Method and system for achieving satellite intersatellite data link security
By utilizing the SMF and inter-satellite communication functions of the core network in the 5G satellite communication system to determine the inter-satellite routing channels and security strategies, the problem of insufficient secure communication capabilities of inter-satellite links in the satellite communication system is solved, achieving the effects of secure transmission and energy saving.
Patent Information
- Application Number
- CN202111050641.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-09-08
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2041-09-08
AI Technical Summary
5G-based satellite communication systems are not yet able to provide secure inter-satellite link communication capabilities on demand, resulting in high satellite energy and computing consumption.
By receiving the tunnel establishment request message through the session management function SMF in the core network, the inter-satellite routing channel and routing information are determined, and the corresponding routing information and security policy information are sent to each satellite. The inter-satellite communication function is used to perform security operations to ensure the secure transmission of data packets on the inter-satellite link.
It realizes the on-demand provision of inter-satellite link secure communication capabilities, reduces the satellite's energy consumption and computing overhead, and ensures the consistency of security policies of communication channels.
Smart Images

Figure CN115776323B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of satellite communication technology, and more specifically, to a method and system for achieving inter-satellite data link security. Background Art
[0002] In 5G-based satellite communication networks, the user plane utilizes the GTP-U protocol. This means that data flows transmitted on the user plane are GTP-U data flows. Tag-based communication technology can be used on inter-satellite data links, allowing for high-speed and efficient data transmission using tags. To reduce limited satellite power consumption while meeting data security requirements, on-demand secure inter-satellite link communication capabilities are required. However, currently developing 5G-based satellite communication systems do not yet have a solution for this. Summary of the Invention
[0003] The present application provides a method and system for achieving inter-satellite data link security, which is used to solve the technical problem that the current 5G-based satellite communication system cannot provide inter-satellite link security communication capabilities on demand.
[0004] In a first aspect, a method for implementing inter-satellite data link security is provided, which is applied to a network controller of a bearer network, the method comprising:
[0005] Receive a tunnel establishment request message sent by a session management function SMF of the core network, where the tunnel establishment request message is sent by the SMF after receiving a protocol data unit PDU session establishment request sent by a user equipment UE, and the tunnel establishment request message includes tunnel information and security policy information;
[0006] Determining an inter-satellite routing channel and routing information according to the tunnel information in the tunnel establishment request message;
[0007] Send corresponding routing information and / or security policy information to each satellite on the inter-satellite routing channel.
[0008] In one possible implementation, sending corresponding routing information and / or security policy information to each satellite on the inter-satellite routing channel includes at least one of the following:
[0009] Sending first routing information and security policy information corresponding to the first routing information to an inter-satellite communication function entity of a source satellite, so that the source satellite performs corresponding security calculations based on the security policy information;
[0010] Sending second routing information to the inter-satellite communication function entity of the relay satellite;
[0011] The third routing information and security policy information corresponding to the third routing information are sent to the inter-satellite communication function entity of the destination satellite, so that the destination satellite performs corresponding security calculations based on the security policy information.
[0012] In one possible implementation, the tunnel information includes any one of the following:
[0013] Tunnel information between the Satellite-User Plane Function (S-UPF) of the source satellite and the S-UPF of the destination satellite;
[0014] Tunnel information between the satellite-gNB of the source satellite and the S-UPF of the destination satellite;
[0015] Tunnel information between the S-UPF of the source satellite and the S-gNB of the destination satellite;
[0016] Tunnel information between the S-gNB of the source satellite and the S-gNB of the destination satellite.
[0017] In a second aspect, a method for implementing inter-satellite data link security is provided, which is applied to the inter-satellite communication function of a source satellite, and the method includes:
[0018] Receive a first data packet sent by the S-UPF or S-gNB of the source satellite;
[0019] receiving routing information and security policy information corresponding to the routing information sent by a network controller, wherein the routing information is routing information related to a source satellite on an inter-satellite routing channel determined by the network controller;
[0020] Perform security operations on the first data packet according to the security policy information.
[0021] In one possible implementation, performing a security operation on the first data packet according to the security policy information includes:
[0022] Sending a first operation request to a security function of the source satellite, where the first operation request carries the security policy information and is used to request the security function of the source satellite to perform a cryptographic operation on the first data packet based on the security policy information;
[0023] Receive a first operation result fed back by the safety function of the source satellite.
[0024] In one possible implementation, the method further includes:
[0025] Determining the routing information and the next-hop satellite of the intersatellite link according to the routing information and the header information of the first data packet;
[0026] A second data packet is constructed according to the first operation result and the routing information of the next hop, and the second data packet is sent to the next hop satellite.
[0027] In one possible implementation, determining, based on the routing information and header information of the first data packet, routing information and a next-hop satellite of an intersatellite link includes:
[0028] According to the routing information and the header information of the first data packet, it is determined that the routing information of the next hop of the intersatellite link is the second routing information, and the next hop satellite is a relay satellite.
[0029] In a possible implementation, if the security policy information includes first cryptographic operation information, the first operation request further carries: the first data packet and destination satellite identification information; or,
[0030] If the security policy information includes: key identification information and first cryptographic operation information, the first operation request also carries the first data packet.
[0031] In a third aspect, a method for implementing inter-satellite data link security is provided, which is applied to the inter-satellite communication function of a destination satellite, the method comprising:
[0032] receiving a third data packet sent by an inter-satellite communication function of a relay satellite, wherein the third data packet is constructed by the inter-satellite communication function of the relay satellite based on a second data packet and routing information from a network controller, wherein the second data packet comes from the inter-satellite communication function of a source satellite;
[0033] receiving routing information sent by the network controller and security policy information corresponding to the routing information, wherein the routing information is routing information related to a destination satellite on an inter-satellite routing channel determined by the network controller;
[0034] Determining, based on the header information of the third data packet and the routing information, data in the third data packet that needs to be security-related processed;
[0035] Perform security operations on the data packets that need to be processed security-related according to the security policy information.
[0036] In one possible implementation, performing security operations on the data packet requiring security-related processing according to the security policy information includes:
[0037] sending a second operation request to a security function of a destination satellite, where the second operation request carries the security policy information and is used to request the security function of the destination satellite to perform a cryptographic operation on the data requiring security-related processing based on the security policy information;
[0038] Receive a second operation result fed back by the safety function of the destination satellite.
[0039] In one possible implementation, the method further includes:
[0040] Send the second operation result to the S-UPF or S-gNB of the destination satellite.
[0041] In a possible implementation, if the security policy information includes second cryptographic operation information, the second operation request further carries: the data requiring security-related processing and source satellite identification information; or,
[0042] If the security policy information includes: key identification information and second cryptographic operation information, the second operation request also carries: the data that needs to be processed in a security-related manner.
[0043] In a fourth aspect, a system for implementing satellite inter-satellite data link security is provided, the system comprising: a satellite, a session management function SMF of a core network, and a network controller of a bearer network, wherein:
[0044] A network controller in the bearer network is configured to determine an inter-satellite routing channel and routing information according to a tunnel establishment request message from the SMF, and send corresponding routing information and / or security policy information to each satellite on the inter-satellite routing channel, wherein each satellite on the inter-satellite routing channel includes a source satellite, a relay satellite, and a destination satellite. The tunnel establishment request message is sent by the SMF after receiving a protocol data unit (PDU) session establishment request sent by a user equipment (UE), and includes tunnel information and security policy information.
[0045] The inter-satellite communication function of the source satellite is configured to receive a first data packet from the S-UPF or S-gNB of the source satellite, as well as routing information and security policy information corresponding to the routing information from the network controller, and perform security operations on the first data packet according to the security policy information;
[0046] an intersatellite communication function of the relay satellite, configured to construct a third data packet based on the second data packet from the source satellite and routing information from the network controller, and send the third data packet to the destination satellite;
[0047] The inter-satellite communication function of the destination satellite is used to receive a third data packet from the relay satellite and routing information and security policy information corresponding to the routing information from the network controller, and determine the data in the third data packet that needs to be security-related processed based on the header information of the third data packet and the routing information; and perform security operations on the data packet that needs to be security-related processed based on the security policy information.
[0048] In one possible implementation, the network controller sends corresponding routing information and / or security policy information to each satellite on the inter-satellite routing channel, including at least one of the following:
[0049] Sending first routing information and security policy information corresponding to the first routing information to an inter-satellite communication function entity of a source satellite, so that the source satellite performs corresponding security calculations based on the security policy information;
[0050] Sending second routing information to the inter-satellite communication function entity of the relay satellite;
[0051] The third routing information and security policy information corresponding to the third routing information are sent to the inter-satellite communication function entity of the destination satellite, so that the destination satellite performs corresponding security calculations based on the security policy information.
