Security processing method for PDCP control pdu

By encrypting and protecting the integrity of the PDCP control PDU, the security deficiencies in the NR system are resolved, and the security and integrity of data transmission are guaranteed.

WO2026157721A1PCT designated stage Publication Date: 2026-07-30ZTE CORP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
ZTE CORP
Filing Date
2025-12-22
Publication Date
2026-07-30

AI Technical Summary

Technical Problem

In existing NR systems, the PDCP control PDU is not encrypted or protected for integrity, resulting in insufficient security.

Method used

A secure processing method for PDCP control PDUs is provided. By configuring the signaling of access network elements or by agreeing on the protocol, the PDCP control PDUs are encrypted and/or protected for integrity. At the PDCP receiving end, the counter value is determined based on the PDCP sequence number for decryption and integrity verification.

Benefits of technology

It improves the security of PDCP control PDU, prevents information leakage and tampering, and ensures the privacy and integrity of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025144457_30072026_PF_FP_ABST
    Figure CN2025144457_30072026_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the embodiments of the present disclosure is a security processing method for a PDCP control PDU. The method comprises: on the basis of a signaling configuration of an access network element or a protocol agreement, performing encryption and / or integrity protection processing on a PDCP control PDU. The embodiments of the present disclosure solve the problems in the related art of the security risk being potentially increased due to not performing encryption and / or integrity protection on a PDCP control PDU, etc.
Need to check novelty before this filing date? Find Prior Art

Description

A PDCP-controlled PDU security processing method

[0001] Cross-references to related applications

[0002] This disclosure is based on and claims priority to Chinese patent application CN202510124773.9, filed on January 26, 2025, entitled "A Secure Processing Method for PDCP Controlled PDUs", and incorporates the entire contents of that patent application by reference. Technical Field

[0003] This disclosure relates to the field of communications, and more specifically, to a secure processing method for PDCP-controlled PDUs. Background Technology

[0004] The PDCP protocol defines PDCP control PDUs for control information between the PDCP receiver and transmitter. PDCP may define various control PDUs; for example, the following control PDUs are defined in NR systems: PDCP status report, Control PDU for interspersed ROHC feedback, Control PDU for EHC feedback, and Control PDU for UDC feedback.

[0005] The PDCP receiver constructs a PDCP status report based on instructions from its upper layer (e.g., RRC) and sends it to the corresponding PDCP sender. Interspersed ROHC feedback is generated at the RHOC protocol layer and submitted to the PDCP protocol layer. The PDCP protocol layer submits the Control PDU for interspersed ROHC feedback to the lower-layer protocol without associating it with the PDCP SN or encrypting it. The PDCP receiver receiving the Control PDU for interspersed ROHC feedback forwards it to the ROHC protocol without decryption. EHC feedback is generated at the EHC protocol layer and submitted to the PDCP protocol layer. The PDCP protocol layer submits the Control PDU for EHC feedback to the lower-layer protocol without encryption or integrity protection. The PDCP receiver receiving the Control PDU for EHC feedback forwards it to the ECH protocol without decryption or integrity verification. PDCP receives the Control PDU for UDC feedback and forwards it to the UDC protocol without decryption or integrity verification.

[0006] In summary, the existing NR system does not encrypt or protect the integrity of the PDCP control PDU, which is detrimental to the protection of the privacy and integrity of the PDCP control PDU. Summary of the Invention

[0007] This disclosure provides a secure processing method for PDCP control PDUs, which at least solves the problem in related technologies that may lead to increased security risks due to the lack of encryption and / or integrity protection for PDCP control PDUs.

[0008] According to one embodiment of this disclosure, a secure processing method for PDCP control PDUs is provided, applied to a PDCP transmitting end, including: encrypting and / or protecting the integrity of the PDCP control PDUs according to the signaling configuration or protocol agreement of the access network element.

[0009] According to another embodiment of this disclosure, a secure processing method for PDCP control PDUs is also provided, applied to a PDCP receiver, comprising: determining a counter value associated with the PDCP control PDU based on the PDCP sequence number in the received PDCP control PDU; decrypting and verifying the integrity of the PDCP control PDU based on the counter value; and submitting the decrypted and verified PDCP control PDU to an upper-layer protocol entity, wherein the protocol entity includes PDCP.

[0010] According to another embodiment of this disclosure, a configuration method for PDCP PDUs is also provided, applied to an access network element, including: for PDCP control PDUs, or one or more types of PDCP control PDUs, the access network element configures whether to deliver PDCP control PDUs and PDCP data PDUs in order or out of order.

[0011] According to another embodiment of this disclosure, a method for processing PDCP control PDUs is also provided, applied to a terminal, comprising: receiving configuration information; configuring PDCP according to the configuration information, wherein the configuration information is used to indicate whether one or more types of PDCP control PDUs are delivered in order or out of order; when the configuration information indicates out-of-order delivery or does not indicate in-order delivery, delivering the PDCP control PDUs to its upper-layer protocol or performing protocol-specified processing at the PDCP layer; and when the configuration information indicates in-order delivery or does not indicate out-of-order delivery, reordering and delivering the PDCP control PDUs in order.

[0012] According to yet another embodiment of this disclosure, a computer-readable storage medium is also provided, wherein a computer program is stored therein, wherein the computer program is configured to perform the steps in any of the above method embodiments when it is run.

[0013] According to yet another embodiment of this disclosure, an electronic device is also provided, including a memory and a processor, wherein the memory stores a computer program and the processor is configured to run the computer program to perform the steps in any of the above method embodiments.

