WO2026007686A1 - 一种数据传输的方法和装置 - Google Patents

一种数据传输的方法和装置

Info

Publication number
WO2026007686A1
WO2026007686A1 PCT/CN2025/101525 CN2025101525W WO2026007686A1 WO 2026007686 A1 WO2026007686 A1 WO 2026007686A1 CN 2025101525 W CN2025101525 W CN 2025101525W WO 2026007686 A1 WO2026007686 A1 WO 2026007686A1
Authority
WO
WIPO (PCT)
Prior art keywords
multicast
node
bit sequence
group
message
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
PCT/CN2025/101525
Other languages
English (en)
French (fr)
Inventor
王勇
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Huawei Technologies Co Ltd
Original Assignee
Huawei Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Technologies Co Ltd filed Critical Huawei Technologies Co Ltd
Publication of WO2026007686A1 publication Critical patent/WO2026007686A1/zh
Pending legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/03Protecting confidentiality, e.g. by encryption
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/10Integrity
    • H04W12/106Packet or message integrity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/06Selective distribution of broadcast services, e.g. multimedia broadcast multicast service [MBMS]; Services to user groups; One-way selective calling services
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/80Services using short range communication, e.g. near-field communication [NFC], radio-frequency identification [RFID] or low energy communication

Definitions

  • This application relates to the field of communications, and more particularly to a method and apparatus for data transmission.
  • the sending and receiving ends can be mutually interested devices or apparatuses, engaging in unicast communication to achieve data transmission; or, the sending end can send information to all receiving ends within its subnet, i.e., data transmission via broadcast; or, data transmission can be achieved through multicast, a method somewhere in between, where the sending end sends information to a group of receiving ends, and devices or apparatuses within that group can receive the information.
  • Multicast transmission can solve both the problems of duplicate data copying and bandwidth duplication in unicast transmission, and the bandwidth resource waste problem in broadcast transmission, thus attracting widespread attention. Therefore, it can be seen that multicast transmission has certain transmission advantages.
  • This application provides a data transmission method and apparatus that can expand the scenarios in which multicast transmission can be applied, making the application scenarios of encrypted multicast transmission more extensive.
  • This application enables first nodes that do not maintain a first bit sequence to obtain the first bit sequence used for encrypted transmission, integrity protection, or both for multicast, by sending first multicast security parameters to the first node in the first multicast group.
  • This allows context-encrypted transmission and/or integrity protection processes to be implemented in the data transmission of the first multicast group.
  • This data transmission method effectively solves the limitation that only nodes that locally maintain the first bit sequence can perform context-encrypted transmission and/or integrity protection operations. It supports new group members (such as members joining the first multicast group after its creation) and nodes that do not maintain a first bit sequence to configure multicast security parameters, increasing the applicable scenarios for multicast transmission and making its application more widespread.
  • one first multicast security parameter corresponds to one logical channel of the first multicast group; or, one first multicast security parameter corresponds to multiple logical channels of the first multicast group. That is, the first multicast group corresponds to at least one logical channel for transmitting multicast data, and one logical channel can correspond to one first multicast security parameter.
  • the first multicast security parameters of each logical channel can be different, or, among multiple logical channels, several logical channels may have the same first multicast security parameter, or the first multicast parameters of all logical channels may be the same, such as all being set to zero.
  • the second communication device and the first node can use the logical channel corresponding to the first multicast security parameter to perform context-encrypted transmission and/or integrity protection processes. Using the corresponding first multicast security parameter for data transmission through different logical channels can improve the reliability of transmission.
  • the first bit sequence includes the high frame number.
  • the high frame number of a GGFN can be maintained by nodes in the first multicast group. However, for newly joined nodes and nodes that have lost their high frame number, the absence of the high frame number will result in a lack of necessary security parameters during context-encrypted transmission and/or integrity protection processes, leading to errors. Therefore, including the high frame number in the first bit sequence helps nodes without a high frame number to obtain it, ensuring that context-encrypted transmission and other processes can be implemented during their data transmission.
  • the first multicast security parameter also includes a second bit sequence of the GGFN, which includes one or more of the following: a link control layer sequence number (SN); or, a physical layer superframe number and a radio frame number.
  • the first multicast parameter may also carry the second bit sequence, which can indicate other parameters required in various stages of data transmission, such as the SN, making the indicated security parameters more complete and comprehensive, thereby ensuring a higher accuracy in various stages of transmission, such as encryption, decryption, and integrity protection.
  • the method further includes: receiving a first message, the first message including the identity (ID) of the first node; generating the first multicast security parameter includes: generating the first multicast security parameter based on the first message.
  • the second device can determine which first node sent the first message based on the ID of the first node carried in the first message. For example, if the first message originates from first node 1, the second device can first determine whether first node 1 is a node in the first multicast group using its ID. If so, it determines and generates the corresponding first multicast security parameter based on the first multicast group. By determining whether a first node is a node in the first multicast group, sending the first multicast security parameter to nodes outside the first multicast group can be effectively avoided, increasing transmission security.
  • the first multicast security parameter is obtained; this first set of keys is the group key of the first multicast group. If the first set of keys is generated, the first multicast security parameter is set to zero.
  • sending the first multicast security parameter to the first node includes: sending the first multicast security parameter to the first node via an association establishment message; or, sending the first multicast security parameter to the first node via a configuration message.
  • the transmission method provided in this application can be applied in different scenarios, using different messages to send the first multicast security parameter to the first node, thus having a wider range of applicable scenarios.
  • this application provides a data transmission method, which can be executed by a first communication device.
  • the "first communication device” in this application can refer to the first node itself (e.g., a terminal node (also called a T-node or terminal device), etc.), a component within the first node (e.g., a processor, chip, or chip system), or a logic module or software capable of implementing all or part of the functions of the first communication device.
  • the method includes: receiving a first multicast security parameter, which includes a first bit sequence of GGFN, the first bit sequence being maintained locally by the nodes of the first multicast group, and the first multicast security parameter being used for encrypted transmission and/or integrity protection of the multicast.
  • one of the first multicast security parameters corresponds to one logical channel of the first multicast group; or, one of the first multicast security parameters corresponds to multiple logical channels of the first multicast group.
  • the first bit sequence includes the high frame number.
  • the first multicast security parameter also includes a second bit sequence of the GGFN, which includes one or more of the following: a link control layer SN; or, a physical layer superframe number and a radio frame number.
  • One possible implementation also includes sending a first message, which includes the ID of the first node.
  • receiving the first multicast security parameter includes: receiving the first multicast security parameter via an association establishment message; or receiving the first multicast security parameter via a configuration message.
  • this application provides a second communication device, which can refer to the second node itself (e.g., a network device, or a management device, etc.), or a component within the second node (e.g., a management node (also referred to as a management device or G node), a network device, etc.), or a component within the second node (e.g., a processor, a chip, or a chip system, etc.), or a logic module or software capable of implementing all or part of the functions of the second communication device.
  • the second node e.g., a network device, or a management device, etc.
  • a management node also referred to as a management device or G node
  • a network device e.g., a network device, etc.
  • a component within the second node e.g., a processor, a chip, or a chip system, etc.
  • a logic module or software capable of implementing all or part of the functions of the second communication
  • the second communication device includes: a processing module for generating first multicast security parameters, the first multicast security parameters including a first bit sequence of GGFN, the first bit sequence being maintained locally by the nodes of a first multicast group, the first multicast security parameters being used for encrypted transmission and/or integrity protection of multicast; and a sending module for sending the first multicast security parameters to a first node, the nodes of the first multicast group including the first node.
  • one of the first multicast security parameters corresponds to one logical channel of the first multicast group; or, one of the first multicast security parameters corresponds to multiple logical channels of the first multicast group.
  • the first bit sequence includes the high frame number.
  • the first multicast security parameter also includes a second bit sequence of the GGFN, which includes one or more of the following: a link control layer SN; or, a physical layer superframe number and a radio frame number.
  • the second communication device further includes: a receiving module for receiving a first message, the first message including the ID of the first node; and a processing module specifically for generating the first multicast security parameters based on the first message.
  • the processing module is further configured to, if a first set of keys exists, obtain the first multicast security parameter, wherein the first set of keys is the group key of the first multicast group; and if the first set of keys is generated, set the first multicast security parameter to zero.
  • the sending module is specifically used to send the first multicast security parameter to the first node via an association establishment message; or, via a configuration message, to the first node.
  • this application provides a first communication device, which can refer to the first node itself (e.g., a terminal node (also called a T-node or terminal device)), a component within the first node (e.g., a processor, chip, or chip system), or a logic module or software capable of implementing all or part of the functions of the first communication device.
  • the first communication device includes: a receiving module for receiving first multicast security parameters, the first multicast security parameters including a first bit sequence of GGFN, the first bit sequence being maintained locally by the nodes of the first multicast group, and the first multicast security parameters being used for encrypted transmission and/or integrity protection of multicast.
  • one of the first multicast security parameters corresponds to one logical channel of the first multicast group; or, one of the first multicast security parameters corresponds to multiple logical channels of the first multicast group.
  • the first bit sequence includes the high frame number.
  • the first multicast security parameter also includes a second bit sequence of the GGFN, which includes one or more of the following: a link control layer SN; or, a physical layer superframe number and a radio frame number.
  • a sending module is also included for sending a first message, which includes the ID of the first node.
  • the receiving module is specifically configured to receive the first multicast security parameter via an association establishment message; or, via a configuration message.
  • this application provides a communication device, which may be a node or a device (e.g., a chip) within a node.
  • the communication device includes modules for performing the methods described in any of the foregoing aspects or any possible implementations thereof, such as a processing module and a transceiver module.
  • this application provides a communication device, which may be a node or a device (e.g., a chip) within a node.
  • the communication device includes a transceiver and a processor for performing the methods described in any of the foregoing aspects or any possible implementations thereof.
  • the transceiver may be a radio frequency module, and the processor may or may not include memory.
  • the communication device includes a transceiver, a memory, and a processor for performing the method as described in any of the above aspects or any possible implementations of any of the above aspects.
  • the memory may be disposed in the communication device or may be an external device of the communication device.
  • this application provides a communication device, comprising: an input/output interface and a logic circuit, wherein the input/output interface is used to acquire input information and/or output information; and the logic circuit is used to perform the method described in any of the above aspects or any possible implementation thereof, processing the input information and/or generating output information.
  • this application provides a communication device including at least one processor and a storage medium.
  • the at least one processor is coupled to the storage medium, which stores instructions that, when executed by the processor, enable the processor to perform the method described in any of the foregoing aspects or any possible implementation thereof.
  • the storage medium may be included in the communication device or disposed outside the communication device.
  • this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the method as described in any of the foregoing aspects or any possible implementations of any of the foregoing aspects.
  • this application provides a computer program product comprising instructions that, when executed on a processor, implement the method as described in any of the foregoing aspects or any possible implementation thereof.
  • this application provides a chip comprising: an interface circuit and a processor.
  • the interface circuit is connected to the processor, and the processor is configured to cause the chip to perform some or all of the operations included in any of the methods described in any of the preceding aspects and any possible implementations of any of the preceding aspects.
  • embodiments of this application also provide a chip, comprising: at least one processor, the at least one processor being configured to execute code in the memory, wherein when the at least one processor executes the code, the chip implements some or all of the operations included in the method of any of the foregoing aspects and any possible implementation of any of the foregoing aspects.
  • the chip also includes a memory.
  • the memory can be integrated with the processor or disposed separately from the processor; the memory can be integrated on the same chip as the processor or disposed on different chips.
  • the chip described above can also be an integrated circuit.
  • this application provides a system comprising a second communication device as described in the third aspect and a first communication device as described in the fourth aspect.
  • this application provides a system that includes the means provided in any of the third to twelfth aspects.
  • Figure 1 is a schematic diagram of the structure of a communication system 100 provided in an embodiment of this application;
  • FIG. 2 is a schematic diagram of an exemplary Starlight Alliance protocol framework provided in an embodiment of this application;
  • FIG. 3 is a flowchart illustrating one of the data transmission methods provided in an embodiment of this application.
  • Figure 4 is a second schematic flowchart of a data transmission method provided in an embodiment of this application.
  • Figure 5a is a third schematic flowchart of a data transmission method provided in an embodiment of this application.
  • Figure 5b is a fourth schematic flowchart of a data transmission method provided in an embodiment of this application.
  • Figure 6 is a fifth flowchart illustrating a data transmission method provided in an embodiment of this application.
  • Figure 7 is a schematic flowchart of a data transmission method provided in an embodiment of this application.
  • Figure 8 is a flowchart of a data transmission method provided in an embodiment of this application (the seventh one).
  • FIG 9 is a flowchart of a data transmission method provided in an embodiment of this application (the eighth one).
  • Figure 10 is a schematic diagram of a confidentiality protection process provided in an embodiment of this application.
  • FIG 11 is a schematic diagram of an integrity protection process provided in an embodiment of this application.
  • Figure 12 is a schematic diagram of an authentication and encryption process provided in an embodiment of this application.
  • Figure 13 is a schematic diagram of one of the structures of a second communication device provided in an embodiment of this application.
  • Figure 14 is a second schematic diagram of the structure of a second communication device provided in an embodiment of this application.
  • Figure 15 is a schematic diagram of the structure of a first communication device provided in an embodiment of this application.
  • Figure 16 is a schematic diagram of the structure of device 50 according to an embodiment of this application.
  • Figure 17 is a schematic diagram of the structure of a device 60 provided in an embodiment of this application.
  • a and/or B can represent: A existing alone, A and B existing simultaneously, and B existing alone.
  • a and B can be single or multiple.
  • At least one of the following" or similar expressions are used to represent any combination of the listed items.
  • at least one of A, B, and/or C can represent: A existing alone, B existing alone, C existing alone, A and B existing simultaneously, B and C existing simultaneously, A and C existing simultaneously, and A, B, and C existing simultaneously.
  • A, B, and C can be single or multiple.
  • first and second used in the specification and claims of this application are used to distinguish different objects, not to describe a specific order of objects.
  • first target object and second target object are used to distinguish different target objects, not to describe a specific order of target objects.
  • the terms "exemplary” or “for example” are used to indicate that something is an example, illustration, or description. Any embodiment or design that is described as “exemplary” or “for example” in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design. Specifically, the use of the terms “exemplary” or “for example” is intended to present the relevant concepts in a specific manner.
  • multiple means two or more.
  • multiple processing units means two or more processing units; multiple systems means two or more systems.
  • the SparkLink Alliance was established and is dedicated to promoting innovation in next-generation short-range wireless communication technologies. SparkLink technology is applicable to scenarios such as smart cars, smart homes, smart terminals, and smart manufacturing, and meets extreme performance requirements.
  • the nodes involved in this application embodiment can communicate based on the next-generation short-range wireless communication technology designed by the SparkLink Alliance.
  • the next-generation short-range wireless communication system designed by the SparkLink Alliance will be referred to as the SparkLink wireless communication system.
  • G-nodes refer to management nodes, which can be used in the StarSpark wireless communication system as nodes that send data scheduling information.
  • T-nodes refer to terminal nodes, which can be used in the StarSpark wireless communication system as nodes that receive data scheduling information and send data according to the data scheduling information.
  • This application embodiment illustrates the use of G-nodes and T-nodes in the StarSpark wireless communication system, but it is not limiting. G-nodes and T-nodes can also be used in other systems with reference to the data transmission method of this application embodiment for multicast transmission.
  • a frame number refers to a unique identifier or sequence number of a network frame.
  • Each transmitted data frame is assigned a frame number, which is used at the receiving end for unique identification and reordering of frames.
  • GGFN is the frame number for multicast data.
  • the communication system 100 to which this application embodiment applies may include multiple nodes, each node comprising an electronic device capable of transmitting and receiving data.
  • a node may be a cockpit domain device, or one or more modules within a cockpit domain device (such as a cockpit domain controller (CDC), camera, screen, microphone, audio system, electronic key, keyless entry or start system controller, etc.).
  • CDC cockpit domain controller
  • this node may also include data relay equipment, such as routers, repeaters, bridges, or switches; it may also include terminal equipment, such as various types of user equipment (UE), mobile phones, tablets, desktop computers, headphones, speakers, etc.; it may also include machine intelligence devices, such as self-driving devices, transportation safety devices, virtual reality (VR) terminal devices, augmented reality (AR) terminal devices, machine type communication (MTC) devices, industrial control devices, remote medical devices, smart grid devices, and smart city devices; it may also include wearable devices (such as smartwatches, smart bracelets, pedometers, etc.), and so on.
  • devices with similar data transmission and reception capabilities may not be called nodes.
  • electronic devices with data transmission and reception capabilities are collectively referred to as nodes in this application embodiment.
  • This node can be applied to various types of communication systems.
  • this node can be applied to communication system 100.
  • the node includes at least one first node 10 and at least one second node 20.
  • the first node can be a T node and the second node can be a G node. Both the G node and the T node support the StarSpark Alliance protocol.
  • the first and second nodes can also be nodes serving as transmitters or receivers in wireless local area network (WLAN), narrowband internet of things (NB-IoT), global system for mobile communications (GSM), enhanced data rate for GSM evolution (EDGE), wideband code division multiple access (WCDMA), code division multiple access 2000 (CDMA2000), time division-synchronization code division multiple access (TD-SCDMA), LTE systems, satellite communications, 5G, 6th-generation (6G) communications, or new communications systems that will emerge in the future.
  • WLAN wireless local area network
  • NB-IoT narrowband internet of things
  • GSM global system for mobile communications
  • EDGE enhanced data rate for GSM evolution
  • WCDMA wideband code division multiple access
  • CDMA2000 code division multiple access 2000
  • TD-SCDMA time division-synchronization code division multiple access
  • LTE long term evolution
  • both the first node 10 and the second node 20 can act as either a sender or a receiver.
  • the initiator of communication is defined as the sending device
  • the receiver of communication is defined as the receiving device.
  • node G sends information to node T
  • node G is the sending device and node T is the receiving device
  • node T sends information to node G
  • node T is both the sending device and the receiving device.
  • the transmitting and receiving devices provided in this application embodiment can be any type of device with transceiver capabilities, including but not limited to: evolved base stations (NodeB, eNB, or e-NodeB) in Long Term Evolution (LTE) systems, base stations (gNodeB or gNB) or transmission receiving points/transmission reception points (TRPs) in New Radio (NR) systems, base stations in subsequent evolutions of the 3rd Generation Partnership Project (3GPP), access nodes in wireless communication systems (e.g., WiFi, Bluetooth), wireless relay nodes, wireless backhaul nodes, and data relay devices (such as routers, repeaters, bridges, or switches).
  • Base stations can be: macro base stations, micro base stations, pico base stations, small cells, relay stations, or balloon stations, etc.
  • the transmitting or receiving device can also be a wireless controller, centralized unit (CU), and/or distributed unit (DU) in a cloud radio access network (CRAN) scenario.
