WO2018098687A1 - Method and device for security processing - Google Patents

Method and device for security processing Download PDF

Info

Publication number
WO2018098687A1
WO2018098687A1 PCT/CN2016/108034 CN2016108034W WO2018098687A1 WO 2018098687 A1 WO2018098687 A1 WO 2018098687A1 CN 2016108034 W CN2016108034 W CN 2016108034W WO 2018098687 A1 WO2018098687 A1 WO 2018098687A1
Authority
WO
WIPO (PCT)
Prior art keywords
pdcp
data packet
entity
sequence number
packet
Prior art date
Application number
PCT/CN2016/108034
Other languages
French (fr)
Chinese (zh)
Inventor
龚晓东
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to CN201680090355.1A priority Critical patent/CN109863769A/en
Priority to PCT/CN2016/108034 priority patent/WO2018098687A1/en
Publication of WO2018098687A1 publication Critical patent/WO2018098687A1/en

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/03Protecting confidentiality, e.g. by encryption
    • H04W12/033Protecting confidentiality, e.g. by encryption of the user plane, e.g. user's traffic
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W80/00Wireless network protocols or protocol adaptations to wireless operation
    • H04W80/02Data link layer protocols

Definitions

  • the first sequence number is used to adjust a parameter COUNT when there is a lost PDCP data packet in a PDCP data packet received by the PDCP entity from the first entity; when the PDCP entity receives from the first entity When there is a lost PDCP data packet in the PDCP data packet, the PDCP entity adjusts the parameter COUNT according to the first sequence number; the PDCP entity performs security processing on the first PDCP data packet according to the adjusted parameter COUNT, where The first PDCP data packet is a PDCP data packet received after the packet loss.
  • the PDCP entity adjusts the parameter COUNT according to the first sequence number, including: the PDCP entity selects a second data packet from a PDCP data packet that is correctly received before the lost PDCP data packet; And according to the first sequence number of the second data packet, the PDCP sequence number of the second data packet, the super frame number HFN of the second data packet, the first sequence number of the first data packet, and the a PDCP sequence number of the first data packet, determining an HFN of the first data packet; determining a parameter COUNT according to an HFN of the first data packet and a PDCP sequence number of the first data packet.
  • the value of the first sequence number is incremented by one when the first entity sends a PDCP data packet to the PDCP entity.
  • the first entity is a radio link control RLC entity.
  • the present application provides an apparatus for secure processing, comprising a processor for storing a program, and a processor for calling a program stored in the memory to perform the method provided in the first aspect above.
  • the present application provides a secure processing program for performing the method of the above fourth aspect when executed by a processor.
  • FIG. 13 is a schematic block diagram of a device 2000 for security processing according to an embodiment of the present application.
  • the terminal is also referred to as a User Equipment (UE), and is a device that provides voice and/or data connectivity to the user.
  • UE User Equipment
  • a handheld device having a wireless connection function an in-vehicle device, or the like.
  • Common terminals include, for example, mobile phones, tablets, notebook computers, PDAs, mobile internet devices (MIDs), wearable devices such as smart watches, smart bracelets, pedometers, and the like.
  • MIDs mobile internet devices
  • wearable devices such as smart watches, smart bracelets, pedometers, and the like.
  • the numbers “first”, “second”, and the like are merely for distinguishing different objects.
  • the protection scope of the embodiment of the present application should not be Become any limit.
  • “Multiple” means two or more.
  • the character “/" generally indicates that the contextual object is an "or" relationship.
  • FIG. 1 is a schematic diagram of a communication scenario according to an embodiment of the present application.
  • the terminal 120 accesses the wireless network through the base station 110 to acquire services of an external network (e.g., the Internet) through the wireless network, or communicates with other terminals through the wireless network.
  • an external network e.g., the Internet
  • the PDCP layer On the user plane, the PDCP layer encrypts the IP data packets from the upper layer and then delivers the IP data packets to the RLC layer.
  • the PDCP layer On the control plane, the PDCP layer provides signaling transmission services for the upper layer RRC, and implements encryption and integrity protection of RRC signaling.
  • the PDCP layer can decrypt the uplink data packet; on the control plane, the decryption and integrity check of the RRC signaling can be implemented.
  • FIG. 4 is a schematic diagram of a security processing method 200 according to an embodiment of the present application.
  • the method 200 is used by a receiving end, where a first entity of the receiving end maintains a first SN (ie, an LSN), and the first entity sends a PDCP data packet to the PDCP entity, and the value of the first SN is increased.
  • a first entity of the receiving end maintains a first SN (ie, an LSN)
  • the first entity sends a PDCP data packet to the PDCP entity, and the value of the first SN is increased.
  • the value of the first SN is incremented by one.
  • the simplest implementation is lower.
  • other values can be added, the principle is similar, but the implementation is relatively complicated, and the application does not limit this.
  • the PDCP entity receives the PDCP data packet and the first SN from the first entity.
  • the first entity may send the first SN in the PDCP data packet to the PDCP entity, and may also send the first SN and the PDCP data packet to the PDCP entity.
  • FIG. 5 is a schematic diagram of another security processing method 300 according to an embodiment of the present application.
  • the method 300 is used by a transmitting end, and the PDCP entity of the transmitting end maintains a first SN (ie, an LSN), and the PDCP entity sends a PDCP data packet to the first entity, and the value of the first SN is increased.
  • a first SN ie, an LSN
  • the PDCP entity sends a PDCP data packet to the first entity, and the value of the first SN is increased.
  • the value of the first SN is incremented by one.
  • the simplest implementation is lower.
  • other values can be added, the principle is similar, but the implementation is relatively complicated, and the application does not limit this.
  • the PDCP entity sends a PDCP data packet to the first SN, where the PDCP data packet includes a PDCP SN, the length of the first SN is greater than the length of the PDCP SN, and the first SN is used to send the first SN to the PDCP entity.
  • the parameter COUNT is adjusted when there is a missing PDCP packet in the entity's PDCP packet.
  • the PDCP entity may send the first SN to the first entity in the PDCP data packet, and may also send the first SN and the PDCP data packet to the first entity.
  • the PDCP entity may also determine whether the number of lost data packets reaches or exceeds a preset threshold.
  • the PDCP entity determines the number of lost data packets according to the packet loss information sent by the first entity. Whether the amount reaches or exceeds a preset threshold.
  • the packet loss information may include, in addition to the first SN of the first lost PDCP data packet, the first SN of the desired next PDCP data packet, or the first SN of the last PDCP data packet before the packet loss, The first SN of the first PDCP data packet received after the packet loss, or the number of lost PDCP data packets, and the like.
  • the downlink refers to the PDCP layer at the transmitting end transmitting data to the RLC layer at the transmitting end.
  • the data packet #1 is a data packet correctly received by the PDCP entity, and the PDCP entity includes multiple modes when selecting the data packet #1. For example, it is possible to select a data packet randomly or periodically, or to select a certain type of data packet. This embodiment of the present application does not specifically limit this.
  • the PDCP entity adjusts the parameter COUNT according to the calculated HFN used for decrypting the packet #2 and the PDCP SN of the packet #2, and decrypts the packet #2 using the adjusted parameter COUNT. deal with.
  • the PDCP entity selects the data packet #1 as a reference point from the plurality of PDCP data packets that are correctly sent to the RLC entity of the receiving end, and records the HFN B , SN B, and LSN B of the reference point, and determines the data packet as the decision point. #2.
  • PDCP #2 calculates the HFN to be used for decrypting the packet #A, and performs the consistency check on the PDCP SN of the packet #A in combination with the PDCP SN carried in the packet #A.
  • the consistency check of the PDCP SN of the packet #A means that it is determined whether the PDCP SN carried in the packet #A and the PDCP SN calculated according to the formula (2) are identical.
  • PDCP#2 calculates, according to the LSN, HFN, and PDCP SN of the “synchronization sequence packet” and the LSN of the data packet #B, the first data packet to be sent to the RLC entity after the packet loss (ie, the data packet of the decision point) , recorded as packet #C) HFN to be used for encryption.
  • the 802 and the PDCP entity determine whether packet loss occurs between the communication links between the RLC layer and the PDCP layer by using the LSN carried in the data packet. In the case of packet loss, it is further determined whether the number of lost packets reaches the PDCP protocol tolerance threshold.
  • the PDCP entity After receiving the LSN L sent by the RLC entity, the PDCP entity calculates an HFN to be used for the next data packet to be sent.
  • the processing unit 1200 is configured to parse the data packet received by the receiving unit into a PDCP data packet.
  • FIG. 14 is a schematic block diagram of an apparatus 3000 for security processing provided by an embodiment of the present application.
  • the device 3000 maintains the first sequence number and transmits a PDCP packet to the first entity, the value of the first sequence number increasing.
  • the device 3000 includes:
  • the processing unit 3200 is configured to: when the device sends the lost PDCP data packet in the PDCP data packet sent by the device to the first entity, obtain the packet loss information from the first entity;
  • the processing unit 3200 is further configured to adjust the parameter COUNT according to the packet loss information and the first sequence number;
  • the apparatus 3000 for security processing may correspond to the PDCP entity described in the foregoing method 300. Moreover, each module or unit in device 3000 is used to perform various actions or processes performed by the PDCP entity in method 300 above. For the sake of brevity, no further details are given here.
  • the processing unit 4200 is configured to determine whether there is a missing PDCP data packet in the PDCP data packet received by the receiving unit from the PDCP entity.
  • FIG. 16 is a schematic structural diagram of a device 5000 for security processing according to an embodiment of the present application.
  • the device 5000 includes a memory 5100, a processor 5200, and a communication interface 5300.
  • the memory 5100, the processor 5200, and the communication interface 5300 are connected to each other through a communication bus 5400.
  • the apparatus 3000 for secure processing provided in FIG. 14 above can be implemented by the securely processed apparatus 7000 shown in FIG.
  • the transmitting unit of FIG. 14 can be implemented by one or more of the communication interfaces 7300 of FIG.
  • the processing unit can be implemented by the processor 7200 shown in FIG.
  • the processor shown in Figures 16-19 above may be a central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more program programs for controlling the present invention. Execution of the integrated circuit.
  • CPU central processing unit
  • ASIC application-specific integrated circuit
  • the communication bus may include a power bus, a control bus, and a status signal bus in addition to the data bus.
  • various buses are labeled as communication buses in the figures.
  • the size of the sequence numbers of the foregoing processes does not mean the order of execution sequence, and the order of execution of each process should be determined by its function and internal logic, and should not be applied to the embodiment of the present application.
  • the implementation process constitutes any limitation.
  • the integrated unit if implemented in the form of a software functional unit and sold or used as a standalone product, may be stored in a computer readable storage medium.
  • the technical solution of the present application may be in essence or part of the contribution to the prior art, or all or part of the technical solution may be embodied in the form of a software product stored in a storage medium.
  • a number of instructions are included to cause a computer device (which may be a personal computer, server, or network device, etc.) to perform all or part of the steps of the methods described in various embodiments of the present application.
  • the foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, and the like. .

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Communication Control (AREA)

Abstract

Disclosed in the embodiments of the present application are a method and a device for security processing, for reducing failures in the security processing of a packet data convergence protocol (PDCP) layer. The method is used at the receiving end. A first entity at the receiving end maintains a first serial number, and each time a PDCP data packet is sent to a PDCP entity, the value of the first serial number is increased. The method comprises: the first entity receiving a data packet, and parsing the data packet to be a PDCP data packet; the first entity sending the PDCP data packet and the first serial number to the PDCP entity, the PDCP data packet comprising a PDCP serial number, the length of the first serial number being greater than the length of the PDCP serial number, the first serial number being used for adjusting the parameter COUNT when some of PDCP data packets sent by the first entity to the PDCP entity have been lost, the parameter COUNT being used for security processing.