[0014] According to yet another embodiment of this disclosure, a computer program product is also provided, including a computer program that, when executed by a processor, implements the steps in any of the above method embodiments. Attached Figure Description

[0015] Figure 1 is a hardware structure block diagram of a computer terminal for a PDCP-controlled PDU security processing method according to an embodiment of the present disclosure;

[0016] Figure 2 is a flowchart of a PDCP control PDU security processing method according to an embodiment of the present disclosure;

[0017] Figure 3 is a flowchart of a PDCP control PDU security processing method according to another embodiment of the present disclosure;

[0018] Figure 4 is a flowchart of a PDCP PDU configuration method according to an embodiment of the present disclosure;

[0019] Figure 5 is a flowchart of a PDCP control PDU processing method according to an embodiment of the present disclosure;

[0020] Figure 6 is a structural block diagram of a PDCP control PDU safety processing device according to an embodiment of the present disclosure;

[0021] Figure 7 is a structural block diagram of a PDCP control PDU safety processing device according to another embodiment of the present disclosure;

[0022] Figure 8 is a structural block diagram of a PDCP PDU configuration device according to an embodiment of the present disclosure;

[0023] Figure 9 is a structural block diagram of a PDCP control PDU processing apparatus according to an embodiment of the present disclosure;

[0024] Figure 10 is a schematic diagram of the wireless access network architecture;

[0025] Figure 11 is an example diagram of the protocol stack for the user plane of the wireless interface in wireless communication;

[0026] Figure 12 is a schematic diagram of the format of the PDCP control PDU according to an embodiment of the present disclosure (I);

[0027] Figure 13 is a schematic diagram of the reordering window of PDCP according to an embodiment of the present disclosure;

[0028] Figure 14 is a schematic diagram (II) of the format of the PDCP control PDU according to an embodiment of the present disclosure. Detailed Implementation

[0029] The embodiments of this disclosure will be described in detail below with reference to the accompanying drawings and examples.

[0030] It should be noted that the terms "first," "second," etc., in the specification, claims, and drawings of this disclosure are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.

[0031] The methods and embodiments provided in this disclosure can be executed in a mobile terminal, a computer terminal, or a similar computing device. Taking a computer terminal as an example, FIG1 is a hardware structure block diagram of a computer terminal in which the methods and embodiments of this disclosure are run. As shown in FIG1, the computer terminal may include one or more (only one is shown in FIG1) processors 102 (processors 102 may include, but are not limited to, microprocessors MCUs or programmable logic devices FPGAs, etc.) and a memory 104 for storing data. The computer terminal may also include a transmission device 106 for communication functions and an input / output device 108. Those skilled in the art will understand that the structure shown in FIG1 is only illustrative and does not limit the structure of the computer terminal. For example, the computer terminal may also include more or fewer components than shown in FIG1, or have a different configuration than shown in FIG1.

[0032] The memory 104 can be used to store computer programs, such as application software programs and modules, like the computer program corresponding to the secure processing method for Packet Data Convergence Protocol (PDCP) control protocol data packets (PDU) in this embodiment of the present disclosure. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, thereby implementing the above-described method. The memory 104 may include high-speed random access memory (RAM) and non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to a computer terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks (LANs), mobile communication networks, and combinations thereof.

[0033] The transmission device 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by a communication provider for the computer terminal. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module, used for wireless communication with the Internet.

[0034] Figure 2 is a flowchart of a PDCP control PDU security processing method according to an embodiment of the present disclosure. As shown in Figure 2, the process includes the following steps:

[0035] Step S202: Perform encryption and / or integrity protection processing on the PDCP control PDU according to the signaling configuration or protocol agreement of the access network element.

[0036] In an exemplary embodiment of this disclosure, the PDCP control PDU is encrypted and / or protected for integrity according to the signaling configuration or protocol of the access network element, including: constructing the PDCP control PDU; associating a counter value with the PDCP control PDU, and encrypting and / or protecting the PDCP control PDU based on the counter value; and submitting the PDCP control PDU to the lower-layer protocol entity.

[0037] In one embodiment, the lower-level protocol entity can be an RLC sender.

[0038] In an exemplary embodiment of this disclosure, encryption and / or integrity protection processing of the PDCP control PDU includes: encrypting and / or protecting the integrity of the PDCP control PDU using the same or different input parameters as the PDCP data PDU.

[0039] In an exemplary embodiment of this disclosure, encryption and / or integrity protection processing of the PDCP control PDU is performed using input parameters different from those of the PDCP data PDU, including at least one of the following: the key used for encrypting / decrypting the PDCP control PDU is different from the key used for encrypting / decrypting the PDCP data PDU; the key used for integrity protection / verification of the PDCP control PDU is different from the key used for integrity protection / verification of the PDCP data PDU; and an identifier different from that used for encryption and / or integrity protection of the PDCP data PDU is used.

[0040] In an exemplary embodiment of this disclosure, the counter value and the PDCP data PDU of the same PDCP entity share the same counter value space.

[0041] In one embodiment, the counter value is set to the value of the PDCP sender variable TX_Next.

[0042] In an exemplary embodiment of this disclosure, the space of counter values ​​is different from the space of counter values ​​of PDCP data PDUs received by the PDCP transmitter.

[0043] In an exemplary embodiment of this disclosure, the lower bit of the counter value is the PDCP sequence number of the PDCP control PDU, and the length of the PDCP sequence number is the same as the length of the PDCP sequence number used by the PDCP data PDU.

[0044] In an exemplary embodiment of this disclosure, the counter value is the value of a PDCP transmitter variable.

[0045] In an exemplary embodiment of this disclosure, the counter value is the value of a PDCP transmitter variable determined according to one or more PDCP control PDU types.

[0046] In one embodiment, the PDCP transmitter sets a set of corresponding PDCP variables for one or more PDCP control PDU types, such as the transmitter variable TX_Next. When setting the COUNT value of a PDCP control PDU, it is set to the value of its corresponding TX_Next, and the value of its corresponding TX_Next is incremented by 1.

[0047] In an exemplary embodiment of this disclosure, the PDCP control PDU includes a PDCP serial number field to indicate the PDCP serial number associated with the PDCP control PDU.

[0048] It should be noted that the PDCP serial number field is a field added in this embodiment.

