Key transmission method and device and related equipment

By preconfiguring the shared key in the core network element, the terminal registration request message of non-terrestrial base stations is generated and encrypted, the problem of key leakage risk in the non-terrestrial base station networking scenario is solved, and the secure transmission of base station keys is realized.

CN120111482APending Publication Date: 2025-06-06CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510265769.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

In the non-terrestrial base station networking scenario, base station keys are easily eavesdropped by attackers, resulting in the risk of key leakage and affecting the security of Internet communications.

Method used

By preconfiguring the shared keys of the non-terrestrial base station and the core network element in the core network element, a base station key is generated in response to the terminal registration request message of the non-terrestrial base station, and the base station key is encrypted according to the shared key, and the encrypted base station key is sent to the non-terrestrial base station.

Benefits of technology

It effectively prevents theft or tampering of base station keys during transmission, and ensures the security of non-terrestrial base station Internet communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120111482A_ABST
    Figure CN120111482A_ABST
Patent Text Reader

Abstract

The invention provides a key transmission method and device and related equipment, and relates to the technical field of network security. The method comprises: in response to a terminal registration request message sent by a non-ground base station, generating a base station key, the terminal registration request message comprising an identifier of the non-ground base station; determining a shared key of the non-ground base station and the core network element according to the identifier of the non-ground base station, wherein the shared key of the non-ground base station and the core network element is pre-configured in the core network element; and encrypting the base station key according to the shared key to obtain an encrypted base station key, and sending the encrypted base station key to the non-ground base station. The base station secret key is encrypted through the shared secret key, the secret key is prevented from being stolen or tampered in the transmission process, and therefore transmission safety of the base station secret key is guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0002] The 5G network ensures the security of base station keys through an authentication-based key derivation mechanism. When a terminal accesses for the first time, the core network and the terminal perform two-way authentication, and then derive the AS layer root key base station key layer by layer. This mechanism relies on the physical proximity between the base station and the core network and the closed nature of the ground network. The base station key is transmitted through a secure channel with limited coverage, making it difficult for attackers to intercept it directly.

[0003] However, in non-ground base station networking scenarios such as satellite base stations, drone base stations, and stratospheric balloon base stations, since the non-ground base station channels are exposed to open airspace and the satellite beam coverage radius is large, attackers can use the non-ground base station downlink wireless signals or the ground uplink sidelobe signals to eavesdrop on the base station keys transmitted in plain text, resulting in the risk of base station keys being leaked, which in turn affects the security of non-ground base station Internet communications.

[0004] It should be noted that the information disclosed in the above background technology section is only used to enhance the understanding of the background of the present disclosure, and therefore may include information that does not constitute the prior art known to ordinary technicians in the field. Summary of the invention

[0005] The present invention provides a key transmission method, device and related equipment to solve the problem of secure key transmission between a core network and a non-ground base station, and ensure the security of Internet communications of the non-ground base station.

[0006] Other features and advantages of the present disclosure will become apparent from the following detailed description, or may be learned in part by the practice of the present disclosure.

[0007] According to one aspect of the present disclosure, a key transmission method is provided, which is applied to a core network network element, and the method includes: generating a base station key in response to a terminal registration request message sent by a non-ground base station, wherein the terminal registration request message includes an identifier of the non-ground base station; determining a shared key between the non-ground base station and the core network network element according to the identifier of the non-ground base station, wherein the shared key between the non-ground base station and the core network network element is pre-configured in the core network network element; encrypting the base station key according to the shared key to obtain the encrypted base station key, and sending the encrypted base station key to the non-ground base station.

[0008] In some embodiments, the core network network element includes an access and mobility management function AMF network element and a key encryption function KEF network element. Before generating the base station key, it also includes: using the AMF network element to derive the AMF key to obtain a base station key, and the AMF key is derived from the security anchor function key KSEAF stored in the AMF network element; according to the AMF network element responding to obtaining the base station key, starting the base station key security protection process; determining the shared key between the non-ground base station and the core network network element according to the identifier of the non-ground base station includes: according to the AMF network element responding to starting the base station key security protection process, using the AMF network element to generate an encryption request message based on the base station key, the encryption request message includes the identifier of the non-ground base station and the base station key, and sending the encryption request message to the KEF network element; the KEF network element is used to determine the shared key between the non-ground base station and the core network network element according to the encryption request message.

[0009] In some embodiments, the KEF network element is pre-configured with a shared key between the non-ground base station and the core network element, and determining the shared key between the non-ground base station and the core network element based on the identifier of the non-ground base station includes: searching in the KEF network element according to the identifier of the non-ground base station to obtain the shared key between the non-ground base station and the core network element.

[0010] In some embodiments, encrypting the base station key according to the shared key to obtain the encrypted base station key, and sending the encrypted base station key to the non-ground base station includes: using the KEF network element to encrypt the base station key according to the shared key to obtain the encrypted base station key; sending an encrypted response message to the AMF network element through the KEF, the encrypted response message including the encrypted base station key; sending the encrypted base station key to the non-ground base station through the AMF network element.

[0011] In some embodiments, the terminal registration request message also includes a terminal identifier. Before generating a base station key, the method also includes: authenticating the terminal according to the terminal identifier in the terminal registration request message to obtain a terminal authentication result; in response to the terminal authentication result being a successful terminal authentication, triggering a security establishment process between the terminal and the non-access layer of the core network network element to obtain a security authentication result; in response to the security authentication result being a successful security authentication, generating a base station key.

[0012] According to another aspect of the present disclosure, a key transmission method is also provided, which is applied to a non-ground base station, and the method includes: sending a terminal registration request message to a core network network element, the terminal registration request message including an identifier of the non-ground base station; receiving an encrypted base station key sent by the core network network element, the encrypted base station key being obtained by the core network network element encrypting the base station key according to a shared key, the shared key being determined according to the identifier of the non-ground base station, the shared key being a shared key pre-configured in the non-ground base station between the non-ground base station and the core network network element, and the base station key being generated by the core network network element in response to a terminal registration request message sent by the non-ground base station; decrypting the encrypted base station key according to the shared key pre-configured in the non-ground base station between the non-ground base station and the core network network element to obtain a base station key.

[0013] In some embodiments, the non-ground base station also includes a security module, which is pre-configured with a shared key between the non-ground base station and the core network element. The decrypting the encrypted base station key to obtain the base station key includes: sending the encrypted base station key to the security module; using the shared key between the non-ground base station and the core network element in the security module to decrypt the encrypted base station key to obtain the base station key.

[0014] In some embodiments, after decrypting the encrypted base station key to obtain the base station key, the method further includes: storing the base station key in the security module.