  • CU centralized unit
  • DU distributed unit
  • the sending or receiving device can also be a server, wearable device (such as a smartwatch, smart bracelet, pedometer, etc.), machine communication device, or vehicle-mounted device, etc.
  • wearable device such as a smartwatch, smart bracelet, pedometer, etc.
  • machine communication device or vehicle-mounted device, etc.
  • the transmitting or receiving device can also be a mobile phone, tablet, computer with wireless transceiver capabilities, headphones, speakers, virtual reality (VR) terminal devices, augmented reality (AR) terminal devices, machine-type communication (MTC) terminals, industrial control terminals, vehicle-mounted terminal devices, self-driving terminals, driver assistance terminal devices, remote medical terminals, smart grid terminals, transportation safety terminals, smart city terminals, smart home terminals, as well as robots and intelligent robots, etc.
  • VR virtual reality
  • AR augmented reality
  • MTC machine-type communication
  • a terminal may also be referred to as a terminal device, user equipment (UE), access terminal device, vehicle-mounted terminal, industrial control terminal, UE unit, UE station, mobile station, mobile station, remote station, remote terminal device, mobile device, UE terminal device, wireless communication device, machine terminal, UE agent, or UE device, etc.
  • a terminal can be fixed or mobile.
  • the transmitting or receiving device can also be a cockpit domain device, or a module within a cockpit domain device (such as a cockpit domain controller (CDC), camera, screen, microphone, audio system, electronic key, keyless entry and start system controller, etc.).
  • a cockpit domain controller CDC
  • camera screen
  • microphone
  • audio system
  • the embodiments of this application do not limit the application scenarios.
  • the embodiments of this application take multicast transmission applied in the StarSpark system as an example, but it is not limited thereto.
  • FIG. 2 is a schematic diagram of an exemplary SparkLink Alliance protocol framework provided in this application embodiment.
  • This protocol framework can be applied to any node that can realize short-range communication, such as any node in the communication system 100 shown in Figure 1.
  • the protocol framework 200 includes an access layer 201, a network and transport layer 202, and an application layer 203 from bottom to top.
  • the access layer 201 can be used to process the underlying logical links, such as establishing, reconfiguring, and deleting logical links, to meet the service requirements of the network and transport layer 202.
  • the access layer 201 includes various access technologies, such as the access technology of the SparkLink Basic (SLB) short-range wireless communication system, the access technology of the SparkLink Low Energy (SLE) short-range wireless communication system, and other access technologies.
  • the network and transport layer 202 can be used to create, add, delete, and release transport channels, and can also be used for logical link control, such as selecting a certain access technology, to meet the traffic, rate, and other service requirements of the application layer 203.
  • the application layer 203 can be divided into control plane transport and service plane transport.
  • the path for transmission between the network and the transport layer 202 can be defined as a transmission channel (TC). Multiple transmission channels can be mapped to the same logical channel, or a single transmission channel can be mapped to logical channels of different access standards.
  • a logical channel (LC) is the path for data transmission in the access layer 201 and can accommodate multiple transmission channel mappings.
  • a logical channel can also be called a logical link, logical channel, etc.
  • This application uses a logical channel as an example for illustration, but it is not limited thereto.
  • this application defines a logical channel identification (LCID) to uniquely identify each logical channel; that is, each logical channel corresponds to a unique LCID.
  • LCID logical channel identification
  • Multicast transmission can solve the problems of duplicate data copying and bandwidth duplication in unicast mode, and it can also solve the waste of bandwidth resources in broadcast mode, so it is applicable to more scenarios.
  • Node G can first broadcast the key negotiation algorithm capability;
  • Node T in the multicast group sends an association request message to Node G;
  • Node G sends a security context request message, and then
  • Node T sends back a security context response message.
  • Node G After receiving the response message, Node G can send an association establishment message, and in the association establishment message, it sends the multicast security parameters such as the group key, group ID, group algorithm, and group key validity period of the multicast group to which Node T belongs; Node T receives the association establishment message, sends back an association completion message, and conducts encrypted communication with Node G according to the multicast security parameters.
  • this encryption process Once this encryption process is established, data transmission is suitable for encrypted communication between T nodes and G nodes already in the multicast group during group creation (multicast group establishment). However, it does not consider new members joining the group after group creation (hereinafter referred to as new members).
  • New members cannot obtain some security parameters (or the first bit sequence) maintained (or stored locally) by the T node that joined the multicast group at the time of group creation, which are used for encrypted transmission and/or integrity protection.
  • the multicast security parameters that new members can obtain are insufficient to support subsequent encrypted transmission, integrity protection, or encrypted transmission and integrity protection operations, thus limiting the applicability of multicast transmission.
  • embodiments of this application provide a data transmission method that enables new members to obtain the first bit sequence, increasing the applicable scenarios for multicast transmission and making its application scenarios more extensive.
  • the data transmission method provided in this application embodiment can be applied to short-range wireless communication to achieve information sharing and wireless service transmission.
  • this method can be applied to a Starflash wireless communication system.
  • Figure 3 is a flowchart illustrating one of the data transmission methods provided in this application embodiment. The method is illustrated by example, with the second device being executed by a second device. This second device can be a device in a G node or a G node itself; this application embodiment does not limit this. In the flowchart shown in Figure 3, the second device can be considered as a transmitting device, and the T node (including the first node) can be considered as a receiving device. As shown in Figure 3, the method includes steps S101 to S102.
  • the second device generates a first multicast security parameter, which includes a first bit sequence of GGFN.
  • the first bit sequence is maintained locally by the nodes of the first multicast group.
  • the first multicast security parameter is used for encrypted transmission and/or integrity protection of multicast.
  • the second device is a G node, which establishes a multicast group with at least one T node.
  • This multicast group can be defined as a first multicast group.
  • the first multicast group may include at least one T node that joined when the group was created, or it may include new members (such as T nodes, which can be defined as first nodes) that joined after the group was created.
  • Each T node that joined when the group was created locally maintains (or stores) a first bit sequence.
  • This first bit sequence can be used for encrypted transmission, integrity protection, or both encrypted transmission and integrity protection in the first multicast group.
  • the first node also needs to obtain this first bit sequence for encrypted transmission, integrity protection, or both encrypted transmission and integrity protection, i.e., it needs to execute step S102.
  • the first multicast group includes multiple T nodes, among which at least one T node joined after the group was created, i.e., a new member, defined as a first node.
  • Each first node needs to execute step S102 to achieve encrypted transmission and/or integrity protection of the multicast in subsequent transmissions.
  • the second device sends the first multicast security parameters to the first node, and the nodes of the first multicast group include the first node.
  • the first multicast security parameters sent by the second device to the first node include a first bit sequence, which enables the first node to receive and maintain the first bit sequence locally, so as to realize encrypted transmission, integrity protection, or encrypted transmission and integrity protection in the transmission of the first multicast group.
  • the first multicast security parameter may be a GGFN
  • the first bit sequence may be the high-order bit sequence of the GGFN, such as the bit sequence corresponding to the high frame number.
  • the high frame number includes at least one of HFN or HSFN.
  • the second device can send the first multicast security parameter to any T node in the first multicast group.
  • This application embodiment uses the second device sending to the first node as an example for illustration, but it is not limited.
  • This application embodiment sends a first multicast security parameter to a first node in a first multicast group, enabling the first node to obtain a first bit sequence for encrypted transmission, integrity protection, or both for multicast.
  • This allows for context-encrypted transmission and/or integrity protection during data transmission within the first multicast group. This effectively solves the problem that only nodes T that joined the first multicast group at the time of group creation locally maintain the first bit sequence, while newly joined nodes T cannot obtain it. It supports multicast security parameter configuration for new members, increasing the applicable scenarios for multicast transmission and making its application more widespread.
  • the first multicast security parameter may include a first bit sequence, or the first multicast security parameter may include a first bit sequence and a second bit sequence.
  • the first bit sequence may include at least one of a high frame number (HFN) or a high super frame number (HSFN), and the second bit sequence may include one or more of the following: a link control layer sequence number (SN); or, a physical layer super frame number and a radio frame number.
  • the first multicast security parameter can be a GGFN, including an HFN and a link control layer SN, wherein the first bit sequence is an HFN and the second bit sequence is a link control layer SN; or, the first multicast security parameter can be a GGFN, including an HSFN, a physical layer superframe number, and a radio frame number, wherein the first bit sequence is an HSFN and the second bit sequence is a physical layer superframe number and a radio frame number; or, the first multicast security parameter can be a first bit sequence, such as a high frame number, where the high frame number includes at least one of an HFN or an HSFN.
  • the data transmission method may also include other steps.
  • Figure 4 is a second schematic diagram of a data transmission method provided by an embodiment of this application. The method is illustrated by example of execution by a second device.
  • the second device may be a device in a G node or a G node itself. This embodiment of the application does not limit the method.
  • the second device may be regarded as a sending device and the T node (including the first node) may be regarded as a receiving device.
  • the method includes steps S201 to S203.
  • the second device receives a first message, which includes the ID of the first node.
  • a second device may receive first messages from multiple first nodes (in this embodiment, the first node may refer to a T node).
  • the first node may refer to a T node.
  • some are newly joined multicast groups, and some are nodes that were already in the multicast group when the group was created. Since the nodes that were already in the multicast group when the group was created have already maintained the required multicast security parameters locally (defined as the first multicast security parameters in this embodiment), this embodiment can take a newly joined T node or a T node that has lost the maintained first multicast security parameters as an example to illustrate the data transmission as a first node.
  • the first message can be an association request message, which includes the ID of the first node.
  • the first message can be different in different application scenarios and is not limited to the examples in this application.
  • the second device generates the first multicast security parameters based on the first message.
  • a first multicast group has been established.
  • the G node can determine whether the first node from which the first message originated is a node in the first multicast group, and the method of determination is not limited.
  • This application embodiment uses the example of a second device obtaining the ID (or fixed ID) of a first node based on the first message.
  • the second device can determine whether the first node belongs to the first multicast group based on the ID of the first node. If it belongs to the first multicast group, it generates first multicast security parameters based on the relevant parameters of the first multicast group.
  • the G node obtains the fixed ID of the first node (such as a T node 1) from the first message, and determines whether the G node has a pre-configured group ID corresponding to the fixed ID of the T node 1. If there is a pre-configured group ID corresponding to the fixed ID of the T node 1, then the first multicast security parameters are generated based on the multicast group corresponding to that group ID, such as the first multicast group.
  • the first node obtains the fixed ID of the first node (such as a T node 1) from the first message, and determines whether the G node has a pre-configured group ID corresponding to the fixed ID of the T node 1. If there is a pre-configured group ID corresponding to the fixed ID of the T node 1, then the first multicast security parameters are generated based on the multicast group corresponding to that group ID, such as the first multicast group.
  • the first multicast group corresponds to at least one logical channel for transmitting multicast data.
  • a first multicast security parameter generated by the G node corresponds to one logical channel of the first multicast group; or, a first multicast security parameter generated by the G node corresponds to multiple logical channels of the first multicast group.
  • node G determines that the first multicast group has a group key (which can be defined as the first group key), it obtains the first multicast security parameters of the first multicast group. If node G determines that the first multicast group does not currently have a group key, it generates the first group key and sets all the first multicast security parameters of the first multicast group to zero.
  • group key which can be defined as the first group key
  • node G can obtain M first multicast security parameters, which is equivalent to each logical channel corresponding to one first multicast security parameter.
  • node G can obtain N first multicast security parameters, where M is a positive integer and N is a positive integer less than M, which is equivalent to multiple logical channels corresponding to one first multicast security parameter.
  • the second device sends the first multicast security parameters to the first node.
  • the second device upon receiving the first message, determines that the first node from which the first message originates is a node in the first multicast group. Based on relevant parameters of the first multicast group, such as the presence of a group key, it generates first multicast security parameters for encrypted transmission and/or integrity protection during multicast data transmission and sends these parameters to the first node. This allows the first node, upon receiving the first multicast security parameters, to perform one or more operations, such as encrypted transmission and integrity protection, in subsequent data transmission with the G node.
  • FIG 5a is a schematic flowchart of a data transmission method provided in an embodiment of this application.
  • the method is illustrated by taking the execution of a first device as an example.
  • the first device can be a device in a T node (such as a first node) or a T node (such as a first node).
  • This embodiment of the application does not limit the method.
  • the G node can be regarded as a sending device and the first device can be regarded as a receiving device.
  • the method includes S301.
  • the first device receives a first multicast security parameter, which includes a first bit sequence of GGFN.
  • the first bit sequence is maintained locally by the nodes of the first multicast group.
  • the first multicast security parameter is used for one or more of the encrypted transmission or integrity protection of multicast.
  • the first multicast security parameter received by the first device can be the same as the example in Figure 3 or Figure 4.
  • the second device generates and sends the first multicast security parameter, which will not be elaborated further.
  • the method shown in Figure 5a can expand the scenarios applicable to multicast transmission, making its application more widespread.
  • the present application embodiment may also provide a data transmission method, as shown in FIG5b, which further includes S302 based on FIG5a.
  • the first device uses the first multicast security parameters to perform multicast transmission.
  • the first device can parse the data on the corresponding logical channel based on the first multicast security parameters to implement one or more operations in encrypted transmission or integrity protection.
  • a G node can send a first multicast security parameter to at least one T node in a first multicast group through an association establishment message; or, a G node can send the first multicast security parameter to at least one T node included in the first multicast group through a configuration message, etc.
  • the following examples illustrate this method, but are not limited to cases where the first multicast security parameter is a different frame number and the first multicast security parameter is sent to node T through an association establishment message or a configuration message.
  • Figure 6 is a fifth flowchart of a data transmission method provided in an embodiment of this application.
  • the method is executed by G node and T node, or by a device in the node. This embodiment of the application does not limit the execution.
  • Figure 6 illustrates the method as being executed by G node and T node. As shown in Figure 6, the method includes S401 to S405.
  • Node T sends an association request message to Node G.
  • the association request message may include the ID of node T, such as a fixed ID of node T, used to identify node T.
  • the association request message may also include other information used to establish the request, such as at least one of the following: key exchange algorithm (KE alg), key exchange algorithm timestamp (KEt), security capabilities set (sec capabilities), or random number (NONCEt), used to ensure the security of the wireless network.
  • KE alg key exchange algorithm
  • KEt key exchange algorithm timestamp
  • sec capabilities security capabilities set
  • NONCEt random number
  • Node G sends a security context request message to Node T.
  • a security context request message may carry at least one of the following: a cryptographic session key (KEg), a random number (NONCEg), a cryptographic context identifier (Kgt ID), or a cryptographic algorithm.
  • the security context request message may also include a message integrity check (MIC) field.
  • Node T sends a security context response message to Node G.
  • a security context response message may carry a message verification code (AUTHt) to verify message integrity.
  • AUTHt message verification code
  • Node G sends an association establishment message to Node T, which includes GGFN.
  • the GGFN includes a first bit sequence and a second bit sequence. That is, the GGFN may include the HFN and the Link Control Layer SN, or the GGFN may include the HSFN, the Physical Layer Superframe Number, and the Radio Frame Number, etc.
  • the first bit sequence of the GGFN can be referred to the example in S102, and the second bit sequence of the GGFN can also be referred to the description in the example above, and will not be repeated here.
  • node G After receiving the association request message and context response message from node T, node G can determine that node T is a member of the first multicast group based on the association request message. It should be understood that when a new member joins the first multicast group, the member list in the first multicast group, also known as the group ID, will be updated.
  • the updated list should include node T's fixed ID (such as the physical layer ID (phy-ID)).
  • node G can determine whether it has a pre-configured group ID corresponding to node T's fixed ID (such as the physical layer ID (phy-ID) in IDforGroupcast).
  • node G has determined that node T1 is a member of the first multicast group.
  • node G determines that node T is a node of the first multicast group, it can first determine whether the group to which node T belongs, i.e. the first multicast group in the example of this application embodiment, has a group key (GK) and a group algorithm (galgorithm).
  • GK group key
  • galgorithm group algorithm
  • node G determines whether there is a group key (GK) for the first multicast group, one possibility is that the first multicast group does not have a group key (GK). Based on this, node G generates a random number, such as a random number (rand), and generates a group key (GK) based on the group ID of the first multicast group and the random number (rand), and also generates a group key identifier (GK ID) for the GK. After generating the group key (GK), the GGFN is initialized to 0, that is, the first bit sequence and the second bit sequence in the GGFN are both set to zero.
  • a group key such as a random number (rand)
  • the GGFNs of all M logical channels can be initialized to 0.
  • the first multicast group has a group key (GK), and node G obtains the GGFNs of different logical channels in the current multicast.
  • GK group key
  • Table 1 is an example of the GGFNs corresponding to the logical channels of the first multicast group provided in the embodiments of this application. As shown in the example in Table 1, each logical channel of the first multicast group corresponds to one GGFN.
  • the first multicast group includes two logical channels, identified as LCID 1 and LCID 2 respectively.
  • Each channel corresponds to a GGFN; for example, the GGFN corresponding to LCID 1 is GGFN 1, and the GGFN corresponding to LCID 2 is GGFN 2.
  • GGFN1 and GGFN 2 can be determined in the actual usage scenario. Here, they are simply used for distinction and are not considered limiting.
  • a G node may choose one option: if the first multicast group has not yet determined a group algorithm, the G node can select one from algorithms supported by all T nodes within the first multicast group, based on a pre-configured algorithm selection strategy. If the first multicast group has not yet determined a group algorithm, the method by which the G node obtains the group algorithm is not limited to the examples in this application. Group algorithms include key derivation functions, encryption algorithms, and integrity protection algorithms or authentication encryption algorithms, with key derivation functions having the highest priority. Alternatively, if the first multicast group has a group algorithm, the G node may use the current group algorithm.
  • the G node Based on the acquired group algorithm (galgorithm), such as the key derivation function, the G node further derives the encryption key and integrity protection key, or authentication encryption key, from the group key (GK). The G node and T node can then use these derived keys to encrypt and transmit the data.
  • group algorithm such as the key derivation function
  • the association establishment message in addition to the GGFN corresponding to each logical channel obtained by the G node through the above method, it may also include at least one of the following: temporary ID, encryption context expiration time (Kgt expiration), group key (GK) (carried when encryption protection of the unicast signaling plane is enabled)/GKc (when encryption protection of the unicast signaling plane is not enabled, the G node encrypts GK to obtain GKc and carries GKc), group key identifier (GK ID), group algorithm (galgorithm), and group key validity period or group key expiration time (GK expiration).
  • Kgt expiration encryption context expiration time
  • GK group key
  • GKc group key identifier
  • galgorithm group algorithm
  • GK expiration group key validity period or group key expiration time
  • GKc/GK means that when encryption protection of the unicast signaling plane (i.e., the transmission between a T node and a G node in the first multicast group can be regarded as unicast) is not enabled, GKc is carried, and when encryption protection of the unicast signaling plane is enabled, GK is carried.
  • the association establishment message may also include a MIC to verify the integrity and authenticity of the association establishment message including the aforementioned content, ensuring that the message is not tampered with or impersonated during transmission.
  • Node T sends an association completion message to Node G.
  • the association completion message may include an MIC to verify integrity and authenticity.
