the broadcast end in the above method embodiments.

[0312] Specifically, taking the broadcast end in the first embodiment as an example, the processing module 1201 can be used to generate a broadcast frame, which includes first information indicating the security capabilities supported by the broadcast end; the transceiver module 1202 can be used to send the broadcast frame.

[0313] For example, the transceiver module 1202 can also be used to receive a response frame, which includes second information and a second public key, wherein the second information is used to indicate the cryptographic algorithm selected by the responding end, and the second public key is the public key of the responding end;

[0314] For example, the processing module 1201 can also be used to generate a first public key based on the second information and the first private key, wherein the first private key is the private key of the broadcasting end and the first public key is the public key of the broadcasting end; the transceiver module 1202 can also be used to send the first public key;

[0315] For example, the processing module 1201 can also be used to generate a first shared key based on the second information, the first private key, and the second public key;

[0316] For example, the processing module 1201 can also be used to securely protect subsequent sessions using the generated first shared key. The broadcaster transmits its supported security capabilities to the responder via broadcast frames, enabling the responder to know the broadcaster's security capabilities, thereby establishing secure session communication with the broadcaster even without a connection and protecting the security of the interactive data.

[0317] For example, the processing module 1201 can also be used to generate a derivation key of the first shared key based on the first shared key;

[0318] For example, the processing module 1201 can also use the first shared key or its derived key to scramble the signal sent by the broadcasting end; or to descramble the received signal. The broadcasting end can encrypt the transmitted physical signal using the first shared key or its derived key, thereby improving the security of the underlying physical signal.

[0319] For example, the processing module 1201 can also use the first shared key or its derived key to perform at least one of the following operations on the data sent by the broadcast end: encryption and integrity protection; or perform at least one of the following operations on the received data: decryption and integrity verification. The broadcast end encrypts and protects the integrity of the sent data using the first shared key or its derived key, and decodes and verifies the integrity of the received data, thereby improving the security of upper-layer interactive data and protecting user privacy.

[0320] For example, the processing module 1201 can also be used to generate a first random number, which can be used to generate a derivation key for the first shared key.

[0321] For example, the processing module 1201 can also be used to parse the response frame and obtain a second random number, which can be used to generate a derivation key for a shared key.

[0322] The broadcast end improves the security of the derivation key of the first shared key by using the first random number and the second random number, thus avoiding replay attacks.

[0323] Reusing Figure 12, in some other embodiments of this application, the security protection communication device can be used to perform the actions performed by the response end in the above method embodiments. In this case, the communication device can be the response end device itself or a chip or functional module configurable in the device. The transceiver module 1202 is used to perform the transmission and reception related operations of the response end in the above method embodiments, and the processing module 1201 is used to perform the processing related operations of the response end in the above method embodiments.

[0324] Specifically, taking the response end in the first embodiment as an example, the transceiver module 1202 can be used to receive broadcast frames from the broadcast end; the processing module 1201 can be used to parse the broadcast frame and obtain first information, which is used to indicate the security capability information supported by the broadcast end.

[0325] For example, the processing module 1201 can also be used to generate second information based on the first information, the second information being used to instruct the responding end to select security capability information, i.e., the selected cryptographic algorithm;

[0326] For example, the processing module 1201 can also be used to generate a second public key based on the second information and the second private key; wherein the second private key is the private key of the responding end and the second public key is the public key of the responding end.

[0327] For example, the transceiver module 1202 can also be used to send a response frame to the broadcast end, the response frame including second information and a second public key;

[0328] For example, the transceiver module 1202 can also be used to receive a first public key from the broadcast end;

[0329] For example, the processing module 1201 can also be used to generate a second shared key based on the second information, the second private key, and the first public key;

[0330] For example, processing module 1201 can also be used to securely protect the session between the responding end and the broadcasting end using a second shared key. The responding end informs the broadcasting end of the selected security capabilities, thereby enabling secure session communication with the broadcasting end in the absence of a connection, and protecting the exchanged data.

[0331] For example, the processing module 1201 can also be used to generate a derivation key of the second shared key based on the second shared key;

[0332] For example, the processing module 1201 can also be used to scramble the signal sent by the response end using the second shared key or a derived key of the second shared key; or to descramble the signal received by the response end using the second shared key or a derived key of the second shared key. The response end can encrypt the sent physical signal using the second shared key or its derived key, thereby improving the security of the underlying physical signal.

