WO2018090339A1 - 无线通信方法、装置及通信设备 - Google Patents
无线通信方法、装置及通信设备 Download PDFInfo
- Publication number
- WO2018090339A1 WO2018090339A1 PCT/CN2016/106451 CN2016106451W WO2018090339A1 WO 2018090339 A1 WO2018090339 A1 WO 2018090339A1 CN 2016106451 W CN2016106451 W CN 2016106451W WO 2018090339 A1 WO2018090339 A1 WO 2018090339A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- information
- data
- signaling
- setting
- sent
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
Definitions
- the present application relates to the field of wireless technologies, and in particular, to a wireless communication method, apparatus, and communication device that can implement communication security.
- Any communication device can join the wireless communication system as long as it complies with the corresponding wireless communication standard, and communicate with other communication devices on the corresponding physical channel.
- the information transmitted in the wireless communication system is not protected, so that any communication device that complies with the corresponding wireless communication standard can listen on the corresponding physical channel, and the communication information is stolen. Information leaks.
- the application provides a wireless communication method, device and communication device, which can ensure the security of wireless communication.
- a first aspect of the present application provides a wireless communication method, including: a communication device extracts setting part information in information to be transmitted; and using the set part information as an initial vector, performing other part information in the to-be-sent information Encrypting; generating new to-be-sent information by using the setting part information and the encrypted other part information; and transmitting the new to-be-sent information.
- the setting part information is check data and/or signaling in the to-be-sent information.
- the information to be sent is signaling
- the setting part information is verification data of the signaling
- the other part information is signaling content of the signaling
- the information to be sent is voice Calling information
- the setting part information is a voice header frame and/or a voice ending frame in the voice call information
- the other part information is a voice frame in the voice call information
- the to-be-sent information is Data service information
- the setting part information is a data header frame and/or a data end frame of the data service information
- the other part information is a data frame of the data service information.
- the method further includes: performing encryption processing on the setting part information according to the setting encryption rule.
- the data is used to calculate other part of the information to be transmitted, and the operation result is used as the encrypted other part information.
- a second aspect of the present application provides a wireless communication method, including: a communication device extracts setting part information in received information; and using the set part information as an initial vector, performing other part information in the received information. Decryption; processing new received information consisting of the set partial information and the decrypted other partial information.
- the setting part information is verification data and/or signaling in the received information.
- the received information is signaling
- the setting part information is check data of the signaling
- the other part information is signaling content of the signaling
- the pair is set by the Processing the new received information consisting of the partial information and the decrypted other partial information, including: generating new verification data from the decrypted signaling content; comparing the verification data and the information in the signaling Whether the new check data is the same; if the same, generating new signaling from the check data and the decrypted signaling content, and responding to the new signaling; otherwise discarding the signaling.
- the received information is voice call information
- the set part information is a voice header frame and/or a voice end frame in the voice call information
- the other part information is voice in the voice call information. frame.
- the received information is data service information
- the set part information is a data header frame and/or a data end frame of the data service information
- the other part information is a data frame of the data service information
- Processing the new received information consisting of the setting part information and the decrypted other part information comprising: generating new check data from the decrypted data frame; comparing the decrypted Whether the check data in the data frame is the same as the new check data; if the same, the decrypted new data service information is processed; otherwise, the data service information is discarded.
- the method further includes: performing decryption processing on the set part information according to a set decryption rule.
- the decrypting the other part of the received information by using the set part information as an initial vector includes: using the set part information as an initial vector, according to setting a decryption formula and setting The data is used to calculate other part of the information to be transmitted, and the operation result is used as the decrypted other part information.
- the third aspect of the present application provides a wireless communication apparatus, including: an extraction module, configured to extract setting part information in information to be sent; and an encryption module, configured to use the set part information as an initial vector, to The other part of the information is sent to be encrypted; the generating module is configured to generate a new to-be-sent information by using the set part information and the encrypted other part information; and the sending module is configured to send the new to-be-sent information.
- a fourth aspect of the present disclosure provides a wireless communication apparatus, including: an extracting module, configured to extract setting part information in received information; and a decrypting module, configured to use the set part information as an initial vector, and the Receiving other part of the information for decryption; and processing module for processing the new received information consisting of the set part information and the decrypted other part of the information.
- a fifth aspect of the present application provides a communication device including a transmitter, a memory, and a processor; the memory is configured to store computer instructions configured to be executed by the processor; the processor executes the computer instructions, And: extracting the setting part information in the information to be sent; using the setting part information as an initial vector, encrypting other part of the information to be sent; using the setting part information and the encrypted part The other part of the information generates new to-be-sent information; the new to-be-sent information is sent by the sender.
- a sixth aspect of the present application provides a communication device including a receiver, a memory, and a processor; the memory is configured to store computer instructions configured to be executed by the processor; the processor executes the computer instructions, Extracting: setting part information in the received information received by the receiver; using the set part information as an initial vector, decrypting other part of the received information; The new received information consisting of the partial information and the decrypted other partial information is processed.
- the communication device uses the setting information of the information to be transmitted or the received information as an initial vector to encrypt or decrypt other parts of the information, so the illegal device cannot steal the information transmitted in the wireless communication system and transmits the information.
- the message cannot obtain the correct response of the wireless communication system, thereby ensuring the security of the wireless communication and avoiding information interference of the illegal device.
- the communication device directly uses part of the information of the information to be transmitted as the initial vector for encryption, no additional is needed. The initial vector, so there is no need to increase the air interface overhead.
- FIG. 1 is a schematic structural diagram of an embodiment of a wireless communication system according to the present application.
- FIG. 3 is a block diagram showing a communication flow of an application scenario of the embodiment shown in FIG. 1;
- FIG. 4 is a block diagram showing a communication flow of another application scenario of the embodiment shown in FIG. 1;
- FIG. 5 is a flowchart of another embodiment of a wireless communication method of the present application.
- FIG. 6 is a block diagram showing a communication flow of an application scenario of the embodiment shown in FIG. 5;
- FIG. 7 is a block diagram showing a communication flow of another application scenario of the embodiment shown in FIG. 5;
- FIG. 8 is a schematic structural diagram of an embodiment of a wireless communication device according to the present application.
- FIG. 9 is a schematic structural diagram of another embodiment of a wireless communication device according to the present application.
- FIG. 10 is a schematic structural diagram of an embodiment of a communication device according to the present application.
- the wireless communication system can be based on devices such as digital mobile radio (English: Digital Mobile) Radio, abbreviation: DMR), police digital cluster (English Police Digital Trunking, abbreviated as: PDT), a system for communicating by wireless communication standards, the communication mode may be a direct mode, a transit mode or a cluster mode, and the direct mode means that devices communicate directly through a wireless channel; the transit mode means that information sent by the device needs to pass The relay station forwards to other devices; in cluster mode, the information sent by the device needs to be forwarded to other devices through the system or base station.
- DMR Digital Mobile Radio
- PDT police digital cluster
- the communication mode may be a direct mode, a transit mode or a cluster mode, and the direct mode means that devices communicate directly through a wireless channel; the transit mode means that information sent by the device needs to pass The relay station forwards to other devices; in cluster mode, the information sent by the device needs to be forwarded to other devices through the system or base station.
- FIG. 1 is a schematic structural diagram of an embodiment of a wireless communication system according to the present application.
- the wireless communication system 10 includes a plurality of communication devices 11, 12, and a plurality of base stations 13, 14 (FIG. 1 exemplarily shows only two communication devices and base stations, but actually a wireless communication system The number of communication devices and base stations in the medium is not limited and can be set according to actual needs).
- the communication devices 11, 12 are connected to the cluster core network 15 through the base stations 13, 14, and the cluster core network 15 can be used for mobility management and call management.
- the communication devices in the wireless communication system 10 can communicate wirelessly through a base station and a cluster core network, such as a call, data interaction, and the like.
- the communication device can be any device capable of wireless communication, such as a mobile phone, a computer, or the like.
- the communication devices 11, 12 encrypt the information when transmitting the information, and decrypt the information when the information is received to ensure the security of the wireless communication of the system 10.
- the system 10 is provided with a unified internal encryption standard, and the communication device joining the system 10 acquires the internal encryption standard, and correctly adds the communication information according to the standard. Decryption processing to ensure effective communication within the system.
- the communication information in the system cannot be correctly encrypted/decrypted, thereby avoiding illegal stealing. Communication information within the system or sending information to the system to ensure the security of the internal communication of the system.
- the encryption/decryption processing of the communication device in the system when transmitting and receiving information should refer to the following embodiments.
- FIG. 2 is a flowchart of an embodiment of a method for wireless communication according to the present application.
- the method is performed by a communication device in a wireless communication system for encrypting information when transmitting information.
- the method includes:
- S201 The communication device extracts the setting part information in the to-be-sent information.
- the communication device needs to transmit data to other communication devices of the wireless communication system
- the original to-be-sent information is generated, and the set portion information is extracted from the information to be transmitted according to the internal encryption standard of the system in which it is located.
