Communication method and device, communication equipment and storage medium

By using quantum key encryption and message authentication code in 5G networks, communication security issues when links between satellites and core networks are not available are solved, and authenticity judgment of user equipment request messages and DOS attack protection are realized.

CN120128915APending Publication Date: 2025-06-10CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510306356.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-14
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

In 5G networks, when the feeder link between the satellite and the core network is unavailable, there may be security problems with the storage and forwarding operations using satellites, such as the inability to judge the authenticity of the request message of the user equipment and is vulnerable to DOS attacks.

Method used

By receiving encrypted messages sent by the user equipment, the availability of storage and forwarding operations is determined, and when available, the encrypted messages are sent to the core network to improve communication security. The specific steps include the user equipment encrypting the request message based on the quantum key, generating a first message, and sending the message to the satellite. After the satellite is received, it determines the operation availability and sends an encrypted message to the core network when it is available.

Benefits of technology

Through quantum key encryption and the use of message authentication code, the security of request messages is improved, DOS attacks are prevented, and communications are ensured when the link between the satellite and the core network is unavailable.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128915A_ABST
    Figure CN120128915A_ABST
Patent Text Reader

Abstract

The invention relates to a communication method and device, communication equipment and a storage medium, and relates to the technical field of communication. The method comprises the following steps: receiving a first message sent by user equipment; wherein the first message is generated by the user equipment based on the first encrypted message, the request message and the first quantum key; the first encrypted message is obtained by encrypting the request message based on the first quantum key. Determining Samp based on the first message; f operation is available. And sending a second message to the core network based on the first encrypted message in the first message when the operation availability condition is available. According to the application, the request message is encrypted based on the first quantum key, the security of the request message is improved, and after the satellite receives the first message, the Samp can be judged according to the first message; the operation availability condition of the F operation is based on Samp; and sending the second message to the core network according to the F operation and the first encrypted message in the first message, thereby further improving the communication security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of mobile communication technologies, and in particular, to a communication method, apparatus, communication device, and storage medium. Background Art

[0002] In the research of 5G non-terrestrial network communication by 3GPP (3rd Generation Partnership Project), it is found that the connection between a user equipment (UE) and a satellite and a terrestrial network may be intermittent. Therefore, it is proposed that the 5G network can use the S&F (Store and Forward Satellite Operation) operation of the satellite, that is, the satellite store and forward operation.

[0003] However, when the feeder link between the satellite and the core network is unavailable, there may be security problems in using the S&F operation of the satellite. For example, when the feeder link is unavailable, the terminal and the satellite (specifically, the base station on the satellite side) / core network cannot establish a security context. If the S&F operation is used, the satellite / core network cannot determine the authenticity of the request message of the user equipment and is vulnerable to DOS (Denial of Service) attacks. Summary of the Invention

[0004] Based on this, it is necessary to provide a communication method, apparatus, communication device, and storage medium that can improve communication security for the above technical problems.

[0005] In a first aspect, the present application provides a communication method applied to a satellite, including:

[0006] Receiving a first message sent by a user equipment; wherein, the first message is generated by the user equipment based on a first encrypted message, a request message, and a first quantum key; the first encrypted message is obtained by encrypting the request message based on the first quantum key;

[0007] Determining the availability of the S&F operation based on the first message;

[0008] When the operation availability is available, sending a second message to the core network based on the first encrypted message in the first message.

[0009] In one embodiment, the first encrypted message is generated by the user equipment performing HMAC processing on the request message based on the first quantum key to obtain a first message authentication code, and based on the first encrypted message, the first message authentication code, and the first key identifier of the first quantum key.

[0010] In one embodiment, determining the availability of the S&F operation based on the first message includes:

[0011] Based on the first message, obtaining a first key identifier, a first encrypted message, and a first message authentication code;

[0012] Based on the first key identifier, obtaining a first quantum key;

[0013] Based on the first quantum key, the first encrypted message, and the first message authentication code, determining the availability of the S&F operation.

[0014] In one embodiment, determining the availability of the S&F operation based on the first quantum key, the first encrypted message, and the first message authentication code includes:

[0015] Performing a decryption process on the first encrypted message based on the first quantum key to obtain a first decrypted message;

[0016] Performing an HMAC process on the first decrypted message based on the first quantum key to obtain a second message authentication code;

[0017] Based on the first message authentication code and the second message authentication code, determining the availability of the S&F operation.

[0018] In one embodiment, determining the availability of the store-and-forward (S&F) function operation based on the first message includes:

[0019] Determining the availability of the feeder line between the satellite and the core network;

[0020] In the case where the availability of the feeder line is unavailable, determining the availability of the S&F operation based on the first message.

[0021] In one embodiment, sending a second message to the core network based on the first encrypted message in the first message includes:

[0022] In the case where the availability of the feeder line becomes available, sending a second message to the core network based on the first encrypted message in the first message.

[0023] In one embodiment, the method further includes:

[0024] Receiving an initial registration request sent by a user equipment; wherein, a first key identifier of the first quantum key is carried in the initial registration request;

[0025] Send a terminal authentication request carrying a first key identifier to the core network based on an initial registration request; wherein, the terminal authentication request is used to instruct the core network to obtain a first quantum key based on the first key identifier and feedback a terminal authentication request response message carrying the first quantum key and the first key identifier to the satellite;

[0026] Store the first quantum key and the first key identifier, and perform encryption processing on the terminal authentication request response message based on a third quantum key to obtain a third encrypted message;

[0027] Send the third encrypted message to the user equipment; wherein, the third encrypted message carries a third key identifier of the third quantum key; the third encrypted message is used to instruct the user equipment to perform a terminal authentication operation based on the third encrypted message and the third key identifier.

[0028] In one embodiment, the third encrypted message is specifically used to instruct the user equipment to send a fourth encrypted message to the satellite; wherein, the fourth encrypted message is obtained by the user equipment encrypting the terminal authentication response message based on a fourth quantum key; the fourth encrypted message carries a third message authentication code and a fourth key identifier of the fourth quantum key; the third message authentication code is obtained by the user equipment performing HMAC processing on the terminal authentication response message based on the fourth quantum key; the terminal authentication response message is generated by the user equipment obtaining the third quantum key based on the third key identifier, decrypting the terminal authentication request response message based on the third quantum key, and according to the decryption result.

[0029] In one embodiment, the method further includes:

[0030] Receive the fourth encrypted message, and obtain the fourth quantum key based on the fourth key identifier carried in the fourth encrypted message;

[0031] Perform decryption processing on the fourth encrypted message based on the fourth quantum key to obtain a second decrypted message;

[0032] Perform HMAC processing on the second decrypted message based on the fourth quantum key to obtain a fourth message authentication code;

[0033] Determine the authenticity of the message based on the fourth message authentication code and the third message authentication code carried in the fourth encrypted message;

[0034] When the authenticity of the message is true, determine that the second decrypted message is the terminal authentication response message, and send the terminal authentication response message to the core network.

[0035] In a second aspect, the present application provides another communication method, which is applied to a user equipment and includes:

[0036] In a case where there is a need to send a request message to the core network, encrypt the request message based on the first quantum key to obtain a first encrypted message;

[0037] Generate a first message based on the first encrypted message, the request message, and the first quantum key;

[0038] Send the first message to the satellite; wherein, the first message is used to instruct the satellite to determine the availability of the S&F operation, and in the case where the availability of the operation is available, based on the first encrypted message in the first message, send a second message to the core network.

[0039] In one embodiment, generating a first message based on the first encrypted message, the request message, and the first quantum key includes:

[0040] Perform HMAC processing on the request message based on the first quantum key to obtain a first message authentication code;

[0041] Generate a first message based on the first encrypted message, the first message authentication code, and the first key identifier of the first quantum key.

[0042] In one embodiment, the method further includes:

[0043] Receive the S&F operation service response message sent by the satellite; wherein, the S&F operation service response message is obtained by the satellite determining the service result based on the availability of the S&F operation and encrypting the service result based on the second quantum key; the S&F operation service response message also carries the second key identifier of the second quantum key;

[0044] Obtain the second quantum key based on the second key identifier;

[0045] Decrypt the S&F operation service response message based on the second quantum key to obtain the service result.

