A method, system and related device for updating key in satellite communication system

By using the time-based key generation method in the Beidou communication system, the problem of lack of authentication and encryption in the Beidou short message communication system is solved, and the security of data transmission and resource conservation are achieved.

CN115696322BActive Publication Date: 2025-09-26HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110924080.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-07-31
Filing Date
2021-08-12
Publication Date
2025-09-26
Estimated Expiration
2041-08-12

AI Technical Summary

Technical Problem

The Beidou short message communication system lacks an effective authentication and encryption mechanism, resulting in insecure data transmission. In addition, the authentication and encryption mechanism of the cellular network is complicated and cannot be effectively applied in the Beidou communication system.

Method used

Terminals and Beidou network devices generate keys based on time, and use the time indication field and encryption indication field to generate and update encryption keys to achieve data transmission security and avoid additional signaling interactions.

Benefits of technology

The security of data transmission is achieved in the Beidou communication system, which saves resources and simplifies the authentication process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115696322B_ABST
    Figure CN115696322B_ABST
Patent Text Reader

Abstract

The present application discloses a key updating method, system and related devices in a satellite communication system. The present application relates to the field of satellite communications. A sending device can generate a key based on the sending time. The sending device can use the key to encrypt the original data and add a time indication field before the encrypted original data to obtain an application layer message. The time indication field can be used to indicate the sending time. The sending device can send the application layer message including the time indication field to the receiving device. The receiving device can determine the sending time based on the receiving time and the time indication field, and obtain the key based on the sending time. The receiving device can use the key to decrypt the application layer message to obtain the original data. In this way, the sending device and the receiving device can encrypt the data using the key updated over time when transmitting data, which not only saves the resources of the Beidou communication system but also ensures the security of the data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of satellite communications, and in particular to a key updating method, system and related devices in a satellite communication system. Background Art

[0002] The BeiDou short message service (BMS) is a key feature of the BeiDou satellite navigation system, distinguishing it from other global positioning and navigation systems, such as the US Global Positioning System (GPS) and Russia's Global Navigation Satellite System (GLONASS). It is particularly suitable for positioning and communication in areas such as oceans, deserts, grasslands, and uninhabited areas where mobile communications are not available, cannot be reached, or are otherwise disrupted. The BMS communication system has undergone technical upgrades, and some essential resources have been made available for civilian use. The communication protocol needs to be designed based on the specific characteristics of the BMS communication system, specifically those used for civilian services and equipment.

[0003] The Beidou communication system provides services including message communication, location reporting, and emergency rescue. Message communication enables communication with other devices. Location reporting allows for sharing positioning information. Emergency rescue allows for direct connection to emergency rescue centers for assistance. Because both message communication and location reporting services are forwarded through the operator's short message center, mutual authentication is required between the terminal and the operator to ensure information security. However, the Beidou short message service communication system currently lacks an authentication and encryption mechanism for civilian terminals.

[0004] Although cellular networks have mature authentication and encryption mechanisms, they are complex and require a lot of air interface resources for interactive signaling. Due to the long latency and limited air interface resources of the Beidou communication system, it cannot support cellular network authentication and encryption mechanisms. Summary of the Invention

[0005] The present application provides a key update method, system and related devices in a Beidou communication system, which realizes the key update of data transmission between terminals and Beidou network devices in the Beidou communication system, ensuring the security of data transmission.

[0006] In a first aspect, the present application provides a key update method in a Beidou communication system, comprising: a terminal generates a first key based on a user identification code IMSI, an identity identification key Ki, and the sending time of a first application layer message. The terminal uses the first key to encrypt first original data to obtain first encrypted data. The terminal adds message header information to the first encrypted data to obtain a first application layer message. The message header information includes a time indication field and an encryption indication field, the encryption indication field is used to indicate a preset encryption algorithm used when encrypting the first original data, and the time indication field is used to indicate the sending time information of the first application layer message. The terminal sends the first application layer message to the Beidou network device.

[0007] This application provides a key update method for the Beidou communication system, enabling terminals to update the key used to encrypt data based on time. This allows terminals and Beidou network devices to encrypt and decrypt data using the key updated over time during data transmission. Key generation does not require additional signaling interaction, conserving Beidou communication system resources while ensuring data security.

[0008] In a possible implementation, the sending time of the first application layer message is a first time point or a second time point; wherein the first time point is the time point when the terminal obtains the first original data, and the second time point is the time point obtained when the terminal generates the first key.

[0009] In one possible implementation, the terminal generates a first key based on the user identification code (IMSI), the identity identification key (Ki), and the time when the first application layer message was sent. Specifically, the terminal obtains a random number (RAND) based on the time and IMSI of sending the first application layer message. The terminal obtains an encryption key (Kc) using a preset key algorithm 1 based on RAND and a preset Ki, and obtains an authentication symbol response (SRES) using a preset key algorithm 2. The terminal obtains the first key based on Kc and SRES using a preset key algorithm 3.

[0010] In a possible implementation, before the terminal uses the first key to encrypt the first original data, the method further includes: the terminal may also compress the first original data.

[0011] In one possible implementation, after the terminal sends the first application layer message to the Beidou network device, the method further includes: the terminal receives the first application layer receipt sent by the Beidou network device, and the first application layer receipt is used to indicate that the Beidou network device has successfully decrypted the first application layer message.

[0012] In one possible implementation, after the terminal sends a first application layer message to the Beidou network device, the method also includes: the terminal generates a third key based on IMSI, Ki and the sending time of the second application layer message; the terminal uses the third key to encrypt the second original data to obtain second encrypted data; the terminal adds message header information to the second encrypted data to obtain a second application layer message; wherein the message header information includes a time indication field and an encryption indication field, the encryption indication field is used to indicate the preset encryption algorithm used when encrypting the second original data, and the time indication field is used to indicate the sending time information of the second application layer message; the terminal sends the second application layer message to the Beidou network device; the terminal receives the second application layer receipt sent by the Beidou network device, and the second application layer receipt is used to indicate that the Beidou network device failed to decrypt the second application layer message.

[0013] In a possible implementation, the terminal determines that the sending time of the first application layer message is the same as the sending time of the second application layer message, and the terminal directly uses the first key to encrypt the second original data to obtain second encrypted data.

[0014] Optionally, the terminal directly uses the time indication field of the first application layer message as the time indication field of the second application layer message.

[0015] In a possible implementation, after the terminal receives the second application layer receipt sent by the Beidou network device, the method further includes: the terminal retransmitting the second application layer message.

[0016] In a possible implementation, after the terminal receives the second application layer receipt sent by the Beidou network device, the method further includes: the terminal displays failure prompt information, where the failure prompt information is used to indicate that the Beidou network device fails to decrypt the second application layer message.

[0017] In a possible implementation, the value of the time indication field is used to indicate the parity value of the sending time of the first application layer message.

[0018] In a second aspect, the present application provides another key update method in a Beidou communication system, comprising: a Beidou network device receives a first application layer message sent by a terminal. The first application layer message includes first encrypted data and message header information, the message header information includes a time indication field and an encryption indication field, the encryption indication field is used to indicate the preset encryption algorithm used when encrypting the first original data, and the time indication field is used to indicate the sending time information of the first application layer message. The Beidou network device generates a second key through a cellular network device based on the time indication field and the reception time of the first application layer message. The Beidou network device successfully decrypts the encrypted data using the second key to obtain the first original data.

[0019] In one possible implementation, the Beidou network device generates a second key through the cellular network device based on the time indication field and the reception time of the first application layer message, specifically including: the Beidou network device determines the sending time of the first application layer message based on the time indication field and the reception time of the first application layer message; the Beidou network device obtains a random number RAND based on the sending time of the first application layer message and the user identification code IMSI obtained from the cellular network device; the Beidou network device sends the RAND to the cellular network device; the Beidou network device obtains the encryption key Kc and authentication symbol response SRES fed back by the cellular network device; the terminal obtains the second key based on Kc and SRES through the preset key algorithm 3.

[0020] In one possible implementation, the reception time of the first application layer message is a specified time point between the third time point and the fourth time point, and the unit of the reception time of the first application layer message is hours; wherein, the third time point is the time point when the Beidou network device receives the first satellite link control layer protocol data unit SLCPDU of the first application layer message, and the fourth time point is the time point obtained when the Beidou network device generates the second key.

[0021] In a possible implementation, the value of the time indication field is used to indicate the parity value of the sending time of the first application layer message.

[0022] In a possible implementation, the Beidou network device determines the sending time of the first application layer message based on the time indication field and the receiving time of the first application layer message, specifically including: when the parity value of the sending time of the first application layer message indicated by the value of the time indication field is the same as the parity value of the receiving time of the first application layer message, the Beidou network device determines that the sending time of the first application layer message is the same as the receiving time of the first application layer message;

[0023] When the parity value of the sending time of the first application layer message indicated by the value of the time indication field is different from the parity value of the receiving time of the first application layer message, the Beidou network device determines that the difference between the receiving time of the first application layer message and the sending time of the first application layer message is 1.

[0024] In one possible implementation, after the Beidou network device successfully decrypts the first encrypted data using the second key and obtains the first original data, the method also includes: the Beidou network device generates a first application layer receipt, and the first application layer receipt is used to indicate that the Beidou network device has successfully decrypted the first application layer message; the Beidou network device sends the first application layer receipt to the terminal.

[0025] In one possible implementation, after the Beidou network device successfully decrypts the first encrypted data using the second key to obtain the first original data, the method also includes: the Beidou network device receives a second application layer message sent by the terminal; wherein the second application layer message includes the second encrypted data and message header information, the message header information includes a time indication field and an encryption indication field, the encryption indication field is used to indicate the preset encryption algorithm used when encrypting the second original data, and the time indication field is used to indicate the sending time information of the second application layer message; the Beidou network device generates a fourth key through the cellular network device based on the time indication field and the reception time of the second application layer message; the Beidou network device fails to decrypt the second encrypted data using the fourth key, and the Beidou network device generates a second application layer receipt, and the second application layer receipt is used to indicate that the Beidou network device fails to decrypt the second application layer message; the Beidou network device sends the second application layer receipt to the terminal.

[0026] In a possible implementation, the Beidou network device determines that the reception time of the first application layer message is the same as the reception time of the second application layer message, and the Beidou network device directly uses the first key to decrypt the second encrypted data.

[0027] In a third aspect, the present application provides a Beidou communication system, including: a terminal and a Beidou network device; wherein,

[0028] The terminal is configured to generate a first key based on a user identification code IMSI, an identity identification key Ki, and a sending time of a first application layer message.

[0029] The terminal is further configured to encrypt the first original data using the first key to obtain first encrypted data.

[0030] The terminal is further configured to add message header information to the first encrypted data to obtain a first application layer message. The message header information includes a time indication field and an encryption indication field. The encryption indication field is configured to indicate a preset encryption algorithm used when encrypting the first original data. The time indication field is configured to indicate a sending time of the first application layer message.

[0031] The terminal is also used to send the first application layer message to the Beidou network device.

[0032] Beidou network equipment, used to receive the first application layer message sent by the terminal.

[0033] The Beidou network device is further used to generate a second key through the cellular network device based on the time indication field and the reception time of the first application layer message.

[0034] The Beidou network device is further configured to successfully decrypt the first encrypted data using the second key to obtain the first original data.

[0035] In a possible implementation manner, the terminal may also execute the method in any possible implementation manner of the first aspect above.

[0036] In a possible implementation, the Beidou network device may also execute the method in any possible implementation of the second aspect above.

[0037] In a fourth aspect, the present application provides a communication device comprising one or more processors, one or more memories, and a transceiver. The transceiver and the one or more memories are coupled to the one or more processors, the one or more memories being configured to store computer program code, the computer program code comprising computer instructions. When the one or more processors execute the computer instructions, the communication device performs the method of any possible implementation of the first aspect described above.

[0038] The communication device may be a terminal or other product-type equipment.

[0039] In a fifth aspect, the present application provides a communication device comprising one or more processors, one or more memories, and a transceiver. The transceiver and the one or more memories are coupled to the one or more processors, the one or more memories being configured to store computer program code, the computer program code comprising computer instructions. When the one or more processors execute the computer instructions, the communication device performs the method of any possible implementation of the second aspect described above.

[0040] The communication device may be a Beidou network device, or any network element or a combination of multiple network elements in the Beidou network device.

[0041] In a sixth aspect, the present application provides a computer storage medium comprising computer instructions, which, when executed on a computer, enable the computer to execute the method in any possible implementation of the first aspect.

[0042] In a seventh aspect, the present application provides a computer storage medium comprising computer instructions, which, when executed on a computer, enable the computer to execute the method in any possible implementation of the second aspect.

[0043] In an eighth aspect, the present application provides a computer program product, which, when executed on a computer, enables the computer to execute the method in any possible implementation of the first aspect.

[0044] In a ninth aspect, the present application provides a computer program product, which, when executed on a computer, enables the computer to execute the method in any possible implementation of the second aspect.

[0045] In the tenth aspect, the present application provides a chip or chip system, which is applied to a terminal, including a processing circuit and an interface circuit, the interface circuit is used to receive code instructions and transmit them to the processing circuit, and the processing circuit is used to run the code instructions to execute the method in any possible implementation of the first aspect above. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] Figure 1 A schematic diagram of a process for authentication and encryption in a cellular network provided in an embodiment of the present application;

[0047] Figure 2 A schematic diagram of the architecture of a Beidou communication system provided in an embodiment of the present application;

[0048] Figure 3A A schematic diagram of a protocol encapsulation architecture for inbound data of a Beidou communication system provided in an embodiment of the present application;

[0049] Figure 3B A schematic diagram of a protocol parsing architecture for inbound data of a Beidou communication system provided in an embodiment of the present application;

[0050] Figure 4A A schematic diagram of a protocol encapsulation architecture for outbound data of a Beidou communication system provided in an embodiment of the present application;

[0051] Figure 4B A schematic diagram of a protocol parsing architecture for outbound data of a Beidou communication system provided in an embodiment of the present application;

[0052] Figure 5 A flowchart of a method for updating a key during inbound transmission in a Beidou communication system provided in an embodiment of the present application;

[0053] Figure 6 A schematic diagram of the structure of a terminal provided in an embodiment of the present application;

[0054] Figure 7 A schematic diagram of an application layer message provided in an embodiment of the present application;

[0055] Figure 8 A flowchart of a method for updating a key during outbound transmission in a Beidou communication system provided in an embodiment of the present application;

[0056] Figure 9 A schematic diagram of a hardware structure provided in an embodiment of the present application;

[0057] Figure 10 A flowchart of a method for controlling inbound transmission in a Beidou communication system provided in an embodiment of the present application;

[0058] Figure 11A schematic structural diagram of a communication device provided in an embodiment of the present application;

[0059] Figure 12 A schematic structural diagram of another communication device provided in an embodiment of the present application;

[0060] Figure 13 A schematic structural diagram of another communication device provided in an embodiment of the present application;

[0061] Figure 14 A schematic diagram of the structure of another communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0062] The following is a clear and detailed description of the technical solutions in the embodiments of the present application, with reference to the accompanying drawings. In the description of the embodiments of the present application, unless otherwise specified, " / " represents the meaning of "or." For example, A / B can represent A or B. "and / or" in the text is merely a description of the association relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone.