[0049] In one embodiment, the PDCP control PDU may have multiple formats. For example, a field indicates that the PDCP PDU is a PDCP data PDU or a PDCP control PDU; the PDU type indicates the type of the PDCP control PDU; the PDCP SN (serial number) indicates the PDCP SN associated with the PDCP control PDU; and the PDCP control SDU contains the content of the control SDU carried by the PDCP control PDU.

[0050] Figure 3 is a flowchart of a PDCP control PDU security processing method according to another embodiment of the present disclosure. As shown in Figure 3, the process includes the following steps:

[0051] Step S302: Determine the counter value associated with the PDCP control PDU based on the PDCP sequence number in the received PDCP control PDU;

[0052] Step S304: Decrypt and verify the integrity of the PDCP control PDU according to the counter value, and submit the decrypted and verified PDCP control PDU to the upper-layer protocol entity, wherein the protocol entity includes PDCP.

[0053] In an exemplary embodiment of this disclosure, before determining the counter value associated with the PDCP control PDU based on the PDCP sequence number in the received PDCP control PDU, the type of the PDCP PDU is determined based on the D / C field carried by the received PDCP PDU and / or the PDU type, wherein the type includes PDCP control PDU and PDCP data PDU.

[0054] In an exemplary embodiment of this disclosure, when the type of the PDCP control PDU is configured by the access network element to be delivered out of order or not configured to be delivered in order, the PDCP control service data packet SDU carried by the PDCP control PDU is delivered to the upper-layer protocol of the PDCP control PDU or processed at the PDCP layer.

[0055] In an exemplary embodiment of this disclosure, when a type of PDCP control PDU is configured by an access network element to be delivered in order or not configured to be delivered out of order, the method further includes: placing the PDCP control SDU carried by the PDCP control PDU into a PDCP reordering window for reordering and in-order delivery processing.

[0056] It should be noted that, in one embodiment, for PDCP data PDUs, the access network element is configured to deliver in order, while for one or more PDCP control PDUs, in-order delivery is not configured. In this embodiment, regardless of whether PDCP data PDUs need to be reordered and / or delivered in order, the PDCP receiver immediately delivers the received PDCP control PDUs of the aforementioned type to its upper-layer protocol or the PDCP layer for corresponding processing; that is, in-order delivery is not required. If in-order delivery is configured for PDCP data PDUs, the maintenance of variables at the PDCP receiver will consider the received PDCP control PDUs as already received and / or already delivered. PDCP control PDUs that have already been delivered will not be delivered again in subsequent operations.

[0057] In an exemplary embodiment of this disclosure, decrypting and verifying the integrity of a PDCP control PDU based on a counter value includes at least one of the following: the key used for encrypting / decrypting the PDCP control PDU is different from the key used for encrypting / decrypting the PDCP data PDU; the key used for integrity protection / verification of the PDCP control PDU is different from the key used for integrity protection / verification of the PDCP data PDU; or an identifier different from that used for encryption and integrity protection of the PDCP data PDU is used.

[0058] Figure 4 is a flowchart of a PDCP PDU configuration method according to an embodiment of the present disclosure. As shown in Figure 4, the process includes the following steps:

[0059] Step S402: For PDCP control PDU, or one or more types of PDCP control PDU, the access network element configures whether to deliver the PDCP control PDU and PDCP data PDU in order or out of order.

[0060] In an exemplary embodiment of this disclosure, the access network element is configured with at least one of the following: configuring whether the PDCP control PDU uses the same encryption / decryption key KEY as the PDCP data PDU; a key for PDCP control PDU encryption / decryption; a key for PDCP control PDU integrity protection / authentication; a key for PDCP control PDU integrity protection / authentication; an identifier for PDCP control PDU radio bearer that is the same as the PDCP data PDU; and an identifier for PDCP control PDU encryption / decryption and integrity protection / authentication radio bearer.

[0061] Figure 5 is a flowchart of a PDCP control PDU processing method according to an embodiment of the present disclosure. As shown in Figure 5, the process includes the following steps:

[0062] Step S502: Receive configuration information and configure PDCP according to the configuration information. The configuration information is used to indicate whether one or more types of PDUs controlled by PDCP are delivered in order or out of order.

[0063] Step S504: If the configuration information indicates out-of-order delivery or does not indicate in-order delivery, the PDCP control SDU is delivered to its upper-layer protocol, or the PDCP layer performs the processing specified by the protocol.

[0064] Step S506: If the configuration information indicates that the PDUs should be submitted in order, or if there is no indication that they should be submitted out of order, the PDCP control PDUs will be reordered and submitted in order.

[0065] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this disclosure, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of this disclosure.

[0066] This embodiment also provides a secure processing device for Packet Data Convergence Protocol (PDCP) control protocol data packets (PDUs). This device is used to implement the above embodiments and preferred embodiments, and details already described will not be repeated. As used below, the term "module" can refer to a combination of software and / or hardware that performs a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.

[0067] Figure 6 is a structural block diagram of a PDCP control PDU security processing device according to an embodiment of the present disclosure. As shown in Figure 6, the device includes:

[0068] The first processing module 10 is configured to perform encryption and / or integrity protection processing on the PDCP control PDU according to the signaling configuration or protocol agreement of the access network element.

[0069] Figure 7 is a structural block diagram of a PDCP control PDU security processing apparatus according to another embodiment of the present disclosure. As shown in Figure 7, the apparatus includes:

[0070] The determination module 20 is configured to determine the counter value associated with the PDCP control PDU based on the PDCP sequence number in the received PDCP control PDU;

[0071] The first delivery module 30 is configured to decrypt and verify the integrity of the PDCP control PDU based on the counter value, and deliver the decrypted and verified PDCP control PDU to the upper-layer protocol entity, wherein the protocol entity includes PDCP.

