Method for security processing of data, and controller and communication device

WO2026189033A1PCT designated stage Publication Date: 2026-09-17ZTE CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2026/074844
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-10
Filing Date
2026-01-26
Publication Date
2026-09-17

Smart Images

  • Figure CN2026074844_17092026_PF_FP_ABST
    Figure CN2026074844_17092026_PF_FP_ABST
Patent Text Reader

Abstract

The present application discloses a method for security processing of data, and a controller and a communication device. The method comprises: determining first data, requiring security processing, of a MAC layer or a PHY layer; performing security processing on the first data; and transmitting the first data having undergone security processing.
Need to check novelty before this filing date? Find Prior Art

Description

Data security processing methods, controllers and communication equipment

[0001] Cross-reference of related applications

[0002] This application is based on and claims priority to Chinese Patent Application No. 202510291228.9, filed on March 10, 2025, the entire contents of which are incorporated herein by reference. Technical Field

[0003] This application relates to the field of network communication technology, and in particular to a data security processing method, controller, and communication device. Background Technology

[0004] In traditional 3GPP (3rd Generation Partnership Project) technology, secure data processing is performed at the PDCP (Packet Data Convergence Protocol) layer. This presents a problem: control information generated at the RLC (Radio Link Control) and MAC (Media Access Control) layers cannot be securely processed, hindering comprehensive security protection for the 3GPP radio access network. Summary of the Invention

[0005] The following is an overview of the subject matter described in detail herein. This overview is not intended to limit the scope of the claims.

[0006] This application provides a data security processing method, controller, and communication device that can perform secure data processing at the MAC layer or physical layer.

[0007] In a first aspect, embodiments of this application provide a method for securely processing data, including:

[0008] The first data that needs to be processed for security purposes is determined, and the first data includes media access control layer data or physical layer data.

[0009] Perform security processing on the first data;

[0010] Send the first data after the security processing.

[0011] Secondly, embodiments of this application provide a controller, including at least one processor and a memory for communicatively connecting to the at least one processor; the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform the security processing method as described above.

[0012] Thirdly, embodiments of this application provide a communication device, including the controller as described above.

[0013] The data security processing method, controller, and communication device provided in this application determine the first data that needs to be security processed at the MAC layer or PHY layer, perform security processing on the first data, and send out the security-processed first data. Compared with the current 3GPP technology's solution of only performing data security processing at the PDCP layer, this application provides a solution for performing security processing on data at the MAC layer or PHY layer, which is beneficial for achieving comprehensive security protection in the 3GPP radio access network.

[0014] Other features and advantages of this application will be set forth in the description which follows, and will be apparent in part from the description, or may be learned by practicing the application. The objectives and other advantages of this application may be realized and obtained by means of the structures particularly pointed out in the description, claims and drawings. Attached Figure Description

[0015] The accompanying drawings are used to provide a further understanding of the technical solutions of this application and form part of the specification. They are used together with the examples of this application to explain the technical solutions of this application and do not constitute a limitation on the technical solutions of this application.

[0016] Figure 1 is an architecture diagram of the protocol stack of the wireless interface user plane;

[0017] Figure 2 is an overall flowchart of a security processing method provided in an embodiment of this application;

[0018] Figure 3 is a schematic diagram of the structure of a MAC PDU provided in an embodiment of this application;

[0019] Figure 4 is a flowchart of a MAC layer determining the first data that needs to be processed for security purposes according to an embodiment of this application;

[0020] Figure 5 is an overall flowchart of a method for performing security processing on MAC layer data according to an embodiment of this application;

[0021] Figure 6 is a flowchart illustrating the inclusion of security processing information in a MAC PDU according to an embodiment of this application;

[0022] Figure 7 is a flowchart illustrating the setting method of the first and second parts of security processing information provided in an embodiment of this application;

[0023] Figures 8a-8c are schematic diagrams of setting the first and second parts of security processing information in a MAC subPDU according to an embodiment of this application;

[0024] Figures 9a-9c are schematic diagrams of setting the first and second parts of security processing information in a MAC subPDU according to an embodiment of this application;

[0025] Figure 10 is a complete schematic diagram of setting security processing information in a MAC subPDU according to an embodiment of this application;

[0026] Figure 11 is a flowchart of an embodiment of the present application, which indicates at least a portion of the security processing information shared by multiple security-processed first data in a shared security information block;

[0027] Figures 12a-12c are schematic diagrams illustrating the setting of the first and second parts of the security processing information corresponding to the data block in one embodiment of this application;

[0028] Figure 13 is a schematic diagram of a MAC subPDU that only indicates integrity protection information according to an embodiment of this application;

[0029] Figure 14 is a flowchart of a physical layer determining the first data that needs to be processed for security purposes, according to an embodiment of this application.

[0030] Figure 15 is a flowchart of a method for indicating first data that needs to be processed securely via a dynamic scheduling instruction, according to an embodiment of this application.

[0031] Figure 16 is a flowchart illustrating the requirement for security processing of a logical channel via signaling or MAC according to an embodiment of this application;

[0032] Figure 17 is a flowchart of a specific embodiment of this application, which provides a flowchart of secure processing of data transmitted via signaling or MAC instructions using designated wireless resources.

[0033] Figure 18 is a flowchart of a processing method based on COUNT value as input parameter provided in an embodiment of this application;

[0034] Figure 19 is a schematic diagram of the structure of a MAC PDU when security processing information is configured individually for each MAC SDU or MAC CE, as provided in an example of this application;

[0035] Figure 20 is a schematic diagram of the structure of a MAC PDU when a shared security information block is used to correspond to a MAC SDU or MAC CE, as provided in an example of this application;

[0036] Figure 21 is a schematic diagram of the structure of a MAC PDU when security processing information is configured individually for each data block, as provided in an example of this application.

[0037] Figure 22 is a schematic diagram of the structure of a MAC PDU when a shared security information block corresponds to multiple data blocks, as provided in an example of this application.

[0038] Figure 23 is a schematic diagram of a MAC subPDU that only indicates integrity protection information provided in an example of this application;

[0039] Figure 24 is a schematic diagram of the structural connection of a controller provided in one embodiment of this application. Detailed Implementation

[0040] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application. Furthermore, the features, operations, or characteristics described in the specification can be combined in any suitable manner to form various implementations. Simultaneously, the steps or actions described in the method description can be rearranged or adjusted in a manner readily apparent to those skilled in the art. Therefore, the various orders in the specification and drawings are merely for the clear description of a particular embodiment and do not imply a mandatory order, unless otherwise stated that a particular order must be followed.

[0041] In the description of this application, "several" means one or more, "more than" means two or more, "greater than," "less than," and "exceeding" are understood to exclude the stated number, while "above," "below," and "within" are understood to include the stated number. The use of "first" and "second" in the description is merely for distinguishing technical features and should not be construed as indicating or implying relative importance, or implicitly indicating the number of indicated technical features, or implicitly indicating the order of the indicated technical features.

[0042] The serial numbers assigned to components in this document, such as "first" and "second," are used only to distinguish the described objects and have no sequential or technical meaning. Unless otherwise specified, the terms "connection" and "linkage" used in this application include both direct and indirect connections (linkages).

[0043] Taking the radio interface protocol of 5G communication as an example, the protocol stack of the user plane of the radio interface in wireless communication is shown in Figure 1. The user plane of the radio interface between the access network element (e.g., gNB) and the user equipment (UE) includes the PHY (Physical) layer, MAC (Media Access Control) layer, RLC (Radio Link Control) layer, PDCP (Packet Data Convergence Protocol) layer, and SDAP (Service Data Adaptation Protocol) layer. In the 5G architecture, security processing includes data encryption / decryption, data integrity protection / verification, and other processing methods. The PDCP layer is the core layer for security processing of user plane data and control plane data. For the sending end, it encrypts and / or protects the integrity of the data according to the specified algorithm or key, encapsulates it, and submits it to the lower-layer RLC entity. For the receiving end, it decrypts and / or verifies the integrity of the received data according to the specified algorithm or key.

[0044] The aforementioned security processing only involves data from the PDCP layer and not other layers of the user plane. This raises a problem: control information generated by the RLC and MAC layers, such as RLC control PDUs (Protocol Data Units) or MAC CEs, cannot be securely processed, which is detrimental to achieving comprehensive security protection for the 3GPP radio access network.

[0045] Based on this, this application provides a data security processing method, controller, and communication device, which determines the first data that needs to be security processed at the MAC layer or PHY layer, performs security processing on the first data, and sends out the security-processed first data. Compared with the current 3GPP technology's solution of only performing data security processing at the PDCP layer, this application provides a solution for performing security processing on data at the MAC layer or PHY layer, which is beneficial for achieving comprehensive security protection in the 3GPP radio access network.

[0046] The following describes the data security processing method, controller, and communication device of this application through specific embodiments.

[0047] Referring to the overall flowchart of the data security processing method shown in Figure 2, the data security processing method provided in this application embodiment includes, but is not limited to, the following steps:

[0048] Step S110: Determine the first data that needs to be processed for security. The first data includes media access control layer data or physical layer data.

[0049] Step S120: Perform security processing on the first data;

[0050] Step S130: Send the first data after it has been securely processed.

[0051] The MAC layer's functions include mapping between logical channels and transport channels, and multiplexing and demultiplexing MAC SDUs (Service Data Units) of different logical channels to MAC PDUs (Protocol Data Units) or TBs (Transport Blocks). The mapping between logical channels and transport channels involves multiple logical channels being mapped to one transport channel. One DRB (Data Radio Bearer) corresponds to one logical channel, and the logical channels of multiple DRBs are mapped to one transport channel DTCH (Dedicated Traffic Channel). The transport channel is further mapped to a physical channel PDSCH (Physical Downlink Shared Channel) for transmission over the radio interface. MAC SDUs of multiple logical channels can be contained within a single MAC PDU and sent as a transport block to the physical layer.

[0052] MAC PDUs transmitted in the uplink and downlink channels have specific structures. One or more MAC subPDUs (sub-protocol data units) are contained within a single MAC PDU for transmission. Figure 3 shows an example of the MAC PDU structure for DL-SCH (Downlink Shared Channel) and UL-SCH (Uplink Shared Channel).

[0053] A MAC PDU includes one or more MAC subPDUs. A MAC subPDU includes a MAC sub header and a payload portion. The payload portion may be a MAC CE (MAC Control Element), a MAC SDU, or padding bytes. Figure 2 shows three scenarios where the payload portion contains different data, from left to right: MAC subPDU including MAC CE, MAC subPDU including MAC SDU, and MAC subPDU including padding.

