IP Library › Granted Patent US 11,025,645
Granted Patent B2
US 11,025,645 · App. 16/540,695 · Granted Jun 1, 2021

Data integrity protection method and apparatus

Inventors: Chong Lou (Shanghai, CN); Qufang Huang (Shanghai, CN); Xing Liu (Shenzhen, CN)
Assignee: Huawei Technologies Co., Ltd.
H04L63/123H04L63/0428H04W12/102H04W12/106
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,025,645
App. No.
16/540,695
Granted
Jun 1, 2021
Kind
B2
Abstract

A data integrity protection method and apparatus in a network environment are described. A terminal device obtains an integrity protection algorithm and a key corresponding to a session or a flow, and a DRB corresponding to the session. The terminal device performs, by using the integrity protection algorithm and the key corresponding to the session, integrity protection on data of the DRB corresponding to the session or the flow, where one session includes a plurality of flows. Different integrity protection algorithms and keys can be used for different sessions, and different integrity protection algorithms and keys can also be used for different flows. In this way, integrity protection is more flexible and meets security requirements of a same user for different services.

Claims (47)

1. A data integrity protection method carried out by a terminal device, the method comprising:

sending a first message to an access network device, wherein the first message is a request to establish a session;

receiving a second message from the access network device, wherein the second message comprises:

an identifier of the session, and an identifier of a first data radio bearer (DRB) corresponding to the session; and

performing an integrity protection on a data of the first DRB by using a first integrity protection algorithm corresponding to the session and a first key corresponding to the session, wherein the data is a user plane data of an air interface between the access network device and the terminal device, wherein the session corresponds to a plurality of DRBs including the first DRB, wherein the first integrity protection algorithm and the first key are used for each one of the plurality of DRBs corresponding to the session, and wherein the second message comprises a first protocol layer configuration, wherein the first protocol layer configuration comprises the identifier of the session, and wherein the first protocol layer processes a mapping from a flow to a DRB of the plurality of DRBs including the first DRB.

2. The method according to claim 1 , wherein the second message further comprises:

a first indication,

wherein the first indication indicates, to the terminal device, whether to enable an integrity protection function or not.

3. The method according to claim 2 , wherein the second message comprises a Packet Data Convergence Protocol (PDCP) layer configuration, and wherein the PDCP layer configuration comprises the first indication.

4. The method according to claim 1 , wherein the second message further comprises:

a second indication,

wherein the second indication indicates, to the terminal device, a protocol layer where the integrity protection is performed.

5. The method according to claim 1 , wherein the data of the DRB is a PDCP layer data packet.

6. An apparatus, comprising at least one processor and a memory coupled to the at least one processor, the at least one processor being configured to:

send a first message to an access network device, wherein the first message is a request to establish a session;

receive a second message from the access network device, wherein the second message comprises an identifier of the session, an identifier of a first data radio bearer (DRB) corresponding to the session; and

perform an integrity protection on a data of the first DRB by using a first integrity protection algorithm corresponding to the session and a first key corresponding to the session, wherein the data is a user plane data of an air interface between the access network device and the terminal device, wherein the session corresponds to a plurality of DRBs including the first DRB, wherein the first integrity protection algorithm and the first key are used for each one of the plurality of DRBs corresponding to the session, and wherein the second message comprises a first protocol layer configuration, wherein the first protocol layer configuration comprises the identifier of the session, and wherein the first protocol layer processes a mapping from a flow to a DRB of the plurality of DRBs including the first DRB.

7. The apparatus according to claim 6 , wherein the second message further comprises:

a first indication,

wherein the first indication indicates whether to enable an integrity protection function or not.

8. The apparatus according to claim 7 , wherein the second message comprises a Packet Data Convergence Protocol (PDCP) layer configuration, and wherein the PDCP layer configuration comprises the first indication.

9. The apparatus according to claim 6 , wherein the second message further comprises:

a second indication,

wherein the second indication is used to indicate a protocol layer where the integrity protection is performed.

10. The apparatus according to claim 6 , wherein the data of the DRB is a PDCP layer data packet.

11. An apparatus comprising a transceiver and a processor, wherein:

the transceiver is configured to send a first message to an access network device, wherein the first message is a request to establish a session;

the transceiver is further configured to receive a second message from the access network device, wherein the second message comprises an identifier of the session, an identifier of a first data radio bearer (DRB) corresponding to the session; and

the processor is configured to perform an integrity protection on a data of the first DRB by using a first integrity protection algorithm corresponding to the session and a first key corresponding to the session, wherein the data is a user plane data of an air interface between the access network device and the terminal device, wherein the session corresponds to a plurality of DRBs including the first DRB, wherein the first integrity protection algorithm and the first key are used for each one of the plurality of DRBs corresponding to the session, and wherein the second message comprises a first protocol layer configuration, wherein the first protocol layer configuration comprises the identifier of the session, and wherein the first protocol layer processes a mapping from a flow to a DRB of the plurality of DRBs including the first DRB.

12. The apparatus according to claim 11 , wherein the second message further comprises:

a first indication,

wherein the first indication indicates whether to enable an integrity protection function or not.

13. The apparatus according to claim 12 , wherein the second message comprises a Packet Data Convergence Protocol (PDCP) layer configuration, and the PDCP layer configuration comprises the first indication.

14. The apparatus according to claim 11 , wherein the second message further comprises:

a second indication,

wherein the second indication indicates a protocol layer where the integrity protection is performed.

15. The apparatus according to claim 11 , wherein the data of the DRB is a PDCP layer data packet.

16. A non-transitory computer-readable storage medium, comprising a program, wherein when being executed by a processor, the following steps are performed:

sending a first message to an access network device, wherein the first message is used to request to establish a session;

receiving a second message from the access network device, wherein the second message comprises an identifier of the session, an identifier of a first data radio bearer (DRB) corresponding to the session; and

performing an integrity protection on a data of the first DRB by using a first integrity protection algorithm corresponding to the session and a first key corresponding to the session, wherein the data is a user plane data of an air interface between the access network device and the terminal device, wherein the session corresponds to a plurality of DRBs including the first DRB, wherein the first integrity protection algorithm and the first key are used for the plurality of DRBs corresponding to the session, and wherein the second message comprises a first protocol layer configuration, wherein the first protocol layer configuration comprises the identifier of the session, and wherein the first protocol layer processes a mapping from a flow to a DRB of the plurality of DRBs including the first DRB.

17. The method according to claim 1 , wherein the second message comprises integrity protection algorithm and the key corresponding to the session; or

the integrity protection algorithm and the key corresponding to the session are configured in advance in the terminal device.

18. The apparatus according to claim 6 , wherein the second message comprises integrity protection algorithm and the key corresponding to the session; or

the integrity protection algorithm and the key corresponding to the session are configured in advance in the terminal device.

19. The apparatus according to claim 11 , wherein the second message comprises integrity protection algorithm and the key corresponding to the session; or

the integrity protection algorithm and the key corresponding to the session are configured in advance in the terminal device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 19, 2020
From: LOU, CHONG; HUANG, QUFANG; LIU, XING
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 051863/0417 →
Priority Claims (1)
CN 201710686855.8 · Aug 11, 2017 · national
Continuity (2)
Continuation PCTCN2018099916 · Aug 10, 2018
Related Publication 20190372995A1 · Dec 5, 2019