Satellite network connection methods, devices, equipment, and storage media
By using satellite network connectivity and vehicle terminal identification codes for authentication, a dedicated communication tunnel is established, solving the problem of vehicles being unable to access cloud service platforms globally and enabling the normal operation of vehicle-to-everything (V2X) services.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-31
- Publication Date
- 2026-03-10
AI Technical Summary
Globally, vehicles are unable to access automakers' cloud service platforms, especially in countries with low network coverage. This prevents services such as vehicle software updates and remote control from being implemented, impacting the reputation of vehicle manufacturers.
By using satellite network connectivity and vehicle-mounted terminal identification codes for authentication, a dedicated communication tunnel is established to achieve direct connection with the enterprise cloud platform, avoiding reliance on carrier networks.
Support the construction of enterprise private networks that do not rely on operator networks, solve the problem of vehicles being unable to access domestic networks abroad, and ensure the normal operation of vehicle networking services such as software upgrades and fault diagnosis.
Smart Images

Figure CN115696635B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of satellite communication technology, specifically to a satellite network connection method, apparatus, device, and storage medium. Background Technology
[0002] With the widespread application of vehicle-to-everything (V2X) communication, the demand for services such as vehicle-mounted terminals accessing the network, timely reporting of vehicle status, and receiving remote control signals is becoming increasingly diverse. However, as Chinese-made vehicles are exported and distributed around the world, some countries' telecommunications operators cannot access my country's core network system, and some countries have low network coverage. This results in vehicles being unable to properly access automakers' cloud service platforms and unable to update vehicle software versions in a timely manner, which to some extent affects the reputation of vehicle manufacturers.
[0003] Currently, satellite communication applications are gradually penetrating various industries, and vehicle-to-everything (V2X) applications based on satellite communication are an inevitable future trend. However, SIM card-based network access methods face interoperability barriers between national telecommunications systems, especially in countries with poor network coverage, where even terrestrial network access is challenging. Therefore, it is necessary to consider satellite communication networks that do not rely on SIM cards to solve the problem of global V2X access. Summary of the Invention
[0004] In view of the shortcomings of the prior art described above, the present invention provides a satellite network connection method to solve the above technical problems.
[0005] The satellite network connection method provided by the present invention includes: initiating a wireless connection request to a satellite through a public channel so that the satellite allocates a dedicated channel;
[0006] Receive configuration information sent by the satellite and configure a dedicated channel according to the configuration information;
[0007] The wireless connection establishment completion information is sent through a dedicated channel. The wireless connection establishment completion information carries the vehicle terminal identification code, which is used to identify the enterprise to which the enterprise belongs and to initiate an identity authentication request to the corresponding enterprise cloud platform.
[0008] Receive authentication and encryption commands;
[0009] Based on the authentication and encryption commands, calculate the corresponding secret key or key and send it to the enterprise cloud platform so that the enterprise cloud platform can identify the legitimate identity and send identity authentication information, which includes whether the identity is legitimate or illegitimate. If the identity authentication information is legitimate, establish a dedicated communication tunnel with the enterprise cloud platform.
[0010] In an exemplary embodiment of this application, the method for identifying the enterprise through the vehicle terminal identification code and initiating an identity authentication request to the corresponding enterprise cloud platform includes:
[0011] Send a user access initialization request to the gateway station, and send the configuration information and vehicle terminal identification code to the gateway station so as to identify the enterprise to which the enterprise belongs based on the vehicle terminal identification code, and initiate an identity authentication request to the corresponding enterprise cloud platform;
[0012] After verifying whether the vehicle terminal identification code corresponds to the company's equipment, an authentication success command or authentication failure command is issued so that the gateway station can determine whether the associated company is correct. If the associated company is correct, an authentication and encryption command is sent.
[0013] In an exemplary embodiment of this application, after verifying whether the vehicle terminal identification code corresponds to the enterprise's equipment, an identity authentication message is sent so that the gateway station can determine whether the associated enterprise is correct. If the associated enterprise is correct, an authentication and encryption command is sent, including:
[0014] If the vehicle terminal identification code does not correspond to the company's equipment or the vehicle terminal identification code has expired, an authentication failure command is sent. The authentication failure command includes a failure reason code, which enables the gateway station to notify the satellite to disconnect from the vehicle terminal and send the failure reason code.