[0015] In some embodiments, before sending the terminal registration request message to the core network element, the method also includes: receiving an initial registration request message sent by the terminal, the initial registration request message including the terminal identifier of the terminal; generating a terminal registration request message according to the terminal identifier and the identifier of the non-ground base station.

[0016] According to another aspect of the present disclosure, a key transmission device is also provided, which is applied to a core network network element, and the device includes: a first generation module, used to generate a base station key in response to a terminal registration request message sent by a non-ground base station, and the terminal registration request message includes an identifier of the non-ground base station; a first determination module, used to determine a shared key between the non-ground base station and the core network network element according to the identifier of the non-ground base station, and the shared key between the non-ground base station and the core network network element is pre-configured in the core network network element; an encryption module, used to encrypt the base station key according to the shared key to obtain the encrypted base station key, and send the encrypted base station key to the non-ground base station.

[0017] According to another aspect of the present disclosure, a key transmission device is also provided, which is applied to a non-ground base station, and the device includes: a sending module, which is used to send a terminal registration request message to a core network network element, and the terminal registration request message includes an identifier of the non-ground base station; a receiving module, which is used to receive an encrypted base station key sent by the core network network element, and the encrypted base station key is obtained by the core network network element encrypting the base station key according to a shared key, and the shared key is determined according to the identifier of the non-ground base station, and the shared key is a shared key pre-configured in the non-ground base station between the non-ground base station and the core network element, and the base station key is generated by the core network element in response to the terminal registration request message sent by the non-ground base station; a decryption module, which is used to generate a shared key pre-configured in the non-ground base station between the non-ground base station and the core network element according to the shared key pre-configured in the non-ground base station.

[0018] According to another aspect of the present disclosure, an electronic device is also provided, which includes: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute any one of the key transmission methods described above by executing the executable instructions.

[0019] According to another aspect of the present disclosure, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the key transmission method described in any one of the above is implemented.

[0020] According to another aspect of the present disclosure, a computer program product is further provided, including: a computer program or instructions, wherein when the computer program or instructions are executed by a processor, any one of the above-mentioned key transmission methods is implemented.

[0021] A key transmission method provided in an embodiment of the present disclosure is applied to a core network element. The method includes: generating a base station key in response to a terminal registration request message sent by a non-ground base station, wherein the terminal registration request message includes an identifier of the non-ground base station; determining a shared key between the non-ground base station and the core network element according to the identifier of the non-ground base station, wherein the shared key between the non-ground base station and the core network element is pre-configured in the core network element; encrypting the base station key according to the shared key to obtain the encrypted base station key, and sending the encrypted base station key to the non-ground base station. The present disclosure determines a shared key between the non-ground base station and the core network element pre-configured in the core network element based on the identifier of the non-ground base station, and then uses the shared key to encrypt the base station key, and finally sends the encrypted base station key to the non-ground base station. In this way, the base station key is encrypted by the shared key to prevent the key from being stolen or tampered with during the transmission process, thereby ensuring the transmission security of the base station key.

[0022] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] The accompanying drawings herein are incorporated into the specification and constitute a part of the specification, illustrate embodiments consistent with the present disclosure, and together with the specification are used to explain the principles of the present disclosure. Obviously, the accompanying drawings described below are only some embodiments of the present disclosure, and for ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without creative work.

[0024] Figure 1 A schematic diagram showing the system architecture of a key transmission method in an embodiment of the present disclosure is shown;

[0025] Figure 2 A schematic diagram of a key transmission method in an embodiment of the present disclosure is shown;

[0026] Figure 3 A flow chart of a method for determining a shared key in an embodiment of the present disclosure is shown;

[0027] Figure 4 A flow chart of a method for sending a key in an embodiment of the present disclosure is shown;

[0028] Figure 5 A flow chart of a method for generating a base station key in an embodiment of the present disclosure is shown;

[0029] Figure 6 A flow chart of a key transmission method in an embodiment of the present disclosure is shown;

[0030] Figure 7 A flow chart of a method for encrypting a base station key in an embodiment of the present disclosure is shown;

[0031] Figure 8 A signaling diagram showing a key transmission method in an embodiment of the present disclosure;

[0032] Fig. 9 A schematic diagram of a key transmission device in an embodiment of the present disclosure is shown;

[0033] Fig.10 A schematic diagram of a key transmission device in an embodiment of the present disclosure is shown;

[0034] Fig.11 A structural block diagram of an electronic device in an embodiment of the present disclosure is shown. DETAILED DESCRIPTION

[0035] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in a variety of forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that the disclosure will be more comprehensive and complete and to fully convey the concepts of the example embodiments to those skilled in the art. The described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0036] In addition, the accompanying drawings are only schematic illustrations of the present disclosure and are not necessarily drawn to scale. The same reference numerals in the figures represent the same or similar parts, and their repeated description will be omitted. Some of the block diagrams shown in the accompanying drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities can be implemented in software form, or implemented in one or more hardware modules or integrated circuits, or implemented in different networks and / or processor devices and / or microcontroller devices.

[0037] For ease of understanding, before introducing the embodiments of the present disclosure, several terms involved in the embodiments of the present disclosure are first explained as follows:

[0038] Access and Mobility Management Function (AMF) network element: It is a functional entity of the 5G core network, responsible for handling access and mobility management tasks of user equipment (UE), such as registration management and connection management.

[0039] Access and Mobility Management Function Key (KAMF): It is the key used by the AMF functional entity to ensure the security of the access and mobility management process. The NAS Encryption Key (KNASenc) and the NAS Integrity Key (KNASint) can be directly derived from KAMF to independently ensure the security of the control plane signaling between the terminal and the core network AMF.

[0040] Access Stratum Security Mode Command (AS SMC): is a command used to manage and perform access layer security operations to ensure the security of user equipment (UE) when accessing the network.

[0041] Radio Resource Control Encryption Key (KRRCenc): protects the encryption of RRC layer (Radio Resource Control Layer) signaling.

[0042] Radio Resource Control Integrity Key (KRRCint): ensures the integrity of RRC layer signaling.

[0043] User Plane Encryption Key (KUPenc): used for encryption protection of user plane data.

[0044] User Plane Integrity Key (KUPint): ensures the integrity verification of user plane data.

[0045] Next Generation Application Protocol (NGAP): It is a protocol used for control plane signaling transmission in 5G systems. It defines various message types exchanged between the 5G core network and gNB (5G base station).

[0046] 5G base station key (Next Generation Node B Key, KgNB): It is a key key in the 5G network, used to generate various other keys to ensure the security and privacy of communications.

[0047] Subscription Concealed Identifier (SUCI): is an identifier used to hide user subscription information to ensure user privacy.

[0048] Non-Access Stratum (NAS): It is a protocol layer in the 5G system, responsible for processing non-access stratum signaling between UE and core network, such as registration, authentication and session management.