[0052] In another possible implementation, the tunnel information includes any one of the following:
[0053] Tunnel information between the Satellite-User Plane Function (S-UPF) of the source satellite and the S-UPF of the destination satellite;
[0054] Tunnel information between the satellite-gNB of the source satellite and the S-UPF of the destination satellite;
[0055] Tunnel information between the S-UPF of the source satellite and the S-gNB of the destination satellite;
[0056] Tunnel information between the S-gNB of the source satellite and the S-gNB of the destination satellite.
[0057] In yet another possible implementation, the inter-satellite communication function of the source satellite, when performing security calculation on the first data packet according to the security policy information, is specifically configured to:
[0058] Sending a first operation request to a security function of the source satellite, where the first operation request carries security policy information corresponding to the first routing information, and is used to request the security function of the source satellite to perform a cryptographic operation on the first data packet based on the security policy information;
[0059] Receive a first operation result fed back by the safety function of the source satellite.
[0060] In yet another possible implementation, the inter-satellite communication function of the source satellite is further used to:
[0061] Determining the routing information and the next-hop satellite of the intersatellite link according to the routing information and the header information of the first data packet;
[0062] A second data packet is constructed according to the first operation result and the routing information of the next hop, and the second data packet is sent to the next hop satellite.
[0063] In yet another possible implementation, the inter-satellite communication function of the source satellite, when determining the routing information and the next-hop satellite of the inter-satellite link based on the routing information and the header information of the first data packet, is specifically configured to:
[0064] According to the routing information and the header information of the first data packet, it is determined that the routing information of the next hop of the intersatellite link is the second routing information, and the next hop satellite is a relay satellite.
[0065] In another possible implementation,
[0066] If the security policy information corresponding to the first routing information includes first cryptographic operation information, the first operation request further carries: the first data packet and the destination satellite identification information; or
[0067] If the security policy information corresponding to the first routing information includes: key identification information and first cryptographic operation information, the first operation request also carries the first data packet.
[0068] In another possible implementation, the inter-satellite communication function of the target satellite, when performing security operations on the data packet requiring security-related processing according to the security policy information, is specifically configured to:
[0069] sending a second operation request to a security function of a destination satellite, where the second operation request carries security policy information corresponding to the third routing information, and is used to request the security function of the destination satellite to perform a cryptographic operation on the data requiring security-related processing based on the security policy information;
[0070] Receive a second operation result fed back by the safety function of the destination satellite.
[0071] In yet another possible implementation, the inter-satellite communication function of the target satellite is further used to:
[0072] Send the second operation result to the S-UPF or S-gNB of the destination satellite.
[0073] In another possible implementation, if the security policy information corresponding to the third routing information includes second cryptographic operation information, the second operation request further carries: the data requiring security-related processing and source satellite identification information; or,
[0074] If the security policy information corresponding to the third routing information comprises key identification information and second password operation information, the second operation request further carries the data requiring security-related processing.
[0075] The technical scheme provided by the application has the beneficial effects that:
[0076] When the SMF in the core network receives the PDU session establishment request sent by the UE, a tunnel establishment request message is sent to the network controller in the bearer network, the network controller determines the inter-satellite routing channel and routing information according to the tunnel information and security policy information in the tunnel establishment request message, and sends the routing information or the routing information and the corresponding security policy information to each satellite on the inter-satellite routing channel, thereby realizing the secure transmission of inter-satellite data and providing inter-satellite link security communication capability on demand in units of user PDU sessions.
[0077] In addition, since the bearer network can use the security policy of the PDU session set by the 5G network to configure the security policy on the inter-satellite link, the consistency of the security policy on the entire communication channel can be ensured, thereby reducing the satellite overhead, achieving the purpose of saving satellite energy and reducing computing consumption. BRIEF DESCRIPTION OF DRAWINGS
[0078] In order to more clearly illustrate the technical solutions in the embodiments of the application, the drawings needed in the description of the embodiments of the application will be briefly introduced.
[0079] Figure 1 A schematic diagram of a PDU session user plane protocol stack in a 5G network;
[0080] Figure 2 A schematic diagram of a 5G system architecture;
[0081] Figure 3 A schematic diagram of a system for implementing satellite inter-satellite data link security provided by an embodiment of the application;
[0082] Figure 4 A flowchart of a method for implementing satellite inter-satellite data link security provided by an embodiment of the application;
[0083] Figure 5 A flowchart of a method for implementing satellite inter-satellite data link security provided by another embodiment of the application;
[0084] Figure 6 A flowchart of a method for implementing satellite inter-satellite data link security provided by another embodiment of the application;
[0085] Figure 7 An interaction diagram of a method for implementing satellite inter-satellite data link security provided by an embodiment of the application;
[0086] Figure 8 An interactive schematic diagram of a method for achieving inter-satellite data link security provided in another embodiment of the present application. DETAILED DESCRIPTION
[0087] The following describes in detail embodiments of the present application, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present application, and are not to be construed as limiting the present invention.
[0088] It will be understood by those skilled in the art that, unless expressly stated otherwise, the singular forms "a", "an", "said" and "the" used herein may also include the plural forms. It should be further understood that the term "comprising" used in the specification of the present application refers to the presence of the features, integers, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof. It should be understood that when we refer to an element as being "connected" or "coupled" to another element, it may be directly connected or coupled to the other element, or there may be intermediate elements. In addition, "connected" or "coupled" as used herein may include wireless connections or wireless couplings. The term "and / or" used herein includes all or any units and all combinations of one or more associated listed items.
[0089] In order to make the objectives, technical solutions and advantages of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.
[0090] The technical solution provided in the embodiment of the present application can be applicable to a variety of systems, especially 5G systems. For example, the applicable system can be a global system of mobile communication (GSM) system, a code division multiple access (CDMA) system, a wideband code division multiple access (WCDMA) general packet radio service (GPRS) system, a long term evolution (LTE) system, a LTE frequency division duplex (FDD) system, a LTE time division duplex (TDD) system, an advanced long term evolution (LTE-A) system, a universal mobile telecommunication system (UMTS), a world-wide interoperability for microwave access (WiMAX) system, a 5G new air interface (NR) system, etc. These various systems include terminal equipment and network side equipment. The system can also include a core network part, such as an evolved packet system (EPS), a 5G system (5GS), etc.
[0091] First, the relevant technologies involved in this application are introduced and explained:
[0092] 1. PDU Session User Plane Protocol Stack in 5G Networks
[0093] The 5G protocol data unit PDU session user plane protocol stack given in 3GPP TS 23.501 is as follows Figure 1The 5G system architecture is shown in FIG. 1. In the 5G system, the user plane function UPF is usually implemented using GTP tunnels. The GTP (GPRS tunneling protocol, tunnel endpoint identifier) tunnel is bidirectional and is identified by the source IP address, destination IP address, UDP port number, source GTP TEID (Tunnel Endpoint Identifier), and destination GTP TEID. The GTP TEID is allocated by the network elements at both ends of the tunnel. A session consists of multiple GTP tunnels, and in the data forwarding process, the forwarding network element determines the data packet according to the GTP data packet header in the data packet; if a match is found, the GTP data packet header in the data packet is replaced with the GTP data packet header of the next segment of the tunnel, and the data packet is forwarded out.
[0094] II. 5G System Architecture
[0095] The 3GPP 5G system architecture is shown in FIG. 1. According to the description in 3GPP TS 33.501, in the PDU session establishment process, the SMF is responsible for providing the user plane UP security policy of the PDU session to the ng-eNB / gNB. In the 3GPP core network, the protection of data communication between UPFs is provided by IPSec (Internet Protocol Security), which protects all data communication between UPFs. Figure 2
[0096] (R)AN: access network, which can be a 3gpp access network (such as LTE, 5G-NR), or a non-3gpp access network (such as common wifi access); if the most common mobile phone is used for online, this (R)AN node is the base station.
[0097] AMF: Access and Mobility Management Function, access and mobility management function entity; terminal point of RAN signaling interface (N2), terminal point of NAS (N1) signaling (MM message), responsible for encryption and protection of NAS messages, responsible for registration, access, mobility, authentication, transparent short message, etc. In addition, when interacting with the EPS network, it is also responsible for the allocation of EpsBearer Id. The AMF can be compared to the MME entity of the 4G.
[0098] SMF: Session Management Function, session management function entity; the main functions of SMF are: 1) the termination point of SM message of NAS message; 2) establishment, modification and release of session; 3) allocation and management of UE IP; 4) DHCP function; 5) ARP proxy or IPv6 neighbor request agent (in Ethernet PDU scenario); 6) selection and control of UPF for a session; 7) collection of billing data and support of billing interface; 8) determination of SSC mode of a session; 9) downlink data indication; etc.