[0072] Figure 8 is a structural block diagram of a PDCP PDU configuration device according to an embodiment of the present disclosure. As shown in Figure 8, the device includes:

[0073] Configuration module 40 is configured to allow access network elements to configure whether to deliver PDCP control PDUs and PDCP data PDUs in order or out of order for one or more types of PDCP control PDUs.

[0074] Figure 9 is a structural block diagram of a PDCP-controlled PDU processing apparatus according to an embodiment of the present disclosure. As shown in Figure 9, the apparatus includes:

[0075] The receiving module 50 is configured to receive configuration information and configure the PDCP according to the configuration information. The configuration information is used to indicate whether one or more types of PDCP control PDUs are delivered in order or out of order.

[0076] The second delivery module 60 is configured to deliver the PDCP control SDU to its upper-layer protocol when the configuration information indicates out-of-order delivery or does not indicate in-order delivery, or to perform the processing specified by the protocol at the PDCP layer.

[0077] The second processing module 70 is configured to reorder and deliver the PDCP control PDUs in order when the configuration information indicates that they should be delivered in order, or when there is no indication that they should be delivered out of order.

[0078] It should be noted that the above modules can be implemented by software or hardware. For the latter, they can be implemented in the following ways, but are not limited to: all the above modules are located in the same processor; or, the above modules are located in different processors in any combination.

[0079] To facilitate understanding of the technical solutions provided in the application embodiments, the following description is based on specific scenario embodiments.

[0080] Figure 10 is a schematic diagram of the wireless access network architecture, where AMF / UPF is the core network element, gNB is the access network element or base station, NG interface is the interface between AMF / UPF and gNB, NG interface includes NG user plane interface (NG-U) and control plane interface (NG-U), NG control plane interface (NG-C) provides functions including NG interface management, UE context management, UE mobility management, transmission of NAS messages, paging, PDU session management, etc.

[0081] Figure 11 is an example diagram of the protocol stack of the user plane of the radio interface in wireless communication. The user plane of the radio interface between the access network element (gNB, or base station) and the user equipment (UE) includes the physical layer, MAC layer, RLC layer, PDCP layer, and SDAP layer.

[0082] PDCP resides in the PDCP sublayer, and a UE can configure multiple PDCPs. Each PDCP is used to carry data for a radio bearer, including the data radio bearer (DRB) and the signaling radio bearer (SRB).

[0083] The PDCP layer can perform the following functions: header compression and decompression, such as using the ROHC or ECH protocols; uplink data compression and decompression, such as using the UDC protocol; ciphering and deciphering; integrity protection and integrity verification; timer-based SDU discard; reordering and in-order delivery; out-of-order delivery; duplication discarding; duplication; and routing for split bearers and DAPS bearers.

[0084] The PDCP layer includes the PDCP transmitter and the PDCP receiver.

[0085] The PDCP sender performs the following actions:

[0086] Receive a PDCP SDU from the upper layer and associate a COUNT value with the received PDCP SDU.

[0087] The COUNT value consists of two parts: the HFN part and the PDCP SN part. The PDCP SN part is the least significant bit part of the COUNT, and the HFN part is the most significant bit part of the COUNT.

[0088] Based on the associated COUNT value, the PDCP receiver may perform header compression, integrity protection, and ciphering operations on the PDCP SDU.

[0089] The PDCP receiver constructs the PDCP PDU corresponding to the PDCP SDU. The PDCP PDU includes the PDCP SDU and the protocol header of the PDCP PDU, and the PDCP SN is included in the PDCP header.

[0090] If a PDCP discard timer is configured, the PDCP transmitter starts a discard timer for each PDCP SDU received from the upper layer. When the PDCP transmitter receives a PDCP status report, or the lower layer confirms that the PDCP SDU has been successfully received, the timer is stopped. If the timer expires, the PDCP transmitter discards the PDCP SDU and its corresponding PDCP PDU, or all PDCP SDUs and their corresponding PDCP PDUs belonging to the same PDCP set as the PDCP SDU.

[0091] The PDCP transmitter maintains the following variable: TX_NEXT: This variable is the COUNT value of the next PDCP SDU to be sent. Except for setting the SRB for the continued use of the variable, the initial value of this variable is 0.

[0092] The PDCP receiver performs the following actions:

[0093] Receives an RLC SDU, i.e., a PDCP PDU, from its lower-level protocol (RLC layer).

[0094] Based on the PDCP SN of the PDCP PDU, determine the COUNT value associated with the PDCP PDU.

[0095] Based on the COUNT value, if the PDCP PDU is encrypted or protected for integrity, then the PDCP PDU is deciphered and its integrity is verified.

[0096] Based on the COUNT value, determine whether this PDCP PDU has been received before. If so, discard the PDCP PDU; otherwise, put it into the receive buffer.

[0097] If out-of-order delivery is not configured, or in-order delivery is configured, the received PDCP SDUs are reordered based on the COUNT value, and the received PDCP SDUs are delivered to the upper layer in order according to their associated COUNT values.

[0098] When the PDCP detects a missing PDCP SDU, for example when the COUNT value of the received PDCP SDU is discontinuous, the PDCP may start a reordering timer to wait for the missing PDCP SDU. When the reordering timer expires, the PDCP layer abandons waiting for the missing PDCP SDU.

[0099] The PDCP receiver maintains the following variables: RX_DELIV, which is the COUNT value of the first PDCP SDU that has not been delivered to the upper layer but is still waiting to be received, that is, the COUNT value of the next PDCP SDU to be delivered to the upper layer in order. Except for the broadcast channel of sidelink, the SRB and MRB configured with variable continuation, its initial value is 0; RX_NEXT, which is the next COUNT value after the maximum COUNT value in the PDCP SDUs in the PDCP receive buffer, that is, the COUNT value of the next PDCP SDU expected to be received; RCVD_COUNT, which is the COUNT value of the currently received PDCP SDU; RX_REORD, which is the next COUNT value after the COUNT value of the PDCP data PDU that triggers the reordering timer.

