Key update method, information transmission method, device, medium and satellite network
By broadcasting update signaling and using a preset time mechanism in the satellite network, the dynamic updating of network element keys is achieved, which solves the problems of session keys being easily cracked and terminal state limitations, and improves the security and flexibility of data transmission.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-20
- Publication Date
- 2026-03-27
AI Technical Summary
In existing satellite network systems, session keys are easily cracked during data transmission, leading to data leakage. Furthermore, existing key update methods require the terminal to be idle before they can be triggered, resulting in low data transmission flexibility.
The network element dynamically updates the sending and receiving keys by broadcasting update signaling through the user's home server, based on the key version number and random number in the signaling. This avoids direct transmission of the session key and uses a preset time mechanism to ensure the flexibility and stability of the update.
It improves the security and flexibility of data transmission in satellite networks, avoids data leakage, ensures the flexibility of encryption and decryption between network elements and the stability of data transmission, and reduces key update time.
Smart Images

Figure CN116321140B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of key update of satellite network, and particularly provides a key update method, an information transmission method, a device, a medium and a satellite network. BACKGROUND
[0002] DVB-RCS2 is a satellite network standard and is widely used in satellite communication systems. DVB-RCS2 shares encrypted passwords with user terminals and network control centers.
[0003] In the current satellite network system, in data transmission, the network control center generates an encrypted session key for data transmission when the user terminal is registered, and then the network control center issues the encrypted session key to the user terminal after encrypting the session key by password. However, this data transmission method directly transmits the session key in the satellite network, which is easy to cause the session key to be cracked and lead to data leakage.
[0004] The key update method in the prior art is that the user terminal needs to be registered again, and then the network control center issues a newly generated session key to the user terminal. However, this key update method needs to trigger the update when the terminal is in an idle state, which leads to the fact that the user terminal cannot update the key in real time, and further makes the flexibility of data transmission between the network control center and the user terminal low.
[0005] Correspondingly, there is a need in the art for a new key update scheme to solve the above problems. SUMMARY
[0006] In order to overcome the above defects, the present application is proposed to provide a key update method, an information transmission method, a device, a medium and a satellite network to solve or at least partially solve the technical problem that the key update is limited by the state of the terminal and cannot be updated in real time.
[0007] In a first aspect, the present application provides a key update method, which is applied to a satellite network, the satellite network comprising a user home server and at least one network element interacting with the user home server, the network element using a receiving key when receiving data, the receiving key comprising a first receiving key and a second receiving key, the network element using a sending key when sending data; the method comprising the following steps: the user home server broadcasting update signaling, wherein the update signaling comprises two updated key version numbers and random numbers corresponding to the two updated key version numbers respectively, wherein the two updated key version numbers comprise a current key version number to be updated and a next key version number to be updated; the network element receiving and responding to the update signaling, within a preset time, updating the sending key based on the current key version number to be updated and the random number in the update signaling, maintaining the receiving key unchanged, at this time, the first receiving key is the same as the running key before the update, and the key version number in the second receiving key and the random number thereof are the same as the current key version number to be updated and the random number respectively; after the preset time, the network element updating the receiving key based on the two updated key version numbers and the random numbers corresponding to the two updated key version numbers in the received update signaling, at this time, the key version number in the first receiving key and the random number thereof are the same as the current key version number to be updated and the random number respectively, and the key version number in the second receiving key and the random number thereof are the same as the next key version number to be updated and the random number respectively.
[0008] In one technical solution of the above key update method, the at least one network element comprises a network side network element and a terminal side network element, the network side network element at least comprising an authentication center, the terminal side network element comprising at least one user terminal that has been authenticated by the authentication center, the user terminal storing a root key, and the authentication center also storing the root key correspondingly.
[0009] In one of the technical solutions of the key updating method, the network side network element further comprises a gateway, and the method further comprises: the authentication center performing key derivation based on a root key of the authentication center, the sending key or the receiving key, obtaining a session key of the authentication center, and sending the session key to the user home server; the user home server taking the received session key of the authentication center as a root key of the user home server, performing key derivation based on the root key of the user home server, the sending key or the receiving key, obtaining a session key of the user home server, and sending the session key to the gateway; and the gateway taking the received session key of the user home server as a root key of the gateway, performing key derivation based on the root key of the gateway, the sending key or the receiving key, and obtaining a session key of the gateway.
[0010] In one of the technical solutions of the key updating method, the gateway comprises an IP gateway, a forward link gateway MCS and a reverse link gateway RCM, the IP (Internet Protocol) gateway uses the received session key of the user home server as the root key of the IP gateway; the gateway performs key derivation based on the root key, the sending key or the receiving key of the gateway to obtain the session key of the gateway, including: the IP gateway performs key derivation based on the root key, the sending key or the receiving key of the IP gateway to obtain the session key of the IP gateway and selectively sends the session key to the forward link gateway and the reverse link gateway respectively, wherein the session key of the IP gateway comprises a NAS (Non-Access-stratum, non-access layer) layer signaling encryption key, a NAS layer signaling integrity protection key, an E-PDCP (Extended Packet Data Convergence Protocol) encryption key, a forward link root key sent to the forward link gateway and a reverse link root key sent to the reverse link gateway; the forward link gateway uses the received forward link root key as the root key of the forward link gateway, and the forward link gateway performs key derivation based on the root key, the sending key or the receiving key of the forward link gateway to obtain the session key of the forward link gateway, wherein the session key of the forward link gateway comprises an AS (Access-stratum, access layer) layer signaling forward encryption key, an AS layer signaling forward integrity protection key and a link layer forward data encryption key; the reverse link gateway uses the received reverse link root key as the root key of the reverse link gateway, and the reverse link gateway performs key derivation based on the root key, the sending key or the receiving key of the reverse link gateway to obtain the session key of the reverse link gateway, wherein the session key of the reverse link gateway comprises an AS layer signaling reverse encryption key, an AS layer signaling reverse integrity protection key and a link layer reverse data encryption key.
[0011] In one of the technical solutions of the key updating method, the user home server periodically broadcasts the updating signaling, and the broadcast frequency of the user home server to the terminal side network element is much higher than the broadcast frequency of the user home server to the network side network element.
