Key distribution method, communication system and related equipment

By using non-access layer messages in 5G networks to carry access network device identification and encrypt the access layer key, the problem of low security in the transmission of the satellite-borne base station is solved, and the security guarantee for key transmission is achieved.

CN120201422AActive Publication Date: 2025-06-24CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510346238.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-21
Publication Date
2025-06-24
Estimated Expiration
2045-03-21

AI Technical Summary

Technical Problem

In 5G networks, KgNB keys are not very secure when transmitted from the ground core network to the satellite-based base station, especially in wireless links, which are easily intercepted by attackers, resulting in communication data leakage.

Method used

By carrying the identification of the access network device in the non-access layer message, the ground core network element queries the pre-configured shared key, and uses the key to encrypt the access layer key to be encrypted to transmit, generate the access layer key in the form of ciphertext, and transmit it to the access network device for decryption, ensuring the security of key transmission.

Benefits of technology

The security of KgNB key transmission between the ground core network and non-ground access network equipment is improved, key leakage is prevented, and the security of satellite communication is ensured.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120201422A_ABST
    Figure CN120201422A_ABST
Patent Text Reader

Abstract

The invention provides a key distribution method, a communication system and related equipment, and relates to the technical field of communication. The method comprises: a core network element of a ground core network receiving a non-access stratum message forwarded by an access network device, the non-access stratum message carrying an access network device identifier of the access network device; according to an access network device identifier carried in the non-access layer message, querying a pre-configured shared key for performing secure communication between the access network device and a ground core network, and encrypting an access layer key to be transmitted in an encrypted manner by using the shared key to obtain an access layer key in a ciphertext form; and sending the access layer key in the ciphertext form to the access network equipment, so that the access network equipment decrypts the access layer key in the ciphertext form to obtain an access layer key in a plaintext form. According to the invention, the security of transmission of the access layer key between the ground core network and the non-ground access network equipment can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0002] In the existing 5G standard, when a terrestrial terminal first accesses the network, it will be authenticated, and UP (User Plane) layer keys and RRC (Radio Resource Control) layer keys for air interface confidentiality and integrity protection will be derived, thereby establishing the security mechanisms of NAS (Non-Access Stratum) and AS (Access Stratum) to ensure the confidentiality and integrity of air interface communication. Among them, the KgNB key (base station key) is a key in the 5G network. As the root key of the AS layer, it can derive other keys, such as KUPint (User Plane Integrity Key), KUPenc (User Plane Encryption Key), KRRCint (RRC Integrity Key), and KRRCenc (RRC Encryption Key), etc. The non-terminal side source of the KgNB key is the AMF (Access and Mobility Management Function) network element in the core network.

[0003] In the terrestrial network, the communication between the core network and the base station is often achieved through a wired connection. Due to the physical isolation characteristics of wired transmission, the security of data transmission is relatively high, and the communication link is relatively controllable. Therefore, the communication security protection measures between the terrestrial core network and the terrestrial base station are relatively simple. The existing 5G standard stipulates that the KgNB key is sent from the AMF network element to the base station through the Next Generation Application Protocol (NGAP) message. Although the 5G standard supports using IPSec (Internet Protocol Security) for encryption protection on the N2 interface between the base station and the core network AMF network element, in actual deployment, IPSec is usually not enabled.

[0004] When a base station is assembled onto a non - terrestrial carrier such as a satellite, the communication environment undergoes a fundamental change. Since the communication between the space - borne base station and the terrestrial core network is achieved through a wireless link, the following security issues will arise: 1) The wireless link in satellite communication is exposed in open space, and an attacker can intercept the communication data between the space - borne base station and the terrestrial core network within a certain range, thereby obtaining sensitive information; 2) Different from the wired connections in terrestrial networks, the wireless link in satellite communication cannot be effectively physically isolated and monitored, making it more difficult to ensure the security of the communication link. In the scenario of the space - borne base station (S - gNB), the KgNB key needs to be synchronized between the terrestrial core network and the space - borne base station.

[0005] Since the KgNB key is directly related to the security of subsequent communications, it cannot be transmitted in plain text between communication entities. There is an urgent need to provide a key distribution method in the satellite communication scenario, aiming to solve the problem of the secure transmission of the KgNB key between the terrestrial core network and the space - borne base station, thereby ensuring the security of satellite communication.

[0006] It should be noted that the information disclosed in the above - mentioned background art section is only used to enhance the understanding of the background of the present disclosure, and thus may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention

[0007] The present disclosure provides a key distribution method, a communication system, and related devices, which at least to some extent overcome the technical problem of low security in the transmission of keys between the terrestrial core network and non - terrestrial base stations in the related art.

[0008] Other features and advantages of the present disclosure will become apparent through the following detailed description, or will be learned in part through the practice of the present disclosure.

[0009] According to one aspect of the present disclosure, a key distribution method is provided, which is applied to a core network element of a terrestrial core network. The method includes: receiving a non - access stratum message forwarded by an access network device, where the non - access stratum message is a signaling message sent by a terminal to the terrestrial core network, and the non - access stratum message carries an access network device identifier of the access network device; querying a shared key for secure communication between the access network device and the terrestrial core network pre - configured according to the access network device identifier carried in the non - access stratum message, and using the shared key to encrypt an access stratum key to be transmitted securely, obtaining the access stratum key in ciphertext form, where the access stratum key is a key for secure communication between the access network device and the terminal; sending the access stratum key in ciphertext form to the access network device, so that the access network device decrypts the access stratum key in ciphertext form to obtain the access stratum key in plaintext form.

[0010] In some embodiments, the access stratum key in ciphertext form is sent to the access network device via a Next Generation Application Protocol (NGAP) message, where the NGAP message is an interaction message between the terrestrial core network and the access network device.

[0011] In some embodiments, before encrypting the access stratum key to be transmitted using the shared key to obtain the access stratum key in ciphertext form, the method further includes: generating an access stratum key to be encrypted and transmitted in response to the completion of the two-way authentication process between the core network element and the terminal.

[0012] In some embodiments, the terrestrial core network is a 5G core network, and the core network element is an Access and Mobility Management Function (AMF) network element.

[0013] In some embodiments, the access network device is a terrestrial access network device deployed on a terrestrial infrastructure platform.

[0014] In some embodiments, the terrestrial access network device is a terrestrial base station.