[0100] The behaviors of reordering and in-order delivery include: setting RX_DELIV to the COUNT value of the first PDCP SDU that has not been delivered to the upper layer; if RCVD_COUNT = RX_DELIV, then deliver the PDCP SDUs in the receive buffer starting from RX_RCVD, with COUNT values greater than or equal to RX_DELIV and continuous COUNT values, to the upper layer; if RX_NEXT is greater than RX_DELIV, start the reordering timer and set the value of RX_REORD to RX_NEXT; if the reordering timer is running and RX_DELIV is greater than or equal to RC_REORD, stop the reordering timer; if the reordering timer expires, deliver the PDCP SDUs with COUNT values less than RX_REORD in the buffer to its upper layer, and deliver the continuous PDCP SDUs starting from the COUNT value of RX_REORD to its upper layer. Update the value of RX_DELIV. If RX_DELIV < RX_NEXT, start the reordering timer (at this time there are still PDCP SDUs not received / lost).

[0101] For PDCP re-establishment or PDCP recovery operations, the PDCP performs PDCP re-establishment or PDCP recovery operations according to the instructions of the upper layer.

[0102] The PDCP transmitter performs the following behaviors:

[0103] For AM DRBs that are not suspended in PDCP, starting with the first PDCP data SDU that has not been successfully confirmed by its lower layer, all PDCP SDUs that were associated with the PDCP SN before PDCP reconstruction are sent or resent to their lower layer protocols in ascending order of their COUNT values.

[0104] For AM DRBs with suspended PDCP, starting with the first PDCP data SDU that has not been successfully sent by its lower layer, each PDCP SDU associated with a PDCP SN but not yet sent to its lower layer protocol is sent to the lower layer protocol in ascending order of its COUNT value.

[0105] For DRBs in UM mode, for each PDCP SDU associated with a PDCP SN but not yet sent to its underlying protocol, send it to the underlying protocol in ascending order of its COUNT value.

[0106] The PDCP receiver exhibits the following behaviors: For UM DRB and SRB, it resets RX_NEXT and RX_DELIV, stops operation, and resets the reordering timer; for UM DRB, it sends the stored PDCP SDUs to its upper-layer protocol in the order of their COUNT values. For SRB, it discards all stored PDCP SDUs and PDCP PDUs.

[0107] AM DRB data recovery function: Retransmit PDCP SDUs that were previously sent to the reconstructed or released AM RLC entities in ascending order of COUNT value and which have not received confirmation of successful transmission from the lower layer protocol.

[0108] Status reporting function: The PDCP receiver constructs a PDCP status report according to the instructions of its upper layer (e.g., RRC) and sends it to the corresponding PDCP sender.

[0109] Reasons that trigger a PDCP status report include: upper layer requesting PDCP entity re-establishment; upper layer requesting PDCP data recovery; upper layer requesting uplink data switching; and upper layer reconfiguring PDCP to release DAPS.

[0110] The PDCP status report includes: a COUNT value for a lost PDCP SDU, indicating the COUNT value of the first PDCP SDU that the PDCP receiver did not receive, i.e., the value of RX_DELIV; and a bitmap indicating the reception status of one or more PDCP SDUs, with each bit indicating the reception status of a PDCP SDU following the first unreceived PDCP SDU, i.e., whether the PDCP SDU has been received.

[0111] The PDCP transmitter determines whether a PDCP SDU has been received based on the content of the PDCP status report. If a PDCP SDU has been received, the PDCP transmitter removes it from the transmission buffer queue.

[0112] Scenario Example 1: PDCP Control PDU Security Handling Method - Shared Count

[0113] This embodiment provides a method for security processing of PDCP control PDUs. In this embodiment, one or more PDCP control PDUs are encrypted and / or protected for integrity. The access network element can configure, or agree on, at least one of the following through signaling or protocol: whether to encrypt and / or protect the integrity of the PDCP control PDU; whether to encrypt and / or protect the integrity of one or more PDCP control PDUs.

[0114] In this embodiment, the PDCP transmitter includes the following behaviors:

[0115] Step S601: Associate a COUNT value with a PDCP control PDU, or a PDCP control SDU contained in a PDCP control PDU.

[0116] Specifically, the associated COUNT value and the PDCP data PDU of the same PDCP entity share the same COUNT value space. For example, the COUNT value is set to the value of the PDCP transmitter variable TX_Next. In this case, the PDCP transmitter variable TX_Next is shared by the PDCP data PDU and the PDCP control PDU.

[0117] Step S602: Perform integrity protection and / or encryption on the PDCP control SDU based on the associated COUNT value.

[0118] Step S603: Set the PDCP SN of the PDCP control PDU to the low-order part of the COUNT value, and the length of the PDCP SN is the same as the length of the PDCP SN used by the PDCP data PDU.

[0119] Step S604: Submit the PDCP control PDU to the lower-level protocol entity of PDCP;

[0120] Specifically, the lower-level protocol entity may be the RLC sender.

[0121] An example of a PDCP control PDU format includes at least one of the following:

[0122] The D / C field indicates whether the PDCP PDU is a PDCP data PDU or a PDCP control PDU;

[0123] PDU type indicates the type of PDCP control PDU;

[0124] The PDCP SN indicates the PDCP SN associated with the PDCP control PDU (a newly added field in this instance);

[0125] The PDCP control SDU contains the contents of the control SDU carried by the PDCP control PDU.

[0126] The format of the PDCP control PDU can be shown in Figure 12. Oct 1 is D / C, PDU Type and PDCP SN, Oct 2 is PDCP SN, and Oct 3 is PDCP Control SDU.

[0127] In this embodiment, the PDCP receiver performs the following actions:

[0128] Step S701: Determine the type of the received PDCP PDU;

[0129] Specifically, determine whether the PDCP PDU is a PDCP data PDU or a PDCP control PDU.

[0130] Step S702: Determine the COUNT value associated with the PDCP control PDU.