Description

安全处理的方法和装置Method and device for safe handling 技术领域Technical field
本申请涉及通信领域,尤其涉及安全处理的方法和装置。The present application relates to the field of communications, and in particular to a method and apparatus for secure processing.
背景技术Background technique
在无线通信系统中,终端通过基站接入无线网络,终端与基站之间的接口称为空口。目前,空口协议栈主要包括分组数据汇聚协议(Packet Data Convergence Protocol,PDCP)层、无线链路控制(Radio Link Control,RLC)层、媒体接入控制(Media Access Control,MAC)层和物理(PHY)层。In a wireless communication system, a terminal accesses a wireless network through a base station, and an interface between the terminal and the base station is called an air interface. Currently, the air interface protocol stack mainly includes a Packet Data Convergence Protocol (PDCP) layer, a Radio Link Control (RLC) layer, a Media Access Control (MAC) layer, and a physical (PHY). )Floor.
目前,PDCP层和其下的协议层通常集中在一起布置,但是随着通信技术的发展,PDCP层和其下的协议层可能布局在不同的物理实体上,这使得PDCP层和RLC层之间可能存在大量丢包的问题。这些丢包往往引起PDCP层安全处理的失败。At present, the PDCP layer and the protocol layers under it are usually arranged together, but with the development of communication technology, the PDCP layer and the protocol layer under it may be placed on different physical entities, which makes the PDCP layer and the RLC layer There may be a lot of problems with packet loss. These packet loss often cause the failure of the PDCP layer to be handled securely.
发明内容Summary of the invention
本申请提供一种安全处理的方法和装置,以期减少PDCP层安全处理的失败。The present application provides a method and apparatus for secure processing to reduce the failure of the PDCP layer security processing.
第一方面,本申请提供一种安全处理的方法,用于接收端,所述接收端的第一实体维护第一序列号,且每向分组数据汇聚协议PDCP实体发送一个PDCP数据包,所述第一序列号的值增加,所述方法包括:所述第一实体接收数据包,并将所述数据包解析为PDCP数据包;所述第一实体向所述PDCP实体发送所述PDCP数据包和第一序列号,其中,所述PDCP数据包包括PDCP序列号,所述第一序列号的长度大于所述PDCP序列号的长度,且所述第一序列号用于在所述第一实体发送给所述PDCP实体的PDCP数据包中存在丢失的PDCP数据包时调整参数COUNT,所述参数COUNT用于安全处理。In a first aspect, the present application provides a method for security processing, where a first entity of the receiving end maintains a first sequence number, and a PDCP data packet is sent to a packet data convergence protocol PDCP entity. The value of a sequence number is increased, the method comprising: the first entity receiving a data packet and parsing the data packet into a PDCP data packet; the first entity sending the PDCP data packet to the PDCP entity and a first sequence number, wherein the PDCP data packet includes a PDCP sequence number, a length of the first sequence number is greater than a length of the PDCP sequence number, and the first sequence number is used to be sent by the first entity The parameter COUNT is adjusted when there is a missing PDCP packet in the PDCP packet of the PDCP entity, and the parameter COUNT is used for security processing.
在一种可能的实现方式中,所述第一序列号在所述第一实体发送给所述PDCP实体的PDCP数据包中存在丢失的PDCP数据包,且所述丢失的PDCP数据包达到或超过预设阈值时,用于调整参数COUNT。In a possible implementation manner, the first sequence number has a lost PDCP data packet in a PDCP data packet sent by the first entity to the PDCP entity, and the lost PDCP data packet meets or exceeds Used to adjust the parameter COUNT when the threshold is preset.
在一种可能的实现方式中,所述第一实体每向所述PDCP实体发送一个 PDCP数据包,所述第一序列号的值加1。In a possible implementation manner, the first entity sends one to each of the PDCP entities. The PDCP packet, the value of the first sequence number is incremented by one.
在一种可能的实现方式中,所述第一实体为无线链路控制RLC实体。In a possible implementation manner, the first entity is a radio link control RLC entity.
第二方面,本申请提供一种安全处理的方法,用于接收端,所述方法包括:分组数据汇聚协议PDCP实体从第一实体接收PDCP数据包和第一序列号,其中所述第一序列号的值在所述第一实体每向所述PDCP实体发送一个PDCP数据包时增加,所述PDCP数据包包括PDCP序列号,所述第一序列号的长度大于所述PDCP序列号的长度,且所述第一序列号用于在所述PDCP实体从所述第一实体接收的PDCP数据包中存在丢失的PDCP数据包时调整参数COUNT;当所述PDCP实体从所述第一实体接收的PDCP数据包中存在丢失的PDCP数据包时,所述PDCP实体根据所述第一序列号调整参数COUNT;所述PDCP实体根据调整后的参数COUNT对第一PDCP数据包进行安全处理,其中,所述第一PDCP数据包为丢包后接收的PDCP数据包。In a second aspect, the present application provides a method for security processing, for a receiving end, the method comprising: a packet data convergence protocol PDCP entity receiving a PDCP data packet and a first sequence number from a first entity, wherein the first sequence The value of the number is increased when the first entity sends a PDCP data packet to the PDCP entity, where the PDCP data packet includes a PDCP sequence number, and the length of the first sequence number is greater than the length of the PDCP sequence number. And the first sequence number is used to adjust a parameter COUNT when there is a lost PDCP data packet in a PDCP data packet received by the PDCP entity from the first entity; when the PDCP entity receives from the first entity When there is a lost PDCP data packet in the PDCP data packet, the PDCP entity adjusts the parameter COUNT according to the first sequence number; the PDCP entity performs security processing on the first PDCP data packet according to the adjusted parameter COUNT, where The first PDCP data packet is a PDCP data packet received after the packet loss.
在一种可能的实现方式中,所述PDCP实体根据所述第一序列号调整参数COUNT,包括:当所述PDCP实体从所述第一实体接收的PDCP数据包中存在丢失的PDCP数据包,且所述丢失的PDCP数据包的数量达到或超过预设阈值时,所述PDCP实体根据所述第一序列号调整参数COUNT。In a possible implementation manner, the PDCP entity adjusts the parameter COUNT according to the first sequence number, including: when the PDCP entity receives a lost PDCP data packet from a PDCP data packet received by the first entity, And when the number of the lost PDCP data packets reaches or exceeds a preset threshold, the PDCP entity adjusts the parameter COUNT according to the first sequence number.
在一种可能的实现方式中,所述PDCP实体根据所述第一序列号调整参数COUNT,包括:所述PDCP实体从丢失的PDCP数据包之前正确接收的PDCP数据包中选择第二数据包;根据所述第二数据包的第一序列号、所述第二数据包的PDCP序列号、所述第二数据包的超帧号HFN、所述第一数据包的第一序列号和所述第一数据包的PDCP序列号,确定所述第一数据包的HFN;根据所述第一数据包的HFN和所述第一数据包的PDCP序列号,确定参数COUNT。In a possible implementation manner, the PDCP entity adjusts the parameter COUNT according to the first sequence number, including: the PDCP entity selects a second data packet from a PDCP data packet that is correctly received before the lost PDCP data packet; And according to the first sequence number of the second data packet, the PDCP sequence number of the second data packet, the super frame number HFN of the second data packet, the first sequence number of the first data packet, and the a PDCP sequence number of the first data packet, determining an HFN of the first data packet; determining a parameter COUNT according to an HFN of the first data packet and a PDCP sequence number of the first data packet.
在一种可能的实现方式中,根据第二数据包的第一序列号、第二数据包的PDCP序列号、第二数据包的超帧号HFN、第一数据包的第一序列号和第一数据包的PDCP序列号,确定第一数据包的HFN,包括:根据以下公式确定所述第一数据包的HFN:In a possible implementation, the first sequence number of the second data packet, the PDCP sequence number of the second data packet, the super frame number HFN of the second data packet, the first serial number of the first data packet, and the first Determining the HFN of the first data packet by determining a PDCP sequence number of the data packet includes: determining an HFN of the first data packet according to the following formula:
Figure PCTCN2016108034-appb-000001
Figure PCTCN2016108034-appb-000001
其中,HFNN为第一数据包的HFN,SNN为第一数据包的PDCP SN,LSNN为第一数据包的第一序列号,LSNB为第二数据包的第一序列号,HFNB为第 二数据包的HFN,SNB为第二数据包的PDCP SN,c为参数COUNT的长度,n为PDCP SN的长度,k为第一序列号的长度。Wherein, HFN N is the HFN of the first data packet, SN N is the PDCP SN of the first data packet, LSN N is the first sequence number of the first data packet, and LSN B is the first sequence number of the second data packet, HFN B is the HFN of the second data packet, SN B is the PDCP SN of the second data packet, c is the length of the parameter COUNT, n is the length of the PDCP SN, and k is the length of the first serial number.
在一种可能的实现方式中,第一序列号的值在第一实体每向PDCP实体发送一个PDCP数据包时加1。In a possible implementation manner, the value of the first sequence number is incremented by one when the first entity sends a PDCP data packet to the PDCP entity.
在一种可能的实现方式中,第一实体为无线链路控制RLC实体。In a possible implementation manner, the first entity is a radio link control RLC entity.
第三方面,本申请提供一种安全处理的方法,用于发送端,其中发送端的分组数据汇聚协议PDCP实体维护第一序列号,且每向第一实体发送一个PDCP数据包,第一序列号的值增加,该方法包括:PDCP实体向第一实体发送PDCP数据包和第一序列号,其中,PDCP数据包包括PDCP序列号,第一序列号的长度大于PDCP序列号的长度,且第一序列号用于在PDCP实体发送给第一实体的PDCP数据包中存在丢失的PDCP数据包时调整参数COUNT;当PDCP实体发送给第一实体的PDCP数据包中存在丢失的PDCP数据包时,PDCP实体从第一实体获取丢包信息;PDCP实体根据丢包信息和第一序列号调整参数COUNT;PDCP实体根据调整后的参数COUNT对第一PDCP数据包进行安全处理,其中,第一PDCP数据包为丢包后发送的PDCP数据包。In a third aspect, the present application provides a method for security processing, where a packet data convergence protocol PDCP entity at a transmitting end maintains a first sequence number, and sends a PDCP data packet to a first entity, a first sequence number. The method includes: the PDCP entity sends the PDCP data packet and the first sequence number to the first entity, where the PDCP data packet includes a PDCP sequence number, the length of the first sequence number is greater than the length of the PDCP sequence number, and the first The sequence number is used to adjust the parameter COUNT when there is a missing PDCP data packet in the PDCP data packet sent by the PDCP entity to the first entity; when there is a missing PDCP data packet in the PDCP data packet sent by the PDCP entity to the first entity, the PDCP The entity obtains the packet loss information from the first entity; the PDCP entity adjusts the parameter COUNT according to the packet loss information and the first sequence number; the PDCP entity performs security processing on the first PDCP data packet according to the adjusted parameter COUNT, where the first PDCP data packet PDCP packet sent after packet loss.
在一种可能的实现方式中,PDCP实体根据第一序列号调整参数COUNT,包括:当PDCP实体发送给第一实体的PDCP数据包中存在丢失的PDCP数据包,且该丢失的PDCP数据包的数量达到或超过预设阈值时,PDCP实体根据第一序列号调整参数COUNT。In a possible implementation manner, the PDCP entity adjusts the parameter COUNT according to the first sequence number, including: when there is a lost PDCP data packet in the PDCP data packet sent by the PDCP entity to the first entity, and the lost PDCP data packet When the number reaches or exceeds the preset threshold, the PDCP entity adjusts the parameter COUNT according to the first sequence number.
在一种可能的实现方式中,PDCP实体根据丢包信息和第一序列号调整参数COUNT,包括:PDCP实体根据丢包信息从丢失的PDCP数据包之前被第一实体正确接收的PDCP数据包中选择第二数据包,并确定丢包前最后一个正确接收的第三PDCP数据包;根据第二数据包的第一序列号、第二数据包的PDCP序列号、第二数据包的超帧号HFN、第三数据包的第一序列号,和第一数据包的PDCP序列号,确定第一数据包的HFN;根据第一数据包的HFN和第一数据包的PDCP序列号,确定参数COUNT。In a possible implementation manner, the PDCP entity adjusts the parameter COUNT according to the packet loss information and the first sequence number, including: the PDCP entity is correctly received by the first entity from the lost PDCP data packet according to the packet loss information. Selecting the second data packet, and determining the last correctly received third PDCP data packet before the packet loss; according to the first sequence number of the second data packet, the PDCP sequence number of the second data packet, and the super frame number of the second data packet HFN, a first sequence number of the third data packet, and a PDCP sequence number of the first data packet, determining an HFN of the first data packet; determining a parameter COUNT according to the HFN of the first data packet and the PDCP sequence number of the first data packet .
在一种可能的实现方式中,根据第二数据包的第一序列号、第二数据包的PDCP序列号、第二数据包的超帧号HFN、第三数据包的第一序列号和第一数据包的PDCP序列号,确定第一数据包的HFN,包括:根据以下公式确定第一数据包的HFN: In a possible implementation, the first sequence number of the second data packet, the PDCP sequence number of the second data packet, the super frame number HFN of the second data packet, the first serial number of the third data packet, and the first Determining the HFN of the first data packet by determining the PDCP sequence number of the data packet includes: determining the HFN of the first data packet according to the following formula:
Figure PCTCN2016108034-appb-000002
Figure PCTCN2016108034-appb-000002
,其中,HFNN为第一数据包的HFN,SNN为第一数据包的PDCP SN,LSNL为第三数据包的第一序列号,LSNB为第二数据包的第一序列号,HFNB为第二数据包的HFN,SNB为第二数据包的PDCP SN,c为参数COUNT的长度,n为PDCP SN的长度,k为第一序列号的长度,t为常数,且为大于或等于1的正整数。Where HFN N is the HFN of the first data packet, SN N is the PDCP SN of the first data packet, LSN L is the first sequence number of the third data packet, and LSN B is the first sequence number of the second data packet, HFN B is the HFN of the second data packet, SN B is the PDCP SN of the second data packet, c is the length of the parameter COUNT, n is the length of the PDCP SN, k is the length of the first serial number, t is a constant, and is A positive integer greater than or equal to 1.
在一种可能的实现方式中,丢包信息包括以下信息之一或更多:第一个丢失的PDCP数据包的第一SN、期望的下一个PDCP数据包的第一SN、丢包前最后一个PDCP数据包的第一SN、丢包后接收的第一个PDCP数据包的第一SN、丢失的PDCP数据包的数量。In a possible implementation manner, the packet loss information includes one or more of the following information: a first SN of the first lost PDCP data packet, a first SN of the expected next PDCP data packet, and a last packet loss The first SN of a PDCP packet, the first SN of the first PDCP packet received after packet loss, and the number of lost PDCP packets.
在一种可能的实现方式中,PDCP实体每向第一实体发送一个PDCP数据包,第一序列号的值加1。In a possible implementation manner, the PDCP entity sends a PDCP data packet to the first entity, and the value of the first sequence number is incremented by one.
在一种可能的实现方式中,第一实体为无线链路控制RLC实体。In a possible implementation manner, the first entity is a radio link control RLC entity.
第四方面,本申请提供一种安全处理的方法,用于发送端,该方法包括:第一实体从分组数据汇聚协议PDCP实体接收PDCP数据包和第一序列号,其中,第一序列号的值在PDCP实体每向第一实体发送一个PDCP数据包时增加,PDCP数据包包括PDCP序列号,第一序列号的长度大于PDCP序列号的长度,且第一序列号用于在第一实体从PDCP实体接收的PDCP数据包中存在丢失的PDCP数据包时调整参数COUNT;当第一实体从PDCP实体接收的PDCP数据包中存在丢失的PDCP数据包时,第一实体通知PDCP实体丢包信息;第一实体在丢包后从PDCP实体接收第一PDCP数据包,且第一PDCP数据包的安全处理是根据调整后的参数COUNT进行的,且该参数COUNT的调整是根据第一序列号和丢包信息进行的。In a fourth aspect, the application provides a method for security processing, where the method includes: receiving, by a first entity, a PDCP data packet and a first sequence number from a packet data convergence protocol PDCP entity, where the first serial number is The value is increased when the PDCP entity sends a PDCP data packet to the first entity. The PDCP data packet includes a PDCP sequence number, the length of the first sequence number is greater than the length of the PDCP sequence number, and the first sequence number is used in the first entity. The parameter COUNT is adjusted when there is a missing PDCP data packet in the PDCP data packet received by the PDCP entity; when the first entity receives the lost PDCP data packet from the PDCP data packet received by the PDCP entity, the first entity notifies the PDCP entity of the packet loss information; The first entity receives the first PDCP data packet from the PDCP entity after the packet loss, and the security processing of the first PDCP data packet is performed according to the adjusted parameter COUNT, and the adjustment of the parameter COUNT is based on the first serial number and the lost Package information is carried out.
在一种可能的实现方式中,第一序列号在第一实体从PDCP实体接收的PDCP数据包中存在丢失的PDCP数据包,且丢失的PDCP数据包达到或超过预设阈值时,用于调整参数COUNT。In a possible implementation manner, the first sequence number is used to adjust when there is a missing PDCP data packet in the PDCP data packet received by the first entity from the PDCP entity, and the lost PDCP data packet reaches or exceeds a preset threshold. Parameter COUNT.
在一种可能的实现方式中,丢包信息包括以下信息之一或更多:第一个丢失的PDCP数据包的第一SN、期望的下一个PDCP数据包的第一SN、丢包前最后一个PDCP数据包的第一SN、丢包后接收的第一个PDCP数据包的第一SN、丢失的PDCP数据包的数量。In a possible implementation manner, the packet loss information includes one or more of the following information: a first SN of the first lost PDCP data packet, a first SN of the expected next PDCP data packet, and a last packet loss The first SN of a PDCP packet, the first SN of the first PDCP packet received after packet loss, and the number of lost PDCP packets.
在一种可能的实现方式中,第一序列号的值在PDCP实体每向第一实体 发送一个PDCP数据包时加1。In a possible implementation manner, the value of the first sequence number is in the first entity of the PDCP entity. Add 1 when sending a PDCP packet.
在一种可能的实现方式中,第一实体为无线链路控制RLC实体。In a possible implementation manner, the first entity is a radio link control RLC entity.
第五方面,本申请提供一种安全处理的装置,包括,用于执行以上第一方面各个步骤的单元或手段(means)。In a fifth aspect, the present application provides an apparatus for secure processing, comprising means or means for performing the various steps of the above first aspect.
第六方面,本申请提供一种安全处理的装置,包括,用于执行以上第二方面各个步骤的单元或手段(means)。In a sixth aspect, the present application provides an apparatus for secure processing, comprising means or means for performing the various steps of the second aspect above.
第七方面,本申请提供一种安全处理的装置,包括,用于执行以上第三方面各个步骤的单元或手段(means)。In a seventh aspect, the present application provides an apparatus for secure processing, comprising means or means for performing the various steps of the third aspect above.
第八方面,本申请提供一种安全处理的装置,包括,用于执行以上第四方面各个步骤的单元或手段(means)。In an eighth aspect, the present application provides an apparatus for secure processing, comprising means or means for performing the various steps of the above fourth aspect.
第九方面,本申请提供一种安全处理的装置,包括处理器和存储器,存储器用于存储程序,处理器用于调用存储器存储的程序,以执行上述第一方面中提供的方法。In a ninth aspect, the present application provides an apparatus for secure processing, comprising a processor for storing a program, and a processor for calling a program stored in the memory to perform the method provided in the first aspect above.
第十方面,本申请提供一种安全处理的装置,包括处理器和存储器,存储器用于存储程序,处理器用于调用存储器存储的程序,以执行上述第二方面中提供的方法。In a tenth aspect, the present application provides an apparatus for secure processing, comprising a processor for storing a program, and a processor for calling a program stored in the memory to perform the method provided in the second aspect above.
第十一方面,本申请提供一种安全处理的装置,包括处理器和存储器,存储器用于存储程序,处理器用于调用存储器存储的程序,以执行上述第三方面中提供的方法。In an eleventh aspect, the present application provides a device for secure processing, comprising a processor for storing a program, and a processor for calling a program stored in the memory to perform the method provided in the above third aspect.
第十二方面,本申请提供一种安全处理的装置,包括处理器和存储器,存储器用于存储程序,处理器用于调用存储器存储的程序,以执行上述第四方面中提供的方法。In a twelfth aspect, the present application provides an apparatus for secure processing, comprising a processor for storing a program, and a processor for calling a program stored in the memory to perform the method provided in the fourth aspect above.
第十三方面,本申请提供一种安全处理的装置,包括用于执行上述第一方面的方法的至少一个处理元件(或芯片)。In a thirteenth aspect, the present application provides an apparatus for secure processing, comprising at least one processing element (or chip) for performing the method of the above first aspect.
第十四方面,本申请提供一种安全处理的装置,包括用于执行上述第二方面的方法的至少一个处理元件(或芯片)。In a fourteenth aspect, the present application provides a device for secure processing, comprising at least one processing element (or chip) for performing the method of the second aspect above.
第十五方面,本申请提供一种安全处理的装置,包括用于执行上述第三方面的方法的至少一个处理元件(或芯片)。In a fifteenth aspect, the present application provides an apparatus for secure processing, comprising at least one processing element (or chip) for performing the method of the above third aspect.
第十六方面,本申请提供一种安全处理的装置,包括用于执行上述第四方面的方法的至少一个处理元件(或芯片)。In a sixteenth aspect, the present application provides an apparatus for secure processing, comprising at least one processing element (or chip) for performing the method of the above fourth aspect.
第十七方面,本申请提供一种安全处理的程序,该程序在处理器执行时, 用于执行上述第一方面中的方法。In a seventeenth aspect, the present application provides a program for secure processing, when the processor executes Used to perform the method of the first aspect above.
第十八方面,本申请提供一种安全处理的程序,该程序在处理器执行时,用于执行上述第二方面中的方法。In an eighteenth aspect, the present application provides a secure processing program for performing the method of the second aspect described above when executed by a processor.
第十九方面,本申请提供一种安全处理的程序,该程序在处理器执行时,用于执行上述第三方面中的方法。In a nineteenth aspect, the present application provides a secure processing program for performing the method of the above third aspect when executed by a processor.
第二十方面,本申请提供一种安全处理的程序,该程序在处理器执行时,用于执行上述第四方面中的方法。In a twentieth aspect, the present application provides a secure processing program for performing the method of the above fourth aspect when executed by a processor.
第二十一方面,本申请提供一种程序产品,例如,计算机可读存储介质。包括第十七方面的程序。In a twenty first aspect, the application provides a program product, such as a computer readable storage medium. Includes the procedure of the seventeenth aspect.
第二十二方面,本申请提供一种程序产品,例如,计算机可读存储介质。包括第十八方面的程序。In a twenty second aspect, the application provides a program product, such as a computer readable storage medium. Includes the procedures of the eighteenth aspect.