[0012] In one of the technical solutions of the key updating method, the method further comprises: presetting a plurality of rotating key version numbers and random numbers corresponding to the key version numbers; and generating the updating signaling based on the preset plurality of rotating key version numbers and the random numbers corresponding to the key version numbers.
[0013] In a second aspect, the present application provides an information transmission method, which is applied to a satellite network, the network comprising at least an IP gateway, a forward link gateway, a reverse link gateway and a user terminal, the user terminal corresponding keys comprising an E-PDCP encryption key, a NAS layer signaling encryption key and a NAS layer signaling integrity protection key, the forward link gateway corresponding keys comprising an AS layer signaling forward encryption key, an AS layer signaling forward integrity protection key and a link layer forward data encryption key, the reverse link gateway corresponding keys comprising an AS layer signaling reverse encryption key, an AS layer signaling reverse integrity protection key and a link layer reverse data encryption key; the method comprising: the forward link gateway performing information data transmission with the IP gateway based on E-PDCP encrypted data and performing information data transmission with the user terminal based on data after AS layer signaling encryption and link layer BBFrame (Baseband frame) encryption on the E-PDCP encrypted data; the reverse link gateway performing information data transmission with the IP gateway based on E-PDCP encrypted data and performing information data transmission with the user terminal based on data after AS layer signaling encryption and link layer MAC (Media Access Control) encryption on the E-PDCP encrypted data; wherein at least one key of the corresponding keys of the IP gateway, the forward link gateway, the reverse link gateway and the user terminal is updated based on any one of the above methods.
[0014] In a third aspect, a control device is provided, which comprises a processor and a memory, the memory being adapted to store a plurality of program codes, the program codes being adapted to be loaded and run by the processor to execute the key update method of any one of the technical solutions of the above key update method.
[0015] In a fourth aspect, a computer readable storage medium is provided, which has a plurality of program codes stored therein, the program codes being adapted to be loaded and run by a processor to execute the key update method of any one of the technical solutions of the above key update method.
[0016] In a fifth aspect, a satellite network is provided, the satellite network comprising a user home server, at least one network element, and the control device described above, the at least one network element comprising: a network-side network element and a terminal-side network element, the network-side network element comprising at least an authentication center and a gateway, and the terminal-side network element comprising at least one user terminal authenticated by the authentication center, wherein the user home server is configured to broadcast update signaling to the at least one network element respectively; the gateway is configured to transmit data between the authentication center and the at least one user terminal; and the control device is configured to perform the key update method described in any one of the above aspects, and the control device is configured to interact with the network-side network element and / or the terminal-side network element respectively to enable the network-side network element and / or the terminal-side network element to update the key based on the control device.
[0017] The one or more technical solutions of the present application described above have at least one or more of the following beneficial effects: the sending key of the network element is updated according to the update signaling broadcast by the user home server, and the receiving key is updated after a preset time, which realizes dynamic updating of the sending key and the receiving key of the network element, and makes the dynamic updating of the sending key and the receiving key of the network element not affected by the state of the network element, thereby ensuring the stability of data transmission between the network elements in the satellite network, and avoiding the update mode in the prior art which requires the terminal to be in an idle state to trigger the update, resulting in that the user terminal cannot update the key in real time, and thereby the flexibility of data transmission between the network control center and the user terminal is low.
[0018] In the implementation of the technical solutions of the present application, the session key used for data transmission of the network element is derived by the network element using the sending key or the receiving key based on the root key of the network element, so that the session key is not involved in data transmission in the satellite network, which improves the security of data transmission in the satellite network, and avoids the situation of data leakage due to direct data transmission of the session key in the prior art.
[0019] In the implementation of the technical solutions of the present application, by setting a preset time, when the key version numbers of the data of the receiving network element and the sending network element are different, the receiving network element can still decrypt the data it receives by using the first receiving key or the second receiving key in the receiving key, which improves the flexibility of encryption or decryption in data transmission between the network elements.
[0020] In the technical scheme of the present application, the user home server periodically broadcasts update signaling, and the update signaling is a plurality of rotating key version numbers and random numbers corresponding to the key version numbers, so that the rotation of the update signaling can be regularly switched, ensuring stable operation of key derivation of each network element, thereby improving the stability of data transmission of the satellite network, reducing the time required for key derivation during dynamic update of the key of each gateway, and improving the efficiency of dynamic update of the key. BRIEF DESCRIPTION OF DRAWINGS
[0021] The disclosure of the present application will become more apparent from the following description in conjunction with the accompanying drawings. It is readily understood by those skilled in the art that the drawings are merely intended to illustrate the present application and are not intended to limit the scope of protection of the present application. In addition, similar numbers in the drawings are used to represent similar components, wherein:
[0022] Figure 1 is a schematic diagram of the architecture of an existing satellite network system;
[0023] Figure 2 is a schematic diagram of the space network security architecture of the present application;
[0024] Figure 3 is a schematic diagram of the main steps of the key update method according to an embodiment of the present application;
[0025] Figure 4 is a schematic diagram of the key derivation of the user terminal according to the present application within a preset time after receiving and responding to the update signaling;
[0026] Figure 5 is a schematic diagram of the key derivation of the user terminal according to the present application after a preset time after receiving and responding to the update signaling;
[0027] Figure 6 is a schematic diagram of the key derivation of the network side network element according to the present application within a preset time after receiving and responding to the update signaling;
[0028] Figure 7 is a schematic diagram of the key derivation of the network side network element according to the present application after a preset time after receiving and responding to the update signaling;
[0029] Figure 8 is a schematic diagram of the key system for key derivation of the network side network element or the terminal side network element according to the present application;
[0030] Figure 9 is a schematic diagram of the key update according to the present application;
[0031] Figure 10 is a schematic diagram of the steps of the key update according to the present application;
[0032] Figure 11 is a schematic diagram of broadcast update signaling of a user home server to a network side network element and a terminal side network element respectively according to the present application;
[0033] Figure 12 is a schematic diagram of data transmission between a network side network element and a terminal side network element when the network side network element receives the update signaling first according to the present application;
[0034] Figure 13 is a schematic diagram of data transmission between a network side network element and a terminal side network element when the terminal side network element receives the update signaling first according to the present application;
[0035] Figure 14 is a schematic diagram of main steps of an information transmission method according to an embodiment of the present application;
[0036] Figure 15 is a schematic diagram of a spatial network layered encryption structure according to the present application;
[0037] Figure 16 is a schematic diagram of main structure of a control device according to an embodiment of the present application;
[0038] Figure 17 is a schematic diagram of main structure of a satellite network according to an embodiment of the present application.