[0131] Step S703: Use the associated COUNT value to decrypt and verify the integrity of the PDCP control PDU.

[0132] Access network elements can configure, through signaling or protocol, whether to deliver PDCP control PDUs, or one or more types of PDCP control PDUs, in order or out of order. Access network elements may configure PDCP data PDUs and PDCP control PDUs separately for whether to deliver in order or out of order. That is, different order / out-of-order delivery configurations may be configured for PDCP data PDUs and PDCP control PDUs.

[0133] If the access network element is configured to deliver out-of-order PDCP control PDUs, or if the PDCP control PDUs are not configured to be delivered in order, the PDCP receiver will deliver the PDCP control SDUs it carries to its upper-layer protocol, or process them at the PDCP layer.

[0134] For example, if it is a Control PDU for interspersed ROHC feedback, it is submitted to the associated ROHC protocol entity; if it is a Control PDU for EHC feedback, it is submitted to the associated EHC protocol entity; if it is a Control PDU for UDC feedback, it is submitted to the associated UDC protocol entity; and if it is a PDCP status report, it is processed accordingly.

[0135] If the access network element is configured to deliver in order for one type of PDCP control PDU, or not configured to deliver out of order, the PDCP receiver will put the PDCP control SDU it carries into the PDCP reordering window for reordering and in-order delivery processing.

[0136] In one embodiment, the access network element is configured to deliver PDCP data PDUs in order, while it is not configured to deliver one or more PDCP control PDUs in order. In this embodiment, regardless of whether PDCP data PDUs need to be reordered and / or delivered in order, the PDCP receiver immediately delivers the received PDCP control PDUs of the aforementioned type to its upper-layer protocol or the PDCP layer for corresponding processing, i.e., it does not need to deliver in order.

[0137] If the PDCP data PDU is configured for sequential delivery, then in the maintenance of PDCP receiver variables, the received PDCP control PDU is considered to have been received and / or delivered.

[0138] For PDCP control PDUs that have already been submitted, they will not be submitted again in subsequent operations.

[0139] Figure 13 is a schematic diagram of the PDCP reordering window according to an embodiment of the present disclosure. As shown in Figure 13, a PDCP control PDU is received with a COUNT value of M1. At this time, the PDCP variables RX_DELIV, RX_REORD, and RX_Next are all N0, N1, and N2, respectively. The value of M1 is greater than N0 and less than N2.

[0140] Because the PDCP control PDU is not configured to be delivered in sequence, the PDCP will receive a PDCP control with a COUNT value equal to M1.

[0141] The PDU is submitted to the upper-layer protocol (if it is a PDCP data PDU, it is submitted in order, because M1 is not equal to N0, the PDCP data PDU with a COUNT value of M1 must wait in the reordering queue instead of being submitted to its upper-layer protocol).

[0142] The PDCP receiver considers PDCP PDUs with a COUNT value equal to M1 in the reordering window as having been received and / or delivered.

[0143] When the PDCP receiver times out due to a reordering timer or receives a PDCP SDU with a COUNT value equal to N0 and submits it to the upper layer, it will no longer submit the PDCP control PDU with a COUNT value of M1 (skip the COUNT value). For example, when the reordering timer times out, the PDCP will submit the PDCP SDUs that have been received between N0 and N1. However, in this embodiment, the PDCP control PDU with a COUNT value of M1 will be skipped, that is, it will not be submitted again.

[0144] When maintaining PDCP variables, consider that a PDCP SDU with a COUNT value of M1 has been received and / or submitted.

[0145] In this embodiment, the input parameters for encryption and / or integrity protection operations used on the PDCP control PDU are the same as those for the PDCP data PDU, including at least one of the following input parameters: key KEY, which corresponds to encryption key and integrity protection key for encryption / decryption and integrity protection / verification operations, respectively; associated COUNT value, COUNT; bearer ID; and 1 bit of direction indication DIRECTION, used to identify uplink and downlink.

[0146] This embodiment achieves encryption and integrity protection for the PDCP control PDU by associating it with a COUNT and identifying the PDCP SN in the PDCP control PDU header. Simultaneously, by performing independent processing on the PDCP control PDU at the PDCP receiver, including but not limited to reordering and in-order delivery operations, the adverse effects of PDCP reordering and in-order delivery functions on the processing of the PDCP control PDU are avoided.

[0147] Scenario Example 2: Security Handling Method for PDCP Control PDU - Independent Count

[0148] This embodiment provides another method for implementing secure processing of PDCP control PDUs. This embodiment performs encryption and / or integrity protection on one or more PDCP control PDUs. Access network elements can indicate, through signaling or by protocol, at least one of the following: whether to encrypt and / or protect the integrity of the PDCP control PDUs; or whether to encrypt and / or protect the integrity of one or more combinations of PDCP control PDUs.

[0149] In this embodiment, the PDCP sender performs the following actions:

[0150] Step S801: For a combination of one or more PDCP control PDUs, use a COUNT value space that is different from that of the PDCP data PDU;

[0151] Specifically, the COUNT values ​​associated with these PDCP control PDUs come from a value space different from the COUNT values ​​of the PDCP data PDUs.

[0152] Step S802: Associate a COUNT value with a PDCP control PDU or a PDCP control SDU contained in a PDCP control PDU.

[0153] Specifically, in one embodiment, the PDCP transmitter sets a set of corresponding PDCP variables for one or more PDCP control PDU types, such as the transmitter variable TX_Next. When setting the COUNT value of a PDCP control PDU, it is set to the value of its corresponding TX_Next, and the value of its corresponding TX_Next is incremented by 1.

[0154] Step S803: Perform integrity protection and / or encryption on the PDCP control SDU based on the COUNT value.

[0155] Step S804: Set the PDCP SN of the PDCP control PDU to the low-order part of the COUNT value.

[0156] Step S805: Submit the PDCP control PDU to the lower-level protocol entity of PDCP;

[0157] Specifically, the lower-level protocol entity may be the RLC sender.