[0015] In an exemplary embodiment of this application, calculating the corresponding secret key or critical key based on the authentication and encryption command and sending it to the enterprise cloud platform includes:
[0016] Calculate the corresponding secret key or key based on the authentication and encryption commands;
[0017] The response message is encrypted, and includes a corresponding secret key or key, before being sent to the enterprise cloud platform.
[0018] In an exemplary embodiment of this application, the enterprise cloud platform identifies a legitimate identity and sends identity authentication information, which includes whether the identity is legitimate or illegitimate. When the identity authentication information indicates a legitimate identity, a dedicated communication tunnel with the enterprise cloud platform is established, including:
[0019] The enterprise cloud platform failed to decrypt the response message normally, the authentication process failed, and the gateway station was notified that the identity authentication was invalid. This prompted the gateway station to notify the satellite to disconnect from the vehicle terminal and send a failure reason code.
[0020] In an exemplary embodiment of this application, when the identity authentication information indicates that the identity is valid, the gateway station establishes a dedicated communication tunnel between the vehicle terminal and the enterprise cloud platform for business data transmission.
[0021] In an exemplary embodiment of this application, the vehicle terminal identification code includes a manufacturer code, production year, production month, production day, terminal supplier code, and verification code.
[0022] This application also provides a satellite network connection device, the device comprising:
[0023] The satellite access module initiates a wireless connection request to the satellite through a public channel to enable the satellite to allocate a dedicated channel; it also receives configuration information sent by the satellite and configures the dedicated channel according to the configuration information; it sends a wireless connection establishment completion message through the dedicated channel, which carries a vehicle terminal identification code for identifying the enterprise to which the vehicle terminal belongs and initiating an identity authentication request to the corresponding enterprise cloud platform; and it receives authentication and encryption commands.
[0024] The information response module calculates the corresponding key or critical key based on the authentication and encryption commands, and sends it to the enterprise cloud platform so that the enterprise cloud platform can identify the legitimate identity and send identity authentication information, which includes whether the identity is legitimate or illegitimate. If the identity authentication information is legitimate, a dedicated communication tunnel with the enterprise cloud platform is established.
[0025] This application also provides an electronic device, which includes:
[0026] One or more processors;
[0027] A storage device for storing one or more programs that, when executed by one or more processors, enable an electronic device to implement a satellite network connectivity method as described above.
[0028] This application also provides a machine-readable storage medium, characterized in that it stores a computer program thereon, which, when executed by a machine's processor, causes the machine to perform any of the satellite network connection methods described above.
[0029] The beneficial effects of this invention are as follows: The vehicle-mounted terminal in this invention accesses the network via satellite. After identity authentication and encryption are completed based on the vehicle-mounted terminal identification code and the enterprise cloud platform, it can directly transmit vehicle-to-everything (V2X) services with the enterprise cloud platform. This approach can support the construction of enterprise private networks that do not rely on operator networks, and it can also solve the problem of V2X services when the vehicle SIM card is invalid for some reason. In particular, when vehicles are sold overseas, if a foreign SIM card is installed, the car manufacturer can still conduct V2X services normally, such as software upgrades and fault diagnosis.
[0030] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description
[0031] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application. It is obvious that the drawings described below are merely some embodiments of this application, and those skilled in the art can obtain other drawings based on these drawings without any inventive effort. In the drawings:
[0032] Figure 1 This is a schematic diagram of a satellite network connection link shown in an exemplary embodiment of this application;
[0033] Figure 2 This is a schematic diagram illustrating a satellite network connection method based on a vehicle terminal identification code, as shown in an exemplary embodiment of this application.
[0034] Figure 3 This application Figure 2 The flowchart of step S230 in the illustrated embodiment is shown in an exemplary embodiment.
[0035] Figure 4 An authentication and encryption flowchart illustrated for an exemplary embodiment of this application;
[0036] Figure 5 A schematic diagram of a satellite network connection system shown as an exemplary embodiment of this application;
[0037] Figure 6 A schematic diagram illustrating a satellite network connection system authentication failure, as shown in an exemplary embodiment of this application;
[0038] Figure 7 This is a schematic diagram illustrating an invalid identity authentication in a satellite network connection system, as an exemplary embodiment of this application.
[0039] Figure 8 A schematic diagram of the structure of a computer system suitable for implementing the electronic device of the present application is shown. Detailed Implementation
[0040] The embodiments of the present invention will be described below with reference to the accompanying drawings and preferred embodiments. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be understood that the preferred embodiments are only for illustrating the present invention and not for limiting the scope of protection of the present invention.