[0046] In one embodiment, before encrypting the request message based on the first quantum key to obtain a first encrypted message in response to sending a request for the request message, the method further includes:

[0047] Send an initial registration request carrying the first key identifier of the first quantum key to the satellite, so that the satellite sends a terminal authentication request carrying at least the first key identifier to the core network based on the initial registration request; wherein, the terminal authentication request is used to instruct the core network to obtain the first quantum key based on the first key identifier and feedback a terminal authentication request response message carrying the first quantum key and the first key identifier to the satellite; the terminal authentication request response message is used to instruct the satellite to store the first quantum key and the first key identifier and encrypt the terminal authentication request response message based on the third quantum key to obtain a third encrypted message;

[0048] Receive a third encrypted message sent by a satellite; wherein, the third encrypted message carries at least a third key identifier of a third quantum key;

[0049] Perform a terminal authentication operation based on the third encrypted message and the third key identifier.

[0050] In one embodiment, performing a terminal authentication operation based on the third encrypted message and the third key identifier includes:

[0051] Obtain a third quantum key based on the third key identifier;

[0052] Decrypt a terminal authentication request response message based on the third quantum key, and generate a terminal authentication response message according to the decryption result;

[0053] Encrypt the terminal authentication response message based on a fourth quantum key to obtain a fourth encrypted message;

[0054] Perform HMAC processing on the terminal authentication response message based on the fourth quantum key to obtain a third message authentication code;

[0055] Send a fourth encrypted message carrying the third message authentication code and the key identifier of the fourth quantum key to the satellite; wherein, the fourth encrypted message is used to instruct the satellite to determine the authenticity of the message based on the fourth encrypted message, and in the case where the authenticity of the message is true, send a terminal authentication response message to the core network.

[0056] In a third aspect, the present application provides a communication device configured in a satellite, and the device includes:

[0057] A first receiving module, configured to receive a first message sent by a user equipment; wherein, the first message is generated by the user equipment based on a first encrypted message, a request message, and a first quantum key; the first encrypted message is obtained by encrypting the request message based on the first quantum key;

[0058] A first determining module, configured to determine the availability of S&F operations based on the first message;

[0059] A first sending module, configured to, in the case where the operation availability is available, send a second message to the core network based on the first encrypted message in the first message.

[0060] In a fourth aspect, the present application provides a communication device configured in a user equipment, and the device includes:

[0061] An encryption module, configured to, in the case of having a need to send a request message to the core network, encrypt the request message based on a first quantum key to obtain a first encrypted message;

[0062] A generation module, configured to generate a first message based on a first encrypted message, a request message, and a first quantum key;

[0063] A second sending module, configured to send the first message to a satellite; wherein, the first message is used to instruct the satellite to determine the availability of an S&F operation, and when the availability of the operation is available, based on the first encrypted message in the first message, send a second message to a core network.

[0064] In a fifth aspect, the present application further provides a communication device, including a memory, a transceiver, and a processor. The memory stores a computer program. The transceiver is configured to receive or send data under the control of the processor. When the processor executes the computer program, the following method is implemented:

[0065] Receive a first message sent by a user equipment; wherein, the first message is generated by the user equipment based on a first encrypted message, a request message, and a first quantum key; the first encrypted message is obtained by encrypting the request message based on the first quantum key;

[0066] Based on the first message, determine the availability of an S&F operation;

[0067] When the availability of the operation is available, based on the first encrypted message in the first message, send a second message to a core network.

[0068] In a sixth aspect, the present application further provides another communication device, including a memory, a transceiver, and a processor. The memory stores a computer program. The transceiver is configured to receive or send data under the control of the processor. When the processor executes the computer program, the following method is implemented:

[0069] When there is a need to send a request message to a core network, encrypt the request message based on a first quantum key to obtain a first encrypted message;

[0070] Based on the first encrypted message, the request message, and the first quantum key, generate a first message;

[0071] Send the first message to a satellite; wherein, the first message is used to instruct the satellite to determine the availability of an S&F operation, and when the availability of the operation is available, based on the first encrypted message in the first message, send a second message to a core network.

[0072] In a seventh aspect, the present application further provides a computer-readable storage medium, storing a computer program thereon. When the computer program is executed by a processor, the following method is implemented:

[0073] Receive a first message sent by a user device; wherein, the first message is generated by the user device based on a first encrypted message, a request message, and a first quantum key; the first encrypted message is obtained by encrypting the request message based on the first quantum key;

[0074] Based on the first message, determine the availability of the S&F operation;

[0075] When the operation availability is available, send a second message to the core network based on the first encrypted message in the first message.

[0076] In an eighth aspect, the present application further provides another computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the following method is implemented:

[0077] In the case of having a need to send a request message to the core network, encrypt the request message based on the first quantum key to obtain a first encrypted message;

[0078] Generate a first message based on the first encrypted message, the request message, and the first quantum key;

[0079] Send the first message to a satellite; wherein, the first message is used to instruct the satellite to determine the availability of the S&F operation, and when the operation availability is available, send a second message to the core network based on the first encrypted message in the first message.

[0080] In a ninth aspect, the present application further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the following method is implemented:

[0081] Receive a first message sent by a user device; wherein, the first message is generated by the user device based on a first encrypted message, a request message, and a first quantum key; the first encrypted message is obtained by encrypting the request message based on the first quantum key;

[0082] Based on the first message, determine the availability of the S&F operation;

[0083] When the operation availability is available, send a second message to the core network based on the first encrypted message in the first message.

[0084] In a tenth aspect, the present application further provides another computer program product, including a computer program, and when the computer program is executed by a processor, the following method is implemented:

[0085] In the case of having a need to send a request message to the core network, encrypt the request message based on the first quantum key to obtain a first encrypted message;

[0086] Generate a first message based on the first encrypted message, the request message, and the first quantum key;

[0087] Send the first message to the satellite; wherein, the first message is used to instruct the satellite to determine the availability of the S&F operation, and when the availability of the operation is available, based on the first encrypted message in the first message, send a second message to the core network.

[0088] The above communication method, device, communication equipment, and storage medium receive the first message sent by the user equipment; wherein, the first message is generated by the user equipment based on the first encrypted message, the request message, and the first quantum key; the first encrypted message is obtained by encrypting the request message based on the first quantum key. Determine the availability of the S&F operation based on the first message. When the availability of the operation is available, send a second message to the core network based on the first encrypted message in the first message. This application encrypts the request message based on the first quantum key, improving the security of the request message. After receiving the first message, the satellite can also determine the availability of the S&F operation according to the first message. Only when the first message meets the requirements, the availability of the operation is available. Then, based on the S&F operation and the first encrypted message in the first message, send a second message to the core network, further improving the security of communication. Description of the Drawings

[0089] Figure 1 It is an application environment diagram of a communication method provided in this embodiment;

[0090] Figure 2 It is a flowchart of the first communication method provided in this embodiment;

[0091] Figure 3 It is a flowchart of determining the availability of the S&F operation provided in this embodiment;

[0092] Figure 4 It is a flowchart of sending a third encrypted message to the user equipment provided in this embodiment;

[0093] Figure 5 It is a flowchart of the second communication method provided in this embodiment;

[0094] Figure 6 It is a flowchart of obtaining a service result provided in this embodiment;

[0095] Figure 7 It is a flowchart of terminal registration authentication provided in this embodiment;

[0096] Figure 8 It is a signaling interaction diagram of terminal authentication registration provided in this embodiment;

[0097] Figure 9 The signaling interaction diagram during message transmission among the terminal, satellite, and core network provided in this embodiment;

[0098] Figure 10 The structural block diagram of the first communication device provided in this embodiment;

[0099] Figure 11 The structural block diagram of the second communication device provided in this embodiment;

[0100] Figure 12 The internal structure diagram of the communication device provided in this embodiment. Detailed implementation manners

[0101] In order to make the objectives, technical solutions, and advantages of this application clearer and more understandable, the following further elaborates on this application in combination with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not used to limit this application.

[0102] The communication method provided in the embodiments of this application can be applied to Figure 1 the application environment shown.

[0103] Among them, when the user equipment has a need to send a request message to the core network, the user equipment encrypts the request message based on the first quantum key to obtain a first encrypted message; and generates a first message based on the first encrypted message, the request message, and the first quantum key. The satellite receives the first message sent by the user equipment. Then, based on the first message, it determines the available situation of the S&F operation; and when the available situation is available, it sends a second message to the core network based on the first encrypted message in the first message.

[0104] Among them, the satellite refers to an artificial satellite, mainly including but not limited to communication, navigation, meteorological observation, earth observation, scientific research, etc. The satellite in this application mainly refers to an artificial satellite with communication functions, which can play a role in relaying communication between the user equipment and the core network.