[0063] In the following, the terms "first" and "second" are used for descriptive purposes only and should not be understood to imply or suggest relative importance or implicitly indicate the number of the technical features indicated. Therefore, the features defined as "first" and "second" may explicitly or implicitly include one or more of the features. In the description of the embodiments of this application, unless otherwise specified, "plurality" means two or more.

[0064] The following describes an authentication and encryption mechanism in a cellular network provided by an embodiment of the present application.

[0065] For example, Figure 1 As shown, the terminal and the network element device in the cellular network (also known as a cellular network device) can first perform a mutual authentication step. Only after the identities of both parties are confirmed through authentication can the data encryption transmission step be performed. The cellular network device may include but is not limited to a mobile switching center (MSC), a visiting location register (VLR), a home location register (HLR), and an authentication center (AuC). The steps for the terminal and the cellular network device to authenticate and generate a key are as follows:

[0066] S101: The terminal sends a service request to the MSC / VLR.

[0067] The service request may include a user identification (ID) number of the terminal.

[0068] S102, the MSC / VLR sends the international mobile subscriber identity (IMSI) of the terminal to the HLR / AuC.

[0069] After receiving the service request from the terminal, the MSC / VLR can look up the IMSI corresponding to the terminal based on the terminal's ID number. The MSC / VLR can send the IMSI to the HLR / AuC.

[0070] S103, HLR / AuC can generate a random number (RAND), obtain the corresponding identity identification key (Ki) through IMSI, and generate a signed authentication response (SRES) (1) and an encryption key (Kc) (1) through RAND and Ki.

[0071] After receiving the IMSI, the HLR / AuC can generate authentication parameters. The authentication parameters may include but are not limited to RAND, SRES, and Kc. The HLR / AuC can generate RAND through a random number generator. The HLR / AuC can obtain the corresponding Ki through the IMSI. The HLR / AuC can calculate SRES (1) and Kc (1) based on Ki and RAND through a preset key algorithm. Ki is an identity identification key, which is stored in the subscriber identity module (SIM) card and the network element device in the cellular network and can be used to calculate the encryption key and the authentication symbol response. SRES can be used for authentication. Kc is used to encrypt data. After successful authentication, the terminal and the cellular network device can use Kc to encrypt and decrypt data to ensure data security.

[0072] S104, HLR / AuC may send RAND, SRES(1) and Kc(1) to MSC / VLR.

[0073] S105: The MSC / VLR may send an authentication request to the terminal, where the authentication request includes RAND.

[0074] After receiving the authentication parameters fed back by the HLR / AuC, the MSC / VLR may send an authentication request to the terminal, wherein the authentication request may include RAND.

[0075] S106: The terminal may generate SRES(2) and Kc(2) through the SIM card based on the received RAND.

[0076] After receiving the authentication request, the terminal can transfer the RAND to the SIM card. The SIM card stores the Ki obtained when the terminal opened an account in the cellular network. The terminal can calculate SRES (2) and Kc (2) based on the RAND and the preset Ki using the preset key algorithm on the SIM card. The Ki and preset key algorithm in the SIM card are the same as those in the HLR / AuC.

[0077] S107, the terminal sends an authentication response to the MSC / VLR, where the authentication response includes SRES (2).

[0078] After the terminal calculates and obtains SRES(2), it may reply an authentication response to the MSC / VLR, where the authentication response includes SRES(2).

[0079] S108, MSC / VLR may determine whether SRES (1) and SRES (2) are the same.

[0080] If SRES(1) and SRES(2) are the same, authentication is successful, and MSC / VLR can send the result of the service request encrypted based on Kc(1) to the terminal; if SRES(1) and SRES(2) are different, authentication fails, and MSC / VLR does not respond to the terminal's service request.

[0081] Specifically, the terminal can encrypt data using its Kc and then send the encrypted data to the cellular network device. The cellular network device can decrypt the data using its Kc. The cellular network device can encrypt data using its Kc and then send the encrypted data to the terminal. The terminal can decrypt the data using its Kc.

[0082] In summary, both the terminal and the cellular network device must perform authentication before data transmission. Cellular network authentication is complex and requires significant air interface resources for signaling. Due to the long latency and limited air interface resources of the Beidou communication system, it cannot support cellular network authentication and encryption mechanisms.

[0083] An embodiment of the present application provides a key update method in a Beidou communication system. A sending device can generate a key based on the sending time. The sending device can use the key to encrypt the original data, and add a message header information including a time indication field before the encrypted original data to obtain an application layer message. The time indication field can be used to indicate the sending time. The sending device can send the application layer message including the time indication field to a receiving device. The receiving device can determine the sending time based on the receiving time and the time indication field, and obtain the key based on the sending time. The receiving device can use the key to decrypt the application layer message to obtain the original data. In this way, the sending device and the receiving device can encrypt the data using the key updated over time when transmitting data, which not only saves the resources of the Beidou communication system but also ensures the security of the data.

[0084] The following introduces a Beidou communication system 10 provided in an embodiment of the present application.

[0085] like Figure 2 As shown, the Beidou communication system 10 may include but is not limited to a terminal 100, a Beidou short message satellite 21, a Beidou network device 200, a cellular network device 400, a terminal 300, and the like.

[0086] Beidou network terminal 100 can send a Beidou short message to cellular network terminal 300. Specifically, terminal 100 can first send the Beidou short message to Beidou short message satellite 21. Beidou short message satellite 21 only relays the Beidou short message sent by terminal 100 and directly forwards it to Beidou network device 200 on the ground. Beidou network device 200 can parse the Beidou short message forwarded by the satellite according to the Beidou communication protocol and forward the message content parsed from the Beidou short message to cellular network device 400. Cellular network device 400 can then forward the message content to terminal 300 via a traditional cellular communication network.

[0087] The cellular network terminal 300 can also send a Beidou short message to the Beidou network terminal 100. The terminal 300 can send the short message to the short message center 25 via the traditional cellular communication network. The short message center 25 can forward the short message from the terminal 300 to the Beidou network device 200. The Beidou network device 200 can relay the short message from the terminal 300 to the terminal 100 via the Beidou short message satellite 21.

[0088] Optionally, the BeiDou communication system 10 may further include an emergency rescue platform and an emergency rescue center. The BeiDou network device 200 may send the emergency rescue message sent by the terminal 100 to the emergency rescue center via the emergency rescue platform.

[0089] Among them, the above-mentioned Beidou network equipment 200 may include but is not limited to the Beidou ground transceiver station 22, the Beidou central station 23 and the Beidou short message fusion communication platform 24. Among them, the Beidou ground transceiver station 22 may include one or more devices with a sending function and one or more devices with a receiving function, or may include one or more devices with a sending function and a receiving function, which is not limited here. The Beidou ground transceiver station 22 can be used for the Beidou network equipment 200 to process data at the physical layer (physical layer protocol, PHY). The Beidou central station 23 can be used for the Beidou network equipment 200 to process data at the satellite link control layer (satellite link control protocol, SLC) layer and the message data convergence protocol (message data convergence protocol, MDCP). The Beidou short message fusion communication platform 24 can be used for the data processing function at the application layer (application layer protocol, APP).

[0090] The cellular network device 400 may include, but is not limited to, a short message service center (SMSC) 25, a home location register (HLR) 28, and a business and operation support system (BOSS) 29. The short message service center 25 may be used to forward data sent by the Beidou network device 200 to a terminal in the cellular network, and may also be used to forward data from the cellular network to the Beidou network device 200.

[0091] The telecommunications service operation support system 29 can be used to open a terminal account. During account opening, the telecommunications service operation support system 29 can store data such as the terminal's (e.g., terminal 100) ID number and IMSI. The ID number can be the terminal's mobile phone number. The IMSI can also be used to calculate a cryptographic key.

[0092] The home location register 28 pre-stores Ki and a preset key algorithm corresponding to the ID number. The home location register 28 can calculate SRES and Kc based on Ki and RAND using the preset key algorithm. The Ki and preset key algorithm (e.g., A3 or A8 algorithm) in the SIM card and cellular network device 400 are the same. SRES and Kc can be used to calculate the key.

[0093] It should be noted that, in the Beidou communication system, the process of the terminal 100 sending data to the Beidou network device 200 is inbound, and the process of the Beidou network device 200 sending data to the terminal 100 is outbound.

[0094] Next, a protocol architecture for inbound data of a Beidou communication system 10 provided in an embodiment of the present application is introduced.

[0095] Figure 3A A schematic diagram of a protocol encapsulation architecture for inbound data of a Beidou communication system 10 provided in an embodiment of the present application is shown.

[0096] like Figure 3A As shown, the Beidou message transmission protocol layer on the terminal 100 can be divided into an application layer, a message data aggregation layer, a satellite link control layer and a physical layer.

[0097] When the terminal 100 sends data to the BeiDou network device 200, the workflow of the BeiDou message transmission protocol on the terminal 100 may be as follows:

[0098] Terminal 100 can generate a key based on the sending time (also known as the sending time) of the application layer message and use the key to encrypt the original data to obtain encrypted data. The encrypted data is then preceded by message header information to obtain the application layer message. The original data may include, but is not limited to, data (e.g., text data, image data, audio data, video data, etc.) input by the calling user (e.g., the user of terminal 100), an indication of the number of called users (e.g., the called user may include the user of terminal 300), the called user's ID, and the location information of terminal 100.

[0099] The application layer message may be sent at a specified time point between the first time point and the second time point (including both the first time point and the second time point), which is not limited in this application. The first time point is the time point at which the terminal 100 obtains the original data. For example, the time point at which the terminal 100 obtains the original data may be the time point at which the terminal 100 receives the input of the Beidou short message sent by the calling user. In this case, the original data includes the data input by the calling user.

[0100] The second time point is the time point obtained when terminal 100 generates the key. Specifically, the second time point can be the current time point obtained by executing a program statement that obtains the sending time of the application layer message when terminal 100 calculates the key (for example, by using the getCurrentTime() function). The unit of the application layer message sending time is hours. It should be noted that terminal 100 must obtain this specified time point before encrypting the original data.

[0101] The message header information may include, but is not limited to, an encryption indication field, a time indication field, and the like. The encryption indication field is used to indicate the type of encryption algorithm used by terminal 100 to encrypt data. The time indication field may be used to indicate transmission time information. Specifically, the value of the time indication field may indicate the parity value of the transmission time T.

[0102] Optionally, before encrypting the original data, the terminal 100 may first compress the original data. It is understood that the message header may also include a compression indication field. The compression indication field may be used to indicate the type of compression algorithm used by the terminal 100 to compress the data.

[0103] Further optionally, the terminal 100 can compress the original data to obtain compressed data. The terminal 100 can add the above-mentioned compression indication field before the compressed data. The compressed data with the compression indication field added is then encrypted using a key to obtain encrypted data. At the MDCP layer, the terminal 100 can obtain the application layer message sent by the APP layer through the inter-layer interface and use the application layer message as an MDCP SDU. At the MDCP layer, the terminal 100 can add padding data (padding) to the end of the MDCP SDU to a specified length and add a redundant length indication field to the MDCP SDU. The redundant length indication field can be used to indicate the length of the padding data. The terminal 100 can split the padding data and the MDCP SDU after adding the redundant length indication field into one or more fixed-length MDCP segment data (M_segment), and add a subsequent indication field to the header of each MDCP segment data to obtain an MDCP PDU. That is, the MDCP PDU includes the M_segment and the subsequent indication field. Among them, the successor indication field can be used to indicate the order of the current MDCPPDU among multiple MDCPPDUs in the same MDCPSDU, or the current MDCPPDU is the only MDCPPDU in the MDCPSDU.

[0104] At the SLC layer, the terminal 100 can obtain the MDCP PDU sent by the MDCP layer through the inter-layer interface as an SLC SDU. At the SLC layer, the terminal 100 can segment the SLC SDU into one or more (for example, 4) fixed-length SLC segment data (S_segment), and add frame header information (also known as frame format indication information) to each S_segment header to obtain the SLC PDU. The frame header information may include but is not limited to a user ID field, a total number of frames field, and a frame sequence number field. The user ID field can be used to indicate the terminal (for example, terminal 100) that generates the SLC PDU. The total number of frames field can be used to indicate the total number of SLC PDUs included in the SLC SDU to which the SLC PDU belongs. The frame sequence number field can be used to indicate the sequence number of the SLC PDU in the SLC SDU to which it belongs.

[0105] At the PHY layer, the terminal 100 can obtain the SLC PDU issued by the SLC layer through the inter-layer interface. The terminal 100 can perform physical layer processing (for example, encoding, pilot insertion, modulation, spread spectrum, etc.) on the SLC PDU to obtain inbound data. The terminal 100 can then send the inbound data to the Beidou short message satellite 21, which will relay it to the Beidou network device 200.

[0106] Figure 3B A schematic diagram of a protocol parsing architecture for inbound data of a Beidou communication system 10 provided in an embodiment of the present application is shown.

[0107] like Figure 3B As shown, the BeiDou message transmission protocol layer on the BeiDou network device 200 can be divided into the application layer, the message data aggregation layer, the satellite link control layer, and the physical layer. The BeiDou network device 200 may include, but is not limited to, a BeiDou ground transceiver station 22, a BeiDou central station 23, and a BeiDou short message fusion communication platform 24. The BeiDou ground transceiver station 22 may be responsible for protocol processing at the PHY layer. The BeiDou central station 23 may be responsible for protocol processing at the SLC and MDCP layers. The BeiDou short message fusion communication platform 24 may be responsible for protocol processing at the APP layer.