[0015] In some embodiments, the access network device is a non-terrestrial access network device deployed on a non-terrestrial infrastructure platform.

[0016] In some embodiments, the non-access network device is a spaceborne base station.

[0017] According to another aspect of the present disclosure, there is also provided a key distribution method applied to an access network device. The method includes: receiving a non-access stratum message from a terminal, where the non-access stratum message is a signaling message sent by the terminal to the terrestrial core network; adding the access network device identifier of the access network device to the non-access stratum message and forwarding the non-access stratum message carrying the access network device identifier to a core network element of the terrestrial core network, where the core network element is configured to query a shared key for secure communication between the access network device and the terrestrial core network according to the access network device identifier carried in the non-access stratum message, and use the shared key to encrypt the access stratum key to be transmitted to obtain the access stratum key in ciphertext form, and the access stratum key is a key for secure communication between the access network device and the terminal; receiving the access stratum key in ciphertext form returned by the core network element and decrypting the access stratum key in ciphertext form to obtain the access stratum key in plaintext form.

[0018] In some embodiments, after receiving the access layer key in ciphertext form returned by the core network element, the method further includes: obtaining a shared key pre-configured for secure communication between the access network device and the terrestrial core network; using the shared key to decrypt the access layer key in ciphertext form; storing the decrypted access layer key so that the access network device can use the access layer key to establish a secure connection for the access layer.

[0019] In some embodiments, after receiving the access layer key in ciphertext form returned by the core network element, the method further includes: transmitting the access layer key in ciphertext form to a security module, where a shared key is stored on the security module, and the security module is further configured to use the shared key to decrypt the access layer key in ciphertext form and store the decrypted access layer key; obtaining the decrypted access layer key from the security module and using the access layer key to establish a secure connection for the access layer.

[0020] In some embodiments, the terrestrial core network is a 5G core network, and the core network element is an access and mobility management function (AMF) network element.

[0021] In some embodiments, the access network device is a terrestrial access network device deployed on a terrestrial infrastructure platform.

[0022] In some embodiments, the terrestrial access network device is a terrestrial base station.

[0023] In some embodiments, the access network device is a non-terrestrial access network device deployed on a non-terrestrial infrastructure platform.

[0024] In some embodiments, the non-access network device is a spaceborne base station.

[0025] According to another aspect of the present disclosure, a core network device is further provided. The core network device includes: a non-terrestrial network communication module, configured to receive a non-access stratum message forwarded by an access network device, where the non-access stratum message is a signaling message sent by a terminal to a terrestrial core network, and the non-access stratum message carries an access network device identifier of the access network device; a key encryption module, configured to query a shared key for secure communication between the access network device and the terrestrial core network pre-configured according to the access network device identifier carried in the non-access stratum message, and use the shared key to encrypt an access stratum key to be encrypted and transmitted, so as to obtain an access stratum key in ciphertext form, where the access stratum key is a key for secure communication between the access network device and the terminal; an encrypted key distribution module, configured to send the access stratum key in ciphertext form to the access network device, so that the access network device decrypts the access stratum key in ciphertext form to obtain an access stratum key in plaintext form.

[0026] According to another aspect of the present disclosure, an access network device is further provided. The access network device includes: a non-access stratum message receiving module, configured to receive a non-access stratum message from a terminal, where the non-access stratum message is a signaling message sent by the terminal to a terrestrial core network; a non-access stratum message forwarding module, configured to add an access network device identifier of the access network device to the non-access stratum message, and forward the non-access stratum message carrying the access network device identifier to a core network element of the terrestrial core network, where the core network element is configured to query a shared key for secure communication between the access network device and the terrestrial core network pre-configured according to the access network device identifier carried in the non-access stratum message, and use the shared key to encrypt an access stratum key to be encrypted and transmitted, so as to obtain an access stratum key in ciphertext form, and the access stratum key is a key for secure communication between the access network device and the terminal; a key acquisition module, configured to receive the access stratum key in ciphertext form returned by the core network element, and decrypt the access stratum key in ciphertext form to obtain an access stratum key in plaintext form.

[0027] According to another aspect of the present disclosure, a communication system is further provided. The system includes: an access network device and a terrestrial core network; the terrestrial core network includes: a core network element; wherein, the access network device is configured to receive a non-access stratum message from a terminal, add an access network device identifier to the non-access stratum message, and then forward it to the core network element; the core network element is configured to query a pre-configured shared key for secure communication between the access network device and the terrestrial core network according to the access network device identifier carried in the non-access stratum message, encrypt the access stratum key to be encrypted and transmitted using the shared key to obtain an access stratum key in ciphertext form, and send it to the access network device, so that the access network device decrypts the access stratum key in ciphertext form to obtain an access stratum key in plaintext form, and the access stratum key is a key for secure communication between the access network device and the terminal.

[0028] According to another aspect of the present disclosure, an electronic device is further provided, including: a processor; and a memory for storing executable instructions of the processor; wherein, the processor is configured to execute the key distribution method according to any one of the above by executing the executable instructions.

[0029] According to another aspect of the present disclosure, a computer-readable storage medium is further provided, on which a computer program is stored, and when the computer program is executed by a processor, the key distribution method according to any one of the above is implemented.

[0030] According to another aspect of the present disclosure, a computer program product is further provided, including: a computer program or instruction, and when the computer program or instruction is executed by a processor, the key distribution method according to any one of the above is implemented.

[0031] In the key distribution method, communication system and related devices provided in the embodiments of the present disclosure, when the access network device forwards a non-access stratum message from the terminal to the core network element of the terrestrial core network, it carries the access network device identifier of the access network device in the non-access stratum message, so that the core network element queries a pre-configured shared key for secure communication between the access network device and the terrestrial core network according to the access network device identifier carried in the non-access stratum message, encrypts the access stratum key to be encrypted and transmitted using the shared key to obtain an access stratum key in ciphertext form, sends it to the access network device, and the access network device decrypts the access stratum key in ciphertext form to obtain an access stratum key in plaintext form.

[0032] Through the embodiments of the present disclosure, the security of the access stratum key transmission between the terrestrial core network and the non-terrestrial access network device can be improved.

[0033] It should be understood that the above general description and the following detailed description are merely exemplary and explanatory, and do not limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] The accompanying drawings herein are incorporated into the specification and form a part of the specification, showing embodiments consistent with the present disclosure, and are used together with the specification to explain the principles of the present disclosure. Obviously, the drawings in the following description are only some embodiments of the present disclosure, and those of ordinary skill in the art can obtain other drawings based on these drawings without creative efforts.