[0049] Non-Access Stratum Security Mode Command (NASSMC): Mainly used to start security-related operations at the NAS layer. When the network side (such as MME and other core network elements) sends NAS SMC to UE (user equipment), the purpose is to negotiate and activate the security mechanism of the NAS layer. This includes the activation of security functions such as encryption and integrity protection to ensure the security of NAS signaling interaction and prevent security threats such as signaling theft and tampering.

[0050] Authentication and Key Agreement (AKA): is a protocol used for authentication and key negotiation, ensuring the identity authentication and secure exchange of keys between the communicating parties.

[0051] Security Anchor Function Key (KSEAF): is a key used for the security anchor function to ensure secure communication between the UE and the core network.

[0052] Key Encryption Function (KEF): Mainly involves key management and encryption functions. In a network environment, it is responsible for encrypting specific keys. First of all, keys are key elements to ensure information security, such as symmetric keys used to encrypt communication content or asymmetric keys used for digital signatures. The role of KEF is to encrypt these keys, so that the security of the keys during storage or transmission is improved.

[0053] In the 5G network architecture, the terminal (User Equipment, UE) needs to complete the 5G AKA authentication process (5G Authentication and Key Agreement) when it first accesses the network. After the authentication is successful, the system derives multi-level security keys layer by layer based on the KSEAF key to build a hierarchical security mechanism to ensure the confidentiality and integrity of wireless air interface communications. Among them, the KgNB key is the core key in the 5G network. As the root key of the AS layer key, it is the basis for deriving other keys. Keys such as KUPint, KUPenc, KRRCint, and KRRCenc are all derived from the KgNB key.

[0054] For example, in the 6G satellite-ground fusion network, by deploying ground base stations (gNB) and core network functions (such as AMF, UPF) on non-ground nodes such as low-orbit satellites (LEO) or high-altitude platforms (HAPS), the signal transmission distance can be shortened, latency can be reduced, and coverage efficiency can be improved. However, its open wireless channel characteristics introduce significant security risks: the wide-area beam coverage of the downlink user link (User Link) and the feeder link (Feeder Link) can be easily intercepted and reversed by attackers; the sidelobe radiation of the ground station antenna in the uplink may cause sidelobe eavesdropping, threatening the security of key keys (such as the base station key KgNB). Once KgNB is attacked by a man-in-the-middle attack (MitM) or quantum computing brute force, its derived access layer subkeys (KRRCenc, KUPint, etc.) will become invalid, resulting in a complete collapse of air interface data confidentiality and integrity. It is worth noting that the above risks exist not only in satellite base stations, but also apply to non-ground base stations such as UAV base stations (UAV-BS) and stratospheric balloon base stations (Stratospheric Balloon-BS). This is mainly because non-ground base stations need to cover a wide area of ​​users through wireless links, making it difficult to achieve physical layer isolation.

[0055] In view of this, a key transmission method provided in an embodiment of the present disclosure is applied to a core network element. The method includes: generating a base station key in response to a terminal registration request message sent by a non-ground base station, wherein the terminal registration request message includes an identifier of the non-ground base station; determining a shared key between the non-ground base station and the core network element according to the identifier of the non-ground base station, wherein the shared key between the non-ground base station and the core network element is pre-configured in the core network element; encrypting the base station key according to the shared key to obtain the encrypted base station key, and sending the encrypted base station key to the non-ground base station. The present disclosure determines a shared key between the non-ground base station and the core network element pre-configured in the core network element according to the identifier of the non-ground base station, and then uses the shared key to encrypt the base station key, and finally sends the encrypted base station key to the non-ground base station. In this way, the base station key is encrypted by the shared key, and only the non-ground base station with the corresponding shared key can decrypt and obtain the base station key, thereby preventing the key from being stolen or tampered with during transmission, thereby ensuring the transmission security of the base station key.

[0056] The specific implementation of the embodiment of the present disclosure is described in detail below with reference to the accompanying drawings.

[0057] like Figure 1 As shown, the system architecture includes a terminal device 101 , a network 102 and a network side device 103 .

[0058] The network 102 is a medium for providing a communication link between the terminal device 101 and the network-side device 103 , and may be a wired network or a wireless network.

[0059] Optionally, the wireless network or wired network described above uses standard communication technology and / or protocol. The network is usually the Internet, but it can also be any network, including but not limited to a local area network (LAN), a metropolitan area network (MAN), a wide area network (WAN), a mobile, wired or wireless network, a dedicated network or any combination of a virtual private network). In some embodiments, the data exchanged through the network is represented by technologies and / or formats including Hyper Text Mark-up Language (HTML), Extensible Markup Language (XML), etc. In addition, conventional encryption technologies such as Secure Socket Layer (SSL), Transport Layer Security (TLS), Virtual Private Network (VPN), Internet Protocol Security (IPSec) can also be used to encrypt all or some links. In other embodiments, customized and / or dedicated data communication technologies can also be used to replace or supplement the above data communication technologies.

[0060] Optionally, the terminal device in the embodiment of the present disclosure may also be referred to as UE (User Equipment). In a specific implementation, the terminal device may be a mobile phone, a tablet computer (Tablet Personal Computer), a laptop computer (Laptop Computer), a personal digital assistant (Personal Digital Assistant, PDA), a mobile Internet device (Mobile Internet Device, MID), a wearable device (Wearable Device) or a vehicle-mounted device, etc. It should be noted that the specific type of the terminal device is not limited in the embodiment of the present disclosure, and the terminals in the present disclosure all have the ability to communicate with non-ground base stations.

[0061] The network side device may be a base station, a relay or an access point, etc. The base station may be a base station of 5G or later versions (e.g., 5G NR NB), or a base station in other communication systems (e.g., an eNB base station). It should be noted that the specific type of the network side device is not limited in the embodiments of the present disclosure.

[0062] Those skilled in the art will know that Figure 1The number of terminals, networks, and network-side devices in the example is only illustrative, and any number of terminals, networks, and network-side devices may be provided according to actual needs. The embodiments of the present disclosure are not limited to this.

[0063] Under the above system architecture, a key transmission method is provided in an embodiment of the present disclosure, and the method can be executed by any electronic device with computing and processing capabilities.

[0064] In some embodiments, the key transmission method provided in the embodiments of the present disclosure can be executed by a terminal device of the above-mentioned system architecture; in other embodiments, the key transmission method provided in the embodiments of the present disclosure can be executed by a server in the above-mentioned system architecture; in other embodiments, the key transmission method provided in the embodiments of the present disclosure can be implemented by the terminal device and the server in the above-mentioned system architecture through interaction.

[0065] Figure 2 A schematic diagram of a key transmission method provided by an embodiment of the present disclosure is shown, which is applied to a core network element. Figure 2 As shown, the key transmission method provided by the embodiment of the present disclosure includes the following steps:

[0066] S202: Generate a base station key in response to a terminal registration request message sent by a non-ground base station, where the terminal registration request message includes an identifier of the non-ground base station.