第二十三方面,本申请提供一种程序产品,例如,计算机可读存储介质。包括第十九方面的程序。In a twenty-third aspect, the application provides a program product, such as a computer readable storage medium. Includes the procedures of the nineteenth aspect.
第二十四方面,本申请提供一种程序产品,例如,计算机可读存储介质。包括第二十方面的程序。In a twenty-fourth aspect, the application provides a program product, such as a computer readable storage medium. Includes the twentieth aspect of the program.
可见,本申请实施例中,通过在传输数据包的发送端或接收端的分组数据汇聚协议PDCP层和无线链路控制RLC层之间传递第一序列号(其中,第一序列号的长度大于该数据包携带的PDCP序列号的长度),从而在PDCP层和RLC层之间发生数据丢包时,发送端或接收端可以利用该第一序列号调整参数COUNT。由于第一序列号的长度大于PDCP序列号的长度,因此,发送端或接收端对丢失数据包的容忍度增加,从而能够减少安全处理的失败。It can be seen that, in the embodiment of the present application, the first sequence number is transmitted between the packet data convergence protocol PDCP layer and the radio link control RLC layer at the transmitting end or the receiving end of the transport data packet (where the length of the first serial number is greater than the length The length of the PDCP sequence number carried in the data packet, so that when data loss occurs between the PDCP layer and the RLC layer, the transmitting end or the receiving end can adjust the parameter COUNT by using the first serial number. Since the length of the first sequence number is greater than the length of the PDCP sequence number, the tolerance of the lost data packet is increased at the transmitting end or the receiving end, thereby reducing the failure of the security processing.
附图说明DRAWINGS
图1为本申请实施例提供的一种通信场景的示意图。FIG. 1 is a schematic diagram of a communication scenario according to an embodiment of the present application.
图2为本申请实施例提供的一种空口协议栈的结构示意图。FIG. 2 is a schematic structural diagram of an air interface protocol stack according to an embodiment of the present disclosure.
图3为本申请实施例提供的一种参数COUNT的格式示意图。FIG. 3 is a schematic diagram of a format of a parameter COUNT according to an embodiment of the present application.
图4为本申请实施例提供的一种安全处理方法200的示意图。FIG. 4 is a schematic diagram of a security processing method 200 according to an embodiment of the present application.
图5为本申请实施例提供的另一种安全处理方法300的示意图。FIG. 5 is a schematic diagram of another security processing method 300 according to an embodiment of the present disclosure.
图6为本申请实施例提供的一种数据包、参数COUNT和第一序列号的示意图。 FIG. 6 is a schematic diagram of a data packet, a parameter COUNT, and a first sequence number according to an embodiment of the present application.
图7为本申请实施例提供的安全处理的方法200的一个示例。FIG. 7 is an example of a method 200 of security processing provided by an embodiment of the present application.
图8为本申请实施例提供的安全处理的方法200的另一示例。FIG. 8 is another example of a method 200 of security processing provided by an embodiment of the present application.
图9为本申请实施例应用于主备冗余系统中上行丢包场景的示意图。FIG. 9 is a schematic diagram of an uplink packet loss scenario applied to an active/standby redundancy system according to an embodiment of the present application.
图10为本申请实施例应用于主备冗余系统中下行丢包场景的示意图。FIG. 10 is a schematic diagram of a downlink packet loss scenario applied to an active/standby redundancy system according to an embodiment of the present application.
图11为本申请实施例应用于RLC层与PDCP层之间通信链路异常导致丢包场景下的示意图。FIG. 11 is a schematic diagram of a packet loss scenario caused by an abnormal communication link between an RLC layer and a PDCP layer according to an embodiment of the present application.
图12为本申请实施例提供的安全处理的装置1000的示意性框图。FIG. 12 is a schematic block diagram of an apparatus 1000 for security processing according to an embodiment of the present application.
图13为本申请实施例的安全处理的装置2000的示意性框图。FIG. 13 is a schematic block diagram of a device 2000 for security processing according to an embodiment of the present application.
图14为本申请实施例提供的安全处理的装置3000的示意性框图。FIG. 14 is a schematic block diagram of an apparatus 3000 for security processing according to an embodiment of the present application.
图15为本申请实施例提供的安全处理的装置4000的示意性框图。FIG. 15 is a schematic block diagram of a device 4000 for security processing according to an embodiment of the present application.
图16为本申请实施例提供的安全处理的设备5000的示意性结构图。FIG. 16 is a schematic structural diagram of a device 5000 for security processing according to an embodiment of the present application.
图17为本申请实施例提供的安全处理的设备6000的示意性结构图。FIG. 17 is a schematic structural diagram of a device 6000 for security processing according to an embodiment of the present application.
图18为本申请实施例提供的安全处理的设备7000的示意性结构图。FIG. 18 is a schematic structural diagram of a device 7000 for security processing according to an embodiment of the present application.
图19为本申请实施例提供的安全处理的设备8000的示意性结构图。FIG. 19 is a schematic structural diagram of a device 8000 for security processing according to an embodiment of the present application.
具体实施方式detailed description
下面结合附图,对本申请实施例的技术方案进行描述。The technical solutions of the embodiments of the present application are described below with reference to the accompanying drawings.
本申请实施例中:终端又称之为用户设备(User Equipment,UE),是一种向用户提供语音和/或数据连通性的设备。例如,具有无线连接功能的手持式设备、车载设备等。常见的终端例如包括:手机、平板电脑、笔记本电脑、掌上电脑、移动互联网设备(mobile internet device,MID)、可穿戴设备,例如智能手表、智能手环、计步器等。In the embodiment of the present application, the terminal is also referred to as a User Equipment (UE), and is a device that provides voice and/or data connectivity to the user. For example, a handheld device having a wireless connection function, an in-vehicle device, or the like. Common terminals include, for example, mobile phones, tablets, notebook computers, PDAs, mobile internet devices (MIDs), wearable devices such as smart watches, smart bracelets, pedometers, and the like.
基站又称为无线接入网(Radio Access Network,RAN)设备,是一种将终端接入到无线网络的设备,包括但不限于:演进型节点B(evolved Node B,eNB)、无线网络控制器(radio network controller,RNC)、节点B(Node B,NB)、基站控制器(Base Station Controller,BSC)、基站收发台(Base Transceiver Station,BTS)、家庭基站(例如,Home evolved NodeB,或Home Node B,HNB)、基带单元(BaseBand Unit,BBU)。此外,还可以包括Wifi接入点(Access Point,AP)等。The base station is also referred to as a radio access network (RAN) device, and is a device for accessing a terminal to a wireless network, including but not limited to: an evolved Node B (eNB), and a wireless network control. Radio network controller (RNC), Node B (Node B, NB), Base Station Controller (BSC), Base Transceiver Station (BTS), home base station (for example, Home evolved NodeB, or Home Node B, HNB), BaseBand Unit (BBU). In addition, a Wifi Access Point (AP) or the like may also be included.
此外,在本申请实施例中,编号“第一”、“第二”等仅仅为了区分不同的对象。例如,为了区分不同的数据包,不应对本申请实施例的保护范围构 成任何限定。“多个”是指两个或两个以上。“和/或”,描述关联对象的关联关系,表示可以存在三种关系,例如,A和/或B,可以表示:单独存在A,同时存在A和B,单独存在B这三种情况。字符“/”一般表示前后关联对象是一种“或”的关系。In addition, in the embodiment of the present application, the numbers "first", "second", and the like are merely for distinguishing different objects. For example, in order to distinguish different data packets, the protection scope of the embodiment of the present application should not be Become any limit. "Multiple" means two or more. "and/or", describing the association relationship of the associated objects, indicating that there may be three relationships, for example, A and/or B, which may indicate that there are three cases where A exists separately, A and B exist at the same time, and B exists separately. The character "/" generally indicates that the contextual object is an "or" relationship.
请参考图1,其为本申请实施例提供的一种通信场景的示意图。如图1所示,终端120通过基站110接入到无线网络,以通过无线网络获取外网(例如,因特网)的服务,或者通过无线网络与其它终端通信。Please refer to FIG. 1 , which is a schematic diagram of a communication scenario according to an embodiment of the present application. As shown in FIG. 1, the terminal 120 accesses the wireless network through the base station 110 to acquire services of an external network (e.g., the Internet) through the wireless network, or communicates with other terminals through the wireless network.
终端与基站之间的接口称为空口,又称为Uu口。请参考图2,其为本申请实施例提供的一种空口协议栈的结构示意图。如图2所示,空口协议栈包括但不限于PDCP层、RLC层、MAC层和PHY层。对于控制面,还包括(Radio Resource Control,RRC)层。PDCP层在控制面的上层是RRC层,在用户面的上层是网络层,例如因特网协议(Internet Protocol,IP)层。PDCP层的下层是RLC层。PDCP层可以处理控制面上的RRC消息和用户面上的数据包,例如IP包。PDCP层的主要功能包括安全处理功能,该安全处理功能可以包括数据的加/解密,和/或,完整性保护/校验。对控制面的数据,PDCP可以进行完整性保护/校验和加/解密;对用户面的数据,PDCP可以只进行加/解密,不进行完整性保护/校验。在某些场景,例如,中继(relay)或蜂窝物联网(CIoT)等,可以对用户面数据进行完整性保护/校验。其中加密和完整性保护是对于发送端而言的,解密和完整性校验是对于接收端而言的。以下行传输为例,在用户面上,PDCP层将来自上层的IP数据分组后,对IP数据分组进行加密,然后递交到RLC层。在控制面上,PDCP层为上层RRC提供信令传输服务,并实现RRC信令的加密和完整性保护。类似的,在上行传输中,在用户面上,PDCP层可以实现对上行数据包的解密;在控制面上,可以实现RRC信令的解密和完整性校验。The interface between the terminal and the base station is called an air interface, and is also called a Uu port. Please refer to FIG. 2 , which is a schematic structural diagram of an air interface protocol stack according to an embodiment of the present application. As shown in FIG. 2, the air interface protocol stack includes but is not limited to a PDCP layer, an RLC layer, a MAC layer, and a PHY layer. For the control plane, a (Radio Resource Control, RRC) layer is also included. The PDCP layer is the RRC layer on the upper layer of the control plane, and the network layer on the upper layer of the user plane, such as the Internet Protocol (IP) layer. The lower layer of the PDCP layer is the RLC layer. The PDCP layer can process RRC messages on the control plane and data packets on the user plane, such as IP packets. The main functions of the PDCP layer include security processing functions, which may include encryption/decryption of data, and/or integrity protection/verification. For the control plane data, PDCP can perform integrity protection/checking and encryption/decryption; for user plane data, PDCP can only perform encryption/decryption without integrity protection/verification. In some scenarios, such as relay or cellular Internet of Things (CIoT), integrity protection/verification of user plane data can be performed. The encryption and integrity protection is for the sender, and the decryption and integrity check is for the receiver. The following line transmission is taken as an example. On the user plane, the PDCP layer encrypts the IP data packets from the upper layer and then delivers the IP data packets to the RLC layer. On the control plane, the PDCP layer provides signaling transmission services for the upper layer RRC, and implements encryption and integrity protection of RRC signaling. Similarly, in the uplink transmission, on the user plane, the PDCP layer can decrypt the uplink data packet; on the control plane, the decryption and integrity check of the RRC signaling can be implemented.
在本申请实施例中的数据包可以是用户面的数据包,也可以是控制面的数据包。The data packet in the embodiment of the present application may be a data packet of a user plane, or may be a data packet of a control plane.
在对数据包进行完整性保护或者加/解密的过程中,需要用到参数,计数(COUNT)。请参考图3,其为本申请实施例提供的一种参数COUNT的格式示意图。如图3所示,该参数COUNT包括两部分,分别为高位的超帧号(Hyper Frame Number,HFN)和低位的PDCP序列号(PDCP Sequence Number,PDCP SN)。 In the process of integrity protection or encryption/decryption of data packets, parameters and counts (COUNT) are needed. Please refer to FIG. 3 , which is a schematic diagram of a format of a parameter COUNT according to an embodiment of the present application. As shown in FIG. 3, the parameter COUNT includes two parts, a high-order Hyper Frame Number (HFN) and a low-level PDCP Sequence Number (PDCP SN).
PDCP SN和HFN由PDCP层维护,初始值均可以为0,当然也可以将初始值设定为其它值,本申请不做限制。令发送端PDCP层维护的PDCP SN为TX_PDCP SN,且每发送一个数据包,TX_PDCP SN的数值加1,且当前的TX_PDCP SN表示下一个将要发送的PDCP数据包的序列号。当TX_PDCP SN达到最大值时,HFN加1,TX_PDCP SN重置为0。发送的PDCP数据包中携带的PDCP SN表示当前发送的PDCP数据包的序列号。令接收端PDCP层维护的PDCP SN为RX_PDCP SN,且接收端PDCP层维护的RX_PDCP SN的数值为当前接收的PDCP数据包的PDCP SN加1,其表示下一个接收到的PDCP数据包的期望序列号。当RX_PDCP SN达到最大值时,HFN加1,RX_PDCP SN重置为0。PDCP SN的长度包括但不限于以下任一数值:5bit、7bit、12bit、15bit和16bit。参数COUNT的长度通常为32bit,若PDCP SN的长度为n bit,则HFN的长度为(32-n)bit。The PDCP SN and the HFN are maintained by the PDCP layer, and the initial value may be 0. Of course, the initial value may be set to other values, which is not limited in this application. The PDCP SN maintained by the PDCP layer of the transmitting end is TX_PDCP SN, and the value of TX_PDCP SN is incremented by one every time a data packet is transmitted, and the current TX_PDCP SN indicates the sequence number of the next PDCP data packet to be transmitted. When TX_PDCP SN reaches the maximum value, HFN is incremented by 1, and TX_PDCP SN is reset to zero. The PDCP SN carried in the transmitted PDCP data packet indicates the serial number of the currently transmitted PDCP data packet. The PDCP SN maintained by the PDCP layer of the receiving end is the RX_PDCP SN, and the value of the RX_PDCP SN maintained by the PDCP layer of the receiving end is 1 for the PDCP SN of the currently received PDCP packet, which indicates the expected sequence of the next received PDCP packet. number. When the RX_PDCP SN reaches the maximum value, the HFN is incremented by 1, and the RX_PDCP SN is reset to zero. The length of the PDCP SN includes but is not limited to any of the following values: 5bit, 7bit, 12bit, 15bit, and 16bit. The length of the parameter COUNT is usually 32 bits. If the length of the PDCP SN is n bit, the length of the HFN is (32-n) bits.
以PDCP层的数据包加/解密过程为例,发送端使用COUNT及其它参数对数据包进行加密,并在包头上携带该数据包的PDCP SN发送给接收端。发送端仅发送PDCP SN,而不发送HFN。接收端接收到数据包后,从包头中解析出PDCP SN,和自己维护的HFN一起拼接成COUNT,对收到的数据包进行解密。Taking the packet encryption/decryption process of the PDCP layer as an example, the transmitting end encrypts the data packet by using COUNT and other parameters, and sends the PDCP SN carrying the data packet on the packet header to the receiving end. The sender only sends the PDCP SN and does not send the HFN. After receiving the data packet, the receiving end parses the PDCP SN from the packet header and splices it into COUNT together with the HFN maintained by itself to decrypt the received data packet.
在上述过程中,在数据包没有丢失的情况下,发送端和接收端的HFN是相同的,因此COUNT也是相同的。但是,如果收发数据包的过程中有大量数据包丢失,可能会造成发送端和接收端的HFN不一致,进而导致COUNT的值不一致。而COUNT的值不一致会造成接收端解密失败。In the above process, the HFN of the transmitting end and the receiving end are the same in the case where the data packet is not lost, so the COUNT is also the same. However, if a large number of data packets are lost during the process of sending and receiving data packets, the HFNs of the sender and the receiver may be inconsistent, which may result in inconsistent values of COUNT. The inconsistent value of COUNT will cause the receiving end to fail to decrypt.
比如,发送端维护的TX_PDCP SN为11,则发送端发送PDCP数据包,该PDCP数据包携带的PDCP SN为11,且将TX_PDCP SN加1。此时,接收端接收到的数据包携带的PDCP SN为11,RX_PDCP SN加1,为12,即下一个接收到的PDCP数据包的期望序列号为12。然而,接下来,发送端发送的数据包大量丢失,且丢失的数据包的数量超过了PDCP SN最大值,但发送端的TX_PDCP SN随着发送PDCP数据包的增加,TX_PDCP SN不断增加,并发生了翻转,从而HFN至少加1。而接收端没有接收到丢失的数据包,因此RX_PDCP SN仍然为12,HFN并没有和发送端一样发生变化;甚至当丢失的数据包使得接收端接收到的数据包的PDCP SN在12之后(例如为14)时,接收端并不知道HFN发生了变化,因此接收端和发送端维护的 HFN不同,参数COUNT不一致,导致解密失败。For example, if the TX_PDCP SN maintained by the sender is 11, the sender sends a PDCP packet, the PDCP SN carried by the PDCP packet is 11, and the TX_PDCP SN is incremented by 1. At this time, the data packet received by the receiving end carries a PDCP SN of 11, and the RX_PDCP SN is incremented by 1, which is 12, that is, the expected sequence number of the next received PDCP data packet is 12. However, next, the number of data packets sent by the sender is lost, and the number of lost packets exceeds the maximum value of the PDCP SN. However, as the TX_PDCP SN of the sender increases, the TX_PDCP SN increases and occurs. Flip so that the HFN is increased by at least 1. The receiving end does not receive the lost data packet, so the RX_PDCP SN is still 12, and the HFN does not change as the transmitting end; even when the lost data packet causes the PDCP SN of the data packet received by the receiving end to be 12 (for example When 14), the receiving end does not know that the HFN has changed, so the receiving end and the transmitting end maintain Unlike HFN, the parameter COUNT is inconsistent, causing the decryption to fail.
完整性保护/校验同样需要用到参数COUNT,因此也存在以上问题。The integrity protection/verification also requires the parameter COUNT, so the above problem also exists.
目前,对于以上问题的解决,并未考虑到PDCP层和其下层协议层之间的大量丢包的情况。At present, for the above problem, the situation of a large amount of packet loss between the PDCP layer and its lower protocol layer is not considered.
本申请实施例提供一种长序列号LSN,在PDCP和其下层之间传递,用于调整参数COUNT,以减少因PDCP层和其下层之间的数据包丢失导致的安全处理失败。所谓LSN,即为长度大于PDCP SN的长度的序列号。The embodiment of the present application provides a long sequence number LSN, which is transmitted between the PDCP and its lower layer, for adjusting the parameter COUNT to reduce the security processing failure caused by packet loss between the PDCP layer and its lower layer. The so-called LSN is a serial number whose length is longer than the length of the PDCP SN.
以下结合附图进行说明。The following description will be made with reference to the drawings.
请参考图4,其为本申请实施例提供的一种安全处理方法200的示意图。该方法200用于接收端,该接收端的第一实体维护第一SN(即LSN),且该第一实体每向PDCP实体发送一个PDCP数据包,该第一SN的值增加。通常,每发送一个PDCP数据包,第一SN的值加1,如此,实现最为简单成本较低。当然也可以加别的数值,原理类似,但实现相对复杂,本申请对此不作限制。Please refer to FIG. 4 , which is a schematic diagram of a security processing method 200 according to an embodiment of the present application. The method 200 is used by a receiving end, where a first entity of the receiving end maintains a first SN (ie, an LSN), and the first entity sends a PDCP data packet to the PDCP entity, and the value of the first SN is increased. Generally, each time a PDCP packet is sent, the value of the first SN is incremented by one. Thus, the simplest implementation is lower. Of course, other values can be added, the principle is similar, but the implementation is relatively complicated, and the application does not limit this.
需要说明的是,这里的第一实体是指PDCP层以下的协议层所在的实体,例如,RLC实体或者MAC实体。当然RLC实体和MAC实体也可以结合在一起。对于MAC实体是对于RLC实体为数据包在RLC实体透传的场景。It should be noted that the first entity herein refers to an entity where a protocol layer below the PDCP layer is located, for example, an RLC entity or a MAC entity. Of course, the RLC entity and the MAC entity can also be combined. For the MAC entity, it is a scenario in which the RLC entity transparently transmits the data packet to the RLC entity.
如图4所示,该方法200包括如下步骤:As shown in FIG. 4, the method 200 includes the following steps:
S210:第一实体接收数据包,并将数据包解析为PDCP数据包;S210: The first entity receives the data packet, and parses the data packet into a PDCP data packet.
S220:第一实体向PDCP实体发送解析得到的PDCP数据包和第一SN。该PDCP数据包包括PDCP SN,所述第一SN的长度大于PDCP SN的长度,且该第一SN用于在第一实体发送给PDCP实体的PDCP数据包中存在丢失的PDCP数据包时调整参数COUNT,该参数COUNT用于安全处理。S220: The first entity sends the parsed PDCP data packet and the first SN to the PDCP entity. The PDCP data packet includes a PDCP SN, the length of the first SN is greater than the length of the PDCP SN, and the first SN is used to adjust parameters when there is a missing PDCP data packet in a PDCP data packet sent by the first entity to the PDCP entity. COUNT, this parameter COUNT is used for security processing.
PDCP实体从第一实体接收PDCP数据包和第一SN。The PDCP entity receives the PDCP data packet and the first SN from the first entity.
S230:当PDCP实体从第一实体接收的PDCP数据包中存在丢失的PDCP数据包时,PDCP实体根据第一SN调整参数COUNT;S230: When there is a lost PDCP data packet in the PDCP data packet received by the PDCP entity from the first entity, the PDCP entity adjusts the parameter COUNT according to the first SN;
S240:PDCP实体根据调整后的参数COUNT对PDCP数据包进行安全处理。S240: The PDCP entity performs security processing on the PDCP data packet according to the adjusted parameter COUNT.
可见,在以上方法中,当接收端发现RLC实体和PDCP实体之间存在丢失的数据包时,可以利用第一SN调整参数COUNT,由于第一SN的长度大于PDCP SN,因此其对丢失数据包的容忍度增加,可以减少安全处理的失 败。It can be seen that, in the foregoing method, when the receiving end finds that there is a lost data packet between the RLC entity and the PDCP entity, the first SN may be used to adjust the parameter COUNT. Since the length of the first SN is greater than the PDCP SN, the lost data packet is lost. Increased tolerance can reduce the loss of safe handling defeat.
在以上步骤S210中,第一实体从其下层实体接收发送端发来的数据包,并将数据包解析为PDCP数据包。例如,当第一实体为RLC实体时,其从MAC实体接收RLC数据包,并将RLC数据包解析为PDCP数据包,进而发送给PDCP实体。In the above step S210, the first entity receives the data packet sent by the sender from its lower layer entity, and parses the data packet into a PDCP data packet. For example, when the first entity is an RLC entity, it receives the RLC data packet from the MAC entity, and parses the RLC data packet into a PDCP data packet, and then sends the data to the PDCP entity.
在以上步骤S220中,第一实体可以将第一SN携带在PDCP数据包中一起发送给PDCP实体,也可以将第一SN和PDCP数据包分别发送给PDCP实体。In the above step S220, the first entity may send the first SN in the PDCP data packet to the PDCP entity, and may also send the first SN and the PDCP data packet to the PDCP entity.