- the system internal encryption standard may set any part of the to-be-sent information as the setting part information according to actual communication requirements. Since the setting part information is used as an initial vector of encryption, in order to further ensure security of encryption, it is preferable to set non-sensitive and non-constant information of information to be transmitted as the setting part information, for example, in the information to be transmitted. Checking data and/or signaling. For different information to be sent, the check part and the signaling part are usually different, that is, each piece of information to be sent is encrypted differently, thus ensuring the variability of encryption, further Improve communication security.
- the signaling described in this application includes a voice link frame, a data link frame, a control signaling block, and the like.
- the voice link frame is a voice header frame and a voice end frame.
- the voice link frame is divided into embedded and non-embedded according to different setting manners, and the embedded voice link frame is divided into A plurality of parts are inserted into the speech frame, and the non-embedded voice link frame, that is, the voice link frame is disposed in front of or behind the voice frame as a whole;
- the data link frame is a data header frame and a data end frame.
- the communication device uses the set part information as an initial vector to encrypt other part of the information to be sent.
- the communication device uses the extracted setting portion information as an initial vector, and performs calculation on other parts of the information to be transmitted according to the setting encryption formula and the setting data, and uses the operation result as the encrypted other part information.
- the setting encryption formula can be an existing encryption algorithm or a custom arbitrary operation formula.
- the communication device can determine the set encryption formula and the setting data according to the internal encryption standard of the system.
- the other part of the information is all or part of the remaining information of the information to be transmitted except the set part information.
- S203 The communication device generates new to-be-sent information by using the setting part information and the encrypted other part information.
- the communication device combines the set part information and the other part of the information to form a new to-be-sent information;
- the other part of the information is the part of the information to be sent except the set part of the information, and the communication device combines the set part information, the other part information and another part of the information to form a new to-be-sent information, the other A part of the information is the remaining information of the information to be transmitted except the set part information and the other part of the information.
- the communication device may perform encryption processing on the set portion information according to the set encryption rule before S203, and reuse the encrypted set portion information in S203. And other pieces of information after encryption to generate a message to be sent.
- the setting encryption rule is specified in the system internal encryption standard, and the setting encryption rule may be any data processing algorithm, such as an existing encryption algorithm or an encryption method as described in this embodiment. It can be understood that the encryption processing of the setting partial information can also be performed before S202, and the corresponding processing is performed by using the encrypted setting partial information in steps S202 and subsequent steps.
- S204 The communication device sends the new to-be-sent information.
- the communication device transmits the new to-be-sent information through the air interface.
- the following provides a further example of the method of the present embodiment for three different information to be sent.
- the information to be sent is signaling
- the setting part information is verification data of the signaling
- the other part information is signaling content of the signaling.
- the check data may specifically be a checksum, a cyclic redundancy check code (English abbreviation: CRC), a parity bit, and the like.
- the signaling content is data for carrying information to be transmitted by the signaling, such as control data, management data, and the like in the signaling.
- the communication device when it is required to send signaling, such as a control signaling block, to other communication terminals, the communication device generates original signaling to be transmitted according to the wireless communication standard, and then uses the verification data in the signaling as an initial vector, and internally
- the setting data specified by the encryption standard and the signaling content in the signaling are substituted into an encryption formula specified by the internal encryption standard of the system, and the operation result is used as a new signaling content, and the new signaling content is corrected.
- the test data is sent out through the air interface.
- the communication device For the communication flow diagram in the application scenario where the information to be sent is an embedded link frame, the communication device generates signaling content and corresponding first check data, such as a checksum, and performs forward correction. Wrong (English: Forward Error Correction, abbreviated as: FEC) After channel coding, signaling data A is generated, and then the second parity data in the signaling data A, such as a parity bit, is used as an initial vector, and in addition to the second parity data in the signaling data A The remaining part of the data is encrypted according to the set encryption algorithm and the key, and the signaling data B is generated and transmitted through the air interface.
- first check data such as a checksum
- FEC Forward Error Correction
- the communication device For the communication flow diagram in the application scenario where the information to be transmitted is a non-embedded link frame, the communication device generates signaling content A and corresponding verification data such as CRC, and then uses the verification data as an initial.
- the vector is encrypted according to the set encryption algorithm and the key, and the signaling content B is generated.
- the signaling content B and the verification data are encoded by the FEC channel to generate signaling data, which is transmitted through the air interface.
- the information to be sent is voice call information
- the set part information is a voice header frame and/or a voice end frame in the voice call information
- the other part information is voice in the voice call information frame.
- one voice call information includes a voice header frame, a voice frame, and a voice end frame.
- the communication device may use the voice header frame or/or the voice end frame as the setting portion information according to an internal encryption standard of the system.
- the voice call information is generated, and the voice header frame in the voice call information is used as an initial vector, and the voice frame is encrypted according to the set encryption algorithm and the key, thereby generating a new voice frame.
- the new voice call information composed of the voice header frame, the new voice frame, and the voice end frame is sent out through the air interface.
- the information to be sent is data service information
- the setting part information is a data header frame and/or a data end frame of the data service information
- the other part information is a data frame of the data service information.
- the primary data service information includes a data header frame and a data frame, and some data service information also includes a data end frame.
- the communication device may use the data header frame and/or the data end frame as the set portion information according to an internal encryption standard of the system.
- the data service information is generated, and the data header frame in the data service information is used as an initial vector, and the data frame is encrypted according to the set encryption algorithm and the key, thereby generating
- the new data frame sends new data service information consisting of the data header frame and the new data frame through the air interface.
- the speech header frame and/or the speech end frame, the data header frame, and/or the data end frame as the initial vector may be encrypted before being used as the initial vector by the encryption method as described in the above signaling embodiment.
- the communication device uses the information to be sent to set the information as the initial vector to encrypt or decrypt other parts of the information, so the illegal device cannot steal the information transmitted in the wireless communication system, thereby ensuring the wireless communication.
- Security since the communication device directly uses the partial information of the information to be transmitted as the initial vector for encryption, no additional initial vector is needed, so there is no need to increase the air interface overhead.
- FIG. 5 is a flowchart of another embodiment of a method for wireless communication according to the present application.
- the method is performed by a communication device in a wireless communication system for decrypting information upon receipt of the information.
- the method includes:
- S501 The communication device extracts the setting part information in the received information.
- the communication device when receiving the information transmitted by the other communication device, extracts the setting partial information from the received information according to the internal encryption standard of the system in which it is located.
- the system internal encryption standard may set any part of the received information as the setting part information, for example, the setting part information is check data and/or signaling in the received information. It can be understood that the internal encryption standard is the same for the setting information of the to-be-sent data and the received information in the wireless communication system, so as to ensure that the communication information inside the system can be correctly decrypted.
- S502 The communication device decrypts other part of the received information by using the setting part information as an initial vector.
- the communication device uses the extracted setting portion information as an initial vector, performs calculation on other parts of the received information according to the setting decryption formula and the setting data, and uses the operation result as the decrypted other part information.
- the setting decryption formula corresponds to the above-mentioned setting encryption formula of the wireless communication system, and may be an existing decryption algorithm or a custom arbitrary calculation formula.
- the communication device can determine the set decryption formula and the setting data according to the internal encryption standard of the system.
- the above setting encryption formula, setting decryption formula, and setting data are all stored locally in the communication device, and the limitation cannot be transmitted through the air interface, so as to ensure that the illegal device cannot correctly encrypt/decrypt the information of the system.
- the other partial information is all or part of the remaining information of the received information except the set partial information.
- the internal encryption standard sets the same for the data to be transmitted and the other portion of the received information in the wireless communication system.
- the communication device performs decryption processing on the setting portion information according to the setting decryption rule, and adopts in a subsequent step.
- the decrypted setting part information is processed accordingly.
- the setting decryption rule corresponds to the setting encryption rule, and is specified in the system internal encryption standard. Specifically, when the encryption of the setting partial information is performed before the above S202, the decryption of the setting partial information is performed after S502, and when the encryption of the setting partial information is performed before the above S203, the decryption of the setting partial information is Executed before S502.
- S503 The communication device processes the new received information composed of the setting part information and the decrypted other part information.
- the type of the received information and the division of the setting part information and other partial information may correspond to the signaling, the voice call information, the data service information, the setting part information thereof, and the like described in the foregoing embodiments.
- the division of some information may correspond to the signaling, the voice call information, the data service information, the setting part information thereof, and the like described in the foregoing embodiments.
- the communication device uses the check data in the signaling as an initial vector, and substitutes the setting data specified by the internal encryption standard of the system and the signaling content in the signaling. Performing an operation in a decryption formula specified by the internal encryption standard of the system, and using the operation result as the decrypted signaling content, and performing new received information composed of the verification data and the decrypted signaling content.
- the processing specifically includes: generating new check data from the decrypted signaling content; comparing whether the check data in the signaling is the same as the new check data; if the same, the pair is verified by the check.