[0067] In this embodiment, the non-ground base station is different from the traditional ground base station. It may be located in the air (such as a drone base station, a satellite base station, and a stratospheric balloon base station, etc.) or other special non-ground locations to provide functions such as communication coverage. The terminal registration request message is a type of message in network communication, the purpose of which is to allow the receiver to verify the legitimacy of the terminal's identity and obtain terminal-related information in order to allocate resources for it, thereby allowing the terminal to legally use network services. The base station key (BS Key) is a root key dynamically generated by the core network security function (such as 5G AMF or 6G equivalent entity) in the mobile communication system, which is used to protect the air interface communication security between the terminal (UE) and the base station (such as 5G gNB, 6G non-ground base station). Base stations of different generations (such as 5G, 6G, etc.) can have their own specific base station key system to ensure communication security, device identity authentication and other functions. The base station key generation is usually triggered by a terminal registration request, and the request carries the non-ground base station unique identifier (such as gNBID, satellite orbit parameters, etc.) to ensure that the key is bound to a specific base station and session context. The base station key serves as the root key of the access layer security subkey, ensuring the confidentiality (encryption) and integrity (anti-tampering) of air interface data.

[0068] Specifically, the 5G base station key (KgNB, Next Generation Node B Key) is derived from the access and mobility management function key (KAMF) as the access layer (AS) root key, which is used to generate the encryption and integrity keys of the user plane (KUPenc / KUPint) and the RRC layer (KRRCenc / KRRCint). 6G base station key (such as KNTN, Non-Terrestrial NodeKey): Designed for non-terrestrial base stations (satellites, drones, etc.), enhanced mechanisms (such as quantum security algorithms, satellite-ground collaborative key negotiation) can be introduced to deal with the risks of eavesdropping and man-in-the-middle attacks under wide-area coverage.

[0069] S204, determining a shared key between the non-ground base station and a core network element according to the identifier of the non-ground base station, wherein the shared key between the non-ground base station and the core network element is pre-configured in the core network element.

[0070] In this embodiment, the core network element is a functional unit in the core network, such as the mobility management entity (MME) and the session management function (SMF), which is responsible for managing important functions such as user authentication, billing, and session management. The shared key is a key used for security-related operations such as encrypted communication and identity authentication between the non-terrestrial base station and the core network element.

[0071] In some embodiments, there are multiple possible implementations of the shared key between the non-ground base station and the core network element. For example, the non-ground base station and the core network element are determined through a key negotiation protocol. Specifically, the non-ground base station and the core network element exchange their respective relevant parameters (such as public keys, etc.) through a specific security protocol (such as the IKE protocol), and dynamically generate a shared key through a series of calculation steps. This method is more secure and can adapt to changes in the network environment.

[0072] In some embodiments, the shared key may be distributed by an authentication center. After the authentication center authenticates the non-terrestrial base station and the core network element, it generates and distributes the shared key for the two according to pre-stored rules and algorithms to ensure that only legitimate base stations and network elements can obtain the correct key for secure operation.

[0073] In some embodiments, since non-ground base stations are limited by power consumption and computing resources, it is difficult to achieve high-intensity information interaction. In order to further reduce the amount of authentication calculations during interaction between non-ground base stations and core network elements, the shared keys between the non-ground base stations and the core network elements can be pre-stored in the core network elements.

[0074] S206, encrypting the base station key according to the shared key to obtain the encrypted base station key, and sending the encrypted base station key to the non-ground base station.

[0075] In this embodiment, the base station key is encrypted using the shared key determined in step S204. For example, a symmetric encryption algorithm (such as AES) is used, the base station key is used as plain text, and the shared key is used as a key to perform encryption operations to obtain the encrypted base station key. It should be noted that in order to further deal with quantum attacks, the key length of the shared key provided in this embodiment can be greater than or equal to 256 bits, for example, a quantum secure symmetric encryption algorithm with a key length of 256 bits is used, such as AES-256. In addition, since the quantum key is based on the characteristics of quantum mechanics and has higher security, the shared key of this embodiment can also use a quantum key. The core network element and the non-ground base station obtain the quantum key as a shared key in the following ways: first, through the quantum key distribution network, the key information is transmitted using quantum states such as single photons; second, a true random key is generated by using a quantum random number generator; third, a key distribution technology based on quantum entanglement is used to allow particles in an entangled state to establish associations between different locations to generate and distribute keys. Since the base station key itself is very important, it is not safe to send it directly. After encryption, it is sent to the non-ground base station. At the receiving end, the non-ground base station uses the corresponding shared key to decrypt it to obtain the original base station key for subsequent secure communication and other operations.

[0076] In this embodiment, in response to the problem of plain text transmission of KgNB keys in the current terrestrial 5G standard, a KgNB key encryption transmission scheme is proposed. The base station key is encrypted by a shared key. Only non-ground base stations with the corresponding shared key can decrypt and obtain the base station key, preventing the key from being stolen or tampered with during transmission, thereby ensuring the security of key transmission between non-ground base stations such as satellites and the core network, providing security keys for the establishment of AS layer security, and ensuring the security of satellite communications.

[0077] In some embodiments, the core network network element includes an access and mobility management function AMF network element and a key encryption function KEF network element. Figure 3 A flow chart of a method for determining a shared key in an embodiment of the present disclosure is shown. Figure 3 As shown, the method for determining a shared key provided in an embodiment of the present disclosure includes the following steps:

[0078] S302, use the AMF network element to derive the AMF key to obtain the base station key. The AMF key is derived from the security anchor function key KSEAF stored in the AMF network element.

[0079] In this embodiment, the AMF network element is an access and mobility management function network element, which is responsible for access management and other functions in the 5G network. The AMF key is used as the root key for AMF-related security operations. The security anchor function key KSEAF is a key key stored in the AMF network element and is the basis for deriving other keys. Derivation refers to the generation of new keys (such as AMF keys and base station keys) from an initial key (such as the security anchor function key KSEAF) through a specific algorithm and process.

[0080] Specifically, the KSEAF is first stored in the AMF network element. Then, the AMF network element is used to perform a specific derivation algorithm operation on the KSEAF to obtain the AMF key. Finally, based on the obtained AMF key, the base station key is further obtained through the corresponding derivation mechanism. This process ensures that the key is gradually derived from the high-level security anchor key to the key suitable for the base station, ensuring the secure communication of all parts of the network.

[0081] S304, starting the base station key security protection process based on the AMF network element's response to obtaining the base station key.

[0082] In this embodiment, after obtaining the base station key, the AMF network element then starts the base station key security protection process. This process may include encrypting and storing the key, setting key usage permissions, starting the key update mechanism and other related operations to ensure the security of the base station key during the entire network operation process.