[0039] List of reference signs:
[0040] 700: control device; 701: processor; 702: memory; 703: program code; 800: satellite network; 801: authentication center; 802: user home server; 803: gateway; 804: user terminal. DETAILED DESCRIPTION
[0041] Some embodiments of the present application will be described below with reference to the accompanying drawings. It should be understood by those skilled in the art that these embodiments are only used to explain the technical principles of the present application, and are not intended to limit the protection scope of the present application.
[0042] In the description of the present application, "module" and "processor" can include hardware, software or a combination of both. A module can include hardware circuitry, various suitable sensors, communication ports, memories, and can also include a software part such as program code, and can be a combination of software and hardware. The processor can be a central processor, a microprocessor, an image processor, a digital signal processor or any other suitable processor. The processor has data and / or signal processing functions. The processor can be implemented in software, hardware or a combination of both. The non-transitory computer readable storage medium includes any suitable medium that can store program code, such as a magnetic disk, a hard disk, an optical disk, a flash memory, a read-only memory, a random access memory, etc. The term "A and / or B" means all possible combinations of A and B, such as only A, only B or both A and B. The term "at least one of A or B" or "at least one of A and B" has a similar meaning as "A and / or B" and can include only A, only B or both A and B. The singular form of the term "one", "this" can also include the plural form.
[0043] The schematic diagram of the architecture of the existing satellite network system is shown in Figure 1 The existing satellite network system is composed of a ground segment, a space segment and a user segment. The gateway system of the ground segment includes an IP gateway, a forward link gateway and a reverse link gateway. The space segment includes a transparent star or a low-orbit satellite constellation with regeneration function. The user segment includes a user terminal and a connected terminal network.
[0044] The schematic diagram of the space network security architecture of the present application is shown in Figure 2 The space network security architecture is composed of four fields: access domain security, transmission domain security, non-access layer home service domain security and application domain security. The access domain security guarantees the access authentication and secure transmission between the user terminal and the transparent forwarding satellite gateway or the access satellite with inter-satellite link. The transmission domain security guarantees the point-to-point security of the inter-satellite link, the point-to-point security of the feeder link and the point-to-point transmission security between the ground gateways. The non-access layer home service domain security guarantees the security at the network layer between the user terminal and the core network access anchor IP gateway, including the bidirectional authentication and encrypted transmission between the terminal and the IP gateway. The application domain security is realized by means of mature transmission layer protocol. Specifically, the present application mainly focuses on the two fields of access domain security and non-access layer home service domain security of the satellite network, and is mainly used for encryption and integrity protection at the access layer and the non-access layer.
[0045] Those skilled in the art can understand that Figure 2 The overall architecture shown in the above table does not constitute a limitation on the satellite network. In actual application, the satellite network can include more or fewer components than those shown in the diagram, or some components can be combined, or different component arrangement.
[0046] The application provides a key updating method, which is applied to a satellite network, the satellite network comprising a user home server and at least one network element interacting with the user home server, the network element using a receiving key when receiving data, the receiving key comprising a first receiving key and a second receiving key, and the network element using a sending key when sending data.
[0047] Referring to the accompanying Figure 3 , Figure 3 is a main step flowchart of the key updating method according to an embodiment of the application. As shown in Figure 3 , the key updating method in the embodiment of the application mainly comprises the following steps S301-S303.
[0048] Step S301: the user home server broadcasts an updating signaling, wherein the updating signaling comprises two updated key version numbers and random numbers corresponding to the two updated key version numbers respectively, and the two updated key version numbers comprise a current key version number to be updated and a next key version number to be updated.
[0049] Specifically, in some embodiments, the user home server broadcasting the updating signaling comprises that the user home server periodically broadcasts the updating signaling, and the broadcasting frequency of the user home server to the terminal-side network element is much higher than the broadcasting frequency of the user home server to the network-side network element, so that when a new user terminal is registered, the user home server can timely broadcast the current updating signaling to the terminal-side network element, so that the new user terminal can timely perform data transmission.
[0050] In the above embodiment, the user home server periodically broadcasts the updating signaling, and the updating signaling is a plurality of rotating key version numbers and random numbers corresponding to the key version numbers, so that the rotation of the updating signaling can be regularly switched, ensuring the stable operation of the key derivation of each network element, thereby improving the stability of data transmission of the satellite network, reducing the time required for key derivation during the dynamic updating of the key of each gateway, and improving the efficiency of the dynamic updating of the key.
[0051] Step S302: the network element receives and responds to the updating signaling, and within a preset time, the network element updates the sending key based on the current key version number to be updated and the random number in the updating signaling, and maintains the receiving key unchanged, at this time, the first receiving key is the same as the running key before updating, and the key version number and the random number in the second receiving key are the same as the current key version number to be updated and the random number respectively.
[0052] Step S303: After the preset time, the network element updates the received key based on the two updated key version numbers in the received update signaling and the random numbers corresponding to the two updated key version numbers respectively, at this time, the key version number and the random number in the first received key are the same as the current key version number and the random number that need to be updated respectively, and the key version number and the random number in the second received key are the same as the next key version number and the random number that need to be updated respectively.
[0053] Specifically, in some embodiments, when the network element receives and responds to the update signaling, and after the preset time, the received key is updated, and the updated sending key is maintained unchanged.
[0054] In the above embodiments, by setting the preset time, when the key version numbers of the data of the receiving network element and the sending network element are different, the receiving network element can still decrypt the data it receives through the first received key or the second received key in the received key, improving the flexibility of encryption or decryption in data transmission between network elements.
[0055] Further, in some embodiments, the user home server broadcasts the update signaling at a period higher than the preset time, so as to stabilize the update of the sending key and the received key.
[0056] Specifically, in some embodiments, the preset time is set to 10 minutes, and can also be 1 minute. Here, the setting of the preset time is only exemplary, and those skilled in the art can set it according to actual needs in actual tests, which will not be described here.