- the data and the decrypted content of the signaling generate new signaling and respond to the new signaling; otherwise, the signaling is discarded, ie, the signaling is not responded.
- the communication device when the communication device receives an embedded link frame signaling data B, it first uses signaling data B.
- the second check data such as a parity bit, is used as an initial vector, and another part of the data of the signaling data B is decrypted according to a set decryption algorithm and a key to obtain signaling data A, the signaling data A and the second
- the new signaling content and the first check data such as a checksum
- the new signaling content is calculated according to the checksum calculation rule specified by the wireless communication standard, and the checksum is calculated.
- the calculated checksum is the same as the checksum in the received signaling, it indicates that the signaling content is correct, and the signaling content is subsequently processed according to the wireless communication standard; otherwise, the signaling content is illegal. Directly discarded.
- the communication device when receiving a signaling data, the communication device first performs FEC channel decoding on the signaling data to obtain a letter. Let content B and check data, such as CRC, then use CRC as the initial vector, decrypt the signaling content B according to the set decryption algorithm and key, generate signaling content A, and then set the signaling content A according to the wireless communication standard.
- the CRC calculation rule calculates the CRC. When the calculated CRC is the same as the CRC in the received signaling, it indicates that the signaling content A is correct, and the signaling content A is subsequently processed according to the wireless communication standard; otherwise, the signal is Let content A be illegal and discard it directly.
- the communication device may use the voice header frame in the voice call information as an initial vector, and decrypt the voice frame in the voice call information according to the set decryption algorithm and the key, to obtain The original speech frame is then subjected to subsequent processing, such as playing the speech frame. If the voice call information is sent by an illegal device, the decrypted voice frame is not originally transmitted by the illegal device, so the information cannot be played correctly, for example, a noise is generated.
- the communication device may use the data header frame of the data service information as an initial vector, decrypt the data frame of the data service information according to the set decryption algorithm and the key, and obtain the decrypted data. And processing the new received information consisting of the set portion information and the decrypted data frame, specifically comprising: generating new check data from the decrypted data frame; comparing the decryption Whether the check data in the subsequent data frame is the same as the new check data; if the same, generating new data service information from the set portion information and the decrypted data frame, and responding to the new data service Information; otherwise, the data service information is discarded, that is, the data service information is not responded.
- the communication device uses the set partial information of the received information as an initial vector to decrypt other partial information, so that the message sent by the illegal device cannot obtain the correct response of the wireless communication system, thereby ensuring the wireless communication. Security, avoiding information interference from illegal devices.
- FIG. 8 is a schematic structural diagram of an embodiment of a wireless communication device according to the present application.
- the communication terminal of the wireless communication device 80 for the wireless communication system specifically includes an extraction module 81, an encryption module 82, a generation module 83, and a transmission module 84.
- the extracting module 81 is configured to extract setting part information in the information to be sent;
- the encryption module 82 is configured to encrypt the other part of the information to be sent by using the set part information as an initial vector;
- the generating module 83 is configured to generate new to-be-sent information by using the setting part information and the encrypted other part information;
- the sending module 84 is configured to send the new to-be-sent information.
- the setting part information is check data and/or signaling in the information to be sent, and may be specifically as described in the foregoing embodiment.
- the encryption module 82 is further configured to perform encryption processing on the setting part information according to a setting rule.
- the encryption module 82 is specifically configured to use the set part information as an initial vector, perform operation on the other part of the information to be sent according to the set encryption formula and the setting data, and use the operation result as the encrypted The other part of the information.
- FIG. 9 is a schematic structural diagram of another embodiment of a wireless communication device according to the present application.
- the wireless communication device 90 is used in a communication device in a wireless communication system, and specifically includes an extraction module 91, a decryption module 92, and a processing module 93.
- the extracting module 91 is configured to extract setting part information in the received information
- the decryption module 92 is configured to decrypt the other part of the received information by using the set part information as an initial vector;
- the processing module 93 is configured to process the new received information composed of the setting part information and the decrypted other part information.
- the setting part information is check data and/or signaling in the received information, which may be specifically described in the foregoing method embodiment.
- the processing module 83 is specifically configured to: when the received information is signaling, generate new check data from the decrypted signaling content; compare the check data in the signaling with the new Verifying whether the data is the same; if the same, generating new signaling from the verification data and the decrypted signaling content, and responding to the new signaling; otherwise discarding the signaling.
- the processing module 93 is specifically configured to: when the received information is data service information, generate new check data from the decrypted data frame; compare the check data in the decrypted data frame with Whether the new check data is the same; if the same, processing the decrypted new data service information; otherwise, discarding the data service information.
- the decryption module 92 is further configured to perform decryption processing on the set portion information according to the set decryption rule.
- the decrypting module 92 is specifically configured to use the set part information as an initial vector, perform operation on the other part of the information to be sent according to the setting decryption formula and the setting data, and use the operation result as the decrypted The other part of the information.
- the modules of the foregoing apparatus may be correspondingly used to perform the steps in the foregoing method embodiments.
- wireless communication devices in the embodiments shown in FIGS. 8 and 9 can be disposed in the same communication device.
- FIG. 10 is a schematic structural diagram of an embodiment of a communication device according to the present application.
- the communication device 100 of the present embodiment includes a transmitter 101, a receiver 102, a processor 103, a memory 104, and a bus 105.
- the transmitter 101 is for transmitting a message to an external device such as another communication device in the wireless communication system.
- Receiver 102 is configured to receive messages transmitted by external devices, such as other communication devices in a wireless communication system.
- the memory 104 is used to store computer instructions that are configured to be executed by the processor 103 and data that needs to be saved or cached during operation of the processor 103.
- the processor 103 is configured to perform at least one of the following two aspects by calling a computer instruction stored in the memory 104:
- the first aspect the encryption processing of the data to be sent
- the new to-be-sent information is transmitted by the transmitter 101.
- the setting part information is check data and/or signaling in the information to be sent, and may be specifically as described in the foregoing embodiment.
- the processor 103 is further configured to perform encryption processing on the setting part information according to a setting rule.
- the processor 103 is specifically configured to use the set part information as an initial vector, perform operation on the other part of the information to be sent according to the set encryption formula and the setting data, and use the operation result as the encrypted The other part of the information.
- the second aspect decryption processing of the received data
- the new received information composed of the set portion information and the decrypted other portion information is processed.
- the setting part information is check data and/or signaling in the received information, which may be specifically described in the foregoing method embodiment.
- the processor 103 is specifically configured to: when the received information is signaling, generate new check data from the decrypted signaling content; compare the check data in the signaling with the new Verifying whether the data is the same; if the same, generating new signaling from the verification data and the decrypted signaling content, and responding to the new signaling; otherwise discarding the signaling.
- the processor 103 is specifically configured to: when the received information is data service information, generate new check data from the decrypted data frame; compare the check data in the decrypted data frame with Whether the new check data is the same; if the same, processing the decrypted new data service information; otherwise, discarding the data service information.
- the processor 103 is further configured to perform decryption processing on the setting part information according to the setting decryption rule.
- the processor 103 is specifically configured to use the set portion information as an initial vector, perform operation on the other part of the information to be sent according to the set decryption formula and the setting data, and use the operation result as the decrypted The other part of the information.
- the processor 103 can be used only to perform the first aspect or the second aspect, or can be used to perform the above two aspects.
- the processor 103 described above may also be referred to as a CPU (Central Processing). Unit, central processing unit).
- Memory 104 can include read only memory and random access memory and provides instructions and data to processor 103. A portion of the memory 104 may also include non-volatile random access memory (NVRAM).
- NVRAM non-volatile random access memory
- the above components of the mobile terminal are coupled together by a bus 105.
- the bus 105 may include a power bus, a control bus, a status signal bus, and the like in addition to the data bus. However, for clarity of description, various buses are labeled as bus 105 in the figure.
- the method disclosed in the foregoing embodiments of the present invention may be applied to the processor 103 or implemented by the processor 103.
- the processor 103 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method may be completed by an integrated logic circuit of hardware in the processor 103 or an instruction in a form of software.
- the processor 103 described above may be a general purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), an off-the-shelf programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, or discrete hardware. Component.
- DSP digital signal processor
- ASIC application specific integrated circuit
- FPGA off-the-shelf programmable gate array
- the methods, steps, and logical block diagrams disclosed in the embodiments of the present invention may be implemented or carried out.
- the general purpose processor may be a microprocessor or the processor or any conventional processor or the like.
- the steps of the method disclosed in the embodiments of the present invention may be directly implemented by the hardware decoding processor, or may be performed by a combination of hardware and software modules in the decoding processor.
- the software module can be located in a conventional storage medium such as random access memory, flash memory, read only memory, programmable read only memory or electrically erasable programmable memory, registers, and the like.
- the storage medium is located in the memory 104, and the processor 103 reads the information in the memory 104 and, in conjunction with its hardware, performs the steps of the above method.
- the illegal device cannot steal the information transmitted in the wireless communication system, improve the information security of the private network communication, and ensure the security of the communication.