[0099] UPF: User Plane Function. Its primary function is to route and forward packets and perform QoS flow mapping. It is similar to the GW (SGW + PGW) in 4G.
[0100] PCF: Policy Control Function. This entity supports a unified policy framework to manage network behavior, provides policy rules for network entities to implement, and accesses subscription information in the Unified Data Repository (UDR). The PCF can only access the Unified Data Repository (NDR) for the same PLMN. See TS 23.503, section 6.2.1, for details.
[0101] UDM: Unified Data Management. Its main functions include: 1) generating 3GPP authentication certificates / authentication parameters; 2) storing and managing the 5G system's permanent user ID (SUPI); 3) managing subscription information; 4) delivering MT-SMS messages; 5) managing SMS messages; and 6) managing user registration with service network elements (e.g., AMF and SMF, which currently provide services to the terminal).
[0102] AUSF: Authentication Server Function, authentication server network element; supports authentication of 3GPP access and authentication of untrusted non-3GPP access.
[0103] NSSF: The Network Slice Selection Function, network slice selection functional entity; the main functions of NSSF are: 1) select the set of network slice instances serving the UE; 2) determine the allowed NSSAI and, when necessary, the mapping to the subscribed S-NSSAI; 3) determine the configured NSSAI and, when necessary, the mapping to the subscribed S-NSSAI; 4) determine the set of AMFs that may be used to query the UE, or determine a list of candidate AMFs based on the configuration.
[0104] Among them, S-NSSAI, Single Network Slice Selection Assistance Information, is used to identify a network slice.
[0105] NSSAAF: The Network Slice Selection Authentication and Authorization Function, the network slice selection authentication and authorization function entity.
[0106] NSACF: The Network Slice Administration Control Function, network slice management control function entity.
[0107] 3. 5G-based satellite communication system
[0108] The 5G-based satellite communication system will use GTP-U to transmit user data, while the inter-satellite links serving as the bearer network can use tag-based technology for data transmission.
[0109] Specifically, in 5G-based satellite communication networks, the user plane utilizes the GTP-U protocol, meaning that data flows transmitted on the user plane are GTP-U data flows. Tag-based communication technology can be used on inter-satellite data links, leveraging tags to guide high-speed and efficient data transmission. To reduce limited satellite power consumption while meeting data security requirements, on-demand secure inter-satellite link communication capabilities are required. However, the 5G-based satellite communication systems currently under development do not yet have a solution for this.
[0110] Therefore, the present application provides a method and system for achieving inter-satellite data link security, which aims to solve the above technical problems of the prior art, while also achieving the purpose of saving satellite energy and reducing computing consumption.
[0111] The following specific embodiments describe in detail the technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.
[0112] like Figure 3 The present invention provides a system for implementing inter-satellite data link security, including a satellite, a satellite terminal, a session management function (SMF) of a core network, and a network controller of a bearer network. The satellites include a source satellite, a relay satellite, and a destination satellite.
[0113] Each satellite includes intersatellite communication functions for intersatellite communications and has the ability to route and process security-related message operations;
[0114] The source satellite and the destination satellite also include: satellite-base station S-gNB, satellite-user plane function S-UPF and security functions, among which,
[0115] S-gNB is the base station function in the satellite;
[0116] S-UPF is the user plane function UPF in the satellite;
[0117] Security functions, used for communication security between S-gNB and satellite terminals and inter-satellite communication security, with the ability to store keys and perform cryptographic operations;
[0118] The satellite terminal is a terminal device with satellite communication capabilities, which will initiate a PDU session request to the SMF in the core network;
[0119] SMF in the core network: used to provide security policies related to PDU sessions to the base station function S-gNB in the satellite and the network controller in the bearer network responsible for controlling the satellite inter-satellite communication routing function.
[0120] The network controller in the bearer network is used to send corresponding security policy information to the inter-satellite communication functions of the source satellite and the destination satellite respectively according to the PDU session security policy related to the PDU session from the SMF.
[0121] This application is based on Figure 3 The system shown provides a method for achieving inter-satellite data link security. Figure 4 As shown, applied to a network controller, the method includes:
[0122] S101. Receive a tunnel establishment request message sent by an SMF, where the tunnel establishment request message includes tunnel information and security policy information. The tunnel establishment request message is sent by the SMF after receiving a protocol data unit (PDU) session establishment request sent by a user equipment (UE).
[0123] Specifically, in this embodiment, the tunnel information in the tunnel establishment request message may be tunnel information between the S-UPF of the source satellite and the S-UPF of the destination satellite, or may be tunnel information between the S-gNB of the source satellite and the S-UPF of the destination satellite, or may be tunnel information between the S-gNB of the source satellite and the S-UPF of the destination satellite, or may be tunnel information between the S-gNB of the source satellite and the S-UPF of the destination satellite, or may be tunnel information between the S-gNB of the source satellite and the S-gNB of the destination satellite.
[0124] S102. Determine an inter-satellite routing channel and routing information according to the tunnel information in the tunnel establishment request message;
[0125] That is, according to the tunnel information in the tunnel establishment request message, the routing channel that the source satellite needs to pass through when communicating with the destination satellite, as well as the routing information corresponding to each hop satellite on the routing channel are determined.
[0126] Inter-satellite communication in a satellite communication system is based on labels, that is, the routing information corresponding to each hop satellite is label-based routing information.
[0127] S103: Send corresponding routing information and / or security policy information to each satellite on the inter-satellite routing channel.
[0128] In other words, each satellite on an inter-satellite routing channel includes a source satellite and a destination satellite, i.e., data is routed from a source satellite to a destination satellite. Alternatively, each satellite on an inter-satellite routing channel includes a source satellite, a relay satellite, and a destination satellite, i.e., data is routed from a source satellite via a relay satellite to a destination satellite, with data securely processed on both the source and destination satellites. There can be one or more relay satellites on an inter-satellite routing channel.
[0129] Corresponding information including routing information or routing information and security policy information is sent to each satellite on the inter-satellite routing channel.
[0130] Optionally, S103 may include at least one of the following:
[0131] S1031. Send first routing information and security policy information corresponding to the first routing information to an inter-satellite communication function entity of the source satellite, so that the source satellite performs corresponding security operations based on the security policy information. Tunnel information related to the S-UPF or S-gNB of the source satellite may also be sent to the inter-satellite communication function entity of the source satellite.
[0132] S1032. Send second routing information to the inter-satellite communication function entity of the relay satellite;
[0133] S1033: Send the third routing information and security policy information corresponding to the third routing information to the inter-satellite communication function entity of the destination satellite, so that the destination satellite performs corresponding security calculations based on the security policy information.
[0134] It should be noted that when the routing information and the corresponding security policy information are sent to the source satellite or the destination satellite, the security policy information can be taken as an element of the routing information, for example, the routing information itself is three-tuple information, and the security policy information can be taken as a fourth element, and in this case, the routing information is four-tuple information; or the security policy information is independent of the routing information and is sent at the same time as the routing information, and the specific sending mode of the routing information and the corresponding security policy information is not limited in the embodiments of the present application.
[0135] In the above embodiments, the security policy information includes at least one or more of the following:
[0136] security algorithm indication information;
[0137] integrity protection policy information;
[0138] confidentiality protection policy information;
[0139] key identification information.
[0140] Specifically, in this embodiment, the security algorithm indication information is used to indicate which algorithm is used in the cryptographic operation, for example: symmetric encryption algorithm AES, SNOW 3G, ZUC128, SM4, etc. The integrity protection policy is used to represent whether the integrity protection is enabled; the confidentiality protection policy is used to represent whether the encryption function is enabled; and the key identification information is used to represent which key is used for the cryptographic operation.
[0141] It should be noted that in this embodiment, the parameters included in the security policy sent by the SMF and received by the network controller and the security policy sent by the network controller to the satellite can be the same parameters, and the data structure or expression manner of the parameters can be different, for example: the data structure or expression manner of the parameters included in the security policy sent by the SMF is suitable for the communication between the UE and the gNB (or S-gNB), and the data structure or expression manner of the parameters included in the security policy sent by the network controller to the satellite is suitable for the communication between the satellites, i.e., the communication between the S-UPF and the S-gNB.
[0142] In the above embodiments, the granularity level of the tunnel information can be N19 tunnel identification level, or quality of service (QoS) flow identification level, or other levels, and the embodiments of the present application do not limit this.
[0143] In the above embodiments, the network controller uses the security policy of the PDU session set by the 5G network to configure the security policy on the inter-satellite link, ensures the consistency of the security policy on the entire inter-satellite communication channel, and reduces the overall overhead of the satellite.