[0105] The user equipment refers to the terminal equipment on the user side, including but not limited to intelligent terminals such as mobile phones and computers, and can also be intelligent wearable devices such as intelligent bracelets and intelligent watches.

[0106] The core network refers to the core part of a mobile communication network responsible for processing user data and signaling. It is a bridge connecting user equipment and external networks, providing various services such as voice calls, text messages, data transmission, Internet access, etc. The core network is the heart of a mobile communication network, responsible for managing and controlling the communication process of the entire network; the core network of this application can be the 5G core network of the fifth-generation mobile communication technology (i.e., 5GC (5G Core, 5G core network)).

[0107] In an alternative embodiment, as Figure 2 shown, a communication method is provided that can be applied to Figure 1 the satellite shown. In this embodiment, the method includes the following steps:

[0108] S201, receive a first message sent by a user equipment.

[0109] Among them, the first message is generated by the user equipment based on a first encrypted message, a request message, and a first quantum key; the first encrypted message is obtained by encrypting the request message based on the first quantum key. The user equipment refers to the terminal equipment on the user side, including but not limited to intelligent terminals such as mobile phones and computers, and can also be intelligent wearable devices such as intelligent bracelets and intelligent watches. The request message refers to the communication message that the user equipment needs to send to the core network.

[0110] Optionally, in this embodiment, the user equipment needs to obtain the first quantum key in advance. Specifically, the user equipment can obtain or pre-inject quantum keys in real time through a QKD (Quantum Key Distribution) network; at least the first quantum key is included.

[0111] Optionally, an alternative implementation manner for the user equipment to generate the first message in this embodiment is to perform HMAC processing on the request message based on the first quantum key to obtain a first message authentication code. Based on the first encrypted message, the first message authentication code, and the first key identifier of the first quantum key, generate the first message. Among them, the HMAC processing refers to the process of using the HMAC (Hash-based Message Authentication Code) algorithm to process the request message to obtain the first message authentication code. An alternative implementation manner for generating the first message based on the first encrypted message, the first message authentication code, and the first key identifier of the first quantum key in this embodiment is to add the first message authentication code and the first key identifier of the first quantum key to the first encrypted message to obtain the first message. Another alternative implementation manner for generating the first message based on the first encrypted message, the first message authentication code, and the first key identifier of the first quantum key in this embodiment is to add the first message authentication code and the first key identifier of the first quantum key to the first encrypted message to obtain the first message.

[0112] S202. Determine the operation availability of the S&F operation based on the first message.

[0113] Among them, the S&F (Store and Forward Satellite Operation) operation refers to the operation of performing the store and forward function of the satellite.

[0114] As an alternative implementation manner of the present application, based on the first message, determine the message authenticity of the first message; according to the message authenticity, determine the operation availability of the S&F operation. For example, when the message authenticity is true, determine that the operation availability of the S&F operation is operationally available.

[0115] As another alternative implementation manner of the present application, based on the first message, obtain the service subscription information of the user equipment. When the user equipment subscribes to the service related to the S&F operation, determine that the operation availability of the S&F operation is operationally available.

[0116] As yet another alternative implementation manner of the present application, determine the feeder line availability of the feeder line between the satellite and the core network. When the feeder line availability is unavailable, based on the first message, determine the operation availability of the S&F operation. That is to say, the present application is mainly applicable to the case where the feeder line availability of the feeder line between the satellite and the core network is unavailable. Because when the feeder line availability is available, the core network can establish a security context with the user equipment. In this case, even if communication is carried out through the satellite, DOS attacks can be effectively avoided. Therefore, the present application is mainly applied to the case where the feeder line availability is unavailable.

[0117] S203. When the operation availability is available, send a second message to the core network based on the first encrypted message in the first message.

[0118] As an alternative implementation manner of the present application, when the operation availability is available, use the first encrypted message in the first message as the second message; send the second message to the core network. Among them, the second message also carries the first key identifier of the first quantum key, so that the core network can obtain the first quantum key based on the first key identifier, and then decrypt the first encrypted message to obtain the request message.

[0119] As another alternative embodiment of the present application, when the operation availability is available, the first encrypted message in the first message is decrypted based on the first quantum key to obtain a request message, and the request message is used as the second message and sent to the core network. It should be noted that the satellite can also perform conventional processing on the request message (for example, format conversion, signal amplification, etc.), and then use the processed request message as the second message and send the second message to the core network.

[0120] Based on the above embodiments, another alternative embodiment of the present application is that when the feeder line availability becomes available, a second message is sent to the core network based on the first encrypted message in the first message. Since the S&F operation of the satellite is mainly performed when the feeder line is unavailable, only when the feeder line becomes available can a second message be sent to the core network.

[0121] The above communication method includes receiving a first message sent by a user equipment; wherein, the first message is generated by the user equipment based on a first encrypted message, a request message, and a first quantum key; the first encrypted message is obtained by encrypting the request message based on the first quantum key. Based on the first message, the operation availability of the S&F operation is determined. When the operation availability is available, a second message is sent to the core network based on the first encrypted message in the first message. The present application encrypts the request message based on the first quantum key, improving the security of the request message. After the satellite receives the first message, it can also determine the operation availability of the S&F operation according to the first message. Only when the first message meets the requirements, the operation availability is available. Then, based on the S&F operation and the first encrypted message in the first message, a second message is sent to the core network, further improving the security of communication.

[0122] Based on the above embodiments, in order to further improve the communication security and the accuracy of the determined operation availability of the S&F operation, as Figure 3 shown, an alternative embodiment of S202 includes:

[0123] S301, obtaining a first key identifier, a first encrypted message, and a first message authentication code based on the first message.

[0124] Optionally, in this embodiment, the first message is parsed to obtain a first key identifier, a first encrypted message, and a first message authentication code.

[0125] S302, obtaining a first quantum key based on the first key identifier.

[0126] Optionally, in this embodiment, a first quantum key is obtained from candidate quantum keys stored locally based on a first key identifier; each candidate quantum key has a corresponding key identifier. It should be noted that the candidate quantum keys are synchronized from the core network to the satellite.

[0127] S303. Determine the operation availability of the S&F operation based on the first quantum key, the first encrypted message, and the first message authentication code.

[0128] Optionally, in this embodiment, the first encrypted message is decrypted based on the first quantum key to obtain a first decrypted message. The first decrypted message is subjected to HMAC processing based on the first quantum key to obtain a second message authentication code. The operation availability of the S&F operation is determined based on the first message authentication code and the second message authentication code. An optional implementation manner of determining the operation availability of the S&F operation based on the first message authentication code and the second message authentication code in this embodiment is to determine the message authenticity of the first message based on the first message authentication code and the second message authentication code; and determine the operation availability of the S&F operation according to the message authenticity of the first message. An optional implementation manner of determining the message authenticity of the first message based on the first message authentication code and the second message authentication code in this embodiment is to determine the consistency between the first message authentication code and the second message authentication code. If they are consistent, it is determined that the message authenticity of the first message is true, that is, the first message has not been maliciously tampered with. If they are inconsistent, it is determined that the message authenticity of the first message is false, that is, the first message has been maliciously tampered with or attacked. An optional actual manner of determining the operation availability of the S&F operation according to the message authenticity of the first message in this embodiment is that when the message authenticity is true, the operation availability of the S&F operation is available; when the message authenticity is false, the operation availability of the S&F operation is unavailable. It should be noted that when the operation availability of the S&F operation is unavailable, the first encrypted message can be discarded.

[0129] Optionally, in this embodiment, after determining the availability of the S&F operation based on the first quantum key, the first encrypted message, and the first message authentication code, an optional implementation of a communication method is to determine the service result based on the availability of the S&F operation. Encrypt the service result based on the second quantum key to obtain the S&F operation service response message. Send the S&F operation service response message to the user equipment; wherein, the S&F operation service response message carries the second key identifier of the second quantum key. So that the user equipment can obtain the second quantum key based on the second key identifier. Decrypt the S&F operation service response message based on the second quantum key to obtain the service result. Wherein, the service result indicates whether the S&F service is available or not, and is used to inform the user equipment. It should be noted that the second quantum key may be the same quantum key as the first quantum key, or may be a different quantum key.