[0054] Nodes in a wireless access network determine the data requiring secure processing according to specific or agreed-upon methods. This means identifying the first data requiring secure processing. Since the first data may be MAC layer data or physical layer data, the method for determining it may differ depending on the characteristics of the MAC and physical layers. For MAC layer data, the first data requiring secure processing can be determined through signaling indications, protocol agreements, etc. For physical layer data, the first data requiring secure processing can be indicated through dynamic scheduling signaling, RRC (Radio Resource Control) signaling, etc.

[0055] After identifying the first data that requires security processing, the first data is then processed. Security processing includes methods such as data encryption / decryption and data integrity protection / verification. The specific type of security processing can be indicated through specific or agreed-upon methods. For example, the first data transmitted through a certain logical channel can be encrypted according to a protocol. The sending end encrypts the first data according to the protocol and then sends it through the logical channel. The receiving end decrypts the received data according to the protocol to obtain the first data. Alternatively, the integrity of a certain type of first data can be protected through signaling. The sending end uses a specific algorithm to protect the integrity of this type of first data according to the signaling instruction. The receiving end verifies the integrity of the received first data to confirm that the first data transmission is error-free.

[0056] The first data that has undergone security processing is transmitted according to the layer it belongs to. If security processing is performed at the MAC layer, the first data that has undergone security processing is included in the MAC PDU and transmitted. If security processing is performed at the physical layer, the first data that has undergone security processing is transmitted through the physical channel.

[0057] The processing procedures of the MAC layer and the physical layer are explained in detail below.

[0058] Perform security measures at the MAC layer:

[0059] The first data that the sender determines requires security processing includes MAC SDU and / or MAC CE, and performs security processing on at least one of the following:

[0060] One MAC SDU;

[0061] A MAC CE;

[0062] A MAC subPDU containing a MAC SDU or MAC CE;

[0063] The sending end includes the first data, which has undergone security processing, in the MAC PDU for transmission. This security processing includes at least encryption and / or integrity protection. After receiving the MAC PDU, the receiving end decrypts and / or verifies the integrity of the first data, which has undergone security processing, contained in the MAC PDU according to the corresponding security processing method.

[0064] This application embodiment indicates the MAC SDU and / or MAC CE that need to be security processed through signaling instructions or protocol agreements. Specifically, referring to FIG4, in some embodiments, the first data that needs to be security processed in step S110 above includes at least one of the following:

[0065] Step S210: Determine the first data that needs to be securely processed as a MAC SDU transmitted on a designated logical channel based on the first indication information in the signaling or the first agreement content of the protocol.

[0066] Step S220: Determine the first data requiring security processing as a specified type MAC CE based on the second instruction information in the signaling or the second agreement content of the protocol.

[0067] Step S230: Determine the first data that needs to be processed for security purposes as a MAC SDU containing a Protocol Data Unit (PDU) of a specified type, based on the third instruction information in the signaling or the third agreement content of the protocol.

[0068] Step S240: Based on the fourth instruction information of the upper-layer protocol entity, the first data that needs to be processed for security is determined to be the MAC SDU sent by the upper-layer protocol entity this time.

[0069] In step S210, the designated logical channel is indicated by the logical channel identifier, data radio bearer (DRB) identifier, or signaling radio bearer (SRB) identifier in the first indication information or the first agreement content. Specifically, the data to be securely processed is determined to be a MAC SDU transmitted on the designated logical channel through signaling indication or protocol agreement, and the sending end performs security processing on all MAC SDUs transmitted on the designated logical channel. The first indication information may indicate the LCID (Logic channel Identifier) ​​transmitted on the designated logical channel, or the identifier of the DRB or SRB corresponding to the designated logical channel; similarly, the first agreement content is agreed upon between the sending end and the receiving end through a protocol, and the first agreement content may indicate the LCID transmitted on the designated logical channel, or the identifier of the DRB or SRB corresponding to the designated logical channel.

[0070] In step S220, the specified type of MAC CE is indicated by the logical channel identifier corresponding to the MAC CE in the second indication information or the second agreement content. Specifically, the data to be securely processed is determined to be a specified type of MAC CE through signaling indication or protocol agreement, and the sending end performs security processing on all MAC CEs of this specified type. The second indication information can indicate the LCID corresponding to the specified type of MAC CE; similarly, the second agreement content is agreed upon between the sending end and the receiving end through a protocol, and the second agreement content can indicate the LCID corresponding to the specified type of MAC CE.

[0071] In step S230, the specified type of protocol data unit is indicated by third indication information or third agreement content. The specified type of protocol data unit includes RLC control PDU and / or PDCP control PDU. Specifically, the data to be securely processed is determined to be a MAC SDU containing a specified type of PDU by signaling indication or protocol agreement. For example, the specified type of PDU may be a specific type of RLC control PDU or a PDCP control PDU contained within an RLC PDU. The third indication information instructs the sending end to perform secure processing on the MAC SDU containing the specific type of RLC control PDU or PDCP control PDU. Similarly, the third agreement content is agreed upon between the sending end and the receiving end through the protocol. The third agreement content stipulates that the sending end will perform secure processing on the MAC SDU containing the specific type of RLC control PDU or PDCP control PDU.

[0072] In step S240, the upper-layer protocol entity of the MAC entity indicates whether a certain MAC SDU requires security processing. When sending a MAC SDU to the MAC entity, the upper-layer protocol entity of the MAC entity instructs the MAC entity whether it needs to perform security processing on this MAC SDU. The upper-layer protocol entity of the MAC entity can be an RLC entity, PDCP entity, RRC entity, or application layer. For example, if the upper-layer protocol entity of the MAC entity is the RLC layer, when the RLC layer sends an RLC PDU, it sends a fourth indication message, instructing the MAC entity whether it needs to perform security processing on the sent RLC PDU. The RLC layer can determine which RLC PDUs need security processing based on some automatic or manual settings. For example, if the RLC layer determines that an RLC PDU containing RLC control information (e.g., an RLC control PDU) needs security processing by the MAC layer, then when the RLC layer sends an RLC PDU containing the RLC control PDU, it instructs the MAC layer to perform security processing on that RLC PDU.

[0073] Depending on the security processing performed, the sending end may need to send the corresponding security processing information along with the first data that has undergone security processing. For encryption / decryption processing, if the network agrees on encryption and decryption algorithms through protocols, the sending end may additionally send the corresponding encryption security processing information. For example, if the security processing information indicates that the data has been encrypted, the sending end may not send additional encryption security processing information. For integrity protection processing, since the data being sent is often different, the sending end usually needs to send additional integrity protection information. In practical applications, different security processing methods require different considerations based on the scenario and network requirements to determine whether to send additional security processing information. The following explains some possible scenarios for sending security processing information.

[0074] In some embodiments, referring to FIG5, the security processing method further includes:

[0075] Step S310: Generate security processing information corresponding to the security processing;

[0076] Sending the first data after security processing in step S130 includes:

[0077] Step S320: The first data and security processing information after security processing are included in the Media Access Control Protocol Data Unit (MAC PDU).

[0078] Step S330: Send MAC PDU.

[0079] After performing security processing on the first data, the sending end generates security processing information, which is then included in a MAC PDU along with the security-processed first data and transmitted. Based on the structure of a MAC PDU, a MAC PDU contains one or more MAC subPDUs. Each MAC subPDU contains a MAC CE or MAC SDU through its payload portion. Therefore, a MAC PDU transmitted by the sending end may contain at least one MAC subPDU containing the security-processed first data. This leads to two different scenarios for setting the security processing information: one is that the security processing information follows the MAC subPDU containing the MAC CE or MAC SDU, in which case the security processing information corresponds to each MAC CE or MAC SDU; the other is that the security processing information is additionally set in a MAC subPDU, and the portion of the MAC subPDU containing the security processing information serves as a shared security processing block, in which case the shared security processing block corresponds to one or more MAC CEs or MAC SDUs.

[0080] Specifically, in some embodiments, referring to FIG6, the security processing information included in the MAC PDU in step S320 above includes:

[0081] Step S410: Indicate at least a portion of the security processing information in the MAC sub-header corresponding to the first data after security processing;

[0082] Alternatively, in step S420, a shared security information block is set in the MAC PDU, indicating at least a portion of the security processing information shared by multiple first data that have undergone security processing.

[0083] The first data may be a single MAC SDU or MAC CE; it may also be a data block composed of multiple MAC SDUs or MAC CEs connected in series, or a data block composed of multiple MAC subPDUs containing MAC SDUs or MAC CEs connected in series. The following sections will explain each case separately.

[0084] For step S410, if the first data is a MAC SDU or MAC CE, security processing is performed separately for each MAC SDU or MAC CE. At least a portion of the security processing information is indicated in the MAC sub-header corresponding to the MAC SDU or MAC CE. The MAC subPDU contains the security-processed MAC SDU or MAC CE and a MAC sub-header containing at least a portion of the corresponding security processing information.

[0085] If the first data is a data block, security processing is performed on the data block, and the security-processed data block is included as part of the payload in a MAC subPDU, the MAC sub header of which indicates at least a portion of the security processing information.

[0086] For step S420, if the first data is a MAC SDU or MAC CE, security processing is performed on multiple MAC SDUs or MAC CEs. These security-processed MAC SDUs or MAC CEs may share some security processing information. Therefore, at least a portion of the shared security processing information can be indicated in the MAC sub-header of a MAC subPDU. The MAC subPDU may not contain the security-processed MAC SDUs or MAC CEs, or it may contain one of the security-processed MAC SDUs or MAC CEs.

[0087] Depending on the security processing method, the content of the security processing information may vary. Security processing methods include encryption / decryption and integrity protection / verification, while the security processing information may include at least one of the following: security status indication information, key information, algorithm information, integrity protection information, and security processing input parameters. When sending security processing information in a MAC PDU, different parts of the security processing information can be placed in different locations within the MAC PDU as needed.

[0088] Referring to Figure 7, in some embodiments, in step S410 above, indicating at least a portion of the security processing information in the MAC sub-header corresponding to the first data after security processing includes:

[0089] Step S510: Indicate the first part of the security processing information in the MAC sub-header corresponding to the first data after security processing, and / or, indicate the second part of the security processing information in the MAC subPDU corresponding to the first data after security processing;

[0090] Alternatively, in step S520, the second part of the security processing information is indicated in the MAC sub-header corresponding to the first data after security processing, and / or the first part of the security processing information is indicated in the MAC subPDU corresponding to the first data after security processing.