[0144] The present application is based on Figure 3The system shown provides a method for achieving inter-satellite data link security. Figure 5 As shown, the inter-satellite communication function applied to the source satellite includes:
[0145] S201. Receive a first data packet sent by an S-UPF or S-gNB of a source satellite;
[0146] S202: Receive routing information and security policy information corresponding to the routing information sent by a network controller, where the routing information is routing information related to a source satellite on an inter-satellite routing channel determined by the network controller;
[0147] S203: Perform security operations on the first data packet according to the security policy information.
[0148] Specifically, in this embodiment, if the security policy received by the inter-satellite communication function of the source satellite is to perform encryption operation using the AES algorithm, the first data packet is encrypted using the AES algorithm.
[0149] In one embodiment, S203 may specifically include:
[0150] S2031: Send a first operation request to the security function of the source satellite, where the first operation request carries the security policy information and is used to request the security function of the source satellite to perform a cryptographic operation on the first data packet based on the security policy information.
[0151] S2032: Receive a first operation result fed back by the safety function of the source satellite.
[0152] Specifically, in this embodiment, if the security policy received by the inter-satellite communication function of the source satellite is to perform encryption operations using the AES algorithm, a first operation request is sent to the security function of this satellite to perform an encryption operation on the first data packet using the AES algorithm, and the encryption operation result fed back by the security function of this satellite is received.
[0153] That is to say, the inter-satellite communication function of the source satellite can implement security operations on the first data packet by calling the security function module of the satellite.
[0154] Optionally, the method further includes:
[0155] S204: Determine the routing information and the next-hop satellite of the intersatellite link according to the routing information and the header information of the first data packet;
[0156] S205: Construct a second data packet according to the first operation result and the routing information of the next hop, and send the second data packet to the next hop satellite.
[0157] Specifically, S204 may include:
[0158] According to the routing information and the header information of the first data packet, it is determined that the routing information of the next hop of the intersatellite link is the second routing information, and the next hop satellite is a relay satellite.
[0159] That is to say, when the inter-satellite communication function of the source satellite determines that the routing information of the next hop of the inter-satellite link is the second routing information based on the received routing information and the header information of the first data packet, and the next hop satellite is the relay satellite, it constructs a second data packet based on the first operation result and the second routing information received from the security function of this satellite, and sends the second data packet to the relay satellite.
[0160] It should be noted that the specific implementation process of determining the next hop routing information based on the routing information and the packet header information of the data packet can be implemented using existing technologies, and the specific implementation process of constructing the second data packet based on the first operation result and the second routing information can also be implemented using existing technologies. For the sake of brevity, it will not be repeated here.
[0161] In the above embodiment, if the security policy information includes the first cryptographic operation information, the first operation request further carries: the first data packet and the destination satellite identification information; or,
[0162] If the security policy information includes: key identification information and first cryptographic operation information, the first operation request also carries the first data packet.
[0163] Specifically, in this embodiment, the first operation request may include: a first data packet, destination satellite identification information, and cryptographic operation information. Alternatively, it may include: a first data packet, key identification information, and cryptographic operation information. The first cryptographic operation information may include: encryption / decryption indication information, or at least one of encryption indication information, integrity protection indication information, and cryptographic algorithm indication information. For example, it may include integrity protection indication information, encryption indication information and cryptographic algorithm indication information, or encryption / decryption indication information and cryptographic algorithm indication information.
[0164] It should be noted that, in this embodiment, the routing information received by the inter-satellite communication function of the source satellite corresponds to the first routing information mentioned above, and the security policy information corresponding to the routing information is: the security policy information corresponding to the first routing information mentioned above.
[0165] In the above embodiment, the inter-satellite communication function of the source satellite performs security operations on the transmitted data packets according to the security policy from the network controller to ensure the security of inter-satellite link data transmission.
[0166] This application is based on Figure 3The system shown provides a method for achieving inter-satellite data link security. Figure 6 As shown, the inter-satellite communication function applied to the target satellite includes:
[0167] S301, receiving a third data packet sent by an inter-satellite communication function of a relay satellite, where the third data packet is constructed by the inter-satellite communication function of the relay satellite based on a second data packet and second routing information from a network controller, where the second data packet comes from the inter-satellite communication function of a source satellite;
[0168] S302: Receive routing information sent by the network controller and security policy information corresponding to the routing information, where the routing information is routing information related to a destination satellite on an inter-satellite routing channel determined by the network controller;
[0169] S303: Determine, based on the header information of the third data packet and the routing information, data in the third data packet that needs to be security-related processed;
[0170] S304: Perform security operations on the data packets that require security-related processing according to the security policy information.
[0171] Specifically, in this embodiment, the inter-satellite communication function of the destination satellite determines the data in the third data packet that needs to be processed with security-related features based on the header information and routing information of the received third data packet. If the security policy received by the inter-satellite communication function of the destination satellite is to use the AES algorithm for decryption operations, the AES algorithm is used to decrypt the data in the third data packet that needs to be processed with security-related features.
[0172] In one embodiment, S304 may specifically include:
[0173] S3041: Send a second operation request to the security function of the destination satellite, where the second operation request carries the security policy information and is used to request the security function of the destination satellite to perform a cryptographic operation on the data requiring security-related processing based on the security policy information.
[0174] S3042: Receive a second operation result fed back by the safety function of the destination satellite.
[0175] Specifically, in this embodiment, the inter-satellite communication function of the destination satellite determines the data in the third data packet that needs to be security-related processed based on the header information and routing information of the received third data packet. If the security policy received by the inter-satellite communication function of the destination satellite is to use the AES algorithm for decryption operations, a second operation request is sent to the security function of this satellite to use the AES algorithm to decrypt the data in the third data packet that needs to be security-related processed, and the decryption operation result is fed back by the security function of this satellite.
[0176] Optionally, the method further includes:
[0177] S305. Send the second operation result to the S-UPF or S-gNB of the destination satellite.
[0178] After receiving the decryption operation result fed back by the security function of this satellite, the inter-satellite communication function of the destination satellite can also send the decryption operation result to the S-UPF or S-gNB of this satellite, thereby realizing the secure transmission of data packets.
[0179] In the above embodiment, if the security policy information includes second cryptographic operation information, the second operation request further carries: the data requiring security-related processing and source satellite identification information; or,
[0180] If the security policy information includes: key identification information and second cryptographic operation information, the second operation request also carries: the data that needs to be processed in a security-related manner.
[0181] Specifically, in this embodiment, the second operation request may include: data requiring security-related processing, source satellite identification information, and cryptographic operation information. Alternatively, it may include: data requiring security-related processing, key identification information, and cryptographic operation information.
[0182] The second cryptographic operation information may include: encryption and decryption instruction information or at least one of decryption instruction information, integrity protection verification instruction information, and cryptographic algorithm instruction information. For example, the second cryptographic operation information may include integrity protection verification instruction information, decryption instruction information and cryptographic algorithm instruction information, or encryption and decryption instruction information and cryptographic algorithm instruction information.
[0183] It should be noted that, in this embodiment, the routing information received by the inter-satellite communication function of the destination satellite corresponds to the third routing information mentioned above, and the security policy information corresponding to the routing information is: the security policy information corresponding to the third routing information mentioned above.
[0184] In the above embodiment, the inter-satellite communication function of the destination satellite performs security operations on the received data packets according to the security policy from the network controller, thereby achieving the security of inter-satellite link data transmission.
[0185] The embodiment of the present application provides a method for implementing satellite inter-satellite data link security, which is applied to a system for implementing satellite inter-satellite data link security. The system includes: a satellite, a session management function SMF of a core network, and a network controller of a bearer network, such as Figure 7 As shown, the method includes:
[0186] S401. A network controller in a bearer network determines an inter-satellite routing channel and routing information based on a tunnel establishment request message from an SMF, and sends corresponding information to each satellite on the inter-satellite routing channel, wherein each satellite on the inter-satellite routing channel includes a source satellite, a relay satellite, and a destination satellite. The tunnel establishment request message is sent by the SMF after receiving a protocol data unit (PDU) session establishment request sent by a user equipment (UE), and includes tunnel information and security policy information.
[0187] S402: The inter-satellite communication function of the source satellite receives a first data packet from the S-UPF or S-gNB of the source satellite, as well as routing information and security policy information corresponding to the routing information from the network controller, and performs a security operation on the first data packet according to the security policy information.
[0188] S403: The inter-satellite communication function of the relay satellite constructs a third data packet according to the second data packet from the source satellite and the routing information from the network controller, and sends the third data packet to the destination satellite;
[0189] S404. The inter-satellite communication function of the destination satellite receives the third data packet from the relay satellite and the routing information and security policy information corresponding to the routing information from the network controller, and determines the data in the third data packet that needs to be security-related processed based on the header information of the third data packet and the routing information; and performs security operations on the data packet that needs to be security-related processed based on the security policy information.