[0057] In the above embodiments, by updating the sending key of the network element according to the received update signaling broadcast by the user home server, and updating the received key after the preset time, dynamic updating of the sending key and the received key of the network element is realized, and the dynamic updating of the sending key and the received key of the network element is not affected by the state of the network element, thereby ensuring the stability of data transmission between network elements in the satellite network, avoiding the update mode in the prior art which needs to trigger the update when the terminal is in an idle state, resulting in that the user terminal cannot update the key in real time, and further making the flexibility of data transmission between the network control center and the user terminal low.
[0058] Further, in some embodiments, the at least one network element includes a network side network element and a terminal side network element, the network side network element at least includes an authentication center, and the terminal side network element includes at least one user terminal that has been authenticated by the authentication center, the user terminal stores a root key, and the authentication center also stores the root key of the user terminal.
[0059] Specifically, the user terminal is provided with an embedded security module, and the embedded security module is provided with a root key and an electronic serial number of the user terminal. The authentication center also stores the root key and the electronic serial number of the user terminal.
[0060] Referring to the accompanying Figure 4 , Figure 4 is a flowchart of the key derivation of the user terminal according to the present application within a preset time after receiving and responding to the update signaling. Specifically, the key derivation process of the user terminal within a preset time after receiving and responding to the update signaling is similar to the key derivation process after the preset time.
[0061] As Figure 4 shown, the key derivation of the user terminal within a preset time after receiving and responding to the update signaling in the key update method in the embodiment of the present application includes:
[0062] The user terminal performs key derivation based on the root key of the user terminal and the updated sending key to obtain a first root key. The user terminal performs key derivation based on the first root key and the updated sending key to obtain a second root key. The user terminal performs key derivation based on the second root key and the updated sending key to obtain a third root key, a fourth root key, and a first group of three session keys. The user terminal performs key derivation based on the third root key and the updated sending key to obtain a second group of three session keys. The user terminal performs key derivation based on the fourth root key and the updated sending key to obtain a third group of three session keys. In this way, the user terminal can complete derivation by using the updated sending key and the root key to obtain nine session keys for encrypting data when sending data.
[0063] Further, referring to the accompanying Figure 5 , Figure 5 is a flowchart of the key derivation of the user terminal according to the present application after a preset time after receiving and responding to the update signaling. As Figure 5 shown, the key derivation of the user terminal after a preset time after receiving and responding to the update signaling in the key update method in the embodiment of the present application is different from the key derivation of the user terminal within a preset time after receiving and responding to the update signaling in that: in the multiple rounds of key derivation based on the root key, the user terminal uses the second receiving key of the updated receiving key to obtain nine session keys for decrypting data when receiving data. The specific derivation process is the same as the above key derivation process, and thus is not described here.
[0064] Referring to the accompanyingFigure 6 , Figure 6 is a flowchart of the network-side network element according to the present application in the process of receiving and responding to update signaling and key derivation within a preset time. Specifically, the network-side network element in the process of receiving and responding to update signaling and key derivation within a preset time is similar to the process of key derivation after a preset time.
[0065] As shown in Figure 6 , the network-side network element further comprises a gateway, and the network-side network element in the key update method in the embodiment of the present application in the process of receiving and responding to update signaling and key derivation within a preset time comprises:
[0066] The authentication center performs key derivation based on the root key of the authentication center and the updated sending key, derives a session key of the authentication center and sends it to the user home server, wherein the session key of the authentication center is the same as the first root key; the user home server takes the received session key of the authentication center as a root key of the user home server, performs key derivation based on the root key of the user home server and the updated sending key, derives a session key of the user home server and sends it to the gateway, wherein the session key of the user home server is the same as the second root key; the gateway takes the received session key of the user home server as a root key of the gateway, performs key derivation based on the root key of the gateway and the updated sending key, and derives a session key of the gateway.
[0067] Specifically, in some embodiments, the gateway comprises an IP gateway, a forward link gateway and a reverse link gateway, the IP gateway takes the received session key of the user home server as a root key of the IP gateway; the gateway performs key derivation based on the root key of the gateway and the updated sending key to obtain session keys of the gateway, including: the IP gateway performs key derivation based on the root key of the IP gateway and the updated sending key to obtain session keys of the IP gateway and selectively sends to the forward link gateway and the reverse link gateway respectively, wherein the session keys of the IP gateway include: NAS layer signaling encryption key, NAS layer signaling integrity protection key, E-PDCP encryption key, forward link root key sent to the forward link gateway and reverse link root key sent to the reverse link gateway, specifically, the session keys of the IP gateway are respectively the same as the three session keys of the first group, the third root key and the fourth root key, wherein the forward link root key is the same as the third root key, and the reverse link root key is the same as the fourth root key; the forward link gateway takes the received forward link root key as a root key of the forward link gateway, and the forward link gateway performs key derivation based on the root key of the forward link gateway and the updated sending key to obtain session keys of the forward link gateway, wherein the session keys of the forward link gateway include: AS layer signaling forward encryption key, AS layer signaling forward integrity protection key and link layer forward data encryption key, specifically, the session keys of the forward link gateway are respectively the same as the three session keys of the second group; the reverse link gateway takes the received reverse link root key as a root key of the reverse link gateway, and the reverse link gateway performs key derivation based on the root key of the reverse link gateway and the updated sending key to obtain session keys of the reverse link gateway, wherein the session keys of the reverse link gateway include: AS layer signaling reverse encryption key, AS layer signaling reverse integrity protection key and link layer reverse data encryption key, specifically, the session keys of the reverse link gateway are respectively the same as the three session keys of the third group, so as to realize that the network side network element completes derivation through the updated sending key and the root key thereof to obtain nine session keys for the network side network element to encrypt data when sending data.
[0068] Further, referring to the accompanying drawings Figure 7 , Figure 7 is a flowchart of the network side network element according to the present application in receiving and responding to the update signaling and key derivation after a preset time. As Figure 7As shown, in the key update method in the embodiment of the present application, the difference between the key derivation of the network side network element after receiving and responding to the update signaling and after the preset time and the key derivation of the network side network element within the preset time after receiving and responding to the update signaling is that: in the multiple rounds of key derivation based on the root key of the network side network element, the second receiving key of the updated receiving key is used to obtain 9 session keys for the network side network element to decrypt the data when receiving the data.