在以上步骤S230中,PDCP实体可以在丢失的数据包的数量达到或超过预设阈值时,根据第一SN调整参数COUNT。该第一阈值可以根据PDCP SN的长度来确定,且可以设定为PDCP层能够容忍的丢包数据,例如2nIn the above step S230, the PDCP entity may adjust the parameter COUNT according to the first SN when the number of lost data packets reaches or exceeds a preset threshold. The first threshold may be determined according to the length of the PDCP SN, and may be set as packet loss data that the PDCP layer can tolerate, such as 2 n .
PDCP实体可以根据第一SN来确定丢失数据包的数量,假设第一SN未发生翻转,丢包前收到的第一SN为30,丢包后收到的第一SN为1930,则丢失的数据包的数量为1899。The PDCP entity may determine the number of lost data packets according to the first SN, and assume that the first SN does not roll over, the first SN received before the packet loss is 30, and the first SN received after the packet loss is 1930, and the lost The number of packets is 1899.
请参考图5,其为本申请实施例提供的另一种安全处理方法300的示意图。该方法300用于发送端,该发送端的PDCP实体维护第一SN(即LSN),且该PDCP实体每向第一实体发送一个PDCP数据包,该第一SN的值增加。通常,每发送一个PDCP数据包,第一SN的值加1,如此,实现最为简单成本较低。当然也可以加别的数值,原理类似,但实现相对复杂,本申请对此不作限制。Please refer to FIG. 5 , which is a schematic diagram of another security processing method 300 according to an embodiment of the present application. The method 300 is used by a transmitting end, and the PDCP entity of the transmitting end maintains a first SN (ie, an LSN), and the PDCP entity sends a PDCP data packet to the first entity, and the value of the first SN is increased. Generally, each time a PDCP packet is sent, the value of the first SN is incremented by one. Thus, the simplest implementation is lower. Of course, other values can be added, the principle is similar, but the implementation is relatively complicated, and the application does not limit this.
需要说明的是,这里的第一实体是指PDCP层以下的协议层所在的实体,例如,RLC实体或者MAC实体。当然RLC实体和MAC实体也可以结合在一起。对于MAC实体是对于RLC实体为数据包在RLC实体透传的场景。It should be noted that the first entity herein refers to an entity where a protocol layer below the PDCP layer is located, for example, an RLC entity or a MAC entity. Of course, the RLC entity and the MAC entity can also be combined. For the MAC entity, it is a scenario in which the RLC entity transparently transmits the data packet to the RLC entity.
如图5所示,该方法300包括如下步骤:As shown in FIG. 5, the method 300 includes the following steps:
S310:PDCP实体向第一实体发送PDCP数据包和第一SN,其中,PDCP数据包包括PDCP SN,第一SN的长度大于PDCP SN的长度,且第一SN用于在PDCP实体发送给第一实体的PDCP数据包中存在丢失的PDCP数据包时调整参数COUNT。S310: The PDCP entity sends a PDCP data packet to the first SN, where the PDCP data packet includes a PDCP SN, the length of the first SN is greater than the length of the PDCP SN, and the first SN is used to send the first SN to the PDCP entity. The parameter COUNT is adjusted when there is a missing PDCP packet in the entity's PDCP packet.
第一实体从PDCP实体接收PDCP数据包,当发现第一SN不连续时,第一实体确定PDCP实体发送给第一实体的PDCP数据包中存在丢失的PDCP数据包(S320),则RLC实体向PDCP实体发送丢包信息(S330)。 The first entity receives the PDCP data packet from the PDCP entity. When the first SN is found to be discontinuous, the first entity determines that there is a lost PDCP data packet in the PDCP data packet sent by the PDCP entity to the first entity (S320), and the RLC entity The PDCP entity transmits the packet loss information (S330).
S330:PDCP实体从第一实体获取丢包信息。S330: The PDCP entity acquires packet loss information from the first entity.
S340:PDCP实体根据丢包信息和第一SN调整参数COUNT;S340: The PDCP entity adjusts the parameter COUNT according to the packet loss information and the first SN;
S350:PDCP实体根据调整后的参数COUNT对第一PDCP数据包进行安全处理,其中,第一PDCP数据包为丢包后发送的PDCP数据包。S350: The PDCP entity performs security processing on the first PDCP data packet according to the adjusted parameter COUNT, where the first PDCP data packet is a PDCP data packet that is sent after the packet loss.
S360:PDCP实体将经过安全处理的第一PDCP数据包发送给第一实体。S360: The PDCP entity sends the first PDCP data packet that is processed securely to the first entity.
可见,在以上方法中,当发送端发现RLC实体和PDCP实体之间存在丢失的数据包时,可以利用第一SN调整参数COUNT,由于第一SN的长度大于PDCP SN,因此其对丢失数据包的容忍度增加,可以减少安全处理的失败。It can be seen that, in the foregoing method, when the transmitting end finds that there is a lost data packet between the RLC entity and the PDCP entity, the first SN can be used to adjust the parameter COUNT. Since the length of the first SN is greater than the PDCP SN, the lost data packet is lost. Increased tolerance can reduce the failure of secure processing.
在以上步骤S310中,PDCP实体可以将第一SN携带在PDCP数据包中一起发送给第一实体,也可以将第一SN和PDCP数据包分别发送给第一实体。In the above step S310, the PDCP entity may send the first SN to the first entity in the PDCP data packet, and may also send the first SN and the PDCP data packet to the first entity.
在以上步骤S320和S330中,丢包信息可以包括以下信息之一或更多:第一个丢失的PDCP数据包的第一SN、期望的下一个PDCP数据包的第一SN、丢包前最后一个PDCP数据包的第一SN、丢包后接收的第一个PDCP数据包的第一SN、丢失的PDCP数据包的数量。In the above steps S320 and S330, the packet loss information may include one or more of the following information: the first SN of the first lost PDCP data packet, the first SN of the desired next PDCP data packet, and the last before the packet loss The first SN of a PDCP packet, the first SN of the first PDCP packet received after packet loss, and the number of lost PDCP packets.
在以上步骤S340中,PDCP实体可以在丢失的数据包的数量达到或超过预设阈值时,根据第一SN调整参数COUNT。该第一阈值可以根据PDCP SN的长度来确定,且可以设定为PDCP层能够容忍的丢包数据,例如2nIn the above step S340, the PDCP entity may adjust the parameter COUNT according to the first SN when the number of lost data packets reaches or exceeds a preset threshold. The first threshold may be determined according to the length of the PDCP SN, and may be set as packet loss data that the PDCP layer can tolerate, such as 2 n .
在本实施例中,可以由第一实体判断丢失的数据包的数量是否达到或超过预设阈值。例如,第一实体可以根据第一SN来确定丢失数据包的数量,假设第一SN未发生翻转,丢包前收到的第一SN为30,丢包后收到的第一SN为1930,则丢失的数据包的数量为1899。当判断出丢失的数据包的数量达到或超过预设阈值时,第一实体向PDCP实体发送丢包信息。此时,丢包信息可以包括第一个丢失的PDCP数据包的第一SN、期望的下一个PDCP数据包的第一SN、或丢包前最后一个PDCP数据包的第一SN。当然也可以还包括其它信息,如此,PDCP实体可以根据该丢包信息确定丢包前正确接收的数据包。进而利用正确接收的数据包的第一SN来调整参数COUNT,具体调整方式在后续实施例中详细描述。In this embodiment, it may be determined by the first entity whether the number of lost data packets reaches or exceeds a preset threshold. For example, the first entity may determine the number of lost data packets according to the first SN, and assume that the first SN does not roll over, the first SN received before the packet loss is 30, and the first SN received after the packet loss is 1930. The number of lost packets is 1899. When it is determined that the number of lost data packets reaches or exceeds a preset threshold, the first entity sends packet loss information to the PDCP entity. At this time, the packet loss information may include the first SN of the first lost PDCP data packet, the first SN of the desired next PDCP data packet, or the first SN of the last PDCP data packet before the packet loss. Of course, other information may also be included, so that the PDCP entity can determine the data packet correctly received before the packet loss according to the packet loss information. The parameter COUNT is further adjusted by using the first SN of the correctly received data packet, and the specific adjustment manner is described in detail in the subsequent embodiments.
此外,也可以由PDCP实体判断丢失的数据包的数量是否达到或超过预设阈值。PDCP实体根据第一实体发送的丢包信息,判断丢失的数据包的数 量是否达到或超过预设阈值。此时,丢包信息除了包括第一个丢失的PDCP数据包的第一SN、期望的下一个PDCP数据包的第一SN、或丢包前最后一个PDCP数据包的第一SN以外,还可以包括丢包后接收的第一个PDCP数据包的第一SN、或丢失的PDCP数据包的数量等。PDCP实体可以根据该丢包信息确定丢失的PDCP数据包的数量,进而判断丢失的PDCP数据包的数量是否达到或超过预设阈值。例如,当丢包信息包括第一个丢失的PDCP数据包的第一SN(或期望的下一个PDCP数据包的第一SN)和丢包后接收的第一个PDCP数据包的第一SN时,PDCP实体根据这两个第一SN,计算丢失的PDCP数据包的数量。同样假设第一SN未发生翻转,第一个丢失的PDCP数据包的第一SN为30,丢包后接收的第一个PDCP数据包的第一SN为1930,则丢失的数据包的数量为1900。当丢包信息包括丢失的PDCP数据包的数量时,可以直接获得丢失的数据包的数量。当丢包信息丢包前最后一个PDCP数据包的第一SN和丢包后接收的第一个PDCP数据包的第一SN时,PDCP实体根据这两个第一SN,计算丢失的PDCP数据包的数量。同样假设第一SN未发生翻转,丢包前最后一个PDCP数据包的第一SN为30,丢包后接收的第一个PDCP数据包的第一SN为1930,则丢失的数据包的数量为1899。In addition, the PDCP entity may also determine whether the number of lost data packets reaches or exceeds a preset threshold. The PDCP entity determines the number of lost data packets according to the packet loss information sent by the first entity. Whether the amount reaches or exceeds a preset threshold. At this time, the packet loss information may include, in addition to the first SN of the first lost PDCP data packet, the first SN of the desired next PDCP data packet, or the first SN of the last PDCP data packet before the packet loss, The first SN of the first PDCP data packet received after the packet loss, or the number of lost PDCP data packets, and the like. The PDCP entity may determine the number of lost PDCP data packets according to the packet loss information, and further determine whether the number of lost PDCP data packets reaches or exceeds a preset threshold. For example, when the packet loss information includes the first SN of the first lost PDCP data packet (or the first SN of the expected next PDCP data packet) and the first SN of the first PDCP data packet received after the packet loss The PDCP entity calculates the number of lost PDCP data packets based on the two first SNs. Also assume that the first SN does not roll over, the first SN of the first lost PDCP packet is 30, and the first SN of the first PDCP packet received after the packet loss is 1930, the number of lost packets is 1900. When the packet loss information includes the number of lost PDCP packets, the number of lost packets can be directly obtained. When the first SN of the last PDCP packet before the packet loss packet loss and the first SN of the first PDCP packet received after the packet loss, the PDCP entity calculates the lost PDCP packet according to the two first SNs. quantity. It is also assumed that the first SN does not roll over, the first SN of the last PDCP packet before the packet loss is 30, and the first SN of the first PDCP packet received after the packet loss is 1930, and the number of lost packets is 1899.
需要说明的是,本申请实施例中的实体是指发送端或接收端的物理装置,例如PDCP实体是指PDCP层所在的物理装置,第一实体可以是RLC层所在的物理装置,也可以是MAC层所在的物理装置。It should be noted that the entity in the embodiment of the present application refers to a physical device of the sending end or the receiving end. For example, the PDCP entity refers to a physical device where the PDCP layer is located, and the first entity may be a physical device where the RLC layer is located, or may be a MAC. The physical device where the layer is located.
在以上发送端和接收端的实施例中,PDCP实体调整参数COUNT的过程中,会确定基准点和判决点,并根据基准点的第一序列号和判决点的第一第一序列号对判决点的参数COUNT进行调整。这里的基准点可以从正确接收的PDCP数据包中选一个,通常可以从最近接收的第一SN所能表达的最大数量的PDCP数据包中选择PDCP数据包。判决点即为丢包后待进行安全处理的PDCP数据包。In the above embodiments of the transmitting end and the receiving end, in the process of adjusting the parameter COUNT by the PDCP entity, the reference point and the decision point are determined, and the decision point is determined according to the first serial number of the reference point and the first first serial number of the decision point. The parameter COUNT is adjusted. The reference point here can be selected from the correctly received PDCP data packets, and the PDCP data packet can usually be selected from the largest number of PDCP data packets that can be expressed by the most recently received first SN. The decision point is the PDCP packet to be safely processed after packet loss.
下面结合附图描述调整参数COUNT的方法。图6示出了本申请实施例提供的一种数据包、参数COUNT和第一序列号(图6中记作LSN)的示意图。如图6所示,以SN的长度为n作为示例,参数COUNT包括两部分,PDCP SN和HFN。在发送端的PDCP层,每发送一个数据包,PDCP SN的数值递增1,当PDCP SN达到预设长度(即,2n)时,开始新一轮的循环, 同时,HFN加1。The method of adjusting the parameter COUNT will be described below with reference to the drawings. FIG. 6 is a schematic diagram of a data packet, a parameter COUNT, and a first serial number (referred to as LSN in FIG. 6) provided by an embodiment of the present application. As shown in FIG. 6, taking the length of the SN as an example, the parameter COUNT includes two parts, PDCP SN and HFN. At the PDCP layer of the transmitting end, the value of the PDCP SN is incremented by one every time a data packet is transmitted. When the PDCP SN reaches a preset length (ie, 2 n ), a new round of looping is started, and at the same time, the HFN is incremented by one.
需要说明的是,本申请实施例中的第一长序列号(图6中记作LSN),其长度大于PDCP SN的长度。例如,LSN可以取为32位或64位等。It should be noted that the first long serial number (referred to as LSN in FIG. 6) in the embodiment of the present application has a length greater than the length of the PDCP SN. For example, the LSN can be taken as 32-bit or 64-bit, and the like.
以下对本申请实施例提供的安全处理的方法,分别在上行(即,RLC层向PDCP层发送数据包)和下行(即,PDCP层向RLC层发送数据包)两种情况进行说明。The following describes the security processing method provided by the embodiment of the present application in the uplink (that is, the RLC layer sends a data packet to the PDCP layer) and the downlink (that is, the PDCP layer sends a data packet to the RLC layer).
需要说明的是,本申请各实施例中所说的上行或下行,是指发送端或接收端各自内部的PDCP层与RLC层之间传输数据包的方向。It should be noted that the uplink or downlink in the embodiments of the present application refers to a direction in which a data packet is transmitted between a PDCP layer and an RLC layer inside the transmitting end or the receiving end.
例如,上行可以为接收端的RLC层向接收端的PDCP层发送数据。For example, the uplink may send data to the PDCP layer of the receiving end for the RLC layer of the receiving end.
又例如,下行是指发送端的PDCP层向发送端的RLC层发送数据。For another example, the downlink refers to the PDCP layer at the transmitting end transmitting data to the RLC layer at the transmitting end.
以下实施例以数据包的加解密作为示例,对本申请提供的安全处理的方法进行举例说明。The following embodiment exemplifies the method of security processing provided by the present application by taking the encryption and decryption of a data packet as an example.
首先以上行(例如,接收端的RLC层向接收端的PDCP层发送数据包)为例:First, the above line (for example, the RLC layer at the receiving end sends a data packet to the PDCP layer at the receiving end) as an example:
在本实施例中,PDCP实体调整参数COUNT的方法包括:PDCP实体从丢失的PDCP数据包之前正确接收的PDCP数据包中选择第二数据包(即以下的数据包#1);根据第二数据包的第一SN、第二数据包的PDCP SN、第二数据包的HFN、第一数据包(即以下的数据包#2)的第一SN和第一数据包的PDCP SN,确定第一数据包的HFN;进而根据第一数据包的HFN和第一数据包的PDCP SN,确定参数COUNT。In this embodiment, the method for adjusting the parameter COUNT by the PDCP entity includes: selecting, by the PDCP entity, the second data packet (ie, the following data packet #1) from the PDCP data packet correctly received before the lost PDCP data packet; according to the second data Determining the first SN of the packet, the PDCP SN of the second data packet, the HFN of the second data packet, the first SN of the first data packet (ie, the following data packet #2), and the PDCP SN of the first data packet, determining the first The HFN of the data packet; and further the parameter COUNT is determined based on the HFN of the first data packet and the PDCP SN of the first data packet.
图7为本申请实施例提供的安全处理的方法200的一个示例。如图7所示,该示例主要包括如下过程:FIG. 7 is an example of a method 200 of security processing provided by an embodiment of the present application. As shown in FIG. 7, the example mainly includes the following process:
401、当接收端的PDCP实体接收RLC实体发送的PDCP数据包发生丢包,且丢包数量达到或超过预设阈值时,PDCP实体选择作为基准点的数据包#1,并记录基准点的HFNB(基准点的HFN)、SNB(基准点的PDCP SN)和LSNB(基准点的第一序列号)。401. When the PDCP entity at the receiving end receives the packet loss of the PDCP data packet sent by the RLC entity, and the number of lost packets reaches or exceeds a preset threshold, the PDCP entity selects the data packet #1 as the reference point, and records the HFN B of the reference point. (HFN of reference point), SN B (PDCP SN of reference point), and LSN B (first sequence number of reference point).
步骤401中,数据包#1为PDCP实体正确接收的数据包,PDCP实体在选择数据包#1时包括多种方式。例如,可以是随机或周期性地选择一个数据包,也可以是选择某一类数据包。本申请实施例对此不作特别限定。In step 401, the data packet #1 is a data packet correctly received by the PDCP entity, and the PDCP entity includes multiple modes when selecting the data packet #1. For example, it is possible to select a data packet randomly or periodically, or to select a certain type of data packet. This embodiment of the present application does not specifically limit this.
402、PDCP实体确定作为判决点的数据包#2,并获取数据包#2的第一序列号LSNN402. The PDCP entity determines the data packet #2 as the decision point, and acquires the first sequence number LSN N of the data packet #2.
其中,数据包#2以发生丢包后PDCP实体接收到的待进行安全处理(例如,解密)的第一个PDCP数据包为例。其也可以是丢包后的其它待处理的PDCP数据包。The data packet #2 is exemplified by the first PDCP data packet to be subjected to security processing (for example, decryption) received by the PDCP entity after the packet loss occurs. It can also be other PDCP packets to be processed after packet loss.
具体地,若RLC实体发送给PDCP实体的PDCP数据包出现丢包且超过阈值(例如,PDCP协议能够容忍的丢包数量为2n)时,PDCP实体可以读取丢包后RLC实体发送的第一个PDCP数据包携带的第一序列号LSNNSpecifically, if the PDCP packet sent by the RLC entity to the PDCP entity is packet loss and exceeds a threshold (for example, the number of packet loss that the PDCP protocol can tolerate is 2 n ), the PDCP entity can read the packet sent by the RLC entity after the packet loss. The first sequence number LSN N carried by a PDCP packet.
步骤401中选择作为基准点的数据包#1和步骤402中确定作为判决点的数据包#2之间并没有先后关系,上述顺序仅作为示例。There is no succession between the selection of the data packet #1 as the reference point in step 401 and the data packet #2 determined as the decision point in step 402. The above sequence is merely an example.
403、PDCP实体根据基准点的HFNB、SNB、LSNB和判决点的LSNN,计算对数据包#2进行解密所应使用的HFN。403. The PDCP entity calculates an HFN to be used for decrypting the data packet #2 according to the HFN B , SN B , LSN B of the reference point and the LSN N of the decision point.
可选地,作为一个实施例,PDCP实体根据基准点的HFNB、SNB、LSNB和判决点的LSNN,计算对数据包#2进行解密所应使用的HFN,包括:Alternatively, as an embodiment, the PDCP entity of HFN reference point B, SN B, LSN B and decision point of LSN N, is calculated for packet # 2 should be used to decrypt the HFN, comprising:
PDCP实体根据如下公式计算对数据包#2进行解密所应使用的HFN(公式中记作HFNN):The PDCP entity calculates the HFN (denoted as HFN N in the formula) that should be used to decrypt packet #2 according to the following formula:
Figure PCTCN2016108034-appb-000003
Figure PCTCN2016108034-appb-000003
其中,“%”表示取余,
Figure PCTCN2016108034-appb-000004
表示向下取整。
Where "%" means surplus,
Figure PCTCN2016108034-appb-000004
Indicates rounding down.
可以理解的是,在上述公式(1)中,c为参数COUNT的长度,n为PDCP SN的长度,k为第一序列号的长度。It can be understood that, in the above formula (1), c is the length of the parameter COUNT, n is the length of the PDCP SN, and k is the length of the first serial number.
404、PDCP实体根据计算得到的对数据包#2(即,判决点)进行安全处理所应使用的HFN,对数据包#2进行安全处理。404. The PDCP entity performs security processing on the packet #2 according to the calculated HFN that should be used for performing security processing on the packet #2 (ie, the decision point).
具体地,PDCP实体根据计算得到的对数据包#2进行解密所应使用的HFN和数据包#2的PDCP SN,对参数COUNT进行调整,并使用调整后的参数COUNT对数据包#2进行解密处理。Specifically, the PDCP entity adjusts the parameter COUNT according to the calculated HFN used for decrypting the packet #2 and the PDCP SN of the packet #2, and decrypts the packet #2 using the adjusted parameter COUNT. deal with.
这里,数据包#2的PDCP SN(公式中记作SNN)可以由PDCP实体直接读取数据包#2携带的PDCP SN,或者,PDCP实体也可以根据如下公式(2)进行计算:Here, the PDCP SN of the packet #2 (referred to as SN N in the formula) may directly read the PDCP SN carried by the packet #2 by the PDCP entity, or the PDCP entity may also calculate according to the following formula (2):
Figure PCTCN2016108034-appb-000005
Figure PCTCN2016108034-appb-000005
下面以下行(例如,发送端的PDCP层向发送端的RLC层发送数据包)为例:For example, the following line (for example, the PDCP layer at the transmitting end sends a data packet to the RLC layer at the transmitting end):
在本实施例中,PDCP实体根据丢包信息和第一SN调整参数COUNT, 包括:PDCP实体根据丢包信息从丢失的PDCP数据包之前被第一实体正确接收的PDCP数据包中选择第二数据包(即以下的数据包#1),并确定丢包前最后一个正确接收的第三PDCP数据包(即以下的数据包#3);根据第二数据包的第一SN,第二数据包的PDCP SN,第二数据包的HFN,第三数据包的第一SN,和第一数据包(即以下的数据包#2)的PDCP SN,确定第一数据包的HFN;根据第一数据包的HFN和第一数据包的PDCP SN,确定参数COUNT。In this embodiment, the PDCP entity adjusts the parameter COUNT according to the packet loss information and the first SN. The method includes: selecting, by the PDCP entity, the second data packet (ie, the following data packet #1) from the PDCP data packet correctly received by the first entity before the lost PDCP data packet according to the packet loss information, and determining the last correct reception before the packet loss a third PDCP packet (ie, packet #3 below); a first SN according to the second packet, a PDCP SN of the second packet, an HFN of the second packet, and a first SN of the third packet, And the PDCP SN of the first data packet (ie, the following data packet #2), determining the HFN of the first data packet; determining the parameter COUNT according to the HFN of the first data packet and the PDCP SN of the first data packet.
图8为本申请实施例提供的安全处理的方法200的另一示例。如图8所示,该示例中主要包括如下过程:FIG. 8 is another example of a method 200 of security processing provided by an embodiment of the present application. As shown in FIG. 8, the example mainly includes the following process:
501、当发送端的PDCP实体发送给RLC实体的PDCP数据包发生丢包,且丢失的PDCP数据包的数量达到或超过预设阈值时,PDCP实体从RLC实体获取丢包信息。501. When a PDCP packet sent by the PDCP entity of the sending end to the RLC entity is lost, and the number of the lost PDCP data reaches or exceeds a preset threshold, the PDCP entity obtains the packet loss information from the RLC entity.
502、PDCP实体从正确发送给接收端的RLC实体的多个PDCP数据包中选择数据包#1作为基准点,并记录基准点的HFNB、SNB和LSNB,并确定作为判决点的数据包#2。502. The PDCP entity selects the data packet #1 as a reference point from the plurality of PDCP data packets that are correctly sent to the RLC entity of the receiving end, and records the HFN B , SN B, and LSN B of the reference point, and determines the data packet as the decision point. #2.
其中,丢包信息同以上描述,在此不再赘述,PDCP实体可以根据丢包信息确定正确接收的数据包,从而选择数据包#1。在此,以数据包#2为发生丢包后PDCP层待进行安全处理后发送至RLC层的第一个数据包为例。当然,也可以为后续的数据包。The packet loss information is the same as the above description, and is not described here. The PDCP entity can determine the correctly received data packet according to the packet loss information, thereby selecting the data packet #1. Here, the packet #2 is taken as an example of the first data packet sent to the RLC layer after the PDCP layer is subjected to security processing after packet loss occurs. Of course, it can also be a subsequent packet.
丢包前RLC实体正确接收的最后一个数据包,实际上为(判决点-1)对应的数据包#3,图8中记作LSNLThe last data packet correctly received by the RLC entity before packet loss is actually packet #3 corresponding to (decision point-1), and is denoted as LSN L in FIG.
503、PDCP实体根据基准点(即,数据包#1)的HFNB、SNB、LSNB和数据包#3的LSNL,计算对数据包#2加密应该使用的HFN。503. The PDCP entity calculates an HFN that should be used to encrypt the packet #2 according to the HFN B , SN B , LSN B of the reference point (ie, packet #1) and the LSN L of the packet #3.
可选地,作为一个实施例,PDCP实体根据基准点的HFNB、SNB、LSNB和数据包#3的LSNL,计算对数据包#2加密应该使用的HFN,包括:Optionally, as an embodiment, the PDCP entity calculates the HFN that should be used to encrypt the data packet #2 according to the HFN B , SN B , LSN B of the reference point and the LSN L of the data packet #3, including:
PDCP实体根据如下公式计算对数据包#2加密所应使用的HFN(公式中记作HFNN):The PDCP entity calculates the HFN (denoted as HFN N in the formula) that should be used to encrypt packet #2 according to the following formula:
Figure PCTCN2016108034-appb-000006
Figure PCTCN2016108034-appb-000006
其中,“%”表示取余,
Figure PCTCN2016108034-appb-000007
表示向下取整。c为参数COUNT的长度,n为PDCP SN的长度,k为第一序列号的长度,t为常数,且为大于或等于1 的正整数。
Where "%" means surplus,
Figure PCTCN2016108034-appb-000007
Indicates rounding down. c is the length of the parameter COUNT, n is the length of the PDCP SN, k is the length of the first sequence number, t is a constant, and is a positive integer greater than or equal to 1.
504、PDCP实体根据计算得到的对数据包#2加密所应使用的HFN和数据包#2的PDCP SN,对数据包#2进行加密处理。504. The PDCP entity encrypts the data packet #2 according to the calculated HFN used for encrypting the data packet #2 and the PDCP SN of the data packet #2.
另外,数据包#2的PDCP SN可以直接读取数据包#2携带的PDCP SN,或者,也可以根据如下公式(4)进行计算:In addition, the PDCP SN of the packet #2 can directly read the PDCP SN carried by the packet #2, or can be calculated according to the following formula (4):
Figure PCTCN2016108034-appb-000008
Figure PCTCN2016108034-appb-000008
同样地,k为第一序列号的长度,t为常数,且为大于或等于1的正整数。Similarly, k is the length of the first serial number, t is a constant, and is a positive integer greater than or equal to one.
以上结合图7和图8,分别对本申请实施例的安全处理的方法在上行和下行两种情况下的应用进行了详细说明。以下结合图9和图10,对本申请实施例在不同丢包场景下的应用进行举例说明。The application of the security processing method of the embodiment of the present application in the uplink and downlink cases is described in detail above with reference to FIG. 7 and FIG. 8 respectively. The application of the embodiment of the present application in different packet loss scenarios is exemplified in the following with reference to FIG. 9 and FIG.
图9为本申请实施例应用于主备冗余系统中上行丢包场景的示意图。FIG. 9 is a schematic diagram of an uplink packet loss scenario applied to an active/standby redundancy system according to an embodiment of the present application.
为了便于理解,首先对冗余系统进行说明。For ease of understanding, the redundant system will first be described.
冗余系统,是指为了增加系统的可靠性,采取两套或两套以上相同的、相互独立配置的设备组成的系统。通过提供系统运行所需的所有关键设备的冗余的方法,当系统发生故障时,冗余配置的设备介入并承担故障设备的工作,由此提高系统的容错能力、减少系统的故障时间。Redundant system refers to a system consisting of two or more sets of identical, independently configured devices in order to increase the reliability of the system. By providing a redundant method for all critical equipment required for system operation, when a system fails, redundantly configured equipment intervenes and assumes the operation of the failed equipment, thereby increasing the system's fault tolerance and reducing system downtime.
以下,对主备冗余场景下的上行过程进行说明。The following describes the uplink process in the active/standby redundancy scenario.
601、主备PDCP实体之间备份加解密参数。601. The backup and decryption parameters are between the active and standby PDCP entities.
如图9所示的PDCP#1实体为主PDCP,PDCP#2实体为备PDCP。The PDCP #1 entity shown in FIG. 9 is the primary PDCP, and the PDCP #2 entity is the standby PDCP.
602、主备PDCP实体进行PDCP SN的同步。602. The primary and backup PDCP entities perform synchronization of the PDCP SN.
具体地,在本申请实施例中,RLC实体和PDCP实体之间传输数据包时在通信接口传输第一序列号(下面记作LSN)。每发送一个报文,第一序列号的值递增。Specifically, in the embodiment of the present application, when the data packet is transmitted between the RLC entity and the PDCP entity, the first serial number (hereinafter referred to as LSN) is transmitted on the communication interface. The value of the first serial number is incremented each time a message is sent.
主备PDCP实体通过“同步序列包”的同步参数进行PDCP SN的同步。其中,同步参数包括第一序列号、HFN和PDCP SN。The active and standby PDCP entities synchronize the PDCP SN through the synchronization parameters of the "synchronization sequence packet". The synchronization parameters include a first sequence number, an HFN, and a PDCP SN.
在步骤602中,有两点需要说明。In step 602, there are two points that need to be explained.
第一,这里所说的“同步序列包”可对应上述实施例中作为基准点的数据包。因此,“同步序列包”的选取方式为:主PDCP(即,PDCP#1实体)从已接收的数据包中选择一个数据包作为“同步序列包”。选择的周期以确保在第一序列号的最大范围内至少存在一个数据包的PDCP SN信息同步到备PDCP(即,PDCP#2实体)为准。 First, the "synchronization sequence packet" referred to herein may correspond to a data packet as a reference point in the above embodiment. Therefore, the "synchronization sequence packet" is selected in such a manner that the primary PDCP (ie, the PDCP #1 entity) selects one of the received data packets as a "synchronization sequence packet". The selected period is to ensure that the PDCP SN information of at least one data packet is synchronized to the standby PDCP (ie, PDCP #2 entity) within the maximum range of the first sequence number.
考虑到系统的鲁棒性,主PDCP实体也可以选择多个(例如,2~3个)数据包作为“同步序列包”。Considering the robustness of the system, the primary PDCP entity may also select multiple (eg, 2 to 3) data packets as "synchronization sequence packets."
第二,当加解密参数发生配置变更(例如,增加、删减或更新等)时,主备PDCP实体之间需要立刻触发“同步序列包”的PDCP SN的同步过程。Second, when the configuration of the encryption/decryption parameters is changed (for example, adding, deleting, or updating, etc.), the synchronization process of the PDCP SN of the "synchronization sequence packet" needs to be triggered immediately between the active and standby PDCP entities.
603、主备倒换,PDCP#2替代PDCP#1成为主PDCP实体。603. Active/standby switchover, PDCP#2 replaces PDCP#1 as the primary PDCP entity.
在主备倒换过程中,通常会出现丢包。During the active/standby switchover, packet loss usually occurs.
604、PDCP#2获取丢包后接收到的第一个数据包(记作数据包#A)的第一序列号LSN和PDCP SN。604. The PDCP #2 obtains the first sequence numbers LSN and PDCP SN of the first data packet (referred to as packet #A) received after the packet loss.
605、PDCP#2根据“同步序列包”的LSN、HFN和PDCP SN,计算解密数据包#A(即,判决点)所应使用的HFN。605. The PDCP #2 calculates the HFN to be used for decrypting the packet #A (ie, the decision point) based on the LSN, HFN, and PDCP SN of the "synchronization sequence packet".
具体地,在计算解密数据包#A所应使用的HFN时,可以根据前文所述的公式(1)进行计算。这里不再赘述。Specifically, when calculating the HFN to be used for decrypting the packet #A, the calculation can be performed according to the formula (1) described above. I won't go into details here.
后续,PDCP#2计算出解密数据包#A所应使用的HFN后,结合数据包#A携带的PDCP SN,对数据包#A的PDCP SN进行一致性校验。Subsequently, PDCP #2 calculates the HFN to be used for decrypting the packet #A, and performs the consistency check on the PDCP SN of the packet #A in combination with the PDCP SN carried in the packet #A.
这里,对数据包#A的PDCP SN的一致性校验是指,对数据包#A携带的PDCP SN和根据公式(2)计算得到的PDCP SN是否一致进行判断。Here, the consistency check of the PDCP SN of the packet #A means that it is determined whether the PDCP SN carried in the packet #A and the PDCP SN calculated according to the formula (2) are identical.
若校验通过,PDCP#2对数据包#A按照PDCP协议的流程处理。若校验未通过,重建PDCP或释放用户。If the check is passed, PDCP#2 processes the packet #A according to the PDCP protocol. If the check fails, rebuild the PDCP or release the user.
主备PDCP倒换后,PDCP#2正确接收到第一个数据包后,对后续接收到的数据包按照协议的正常流程处理。After the primary and backup PDCPs are switched, after PDCP#2 correctly receives the first data packet, it processes the subsequent received data packets according to the normal flow of the protocol.
下面,说明主备冗余场景下的下行过程。The following describes the downlink process in the active/standby redundancy scenario.
图10为本申请实施例应用于主备冗余系统中下行丢包场景的示意图。FIG. 10 is a schematic diagram of a downlink packet loss scenario applied to an active/standby redundancy system according to an embodiment of the present application.
701、主备PDCP实体之间备份加解密参数。701. The backup and decryption parameters are between the active and standby PDCP entities.
702、主备PDCP实体进行PDCP SN的同步。702. The primary and secondary PDCP entities perform synchronization of the PDCP SN.
703、主备倒换,PDCP#2替代PDCP#1成为主PDCP实体。703. Active/standby switchover, PDCP#2 replaces PDCP#1 as the primary PDCP entity.
需要说明的是,步骤701-703可以分别参考上述步骤601-603,此处不再赘述。It should be noted that steps 701-703 may refer to steps 601-603 above, and details are not described herein again.
704、PDCP#2获取丢包前RLC实体正确接收的最后一个数据包(记作数据包#B)的第一序列号LSN。704. The PDCP #2 obtains the first sequence number LSN of the last data packet (referred to as the data packet #B) correctly received by the RLC entity before the packet loss.
具体地,在步骤704中,对PDCP#2获取第一序列号的方式不作任何限定。例如,可以为PDCP#2通过查询得到,或者,也可以为RLC实体主动 上报。Specifically, in step 704, the manner in which the PDCP #2 obtains the first serial number is not limited. For example, it can be obtained by querying PDCP#2, or it can be active for the RLC entity. Reported.
705、PDCP#2根据“同步序列包”的LSN、HFN和PDCP SN和数据包#B的LSN,计算对丢包后待发送至RLC实体的第一个数据包(即,判决点的数据包,记作数据包#C)进行加密所应使用的HFN。705. PDCP#2 calculates, according to the LSN, HFN, and PDCP SN of the “synchronization sequence packet” and the LSN of the data packet #B, the first data packet to be sent to the RLC entity after the packet loss (ie, the data packet of the decision point) , recorded as packet #C) HFN to be used for encryption.
类似地,计算对判决点的数据包进行加密应该使用的HFN可以根据前文所述的公式(3)进行计算。这里不再赘述。Similarly, the HFN that should be used to calculate the encryption of the data packets of the decision point can be calculated according to the formula (3) described above. I won't go into details here.
706、PDCP#2按照计算得到的对判决点的数据包进行加密所应使用的HFN和数据包#C携带的PDCP SN,对参数COUNT进行调整,并根据调整后的COUNT,按照协议正常流程,对数据包#C进行加密处理。706. PDCP#2 adjusts the parameter COUNT according to the calculated HFN used for encrypting the data packet of the decision point and the PDCP SN carried by the data packet #C, and according to the adjusted COUNT, according to the normal procedure of the protocol. Encryption of packet #C.
与上行过程类似,主备倒换后,PDCP#2正确发送第一个数据包后,后续的下行数据包按照协议的正常流程进行处理。这里不再详述。Similar to the uplink process, after the master/slave switchover, PDCP#2 correctly sends the first data packet, and subsequent downlink data packets are processed according to the normal flow of the protocol. It will not be detailed here.
图11为本申请实施例应用于RLC层与PDCP层之间通信链路异常导致丢包场景下的示意图。FIG. 11 is a schematic diagram of a packet loss scenario caused by an abnormal communication link between an RLC layer and a PDCP layer according to an embodiment of the present application.
总体来说,在本申请实施例中,通过在PDCP层与RLC层的通信接口传递第一序列号,并使得第一序列号的长度尽可能远大于现有PDCP协议中为PDCP数据包配置的PDCP序列号的长度。例如,第一序列号的长度取为32位或64位等。Generally, in the embodiment of the present application, the first serial number is transmitted through the communication interface between the PDCP layer and the RLC layer, and the length of the first serial number is as far as possible is larger than that configured for the PDCP data packet in the existing PDCP protocol. The length of the PDCP serial number. For example, the length of the first serial number is taken as 32 bits or 64 bits or the like.
同样地,与上述主备冗余场景类似,下面对RLC层与PDCP层之间通信链路异常导致的上行丢包场景和下行丢包场景分别进行说明。Similarly, similar to the above-mentioned active/standby redundancy scenario, the following describes the uplink packet loss scenario and the downlink packet loss scenario caused by the abnormal communication link between the RLC layer and the PDCP layer.
上行(例如,基站的RLC层向基站的PDCP层发送数据包)Uplink (for example, the RLC layer of the base station transmits a data packet to the PDCP layer of the base station)
801、PDCP实体从接收的PDCP数据包中选择一个数据包作为基准点,并记录基准点的第一SN、HFN和PDCP SN。801. The PDCP entity selects a data packet from the received PDCP data packet as a reference point, and records the first SN, HFN, and PDCP SN of the reference point.
802、PDCP实体在接收数据包时,通过数据包携带的LSN,判断RLC层-PDCP层之间的通信链路之间是否出现丢包。在丢包情况下,进一步判断丢包数量是否达到PDCP协议容忍阈值。When receiving the data packet, the 802 and the PDCP entity determine whether packet loss occurs between the communication links between the RLC layer and the PDCP layer by using the LSN carried in the data packet. In the case of packet loss, it is further determined whether the number of lost packets reaches the PDCP protocol tolerance threshold.
803、当PDCP实体确定丢包数量达到或超过协议容忍阈值时,PDCP实体根据丢包后第一个接收的数据包(即,判决点)携带的第一序列号LSNN,计算出对判决点的数据包进行解密应该使用的HFN。803. When the PDCP entity determines that the number of lost packets meets or exceeds a protocol tolerance threshold, the PDCP entity calculates a decision point according to the first sequence number LSN N carried by the first received data packet (ie, the decision point) after the packet loss. The HFN that the packet should be decrypted should be used.
可选地,PDCP实体可以根据前文的公式(2)计算判决点的PDCP SN。Optionally, the PDCP entity may calculate the PDCP SN of the decision point according to the foregoing formula (2).
804、PDCP实体对判决点的数据包的PDCP SN进行一致性校验,并在校验通过后,使用对判决点的数据包进行解密应该使用的HFN和判决点数 据包的PDCP SN,对参数COUNT进行调整,并根据调整后的COUNT对判决点的数据包进行解密。804. The PDCP entity performs consistency check on the PDCP SN of the data packet of the decision point, and after using the verification, uses the HFN and the number of decision points that should be used to decrypt the data packet of the decision point. According to the PDCP SN of the packet, the parameter COUNT is adjusted, and the data packet of the adjusted COUNT pair decision point is decrypted.
下行(例如,基站的PDCP层向基站的RLC层发送数据包)Downlink (for example, the PDCP layer of the base station sends a data packet to the RLC layer of the base station)
901、PDCP实体从被RLC实体接收的数据包中选择一个数据包作为基准点,并记录基准点的HFNB、SNB、LSNB901. The PDCP entity selects a data packet from the data packet received by the RLC entity as a reference point, and records the HFN B , SN B , and LSN B of the reference point.
902、RLC实体接收到数据包后,通过数据包携带的LSN,判断PDCP层-RLC层通信链路之间是否出现丢包。在丢包情况下,进一步判断是否超过PDCP协议容忍阈值。902. After receiving the data packet, the RLC entity determines whether packet loss occurs between the PDCP layer and the RLC layer communication link by using the LSN carried in the data packet. In the case of packet loss, it is further determined whether the PDCP protocol tolerance threshold is exceeded.
903、若RLC实体确定丢包数量超过PDCP协议的容忍阈值,RLC实体将丢包前接收的最后一个数据包(即,判决点-1)的LSNL通知PDCP实体。903. If the RLC entity determines that the number of lost packets exceeds the tolerance threshold of the PDCP protocol, the RLC entity notifies the PDCP entity of the LSN L of the last data packet (ie, the decision point-1) received before the packet loss.
904、PDCP实体接收到RLC实体发送的LSNL后,计算下一个即将发送的数据包加密所应使用的HFN。904. After receiving the LSN L sent by the RLC entity, the PDCP entity calculates an HFN to be used for the next data packet to be sent.
具体计算过程参见前文的公式(3),此处不再赘述。For the specific calculation process, refer to the formula (3) above, which will not be repeated here.
后续,PDCP实体根据计算得到的对判决点的数据包进行加密所应使用的HFN和判决点的数据包携带的PDCP SN,对参数COUNT进行调整,并根据调整后的COUNT对判决点的数据包进行加密处理。Subsequently, the PDCP entity adjusts the parameter COUNT according to the calculated HFN and the PDCP SN carried by the data packet of the decision point used for encrypting the data packet of the decision point, and according to the adjusted COUNT pair of decision point data packets Perform encryption processing.
以上结合图1至图11,详细说明了本申请实施例提供的安全处理的方法,以下结合图12至图11说明本申请实施例提供的安全处理的装置和设备。The method for security processing provided by the embodiment of the present application is described in detail below with reference to FIG. 1 to FIG. 11. The apparatus and device for security processing provided by the embodiment of the present application are described below with reference to FIG. 12 to FIG.
图12示出了本申请实施例提供的安全处理的装置1000的示意性框图。该装置1000维护第一序列号,且每向PDCP实体发送一个PDCP数据包,第一序列号的值增加。如图12所示,装置1000包括:FIG. 12 is a schematic block diagram of an apparatus 1000 for security processing provided by an embodiment of the present application. The device 1000 maintains the first sequence number and sends a PDCP packet to the PDCP entity, the value of the first sequence number is increased. As shown in FIG. 12, the apparatus 1000 includes:
接收单元1100,用于接收数据包;The receiving unit 1100 is configured to receive a data packet.
处理单元1200,用于将接收单元接收的数据包解析为PDCP数据包;The processing unit 1200 is configured to parse the data packet received by the receiving unit into a PDCP data packet.
发送单元1300,用于向PDCP实体发送PDCP数据包和第一序列号,其中,PDCP数据包包括PDCP序列号,第一序列号的长度大于PDCP序列号的长度,且第一序列号用于在该装置发送给PDCP实体的PDCP数据包中存在丢失的PDCP数据包时调整参数COUNT,参数COUNT用于安全处理。The sending unit 1300 is configured to send a PDCP data packet and a first sequence number to the PDCP entity, where the PDCP data packet includes a PDCP serial number, the length of the first serial number is greater than the length of the PDCP serial number, and the first serial number is used in When the device sends a PDCP packet to the PDCP entity, the parameter COUNT is adjusted when there is a missing PDCP packet, and the parameter COUNT is used for security processing.
本申请实施例提供的安全处理的装置1000,可以对应上述方法200中描述的第一实体。并且,装置1000中各模块或单元分别用于执行上述方法200中第一实体所执行的各动作或处理过程。为了简洁,此处不作赘述。The apparatus 1000 for security processing provided by the embodiment of the present application may correspond to the first entity described in the foregoing method 200. Moreover, each module or unit in the device 1000 is used to perform each action or process performed by the first entity in the method 200 described above. For the sake of brevity, no further details are given here.
图13示出了本申请实施例的安全处理的装置2000的示意性框图。如图 13所示,装置2000包括:FIG. 13 shows a schematic block diagram of an apparatus 2000 for secure processing of an embodiment of the present application. As shown As shown in Figure 13, device 2000 includes:
接收单元2100,用于接收从第一实体接收PDCP数据包和第一序列号,其中,第一序列号的值在第一实体每向该装置发送一个PDCP数据包时增加,PDCP数据包包括PDCP序列号,第一序列号的长度大于PDCP序列号的长度,且第一序列号用于在该装置从第一实体接收的PDCP数据包中存在丢失的PDCP数据包时调整参数COUNT;The receiving unit 2100 is configured to receive, by the first entity, a PDCP data packet and a first sequence number, where the value of the first sequence number is increased when the first entity sends a PDCP data packet to the device, and the PDCP data packet includes the PDCP. a serial number, the length of the first serial number is greater than the length of the PDCP serial number, and the first serial number is used to adjust the parameter COUNT when there is a missing PDCP data packet in the PDCP data packet received by the device from the first entity;
处理单元2200,用于当该装置从第一实体接收的PDCP数据包中存在丢失的PDCP数据包时,根据所述第一序列号调整参数COUNT;The processing unit 2200 is configured to: when the device receives the lost PDCP data packet from the PDCP data packet received by the first entity, adjust the parameter COUNT according to the first serial number;
处理单元2200,还用于根据调整后的参数COUNT对第一PDCP数据包进行安全处理,其中,第一PDCP数据包为丢包后接收的PDCP数据包。The processing unit 2200 is further configured to perform security processing on the first PDCP data packet according to the adjusted parameter COUNT, where the first PDCP data packet is a PDCP data packet received after the packet loss.