[0130] In this embodiment, based on the first message, obtain the first key identifier, the first encrypted message, and the first message authentication code. Based on the first key identifier, obtain the first quantum key. Decrypt the first encrypted message based on the first quantum key to obtain the first decrypted message. Perform HMAC processing on the first decrypted message based on the first quantum key to obtain the second message authentication code. Determine the availability of the S&F operation based on the first message authentication code and the second message authentication code. In this application, the authenticity of the first message can be judged based on the consistency between the first message authentication code and the second message authentication code, that is, whether the first message is a tampered attack message. Only when the first message authentication code and the second message authentication code are consistent, that is, when the message authenticity is true, is the availability of the S&F operation determined to be operationally available, further improving communication security and avoiding satellite attacks.

[0131] In one of the embodiments, before the user equipment sends a request message to the satellite, it needs to complete the authentication process, such as Figure 4 shown, an optional implementation of a communication method includes:

[0132] S401, receive the initial registration request sent by the user equipment.

[0133] Wherein, the initial registration request carries the first key identifier of the first quantum key. The initial registration situation refers to the registration request message sent by the user equipment to the satellite when it has a communication requirement, which internally carries the authentication registration information required for the user equipment to register and authenticate; the initial registration request also needs to carry the SUCI (Subscription Concealed Identifier) of the user equipment. It should be noted that the initial registration request can be an encrypted message or a non-encrypted message; if it is an encrypted message, the initial registration request also needs to carry the key identifier of the quantum key.

[0134] S402. Send a terminal authentication request carrying the first key identifier to the core network based on the initial registration request.

[0135] Among them, the terminal authentication request is used to instruct the core network to obtain the first quantum key based on the first key identifier and feedback a terminal authentication request response message carrying the first quantum key and the first key identifier to the satellite. The terminal authentication request carries the SUCI of the user equipment.

[0136] It should be noted that the core network needs to obtain the first quantum key in advance. Specifically, the core network can obtain or pre-inject quantum keys in real time through the QKD network; at least the first quantum key is included.

[0137] Optionally, in this embodiment, the satellite generates a terminal authentication request based on the initial registration request and adds the first key identifier to the terminal authentication request.

[0138] Optionally, the way for the core network to generate the terminal authentication request response message in this embodiment is that the core network generates an authentication vector based on the SUCI of the user equipment and generates a terminal authentication request response message based on the authentication vector. Add the first quantum key and the first key identifier to the terminal authentication request response message. It should be noted that the specific process of generating the terminal authentication request response message based on the authentication vector is described in detail in the 3GPP standard process and will not be elaborated here.

[0139] S403. Store the first quantum key and the first key identifier, and encrypt the terminal authentication request response message based on the third quantum key to obtain a third encrypted message.

[0140] Among them, the third quantum key refers to the quantum key stored in the satellite. The third quantum key and the first quantum key can be the same quantum key or different quantum keys. The third encrypted message refers to the message obtained by encrypting the terminal authentication request response message based on the third quantum key.

[0141] S404. Send the third encrypted message to the user equipment.

[0142] Among them, the third encrypted message carries the third key identifier of the third quantum key; the third encrypted message is used to instruct the user equipment to perform a terminal authentication operation based on the third encrypted message and the third key identifier.

[0143] Optionally, in this embodiment, an optional implementation manner for the user equipment to perform terminal authentication operations based on the third encrypted message and the third key identifier is as follows: Based on the third key identifier, obtain the third quantum key. Based on the third quantum key, decrypt the terminal authentication request response message, and generate a terminal authentication response message according to the decryption result. Encrypt the terminal authentication response message based on the fourth quantum key to obtain a fourth encrypted message. Perform HMAC processing on the terminal authentication response message based on the fourth quantum key to obtain a third message authentication code. Send the fourth encrypted message carrying the third message authentication code and the key identifier of the fourth quantum key to the satellite; where the fourth encrypted message is used to instruct the satellite to determine the authenticity of the message based on the fourth encrypted message, and in the case where the authenticity of the message is true, send the terminal authentication response message to the core network, so that the core network completes the authentication process of the user equipment based on the terminal authentication response message. An optional implementation manner for the satellite to determine the authenticity of the message based on the fourth message authentication code and the third message authentication code carried in the fourth encrypted message in this embodiment is to determine the consistency between the third message authentication code and the fourth message authentication code. If they are consistent, it is determined that the authenticity of the terminal authentication response message is true, that is, the terminal authentication response message has not been maliciously tampered with. If they are inconsistent, it is determined that the authenticity of the terminal authentication response message is false, that is, the terminal authentication response message has been maliciously tampered with or attacked. In the case where the message authenticity request is false, the tampered terminal authentication response message will be discarded.

[0144] In this embodiment, receive the second encrypted message sent by the user equipment; where the second encrypted message is obtained by the user equipment encrypting the initial registration request based on the first quantum key; the second encrypted message carries the first key identifier of the first quantum key. Send a terminal authentication request carrying the first key identifier to the core network based on the second encrypted message; where the terminal authentication request is used to instruct the core network to obtain the first quantum key based on the first key identifier and feedback a terminal authentication request response message carrying the first quantum key and the first key identifier to the satellite. Store the first quantum key and the first key identifier, and encrypt the terminal authentication request response message based on the third quantum key to obtain a third encrypted message. Send the third encrypted message to the user equipment; where the third encrypted message carries the third key identifier of the third quantum key; the third encrypted message is used to instruct the user equipment to perform terminal authentication operations based on the third encrypted message and the third key identifier. This embodiment not only realizes the synchronization of the first quantum key from the core network to the satellite, but also ensures the security of user equipment authentication, thereby enhancing the security of communication.

[0145] In an optional embodiment, as Figure 5 shown, a communication method is provided, which can be applied to Figure 1In the user equipment shown. In this embodiment, the method includes the following steps:

[0146] S501, when there is a need to send a request message to the core network, encrypt the request message based on the first quantum key to obtain a first encrypted message.

[0147] Optionally, in this embodiment, when there is a need to send a request message to the core network, the entire request message is encrypted based on the first quantum key to obtain a first encrypted message.

[0148] Optionally, in this embodiment, when there is a need to send a request message to the core network, obtain the sensitive data in the request message, and encrypt the sensitive data in the request message based on the first quantum key to obtain a first encrypted message.

[0149] S502, generate a first message based on the first encrypted message, the request message, and the first quantum key.

[0150] Optionally, in this embodiment, perform HMAC processing on the request message based on the first quantum key to obtain a first message authentication code. Generate a first message based on the first encrypted message, the first message authentication code, and the first key identifier of the first quantum key.

[0151] Optionally, in this embodiment, an alternative implementation of generating a first message based on the first encrypted message, the first message authentication code, and the first key identifier of the first quantum key is to add the first message authentication code and the first key identifier of the first quantum key to the first encrypted message to obtain the first message.

[0152] Another alternative implementation of generating a first message based on the first encrypted message, the first message authentication code, and the first key identifier of the first quantum key in this embodiment is to add the first message authentication code and the first key identifier of the first quantum key to the first encrypted message to obtain the first message.

[0153] S503, send the first message to the satellite.

[0154] Wherein, the first message is used to instruct the satellite to determine the availability of the S&F operation, and when the availability of the operation is available, based on the first encrypted message in the first message, send a second message to the core network.

[0155] Optionally, in this embodiment, an alternative implementation for the satellite to determine the availability of the S&F operation based on the first message is that the first message is specifically used to instruct the satellite to obtain the first quantum key based on the first key identifier, and determine the availability of the S&F operation based on the first quantum key, the first encrypted message, and the first message authentication code. Specifically, the first message is specifically used to instruct the satellite to decrypt the first encrypted message based on the first quantum key to obtain the first decrypted message, perform HMAC processing on the first decrypted message based on the first quantum key to obtain the second message authentication code, and determine the availability of the S&F operation based on the first message authentication code and the second message authentication code. An alternative implementation for determining the availability of the S&F operation based on the first message authentication code and the second message authentication code in this embodiment is to determine the authenticity of the first message based on the first message authentication code and the second message authentication code; determine the availability of the S&F operation according to the authenticity of the first message. An alternative implementation for determining the authenticity of the first message based on the first message authentication code and the second message authentication code in this embodiment is to determine the consistency between the first message authentication code and the second message authentication code. If they are consistent, it is determined that the authenticity of the first message is true, that is, the first message has not been maliciously tampered with. If they are inconsistent, it is determined that the authenticity of the first message is false, that is, the first message has been maliciously tampered with or attacked. An alternative actual implementation for determining the availability of the S&F operation according to the authenticity of the first message in this embodiment is that when the authenticity of the message is true, the availability of the S&F operation is available; when the authenticity of the message is false, the availability of the S&F operation is unavailable. It should be noted that when the availability of the S&F operation is unavailable, the first encrypted message can be discarded.