[0333] For example, the processing module 1201 can also be used to perform at least one of the following operations on the data sent by the responding end using the second shared key or a derived key of the second shared key: encryption and integrity protection; or to perform at least one of the following operations on the data received by the responding end using the second shared key or a derived key of the second shared key: decryption and integrity verification. The responding end can encrypt and protect the integrity of the sent data through the second shared key and its derived key, which improves the security of upper-layer interactive data and protects the security of user privacy.

[0334] For example, the transceiver module 1202 can also be used to receive broadcast frames and obtain a first random number, which is used to generate a derivation key for the second shared key.

[0335] For example, the processing module 1201 can also be used to generate a second random number, which is used to generate the derivation key of the second shared key. By using the first and second random numbers, the response end improves the security of the derivation key of the second shared key and avoids replay attacks.

[0336] Optionally, in the above embodiments, the security protection communication device may further include a storage module, which can be used to store instructions and / or data. The processing module 1201 can read the instructions and / or data in the storage module so that the security protection communication device can implement the aforementioned method embodiments.

[0337] In the above embodiments, the specific descriptions of terms or steps such as broadcast frame, first information, security capability information, second information, selected cryptographic algorithm, first public key, second public key, first private key, second private key, first shared key, second shared key, derivation key of first shared key, derivation key of second shared key, connectionless communication, and security protection can be found in the above method embodiments, and will not be described in detail here.

[0338] The specific descriptions of the transceiver module and processing module shown in the above embodiments are merely examples. For the specific functions or execution steps of the transceiver module and processing module, please refer to the above method embodiments, which will not be described in detail here.

[0339] The security protection communication device of this application embodiment has been described above. The following describes possible product forms of the security protection communication device. Any product possessing the functions of the security protection communication device described in FIG12 above falls within the protection scope of this application embodiment. The following description is merely illustrative and does not limit the product form of the security protection communication device of this application embodiment to this.

[0340] In one possible implementation, in the security protection communication device shown in FIG12, the processing module 1201 can be one or more processors, and the transceiver module 1202 can be a transceiver, or the transceiver module 1202 can also be a sending module and a receiving module. The sending module can be a transmitter, and the receiving module can be a receiver. The sending module and the receiving module are integrated into one device, such as a transceiver. In the embodiments of this application, the processor and the transceiver can be coupled, etc., and the connection method of the processor and the transceiver is not limited in the embodiments of this application. In the process of executing the above method, the process of sending information in the above method can be the process of the processor outputting the above information. When outputting the above information, the processor outputs the above information to the transceiver so that the transceiver can transmit it. After the above information is output by the processor, it may need to undergo other processing before reaching the transceiver. Similarly, the process of receiving information in the above method can be the process of the processor receiving the input above information. When the processor receives the input information, the transceiver receives the above information and inputs it into the processor. Furthermore, after the transceiver receives the aforementioned information, the information may need to undergo further processing before being input into the processor.

[0341] As shown in Figure 13, the communication device 130 includes one or more processors 1320 and transceivers 1310.

[0342] In some embodiments of this application, the security protection communication device can be used to execute the steps, methods, or functions executed by the SBP initiator described above. For example, the processor 1320 can be used to execute the functions or steps implemented by the processing module 1201 shown in FIG. 12, and the transceiver 1310 can be used to execute the functions or steps implemented by the transceiver module 1202 shown in FIG. 12. Detailed descriptions of the processor 1320 and transceiver 1310 can be found in FIG. 12 or the method embodiments shown above, and will not be elaborated further here.

[0343] In other embodiments of this application, the security protection communication device is used to execute the steps, methods, or functions performed by the SBP response terminal described above. For example, the processor 1320 can be used to execute the functions or steps implemented by the processing module 1201 shown in FIG. 12, and the transceiver 1310 can be used to execute the functions or steps implemented by the transceiver module 1202 shown in FIG. 12. Detailed descriptions of the processor 1320 and transceiver 1310 can be found in FIG. 12 or the method embodiments shown above, and will not be elaborated further here.

[0344] In various implementations of the security protection communication device shown in Figure 13, the transceiver may include a receiver for performing the function (or operation) of receiving, and a transmitter for performing the function (or operation) of transmitting. The transceiver is also used to communicate with other devices / appliances via a transmission medium.

[0345] Optionally, the security protection communication device 130 may further include one or more memories 1330 for storing program instructions and / or data. The memories 1330 and the processor 1320 are coupled. The coupling in this embodiment is an indirect coupling or communication connection between security protection communication devices, units, or modules, and can be electrical, mechanical, or other forms, used for information exchange between security protection communication devices, units, or modules. The processor 1320 may operate in conjunction with the memories 1330. The processor 1320 may execute program instructions stored in the memories 1330. Optionally, at least one of the above-mentioned memories may be included in the processor.