  • the method provided in this application embodiment indicates the GGFN to node T by sending an association establishment message to node T, so that nodes in the first multicast group that do not locally maintain a GGFN can obtain the GGFN and perform at least one of encrypted transmission or integrity protection for multicast.
  • Nodes in the first multicast group that do not locally maintain a GGFN include new members joining the first multicast group or group-creating members who have lost their locally maintained GGFN.
  • the data transmission method provided in this application embodiment embodiment effectively avoids errors in the encrypted transmission and/or integrity protection process due to nodes in the first multicast group not maintaining a GGFN, expanding the application scenarios of multicast and making multicast transmission applications more widespread.
  • Figure 7 is a schematic flowchart of a data transmission method provided in an embodiment of this application. The method is executed by the G node and the T node, or by the device in the node. This embodiment of the application does not limit the execution. As shown in Figure 7, compared with the method shown in Figure 6, S404 is replaced by S406. That is, the method includes S401 to S403, S406 and S405.
  • Node T sends an association request message to Node G.
  • Node G sends a security context request message to Node T.
  • Node T sends a security context response message to Node G.
  • Node G sends an association establishment message to Node T, which includes at least one of HFN or HSFN.
  • the G node determines that the first multicast security parameters, including the high frame number of GGFN, are to be sent to the T node, it can first determine whether the first multicast group has a group key (GK) and a group algorithm (galgorithm). The method for determining this is the same as the example in S404. The method for obtaining the group key (GK) and group algorithm (galgorithm) can also be found in the example in S404, and will not be elaborated here.
  • GK group key
  • galgorithm group algorithm
  • the G node obtains at least one of the HFN or HSFN of the different logical channels of the current multicast. In other words, the G node can obtain the high frame number of the GGFN to get the first bit sequence.
  • GK group key
  • Table 2 provides an example of the HFN and HSFN corresponding to the logical channels of a first multicast group according to an embodiment of this application.
  • each logical channel of the first multicast group corresponds to one HFN or HSFN.
  • the M logical channels of the first multicast group obtained by node G may all correspond to HFNs, or the M logical channels of the first multicast group obtained by node G may all correspond to HSFNs, or, of the M channels of the first multicast group obtained by node G, Q correspond to HFNs and M-Q correspond to HSFNs, etc., where Q is a positive integer less than or equal to M.
  • Table 2 of this application embodiment illustrates that some logical channels of the first multicast group correspond to HFNs and some logical channels correspond to HSFNs, but this is not a limitation.
  • the first multicast group includes two logical channels, identified as LCID 1 and LCID 2 respectively.
  • the first channel corresponds to an HFN
  • the second channel corresponds to an HSFN.
  • the HFN corresponding to LCID 1 is HFN1
  • the HSFN corresponding to LCID 2 is HSFN1.
  • the bytes and bits occupied by each LCID, HFN, and HSFN in Table 2 are for illustrative purposes only and are not limited.
  • the frame numbers of HFN1 and HSFN1 can also be determined in actual use scenarios. Table 2 is just an example and is not limited.
  • association establishment message in addition to at least one of the HFN or HSFN corresponding to each logical channel obtained by the G node through the above method, it may also include at least one of the following: temporary ID, encryption context expiration time (Kgt expiration), GK/GKc, GK ID, group algorithm (galgorithm), and group key validity period or group key expiration time (GK expiration).
  • GKc/GK means that GKc is carried when the encryption protection of the unicast signaling plane is not enabled, and GK is carried when the encryption protection of the unicast signaling plane is enabled.
  • Node T sends an association completion message to Node G.
  • Figure 8 is a flowchart of a data transmission method provided in an embodiment of this application. The method is executed by G node and T node, or by a device in the node. This embodiment of the application does not limit the execution.
  • Figure 8 illustrates the method as being executed by G node and T node. As shown in Figure 8, the method includes steps S501 to S502.
  • control messages will be exchanged, such as common control messages and private control messages.
  • This embodiment uses the sending of the first multicast security parameters via a private control message as an example for illustration, but it is not intended to be limiting.
  • Node T sends a dedicated control message to Node G, which includes GGFN.
  • the first multicast group includes two logical channels, identified as LCID 1 and LCID 2 respectively.
  • Each channel corresponds to a GGFN.
  • the GGFN corresponding to LCID 1 is GGFN 1, which occupies bytes 2 to 5.
  • the GGFN corresponding to LCID 2 is GGFN 2, which occupies bytes 7 to 10. It should be understood that the bytes and bits occupied by each LCID and GGFN in Table 3 are examples and are not limited.
  • the frame numbers of GGFN1 and GGFN 2 can also be determined in actual use scenarios. Here, they are simply referred to as GGFN1 and GGFN 2 for distinction, but this is not a limitation.
  • the groupcastConfig may also include a multicast group, such as the physical layer identifier of the first multicast group, the multicast type, and control information resources, and at least one of the acknowledge character (ACK) or negative acknowledge (NACK) feedback resources.
  • a multicast group such as the physical layer identifier of the first multicast group, the multicast type, and control information resources, and at least one of the acknowledge character (ACK) or negative acknowledge (NACK) feedback resources.
  • ACK acknowledge character
  • NACK negative acknowledge
  • S502 and T nodes receive dedicated control messages and obtain GGFN for multicast transmission.
  • node T can use the GGFN carried in the groupcast configuration to perform encrypted transmission and/or integrity protection in subsequent multicast transmissions.
  • the method provided in this application embodiment can indicate the GGFN to the T node through a dedicated control message, such as XRC reconfiguration, so that nodes in the first multicast group that do not locally maintain the GGFN can obtain the GGFN and perform at least one of the following: encrypted transmission or integrity protection of multicast. This effectively avoids errors in the encrypted transmission and/or integrity protection process caused by nodes in the first multicast group not maintaining the GGFN.
  • the data transmission method provided in this application embodiment expands the multicast application scenarios, making multicast transmission applications more widespread.
  • Figure 9 is a flowchart of a data transmission method provided in an embodiment of this application. The method is executed by G node and T node, or by a device in the node. This embodiment of the application does not limit the execution.
  • Figure 9 illustrates the method by example of execution by G node and T node. As shown in Figure 9, the method includes S601 to S602.
  • nodes T and G will exchange various control messages.
  • the T node sends a dedicated control message to the G node, which includes the high frame number of the GGFN.
  • the dedicated control message includes the high frame number of GGFN, which may include at least one of HFN or HSFN.
  • the high bit may also include other frame numbers, not limited to HFN or HSFN.
  • node G can configure node T using dedicated control messages, such as the XRC reconfiguration (cross-reference configuration reconfiguration, xrcReconfiguration) message.
  • XRC reconfiguration cross-reference configuration reconfiguration
  • node G can configure node T with at least one of the HFN or HSFN corresponding to different logical channels of the multicast group using the multicast configuration (groupcastConfig) carried in the XRC reconfiguration (xrcReconfiguration) message.
  • Node G can refer to the example in S406 to obtain the high frame number corresponding to the logical channel of the first multicast group.
  • Table 4 provides an example of the HFN and HSFN corresponding to the logical channels of a first multicast group according to an embodiment of this application.
  • the multicast configuration (groupcastConfig) can refer to Table 4, carrying at least one of the HFN or HSFN corresponding to different logical channels.
  • the first multicast group includes two logical channels, identified as LCID 1 and LCID 2 respectively.
  • the first channel corresponds to an HFN
  • the second channel corresponds to an HSFN.
  • the HFN corresponding to LCID 1 is HFN1
  • the HSFN corresponding to LCID 2 is HSFN1.
  • the bytes and bits occupied by each LCID, HFN, and HSFN in Table 4 are examples and are not limited.
  • the frame numbers of HFN1 and HSFN1 can also be determined in the actual usage scenario. Table 4 is just an example and is not limited.
  • S602 and T nodes receive dedicated control messages and obtain the high frame number of GGFN for multicast transmission.
  • the method provided in this application embodiment indicates the high frame number of GGFN to the T node by sending a dedicated control message, such as XRC Reconfiguration, to the T node.
  • a dedicated control message such as XRC Reconfiguration
  • the dedicated control message carries the high frame number of GGFN, which can reduce the transmission overhead.
  • plaintext in the confidentiality protection process, plaintext can be transformed into ciphertext using a keystream obtained from an encryption algorithm.
  • This encryption algorithm can be generated by the sending device, such as a G node, based on an encryption key (kenc), a freshness parameter, and a length, and then XORed with the plaintext to obtain the ciphertext.
  • the freshness parameter can include GGFN, a logical channel identifier, and a reserved field; the length is the length of the plaintext to be encrypted and can be used to control the length of the keystream.
  • the G node After encrypting the text into ciphertext using the freshness parameter and length, the G node sends it to the receiving device, such as a T node.
  • the T node can refer to the methods described in Figures 3 to 9 above to obtain the bit sequence corresponding to the high-order bits of GGFN, i.e., the first bit sequence. Based on this first bit sequence, it obtains GGFN and generates the same keystream using the same input parameters as the G node (such as the encryption key (kenc), freshness parameter, and length), and then XORs the keystream with the ciphertext to recover the plaintext.
  • the methods for obtaining other obtainable fields (such as logical channel identifier) and length in the freshness parameter can be based on information carried in other messages or obtained according to configuration, etc., and are not limited in this application embodiment.
  • Methods for obtaining the GGFN in the freshness parameter include: obtaining it through the GGFN carried in the first message (including the first bit sequence (i.e., the bit sequence corresponding to the high frame number) and the second bit sequence); or obtaining the first bit sequence through the first bit sequence carried in the first message and obtaining the second bit sequence through other means (such as other messages) to obtain the GGFN, and are not limited in this application embodiment.
  • the data sent between node G and node T can be verified using a message authentication code (MAC), such as whether a message carrying data is complete and has not been tampered with.
  • the integrity protection algorithm often simply called the integrity protection algorithm, can derive the MAC based on the integrity protection key (kint), freshness parameters, and the message.
  • the freshness parameters can be referenced from the examples in Figure 10, but are not limited thereto; the message is the content to be protected for integrity.
  • the sending device such as node G, uses the integrity protection algorithm to calculate a message integrity code (MIC) based on the integrity protection key (kint), freshness parameters, and the message, and appends the MIC to the message when sending it.
  • MIC message integrity code
  • the receiving device such as a T node in a multicast, after receiving a message, can obtain the GGFN by referring to the methods in Figures 3 to 9 above. Then, based on the GGFN, other obtainable fields in the freshness parameters, and the obtained message information, it calculates the expected message integrity code (XMIC).
  • the T node can compare the XMIC with the received MIC. If the XMIC matches the MIC, the integrity protection verification is passed, indicating that the received message is complete and unaltered. If they do not match, the integrity protection verification is not passed, indicating that the message may be incomplete or tampered with.
  • Methods for obtaining the GGFN in the freshness parameters include: obtaining it through the GGFN carried in the first message (including the first bit sequence (i.e., the bit sequence corresponding to the high frame number) and the second bit sequence); or obtaining the first bit sequence through the first bit sequence carried in the first message and obtaining the second bit sequence through other means (such as other messages) to obtain the GGFN.
  • This application embodiment does not limit the methods.
  • the sending device such as node G
  • Node G can send the ciphertext, AAD, and MIC to node T, where the IV includes GGFN.
  • Node T can obtain GGFN using the methods described in Figures 3 to 9 above.
  • node T can use the same input parameters as node G for generating these data, such as the encryption key (KAC), IV, and ADD, to generate plaintext and XMIC based on the received ciphertext.
  • the methods for obtaining the GGFN in the IV include: obtaining it through the GGFN carried by the first message (including the first bit sequence (i.e., the bit sequence corresponding to the high frame number) and the second bit sequence); or obtaining the first bit sequence through the first bit sequence carried by the first message and obtaining the second bit sequence through other means (such as other messages) to obtain the GGFN.
  • the embodiments of this application do not limit this.
  • Figures 10 to 12 are just examples and are not limited to the examples in Figures 10 to 12.
  • FIG 13 is a schematic diagram of one of the structures of a second communication device provided in an embodiment of this application.
  • the second communication device can refer to the second node itself (e.g., a management node (also known as a management device or G node), a network device, etc.), a component in the second node (e.g., a processor, a chip, or a chip system, etc.), or a logic module or software that can implement all or part of the functions of the second communication device.
  • the second communication device 30 includes: a processing module 301 and a transmitting module 302.
  • Processing module 301 is used to generate a first multicast security parameter, which includes a first bit sequence of GGFN, which is maintained locally by the nodes of the first multicast group, and the first multicast security parameter is used for encrypted transmission and/or integrity protection of multicast.
  • the sending module 302 is used to send the first multicast security parameters to the first node, wherein the nodes of the first multicast group include the first node.
  • one of the first multicast security parameters corresponds to one logical channel of the first multicast group; or, one of the first multicast security parameters corresponds to multiple logical channels of the first multicast group.
  • the first bit sequence includes the high frame number.
  • the first multicast security parameter also includes a second bit sequence of the GGFN, which includes one or more of the following: a link control layer SN; or, a physical layer superframe number and a radio frame number.
  • the second communication device further includes a receiving module 303 for receiving a first message, the first message including the ID of the first node.
  • the processing module 301 is specifically used to generate the first multicast security parameters based on the first message.
  • the processing module 301 is further configured to, if a first set of keys exists, obtain the first multicast security parameter, wherein the first set of keys is the group key of the first multicast group; and if the first set of keys is generated, set the first multicast security parameter to zero.
  • the sending module 302 is specifically used to send the first multicast security parameter to the first node via an association establishment message; or, via a configuration message, to the first node.
  • each module shown in Figures 13 and 14 is merely examples, and each module can perform its operations or variations thereof with reference to the method section of the embodiments of this application. Other operations can also be performed in the examples provided in the embodiments of this application, and are not limited to the examples of the embodiments of this application.
  • FIG 15 is a schematic diagram of the structure of a first communication device provided in an embodiment of this application.
  • the first communication device can refer to the first node itself (e.g., a terminal node (also called a T node or terminal device)), a component in the first node (e.g., a processor, chip, or chip system), or a logic module or software that can implement all or part of the functions of the first communication device.
  • the first communication device 40 includes: a receiving module 401 and a transmitting module 402.
  • the receiving module 401 is used to receive a first multicast security parameter, which includes a first bit sequence of GGFN, which is maintained locally by the nodes of the first multicast group, and the first multicast security parameter is used for encrypted transmission and/or integrity protection of multicast.
  • one of the first multicast security parameters corresponds to one logical channel of the first multicast group; or, one of the first multicast security parameters corresponds to multiple logical channels of the first multicast group.
  • the first bit sequence includes the high frame number.
  • the first multicast security parameter also includes a second bit sequence of the GGFN, which includes one or more of the following: a link control layer SN; or, a physical layer superframe number and a radio frame number.
  • a sending module 402 is also included for sending a first message, which includes the ID of the first node.
  • the receiving module 401 is specifically used to receive the first multicast security parameter through an association establishment message; or, through a configuration message, to receive the first multicast security parameter.
  • Device 50 also corresponds to the first communication device, first node, or T node executable in the method, used to execute methods S301, or S301 to S302, S401 to S405, or S401 to S403, S406 and S405, or S501 to S502, or S601 to S602 in the above embodiments.
  • the memory 602 stores computer-readable instructions, which include multiple software modules, such as a sending module, a processing module, and a receiving module. After executing each software module, the processor 601 can perform corresponding operations according to the instructions of each software module. In this embodiment, the operation performed by a software module actually refers to the operation performed by the processor 601 according to the instructions of the software module.
  • the processor 601 may also store program code or instructions for executing the scheme of the embodiments of this application. In this case, the processor 601 does not need to read the program code or instructions from the memory 602.
  • the device 60 can be used to perform the methods in the above embodiments.
  • the device 60 is equivalent to the second communication device, or the second node, or the G node in the example of the method, and can perform the methods S101 to S102, or S201 to S203, or S401 to S405, or S401 to S403, S406 and S405, or S501 to S502, or S601 to S602 in the above embodiments.
  • the device 60 may be equivalent to the first communication device, or the first node, or the T node in the example of the method, for executing the methods S301, or S301 to S302, S401 to S405, or S401 to S403, S406 and S405, or S501 to S502, or S601 to S602 in the above embodiments.
  • the communication device includes a storage medium and a processor connected to the storage medium.
  • the storage medium stores instructions, which, when executed by the processor, enable the processor to implement some or all of the operations in any of the methods described in any of the foregoing embodiments.
  • the communication device includes a processor connected to a storage medium.
  • the storage medium may be disposed within or outside the communication device.
  • the storage medium stores instructions, which, when executed by the processor, enable the processor to implement some or all of the operations in any of the methods described in any of the foregoing embodiments.
  • This application also provides a computer-readable storage medium storing instructions that, when executed on a processor, implement some or all of the operations in any of the methods in any of the foregoing embodiments.
  • This application also provides a computer program product, including a computer program that, when run on a processor, implements some or all of the operations in any method of any of the foregoing embodiments.
  • This application also provides a chip, including an interface circuit and a processor.
  • the interface circuit and the processor are connected, and the processor is used to cause the chip to perform some or all of the operations in any of the methods in any of the foregoing embodiments.
  • This application also provides a chip system, including: a processor coupled to a memory, the memory being used to store programs or instructions, and when the program or instructions are executed by the processor, the chip system enables the chip system to perform some or all of the operations in any one of the methods in any of the foregoing embodiments.
  • the chip system may contain one or more processors.
  • processors can be implemented in hardware or software.
  • the processor can be a logic circuit, an integrated circuit, etc.
  • the processor can be a general-purpose processor, implemented by reading software code stored in memory.
  • the chip system may contain one or more memories.
  • the memory may be integrated with the processor or disposed separately from it; this application embodiment does not limit this.
  • the memory may be a non-transient processor, such as a read-only memory (ROM), which may be integrated with the processor on the same chip or disposed separately on different chips.
  • ROM read-only memory
  • This application embodiment does not specifically limit the type of memory or the arrangement of the memory and processor.
  • the chip system can be an FPGA, an ASIC, a system-on-chip (SoC), a CPU, an NP, a digital signal processor (DSP), a microcontroller unit (MCU), a programmable logic device (PLD), or other integrated chips.
  • SoC system-on-chip
  • DSP digital signal processor
  • MCU microcontroller unit
  • PLD programmable logic device
  • This application also provides a system, including one or more of the above-described devices, apparatuses, computer-readable storage media, computer program products, chips, or chip systems. It can be applied to the scenario shown in Figure 1, but is not limited thereto.
  • the system provided in this application embodiment includes at least one first communication device and at least one second communication device.
  • the disclosed systems, apparatuses, and methods can be implemented in other ways.
  • the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical business division, and in actual implementation, there may be other division methods.
  • multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed.
  • the coupling or direct coupling or communication connection shown or discussed may be through some interfaces, indirect coupling or communication connection between apparatuses or units, and may be electrical, mechanical, or other forms.
  • the units described as separate components may or may not be physically separate.
  • the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
  • the various business units in the embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
  • the integrated unit can be implemented in hardware or as a software business unit.
  • the integrated unit is implemented as a software business unit and sold or used as an independent product, it can be stored in a computer-readable storage medium.
  • This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application.
  • the aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, Random Access Memory, magnetic disks, or optical disks.
  • the services described in this application can be implemented using hardware, software, firmware, or any combination thereof. When implemented using software, these services can be stored in a computer-readable medium or transmitted as one or more instructions or code on a computer-readable medium.
  • Computer-readable media include computer storage media and communication media, wherein communication media include any medium that facilitates the transfer of computer programs from one place to another. Storage media can be any available medium accessible to general-purpose or special-purpose computers.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Multimedia (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本申请提供了一种数据传输的方法和装置,该方法包括:生成第一组播安全参数,所述第一组播安全参数包括组播全局帧号GGFN的第一比特序列,所述第一比特序列由第一组播组的节点在本地维护,所述第一组播安全参数用于组播的加密传输和/或完整性保护;向第一节点发送所述第一组播安全参数,所述第一组播组的节点包括所述第一节点。能够增加组播传输能够适用的场景,使得组播加密传输的应用场景更加广泛。