[0156] Optionally, another alternative implementation for the satellite to determine the availability of the S&F operation based on the first message in this embodiment is to obtain the service subscription information of the user equipment based on the first message. When the user equipment subscribes to the relevant service of the S&F operation, it is determined that the availability of the S&F operation is operationally available.

[0157] Optionally, in this embodiment, another optional implementation manner for the satellite to determine the availability of the S&F operation based on the first message is to determine the availability of the power supply line between the satellite and the core network. When the availability of the power supply line is unavailable, the availability of the S&F operation is determined based on the first message. That is to say, this application is mainly applicable when the availability of the power supply line between the satellite and the core network is unavailable. Because when the availability of the power supply line is available, the core network can establish a security context with the user equipment. In this case, even if communication is performed through the satellite, DOS attacks can be effectively avoided. Therefore, this application is mainly applied when the availability of the power supply line is unavailable.

[0158] Optionally, in this embodiment, when the availability of the operation is available, an optional implementation manner for sending the second message to the core network based on the first encrypted message in the first message is that when the availability of the operation is available, the first encrypted message in the first message is used as the second message; and the second message is sent to the core network. The second message also carries the first key identifier of the first quantum key, so that the core network can obtain the first quantum key based on the first key identifier, and then decrypt the first encrypted message to obtain the request message.

[0159] Optionally, in this embodiment, when the availability of the operation is available, another optional implementation manner for sending the second message to the core network based on the first encrypted message in the first message is that when the availability of the operation is available, the first encrypted message in the first message is decrypted based on the first quantum key to obtain the request message, the request message is used as the second message, and the second message is sent to the core network. It should be noted that the satellite can also perform conventional processing on the request message (such as format conversion, signal amplification, etc.), and then use the processed request message as the second message and send the second message to the core network.

[0160] Optionally, in this embodiment, when the availability of the operation is available, another optional implementation manner for sending the second message to the core network based on the first encrypted message in the first message is that when the availability of the power supply line becomes available, the second message is sent to the core network based on the first encrypted message in the first message. Because the S&F operation of the satellite is mainly performed when the power supply line is unavailable, only when the power supply line becomes available can the second message be sent to the core network.

[0161] In this embodiment, in the case of having a requirement to send a request message to the core network, the request message is encrypted based on the first quantum key to obtain a first encrypted message. A first message is generated based on the first encrypted message, the request message, and the first quantum key. The first message is sent to the satellite; wherein, the first message is used to instruct the satellite to determine the availability of the S&F operation, and in the case where the availability of the operation is available, based on the first encrypted message in the first message, a second message is sent to the core network. This application not only improves the security of the request message, but also after the satellite receives the first message, it can also judge the availability of the S&F operation according to the first message. Only when the first message meets the requirements, the availability of the operation is available. Furthermore, based on the S&F operation and the first encrypted message in the first message, a second message is sent to the core network, further improving the security of communication.

[0162] In one embodiment, in order to notify the service result of the S&F operation of the user equipment, such as Figure 6 shown, an alternative implementation manner of a communication method includes:

[0163] S601, receive the S&F operation service response message sent by the satellite.

[0164] Wherein, the S&F operation service response message is obtained by the satellite determining the service result based on the availability of the S&F operation and encrypting the service result based on the second quantum key; the second key identifier of the second quantum key is also carried in the S&F operation service response message. It should be noted that the second quantum key may be the same quantum key as the first quantum key or a different quantum key. The service result refers to whether the S&F service is available or not, and is used to inform the user equipment.

[0165] S602, obtain the second quantum key based on the second key identifier.

[0166] Optionally, in this embodiment, the second quantum key is obtained by looking up locally based on the second key identifier or through the QKD network.

[0167] S603, decrypt the S&F operation service response message based on the second quantum key to obtain the service result.

[0168] In this embodiment, a service response message of the S&F operation sent by a satellite is received. The service response message of the S&F operation is obtained by the satellite determining a service result based on the availability of the S&F operation and encrypting the service result with a second quantum key. The service response message of the S&F operation also carries a second key identifier of the second quantum key. Based on the second key identifier, the second quantum key is obtained. Based on the second quantum key, the service response message of the S&F operation is decrypted to obtain the service result, and based on this embodiment, the user equipment can be notified whether the S&F operation can be used.

[0169] In one embodiment, before sending a request in response to a request message and encrypting the request message with a first quantum key to obtain a first encrypted message, as Figure 7 shown, an optional implementation manner of a communication method includes:

[0170] S701: Send an initial registration request carrying a first key identifier of a first quantum key to a satellite, so that the satellite sends a terminal authentication request carrying at least the first key identifier to a core network based on the initial registration request. The terminal authentication request is used to instruct the core network to obtain the first quantum key based on the first key identifier and feedback a terminal authentication request response message carrying the first quantum key and the first key identifier to the satellite. The terminal authentication request response message is used to instruct the satellite to store the first quantum key and the first key identifier and encrypt the terminal authentication request response message with a third quantum key to obtain a third encrypted message. The terminal authentication request carries the SUCI of the user equipment.

[0171] Optionally, in this embodiment, the manner in which the core network generates the terminal authentication request response message is that the core network generates an authentication vector based on the SUCI of the user equipment, and generates the terminal authentication request response message based on the authentication vector. The first quantum key and the first key identifier are added to the terminal authentication request response message. It should be noted that the specific process of the core network generating an authentication vector based on the SUCI of the user equipment and generating the terminal authentication request response message based on the authentication vector is described in detail in the 3GPP standard process and will not be elaborated here.

[0172] S702: Receive the third encrypted message sent by the satellite.

[0173] The third encrypted message carries at least a third key identifier of the third quantum key.

[0174] S703: Perform a terminal authentication operation based on the third encrypted message and the third key identifier.

[0175] Optionally, in this embodiment, a third quantum key is obtained based on the third key identifier. Based on the third quantum key, the terminal authentication request response message is decrypted, and a terminal authentication response message is generated according to the decryption result. The terminal authentication response message is encrypted based on the fourth quantum key to obtain a fourth encrypted message. The terminal authentication response message is subjected to HMAC processing based on the fourth quantum key to obtain a third message authentication code. The fourth encrypted message carrying the third message authentication code and the key identifier of the fourth quantum key is sent to the satellite; wherein, the fourth encrypted message is used to instruct the satellite to determine the authenticity of the message based on the fourth encrypted message, and in the case where the authenticity of the message is true, send the terminal authentication response message to the core network.

[0176] Optionally, in this embodiment, an optional implementation manner for the satellite to determine the authenticity of the message based on the fourth encrypted message and send the terminal authentication response message to the core network in the case where the authenticity of the message is true is as follows: receive the fourth encrypted message, and obtain the fourth quantum key based on the fourth key identifier carried in the fourth encrypted message. The fourth encrypted message is decrypted based on the fourth quantum key to obtain a second decrypted message. The second decrypted message is subjected to HMAC processing based on the fourth quantum key to obtain a fourth message authentication code. The authenticity of the message is determined based on the fourth message authentication code and the third message authentication code carried in the fourth encrypted message. In the case where the authenticity of the message is true, determine that the second decrypted message is the terminal authentication response message, and send the terminal authentication response message to the core network. An optional implementation manner for the satellite to determine the authenticity of the message based on the fourth message authentication code and the third message authentication code carried in the fourth encrypted message in this embodiment is to determine the consistency of the third message authentication code and the fourth message authentication code. If they are consistent, it is determined that the authenticity of the terminal authentication response message is true, that is, the terminal authentication response message has not been maliciously tampered with. If they are inconsistent, it is determined that the authenticity of the terminal authentication response message is false, that is, the terminal authentication response message has been maliciously tampered with or attacked. In the case where the message authenticity request is false, the tampered terminal authentication response message is discarded. It should be noted that the fourth quantum key may be the same quantum key as the first quantum key or a different quantum key.