[0083] S306, according to the AMF network element's response to starting the base station key security protection process, the AMF network element is used to generate an encryption request message based on the base station key, and the encryption request message is sent to the KEF network element.

[0084] In this embodiment, the encryption request message includes the identifier of the non-ground base station and the base station key, and the KEF network element is used to determine the shared key between the non-ground base station and the core network element according to the encryption request message.

[0085] In some embodiments, the KEF network element is pre-configured with a shared key between the non-ground base station and the core network element, and the shared key between the non-ground base station and the core network element is determined according to the identification of the non-ground base station, including: searching in the KEF network element according to the identification of the non-ground base station to obtain the shared key between the non-ground base station and the core network element.

[0086] In this embodiment, a key system suitable for non-ground base station Internet (such as satellite Internet) is proposed. The system structure is simple, and the new network elements can be developed by the operator itself. The solution does not rely on equipment manufacturers, and the existing core network elements do not need to be changed. The relevant key presetting and encryption and decryption functions are completed in the newly added KEF network elements, which does not affect other core network element functions and current standard processes.

[0087] In some embodiments, Figure 4 A flow chart of a method for sending a key in an embodiment of the present disclosure is shown. Figure 4 As shown, the key sending method provided in the embodiment of the present disclosure includes the following steps:

[0088] S402: Use the KEF network element to encrypt the base station key according to the shared key to obtain the encrypted base station key.

[0089] S404, sending an encrypted response message to the AMF network element through KEF, where the encrypted response message includes the encrypted base station key.

[0090] S406, sending the encrypted base station key to the non-ground base station through the AMF network element.

[0091] In this embodiment, the AMF network element sends the key ciphertext to the non-ground base station through the INITIAL CONTEXT SETUP message of the NGAP process. Among them, the NITIAL CONTEXT SETUP message mainly appears in the relevant protocols of mobile network communications (such as 5G, etc.). When the user equipment (UE) wants to access the network, the network side (such as the base station, etc.) will send this message. It contains various information required to establish a communication context for the UE, such as resource information allocated by the network to the UE, including wireless resources (such as frequency bands, time slots and other related parameters), security-related configuration information (used to ensure communication security, such as encryption algorithms and other related settings). This message is a key part of the initial interaction between the network and the UE, which helps to establish a communication link between the two, so that subsequent data transmission, business interaction, etc. can proceed smoothly.

[0092] In this embodiment, by encrypting the transmission of the base station key, the operator can control the key distribution security on the N2 link. Regardless of whether the channel has IPSEC encryption or a dedicated encryption channel on the satellite, the base station key is sent in ciphertext, ensuring the security of the base station key and subsequent RRC signaling.

[0093] In some embodiments, the terminal registration request message also includes a terminal identifier. The core network element (such as AMF, SMF) interacts with the terminal on the control plane through the non-access layer (NAS) protocol and is responsible for implementing core functions such as registration management and session management. Figure 5 A flow chart of a method for generating a base station key in an embodiment of the present disclosure is shown. Figure 5 As shown, the method for generating a base station key provided in the embodiment of the present disclosure includes the following steps:

[0094] S502: Authenticate the terminal according to the terminal identifier in the terminal registration request message to obtain a terminal authentication result.

[0095] In this embodiment, the terminal registration request information is used to trigger the authentication process for the terminal. The terminal identifier is an identifier used to identify the terminal device. For example, SUCI (Subscription Hidden Identifier), which is a user hidden identifier in the 5G system to protect user privacy. 5G GUTI (5G Globally Unique Temporary Identifier) ​​is used to uniquely identify a user device in the 5G network. Terminal authentication is the process of verifying the legitimacy of the terminal device. By verifying information such as the terminal identifier, it is determined whether the terminal is a device that legally accesses the network.

[0096] Specifically, the terminal sends a registration request message, which contains the terminal identifier. After receiving the request, the AMF network element in the core network starts the authentication process according to the terminal identifier. The authentication system verifies the terminal identifier. Finally, the terminal authentication result is obtained to determine whether the terminal can legally access the network.

[0097] S504, in response to the terminal authentication result being successful, triggering a security establishment process of the non-access layer between the terminal and the core network element to obtain a security authentication result.

[0098] In this embodiment, the non-access layer NAS processes the control plane functions related to the core network, such as authentication, security, etc., and is located between the access network and the core network. The security mode control SMC process is a process used by the NAS layer to establish a security context and determine security parameters such as encryption and integrity protection.

[0099] Specifically, after the terminal is successfully authenticated, the NAS security establishment process is triggered. NAS sends a relevant request to the core network, including terminal information, etc. The AMF network element in the core network negotiates security parameters such as key generation based on the request.

[0100] S506: In response to the security authentication result being a successful security authentication, a base station key is generated.

[0101] Figure 6 A schematic diagram of a key transmission method provided by an embodiment of the present disclosure is shown, which is applied to a non-ground base station. Figure 6 As shown, the key transmission method provided by the embodiment of the present disclosure includes the following steps:

[0102] S602: Send a terminal registration request message to a core network element, where the terminal registration request message includes an identifier of the non-ground base station.

[0103] In some embodiments, before sending a terminal registration request message to a core network element, it also includes: receiving an initial registration request message sent by the terminal, the initial registration request message including the terminal identifier of the terminal; generating a terminal registration request message based on the terminal identifier and the identifier of a non-ground base station.

[0104] In this embodiment, a terminal first sends an initial registration request message, in which the terminal identifier is received by the non-ground base station. Then, the terminal registration request message is generated in combination with the non-ground base station identifier and then sent to the core network element. The combination of the two identifiers can better locate the terminal and the service, so as to facilitate the subsequent encryption and transmission of the basic key and enhance the network management efficiency.

[0105] S604: Receive the encrypted base station key sent by the core network element.

[0106] In this embodiment, the encrypted base station key is obtained by encrypting the base station key by the core network element according to the shared key, the shared key is determined according to the identifier of the non-ground base station, the shared key is a shared key pre-configured in the non-ground base station between the non-ground base station and the core network element, and the base station key is generated by the core network element in response to the terminal registration request message sent by the non-ground base station. The specific implementation process is not repeated here.

[0107] S606: Decrypt the encrypted base station key according to the shared key pre-configured in the non-ground base station and the core network element in the non-ground base station to obtain the base station key.

[0108] In this embodiment, a shared key is pre-configured between the non-ground base station and the core network element, and is used to encrypt and decrypt the key of the relevant data. The non-ground base station receives the encrypted base station key, and uses the pre-configured shared key with the non-ground base station and the core network element to decrypt the encrypted base station key through a decryption algorithm, and finally obtains the base station key.