本申请实施例提供的安全处理的装置2000,可以对应上述方法200中描述的PDCP实体。并且,装置2000中各模块或单元分别用于执行上述方法200中PDCP实体所执行的各动作或处理过程。为了简洁,此处不作赘述。The apparatus 2000 for security processing provided by the embodiment of the present application may correspond to the PDCP entity described in the foregoing method 200. Moreover, each module or unit in the device 2000 is used to perform various actions or processes performed by the PDCP entity in the above method 200, respectively. For the sake of brevity, no further details are given here.
图14示出了本申请实施例提供的安全处理的装置3000的示意性框图。该装置3000维护第一序列号,且每向第一实体发送一个PDCP数据包,所述第一序列号的值增加。如图14所示,装置3000包括:FIG. 14 is a schematic block diagram of an apparatus 3000 for security processing provided by an embodiment of the present application. The device 3000 maintains the first sequence number and transmits a PDCP packet to the first entity, the value of the first sequence number increasing. As shown in FIG. 14, the device 3000 includes:
发送单元3100,用于向第一实体发送PDCP数据包和第一序列号,其中,PDCP数据包包括PDCP序列号,第一序列号的长度大于PDCP序列号的长度,且第一序列号用于在该装置发送给第一实体的PDCP数据包中存在丢失的PDCP数据包时调整参数COUNT;The sending unit 3100 is configured to send a PDCP data packet and a first sequence number to the first entity, where the PDCP data packet includes a PDCP serial number, the length of the first serial number is greater than the length of the PDCP serial number, and the first serial number is used. Adjusting the parameter COUNT when there is a missing PDCP data packet in the PDCP data packet sent by the device to the first entity;
处理单元3200,用于当该装置发送给第一实体的PDCP数据包中存在丢失的PDCP数据包时,从第一实体获取丢包信息;The processing unit 3200 is configured to: when the device sends the lost PDCP data packet in the PDCP data packet sent by the device to the first entity, obtain the packet loss information from the first entity;
处理单元3200,还用于根据丢包信息和第一序列号调整参数COUNT;The processing unit 3200 is further configured to adjust the parameter COUNT according to the packet loss information and the first sequence number;
处理单元3200,还用于根据调整后的参数COUNT对第一PDCP数据包进行安全处理,其中,第一PDCP数据包为丢包后发送的PDCP数据包。The processing unit 3200 is further configured to perform security processing on the first PDCP data packet according to the adjusted parameter COUNT, where the first PDCP data packet is a PDCP data packet that is sent after the packet loss.
本申请实施例提供的安全处理的装置3000,可以对应上述方法300中描述的PDCP实体。并且,装置3000中各模块或单元分别用于执行上述方法300中PDCP实体所执行的各动作或处理过程。为了简洁,此处不作赘述。The apparatus 3000 for security processing provided by the embodiment of the present application may correspond to the PDCP entity described in the foregoing method 300. Moreover, each module or unit in device 3000 is used to perform various actions or processes performed by the PDCP entity in method 300 above. For the sake of brevity, no further details are given here.
图15示出了本申请实施例提供的安全处理的装置4000的示意性框图。如图15所示,装置4000包括:FIG. 15 is a schematic block diagram of an apparatus 4000 for security processing provided by an embodiment of the present application. As shown in Figure 15, device 4000 includes:
接收单元4100,用于从分组数据汇聚协议PDCP实体接收PDCP数据包 和第一序列号,其中,第一序列号的值在PDCP实体每向该装置发送一个PDCP数据包时增加,PDCP数据包包括PDCP序列号,第一序列号的长度大于PDCP序列号的长度,且第一序列号用于在第一实体从PDCP实体接收的PDCP数据包中存在丢失的PDCP数据包时调整参数COUNT;The receiving unit 4100 is configured to receive the PDCP data packet from the packet data convergence protocol PDCP entity. And a first serial number, wherein the value of the first serial number is increased when the PDCP entity sends a PDCP data packet to the device, and the PDCP data packet includes a PDCP serial number, and the length of the first serial number is greater than the length of the PDCP serial number, And the first sequence number is used to adjust the parameter COUNT when there is a missing PDCP data packet in the PDCP data packet received by the first entity from the PDCP entity;
处理单元4200,用于判断接收单元从PDCP实体接收的PDCP数据包中是否存在丢失的PDCP数据包;The processing unit 4200 is configured to determine whether there is a missing PDCP data packet in the PDCP data packet received by the receiving unit from the PDCP entity.
发送单元4300,还用于当接收单元从PDCP实体接收的PDCP数据包中存在丢失的PDCP数据包时,通知PDCP实体丢包信息;The sending unit 4300 is further configured to: when the receiving unit receives the lost PDCP data packet from the PDCP data packet received by the PDCP entity, notify the PDCP entity of the packet loss information;
接收单元4100,还用于在丢包后从PDCP实体接收第一PDCP数据包,且第一PDCP数据包的安全处理是根据调整后的参数COUNT进行的,且参数COUNT的调整是根据第一序列号和丢包信息进行的。The receiving unit 4100 is further configured to receive the first PDCP data packet from the PDCP entity after the packet loss, and the security processing of the first PDCP data packet is performed according to the adjusted parameter COUNT, and the parameter COUNT is adjusted according to the first sequence. Number and packet loss information.
本申请实施例提供的安全处理的装置4000,可以对应上述方法300中描述的第一实体。并且,装置4000中各模块或单元分别用于执行上述方法300中第一实体所执行的各动作或处理过程。为了简洁,此处不作赘述。The apparatus 4000 for security processing provided by the embodiment of the present application may correspond to the first entity described in the foregoing method 300. Moreover, each module or unit in device 4000 is used to perform various actions or processes performed by the first entity in method 300 above. For the sake of brevity, no further details are given here.
应理解,上述安全处理的装置1000-4000中,各个单元的划分仅仅是一种逻辑功能的划分,实际实现时可以全部或部分集成到一个物理实体上,也可以物理上分开。且这些单元可以全部以软件通过处理元件调用的形式实现。也可以全部以硬件的形式实现。还可以部分单元通过软件通过处理元件调用的形式实现,部分单元通过硬件的形式实现。例如,处理单元可以为单独设立的处理元件,也可以集成在装置的某一个芯片中实现,此外,也可以以程序的形式存储于装置的存储器中,由装置的某一个处理元件调用并执行以上各个单元的功能。其它单元的实现与之类似。此外这些单元全部或部分可以集成在一起,也可以独立实现。这里所述的处理元件可以是一种集成电路,具有信号的处理能力。在实现过程中,上述方法的各步骤或以上各个单元可以通过处理器元件中的硬件的集成逻辑电路或者软件形式的指令完成。It should be understood that, in the above-mentioned security processing apparatus 1000-4000, the division of each unit is only a division of a logical function, and the actual implementation may be integrated into one physical entity in whole or in part, or may be physically separated. And these units can all be implemented in software in the form of processing component calls. It can also be implemented entirely in hardware. It is also possible that some units are implemented by software in the form of processing component calls, and some units are implemented in the form of hardware. For example, the processing unit may be a separately set processing element, or may be integrated in one of the chips of the device, or may be stored in the memory of the device in the form of a program, which is called and executed by one of the processing elements of the device. The function of each unit. The implementation of other units is similar. In addition, all or part of these units can be integrated or implemented independently. The processing elements described herein can be an integrated circuit with signal processing capabilities. In the implementation process, each step of the above method or each of the above units may be completed by an integrated logic circuit of hardware in the processor element or an instruction in a form of software.
另外,以上这些单元可以是被配置成实施以上方法的一个或多个集成电路,例如:一个或多个特定集成电路(Application Specific Integrated Circuit,ASIC),或,一个或多个微处理器(digital signal processor,DSP),或,一个或者多个现场可编程门阵列(Field Programmable Gate Array,FPGA)等。又例如,当以上某个单元通过处理元件调度程序的形式实现时,该处理元件可以是通用处理器、中央处理器(Central Processing Unit,CPU)或其它可 以调用程序的处理器。再例如,这些单元可以集成在一起,以片上系统(system-on-a-chip,SOC)的形式实现。Additionally, the above units may be one or more integrated circuits configured to implement the above methods, such as one or more Application Specific Integrated Circuits (ASICs), or one or more microprocessors (digital) Signal processor, DSP), or one or more Field Programmable Gate Arrays (FPGAs). For another example, when one of the above units is implemented in the form of a processing component scheduler, the processing component may be a general purpose processor, a central processing unit (CPU), or the like. To call the program's processor. As another example, these units can be integrated and implemented in the form of a system-on-a-chip (SOC).
图16为本申请实施例提供的安全处理的设备5000的示意性结构图。图16所示,设备5000包括:存储器5100、处理器5200和通信接口5300。其中,存储器5100、处理器5200和通信接口5300通过通信总线5400相互连接。FIG. 16 is a schematic structural diagram of a device 5000 for security processing according to an embodiment of the present application. As shown in FIG. 16, the device 5000 includes a memory 5100, a processor 5200, and a communication interface 5300. The memory 5100, the processor 5200, and the communication interface 5300 are connected to each other through a communication bus 5400.
存储器5100用于存储执行本发明方案的应用程序、代码或指令。处理器5200用于执行存储器5100中存储的应用程序、代码或指令,以完成安全处理的方法300以及各实施例中由第一实体执行的相应流程和/或操作。为了简洁,此处不再赘述。 Memory 5100 is for storing applications, code or instructions that perform the inventive arrangements. The processor 5200 is configured to execute an application, code or instructions stored in the memory 5100 to perform the method 300 of security processing and corresponding flows and/or operations performed by the first entity in various embodiments. For the sake of brevity, it will not be repeated here.
上述图12中提供的安全处理的装置1000,可以通过图16中所示的安全处理的设备5000来实现。例如,图12中的接收单元以及发送单元可以由图16中的一个或多个通信接口5300来实现。处理单元可以由图16中所示的处理器5200实现。The apparatus 1000 for security processing provided in the above FIG. 12 can be implemented by the apparatus 5000 for security processing shown in FIG. For example, the receiving unit and the transmitting unit in FIG. 12 may be implemented by one or more communication interfaces 5300 in FIG. The processing unit can be implemented by the processor 5200 shown in FIG.
图17为本申请实施例提供的安全处理的设备6000的示意性结构图。图17所示,设备6000包括:存储器6100、处理器6200和通信接口6300。其中,存储器6100、处理器6200和通信接口6300通过通信总线6400相互连接。FIG. 17 is a schematic structural diagram of a device 6000 for security processing according to an embodiment of the present application. As shown in FIG. 17, the device 6000 includes a memory 6100, a processor 6200, and a communication interface 6300. The memory 6100, the processor 6200, and the communication interface 6300 are connected to each other through a communication bus 6400.
存储器6100用于存储执行本发明方案的应用程序、代码或指令。处理器6200用于执行存储器6100中存储的应用程序、代码或指令,以完成安全处理的方法300以及各实施例中由PDCP实体执行的相应流程和/或操作。为了简洁,此处不再赘述。 Memory 6100 is for storing applications, code or instructions that perform the inventive arrangements. The processor 6200 is configured to execute the application, code or instructions stored in the memory 6100 to perform the method 300 of security processing and the corresponding processes and/or operations performed by the PDCP entity in various embodiments. For the sake of brevity, it will not be repeated here.
上述图13中提供的安全处理的装置2000,可以通过图17中所示的安全处理的设备6000来实现。例如,图13中的接收单元可以由图17中的一个或多个通信接口6300来实现。处理单元可以由图17中所示的处理器6200实现。The device 2000 for security processing provided in FIG. 13 above can be implemented by the device 6000 for security processing shown in FIG. For example, the receiving unit of FIG. 13 can be implemented by one or more of the communication interfaces 6300 of FIG. The processing unit can be implemented by the processor 6200 shown in FIG.
图18为本申请实施例提供的安全处理的设备7000的示意性结构图。图18所示,设备7000包括:存储器7100、处理器7200和通信接口7300。其中,存储器7100、处理器7200和通信接口7300通过通信总线7400相互连接。FIG. 18 is a schematic structural diagram of a device 7000 for security processing according to an embodiment of the present application. As shown in FIG. 18, the device 7000 includes a memory 7100, a processor 7200, and a communication interface 7300. The memory 7100, the processor 7200, and the communication interface 7300 are connected to each other through a communication bus 7400.
存储器7100用于存储执行本发明方案的应用程序、代码或指令。处理 器7200用于执行存储器7100中存储的应用程序、代码或指令,以完成安全处理的方法300以及各实施例中由PDCP实体执行的相应流程和/或操作。为了简洁,此处不再赘述。 Memory 7100 is for storing applications, code or instructions that perform the inventive arrangements. deal with The processor 7200 is for executing the application, code or instructions stored in the memory 7100 to perform the method 300 of security processing and the corresponding processes and/or operations performed by the PDCP entity in various embodiments. For the sake of brevity, it will not be repeated here.
上述图14中提供的安全处理的装置3000,可以通过图18中所示的安全处理的设备7000来实现。例如,图14中的发送单元可以由图18中的一个或多个通信接口7300来实现。处理单元可以由图18中所示的处理器7200实现。The apparatus 3000 for secure processing provided in FIG. 14 above can be implemented by the securely processed apparatus 7000 shown in FIG. For example, the transmitting unit of FIG. 14 can be implemented by one or more of the communication interfaces 7300 of FIG. The processing unit can be implemented by the processor 7200 shown in FIG.
图19为本申请实施例提供的安全处理的设备8000的示意性结构图。图19所示,设备8000包括:存储器8100、处理器8200和通信接口8300。其中,存储器8100、处理器8200和通信接口8300通过通信总线8400相互连接。FIG. 19 is a schematic structural diagram of a device 8000 for security processing according to an embodiment of the present application. As shown in FIG. 19, device 8000 includes a memory 8100, a processor 8200, and a communication interface 8300. The memory 8100, the processor 8200, and the communication interface 8300 are connected to each other through a communication bus 8400.
存储器8100用于存储执行本发明方案的应用程序、代码或指令。处理器8200用于执行存储器8100中存储的应用程序、代码或指令,以完成安全处理的方法300以及各实施例中由第一实体执行的相应流程和/或操作。为了简洁,此处不再赘述。 Memory 8100 is for storing applications, code or instructions that perform the inventive arrangements. The processor 8200 is configured to execute the application, code, or instructions stored in the memory 8100 to perform the method 300 of security processing and the corresponding processes and/or operations performed by the first entity in various embodiments. For the sake of brevity, it will not be repeated here.
上述图15中提供的安全处理的装置4000,可以通过图19中所示的安全处理的设备8000来实现。例如,图15中的接收单元可以由图19中的一个或多个通信接口8300来实现。处理单元可以由图19中所示的处理器8200实现。The apparatus 4000 for security processing provided in the above FIG. 15 can be implemented by the securely processed apparatus 8000 shown in FIG. For example, the receiving unit in FIG. 15 can be implemented by one or more communication interfaces 8300 in FIG. The processing unit can be implemented by the processor 8200 shown in FIG.
以上图16-19中所示的处理器可以为中央处理器(CPU)、微处理器、特定应用集成电路(application-specific integrated circuit,ASIC),或一个或多个用于控制本发明方案程序执行的集成电路。The processor shown in Figures 16-19 above may be a central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more program programs for controlling the present invention. Execution of the integrated circuit.
图16-19中所示的存储器可以是只读存储器(read-only memory,ROM)或可存储静态信息和指令的其他类型的静态存储设备,随机存取存储器(random access memory,RAM)或者可存储信息和指令的其他类型的动态存储设备,也可以是电可擦可编程只读存储器(Electrically Erasable Programmable Read-Only Memory,EEPROM)、只读光盘(Compact Disc Read-Only Memory,CD-ROM)或其他光盘存储、光碟存储(包括压缩光碟、激光碟、光碟、数字通用光碟、蓝光光碟等)、磁盘存储介质或者其他磁存储设备、或者能够用于携带或存储具有指令或数据结构形式的期望的程序代码并能够由计算机存取的任何其他介质,但不限于此。存储器可以是独立存 在,通过通信总线与处理器相连接。存储器也可以和处理器集成在一起。The memory shown in Figures 16-19 may be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or Other types of dynamic storage devices that store information and instructions may also be Electrically Erasable Programmable Read-Only Memory (EEPROM) or Compact Disc Read-Only Memory (CD-ROM). Or other disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), disk storage media or other magnetic storage devices, or can be used to carry or store expectations in the form of instructions or data structures Program code and any other medium that can be accessed by a computer, but is not limited thereto. Memory can be stored separately It is connected to the processor through a communication bus. The memory can also be integrated with the processor.
通信总线除包括数据总线之外,还可以包括电源总线、控制总线和状态信号总线等。为了清楚说明起见,在图中将各种总线都标为通信总线。The communication bus may include a power bus, a control bus, and a status signal bus in addition to the data bus. For clarity of description, various buses are labeled as communication buses in the figures.
通信接口可以是有线接口,例如光纤分布式数据接口(Fiber Distributed Data Interface,简称FDDI)、千兆以太网(Gigabit Ethernet,简称GE)接口等,也可以是无线接口。本申请实施例对此不作特别限定。The communication interface may be a wired interface, such as a Fiber Distributed Data Interface (FDDI), a Gigabit Ethernet (GE) interface, or the like. This embodiment of the present application does not specifically limit this.
应理解,在本申请的各种实施例中,上述各过程的序号的大小并不意味着执行顺序的先后,各过程的执行顺序应以其功能和内在逻辑确定,而不应对本申请实施例的实施过程构成任何限定。It should be understood that, in the various embodiments of the present application, the size of the sequence numbers of the foregoing processes does not mean the order of execution sequence, and the order of execution of each process should be determined by its function and internal logic, and should not be applied to the embodiment of the present application. The implementation process constitutes any limitation.
本领域普通技术人员可以意识到,结合本文中所公开的实施例描述的各示例的单元及算法步骤,能够以电子硬件、计算机软件或者二者的结合来实现,为了清楚地说明硬件和软件的可互换性,在上述说明中已经按照功能一般性地描述了各示例的组成及步骤。这些功能究竟以硬件还是软件方式来执行,取决于技术方案的特定应用和设计约束条件。专业技术人员可以对每个特定的应用来使用不同方法来实现所描述的功能,但是这种实现不应认为超出本申请的范围。Those of ordinary skill in the art will appreciate that the elements and algorithm steps of the various examples described in connection with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both, for clarity of hardware and software. Interchangeability, the composition and steps of the various examples have been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the solution. A person skilled in the art can use different methods to implement the described functions for each particular application, but such implementation should not be considered to be beyond the scope of the present application.
所属领域的技术人员可以清楚地了解到,为了描述的方便和简洁,上述描述的系统、装置和单元的具体工作过程,可以参考前述方法实施例中的对应过程,在此不再赘述。A person skilled in the art can clearly understand that, for the convenience and brevity of the description, the specific working process of the system, the device and the unit described above can refer to the corresponding process in the foregoing method embodiment, and details are not described herein again.
在本申请所提供的几个实施例中,应该理解到,所揭露的系统、装置和方法,可以通过其它的方式实现。例如,以上所描述的装置实施例仅仅是示意性的,例如,所述单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另外,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口、装置或单元的间接耦合或通信连接,也可以是电的,机械的或其它的形式连接。In the several embodiments provided by the present application, it should be understood that the disclosed systems, devices, and methods may be implemented in other manners. For example, the device embodiments described above are merely illustrative. For example, the division of the unit is only a logical function division. In actual implementation, there may be another division manner, for example, multiple units or components may be combined or Can be integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interface, device or unit, or an electrical, mechanical or other form of connection.
所述作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部单元来实现本申请实施例方案的目的。The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, may be located in one place, or may be distributed to multiple network units. Some or all of the units may be selected according to actual needs to achieve the objectives of the embodiments of the present application.
另外,在本申请各个实施例中的各功能单元可以集成在一个处理单元 中,也可以是各个单元单独物理存在,也可以是两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用软件功能单元的形式实现。In addition, each functional unit in various embodiments of the present application may be integrated in one processing unit In addition, each unit may exist physically separately, or two or more units may be integrated into one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
所述集成的单元如果以软件功能单元的形式实现并作为独立的产品销售或使用时,可以存储在一个计算机可读取存储介质中。基于这样的理解,本申请的技术方案本质上或者说对现有技术做出贡献的部分,或者该技术方案的全部或部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)执行本申请各个实施例所述方法的全部或部分步骤。而前述的存储介质包括:U盘、移动硬盘、只读存储器(ROM,Read-Only Memory)、随机存取存储器(RAM,Random Access Memory)、磁碟或者光盘等各种可以存储程序代码的介质。The integrated unit, if implemented in the form of a software functional unit and sold or used as a standalone product, may be stored in a computer readable storage medium. Based on such understanding, the technical solution of the present application may be in essence or part of the contribution to the prior art, or all or part of the technical solution may be embodied in the form of a software product stored in a storage medium. A number of instructions are included to cause a computer device (which may be a personal computer, server, or network device, etc.) to perform all or part of the steps of the methods described in various embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, and the like. .
以上所述,仅为本申请的具体实施方式,但本申请的保护范围并不局限于此,任何熟悉本技术领域的技术人员在本申请揭露的技术范围内,可轻易想到各种等效的修改或替换,这些修改或替换都应涵盖在本申请的保护范围之内。因此,本申请的保护范围应以权利要求的保护范围为准。 The foregoing is only a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto, and any equivalents can be easily conceived by those skilled in the art within the technical scope disclosed in the present application. Modifications or substitutions are intended to be included within the scope of the present application. Therefore, the scope of protection of this application should be determined by the scope of protection of the claims.