[0035] Figure 1 Showing a schematic diagram of a communication system architecture in an embodiment of the present disclosure; Figure 2 Showing a flowchart of a key distribution method in an embodiment of the present disclosure; Figure 3 Showing a flowchart of an access layer key derivation method in an embodiment of the present disclosure; Figure 4 Showing a flowchart of another key distribution method in an embodiment of the present disclosure; Figure 5 Showing a flowchart of establishing an access layer secure connection in an embodiment of the present disclosure; Figure 6 Showing a flowchart of establishing an access layer secure connection in an embodiment of the present disclosure; Figure 7 Showing a flowchart of key distribution in a satellite communication system in an embodiment of the present disclosure; Figure 8 Showing a schematic diagram of a core network device in an embodiment of the present disclosure; Figure 9 Showing a schematic diagram of an access network device in an embodiment of the present disclosure; Figure 10 Showing a structural block diagram of an electronic device in an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0036] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be more complete and comprehensive, and will fully convey the concept of the example embodiments to those skilled in the art. The features, structures, or characteristics described may be combined in any suitable manner in one or more embodiments.

[0037] In addition, the accompanying drawings are only schematic illustrations of the present disclosure and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and thus repeated descriptions thereof will be omitted. Some of the block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities may be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0038] For ease of understanding, before introducing the embodiments of the present disclosure, several terms involved in the embodiments of the present disclosure are explained as follows: AMF: Access and Mobility Management Function, which is a functional entity in the 5G core network and is responsible for handling access and mobility management tasks of user equipment (UE), such as registration management and connection management.

[0039] AS SMC: Access Security Command, which is a command for managing and executing access layer security operations to ensure the security of user equipment (UE) when accessing the network.

[0040] NGAP: Next Generation Application Protocol, which is a protocol for control plane signaling transmission in the 5G system and defines various message types exchanged between the 5G core network and gNB (5G base station).

[0041] KgNB: gNB Key, which is a key key in the 5G system. As a root key, it can generate various other keys to ensure the security and privacy of communication.

[0042] SUCI: Subscription Concealed Identifier, which is an identifier for hiding user subscription information to ensure user privacy.

[0043] NAS: Non-Access Stratum, which is a protocol layer in the 5G system and is responsible for handling non-access layer signaling between the UE and the core network, such as registration, authentication, and session management.

[0044] NAS SMC: Non-Access Stratum Security Mode Command. In a mobile communication network (such as LTE, etc.), the Non-Access Stratum (NAS) processes signaling interactions unrelated to access between the UE (User Equipment) and the core network. The security mode command is an important part of the NAS signaling, mainly used to initiate the security mode process between the UE and the network, including security operations such as encrypting signaling and user data and integrity protection.

[0045] AKA: Authentication and Key Agreement, a protocol for authentication and key agreement, which ensures the authentication of both communication parties and the secure exchange of keys.

[0046] KSEAF: Security Anchor Function Key, a key used for the security anchor function, which ensures secure communication between the UE and the core network.

[0047] KAMF: Access and Mobility Management Function Key, a key used by the AMF functional entity to ensure the security of the access and mobility management process.

[0048] The following will describe in detail the specific implementation manners of the embodiments of the present disclosure in conjunction with the accompanying drawings.

[0049] Figure 1 The schematic diagram of the communication system architecture to which the key distribution method in the embodiments of the present disclosure can be applied is shown. As Figure 1 shown, the system includes: access network devices (non-terrestrial access network device 20 or terrestrial access network device 50) and terrestrial core network 10; the terrestrial core network 10 includes: core network element 101.

[0050] Among them, the access network device (non-terrestrial access network device 20 or terrestrial access network device 50) is respectively connected to the terminal 30 and the terrestrial core network 10, and is used to receive non-access stratum messages from the terminal 30. After adding the access network device identifier to the non-access stratum messages, it forwards them to the core network element 101 within the terrestrial core network 10. The core network element 101 queries the pre-configured shared key for secure communication between the access network device and the terrestrial core network according to the access network device identifier carried in the non-access stratum message, encrypts the access stratum key to be encrypted and transmitted using the shared key, and obtains the access stratum key in ciphertext form, and sends it to the access network device (non-terrestrial access network device 20 or terrestrial access network device 50), so that the access network device (non-terrestrial access network device 20 or terrestrial access network device 50) decrypts the access stratum key in ciphertext form to obtain the access stratum key in plaintext form. The access stratum key is the key for secure communication between the access network device (non-terrestrial access network device 20 or terrestrial access network device 50) and the terminal 30.

[0051] It should be noted that the terrestrial gateway station 40 is a key infrastructure in a non-terrestrial communication system (such as a satellite communication system), and is responsible for establishing a data link between the non-terrestrial network (such as a satellite network) and the terrestrial network (such as the Internet, a mobile communication network, etc.), and realizing signal relay, protocol conversion, and data exchange. The non-terrestrial access network device 20 in the embodiments of the present disclosure refers to an access network device (such as an on-board base station, etc.) carried or deployed on a non-terrestrial infrastructure platform (such as a satellite, a high-altitude platform, etc.), and is responsible for establishing a communication connection with the terminal 30 and forwarding relevant signaling / data. The non-terrestrial access network device 20 needs to communicate with the terrestrial core network 10 through the terrestrial gateway station 40.

[0052] The terrestrial network access network device 50 in the embodiments of the present disclosure refers to an access network device (such as a terrestrial base station, a relay, or an access point, etc.) carried or deployed on a terrestrial infrastructure platform, and is responsible for establishing a communication connection with the terminal 30 and forwarding relevant signaling / data.

[0053] The terrestrial core network in the embodiments of the present disclosure refers to a core network deployed on the ground, and the core network elements included therein (the network elements here can also be referred to as "functional entities") can be, but are not limited to, AMF network elements. In some other embodiments, the terrestrial core network 10 may further include core network elements such as SMF network elements.

[0054] In some embodiments, when the access network device is a base station, the base station can be a base station of any communication standard. For example, it can be a gNB (gNodeB) in the 5th generation mobile communication (5G) system, a 6G base station in the 6th generation mobile communication system, an eNB (evolved NodeB) in the Long-Term Evolution (LTE) system, and so on. It should be emphasized that the technical solutions described in this disclosure do not limit the physical form and communication standard of the access network device. It is applicable to various base station devices defined by current standards and is also compatible with future evolved new base station architectures.