[0069] Referring to the accompanying Figure 8 , Figure 8 is a schematic diagram of a key system for key derivation of the network side network element or the terminal side network element according to the present application. As Figure 8 shown, the key derivation process of the network side network element is as follows:
[0070] The authentication center derives the session keys CK and IK of the authentication center based on the root key KeyRoot and the sending key or the receiving key and sends them to the user home server;
[0071] The user home server derives the session key KeyASME of the user home server based on the CK and IK and the sending key or the receiving key and sends it to the IP gateway;
[0072] The IP gateway derives the session keys of the IP gateway, i.e. the NAS layer signaling encryption key KeyNAS_enc, the NAS layer signaling integrity protection key KeyNAS_int, the E-PDCP encryption key KeyUP_enc, the forward link root key KeyMCS, and the reverse link root key KeyRCM based on the KeyASME and the sending key or the receiving key, wherein the KeyMCS is sent to the forward link gateway and the KeyRCM is sent to the reverse link gateway;
[0073] The forward link gateway derives the AS layer signaling forward encryption key KeyASF_enc, the AS layer signaling forward integrity protection key KeyASF_int, and the link layer forward data encryption key KeyFL_enc based on the KeyMCS and the sending key or the receiving key;
[0074] The reverse link gateway derives the AS layer signaling reverse encryption key KeyASR_enc, the AS layer signaling reverse integrity protection key KeyASR_int, and the link layer reverse data encryption key KeyRL_enc based on the KeyRCM and the sending key or the receiving key.
[0075] The key derivation process of the terminal side network element is as follows:
[0076] The user terminal derives a first root key CK and IK based on the root key KeyRoot and a transmission key or a reception key;
[0077] The user terminal derives a second root key KeyASME based on the CK and IK and a transmission key or a reception key;
[0078] The user terminal derives a third root key KeyMCS based on the KeyASME and a transmission key or a reception key;
[0079] The user terminal derives a fourth root key KeyRCM based on the KeyASME and a transmission key or a reception key;
[0080] The user terminal derives a first group of three session keys KeyNAS_enc, KeyNAS_int, KeyUP_enc based on the KeyMCS and a transmission key or a reception key;
[0081] The user terminal derives a second group of three session keys KeyASF_enc, KeyASF_int, KeyFL_enc based on the KeyRCM and a transmission key or a reception key.
[0082] Referring to the accompanying drawings Figure 9 , Figure 9 is a flowchart of the key update according to the present application. As shown in Figure 9 , in the present embodiment, a plurality of rotating key version numbers use A and B, and the steps of the key update are as follows:
[0083] The user home server broadcasts the update signaling A-B;
[0084] The user home server derives KeyASME-A based on A and sends it to the IP gateway;
[0085] The IP gateway derives KeyNAS_enc, KeyNAS_int, KeyUP_enc and two encrypted version numbers KeyMCS-A and KeyRCM-A based on KeyASME-A and the updated key, and forwards the encrypted version numbers to the forward link gateway and the reverse link gateway correspondingly;
[0086] The user terminal performs association registration with the IP gateway;
[0087] When the user terminal receives the new update signaling, the new three-layer keys KeyNAS_enc, KeyNAS_int, KeyUP_enc and the previous reverse link encryption keys KeyASF_enc, KeyASF_int, KeyFL_enc and KeyASR_enc, KeyASR_int, KeyRL_enc are derived based on the new key version number;
[0088] The forward link gateway derives the KeyASF_enc, KeyASF_int, KeyFL_enc based on the KeyMCS-A and the updated keys;
[0089] The reverse link gateway derives the KeyASR_enc, KeyASR_int, KeyRL_enc based on the KeyRCM-A and the updated keys;
[0090] The user home server broadcasts the update signaling B-A;
[0091] The user home server derives the KeyAsme-B based on B and sends it to the IP gateway;
[0092] The IP gateway derives the new KeyNAS_enc, KeyNAS_int, KeyUP_enc and the two encryption version numbers KeyMCS-B and KeyRCM-B based on the KeyAsme-B and the updated keys, and forwards the encryption version numbers to the forward link gateway and the reverse link gateway;
[0093] The forward link gateway derives the new KeyASF_enc, KeyASF_int, KeyFL_enc based on the KeyMCS-B and the updated keys;
[0094] The reverse link gateway derives the new KeyASR_enc, KeyASR_int, KeyRL_enc based on the KeyRCM-B and the updated keys.
[0095] In the above embodiment, the session key used for data transmission of the network element is derived by the network element using the sending key or the receiving key based on the root key of the network element, so that the session key is not involved in the data transmission in the satellite network, the security of the data transmission in the satellite network is improved, and the situation that data is leaked due to direct data transmission of the session key in the prior art is avoided.
[0096] Furthermore, in some embodiments, the method further includes: presetting a plurality of rotating key version numbers and random numbers corresponding to the key version numbers; and generating update signaling in rotation based on the preset plurality of rotating key version numbers and random numbers corresponding to the key version numbers.
[0097] Specifically, in some embodiments, the number of preset multiple rotating key version numbers can be 2, 3 or 4. The setting of the number of preset multiple rotating key version numbers is only an example. In actual testing, those skilled in the art can set it according to actual needs, which will not be elaborated here.
[0098] The solution of the present invention will be further described below with reference to application examples.
[0099] See appendix Figure 10 , Figure 10 This is a schematic diagram illustrating the key update steps according to the present invention. Figure 10 As shown, in this embodiment, multiple rotating key version numbers are represented by numbers 0 to 7, the preset time is set to DeltaT, the sending key is the sending key, and the receiving key is the receiving key. The specific steps for key updating in this invention are as follows:
[0100] When the first update signaling is received, the sending key is updated to 0. At this time, the receiving key is 0. After DeltaT, the sending key is 0, and the receiving key is updated to 0 and 1, thus realizing the first update of the sending key and the receiving key.
[0101] Upon receiving a new update signaling, the sending key is updated to 1, while the receiving key remains unchanged: 0 and 1. After DeltaT, the sending key remains unchanged: 1, while the receiving key is updated to 1 and 2, thus realizing the second update of the sending and receiving keys.
[0102] Upon receiving a new update signaling, the sending key is updated to 2, while the receiving key remains unchanged: 1 and 2. After DeltaT, the sending key remains unchanged: 2, while the receiving key is updated to 2 and 3, thus realizing the third update of the sending and receiving keys.