[0091] Alternatively, in step S530, the entirety of the security processing information is indicated in the MAC sub-header corresponding to the first data after security processing.

[0092] In the above embodiments, the security processing information corresponding to each first data may be divided into a first part and a second part. The first part includes at least one of security status indication information, key information, algorithm information and security processing input parameters, and the second part includes at least one of integrity protection information, key information, algorithm information and security processing input parameters.

[0093] There are three scenarios for step S510, corresponding to Figures 8a, 8b, and 8c, respectively. The first scenario is that the security processing information only contains the first part, in which case the first part is placed in the MAC sub-header corresponding to the first data after security processing. The second scenario is that the security processing information only contains the second part, in which case the second part is placed in the MAC subPDU corresponding to the first data after security processing (i.e., not placed in the MAC sub-header). The third scenario is that the security processing information contains both the first and second parts, in which case the first part is placed in the MAC sub-header corresponding to the first data after security processing, and the second part is placed in the MAC subPDU corresponding to the first data after security processing.

[0094] There are three scenarios for step S520, corresponding to Figures 9a, 9b, and 9c, respectively. The first scenario is that the security processing information only contains the second part, in which case the second part is placed in the MAC sub-header corresponding to the first data after security processing. The second scenario is that the security processing information only contains the first part, in which case the first part is placed in the MAC subPDU corresponding to the first data after security processing (i.e., not placed in the MAC sub-header). The third scenario is that the security processing information contains both the first and second parts, in which case the second part is placed in the MAC sub-header corresponding to the first data after security processing, and the first part is placed in the MAC subPDU corresponding to the first data after security processing.

[0095] Step S530 corresponds to Figure 10. All security processing information is contained in the MAC sub-header corresponding to the first data after security processing.

[0096] It is worth noting that the first data in Figures 8 to 10 may be a MAC SDU or MAC CE, and at least a portion of the MAC SDU or MAC CE and the corresponding security processing information are included in a corresponding MAC subPDU; the first data in Figures 8 to 10 may also be a data block composed of multiple MAC SDUs or MAC CEs connected in series, and this data block is included as a load part and at least a portion of the corresponding security processing information in a corresponding MAC subPDU; the first data in Figures 8 to 10 may also be a data block composed of multiple MAC subPDUs containing MAC SDUs or MAC CEs connected in series, and this data block is included as a load part and at least a portion of the corresponding security processing information in a corresponding MAC subPDU.

[0097] Security processing information may include, for example, key information, algorithm information, input parameters for security processing, and integrity protection information. This information needs to be included in the MAC sub-header of the MAC subPDU in a specific format. Below is an example of a MAC sub-header containing security processing information:

[0098] Where R is reserved bits, F is the format field, and L is used to indicate length information. If the integrity protection information is included in the MAC sub-header, L indicates the length of the MAC SDU or MAC CE. If the integrity protection information is included in the MAC subPDU (i.e. not included in the MAC sub-header), L indicates the length of the MAC SDU or MAC CE as well as the length of the integrity protection information (if the security protection information does not include the integrity protection information, L actually indicates the length of the MAC SDU or MAC CE).

[0099] LCID is used to indicate the LCID of the logical channel corresponding to a specific type of MAC CE;

[0100] I NT is used to indicate whether the MAC sub-header contains integrity protection information.

[0101] Referring to FIG11, in some embodiments, at least a portion of the security processing information shared by multiple security-processed first data is indicated in a shared security information block, including:

[0102] Step S610: In the shared security information block, the first part of the security processing information is indicated, and in the MAC subPDU corresponding to the first data after security processing, the second part of the security processing information is indicated.

[0103] Alternatively, in step S620, the second part of the security processing information is indicated in the shared security information block, and the first part of the security processing information is indicated in the MAC subPDU corresponding to the first data after security processing.

[0104] Alternatively, in step S630, all security processing information is indicated in a shared security information block.

[0105] In the above embodiments, the security processing information corresponding to each first data may be divided into a first part and a second part. The first part includes at least one of security status indication information, key information, algorithm information and security processing input parameters, and the second part includes at least one of integrity protection information, key information, algorithm information and security processing input parameters.

[0106] Referring to FIG12a, the situation of step S610 includes a shared security information block and multiple MAC subPDUs. The first data 1 after security processing is included in MAC subPDU1, and the first data 2 after security processing is included in MAC subPDU4. The security processing information corresponding to the security processing of the first data 1 and the second data 2 has a shared part. The shared part is that the first part of the security processing information is placed in the shared security information block, and the second part of the security processing information is respectively set in the MAC subPDU where the corresponding data after security processing is located, that is, the second part 1 is placed in MAC subPDU1, and the second part 2 is placed in MAC subPDU4.

[0107] Referring to Figure 12b, the situation in step S620 includes a shared security information block and multiple MAC subPDUs. The first data 1 after security processing is included in MAC subPDU1, and the first data 2 after security processing is included in MAC subPDU4. The security processing information corresponding to the security processing of the first data 1 and the second data 2 has a common part. The common part is that the second part of the security processing information is placed in the shared security information block. The first part of the security processing information is respectively set in the corresponding MAC subPDU where the security-processed data is located, that is, the first part 1 is placed in MAC subPDU1, and the first part 2 is placed in MAC subPDU4.

[0108] The situation in step S620 is shown in FIG12c. The MAC PDU includes a shared security information block and multiple MAC subPDUs. The first data 1 after security processing is included in MAC subPDU1, and the first data 2 after security processing is included in MAC subPDU4. The security processing information corresponding to the security processing of the first data 1 and the second data 2 is all shared, and all of the security processing information is placed in the shared security information block.

[0109] It is worth noting that the first data in Figure 12 may be a MAC SDU or MAC CE. At least a portion of the MAC SDU or MAC CE and the corresponding security processing information are contained in a corresponding MAC subPDU. All MAC subPDUs containing the security-processed MAC SDU or MAC CE are contained in a MAC PDU. The first data in Figure 12 may also be a data block composed of multiple MAC SDUs or MAC CEs connected in series. This data block, as a load portion, and at least a portion of the corresponding security processing information are contained in a corresponding MAC subPDU. All MAC subPDUs containing the security-processed data block are contained in a MAC PDU. The first data in Figure 12 may also be a data block composed of multiple MAC subPDUs containing MAC SDUs or MAC CEs connected in series. This data block, as a load portion, and at least a portion of the corresponding security processing information are contained in a corresponding MAC subPDU. All MAC subPDUs containing the security-processed data block are contained in a MAC PDU.

[0110] The shared security information block is a MAC subPDU containing a specific type of MAC CE. At least a portion of the security processing information is contained in the MAC subheader of the MAC subPDU containing the specific type of MAC CE. This security processing information may include, for example, key information, algorithm information, input parameters for security processing, integrity protection information, etc., and must be included in the MAC subheader of the MAC subPDU according to a specific format. Below is an example of a MAC subheader containing security processing information:

[0111] Where R represents reserved bits and F represents the format field;

[0112] LCID is used to indicate the LCID of the logical channel corresponding to a specific type of MAC CE;

[0113] INT is used to indicate whether the MAC sub-header contains integrity protection information.

[0114] Additionally, the shared security information block can also be a specific type of MAC CE, which contains at least a portion of the security processing information. In this case, the MAC CE used as the shared security information block corresponds to a specific MAC CE type or LCID, and this MAC CE is included in a MAC subPDU. Similarly, the security processing information may include, for example, key information, algorithm information, input parameters for security processing, integrity protection information, etc., and needs to be included in the MAC CE according to a certain format. Below is an example of a MAC CE containing security processing information:

[0115] In some possible cases, a portion of the security processing information can be agreed upon or configured in other ways, without being transmitted via MAC PDU. Therefore, in some embodiments, the security processing method further includes:

[0116] At least a portion of the security processing information is configured through signaling or agreed upon through protocols.

[0117] Specifically, the first part of the security processing information can be specified through signaling configuration or protocol, and the second part of the security processing information can be indicated in the MAC subPDU corresponding to the first data after security processing.

[0118] For example, referring to Figure 13, the first data is a data block composed of multiple MAC subSDUs concatenated, including MAC CE or MAC SDU. It is determined that the first data needs to be encrypted and protected for integrity. However, the MAC PDU does not contain a security information block. Integrity protection information is only set after the first data has undergone security processing. The key information, algorithm information, etc. used for security processing are configured through signaling and instructed to the UE by the access network element through the signaling. The input parameters used for security processing can be agreed upon by the protocol, or the system time value, radio resource number, etc. can be used. The length of the first data after security processing can be determined by the receiving end. First, the length of the integrity protection information is agreed upon by the protocol. After the receiving end receives the MAC PDU or TB, it determines the length of the MAC PDU or TB, and then subtracts the length of the integrity protection information agreed upon by the protocol from the length. The result is the length of the data block after security processing.

[0119] Based on the MAC PDU structure shown in Figure 13, if only the first data is encrypted, the MAC PDU in Figure 13 may not contain integrity protection information. This means that when the first data is securely processed, no corresponding security processing information is generated. Information necessary for security processing, such as algorithm information and key information, is configured through signaling or agreed upon by the protocol and does not need to be transmitted in the MAC PDU.

[0120] As mentioned above, security processing information includes parameters such as security status indication information, key information, algorithm information, integrity protection information, and input parameters for security processing. Among these, the security status indication information may include at least one of the following:

[0121] The first information is used to indicate whether the first data has been encrypted and / or protected for integrity.

[0122] The second information is used to indicate whether the MAC PDU contains integrity protection information for the first data;

[0123] The logical channel identifier of the logical channel or the logical channel identifier of the MAC CE is used to indicate whether the first data has been encrypted and / or protected for integrity.

[0124] The third piece of information is used to indicate whether the first data has been encrypted and / or protected for integrity according to the default processing method of the logical channel or MAC CE type to which it belongs.

[0125] Specifically, the first information indicates the security processing status of the MAC SDU or MAC CE, such as whether encryption and / or integrity protection processing has been performed; the second information indicates whether the MAC PDU contains integrity protection / authentication information for the MAC SDU or MAC CE. In a special case, if an access network element configures a specified logical channel requiring security processing via signaling, or indicates that a specified type of MAC CE requires security processing, the LCID corresponding to that specified logical channel or MAC CE type can be used as security status indication information. In this case, the LCID in the MAC sub-header is used to indicate whether the corresponding MAC SDU or MAC CE has undergone security processing. Another special case is that the access network element is configured with the default security processing method according to the signaling, and instructs the specified logical channel or the specified type of MAC CE to be encrypted according to the default processing method. In this case, the third information can be used to indicate whether the MAC SDU of the specified logical channel or the specific type of MAC CE in the current MAC PDU has been processed securely according to the default processing method. For example, the third information uses one bit to indicate whether the first data has been processed securely according to the default processing method. That is, in actual processing, the first data can be treated as an exception and not processed securely according to the default processing method configured by the signaling.