[0109] In this embodiment, the base station key is encrypted by a shared key, and only a non-ground base station with the corresponding shared key can decrypt and obtain the base station key, preventing the key from being stolen or tampered with during transmission, thereby ensuring the transmission security of the base station key.

[0110] In some embodiments, the non-ground base station further includes a security module, in which a shared key between the non-ground base station and a core network element is pre-configured. Figure 7 A schematic diagram of a method for decrypting a base station key provided by an embodiment of the present disclosure is shown. Figure 7 As shown, the method for decrypting a base station key provided by an embodiment of the present disclosure includes the following steps:

[0111] S702: Send the encrypted base station key to the security module.

[0112] In this embodiment, for example, the satellite base station receives the ciphertext KgNB and then forwards it to the satellite security module.

[0113] S704, using the shared key between the non-ground base station and the core network element in the security module, decrypt the encrypted base station key to obtain the base station key.

[0114] In this embodiment, a shared key A between the security module and the core network is preset in the security module, and the encrypted base station key such as the ciphertext KgNB is decrypted using the key A to obtain the KgNB key plaintext.

[0115] In some embodiments, after decrypting the encrypted base station key to obtain the base station key, the method further includes: storing the base station key in a security module.

[0116] In this embodiment, the base station key is used to ensure the security of base station-related communications. The shared key is a key pre-set by the base station and the core network element for encryption and decryption. The security module is responsible for key-related operations to ensure security and reduce modifications to non-ground base stations.

[0117] In some embodiments, the security module is also used to execute an access layer security model command (AS Security Model Command, AS SMC) establishment process between the terminal and the non-ground base station, establish AS security, and derive an AS layer key based on the basic key.

[0118] Figure 8 A signaling diagram of a key transmission method provided by an embodiment of the present disclosure is shown. Figure 8 As shown, it includes a satellite terminal, a satellite, a gateway station and a core network. Among them, the satellite terminal includes a security module; the satellite includes an onboard base station and an onboard security module, and the onboard base station includes a non-access layer NAS; the core network includes AMF, KEF, AUSF (Authentication Server Function, authentication server function) and UDM (Unified Data Management, unified data management) / ARPF (Authentication Credential Repository and Processing Function, authentication credential storage and processing function), and the onboard security module of the satellite and the KEF network element of the core network are preset with a shared key A. The key transmission method provided in the embodiment of the present disclosure includes the following steps:

[0119] S1, the satellite terminal sends a registration request message carrying the terminal identifier (SUCI or 5G GUTI) to the satellite base station.

[0120] S2, the satellite base station forwards the non-access layer NAS registration request message to the gateway station, and adds the satellite base station identifier in the registration request message. The gateway station sends the registration request message to the core network AMF network element.

[0121] S3, the standard AKA authentication process is completed between the satellite terminal and the core network, in which the KAMF key derived from the KSEAF key is stored in the AMF network element.

[0122] S4, the NAS SMC process is initiated between the satellite terminal and the core network AMF network element to establish a NAS security context between the UE and AMF.

[0123] S5, the AMF network element derives the KgNB key based on KAMF and starts the KgNB protection process.

[0124] S6, the AMF network element sends an encryption request message to the KEF network element, carrying the KgNB key and the satellite base station identifier.

[0125] S7, the KEF network element retrieves the preset shared key according to the onboard base station identifier.

[0126] S8, the KEF network element uses the preset shared key to encrypt KgNB to obtain the ciphertext KgNB*.

[0127] S9, the KEF network element returns an encryption request response to the AMF, carrying the ciphertext KgNB*.

[0128] S10, AMF sends the key ciphertext to the satellite base station through the NGAP message.

[0129] S11, after receiving the ciphertext, the onboard base station forwards it to the onboard security module.

[0130] S12, the onboard security module uses the preset shared key to decrypt and obtain KgNB, and stores KgNB in ​​the onboard security module.

[0131] S13, then carry out the standard AS security establishment process.

[0132] Based on the same inventive concept, the present disclosure also provides a key transmission device in the following embodiments. Since the principle of solving the problem in the device embodiment is similar to that in the above method embodiment, the implementation of the device embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be repeated.

[0133] Fig. 9 FIG. 2 shows a schematic diagram of a key transmission device in an embodiment of the present disclosure, which is applied to a core network element. Fig. 9 As shown, the device includes: a first generating module 91, a first determining module 92 and an encryption module 93.

[0134] The first generation module 91 is used to generate a base station key in response to a terminal registration request message sent by a non-ground base station, wherein the terminal registration request message includes an identifier of the non-ground base station; the first determination module 92 is used to determine a shared key between the non-ground base station and the core network element according to the identifier of the non-ground base station, wherein the shared key between the non-ground base station and the core network element is pre-configured in the core network element; the encryption module 93 is used to encrypt the base station key according to the shared key to obtain the encrypted base station key, and send the encrypted base station key to the non-ground base station.

[0135] In some embodiments, the core network network element includes an access and mobility management function AMF network element and a key encryption function KEF network element, and the first generation module 91 is also used to: use the AMF network element to derive the AMF key to obtain a base station key, and the AMF key is derived from the security anchor function key KSEAF stored in the AMF network element; according to the AMF network element responding to obtaining the base station key, start the base station key security protection process; the determining the shared key between the non-ground base station and the core network network element according to the identifier of the non-ground base station includes: according to the AMF network element responding to starting the base station key security protection process, using the AMF network element to generate an encryption request message based on the base station key, the encryption request message includes the identifier of the non-ground base station and the base station key, and sending the encryption request message to the KEF network element; the KEF network element is used to determine the shared key between the non-ground base station and the core network network element according to the encryption request message.

[0136] In some embodiments, the KEF network element is pre-configured with a shared key between the non-ground base station and the core network element, and the first determination module 92 is used to: search in the KEF network element according to the identifier of the non-ground base station to obtain the shared key between the non-ground base station and the core network element.

[0137] In some embodiments, the encryption module 93 is used to: use the KEF network element to encrypt the base station key according to the shared key to obtain an encrypted base station key; send an encrypted response message to the AMF network element through the KEF, and the encrypted response message includes the encrypted base station key; send the encrypted base station key to the non-ground base station through the AMF network element.

[0138] In some embodiments, the terminal registration request message also includes a terminal identifier, and the first generation module 91 is further used to: authenticate the terminal according to the terminal identifier in the terminal registration request message to obtain a terminal authentication result; in response to the terminal authentication result being a successful terminal authentication, trigger a security establishment process between the terminal and the non-access layer of the core network element to obtain a security authentication result; in response to the security authentication result being a successful security authentication, generate a base station key.

[0139] Fig.10 FIG. 1 is a schematic diagram of a key transmission device in an embodiment of the present disclosure, which is applied to a non-ground base station. Fig.10 As shown, the device includes: a sending module 111, a receiving module 112 and a decryption module 113.