- the illegal device After the communication device in the wireless communication system encrypts the communication information, the illegal device cannot know the decryption rule. Therefore, even if the communication information in the wireless communication system is acquired, the communication cannot be correctly decrypted and the wireless communication system cannot be stolen.
- the information transmitted inside, the illegal device can not steal the information transmitted in the wireless communication system, improve the information security of the private network communication, and ensure the security of the communication.
- the illegal device cannot know the encryption rules, the information cannot be correctly encrypted. Even if the communication device in the wireless communication system receives the information sent by the illegal device, after decrypting, it can find that the information is illegally transmitted or cannot be restored to an illegal device. The information, so as to avoid information interference of illegal equipment, to ensure the reliability of information.
- the information sent by the illegal device is detected by the device in the wireless communication system, so no response is received. For example, if the relay station of the wireless communication system receives the information of the illegal device, the device does not forward the packet, so the illegal device is restricted. Use this wireless communication system resource to ensure system security.
- the communication device directly uses the partial information of the information to be transmitted as the initial vector for encryption, no additional initial vector is needed, so there is no need to increase the air interface overhead.
- the disclosed system, apparatus, and method may be implemented in other manners.
- the device implementations described above are merely illustrative.
- the division of the modules or units is only a logical function division.
- there may be another division manner for example, multiple units or components may be used. Combinations can be integrated into another system, or some features can be ignored or not executed.
- the mutual coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interface, device or unit, and may be in an electrical, mechanical or other form.
- the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, may be located in one place, or may be distributed to multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of the present embodiment.
- each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
- the above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
- the integrated unit if implemented in the form of a software functional unit and sold or used as a standalone product, may be stored in a computer readable storage medium.
- a computer readable storage medium A number of instructions are included to cause a computer device (which may be a personal computer, server, or network device, etc.) or a processor to perform all or part of the steps of the methods described in various embodiments of the present application.
- the foregoing storage medium includes: a U disk, a mobile hard disk, a read only memory (ROM, Read-Only) Memory, random access memory (RAM), disk or optical disk, and other media that can store program code.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
本申请公开了无线通信方法、装置及通信设备。其中,该方法包括:通信设备提取待发送信息中的设定部分信息;以所述设定部分信息作为初始向量,对所述待发送信息中的其他部分信息进行加密;利用所述设定部分信息和加密后的所述其他部分信息生成新的待发送信息;发送所述新的待发送信息。通过上述方式,能够保证无线通信的安全性。
Description
【技术领域】
本申请涉及无线技术领域,特别是可实现通信安全的无线通信方法、装置及通信设备。
【背景技术】
在目前无线通信标准如DMR/PDT中,信息均是以明文的形式在空中传输。任何一个通信设备,只要遵循对应的无线通信标准,就能加入到该无线通信系统,在相应的物理信道上与其他通信设备进行相互通信。
显然,现有的无线通信标准中,缺乏对无线通信系统中传输的信息进行保护,使得任何一个遵循对应无线通信标准的通信设备均可在相应的物理信道上进行监听,导致通信信息被窃取,信息泄密。
【发明内容】
本申请提供无线通信方法、装置及通信设备,能够保证无线通信的安全性。
本申请第一方面提供一种无线通信方法,包括:通信设备提取待发送信息中的设定部分信息;以所述设定部分信息作为初始向量,对所述待发送信息中的其他部分信息进行加密;利用所述设定部分信息和加密后的所述其他部分信息生成新的待发送信息;发送所述新的待发送信息。
其中,所述设定部分信息为所述待发送信息中的校验数据和/或信令。
其中,所述待发送信息为信令,所述设定部分信息为所述信令的校验数据,所述其他部分信息为所述信令的信令内容;或所述待发送信息为语音呼叫信息,所述设定部分信息为所述语音呼叫信息中的语音头帧和/或语音结束帧,所述其他部分信息为所述语音呼叫信息中的语音帧;或所述待发送信息为数据业务信息,所述设定部分信息为所述数据业务信息的数据头帧和/或数据结束帧,所述其他部分信息为所述数据业务信息的数据帧。
其中,在所述利用所述设定部分信息和加密后的所述其他部分信息生成新的待发送信息之前,还包括:对所述设定部分信息按照设定加密规则进行加密处理。
其中,所述以所述设定部分信息作为初始向量,对所述待发送信息中的其他部分信息进行加密,包括:以所述设定部分信息作为初始向量,按照设定加密公式和设定数据对所述待发送信息中的其他部分信息进行运算,将运算结果作为加密后的所述其他部分信息。
本申请第二方面提供一种无线通信方法,包括:通信设备提取已接收信息中的设定部分信息;以所述设定部分信息作为初始向量,对所述已接收信息中的其他部分信息进行解密;对由所述设定部分信息和解密后的所述其他部分信息组成的新的已接收信息进行处理。