Description

一种数据传输的方法和装置
本申请要求于2024年07月02日提交中国专利局、申请号为202410881419.6、申请名称为“一种数据传输的方法和装置”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本申请涉及通信领域,尤其涉及一种数据传输的方法和装置。
背景技术
随着通信技术的不断发展,数据传输能够通过不同的方式实现。如,在不同的场景中,发送端与接收端可以是互相感兴趣的设备或装置,进行单播通信,实现数据传输;或者,发送端向所在子网内所有接收端发送信息,即通过广播的方式进行数据传输;或者,通过介于两者之间的组播方式,进行数据传输,即由发送端向一组接收端发送信息,在该组内的设备或装置可以接收到信息,即通过组播的方式实现数据传输。组播传输,既能够解决单播传输时,数据的重复拷贝及带宽的重复占用问题,也能够解决广播方式下的带宽资源的浪费问题,因此受到广泛的关注。由此可以看出,组播传输具有一定的传输优势。
为了保障数据传输过程中的安全性,组播传输时,可以对传输的数据进行保护,如可以进行加密传输,进行完整性保护等,以防止组外的设备或装置对组内的通信进行干涉,如篡改、干扰等。因此如何增加组播传输能够适用的场景,使得组播加密传输的应用场景更加广泛,成为了需要解决的问题。
发明内容
本申请提供了一种数据传输的方法和装置,能够增加组播传输能够适用的场景,使得组播加密传输的应用场景更加广泛。
第一方面,本申请提供一种数据传输的方法,该方法可以由第二通信装置执行,在并不特殊说明的情况下,本申请中的“第二通信装置”既可以指第二节点本身(例如,管理节点(也可以被称为管理设备或G节点)、网络设备等),也可以是第二节点中的组件(例如,处理器、芯片、或芯片系统等),或者也可以是能实现全部或部分第二通信装置功能的逻辑模块或软件。该方法包括:生成第一组播安全参数,该第一组播安全参数包括组播全局帧号(group globally frame numbe,GGFN)的第一比特序列,该第一比特序列由第一组播组的节点在本地维护,该第一组播安全参数用于组播的加密传输和/或完整性保护;向第一节点发送该第一组播安全参数,该第一组播组的节点包括该第一节点。
本申请通过向第一组播组中的第一节点发送第一组播安全参数,使得未维护有第一比特序列的第一节点,能够获取到用于组播的加密传输、或完整性保护、或加密传输和完整性保护的第一比特序列,进而在第一组播组的数据传输中,实现上下文加密传输和/或完整性保护等流程。这种数据传输的方法,有效解决了只有本地维护有第一比特序列的节点,能够进行上下文加密传输和/或完整性保护操作的限制,能够支持新进组成员(如建组后加入第一组播组的成员)等,未维护有第一比特序列的节点,进行组播安全参数配置,增加了组播传输能够适用的场景,使得组播传输的应用场景更加广泛。
在一种可能的实现方式中,一个该第一组播安全参数对应该第一组播组的一个逻辑信道;或者,一个该第一组播安全参数对应该第一组播组的多个逻辑信道。即,第一组播组对应有至少一个传输组播数据的逻辑信道,一个逻辑信道可以对应一个第一组播安全参数,各逻辑信道的第一组播安全参数可以不同,或者,多个逻辑信道中,有几个逻辑信道的第一组播安全参数相同,或者,各逻辑信道的第一组播参数均相同,如均置为零。第二通信装置与第一节点可以通过第一组播安全参数对应的逻辑信道,使用该第一组播安全参数,进行上下文加密传输和/或完整性保护等流程。通过不同的逻辑信道使用对应的第一组播安全参数进行数据传输,能够提高传输的可靠性。
在一种可能的实现方式中,该第一比特序列包括高帧号。GGFN的高帧号可以由第一组播组中的节点维护,但对于新加入组播组的节点,和维护的高帧号丢失的节点来说,没有高帧号,进行上下文加密传输和/或完整性保护等流程时,会缺少必须的安全参数,使得流程出错。因此,第一比特序列中包括高帧号,能够帮助没有高帧号的节点,获取高帧号,以保障其数据传输时,上下文加密传输等流程能够实现。
在一种可能的实现方式中,该第一组播安全参数还包括该GGFN的第二比特序列,该第二比特序列包括以下一项或多项:链路控制层序列号(sequence number,SN);或者,物理层超帧号和无线帧编号。第一组播参数中还可以携带第二比特序列,第二比特序列可以指示数据传输的各流程中其他所需的参数,如SN等,使得指示的安全参数更完整、全面,进而保障传输中各流程,如加密、解密、完整性保护等的正确率更高。
在一种可能的实现方式中,该方法还包括:接收第一消息,该第一消息包括该第一节点的身份标识(identity,ID);该生成第一组播安全参数包括:根据该第一消息,生成该第一组播安全参数。假设在一个第二装置与多个第一节点的传输场景中,第二装置接收到第一消息后,可以根据第一消息中携带的第一节点的ID,判断该第一消息是哪个第一节点发送的,如,该第一消息来源于第一节点1,第二装置可以先通过第一节点1的ID,判断其是否为第一组播组的节点,如果是,则根据第一组播组,确定并生成相应第一组播安全参数。通过判断第一节点是否为第一组播组的节点,可以有效避免为非第一组播组的节点发送第一组播安全参数,增加传输的安全性。
在一种可能的实现方式中,若存在第一组密钥,则获取该第一组播安全参数,该第一组密钥是该第一组播组的组密钥;若生成该第一组密钥,则将该第一组播安全参数置零。通过第一组播组是否存在第一组密钥,分别对应不同的方式,获得第一组播安全参数,使得获取第一组播安全参数的方法更多样,适用的场景更广泛。
在一种可能的实现方式中,该向第一节点发送该第一组播安全参数包括:通过关联建立消息,向该第一节点发送该第一组播安全参数;或者,通过配置消息,向该第一节点发送该第一组播安全参数。本申请提供的传输方法可以应用在不同的场景中,使用不同的消息向第一节点发送该第一组播安全参数,适用的场景更加广泛。
第二方面,本申请提供一种数据传输的方法,该方法可以由第一通信装置执行,在并不特殊说明的情况下,本申请中的“第一通信装置”既可以指第一节点本身(例如,终端节点(也可以称为T节点或终端设备)等),也可以是第一节点中的组件(例如,处理器、芯片、或芯片系统等),或者也可以是能实现全部或部分第一通信装置功能的逻辑模块或软件。该方法包括:接收第一组播安全参数,该第一组播安全参数包括GGFN的第一比特序列,该第一比特序列由第一组播组的节点在本地维护,该第一组播安全参数用于组播的加密传输和/或完整性保护。
在一种可能的实现方式中,一个该第一组播安全参数对应该第一组播组的一个逻辑信道;或者,一个该第一组播安全参数对应该第一组播组的多个逻辑信道。
在一种可能的实现方式中,该第一比特序列包括高帧号。
在一种可能的实现方式中,该第一组播安全参数还包括该GGFN的第二比特序列,该第二比特序列包括以下一项或多项:链路控制层SN;或者,物理层超帧号和无线帧编号。
在一种可能的实现方式中,还包括:发送第一消息,该第一消息包括该第一节点的ID。
在一种可能的实现方式中,该接收第一组播安全参数包括:通过关联建立消息,接收该第一组播安全参数;或者,通过配置消息,接收该第一组播安全参数。
应当理解的是,本申请的第二方面与本申请的第一方面的技术方案相应,各方面及对应的可行实施方式所取得的有益效果相似,此处不再赘述。
第三方面,本申请提供了一种第二通信装置,该第二通信装置既可以指第二节点本身(例如,网络设备,或管理设备等),也可以是第二节点中的组件(例如,管理节点(也可以被称为管理设备或G节点)、网络设备等),也可以是第二节点中的组件(例如,处理器、芯片、或芯片系统等),或者也可以是能实现全部或部分第二通信装置功能的逻辑模块或软件。该第二通信装置包括:处理模块,用于生成第一组播安全参数,该第一组播安全参数包括GGFN的第一比特序列,该第一比特序列由第一组播组的节点在本地维护,该第一组播安全参数用于组播的加密传输和/或完整性保护;发送模块,用于向第一节点发送该第一组播安全参数,该第一组播组的节点包括该第一节点。
在一种可能的实现方式中,一个该第一组播安全参数对应该第一组播组的一个逻辑信道;或者,一个该第一组播安全参数对应该第一组播组的多个逻辑信道。
在一种可能的实现方式中,该第一比特序列包括高帧号。
在一种可能的实现方式中,该第一组播安全参数还包括该GGFN的第二比特序列,该第二比特序列包括以下一项或多项:链路控制层SN;或者,物理层超帧号和无线帧编号。
在一种可能的实现方式中,该第二通信装置还包括:接收模块,用于接收第一消息,该第一消息包括该第一节点的ID;该处理模块,具体用于根据该第一消息,生成该第一组播安全参数。
在一种可能的实现方式中,该处理模块还用于若存在第一组密钥,则获取该第一组播安全参数,该第一组密钥是该第一组播组的组密钥;若生成该第一组密钥,则将该第一组播安全参数置零。
在一种可能的实现方式中,该发送模块,具体用于通过关联建立消息,向该第一节点发送该第一组播安全参数;或者,通过配置消息,向该第一节点发送该第一组播安全参数。
应当理解的是,本申请的第三方面与本申请的第一方面的技术方案相同,各方面及对应的可行实施方式所取得的有益效果相似,此处不再赘述。
第四方面,本申请提供了一种第一通信装置,该第一通信装置既可以指第一节点本身(例如,终端节点(也可以称为T节点或终端设备)等),也可以是第一节点中的组件(例如,处理器、芯片、或芯片系统等),或者也可以是能实现全部或部分第一通信装置功能的逻辑模块或软件。该第一通信装置包括:接收模块,用于接收第一组播安全参数,该第一组播安全参数包括GGFN的第一比特序列,该第一比特序列由第一组播组的节点在本地维护,该第一组播安全参数用于组播的加密传输和/或完整性保护。
在一种可能的实现方式中,一个该第一组播安全参数对应该第一组播组的一个逻辑信道;或者,一个该第一组播安全参数对应该第一组播组的多个逻辑信道。
在一种可能的实现方式中,该第一比特序列包括高帧号。
在一种可能的实现方式中,该第一组播安全参数还包括该GGFN的第二比特序列,该第二比特序列包括以下一项或多项:链路控制层SN;或者,物理层超帧号和无线帧编号。
在一种可能的实现方式中,还包括发送模块,用于发送第一消息,该第一消息包括该第一节点的ID。
在一种可能的实现方式中,该接收模块,具体用于通过关联建立消息,接收该第一组播安全参数;或者,通过配置消息,接收该第一组播安全参数。
应当理解的是,本申请的第四方面与本申请的第一方面的技术方案相应,与第二方面的技术方案相同,各方面及对应的可行实施方式所取得的有益效果相似,此处不再赘述。
第五方面,本申请提供一种通信装置,该通信装置可以是节点或节点中的装置(例如芯片)。该通信装置包括用于执行如以上任一方面或任一方面的任一可能的实现方式所述的方法的模块,例如处理模块和收发模块。
第六方面,本申请提供一种通信装置,该通信装置可以是节点或节点中的装置(例如芯片)。该通信装置包括用于执行如以上任一方面或任一方面的任一可能的实现方式所述的方法的收发器和处理器,示例性的,该收发器可以是射频模块,该处理器中可以包括存储器,或不包括存储器;
可选地,该通信装置包括用于执行如以上任一方面或任一方面的任一可能的实现方式所述的方法的收发器、存储器和处理器,示例性的,该存储器可以设置在通信装置中,也可以是通信装置的外接器件。
第七方面,本申请提供一种通信装置,提供一种通信装置,包括:输入输出接口和逻辑电路,该输入输出接口,用于获取输入信息和/或输出信息;该逻辑电路用于执行如以上任一方面或任一方面的任一可能的实现方式所述的方法,根据输入信息进行处理和/或生成输出信息。
第八方面,本申请提供一种通信装置,该装置包括至少一个处理器和存储介质,该至少一个处理器与存储介质耦合,该存储介质存储有指令,该指令被该处理器运行时,该处理器用于执行如以上任一方面或任一方面的任一可能的实现方式所述的方法。该存储介质可以包括在该通信装置中,也可以设置于通信装置外部。
第九方面,本申请提供了一种计算机可读存储介质,该计算机可读存储介质存储有计算机程序,该计算机程序被处理器执行时实现如以上任一方面或任一方面的任一可能的实现方式所述的方法。
第十方面,本申请提供了一种计算机程序产品,该计算机程序产品包含指令,当其在处理器上运行时,实现如以上任一方面或任一方面的任一可能的实现方式所述的方法。
第十一方面,本申请提供了一种芯片包括:接口电路和处理器。该接口电路和该处理器相连接,该处理器用于使得该芯片执行前述任一方面该的方法以及前述任一方面的任一可能的实现方式中所包括的部分或全部操作。
第十二方面,本申请实施例还提供一种芯片,包括:至少一个处理器,至少一个处理器用于执行该存储器中的代码,当该至少一个处理器执行该代码时,该芯片实现前述任一方面该的方法以及前述任一方面的任一可能的实现方式中所包括的部分或全部操作。
可选地,该芯片还包括存储器。该存储器可以与处理器集成在一起,也可以和处理器分离设置,该存储器可以与处理器集成在同一块芯片上,也可以分别设置在不同的芯片上。
可选地,上述芯片还可以为集成电路。
第十三方面,本申请提供了一种系统,该系统中包括如第三方面所述的第二通信装置和如第四方面所述的第一通信装置。
第十四方面,本申请提供了一种系统,该系统中包括如第三方面至第十二方面任意方面中提供的装置。
应当理解的是,本申请的第五方面至第十四方面与本申请的第一方面和第二方面的技术方案一致或相应,各方面及对应的可行实施方式所取得的有益效果相似,此处不再赘述。
附图说明
为了更清楚地说明本申请实施例的技术方案,下面将对本申请实施例的描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本申请的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动性的前提下,还可以根据这些附图获得其他的附图。
图1是本申请实施例提供的一种通信系统100的结构示意图;
图2是本申请实施例提供的示例性的星闪联盟协议框架示意图;
图3是本申请实施例提供的一种数据传输方法的流程示意图之一;
图4是本申请实施例提供的一种数据传输方法的流程示意图之二;
图5a是本申请实施例提供的一种数据传输方法的流程示意图之三;
图5b是本申请实施例提供的一种数据传输方法的流程示意图之四;
图6是本申请实施例提供的一种数据传输方法的流程示意图之五;
图7是本申请实施例提供的一种数据传输方法的流程示意图之六;
图8是本申请实施例提供的一种数据传输方法的流程示意图之七;
图9是本申请实施例提供的一种数据传输方法的流程示意图之八;
图10是本申请实施例提供的一种机密性保护流程示意图;
图11是本申请实施例提供的一种完整性保护流程示意图;
图12是本申请实施例提供的一种认证加密流程示意图;
图13是本申请实施例提供的一种第二通信装置的结构示意图之一;
图14是本申请实施例提供的一种第二通信装置的结构示意图之二;
图15是本申请实施例提供的一种第一通信装置的结构示意图;
图16是本申请实施例的设备50的结构示意图;
图17是本申请实施例提供的一种设备60的结构示意图。
具体实施方式
为了使本技术领域的人员更好地理解本申请中的方案,下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅是本申请一部分实施例,而不是全部的实施例。
本文中术语“和/或”,仅仅是一种描述关联对象的关联关系,表示可以存在三种关系,例如,A和/或B,可以表示:单独存在A,同时存在A和B,单独存在B这三种情况,其中,A、B可以是单个也可以是多个。“以下至少一项”或其类似表达用于表示所列出的各项的任意组合,例如,A、B和(或)C中的至少一项,可以表示:单独存在A,单独存在B,单独存在C,同时存在A和B,同时存在B和C,同时存在A和C,同时存在A、B和C,其中,A、B、C可以是单个也可以是多个。
本申请实施例的说明书和权利要求书中的术语“第一”和“第二”等是用于区别不同的对象,而不是用于描述对象的特定顺序。例如,第一目标对象和第二目标对象等是用于区别不同的目标对象,而不是用于描述目标对象的特定顺序。
在本申请实施例中,“示例性的”或者“例如”等词用于表示作例子、例证或说明。本申请实施例中被描述为“示例性的”或者“例如”的任何实施例或设计方案不应被解释为比其它实施例或设计方案更优选或更具优势。确切而言,使用“示例性的”或者“例如”等词旨在以具体方式呈现相关概念。
在本申请实施例的描述中,除非另有说明,“多个”的含义是指两个或两个以上。例如,多个处理单元是指两个或两个以上的处理单元;多个系统是指两个或两个以上的系统。
为了便于理解,下面先对本申请实施例所使用到的相关名词或术语进行解释说明:
1、星闪(技术)
星闪联盟(sparklink alliance)成立并致力于推动新一代无线短距通信技术创新,星闪技术能够适用在智能汽车、智能家居、智能终端和智能制造等场景,并满足极致性能需求。本申请实施例中所涉及的节点可以基于星闪联盟所设计的新一代无线短距通信技术进行通信,本申请实施例中将基于星闪联盟所设计的新一代无线短距通信系统简称为星闪无线通信系统。
2、G节点和T节点
G节点指管理节点,可以适用在星闪无线通信系统中,作为发送数据调度信息的节点。T节点指终端节点,可以适用在星闪无线通信系统中,作为接收数据调度信息,根据数据调度信息发送数据的节点。本申请实施例对G节点和T节点在星闪无线通信系统中使用为例进行说明,但不做限定,G节点和T节点应用在其他系统中也可以参考本申请实施例的数据传输方法,进行组播传输。
3、初始化向量(initialization vector,IV),或称为初向量、初始向量等