[0055] Correspondingly, Figure 1 The shown terrestrial core network can be a core network of any communication standard, such as a 5G core network or a 6G core network.

[0056] Optionally, the terminal 30 in the embodiments of this disclosure can also be referred to as a UE (User Equipment). In specific implementations, the terminal 30 can be a mobile phone, a tablet personal computer, a laptop computer, a personal digital assistant (PDA), a mobile internet device (MID), a wearable device, or a vehicle-mounted device, etc. It should be noted that the specific type of the terminal 30 is not limited in the embodiments of this invention.

[0057] Those skilled in the art can understand that Figure 1 the numbers of terminals, non-terrestrial access network devices, terrestrial gateway stations, terrestrial access network devices, and core network elements in

[0058] are merely illustrative. According to actual needs, there can be any number of terminals, non-terrestrial access network devices, terrestrial gateway stations, terrestrial access network devices, and core network elements. The embodiments of this disclosure do not limit this.

[0059] Figure 2 The flowchart of a key distribution method in the embodiments of this disclosure is shown. As Figure 2 shown, the method includes the following steps: S202. Receive a non-access stratum message forwarded by an access network device. The non-access stratum message is a signaling message sent by a terminal to a terrestrial core network, and the access network device identifier of the access network device is carried in the non-access stratum message.

[0060] In the embodiments of the present disclosure, a non-access stratum (NAS) message refers to a signaling message directly interacting between a terminal and a core network, including but not limited to a registration message or a network handover message of the terminal. The above-mentioned access network device identifier can be any information such as a character or a number that can uniquely identify the access network device, and the specific form of the access network device identifier is not limited in the embodiments of the present disclosure.

[0061] Generally, for a non-access stratum message directly sent by a terminal to a core network, the access network device only forwards it without any processing. In the embodiments of the present disclosure, when the access network device forwards a non-access stratum message from a terminal to a terrestrial core network, adding the access network device identifier of the access network device to the non-access stratum message can facilitate the terrestrial core network to query a pre-configured shared key for secure communication between the access network device and the terrestrial core network, encrypt the access stratum key for secure communication between the access network device and the terminal, and realize the secure transmission of the access stratum key.

[0062] S204. Query a pre-configured shared key for secure communication between the access network device and the terrestrial core network according to the access network device identifier carried in the non-access stratum message, and use the shared key to encrypt the access stratum key to be encrypted and transmitted, obtaining the access stratum key in ciphertext form, where the access stratum key is the key for secure communication between the access network device and the terminal.

[0063] It should be noted that the access stratum key in the embodiments of the present disclosure can be any key for secure communication between the access network device and the terminal, and can be but not limited to the root key used by the access stratum to derive other keys. For example, in one embodiment, when the non-terrestrial access network device is a spaceborne base station, the access stratum key to be encrypted in S204 above is the KgNB key (base station key), which can be used to derive but not limited to: KUPint (User Plane Integrity Key), KUPenc (User Plane Encryption Key), KRRCint (RRC Integrity Key), and KRRCenc (RRC Encryption Key), etc.

[0064] S206. Send the access stratum key in ciphertext form to the access network device, so that the access network device decrypts the access stratum key in ciphertext form to obtain the access stratum key in plaintext form.

[0065] In the embodiments of the present disclosure, the access stratum key is sent by the terrestrial core network to the access network device in ciphertext form. Therefore, it can avoid the problem of potential security risks in the transmission of the access stratum key in plaintext form between the terrestrial core network and the access network device. After receiving the access stratum key in ciphertext form, the access network device decrypts the access stratum key in ciphertext form using the shared key pre-configured for secure communication between the access network device and the terrestrial core network to obtain the access stratum key in plaintext form. Further, non-access network devices can derive other keys of the access stratum using the decrypted access stratum key.

[0066] For non-terrestrial access network devices (such as satellite base stations) carried or deployed on non-terrestrial infrastructure platforms, which communicate with the terrestrial core network through wireless links and have relatively low security. Therefore, in the key distribution method provided in the embodiments of the present disclosure, the access stratum key transmitted between the non-terrestrial access network device and the terrestrial core network is in ciphertext, which can ensure the security of the transmission of the access stratum key (such as the KgNB key).

[0067] For terrestrial access network devices (such as terrestrial base stations) carried or deployed on terrestrial infrastructure platforms, which communicate with the terrestrial core network through wired links and have relatively high security. However, for some scenarios with high-security communication requirements (such as high-security networks in specific industries), it may be necessary to protect the access stratum key between the terrestrial base station and the terrestrial core network. Therefore, in the key distribution method provided in the embodiments of the present disclosure, which is applied to the transmission of keys between the terrestrial base station and the core network, the access stratum key transmitted between the terrestrial base station and the core network is in ciphertext, which can ensure the security of the transmission of the access stratum key (such as the KgNB key).

[0068] In some embodiments, in the above S206, the access stratum key in ciphertext form can be sent to the access network device through the Next Generation Application Protocol (NGAP) message, where the NGAP message is an interaction message between the terrestrial core network and the access network device.

[0069] In some embodiments, before encrypting the access stratum key to be transmitted using the shared key to obtain the access stratum key in ciphertext form, as Figure 3 shown, the method provided in the embodiments of the present disclosure can also obtain the access stratum key to be encrypted through the following steps: S200. In response to the completion of the two-way authentication process between the core network element and the terminal, generate the access stratum key to be encrypted for transmission.

[0070] In some embodiments, the access network device in the embodiments of the present disclosure is a terrestrial access network device deployed on a terrestrial infrastructure platform.

[0071] In some embodiments, the terrestrial access network device is a terrestrial base station.

[0072] In some other embodiments, the access network device in the embodiments of the present disclosure is a non-terrestrial access network device deployed on a non-terrestrial infrastructure platform.

[0073] In some embodiments, the non-access network device is a spaceborne base station.

[0074] In some embodiments, the terrestrial core network in the embodiments of the present disclosure is a 5G core network, and the core network element is an access and mobility management function (AMF) network element.

[0075] Based on the same inventive concept, an embodiment of the present disclosure also provides a key distribution method. In principle, this method can be executed by any electronic device with computing and processing capabilities. In some embodiments, the key distribution method provided in the embodiments of the present disclosure can be executed by the access network device in the above system architecture; in some other embodiments, the key distribution method provided in the embodiments of the present disclosure can be implemented by the access network device and the core network element of the terrestrial core network in the above system architecture through interaction.