[0190] In the above embodiment, the network controller sends corresponding routing information and / or security policy information to each satellite on the inter-satellite routing channel, including at least one of the following:
[0191] Sending first routing information and security policy information corresponding to the first routing information to an inter-satellite communication function entity of a source satellite, so that the source satellite performs corresponding security calculations based on the security policy information;
[0192] Sending second routing information to the inter-satellite communication function entity of the relay satellite;
[0193] The third routing information and security policy information corresponding to the third routing information are sent to the inter-satellite communication function entity of the destination satellite, so that the destination satellite performs corresponding security calculations based on the security policy information.
[0194] In some embodiments, the process of performing security calculation on the first data packet according to the security policy information in S402 may include:
[0195] The inter-satellite communication function of the source satellite sends a first operation request to the security function of the source satellite, where the first operation request carries the security policy information and is used to request the security function of the source satellite to perform a cryptographic operation on the first data packet based on the security policy information;
[0196] The inter-satellite communication function of the source satellite receives the first operation result fed back by the safety function of the source satellite.
[0197] Specifically, in this embodiment, the first operation request carries security policy information corresponding to the first routing information, and is used to request the security function of the source satellite to perform a cryptographic operation on the first data packet based on the security policy information corresponding to the first routing information.
[0198] If the security policy information corresponding to the first routing information includes first cryptographic operation information, the first operation request further carries: the first data packet and the destination satellite identification information; or
[0199] If the security policy information corresponding to the first routing information includes: key identification information and first cryptographic operation information, the first operation request also carries the first data packet.
[0200] In other embodiments, the process of performing security operations on the data packet requiring security-related processing according to the security policy information in S404 may include:
[0201] The intersatellite communication function of the destination satellite sends a second operation request to the security function of the destination satellite, where the second operation request carries the security policy information and is used to request the security function of the destination satellite to perform a cryptographic operation on the data requiring security-related processing based on the security policy information;
[0202] The inter-satellite communication function of the destination satellite receives the second operation result fed back by the safety function of the destination satellite.
[0203] Specifically, in this embodiment, the second operation request carries the security policy information corresponding to the third routing information, and is used to request the security function of the destination satellite to perform cryptographic operations on the data that requires security-related processing based on the security policy information corresponding to the third routing information.
[0204] If the security policy information corresponding to the third routing information includes second cryptographic operation information, the second operation request further carries: the data requiring security-related processing and source satellite identification information; or
[0205] If the security policy information corresponding to the third routing information includes: key identification information and second cryptographic operation information, the second operation request further carries: the data that needs to be processed in a security-related manner.
[0206] In some embodiments, the inter-satellite communication function of the source satellite further includes, before constructing the second data packet:
[0207] The inter-satellite communication function of the source satellite determines, based on the routing information and the header information of the first data packet, that the routing information of the next hop of the inter-satellite link is the second routing information, and the next hop satellite is the relay satellite.
[0208] In some embodiments, the inter-satellite communication function of the destination satellite determines, based on the third data packet from the relay satellite and the routing information from the network controller, data in the third data packet that requires security-related processing, including:
[0209] The inter-satellite communication function of the destination satellite determines the data in the third data packet that needs to be processed in a security-related manner based on the header information of the third data packet and the third routing information.
[0210] In each of the above embodiments, the security policy information includes at least one or more of the following:
[0211] Security algorithm indication information;
[0212] Integrity protection policy information;
[0213] Confidentiality protection policy information;
[0214] Key identification information.
[0215] Specifically, in this embodiment, the security algorithm indication information is used to indicate the specific algorithm used for cryptographic operations, such as symmetric encryption algorithms AES, SNOW 3G, ZUC128, and SM4. The integrity protection policy is used to indicate whether integrity protection is enabled; the confidentiality protection policy is used to indicate whether encryption is enabled; and the key identification information is used to indicate which keys are used for cryptographic operations.
[0216] The following combination Figure 8 , a method for achieving inter-satellite data link security provided by an embodiment of the present application is described in detail. Figure 8 As shown, the method includes:
[0217] 1. The SMF in the core network receives the PDU session establishment request sent by the UE, establishes routing information for the PDU session in the 5G network (which may include tunnel information and security policies), and sends this routing information to each node on the data channel. For example, the tunnel information and security policies are sent to the S-gNB, and the tunnel information is sent to the S-UPF and the UPF in the core network.
[0218] 2. The SMF sends the tunnel information and corresponding security policy between the source satellite S-UPF and the destination satellite S-UPF to the network controller in the bearer network.
[0219] In this embodiment, the security policy describes the following information applied to the tunnel: security algorithm indication information (indicating which specific algorithm is used in cryptographic operations, for example: AES, SNOW 3G, ZUC128, SM4, etc.), integrity protection policy (whether integrity protection is enabled) and confidentiality protection policy (whether encryption function is enabled), key identification information (which keys are used for cryptographic operations), etc.
[0220] That is, the security policy may include at least one of the above.
[0221] 3. Based on the tunnel information and security policy provided by the SMF and the label-based data transmission mechanism adopted by the bearer network, the network controller in the bearer network determines the inter-satellite routing channel and thus the routing information of the source satellite, relay satellite, and destination satellite on the routing channel. The routing information and corresponding security policy are then sent to the inter-satellite communication functions on these satellites.
[0222] The information sent to the source satellite is: tunnel information related to the source satellite S-UPF or S-gNB, the first routing information, and the security policy corresponding to the first routing information.
[0223] The information sent to the relay satellite is: second routing information;
[0224] The information sent to the destination satellite is: the third routing information and the security policy corresponding to the third routing information.
[0225] The security policy sent by the network controller is: a security policy for the inter-satellite communication function of the satellite generated based on the SMF security policy, which may include: at least one of: security algorithm indication information, integrity protection policy, confidentiality protection policy, and key identification information.
[0226] For example, if the security policy sent to the source satellite is to use the AES algorithm for encryption, the security policy sent to the destination satellite is to use the AES algorithm for decryption. Alternatively, if the security policy sent to the source satellite is to use integrity protection indication information, the security policy sent to the destination satellite is to use integrity protection verification indication information.
[0227] It should be noted that, in this embodiment, the parameters included in the security policy sent by the SMF and the security policy sent by the network controller may be the same parameters, but the data structure or expression of the parameters may be different. For example, the data structure or expression of the parameters included in the security policy sent by the SMF is applicable to the communication between the UE and the gNB (or, S-gNB), and the data structure or expression of the parameters included in the security policy sent by the network controller is applicable to the communication between satellites, that is, the communication between the S-UPF and the S-gNB.
[0228] 4. The S-UPF or S-gNB of the source satellite sends a first data packet to the inter-satellite communication function of the source satellite. For example, the first data packet can be a GTP-U data packet.
[0229] 5. The inter-satellite communication function of the source satellite determines the routing information and next-hop satellite of the inter-satellite link based on the header information of the first data packet.
[0230] 6. The inter-satellite communication function of the source satellite sends a first operation request to the security function module of the source satellite. The request may include: a first data packet, destination satellite identification information or key identification information, and cryptographic operation information (for example: encryption and decryption indication information, integrity protection indication information, cryptographic algorithm indication information).
[0231] Specifically, in this embodiment, the first operation request may include: a first data packet, destination satellite identification information, and cryptographic operation information. Alternatively, it may include: a first data packet, key identification information, and cryptographic operation information.
[0232] In addition, in this embodiment, the cryptographic operation information may include encryption and decryption indication information or at least one of encryption indication information, integrity protection indication information, and cryptographic algorithm indication information. For example, the cryptographic operation information may include integrity protection indication information, encryption indication information and cryptographic algorithm indication information, or encryption and decryption indication information and cryptographic algorithm indication information.
[0233] 7. The security function module of the source satellite performs cryptographic operations to obtain a first operation result. Specifically, the following operations may be performed:
[0234] (1) Determine the key used for cryptographic operations based on the destination satellite identification information or key identification information. If key identification information is provided in the request, use the key specified by the key identification information.
[0235] (2) Using the determined key and the cryptographic algorithm specified in the cryptographic operation information, perform a cryptographic operation on the first data packet, such as an encryption operation and / or an integrity protection operation.
[0236] It should be understood that in this embodiment, the specific implementation process of the cryptographic operation can be implemented using existing cryptographic operation methods, and for the sake of brevity, it will not be repeated here.
[0237] 8. The security function module of the source satellite returns the first operation result to the inter-satellite communication function of the source satellite.
[0238] 9. The inter-satellite communication function of the source satellite constructs a second data packet using the first operation result and the first routing information received from the network controller, and sends it to the relay satellite.
[0239] 10. The inter-satellite communication function of the relay satellite constructs a third data packet using the first inter-satellite routing data packet and the second routing information received from the network controller and sends it to the next-hop satellite.