其中,所述设定部分信息为所述已接收信息中的校验数据和/或信令。
其中,所述已接收信息为信令,所述设定部分信息为所述信令的校验数据,所述其他部分信息为所述信令的信令内容;所述对由所述设定部分信息和解密后的所述其他部分信息组成的新的已接收信息进行处理,包括:由解密后的所述信令内容生成新校验数据;比较所述信令中的校验数据与所述新校验数据是否相同;若相同,则对由所述校验数据和解密后的所述信令内容生成新信令,并响应所述新信令;否则丢弃所述信令。
其中,所述已接收信息为语音呼叫信息,所述设定部分信息为所述语音呼叫信息中的语音头帧和/或语音结束帧,所述其他部分信息为所述语音呼叫信息中的语音帧。
其中,所述已接收信息为数据业务信息,所述设定部分信息为所述数据业务信息的数据头帧和/或数据结束帧,所述其他部分信息为所述数据业务信息的数据帧;
所述对由所述设定部分信息和解密后的所述其他部分信息组成的新的已接收信息进行处理,包括:由解密后的所述数据帧生成新校验数据;比较所述解密后的数据帧中的校验数据与所述新校验数据是否相同;若相同,则对解密后的新数据业务信息进行处理;否则丢弃所述数据业务信息。
其中,在所述以所述设定部分信息作为初始向量,对所述已接收信息中的其他部分信息进行解密之前,还包括:对所述设定部分信息按照设定解密规则进行解密处理。
其中,所述以所述设定部分信息作为初始向量,对所述已接收信息中的其他部分信息进行解密,包括:以所述设定部分信息作为初始向量,按照设定解密公式和设定数据对所述待发送信息中的其他部分信息进行运算,将运算结果作为解密后的所述其他部分信息。
本申请第三方面提供一种无线通信装置,包括:提取模块,用于提取待发送信息中的设定部分信息;加密模块,用于以所述设定部分信息作为初始向量,对所述待发送信息中的其他部分信息进行加密;生成模块,用于利用所述设定部分信息和加密后的所述其他部分信息生成新的待发送信息;发送模块,用于发送所述新的待发送信息。
本申请第四方面提供一种无线通信装置,包括:提取模块,用于提取已接收信息中的设定部分信息;解密模块,用于以所述设定部分信息作为初始向量,对所述已接收信息中的其他部分信息进行解密;处理模块,用于对由所述设定部分信息和解密后的所述其他部分信息组成的新的已接收信息进行处理。
本申请第五方面提供一种通信设备,包括发送器、存储器及处理器;所述存储器用于存储被配置为被所述处理器执行的计算机指令;所述处理器执行所述计算机指令,用于:提取待发送信息中的设定部分信息;以所述设定部分信息作为初始向量,对所述待发送信息中的其他部分信息进行加密;利用所述设定部分信息和加密后的所述其他部分信息生成新的待发送信息;通过所述发送器发送所述新的待发送信息。
本申请第六方面提供一种通信设备,包括接收器、存储器及处理器;所述存储器用于存储被配置为被所述处理器执行的计算机指令;所述处理器执行所述计算机指令,用于:提取所述接收器接收到的已接收信息中的设定部分信息;以所述设定部分信息作为初始向量,对所述已接收信息中的其他部分信息进行解密;对由所述设定部分信息和解密后的所述其他部分信息组成的新的已接收信息进行处理。
上述方案中,通信设备采用待发送信息或已接收信息的设定部分信息作为初始向量对其他部分信息进行加密或解密处理,故非法设备无法窃取到该无线通信系统内传输的信息且其发送的消息无法得到该无线通信系统的正确响应,从而保证了该无线通信的安全性,避免了非法设备的信息干扰,另外,由于通信设备直接利用待发送信息的部分信息作为初始向量进行加密,无需额外初始向量,故无需增加空口开销。
【附图说明】
图1是本申请无线通信系统一实施方式的结构示意图;
图2是本申请无线通信方法一实施方式的流程图;
图3是图1所示实施例一应用场景的通信流程框图;
图4是图1所示实施例另一应用场景的通信流程框图;
图5是本申请无线通信方法另一实施方式的流程图;
图6是图5所示实施例一应用场景的通信流程框图;
图7是图5所示实施例另一应用场景的通信流程框图;
图8是本申请无线通信装置一实施方式的结构示意图;
图9是本申请无线通信装置另一实施方式的结构示意图;
图10是本申请通信设备一实施方式的结构示意图。
【具体实施方式】
以下描述中,为了说明而不是为了限定,提出了诸如特定系统结构、接口、技术之类的具体细节,以便透彻理解本申请。然而,本领域的技术人员应当清楚,在没有这些具体细节的其它实施方式中也可以实现本申请。在其它情况中,省略对众所周知的装置、电路以及方法的详细说明,以免不必要的细节妨碍本申请的描述。
为便于理解本申请,先对本申请无线通信系统进行说明。
该无线通信系统为设备间可根据如数字移动无线电(英文:Digital Mobile
Radio,简称:DMR)、警用数字集群(英文Police Digital
Trunking,简称:PDT)等无线通信标准进行通信的系统,其通信模式可以为直通模式、中转模式或集群模式,直通模式即设备间直接通过无线信道进行通信;中转模式即设备发送的信息需经过中转台转发到其他设备;集群模式即设备发送的信息需经过系统或基站转发到其他设备。
请参阅图1,图1是本申请无线通信系统一实施方式的结构示意图。以集群模式的无线通信系统举例,该无线通信系统10包括多个通信设备11、12、多个基站13、14(图1仅示范性示出两个通信设备和基站,但实际上无线通信系统中的通信设备和基站的数量是不受限定,可根据实际需求设置)。其中,通信设备11、12通过基站13、14与集群核心网15连接,集群核心网15可用于移动性管理和呼叫管理。
该无线通信系统10中的通信设备之间可通过基站和集群核心网进行无线通信,如通话、数据交互等。具体,该通信设备可以为任意可进行无线通信的设备,例如手机、电脑等终端。
本实施例中,通信设备11、12在发送信息时对其信息进行加密处理,并在接收到信息时对其信息进行相应解密,以保证该系统10无线通信的安全性。具体,为了保证该系统10的通信设备的正常通信,该系统10设置有统一的内部加密标准,加入该系统10的通信设备获取该内部加密标准,并按照该标准对通信信息进行正确的加/解密处理,从而保证系统内部的有效通信,同时,由于未经系统10认证的外部非法通信设备无法获取该加密标准,故无法对系统内的通信信息进行正确的加/解密,从而避免其非法窃取系统内的通信信息或向系统发送信息,保证系统内部通信的安全性。
具体地,系统中的通信设备在发送和接收信息时的加/解密处理请对应参阅以下实施例。
请参阅图2,图2是本申请无线通信方法一实施方式的流程图。该方法由无线通信系统中的通信设备执行,用于在发送信息时对信息进行加密处理。具体,该方法包括:
S201:通信设备提取待发送信息中的设定部分信息。
例如,当通信设备需要向该无线通信系统的其他通信设备发送数据时,生成原始的待发送信息,并根据所在系统的内部加密标准,从在待发送信息中提取设定部分信息。
其中,根据实际通信需求,系统内部加密标准可设置该待发送信息的任一部分作为该设定部分信息。由于该设定部分信息用于作为加密的初始向量,为了进一步保证加密的安全性,优选将待发送信息的非敏感且非恒定信息设置为该设定部分信息,例如,该待发送信息中的校验数据和/或信令,对于不同的待发送信息,其校验部分、信令部分通常也是不同的,即每条待发送信息加密都是不同的,故保证了加密的变化性,进一步提高了通信安全。
具体,本申请所述的信令包括语音链路帧、数据链路帧、控制信令块等。该语音链路帧如语音头帧、语音结束帧,进一步地,该语音链路帧按照不同的设置方式分为嵌入式和非嵌入式,嵌入式语音链路帧即该语音链路帧划分为若干部分插入至语音帧中,非嵌入式语音链路帧即该语音链路帧作为整体设置在语音帧的前面或后面;该数据链路帧如数据头帧、数据结束帧。
S202:通信设备以所述设定部分信息作为初始向量,对所述待发送信息中的其他部分信息进行加密。
例如,通信设备以提取的设定部分信息作为初始向量,按照设定加密公式和设定数据对所述待发送信息中的其他部分信息进行运算,将运算结果作为加密后的所述其他部分信息。该设定加密公式可为现有的加密算法,或者自定义的任意运算公式。通信设备根据该系统的内部加密标准可确定该设定加密公式和设定数据。
可以理解的是,该所述其他部分信息为该待发送信息中除该设定部分信息外的剩余信息的全部或部分信息。
S203:通信设备利用所述设定部分信息和加密后的所述其他部分信息生成新的待发送信息。
例如,若该其他部分信息为该待发送信息的中除该设定部分信息外的剩余信息的全部信息,则通信设备将设定部分信息和该其他部分信息组成新的待发送信息;若该其他部分信息为该待发送信息的中除该设定部分信息外的剩余信息的部分信息,则通信设备将设定部分信息、该其他部分信息以及另一部分信息组成新的待发送信息,该另一部分信息即为该待发送信息的中除该设定部分信息和该其他部分信息外的剩余信息。
在另一实施例中,为进一步提高通信信息的安全性,通信设备可以在S203之前,对该设定部分信息按照设定加密规则进行加密处理,在S203中再利用加密后的设定部分信息和加密后的其他部分信息生成信息的待发送消息。其中,该设定加密规则为系统内部加密标准中指定的,该设定加密规则可以为任何数据处理算法,例如为现有的加密算法、或者如本实施例所述的加密方法。可以理解的是,该设定部分信息的加密处理也可以在S202之前执行,在S202及之后的步骤中采用加密后的设定部分信息进行相应处理。
S204:通信设备发送所述新的待发送信息。
例如,通信设备通过空口将该新的待发送信息发射出去。
具体地,以下提供对三种不同的待发送信息对本实施例方法进行进一步举例说明。
1)所述待发送信息为信令,所述设定部分信息为所述信令的校验数据,所述其他部分信息为所述信令的信令内容。该校验数据具体可为校验和、循环冗余校验码(英文简称:CRC)、奇偶校验位等。该信令内容为用于承载该信令需传递的信息的数据,例如为该信令中的控制数据、管理数据等。
具体如,当需要向其他通信终端发送信令如控制信令块时,通信设备按照无线通信标准生成原始的待发送的信令,然后使用信令中的校验数据作为初始向量,将系统内部加密标准指定的设定数据和该信令中信令内容代入至系统内部加密标准指定的加密公式中进行运算,并将运算结果作为新的信令内容,并将该新的信令内容和校验数据通过空口发送出去。
如图3所示,为该待发送信息为嵌入式链路帧的应用场景中的通信流程框图,通信设备生成信令内容和对应的第一校验数据如校验和,并经过前向纠错(英文:Forward
Error
Correction,简称:FEC)信道编码后,生成信令数据A,然后以信令数据A中第二校验数据如奇偶校验位作为初始向量,对信令数据A中除第二校验数据外的剩余部分数据按照设定加密算法和密钥进行加密,生成信令数据B,通过空口发射。