Claims (44)

  1. 一种安全处理的方法,其特征在于,用于接收端,所述接收端的第一实体维护第一序列号,且每向分组数据汇聚协议PDCP实体发送一个PDCP数据包,所述第一序列号的值增加,所述方法包括:A method for security processing, characterized in that, for a receiving end, a first entity of the receiving end maintains a first sequence number, and each PDTP data packet is sent to a packet data convergence protocol PDCP entity, the first sequence number The value of the method is increased, and the method includes:
    所述第一实体接收数据包,并将所述数据包解析为PDCP数据包;Receiving, by the first entity, a data packet, and parsing the data packet into a PDCP data packet;
    所述第一实体向所述PDCP实体发送所述PDCP数据包和第一序列号,其中,所述PDCP数据包包括PDCP序列号,所述第一序列号的长度大于所述PDCP序列号的长度,且所述第一序列号用于在所述第一实体发送给所述PDCP实体的PDCP数据包中存在丢失的PDCP数据包时调整参数COUNT,所述参数COUNT用于安全处理。Transmitting, by the first entity, the PDCP data packet and the first sequence number to the PDCP entity, where the PDCP data packet includes a PDCP sequence number, and the length of the first sequence number is greater than a length of the PDCP sequence number And the first sequence number is used to adjust a parameter COUNT when there is a missing PDCP data packet in a PDCP data packet sent by the first entity to the PDCP entity, where the parameter COUNT is used for security processing.
  2. 根据权利要求1所述的方法,其特征在于,所述第一序列号在所述第一实体发送给所述PDCP实体的PDCP数据包中存在丢失的PDCP数据包,且所述丢失的PDCP数据包达到或超过预设阈值时,用于调整参数COUNT。The method according to claim 1, wherein the first sequence number has a lost PDCP data packet in a PDCP data packet sent by the first entity to the PDCP entity, and the lost PDCP data Used to adjust the parameter COUNT when the packet reaches or exceeds the preset threshold.
  3. 根据权利要求1或2所述的方法,其特征在于,所述第一实体每向所述PDCP实体发送一个PDCP数据包,所述第一序列号的值加1。The method according to claim 1 or 2, wherein the first entity sends a PDCP data packet to the PDCP entity, and the value of the first sequence number is incremented by one.
  4. 根据权利要求1至3任一项所述的方法,其特征在于,所述第一实体为无线链路控制RLC实体。The method according to any one of claims 1 to 3, wherein the first entity is a radio link control RLC entity.
  5. 一种安全处理的方法,其特征在于,用于接收端,所述方法包括:A method for security processing, characterized in that, for a receiving end, the method includes:
    分组数据汇聚协议PDCP实体从第一实体接收PDCP数据包和第一序列号,其中所述第一序列号的值在所述第一实体每向所述PDCP实体发送一个PDCP数据包时增加,所述PDCP数据包包括PDCP序列号,所述第一序列号的长度大于所述PDCP序列号的长度,且所述第一序列号用于在所述PDCP实体从所述第一实体接收的PDCP数据包中存在丢失的PDCP数据包时调整参数COUNT;a packet data convergence protocol PDCP entity receives a PDCP data packet and a first sequence number from a first entity, wherein a value of the first sequence number is incremented each time the first entity sends a PDCP data packet to the PDCP entity, The PDCP data packet includes a PDCP sequence number, the length of the first sequence number is greater than a length of the PDCP sequence number, and the first sequence number is used for PDCP data received by the PDCP entity from the first entity. Adjust the parameter COUNT when there is a missing PDCP packet in the packet;
    当所述PDCP实体从所述第一实体接收的PDCP数据包中存在丢失的PDCP数据包时,所述PDCP实体根据所述第一序列号调整参数COUNT;When the PDCP entity receives a lost PDCP data packet from the PDCP data packet received by the first entity, the PDCP entity adjusts the parameter COUNT according to the first sequence number;
    所述PDCP实体根据调整后的参数COUNT对第一PDCP数据包进行安全处理,其中,所述第一PDCP数据包为丢包后接收的PDCP数据包。The PDCP entity performs security processing on the first PDCP data packet according to the adjusted parameter COUNT, where the first PDCP data packet is a PDCP data packet received after the packet loss.
  6. 根据权利要求5所述的方法,其特征在于,所述PDCP实体根据所述第一序列号调整参数COUNT,包括: The method according to claim 5, wherein the PDCP entity adjusts the parameter COUNT according to the first sequence number, including:
    当所述PDCP实体从所述第一实体接收的PDCP数据包中存在丢失的PDCP数据包,且所述丢失的PDCP数据包的数量达到或超过预设阈值时,所述PDCP实体根据所述第一序列号调整参数COUNT。When the PDCP entity has a lost PDCP data packet in a PDCP data packet received by the first entity, and the number of the lost PDCP data packet reaches or exceeds a preset threshold, the PDCP entity is configured according to the A serial number adjustment parameter COUNT.
  7. 根据权利要求5或6所述的方法,其特征在于,所述PDCP实体根据所述第一序列号调整参数COUNT,包括:The method according to claim 5 or 6, wherein the PDCP entity adjusts the parameter COUNT according to the first sequence number, including:
    所述PDCP实体从丢失的PDCP数据包之前正确接收的PDCP数据包中选择第二数据包;The PDCP entity selects a second data packet from a PDCP data packet that is correctly received before the lost PDCP data packet;
    根据所述第二数据包的第一序列号、所述第二数据包的PDCP序列号、所述第二数据包的超帧号HFN、所述第一数据包的第一序列号和所述第一数据包的PDCP序列号,确定所述第一数据包的HFN;And according to the first sequence number of the second data packet, the PDCP sequence number of the second data packet, the super frame number HFN of the second data packet, the first sequence number of the first data packet, and the Determining an HFN of the first data packet by a PDCP sequence number of the first data packet;
    根据所述第一数据包的HFN和所述第一数据包的PDCP序列号,确定参数COUNT。The parameter COUNT is determined according to the HFN of the first data packet and the PDCP sequence number of the first data packet.
  8. 根据权利要求7所述的方法,其特征在于,所述根据所述第二数据包的第一序列号、所述第二数据包的PDCP序列号、所述第二数据包的超帧号HFN、所述第一数据包的第一序列号和所述第一数据包的PDCP序列号,确定所述第一数据包的HFN,包括:The method according to claim 7, wherein said first sequence number according to said second data packet, a PDCP sequence number of said second data packet, and a super frame number HFN of said second data packet Determining the HFN of the first data packet by using the first sequence number of the first data packet and the PDCP sequence number of the first data packet, including:
    根据以下公式确定所述第一数据包的HFN:The HFN of the first data packet is determined according to the following formula:
    Figure PCTCN2016108034-appb-100001
    Figure PCTCN2016108034-appb-100001
    其中,HFNN为所述第一数据包的HFN,SNN为所述第一数据包的PDCP SN,LSNN为所述第一数据包的第一序列号,LSNB为所述第二数据包的第一序列号,HFNB为所述第二数据包的HFN,SNB为所述第二数据包的PDCP SN,c为参数COUNT的长度,n为PDCP SN的长度,k为第一序列号的长度。The HFN N is the HFN of the first data packet, the SN N is the PDCP SN of the first data packet, the LSN N is the first sequence number of the first data packet, and the LSN B is the second data. The first sequence number of the packet, HFN B is the HFN of the second data packet, SN B is the PDCP SN of the second data packet, c is the length of the parameter COUNT, n is the length of the PDCP SN, and k is the first The length of the serial number.
  9. 根据权利要求5至8任一项所述的方法,其特征在于,所述第一序列号的值在所述第一实体每向所述PDCP实体发送一个PDCP数据包时加1。The method according to any one of claims 5 to 8, wherein the value of the first sequence number is incremented by one each time the first entity sends a PDCP packet to the PDCP entity.
  10. 根据权利要求5至9任一项所述的方法,其特征在于,所述第一实体为无线链路控制RLC实体。The method according to any one of claims 5 to 9, wherein the first entity is a radio link control RLC entity.
  11. 一种安全处理的方法,其特征在于,用于发送端,所述发送端的分组数据汇聚协议PDCP实体维护第一序列号,且每向第一实体发送一个PDCP数据包,所述第一序列号的值增加,所述方法包括:A method for security processing, characterized in that, for a transmitting end, a packet data convergence protocol PDCP entity of the transmitting end maintains a first sequence number, and each time a PDCP data packet is sent to the first entity, the first sequence number The value of the method is increased, and the method includes:
    所述PDCP实体向所述第一实体发送PDCP数据包和第一序列号,其中 所述PDCP数据包包括PDCP序列号,所述第一序列号的长度大于所述PDCP序列号的长度,且所述第一序列号用于在所述PDCP实体发送给所述第一实体的PDCP数据包中存在丢失的PDCP数据包时调整参数COUNT;Transmitting, by the PDCP entity, a PDCP data packet and a first serial number to the first entity, where The PDCP data packet includes a PDCP sequence number, the length of the first sequence number is greater than the length of the PDCP sequence number, and the first sequence number is used by the PDCP entity to send the PDCP to the first entity. Adjust the parameter COUNT when there is a missing PDCP packet in the data packet;
    当所述PDCP实体发送给所述第一实体的PDCP数据包中存在丢失的PDCP数据包时,所述PDCP实体从所述第一实体获取丢包信息;When the PDCP data packet sent by the PDCP entity to the first entity has a lost PDCP data packet, the PDCP entity acquires packet loss information from the first entity;
    所述PDCP实体根据丢包信息和所述第一序列号调整参数COUNT;The PDCP entity adjusts the parameter COUNT according to the packet loss information and the first sequence number;
    所述PDCP实体根据调整后的参数COUNT对第一PDCP数据包进行安全处理,其中所述第一PDCP数据包为丢包后发送的PDCP数据包。The PDCP entity performs security processing on the first PDCP data packet according to the adjusted parameter COUNT, where the first PDCP data packet is a PDCP data packet that is sent after the packet is lost.
  12. 根据权利要求11所述的方法,其特征在于,所述PDCP实体根据所述第一序列号调整参数COUNT,包括:The method according to claim 11, wherein the PDCP entity adjusts the parameter COUNT according to the first sequence number, including:
    当所述PDCP实体发送给所述第一实体的PDCP数据包中存在丢失的PDCP数据包,且所述丢失的PDCP数据包的数量达到或超过预设阈值时,所述PDCP实体根据所述第一序列号调整参数COUNT。When the PDCP data packet sent by the PDCP entity to the first entity has a lost PDCP data packet, and the number of the lost PDCP data packet reaches or exceeds a preset threshold, the PDCP entity is configured according to the foregoing A serial number adjustment parameter COUNT.
  13. 根据权利要求11或12所述的方法,其特征在于,所述PDCP实体根据丢包信息和所述第一序列号调整参数COUNT,包括:The method according to claim 11 or 12, wherein the PDCP entity adjusts the parameter COUNT according to the packet loss information and the first sequence number, including:
    所述PDCP实体根据所述丢包信息从丢失的PDCP数据包之前被所述第一实体正确接收的PDCP数据包中选择第二数据包,并确定丢包前最后一个正确接收的第三PDCP数据包;Determining, by the PDCP entity, the second data packet from the PDCP data packet correctly received by the first entity before the lost PDCP data packet according to the packet loss information, and determining the last correctly received third PDCP data before the packet loss package;
    根据所述第二数据包的第一序列号、所述第二数据包的PDCP序列号、所述第二数据包的超帧号HFN、所述第三数据包的第一序列号、和所述第一数据包的PDCP序列号,确定所述第一数据包的HFN;And according to the first sequence number of the second data packet, the PDCP sequence number of the second data packet, the super frame number HFN of the second data packet, the first serial number of the third data packet, and the Determining a PDCP sequence number of the first data packet, determining an HFN of the first data packet;
    根据所述第一数据包的HFN和所述第一数据包的PDCP序列号,确定参数COUNT。The parameter COUNT is determined according to the HFN of the first data packet and the PDCP sequence number of the first data packet.
  14. 根据权利要求13所述的方法,其特征在于,所述根据所述第二数据包的第一序列号、所述第二数据包的PDCP序列号、所述第二数据包的超帧号HFN、所述第三数据包的第一序列号、和所述第一数据包的PDCP序列号,确定所述第一数据包的HFN,包括:The method according to claim 13, wherein said first sequence number according to said second data packet, a PDCP sequence number of said second data packet, and a super frame number HFN of said second data packet Determining the HFN of the first data packet by using the first sequence number of the third data packet and the PDCP sequence number of the first data packet, including:
    根据以下公式确定所述第一数据包的HFN:The HFN of the first data packet is determined according to the following formula:
    Figure PCTCN2016108034-appb-100002
    ,其中,HFNN为所述第一数据包的HFN,SNN为所述第一数据包的PDCP SN,LSNL为所述第三数据包的第一序列号,LSNB为所述第二数据包的第一序列 号,HFNB为所述第二数据包的HFN,SNB为所述第二数据包的PDCP SN,c为参数COUNT的长度,n为PDCP SN的长度,k为第一序列号的长度,t为常数,且为大于或等于1的正整数。
    Figure PCTCN2016108034-appb-100002
    Wherein HFN N is the HFN of the first data packet, SN N is the PDCP SN of the first data packet, LSN L is the first sequence number of the third data packet, and LSN B is the second The first sequence number of the data packet, HFN B is the HFN of the second data packet, SN B is the PDCP SN of the second data packet, c is the length of the parameter COUNT, n is the length of the PDCP SN, and k is the The length of a serial number, t is a constant, and is a positive integer greater than or equal to one.
  15. 根据权利要求11至14任一项所述的方法,其特征在于,所述丢包信息包括以下信息之一或更多:第一个丢失的PDCP数据包的第一SN、期望的下一个PDCP数据包的第一SN、丢包前最后一个PDCP数据包的第一SN、丢包后接收的第一个PDCP数据包的第一SN、丢失的PDCP数据包的数量。The method according to any one of claims 11 to 14, wherein the packet loss information comprises one or more of the following: a first SN of the first lost PDCP data packet, a desired next PDCP The first SN of the data packet, the first SN of the last PDCP data packet before the packet loss, the first SN of the first PDCP data packet received after the packet loss, and the number of lost PDCP data packets.
  16. 根据权利要求11至15任一项所述的方法,其特征在于,所述PDCP实体每向所述第一实体发送一个PDCP数据包,所述第一序列号的值加1。The method according to any one of claims 11 to 15, wherein the PDCP entity sends a PDCP data packet to the first entity, and the value of the first sequence number is incremented by one.
  17. 根据权利要求11至16任一项所述的方法,其特征在于,所述第一实体为无线链路控制RLC实体。The method according to any one of claims 11 to 16, wherein the first entity is a radio link control RLC entity.
  18. 一种安全处理的方法,其特征在于,用于发送端,所述方法包括:A method for security processing, characterized in that, for a transmitting end, the method includes:
    第一实体从分组数据汇聚协议PDCP实体接收PDCP数据包和第一序列号,其中所述第一序列号的值在所述PDCP实体每向所述第一实体发送一个PDCP数据包时增加,所述PDCP数据包包括PDCP序列号,所述第一序列号的长度大于所述PDCP序列号的长度,且所述第一序列号用于在所述第一实体从所述PDCP实体接收的PDCP数据包中存在丢失的PDCP数据包时调整参数COUNT;Receiving, by the first entity, a PDCP data packet and a first sequence number from a packet data convergence protocol PDCP entity, wherein a value of the first sequence number is increased each time the PDCP entity sends a PDCP data packet to the first entity, where The PDCP data packet includes a PDCP sequence number, the length of the first sequence number is greater than a length of the PDCP sequence number, and the first sequence number is used for PDCP data received by the first entity from the PDCP entity. Adjust the parameter COUNT when there is a missing PDCP packet in the packet;
    当所述第一实体从所述PDCP实体接收的PDCP数据包中存在丢失的PDCP数据包时,所述第一实体通知所述PDCP实体丢包信息;When the first entity has a lost PDCP data packet in a PDCP data packet received by the first entity, the first entity notifies the PDCP entity of packet loss information;
    所述第一实体在丢包后从所述PDCP实体接收第一PDCP数据包,且所述第一PDCP数据包的安全处理是根据调整后的参数COUNT进行的,且所述参数COUNT的调整是根据所述第一序列号和所述丢包信息进行的。The first entity receives the first PDCP data packet from the PDCP entity after the packet loss, and the security processing of the first PDCP data packet is performed according to the adjusted parameter COUNT, and the adjustment of the parameter COUNT is And performing according to the first serial number and the packet loss information.
  19. 根据权利要求18所述的方法,其特征在于,所述第一序列号在所述第一实体从所述PDCP实体接收的PDCP数据包中存在丢失的PDCP数据包,且所述丢失的PDCP数据包达到或超过预设阈值时,用于调整参数COUNT。The method according to claim 18, wherein said first sequence number has a lost PDCP data packet in a PDCP data packet received by said first entity from said PDCP entity, and said lost PDCP data Used to adjust the parameter COUNT when the packet reaches or exceeds the preset threshold.
  20. 根据权利要求18或19所述的方法,其特征在于,所述丢包信息包括以下信息之一或更多:第一个丢失的PDCP数据包的第一SN、期望的下一个PDCP数据包的第一SN、丢包前最后一个PDCP数据包的第一SN、丢 包后接收的第一个PDCP数据包的第一SN、丢失的PDCP数据包的数量。The method according to claim 18 or 19, wherein the packet loss information comprises one or more of the following: a first SN of the first lost PDCP data packet, and a desired next PDCP data packet. The first SN, the first SN of the last PDCP packet before the packet loss, and the lost The number of the first SN, the lost PDCP packet of the first PDCP packet received after the packet.
  21. 根据权利要求18至20任一项所述的方法,其特征在于,所述第一序列号的值在所述PDCP实体每向所述第一实体发送一个PDCP数据包时加1。The method according to any one of claims 18 to 20, wherein the value of the first sequence number is incremented by one every time the PDCP entity sends a PDCP packet to the first entity.
  22. 根据权利要求18至21任一项所述的方法,其特征在于,所述第一实体为无线链路控制RLC实体。The method according to any one of claims 18 to 21, wherein the first entity is a radio link control RLC entity.
  23. 一种安全处理的装置,其特征在于,配置在包括分组数据汇聚协议PDCP实体的接收端,所述装置维护第一序列号,且每向所述PDCP实体发送一个PDCP数据包,所述第一序列号的值增加,所述装置包括:A device for security processing, characterized in that it is configured at a receiving end including a packet data convergence protocol PDCP entity, the device maintains a first sequence number, and each time a PDCP data packet is sent to the PDCP entity, the first The value of the serial number is increased, and the device includes:
    接收单元,用于接收数据包;a receiving unit, configured to receive a data packet;
    处理单元,用于将所述接收单元接收的所述数据包解析为PDCP数据包;a processing unit, configured to parse the data packet received by the receiving unit into a PDCP data packet;
    发送单元,用于向所述PDCP实体发送所述PDCP数据包和第一序列号,其中,所述PDCP数据包包括PDCP序列号,所述第一序列号的长度大于所述PDCP序列号的长度,且所述第一序列号用于在所述装置发送给所述PDCP实体的PDCP数据包中存在丢失的PDCP数据包时调整参数COUNT,所述参数COUNT用于安全处理。a sending unit, configured to send the PDCP data packet and the first serial number to the PDCP entity, where the PDCP data packet includes a PDCP serial number, and the length of the first serial number is greater than a length of the PDCP serial number And the first sequence number is used to adjust a parameter COUNT when there is a missing PDCP data packet in a PDCP data packet sent by the device to the PDCP entity, and the parameter COUNT is used for security processing.
  24. 根据权利要求23所述的装置,其特征在于,所述第一序列号在所述装置发送给所述PDCP实体的PDCP数据包中存在丢失的PDCP数据包,且所述丢失的PDCP数据包达到或超过预设阈值时,用于调整参数COUNT。The apparatus according to claim 23, wherein said first sequence number has a lost PDCP data packet in a PDCP data packet sent by said apparatus to said PDCP entity, and said lost PDCP data packet is reached Used to adjust the parameter COUNT when the preset threshold is exceeded.
  25. 根据权利要求23或24所述的装置,其特征在于,所述装置每向所述PDCP实体发送一个PDCP数据包,所述第一序列号的值加1。The apparatus according to claim 23 or 24, wherein said apparatus transmits a PDCP data packet to said PDCP entity, said first sequence number being incremented by one.
  26. 根据权利要求23至25中任一项所述的装置,其特征在于,所述装置为无线链路控制RLC实体。Apparatus according to any one of claims 23 to 25, wherein the apparatus is a radio link control RLC entity.
  27. 一种安全处理的装置,其特征在于,配置在包括第一实体的接收端,所述装置包括:A device for security processing, characterized in that it is configured at a receiving end including a first entity, the device comprising:
    接收单元,用于从所述第一实体接收PDCP数据包和第一序列号,其中所述第一序列号的值在所述第一实体每向所述装置发送一个PDCP数据包时增加,所述PDCP数据包包括PDCP序列号,所述第一序列号的长度大于所述PDCP序列号的长度,且所述第一序列号用于在所述装置从所述第一实体接收的PDCP数据包中存在丢失的PDCP数据包时调整参数COUNT;a receiving unit, configured to receive a PDCP data packet and a first sequence number from the first entity, where a value of the first sequence number is increased when the first entity sends a PDCP data packet to the device, where The PDCP data packet includes a PDCP sequence number, the length of the first sequence number is greater than a length of the PDCP sequence number, and the first sequence number is used for a PDCP data packet received by the device from the first entity. Adjust the parameter COUNT when there is a missing PDCP packet;
    处理单元,用于当所述接收单元从所述第一实体接收的PDCP数据包中 存在丢失的PDCP数据包时,根据所述第一序列号调整参数COUNT;a processing unit, configured to: when the receiving unit receives the PDCP data packet from the first entity When there is a lost PDCP data packet, the parameter COUNT is adjusted according to the first serial number;
    所述处理单元,还用于根据调整后的参数COUNT对第一PDCP数据包进行安全处理,其中,所述第一PDCP数据包为丢包后接收的PDCP数据包。The processing unit is further configured to perform security processing on the first PDCP data packet according to the adjusted parameter COUNT, where the first PDCP data packet is a PDCP data packet received after the packet loss.
  28. 根据权利要求27所述的装置,其特征在于,所述处理单元具体用于:The device according to claim 27, wherein the processing unit is specifically configured to:
    当所述接收单元从所述第一实体接收的PDCP数据包中存在丢失的PDCP数据包,且所述丢失的PDCP数据包的数量达到或超过预设阈值时,根据所述第一序列号调整参数COUNT。And when the receiving unit has a lost PDCP data packet in the PDCP data packet received by the first entity, and the number of the lost PDCP data packet reaches or exceeds a preset threshold, according to the first serial number adjustment Parameter COUNT.
  29. 根据权利要求27或28所述的装置,其特征在于,所述处理单元具体用于:The device according to claim 27 or 28, wherein the processing unit is specifically configured to:
    从丢失的PDCP数据包之前正确接收的PDCP数据包中选择第二数据包;Selecting a second data packet from a PDCP data packet correctly received before the lost PDCP data packet;
    根据所述第二数据包的第一序列号、所述第二数据包的PDCP序列号、所述第二数据包的超帧号HFN、所述第一数据包的第一序列号和所述第一数据包的PDCP序列号,确定所述第一数据包的HFN;And according to the first sequence number of the second data packet, the PDCP sequence number of the second data packet, the super frame number HFN of the second data packet, the first sequence number of the first data packet, and the Determining an HFN of the first data packet by a PDCP sequence number of the first data packet;
    根据所述第一数据包的HFN和所述第一数据包的PDCP序列号,确定参数COUNT。The parameter COUNT is determined according to the HFN of the first data packet and the PDCP sequence number of the first data packet.
  30. 根据权利要求29所述的装置,其特征在于,所述处理单元具体用于根据以下公式确定所述第一数据包的HFN:The apparatus according to claim 29, wherein the processing unit is specifically configured to determine an HFN of the first data packet according to the following formula:
    Figure PCTCN2016108034-appb-100003
    Figure PCTCN2016108034-appb-100003
    其中,HFNN为所述第一数据包的HFN,SNN为所述第一数据包的PDCP SN,LSNN为所述第一数据包的第一序列号,LSNB为所述第二数据包的第一序列号,HFNB为所述第二数据包的HFN,SNB为所述第二数据包的PDCP SN,c为参数COUNT的长度,n为PDCP SN的长度,k为第一序列号的长度。The HFN N is the HFN of the first data packet, the SN N is the PDCP SN of the first data packet, the LSN N is the first sequence number of the first data packet, and the LSN B is the second data. The first sequence number of the packet, HFN B is the HFN of the second data packet, SN B is the PDCP SN of the second data packet, c is the length of the parameter COUNT, n is the length of the PDCP SN, and k is the first The length of the serial number.
  31. 根据权利要求27至30中任一项所述的装置,其特征在于,所述第一序列号的值在所述第一实体每向所述装置发送一个PDCP数据包时加1。The apparatus according to any one of claims 27 to 30, wherein the value of the first sequence number is incremented by one each time the first entity sends a PDCP packet to the apparatus.
  32. 根据权利要求27至31中任一项所述的装置,其特征在于,所述第一实体为无线链路控制RLC实体。The apparatus according to any one of claims 27 to 31, wherein the first entity is a radio link control RLC entity.
  33. 一种安全处理的装置,其特征在于,配置在包括第一实体的发送端,所述装置维护第一序列号,且每向所述第一实体发送一个PDCP数据包,所 述第一序列号的值增加,所述装置包括:A device for security processing, characterized in that it is configured at a transmitting end including a first entity, the device maintains a first serial number, and each time a PDCP data packet is sent to the first entity, The value of the first serial number is increased, and the device includes:
    发送单元,用于向所述第一实体发送PDCP数据包和第一序列号,其中所述PDCP数据包包括PDCP序列号,所述第一序列号的长度大于所述PDCP序列号的长度,且所述第一序列号用于在所述装置发送给所述第一实体的PDCP数据包中存在丢失的PDCP数据包时调整参数COUNT;a sending unit, configured to send a PDCP data packet and a first sequence number to the first entity, where the PDCP data packet includes a PDCP serial number, where a length of the first serial number is greater than a length of the PDCP serial number, and The first sequence number is used to adjust a parameter COUNT when there is a missing PDCP data packet in the PDCP data packet sent by the device to the first entity;
    处理单元,用于当所述装置发送给所述第一实体的PDCP数据包中存在丢失的PDCP数据包时,从所述第一实体获取丢包信息;a processing unit, configured to acquire packet loss information from the first entity when there is a lost PDCP data packet in a PDCP data packet sent by the device to the first entity;
    根据丢包信息和所述第一序列号调整参数COUNT;Adjusting the parameter COUNT according to the packet loss information and the first serial number;
    根据调整后的参数COUNT对第一PDCP数据包进行安全处理,其中所述第一PDCP数据包为丢包后发送的PDCP数据包。The first PDCP data packet is securely processed according to the adjusted parameter COUNT, wherein the first PDCP data packet is a PDCP data packet sent after the packet loss.
  34. 根据权利要求33所述的装置,其特征在于,所述处理单元具体用于当所述发送单元发送给所述第一实体的PDCP数据包中存在丢失的PDCP数据包,且所述丢失的PDCP数据包的数量达到或超过预设阈值时,根据所述第一序列号调整参数COUNT。The apparatus according to claim 33, wherein the processing unit is configured to: when there is a lost PDCP data packet in a PDCP data packet sent by the sending unit to the first entity, and the lost PDCP When the number of data packets reaches or exceeds a preset threshold, the parameter COUNT is adjusted according to the first serial number.
  35. 根据权利要求33或34所述的装置,其特征在于,所述处理单元具体用于:The device according to claim 33 or 34, wherein the processing unit is specifically configured to:
    根据所述丢包信息从丢失的PDCP数据包之前被所述第一实体正确接收的PDCP数据包中选择第二数据包,并确定丢包前最后一个正确接收的第三PDCP数据包;Determining, according to the packet loss information, a second data packet from a PDCP data packet correctly received by the first entity before the lost PDCP data packet, and determining a last correctly received third PDCP data packet before the packet loss;
    根据所述第二数据包的第一序列号、所述第二数据包的PDCP序列号、所述第二数据包的超帧号HFN、所述第三数据包的第一序列号和所述第一数据包的PDCP序列号,确定所述第一数据包的HFN;Determining, according to a first sequence number of the second data packet, a PDCP sequence number of the second data packet, a superframe number HFN of the second data packet, a first sequence number of the third data packet, and the Determining an HFN of the first data packet by a PDCP sequence number of the first data packet;
    根据所述第一数据包的HFN和所述第一数据包的PDCP序列号,确定参数COUNT。The parameter COUNT is determined according to the HFN of the first data packet and the PDCP sequence number of the first data packet.
  36. 根据权利要求35所述的装置,其特征在于,所述处理单元具体用于根据以下公式确定所述第一数据包的HFN:The apparatus according to claim 35, wherein the processing unit is specifically configured to determine an HFN of the first data packet according to the following formula:
    Figure PCTCN2016108034-appb-100004
    ,其中,HFNN为所述第一数据包的HFN,SNN为所述第一数据包的PDCP SN,LSNL为所述第三数据包的第一序列号,LSNB为所述第二数据包的第一序列号,HFNB为所述第二数据包的HFN,SNB为所述第二数据包的PDCP SN,c为参数COUNT的长度,n为PDCP SN的长度,k为第一序列号的长度,t 为常数,且为大于或等于1的正整数。
    Figure PCTCN2016108034-appb-100004
    Wherein HFN N is the HFN of the first data packet, SN N is the PDCP SN of the first data packet, LSN L is the first sequence number of the third data packet, and LSN B is the second The first sequence number of the data packet, HFN B is the HFN of the second data packet, SN B is the PDCP SN of the second data packet, c is the length of the parameter COUNT, n is the length of the PDCP SN, and k is the The length of a sequence number, t is a constant, and is a positive integer greater than or equal to 1.
  37. 根据权利要求33至36中任一项所述的装置,其特征在于,所述丢包信息包括以下信息之一或更多:第一个丢失的PDCP数据包的第一SN、期望的下一个PDCP数据包的第一SN、丢包前最后一个PDCP数据包的第一SN、丢包后接收的第一个PDCP数据包的第一SN、丢失的PDCP数据包的数量。The apparatus according to any one of claims 33 to 36, wherein the packet loss information comprises one or more of the following: a first SN of the first lost PDCP data packet, a desired next one The first SN of the PDCP data packet, the first SN of the last PDCP data packet before the packet loss, the first SN of the first PDCP data packet received after the packet loss, and the number of lost PDCP data packets.
  38. 根据权利要求33至37中任一项所述的装置,其特征在于,所述装置每向所述第一实体发送一个PDCP数据包,所述第一序列号的值加1。The apparatus according to any one of claims 33 to 37, wherein the apparatus transmits a PDCP data packet to the first entity, and the value of the first serial number is incremented by one.
  39. 根据权利要求33至38中任一项所述的装置,其特征在于,所述第一实体为无线链路控制RLC实体。The apparatus according to any one of claims 33 to 38, wherein the first entity is a radio link control RLC entity.
  40. 一种安全处理的装置,其特征在于,配置在包括分组数据汇聚协议PDCP实体的发送端,所述装置包括:A device for security processing, characterized in that it is configured at a transmitting end including a packet data convergence protocol PDCP entity, and the device includes:
    接收单元,用于接收从所述PDCP实体接收PDCP数据包和第一序列号,其中,所述第一序列号的值在所述PDCP实体每向所述装置发送一个PDCP数据包时增加,所述PDCP数据包包括PDCP序列号,所述第一序列号的长度大于所述PDCP序列号的长度,且所述第一序列号用于在所述装置从所述PDCP实体接收的PDCP数据包中存在丢失的PDCP数据包时调整参数COUNT;a receiving unit, configured to receive a PDCP data packet and a first sequence number received from the PDCP entity, where a value of the first sequence number is increased when the PDCP entity sends a PDCP data packet to the device, where The PDCP data packet includes a PDCP sequence number, the length of the first sequence number is greater than a length of the PDCP sequence number, and the first sequence number is used in a PDCP data packet received by the device from the PDCP entity. Adjust the parameter COUNT when there is a missing PDCP packet;
    发送单元,用于当所述装置从所述PDCP实体接收的PDCP数据包中存在丢失的PDCP数据包时,向所述PDCP实体通知丢包信息;a sending unit, configured to notify the PDCP entity of the packet loss information when there is a lost PDCP data packet in the PDCP data packet received by the device from the PDCP entity;
    所述接收单元,还用于在丢包后从所述PDCP实体接收第一PDCP数据包,且所述第一PDCP数据包的安全处理是根据调整后的参数COUNT进行的,且所述参数COUNT的调整是根据所述第一序列号和所述丢包信息进行的。The receiving unit is further configured to receive a first PDCP data packet from the PDCP entity after the packet loss, and the security processing of the first PDCP data packet is performed according to the adjusted parameter COUNT, and the parameter COUNT The adjustment is performed according to the first serial number and the packet loss information.
  41. 根据权利要求40所述的装置,其特征在于,所述第一序列号在所述装置从所述PDCP实体接收的PDCP数据包中存在丢失的PDCP数据包,且所述丢失的PDCP数据包达到或超过预设阈值时,用于调整参数COUNT。The apparatus according to claim 40, wherein said first sequence number has a lost PDCP data packet in a PDCP data packet received by said apparatus from said PDCP entity, and said lost PDCP data packet is reached Used to adjust the parameter COUNT when the preset threshold is exceeded.
  42. 根据权利要求40或41所述的装置,其特征在于,所述丢包信息包括以下信息之一或更多:第一个丢失的PDCP数据包的第一SN、期望的下一个PDCP数据包的第一SN、丢包前最后一个PDCP数据包的第一SN、丢包后接收的第一个PDCP数据包的第一SN、丢失的PDCP数据包的数量。 The apparatus according to claim 40 or 41, wherein said packet loss information comprises one or more of the following: a first SN of the first lost PDCP data packet, a desired next PDCP data packet The first SN, the first SN of the last PDCP packet before the packet loss, the first SN of the first PDCP packet received after the packet loss, and the number of lost PDCP packets.
  43. 根据权利要求40至42中任一项所述的装置,其特征在于,所述第一序列号的值在所述PDCP实体每向所述装置发送一个PDCP数据包时加1。The apparatus according to any one of claims 40 to 42, wherein the value of the first sequence number is incremented by one each time the PDCP entity sends a PDCP packet to the apparatus.
  44. 根据权利要求40至43中任一项所述的装置,其特征在于,所述装置为无线链路控制RLC实体。 Apparatus according to any one of claims 40 to 43, wherein the apparatus is a radio link control RLC entity.
PCT/CN2016/108034 2016-11-30 2016-11-30 Method and device for security processing WO2018098687A1 (en)