[0158] An example of a PDCP control PDU format includes at least one of the following:

[0159] The D / C field indicates whether the PDCP PDU is a PDCP data PDU or a PDCP control PDU;

[0160] PDU type indicates the type of PDCP control PDU;

[0161] The PDCP control SN indicates the PDCP SN associated with the PDCP control PDU (a newly added field in this instance);

[0162] The PDCP control SDU contains the contents of the control SDU carried by the PDCP control PDU.

[0163] In this embodiment, the format of the PDCP control PDU can be as shown in Figure 14, where Oct 1 is D / C, PDU Type and PDCP control SN, Oct 2 is PDCP control SN and Oct 3 is PDCP Control SDU.

[0164] In this embodiment, the PDCP receiver performs the following actions:

[0165] Step S901: For one or more types of PDCP control PDUs mentioned above, the PDCP receiver maintains a set of corresponding PDCP variables;

[0166] Specifically, this set of PDCP variables may include one or more of the following variables: RX_Next, Rx_DELIV, and RX_REORD.

[0167] Step S902: For the received PDCP PDU, determine whether it is a PDCP data PDU or a PDCP control PDU;

[0168] Specifically, the PDCP receiver can determine the type of the PDCP PDU based on the D / C field and / or PDU type carried by the PDCP PDU.

[0169] Step S903: For the PDCP control PDU, determine its associated COUNT value based on its PDCP SN.

[0170] Step S904: Use its associated COUNT value to decrypt and verify the integrity of the PDCP control PDU.

[0171] Access network elements can configure, via signaling, whether to deliver PDCP control PDUs of one or more types or combinations thereof in order or out of order. Access network elements may configure PDCP data PDUs and PDCP control PDUs separately for in-order or out-of-order delivery. That is, different in-order / out-of-order delivery configurations may be configured for PDCP data PDUs and PDCP control PDUs.

[0172] If the access network element is configured to deliver out-of-order or not in-order for one or more types of PDCP control PDUs, the PDCP receiver will deliver the PDCP control SDU it carries to its upper-layer protocol, or perform the processing specified by the protocol at the PDCP layer.

[0173] If the access network element is configured to deliver in order for one or more types of PDCP control PDUs, or is not configured to deliver out of order, the PDCP receiver will reorder and deliver the received PDCP control PDUs in order.

[0174] In this embodiment, the encryption and / or integrity protection operations used on the PDCP control PDU may use the same input parameters as the PDCP data PDU, or they may use different input parameters.

[0175] Input parameters may include at least one of the following: a different key used for PDCP control PDU encryption / decryption than the key used for PDCP data PDU encryption / decryption; a different key used for PDCP control PDU integrity protection / authentication than the key used for PDCP data PDU integrity protection / authentication. A different bearer ID is used than the one used for PDCP data PDU encryption and integrity protection. Optionally, this parameter may be configured by the access network element.

[0176] Corresponding to the above access parameters, the access network element can be configured with at least one of the following: whether to use the same encryption / decryption key KEY for PDCP control PDU as for PDCP data PDU; key KEY for PDCP control PDU encryption / decryption; whether to use the same integrity protection / authentication key KEY for PDCP control PDU as for PDCP data PDU; key KEY for PDCP control PDU integrity protection / authentication; whether to use the same bearer ID for PDCP control PDU as for PDCP data PDU; and bearer ID for PDCP control PDU encryption / decryption and integrity protection / authentication.

[0177] In this embodiment, by configuring different keys or different bearer IDs, it is possible to ensure that even when the COUNT values ​​of the PDCP control PDU and PDCP data PDU are the same (because they are independent COUNT value spaces), the input parameters for encryption / decryption and integrity protection / verification operations of the PDCP control PDU and PDCP data PDU are not completely the same. This avoids the risk of the same set of security parameters being used twice.

[0178] Through the embodiments of this disclosure, a COUNT value space independent of the PDCP data PDU is used for one or more types of PDCP control PDUs, thereby enabling encryption and / or integrity protection of the PDCP control PDUs while avoiding any impact on the PDCP data PDUs.

[0179] Embodiments of this disclosure also provide a computer-readable storage medium storing a computer program configured to perform the steps in any of the above method embodiments when executed.

[0180] In one exemplary embodiment, the aforementioned computer-readable storage medium may include, but is not limited to, various media capable of storing computer programs, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard disk, magnetic disk, or optical disk.

[0181] Embodiments of this disclosure also provide an electronic device including a memory and a processor, the memory storing a computer program and the processor being configured to run the computer program to perform the steps in any of the above method embodiments.

[0182] In one exemplary embodiment, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor and the input / output device is connected to the processor.

[0183] Specific examples in this embodiment can be found in the examples described in the above embodiments and exemplary implementations, and will not be repeated here.

[0184] It is obvious to those skilled in the art that the modules or steps of this disclosure described above can be implemented using general-purpose computing devices. They can be centralized on a single computing device or distributed across a network of multiple computing devices. They can be implemented using computer-executable program code, and thus can be stored in a storage device for execution by a computing device. In some cases, the steps shown or described can be performed in a different order than those presented herein, or they can be fabricated as separate integrated circuit modules, or multiple modules or steps can be fabricated as a single integrated circuit module. Thus, this disclosure is not limited to any particular combination of hardware and software.

[0185] The above description is merely a preferred embodiment of this disclosure and is not intended to limit this disclosure. Various modifications and variations can be made to this disclosure by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the principles of this disclosure should be included within the scope of protection of this disclosure.

Claims

1. A secure processing method for PDCP control PDUs, applied at the PDCP transmitter, comprising: According to the signaling configuration or protocol agreement of the access network element, the Packet Data Convergence Protocol (PDCP) control protocol data packets (PDU) are encrypted and / or protected for integrity.