[0140] The sending module 111 is used to send a terminal registration request message to a core network network element, and the terminal registration request message includes the identifier of the non-ground base station; the receiving module 112 is used to receive the encrypted base station key sent by the core network network element, and the encrypted base station key is obtained by the core network network element encrypting the base station key according to a shared key, and the shared key is determined according to the identifier of the non-ground base station, and the shared key is a shared key pre-configured in the non-ground base station between the non-ground base station and the core network element, and the base station key is generated by the core network element in response to the terminal registration request message sent by the non-ground base station; the decryption module 113 is used to generate the shared key pre-configured in the non-ground base station between the non-ground base station and the core network element.

[0141] In some embodiments, the non-ground base station also includes a security module, which is pre-configured with a shared key between the non-ground base station and the core network element. The receiving module 112 is used to: send the encrypted base station key to the security module; the decryption module 113 is used to: use the shared key between the non-ground base station and the core network element in the security module to decrypt the encrypted base station key to obtain the base station key.

[0142] In some embodiments, the decryption module 113 is further used to: store the base station key in the security module.

[0143] In some embodiments, the receiving module 112 is further used to: receive an initial registration request message sent by a terminal, the initial registration request message including a terminal identifier of the terminal; and generate a terminal registration request message according to the terminal identifier and an identifier of the non-ground base station.

[0144] It should be noted that the examples and application scenarios implemented by the modules in the above-mentioned device embodiment are the same as those of the corresponding steps in the method embodiment, but are not limited to the contents disclosed in the above-mentioned method embodiment. It should be noted that the above-mentioned modules as part of the device can be executed in a computer system such as a set of computer executable instructions.

[0145] Those skilled in the art will appreciate that various aspects of the present disclosure may be specifically implemented in the following forms, namely: a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or an implementation that combines hardware and software aspects, which may be collectively referred to herein as a "circuit," "module," or "system."

[0146] Based on the same inventive concept, an electronic device is also provided in an embodiment of the present disclosure, the electronic device comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute any one of the above-mentioned key transmission methods by executing the executable instructions. Since the principle of solving the problem in the electronic device embodiment is similar to that in the above-mentioned method embodiment, the implementation of the electronic device embodiment can refer to the implementation of the above-mentioned method embodiment, and the repeated parts will not be repeated.

[0147] Refer to the following Fig.11 1100 according to this embodiment of the present disclosure is described. Fig.11 The electronic device 1100 shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.

[0148] like Fig.11 As shown, the electronic device 1100 is in the form of a general computing device. The components of the electronic device 1100 may include but are not limited to: at least one processing unit 1110, at least one storage unit 1120, and a bus 1130 connecting different system components (including the storage unit 1120 and the processing unit 1110).

[0149] Among them, the storage unit stores a program code, and the program code can be executed by the processing unit 1110, so that the processing unit 1110 executes the steps according to various exemplary embodiments of the present disclosure described in the above "Exemplary Method" section of this specification. For example, the processing unit 1110 can execute the following steps of the above method embodiment: in response to a terminal registration request message sent by a non-ground base station, a base station key is generated, and the terminal registration request message includes an identifier of the non-ground base station; a shared key between the non-ground base station and the core network element is determined according to the identifier of the non-ground base station, and the shared key between the non-ground base station and the core network element is pre-configured in the core network element; the base station key is encrypted according to the shared key to obtain the encrypted base station key, and the encrypted base station key is sent to the non-ground base station. The present disclosure determines the shared key between the non-ground base station and the core network element pre-configured in the core network element according to the identifier of the non-ground base station, and then uses the shared key to encrypt the base station key, and finally sends the encrypted base station key to the non-ground base station. In this way, the base station key is encrypted by the shared key to prevent the key from being stolen or tampered with during the transmission process, thereby ensuring the transmission security of the base station key.

[0150] The storage unit 1120 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 11201 and / or a cache storage unit 11202 , and may further include a read-only storage unit (ROM) 11203 .

[0151] The storage unit 1120 may also include a program / utility 11204 having a set (at least one) of program modules 11205, such program modules 11205 including but not limited to: an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment.

[0152] Bus 1130 may represent one or more of several types of bus structures, including a memory unit bus or memory unit controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus architectures.

[0153] The electronic device 1100 may also communicate with one or more external devices 1140 (e.g., keyboards, pointing devices, Bluetooth devices, etc.), may also communicate with one or more devices that enable a user to interact with the electronic device 1100, and / or communicate with any device that enables the electronic device 1100 to communicate with one or more other computing devices (e.g., routers, modems, etc.). Such communication may be performed via an input / output (I / O) interface 1150. Furthermore, the electronic device 1100 may also communicate with one or more networks (e.g., local area networks (LANs), wide area networks (WANs), and / or public networks, such as the Internet) via a network adapter 1160. As shown, the network adapter 1160 communicates with other modules of the electronic device 1100 via a bus 1130. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 1100, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0154] Through the description of the above implementation, it is easy for those skilled in the art to understand that the example implementation described here can be implemented by software, or by software combined with necessary hardware. Therefore, the technical solution according to the implementation of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the implementation of the present disclosure.

[0155] Based on the same inventive concept, the embodiment of the present disclosure also provides a computer-readable storage medium on which a computer program is stored, and when the computer program is executed by a processor, any of the above-mentioned key transmission methods is implemented. Since the principle of solving the problem in the embodiment of the computer-readable storage medium is similar to that in the above-mentioned method embodiment, the implementation of the embodiment of the computer-readable storage medium can refer to the implementation of the above-mentioned method embodiment, and the repeated parts will not be repeated.

[0156] More specific examples of computer-readable storage media in the present disclosure may include, but are not limited to, an electrical connection having one or more conductors, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0157] In the present disclosure, a computer readable storage medium may include a data signal propagated in baseband or as part of a carrier wave, wherein a readable program code is carried. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A readable signal medium may also be any readable medium other than a readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0158] Alternatively, the program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination of the foregoing.

[0159] In a specific implementation, the program code for performing the operations of the present disclosure may be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java, C++, etc., and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, as a separate software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., using an Internet service provider to connect through the Internet).

[0160] Based on the same inventive concept, a computer program product is also provided in the embodiments of the present disclosure, including a computer program product, including: a computer program or an instruction, wherein when the computer program or the instruction is executed by a processor, the key transmission method of any one of the above method embodiments is implemented. Since the principle of solving the problem in the computer program product embodiment is similar to that in the above method embodiment, the implementation of the computer program product embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be repeated.

[0161] It should be noted that, although several modules or units of the device for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. On the contrary, the features and functions of one module or unit described above can be further divided into multiple modules or units to be embodied.