[0108] When the terminal 100 sends data to the BeiDou network device 200, the workflow of the BeiDou message transmission protocol on the terminal 100 may be as follows:

[0109] At the PHY layer, the BeiDou network device 200 can obtain inbound data sent by the terminal 100. The BeiDou network device 200 performs physical layer processing (e.g., despreading, demodulation, pilot removal, decoding, etc.) on the inbound data and then presents it to the SLC layer through the inter-layer interface as an SLC PDU of the SLC layer.

[0110] At the SLC layer, the BeiDou network device 200 can concatenate the SLC PDUs of the same SLC SDU belonging to the same terminal into one SLC SDU based on the frame header information of the SLC PDU. The BeiDou network device 200 can present the SLC SDU to the MDCP layer through the inter-layer interface as an MDCP PDU of the MDCP layer.

[0111] At the MDCP layer, the BeiDou network device 200 can concatenate all MDCP PDUs belonging to the same MDCP SDU according to the reception time, and remove the padding data and redundant length indicator field from the concatenated MDCP PDU to obtain an MDCP SDU. The BeiDou network device 200 can present the MDCP SDU to the APP layer through the inter-layer interface as an application layer message received by the APP layer.

[0112] At the APP layer, the BeiDou network device 200 can determine the sending time of the application layer message based on the time indication field in the message header information and the reception time of the application layer message (also known as the reception time), and calculate the key based on the sending time of the application layer message. The BeiDou network device 200 can decrypt the encrypted data in the application layer message using the key to obtain the original data.

[0113] The receiving time of the application layer message may be a specified time point between the third time point and the fourth time point (including the third time point and the fourth time point), which is not limited in the embodiment of the present application. The third time point may be the time point when the Beidou network device 200 receives the first SLC PDU of the application layer message sent by the terminal 100. The fourth time point may be the time point obtained when the Beidou network device 200 generates the key. Specifically, the fourth time point may be the current time point obtained by executing a program statement for obtaining the sending time of the application layer message when the Beidou network device 200 calculates the key (for example, by obtaining the current time function getCurrentTime()). The unit of the receiving time of the application layer message is hours. It should be noted that the Beidou network device 200 must obtain the specified time point before decrypting the encrypted data.

[0114] Optionally, the Beidou network device 200 decrypts the encrypted data to obtain compressed data, and decompresses the compressed data to obtain the authentication code and the original data.

[0115] In the embodiments of the present application, the above-mentioned protocol processing process is only an example, and the present application does not limit the specific operations of the protocol processing.

[0116] Next, a protocol architecture for outbound data of a Beidou communication system 10 provided in an embodiment of the present application is introduced.

[0117] Figure 4A A schematic diagram of a protocol encapsulation architecture for outbound data of a Beidou communication system 10 provided in an embodiment of the present application is shown.

[0118] like Figure 4A As shown, the Beidou message transmission protocol layer on the Beidou network device 200 can be divided into an application layer, a message data aggregation layer, a satellite link control layer and a physical layer.

[0119] When the BeiDou network device 200 sends data to the terminal 100, the workflow of the BeiDou message transmission protocol on the BeiDou network device 200 may be as follows:

[0120] At the APP layer, the Beidou network device 200 can generate a key based on the sending time and use the key to encrypt the original data to obtain encrypted data. The encrypted data is then prepended with message header information to obtain an application layer message. The original data may include, but is not limited to, data sent by a third-party server (e.g., the short message center 25) (e.g., data entered by the called user), text, flag signals, voice, images, animations, etc.

[0121] The sending time of the application layer message may be a specified time point between the fifth time point and the sixth time point (including the fifth time point and the sixth time point), which is not limited in the embodiment of the present application. Among them, the fifth time point is the time point when the Beidou network device 200 obtains the original data. For example, the time point when the Beidou network device 200 obtains the original data may be the time point when the service request information sent by the terminal 100 is received. Exemplarily, the service request information may be a request to download the application layer message, and the receiving device of the application layer message here is the terminal 100. At this time, the original data may be the data entered by the called user. For another example, the time point when the Beidou network device 200 obtains the original data may be the time point when the data sent to the terminal 100 by the cellular network device 400 or other third-party server is received.

[0122] The sixth time point is the time point obtained when the Beidou network device 200 generates the key. Specifically, the sixth time point can be the current time point obtained by executing a program statement that obtains the application layer message sending time when the Beidou network device 200 calculates the key (for example, by using the getCurrentTime() function). The application layer message sending time is expressed in hours. It should be noted that the Beidou network device 200 must obtain this specified time point before encrypting the original data.

[0123] The message header information may include, but is not limited to, an encryption indication field, a time indication field, and the like. The encryption indication field is used to indicate the type of encryption algorithm used by Beidou network device 200 to encrypt data. The time indication field may be used to indicate transmission time information. Specifically, the value of the time indication field may indicate the parity value of the transmission time T.

[0124] Optionally, before encrypting the original data, the Beidou network device 200 may compress the original data. It is understood that the message header may also include a compression indication field. The compression indication field may be used to indicate the type of compression algorithm used by the Beidou network device 200 to compress the data.

[0125] Further optionally, the BeiDou network device 200 may compress the original data to obtain compressed data. The BeiDou network device 200 may add the compression indication field before the compressed data. The compressed data to which the compression indication field is added may then be encrypted using a key to obtain encrypted data.

[0126] At the MDCP layer, the Beidou network device 200 can obtain the application layer message sent by the APP layer through the inter-layer interface and use the application layer message as an MDCP SDU. The Beidou network device 200 can split the MDCP SDU into one or more fixed-length MDCP segments (M_segment) and add a successor indicator field to the header of each MDCP segment to obtain an MDCP PDU. That is, the MDCP PDU includes an M_segment and a successor indicator field. The successor indicator field can be used to indicate the order of the current MDCP PDU within the same MDCP SDU.

[0127] At the SLC layer, the Beidou network device 200 can obtain the MDCP PDU sent by the MDCP layer through the inter-layer interface as an SLC SDU. The Beidou network device 200 can segment the SLC SDU into one or more (for example, 4) fixed-length SLC segment data (S_segment), and add frame header information to each S_segment header to obtain the SLC PDU. The frame header information may include but is not limited to a user ID field, a total number of frames field, and a frame sequence number field. The user ID field can be used to identify the receiving device (for example, the terminal 100), and the value of the user ID field is the ID number of the receiving device. For a detailed description of the total number of frames field and the frame sequence number field, please refer to the embodiment described in 3A above, which will not be repeated here.

[0128] At the PHY layer, the Beidou network device 200 can obtain the SLC PDU issued by the SLC layer through the inter-layer interface as a user frame. The Beidou network device 200 can splice together the user frames (also known as data frames) of multiple users or one user, and add a frame header (such as a version number) and a check bit to obtain a physical frame. The Beidou network device 200 can obtain the coded data of the message branch (S2C-d branch) after performing physical layer processing (for example, encoding, inserting pilots, modulation, spread spectrum, etc.). The Beidou network device 200 can form the pilot coded data of the S2C-d branch and the pilot data (also known as secondary code) of the pilot branch (S2C-p branch), i.e., outbound data. The outbound data is sent to the Beidou short message satellite 21 and relayed to one or more terminals via the Beidou short message satellite 21. It can be understood that the pilot data of the S2C-p branch is related to the satellite beam. When the satellite beam is known, the pilot data of the S2C-p branch is also known and does not need to be decoded. However, the coded data of the S2C-d branch needs to be decoded.

[0129] Figure 4B A schematic diagram of a protocol parsing architecture for outbound data of a Beidou communication system 10 provided in an embodiment of the present application is shown.

[0130] like Figure 4B As shown, the Beidou message transmission protocol layer on the terminal 100 can be divided into an application layer, a message data aggregation layer, a satellite link control layer and a physical layer.

[0131] At the PHY layer, the terminal 100 can capture the coded data of the S2C-d branch based on the secondary code of the S2C-p branch sent by the Beidou network device 200. After capturing the coded data of the S2C-d branch, the terminal 100 can perform physical layer processing (for example, despreading, demodulation, pilot removal, decoding, etc.) on the coded data of the S2C-d branch to obtain a physical frame. The terminal 100 can extract the user frame belonging to the terminal 100 from the physical frame. The terminal 100 can present the user frame to the SLC layer through the inter-layer interface as an SLC PDU of the SLC layer.

[0132] At the SLC layer, when the user frame received by terminal 100 is a general data frame, terminal 100 can concatenate the SLC PDUs belonging to the same SLC SDU into a single SLC SDU. Terminal 100 can present the SLC SDU to the MDCP layer via the inter-layer interface as an MDCP PDU. When the user frame received by terminal 100 is an ACK frame, terminal 100 can retransmit the data, send the next SLC SDU, or stop sending data to Beidou network device 200.

[0133] At the MDCP layer, the terminal 100 may concatenate one or more MDCP PDUs into an MDCP SDU. The terminal 100 may present the MDCP SDU to the APP layer via an inter-layer interface as an application layer message received by the APP layer.

[0134] At the APP layer, the terminal 100 can determine the sending time based on the time indication field in the message header and the reception time, and calculate the key based on the sending time and other information. After successfully decrypting the encrypted data of the application layer message using the key, the Beidou network device 200 can obtain the original data.

[0135] Among them, the receiving time of the application layer message can be a specified time point between the seventh time point and the eighth time point (including the seventh time point and the eighth time point), and the embodiment of the present application is not limited to this. Among them, the seventh time point can be the time point when the terminal 100 receives the first SLC PDU of the application layer message sent by the Beidou network device 200. The eighth time point can be the time point obtained when the terminal 100 generates the key. Specifically, the eighth time point can be the current time point obtained by running a program statement to obtain the sending time of the application layer message when the terminal 100 calculates the key (for example, by obtaining the current time function getCurrentTime()). Among them, the unit of the receiving time of the application layer message is hours. It should be noted that the terminal 100 must obtain the specified time point before decrypting the encrypted data of the application layer message.

[0136] In the embodiments of the present application, the above-mentioned protocol processing process is only an example, and the present application does not limit the specific operations of the protocol processing.

[0137] The following describes a key update method in a Beidou communication system provided in an embodiment of the present application.

[0138] Figure 5 A flow chart of a key update method during inbound transmission in a Beidou communication system provided in an embodiment of the present application is shown.

[0139] like Figure 5 As shown, the key update method for inbound transmission includes the following steps:

[0140] S501: The terminal 100 obtains original data.

[0141] The original data may include but is not limited to data input by the calling user (such as text data, image data, audio data, video data, etc.), the number of called users, the ID of the called user, the location information of the terminal 100, etc.

[0142] In some embodiments, after receiving the first input from the calling user, the terminal 100 may obtain raw data and send the raw data to the Beidou network device 200. In this embodiment of the present application, the input may include, but is not limited to, gestures, voice, etc. Gestures include gestures that directly touch the display screen of the terminal 100 and hovering gestures that do not directly touch the display screen.

[0143] S502: Terminal 100 generates key A.

[0144] After acquiring the original data, the terminal 100 may generate a key A based on the sending time T. The key A may be used to encrypt the original data.

[0145] The sending time T may be a specified time point between the first time point and the second time point. The sending time is in hours. The specific description of the first time point and the second time point can be found in Figure 3A The embodiment shown is not described in detail here. For example, the sending time T can be the time point when the first input is received. For example, when the terminal 100 receives the first input at 08:58 Beijing time (24-hour system), the value of the clock is 8, then the value of the sending time T is 8.

[0146] In some embodiments, terminal 100 may generate key A based on the transmission time T, Ki in the SIM card, and IMSI. Terminal 100 may obtain the IMSI stored in the SIM card and obtain RAND based on the IMSI and the transmission time T. Terminal 100 may then use a preset key algorithm 1 to obtain Kc based on RAND and Ki stored in the SIM card. Terminal 100 may also use a preset key algorithm 2 to obtain SRES based on RAND and Ki. Finally, terminal 100 may obtain key A based on SRES and Kc.

[0147] Specifically, such as Figure 6 As shown, first, the application processor (AP) of the terminal 100 can obtain the IMSI from the SIM card, and then concatenate the IMSI and the sending time T to obtain RAND.

[0148] Among them, IMSI is a number used to uniquely identify a mobile user internationally. IMSI can be composed of the mobile country code (MCC), mobile network code (MNC) and mobile subscriber identification number (MSIN / MIN). The calculation formula of IMSI is as follows:

[0149] IMSI=MCC||MNC||MIN / MSIN

[0150] Among them, MCC is the code of the country to which the mobile user belongs, including 3 digits (for example, China's MCC is 460). MNC is the mobile network number, which can be used to identify the mobile communication network to which the mobile user belongs (for example, The MSIN is a two-digit number used to identify a subscriber on a mobile communication network. It consists of 10 digits and is provided by the network operator. The || operator is a concatenation operator. The resulting IMSI is 15 decimal digits long and can be represented by a 15-byte string.

[0151] The length of the sending time T may be a 2-digit decimal number, such as 08. The sending time T may be represented by a 1-byte character string.

[0152] Among them, RAND is obtained by concatenating IMSI and sending time T. The length of RAND can be 16 bytes. For example, when IMSI is 460030912121001 and sending time T is 08,

[0153] RAND=IMSI||T=04 06 00 00 03 00 09 01 02 01 02 01 00 00 01 08

[0154] After receiving RAND, the AP of terminal 100 can send RAND to the SIM card. After receiving RAND, the SIM card of terminal 100 can obtain Kc based on Ki and RAND using preset key algorithm 1, and generate SRES using preset key algorithm 2. Preset key algorithm 1 can be the A8 algorithm, and preset key algorithm 2 can be the A3 algorithm. The calculation formulas for Kc and SRES are as follows:

[0155] Kc=A8(Ki,RAND)

[0156] SRES=A3(Ki,RAND)

[0157] Kc can be 4 bytes long, and SRES can be 8 bytes long. The SIM card can then send Kc and SRES to the AP. After receiving Kc and SRES, the AP of terminal 100 can obtain key A based on them. For example, terminal 100 can concatenate Kc and SRES to obtain key A. Alternatively, terminal 100 can obtain key A based on Kc and SRES using a preset key algorithm 3. The preset key algorithm 3 can be a hash-based message authentication code (HMAC) algorithm based on SM3, a national secret algorithm.