是一个输入值,该输入值长度可以固定,通常为随机数或拟随机数。
4、组播全局帧号(GGFN)
在网络中,特别是在数据链路层(如以太网)或物理层(如Wi-Fi)中,帧号(Frame Number)指的是网络帧(Frame)的唯一标识符或序列号。每个发送的数据帧都会被赋予一个帧号,用于在接收端进行帧的唯一标识和顺序重组。GGFN就是组播数据的帧号。
本申请实施例适用的通信系统100可以包括多个节点,该节点包括具有数据收发能力的电子设备。例如,节点可以为汽车座舱(Cockpit Domain)设备,或者汽车座舱设备中的一个模块(例如座舱域控制器(cockpit domain controller,CDC)、摄像头、屏幕、麦克风、音响、电子钥匙、无钥匙进入或启动系统控制器等模块中的一个或者多个)。在具体实施过程中,该节点还可以包括数据中转设备,例如路由器、中继器、桥接器或交换机;也可以包括终端设备,例如各种类型的用户设备(user equipment,UE)、手机(mobile phone)、平板电脑(pad)、台式电脑、耳机、音响等;还可以包括机器智能设备,如无人驾驶(self-driving)设备、运输安全(transportation safety)设备、虚拟现实(virtual reality,VR)终端设备、增强现实(augmented reality,AR)终端设备、机器类型通信(machine type communication,MTC)设备、工业控制(industrial control)设备、远程医疗(remote medical)设备、智能电网(smart grid)设备、智慧城市(smart city)设备;还可以包括可穿戴设备(如智能手表,智能手环,计步器等)等等。在某些技术场景中,具备相类似数据收发能力的设备的名称也可能不称为节点,但是为了方便描述,本申请实施例中将具有数据收发能力的电子设备统称为节点。
该节点可以应用于各种类型的通信系统。示例性的,参考图1,该节点可以应用于通信系统100中,该节点包括至少一个第一节点10和至少一个第二节点20,假如通信系统100是星闪无线通信系统,该第一节点可以是T节点,第二节点可以是G节点,G节点和T节点均支持星闪联盟协议。此外,第一节点和第二节点也可以是无线局域网系统(wireless local area network,WLAN)、窄带物联网系统(narrow band-internet of things,NB-IoT)、全球移动通信系统(global system for mobile communications,GSM)、增强型数据速率GSM演进系统(enhanced data rate for gsm evolution,EDGE)、宽带码分多址系统(wideband code division multiple access,WCDMA)、码分多址2000系统(code division multiple access,CDMA2000)、时分同步码分多址系统(time division-synchronization code division multiple access,TD-SCDMA),LTE系统、卫星通信、第五代5G通信系统、第六代(6th-generation,6G)通信系统或者将来出现的新的通信系统中作为发送端或接收端的节点,本申请实施例不做限定。图1所示的通信系统100仅用于举例,并非用于限制本申请的技术方案。本领域的技术人员应当明白,在具体实现过程中,通信系统100还可以包括其他设备,同时也可根据具体需要来确定各节点的数量,不予限制。
参考图1所示的通信系统100,第一节点10和第二节点20均可以作为发送端或接收端。本申请实施例将通信的发起方定义为发送端设备,将通信的接收方定义为接收端设备,如在G节点向T节点发送信息时,G节点为发送端设备,T节点为接收端设备,T节点向G节点发送信息时,T节点为发送端设备,T节点为接收端设备。
本申请实施例提供的发送端设备和接收端设备可以是任意一种具有收发功能的设备,包括但不限于:通用移动通信技术的长期演进(long term evolution,LTE)系统中的演进型基站(NodeB或eNB或e-NodeB,evolutional Node B),新空口(new radio,NR)系统中的基站(gNodeB或gNB)或收发点(transmission receiving point/transmission reception point,TRP),第三代合作伙伴计划(the 3rd generation partnership project,3GPP)后续演进的基站,无线通信系统(例如WiFi,蓝牙等)中的接入节点,无线中继节点,无线回传节点,数据中转设备(如路由器、中继器、桥接器或交换机)等。基站可以是:宏基站,微基站,微微基站,小站,中继站,或,气球站等。
发送端设备或接收端设备还可以是云无线接入网络(cloud radio access network,CRAN)场景下的无线控制器、集中单元(centralized unit,CU),和/或,分布单元(distributed unit,DU)。
发送端设备或接收端设备还可以是服务器,可穿戴设备(如智能手表,智能手环,计步器等),机器通信设备、或车载设备等。
发送端设备或接收端设备还可以是手机(mobile phone)、平板电脑(Pad)、带无线收发功能的电脑、耳机、音响、虚拟现实(virtual reality,VR)终端设备、增强现实(augmented reality,AR)终端设备、机器类型通信(machine type communication,MTC)中的终端、工业控制(industrial control)中的终端、车载终端设备、无人驾驶(self driving)中的终端、辅助驾驶中的终端设备、远程医疗(remote medical)中的终端、智能电网(smart grid)中的终端、运输安全(transportation safety)中的终端、智慧城市(smart city)中的终端、智慧家庭(smart home)中的终端、以及机器人、智能机器人等。终端有时也可以称为终端设备、用户设备(user equipment,UE)、接入终端设备、车载终端、工业控制终端、UE单元、UE站、移动站、移动台、远方站、远程终端设备、移动设备、UE终端设备、无线通信设备、机器终端、UE代理或UE装置等。终端可以是固定的,也可以是移动。
发送端设备或接收端设备还可以是汽车座舱(cockpit domain)设备,或者汽车座舱设备中的一个模块(座舱域控制器(cockpit domain controller,CDC)、摄像头、屏幕、麦克风、音响、电子钥匙、无钥匙进入及启动系统控制器等模块)。
本申请的实施例对应用场景不做限定,为了说明组播数据传输方法,本申请实施例以应用在星闪系统中的组播传输为例,但不以此做限定。
本申请实施例提供一种星闪联盟协议框架,能够针对上述场景,能够支撑星闪联盟无线短距通信技术,并实现短距业务的完整流程。图2是本申请实施例提供的示例性的星闪联盟协议框架示意图。该协议框架可应用于任何可实现短距离通信的节点中,如图1所示的通信系统100中的任意一个节点。参照图2,协议框架200自下而上包括接入层201、网络与传输层202和应用层203,其中,接入层201可以用于对底层逻辑链路进行处理,如接入层201可以负责逻辑链路的建立、重配置、删除等,以承接网络与传输层202的业务需求。示例性的,接入层201包括多种接入技术,如星闪基础(sparklink basic,SLB)短距无线通信系统的接入技术、星闪低功耗(sparklink low energy,SLE)短距无线通信系统的接入技术及其他的接入技术等。网络与传输层202可以用于创建、添加、删除、释放传输通道等,还可以用于逻辑链路的控制,如选择某接入技术等,以承接应用层203的流量、速率等业务需求。应用层203可以分为控制面的传输和业务面的传输等。
结合该协议框架200,对数据传输的通道进行说明:网络与传输层202进行传输的通路可以定义为传输通道(transmission channel,TC),传输通道可以实现多个传输通道映射到同一逻辑信道,或者一个传输通道也可以映射不同的接入制式的逻辑信道。逻辑信道(logical channel,LC)是接入层201进行数据传输的通路,可承接多个传输通道映射,可选的,逻辑信道也可以称为逻辑链路、逻辑通道等,本申请实施例以逻辑信道举例进行说明,但不做限定。进一步地,为了区分逻辑信道,本申请实施例中定义了逻辑信道的标识(logical channelidentification,LCID),用于唯一标识逻辑信道,也就是说,每个逻辑信道对应一个LCID。
由于组播传输能够解决单播情况下,数据的重复拷贝及带宽的重复占用的问题,也能够解决广播方式下带宽资源的浪费,因此适用的场景更多。以一种组播的认证和安全上下文协商流程为例,简单说明组播数据传输的步骤:G节点可以先广播密钥协商算法能力;在组播组中的T节点向G节点发送关联请求消息;由G节点发送安全上下文请求消息,再由T节点反馈安全上下文响应消息,G节点收到该响应消息后,可以发送关联建立消息,并在关联建立消息中,下发T节点所在组播组的组密钥、组ID、组算法、组密钥有效期等组播安全参数;T节点收到关联建立消息,反馈关联完成消息,并根据该组播安全参数与G节点进行加密通信。这种加密的流程建立后,进行数据传输适用于建组(建立组播组)时,已经在组播组中的T节点与G节点之间的加密通信,但未考虑到建组后,新进组的成员(后文简单称为新进组成员),新进组成员接无法获取到一些建组时就加入组播组的T节点在本地维护(或者在本地保存)的,用于加密传输和/或完整性保护的安全参数(或称为第一比特序列),也就是说,新进组成员受限于缺乏第一比特序列,其能够获取到的组播安全参数不足以支持后续的加密传输、或完整性保护、或加密传输和完整性保护等操作,限制了组播传输的适用范围。为了解决这个问题,本申请实施例提供一种数据传输方法,该方法能够支持新进组成员获取到第一比特序列,增加了组播传输能够适用的场景,使得组播传输的应用场景更加广泛。
本申请实施例提供的数据传输的方法,可以应用在无线短距通信中进行通信,以实现信息共享和业务的无线传输,如该方法可以应用于星闪无线通信系统。图3是本申请实施例提供的一种数据传输方法的流程示意图之一,该方法由第二装置执行为例进行说明,该第二装置可以是G节点中的装置,也可以是G节点,本申请实施例不做限定,在图3所示流程中,第二装置可以视为发送端设备,T节点(包括第一节点)可以视为接收端设备,如图3所示,该方法包括S101至S102。
S101、第二装置生成第一组播安全参数,第一组播安全参数包括GGFN的第一比特序列,第一比特序列由第一组播组的节点在本地维护,第一组播安全参数用于组播的加密传输和/或完整性保护。
示例性的,第二装置是G节点,G节点与至少一个T节点建立了组播组,该组播组可以定义为第一组播组,第一组播组中可以包括建组时就加入的至少一个T节点,也可以包括建组后新加入的成员(如T节点,可以定义为第一节点),其中,建组时就加入的每个T节点中,本地维护(或称为在本地保存)有第一比特序列,该第一比特序列能够用于第一组播组的加密传输、完整性保护、或者加密传输和完整性保护。第一节点为了加密传输、完整性保护、或者加密传输和完整性保护,也需要获取该第一比特序列,即,需要执行步骤S102。也就是说,第一组播组中包括多个T节点,该多个节点中包括至少一个建组后加入的T节点,即新进组成员,定义为第一节点,每个第一节点为了后续传输中能够实现组播的加密传输和/或完整性保护,需要执行步骤S102。
S102、第二装置向第一节点发送第一组播安全参数,第一组播组的节点包括第一节点。
第二装置向第一节点发送的第一组播安全参数中,包括第一比特序列,能够便于第一节点接收并本地维护该第一比特序列,以实现在第一组播组的传输中进行加密传输、完整性保护、或者加密传输和完整性保护。
示例性的,第一组播安全参数可以是GGFN,第一比特序列可以是GGFN的高位的比特序列,如高帧号对应的比特序列。高帧号包括HFN或HSFN中的至少一项。
应理解的是,第二装置可以向第一组播组中任意的T节点发送该第一组播安全参数,本申请实施例以第二装置向第一节点发送为例进行说明,但不做限定。
本申请实施例通过向第一组播组中的第一节点发送第一组播安全参数,使得第一节点能够获取到用于组播的加密传输、或完整性保护、或加密传输和完整性保护的第一比特序列,进而在第一组播组的数据传输中,进行上下文加密传输和/或完整性保护等。有效解决了只有建组时加入第一组播组的T节点才本地维护有第一比特序列,新加入第一组播组的T节点无法获取到第一比特序列的问题,能够支持新进组成员的组播安全参数配置,增加了组播传输能够适用的场景,使得组播传输的应用场景更加广泛。
在一种可能的实现方式中,第一组播安全参数可以包括第一比特序列,或者,第一组播安全参数可以包括第一比特序列和第二比特序列。第一比特序列可以包括高帧号(high frame numbe,HFN)或高帧号(high super frame numbe,HSFN)中的至少一项,第二比特序列包括以下一项或多项:链路控制层序列号SN;或者,物理层超帧号和无线帧编号。
举例来说,第一组播安全参数可以是GGFN,包括HFN和链路控制层SN,其中,第一比特序列是HFN,第二比特序列是链路控制层SN;或者,第一组播安全参数可以是GGFN,包括HSFN、物理层超帧号和无线帧编号,其中,第一比特序列是HSFN,第二比特序列是物理层超帧号和无线帧编号;或者,第一组播安全参数可以是第一比特序列,如第一比特序列是高帧号,高帧号包括HFN或HSFN中的至少一项。
在一种可能的实现方式中,基于图3,该数据传输方法的流程还可以包括其他步骤,示例性的,图4是本申请实施例提供的一种数据传输方法的流程示意图之二,该方法由第二装置执行为例进行说明,该第二装置可以是G节点中的装置,也可以是G节点,本申请实施例不做限定,在图4所示流程中,第二装置可以视为发送端设备,T节点(包括第一节点)可以视为接收端设备,如图4所示,该方法包括S201至S203。
S201、第二装置接收第一消息,第一消息包括第一节点的ID。
可选的,在一些可能实现的场景中,一个第二装置可能会收到多个第一节点(本申请实施例中第一节点可以指T节点)发送的第一消息,这些第一节点中,有的是新加入组播组的节点,有的是建组时已经在组播组中的节点,由于建组时已经在组播组中的节点已经在本地维护了所需的组播安全参数(本申请实施例定义为第一组播安全参数),因此,本申请实施例可以针对新加入组播组的T节点或丢失了维护的第一组播安全参数的T节点为例,作为第一节点对数据传输进行说明。
示例性的,参考上文示例的一种组播的认证和安全上下文协商流程,该第一消息可以是关联请求消息,第一消息中包括第一节点的ID。第一消息在不同的应用场景中可以是不同的消息,不以本申请实施例的示例为限定。
S202、第二装置根据第一消息,生成第一组播安全参数。
示例性的,假设在一个G节点与多个T节点的传输场景中,已经建立有一个第一组播组,G节点接收到第一消息后,可以根据第一消息,判断该第一消息所来源的第一节点,是否是第一组播组的节点,判断的方法不做限制。本申请实施例以第二装置根据第一消息得到第一节点的ID(或称为固定ID)为例进行说明,第二装置可以基于该第一节点的ID判断该第一节点是否属于第一组播组,如果属于第一组播组,基于第一组播组的相关参数生成第一组播安全参数。一种示例是,G节点从第一消息中获取到的第一节点(如一个T节点1)的固定ID,根据该固定ID判断G节点是否有预配置与该T节点1固定ID对应的组ID,如果有预配置的与该T节点1固定ID对应的组ID,则基于该组ID对应的组播组,如第一组播组,生成第一组播安全参数。
示例性的,第一组播组对应有至少一个传输组播数据的逻辑信道。可选的,G节点生成的一个第一组播安全参数对应第一组播组的一个逻辑信道;或者,G节点生成的一个第一组播安全参数对应第一组播组的多个逻辑信道。
举例来说,G节点如果确定第一组播组存在组密钥(可定义为第一组密钥),则获取第一组播组的第一组播安全参数。G节点如果确定第一组播组当前不存在组密钥,则生成第一组密钥,并将第一组播组的第一组播安全参数均置为零。
综合上述描述,假如第一组播组对应M个逻辑信道,G节点可以获取M个第一组播安全参数,相当于,每个逻辑信道对应一个第一组播安全参数。或者,第一组播组对应M个逻辑信道,G节点可以获取N个第一组播安全参数,其中,M是正整数,N是小于M的正整数,相当于,多个逻辑信道对应一个第一组播安全参数。
S203、第二装置向第一节点发送第一组播安全参数。
第二装置通过第一消息,确定第一消息所来源的第一节点是第一组播组中的节点,可以基于第一组播组的相关参数,如是否存在组密钥,生成用于该组播数据传输中,加密传输和/或完整性保护的第一组播安全参数发送至第一节点。以便于第一节点获知第一组播安全参数后,可以根据该第一组播安全参数,在后续与G节点的数据传输中,进行加密传输、完整性保护等操作中的一种或几种操作,有效的为加入第一组播组的新成员(即在建组后才加入第一组播组的T节点),或,因故丢失了本地维护的第一组播安全参数的建组成员(即建组时就加入第一组播组的T节点),配置第一组播安全参数,增加了组播传输能够适用的场景,使得组播传输的应用场景更加广泛。