[0126] Security measures are implemented at the physical layer:

[0127] Referring to Figure 14, the first data that needs to be security processed in step S110 above includes at least one of the following:

[0128] Step S710: Instruct the user terminal UE to perform secure processing on the first data of the current transmission schedule through dynamic scheduling signaling;

[0129] Step S720: Indicate the identifier of the DRB or the logical channel identifier of the logical channel that needs to be processed by Radio Resource Control (RRC) signaling or MAC CE.

[0130] Step S730: Securely process the data transmitted on the specified radio resources through RRC signaling or MAC CE instruction. The specified radio resources include semi-statically configured radio resources and / or semi-persistently configured radio resources.

[0131] Security processing of physical layer data typically occurs on the physical channel. Physical layer data processing is relatively flexible; the first data requiring security processing can be determined through signaling related to physical layer transmission resources.

[0132] The first method involves the access network element instructing the UE whether to securely process the currently transmitted data via dynamic scheduling signaling. Specifically, referring to Figure 15, this includes the following steps:

[0133] Step S810: The access network element instructs the UE in the downlink control information (DCI) that schedules uplink transmission, so that the UE encrypts and / or protects the integrity of the first data of the current transmission schedule.

[0134] In step S820, the access network element indicates security processing status information in the DCI of the downlink transmission, so that the UE can decrypt and / or verify the integrity of the received data according to the security processing status information.

[0135] In the case of uplink scheduling, the access network element instructs the UE in the DCI (Distributed Control Interface) for scheduling uplink transmissions whether to perform security processing on the uplink transmission data scheduled by that DCI. If the DCI instructs the UE to perform security processing on the currently scheduled data, the UE performs security processing on the first data of the uplink transmission according to the DCI, such as performing encryption and / or integrity protection processing as instructed by the DCI. In some possible cases, the access network element may also instruct at least some security processing information in the uplink transmission DCI, such as indicating the input parameters for security processing in the uplink transmission DCI.

[0136] In the case of downlink scheduling, the access network element indicates security processing status information in the DCI (Distributed Control Information Center) for scheduling downlink transmission. The UE, based on the DCI indication and the security processing status information, decrypts and / or verifies the integrity of the received downlink data. This security processing status information may include at least one of the following:

[0137] Information indicating whether it has been encrypted;

[0138] Information indicating whether integrity protection has been implemented;

[0139] Integrity protection information;

[0140] Input parameters for security processing.

[0141] Understandably, in the first method described above, the access network element instructs the UE to perform certain security processing on the first data via DCI. When the UE sends data containing the security-processed first data, it may not need to send the corresponding security processing information, because the access network element knows what security processing the UE has performed according to the DCI instruction. Of course, in some cases, the UE may also send security processing information carrying the corresponding security processing, and the access network element will further determine the security processing status of the received data based on the received security processing information.

[0142] The second approach involves the access network element instructing via signaling whether data containing a specific DRB or a specific logical channel requires security processing.

[0143] Specifically, referring to Figure 16, the following steps are included:

[0144] In step S910, the access network element instructs the UE via RRC signaling or MAC CE to encrypt and / or protect the integrity of data containing a specified DRB or a specified logical channel during uplink transmission, and to indicate the security processing status information in the uplink control information (UCI) of the uplink transmission.

[0145] In step S920, the access network element indicates security processing status information in the DCI that schedules downlink transmission, so that the UE can decrypt and / or verify the integrity of the received data according to the security processing status information.

[0146] The access network element indicates the DRB ID or the LCID of the logical channel via RRC signaling or MAC CE. Based on the indication in the RRC signaling or MAC CE, the UE determines the data of the specified DRB or the specified logical channel as the first data and performs encryption and / or integrity protection processing on the first data. In some possible cases, the access network element can also indicate the security processing method via RRC signaling or MAC CE, for example, instructing the UE how to perform security processing on data containing a specific DRB or data transmitted on a logical channel, including whether to perform encryption processing or integrity protection processing.

[0147] Based on the aforementioned RRC signaling or MAC CE instructions (which may include the indicated security processing method), the UE performs security processing on data containing a specific DRB or data transmitted via a logical channel when transmitting uplink data. When transmitting the first data after security processing, the UE indicates the security processing status information in the UCI of the uplink transmission. Upon receiving the security-processed data from the UE, the access network element decrypts and / or verifies the integrity of the data according to the previously indicated encryption and / or integrity protection processing method.

[0148] When an access network element sends securely processed data to a UE, it indicates the security processing status information in the DCI that schedules downlink transmission, so as to instruct the UE to decrypt and / or verify the integrity of the received downlink data.

[0149] The security processing status information mentioned in the above uplink and downlink transmissions may include at least one of the following:

[0150] Information indicating whether it has been encrypted;

[0151] Information indicating whether integrity protection has been implemented;

[0152] Integrity protection information;

[0153] Input parameters for security processing.

[0154] The third method involves the access network element instructing the UE to perform secure processing on data transmitted through specific radio resources via signaling. Specifically, as shown in Figure 17, this includes the following steps:

[0155] Step S1010: The access network element instructs the UE via RRC signaling or MAC CE to encrypt and / or protect the integrity of data transmitted using designated radio resources during uplink transmission.

[0156] In step S1020, the access network element instructs the UE via RRC signaling or MAC CE to decrypt and / or verify the integrity of the received data when the UE receives downlink data using designated radio resources.

[0157] Access network elements instruct the UE via RRC signaling or MAC CE whether to perform secure processing on data transmitted using the following radio resources:

[0158] Configured grant the configured wireless resources;

[0159] Configured assignment: Wireless resources configured;

[0160] Radio resources configured for uplink semi-persistent scheduling (SPS);

[0161] Downlink semi-persistent configuration of radio resources;

[0162] The aforementioned radio resource configurations are all semi-static or semi-persistent radio resource configurations configured by access network elements. The aforementioned MAC CE may be a MAC CE used to activate the radio resource configuration.

[0163] Based on the aforementioned RRC signaling or MAC CE instructions, when transmitting uplink data using the specified radio resources, the UE performs encryption and / or integrity protection processing on the first data transmitted using those radio resources. In some possible cases, when transmitting the securely processed first data, the UE indicates the security processing status information, including integrity protection information and / or security processing input parameters, in the uplink transmission UCI. Upon receiving the securely processed data from the UE, the access network element decrypts and / or verifies the data according to the previously indicated encryption and / or integrity protection processing methods.

[0164] When an access network element sends securely processed data to a UE, it instructs the UE to decrypt and / or verify the integrity of the received downlink data via RRC signaling or MAC CE.

[0165] Understandably, the above description of the third method does not mention how to instruct the UE to perform security processing. In fact, the access network element and the UE configure the security processing method for data transmitted using the above-mentioned radio resources through signaling. That is, after configuration, the data transmitted using the above-mentioned radio resources is security processed by default. Therefore, it is not necessary to indicate whether security processing has been performed in the DCI or UCI.

[0166] The input parameters for security processing mentioned in the above embodiments typically include one or more optional values. In traditional 3GPP network access technologies, data security processing is performed on the PDCP SDU by the PDCP layer. Security processing methods typically include encryption / decryption and / or integrity protection / verification. The input parameters used for security processing at the PDCP layer may include the following:

[0167] Keys, including encryption / decryption keys used for encryption / decryption and integrity protection / verification keys used for integrity protection / verification.

[0168] An indicator of transmission direction, used to identify uplink and downlink transmissions;

[0169] The identifier of the radio bearer associated with the PDCP entity, including DRB ID or SRB ID;

[0170] A one-bit direction indicator (DIRECTION) is used to identify uplink and downlink;

[0171] The COUNT value associated with PDCP SDU.

[0172] The aforementioned COUNT value is maintained by the PDCP entity (DRB), meaning one COUNT value space corresponds to one PDCP entity. The PDCP transmitter associates a COUNT value with each PDCP SDU and carries the lower-order part of the COUNT value (the PDCP SN) in the PDCP PDU header to identify the PDCP PDU, ensuring that the COUNT value corresponding to each PDCP SDU is globally unique and monotonically increasing. In wireless network security requirements, a principle for using keys and input parameters is that a key cannot be used with the same input parameter more than twice. Therefore, introducing a COUNT value as an input parameter in traditional security processing methods requires using different COUNT values ​​for different PDCP SDUs, thereby avoiding potential security risks.

[0173] In this application, security processing is performed at the MAC layer or physical layer, and the COUNT value mechanism used in traditional PDCP layer security processing cannot be directly used. Therefore, the input parameters for security processing need to be redesigned.

[0174] In some embodiments, the security processing information includes input parameters used to perform security processing on the first data; the input parameters include at least one of the following:

[0175] The first key includes keys used for encryption and decryption, and / or keys used for integrity protection and integrity verification;

[0176] The transmission direction indication information is used to indicate uplink and downlink transmissions.

[0177] In addition to the parameters mentioned above, the input parameters also include at least one of the following or a combination of at least one of the following:

[0178] Channel identification information; the channel identifier represents the channel to which the first data belongs.

[0179] The value of the counter is used in conjunction with the first key for encryption and decryption.

[0180] A random number, generated by the sending end and associated with the first data, is used to instruct the sending and receiving ends to perform secure processing according to the random number.

[0181] The identification of a radio resource includes its identification in the time domain and / or its identification in the frequency domain.

[0182] The first value is indicated periodically by system messages;

[0183] The second value associated with time.

[0184] The following sections will provide a detailed explanation of the input parameters mentioned above.

[0185] Channel identification information (or channel ID) may be one of the following:

[0186] (1) When the first data is a single MAC CE, the channel identification information is the logical channel identifier of the MAC CE. Specifically, when performing security processing on a MAC SDU, the channel identification information may be the LCID of the logical channel to which the MAC SDU belongs, or it may be the DRB ID or SRB ID to which the MAC SDU belongs.

[0187] (2) When the first data is a single MAC CE, the channel identification information is the logical channel identifier of the MAC CE; specifically, when performing security processing on a MAC CE, the channel identification information may be a value used to identify the type of the MAC CE, for example, using the LCID corresponding to the MAC CE as the channel identification information.