[0076] Figure 4 The flowchart of a key distribution method in an embodiment of the present disclosure is shown as Figure 4 shown, and the method includes the following steps: S402: Receive a non-access stratum message from a terminal, where the non-access stratum message is a signaling message sent by the terminal to the terrestrial core network; S404: Add the access network device identifier of the access network device to the non-access stratum message, and forward the non-access stratum message carrying the access network device identifier to the core network element of the terrestrial core network. The core network element is used to query the shared key for secure communication between the access network device and the terrestrial core network pre-configured according to the access network device identifier carried in the non-access stratum message, and use the shared key to encrypt the access stratum key to be encrypted and transmitted, obtaining the access stratum key in ciphertext form. The access stratum key is the key for secure communication between the access network device and the terminal; S406: Receive the access stratum key in ciphertext form returned by the core network element, and decrypt the access stratum key in ciphertext form to obtain the access stratum key in plaintext form.

[0077] In some embodiments, the access network device in the embodiments of the present disclosure is a terrestrial access network device deployed on a terrestrial infrastructure platform.

[0078] In some embodiments, the terrestrial access network device is a terrestrial base station.

[0079] In other embodiments, the access network device in the embodiments of the present disclosure is a non-terrestrial access network device deployed on a non-terrestrial infrastructure platform.

[0080] In some embodiments, the non-access network device is a spaceborne base station.

[0081] In some embodiments, as Figure 5 shown, after receiving the access layer key in ciphertext form returned by the core network element, the method provided in the embodiments of the present disclosure may further include the following steps: S502, obtain a shared key for secure communication between the pre-configured access network device and the terrestrial core network; S504, use the shared key to decrypt the access layer key in ciphertext form; S506, store the decrypted access layer key so that the access network device uses the access layer key to establish a secure connection for the access layer.

[0082] In some embodiments, as Figure 6 shown, after receiving the access layer key in ciphertext form returned by the core network element, the method provided in the embodiments of the present disclosure may further include the following steps: S602, transmit the access layer key in ciphertext form to the security module. A shared key is stored on the non-terrestrial security module, and the security module is further configured to enable the security module to use the shared key to decrypt the access layer key in ciphertext form and store the decrypted access layer key; S604, obtain the decrypted access layer key from the security module and use the access layer key to establish a secure connection for the access layer.

[0083] It should be noted that when the access network device is a non-terrestrial access network device, the above security module is a non-terrestrial security module carried or deployed on a non-terrestrial infrastructure platform; when the access network device is a terrestrial access network device, the above security module is a terrestrial security module carried or deployed on a terrestrial infrastructure platform.

[0084] In some embodiments, the terrestrial core network is a 5G core network, and the core network element is an access and mobility management function (AMF) network element.

[0085] Figure 7 Shows a key distribution flowchart of a satellite communication system in the embodiments of the present disclosure, as Figure 7As shown in the figure, in this satellite communication system, an on-board security module is carried on the satellite, and a shared key for communicating with the ground core network is preset for encryption and decryption operations. In the AMF network element, a key module and a cryptographic operation module are added. Among them, the key module is used to store the preset upper-layer shared key and the corresponding key identifier between the on-board base station; the cryptographic operation module is used to perform key derivation (KDF) operations, including deriving the key KgNB from the key KAMF, and deriving the keys KNASint and KNASenc from KAMF; encrypting the key KgNB to generate the key ciphertext KgNB*. In specific implementation, the key distribution process of this satellite communication system includes the following steps: S700, a symmetric shared key is preset between the on-board base station and the ground core network, and this shared key is used to encrypt the access layer key transmitted between the ground core network and the on-board base station.

[0086] S702, the satellite terminal sends a registration request message (NAS message) carrying the terminal identifier (such as SUCI or 5G GUTI, etc.) to the on-board base station.

[0087] S702, the on-board base station forwards the registration request message from the satellite terminal to the AMF network element of the ground core network via the gateway station. The on-board base station forwards the registration request message (NAS message) to the gateway station and adds the satellite base station identifier to the message; the gateway station sends the registration request message (NAS message) carrying the satellite base station identifier to the AMF network element of the core network.

[0088] S706, a standard 5G AKA authentication process is completed between the satellite terminal and the core network, and two-way authentication between the satellite terminal and the core network is completed. After the AKA authentication process is executed, the KAMF key derived from the KSEAF key is stored in the AMF network element.

[0089] S708, a NAS security establishment process is executed between the satellite terminal and the AMF network element.

[0090] S710, the AMF network element retrieves the preset shared key according to the satellite base station identifier.

[0091] S712, the AMF network element derives the KgNB key based on the KAMF key, and encrypts the KgNB key using the preset shared key to obtain the key ciphertext KgNB*. The algorithm for encrypting the KgNB key using the shared key is an algorithm supported by both the AMF network element of the core network and the on-board security module, including but not limited to encryption algorithms such as AES.

[0092] S714, the AMF network element sends the key ciphertext KgNB* to the on-board base station through the NGAP message.

[0093] S716. After receiving the key ciphertext, the spaceborne base station forwards it to the spaceborne security module. A shared key between the spaceborne security module and the core network is pre-set.

[0094] S718. The spaceborne security module uses the pre-set shared key to decrypt and obtain the KgNB key, and stores the KgNB key in the spaceborne security module.

[0095] S720. A standard AS SMC (Security Command) process is executed between the satellite terminal and the spaceborne base station. In specific implementation, other keys at the AS layer can be derived based on the KgNB key.

[0096] As can be seen from the above, the existing terrestrial communication standards do not provide a protection scheme for the secure transmission of the base station key KgNB, and cannot cope with the future network security risks of the integration of space, air, and ground. The key distribution method provided in the embodiments of the present disclosure can ensure the secure distribution of the KgNB key between the terrestrial core network and the spaceborne base station, realize the secure and efficient key encryption and transmission between the satellite terminal and the terrestrial core network, and ensure the security of the subsequent RRC and UP planes. This not only improves the security of satellite Internet communication, but also provides a solution for the formulation of 6G-related standards. By encrypting and transmitting the KgNB, the operator can independently control the security of the key distribution on the N2 link. Whether the channel enables IPSEC encryption or a dedicated encryption channel on the satellite, the KgNB is sent in ciphertext form, ensuring the security of the key and the subsequent RRC signaling.