[0240] It should be understood that in this embodiment, the next-hop satellite can be a relay satellite or a destination satellite. In other words, there can be one or more relay satellites on the inter-satellite path.
[0241] 11. The inter-satellite communication function of the destination satellite sends a second operation request to the security function module of the destination satellite. The request may include: data in the third data packet that needs to be processed in a security-related manner, source satellite identification information or key identification information, and cryptographic operation information.
[0242] Specifically, in this embodiment, the second operation request may include: data requiring security-related processing, source satellite identification information, and cryptographic operation information. Alternatively, it may include: data requiring security-related processing, key identification information, and cryptographic operation information.
[0243] In addition, in this embodiment, the cryptographic operation information may include: encryption and decryption instruction information or at least one of decryption instruction information, integrity protection verification instruction information, and cryptographic algorithm instruction information. For example, the information may include integrity protection verification instruction information, decryption instruction information and cryptographic algorithm instruction information, or encryption and decryption instruction information and cryptographic algorithm instruction information.
[0244] It should be noted that, in this embodiment, before the inter-satellite communication function of the destination satellite sends the second operation request to the security function module of the destination satellite, it needs to determine the data in the third data packet that needs to be security-related processed based on the header information of the third data packet and the third routing information in the second information.
[0245] It should be understood that in this embodiment, the specific implementation process of determining data from a data packet based on the packet header information and routing information of the data packet can be implemented using existing technologies, and for the sake of brevity, it will not be repeated here.
[0246] 12. The security function module of the destination satellite performs a cryptographic operation to obtain a second operation result. Specifically, the following operations may be performed:
[0247] (1) Determine the key used for cryptographic operations based on the source satellite identification information or key identification information. If key identification information is provided in the request, use the key specified by the key identification information.
[0248] (2) Using the selected key and the cryptographic algorithm specified in the cryptographic operation information, perform a cryptographic operation on the third data packet, such as a decryption operation and / or integrity protection verification, to obtain a second operation result.
[0249] In this embodiment, if the first data packet is a GTP-U data packet, the second operation result obtained after encryption and decoding is a GTP-U data packet.
[0250] 13. The safety function module of the destination satellite returns the second operation result to the inter-satellite communication function of the safety function module of the destination satellite.
[0251] 14. The inter-satellite communication function of the destination satellite can send GTP-U data packets to the S-UPF or S-gNB of the destination satellite.
[0252] That is to say, in this embodiment, through the security function modules in the source satellite and the destination satellite, it can be ensured that data can be safely transmitted from the S-gNB of the source satellite to the S-UPF or S-gNB of the destination satellite via the inter-satellite communication function in the satellite; or, data can be safely transmitted from the S-UPF of the source satellite to the S-UPF or S-gNB of the destination satellite via the inter-satellite communication function in the satellite.
[0253] Specifically, a method for managing the secure communication capability of inter-satellite links based on user PDU sessions is provided. When the SMF in the core network receives the PDU session establishment request sent by the UE, it sends a tunnel establishment request message to the network controller in the bearer network. The network controller determines the inter-satellite routing channel and routing information based on the tunnel information and security policy information in the tunnel establishment request message, and sends the routing information or the routing information and corresponding security policy information to each satellite on the inter-satellite routing channel. After the inter-satellite communication function of the source satellite on the inter-satellite routing channel receives the data packet, it can call the security function module of the source satellite to perform cryptographic operations on the data packet and After the calculation result is transmitted to the inter-satellite communication function of the next-hop satellite based on the inter-satellite routing information until it is transmitted to the inter-satellite communication function of the destination satellite, the inter-satellite communication function of the destination satellite can call the security function module of the destination satellite to perform cryptographic operations on the received data packet to obtain the final data packet, and send the data packet to the S-UPF or S-gNB of the destination satellite, thereby realizing the secure transmission of inter-satellite data, and being able to provide inter-satellite link security communication capabilities on demand based on user PDU sessions, which can not only ensure the consistency of security policies on the entire communication channel, but also reduce the overall satellite overhead, thereby achieving the purpose of saving satellite energy and reducing computing consumption.
[0254] Based on the same inventive concept, an embodiment of the present application further provides a network controller, including:
[0255] A receiving module, configured to receive a tunnel establishment request message sent by an SMF, wherein the tunnel establishment request message includes tunnel information and security policy information, and the tunnel establishment request message is sent by the SMF after receiving a protocol data unit (PDU) session establishment request sent by a user equipment (UE);
[0256] A determination module, configured to determine an inter-satellite routing channel and routing information according to the tunnel information in the tunnel establishment request message;
[0257] The sending module is used to send corresponding routing information and / or security policy information to each satellite on the inter-satellite routing channel.
[0258] In some embodiments, when the sending module sends corresponding routing information and / or security policy information to each satellite on the inter-satellite routing channel, it is specifically used for at least one of the following:
[0259] Sending tunnel information related to the S-UPF or S-gNB of the source satellite, first routing information, and security policy information corresponding to the first routing information to the inter-satellite communication function entity of the source satellite, so that the source satellite performs corresponding security operations based on the security policy information;
[0260] Sending second routing information to the inter-satellite communication function entity of the relay satellite;
[0261] The third routing information and security policy information corresponding to the third routing information are sent to the inter-satellite communication function entity of the destination satellite, so that the destination satellite performs corresponding security calculations based on the security policy information.
[0262] In the above embodiment, the security policy information includes at least one or more of the following:
[0263] Security algorithm indication information;
[0264] Integrity protection policy information;
[0265] Confidentiality protection policy information;
[0266] Key identification information.
[0267] In the above embodiment, the tunnel information includes any one of the following:
[0268] Tunnel information between the Satellite-User Plane Function (S-UPF) of the source satellite and the S-UPF of the destination satellite;
[0269] Tunnel information between the satellite-gNB of the source satellite and the S-UPF of the destination satellite;
[0270] Tunnel information between the S-UPF of the source satellite and the S-gNB of the destination satellite;
[0271] Tunnel information between the S-gNB of the source satellite and the S-gNB of the destination satellite.
[0272] Based on the same inventive concept, an embodiment of the present application further provides an inter-satellite communication functional entity of a source satellite, including:
[0273] a receiving module, configured to receive a first data packet sent by an S-UPF or S-gNB of a source satellite, as well as routing information and security policy information corresponding to the routing information sent by a network controller, where the routing information is routing information related to the source satellite on the inter-satellite routing channel determined by the network controller;
[0274] A processing module is used to perform security operations on the first data packet according to the security policy information.
[0275] In some embodiments, the processing module may specifically include:
[0276] a sending unit, configured to send a first operation request to a security function of a source satellite, where the first operation request carries the security policy information and is configured to request the security function of the source satellite to perform a cryptographic operation on the first data packet based on the security policy information;
[0277] A receiving unit is configured to receive a first operation result fed back by the safety function of the source satellite.
[0278] In some embodiments, it may also include:
[0279] a determination module, configured to determine the routing information and the next-hop satellite of the intersatellite link based on the routing information and the header information of the first data packet;
[0280] A construction module, configured to construct a second data packet according to the first operation result and the routing information of the next hop;
[0281] The sending module is used to send the second data packet to the next-hop satellite.
[0282] Specifically, in this embodiment, the determining module is specifically configured to:
[0283] According to the routing information and the header information of the first data packet, it is determined that the routing information of the next hop of the intersatellite link is the second routing information, and the next hop satellite is a relay satellite.
[0284] In the above embodiment, if the security policy information includes the first cryptographic operation information, the first operation request further carries: the first data packet and the destination satellite identification information; or,
[0285] If the security policy information includes: key identification information and first cryptographic operation information, the first operation request also carries the first data packet.
[0286] Based on the same inventive concept, an embodiment of the present application further provides an inter-satellite communication functional entity of a destination satellite, including:
[0287] a receiving module, configured to receive a third data packet sent by an inter-satellite communication function of a relay satellite, as well as routing information and security policy information corresponding to the routing information sent by a network controller, wherein the routing information is routing information related to a destination satellite on an inter-satellite routing channel determined by the network controller, the third data packet is constructed by the inter-satellite communication function of the relay satellite based on a second data packet and the routing information from the network controller, and the second data packet is from the inter-satellite communication function of a source satellite;
[0288] A processing module is used to determine the data in the third data packet that needs to be processed security-related based on the header information of the third data packet and the routing information, and perform security operations on the data packet that needs to be processed security-related based on the security policy information.
[0289] In some embodiments, when the processing module performs security operations on the data packet requiring security-related processing according to the security policy information, the processing module may specifically include:
[0290] a sending unit, configured to send a second operation request to a security function of a destination satellite, wherein the second operation request carries the security policy information and is configured to request a security computer of the destination satellite to perform a cryptographic operation on the data requiring security-related processing based on the security policy information;
[0291] The receiving unit is configured to receive a second operation result fed back by the safety function of the destination satellite.