图5a是本申请实施例提供的一种数据传输方法的流程示意图之三,该方法由第一装置执行为例进行说明,该第一装置可以是T节点(如第一节点)中的装置,也可以是T节点(如第一节点),本申请实施例不做限定,在图5所示流程中,G节点可以视为发送端设备,第一装置可以视为接收端设备,如图5a所示,该方法包括S301。
S301、第一装置接收第一组播安全参数,第一组播安全参数包括GGFN的第一比特序列,第一比特序列由第一组播组的节点在本地维护,第一组播安全参数用于组播的加密传输或完整性保护中的一项或多项。
第一装置接收到的第一组播安全参数,可以是参数图3示例或图4示例中,第二装置生成并发送的第一组播安全参数,不再展开赘述。图5a所示方法可以达到增加了组播传输能够适用的场景,使得组播传输的应用场景更加广泛的效果。
在一种可能的实现方式中,本申请实施例还可以提供一种数据传输方法,该方法如图5b所示,在图5a的基础上,还包括S302。
S302、第一装置使用第一组播安全参数,进行组播传输。
示例性的,第一装置可以基于第一组播安全参数,解析对应的逻辑信道上的数据,实现加密传输或完整性保护中的一项或多项操作。
本申请实施例图3至图5b提供的数据传输方法,在不同的场景中,可以通过不同的方式实现。例如,G节点可以通过关联建立消息向第一组播组中的至少一个T节点发送第一组播安全参数;或者,G节点可以通过配置消息,向第一组播组中包括的至少一个T节点发送第一组播安全参数等。
下面分别以第一组播安全参数是不同的帧号、第一组播安全参数通过关联建立消息或配置消息向T节点发送为例,对该方法进行举例说明,但不做限定。
图6是本申请实施例提供的一种数据传输方法的流程示意图之五,该方法由G节点和T节点执行,也可以由节点中的装置执行,本申请实施例不做限定,图6以该方法由G节点和T节点执行为例进行说明,如图6所示,该方法包括S401至S405。
S401、T节点向G节点发送关联请求消息。
该关联请求消息中可以包括T节点的ID,如T节点的固定ID,用于识别该T节点。可选的,该关联请求消息中还可以包括其他用于建立请求的信息,如密钥交换算法(key exchange alg,KE alg)、密钥交换算法时间戳(key exchange time,KEt)、安全能力集(sec capabilities)或随机数(NONCEt)中的至少一种,用于保障无线网络的安全性,其中,Ket表示密钥交换算法中使用的时间戳,用于确保密钥交换的安全性;安全能力集(sec capabilities)可以用于描述通信双方(如本申请实施例中的G节点与T节点)的加密和认证能力,以便于选择合适的加密和认证算法;随机数(NONCEt)可以用于防止重放攻击等。
S402、G节点向T节点发送安全上下文请求消息。
示例性的,安全上下文请求消息中可以携带加密会话密钥(KEg)、随机数(NONCEg)、加密上下文标识符(Kgt ID)或加密算法(algorithm)中的至少一项,安全上下文请求消息中还可以包括消息完整性检查(messages integrity check,MIC)的字段。
S403、T节点向G节点发送安全上下文响应消息。
示例性的,安全上下文响应消息中可以携带消息验证码(AUTHt),用于验证消息完整性。
S404、G节点向T节点发送关联建立消息,该关联建立消息中包括GGFN。
示例性的,GGFN包括第一比特序列和第二比特序列。即GGFN可以包括HFN和链路控制层SN,或者,GGFN可以包括HSFN、物理层超帧号和无线帧编号,等等。GGFN的第一比特序列可以参考S102的示例,GGFN的第二比特序列也可以参考上文示例的描述,在此不再赘述。
G节点接收到T节点发送的关联请求消息和上下文问响应消息后,可以基于关联请求消息,确定T节点是加入第一组播组的成员。应理解的是,当有新成员加入第一组播组后,第一组播组中的成员名单,也可以称为组ID,会进行更新,更新后应包括该T节点的固定ID(如物理层ID(phy-ID))。示例性的,G节点可以根据T节点的固定ID,判断G节点是否预配置有与该T节点固定ID对应的组ID(如IDforGroupcast中对应的物理层ID(phy-ID)),如果有与该T节点,如T节点1的固定ID对应的组ID,如第一组播组的组ID中包括T节点1的固定ID,则相当于G节点确定T节点1是第一组播组的成员。
示例性的,G节点确定T节点是第一组播组的节点后,可以先判断T节点所在组,即本申请实施例示例的第一组播组,是否有组密钥(GK)和组算法(galgorithm)。
举例来说,G节点判断是否有第一组播组的组密钥(GK),一种可能的情况是,第一组播组没有组密钥(GK),基于此,G节点产生随机数,如随机数(rand),并根据第一组播组的组ID和该随机数(rand),生成组密钥(GK),并生成GK的组密钥标识符(GK ID)。生成组密钥(GK)后,GGFN初始化为0,即GGFN中的第一比特序列和第二比特序列均置为零。示例性的,假如第一组播组对应M个逻辑信道,则M个逻辑信道的GGFN均可以初始化为0。另一种可能的情况是,第一组播组有组密钥(GK),G节点获取当前组播的不同逻辑信道的GGFN。表1是本申请实施例提供的一种第一组播组的逻辑信道对应的GGFN的示例,如表1的示例,第一组播组的每个逻辑信道对应一个GGFN。
表1
参考表1的示例,第一组播组包括两个逻辑信道,分别标识为LCID 1和LCID 2,每个信道对应一个GGFN,如LCID 1对应的GGFN是GGFN 1,LCID 2对应的GGFN是GGFN 2。应理解的是,表1中各LCID和GGFN所占的字节及所在的比特位均为示例,不做限定,GGFN1和GGFN 2的帧号取值可以在实际使用的场景中确定,此处只是为了区分,分别以GGFN1和GGFN 2表示,但不做限定。
G节点判断是否有组算法(galgorithm),一种可能的情况是,第一组播组未确定组算法(galgorithm),G节点可以在第一组播组内所有T节点均支持的算法中,根据预配置的算法优选策略,选择组算法(galgorithm),第一组播组未确定组算法(galgorithm),G节点获得组算法(galgorithm)的方法不以本申请实施例的示例为限定。组算法(galgorithm)包括密钥派生函数、加密算法和完整性保护算法或认证加密算法等,其中,优先级最高的包括密钥派生函数。另一种可能的情况是,第一组播组有组算法(galgorithm),G节点使用当前的组算法(galgorithm)。
G节点根据获取到的组算法(galgorithm),如密钥派生函数,进一步从组密钥(GK)推演出加密密钥和完整性保护密钥,或认证加密密钥。G节点与T节点可以通过该推演出的密钥,对需要传输的数据进行加密传输。
示例性的,关联建立消息中,除了G节点通过上述方法获取到的各逻辑信道对应的GGFN,还可以包括临时ID、加密上下文过期时间(Kgt expiration)、组密钥(group key,GK)(当单播信令面的加密保护开启时携带GK)/GKc(当单播信令面的加密保护未开启时,G节点加密GK得到GKc,并携带GKc)、组密钥标识符(GK ID)、组算法(galgorithm)、组密钥的有效期或者称为组密钥过期时间(GK expiration)中的至少一项,其中,GKc/GK表示当单播信令面(即对于第一组播组中的一个T节点与G节点的传输,可以视为单播)的加密保护未开启时携带GKc,当单播信令面的加密保护开启时携带GK。
可选的,该关联建立消息中还可以包括MIC,以验证包括前述内容的关联建立消息的完整性和真实性,确保消息在传输过程中没有被篡改或冒充。
S405、T节点向G节点发送关联完成消息。
可选的,该关联完成消息可以包括MIC,以验证完整性和真实性。
本申请实施例提供的方法,通过向T节点发送的关联建立消息,向T节点指示GGFN,以便于没有本地维护GGFN的第一组播组中的节点,能够获取到GGFN,执行组播的加密传输或完整性保护中的至少一项。没有本地维护GGFN的第一组播组中的节点包括加入第一组播组的新成员,或丢失了本地维护的GGFN的建组成员等。本申请实施例提供的数据传输方法,有效避免了第一组播组中的节点,因没有维护GGFN,导致加密传输和/或完整性保护过程出错,扩展了组播应用场景,使得组播传输应用的场景更广泛。
图7是本申请实施例提供的一种数据传输方法的流程示意图之六,该方法由G节点和T节点执行,也可以由节点中的装置执行,本申请实施例不做限定,如图7所示,该方法与图6所示的方法相比,由S406替换了S404,即该方法包括S401至S403、S406和S405。
S401、T节点向G节点发送关联请求消息。
S402、G节点向T节点发送安全上下文请求消息。
S403、T节点向G节点发送安全上下文响应消息。
S401至S403参考图6示例中的描述,不再展开赘述。
S406、G节点向T节点发送关联建立消息,该关联建立消息中包括HFN或HSFN中的至少一项。
可以参考S404中示例,G节点确定向该T节点发送第一组播安全参数包括GGFN的高帧号后,可以先判断第一组播组是否有组密钥(GK)和组算法(galgorithm),判断的方法参考S404中的示例,得到组密钥(GK)和组算法(galgorithm)的方法也可以参考S404中的示例,在此不再展开。
与S404不同的是,若判断第一组播组有组密钥(GK),G节点获取当前组播的不同逻辑信道的HFN或HSFN中的至少一项。也就是说,G节点可以获取GGFN的高帧号,得到第一比特序列。
表2是本申请实施例提供的一种第一组播组的逻辑信道对应的HFN和HSFN的示例。如表2的示例,第一组播组的每个逻辑信道对应一个HFN或HSFN。示例性的,G节点获取到的第一组播组的M个逻辑信道可能均对应HFN,或,G节点获取到的第一组播组的M个逻辑信道可能均对应HSFN,或,G节点获取到的第一组播组的M个中,有Q个对应HFN,M-Q个对应HSFN等,其中,Q为小于或等于M的正整数。本申请实施例的表2以第一组播组的有的逻辑信道对应HFN,有的逻辑信道对应HSFN举例说明,但不做限定。
表2
参考表2的示例,第一组播组包括两个逻辑信道,分别标识为LCID 1和LCID 2,第一个信道对应一个HFN,第二个信道对应一个HSFN,如LCID 1对应的HFN是HFN1,LCID 2对应的HSFN是HSFN1。应理解的是,表2中各LCID、HFN和HSFN所占的字节及所在的比特位均为示例,不做限定,HFN1和HSFN1的帧号取值也可以在实际使用的场景中确定,表2只是示例,不做限定。
示例性的,关联建立消息中,除了G节点通过上述方法获取到的各逻辑信道对应的HFN或HSFN中的至少一项,还可以包括临时ID、加密上下文过期时间(Kgt expiration)、GK/GKc、GK ID、组算法(galgorithm)、组密钥的有效期或者称为组密钥过期时间(GK expiration)中的至少一项,其中,GKc/GK表示当单播信令面的加密保护未开启时携带GKc,当单播信令面的加密保护开启时携带GK。
S405、T节点向G节点发送关联完成消息。
S405参考图6示例中的描述,不再展开。
本申请实施例提供的方法,通过向T节点发送的关联建立消息,向T节点指示GGFN的第一比特序列,即HFN或HSFN中的至少一项,相比于图6提供的方法,关联建立消息仅包括第一比特序列,能够减少传输的开销。
图8是本申请实施例提供的一种数据传输方法的流程示意图之七,该方法由G节点和T节点执行,也可以由节点中的装置执行,本申请实施例不做限定,图8以该方法由G节点和T节点执行为例进行说明,如图8所示,该方法包括S501至502。
已建立连接的T节点与G节点之间,会互发多种控制消息,如公共控制消息、专用控制消息等。本申请实施例以通过专用控制消息发送第一组播安全参数为例进行说明,但不做限定。
S501、T节点向G节点发送专用控制消息,该专用控制消息中包括GGFN。
当T节点处在连接态时,G节点可以通过专用控制消息,如XRC重配置(cross reference configuration reconfiguration,xrcReconfiguration)消息为T节点进行配置,例如,为T节点建立更多的逻辑信道,为T节点进行安全相关的配置,为T节点进行测量相关的配置、为T节点进行调度资源配置、为T节点配置更多数据传输的载波等。其中,XRC重配置(xrcReconfiguration)可以在不中断网络连接的情况下实现重新配置,能够最小化对网络性能和可用性的影响,能够适用于T节点处于连接态时进行配置。
示例性的,G节点通过XRC重配置(xrcReconfiguration)消息中携带的组播配置(groupcastConfig),给T节点配置组播的不同逻辑信道对应的GGFN。G节点可以参考S404的示例,获取第一组播组的逻辑信道的GGFN,表3是本申请实施例提供的一种第一组播组的逻辑信道对应的GGFN的示例,如表3的示例,第一组播组的每个逻辑信道对应一个GGFN,组播配置(groupcastConfig)中可以参考表3携带不同逻辑信道对应的GGFN。
表3
参考表3的示例,第一组播组包括两个逻辑信道,分别标识为LCID 1和LCID 2,每个信道对应一个GGFN,如LCID 1对应的GGFN是GGFN 1,GGFN 1占字节2至字节5,LCID 2对应的GGFN是GGFN 2,GGFN 2占字节7至字节10。应理解的是,表3中各LCID和GGFN所占的字节及所在的比特位均为示例,不做限定,GGFN1和GGFN 2的帧号取值也可以在实际使用的场景中确定,此处只是为了区分,分别以GGFN1和GGFN 2表示,但不做限定。
可选的,该组播配置(groupcastConfig)中还可以包括组播组,如第一组播组的物理层标识、组播类型、以及控制信息资源,和确认字符(acknowledge character,ACK)或否认字符(negative acknowledge,NACK)反馈资源中的至少一项。
S502、T节点接收专用控制消息,并获取GGFN进行组播传输。
示例性的,若T节点接收到XRC重配置(xrcReconfiguration)消息,该XRC重配置(xrcReconfiguration)消息中组播配置(groupcastConfig)。T节点可以根据组播配置(groupcastConfig)中携带的GGFN,在后续的组播传输中,进行加密传输和/或完整性保护。
本申请实施例提供的方法,可以通过向T节点发送的专用控制消息,如XRC重配置(xrcReconfiguration),向T节点指示GGFN,以便于没有本地维护GGFN的第一组播组中的节点,能够获取到GGFN,执行组播的加密传输或完整性保护中的至少一项,有效避免了第一组播组中的节点,因没有维护GGFN,导致加密传输和/或完整性保护过程出错。本申请实施例提供的数据传输方法,扩展了组播应用场景,使得组播传输应用的场景更广泛。
图9是本申请实施例提供的一种数据传输方法的流程示意图之八,该方法由G节点和T节点执行,也可以由节点中的装置执行,本申请实施例不做限定,图9以该方法由G节点和T节点执行为例进行说明,如图9所示,该方法包括S601至S602。
参考图8示例的描述,T节点与G节点之间会互发多种控制消息。
S601、T节点向G节点发送专用控制消息,该专用控制消息中包括GGFN的高帧号。
示例性的,该专用控制消息中包括GGFN的高帧号,该高帧号可以包括HFN或HSFN中的至少一项,该高位也可以包括其他帧号,不以HFN或HSFN为限定。
当T节点处在连接态时,G节点可以通过专用控制消息,如XRC重配置(cross reference configuration reconfiguration,xrcReconfiguration)消息,为T节点进行配置,示例性的,G节点通过XRC重配置(xrcReconfiguration)消息中携带的组播配置(groupcastConfig),给T节点配置组播的不同逻辑信道对应的HFN或HSFN中的至少一项。G节点可以参考S406的示例,获取第一组播组的逻辑信道对应的高帧号。
表4是本申请实施例提供的一种第一组播组的逻辑信道对应的HFN和HSFN的示例。组播配置(groupcastConfig)中可以参考表4,携带不同逻辑信道对应的HFN或HSFN中的至少一项。
表4
参考表4,第一组播组包括两个逻辑信道,分别标识为LCID 1和LCID 2,第一个信道对应一个HFN,第二个信道对应一个HSFN,如LCID 1对应的HFN是HFN1,LCID 2对应的HSFN是HSFN1。应理解的是,表4中各LCID、HFN和HSFN所占的字节及所在的比特位均为示例,不做限定,HFN1和HSFN1的帧号取值也可以在实际使用的场景中确定,表4只是示例,不做限定。
S602、T节点接收专用控制消息,并获取GGFN的高帧号进行组播传输。
本申请实施例提供的方法,通过向T节点发送的专用控制消息,如XRC重配置(xrcReconfiguration),向T节点指示GGFN的高帧号,相比于图8提供的方法,专用控制消息携带GGFN的高帧号,能够减少传输的开销。
上述图3至图9任意示例中的数据传输方法,可以适用在不同的组播传输流程中,以下通过几个示例说明。