[0346] This application embodiment does not limit the specific connection medium between the transceiver 1310, processor 1320, and memory 1330. In Figure 13, the memory 1330, processor 1320, and transceiver 1310 are connected via a bus 1340, which is represented by a thick line in Figure 13. The connection methods between other components are only illustrative and are not intended to be limiting. The bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used in Figure 13, but this does not mean that there is only one bus or one type of bus.

[0347] In the embodiments of this application, the processor may be a general-purpose processor, a digital signal processor, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc., and can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly manifested as being executed by a hardware processor, or being executed by a combination of hardware and software modules within the processor.

[0348] In this application embodiment, the memory may include, but is not limited to, non-volatile memory such as hard disk drive (HDD) or solid-state drive (SSD), random access memory (RAM), erasable programmable read-only memory (EPROM), read-only memory (ROM), or compact disc read-only memory (CD-ROM), etc. Memory is any storage medium capable of carrying or storing program code in the form of instructions or data structures, and capable of being read and / or written by a computer (such as the security protection communication device shown in this application), but is not limited to this. The memory in this application embodiment may also be a circuit or any other device capable of implementing storage functions, used to store program instructions and / or data.

[0349] The processor 1320 is primarily used for processing communication protocols and data, controlling the entire security protection communication device, executing software programs, and processing software program data. The memory 1330 is primarily used for storing software programs and data. The transceiver 1310 may include control circuitry and an antenna. The control circuitry is primarily used for converting baseband signals to radio frequency signals and processing radio frequency signals. The antenna is primarily used for transmitting and receiving radio frequency signals in the form of electromagnetic waves. Input / output devices, such as touchscreens, displays, and keyboards, are primarily used for receiving user input data and outputting data to the user.

[0350] When the security protection communication device is powered on, the processor 1320 can read the software program in the memory 1330, interpret and execute the instructions of the software program, and process the data of the software program. When data needs to be transmitted wirelessly, the processor 1320 performs baseband processing on the data to be transmitted and outputs the baseband signal to the radio frequency (RF) circuit. The RF circuit processes the baseband signal and transmits the RF signal outward in the form of electromagnetic waves through the antenna. When data is sent to the security protection communication device, the RF circuit receives the RF signal through the antenna, converts the RF signal into a baseband signal, and outputs the baseband signal to the processor 1320. The processor 1320 converts the baseband signal into data and processes the data.

[0351] In another implementation, the radio frequency circuit and antenna can be set up independently of the processor that performs baseband processing. For example, in a distributed scenario, the radio frequency circuit and antenna can be arranged in a remote manner, independent of the security protection communication device.

[0352] The security protection communication device shown in this application embodiment may also have more components than those in Figure 13, and this application embodiment does not limit this. The methods executed by the processor and transceiver shown above are only examples, and the specific steps executed by the processor and transceiver can be referred to the methods described above.

[0353] In another possible implementation, in the security protection communication device shown in Figure 12, the processing module 1201 can be one or more logic circuits, and the transceiver module 1202 can be an input / output interface, or a communication interface, or an interface circuit, or an interface, etc. Alternatively, the transceiver module 1202 can also be a sending module and a receiving module. The sending module can be an output interface, and the receiving module can be an input interface. The sending module and the receiving module are integrated into one module, such as an input / output interface. As shown in Figure 14, the security protection communication device shown in Figure 14 includes a logic circuit 1401 and an interface 1402. That is, the above-mentioned processing module 1201 can be implemented using the logic circuit 1401, and the transceiver module 1202 can be implemented using the interface 1402. Among them, the logic circuit 1401 can be a chip, a processing circuit, an integrated circuit, or a system-on-a-chip (SoC) chip, etc., and the interface 1402 can be a communication interface, an input / output interface, pins, etc. For example, Figure 14 uses the above-mentioned security protection communication device as a chip, which includes the logic circuit 1401 and the interface 1402.

[0354] In this embodiment, the logic circuit and the interface can also be coupled to each other. The specific connection method of the logic circuit and the interface is not limited in this embodiment. For example, the logic circuit 1401 can be used to execute the functions or steps implemented by the processing module 1201 shown in FIG. 12, and the interface 1402 can be used to execute the functions or steps implemented by the transceiver module 1202 shown in FIG. 12. For a detailed description of the logic circuit 1401 and the interface 1402, please refer to FIG. 12 or the method embodiment shown above, which will not be detailed here.