[0103] Upon receiving a new update signaling, the sending key is updated to 3, while the receiving key remains unchanged: 2 and 3. After DeltaT, the sending key remains unchanged: 3, while the receiving key is updated to 3 and 4, thus achieving the fourth update of the sending and receiving keys.
[0104] This process is repeated to update the sending and receiving keys.
[0105] See appendix Figure 11 ,Figure 11 This is a schematic diagram illustrating the broadcast update signaling by the user's home server to both network-side and terminal-side network elements according to the present invention. Figure 11 As shown, in this embodiment, multiple rotating key version numbers use A and B. This AB rotation overcomes the asynchrony problem caused by the key switching occurring at different times between the two network elements at the receiving and sending ends, thus achieving seamless key switching. Specifically, in some embodiments, the signaling broadcast density from the user's home server to the terminal-side network elements is much greater than the signaling broadcast density from the user's home server to the network-side network elements, because user terminals frequently go online and offline, while the gateway remains in an active, service-oriented state.
[0106] See appendix Figure 12 , Figure 12 This is a schematic diagram illustrating data transmission between the network-side network element and the terminal-side network element when the network-side network element first receives the update signaling, according to the present invention. Figure 12 As shown, in this embodiment, the multiple rotating key version numbers use A0-B1-A2-B3. The preset time is set so that when the DeltaT network-side network element receives the update signaling first, the data transmission steps with the terminal-side network element are as follows:
[0107] When a network element needs to send data to a terminal element, its sending key is A0 and its receiving key is A0 and B1. Then, A0 is used to encrypt the data to be sent to the terminal element.
[0108] When a terminal-side network element receives data encrypted with A0, its sending key is A0, and its receiving key is A0 and B1. It then uses A0 from the receiving key to decrypt the data and uses A0 to encrypt the sent data before sending it back to the network-side network element.
[0109] When a network-side network element receives an update signaling message, within the DeltaT time period, its sending key is updated to B1, and its receiving key is A0 and B1. When a network-side network element receives data encrypted with A0, it decrypts the data using A0 in the receiving key and encrypts the sending data using B1 to send the data back to the terminal-side network element.
[0110] When a terminal-side network element receives an update signaling message, within the DeltaT time period, its sending key is updated to B1, and its receiving key is A0 and B1. When a terminal-side network element receives data encrypted with B1, it decrypts the data using B1 in the receiving key and encrypts the sending data using B1 to send the data back to the network-side network element.
[0111] The network side network element updates the sending key to B1 and the receiving key to B1 and A2 after DeltaT time. The network side network element receives data encrypted by B1, decrypts the data by using B1 in the receiving key, and encrypts the sending data by using B1. The reverse network side network element sends data.
[0112] The terminal side network element updates the sending key to B1 and the receiving key to B1 and A2 after DeltaT time. The terminal side network element receives data encrypted by B1, decrypts the data by using B1 in the receiving key, and encrypts the sending data by using B1. The reverse network side network element sends data. In this way, seamless transmission between the terminal side network element and the network side network element is realized.
[0113] Referring to the accompanying drawings Figure 13 , Figure 13 Fig. 1 is a schematic diagram of data transmission between a terminal side network element and a network side network element according to the present application. As shown in Fig. 1, in this embodiment, the multiple rotating key version numbers are A0-B1-A2-B3, and the preset time is DeltaT. The steps of data transmission between the terminal side network element and the network side network element when the terminal side network element first receives the update signaling are as follows: Figure 13
[0114] The terminal side network element needs to send data to the network side network element. At this time, the sending key is A0, and the receiving key is A0 and B1. The terminal side network element encrypts the sending data by using A0. The reverse network side network element sends data.
[0115] The network side network element receives data encrypted by A0. At this time, the sending key is A0, and the receiving key is A0 and B1. The network side network element decrypts the data by using A0 in the receiving key, and encrypts the sending data by using A0. The reverse terminal side network element sends data.
[0116] The terminal side network element receives the update signaling. Within DeltaT time, the sending key is updated to B1, and the receiving key is A0 and B1. The terminal side network element receives data encrypted by A0. The terminal side network element decrypts the data by using A0 in the receiving key, and encrypts the sending data by using B1. The reverse network side network element sends data.
[0117] The network side network element receives the update signaling. Within DeltaT time, the sending key is updated to B1, and the receiving key is A0 and B1. The network side network element receives data encrypted by B1. The network side network element decrypts the data by using B1 in the receiving key, and encrypts the sending data by using B1. The reverse terminal side network element sends data.
[0118] The terminal side network element updates the sending key to B1 after DeltaT time, the receiving key is B1 and A2, the terminal side network element receives the data encrypted by B1, decrypts the data by using B1 in the receiving key, and encrypts the sending data by using B1, and the reverse terminal side network element sends the data;
[0119] The network side network element updates the sending key to B1 after DeltaT time, the receiving key is B1 and A2, the network side network element receives the data encrypted by B1, decrypts the data by using B1 in the receiving key, and encrypts the sending data by using B1, and the reverse terminal side network element sends the data, and so on, so as to realize seamless transmission between the network side network element and the terminal side network element.
[0120] Further, the application also provides an information transmission method, which is applied to a satellite network, the network at least includes an IP gateway, a forward link gateway, a reverse link gateway and a user terminal, the user terminal corresponding keys include an E-PDCP encryption key, a NAS layer signaling encryption key and a NAS layer signaling integrity protection key, the forward link gateway corresponding keys include an AS layer signaling forward encryption key, an AS layer signaling forward integrity protection key and a link layer forward data encryption key, and the reverse link gateway corresponding keys include an AS layer signaling reverse encryption key, an AS layer signaling reverse integrity protection key and a link layer reverse data encryption key.
[0121] Refer to the accompanying drawings Figure 14 , Figure 14 is the main step flow diagram of the information transmission method according to an embodiment of the application. As shown in the figure, Figure 14 The information transmission method in the embodiment of the application mainly includes the following steps S601-S602.