如图4所示,为该待发送信息为非嵌入式链路帧的应用场景中的通信流程框图,通信设备生成信令内容A和对应的校验数据如CRC,然后以校验数据作为初始向量,对信令内容A按照设定加密算法和密钥进行加密,生成信令内容B,将信令内容B和校验数据经过FEC信道编码后生成信令数据,通过空口发射。
2)所述待发送信息为语音呼叫信息,所述设定部分信息为所述语音呼叫信息中的语音头帧和/或语音结束帧,所述其他部分信息为所述语音呼叫信息中的语音帧。
在如DMR/PDT等无线通信标准中,一次语音呼叫信息包含语音头帧、语音帧和语音结束帧。通信设备可按照系统内部加密标准将所述语音头帧或/或语音结束帧作为该设定部分信息。
具体如,通信设备在进行语音呼叫时,生成语音呼叫信息,并使用语音呼叫信息中的语音头帧作为初始向量,按照设定加密算法和密钥对语音帧进行加密,从而生成新的语音帧,通过空口将由该语音头帧、新的语音帧、语音结束帧组成的新的语音呼叫信息发送出去。
3)所述待发送信息为数据业务信息,所述设定部分信息为所述数据业务信息的数据头帧和/或数据结束帧,所述其他部分信息为所述数据业务信息的数据帧。
在如DMR/PDT等无线通信标准中,一次数据业务信息包含数据头帧和数据帧,在有些数据业务信息中还包含数据结束帧。通信设备可按照系统内部加密标准将所述数据头帧和/或数据结束帧作为该设定部分信息。
具体如,通信设备在与其他通信设备进行数据业务时,生成数据业务信息,并使用数据业务信息中的数据头帧作为初始向量,按照设定加密算法和密钥对数据帧进行加密,从而生成新的数据帧,通过空口将由该数据头帧、新的数据帧组成的新的数据业务信息发送出去。
在其他实施例,上述作为初始向量的语音头帧和/或语音结束帧、数据头帧和/或数据结束帧在作为初始向量之前,可采用如上述信令实施例加密方法对其进行加密。
本实施例中,通信设备采用待发送信息设定部分信息作为初始向量对其他部分信息进行加密或解密处理,故非法设备无法窃取到该无线通信系统内传输的信息,从而保证了该无线通信的安全性,另外,由于通信设备直接利用待发送信息的部分信息作为初始向量进行加密,无需额外初始向量,故无需增加空口开销。
请参阅图5,图5是本申请无线通信方法另一实施方式的流程图。该方法由无线通信系统中的通信设备执行,用于在接收到信息时对信息进行解密处理。具体,该方法包括:
S501:通信设备提取已接收信息中的设定部分信息。
例如,通信设备在接收到其他通信设备发送的信息时,根据所在系统的内部加密标准,从在已接收信息中提取设定部分信息。
如上一实施例所述,系统内部加密标准可设置该已接收信息的任一部分作为该设定部分信息,例如,该设定部分信息为该已接收信息中的校验数据和/或信令。可以理解的是,内部加密标准对该无线通信系统中的待发送数据和已接收信息的设定部分信息是相同的,以保证系统内部的通信信息可正确被解密。
S502:通信设备以所述设定部分信息作为初始向量,对所述已接收信息中的其他部分信息进行解密。
例如,通信设备以提取的设定部分信息作为初始向量,按照设定解密公式和设定数据对所述已接收信息中的其他部分信息进行运算,将运算结果作为解密后的所述其他部分信息。该设定解密公式与该无线通信系统的上述设定加密公式是对应的,可为现有的解密算法,或者自定义的任意运算公式。通信设备根据该系统的内部加密标准可确定该设定解密公式和设定数据。其中,上述设定加密公式、设定解密公式、设定数据均存储在通信设备本地,并限制无法通过空口传输,以保证非法设备无法对该系统的信息进行正确加/解密。
可以理解的是,该所述其他部分信息为该已接收信息中除该设定部分信息外的剩余信息的全部或部分信息。同样地,为保证系统内部的通信信息可正确被解密,内部加密标准对该无线通信系统中的待发送数据和已接收信息的该其他部分信息的设置是相同的。
进一步地,在另一该设定部分信息被加密处理的实施例中,在该S502之前或之后,通信设备对所述设定部分信息按照设定解密规则进行解密处理,并在后续步骤中采用该解密后的设定部分信息进行相应处理。其中,该设定解密规则与上述设定加密规则对应,为系统内部加密标准中指定的。具体,当设定部分信息的加密在上述S202之前执行,则上述设定部分信息的解密在S502之后执行,当设定部分信息的加密在上述S203之前执行,则上述设定部分信息的解密在S502之前执行。
S503:通信设备对由所述设定部分信息和解密后的所述其他部分信息组成的新的已接收信息进行处理。
本实施例中,该已接收信息的类型及其设定部分信息和其他部分信息的划分可对应为上述实施例所述的信令、语音呼叫信息、数据业务信息及其设定部分信息和其他部分信息的划分。
具体地,以下提供对三种不同的已接收信息对本实施例方法进行进一步举例说明。
1)当该已接收信息为信令如控制信令块时,通信设备使用信令中的校验数据作为初始向量,将系统内部加密标准指定的设定数据和该信令中信令内容代入至系统内部加密标准指定的解密公式中进行运算,并将运算结果作为解密后的信令内容,并对由所述校验数据和解密后的所述信令内容组成的新的已接收信息进行处理,具体包括:由解密后的所述信令内容生成新校验数据;比较所述信令中的校验数据与所述新校验数据是否相同;若相同,则对由所述校验数据和解密后的所述信令内容生成新信令,并响应所述新信令;否则丢弃所述信令,也即对该信令不做响应。
如图6所示,为该已接收信息为嵌入式链路帧的应用场景中的通信流程框图,通信设备在收到一条嵌入式链路帧信令数据B时,先以信令数据B中的第二校验数据如奇偶校验位作为初始向量,对信令数据B的另一部分数据按照设定解密算法和密钥进行解密,得到信令数据A,对该信令数据A和第二校验数据进行FEC信道解码后,得到新的信令内容和第一校验数据如校验和,接着将新的信令内容按无线通信标准规定的校验和计算规则计算出校验和,当计算得到的校验和与接收到的信令中的校验和相同时,则表示信令内容是正确的,按无线通信标准对信令内容进行后续处理;否则表示信令内容是不合法的,直接丢弃。
如图7所示,为该已接收信息为非嵌入式链路帧的应用场景中的通信流程框图,通信设备在收到一条信令数据时,先对信令数据进行FEC信道解码,得到信令内容B和校验数据如CRC,然后以CRC作为初始向量,对信令内容B按照设定解密算法和密钥进行解密,生成信令内容A,接着将信令内容A按无线通信标准规定的CRC计算规则计算出CRC,当计算得到的CRC与接收到的信令中CRC相同时,则表示信令内容A是正确的,按无线通信标准对信令内容A进行后续处理;否则表示信令内容A是不合法的,直接丢弃。
2)当该已接收信息为语音呼叫信息时,通信设备可用该语音呼叫信息中的语音头帧作为初始向量,按照设定解密算法和密钥对该语音呼叫信息中的语音帧进行解密,得到原始的语音帧,然后进行后续处理,如将该语音帧进行播放。若该语音呼叫信息为非法设备发送的,则解密后的语音帧并非为非法设备原始发送的信息,故无法正确播放信息,例如会出现播放的是杂音。
3)当该已接收信息为数据业务信息时,通信设备可用数据业务信息的数据头帧作为初始向量,按照设定解密算法和密钥对数据业务信息的数据帧进行解密,得到解密后的数据帧,然后对由所述设定部分信息和解密后的所述数据帧组成的新的已接收信息进行处理,具体包括:由解密后的所述数据帧生成新校验数据;比较所述解密后的数据帧中的校验数据与所述新校验数据是否相同;若相同,则对由所述设定部分信息和解密后的数据帧生成新数据业务信息,并响应所述新数据业务信息;否则丢弃所述数据业务信息,也即对该数据业务信息不做响应。
本实施例中,通信设备采用已接收信息的设定部分信息作为初始向量对其他部分信息进行解密处理,故非法设备发送的消息无法得到该无线通信系统的正确响应,从而保证了该无线通信的安全性,避免了非法设备的信息干扰。
请参阅图8,图8是本申请无线通信装置一实施方式的结构示意图。该无线通信装置80用于无线通信系统的通信终端具体包括提取模块81、加密模块82、生成模块83和发送模块84。
提取模块81用于提取待发送信息中的设定部分信息;
加密模块82用于以所述设定部分信息作为初始向量,对所述待发送信息中的其他部分信息进行加密;
生成模块83用于利用所述设定部分信息和加密后的所述其他部分信息生成新的待发送信息;
发送模块84用于发送所述新的待发送信息。
可选地,所述设定部分信息为所述待发送信息中的校验数据和/或信令,具体可如上述实施例所述。
可选地,加密模块82还用于对所述设定部分信息按照设定规则进行加密处理。
可选地,加密模块82具体用于以所述设定部分信息作为初始向量,按照设定加密公式和设定数据对所述待发送信息中的其他部分信息进行运算,将运算结果作为加密后的所述其他部分信息。
请参阅图9,图9是本申请无线通信装置另一实施方式的结构示意图。该无线通信装置90用于无线通信系统中的通信设备,具体包括:提取模块91、解密模块92和处理模块93。
提取模块91用于提取已接收信息中的设定部分信息;
解密模块92用于以所述设定部分信息作为初始向量,对所述已接收信息中的其他部分信息进行解密;
处理模块93用于对由所述设定部分信息和解密后的所述其他部分信息组成的新的已接收信息进行处理。
可选地,所述设定部分信息为所述已接收信息中的校验数据和/或信令,具体可如上述方法实施例所述。
可选地,处理模块83具体用于当所述已接收信息为信令时,由解密后的所述信令内容生成新校验数据;比较所述信令中的校验数据与所述新校验数据是否相同;若相同,则对由所述校验数据和解密后的所述信令内容生成新信令,并响应所述新信令;否则丢弃所述信令。
可选地,处理模块93具体用于当所述已接收信息为数据业务信息时,由解密后的所述数据帧生成新校验数据;比较所述解密后的数据帧中的校验数据与所述新校验数据是否相同;若相同,则对解密后的新数据业务信息进行处理;否则丢弃所述数据业务信息。
可选地,解密模块92还用于对所述设定部分信息按照设定解密规则进行解密处理。
可选地,解密模块92具体用于以所述设定部分信息作为初始向量,按照设定解密公式和设定数据对所述待发送信息中的其他部分信息进行运算,将运算结果作为解密后的所述其他部分信息。
上述装置的模块可对应用于执行上述方法实施例中的步骤,具体说明请参阅上述方法实施例的描述。
可以理解的是,图8和图9所示实施例中的无线通信装置可设置在同一通信设备中。
参阅图10,图10是本申请通信设备一实施方式的结构示意图。本实施方式的通信设备100,包括发送器101、接收器102、处理器103、存储器104以及总线105。
发送器101用于向外部设备如无线通信系统中的其他通信设备发送消息。