[0177] In this embodiment, an initial registration request carrying a first key identifier of a first quantum key is sent to a satellite, so that the satellite sends a terminal authentication request carrying at least the first key identifier to a core network based on the initial registration request; wherein, the terminal authentication request is used to instruct the core network to obtain the first quantum key based on the first key identifier and feedback a terminal authentication request response message carrying the first quantum key and the first key identifier to the satellite; the terminal authentication request response message is used to instruct the satellite to store the first quantum key and the first key identifier and perform an encryption process on the terminal authentication request response message based on a third quantum key to obtain a third encrypted message. The third encrypted message sent by the satellite is received; wherein, the third encrypted message carries at least a third key identifier of the third quantum key. Based on the third encrypted message and the third key identifier, a terminal authentication operation is performed. This not only improves the security of terminal registration authentication but also realizes the synchronization of the first quantum key from the core network to the satellite.

[0178] In one embodiment, as Figure 8 , Figure 9 shown, a communication method is provided, and the method includes the following steps:

[0179] A user equipment sends an initial registration request carrying a first key identifier of a first quantum key to a satellite.

[0180] The satellite sends a terminal authentication request carrying at least the first key identifier to the core network based on the initial registration request.

[0181] The core network obtains the first quantum key based on the first key identifier and feedbacks a terminal authentication request response message carrying the first quantum key and the first key identifier to the satellite.

[0182] The satellite stores the first quantum key and the first key identifier and performs an encryption process on the terminal authentication request response message based on a third quantum key to obtain a third encrypted message.

[0183] The user equipment receives the third encrypted message sent by the satellite. Wherein, the third encrypted message carries at least a third key identifier of the third quantum key.

[0184] The user equipment obtains the third quantum key based on the third key identifier.

[0185] The user equipment decrypts the terminal authentication request response message based on the third quantum key and generates a terminal authentication response message according to the decryption result.

[0186] The user equipment encrypts the terminal authentication response message based on a fourth quantum key to obtain a fourth encrypted message.

[0187] The user equipment performs HMAC processing on the terminal authentication response message based on the fourth quantum key to obtain the third message authentication code.

[0188] The user equipment sends the fourth encrypted message carrying the third message authentication code and the key identifier of the fourth quantum key to the satellite.

[0189] The satellite receives the fourth encrypted message and obtains the fourth quantum key based on the fourth key identifier carried in the fourth encrypted message.

[0190] The satellite decrypts the fourth encrypted message based on the fourth quantum key to obtain the second decrypted message.

[0191] The satellite performs HMAC processing on the second decrypted message based on the fourth quantum key to obtain the fourth message authentication code.

[0192] The satellite determines the authenticity of the message based on the fourth message authentication code and the third message authentication code carried in the fourth encrypted message.

[0193] When the authenticity of the message is true, the satellite determines that the second decrypted message is the terminal authentication response message and sends the terminal authentication response message to the core network.

[0194] When there is a need to send a request message to the core network, the user equipment encrypts the request message based on the first quantum key to obtain the first encrypted message.

[0195] The user equipment performs HMAC processing on the request message based on the first quantum key to obtain the first message authentication code.

[0196] The user equipment generates the first message based on the first encrypted message, the first message authentication code, and the first key identifier of the first quantum key.

[0197] The user equipment sends the first message to the satellite.

[0198] The satellite determines the availability of the feeder line between the satellite and the core network.

[0199] When the availability of the feeder line is unavailable, the satellite obtains the first key identifier, the first encrypted message, and the first message authentication code based on the first message.

[0200] The satellite obtains the first quantum key based on the first key identifier.

[0201] The satellite decrypts the first encrypted message based on the first quantum key to obtain the first decrypted message.

[0202] The satellite performs HMAC processing on the first decrypted message based on the first quantum key to obtain the second message authentication code.

[0203] The satellite determines the operational availability of the S&F operation based on the first message authentication code and the second message authentication code.

[0204] When the operational availability of the S&F operation is available and the feeder line availability becomes available, the satellite sends a second message to the core network based on the first encrypted message in the first message.

[0205] This embodiment also includes a service result notification process between the user equipment and the satellite, which is as follows:

[0206] The satellite determines the service result based on the operational availability of the S&F operation.

[0207] The satellite encrypts the service result based on the second quantum key to obtain an S&F operation service response message.

[0208] The user equipment receives the S&F operation service response message sent by the satellite. Among them, the S&F operation service response message also carries the second key identifier of the second quantum key.

[0209] The user equipment obtains the second quantum key based on the second key identifier.

[0210] The user equipment decrypts the S&F operation service response message based on the second quantum key to obtain the service result.

[0211] In this embodiment, the first message sent by the user equipment is received; among them, the first message is generated by the user equipment based on the first encrypted message, the request message, and the first quantum key; the first encrypted message is obtained by encrypting the request message based on the first quantum key. Based on the first message, the operational availability of the S&F operation is determined. When the operational availability is available, a second message is sent to the core network based on the first encrypted message in the first message. This application encrypts the request message based on the first quantum key, improving the security of the request message. After receiving the first message, the satellite can also judge the operational availability of the S&F operation according to the first message. Only when the first message meets the requirements, the operational availability is available. Then, based on the S&F operation, a second message is sent to the core network based on the first encrypted message in the first message, further improving the security of communication.

[0212] It should be understood that although the steps in the flowcharts involved in the above embodiments are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.

[0213] Based on the same inventive concept, an embodiment of the present application further provides a communication device for implementing the communication method involved above. The solution provided by this device to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more communication device embodiments provided below can refer to the limitations on the communication method in the above text, and will not be repeated here.

[0214] In one embodiment, as Figure 9 shown, a communication device 1 is provided, including:

[0215] A first receiving module 11, configured to receive a first message sent by a user equipment; wherein, the first message is generated by the user equipment based on a first encrypted message, a request message, and a first quantum key; the first encrypted message is obtained by encrypting the request message based on the first quantum key;

[0216] A first determining module 12, configured to determine the operation availability of the S&F operation based on the first message;

[0217] A first sending module 13, configured to send a second message to the core network based on the first encrypted message in the first message when the operation availability is available.

[0218] In one of the embodiments, the first encrypted message is generated by the user equipment performing HMAC processing on the request message based on the first quantum key to obtain a first message authentication code, and based on the first encrypted message, the first message authentication code, and the first key identifier of the first quantum key.

[0219] In one of the embodiments, the first determining module 12 is further specifically configured to:

[0220] Obtain a first key identifier, a first encrypted message, and a first message authentication code based on the first message;

[0221] Obtain the first quantum key based on the first key identifier;

[0222] Determine the operation availability of the S&F operation based on the first quantum key, the first encrypted message, and the first message authentication code.

[0223] In one embodiment, the first determination module 12 is further specifically configured to:

[0224] Decrypt the first encrypted message based on the first quantum key to obtain a first decrypted message;

[0225] Perform HMAC processing on the first decrypted message based on the first quantum key to obtain a second message authentication code;

[0226] Determine the operation availability of the S&F operation based on the first message authentication code and the second message authentication code.

[0227] In one embodiment, the first determination module 12 is further specifically configured to:

[0228] Determine the availability of the feeder line between the satellite and the core network;

[0229] In the case where the availability of the feeder line is unavailable, determine the operation availability of the S&F operation based on the first message.

[0230] In one embodiment, the first sending module 13 is further specifically configured to:

[0231] In the case where the availability of the feeder line becomes available, send a second message to the core network based on the first encrypted message in the first message.

[0232] In one embodiment, the above Figure 9 The communication device 1 further includes:

[0233] A second receiving module, configured to receive an initial registration request sent by a user equipment; wherein, a first key identifier of the first quantum key is carried in the initial registration request;

[0234] A third sending module, configured to send a terminal authentication request carrying the first key identifier to the core network based on the initial registration request; wherein, the terminal authentication request is used to instruct the core network to obtain the first quantum key based on the first key identifier and feedback a terminal authentication request response message carrying the first quantum key and the first key identifier to the satellite;

[0235] A storage module, configured to store the first quantum key and the first key identifier, and encrypt the terminal authentication request response message based on the third quantum key to obtain a third encrypted message;

[0236] A fourth sending module, configured to send a third encrypted message to a user equipment; wherein, a third key identifier of a third quantum key is carried in the third encrypted message; the third encrypted message is used to instruct the user equipment to perform a terminal authentication operation based on the third encrypted message and the third key identifier.

[0237] In one embodiment, the third encrypted message is specifically used to instruct the user equipment to send a fourth encrypted message to a satellite; wherein, the fourth encrypted message is obtained by the user equipment encrypting a terminal authentication response message based on a fourth quantum key; a third message authentication code and a fourth key identifier of the fourth quantum key are carried in the fourth encrypted message; the third message authentication code is obtained by the user equipment performing HMAC processing on the terminal authentication response message based on the fourth quantum key; the terminal authentication response message is generated by the user equipment obtaining the third quantum key based on the third key identifier, decrypting the terminal authentication request response message based on the third quantum key, and according to the decryption result.