[0041] It should be noted that the illustrations provided in the following embodiments are only schematic representations of the basic concept of the present invention. Therefore, the drawings only show the components related to the present invention and are not drawn according to the actual number, shape and size of the components in the actual implementation. In the actual implementation, the form, quantity and proportion of each component can be arbitrarily changed, and the layout of the components may also be more complex.
[0042] In the following description, numerous details are explored to provide a more thorough explanation of embodiments of the invention. However, it will be apparent to those skilled in the art that embodiments of the invention may be practiced without these specific details. In other embodiments, well-known structures and devices are shown in block diagram form rather than in detail to avoid obscuring embodiments of the invention.
[0043] Satellite communication is communication between radio communication stations on Earth (including the ground and the lower atmosphere) using satellites as relays. A satellite communication system consists of two parts: a satellite and earth stations. The characteristics of satellite communication are: large communication range; communication can be made between any two points within the coverage area of the satellite's emitted radio waves; it is not easily affected by land-based disasters (high reliability); it can be activated simply by setting up earth station circuits (rapid circuit activation); it can receive signals from multiple locations simultaneously, enabling economical broadcasting and multiple access communication (multiple access feature); circuit setup is very flexible, allowing for the distribution of excessively concentrated traffic; the same channel can be used in different directions or different areas (multiple access connection).
[0044] Satellite communication ground systems typically employ a star topology, comprising gateway stations and user stations. Gateway stations have a large capacity and are generally equipped with large-aperture antennas to connect the terrestrial network and the satellite feed beam. User stations communicate with the gateway stations via communication satellites. Typically, user stations transmit relatively small amounts of data to the gateway stations, while backhaul data transmission is significantly larger. In addition, satellite communication ground systems also include a network operations center for managing the satellite network and user services.
[0045] With the widespread application of satellite communication networks, areas with insufficient terrestrial network coverage can access the network through satellite communication systems. In addition to authenticating the SIM card, the access device also needs to be authenticated to ensure that it is a legitimate user accessing the network.
[0046] As my country's car exports increase, if these vehicles are equipped with local SIM cards, their access to my country's satellite network and domestic operators' core network is similar to a foreign SIM card accessing my country's operator network. However, the authentication mechanisms relying on SIM cards and core networks may deem the user an unauthorized user and not support service transmission. Alternatively, if there are interoperability difficulties between some foreign operators and my country's network, identity verification may also be impossible.
[0047] Figure 1 This is a schematic diagram of a satellite network connection link illustrated in an exemplary embodiment of this application. It includes a vehicle, a communication satellite, a gateway station, and an enterprise cloud platform. The vehicle has satellite access capabilities and a globally unique vehicle terminal identification code. In one embodiment, the vehicle terminal identification code can be a TUID, composed of 32 bits, with the following encoding rules:
[0048] GGGTTMMMYYYYMMDDSSXXXXXXXXXXXXVV
[0049] in:
[0050] GGG indicates the country code;
[0051] TT indicates the device type, and the type can take the following values;
[0052] MMM stands for car manufacturer;
[0053] YYYY indicates the year of production, such as 2016 indicating 2016;
[0054] MM represents the month of production, such as 12 representing December;
[0055] DD represents the coded production date, such as 31 representing the 31st;
[0056] The two digits SS represent the terminal supplier;
[0057] XXXXXXXXXXXX: Represents 12 decimal digits (can be a serial number);
[0058] VV represents the checksum of the first 30 digits of the TUID string.
[0059] The satellite possesses functions such as wireless resource management, wireless link maintenance, and mobility management, similar to the eNodeB in LTE systems and the gNodeB in 5G systems. The gateway station connects the satellite link to the ground system, possessing functions such as satellite terminal access management, gateway function for satellite network access to the ground network, and identification of the enterprise cloud corresponding to the vehicle terminal identification code. The enterprise cloud platform has functions such as vehicle identity failure and encryption, and TSP services.
[0060] To address the aforementioned problems, this invention proposes a satellite network connection method based on vehicle terminal identification codes within a global satellite communication system environment, in order to solve the problem of vehicle networking applications in areas with no network coverage or where foreign vehicle terminals cannot access domestic networks.
[0061] Figure 2This is a schematic diagram illustrating a satellite network connection method based on a vehicle terminal identification code, as shown in an exemplary embodiment of this application. The satellite network connection method based on a vehicle terminal identification code includes at least steps S210 to S240, which are described in detail below:
[0062] Step S210: Initiate a radio connection request to the satellite through a public channel so that the satellite can allocate a dedicated channel.