[0097] The key distribution system provided in the embodiments of the present disclosure has a simple structure and a small amount of modification. It only needs to pre-set the key in the AMF network element and complete the encryption operation of the key, without affecting the functions and standard processes of other core network network elements.

[0098] Based on the same inventive concept, an embodiment of a core network device is also provided in the embodiments of the present disclosure as described in the following embodiments. Since the principle of solving problems in this embodiment of the core network device is similar to that of the above method embodiment, the implementation of this embodiment of the core network device can refer to the implementation of the above method embodiment, and the repeated parts will not be described again.

[0099] Figure 8 The schematic diagram of a core network device in the embodiments of the present disclosure is shown, as Figure 8 shown, the core network device includes: a non-terrestrial network communication module 801, a key encryption module 802, and an encrypted key distribution module 803.

[0100] Among them, the non-terrestrial network communication module 801 is used to receive non-access stratum messages forwarded by the access network device. The non-access stratum message is a signaling message sent by the terminal to the terrestrial core network, and the access network device identifier of the access network device is carried in the non-access stratum message. The key encryption module 802 is used to query the pre-configured shared key for secure communication between the access network device and the terrestrial core network according to the access network device identifier carried in the non-access stratum message, and use the shared key to encrypt the access stratum key to be encrypted and transmitted to obtain the access stratum key in ciphertext form. The access stratum key is the key for secure communication between the access network device and the terminal. The encrypted key distribution module 803 is used to send the access stratum key in ciphertext form to the access network device, so that the access network device decrypts the access stratum key in ciphertext form to obtain the access stratum key in plaintext form.

[0101] In some embodiments, the access stratum key in ciphertext form is sent to the access network device through the Next Generation Application Protocol (NGAP) message, where the NGAP message is an interaction message between the terrestrial core network and the access network device.

[0102] In some embodiments, the core network device in the embodiments of the present disclosure may further include: a key generation module 800, which is used to generate the access stratum key to be encrypted and transmitted in response to the completion of the mutual authentication process between the core network element and the terminal.

[0103] In some embodiments, the access network device in the embodiments of the present disclosure is a terrestrial access network device deployed on a terrestrial infrastructure platform.

[0104] In some embodiments, the terrestrial access network device is a terrestrial base station.

[0105] In other embodiments, the access network device in the embodiments of the present disclosure is a non-terrestrial access network device deployed on a non-terrestrial infrastructure platform.

[0106] In some embodiments, the non-access network device is a spaceborne base station.

[0107] In some embodiments, the terrestrial core network is a 5G core network, and the core network element is an Access and Mobility Management Function (AMF) network element.

[0108] Based on the same inventive concept, embodiments of the present disclosure also provide an access network device. The access network device may be a non-terrestrial access network device (such as a satellite-borne base station, etc.) carried or deployed on a non-terrestrial infrastructure platform (such as a satellite, high-altitude platform, etc.), or a terrestrial access network device (such as a terrestrial base station, relay, or access point, etc.) carried or deployed on a terrestrial infrastructure platform, as in the following embodiments. Since the principle of solving problems in the access network device embodiments is similar to that of the above method embodiments, the implementation of the access network device embodiments can refer to the implementation of the above method embodiments, and the repeated parts will not be elaborated.

[0109] Figure 9 Figure 1 shows a schematic diagram of an access network device in an embodiment of the present disclosure, as Figure 9 shown, the device includes: a non-access stratum message receiving module 901, a non-access stratum message forwarding module 902, and a key acquisition module 903.

[0110] Among them, the non-access stratum message receiving module 901 is configured to receive non-access stratum messages from a terminal, where the non-access stratum messages are signaling messages sent by the terminal to the terrestrial core network; the non-access stratum message forwarding module 902 is configured to add an access network device identifier of the access network device to the non-access stratum message and forward the non-access stratum message carrying the access network device identifier to a core network element of the terrestrial core network, where the core network element is configured to query a shared key for secure communication between the access network device and the terrestrial core network pre-configured according to the access network device identifier carried in the non-access stratum message, and use the shared key to encrypt the access stratum key to be encrypted and transmitted to obtain the access stratum key in ciphertext form, and the access stratum key is the key for secure communication between the access network device and the terminal; the key acquisition module 903 is configured to receive the access stratum key in ciphertext form returned by the core network element and decrypt the access stratum key in ciphertext form to obtain the access stratum key in plaintext form.

[0111] In some embodiments, the access network device provided in the embodiments of the present disclosure may further include: a key decryption module 904, configured to obtain the shared key for secure communication between the access network device and the terrestrial core network pre-configured; use the shared key to decrypt the access stratum key in ciphertext form; and store the decrypted access stratum key so that the access network device uses the access stratum key to establish a secure connection at the access stratum.

[0112] In some embodiments, the above-mentioned key decryption module 904 is further configured to: transmit the access layer key in ciphertext form to the non-terrestrial security module, where the non-terrestrial security module stores a shared key, and the non-terrestrial security module is further configured to enable the non-terrestrial security module to use the shared key to decrypt the access layer key in ciphertext form and store the decrypted access layer key; obtain the decrypted access layer key from the non-terrestrial security module and establish a secure connection for the access layer using the access layer key.

[0113] In some embodiments, the access network device in the embodiments of the present disclosure is a terrestrial access network device deployed on a terrestrial infrastructure platform.

[0114] In some embodiments, the terrestrial access network device is a terrestrial base station.

[0115] In other embodiments, the access network device in the embodiments of the present disclosure is a non-terrestrial access network device deployed on a non-terrestrial infrastructure platform.

[0116] In some embodiments, the non-access network device is a spaceborne base station.

[0117] In some embodiments, the terrestrial core network is a 5G core network, and the core network element is an access and mobility management function (AMF) network element.

[0118] It should be noted here that the examples and application scenarios implemented by each module in the above device embodiments are the same as the corresponding steps in the method embodiments, but are not limited to the content disclosed in the above method embodiments. It should be noted that the above modules, as part of the device, can be executed in a computer system such as a set of computer-executable instructions.

[0119] Those skilled in the art can understand that various aspects of the present disclosure can be specifically implemented in the following forms, namely: a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or an implementation combining hardware and software aspects, which can be collectively referred to as "circuit", "module" or "system" here.