[0122] Step S601: the forward link gateway performs information data transmission with the IP gateway based on the E-PDCP encrypted data and performs information data transmission with the user terminal based on the data after AS layer signaling encryption and link layer BBFrame encryption on the E-PDCP encrypted data;
[0123] Step S602: the reverse link gateway performs information data transmission with the IP gateway based on the E-PDCP encrypted data and performs information data transmission with the user terminal based on the data after AS layer signaling encryption and link layer MAC encryption on the E-PDCP encrypted data, wherein at least one key of the corresponding keys of the IP gateway, the forward link gateway, the reverse link gateway and the user terminal is updated based on the method in any one of the above.
[0124] Refer to the accompanying drawings Figure 15 , Figure 15is a schematic diagram of a space network layered encryption structure according to the present application. As shown in Figure 15 The access layer implements link layer encryption and access layer AS signaling encryption and integrity protection, wherein in the link layer encryption, the forward link layer encryption adopts link layer BBFrame encryption, and the reverse link layer encryption adopts link layer MAC encryption; the non-access layer introduces an E-PDCP sublayer, wherein the end-to-end data between the IP gateway and the terminal are all encrypted by the E-PDCP and the non-access layer NAS signaling, to realize non-access layer NAS signaling integrity protection and data packet header compression, and to realize the end-to-end data encrypted by the E-PDCP and the NAS signaling to be encrypted by the link gateway in the transmission path, i.e. to be encrypted by the access layer MAC between the terminal and the access link gateway, so as to ensure the security of data transmission.
[0125] It should be noted that although the above embodiment describes the steps in a specific order, those skilled in the art can understand that, in order to achieve the effect of the present application, the different steps do not have to be executed in such an order, and they can be executed simultaneously (in parallel) or in other orders, and these changes are within the protection scope of the present application.
[0126] Those skilled in the art can understand that all or part of the processes in the method of the above embodiment can also be completed by a computer program instructing related hardware, and the computer program can be stored in a computer readable storage medium, and when the computer program is executed by a processor, the steps of each method embodiment described above can be realized. The computer program includes computer program code, which can be in the form of source code, object code, executable files or some intermediate forms, etc. The computer readable storage medium can include any entity or device, medium, U disk, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory, random access memory, electrical carrier signal, telecommunication signal and software distribution medium, etc. that can carry the computer program code. It should be noted that the contents included in the computer readable storage medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction, for example, in some jurisdictions, according to legislation and patent practice, the computer readable storage medium does not include electrical carrier signals and telecommunication signals.
[0127] Further, the present application also provides a control device 700.
[0128] Referring to the accompanying Figure 16 , Figure 16 is a schematic diagram of the main structure of a control device according to an embodiment of the present application. As shown in Figure 16As shown, in an embodiment of the control device 700 according to the present application, the control device 700 comprises a processor 701 and a memory 702, the memory 702 can be configured to store program codes 703 for performing the key update method of the above-mentioned method embodiments, and the processor 701 can be configured to execute the program codes 703 in the memory 702, which includes but is not limited to the program codes 703 for performing the key update method of the above-mentioned method embodiments. For the convenience of illustration, only the parts related to the embodiments of the present application are shown, and the specific technical details not disclosed can be referred to the method part of the embodiments of the present application. The control device 700 can be a control device 700 formed by various electronic devices.
[0129] Further, the present application also provides a computer readable storage medium. In an embodiment of the computer readable storage medium according to the present application, the computer readable storage medium can be configured to store program codes 703 for performing the key update method of the above-mentioned method embodiments, which can be loaded and run by the processor 701 to implement the above-mentioned key update method. For the convenience of illustration, only the parts related to the embodiments of the present application are shown, and the specific technical details not disclosed can be referred to the method part of the embodiments of the present application. The computer readable storage medium can be a memory 702 device formed by various electronic devices, and optionally, the computer readable storage medium in the embodiments of the present application is a non-transitory computer readable storage medium.
[0130] Further, the present application also provides a satellite network 800.
[0131] Referring to the accompanying Figure 17 , Figure 17 is the main structure block diagram of the satellite network according to an embodiment of the present application. As shown, Figure 17 In an embodiment of the satellite network 800 according to the present application, the satellite network 800 mainly comprises a user home server 802, at least one network element and the above-mentioned control device 700, the at least one network element comprises: a network side network element and a terminal side network element, the network side network element at least comprises an authentication center 801 and a gateway 803, the terminal side network element comprises at least one user terminal 804 which has been authenticated by the authentication center 801, wherein the user home server 802 is configured to broadcast update signaling to the at least one network element respectively; the gateway 803 is configured to transmit data between the authentication center 801 and the at least one user terminal 804; the control device 700 is configured to perform the key update method of any one of the above-mentioned methods, and the control device 700 respectively interacts with the network side network element and / or the terminal side network element information, so that the network side network element and / or the terminal side network element realizes key update based on the control device 700. In an embodiment, the description of the specific implementation function can be referred to the steps S301-S303.
[0132] The satellite network described above is used to perform Figure 3 The technical principles, technical problems solved and technical effects of the key updating method and the embodiments are similar. For the convenience and brevity of description, the specific working process of the satellite network and the related description can be referred to the description of the embodiments of the key updating method, which will not be repeated here.
[0133] Further, it should be understood that, since the setting of each module is only for illustrating the functional units of the device of the present application, the physical device corresponding to the module can be the processor itself, or a part of software, a part of hardware, or a part of combination of software and hardware in the processor. Therefore, the number of each module in the figure is only illustrative.
[0134] Those skilled in the art can understand that each module in the device can be adaptively split or combined. Such splitting or combining of the specific module will not cause the technical solution to deviate from the principles of the present application, and therefore, the technical solution after splitting or combining will fall within the protection scope of the present application.
[0135] So far, the technical solution of the present application has been described in combination with the preferred embodiments shown in the drawings, but those skilled in the art can easily understand that the protection scope of the present application is obviously not limited to these specific embodiments. Those skilled in the art can make equivalent changes or replacements to the related technical features without deviating from the principles of the present application, and the technical solution after the changes or replacements will fall within the protection scope of the present application.