[0188] (3) When the first data is a data block composed of multiple MAC SDUs and / or MAC CEs connected in series, the channel identification information is a preset value agreed upon by the protocol or indicated by the access network element through signaling, or the channel identification of the transmission channel corresponding to the MAC PDU; specifically, when performing security processing on the data block composed of multiple MAC CEs and / or multiple MAC SDUs, the channel identification information may be a value defined by the protocol or indicated by the access network element through signaling, or it may be the type or ID of the transmission channel corresponding to the MAC PDU.

[0189] (4) When the first data is a MAC PDU or a transport block TB, the channel identification information is the channel identifier of the transport channel or physical channel corresponding to the MAC PDU; specifically, when performing security processing on a MAC PDU or TB block, the channel identification information may be the type or ID of the transport channel or physical channel corresponding to the MAC PDU.

[0190] The value of the counter (or COUNT value) may be one of the following:

[0191] (1) When the first data is a single MAC SDU, the transmitting end associates a counter variable with the logical channel corresponding to the MAC SDU; when the MAC SDU is transmitted through the logical channel corresponding to the MAC SDU, the value of the counter is set to the value of the counter variable, and the value of the counter variable is incremented by 1;

[0192] The first scenario involves associating the COUNT value with a MAC SDU. Specifically, the transmitter associates a variable V_COUNT with the logical channel (which can also be a DRB or SRB) corresponding to the MAC SDU. When the transmitter associates the COUNT value with the MAC SDU of that logical channel, it sets the COUNT value to the current V_COUNT value and then increments the V_COUNT value by 1. This ensures that the transmitter generates a monotonically increasing count value each time it associates the logical channel with a MAC SDU for transmission.

[0193] (2) When the first data is a single MAC CE, the sender associates the type of the MAC CE with a counter variable; when sending a MAC CE of type MAC CE, the value of the counter is set to the value of the counter variable, and the value of the counter variable is incremented by 1;

[0194] The second scenario involves associating the COUNT value with a MAC CE. Specifically, the sender associates a variable V_COUNT with one or more MAC CE types. When the sender associates a COUNT value with a MAC CE type, it sets the COUNT value to the current V_COUNT value and then increments the V_COUNT value by 1. This ensures that the sender generates a monotonically increasing count value each time it associates a MAC CE of that type with a MAC CE and sends a MAC CE.

[0195] (3) When the first data is a data block, MAC PDU or TB composed of multiple MAC SDUs and / or MAC CEs connected in series, the sending end associates a counter variable with the MAC entity; when sending a data block, MAC PDU or TB to the MAC entity, the value of the counter is set to the value of the counter variable and the value of the counter variable is incremented by 1;

[0196] The third scenario involves the COUNT value being associated with a MAC PDU or TB, or with one or more MAC SDUs and / or MAC CEs contained within a MAC PDU. Specifically, the sender associates a variable V_COUNT with a MAC entity. When the sender associates data (including MAC PDUs or TBs, or one or more MAC SDUs and / or MAC CEs) sent by that MAC entity with the COUNT value, the COUNT value is set to the current V_COUNT value, and then the V_COUNT value is incremented by 1. This ensures that the sender generates a monotonically increasing count value each time it associates data sent by that MAC entity.

[0197] In the three cases mentioned above, the initial value of the variable V_COUNT can be specified by the protocol or by the access network element through configuration.

[0198] In some possible cases, the sender carries the counter value in the MAC PDU, DCI, or UCI, and the receiver determines the counter value based on the received MAC SDU, MAC CE, MAC PDU, or TB. When sending the first data that has undergone secure processing, the sender carries all the COUNT values ​​in the MAC PDU, DCI, or UCI. For example, the COUNT value associated with a MAC SDU or MAC CE may be included in the corresponding MAC subheader or security information block, or the COUNT value associated with a MAC PDU or TB may be included in the MAC PDU or the DCI that schedules the MAC PDU. The receiver receives the data (MAC SDU, MAC CE, MAC PDU, or TB) containing all the COUNT values ​​and determines the continuity and uniqueness of the received data based on the recorded COUNT values.

[0199] To improve security, this application can adopt a method similar to the COUNT value used in the PDCP layer, splitting the COUNT value into two parts: HFN (Hyper Frame Number) and SN (Sequence Number), and reconstructing the COUNT value at the receiving end based on the received SN. However, the COUNT value method used in the PDCP layer cannot be directly applied to the MAC layer or physical layer and requires certain adjustments.

[0200] In some possible cases, the transmitting end carries the low-order part of the counter value in the MAC PDU, DCI, or UCI. The receiving end determines the low-order part based on the received MAC SDU, MAC CE, MAC PDU, or TB, and determines the counter value based on the received low-order part. The low-order part consists of multiple least significant bits of the counter value. In the above case, the network specifies that the COUNT value is divided into a high-order part H and a low-order part L. The low-order part L refers to the value composed of N LSBs (Least Significant Bits) of the COUNT value, and the high-order part H refers to the value composed of M MSBs (Most Significant Bits) of the COUNT value. The values ​​of N and M are agreed upon by the protocol or configured by the access network element through signaling, or only the value of N is agreed upon by the protocol or configured by the access network element through signaling, and the value of M is the number of bits remaining in the COUNT value after deducting the low-order part L. When transmitting the first data that has undergone security processing, the sender carries the low-order portion L of the COUNT value in the MAC PDU, DCI, or UCI. For example, the low-order portion L of the COUNT value associated with a MAC SDU or MAC CE is included in the corresponding MAC sub-header or security information block. Alternatively, the low-order portion L of the COUNT value associated with a MAC PDU or TB is included in the MAC PDU or the DCI that schedules the MAC PDU. The receiver receives data (MAC SDU, MAC CE, MAC PDU, or TB) containing the low-order portions L of all COUNT values, reconstructs the current COUNT value based on the low-order portions L, and determines the continuity and uniqueness of the received data based on the recorded COUNT value.

[0201] Referring to Figure 18, the above-described method of determining the counter value based on the received low-order bits includes:

[0202] Step S1110: The receiving end determines the recorded maximum value of the counter and determines the low-order and high-order parts of the maximum value of the counter.

[0203] Step S1120: The receiving end determines the comparison result between the low-order part of the counter's maximum value and the received low-order part, and determines the high-order part of the counter's value based on the comparison result and the high-order part of the counter's maximum value.

[0204] In step S1130, the receiving end determines the value of the counter based on the received low-order part and the high-order part of the determined counter value.

[0205] The receiver maintains a variable RX_Highest, which represents the maximum COUNT value recorded (maximum counter value). The low-order part of RX_Highest is represented as L(RX_Highest), and the high-order part of RX_Highest is represented as H(RX_Highest).

[0206] Let the currently received low-order part be RCV_L, its corresponding high-order part be RCV_H, and the corresponding COUNT value be RCV_COUNT. The receiver compares L (RX_Highest) with RCV_L, calculates RCV_H based on the comparison result, and then reconstructs the COUNT value based on the received RCV_L and the calculated RCV_H.

[0207] Based on the comparison results, RCV_H is calculated, including at least one of the following:

[0208] If the result of subtracting the received low-order part from the low-order part of the maximum value of the counter is greater than the first preset value, then the high-order part of the value of the counter is determined to be equal to the high-order part of the maximum value of the counter plus 1.

[0209] If the result of subtracting the low-order part of the counter's maximum value from the received low-order part is greater than the second preset value, then the high-order part of the counter's value is determined to be equal to the high-order part of the counter's maximum value minus 1.

[0210] If the result of subtracting the received low-order part from the low-order part of the counter's maximum value is less than a first preset value, or if the result of subtracting the low-order part of the counter's maximum value from the received low-order part is less than a second preset value, then the high-order part of the counter's value is determined to be equal to the high-order part of the counter's maximum value.

[0211] The above judgment process can be represented as follows:

[0212] In other words, if the received low-order portion RCV_L is less than the low-order portion L(RX_Highest) of the maximum counter value recorded by the receiver minus the value K1, then the high-order portion RCV_H corresponding to the RCV_L value is considered equal to the high-order portion H(RX_Highest) of the maximum counter value plus 1. At this point, the reconstructed RCV_COUNT value is greater than RX_Highest, and the value of RX_Highest is updated to the value of RCV_COUNT, i.e.:

[0213] if (RCV_COUNT > RX_Highest)

[0214] RX_Highest = RCV_COUNT;

[0215] If the received low-order part RCV_L is greater than or equal to the low-order part L(RX_Highest) of the maximum counter value recorded by the receiver plus the value K2, then the high-order part RCV_H corresponding to the RCV_L value is considered to be equal to the high-order part H(RX_Highest) of the maximum counter value minus 1. At this time, the reconstructed RCV_COUNT value is less than RX_Highest.

[0216] If the above two judgment conditions are not met, then the high-order part RCV_H corresponding to the RCV_L value is considered to be equal to the high-order part H (RX_Highest) of the counter's maximum value.

[0217] The values ​​of K1 and K2 mentioned above are determined by the protocol or configured by the access network through signaling.

[0218] In some embodiments, the random number for the input parameters of the security processing is generated by the sender. A random number may be associated with a MAC SDU or MAC CE, or it may be associated with multiple MAC SDUs and / or MAC CEs, or a MAC PDU or a TB. Upon transmission, similar to the COUNT value, the sender includes this random number in the MAC PDU or DCI and sends it to the receiver. The receiver receives the MAC PDU or DCI and retrieves the random number. Therefore, in this embodiment, both the sender and receiver use this random number to perform security processing on the first data associated with it.

[0219] In some embodiments, the first value, periodically indicated by system messages, can be periodically indicated to the UE by the access network element via system messages. The access network element is responsible for periodically updating the first value, with the update period agreed upon by the protocol or configured by the access network element via signaling. Both the sending and receiving ends use the first value to perform secure processing on their associated first data. Furthermore, the first value can be combined with the radio resource number to form a combined input parameter for secure processing; for example, the first value constitutes the high-order part of the combined input parameter, and the radio resource number constitutes the low-order part.

[0220] In some embodiments, the second time-related value may be the time corresponding to the radio resources used by the MAC PDU or TB for security processing, and the second value may be determined based on part or all of this time. This time can be obtained as follows:

[0221] It is calculated based on the time value periodically indicated by the access network element in the system message; the time indicated by the system message is the time corresponding to a specific radio resource, such as the modification period, repetition period, radio frame, radio subframe, slot or symbol start time of the system message used to send the system message.

[0222] Alternatively, it can be determined based on the time values ​​corresponding to the radio resources obtained by the access network element and the UE respectively; for example, the time obtained by the access network element and the UE respectively by receiving satellite positioning and timing signals.