[0162] In addition, although the steps of the method in the present disclosure are described in a specific order in the drawings, this does not require or imply that the steps must be performed in this specific order, or that all the steps shown must be performed to achieve the desired results. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step, and / or one step may be decomposed into multiple steps, etc.

[0163] Through the description of the above implementation, it is easy for those skilled in the art to understand that the example implementation described here can be implemented by software, or by software combined with necessary hardware. Therefore, the technical solution according to the implementation of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the method according to the implementation of the present disclosure.

[0164] Those skilled in the art will readily appreciate other embodiments of the present disclosure after considering the specification and practicing the invention disclosed herein. The present disclosure is intended to cover any variations, uses or adaptations of the present disclosure, which follow the general principles of the present disclosure and include common knowledge or customary techniques in the art that are not disclosed in the present disclosure. The description and examples are intended to be exemplary only, and the true scope and spirit of the present disclosure are indicated by the appended claims.

Claims

1. A key transmission method, characterized in that: Applied to a core network element, the method comprises: generating a base station key in response to a terminal registration request message sent by a non-ground base station, wherein the terminal registration request message includes an identifier of the non-ground base station; Determining a shared key between the non-ground base station and the core network element according to the identifier of the non-ground base station, wherein the shared key between the non-ground base station and the core network element is pre-configured in the core network element; The base station key is encrypted according to the shared key to obtain an encrypted base station key, and the encrypted base station key is sent to the non-ground base station.

2. The key transmission method according to claim 1, characterized in that: The core network element includes an access and mobility management function AMF network element and a key encryption function KEF network element, and before generating the base station key, further includes: deriving an AMF key using the AMF network element to obtain a base station key, wherein the AMF key is derived from a security anchor function key KSEAF stored in the AMF network element; Initiate the base station key security protection process according to the AMF network element in response to obtaining the base station key; The determining, according to the identifier of the non-ground base station, a shared key between the non-ground base station and the core network element includes: According to the AMF network element, in response to starting the base station key security protection process, the AMF network element is used to generate an encryption request message based on the base station key, wherein the encryption request message includes the identifier of the non-ground base station and the base station key, and the encryption request message is sent to the KEF network element; the KEF network element is used to determine the shared key between the non-ground base station and the core network element according to the encryption request message.

3. The key transmission method according to claim 2, characterized in that: The KEF network element is pre-configured with a shared key between the non-ground base station and the core network element, and the determining the shared key between the non-ground base station and the core network element according to the identifier of the non-ground base station includes: The KEF network element is searched according to the identifier of the non-ground base station to obtain a shared key between the non-ground base station and the core network element.

4. The key transmission method according to claim 3, characterized in that: The step of encrypting the base station key according to the shared key to obtain the encrypted base station key, and sending the encrypted base station key to the non-ground base station includes: Encrypting the base station key using the KEF network element according to the shared key to obtain an encrypted base station key; Sending an encrypted response message to the AMF network element through the KEF, wherein the encrypted response message includes the encrypted base station key; The encrypted base station key is sent to the non-ground base station through the AMF network element.

5. The key transmission method according to claim 1, characterized in that: The terminal registration request message also includes a terminal identifier. Before generating a base station key, the method further includes: Authenticate the terminal according to the terminal identifier in the terminal registration request message to obtain a terminal authentication result; In response to the terminal authentication result being that the terminal authentication is successful, triggering a security establishment process of the non-access layer between the terminal and the core network element to obtain a security authentication result; In response to the security authentication result being that the security authentication is successful, a base station key is generated.

6. A key transmission method, characterized in that: Applied to a non-ground base station, the method comprises: Sending a terminal registration request message to a core network element, wherein the terminal registration request message includes an identifier of the non-terrestrial base station; receiving an encrypted base station key sent by a core network network element, wherein the encrypted base station key is obtained by the core network network element encrypting the base station key according to a shared key, wherein the shared key is determined according to an identifier of the non-ground base station, wherein the shared key is a shared key pre-configured in the non-ground base station between the non-ground base station and the core network network element, and wherein the base station key is generated by the core network network element in response to a terminal registration request message sent by the non-ground base station; The encrypted base station key is decrypted according to the shared key pre-configured in the non-ground base station and the core network element to obtain the base station key.

7. The key transmission method according to claim 6, characterized in that: The non-ground base station further includes a security module, in which a shared key between the non-ground base station and the core network element is pre-configured, and the decrypting the encrypted base station key to obtain the base station key includes: Sending the encrypted base station key to the security module; The encrypted base station key is decrypted using the shared key between the non-ground base station and the core network element in the security module to obtain the base station key.

8. The key transmission method according to claim 7, characterized in that: After decrypting the encrypted base station key to obtain the base station key, the method further includes: The base station key is stored in the security module.

9. The key transmission method according to claim 6, characterized in that: Before sending the terminal registration request message to the core network element, the method further includes: Receiving an initial registration request message sent by a terminal, wherein the initial registration request message includes a terminal identifier of the terminal; A terminal registration request message is generated according to the terminal identifier and the identifier of the non-ground base station.

10. A key transmission device, characterized in that: Applied to a core network element, the device comprises: A first generating module, configured to generate a base station key in response to a terminal registration request message sent by a non-ground base station, wherein the terminal registration request message includes an identifier of the non-ground base station; A first determination module is used to determine a shared key between the non-ground base station and the core network element according to an identifier of the non-ground base station, wherein the shared key between the non-ground base station and the core network element is pre-configured in the core network element; The encryption module is used to encrypt the base station key according to the shared key to obtain the encrypted base station key, and send the encrypted base station key to the non-ground base station.

11. A key transmission device, characterized in that: Applied to a non-ground base station, the device comprises: A sending module, configured to send a terminal registration request message to a core network element, wherein the terminal registration request message includes an identifier of the non-ground base station; a receiving module, configured to receive an encrypted base station key sent by the core network network element, wherein the encrypted base station key is obtained by the core network network element encrypting the base station key according to a shared key, wherein the shared key is determined according to an identifier of the non-ground base station, wherein the shared key is a shared key pre-configured in the non-ground base station between the non-ground base station and the core network network element, and wherein the base station key is generated by the core network network element in response to a terminal registration request message sent by the non-ground base station; A decryption module is used to decrypt the shared key between the non-ground base station and the core network element according to the pre-configured shared key in the non-ground base station.

12. An electronic device, characterized in that: include: processor; as well as A memory, configured to store executable instructions of the processor; The processor is configured to execute the key transmission method according to any one of claims 1 to 9 by executing the executable instructions.

13. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the key transmission method according to any one of claims 1 to 9 is implemented.

14. A computer program product comprising: A computer program or instruction, characterized in that when the computer program or instruction is executed by a processor, it implements the key transmission method described in any one of claims 1 to 9.