[0238] In one embodiment, the Figure 9 above communication device 1 further includes:

[0239] A third receiving module, configured to receive the fourth encrypted message and obtain the fourth quantum key based on the fourth key identifier carried in the fourth encrypted message;

[0240] A second determining module, configured to perform decryption processing on the fourth encrypted message based on the fourth quantum key to obtain a second decrypted message;

[0241] A third determining module, configured to perform HMAC processing on the second decrypted message based on the fourth quantum key to obtain a fourth message authentication code;

[0242] A fourth determining module, configured to determine the authenticity of the message based on the fourth message authentication code and the third message authentication code carried in the fourth encrypted message;

[0243] A fifth determining module, configured to determine that the second decrypted message is the terminal authentication response message and send the terminal authentication response message to the core network when the authenticity of the message is true.

[0244] In one embodiment, as Figure 10 shown, a communication device 2 is provided, including:

[0245] An encryption module 21, configured to perform encryption processing on a request message based on a first quantum key to obtain a first encrypted message when there is a need to send a request message to the core network;

[0246] A generation module 22, configured to generate a first message based on the first encrypted message, the request message, and the first quantum key;

[0247] A second sending module 23, configured to send a first message to a satellite; wherein, the first message is used to instruct the satellite to determine the availability of an S&F operation, and in the case where the availability of the operation is available, based on the first encrypted message in the first message, send a second message to the core network.

[0248] In one embodiment, the generating module 22 is further specifically configured to:

[0249] Perform HMAC processing on the first quantum key pair request message to obtain a first message authentication code;

[0250] Generate a first message based on the first encrypted message, the first message authentication code, and the first key identifier of the first quantum key.

[0251] In one embodiment, the communication device 2 further includes:

[0252] A fourth receiving module, configured to receive an S&F operation service response message sent by the satellite; wherein, the S&F operation service response message is obtained by the satellite determining a service result based on the availability of the S&F operation and encrypting the service result based on a second quantum key; the S&F operation service response message also carries a second key identifier of the second quantum key;

[0253] A first obtaining module, configured to obtain a second quantum key based on the second key identifier;

[0254] A second obtaining module, configured to decrypt the S&F operation service response message based on the second quantum key to obtain the service result.

[0255] In one embodiment, the communication device 2 further includes:

[0256] A fifth sending module, configured to send an initial registration request carrying the first key identifier of the first quantum key to the satellite, so that the satellite sends a terminal authentication request carrying at least the first key identifier to the core network based on the initial registration request; wherein, the terminal authentication request is used to instruct the core network to obtain the first quantum key based on the first key identifier and feedback a terminal authentication request response message carrying the first quantum key and the first key identifier to the satellite; the terminal authentication request response message is used to instruct the satellite to store the first quantum key and the first key identifier, and encrypt the terminal authentication request response message based on a third quantum key to obtain a third encrypted message;

[0257] A fifth receiving module, configured to receive the third encrypted message sent by the satellite; wherein, the third encrypted message carries at least a third key identifier of the third quantum key;

[0258] An execution module, configured to perform a terminal authentication operation based on the third encrypted message and the third key identifier.

[0259] In one of the embodiments, the above-mentioned execution module is further specifically configured to:

[0260] Obtain a third quantum key based on a third key identifier;

[0261] Decrypt the terminal authentication request response message based on the third quantum key, and generate a terminal authentication response message according to the decryption result;

[0262] Encrypt the terminal authentication response message based on a fourth quantum key to obtain a fourth encrypted message;

[0263] Perform HMAC processing on the terminal authentication response message based on the fourth quantum key to obtain a third message authentication code;

[0264] Send the fourth encrypted message carrying the third message authentication code and the key identifier of the fourth quantum key to the satellite; wherein, the fourth encrypted message is used to instruct the satellite to determine the authenticity of the message based on the fourth encrypted message, and in the case where the authenticity of the message is true, send the terminal authentication response message to the core network.

[0265] Each module in the above-mentioned communication device can be implemented in whole or in part by software, hardware, and their combination. Each of the above modules can be embedded in the processor in the communication device in hardware form or independent of it, or stored in the memory in the communication device in software form, so as to facilitate the processor to call and execute the operations corresponding to each of the above modules.

[0266] In one embodiment, a communication device is provided. The communication device can be a server, and its internal structure diagram can be as Figure 11 shown. The communication device includes a processor, a memory, a network interface, and a transceiver connected through a system bus. Among them, the processor of the communication device is used to provide computing and control capabilities. The memory of the communication device includes a non-volatile storage medium and an internal memory. The transceiver of the communication device is used to perform operations of receiving data or sending data under the control of the processor. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the communication device is used to store relevant information of the communication method. The network interface of the communication device is used to communicate with an external terminal through a network connection. The computer program, when executed by the processor, implements a communication method.

[0267] Those skilled in the art can understand, Figure 11The structure shown is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the communication device to which the solution of this application is applied. The specific communication device may include more or fewer components than those shown in the figure, or combine some components, or have a different component layout.

[0268] In one embodiment, a communication device is provided, including a memory and a processor. When the processor executes the processing logic in the computer program, the following steps are implemented:

[0269] Receive a first message sent by a user device; wherein, the first message is generated by the user device based on a first encrypted message, a request message, and a first quantum key; the first encrypted message is obtained by encrypting the request message based on the first quantum key;

[0270] Based on the first message, determine the availability of the S&F operation;

[0271] When the operation availability is available, send a second message to the core network based on the first encrypted message in the first message.

[0272] In one embodiment, another communication device is provided, including a memory and a processor. When the processor executes the processing logic in the computer program, the following steps are implemented:

[0273] When there is a need to send a request message to the core network, encrypt the request message based on the first quantum key to obtain a first encrypted message;

[0274] Generate a first message based on the first encrypted message, the request message, and the first quantum key;

[0275] Send the first message to a satellite; wherein, the first message is used to instruct the satellite to determine the availability of the S&F operation, and when the operation availability is available, send a second message to the core network based on the first encrypted message in the first message.

[0276] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the processing logic in the computer program is executed by a processor, the following steps are implemented:

[0277] Receive a first message sent by a user device; wherein, the first message is generated by the user device based on a first encrypted message, a request message, and a first quantum key; the first encrypted message is obtained by encrypting the request message based on the first quantum key;

[0278] Based on the first message, determine the availability of the S&F operation;

[0279] When the operation availability is available, send a second message to the core network based on the first encrypted message in the first message.

[0280] In one embodiment, another computer-readable storage medium is provided, on which a computer program is stored. When the processing logic in the computer program is executed by a processor, the following steps are implemented:

[0281] When there is a need to send a request message to the core network, encrypt the request message based on the first quantum key to obtain a first encrypted message;

[0282] Generate a first message based on the first encrypted message, the request message, and the first quantum key;

[0283] Send the first message to the satellite; wherein, the first message is used to instruct the satellite to determine the operation availability of the S&F operation, and when the operation availability is available, send a second message to the core network based on the first encrypted message in the first message.

[0284] In one embodiment, a computer program product is provided, on which a computer program is stored. When the processing logic in the computer program is executed by a processor, the following steps are implemented:

[0285] Receive a first message sent by a user equipment; wherein, the first message is generated by the user equipment based on the first encrypted message, the request message, and the first quantum key; the first encrypted message is obtained by encrypting the request message based on the first quantum key;

[0286] Determine the operation availability of the S&F operation based on the first message;

[0287] When the operation availability is available, send a second message to the core network based on the first encrypted message in the first message.

[0288] In one embodiment, another computer program product is provided, on which a computer program is stored. When the processing logic in the computer program is executed by a processor, the following steps are implemented:

[0289] When there is a need to send a request message to the core network, encrypt the request message based on the first quantum key to obtain a first encrypted message;

[0290] Generate a first message based on the first encrypted message, the request message, and the first quantum key;

[0291] Send the first message to the satellite; wherein, the first message is used to instruct the satellite to determine the operation availability of the S&F operation, and when the operation availability is available, send a second message to the core network based on the first encrypted message in the first message.