[0120] Based on the same inventive concept, an electronic device is further provided in the embodiments of the present disclosure. The electronic device includes: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute the key distribution method of any one of the above via executing the executable instructions. Since the principle of solving problems in the embodiment of this electronic device is similar to that in the above method embodiment, the implementation of the embodiment of this electronic device can refer to the implementation of the above method embodiment, and the repeated parts will not be described again.

[0121] Next, refer to Figure 10 to describe the electronic device 1000 according to this embodiment of the present disclosure. Figure 10The illustrated electronic device 1000 is merely an example and should not impose any limitation on the functions and scope of use of the embodiments of the present disclosure.

[0122] As Figure 10 shown, the electronic device 1000 is presented in the form of a general-purpose computing device. The components of the electronic device 1000 may include, but are not limited to: at least one of the above-mentioned processing units 1010, at least one of the above-mentioned storage units 1020, and a bus 1030 that connects different system components (including the storage unit 1020 and the processing unit 1010).

[0123] Among them, the storage unit stores program code, and the program code can be executed by the processing unit 1010, so that the processing unit 1010 executes the steps according to various exemplary embodiments of the present disclosure described in the above "Exemplary Method" section of this specification. For example, the processing unit 1010 may execute the following steps of the above method embodiment: receiving a non-access stratum message from a terminal, where the non-access stratum message is a signaling message sent by the terminal to the terrestrial core network; adding an access network device identifier of the access network device to the non-access stratum message, and forwarding the non-access stratum message carrying the access network device identifier to a core network element of the terrestrial core network, where the core network element is used to query a pre-configured shared key for secure communication between the access network device and the terrestrial core network according to the access network device identifier carried in the non-access stratum message, and using the shared key to encrypt the access stratum key to be encrypted and transmitted to obtain the access stratum key in ciphertext form, and the access stratum key is the key for secure communication between the access network device and the terminal; receiving the access stratum key in ciphertext form returned by the core network element, and decrypting the access stratum key in ciphertext form to obtain the access stratum key in plaintext form.

[0124] The storage unit 1020 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 10201 and / or a cache storage unit 10202, and may further include a read-only storage unit (ROM) 10203.

[0125] The storage unit 1020 may further include a program / utility 10204 having a set (at least one) of program modules 10205. Such program modules 10205 include, but are not limited to: an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include the implementation of a network environment.

[0126] The bus 1030 may represent one or more of several types of bus structures, including a storage unit bus or a storage unit controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any bus structure in a variety of bus structures.

[0127] The electronic device 1000 can also communicate with one or more external devices 1040 (such as a keyboard, a pointing device, a Bluetooth device, etc.), and can also communicate with one or more devices that enable a user to interact with the electronic device 1000, and / or communicate with any device that enables the electronic device 1000 to communicate with one or more other computing devices (such as a router, a modem, etc.). Such communication can be carried out through the input / output (I / O) interface 1050. Moreover, the electronic device 1000 can also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through the network adapter 1060. As shown in the figure, the network adapter 1060 communicates with other modules of the electronic device 1000 through the bus 1030. It should be understood that although not shown in the figure, other hardware and / or software modules can be used in combination with the electronic device 1000, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0128] Through the description of the above embodiments, those skilled in the art can easily understand that the example embodiments described herein can be implemented by software, or can be implemented by the way of software combined with necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, and the software product can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the embodiments of the present disclosure.

[0129] Based on the same inventive concept, an embodiment of the present disclosure also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the key distribution method of any one of the above. Since the principle of solving problems in the embodiment of this computer-readable storage medium is similar to that of the above method embodiment, the implementation of the embodiment of this computer-readable storage medium can refer to the implementation of the above method embodiment, and the repeated parts will not be described again.

[0130] More specific examples of the computer-readable storage medium in the present disclosure can include but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0131] In the present disclosure, a computer-readable storage medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries readable program code. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the foregoing. The readable signal medium may also be any readable medium other than the readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device.

[0132] Optionally, the program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical fiber cable, RF, etc., or any suitable combination of the foregoing.

[0133] In a specific implementation, the program code for performing the operations of the present disclosure may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computing device, partially on the user's device, executed as a stand-alone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., by using an Internet service provider to connect through the Internet).

[0134] Based on the same inventive concept, embodiments of the present disclosure also provide a computer program product, including: a computer program or instruction, which when executed by a processor implements the key distribution method of any one of the foregoing method embodiments. Since the principle of solving problems in this computer program product embodiment is similar to that of the foregoing method embodiments, the implementation of this computer program product embodiment may refer to the implementation of the foregoing method embodiments, and repeated parts will not be described again.

[0135] It should be noted that although several modules or units of a device for action execution are mentioned in the foregoing detailed description, such a division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more of the foregoing modules or units may be embodied in one module or unit. Conversely, the features and functions of one module or unit described above may be further divided and embodied by multiple modules or units.

[0136] In addition, although the various steps of the methods in the present disclosure are described in a specific order in the drawings, this does not require or imply that the steps must be performed in that specific order, or that all of the steps shown must be performed to achieve the desired result. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution, etc.

[0137] From the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described herein can be implemented by software, or by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (such as a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the methods according to the embodiments of the present disclosure.

[0138] After considering the specification and practicing the invention disclosed herein, those skilled in the art will readily conceive of other embodiments of the present disclosure. The present disclosure is intended to cover any variations, uses, or adaptations of the present disclosure, which follow the general principles of the present disclosure and include known common knowledge or conventional technical means in the technical field not disclosed in the present disclosure. The specification and the embodiments are only regarded as exemplary, and the true scope and spirit of the present disclosure are pointed out by the appended claims.

Claims

1. A key distribution method, characterized in that: Core network elements used in ground core networks include: Receiving a non-access layer message forwarded by an access network device, wherein the non-access layer message is a signaling message sent by a terminal to a terrestrial core network, and the non-access layer message carries an access network device identifier of the access network device; According to the access network device identifier carried in the non-access layer message, query the pre-configured shared key for secure communication between the access network device and the ground core network, and use the shared key to encrypt the access layer key to be encrypted and transmitted to obtain the access layer key in ciphertext form, wherein the access layer key is the key for secure communication between the access network device and the terminal; The access layer key in ciphertext form is sent to the access network device, so that the access network device decrypts the access layer key in ciphertext form to obtain the access layer key in plaintext form.