参考图10,在机密性保护流程中,明文可以通过加密算法得到的密钥流,变为密文。该加密算法可以由发送端设备,如G节点基于加密密钥(kenc),新鲜性参数和长度(length)生成密钥流,并将明文和密钥流做异或运算得到密文。其中,新鲜性参数可以包括GGFN、逻辑信道标识和预留字段,长度(length)为待加密的明文长度,可以用于控制密钥流的长度。G节点通过新鲜性参数和长度(length)将文加密为密文后,发送至接收端设备,如T节点,该T节点可以参考上述图3至图9的方法,得到GGFN的高位对应的比特序列,即第一比特序列,进而基于该第一比特序列得到GGFN,并使用与G节点相同的输入参数(如加密密钥(kenc),新鲜性参数和长度(length))生成相同的密钥流,并将密钥流和密文做异或运算,从而恢复明文。获取新鲜性参数中其他能够获取到的字段(如逻辑信道标识等)和长度(length)的方法可以根据其他消息中携带的信息获取、或根据配置获取等等,本申请实施例不做限定。得到新鲜性参数中的GGFN的方法包括:通过第一消息携带的GGFN(包括第一比特序列(即高帧号对应的比特序列)和第二比特序列)获取;也可以通过第一消息携带的第一比特序列获取第一比特序列,通过其他方式(如其他消息)获取第二比特序列,以获取GGFN,本申请实施例不做限定。
参考图11在完整性保护流程中,可以通过消息验证码(message authentication code,MAC)验证G节点与T节点之间发送的数据,如承载数据的某个消息是否完整,有无被篡改。完整保护性算法可以简称为完保算法,能够基于完整性保护密钥(kint)、新鲜性参数和信息(message)得到MAC,其中,新鲜性参数可参考图10的示例包括的字段,但不做限制;信息(message)为待做完整性保护的内容。发送端设备,如G节点基于完整性保护密钥(kint)、新鲜性参数和信息(message),使用完整性保护算法计算一个消息完整性代码(messages integrity code,MIC),并在发送消息时将MIC附加到消息后。接收端设备,如一个组播中的T节点,接收到消息后,可以参考上述图3至图9的方法,得到GGFN,进而基于GGFN、新鲜性参数中其他能够获取到的字段、以及获取到的信息(message),计算预期的消息完整性代码(expect messages integrity code,XMIC),T节点可以将XMIC和收到的MIC做比较,如果XMIC与MIC一致,则通过完整性保护验证,说明接收到的消息完整,无篡改,如果不一致,则没有通过完整性保护验证,说明该消息可能不完整,也可能被篡改等。得到新鲜性参数中的GGFN的方法包括:通过第一消息携带的GGFN(包括第一比特序列(即高帧号对应的比特序列)和第二比特序列)获取;也可以通过第一消息携带的第一比特序列获取第一比特序列,通过其他方式(如其他消息)获取第二比特序列,以获取GGFN,本申请实施例不做限定。
参考图12,在认证加密流程中,发送端设备,如G节点可以通过初始向量(initialisation vector,IV)、明文、额外认证数据(additional authentication data,AAD)、认证加密密钥(kac)等,可以通过认证加密算法得到密文和MIC。G节点可以向T节点发送密文、AAD和MIC,其中IV包括GGFN。T节点可以参考上述图3至图9的方法,得到GGFN。T节点接收到密文、AAD和MIC,可以使用与G节点生成这些数据相同的输入参数,如加密密钥(kac)、IV和ADD等,基于接收到的密文,生成明文和XMIC,并将XMIC和收到的MIC做比较,确定该密文的传输是否通过完整性保护验证,是否通过完整性保护验证的步骤可以参考图11的描述,在此不再赘述。得到IV中的GGFN的方法包括:通过第一消息携带的GGFN(包括第一比特序列(即高帧号对应的比特序列)和第二比特序列)获取;也可以通过第一消息携带的第一比特序列获取第一比特序列,通过其他方式(如其他消息)获取第二比特序列,以获取GGFN,本申请实施例不做限定。
本申请实施例提供的数据传输方法能够广泛的应用在不同的流程中,图10至图12仅为示例,不以图10至图12的示例为限定。
图13是本申请实施例提供的一种第二通信装置的结构示意图之一,该第二通信装置既可以指第二节点本身(例如,管理节点(也可以被称为管理设备或G节点)、网络设备等),也可以是第二节点中的组件(例如,处理器、芯片、或芯片系统等),或者也可以是能实现全部或部分第二通信装置功能的逻辑模块或软件。如图13所示,该第二通信装置30包括:处理模块301和发送模块302。
处理模块301,用于生成第一组播安全参数,该第一组播安全参数包括GGFN的第一比特序列,该第一比特序列由第一组播组的节点在本地维护,该第一组播安全参数用于组播的加密传输和/或完整性保护。
发送模块302,用于向第一节点发送该第一组播安全参数,该第一组播组的节点包括该第一节点。
在一种可能的实现方式中,一个该第一组播安全参数对应该第一组播组的一个逻辑信道;或者,一个该第一组播安全参数对应该第一组播组的多个逻辑信道。
在一种可能的实现方式中,该第一比特序列包括高帧号。
在一种可能的实现方式中,该第一组播安全参数还包括该GGFN的第二比特序列,该第二比特序列包括以下一项或多项:链路控制层SN;或者,物理层超帧号和无线帧编号。
在一种可能的实现方式中,该第二通信装置如图14所示,还包括:接收模块303,用于接收第一消息,该第一消息包括该第一节点的ID。
该处理模块301,具体用于根据该第一消息,生成该第一组播安全参数。
在一种可能的实现方式中,该处理模块301,还用于若存在第一组密钥,则获取该第一组播安全参数,该第一组密钥是该第一组播组的组密钥;若生成该第一组密钥,则将该第一组播安全参数置零。
在一种可能的实现方式中,该发送模302,具体用于通过关联建立消息,向该第一节点发送该第一组播安全参数;或者,通过配置消息,向该第一节点发送该第一组播安全参数。
应理解,图13和图14所示的模块仅是示例,各模块可以参照本申请实施例中方法部分执行其操作,或执行其操作的变形。在本申请实施例提供的示例中,也可以执行其他的操作,不以本申请实施例的示例做限定。
图15是本申请实施例提供的一种第一通信装置的结构示意图,该第一通信装置既可以指第一节点本身(例如,终端节点(也可以称为T节点或终端设备)等),也可以是第一节点中的组件(例如,处理器、芯片、或芯片系统等),或者也可以是能实现全部或部分第一通信装置功能的逻辑模块或软件。如图15所示,该第一通信装置40包括:接收模块401和发送模块402。
接收模块401,用于接收第一组播安全参数,该第一组播安全参数包括GGFN的第一比特序列,该第一比特序列由第一组播组的节点在本地维护,该第一组播安全参数用于组播的加密传输和/或完整性保护。
在一种可能的实现方式中,一个该第一组播安全参数对应该第一组播组的一个逻辑信道;或者,一个该第一组播安全参数对应该第一组播组的多个逻辑信道。
在一种可能的实现方式中,该第一比特序列包括高帧号。
在一种可能的实现方式中,该第一组播安全参数还包括该GGFN的第二比特序列,该第二比特序列包括以下一项或多项:链路控制层SN;或者,物理层超帧号和无线帧编号。
在一种可能的实现方式中,还包括发送模块402,用于发送第一消息,该第一消息包括该第一节点的ID。
在一种可能的实现方式中,该接收模块401,具体用于通过关联建立消息,接收该第一组播安全参数;或者,通过配置消息,接收该第一组播安全参数。
应理解,图15所示的模块仅是示例,各模块可以参照本申请实施例中方法部分执行其操作,或执行其操作的变形。在本申请实施例提供的示例中,也可以执行其他的操作,不以本申请实施例的示例做限定,如第一通信装置中还可以包括处理模块,用于使用第一组播安全参数,进行组播传输。或者,用于根据第一组播安全参数解析加密数据等,其发送模块和接收模块可以是一个模块等。
另外,如图16所示,图16是本申请实施例的设备50的结构示意图。图16所示的设备50包括收发器501和处理器502。该设备50相当于该方法中示例的第二通信装置、或第二节点、或G节点,用于执行以上实施例中的方法S101至S102、或执行S201至S203、或执行S401至S405、或执行S401至S403、S406和S405、或执行S501至S502、或执行S601至S602。该设备50相当于该方法中示例的第一通信装置、或第一节点、或T节点,用于执行以上实施例中的方法S301、或S301至S302、执行S401至S405、或执行S401至S403、S406和S405、或执行S501至S502、或执行S601至S602。
需要说明的是,本申请实施例中对各部分的划分是示意性的,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式。本申请实施例中的各功能集成在一个处理器中,也可以是收发器和处理器单独存在,另外,设备50中可以包括内置的存储器,也可以不包括存储器,还可以包含外置的存储器等等,不以本申请实施例示例的划分为限定。上述集成的器件既可以采用硬件的形式实现,例如芯片,也可以采用软件功能单元的形式实现,也可以采用软硬结合的方式实现。
此外,本申请实施例还提供了一种设备60,参见图17所示,图17是本申请实施例提供的一种设备60的结构示意图。如图17所示,设备60可以包括处理器601,与处理器601耦合连接的存储器602,收发器603。收发器603可以包括MR、LR、通信接口、光模块等,用于接收报文或数据信息等。处理器601可以包括中央处理器(central processing unit,CPU),网络处理器(network processor,NP)或者CPU和NP的组合,用于执行上述实施例所举例的设备中唤醒信号处理的相关步骤。处理器还可以是专用集成电路(application-specific integrated circuit,ASIC),可编程逻辑器件(programmable logic device,PLD)或其组合。上述PLD可以是复杂可编程逻辑器件(complex programmable logic device,CPLD),现场可编程逻辑门阵列(feld-programmable gate array,FPGA),通用阵列逻辑(generic array logic,GAL)或其任意组合。处理器601可以是指一个处理器,也可以包括多个处理器。存储器602可以包括易失性存储器(volatile memory),例如随机存取存储器(random-access memory,RAM);存储器也可以包括非易失性存储器(non-volatile memory),例如只读存储器(read-only memory,ROM),快闪存储器(flash memory),硬盘(hard disk drive,HDD)或固态硬盘(solid-state drive,SSD);存储器602还可以包括上述种类的存储器的组合。存储器602可以是指一个存储器,也可以包括多个存储器,用于存储程序指令。在一个实施方式中,存储器602中存储有计算机可读指令,计算机可读指令包括多个软件模块,例如发送模块,处理模块和接收模块。处理器601执行各个软件模块后可以按照各个软件模块的指示进行相应的操作。在本实施例中,一个软件模块所执行的操作实际上是指处理器601根据软件模块的指示而执行的操作。可选地,处理器601也可以存储执行本申请实施例方案的程序代码或指令,在这种情况下处理器601不需要到存储器602中读取程序代码或指令。
该设备60可以用于执行以上实施例中的方法。具体来说,该设备60相当于该方法中的示例的第二通信装置、或第二节点、或G节点,可以执行以上实施例中的方法S101至S102、或执行S201至S203、或执行S401至S405、或执行S401至S403、S406和S405、或执行S501至S502、或执行S601至S602。
或者,该设备60相当于该方法中示例的第一通信装置、或第一节点、或T节点,用于执行以上实施例中的方法S301、或S301至S302、执行S401至S405、或执行S401至S403、S406和S405、或执行S501至S502、或执行S601至S602。
此外,本申请实施例还提供了一种通信装置。该通信装置包括存储介质,和与存储介质连接的处理器。存储介质存储有指令,指令被处理器运行时,处理器用于实现前述实施例中任一实施例的方法中任一方法中的部分或全部操作。
此外,本申请实施例还提供了一种通信装置。该通信装置包括处理器,该处理器与存储介质连接。该存储介质可以设置在通信装置内,或设置在通信装置外,存储介质存储有指令,指令被处理器运行时,处理器用于实现前述实施例中任一实施例的方法中任一方法中的部分或全部操作。
本申请实施例还提供了一种计算机可读存储介质,计算机可读存储介质中存储有指令,当其在处理器上运行时,实现前述实施例中任一实施例的方法中任一方法中的部分或全部操作。
本申请实施例还提供了一种计算机程序产品,包括计算机程序,当其在处理器上运行时,实现前述实施例中任一实施例的方法中任一方法中的部分或全部操作。
本申请实施例还提供了一种芯片,包括:接口电路和处理器。接口电路和处理器相连接,处理器用于使得芯片执行前述实施例中任一实施例的方法中任一方法中的部分或全部操作。
本申请实施例还提供一种芯片系统,包括:处理器,处理器与存储器耦合,存储器用于存储程序或指令,当程序或指令被处理器执行时,使得该芯片系统实现前述实施例中任一实施例的方法中任意一个方法中的部分或全部操作。
可选地,该芯片系统中的处理器可以为一个或多个。该处理器可以通过硬件实现也可以通过软件实现。当通过硬件实现时,该处理器可以是逻辑电路、集成电路等。当通过软件实现时,该处理器可以是一个通用处理器,通过读取存储器中存储的软件代码来实现。
可选地,该芯片系统中的存储器也可以为一个或多个。该存储器可以与处理器集成在一起,也可以和处理器分离设置,本申请实施例并不限定。示例性的,存储器可以是非瞬时性处理器,例如只读存储器ROM,其可以与处理器集成在同一块芯片上,也可以分别设置在不同的芯片上,本申请实施例对存储器的类型,以及存储器与处理器的设置方式不作具体限定。
示例性的,该芯片系统可以是FPGA,可以是ASIC,还可以是系统芯片(system on chip,SoC),还可以是CPU,还可以是NP,还可以是数字信号处理电路(digital signal processor,DSP),还可以是微控制器(micro controller unit,MCU),还可以是可编程控制器(programmable logic device,PLD)或其他集成芯片。
本申请实施例还提供一种系统,包括上述设备、装置、计算机可读存储介质、计算机程序产品、芯片或芯片系统中的一种或几种。可以应用在图1所示的场景中,但不做限定。
在一种可能的实现方式中,本申请实施例还提供的系统包括至少一个第一通信装置和至少一个第二通信装置。
本申请的说明书和权利要求书及上述附图中的术语“第一”、“第二”、“第三”、“第四”等(如果存在)是用于区别类似的对象,而不必用于描述特定的顺序或先后次序。应该理解这样使用的数据在适当情况下可以互换,以便这里描述的实施例能够以除了在这里图示或描述的内容以外的顺序实施。此外,术语“包括”和“具有”以及他们的任何变形,意图在于覆盖不排他的包含,例如,包含了一系列步骤或单元的过程、方法、系统、产品或设备不必限于清楚地列出的那些步骤或单元,而是可包括没有清楚地列出的或对于这些过程、方法、产品或设备固有的其它步骤或单元。
所属领域的技术人员可以清楚地了解到,为描述的方便和简洁,上述描述的系统,装置和单元的具体工作过程,可以参考前述方法实施例中的对应过程,在此不再赘述。
在本申请所提供的几个实施例中,应该理解到,所揭露的系统,装置和方法,可以通过其它的方式实现。例如,以上所描述的装置实施例仅仅是示意性的,例如,单元的划分,仅仅为一种逻辑业务划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另一点,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口,装置或单元的间接耦合或通信连接,可以是电性,机械或其它的形式。
作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部单元来实现本实施例方案的目的。
另外,在本申请各个实施例中的各业务单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用软件业务单元的形式实现。
集成的单元如果以软件业务单元的形式实现并作为独立的产品销售或使用时,可以存储在一个计算机可读取存储介质中。基于这样的理解,本申请的技术方案的全部或部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)执行本申请各个实施例方法的全部或部分步骤。而前述的存储介质包括:U盘、移动硬盘、ROM、RAM,Random Access Memory、磁碟或者光盘等各种可以存储程序代码的介质。
本领域技术人员应该可以意识到,在上述一个或多个示例中,本申请所描述的业务可以用硬件、软件、固件或它们的任意组合来实现。当使用软件实现时,可以将这些业务存储在计算机可读介质中或者作为计算机可读介质上的一个或多个指令或代码进行传输。计算机可读介质包括计算机存储介质和通信介质,其中通信介质包括便于从一个地方向另一个地方传送计算机程序的任何介质。存储介质可以是通用或专用计算机能够存取的任何可用介质。
以上的具体实施方式,对本申请的目的、技术方案和有益效果进行了进一步详细说明,所应理解的是,以上仅为本申请的具体实施方式而已。
以上,以上实施例仅用以说明本申请的技术方案,而非对其限制;尽管参照前述实施例对本申请进行了详细的说明,本领域的普通技术人员应当理解:其依然可以对前述各实施例所记载的技术方案进行修改,或者对其中部分技术特征进行等同替换;而这些修改或者替换,并不使相应技术方案的本质脱离本申请各实施例技术方案的范围。