[0158] Exemplarily, the terminal 100 may obtain the key A by the following formula:

[0159] Key A = F[SM3HAMC(Kc||SRES,SRES)]

[0160] Formula F is a calculation formula for truncating the first 16 bytes of the input value.

[0161] S503: The terminal 100 may use the key A to encrypt the original data to obtain encrypted data.

[0162] The terminal 100 may use the key A and the original data as inputs of the encryption algorithm, and obtain the encrypted data through calculation by the encryption algorithm.

[0163] S504: The terminal 100 may add a message header before the encrypted data to obtain an application layer message, wherein the message header may include a time indication field.

[0164] like Figure 7 As shown, the application layer message may include a message header and encrypted data, wherein the message header may include but is not limited to an encryption indication field, a time indication field, and a compression indication field.

[0165] The encryption indication field can be 2 bits long. The encryption indication field can be used to indicate the type of encryption algorithm. For example, when the value of the encryption indication field is 00, no encryption algorithm is used; when the value of the encryption indication field is 01, encryption algorithm 1 (such as the national encryption algorithm SM4) can be used for encryption.

[0166] The time indication field can be 1 bit long. The time indication field is used to indicate the transmission time information of the application layer message. Specifically, the value of the time indication field can indicate the parity value of the transmission time T. Specifically, when the value of T is an even number, the value of the time indication field is 1; when the value of T is an odd number, the value of the time indication field is 0. For example, when the transmission time value is 8, the value of the time indication field is 1. When the transmission time value is 17, the value of the time indication field is 0.

[0167] S505 , the terminal 100 sends the application layer message to the Beidou network device 200 .

[0168] Specifically, the specific process description of the terminal 100 sending data to the Beidou network device 200 can be found in the above Figure 3A The embodiments will not be described in detail here. It should be noted that, in the process of the terminal 100 sending the application layer message to the Beidou network device 200, the frame header information added by the terminal 100 at the SLC layer may include a user ID field. The user ID field can be used to identify the terminal 100. The value of the user ID field is the ID number of the terminal 100. The ID number of the terminal 100 can be used to indicate the key-related parameters corresponding to the terminal 100. Among them, the ID number of the terminal 100 may include but is not limited to a mobile phone number, a unique identification number of the terminal 100 negotiated by the terminal 100 and a third-party communication server (for example, a server of an instant messaging software such as Changlian), and so on.

[0169] S506 , the Beidou network device 200 records the receiving time T1 .

[0170] Specifically, the receiving time T1 may be a designated time point between the third time point and the fourth time point, in hours. The specific description of the third time point and the fourth time point can be found in the above Figure 3B The embodiments shown will not be described in detail here.

[0171] Here, the receiving time T1 may be the time point of receiving the first SLC PDU sent by the Beidou network device 100. Specifically, at the SLC layer, when the Beidou network device 200 receives the first SLCPDU corresponding to the application layer message sent by the terminal 100, the Beidou network device 200 may record the time of receiving the SLCPDU as the receiving time T1.

[0172] For example, when the time at which the Beidou network device 200 receives the first SLCPDU sent by the terminal 100 is 08:59 (24-hour system), the Beidou network device 200 may obtain a value of the receiving time T1 as 8.

[0173] For another example, when the time when the Beidou network device 200 receives the first SLCPDU sent by the terminal 100 is 09:00 (24-hour system), the Beidou network device 200 can obtain the value of the receiving time T1 as 9.

[0174] The specific process description of the Beidou network device 200 receiving data from the terminal 100 can be found in the above Figure 3B The embodiments described above will not be described in detail here.

[0175] S507 , the Beidou network device 200 sends an IMSI request to the cellular network device 400 .

[0176] Specifically, after receiving the data of the application layer message, the Beidou network device 200 can send an IMSI request to the cellular network device 150 (e.g., the telecommunications service operation support system 29). The IMSI request can include the ID number of the terminal 100. The IMSI request can be used to instruct the cellular network device 400 to feedback the IMSI corresponding to the ID number.

[0177] S508 , the cellular network device 400 sends the IMSI of the terminal 100 to the Beidou network device 200 .

[0178] Specifically, after receiving the IMSI request, the telecommunications service operation support system 29 may return the corresponding IMSI to the Beidou network device 200 according to the ID number.

[0179] S509 , the Beidou network device 200 obtains RAND based on information such as the time indication field, the receiving time, and the IMSI.

[0180] First, the Beidou network device 200 can determine the sending time T based on the time indication field and the receiving time T1. The value of the time indication field can indicate the parity value of the sending time T. When the parity value of the sending time T indicated by the value of the time indication field is the same as the parity value of the receiving time T1, the sending time T is equal to the receiving time T1. When the parity value of the sending time T indicated by the value of the time indication field is different from the parity value of the receiving time T1, the difference between the receiving time T1 and the sending time T is 1. Specifically:

[0181] When the value of the time indication field is 0 and T1 is an odd number, T=T1;

[0182] When the value of the time indication field is 0 and T1 is an even number, T=T1-1;

[0183] When the value of the time indication field is 1 and T1 is an odd number, T=T1-1;

[0184] When the value of the time indication field is 1 and T1 is an even number, T=T1.

[0185] For example, if the value of the time indication field is 1 and the receiving time T1 is 9, the sending time T is equal to 8. For another example, if the value of the time indication field is 1 and the receiving time T1 is 8, the sending time T is equal to 8.

[0186] Afterwards, the Beidou network device 200 may obtain RAND based on the IMSI and the sending time T. The description of how the Beidou network device 200 obtains RAND can be found in the embodiment described in step S502 above, and will not be repeated here.

[0187] S510 , the Beidou network device 200 may send RAND to the cellular network device 400 .

[0188] Specifically, the Beidou network device 200 may send the random number RAND to the home location register 28 .

[0189] S511: The cellular network device 400 calculates SRES and Kc based on information such as RAND.

[0190] The home location register 28 may store information such as Ki of registered terminals. The home location register 28 may determine Ki of the terminal 100 based on the terminal 100's ID number. The home location register 28 may also derive Kc from Ki and RAND using a preset key algorithm 1. For example, the preset key algorithm 1 may be the A8 algorithm. The home location register 28 may generate SRES from Ki and RAND using a preset key algorithm 2. For example, the preset key algorithm 2 may be the A3 algorithm. The calculation formulas for Kc and SRES may be described in the above. Figure 6 It should be noted that the calculation method used by the home location register 28 to generate SRES and Kc based on RAND and Ki is the same as that used by the terminal 100.

[0191] S512 , the cellular network device 400 may send SRES and Kc to the Beidou network device 200 .

[0192] The home location register 28 may send the calculated SRES and Kc to the Beidou network device 200 .

[0193] S513 , the Beidou network device 200 generates a key B based on SRES and Kc.

[0194] The Beidou network device 200 can generate a key B based on SRES and Kc. The key B can be obtained by concatenating SRES and Kc.

[0195] Optionally, the Beidou network device 200 may calculate the key B based on SRES and Kc using the preset key algorithm 3.

[0196] It should be noted that the algorithm used by the Beidou network device 200 to generate the key B is the same as the algorithm used by the terminal 100 to generate the key A.

[0197] S514, the Beidou network device 200 uses the key B to decrypt the application layer message.

[0198] The Beidou network device 200 can determine the encryption algorithm used by the terminal 100 through the value of the encryption indication field. The terminal 100 can decrypt the encrypted data of the application layer message using the key B and the decryption algorithm corresponding to the encryption algorithm.

[0199] When Beidou network device 200 successfully decrypts the encrypted data of the application layer message, if the original data is a service request message, Beidou network device 200 can send the service data corresponding to the service request message to terminal 100 after decrypting the original data. If the original data is data sent to terminal 300 on the cellular network, Beidou network device 200 can execute step S515. Furthermore, after successful decryption, Beidou network device 200 can also execute step S516.

[0200] When the Beidou network device 200 fails to decrypt the encrypted data of the application layer message, the Beidou network device 200 cannot obtain the original data. Further, the Beidou network device 200 may execute step S517.

[0201] S515 , the Beidou network device 200 may send the original data to the cellular network device 400 .

[0202] The Beidou network device 200 may forward the original data to the short message center 25 , and the short message center 25 may forward the original data to the called user's terminal (eg, terminal 300 ) in a specified format (eg, a text message).

[0203] In one possible implementation, after decrypting the application layer message, the Beidou network device 200 may generate a corresponding application layer receipt based on the result of parsing the application layer message. The Beidou network device 200 may send the application layer receipt to the terminal 100. The terminal 100 may determine the result of parsing the application layer message by the Beidou network device 200 based on the application layer receipt.

[0204] S516 , the Beidou network device 200 may send a first application layer receipt to the terminal 100 .

[0205] After successful decryption, the Beidou network device 200 may send a first application layer receipt to the terminal 100. The first application layer receipt may be used to indicate that the Beidou network device 200 has successfully parsed the application layer message.

[0206] Optionally, after receiving the first application layer receipt, the terminal 100 may display a success prompt. The success prompt may include, but is not limited to, text, voice, or animation. The success prompt indicates that the Beidou network device 200 successfully decrypted the data. For example, the success prompt may be a text prompt reading "Sent Successfully."

[0207] S517 , the Beidou network device 200 may send a second application layer receipt to the terminal 100 .

[0208] After the decryption fails, the Beidou network device 200 may send a second application layer receipt to the terminal 100. The second application layer receipt may indicate that the Beidou network device 200 fails to decrypt the application layer message.

[0209] Optionally, the terminal 100 may retransmit the application layer message after receiving the second application layer receipt.

[0210] Optionally, after receiving the second application layer receipt, the terminal 100 may display a failure prompt. The failure prompt may include, but is not limited to, a text prompt, a voice prompt, an animation prompt, and the like. The failure prompt indicates that the Beidou network device 200 failed to decrypt the data. For example, the failure prompt may be a text prompt such as "Sending failed, please resend."

[0211] In this way, when the terminal 100 and the Beidou network device 200 enter the station, they can encrypt the transmitted data using the key that is updated over time. This not only saves the air interface resources of the Beidou communication system, reduces the signaling and steps required to ensure the safe use of data, but also ensures the security of the transmitted data during transmission.

[0212] Figure 8 A flow chart of a key update method during outbound transmission in a Beidou communication system provided in an embodiment of the present application is shown.

[0213] like Figure 8 As shown, the key update method for outbound transmission includes the following steps:

[0214] S801 , the Beidou network device 200 receives original data sent by the cellular network device 400 .

[0215] Beidou network device 200 receives the original data sent by short message center 25. This original data is the original data (including but not limited to text data and image data input by the calling user, etc.) sent by the calling user (e.g., the user of terminal 300) on the cellular network to the called user (the user of terminal 100) on the Beidou network. It should be noted that when cellular network device 400 forwards the data sent from terminal 300 to terminal 100 to Beidou network device 200, it may also simultaneously forward the called user's ID number (e.g., the ID number of terminal 100) to Beidou network device 200.

[0216] In some embodiments, the raw data acquired by the Beidou network device 200 may be data stored in a memory of the Beidou network device 200. For example, the raw data may be map data stored in the Beidou network device 200.

[0217] In other embodiments, the original data received by the Beidou network device 200 may be data (eg, text data, image data, audio data, video data, etc.) sent to the Beidou network device 200 by a third-party server.

[0218] S802 , the Beidou network device 200 receives a service request sent by the terminal 100 .

[0219] The service request may be a request to download original data, and the receiving device of the original data is the terminal 100. After receiving the service request from the terminal 100, the Beidou network device 200 may execute steps S803 to S12.

[0220] S803 , the Beidou network device 200 sends an IMSI request to the cellular network device 400 .

[0221] Specifically, after the Beidou network device 200 receives the original data and ID number sent to the terminal 100, it can send an IMSI request to the cellular network device 150 (for example, the telecommunications business operation support system 29). The IMSI request may include the ID number of the terminal 100. The IMSI request can be used to instruct the cellular network device 400 to feedback the IMSI corresponding to the ID number. The ID number of the terminal 100 may include but is not limited to a mobile phone number, a unique identification number negotiated between the terminal 100 and a third-party communication server (for example, a server of an instant messaging software such as Changlian), and the like.

[0222] S804 , the cellular network device 400 sends the IMSI of the terminal 100 to the Beidou network device 200 .

[0223] Specifically, after receiving the IMSI request, the telecommunications service operation support system 29 may send the IMSI corresponding to the ID number to the Beidou network device 200 .

[0224] S805: The Beidou network device 200 obtains RAND based on the sending time T, IMSI and other information.

[0225] Here, the sending time T can be a designated time point between the fifth time point and the sixth time point, in hours. The specific description of the fifth time point and the sixth time point can be found in the above Figure 4A The illustrated embodiment will not be described in detail here. For example, the Beidou network device 200 may use the time point when the Beidou network device 200 receives the service request from the terminal 100 as the sending time T. Specifically, when the time when the Beidou network device 200 receives the service request is 08:58 Beijing time (24-hour system), the value of the clock is 8, and the value of the sending time T is 8.

[0226] The BeiDou network device 200 can concatenate the IMSI and the sending time T to obtain RAND. Figure 5 The embodiments described above will not be described in detail here.

[0227] S806 , the Beidou network device 200 may send the RAND to the cellular network device 400 .

[0228] The Beidou network device 200 may send the random number RAND to the home location register 28 .

[0229] S807: The cellular network device 400 calculates SRES and Kc based on information such as RAND.

[0230] The home location register 28 stores information such as Ki of the terminals that have opened accounts. The home location register 28 can determine the Ki of the terminal 100 and generate SRES and Kc based on RAND and Ki. For example, the home location register 28 can determine the Ki of the terminal 100 based on the ID number of the terminal 100. The detailed description of how the home location register 28 obtains SRES and Kc can be found in the above Figure 5 The embodiments described above will not be described in detail here.

[0231] S808 , the cellular network device 400 may send SRES and Kc to the Beidou network device 200 .

[0232] The home location register 28 may send the calculated SRES and Kc to the Beidou network device 200 .