接收器102用于接收外部设备如无线通信系统中的其他通信设备发送的消息。
存储器104用于存储被配置为被所述处理器103执行的计算机指令以及在处理器103工作过程中所需保存或缓存的数据。
在本实施例中,处理器103通过调用存储器104存储的计算机指令,用于执行以下两方面的至少一个:
第一方面:对待发送数据的加密处理;
提取待发送信息中的设定部分信息;
以所述设定部分信息作为初始向量,对所述待发送信息中的其他部分信息进行加密;
利用所述设定部分信息和加密后的所述其他部分信息生成新的待发送信息;
通过发送器101发送所述新的待发送信息。
可选地,所述设定部分信息为所述待发送信息中的校验数据和/或信令,具体可如上述实施例所述。
可选地,处理器103还用于对所述设定部分信息按照设定规则进行加密处理。
可选地,处理器103具体用于以所述设定部分信息作为初始向量,按照设定加密公式和设定数据对所述待发送信息中的其他部分信息进行运算,将运算结果作为加密后的所述其他部分信息。
第二方面:对已接收数据的解密处理;
提取接收器102接收到的已接收信息中的设定部分信息;
以所述设定部分信息作为初始向量,对所述已接收信息中的其他部分信息进行解密;
对由所述设定部分信息和解密后的所述其他部分信息组成的新的已接收信息进行处理。
可选地,所述设定部分信息为所述已接收信息中的校验数据和/或信令,具体可如上述方法实施例所述。
可选地,处理器103具体用于当所述已接收信息为信令时,由解密后的所述信令内容生成新校验数据;比较所述信令中的校验数据与所述新校验数据是否相同;若相同,则对由所述校验数据和解密后的所述信令内容生成新信令,并响应所述新信令;否则丢弃所述信令。
可选地,处理器103具体用于当所述已接收信息为数据业务信息时,由解密后的所述数据帧生成新校验数据;比较所述解密后的数据帧中的校验数据与所述新校验数据是否相同;若相同,则对解密后的新数据业务信息进行处理;否则丢弃所述数据业务信息。
可选地,处理器103还用于对所述设定部分信息按照设定解密规则进行解密处理。
可选地,处理器103具体用于以所述设定部分信息作为初始向量,按照设定解密公式和设定数据对所述待发送信息中的其他部分信息进行运算,将运算结果作为解密后的所述其他部分信息。
可以理解的是,在不同实施例中,该处理器103可仅用于执行第一方面或第二方面,或可用于执行以上两方面。
上述处理器103还可以称为CPU(Central Processing
Unit,中央处理单元)。存储器104可以包括只读存储器和随机存取存储器,并向处理器103提供指令和数据。存储器104的一部分还可以包括非易失性随机存取存储器(NVRAM)。具体的应用中,移动终端的上述各个组件通过总线105耦合在一起,其中总线105除包括数据总线之外,还可以包括电源总线、控制总线和状态信号总线等。但是为了清楚说明起见,在图中将各种总线都标为总线105。
上述本发明实施例揭示的方法可以应用于处理器103中,或者由处理器103实现。处理器103可能是一种集成电路芯片,具有信号的处理能力。在实现过程中,上述方法的各步骤可以通过处理器103中的硬件的集成逻辑电路或者软件形式的指令完成。上述的处理器103可以是通用处理器、数字信号处理器(DSP)、专用集成电路(ASIC)、现成可编程门阵列(FPGA)或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件。可以实现或者执行本发明实施例中的公开的各方法、步骤及逻辑框图。通用处理器可以是微处理器或者该处理器也可以是任何常规的处理器等。结合本发明实施例所公开的方法的步骤可以直接体现为硬件译码处理器执行完成,或者用译码处理器中的硬件及软件模块组合执行完成。软件模块可以位于随机存储器,闪存、只读存储器,可编程只读存储器或者电可擦写可编程存储器、寄存器等本领域成熟的存储介质中。该存储介质位于存储器104,处理器103读取存储器104中的信息,结合其硬件完成上述方法的步骤。
采用上述方案可实现以下有益效果:
1、非法设备无法窃取该无线通信系统内传输的信息,提高了专网通信的信息安全,确保通信的安全性。
无线通信系统内的通信设备对该通信信息进行上述加密后,非法设备由于无法获知其解密规则,故即使获取到该无线通信系统内的通信信息,也无法正确解密进而无法窃取到该无线通信系统内传输的信息,非法设备无法窃取该无线通信系统内传输的信息,提高了专网通信的信息安全,确保通信的安全性。
2、避免了非法设备的信息干扰,确保信息的可靠性。
非法设备由于无法获知其加密规则,故无法将信息正确加密,无线通信系统内的通信设备即使接收到该非法设备发送的信息,经解密后则可发现其信息非法发送或者无法还原成非法设备发送的信息,故避免了非法设备的信息干扰,确保信息的可靠性。
3、限制非法设备使用该无线通信系统资源,确保系统安全性。
如2所述,非法设备发送的信息会被无线通信系统中的设备发现,故不做响应,如无线通信系统的中转台接收到该非法设备的信息后则丢弃不再转发,故限制非法设备使用该无线通信系统资源,确保系统安全性。
4、不增加任何的空口开销。
由于通信设备直接利用待发送信息的部分信息作为初始向量进行加密,无需额外初始向量,故无需增加空口开销。
在本申请所提供的几个实施方式中,应该理解到,所揭露的系统,装置和方法,可以通过其它的方式实现。例如,以上所描述的装置实施方式仅仅是示意性的,例如,所述模块或单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另一点,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口,装置或单元的间接耦合或通信连接,可以是电性,机械或其它的形式。
所述作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部单元来实现本实施方式方案的目的。
另外,在本申请各个实施方式中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用软件功能单元的形式实现。
所述集成的单元如果以软件功能单元的形式实现并作为独立的产品销售或使用时,可以存储在一个计算机可读取存储介质中。基于这样的理解,本申请的技术方案本质上或者说对现有技术做出贡献的部分或者该技术方案的全部或部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)或处理器(processor)执行本申请各个实施方式所述方法的全部或部分步骤。而前述的存储介质包括:U盘、移动硬盘、只读存储器(ROM,Read-Only
Memory)、随机存取存储器(RAM,Random Access Memory)、磁碟或者光盘等各种可以存储程序代码的介质。
Claims (20)
- 一种无线通信方法,其特征在于,包括:通信设备提取待发送信息中的设定部分信息;以所述设定部分信息作为初始向量,对所述待发送信息中的其他部分信息进行加密;利用所述设定部分信息和加密后的所述其他部分信息生成新的待发送信息;发送所述新的待发送信息。
- 如权利要求1所述的无线通信方法,其特征在于,所述设定部分信息为所述待发送信息中的校验数据和/或信令。
- 如权利要求2所述的无线通信方法,其特征在于,所述待发送信息为信令,所述设定部分信息为所述信令的校验数据,所述其他部分信息为所述信令的信令内容;或所述待发送信息为语音呼叫信息,所述设定部分信息为所述语音呼叫信息中的语音头帧和/或语音结束帧,所述其他部分信息为所述语音呼叫信息中的语音帧;或所述待发送信息为数据业务信息,所述设定部分信息为所述数据业务信息的数据头帧和/或数据结束帧,所述其他部分信息为所述数据业务信息的数据帧。
- 如权利要求1所述的无线通信方法,其特征在于,在所述利用所述设定部分信息和加密后的所述其他部分信息生成新的待发送信息之前,还包括:对所述设定部分信息按照设定加密规则进行加密处理。
- 如权利要求1所述的无线通信方法,其特征在于,所述以所述设定部分信息作为初始向量,对所述待发送信息中的其他部分信息进行加密,包括:以所述设定部分信息作为初始向量,按照设定加密公式和设定数据对所述待发送信息中的其他部分信息进行运算,将运算结果作为加密后的所述其他部分信息。
- 一种无线通信方法,其特征在于,包括:通信设备提取已接收信息中的设定部分信息;以所述设定部分信息作为初始向量,对所述已接收信息中的其他部分信息进行解密;对由所述设定部分信息和解密后的所述其他部分信息组成的新的已接收信息进行处理。
- 如权利要求6所述的无线通信方法,其特征在于,所述设定部分信息为所述已接收信息中的校验数据和/或信令。
- 如权利要求7所述的无线通信方法,其特征在于,所述已接收信息为信令,所述设定部分信息为所述信令的校验数据,所述其他部分信息为所述信令的信令内容;所述对由所述设定部分信息和解密后的所述其他部分信息组成的新的已接收信息进行处理,包括:由解密后的所述信令内容生成新校验数据;比较所述信令中的校验数据与所述新校验数据是否相同;若相同,则对由所述校验数据和解密后的所述信令内容生成新信令,并响应所述新信令;否则丢弃所述信令。
- 如权利要求7所述的无线通信方法,其特征在于,所述已接收信息为语音呼叫信息,所述设定部分信息为所述语音呼叫信息中的语音头帧和/或语音结束帧,所述其他部分信息为所述语音呼叫信息中的语音帧。
- 如权利要求7所述的无线通信方法,其特征在于,所述已接收信息为数据业务信息,所述设定部分信息为所述数据业务信息的数据头帧和/或数据结束帧,所述其他部分信息为所述数据业务信息的数据帧;所述对由所述设定部分信息和解密后的所述其他部分信息组成的新的已接收信息进行处理,包括:由解密后的所述数据帧生成新校验数据;比较所述解密后的数据帧中的校验数据与所述新校验数据是否相同;若相同,则对解密后的新数据业务信息进行处理;否则丢弃所述数据业务信息。
- 如权利要求6所述的无线通信方法,其特征在于,在所述以所述设定部分信息作为初始向量,对所述已接收信息中的其他部分信息进行解密之前,还包括:对所述设定部分信息按照设定解密规则进行解密处理。
- 如权利要求6所述的无线通信方法,其特征在于,所述以所述设定部分信息作为初始向量,对所述已接收信息中的其他部分信息进行解密,包括:以所述设定部分信息作为初始向量,按照设定解密公式和设定数据对所述待发送信息中的其他部分信息进行运算,将运算结果作为解密后的所述其他部分信息。