Claims (18)

  1. 一种数据传输的方法,其特征在于,包括:
    生成第一组播安全参数,所述第一组播安全参数包括组播全局帧号GGFN的第一比特序列,所述第一比特序列由第一组播组的节点在本地维护,所述第一组播安全参数用于组播的加密传输和/或完整性保护;
    向第一节点发送所述第一组播安全参数,所述第一组播组的节点包括所述第一节点。
  2. 根据权利要求1所述的方法,其特征在于,
    一个所述第一组播安全参数对应所述第一组播组的一个逻辑信道;或者,
    一个所述第一组播安全参数对应所述第一组播组的多个逻辑信道。
  3. 根据权利要求1或2所述的方法,其特征在于,所述第一比特序列包括高帧号。
  4. 根据权利要求1至3任一项所述的方法,其特征在于,所述第一组播安全参数还包括所述GGFN的第二比特序列,所述第二比特序列包括以下一项或多项:
    链路控制层序列号SN;或者,
    物理层超帧号和无线帧编号。
  5. 根据权利要求1至4任一项所述的方法,其特征在于,还包括:
    接收第一消息,所述第一消息包括所述第一节点的身份标识ID;
    所述生成第一组播安全参数包括:
    根据所述第一消息,生成所述第一组播安全参数。
  6. 根据权利要求2所述的方法,其特征在于,还包括:
    若存在第一组密钥,则获取所述第一组播安全参数,所述第一组密钥是所述第一组播组的组密钥;
    若生成所述第一组密钥,则将所述第一组播安全参数置零。
  7. 根据权利要求1至6任一项所述的方法,其特征在于,所述向第一节点发送所述第一组播安全参数包括:
    通过关联建立消息,向所述第一节点发送所述第一组播安全参数;或者,
    通过配置消息,向所述第一节点发送所述第一组播安全参数。
  8. 一种数据传输的方法,其特征在于,包括:
    接收第一组播安全参数,所述第一组播安全参数包括组播全局帧号GGFN的第一比特序列,所述第一比特序列由第一组播组的节点在本地维护,所述第一组播安全参数用于组播的加密传输和/或完整性保护。
  9. 根据权利要求8所述的方法,其特征在于,
    一个所述第一组播安全参数对应所述第一组播组的一个逻辑信道;或者,
    一个所述第一组播安全参数对应所述第一组播组的多个逻辑信道。
  10. 根据权利要求8或9所述的方法,其特征在于,所述第一比特序列包括高帧号。
  11. 根据权利要求8至10任一项所述的方法,其特征在于,所述第一组播安全参数还包括所述GGFN的第二比特序列,所述第二比特序列包括以下一项或多项:
    链路控制层序列号SN;或者,
    物理层超帧号和无线帧编号。
  12. 根据权利要求8至11任一项所述的方法,其特征在于,还包括:
    发送第一消息,所述第一消息包括所述第一节点的身份标识ID。
  13. 根据权利要求8至12任一项所述的方法,其特征在于,所述接收第一组播安全参数包括:
    通过关联建立消息,接收所述第一组播安全参数;或者,
    通过配置消息,接收所述第一组播安全参数。
  14. 一种通信装置,其特征在于,所述通信装置包括用于执行根据权利要求1至7任一项所述的方法的模块,或者包括用于执行权利要求8至13任一项所述的方法的模块。
  15. 一种通信装置,其特征在于,所述通信装置包括处理器,所述处理器被配置为执行权利要求1至7中任一项所述的方法,或者被配置为执行权利要求8至13任一项所述的方法。
  16. 一种通信装置,其特征在于,包括:输入输出接口和逻辑电路,所述输入输出接口,用于实现获取输入信息或输出信息中的至少一项;所述逻辑电路用于执行权利要求1至7中任一项所述的方法,或,执行权利要求8至13中任一项所述的方法。
  17. 一种计算机可读存储介质,其特征在于,所述计算机可读存储介质包括指令,当所述指令被运行时,使得权利要求1至7中任一项所述的方法被实现,或者使得权利要求8至13任一项所述的方法被实现。
  18. 一种计算机程序产品,其特征在于,所述计算机程序产品包括指令,当所述指令被运行时,使得权利要求1至7中任一项所述的方法被实现,或者使得权利要求8至13任一项所述的方法被实现。
PCT/CN2025/101525 2024-07-02 2025-06-17 一种数据传输的方法和装置 Pending WO2026007686A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202410881419.6 2024-07-02
CN202410881419.6A CN121284540A (zh) 2024-07-02 2024-07-02 一种数据传输的方法和装置

Publications (1)

Publication Number Publication Date
WO2026007686A1 true WO2026007686A1 (zh) 2026-01-08

Family

ID=98224598

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2025/101525 Pending WO2026007686A1 (zh) 2024-07-02 2025-06-17 一种数据传输的方法和装置

Country Status (2)

Country Link
CN (2) CN121284540A (zh)
WO (1) WO2026007686A1 (zh)

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102655452A (zh) * 2011-03-04 2012-09-05 中兴通讯股份有限公司 一种组安全联盟的生成方法及装置
CN103888249A (zh) * 2013-12-04 2014-06-25 中国人民武装警察部队工程大学 组播通信用代理重加密方法
WO2021221329A1 (ko) * 2020-04-28 2021-11-04 삼성전자 주식회사 무결성 검사를 수행하는 전자 장치 및 그 동작 방법
CN117979285A (zh) * 2022-10-24 2024-05-03 华为技术有限公司 一种数据传输方法及装置

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102655452A (zh) * 2011-03-04 2012-09-05 中兴通讯股份有限公司 一种组安全联盟的生成方法及装置
CN103888249A (zh) * 2013-12-04 2014-06-25 中国人民武装警察部队工程大学 组播通信用代理重加密方法
WO2021221329A1 (ko) * 2020-04-28 2021-11-04 삼성전자 주식회사 무결성 검사를 수행하는 전자 장치 및 그 동작 방법
CN117979285A (zh) * 2022-10-24 2024-05-03 华为技术有限公司 一种数据传输方法及装置

Also Published As

Publication number Publication date
CN121284542A (zh) 2026-01-06
CN121284540A (zh) 2026-01-06

Similar Documents

Publication Publication Date Title
US7983615B2 (en) Configuring and connecting to a media wireless network
US20160286395A1 (en) Apparatus, system and method of securing communication between wireless devices
CN108886685B (zh) 一种终端匹配方法、装置
KR20230118849A (ko) 멀티 링크 피어 투 피어 통신을 위한 통신 장치 및 통신 방법
CN107113898A (zh) 用于使用pc5协议的直接通信的系统、方法和设备
JP2018526869A (ja) 暗号化されたクライアントデバイスコンテキストを用いたネットワークアーキテクチャおよびセキュリティ
CN108990048B (zh) 确定终端设备的标识的方法和装置
CN113841366B (zh) 通信方法及装置
CN116963054B (zh) Wlan多链路tdls密钥导出
WO2022027476A1 (zh) 密钥管理方法及通信装置
US20230308864A1 (en) Wireless communication method, apparatus, and system
CN115604700A (zh) 基于Wi-Fi感知的配网方法、嵌入式芯片系统及介质
JP2016509762A (ja) 通信ネットワークで送信されるペイロードの保護
CN114930887B (zh) 一种密钥管理方法、通信装置
CN105812219A (zh) 帧传递方法以及相关装置和通信系统
WO2023050373A1 (zh) 一种通信方法、装置及系统
CN103200191B (zh) 通信装置和无线通信方法
US20170070343A1 (en) Unicast key management across multiple neighborhood aware network data link groups
WO2026007686A1 (zh) 一种数据传输的方法和装置
WO2024131561A1 (zh) 通信认证方法和装置
WO2022237794A1 (zh) 一种报文传输方法及装置
CN109391532B (zh) 一种无线传输装置、无线传输方法及计算机可读存储介质
CN115696636B (zh) 建立直连链路的方法、装置、设备及存储介质
WO2024114205A1 (zh) 密钥协商方法及装置
WO2025256589A1 (zh) 一种数据处理方法、装置、芯片及模组设备

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 25832040

Country of ref document: EP

Kind code of ref document: A1