[0233] S809 , the Beidou network device 200 may generate a key B based on SRES and Kc.

[0234] The detailed description of how the BeiDou network device 200 generates the key B based on SRES and Kc can be found in the above Figure 5 The embodiments described above will not be described in detail here.

[0235] S810, the Beidou network device 200 may use the key B to encrypt the original data to obtain encrypted data.

[0236] S811: The Beidou network device 200 may add a message header to the encrypted data to obtain an application layer message, wherein the message header may include a time indication field.

[0237] For a detailed description of the application layer message, please refer to the above Figure 7 The embodiments described above will not be described in detail here.

[0238] S812 , the Beidou network device 200 may send the application layer message to the terminal 100 .

[0239] The Beidou network device 200 sends the application layer message to the terminal 100 for a detailed description. Figure 4A The embodiments described above will not be described in detail here.

[0240] S813, the terminal 100 generates a key A based on information such as the time indication field and the receiving time T1.

[0241] The detailed description of the terminal 100 receiving the data sent by the Beidou network device 200 can be found in the above Figure 4B The embodiments described above will not be described in detail here.

[0242] The receiving time T1 may be a designated time point between the seventh time point and the eighth time point, in hours. Figure 4B The embodiment shown is not described in detail here. Here, the receiving time may be the time point when the first SLCPDU sent by the Beidou network device 100 is received.

[0243] Afterwards, the terminal 100 can determine the sending time T based on the receiving time T1 and the time indication field. For details, please refer to the above Figure 5 The embodiments described above will not be described in detail here.

[0244] Finally, after the terminal 100 determines the sending time T, it can calculate the key A based on the sending time T and other parameters. The detailed description of how the terminal 100 obtains the key A based on the sending time can be found in Figure 6 The embodiments described above will not be described in detail here.

[0245] S814, the terminal 100 may use key A to decrypt the application layer message.

[0246] If the decryption is successful, the terminal 100 may proceed to step S814. Furthermore, after the decryption is successful, the terminal 100 may proceed to step S815. If the decryption fails, the terminal 100 cannot obtain the original data. Furthermore, the terminal 100 may proceed to step S816.

[0247] S815, the terminal 100 may display a receiving prompt message.

[0248] After successful decryption, terminal 100 may display a receipt prompt on the display screen, indicating that terminal 100 has received a Beidou short message. The receipt prompt may include, but is not limited to, text prompts, image prompts, and animation prompts. When the receipt prompt is text, for example, the receipt prompt may be "Received a Beidou short message from terminal 300."

[0249] In one possible implementation, after decrypting the application layer message, terminal 100 may generate a corresponding application layer receipt based on the result of parsing the application layer message. Terminal 100 may send the application layer receipt to Beidou network device 200. Beidou network device 200 may determine the result of parsing the application layer message by terminal 100 based on the application layer receipt.

[0250] S816 , the terminal 100 may send a first application layer receipt to the Beidou network device 200 .

[0251] After successful decryption, the terminal 100 may send a first application layer receipt to the Beidou network device 200. The first application layer receipt may be used to indicate that the terminal 100 has successfully parsed the application layer message.

[0252] S817, the terminal 100 can send a second application layer receipt to the Beidou network device 200.

[0253] After the decryption fails, the terminal 100 may send a second application layer receipt to the Beidou network device 200. The second application layer receipt may indicate that the terminal 100 fails to decrypt the application layer message.

[0254] Furthermore, the Beidou network device 200 may retransmit the application layer message after receiving the second application layer receipt.

[0255] In this way, when the BeiDou network device 200 and the terminal 100 are transmitting outbound data, they can encrypt the transmitted data using a key that is updated over time. This not only saves the air interface resources of the BeiDou communication system, reduces the signaling and steps required to ensure data security, but also ensures the security of the transmitted data.

[0256] In one possible implementation, the sending device may send a second application layer message to the receiving device after sending the first application layer message to the receiving device. When the sending time of the second application layer message is the same as the sending time of the first application layer message, the sending device may directly use the first key generated based on information such as the sending time of the first application layer message to encrypt the second original data to obtain the second encrypted data. The sending device may add message header information before the second encrypted data to obtain the second application layer message. The time indication field in the message header information of the second application layer message is the same as the time indication field of the first application layer message. In this way, the time for the sending device to calculate the key of the second application layer message can be saved, and the second application layer message can be obtained more quickly.

[0257] In one possible implementation, after receiving the first application layer message from the sending device, the receiving device receives the second application layer message from the sending device. The receiving device determines that the time of receipt of the second application layer message is the same as the time of receipt of the first application layer message. The receiving device may encrypt the second encrypted data of the second application layer message using a second key obtained based on information such as the time of receipt of the first application layer message, thereby obtaining the second original data. This saves the time required by the receiving device to calculate the key for the second application layer message, and allows the receiving device to obtain the second original data of the second application layer message more quickly.

[0258] The terminal 100 provided in an embodiment of the present application is introduced below.

[0259] The terminal 100 can be a mobile phone, a tablet computer, a desktop computer, a laptop computer, a handheld computer, a notebook computer, an ultra-mobile personal computer (UMPC), a netbook, a cellular phone, a personal digital assistant (PDA), an augmented reality (AR) device, a virtual reality (VR) device, an artificial intelligence (AI) device, a wearable device, an in-vehicle device, a smart home device and / or a smart city device. The embodiments of the present application do not impose any special restrictions on the specific type of the electronic device.

[0260] Figure 9 A schematic diagram of a hardware structure provided in an embodiment of the present application is shown.

[0261] The embodiment will be described in detail below using terminal 100 as an example. It should be understood that Figure 9 The terminal 100 shown is only an example, and the terminal 100 may have more Figure 9More or fewer components may be shown, two or more components may be combined, or the components may be arranged differently. Figure 9 The various components shown in the drawings may be implemented in hardware, software, or a combination of hardware and software, including one or more signal processing and / or application specific integrated circuits.

[0262] The terminal 100 may include: a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, an earphone interface 170D, a sensor module 180, a button 190, a motor 191, an indicator 192, a camera 193, a display 194, and a subscriber identification module (SIM) card interface 195, etc. The sensor module 180 may include a pressure sensor 180A, a gyroscope sensor 180B, an air pressure sensor 180C, a magnetic sensor 180D, an acceleration sensor 180E, a distance sensor 180F, a proximity light sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, etc.

[0263] It should be understood that the structure illustrated in the embodiments of the present invention does not constitute a specific limitation on terminal 100. In other embodiments of the present application, terminal 100 may include more or fewer components than shown, or may combine or separate certain components, or arrange the components differently. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.

[0264] The processor 110 may include one or more processing units. For example, the processor 110 may include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU). The different processing units may be independent devices or integrated into one or more processors.

[0265] The controller may be the nerve center and command center of the terminal 100. The controller may generate an operation control signal according to the instruction operation code and the timing signal to complete the control of fetching and executing instructions.

[0266] Processor 110 may also include a memory for storing instructions and data. In some embodiments, the memory in processor 110 is a cache memory. This memory can store instructions or data that have just been used or are being recycled by processor 110. If processor 110 needs to use the same instruction or data again, it can directly access the memory. This avoids duplicate accesses, reduces processor 110 latency, and thus improves system efficiency.

[0267] In some embodiments, the processor 110 may include one or more interfaces. The interfaces may include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface.

[0268] The I2C interface is a bidirectional synchronous serial bus that includes a serial data line (SDA) and a serial clock line (SCL). In some embodiments, the processor 110 may include multiple I2C bus lines. The processor 110 may be coupled to the touch sensor 180K, the charger, the flash, the camera 193, and the like via different I2C bus interfaces. For example, the processor 110 may be coupled to the touch sensor 180K via the I2C interface, enabling communication between the processor 110 and the touch sensor 180K via the I2C bus interface, thereby implementing the touch function of the terminal 100.

[0269] The I2S interface can be used for audio communication. In some embodiments, the processor 110 can include multiple I2S buses. The processor 110 can be coupled to the audio module 170 via the I2S bus to enable communication between the processor 110 and the audio module 170. In some embodiments, the audio module 170 can transmit audio signals to the wireless communication module 160 via the I2S interface, enabling the function of answering calls through a Bluetooth headset.

[0270] The PCM interface can also be used for audio communication, sampling, quantizing, and encoding analog signals. In some embodiments, the audio module 170 and the wireless communication module 160 can be coupled via a PCM bus interface. In some embodiments, the audio module 170 can also transmit audio signals to the wireless communication module 160 via the PCM interface, enabling the function of answering calls via a Bluetooth headset. Both the I2S interface and the PCM interface can be used for audio communication.

[0271] The UART interface is a universal serial data bus used for asynchronous communication. This bus can be a bidirectional communication bus. It converts the data to be transmitted between serial communication and parallel communication. In some embodiments, the UART interface is typically used to connect the processor 110 and the wireless communication module 160. For example, the processor 110 communicates with the Bluetooth module in the wireless communication module 160 via the UART interface to implement Bluetooth functionality. In some embodiments, the audio module 170 can transmit audio signals to the wireless communication module 160 via the UART interface, enabling the function of playing music through Bluetooth headphones.

[0272] The MIPI interface can be used to connect the processor 110 to peripheral devices such as the display 194 and the camera 193. MIPI interfaces include the camera serial interface (CSI) and the display serial interface (DSI). In some embodiments, the processor 110 and the camera 193 communicate via the CSI interface to implement the camera function of the terminal 100. The processor 110 and the display 194 communicate via the DSI interface to implement the display function of the terminal 100.

[0273] The GPIO interface can be configured via software. The GPIO interface can be configured as either a control signal or a data signal. In some embodiments, the GPIO interface can be used to connect the processor 110 to the camera 193, display 194, wireless communication module 160, audio module 170, sensor module 180, etc. The GPIO interface can also be configured as an I2C interface, an I2S interface, a UART interface, a MIPI interface, etc.

[0274] The USB interface 130 is an interface that complies with USB standards and may be a Mini USB interface, a Micro USB interface, a USB Type-C interface, or the like. The USB interface 130 can be used to connect a charger to charge the terminal 100 and to transfer data between the terminal 100 and peripheral devices. It can also be used to connect headphones to play audio. This interface can also be used to connect other electronic devices, such as augmented reality devices.

[0275] It is understood that the interface connection relationship between the modules illustrated in the embodiment of the present invention is merely an illustrative description and does not constitute a structural limitation on the terminal 100. In other embodiments of the present application, the terminal 100 may also adopt a different interface connection method from the above embodiment, or a combination of multiple interface connection methods.

[0276] The charging management module 140 is configured to receive charging input from a charger. The charger can be either a wireless charger or a wired charger. In some wired charging embodiments, the charging management module 140 can receive charging input from the wired charger via the USB interface 130. In some wireless charging embodiments, the charging management module 140 can receive wireless charging input via the wireless charging coil of the terminal 100. While charging the battery 142, the charging management module 140 can also power the electronic device through the power management module 141.

[0277] The power management module 141 is used to connect the battery 142, the charging management module 140 and the processor 110. The power management module 141 receives input from the battery 142 and / or the charging management module 140, and provides power to the processor 110, the internal memory 121, the external memory, the display 194, the camera 193, and the wireless communication module 160. The power management module 141 can also be used to monitor parameters such as battery capacity, battery cycle count, and battery health status (leakage, impedance). In some other embodiments, the power management module 141 can also be set in the processor 110. In other embodiments, the power management module 141 and the charging management module 140 can also be set in the same device.

[0278] The wireless communication function of the terminal 100 can be implemented through the antenna 1, the antenna 2, the mobile communication module 150, the wireless communication module 160, the modem processor and the baseband processor.

[0279] Antenna 1 and Antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in terminal 100 can be used to cover a single or multiple communication frequency bands. Different antennas can also be reused to improve antenna utilization. For example, antenna 1 can be reused as a diversity antenna for a wireless local area network. In other embodiments, the antennas can be used in conjunction with a tuning switch.

[0280] The mobile communication module 150 can provide solutions for wireless communications including 2G / 3G / 4G / 5G applied on the terminal 100. The mobile communication module 150 may include at least one filter, a switch, a power amplifier, a low noise amplifier (LNA), etc. The mobile communication module 150 can receive electromagnetic waves from the antenna 1, and filter, amplify, and process the received electromagnetic waves, and transmit them to the modulation and demodulation processor for demodulation. The mobile communication module 150 can also amplify the signal modulated by the modulation and demodulation processor, and convert it into electromagnetic waves for radiation through the antenna 1. In some embodiments, at least some of the functional modules of the mobile communication module 150 can be set in the processor 110. In some embodiments, at least some of the functional modules of the mobile communication module 150 can be set in the same device as at least some of the modules of the processor 110.

[0281] The modem processor may include a modulator and a demodulator. The modulator is used to modulate the low-frequency baseband signal to be transmitted into a medium-high frequency signal. The demodulator is used to demodulate the received electromagnetic wave signal into a low-frequency baseband signal. The demodulator then transmits the demodulated low-frequency baseband signal to the baseband processor for processing. After being processed by the baseband processor, the low-frequency baseband signal is passed to the application processor. The application processor outputs a sound signal through an audio device (not limited to the speaker 170A, the receiver 170B, etc.) or displays an image or video through the display screen 194. In some embodiments, the modem processor may be an independent device. In other embodiments, the modem processor may be independent of the processor 110 and be set in the same device as the mobile communication module 150 or other functional modules.

[0282] The wireless communication module 160 can provide wireless communication solutions applied on the terminal 100, including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite system (GNSS), satellite communication module, frequency modulation (FM), near field communication (NFC), infrared technology (IR), etc. The wireless communication module 160 can be one or more devices integrating at least one communication processing module. The wireless communication module 160 receives electromagnetic waves via the antenna 2, frequency modulates and filters the electromagnetic wave signals, and sends the processed signals to the processor 110. The wireless communication module 160 can also receive the signal to be sent from the processor 110, frequency modulate it, amplify it, and convert it into electromagnetic waves for radiation through the antenna 2.

[0283] Among them, the satellite communication module can be used to communicate with satellite network equipment. For example, in the Beidou communication system, the satellite communication module can communicate with the Beidou network equipment 200, and the satellite communication module can support short message transmission between the Beidou network equipment 200.