- 一种无线通信装置,其特征在于,包括:提取模块,用于提取待发送信息中的设定部分信息;加密模块,用于以所述设定部分信息作为初始向量,对所述待发送信息中的其他部分信息进行加密;生成模块,用于利用所述设定部分信息和加密后的所述其他部分信息生成新的待发送信息;发送模块,用于发送所述新的待发送信息。
- 一种无线通信装置,其特征在于,包括:提取模块,用于提取已接收信息中的设定部分信息;解密模块,用于以所述设定部分信息作为初始向量,对所述已接收信息中的其他部分信息进行解密;处理模块,用于对由所述设定部分信息和解密后的所述其他部分信息组成的新的已接收信息进行处理。
- 一种通信设备,其特征在于,包括发送器、存储器及处理器;所述存储器用于存储被配置为被所述处理器执行的计算机指令;所述处理器执行所述计算机指令,用于:提取待发送信息中的设定部分信息;以所述设定部分信息作为初始向量,对所述待发送信息中的其他部分信息进行加密;利用所述设定部分信息和加密后的所述其他部分信息生成新的待发送信息;通过所述发送器发送所述新的待发送信息。
- 如权利要求15所述的通信设备,其特征在于,所述待发送信息为信令,所述设定部分信息为所述信令的校验数据,所述其他部分信息为所述信令的信令内容;或所述待发送信息为语音呼叫信息,所述设定部分信息为所述语音呼叫信息中的语音头帧和/或语音结束帧,所述其他部分信息为所述语音呼叫信息中的语音帧;或所述待发送信息为数据业务信息,所述设定部分信息为所述数据业务信息的数据头帧和/或数据结束帧,所述其他部分信息为所述数据业务信息的数据帧。
- 如权利要求15所述的通信设备,其特征在于,所述处理器还用于对所述设定部分信息按照设定加密规则进行加密处理。
- 一种通信设备,其特征在于,包括接收器、存储器及处理器;所述存储器用于存储被配置为被所述处理器执行的计算机指令;所述处理器执行所述计算机指令,用于:提取所述接收器接收到的已接收信息中的设定部分信息;以所述设定部分信息作为初始向量,对所述已接收信息中的其他部分信息进行解密;对由所述设定部分信息和解密后的所述其他部分信息组成的新的已接收信息进行处理。
- 如权利要求18所述的通信设备,其特征在于,所述已接收信息为信令,所述设定部分信息为所述信令的校验数据,所述其他部分信息为所述信令的信令内容;或所述已接收信息为语音呼叫信息,所述设定部分信息为所述语音呼叫信息中的语音头帧和/或语音结束帧,所述其他部分信息为所述语音呼叫信息中的语音帧;或所述已接收信息为数据业务信息,所述设定部分信息为所述数据业务信息的数据头帧和/或数据结束帧,所述其他部分信息为所述数据业务信息的数据帧。
- 如权利要求18所述的通信设备,其特征在于,所述处理器还用于对所述设定部分信息按照设定解密规则进行解密处理。
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/CN2016/106451 WO2018090339A1 (zh) | 2016-11-18 | 2016-11-18 | 无线通信方法、装置及通信设备 |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/CN2016/106451 WO2018090339A1 (zh) | 2016-11-18 | 2016-11-18 | 无线通信方法、装置及通信设备 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2018090339A1 true WO2018090339A1 (zh) | 2018-05-24 |
Family
ID=62145916
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2016/106451 Ceased WO2018090339A1 (zh) | 2016-11-18 | 2016-11-18 | 无线通信方法、装置及通信设备 |
Country Status (1)
| Country | Link |
|---|---|
| WO (1) | WO2018090339A1 (zh) |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2007059558A1 (en) * | 2005-11-23 | 2007-05-31 | The University Of Sydney | Wireless protocol for privacy and authentication |
| CN101542961A (zh) * | 2005-07-27 | 2009-09-23 | 因特隆公司 | 在通信网络中加密数据 |
| CN102136904A (zh) * | 2011-03-30 | 2011-07-27 | 中国科学院软件研究所 | 一种基于分组密码的消息鉴别方法 |
| CN102144370A (zh) * | 2008-09-04 | 2011-08-03 | 富士通株式会社 | 发送装置、接收装置、发送方法及接收方法 |
-
2016
- 2016-11-18 WO PCT/CN2016/106451 patent/WO2018090339A1/zh not_active Ceased
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101542961A (zh) * | 2005-07-27 | 2009-09-23 | 因特隆公司 | 在通信网络中加密数据 |
| WO2007059558A1 (en) * | 2005-11-23 | 2007-05-31 | The University Of Sydney | Wireless protocol for privacy and authentication |
| CN102144370A (zh) * | 2008-09-04 | 2011-08-03 | 富士通株式会社 | 发送装置、接收装置、发送方法及接收方法 |
| CN102136904A (zh) * | 2011-03-30 | 2011-07-27 | 中国科学院软件研究所 | 一种基于分组密码的消息鉴别方法 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2020186775A1 (zh) | 业务数据提供方法、装置、设备及计算机可读存储介质 | |
| WO2011021883A2 (en) | Method and apparatus for reducing overhead for integrity check of data in wireless communication system | |
| WO2014063455A1 (zh) | 即时通信方法和系统 | |
| WO2018151390A1 (ko) | 사물 인터넷 장치 | |
| WO2009000209A1 (en) | A method and a system for transmitting and receiving the data | |
| WO2020036239A1 (ko) | V2x 유니캐스트 통신을 위한 서비스 메세지 인코딩 방법 및 장치 | |
| WO2018000674A1 (zh) | 网络连接方法、网络连接装置和终端 | |
| CN110234102A (zh) | 通信方法和设备 | |
| CN113038459A (zh) | 隐私信息传输方法、装置、计算机设备及计算机可读介质 | |
| WO2023120906A1 (ko) | 펌웨어를 수신하는 방법 및 펌웨어를 전송하는 방법 | |
| WO2020067734A1 (ko) | 넌어드레스 네트워크 장비 및 이를 이용한 통신 보안 시스템 | |
| WO2018000640A1 (zh) | 一种语音加密的测试方法及测试设备 | |
| WO2018032583A1 (zh) | 一种终端位置信息获取方法及装置 | |
| WO2020258351A1 (zh) | 物联网通讯方法、装置、终端及计算机存储介质 | |
| WO2011111981A2 (ko) | 데이터 자동 암복호화 방법 및 장치 | |
| WO2018090339A1 (zh) | 无线通信方法、装置及通信设备 | |
| CN115702424A (zh) | 将asil相关信息从数据源转发到数据宿的方法和车辆总线系统 | |
| CN118450380A (zh) | 终端认证方法、装置、设备、存储介质和程序产品 | |
| WO2023008940A1 (en) | Method and system for securely handling re-connection of client devices to a wireless network | |
| CN106789903B (zh) | 无线通信方法、装置及通信设备 | |
| WO2023113168A1 (ko) | 데이터의 보안 통신 방법 | |
| CN116340954A (zh) | 一种数据安全通道建立方法、系统控制处理器和启动固件 | |
| WO2018086004A1 (zh) | 安全通信的方法、受控装置及设备、遥控装置及设备 | |
| WO2018176700A1 (zh) | 远程访问服务的数据交互方法和系统 | |
| WO2010102577A1 (zh) | 一种密码输入方法和装置 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 16921706 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 32PN | Ep: public notification in the ep bulletin as address of the adressee cannot be established |
Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 15-10-2019) |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 16921706 Country of ref document: EP Kind code of ref document: A1 |