[0292] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memories can include read-only memory (ROM), magnetic tapes, floppy disks, flash memories, optical memories, high-density embedded non-volatile memories, resistive random access memories (ReRAM), magnetoresistive random access memories (MRAM), ferroelectric random access memories (FRAM), phase change memories (PCM), graphene memories, etc. Volatile memories can include random access memory (RAM) or external cache memories, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logics, data processing logics based on quantum computing, etc., without limitation.

[0293] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as within the scope described in this specification.

[0294] The above embodiments only represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.

Claims

1. A communication method, characterized in that: Applications in satellites include: Receiving a first message sent by a user equipment; wherein the first message is generated by the user equipment based on a first encrypted message, a request message and a first quantum key; and the first encrypted message is obtained by encrypting the request message based on the first quantum key; Determining, based on the first message, an operational availability of a store and forward function (S&F) operation; When the operation availability is available, a second message is sent to the core network based on the first encrypted message in the first message.

2. The method according to claim 1, characterized in that The first encrypted message is generated by the user device performing a hash-based message authentication code HMAC processing on the request message based on the first quantum key to obtain a first message authentication code, and is generated based on the first encrypted message, the first message authentication code and a first key identifier of the first quantum key.

3. The method according to claim 2, characterized in that The determining, based on the first message, the availability of an operation of a store and forward function (S&F) operation includes: Based on the first message, obtaining the first key identifier, the first encrypted message and the first message authentication code; Based on the first key identifier, obtaining the first quantum key; Based on the first quantum key, the first encrypted message and the first message authentication code, an operational availability of an S&F operation is determined.

4. The method according to claim 3, characterized in that The determining, based on the first quantum key, the first encrypted message, and the first message authentication code, of the operational availability of the S&F operation comprises: Decrypting the first encrypted message based on the first quantum key to obtain a first decrypted message; Performing HMAC processing on the first decrypted message based on the first quantum key to obtain a second message authentication code; Based on the first message authentication code and the second message authentication code, an operational availability of an S&F operation is determined.

5. The method according to claim 1, characterized in that The determining, based on the first message, the availability of an operation of a store and forward function (S&F) operation includes: determining a feeder line availability of a feeder line between the satellite and the core network; In a case where the feeder line availability is unavailable, an operation availability of an S&F operation is determined based on the first message.

6. The method according to claim 5, characterized in that The sending a second message to the core network based on the first encrypted message in the first message includes: When the feeder line availability becomes available, a second message is sent to a core network based on the first encrypted message in the first message.

7. The method according to claim 1, characterized in that The method further comprises: Receiving an initial registration request sent by the user equipment; wherein the initial registration request carries a first key identifier of the first quantum key; Sending a terminal authentication request carrying the first key identifier to the core network based on the initial registration request; wherein the terminal authentication request is used to instruct the core network to obtain a first quantum key based on the first key identifier, and to feed back a terminal authentication request response message carrying the first quantum key and the first key identifier to the satellite; storing the first quantum key and the first key identifier, and encrypting the terminal authentication request response message based on a third quantum key to obtain a third encrypted message; Sending the third encrypted message to the user equipment; wherein the third encrypted message carries a third key identifier of the third quantum key; the third encrypted message is used to instruct the user equipment to perform a terminal authentication operation based on the third encrypted message and the third key identifier.

8. The method according to claim 7, characterized in that The third encrypted message is specifically used to instruct the user equipment to send a fourth encrypted message to the satellite; wherein, the fourth encrypted message is obtained by the user equipment encrypting a terminal authentication response message based on a fourth quantum key; the fourth encrypted message carries a third message authentication code and a fourth key identifier of a fourth quantum key; the third message authentication code is obtained by the user equipment performing HMAC processing on the terminal authentication response message based on the fourth quantum key; the terminal authentication response message is generated by the user equipment obtaining a third quantum key based on the third key identifier, decrypting the terminal authentication request response message based on the third quantum key, and generating the message based on the decryption result.

9. The method according to claim 8, characterized in that The method further comprises: receiving the fourth encrypted message, and acquiring a fourth quantum key based on a fourth key identifier carried in the fourth encrypted message; Decrypting the fourth encrypted message based on the fourth quantum key to obtain a second decrypted message; Performing HMAC processing on the second decrypted message based on the fourth quantum key to obtain a fourth message authentication code; Determining the authenticity of the message based on the fourth message authentication code and the third message authentication code carried in the fourth encrypted message; When the authenticity of the message is true, determine that the second decrypted message is a terminal authentication response message, and send the terminal authentication response message to the core network.

10. A communication method, characterized in that: Applied to user equipment, including: When there is a need to send a request message to the core network, encrypt the request message based on the first quantum key to obtain a first encrypted message; Generate a first message based on the first encrypted message, the request message and the first quantum key; The first message is sent to the satellite; wherein the first message is used to instruct the satellite to determine the operational availability of the S&F operation, and when the operational availability is available, based on the first encrypted message in the first message, send a second message to the core network.

11. The method according to claim 10, characterized in that The generating a first message based on the first encrypted message, the request message and the first quantum key comprises: Performing HMAC processing on the request message based on the first quantum key to obtain a first message authentication code; The first message is generated based on the first encrypted message, the first message authentication code, and a first key identifier of the first quantum key.

12. The method according to claim 10, characterized in that The method further comprises: receiving an S&F operation service response message sent by the satellite; wherein the S&F operation service response message is obtained after the satellite determines a service result based on the operation availability of the S&F operation and encrypts the service result based on the second quantum key; the S&F operation service response message also carries a second key identifier of the second quantum key; Based on the second key identifier, obtaining the second quantum key; Based on the second quantum key, the S&F operation service response message is decrypted to obtain the service result.

13. The method according to claim 10, characterized in that Before sending a request in response to the request message and encrypting the request message based on the first quantum key to obtain a first encrypted message, the method further includes: sending the initial registration request carrying the first key identifier of the first quantum key to the satellite, so that the satellite sends a terminal authentication request carrying at least the first key identifier to the core network based on the initial registration request; wherein the terminal authentication request is used to instruct the core network to obtain the first quantum key based on the first key identifier, and to feed back a terminal authentication request response message carrying the first quantum key and the first key identifier to the satellite; the terminal authentication request response message is used to instruct the satellite to store the first quantum key and the first key identifier, and to encrypt the terminal authentication request response message based on a third quantum key to obtain a third encrypted message; receiving a third encrypted message sent by the satellite; wherein the third encrypted message carries at least a third key identifier of the third quantum key; A terminal authentication operation is performed based on the third encrypted message and the third key identifier.

14. The method according to claim 13, characterized in that The performing a terminal authentication operation based on the third encrypted message and the third key identifier includes: Based on the third key identifier, obtaining a third quantum key; Decrypting the terminal authentication request response message based on the third quantum key, and generating a terminal authentication response message according to the decryption result; Encrypting the terminal authentication response message based on a fourth quantum key to obtain a fourth encrypted message; Based on the fourth quantum key, perform HMAC processing on the terminal authentication response message to obtain a third message authentication code; Sending a fourth encrypted message carrying the third message authentication code and the key identifier of the fourth quantum key to the satellite; wherein the fourth encrypted message is used to instruct the satellite to determine the authenticity of the message based on the fourth encrypted message, and to send the terminal authentication response message to the core network when the authenticity of the message is true.

15. A communication device, characterized in that: Configured in the satellite, including: A first receiving module, configured to receive a first message sent by a user equipment; wherein the first message is generated by the user equipment based on a first encrypted message, a request message and a first quantum key; and the first encrypted message is obtained by encrypting the request message based on the first quantum key; A first determining module, configured to determine, based on the first message, an operational availability of a store and forward function S&F operation; The first sending module is used to send a second message to the core network based on the first encrypted message in the first message when the operation availability is available.

16. A communication device, characterized in that: Configured in user equipment, including: An encryption module, configured to, when there is a need to send a request message to a core network, encrypt the request message based on a first quantum key to obtain a first encrypted message; A generating module, configured to generate a first message based on the first encrypted message, the request message and the first quantum key; The second sending module is used to send the first message to the satellite; wherein the first message is used to instruct the satellite to determine the operational availability of the S&F operation, and when the operational availability is available, based on the first encrypted message in the first message, send a second message to the core network.

17. A communication device, comprising a memory, a transceiver and a processor, wherein the memory stores a computer program, characterized in that: The transceiver is used to receive data or send data under the control of the processor, and the processor implements the steps of any one of claims 1-14 when executing the computer program.

18. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 14 are implemented.

19. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 14 are implemented.