Claims
1. A key update method characterized by comprising: The method is applied to a satellite network, the satellite network comprising a user home server and at least one network element interacting with the user home server, the network element using a receiving key when receiving data, the receiving key comprising a first receiving key and a second receiving key, the network element using a sending key when sending data; The method comprises the following steps: The user home server broadcasts update signaling, wherein the update signaling comprises two updated key version numbers and random numbers corresponding to the two updated key version numbers respectively, wherein the two updated key version numbers comprise a current key version number to be updated and a next key version number to be updated; The network element receives and responds to the update signaling, and within a preset time, the network element updates the sending key based on the current key version number to be updated and the random number in the update signaling, and maintains the receiving key unchanged, at this time, the first receiving key is the same as the running key before the update, and the key version number and the random number in the second receiving key are the same as the current key version number to be updated and the random number respectively; After the preset time, the network element updates the receiving key based on the two updated key version numbers and the random numbers corresponding to the two updated key version numbers in the received update signaling, at this time, the key version number and the random number in the first receiving key are the same as the current key version number to be updated and the random number respectively, and the key version number and the random number in the second receiving key are the same as the next key version number to be updated and the random number respectively.
2. The key update method according to claim 1, characterized by, The at least one network element comprises a network side network element and a terminal side network element, the network side network element at least comprising an authentication center, and the terminal side network element comprising at least one user terminal authenticated by the authentication center, the user terminal storing a root key, and the authentication center also storing the root key of the user terminal correspondingly.
3. The key update method according to claim 2, characterized by, The network side network element further comprises a gateway, and the method further comprises: The authentication center performs key derivation based on the root key of the authentication center, the updated sending key or receiving key, obtains a session key of the authentication center, and sends the session key to the user home server; The user home server takes the received session key of the authentication center as a root key of the user home server, performs key derivation based on the root key of the user home server, the updated sending key or receiving key, obtains a session key of the user home server, and sends the session key to the gateway; The gateway takes the received session key of the user home server as a root key of the gateway, performs key derivation based on the root key of the gateway, the updated sending key or receiving key, and obtains a session key of the gateway.
4. The key update method according to claim 3, characterized by, The gateway comprises an IP gateway, a forward link gateway and a reverse link gateway, and the IP gateway takes the received session key of the user home server as a root key of the IP gateway; The gateway performs key derivation based on a root key of the gateway, the updated sending key or receiving key, to obtain a session key of the gateway, wherein the session key of the gateway comprises: The IP gateway performs key derivation based on a root key of the IP gateway, the updated sending key or receiving key, to obtain a session key of the IP gateway and selectively send the session key to the forward link gateway and the reverse link gateway respectively, wherein the session key of the IP gateway comprises: a NAS layer signaling encryption key, a NAS layer signaling integrity protection key, an E-PDCP encryption key, a forward link root key sent to the forward link gateway and a reverse link root key sent to the reverse link gateway; The forward link gateway takes the received forward link root key as a root key of the forward link gateway, and performs key derivation based on the root key of the forward link gateway, the updated sending key or receiving key, to obtain a session key of the forward link gateway, wherein the session key of the forward link gateway comprises: an AS layer signaling forward encryption key, an AS layer signaling forward integrity protection key and a link layer forward data encryption key; The reverse link gateway takes the received reverse link root key as a root key of the reverse link gateway, and performs key derivation based on the root key of the reverse link gateway, the updated sending key or receiving key, to obtain a session key of the reverse link gateway, wherein the session key of the reverse link gateway comprises: an AS layer signaling reverse encryption key, an AS layer signaling reverse integrity protection key and a link layer reverse data encryption key.
5. The key update method according to claim 3, wherein The user home server periodically broadcasts the update signaling, and the broadcast frequency of the user home server to the terminal side network element is much higher than the broadcast frequency of the user home server to the network side network element.
6. The key update method according to claim 1, wherein The method further comprises: presetting a plurality of rotating key version numbers and random numbers corresponding to the key version numbers; generating the update signaling based on the preset plurality of rotating key version numbers and the random numbers corresponding to the key version numbers.
7. An information transmission method characterized by comprising: The method is applied to a satellite network, the network comprising at least an IP gateway, a forward link gateway, a reverse link gateway and a user terminal, the user terminal corresponding keys comprising an E-PDCP encryption key, a NAS layer signaling encryption key and a NAS layer signaling integrity protection key, the forward link gateway corresponding keys comprising an AS layer signaling forward encryption key, an AS layer signaling forward integrity protection key and a link layer forward data encryption key, and the reverse link gateway corresponding keys comprising an AS layer signaling reverse encryption key, an AS layer signaling reverse integrity protection key and a link layer reverse data encryption key; the method comprising: The forward link gateway transmits information data with the IP gateway based on the E-PDCP encrypted data and transmits information data with the user terminal based on the data after AS layer signaling encryption and link layer BBFrame encryption of the E-PDCP encrypted data, so as to realize encryption of information data transmission between the forward link gateway and the IP gateway and two-layer encryption of information data transmission between the user terminal and the forward link gateway. The reverse link gateway transmits information data with the IP gateway based on the E-PDCP encrypted data and transmits information data with the user terminal based on the data after AS layer signaling encryption and link layer MAC encryption of the E-PDCP encrypted data, so as to realize encryption of information data transmission between the reverse link gateway and the IP gateway and two-layer encryption of information data transmission between the user terminal and the reverse link gateway. At least one of the corresponding keys of the IP gateway, the forward link gateway, the reverse link gateway and the user terminal is updated based on the method in any one of claims 1-6.
8. A control device comprising a processor and a memory, the memory being adapted to store a plurality of program codes, characterized in that, The program code is adapted to be loaded and run by the processor to execute the key updating method in any one of claims 1-6.
9. A computer readable storage medium having stored therein a plurality of program codes, characterized in that, The program code is adapted to be loaded and run by the processor to execute the key updating method in any one of claims 1-6.
10. A satellite network, characterized by The satellite network comprises a user home server, at least one network element and the control device in claim 8, the at least one network element comprises a network side network element and a terminal side network element, the network side network element at least comprises an authentication center and a gateway, the terminal side network element comprises at least one user terminal which has been authenticated by the authentication center, wherein the user home server is used to broadcast updating signaling to the at least one network element respectively; the gateway is used for data mutual transmission between the authentication center and the at least one user terminal; the control device is used to execute the key updating method in any one of claims 1-6, and the control device respectively interacts with the network side network element and / or the terminal side network element information, so that the network side network element and / or the terminal side network element realize key updating based on the control device.
Citation Information
Patent Citations
Play method for streaming media in IPTV system, EPG server and CDN server
CN106973310A
Secret key updating method and equipment
CN112653911A