[0063] After the vehicle-mounted terminal activates the satellite access function and completes a random connection with the satellite, it initiates a wireless connection request to the satellite through a public satellite so that the satellite can allocate a dedicated channel.
[0064] Step S220: Receive configuration information sent by the satellite and configure a dedicated channel according to the configuration information.
[0065] After receiving the wireless connection request, the satellite allocates a dedicated channel to the vehicle-mounted terminal and sends the configuration information to the terminal via wireless connection establishment. The vehicle-mounted terminal then configures the dedicated channel upon receiving the configuration information.
[0066] Step S230: Send wireless connection establishment completion information through a dedicated channel. The wireless connection establishment completion information carries a vehicle terminal identification code, which is used to identify the enterprise to which the enterprise belongs and to initiate an identity authentication request to the corresponding enterprise cloud platform.
[0067] After the vehicle-mounted terminal is configured with a dedicated channel, it sends a wireless connection establishment completion message to the satellite through the dedicated channel. This message includes the vehicle-mounted terminal's identification code. Upon receiving the wireless connection establishment completion message from the dedicated channel, the satellite recognizes the successful wireless connection and sends a user access initialization request to the gateway station for authentication. Figure 3 A flowchart of identity authentication as an exemplary embodiment is shown below:
[0068] Step S310: Send a user access initialization request to the gateway station.
[0069] The satellite sends a user access initialization request to the gateway station to establish a connection with the enterprise cloud platform through the gateway station and to perform identity recognition and authentication.
[0070] Step S320: Send the configuration information and vehicle terminal identification code to the gateway station.
[0071] The satellite sends the wireless resource configuration information and vehicle terminal identification code of the vehicle terminal to the gateway station, so that the gateway station can identify the enterprise to which the vehicle terminal identification code belongs, and thus establish a connection with the cloud platform of the enterprise corresponding to the vehicle terminal identification code.
[0072] Step S330: Identify the enterprise to which the vehicle belongs based on the vehicle terminal identification code, and initiate an identity authentication request to the corresponding enterprise cloud platform.
[0073] Based on the manufacturer information in the vehicle terminal identification code, the company to which the vehicle terminal belongs is identified, and an identity authentication request is initiated to the corresponding company's cloud platform.
[0074] Step S340: Determine whether the vehicle terminal identification code belongs to this enterprise's terminal.
[0075] The enterprise cloud platform identifies the vehicle terminal identification code. When it confirms that the vehicle terminal identification code belongs to the enterprise terminal, it sends an authentication success command. After receiving the authentication success command, the gateway station sends authentication and encryption commands.
[0076] When the enterprise cloud platform verifies that the vehicle terminal identification code does not belong to the enterprise's terminal or that the vehicle terminal identification code has expired, the enterprise cloud platform notifies the gateway station of the authentication failure and sends a failure reason code. The gateway station then notifies the satellite to disconnect the wireless connection with the terminal and sends a failure reason code.
[0077] like Figure 4 As shown, Figure 4 The authentication and encryption flowchart shown in this exemplary embodiment illustrates that when a terminal receives an authentication and encryption command, it performs the relevant authentication and encryption processes, as detailed below:
[0078] Step S410: Receive authentication and encryption commands.
[0079] The terminal receives authentication and encryption commands sent by the gateway and responds accordingly.
[0080] Step S420: Calculate the corresponding secret key or key.
[0081] After receiving authentication and encryption commands, calculate the corresponding secret key or key for each command.
[0082] Step S430: Encrypt the response message, which includes a corresponding secret key or key, and send the encrypted response message to the enterprise cloud platform.
[0083] To ensure the security of information and data, the response message is encrypted. The response message includes a corresponding secret key or key. The encrypted response message is sent to the enterprise cloud platform so that the enterprise cloud platform can authenticate it.
[0084] The authentication and encryption design methods can be IPSEC, LTE authentication and encryption methods, 5G system AKA authentication methods, etc. This application does not limit the authentication and encryption technologies.
[0085] Step S440: Check if the response message was correctly decrypted.
[0086] After receiving the encrypted response message, the enterprise cloud platform decrypts and authenticates it. If the decryption is successful and the key is correct, the vehicle terminal is considered legitimate. The platform then sends the authentication information to the gateway station. After receiving the authentication information, the gateway station establishes a dedicated communication tunnel between the vehicle terminal and the enterprise cloud platform for business data transmission.