[0284] In some embodiments, the antenna 1 of the terminal 100 is coupled to the mobile communication module 150, and the antenna 2 is coupled to the wireless communication module 160, so that the terminal 100 can communicate with the network and other devices through wireless communication technology. The wireless communication technology may include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technology. The GNSS may include a global positioning system (GPS), a global navigation satellite system (GLONASS), a Beidou navigation satellite system (BDS), a quasi-zenith satellite system (QZSS) and / or a satellite based augmentation system (SBAS).

[0285] Terminal 100 implements display functions through a GPU, display screen 194, and an application processor. The GPU is a microprocessor for image processing that connects display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. Processor 110 may include one or more GPUs that execute program instructions to generate or modify display information.

[0286] Display screen 194 is used to display images, videos, and the like. Display screen 194 includes a display panel. The display panel can be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a MiniLED, a MicroLED, a Micro-oLed, or a quantum dot light-emitting diode (QLED). In some embodiments, terminal 100 may include one or N display screens 194, where N is a positive integer greater than one.

[0287] The terminal 100 can realize the shooting function through the ISP, camera 193, video codec, GPU, display screen 194 and application processor.

[0288] The ISP processes data fed back by camera 193. For example, when taking a photo, the shutter is opened, and light is transmitted through the lens to the camera's photosensitive element. The light signal is converted into an electrical signal, which is then passed to the ISP for processing and converted into a visible image. The ISP can also perform algorithmic optimization on image noise and brightness. It can also optimize parameters such as exposure and color temperature of the captured scene. In some embodiments, the ISP can be located within camera 193.

[0289] The camera 193 is used to capture still images or videos. The object generates an optical image through the lens and projects it onto the photosensitive element. The photosensitive element can be a charge coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the light signal into an electrical signal, and then passes the electrical signal to the ISP for conversion into a digital image signal. The ISP outputs the digital image signal to the DSP for processing. The DSP converts the digital image signal into an image signal in a standard RGB, YUV or other format. In some embodiments, the terminal 100 may include 1 or N cameras 193, where N is a positive integer greater than 1.

[0290] The digital signal processor is used to process digital signals. In addition to processing digital image signals, it can also process other digital signals. For example, when the terminal 100 selects a frequency point, the digital signal processor is used to perform Fourier transform on the frequency point energy.

[0291] Video codecs are used to compress or decompress digital video. Terminal 100 may support one or more video codecs. This allows terminal 100 to play or record videos in various encoding formats, such as Moving Picture Experts Group (MPEG) 1, MPEG2, MPEG3, and MPEG4.

[0292] The NPU is a neural network (NN) computing processor. Drawing on the structure of biological neural networks, such as the transmission patterns between neurons in the human brain, it rapidly processes input information and can continuously self-learn. The NPU enables intelligent cognitive applications in the terminal 100, such as image recognition, face recognition, speech recognition, and text comprehension.

[0293] The external memory interface 120 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the terminal 100. The external memory card communicates with the processor 110 via the external memory interface 120 to implement data storage functions. For example, files such as music and videos can be stored on the external memory card.

[0294] The internal memory 121 can be used to store computer executable program codes, which include instructions. The processor 110 executes various functional applications and data processing of the terminal 100 by running the instructions stored in the internal memory 121. The internal memory 121 may include a program storage area and a data storage area. Among them, the program storage area can store an operating system, an application required for at least one function (such as a sound playback function, an image playback function, etc.), etc. The data storage area can store data created during the use of the terminal 100 (such as audio data, a phone book, etc.), etc. In addition, the internal memory 121 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), etc.

[0295] The terminal 100 can implement audio functions such as music playback and recording through the audio module 170, the speaker 170A, the receiver 170B, the microphone 170C, the headphone jack 170D, and the application processor.

[0296] The audio module 170 is used to convert digital audio information into analog audio signal output, and is also used to convert analog audio input into digital audio signals. The audio module 170 can also be used to encode and decode audio signals. In some embodiments, the audio module 170 can be provided in the processor 110, or some functional modules of the audio module 170 can be provided in the processor 110.

[0297] The speaker 170A, also called a "speaker", is used to convert audio electrical signals into sound signals. The terminal 100 can listen to music or listen to hands-free calls through the speaker 170A.

[0298] The receiver 170B, also called a "handset", is used to convert audio electrical signals into sound signals. When the terminal 100 receives a call or a voice message, the user can place the receiver 170B close to the ear to hear the voice.

[0299] Microphone 170C, also known as "microphone" or "microphone", is used to convert sound signals into electrical signals. When making a call or sending a voice message, the user can speak by putting their mouth close to the microphone 170C to input the sound signal into the microphone 170C. The terminal 100 can be provided with at least one microphone 170C. In other embodiments, the terminal 100 can be provided with two microphones 170C, which can not only collect sound signals but also realize noise reduction function. In other embodiments, the terminal 100 can also be provided with three, four or more microphones 170C to realize sound signal collection, noise reduction, and identification of sound sources, and realize directional recording function, etc.

[0300] The headphone jack 170D is used to connect a wired headphone and can be the USB interface 130 or a 3.5mm open mobile terminal platform (OMTP) standard interface or a cellular telecommunications industry association of the USA (CTIA) standard interface.

[0301] Pressure sensor 180A is used to sense pressure signals and convert them into electrical signals. In some embodiments, pressure sensor 180A can be located on display screen 194. There are many types of pressure sensors 180A, such as resistive, inductive, and capacitive. A capacitive pressure sensor can include at least two parallel plates made of conductive material. When force is applied to pressure sensor 180A, the capacitance between the electrodes changes. Terminal 100 determines the intensity of the pressure based on this change in capacitance. When a touch operation is applied to display screen 194, terminal 100 detects the touch intensity based on pressure sensor 180A. Terminal 100 can also calculate the touch location based on the detection signal from pressure sensor 180A. In some embodiments, touch operations applied to the same touch location but with different touch intensities can correspond to different operation instructions. For example, when a touch operation with an intensity less than a first pressure threshold is applied to a short message application icon, a command to view short messages is executed. When a touch operation with an intensity greater than or equal to the first pressure threshold is applied to a short message application icon, a command to create a new short message is executed.

[0302] The gyroscope sensor 180B can be used to determine the motion posture of the terminal 100. In some embodiments, the angular velocity of the terminal 100 around three axes (i.e., x, y, and z axes) can be determined by the gyroscope sensor 180B. The gyroscope sensor 180B can be used for anti-shake shooting. For example, when the shutter is pressed, the gyroscope sensor 180B detects the angle of the terminal 100 shaking, calculates the distance that the lens module needs to compensate based on the angle, and allows the lens to offset the shaking of the terminal 100 through reverse movement to achieve anti-shake. The gyroscope sensor 180B can also be used for navigation and somatosensory game scenes.

[0303] The air pressure sensor 180C is used to measure air pressure. In some embodiments, the terminal 100 calculates the altitude using the air pressure value measured by the air pressure sensor 180C to assist in positioning and navigation.

[0304] The magnetic sensor 180D includes a Hall sensor. The terminal 100 can use the magnetic sensor 180D to detect the opening and closing of the flip case. In some embodiments, when the terminal 100 is a flip phone, the terminal 100 can detect the opening and closing of the flip cover based on the magnetic sensor 180D. Furthermore, based on the detected opening and closing status of the case or flip cover, features such as automatic unlocking of the flip cover can be configured.

[0305] Accelerometer 180E can detect the magnitude of acceleration of terminal 100 in all directions (generally three axes). When terminal 100 is stationary, it can detect the magnitude and direction of gravity. It can also be used to identify the electronic device's posture, enabling applications such as switching between landscape and portrait modes and pedometers.

[0306] The distance sensor 180F is used to measure distance. The terminal 100 can measure distance using infrared or laser. In some embodiments, when shooting a scene, the terminal 100 can use the distance sensor 180F to measure distance to achieve fast focusing.

[0307] The proximity light sensor 180G may include, for example, a light emitting diode (LED) and a light detector, such as a photodiode. The light emitting diode may be an infrared light emitting diode. The terminal 100 emits infrared light outward through the light emitting diode. The terminal 100 uses the photodiode to detect infrared reflected light from nearby objects. When sufficient reflected light is detected, it can be determined that there is an object near the terminal 100. When insufficient reflected light is detected, the terminal 100 can determine that there is no object near the terminal 100. The terminal 100 can use the proximity light sensor 180G to detect when the user holds the terminal 100 close to the ear to talk, so as to automatically turn off the screen to save power. The proximity light sensor 180G can also be used in leather case mode and pocket mode to automatically unlock and lock the screen.

[0308] Ambient light sensor 180L is used to sense ambient light brightness. Terminal 100 can adaptively adjust the brightness of display screen 194 based on the perceived ambient light brightness. Ambient light sensor 180L can also be used to automatically adjust white balance when taking photos. Ambient light sensor 180L can also work with proximity light sensor 180G to detect whether terminal 100 is in a pocket to prevent accidental touches.

[0309] The fingerprint sensor 180H is used to collect fingerprints. The terminal 100 can use the collected fingerprint characteristics to implement fingerprint unlocking, access application locks, fingerprint photography, fingerprint call answering, etc.

[0310] Temperature sensor 180J is used to detect temperature. In some embodiments, terminal 100 uses the temperature detected by temperature sensor 180J to implement a temperature handling strategy. For example, when the temperature reported by temperature sensor 180J exceeds a threshold, terminal 100 reduces the performance of a processor located near temperature sensor 180J to reduce power consumption and implement thermal protection. In other embodiments, when the temperature falls below another threshold, terminal 100 heats battery 142 to prevent abnormal shutdown of terminal 100 due to low temperature. In other embodiments, when the temperature falls below yet another threshold, terminal 100 boosts the output voltage of battery 142 to prevent abnormal shutdown due to low temperature.

[0311] The touch sensor 180K is also called a "touch panel." The touch sensor 180K can be disposed on the display screen 194. The touch sensor 180K and the display screen 194 form a touch screen, also called a "touch screen." The touch sensor 180K is used to detect touch operations applied thereto or in the vicinity thereof. The touch sensor can transmit the detected touch operations to the application processor to determine the type of touch event. Visual output related to the touch operations can be provided via the display screen 194. In other embodiments, the touch sensor 180K can also be disposed on the surface of the terminal 100, in a location different from that of the display screen 194.

[0312] The bone conduction sensor 180M can obtain vibration signals. In some embodiments, the bone conduction sensor 180M can obtain vibration signals from the vibrating bones of the human body. The bone conduction sensor 180M can also contact the human pulse to receive blood pressure pulse signals. In some embodiments, the bone conduction sensor 180M can also be set in headphones to form bone conduction headphones. The audio module 170 can parse out voice signals based on the vibration signals of the vibrating bones of the human body obtained by the bone conduction sensor 180M to implement voice functions. The application processor can parse heart rate information based on the blood pressure pulse signals obtained by the bone conduction sensor 180M to implement heart rate detection functions.

[0313] Keys 190 include a power button, a volume button, etc. Keys 190 may be mechanical keys or touch keys. Terminal 100 may receive key inputs and generate key signal inputs related to user settings and function control of terminal 100.

[0314] Motor 191 can generate vibration prompts. Motor 191 can be used for incoming call vibration prompts, and can also be used for touch vibration feedback. For example, touch operations acting on different applications (such as taking pictures, audio playback, etc.) can correspond to different vibration feedback effects. For touch operations acting on different areas of the display screen 194, motor 191 can also correspond to different vibration feedback effects. Different application scenarios (for example: time reminders, receiving messages, alarm clocks, games, etc.) can also correspond to different vibration feedback effects. The touch vibration feedback effect can also support customization.

[0315] The indicator 192 may be an indicator light, which may be used to indicate the charging status, power level changes, messages, missed calls, notifications, etc.

[0316] The SIM card interface 195 is used to connect a SIM card. The SIM card can be connected to or removed from the terminal 100 by inserting it into or removing it from the SIM card interface 195. The terminal 100 can support one or N SIM card interfaces, where N is a positive integer greater than one. The SIM card interface 195 can support Nano SIM cards, Micro SIM cards, SIM cards, and the like. Multiple cards can be inserted into the same SIM card interface 195 at the same time. The types of the multiple cards can be the same or different. The SIM card interface 195 can also be compatible with different types of SIM cards. The SIM card interface 195 can also be compatible with external memory cards. The terminal 100 interacts with the network through the SIM card to implement functions such as calls and data communications. In some embodiments, the terminal 100 uses an eSIM, i.e., an embedded SIM card. The eSIM card can be embedded in the terminal 100 and cannot be separated from the terminal 100.

[0317] The following describes a key update method in a Beidou communication system provided in an embodiment of the present application.

[0318] Figure 10 A flow chart of an inbound transmission control method in a Beidou communication system provided in an embodiment of the present application is shown.

[0319] like Figure 10 As shown, the inbound transmission control method in the Beidou communication system includes the following steps:

[0320] S1001. The terminal 100 generates a first key based on the user identification code IMSI, the identity identification key Ki and the sending time of the first application layer message.

[0321] S1002. The terminal 100 encrypts the first original data using the first key to obtain first encrypted data.

[0322] S1003. Terminal 100 adds message header information to the first encrypted data to obtain a first application layer message. The message header information includes a time indication field and an encryption indication field. The encryption indication field is used to indicate the preset encryption algorithm used when encrypting the first original data. The time indication field is used to indicate the sending time information of the first application layer message.

[0323] S1004 . The terminal 100 sends a first application layer message to the Beidou network device 200 .

[0324] S1005. The Beidou network device 200 generates a second key through the cellular network device based on the time indication field and the reception time of the first application layer message.

[0325] S1006. The Beidou network device 200 successfully decrypts the first encrypted data using the second key to obtain the first original data.

[0326] Specifically involving the terminal 100, generating the first key, encrypting the first original data to obtain the first application layer message, the detailed description can be found in the above Figure 5 The embodiments shown will not be described in detail here.

[0327] Specifically, the Beidou network device 200 generates a second key and decrypts the application layer message. Figure 5 The embodiments described above will not be described in detail here.

[0328] Some possible implementations performed by the terminal 100 are described below.

[0329] In a possible implementation, the sending time of the first application layer message is a first time point or a second time point; wherein the first time point is the time point when the terminal obtains the first original data, and the second time point is the time point obtained when the terminal generates the first key.