[0355] The security protection communication device shown in the embodiments of this application can implement the method provided in the embodiments of this application in hardware form or in software form, etc., and the embodiments of this application do not limit it in this way.

[0356] This application also provides a communication system, which includes an SBP initiator and an SBP responder, which can be used to execute the methods in any of the foregoing embodiments.

[0357] In addition, this application also provides a computer program for implementing the operations and / or processes performed by various security protection communication devices in the method provided in this application.

[0358] This application also provides a computer-readable storage medium storing computer code that, when executed on a computer, causes the computer to perform operations and / or processes performed by various security protection communication devices in the methods provided in this application.

[0359] This application also provides a computer program product comprising computer code or a computer program that, when run on a computer, causes the operations and / or processes performed by various entities in the method provided in this application to be executed.

[0360] In the several embodiments provided in this application, it should be understood that the disclosed systems, security protection communication devices, and methods can be implemented in other ways. For example, the security protection communication device embodiments described above are merely illustrative. For instance, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules or components may be combined or integrated into another system, or some features may be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, communication devices, or modules, or it may be an electrical, mechanical, or other form of connection.

[0361] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical modules; that is, they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the technical effects of the solutions provided in the embodiments of this application.

[0362] Furthermore, the functional modules in the various embodiments of this application can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module. The integrated modules described above can be implemented in hardware or as software functional modules.

[0363] If the integrated module is implemented as a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a readable storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned readable storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0364] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A security protection method applied to a broadcast end, characterized in that, The method includes: Send a broadcast frame, the broadcast frame including first information, the first information being used to indicate the security capabilities supported by the broadcast end; Receive a response frame from the responding end, the response frame including second information and a second public key, the second information being used to indicate the cryptographic algorithm selected by the responding end according to the first information, and the second public key being the public key of the responding end; Based on the second information and the first private key, a first public key is generated, wherein the first private key is the private key of the broadcasting end; Send the first public key to the responding end; Based on the second information, the first private key, and the second public key, a first shared key is generated; The first shared key is used to securely protect the session between the broadcaster and the responder.

2. The method of claim 1, wherein, The session is a connectionless communication, including at least one of the following: Connectionless measurement, connectionless bus access; The connectionless measurement refers to the communication between the broadcast end and the response end for measurement in the absence of a connection. The connectionless bus access refers to communication where the responding end accesses the bus in the absence of a connection.

3. The method according to claim 1 or 2, characterized in that, Using the first shared key to securely protect the session between the broadcaster and the responder includes: The signal sent from the broadcasting end to the responding end is scrambled using the first shared key or a derived key of the first shared key; or The signal received by the broadcast terminal from the response terminal is descrambled using the first shared key or a derived key of the first shared key.

4. The method according to claim 1 or 2, characterized in that, Using the first shared key to securely protect the session between the broadcaster and the responder includes: Using the first shared key or a derived key of the first shared key, perform at least one of the following operations on the data sent from the broadcast end to the response end: encryption, integrity protection; or Using the first shared key or a derived key of the first shared key, perform at least one of the following operations on the data received by the broadcast end from the response end: decryption and integrity verification.

5. The method according to claim 1 or 2, characterized in that, The first information includes at least one of the following: Key negotiation algorithm capability, encryption algorithm capability, integrity protection algorithm capability, authentication encryption algorithm capability, key derivation function capability; Wherein: the key negotiation algorithm capability is used to indicate one or more key negotiation algorithms supported by the broadcast end; The encryption algorithm capability is used to indicate one or more encryption algorithms supported by the broadcast end; The integrity protection algorithm capability is used to indicate one or more integrity protection algorithms supported by the broadcast end; The authentication encryption algorithm capability is used to indicate one or more authentication encryption algorithms supported by the broadcast end; The key derivation function capability is used to indicate one or more key derivation functions supported by the broadcast end.

6. The method of claim 1 or 2, wherein, The second information includes at least one of the following: Key negotiation algorithm indication, encryption algorithm indication, integrity protection algorithm indication, authentication encryption algorithm indication, key derivation function indication; The key negotiation algorithm indicates a key negotiation algorithm selected by the responding end. The encryption algorithm indicator is used to indicate an encryption algorithm selected by the responding end; The integrity protection algorithm indicator is used to indicate an integrity protection algorithm selected by the response end; The authentication encryption algorithm indicator is used to indicate an authentication encryption algorithm selected by the responding end; The key derivation function indicates a key derivation function selected by the responder.