[0087] If the enterprise cloud platform fails to decrypt and authenticate the encrypted response message, it considers the vehicle terminal's identity illegitimate, sends an illegitimate authentication message and a failure reason code to the gateway station. Upon receiving the illegitimate authentication message, the gateway station determines the vehicle terminal's identity is illegitimate, notifies the satellite to disconnect from the vehicle terminal, and sends a failure reason code to the vehicle terminal.
[0088] Vehicles access the network via satellite and, after identity authentication and encryption based on the vehicle terminal identification code and the enterprise cloud platform, can directly transmit vehicle-to-everything (V2X) services with the enterprise cloud platform. This method supports the construction of enterprise private networks that do not rely on carrier networks and can also solve the problem of V2X services when the vehicle's SIM card is invalid for some reason. In particular, when vehicles are sold overseas, if a foreign SIM card is installed, the car manufacturer can still conduct V2X services normally, such as software upgrades and fault diagnosis.
[0089] This application also provides a satellite network connection device, comprising: a satellite access module, which initiates a wireless connection request to a satellite through a public channel to enable the satellite to allocate a dedicated channel; receives configuration information sent by the satellite and configures the dedicated channel according to the configuration information; sends wireless connection establishment completion information through the dedicated channel, the wireless connection establishment completion information carrying a vehicle terminal identification code for identifying the enterprise to which the vehicle terminal belongs and initiating an identity authentication request to the corresponding enterprise cloud platform; and receives authentication and encryption commands.
[0090] The information response module calculates the corresponding key or critical key based on the authentication and encryption commands, and sends it to the enterprise cloud platform so that the enterprise cloud platform can identify the legitimate identity and send identity authentication information, which includes whether the identity is legitimate or illegitimate. If the identity authentication information is legitimate, a dedicated communication tunnel with the enterprise cloud platform is established.
[0091] In another exemplary embodiment, the device is applied to a terminal device that has a satellite network connectivity application installed, and the device implements the functional modules provided for the satellite network connectivity application.
[0092] It should be noted that the satellite network connection device and the satellite network connection method provided in the above embodiments belong to the same concept. The specific operation methods of each module and unit have been described in detail in the method embodiments and will not be repeated here. In practical applications, the satellite network connection device provided in the above embodiments can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. This is not a limitation here.
[0093] Embodiments of this application also provide an electronic device, including: one or more processors; and a storage device for storing one or more programs, which, when executed by the one or more processors, cause the electronic device to implement the satellite network connection method provided in the above embodiments.
[0094] Figure 8 A schematic diagram of a computer system suitable for implementing the embodiments of this application is shown. It should be noted that... Figure 8 The computer system 800 of the electronic device shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of this application.
[0095] like Figure 8 As shown, the computer system 800 includes a Central Processing Unit (CPU) 801, which can perform various appropriate actions and processes based on a program stored in Read-Only Memory (ROM) 802 or a program loaded from storage portion 808 into Random Access Memory (RAM) 803, such as performing the methods described in the above embodiments. The RAM 803 also stores various programs and data required for system operation. The CPU 801, ROM 802, and RAM 803 are interconnected via a bus 804. An Input / Output (I / O) interface 805 is also connected to the bus 804.
[0096] The following components are connected to I / O interface 805: an input section 806 including a keyboard, mouse, etc.; an output section 807 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and speakers, etc.; a storage section 808 including a hard disk, etc.; and a communication section 809 including a network interface card such as a LAN (Local Area Network) card, modem, etc. The communication section 809 performs communication processing via a network such as the Internet. A drive 810 is also connected to I / O interface 805 as needed. A removable medium 811, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on drive 810 as needed so that computer programs read from it can be installed into storage section 808 as needed.
[0097] Specifically, according to embodiments of this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program including a computer program for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication section 809, and / or installed from removable medium 811. When the computer program is executed by central processing unit (CPU) 801, it performs various functions defined in the system of this application.
[0098] It should be noted that the computer-readable medium shown in the embodiments of this application can be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), flash memory, optical fiber, portable compact disc read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this application, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying a computer-readable computer program. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media can also be any computer-readable medium other than computer-readable storage media, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The computer program contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to wireless, wired, etc., or any suitable combination thereof.
[0099] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. Each block in a flowchart or block diagram may represent a module, segment, or portion of code, which contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0100] The units described in the embodiments of this application can be implemented in software or hardware, and the described units can also be located in a processor. The names of these units do not necessarily limit the specific unit itself.