[0330] For details, please refer to the above Figure 3A The embodiment described.

[0331] In one possible implementation, the terminal generates a first key based on the user identification code (IMSI), the identity identification key (Ki), and the time when the first application layer message was sent. Specifically, the terminal obtains a random number (RAND) based on the time and IMSI of sending the first application layer message. The terminal obtains an encryption key (Kc) using a preset key algorithm 1 based on RAND and a preset Ki, and obtains an authentication symbol response (SRES) using a preset key algorithm 2. The terminal obtains the first key based on Kc and SRES using a preset key algorithm 3.

[0332] For details, please refer to the above Figure 6 The embodiment described.

[0333] In a possible implementation, before the terminal uses the first key to encrypt the first original data, the method further includes: the terminal may also compress the first original data.

[0334] For details, please refer to the above Figure 3A The embodiment described.

[0335] In one possible implementation, after the terminal sends the first application layer message to the Beidou network device, the method further includes: the terminal receives the first application layer receipt sent by the Beidou network device, and the first application layer receipt is used to indicate that the Beidou network device has successfully decrypted the first application layer message.

[0336] For details, please refer to the above Figure 5 The embodiment described.

[0337] In one possible implementation, after the terminal sends a first application layer message to the Beidou network device, the method also includes: the terminal generates a third key based on IMSI, Ki and the sending time of the second application layer message; the terminal uses the third key to encrypt the second original data to obtain second encrypted data; the terminal adds message header information to the second encrypted data to obtain a second application layer message; wherein the message header information includes a time indication field and an encryption indication field, the encryption indication field is used to indicate the preset encryption algorithm used when encrypting the second original data, and the time indication field is used to indicate the sending time information of the second application layer message; the terminal sends the second application layer message to the Beidou network device; the terminal receives the second application layer receipt sent by the Beidou network device, and the second application layer receipt is used to indicate that the Beidou network device failed to decrypt the second application layer message.

[0338] For details, please refer to the above Figure 5 The embodiment described.

[0339] In a possible implementation, the terminal determines that the sending time of the first application layer message is the same as the sending time of the second application layer message, and the terminal directly uses the first key to encrypt the second original data to obtain second encrypted data.

[0340] Optionally, the terminal directly uses the time indication field of the first application layer message as the time indication field of the second application layer message.

[0341] In a possible implementation, after the terminal receives the second application layer receipt sent by the Beidou network device, the method further includes: the terminal retransmitting the second application layer message.

[0342] For details, please refer to the above Figure 5 The embodiment described.

[0343] In a possible implementation, after the terminal receives the second application layer receipt sent by the Beidou network device, the method further includes: the terminal displays failure prompt information, where the failure prompt information is used to indicate that the Beidou network device fails to decrypt the second application layer message.

[0344] For details, please refer to the above Figure 5 The embodiment described.

[0345] In a possible implementation, the value of the time indication field is used to indicate the parity value of the sending time of the first application layer message.

[0346] For details, please refer to the above Figure 3A The embodiment described.

[0347] The following introduces some possible implementations of the Beidou network device 200.

[0348] In one possible implementation, the Beidou network device generates a second key through the cellular network device based on the time indication field and the reception time of the first application layer message, specifically including: the Beidou network device determines the sending time of the first application layer message based on the time indication field and the reception time of the first application layer message; the Beidou network device obtains a random number RAND based on the sending time of the first application layer message and the user identification code IMSI obtained from the cellular network device; the Beidou network device sends the RAND to the cellular network device; the Beidou network device obtains the encryption key Kc and authentication symbol response SRES fed back by the cellular network device; the terminal obtains the second key based on Kc and SRES through the preset key algorithm 3.

[0349] For details, please refer to the above Figure 5 The embodiment described.

[0350] In one possible implementation, the reception time of the first application layer message is a specified time point between the third time point and the fourth time point, and the unit of the reception time of the first application layer message is hours; wherein, the third time point is the time point when the Beidou network device receives the first satellite link control layer protocol data unit SLCPDU of the first application layer message, and the fourth time point is the time point obtained when the Beidou network device generates the second key.

[0351] For details, please refer to the above Figure 3B The embodiment described.

[0352] In a possible implementation, the value of the time indication field is used to indicate the parity value of the sending time of the first application layer message. Figure 3B The embodiment described.

[0353] In a possible implementation, the Beidou network device determines the sending time of the first application layer message based on the time indication field and the receiving time of the first application layer message, specifically including: when the parity value of the sending time of the first application layer message indicated by the value of the time indication field is the same as the parity value of the receiving time of the first application layer message, the Beidou network device determines that the sending time of the first application layer message is the same as the receiving time of the first application layer message;

[0354] When the parity value of the sending time of the first application layer message indicated by the value of the time indication field is different from the parity value of the receiving time of the first application layer message, the Beidou network device determines that the difference between the receiving time of the first application layer message and the sending time of the first application layer message is 1.

[0355] For details, please refer to the above Figure 5 The embodiment described.

[0356] In one possible implementation, after the Beidou network device successfully decrypts the first encrypted data using the second key and obtains the first original data, the method also includes: the Beidou network device generates a first application layer receipt, and the first application layer receipt is used to indicate that the Beidou network device has successfully decrypted the first application layer message; the Beidou network device sends the first application layer receipt to the terminal.

[0357] For details, please refer to the above Figure 5 The embodiment described.

[0358] In one possible implementation, after the Beidou network device successfully decrypts the first encrypted data using the second key to obtain the first original data, the method also includes: the Beidou network device receives a second application layer message sent by the terminal; wherein the second application layer message includes the second encrypted data and message header information, the message header information includes a time indication field and an encryption indication field, the encryption indication field is used to indicate the preset encryption algorithm used when encrypting the second original data, and the time indication field is used to indicate the sending time information of the second application layer message; the Beidou network device generates a fourth key through the cellular network device based on the time indication field and the reception time of the second application layer message; the Beidou network device fails to decrypt the second encrypted data using the fourth key, and the Beidou network device generates a second application layer receipt, and the second application layer receipt is used to indicate that the Beidou network device fails to decrypt the second application layer message; the Beidou network device sends the second application layer receipt to the terminal.

[0359] For details, please refer to the above Figure 5 The embodiment described.

[0360] In a possible implementation, the Beidou network device determines that the reception time of the first application layer message is the same as the reception time of the second application layer message, and the Beidou network device directly uses the first key to decrypt the second encrypted data.

[0361] The above content elaborates on the method provided by the present application. In order to facilitate better implementation of the above scheme of the embodiment of the present application, the embodiment of the present application also provides corresponding devices or equipment.

[0362] In the embodiment of the present application, the terminal 100 can be divided into functional modules according to the above method example. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one processing module. The above integrated modules can be implemented in the form of hardware or in the form of software functional modules. It should be noted that the division of modules in the embodiment of the present application is schematic and is only a logical functional division. In actual implementation, there may be other division methods.

[0363] The following will be combined Figures 11 to 14 The communication device according to the embodiment of the present application is described in detail.

[0364] In the case of integrated units, see Figure 11 , Figure 11 1 is a schematic diagram of the structure of the communication device 1100 provided in an embodiment of the present application. The communication device 1100 may be the terminal 100 in the above embodiment. Optionally, the communication device 1100 may be a chip / chip system, for example, a Beidou communication chip. Figure 11 As shown, the communication device 1100 may include a transceiver unit 1110 and a processing unit 1120 .

[0365] In one design, processing unit 1120 may be configured to generate a first key based on a user identification code IMSI, an identity identification key Ki, and a sending time of an application layer message.

[0366] The processing unit 1120 is further configured to encrypt the first original data using the first key to obtain first encrypted data.

[0367] Processing unit 1120 is further configured to add message header information to the first encrypted data to obtain a first application layer message. The message header information includes a time indication field and an encryption indication field. The encryption indication field is used to indicate a preset encryption algorithm used when encrypting the first original data. The time indication field is used to indicate the time information of sending the first application layer message.

[0368] The transceiver unit 1110 may be configured to send a first application layer message to the Beidou network device 200 .

[0369] Optionally, the transceiver unit 1110 may also be used to perform the above Figure 10 The terminal 100 in the illustrated method embodiment performs the functional steps related to sending and receiving.

[0370] Optionally, the processing unit 1120 may also be configured to execute the above Figure 10 The method embodiment shown includes the functional steps of protocol parsing and encapsulation and calculation determination performed by the terminal 100.

[0371] It should be understood that the communication device 1100 in this design can execute the method steps executed by the terminal 100 in the aforementioned embodiment. For the sake of brevity, they will not be repeated here.

[0372] In the case of integrated units, see Figure 12 , Figure 121 is a structural diagram of the communication device 1200 provided in an embodiment of the present application. The communication device 1200 may be the BeiDou network device 200 in the above embodiment. Optionally, the communication device 1200 may be a specific network element in the BeiDou network device 200, for example, a network element or a combination of multiple network elements in the BeiDou ground transceiver station 22, the BeiDou central station 23, and the BeiDou short message fusion communication platform 24. Figure 12 As shown, the communication device 1200 may include a transceiver unit 1210 and a processing unit 1220 .

[0373] In one design, the transceiver unit 1210 can be used to receive the first application layer message sent by the terminal 100.

[0374] The processing unit 1220 may be configured to generate a second key through the cellular network device based on the time indication field and the reception time of the first application layer message.

[0375] The processing unit 1220 is further configured to obtain the first original data after successfully decrypting the first encrypted data using the second key.

[0376] Optionally, the transceiver unit 1210 may also be used to perform the above Figure 10 The Beidou network device 200 in the illustrated method embodiment performs the functional steps related to sending and receiving.

[0377] Optionally, the processing unit 1220 may also be configured to execute the above Figure 10 The method embodiment shown includes the functional steps of protocol parsing and encapsulation and calculation determination performed by the Beidou network device 200.

[0378] It should be understood that the communication device 1200 in this design can execute the method steps executed by the Beidou network device 200 in the aforementioned embodiment. For the sake of brevity, they will not be repeated here.

[0379] The above describes the terminal 100 and BeiDou network device 200 of the embodiment of the present application. It should be understood that any device having the above Figure 11 Any product having the functions of the terminal 100 as described above Figure 12 Any product that implements the functions of the Beidou network device 200 falls within the protection scope of the embodiments of the present application.

[0380] As a possible product form, the terminal 100 described in the embodiment of the present application can be implemented by a general bus architecture.

[0381] See also Figure 13 , Figure 13 1 is a schematic diagram of the structure of the communication device 1300 provided in an embodiment of the present application. The communication device 1300 may be the terminal 100, or a device therein. Figure 13 As shown, the communication device 1300 includes a processor 1301 and a transceiver 1302 internally connected to and communicating with the processor. The processor 1301 can be a general-purpose processor or a dedicated processor. For example, it can be a baseband processor or a central processing unit for satellite communication. The baseband processor for satellite communication can be used to process satellite communication protocols and satellite communication data, and the central processing unit can be used to control the communication device (such as a baseband chip, terminal, terminal chip, etc.), execute computer programs, and process computer program data. The transceiver 1302 can be called a transceiver unit, a transceiver, or a transceiver circuit, etc., and is used to implement transceiver functions. The transceiver 1302 can include a receiver and a transmitter. The receiver can be called a receiver or a receiving circuit, etc., and is used to implement the receiving function; the transmitter can be called a transmitter or a transmitting circuit, etc., and is used to implement the transmitting function. Optionally, the communication device 1300 can also include an antenna 1303 and / or a radio frequency unit (not shown). The antenna 1303 and / or the radio frequency unit may be located inside the communication device 1300 or may be separated from the communication device 1300 , that is, the antenna 1303 and / or the radio frequency unit may be remotely or distributedly deployed.

[0382] Optionally, the communication device 1300 may include one or more memories 1304, on which instructions may be stored. The instructions may be computer programs. The computer programs may be executed on the communication device 1300 to enable the communication device 1300 to perform the methods described in the above method embodiments. Optionally, the memories 1304 may also store data. The communication device 1300 and the memories 1304 may be provided separately or integrated together.

[0383] The processor 1301 , the transceiver 1302 , and the memory 1304 may be connected via a communication bus.

[0384] In one design, the communication device 1300 may be configured to perform the functions of the terminal 100 in the aforementioned embodiment: the processor 1301 may be configured to perform the aforementioned Figure 11 In the embodiment shown, the terminal 100 performs the protocol parsing and encapsulation and the functional steps determined by the operation and / or other processes used in the technology described herein; the transceiver 1302 can be used to perform the above Figure 11 The terminal 100 in the illustrated embodiment performs functional steps related to transmission and reception and / or other processes for the technology described herein.

[0385] In any of the above designs, processor 1301 may include a transceiver for implementing receiving and transmitting functions. For example, the transceiver may be a transceiver circuit, an interface, or an interface circuit. The transceiver circuit, interface, or interface circuit for implementing the receiving and transmitting functions may be separate or integrated. The transceiver circuit, interface, or interface circuit may be used for reading and writing code / data, or the transceiver circuit, interface, or interface circuit may be used for transmitting or delivering signals.

[0386] In any of the above designs, processor 1301 may store instructions, which may be computer programs. The computer programs, when executed on processor 1301, may cause communication device 1300 to execute the method steps performed by terminal 100 in the above method embodiments. The computer programs may be fixed in processor 1301, in which case processor 1301 may be implemented by hardware.

[0387] In one implementation, the communication device 1300 may include a circuit that can implement the functions of sending, receiving, or communicating in the aforementioned method embodiments. The processor and transceiver described in this application can be implemented on an integrated circuit (IC), an analog IC, a radio frequency integrated circuit RFIC, a mixed signal IC, an application specific integrated circuit (ASIC), a printed circuit board (PCB), an electronic device, etc. The processor and transceiver can also be manufactured using various IC process technologies, such as complementary metal oxide semiconductor (CMOS), N-type metal oxide semiconductor (nMetal-oxide-semiconductor, NMOS), P-type metal oxide semiconductor (positive channel metal oxide semiconductor, PMOS), bipolar junction transistor (bipolar junction transistor, BJT), bipolar CMOS (BiCMOS), silicon germanium (SiGe), gallium arsenide (GaAs), etc.