2. The method according to claim 1, wherein, According to the signaling configuration or protocol agreement of the access network element, the PDCP control PDU is encrypted and / or its integrity is protected, including: Construct the PDCP control PDU; Associate a counter value with the PDCP control PDU, and based on the counter value, perform encryption and / or integrity protection processing on the PDCP control PDU; The PDCP control PDU is delivered to the lower-level protocol entity.

3. The method according to claim 2, wherein, The encryption and / or integrity protection process for the PDCP control PDU includes: The PDCP control PDU is encrypted and / or its integrity is protected using the same or different input parameters as the PDCP data PDU.

4. The method according to claim 3, wherein, Encryption and / or integrity protection processing of the PDCP control PDU using different input parameters than the PDCP data PDU, including at least one of the following: The key used for encrypting / decrypting PDCP control PDUs is different from the key used for encrypting / decrypting PDCP data PDUs. The key used for PDCP control PDU integrity protection / authentication is different from the key used for PDCP data PDU integrity protection / authentication. Use an identifier that differs from the one used for PDU encryption and / or integrity protection of PDCP data.

5. The method according to claim 2, wherein, The counter value and the PDCP data PDU of the same PDCP entity share the same counter value space.

6. The method according to claim 2, wherein, The space of the counter values ​​is different from the space of the counter values ​​of the PDCP data PDU received by the PDCP transmitter.

7. The method according to claim 2, wherein, The low-order part of the counter value is the PDCP sequence number of the PDCP control PDU, and the length of the PDCP sequence number is the same as the length of the PDCP sequence number used by the PDCP data PDU.

8. The method according to claim 2, wherein, The counter value is the value of the PDCP transmitter variable.

9. The method according to claim 6, wherein, The counter value is the value of a PDCP transmitter variable determined according to one or more PDCP control PDU types.

10. The method according to claim 1, wherein, The PDCP control PDU includes a PDCP sequence number field to indicate the PDCP sequence number associated with the PDCP control PDU.

11. A secure processing method for PDCP control PDUs, applied at a PDCP receiver, comprising: The counter value associated with the PDCP control PDU is determined based on the PDCP sequence number in the received packet convergence protocol PDCP control protocol data packet PDU; The PDCP control PDU is decrypted and its integrity is verified based on the counter value. The decrypted and integrity verified PDCP control PDU is then submitted to the upper-layer protocol entity, wherein the protocol entity includes the PDCP.

12. The method according to claim 11, wherein, Before determining the counter value associated with the PDCP control PDU based on the PDCP sequence number in the received PDCP control PDU, the method further includes: The type of the PDCP PDU is determined based on the D / C field carried by the received PDCP PDU and / or the PDU type, wherein the type includes PDCP control PDU and PDCP data PDU.

13. The method according to claim 12, wherein, When the type of the PDCP control PDU is configured for out-of-order delivery by the access network element, or is not configured for in-order delivery, the method further includes: The PDCP control service data packet SDU carried by the PDCP control PDU is delivered to the upper-layer protocol of the PDCP control PDU, or processed at the PDCP layer.

14. The method according to claim 11, wherein, When one type of the PDCP control PDU is configured by the access network element to be delivered in order, or is not configured to be delivered out of order, the method further includes: The PDCP control SDU carried by the PDCP control PDU is placed into the PDCP reordering window for reordering and sequential delivery.

15. The method according to claim 11, wherein, Decrypting and integrity verification of the PDCP control PDU based on the counter value includes at least one of the following: The key used for encrypting / decrypting the PDCP control PDU is different from the key used for encrypting / decrypting the PDCP data PDU. The key used for PDCP control PDU integrity protection / verification is different from the key used for PDCP data PDU integrity protection / verification. Use an identifier that differs from the radio bearer used for PDCP data PDU encryption and integrity protection.

16. A configuration method for a PDCP PDU, applied to an access network element, comprising: For Packet Data Convergence Protocol (PDCP) control protocol data packets (PDUs), or one or more types of PDCP control PDUs, the access network element is configured to either deliver the PDCP control PDUs or the PDCP data PDUs in order or out of order.

17. The method according to claim 16, wherein, The access network element is configured with at least one of the following: Configure whether the PDCP control PDU uses the same encryption / decryption key KEY as the PDCP data PDU; The key used by PDCP to control PDU encryption / decryption; The PDCP control PDU uses the same integrity protection / verification key as the PDCP data PDU. Keys used for PDCP control PDU integrity protection / verification; Configure whether the PDCP control PDU uses the same radio bearer identifier as the PDCP data PDU; Identifiers used for PDCP control of PDU encryption / decryption and integrity protection / authentication of wireless bearers.

18. A method for processing a PDCP-controlled PDU, applied to a terminal, comprising: Receive configuration information and configure the Packet Data Convergence Protocol (PDCP) according to the configuration information, wherein the configuration information is used to indicate whether one or more types of PDCP control protocol data packets (PDUs) are delivered in order or out of order; If the configuration information indicates out-of-order delivery or does not indicate in-order delivery, the PDCP control SDU is delivered to its upper-layer protocol, or the PDCP layer performs the processing specified by the protocol. If the configuration information indicates that the PDUs should be submitted in order, or if no out-of-order submission is indicated, the PDCP control PDUs will be reordered and submitted in order.

19. A computer-readable storage medium storing a computer program, wherein, When the computer program is executed by a processor, it implements the steps of the method described in any one of claims 1 to 10, or the steps of the method described in any one of claims 11 to 15, or the steps of the method described in any one of claims 16 to 17, or the steps of the method described in claim 18.

20. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the computer program, implements the steps of the method according to any one of claims 1 to 10, or implements the steps of the method according to any one of claims 11 to 15, or implements the steps of the method according to any one of claims 16 to 17, or implements the steps of the method according to claim 18.

21. A computer program product comprising a computer program that, when executed by a processor, implements the steps of the method according to any one of claims 1 to 10, or the steps of the method according to any one of claims 11 to 15, or the steps of the method according to any one of claims 16 to 17, or the steps of the method according to claim 18.