7. The method according to claim 1 or 2, characterized in that, The broadcast frame also includes a first random number. The first random number is used to generate the derivation key of the first shared key.

8. The method of claim 1 or 2, wherein, The response frame also includes a second random number. The second random number is used to generate the derivation key of the first shared key.

9. A security protection method applied to a response end, characterized in that, The method includes: Receive a broadcast frame from a broadcasting end, the broadcast frame including first information, the first information being used to indicate the security capabilities supported by the broadcasting end; Based on the first information, second information is generated, which is used to indicate the cryptographic algorithm selected by the responding end; A second public key is generated based on the second information and the second private key; the second private key is the private key of the responding end. Send a response frame to the broadcasting terminal, the response frame including the second information and the second public key; Receive the first public key from the broadcaster; Based on the second information, the second private key, and the first public key, a second shared key is generated; The second shared key is used to secure the session between the responding end and the broadcasting end.

10. The method of claim 9, wherein, The session is a connectionless communication, which includes at least one of the following: Connectionless measurement, connectionless bus access; The connectionless measurement refers to the communication between the broadcast end and the response end for measurement in the absence of a connection. The connectionless bus access refers to communication where the responding end accesses the bus in the absence of a connection.

11. The method according to claim 9 or 10, characterized in that, Using the second shared key to secure the session between the responding end and the broadcasting end includes: The signal sent from the responding end to the broadcasting end is scrambled using the second shared key or a derived key of the second shared key; or The signal received by the response end from the broadcast end is descrambled using the second shared key or the derivation key of the second shared key.

12. The method according to claim 9 or 10, characterized in that, Using the second shared key to secure the session between the responding end and the broadcasting end includes: Using the second shared key or a derived key of the second shared key, perform at least one of the following operations on the data sent from the responding end to the broadcasting end: encryption, integrity protection; or Using the second shared key or a derived key of the second shared key, perform at least one of the following operations on the data received by the response end from the broadcast end: decryption and integrity verification.

13. The method of claim 9 or 10, wherein, The first information includes at least one of the following: Key negotiation algorithm capability, encryption algorithm capability, integrity protection algorithm capability, authentication encryption algorithm capability, key derivation function capability; The key negotiation algorithm capability is used to indicate one or more key negotiation algorithms supported by the broadcast end; The encryption algorithm capability is used to indicate one or more encryption algorithms supported by the broadcast end; The integrity protection algorithm capability is used to indicate one or more integrity protection algorithms supported by the broadcast end; The authentication encryption algorithm capability is used to indicate one or more authentication encryption algorithms supported by the broadcast end; The key derivation function capability is used to indicate one or more key derivation functions supported by the broadcast end.

14. The method of claim 9 or 10, wherein, The second information includes at least one of the following: Key negotiation algorithm indication, encryption algorithm indication, integrity protection algorithm indication, authentication encryption algorithm indication, key derivation function indication; The key negotiation algorithm indicator is used to instruct the responding end to select a key negotiation algorithm; The encryption algorithm indicator is used to indicate an encryption algorithm selected by the responding end; The integrity protection algorithm indicator is used to indicate an integrity protection algorithm selected by the response end; The authentication encryption algorithm indicator is used to indicate an authentication encryption algorithm selected by the responding end; The key derivation function indicates a key derivation function selected by the responder.

15. The method of claim 9 or 10, wherein, The broadcast frame also includes a first random number. The first random number is used to generate the derivation key for the second shared key.

16. The method of claim 9 or 10, wherein, The response frame also includes a second random number. The second random number is used to generate the derivation key for the second shared key.

17. A communications device, characterized by The communication device is a broadcast terminal or is applied to a broadcast terminal, used to perform the method as described in any one of claims 1-8.

18. A communications device, characterized by The communication device is a response end or applied to a response end, used to perform the method as described in any one of claims 9-16.

19. A chip, characterized by The chip includes at least one processor and an interface, wherein the at least one processor is configured to read and execute instructions stored in a memory, and when the processor executes the instructions, causes the chip to perform the method as described in any one of claims 1-16.

20. A computer-readable storage medium, characterized in that, The computationally readable storage medium stores a computer program that, when executed by a computer, causes the computer to perform the method as described in any one of claims 1-16.

21. A computer program product, characterised in that, When the computer program product is executed, the method described in any one of claims 1-16 is performed.