Priority Applications (2)

Application Number Priority Date Filing Date Title
CN201680090355.1A CN109863769A (en) 2016-11-30 2016-11-30 The method and apparatus of safe handling
PCT/CN2016/108034 WO2018098687A1 (en) 2016-11-30 2016-11-30 Method and device for security processing

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2016/108034 WO2018098687A1 (en) 2016-11-30 2016-11-30 Method and device for security processing

Publications (1)

Publication Number Publication Date
WO2018098687A1 true WO2018098687A1 (en) 2018-06-07

Family

ID=62240974

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2016/108034 WO2018098687A1 (en) 2016-11-30 2016-11-30 Method and device for security processing

Country Status (2)

Country Link
CN (1) CN109863769A (en)
WO (1) WO2018098687A1 (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2023050185A1 (en) * 2021-09-29 2023-04-06 Oppo广东移动通信有限公司 Variable maintenance method and apparatus, and terminal device

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112399478B (en) * 2020-10-28 2023-03-24 展讯半导体(成都)有限公司 Method for preventing uplink desynchronization, communication device and readable storage medium
CN113872752B (en) * 2021-09-07 2023-10-13 哲库科技(北京)有限公司 Security engine module, security engine device, and communication apparatus

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101686494A (en) * 2008-09-22 2010-03-31 大唐移动通信设备有限公司 Method and device for processing packets by packet data convergence protocol (PDCP) layer
US20120308009A1 (en) * 2011-06-01 2012-12-06 Qualcomm Incorporated Mechanisms for detection of and recovery from ciphering parameter mismatch on communication networks
CN103533586A (en) * 2012-07-03 2014-01-22 电信科学技术研究院 Method and apparatus for signaling interaction and layer reconstruction in switching process
CN103686616A (en) * 2012-09-24 2014-03-26 普天信息技术研究院有限公司 Cluster group call security encryption synchronization method
CN105307159A (en) * 2014-06-25 2016-02-03 普天信息技术有限公司 Air interface encryption method for cluster communication group calling service

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2262303B1 (en) * 2008-03-31 2018-06-13 NEC Corporation Concealment processing device, concealment processing method, and concealment processing program
CN102769907A (en) * 2012-07-03 2012-11-07 中兴通讯股份有限公司 Method, device and system for hyper frame number synchronization
US9313756B2 (en) * 2012-10-10 2016-04-12 Qualcomm Incorporated Apparatus and methods for managing hyper frame number (HFN) de-synchronization in radio link control (RLC) unacknowledged mode (UM)

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101686494A (en) * 2008-09-22 2010-03-31 大唐移动通信设备有限公司 Method and device for processing packets by packet data convergence protocol (PDCP) layer
US20120308009A1 (en) * 2011-06-01 2012-12-06 Qualcomm Incorporated Mechanisms for detection of and recovery from ciphering parameter mismatch on communication networks
CN103533586A (en) * 2012-07-03 2014-01-22 电信科学技术研究院 Method and apparatus for signaling interaction and layer reconstruction in switching process
CN103686616A (en) * 2012-09-24 2014-03-26 普天信息技术研究院有限公司 Cluster group call security encryption synchronization method
CN105307159A (en) * 2014-06-25 2016-02-03 普天信息技术有限公司 Air interface encryption method for cluster communication group calling service

Non-Patent Citations (3)

* Cited by examiner, † Cited by third party
Title
"Evolved Universal Terrestrial Radio Access (E-UTRA); Packet Data Convergence Protocol (PDCP) Specification (Release 14", 3GPPTS 36.323 V14.0. 1, 7 October 2016 (2016-10-07), XP051173041 *
ARNAUD MEYLAN: "LTE Radio Layer 2, RRC and Radio Access Network Architecture", 3GPP TSG-RAN WG2, 30 June 2011 (2011-06-30) *
BENOIST SEBIRE: "Radio Access Network Architecture and Protocols", 3GPP TSG-RAN WG2, 30 June 2011 (2011-06-30), XP055145165 *

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2023050185A1 (en) * 2021-09-29 2023-04-06 Oppo广东移动通信有限公司 Variable maintenance method and apparatus, and terminal device

Also Published As

Publication number Publication date
CN109863769A (en) 2019-06-07

Similar Documents

Publication Publication Date Title
CN110915249B (en) System and method for dynamic activation and deactivation of user plane integrity in a wireless network
JP7123201B2 (en) FAILURE HANDLING METHOD, HANDOVER METHOD, TERMINAL DEVICE, AND NETWORK DEVICE
EP2449748B1 (en) Systems, methods, and apparatuses for ciphering error detection and recovery
EP3499954B1 (en) Method and apparatus for reporting user equipment capability information
US20080010677A1 (en) Apparatus, method and computer program product providing improved sequence number handling in networks
US20190253895A1 (en) Control signaling processing method, device, and system
US11523280B2 (en) Radio link recovery for user equipment
TWI670954B (en) Device for handling a bearer type change
EP4271123A2 (en) Rrc connection method and terminal
TW201914339A (en) Apparatus and method for processing bearer type change for radio bearer
WO2018098687A1 (en) Method and device for security processing
WO2009056015A1 (en) Parameter synchronization method and equipment
RU2748314C1 (en) Radio resource configuration
CN111556506B (en) Abnormal link processing method and equipment
CN104168640A (en) Reception end PDCP layer HFN out-off-step recovering method and device
JP5856022B2 (en) Mobile communication method and mobile station
CN115175239A (en) Business processing method, device, equipment, storage medium and program product
WO2020164510A1 (en) Communication method, communication apparatus, and computer-readable storage medium
US20140024344A1 (en) Mobile communication method, radio base station, mobile management node, and mobile station
WO2016054911A1 (en) Detection method, sending end, receiving end and detection system
CN107113606B (en) Method, apparatus and storage medium for communicating with a GPRS network
JP6174365B2 (en) Base station and method
JP2016054552A (en) Mobile communication method and mobile station

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16922744

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 16922744

Country of ref document: EP

Kind code of ref document: A1