[0101] Another aspect of this application provides a machine-readable storage medium storing a machine program that, when executed by a machine's processor, causes the machine to perform the satellite network connection method as described above. This machine-readable storage medium may be included in the electronic device described in the above embodiments, or it may exist independently and not incorporated into the electronic device.
[0102] Another aspect of this application provides a computer program product or computer program including computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the satellite network connection method provided in the various embodiments described above.
[0103] The above embodiments are merely illustrative of the principles and effects of the present invention and are not intended to limit the invention. Any person skilled in the art can modify or alter the above embodiments without departing from the spirit and scope of the present invention. Therefore, all equivalent modifications or alterations made by those skilled in the art without departing from the spirit and technical concept disclosed in the present invention should still be covered by the claims of the present invention.
Claims
1. A method of satellite network connection, characterized by, The method comprises: The vehicle terminal initiates a wireless connection request to the satellite through a public channel, so that the satellite allocates a dedicated channel; The vehicle terminal receives configuration information sent by the satellite, and configures the dedicated channel according to the configuration information; The vehicle terminal sends wireless connection establishment completion information through the dedicated channel, and the wireless connection establishment completion information carries a vehicle terminal identification code, which is used to identify the enterprise to which the vehicle terminal belongs, and initiates an identity authentication request to the corresponding enterprise cloud platform; The vehicle terminal receives an authentication and encryption command; The vehicle terminal calculates a corresponding secret key or key according to the authentication and encryption command, and sends it to the enterprise cloud platform, so that the enterprise cloud platform identifies a legal identity and sends identity authentication information, which includes legal identity or illegal identity. When the identity authentication information is legal, a dedicated communication tunnel is established with the enterprise cloud platform. Wherein, the step of identifying the enterprise to which the vehicle terminal belongs through the vehicle terminal identification code and initiating an identity authentication request to the corresponding enterprise cloud platform comprises: The satellite sends a user access initialization request to the gateway station, and sends the configuration information and the vehicle terminal identification code to the gateway station. The gateway station identifies the enterprise to which the vehicle terminal belongs according to the vehicle terminal identification code, and initiates an identity authentication request to the corresponding enterprise cloud platform. After the enterprise cloud platform identifies whether the vehicle terminal identification code corresponds to the enterprise equipment, it sends an identity authentication information, so that the gateway station determines whether the associated enterprise is correct. When the associated enterprise is correct, the authentication and encryption command is sent.
2. The method of claim 1, wherein, After the enterprise cloud platform identifies whether the vehicle terminal identification code corresponds to the enterprise equipment, it sends an identity authentication information, so that the gateway station determines whether the associated enterprise is correct. When the associated enterprise is correct, the authentication and encryption command is sent. When the vehicle terminal identification code does not correspond to the enterprise equipment or the vehicle terminal identification code has been invalidated, an identity authentication failure command is sent, and the identity authentication failure command includes a failure reason code, so that the gateway station disconnects the satellite and the vehicle terminal, and sends the failure reason code.
3. The method of claim 1, wherein, The vehicle terminal calculates a corresponding secret key or key according to the authentication and encryption command, and sends it to the enterprise cloud platform, which comprises: The vehicle terminal calculates a corresponding secret key or key according to the authentication and encryption command; The vehicle terminal encrypts the response message, which includes the corresponding secret key or key, and sends it to the enterprise cloud platform.
4. The method of claim 3, wherein, The enterprise cloud platform identifies a legal identity and sends identity authentication information, which includes legal identity or illegal identity. When the identity authentication information is legal, a dedicated communication tunnel is established with the enterprise cloud platform, which comprises: The enterprise cloud platform fails to normally decrypt the response message, and the authentication process fails. The gateway station is notified that the identity authentication is illegal, so that the gateway station disconnects the satellite and the vehicle terminal, and sends the failure reason code.
5. The method of claim 4, wherein, When the identity authentication information is legal, the gateway station establishes a special communication tunnel for the vehicle-mounted terminal and the enterprise cloud platform for business data transmission.
6. The method of claim 1, wherein, The vehicle-mounted terminal identification code comprises a manufacturer code, a production year, a production month, a production day, a terminal supplier code and a check code.
Citation Information
Patent Citations
Beidou positioning and communication integrated universal system and configuration method thereof
CN105842715A
A satellite safe access authentication method and a system
CN109039436A