[0388] The scope of the communication device described in this application is not limited thereto, and the structure of the communication device may not be limited thereto. Figure 13 The communication device 1300 may be an independent device or may be part of a larger device. For example, the communication device 1300 may be:

[0389] (1) An independent integrated circuit (IC), or chip, or chip system or subsystem;

[0390] (2) a collection of one or more ICs, optionally including a storage component for storing data and computer programs;

[0391] (3) ASIC, such as modem;

[0392] (4) Modules that can be embedded in other devices;

[0393] (5) Receivers, terminals, smart terminals, cellular phones, wireless devices, handheld devices, mobile units, vehicle-mounted devices, network devices, cloud devices, artificial intelligence devices, etc.;

[0394] (6)Others, etc.

[0395] As a possible product form, any network element in the Beidou network device 200 described in the embodiment of the present application (for example, the Beidou ground transceiver station 22, the Beidou central station 23, the Beidou short message fusion communication platform 24) can be implemented by a general bus architecture.

[0396] See also Figure 14 , Figure 14 1 is a schematic diagram of the structure of the communication device 1400 provided in the embodiment of the present application. The communication device 1400 may be the Beidou network device 200, or a device therein. Figure 14 As shown, the communication device 1400 includes a processor 1401 and a transceiver 1402 connected to the internal communication of the processor. The processor 1401 is a general-purpose processor or a dedicated processor. For example, it can be a baseband processor or a central processing unit for satellite communication. The baseband processor for satellite communication can be used to process satellite communication protocols and satellite communication data, and the central processing unit can be used to control the communication device (such as a baseband chip, etc.), execute computer programs, and process computer program data. The transceiver 1402 can be called a transceiver unit, a transceiver, or a transceiver circuit, etc., for implementing transceiver functions. The transceiver 1402 can include a receiver and a transmitter. The receiver can be called a receiver or a receiving circuit, etc., for implementing a receiving function; the transmitter can be called a transmitter or a transmitting circuit, etc., for implementing a transmitting function. Optionally, the communication device 1400 can also include an antenna 1403 and / or a radio frequency unit (not shown). The antenna 1403 and / or the radio frequency unit may be located inside the communication device 1400 or may be separated from the communication device 1400 , that is, the antenna 1403 and / or the radio frequency unit may be remotely or distributedly deployed.

[0397] Optionally, the communication device 1400 may include one or more memories 1404, on which instructions may be stored. The instructions may be computer programs. The computer programs may be executed on the communication device 1400 to enable the communication device 1400 to perform the methods described in the above method embodiments. Optionally, the memories 1404 may also store data. The communication device 1400 and the memories 1404 may be provided separately or integrated together.

[0398] The processor 1401 , the transceiver 1402 , and the memory 1404 may be connected via a communication bus.

[0399] In one design, the communication device 1400 can be used to perform the functions of the Beidou network device 200 in the above embodiment: the processor 1401 can be used to perform the above Figure 11 In the embodiment shown, the Beidou network device 200 performs the protocol parsing and encapsulation and the functional steps determined by the operation and / or other processes used in the technology described herein; the transceiver 1402 can be used to perform the above Figure 11 The Beidou network device 200 in the illustrated embodiment performs functional steps related to sending and receiving and / or other processes for the technology described herein.

[0400] In any of the above designs, processor 1401 may include a transceiver for implementing receiving and transmitting functions. For example, the transceiver may be a transceiver circuit, an interface, or an interface circuit. The transceiver circuit, interface, or interface circuit for implementing the receiving and transmitting functions may be separate or integrated. The transceiver circuit, interface, or interface circuit may be used for reading and writing code / data, or the transceiver circuit, interface, or interface circuit may be used for transmitting or delivering signals.

[0401] In any of the above designs, processor 1401 may store instructions, which may be computer programs. The computer programs, when executed on processor 1401, may cause communication device 1400 to execute the method steps performed by terminal 100 in the above method embodiments. The computer programs may be fixed in processor 1401, in which case processor 1401 may be implemented by hardware.

[0402] An embodiment of the present application further provides a computer-readable storage medium, in which a computer program code is stored. When the processor executes the computer program code, the electronic device executes the method in any of the aforementioned embodiments.

[0403] An embodiment of the present application further provides a computer program product, which, when executed on a computer, enables the computer to execute the method in any of the aforementioned embodiments.

[0404] An embodiment of the present application also provides a communication device, which can exist in the form of a chip product. The structure of the device includes a processor and an interface circuit. The processor is used to communicate with other devices through a receiving circuit, so that the device executes the method in any of the aforementioned embodiments.

[0405] An embodiment of the present application further provides a Beidou communication system, including a terminal 100 and a Beidou network device 200. The terminal 100 and the Beidou network device 200 can execute the method in any of the aforementioned embodiments.

[0406] This application describes the short message communication function of the Beidou communication system. It is understood that other satellite systems may also support short message communication functions. Therefore, the method described in this application is not limited to the Beidou communication system. If other satellite systems also support short message communication functions, the method described in this application is also applicable to communications in other satellite systems.

[0407] The steps of the method or algorithm described in conjunction with the disclosure of this application can be implemented in hardware or by executing software instructions by a processor. The software instructions can be composed of corresponding software modules, which can be stored in random access memory (RAM), flash memory, erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), registers, hard disks, mobile hard disks, read-only compact disks (CD-ROMs), or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and the storage medium can be located in an ASIC. In addition, the ASIC can be located in a core network interface device. Of course, the processor and the storage medium can also exist in the core network interface device as discrete components.

[0408] Those skilled in the art will appreciate that, in one or more of the examples above, the functions described herein can be implemented using hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. Computer-readable media include computer-readable storage media and communication media, wherein communication media include any medium that facilitates the transmission of a computer program from one place to another. The storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer.

[0409] As described above, the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.

Claims

1. A key updating method in a satellite communication system, characterized in that: include: The terminal generates a first key based on the user identification code IMSI, the identity identification key Ki and the sending time of the first application layer message; The terminal encrypts the first original data using the first key to obtain first encrypted data; The terminal adds message header information to the first encrypted data to obtain a first application layer message; wherein the message header information includes a time indication field and an encryption indication field, the encryption indication field is used to indicate a preset encryption algorithm used when encrypting the first original data, and the time indication field is used to indicate sending time information of the first application layer message; The terminal sends the first application layer message to the satellite network device.

2. The method according to claim 1, characterized in that The sending time of the first application layer message is a first time point or a second time point; wherein, the first time point is the time point when the terminal obtains the first original data, and the second time point is the time point obtained when the terminal generates the first key.

3. The method according to claim 1, characterized in that The terminal generates a first key based on the user identification code IMSI, the identity identification key Ki and the sending time of the first application layer message, specifically including: The terminal obtains a random number RAND based on the sending time and IMSI of the first application layer message; The terminal obtains an encryption key Kc through a preset key algorithm 1 based on the RAND and a preset Ki, and obtains an authentication symbol response SRES through a preset key algorithm 2; The terminal obtains the first key through a preset key algorithm 3 based on the Kc and SRES.

4. The method according to claim 1, wherein Before the terminal uses the first key to encrypt the first original data, the method further includes: The terminal may also compress the first original data.

5. The method according to claim 1, wherein After the terminal sends the first application layer message to the satellite network device, the method further includes: The terminal receives a first application layer receipt sent by the satellite network device, where the first application layer receipt is used to indicate that the satellite network device has successfully decrypted the first application layer message.

6. The method according to any one of claims 1 to 5, characterized in that After the terminal sends the first application layer message to the satellite network device, the method further includes: The terminal generates a third key based on the IMSI, Ki and the sending time of the second application layer message; The terminal encrypts the second original data using the third key to obtain second encrypted data; The terminal adds message header information to the second encrypted data to obtain a second application layer message; wherein the message header information includes a time indication field and an encryption indication field, the encryption indication field is used to indicate a preset encryption algorithm used when encrypting the second original data, and the time indication field is used to indicate sending time information of the second application layer message; The terminal sends the second application layer message to the satellite network device; The terminal receives a second application layer receipt sent by the satellite network device, where the second application layer receipt is used to indicate that the satellite network device fails to decrypt the second application layer message.

7. The method according to claim 6, characterized in that After the terminal receives the second application layer receipt sent by the satellite network device, the method further includes: The terminal retransmits the second application layer message.

8. The method according to claim 6, characterized in that After the terminal receives the second application layer receipt sent by the satellite network device, the method further includes: The terminal displays failure prompt information, where the failure prompt information is used to indicate that the satellite network device fails to decrypt the second application layer message.

9. The method according to any one of claims 1 to 5, characterized in that The value of the time indication field is used to indicate the parity value of the sending time of the first application layer message.

10. A key updating method in a satellite communication system, characterized in that: include: The satellite network device receives a first application layer message sent by a terminal; wherein the first application layer message includes first encrypted data and message header information, the message header information includes a time indication field and an encryption indication field, the encryption indication field is used to indicate a preset encryption algorithm used when encrypting the first original data, and the time indication field is used to indicate sending time information of the first application layer message; The satellite network device generates a second key through the cellular network device based on the time indication field and the reception time of the first application layer message; The satellite network device successfully decrypts the first encrypted data using the second key to obtain the first original data.

11. The method according to claim 10, characterized in that The satellite network device generates a second key through the cellular network device based on the time indication field and the reception time of the first application layer message, specifically including: The satellite network device determines, based on the time indication field and the reception time of the first application layer message, a sending time of the first application layer message; The satellite network device obtains a random number RAND based on the sending time of the first application layer message and the user identification code IMSI obtained from the cellular network device; The satellite network device sends the RAND to the cellular network device; The satellite network device obtains the encryption key Kc and the authentication symbol response SRES fed back by the cellular network device; The terminal obtains the second key through a preset key algorithm 3 based on the Kc and the SRES.

12. The method according to claim 10, characterized in that The reception time of the first application layer message is a specified time point between the third time point and the fourth time point, and the unit of the reception time of the first application layer message is hours; wherein, the third time point is the time point when the satellite network device receives the first satellite link control layer protocol data unit SLCPDU of the first application layer message, and the fourth time point is the time point obtained when the satellite network device generates the second key.

13. The method according to claim 10, characterized in that The value of the time indication field is used to indicate the parity value of the sending time of the first application layer message.

14. The method according to claim 13, characterized in that The satellite network device determines, based on the time indication field and the reception time of the first application layer message, a sending time of the first application layer message, specifically including: When the parity value of the sending time of the first application layer message indicated by the value of the time indication field is the same as the parity value of the receiving time of the first application layer message, the satellite network device determines that the sending time of the first application layer message is the same as the receiving time of the first application layer message; When the parity value of the sending time of the first application layer message indicated by the value of the time indication field is different from the parity value of the receiving time of the first application layer message, the satellite network device determines that the difference between the receiving time of the first application layer message and the sending time of the first application layer message is 1.

15. The method according to claim 10, characterized in that After the satellite network device successfully decrypts the first encrypted data using the second key to obtain the first original data, the method further includes: The satellite network device generates a first application layer receipt, where the first application layer receipt is used to indicate that the satellite network device has successfully decrypted the first application layer message; The satellite network device sends the first application layer receipt to the terminal.

16. The method according to any one of claims 10 to 15, characterized in that After the satellite network device successfully decrypts the first encrypted data using the second key to obtain the first original data, the method further includes: The satellite network device receives a second application layer message sent by the terminal; wherein the second application layer message includes second encrypted data and message header information, the message header information includes a time indication field and an encryption indication field, the encryption indication field is used to indicate a preset encryption algorithm used when encrypting the second original data, and the time indication field is used to indicate sending time information of the second application layer message; The satellite network device generates a fourth key through the cellular network device based on the time indication field and the reception time of the second application layer message; The satellite network device fails to decrypt the second encrypted data using the fourth key, and the satellite network device generates a second application layer receipt, where the second application layer receipt is used to indicate that the satellite network device fails to decrypt the second application layer message; The satellite network device sends the second application layer receipt to the terminal.

17. A satellite communication system, characterized in that: include: Terminals and satellite network equipment; among which, The terminal is configured to generate a first key based on the user identification code IMSI, the identity identification key Ki and the sending time of the first application layer message; The terminal is further configured to encrypt the first original data using the first key to obtain first encrypted data; The terminal is further configured to add message header information to the first encrypted data to obtain a first application layer message; wherein the message header information includes a time indication field and an encryption indication field, the encryption indication field is used to indicate a preset encryption algorithm used when encrypting the first original data, and the time indication field is used to indicate sending time information of the first application layer message; The terminal is further configured to send the first application layer message to the satellite network device; The satellite network device is configured to receive the first application layer message sent by the terminal; The satellite network device is further configured to generate a second key through a cellular network device based on the time indication field and a reception time of the first application layer message; The satellite network device is further configured to successfully decrypt the first encrypted data using the second key to obtain the first original data.

18. A communication device, characterized in that: The communication device comprises one or more processors, one or more memories, and a transceiver; wherein the transceiver and the one or more memories are coupled to the one or more processors, the one or more memories are used to store computer program code, and the computer program code includes computer instructions. When the one or more processors execute the computer instructions, the communication device executes the method according to any one of claims 1 to 9.

19. The communication device according to claim 18, wherein: The communication device is a terminal.

20. A communication device, characterized in that: The communication device comprises one or more processors, one or more memories, and a transceiver; wherein the transceiver and the one or more memories are coupled to the one or more processors, the one or more memories are used to store computer program code, and the computer program code includes computer instructions. When the one or more processors execute the computer instructions, the communication device executes the method according to any one of claims 10 to 16.

21. The communication device according to claim 20, wherein: The communication device is a satellite network device.

22. A computer-readable storage medium, wherein instructions are stored in the computer-readable storage medium, and when the instructions are executed on a computer, the computer is caused to execute the method according to any one of claims 1 to 9.

23. A computer-readable storage medium, wherein instructions are stored in the computer-readable storage medium, and when the instructions are executed on a computer, the computer is caused to execute the method according to any one of claims 10 to 16.

24. A chip or chip system, applied to a terminal, characterized in that: The method comprises a processing circuit and an interface circuit, wherein the interface circuit is used to receive code instructions and transmit the code instructions to the processing circuit, and the processing circuit is used to run the code instructions to execute the method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Beidou short message data transmission method and device, electronic equipment and computer medium

    CN111669219A

  • Secure data transmission method and system for satellite short message communication

    CN112615660A