[0223] Similarly, part or all of the second time-related value can be combined with the radio resource number to form a combined input parameter for secure processing. For example, the second value constitutes the high-order part of the combined input parameter, and the radio resource number constitutes the low-order part of the combined input parameter.

[0224] The aforementioned radio resource number refers to the number of the radio resource used to transmit MAC PDUs or TBs. In practical use, it can be the radio resource's number in the time domain and / or its number in the frequency domain, or a combination of both as a combined input parameter for security processing. When combining, the time domain number and frequency domain number can be calculated using specific arithmetic operations (e.g., addition / subtraction / multiplication / modulo / integer division) or logical operations (e.g., binary AND / OR / XOR, etc.), and the result is used as the combined input parameter. Alternatively, the time domain number and frequency domain number can be used to form the high-order and low-order parts of a combined input parameter, respectively.

[0225] Understandably, if a radio resource contains multiple time resources or multiple frequency resources, then the radio resource number may be the number of one of the time resources or one of the frequency resources contained in that radio resource. Similarly, the input parameters can be determined in the manner described above. For example, if a radio resource contains multiple symbols in the time domain, then the first or last symbol among the multiple symbols is used to calculate the combined input parameters. Or, if a radio resource contains multiple radio resource blocks in the frequency domain, then the first or last frequency resource block or the frequency resource block with the highest or lowest frequency among the multiple radio resource blocks is used to calculate the combined input parameters.

[0226] The time domain numbering mentioned above refers to the numbering of radio resources within a specific time period and at a specific time domain resource level. The frequency domain numbering mentioned above refers to the numbering of radio resources within a specific frequency domain resource segment.

[0227] The specific time period includes, but is not limited to, at least one of the following:

[0228] The time period corresponding to a radio frame. For example, in an NR system, the length of a radio frame is 10 milliseconds, and the value of the SFN (system frame number) of the radio frame can be indicated on the radio interface.

[0229] A radio superframe corresponds to a time period, and a radio superframe contains one or more radio frames. For example, in an NR system, a radio superframe contains 1024 radio frames, and the hyper-SFN value of the radio access network can be indicated in a message for that radio superframe.

[0230] A radio superframe period corresponds to a time period, and one radio superframe period contains one or more radio superframes. For example, in an NR system, one radio superframe period contains 1024 radio superframes.

[0231] A radio subframe corresponds to a time period, and a radio frame may contain multiple radio subframes. For example, in an NR system, a radio frame may contain 10 radio subframes.

[0232] A slot corresponds to a time period. A radio frame may contain multiple slots, and a slot may contain multiple symbols.

[0233] Time-domain resource levels include, but are not limited to, at least one of the following:

[0234] Symbol level, meaning that the number is the number of the symbol where the radio resource is located within that time period;

[0235] Slot level, which means that the number is the number of the slot where the radio resource is located within the time period;

[0236] Radio subframe level, that is, the number is the number of the radio subframe where the radio resource is located within the time period;

[0237] Radio frame level, that is, the number is the number of the radio frame containing the radio resource within that time period;

[0238] Wireless superframe level, that is, the number is the number of the wireless superframe in which the wireless resource is located within this time period;

[0239] For example, the numbering of the time field can be determined using the following example:

[0240] Symbol-level numbering within a radio superframe period: Number T1 = (super-SFN of the radio superframe containing the radio resource multiplied by the number of radio frames in a radio superframe) + (SFN of the radio superframe containing the radio resource multiplied by the number of slots in a radio frame) + (the number of the slot containing the radio resource within the radio frame multiplied by the number of symbols in a slot) + the number of the symbol containing the radio resource (within the slot).

[0241] The frequency domain number may include a combination of one or more of the following values:

[0242] The number of the wireless resource within its respective BWP (Bandwidth Part);

[0243] The number of the wireless resource within its serving cell;

[0244] The radio resource is numbered within the bandwidth comprised of all BWPs configured for the UE;

[0245] The radio resource number within the bandwidth comprised of all cells configured for the UE;

[0246] The number of the radio resource within the bandwidth comprised of all serving cells in the cell group it belongs to;

[0247] The number of the radio resource within the bandwidth comprised of all BWPs in the cell group;

[0248] The above numbering can also be combined with the following resource numbering to form frequency domain numbering:

[0249] The ID, index, or identifier of the cell group where the wireless resource is located;

[0250] The ID, index, or identifier of the serving cell where the wireless resource is located;

[0251] The BWP ID, index, or identifier of the BWP where the wireless resource is located;

[0252] The frequency domain numbering mentioned above may be at the radio block level. A radio block contains a segment of frequency resources. Within a frequency domain bandwidth resource, the radio block numbering can be obtained by sorting the radio blocks in descending order of frequency. That is, the radio block numbering is determined by the frequency sorting order, and thus the frequency domain numbering is determined.

[0253] For example, the frequency domain number can be determined using the following example:

[0254] Number T2 = [Cell group ID of the radio resource, serving cell index, BWP ID, radio resource number within the BWP];

[0255] Number T2 is 16 bits. The above values ​​constitute different parts of the frequency domain number. For example, the cell group ID where the radio resource is located occupies 2 bits, the serving cell index occupies 4 bits, the BWP ID occupies 2 bits, and the number of the radio resource within its BWP occupies 8 bits.

[0256] The aforementioned methods for determining input parameters replace traditional methods for determining input parameters in the PDCP layer. For example, a COUNT value space can be associated with a logical channel, DRB, SRB, or MAC entity. COUNT values ​​can be associated with MAC SDU, MAC CE, MAC PDU, or TB, and the COUNT value serves as one of the input parameters for security processing. Unlike traditional methods using COUNT values, this application proposes a new method for associating COUNT values ​​and a method for the receiver to determine the high-order bits of the COUNT value.

[0257] Furthermore, embodiments of this application also provide a method for using a radio resource number, the time value corresponding to the radio resource, a random number, a system message indication value, or a combination thereof as input parameters for security processing. This method provides a way to use different input parameters for different security processing objects. For example, within a time period, the radio resource number is unique and can therefore be used as an input parameter for security processing.

[0258] This application also provides a method for generating the first key. To easily distinguish it from the key at the PDCP layer, this application refers to the first key applied to the MAC layer or physical layer as the low-layer key. The low-layer key can be an encryption / decryption key, an integrity protection / verification key, or a control plane / user plane key (including encryption / decryption and integrity protection / verification, respectively).

[0259] The encryption / decryption key may be used for encryption / decryption of MAC SDU, MAC CE, MAC PDU, or TB;

[0260] The integrity protection / verification key may be used for the integrity protection / verification of MAC SDU, MAC CE, MAC PDU or TB;

[0261] For control plane keys, they may be used for secure processing (encryption / decryption and / or integrity protection / verification) of MAC CE or MAC SDU containing RLC control PDU or PDCP control PDU;

[0262] For user plane keys, they may be used for secure processing (encryption / decryption and / or integrity protection / verification) of MAC SDUs containing RLC data PDUs or PDCP data PDUs;

[0263] The lower-layer key is derived from a key K of the access network element. In this embodiment, the lower-layer key K is derived based on a preset key K0 and a value C. The access network element indicates the value C to the UE via RRC messages, MAC PDUs, or DCIs. The value C is an integer. The derivation algorithm is set according to actual requirements, and the preset key K0 is selected differently depending on the application scenario: in the NR system, the preset key K0 is K. gNB If the access network element is the SN in the MR-DC configuration, then the default key K0 is K. sn If the access network element is a 6G system base station, then the preset key K0 is the K key in the 6G wireless network. 6g-NB .

[0264] The access network element indicates the value of C to the UE, which is used by the UE to derive the lower-layer key K. The RRC message indicating the value C may include an RRC reconfiguration message, an RRC resume message, or an RRC reestablishment message.

[0265] The value C indicated by the access network element can be associated with the configuration of one or a group of MAC entities. This value C is used to derive the key used by the MAC entity for security processing, or to derive the key used by the physical layer associated with the MAC entity for security processing. Additionally, the value C indicated by the access network element can also be associated with one or a group of serving cells, one or a group of transmit / receive points, or one or a group of BWPs.

[0266] After receiving the value C, if the saved value C is different from the currently received value C, the UE will derive a new lower-level key (first key) based on the currently received value C.

[0267] After updating or deriving a new preset key K0, the UE derives a new lower-level key (first key) based on the new preset key K0.

[0268] In an architecture where CU and DU are separated, an access network element is divided into two parts: CU and DU. This embodiment assumes that the MAC layer and physical layer are located in the DU, and the method for deriving lower-layer keys from the DU is given below. The security processing method of this application also includes:

[0269] When the CU establishes a context for the UE, the DU establishes a context for the UE, the UE performs a handover between DUs, or the CU updates the preset key K0 or value C for the UE, the value C is determined or updated, and a new first key K is derived based on the preset key K0 and value C.

[0270] CU sends the first key and the value C to DU so that DU can derive a new key based on the first key and the value C, or CU can derive a new key based on the first key and the value C and send the new key to DU.

[0271] In some embodiments, if decryption of received encrypted data fails or integrity verification of received integrity-protected data fails, the protocol entity performing the security processing is reset, and / or a failure indication is sent to the upper-layer protocol entity.

[0272] Specifically, security processing failures include failures to decrypt encrypted data or failures to verify the integrity of data under integrity protection. Following a failure, at least one of the following operations must be performed:

[0273] Reset the protocol entities that perform security processing, including MAC entities;

[0274] The failure indication is sent to the upper-layer protocol entity, such as the RLC layer, PDCP layer, or RRC layer.

[0275] When a MAC entity is reset, it can reset variables related to security processing maintained by the MAC entity, such as resetting the COUNT value.

[0276] In summary, this application provides a solution for secure data processing at the MAC or PHY layer, which is more comprehensive than the current 3GPP technology that only performs secure data processing at the PDCP layer. This solution helps to achieve comprehensive security protection in 3GPP radio access networks by determining the first data that needs to be securely processed at the MAC or PHY layer, performing secure processing on the first data, and then sending the securely processed first data out.

[0277] The security handling methods of this application will be explained in detail below with specific examples.

[0278] Example 1: Perform security processing individually for each MAC SDU or MAC CE

[0279] In this example, each MAC SDU or MAC CE that requires security processing is processed independently, and the security-processed MAC SDU or MAC CE, along with the corresponding MAC sub-header, is included in the MAC PDU.

[0280] Referring to Figure 19, which includes multiple MAC CEs and multiple MAC SDUs, it is determined that MAC CE1 and MAC SDU2 need to be encrypted and protected for integrity.