[0292] In some embodiments, it may also include:
[0293] A sending module is used to send the second operation result to the S-UPF or S-gNB of the destination satellite.
[0294] In the above embodiment, if the security policy information includes second cryptographic operation information, the second operation request further carries: the data requiring security-related processing and source satellite identification information; or,
[0295] If the security policy information includes: key identification information and second cryptographic operation information, the second operation request also carries: the data that needs to be processed in a security-related manner.
[0296] An electronic device is also provided in an embodiment of the present application, which includes: a memory and a processor; at least one program, stored in the memory, for being executed by the processor, which can achieve, compared with the prior art: the ability to provide inter-satellite link security communication capabilities on demand based on user PDU sessions. In addition, since the bearer network can use the security policy of the PDU session set by the 5G network to configure the security policy on the inter-satellite link, the consistency of the security policy on the entire communication channel can be ensured, thereby reducing the overall satellite overhead and achieving the purpose of saving satellite energy and reducing computing consumption.
[0297] The electronic device in the embodiment of the present application may be the network controller in the above embodiment, or the inter-satellite communication functional entity of the source satellite, or the inter-satellite communication functional entity of the destination satellite.
[0298] The embodiments of the present application provide a computer-readable storage medium having a computer program stored thereon. When the computer-readable storage medium is executed on a computer, the computer is enabled to execute the corresponding contents of the aforementioned method embodiments. Compared with the prior art, the present application provides inter-satellite link secure communication capabilities on demand, based on user PDU sessions. In addition, because the bearer network can use the security policy of the PDU session set by the 5G network to configure the security policy on the inter-satellite link, the consistency of the security policy on the entire communication channel can be ensured, thereby reducing the overall satellite overhead, saving satellite energy, and reducing computing consumption.
[0299] The embodiments of the present application also provide a system for implementing satellite inter-satellite data link security, comprising a satellite, a session management function (SMF) of a core network, and a network controller of a bearer network, wherein
[0300] The network controller of the bearer network is configured to determine an inter-satellite routing channel and routing information according to a tunnel establishment request message from the SMF, and send corresponding routing information and / or security policy information to each satellite on the inter-satellite routing channel, wherein the each satellite on the inter-satellite routing channel comprises a source satellite, a relay satellite, and a destination satellite, the tunnel establishment request message is sent by the SMF after receiving a protocol data unit (PDU) session establishment request sent by a user equipment (UE), and the tunnel establishment request message comprises tunnel information and security policy information;
[0301] The inter-satellite communication function of the source satellite is configured to receive a first data packet from an S-UPF or an S-gNB of the source satellite, and receive routing information and security policy information corresponding to the routing information from the network controller, and perform security operation on the first data packet according to the security policy information;
[0302] The inter-satellite communication function of the relay satellite is configured to construct a third data packet according to a second data packet from the source satellite and the routing information from the network controller, and send the third data packet to the destination satellite;
[0303] The inter-satellite communication function of the destination satellite is configured to receive a third data packet from the relay satellite, and receive routing information and security policy information corresponding to the routing information from the network controller, and determine data in the third data packet that needs to be processed according to the security policy, and perform security operation on the data packet that needs to be processed according to the security policy.
[0304] In some embodiments, the network controller sends corresponding routing information and / or security policy information to each satellite on the inter-satellite routing channel, comprising at least one of the following:
[0305] The first routing information and the security policy information corresponding to the first routing information are sent to the inter-satellite communication function entity of the source satellite, so that the source satellite performs corresponding security operation based on the security policy information;
[0306] The second routing information is sent to the inter-satellite communication function entity of the relay satellite;
[0307] The third routing information and the security policy information corresponding to the third routing information are sent to the inter-satellite communication function entity of the destination satellite, so that the destination satellite performs corresponding security operation based on the security policy information.
[0308] In some embodiments, when performing security calculations on the first data packet according to the security policy information, the inter-satellite communication function of the source satellite is specifically configured to:
[0309] Sending a first operation request to a security function of the source satellite, where the first operation request carries security policy information corresponding to the first routing information, and is used to request the security function of the source satellite to perform a cryptographic operation on the first data packet based on the security policy information;
[0310] Receive a first operation result fed back by the safety function of the source satellite.
[0311] In some embodiments, the intersatellite communication function of the source satellite is also used to:
[0312] Determining the routing information and the next-hop satellite of the intersatellite link according to the routing information and the header information of the first data packet;
[0313] A second data packet is constructed according to the first operation result and the routing information of the next hop, and the second data packet is sent to the next hop satellite.
[0314] Specifically, when the inter-satellite communication function of the source satellite determines the routing information and the next-hop satellite of the inter-satellite link according to the routing information and the header information of the first data packet, it is specifically used to:
[0315] According to the routing information and the header information of the first data packet, it is determined that the routing information of the next hop of the intersatellite link is the second routing information, and the next hop satellite is a relay satellite.
[0316] In other embodiments, when performing security operations on the data packets requiring security-related processing according to the security policy information, the inter-satellite communication function of the target satellite is specifically configured to:
[0317] sending a second operation request to a security function of a destination satellite, where the second operation request carries security policy information corresponding to the third routing information, and is used to request the security function of the destination satellite to perform a cryptographic operation on the data requiring security-related processing based on the security policy information;
[0318] Receive a second operation result fed back by the safety function of the destination satellite.
[0319] In other embodiments, the inter-satellite communication function of the target satellite is further used to:
[0320] Send the second operation result to the S-UPF or S-gNB of the destination satellite.
[0321] It should be noted that the division of the units in the embodiments of the present application is illustrative, and is merely a logical function division. In actual implementation, another division manner can be used. In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0322] When the integrated unit is realized in the form of a software functional unit and sold or used as an independent product, it can be stored in a processor-readable storage medium. Based on such understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to perform all or part of the steps of the methods described in the embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.
[0323] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can be in the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can be in the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage and optical storage, etc.) containing computer-usable program codes.
[0324] The present application is described with reference to flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of the flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer executable instructions. These computer executable instructions can be provided to a general purpose computer, a special purpose computer, an embedded processor, or other programmable data processing devices to produce a machine, so that the instructions executed by the computer or other programmable data processing devices produce a device for implementing the functions specified in the flowcharts and / or block diagrams. Figure 1 The functions specified in one flow or multiple flows and / or blocks Figure 1 The devices for implementing the functions specified in one flow or multiple flows and / or blocks
[0325] These processor-executable instructions may also be stored in a processor-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the processor-readable memory produce an article of manufacture comprising an instruction device that implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0326] These processor-executable instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are performed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable device to implement the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0327] It should be understood that although the steps in the flowcharts of the accompanying drawings are shown in sequence as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some of the steps in the flowcharts of the accompanying drawings may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be executed in turn or alternately with other steps or at least a portion of the sub-steps or stages of other steps.
[0328] The above descriptions are only partial embodiments of the present invention. It should be pointed out that ordinary technicians in this technical field can make several improvements and modifications without departing from the principles of the present invention. These improvements and modifications should also be regarded as within the scope of protection of the present invention.
Claims
1. A method for achieving inter-satellite data link security, characterized in that: A network controller applied to a bearer network, the method comprising: Receive a tunnel establishment request message sent by a session management function SMF of the core network, where the tunnel establishment request message is sent by the SMF after receiving a protocol data unit PDU session establishment request sent by a user equipment UE, and the tunnel establishment request message includes tunnel information and security policy information; Determining an inter-satellite routing channel and routing information according to the tunnel information in the tunnel establishment request message; Sending corresponding routing information and / or security policy information to each satellite on the inter-satellite routing channel includes: Send first routing information and security policy information corresponding to the first routing information to the inter-satellite communication function entity of the source satellite, so that the source satellite performs corresponding security operations based on the security policy information, wherein the security policy sent by the network controller includes a security policy for the inter-satellite communication function of the satellite generated based on the SMF security policy.
2. The method according to claim 1, characterized in that Sending corresponding routing information and / or security policy information to each satellite on the inter-satellite routing channel also includes at least one of the following: Sending second routing information to the inter-satellite communication function entity of the relay satellite; The third routing information and security policy information corresponding to the third routing information are sent to the inter-satellite communication function entity of the destination satellite, so that the destination satellite performs corresponding security calculations based on the security policy information.
3. The method according to claim 1 or 2, characterized in that The tunnel information includes any of the following: Tunnel information between the Satellite-User Plane Function (S-UPF) of the source satellite and the S-UPF of the destination satellite; Tunnel information between the satellite-gNB of the source satellite and the S-UPF of the destination satellite; Tunnel information between the S-UPF of the source satellite and the S-gNB of the destination satellite; Tunnel information between the S-gNB of the source satellite and the S-gNB of the destination satellite.