2. The key distribution method according to claim 1, characterized in that: The access layer key in encrypted form is sent to the access network device via a Next Generation Application Protocol NGAP message, wherein the NGAP message is an interaction message between the ground core network and the access network device.

3. The key distribution method according to claim 1, characterized in that: Before using the shared key to encrypt the access layer key to be transmitted and encrypted to obtain the access layer key in ciphertext form, the method further includes: In response to the completion of the two-way authentication process between the core network element and the terminal, an access layer key to be encrypted for transmission is generated.

4. The key distribution method according to claim 1, characterized in that: The terrestrial core network is a 5G core network, and the core network network element is an access and mobility management function AMF network element.

5. The key distribution method according to any one of claims 1 to 4, characterized in that: The access network equipment is a ground access network equipment deployed on a ground infrastructure platform.

6. The key distribution method according to claim 5, characterized in that: The ground access network equipment is a ground base station.

7. The key distribution method according to any one of claims 1 to 4, characterized in that: The access network device is a non-ground access network device deployed on a non-ground infrastructure platform.

8. The key distribution method according to claim 7, characterized in that: The non-terrestrial access network device is a satellite-borne base station.

9. A key distribution method, characterized in that: Applied to access network equipment, including: Receiving a non-access layer message from a terminal, wherein the non-access layer message is a signaling message sent by the terminal to a terrestrial core network; adding the access network device identifier of the access network device to the non-access layer message, and forwarding the non-access layer message carrying the access network device identifier to the core network network element of the ground core network, wherein the core network network element is used to query the pre-configured shared key for secure communication between the access network device and the ground core network according to the access network device identifier carried in the non-access layer message, and use the shared key to encrypt the access layer key to be encrypted and transmitted to obtain the access layer key in ciphertext form, wherein the access layer key is the key for secure communication between the access network device and the terminal; Receive the access layer key in ciphertext form returned by the core network element, decrypt the access layer key in ciphertext form, and obtain the access layer key in plaintext form.

10. The key distribution method according to claim 9, characterized in that: After receiving the access layer key in ciphertext form returned by the core network element, the method further includes: Obtaining a pre-configured shared key for secure communication between the access network device and the ground core network; Decrypting the access layer key in ciphertext form using the shared key; The decrypted access layer key is stored so that the access network device uses the access layer key to establish a secure connection at the access layer.

11. The key distribution method according to claim 9, characterized in that: After receiving the access layer key in ciphertext form returned by the core network element, the method further includes: transmitting the access layer key in ciphertext form to a security module, wherein the security module stores a shared key, and the security module is further configured to enable the security module to use the shared key to decrypt the access layer key in ciphertext form and store the decrypted access layer key; The decrypted access layer key is obtained from the security module, and a secure connection at the access layer is established using the access layer key.

12. The key distribution method according to claim 9, characterized in that: The terrestrial core network is a 5G core network, and the core network network element is an access and mobility management function AMF network element.

13. The key distribution method according to any one of claims 9 to 12, characterized in that: The access network equipment is a ground access network equipment deployed on a ground infrastructure platform.

14. The key distribution method according to claim 13, characterized in that: The ground access network equipment is a ground base station.

15. The key distribution method according to any one of claims 9 to 12, characterized in that: The access network device is a non-ground access network device deployed on a non-ground infrastructure platform.

16. The key distribution method according to claim 15, characterized in that: The non-terrestrial access network device is a satellite-borne base station.

17. A core network device, characterized in that: include: A non-terrestrial network communication module, configured to receive a non-access layer message forwarded by an access network device, wherein the non-access layer message is a signaling message sent by a terminal to a terrestrial core network, and the non-access layer message carries an access network device identifier of the access network device; a key encryption module, configured to query a pre-configured shared key for secure communication between the access network device and the ground core network according to the access network device identifier carried in the non-access layer message, and use the shared key to encrypt the access layer key to be encrypted and transmitted to obtain an access layer key in ciphertext form, wherein the access layer key is a key for secure communication between the access network device and the terminal; The encryption key distribution module is used to send the access layer key in ciphertext form to the access network device, so that the access network device decrypts the access layer key in ciphertext form to obtain the access layer key in plaintext form.

18. An access network device, characterized in that: include: A non-access layer message receiving module, used to receive a non-access layer message from a terminal, wherein the non-access layer message is a signaling message sent by the terminal to a terrestrial core network; A non-access layer message forwarding module, used for adding the access network device identifier of the access network device to the non-access layer message, and forwarding the non-access layer message carrying the access network device identifier to the core network network element of the ground core network, wherein the core network network element is used for querying the pre-configured shared key for secure communication between the access network device and the ground core network according to the access network device identifier carried in the non-access layer message, and using the shared key to encrypt the access layer key to be encrypted and transmitted to obtain the access layer key in ciphertext form, wherein the access layer key is the key for secure communication between the access network device and the terminal; The key acquisition module is used to receive the access layer key in ciphertext form returned by the core network element, decrypt the access layer key in ciphertext form, and obtain the access layer key in plaintext form.

19. A communication system, characterized in that: include: Access network equipment and terrestrial core network; The ground core network includes: a core network element; The access network device is used to receive a non-access layer message from a terminal, and after adding an access network device identifier to the non-access layer message, forward it to the core network element; The core network network element is used to query the pre-configured shared key for secure communication between the access network device and the ground core network according to the access network device identifier carried in the non-access layer message, use the shared key to encrypt the access layer key to be encrypted for transmission, obtain the access layer key in ciphertext form, and send it to the access network device, so that the access network device decrypts the access layer key in ciphertext form to obtain the access layer key in plaintext form. The access layer key is the key for secure communication between the access network device and the terminal.

20. An electronic device, characterized in that: include: processor; as well as A memory, configured to store executable instructions of the processor; The processor is configured to execute the key distribution method according to any one of claims 1 to 16 by executing the executable instructions.

21. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the key distribution method according to any one of claims 1 to 16 is implemented.

22. A computer program product comprising: A computer program or instruction, characterized in that when the computer program or instruction is executed by a processor, it implements the key distribution method described in any one of claims 1 to 16.

Citation Information

Patent Citations

  • AMF network element redirection method and device, medium and electronic equipment

    CN117062212A

  • Communication method and device

    CN118138100A

  • Communication method and apparatus

    WO2022198671A1

  • Communication method and apparatus

    WO2024114742A1