[0281] The MAC sub-header corresponding to MAC CE1 indicates that encryption and integrity protection have been implemented, and the integrity protection information is included in the corresponding MAC sub-PDU. Similarly, the MAC sub-header corresponding to MAC SDU2 indicates that encryption and integrity protection have been implemented, and the integrity protection information is included in the corresponding MAC sub-PDU. The corresponding MAC sub-header may also indicate information used for decryption and / or integrity verification, such as key information used for secure processing, algorithm information used, and input parameters for secure processing.

[0282] There is no encryption or integrity protection for MAC CE2 and MAC CE3, so their MAC subPDUs only contain the MAC subheader and themselves.

[0283] As can be seen in this example, MAC CEs or MAC SDUs that have undergone security processing and those that have not can be interleaved.

[0284] Referring to Figure 20, which includes multiple MAC CEs and multiple MAC SDUs, it is determined that MAC CE1 and MAC SDU2 need to be encrypted and protected for integrity.

[0285] The difference from Figure 19 is that the MAC PDU contains a shared security information block, which contains security processing information shared by the MAC SDU or MAC CE contained in the MAC PDU, including one or more of the security processing input parameters, algorithm information, key information, etc.

[0286] The shared security information block is applicable when performing security processing on a MAC SDU or MAC CE contained in a MAC PDU. If some security processing information is shared, it can be indicated through the shared security information block, which helps to reduce the space occupied by security processing information in the MAC PDU.

[0287] The shared security information block can be implemented as at least one of the following:

[0288] A MAC subPDU containing a specific type of MAC CE; in this case, security processing information such as key information, algorithm information, security processing input parameters, and integrity protection information may be included in the MAC subheader of the MAC subPDU.

[0289] A specific type of MAC CE; in this case, security processing information such as key information, algorithm information, security processing input parameters, and integrity protection information may be included in the MAC CE.

[0290] Example 2: Safe handling of data blocks

[0291] In this example, one or more MAC SDUs and / or MAC CEs that require security processing are concatenated (arranged sequentially), the concatenated data blocks are security processed, and the security-processed data blocks are included in a MAC PDU.

[0292] Referring to Figure 21, a security information block corresponds to each data block. Some or all of the information in the security information block is applicable to a data block after security processing. Each data block contained in the MAC PDU corresponds to a security information block, which is applicable to scenarios where different security processing information is used for different data blocks.

[0293] It was determined that data block 1, consisting of MAC subPDU including MAC CE1 and MAC subPDU including MAC CE2, requires security processing, as does data block 2 consisting of MAC subPDU including MAC SDU. This security processing includes encryption and integrity protection.

[0294] The aforementioned data block 1 is encrypted and its integrity is protected to obtain secure data 1, and the aforementioned data block 2 is encrypted and its integrity is protected to obtain secure data 2. Thus, the MAC PDU contains secure data 1 and secure data 2. Each securely processed data in the MAC PDU is preceded by a corresponding security information block (security information block 1 and security information block 2, respectively); each securely processed data in the MAC PDU is also preceded by corresponding integrity protection information (integrity protection information 1 and integrity protection information 2, respectively).

[0295] The aforementioned security information block can be a MAC sub-header, and the security-processed data constitutes a MAC SDU or a MAC CE. The MAC CE or MAC SDU may be of variable length; the MAC CE may correspond to a specific MAC CE type or LCID, and the MAC SDU may correspond to a specific logical channel LCID. The MAC CE or MAC SDU is used to carry the security-processed data within a MAC PDU. In one possible scenario, the MAC sub-header as a security information block and the security-processed data can constitute a MAC subPDU; alternatively, the MAC sub-header as a security information block, the security-processed data, and separately placed integrity protection information can all constitute a MAC subPDU.

[0296] Referring to Figure 22, the security information block is shared by multiple data blocks, and the information indicated by the shared security information block is applicable to all security-processed data blocks in a MAC PDU.

[0297] It was determined that data block 1, consisting of MAC subPDU including MAC CE1 and MAC subPDU including MAC CE2, requires security processing, as does data block 2 consisting of MAC subPDU including MAC CE3. This security processing includes encryption and integrity protection.

[0298] Data block 1 is encrypted and its integrity is protected to obtain secure data 1, and data block 2 is encrypted and its integrity is protected to obtain secure data 2. Thus, the MAC PDU contains secure data 1 and secure data 2. The MAC PDU contains a shared security information block indicating the security processing information for data block 1 and data block 2.

[0299] The aforementioned security information block may be a MAC subPDU containing a specific type of MAC CE. The information contained in the security information block may include one or more of the following: input information for security processing, key information, algorithm information, etc.

[0300] Example 3: In a special case, the MAC PDU does not contain a security information block, but only a data block that has been security processed and integrity protection information.

[0301] Referring to Figure 23, it is determined that the data block composed of MAC subPDU including MAC CE1, MAC subPDU including MAC CE2, and MAC subPDU including MAC SDU needs to be subject to security processing, which includes encryption and integrity protection processing.

[0302] The key information and algorithm information used in security processing are configured through signaling and instructed to the UE by the access network element.

[0303] The input parameters used for security processing are determined by the protocol or refer to the input parameters illustrated in the above embodiments.

[0304] The length of the securely processed data block is determined as follows: the length of the received TB / the length of the MAC PDU is subtracted from the length of the integrity protection information agreed upon by the protocol. The result is the length of the securely processed data block.

[0305] This application also provides a controller, including at least one processor and a memory for communicatively connecting to the at least one processor; the memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, enable the at least one processor to perform the security processing method of the foregoing embodiments.

[0306] Referring to Figure 24, an example is taken where the processor 1001 and memory 1002 in the controller 1000 can be connected via a bus. The memory 1002, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs and non-transitory computer-executable programs. Furthermore, the memory 1002 may include high-speed random access memory, and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, the memory 1002 may optionally include memory remotely located relative to the processor 1001, and these remote memories can be connected to the controller 1000 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0307] Those skilled in the art will understand that the device structure shown in FIG24 does not constitute a limitation on the controller 1000, and may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0308] This application also provides a computer-readable storage medium storing computer-executable instructions that are executed by one or more processors, for example, by one of the processors 1001 in FIG24, which can cause the one or more processors to perform the security processing method in the above method embodiment.

[0309] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.

[0310] This application also provides a communication device, including the controller 1000 described above.

[0311] It will be understood by those skilled in the art that all or some of the steps and systems in the methods disclosed above can be implemented as software, firmware, hardware, and suitable combinations thereof. Some or all of the physical components can be implemented as software executed by a processor, such as a central processing unit, digital signal processor, or microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, which can include computer storage media (or non-transitory media) and communication media (or transient media). As is known to those skilled in the art, the term computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disc (DVD) or other optical disc storage, magnetic cartridges, magnetic tape, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible to a computer. Furthermore, as is known to those skilled in the art, communication media typically contain computer-readable instructions, data structures, program modules, or other data in modulated data signals such as carrier waves or other transmission mechanisms, and may include any information delivery medium.

[0312] The above is a detailed description of the preferred embodiments of this application. However, this application is not limited to the above embodiments. Those skilled in the art can make various equivalent modifications or substitutions without departing from the essence of this application. All such equivalent modifications or substitutions are included within the scope defined by the claims of this application.

Claims

1. A method for securely processing data, comprising: The first data that needs to be processed for security purposes is determined, and the first data includes media access control layer data or physical layer data. Perform security processing on the first data; Send the first data after the security processing.

2. The method according to claim 1, wherein, The first data includes a Media Access Control Service Data Unit (MAC SDU) and / or a Media Access Control Unit (MAC CE); the first data used to determine that security processing is required includes at least one of the following: Based on the first instruction information in the signaling or the first agreement content of the protocol, the first data that needs to be processed securely is the MAC SDU transmitted on the designated logical channel; Based on the second instruction information in the signaling or the second agreement in the protocol, the first data requiring security processing is determined to be a specified type of MAC CE. The first data that needs to be security processed is determined to be a MAC SDU containing a Protocol Data Unit (PDU) of a specified type, based on the third instruction information in the signaling or the third agreement content of the protocol. The first data that needs to be processed for security purposes, as determined by the fourth instruction information of the upper-layer protocol entity, is the MAC SDU sent by the upper-layer protocol entity this time.

3. The method according to claim 2, wherein, The designated logical channel is indicated by the logical channel identifier, data radio bearer (DRB) identifier, or signaling radio bearer (SRB) identifier in the first indication information or the first agreed content. The specified type of MAC CE is indicated by the logical channel identifier corresponding to the MAC CE in the second indication information or the second agreed content; The specified type of protocol data unit is indicated by the third indication information or the third agreement content, and the specified type of protocol data unit includes RLC control PDU and / or PDCP control PDU.

4. The method according to claim 1, wherein, The first data includes MAC SDU and / or MAC CE; The security processing method further includes: Generate security processing information corresponding to the aforementioned security processing; Sending the first data after the security processing includes: The first data after the security processing and the security processing information are included in the Media Access Control Protocol Data Unit (MAC PDU); Send the MAC PDU.

5. The method according to claim 4, wherein, The MAC PDU includes one or more Media Access Control Sub-Protocol Data Units (MAC subPDUs), wherein at least one of the MAC subPDUs includes a MAC SDU or MAC CE that has undergone the security processing.

6. The method according to claim 5, wherein, The MAC subPDU also includes a Media Control Access Subheader (MAC subheader); including the security processing information in the MAC PDU includes: At least a portion of the security processing information is indicated in the MAC sub-header corresponding to the first data after the security processing. Alternatively, a shared security information block may be set in the MAC PDU, indicating at least a portion of the security processing information shared by multiple sets of the first data after the security processing.

7. The method according to claim 6, wherein, The at least part of the security processing information indicated in the MAC sub-header corresponding to the first data after the security processing includes: The first part of the security processing information is indicated in the MAC sub-header corresponding to the first data after the security processing, and / or the second part of the security processing information is indicated in the MAC subPDU corresponding to the first data after the security processing; Alternatively, the second part of the security processing information may be indicated in the MAC sub-header corresponding to the first data after the security processing, and / or the first part of the security processing information may be indicated in the MAC subPDU corresponding to the first data after the security processing; Alternatively, the entirety of the security processing information may be indicated in the MAC sub-header corresponding to the first data after the security processing.