4. A method for achieving inter-satellite data link security, characterized in that: Applied to the inter-satellite communication function of the source satellite, the method comprises: Receive a first data packet sent by the S-UPF or S-gNB of the source satellite; Receive routing information and security policy information corresponding to the routing information sent by a network controller, where the routing information is routing information related to a source satellite on an inter-satellite routing channel determined by the network controller based on a tunnel establishment request message sent by a session management function (SMF) of a core network, wherein the tunnel establishment request message is sent by the SMF after receiving a protocol data unit (PDU) session establishment request sent by a user equipment (UE), and the tunnel establishment request message includes tunnel information and security policy information; the security policy sent by the network controller includes a security policy for an inter-satellite communication function of the satellite generated by the network controller based on the SMF security policy; Perform security operations on the first data packet according to the security policy information.
5. The method according to claim 4, characterized in that Performing a security operation on the first data packet according to the security policy information includes: Sending a first operation request to a security function of the source satellite, where the first operation request carries the security policy information and is used to request the security function of the source satellite to perform a cryptographic operation on the first data packet based on the security policy information; Receive a first operation result fed back by the safety function of the source satellite.
6. The method according to claim 5, characterized in that The method further comprises: Determining the routing information and the next-hop satellite of the intersatellite link according to the routing information and the header information of the first data packet; A second data packet is constructed according to the first operation result and the routing information of the next hop, and the second data packet is sent to the next hop satellite.
7. The method according to claim 6, characterized in that Determining, according to the routing information and the header information of the first data packet, the routing information and the next-hop satellite of the intersatellite link, including: According to the routing information and the header information of the first data packet, it is determined that the routing information of the next hop of the intersatellite link is the second routing information, and the next hop satellite is a relay satellite.
8. The method according to any one of claims 5 to 7, characterized in that If the security policy information includes first cryptographic operation information, the first operation request further carries: the first data packet and destination satellite identification information; or, If the security policy information includes: key identification information and first cryptographic operation information, the first operation request also carries the first data packet.
9. A method for achieving inter-satellite data link security, characterized in that: Applied to the inter-satellite communication function of the destination satellite, the method comprises: receiving a third data packet sent by an inter-satellite communication function of a relay satellite, wherein the third data packet is constructed by the inter-satellite communication function of the relay satellite based on a second data packet and routing information from a network controller, wherein the second data packet comes from the inter-satellite communication function of a source satellite; receiving routing information sent by the network controller and security policy information corresponding to the routing information, wherein the routing information is routing information related to a destination satellite on an inter-satellite routing channel determined by the network controller according to a tunnel establishment request message sent by a session management function (SMF) of a core network, wherein the tunnel establishment request message is sent by the SMF after receiving a protocol data unit (PDU) session establishment request sent by a user equipment (UE), and the tunnel establishment request message includes tunnel information and security policy information; the security policy sent by the network controller includes a security policy for an inter-satellite communication function of the satellite generated by the network controller based on the SMF security policy; Determining, based on the header information of the third data packet and the routing information, data in the third data packet that needs to be security-related processed; Perform security operations on the data packets that need to be processed security-related according to the security policy information.
10. The method according to claim 9, characterized in that The performing security operations on the data packets requiring security-related processing according to the security policy information includes: sending a second operation request to a security function of a destination satellite, where the second operation request carries the security policy information and is used to request the security function of the destination satellite to perform a cryptographic operation on the data requiring security-related processing based on the security policy information; Receive a second operation result fed back by the safety function of the destination satellite.
11. The method according to claim 10, characterized in that The method further comprises: Send the second operation result to the S-UPF or S-gNB of the destination satellite.
12. The method according to any one of claims 10-11, characterized in that If the security policy information includes second cryptographic operation information, the second operation request further carries: the data requiring security-related processing and source satellite identification information; or, If the security policy information includes: key identification information and second cryptographic operation information, the second operation request also carries: the data that needs to be processed in a security-related manner.
13. A system for achieving inter-satellite data link security, characterized in that: The system includes: a satellite, a session management function SMF of a core network, and a network controller of a bearer network, wherein: A network controller in the bearer network is configured to determine an inter-satellite routing channel and routing information based on a tunnel establishment request message from the SMF, and send corresponding routing information and / or security policy information to each satellite on the inter-satellite routing channel, wherein each satellite on the inter-satellite routing channel includes a source satellite, a relay satellite, and a destination satellite. The tunnel establishment request message is sent by the SMF after receiving a protocol data unit (PDU) session establishment request sent by a user equipment (UE). The tunnel establishment request message includes tunnel information and security policy information. The security policy sent by the network controller includes a security policy for the satellite's inter-satellite communication function generated based on the SMF security policy. The inter-satellite communication function of the source satellite is configured to receive a first data packet from the S-UPF or S-gNB of the source satellite, as well as routing information and security policy information corresponding to the routing information from the network controller, and perform security operations on the first data packet according to the security policy information; an intersatellite communication function of the relay satellite, configured to construct a third data packet based on the second data packet from the source satellite and routing information from the network controller, and send the third data packet to the destination satellite; The inter-satellite communication function of the destination satellite is used to receive a third data packet from the relay satellite and routing information from the network controller and security policy information corresponding to the routing information, and determine the data in the third data packet that needs to be security-related processed based on the header information of the third data packet and the routing information; and perform security operations on the data packet that needs to be security-related processed based on the security policy information.
14. The system according to claim 13, wherein: The network controller sends corresponding routing information and / or security policy information to each satellite on the inter-satellite routing channel, including at least one of the following: Sending first routing information and security policy information corresponding to the first routing information to an inter-satellite communication function entity of a source satellite, so that the source satellite performs corresponding security calculations based on the security policy information; Sending second routing information to the inter-satellite communication function entity of the relay satellite; The third routing information and security policy information corresponding to the third routing information are sent to the inter-satellite communication function entity of the destination satellite, so that the destination satellite performs corresponding security calculations based on the security policy information.
15. The system according to claim 13 or 14, characterized in that The tunnel information includes any of the following: Tunnel information between the Satellite-User Plane Function (S-UPF) of the source satellite and the S-UPF of the destination satellite; Tunnel information between the satellite-gNB of the source satellite and the S-UPF of the destination satellite; Tunnel information between the S-UPF of the source satellite and the S-gNB of the destination satellite; Tunnel information between the S-gNB of the source satellite and the S-gNB of the destination satellite.
16. The system according to claim 14, wherein: The inter-satellite communication function of the source satellite is specifically configured to: Sending a first operation request to a security function of the source satellite, where the first operation request carries security policy information corresponding to the first routing information, and is used to request the security function of the source satellite to perform a cryptographic operation on the first data packet based on the security policy information; Receive a first operation result fed back by the safety function of the source satellite.
17. The system according to claim 16, wherein: The intersatellite communication function of the source satellite is also used for: Determining the routing information and the next-hop satellite of the intersatellite link according to the routing information and the header information of the first data packet; A second data packet is constructed according to the first operation result and the routing information of the next hop, and the second data packet is sent to the next hop satellite.
18. The system according to claim 17, wherein: The inter-satellite communication function of the source satellite is specifically configured to: determine the routing information and the next-hop satellite of the inter-satellite link according to the routing information and the header information of the first data packet; According to the routing information and the header information of the first data packet, it is determined that the routing information of the next hop of the intersatellite link is the second routing information, and the next hop satellite is a relay satellite.
19. The system according to any one of claims 16 to 18, characterized in that If the security policy information corresponding to the first routing information includes first cryptographic operation information, the first operation request further carries: the first data packet and destination satellite identification information; or, If the security policy information corresponding to the first routing information includes: key identification information and first cryptographic operation information, the first operation request also carries the first data packet.
20. The system according to claim 14, wherein: The intersatellite communication function of the target satellite is specifically used to: sending a second operation request to a security function of a destination satellite, where the second operation request carries security policy information corresponding to the third routing information, and is used to request the security function of the destination satellite to perform a cryptographic operation on the data requiring security-related processing based on the security policy information; Receive a second operation result fed back by the safety function of the destination satellite.
21. The system according to claim 20, wherein: The target satellite's intersatellite communication function is also used to: Send the second operation result to the S-UPF or S-gNB of the destination satellite.
22. The system according to claim 20 or 21, characterized in that If the security policy information corresponding to the third routing information includes second cryptographic operation information, the second operation request further carries: the data requiring security-related processing and source satellite identification information; or, If the security policy information corresponding to the third routing information includes: key identification information and second cryptographic operation information, the second operation request further carries: the data that needs to be processed in a security-related manner.
Citation Information
Patent Citations
Satellite route establishing method and device
CN108270478A
Routing control method suitable for space-ground biplanar network architecture
CN111313961A