8. The method according to claim 6, wherein, The provision in the shared security information block indicating at least a portion of the security processing information shared by multiple first data after the security processing includes: The first part of the security processing information is indicated in the shared security information block, and the second part of the security processing information is indicated in the MAC subPDU corresponding to the first data after the security processing. Alternatively, the second part of the security processing information may be indicated in the shared security information block, and the first part of the security processing information may be indicated in the MAC subPDU corresponding to the first data after the security processing. Alternatively, the entirety of the security processing information may be indicated in the shared security information block.

9. The method according to claim 8, wherein, The shared security information block is a MAC subPDU containing a specific type of MAC CE, and at least a portion of the security processing information is contained in the MAC sub header of the MAC subPDU containing the specific type of MAC CE. Alternatively, the shared security information block may be a specific type of MAC CE, which contains at least a portion of the security processing information.

10. The method according to claim 1, wherein, The first data includes MAC SDU and / or MAC CE; the security processing method further includes: At least a portion of the security processing information corresponding to the security processing is agreed upon through signaling configuration or protocol.

11. The method according to claim 10, wherein, At least a portion of the security processing information corresponding to the security processing agreed upon through signaling configuration or protocol includes: The first part of the security processing information is specified by signaling configuration or protocol, and the second part of the security processing information is indicated in the MAC subPDU corresponding to the first data after the security processing.

12. The method according to any one of claims 4 to 11, wherein, The first data is a MAC SDU or MAC CE; or, the first data is a data block composed of multiple MAC SDUs or MAC CEs connected in series or a data block composed of multiple MAC subPDUs containing MAC SDUs or MAC CEs connected in series.

13. The method according to claim 7, 8 or 11, wherein, The first part includes at least one of security status indication information, key information, algorithm information, and input parameters of the security process; the second part includes at least one of integrity protection information, key information, algorithm information, and input parameters of the security process.

14. The method according to claim 13, wherein, The security processing status indication information includes at least one of the following: The first information is used to indicate whether the first data has been encrypted and / or protected for integrity. The second piece of information is used to indicate whether the MAC PDU contains integrity protection information for the first data. The logical channel identifier of the logical channel or the logical channel identifier of the MAC CE is used to indicate whether the first data has been encrypted and / or protected. The third piece of information is used to indicate whether the first data has been encrypted and / or protected for integrity according to the default processing method of the logical channel or MAC CE type to which it belongs.

15. The method according to claim 1, wherein, The first data is physical layer data; the first data that is determined to require security processing includes at least one of the following: The user terminal (UE) is instructed to perform secure processing on the first data of the current transmission schedule by dynamic scheduling signaling. The identifier of the DRB or the logical channel identifier of the logical channel is indicated by Radio Resource Control (RRC) signaling or MAC CE. Secure processing is performed on data transmitted through designated radio resources via RRC signaling or MAC CE instructions. These designated radio resources include semi-statically configured radio resources and / or semi-persistently configured radio resources.

16. The method according to claim 15, wherein, The step of instructing the user terminal (UE) to perform secure processing on the first data of the current transmission schedule via dynamic scheduling signaling includes: The access network element instructs the UE in the downlink control information (DCI) that schedules uplink transmissions so that the UE can encrypt and / or protect the integrity of the first data in the current transmission schedule. The access network element indicates security processing status information in the DCI that schedules downlink transmission, so that the UE can decrypt and / or verify the integrity of the received data according to the security processing status information.

17. The method according to claim 15, wherein, The identifier of the DRB requiring security processing, indicated by Radio Resource Control (RRC) signaling or MAC CE, or the logical channel identifier of the logical channel, includes: Access network elements instruct the UE via RRC signaling or MAC CE to encrypt and / or protect the integrity of data containing a specified DRB or a specified logical channel during uplink transmission, and to indicate security processing status information in the uplink control information (UCI) of uplink transmission. The access network element indicates security processing status information in the DCI that schedules downlink transmission, so that the UE can decrypt and / or verify the integrity of the received data according to the security processing status information.

18. The method according to claim 15, wherein, The security processing of designated radio resources via RRC signaling or MAC CE indication includes: The access network element instructs the UE via RRC signaling or MAC CE to encrypt and / or protect the integrity of data transmitted using the specified radio resources during uplink transmission; The access network element instructs the UE via RRC signaling or MAC CE to decrypt and / or verify the integrity of the received data when the UE receives downlink data using the specified radio resources.

19. The method according to any one of claims 16 to 18, wherein, The status information of the security processing includes at least one of the following: First status information used to indicate whether encryption has been performed; Second status information used to indicate whether integrity protection processing has been performed; Integrity protection information; Input parameters for security processing.

20. The method according to claim 1, wherein, The security processing includes encryption processing and / or integrity protection processing; the method further includes: If decryption of received encrypted data fails, or integrity verification of received integrity-protected data fails, the protocol entity performing the security processing is reset, and / or a failure indication is sent to the upper-layer protocol entity.

21. The method according to claim 1, wherein, The security processing information includes input parameters used to perform security processing on the first data; the input parameters include at least one of the following: The first key includes keys used for encryption and decryption, and / or keys used for integrity protection and integrity verification; The transmission direction indication information is used to indicate uplink and downlink transmissions.

22. The method according to claim 21, wherein, The input parameters also include at least one of the following or a combination of at least one of the following: Channel identification information, wherein the channel identifier represents the channel to which the first data belongs; The value of the counter, which is used in conjunction with the first key for encryption and decryption; A random number, generated by the sending end and associated with the first data, is used to instruct the sending end and the receiving end to perform secure processing according to the random number; The identification of a radio resource includes its identification in the time domain and / or its identification in the frequency domain. The first value is indicated periodically by system messages; The second value associated with time.

23. The method according to claim 22, wherein, When the first data is a single MAC SDU, the channel identification information is the logical channel identifier, DRB identifier, or SRB identifier of the logical channel corresponding to the MAC SDU. When the first data is a single MAC CE, the channel identification information is the logical channel identifier of the MAC CE; When the first data is a data block composed of multiple MAC SDUs and / or MAC CEs connected in series, the channel identification information is a preset value agreed upon by the protocol or indicated by the access network element through signaling, or the channel identification of the transmission channel corresponding to the MAC PDU. When the first data is a MAC PDU or a transport block TB, the channel identification information is the channel identifier of the transport channel or physical channel corresponding to the MAC PDU.

24. The method according to claim 22, wherein, Sending the first data after the security processing includes: When the first data is a single MAC SDU, the transmitting end associates a counter variable with the logical channel corresponding to the MAC SDU; when the MAC SDU is transmitted through the logical channel corresponding to the MAC SDU, the value of the counter is set to the value of the counter variable, and the value of the counter variable is incremented by 1; When the first data is a single MAC CE, the sending end associates a counter variable with the type of the MAC CE; when sending the MAC CE of the type of the MAC CE, the value of the counter is set to the value of the counter variable, and the value of the counter variable is incremented by 1; When the first data is a data block, MAC PDU, or TB composed of multiple MAC SDUs and / or MAC CEs connected in series, the sending end associates a counter variable with the MAC entity; when the data block, MAC PDU, or TB is sent to the MAC entity, the value of the counter is set to the value of the counter variable, and the value of the counter variable is incremented by 1.

25. The method according to claim 24, wherein, The transmitting end carries the value of the counter in the MAC PDU, DCI, or UCI, and the receiving end determines the value of the counter based on the received MAC SDU, MAC CE, MAC PDU, or TB. Alternatively, the transmitting end carries the low-order portion of the counter value in a MAC PDU, DCI, or UCI, and the receiving end determines the low-order portion based on the received MAC SDU, MAC CE, MAC PDU, or TB, and determines the counter value based on the received low-order portion, wherein the low-order portion consists of a plurality of least significant bits of the counter value.

26. The method of claim 25, wherein, Determining the value of the counter based on the received low-order portion includes: The receiving end determines the recorded maximum value of the counter, and determines the low-order and high-order parts of the maximum value of the counter; The receiving end determines the comparison result between the low-order part of the maximum value of the counter and the received low-order part, and determines the high-order part of the value of the counter based on the comparison result and the high-order part of the maximum value of the counter; The receiving end determines the value of the counter based on the received low-order part and the high-order part of the determined counter value.

27. The method according to claim 26, wherein, Determining the high-order portion of the counter value based on the comparison result and the high-order portion of the counter's maximum value includes at least one of the following: If the result of subtracting the received low-order part from the low-order part of the maximum value of the counter is greater than the first preset value, then the high-order part of the value of the counter is determined to be equal to the high-order part of the maximum value of the counter plus 1; If the result of subtracting the low-order part of the maximum value of the counter from the received low-order part is greater than the second preset value, it is determined that the high-order part of the value of the counter is equal to the high-order part of the maximum value of the counter minus 1. If the result of subtracting the received low-order part from the low-order part of the maximum value of the counter is less than the first preset value, or if the result of subtracting the low-order part from the low-order part of the maximum value of the counter is less than the second preset value, then the high-order part of the value of the counter is determined to be equal to the high-order part of the maximum value of the counter.

28. The method according to claim 22, wherein, The second time-related value is the time value corresponding to the wireless resources used by the first data; the time value corresponding to the wireless resources is determined by at least one of the following methods: It is calculated based on the time value periodically indicated by the access network element in the system message; The time value corresponding to the radio resource is determined based on the time value obtained by the access network element and the UE, respectively.

29. The method according to claim 21, wherein, The first key is derived by the access network element based on a preset key K0 and a value C. The access network element indicates the value C to the UE via an RRC message, MAC PDU, or DCI. The preset key K0 is K. gNB K sn or K 6g-NB The value C is an integer.

30. The method according to claim 29, wherein, The method further includes at least one of the following: After receiving the value C, if the saved value C is different from the currently received value C, the UE derives a new first key based on the currently received value C. After updating or deriving a new preset key K0, the UE derives a new first key based on the new preset key K0.

31. The method according to claim 30, wherein, When the access network includes a centralized unit (CU) and a distributed unit (DU), the method further includes: When the CU establishes a context for the UE, the DU establishes a context for the UE, the UE undergoes a handover between DUs, or the CU updates the preset key K0 or the value C for the UE, the value C is determined or updated, and a new first key is derived based on the preset key K0 and the value C. The CU sends the first key and the value C to the DU, so that the DU can derive a new key based on the first key and the value C, or the CU can derive a new key based on the first key and the value C and send the new key to the DU.

32. A controller comprising at least one processor and a memory for communicatively connecting to the at least one processor; the memory storing instructions executable by the at least one processor to enable the at least one processor to perform the security processing method as claimed in any one of claims 1 to 31.

33. A communication device comprising the controller as described in claim 32.