Key distribution method, communication system and related devices

By using access network device identifiers and shared keys to encrypt the transmission of access layer keys in satellite communications, the security problem of key transmission between the ground core network and satellite base stations in satellite communications is solved, and the secure transmission of access layer keys and the security of communication links are ensured.

CN120201422BActive Publication Date: 2026-01-06CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510346238.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-21
Publication Date
2026-01-06
Estimated Expiration
2045-03-21

AI Technical Summary

Technical Problem

In satellite communications, there are security issues with the transmission of KgNB keys between the ground core network and the satellite base station. Physical isolation and monitoring cannot be effectively implemented, making it difficult to guarantee the security of the communication link.

Method used

By carrying the access network device identifier when transmitting non-access stratum messages between the access network device and the terrestrial core network, and encrypting the access stratum key with a pre-configured shared key to form a ciphertext key, which is then sent by the core network element to the access network device for decryption, the security of the key during transmission is ensured.

Benefits of technology

This improves the security of access layer key transmission between terrestrial core network and non-terrestrial access network equipment, ensuring the security of satellite communications and the integrity of communication links.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120201422B_ABST
    Figure CN120201422B_ABST
Patent Text Reader

Abstract

The disclosure provides a key distribution method, a communication system and related equipment, and relates to the technical field of communication. The method comprises the following steps: a core network element of a ground core network receiving a non-access layer message forwarded by an access network device, wherein the access network device identifier of the access network device is carried in the non-access layer message; querying a pre-configured shared key for secure communication between the access network device and the ground core network according to the access network device identifier carried in the non-access layer message, encrypting an access layer key to be encrypted and transmitted using the shared key to obtain a ciphertext form of the access layer key; and sending the ciphertext form of the access layer key to the access network device, so that the access network device decrypts the ciphertext form of the access layer key to obtain a plaintext form of the access layer key. The disclosure can improve the security of the transmission of the access layer key between the ground core network and the non-ground access network device.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the field of communication technology, and in particular to a key distribution method, a communication system and related devices. BACKGROUND

[0002] In the existing 5G standard, the ground terminal will perform authentication when it first enters the network, and derive UP (User Plane) layer keys and RRC (Radio Resource Control) layer keys for air interface confidentiality and integrity protection, thereby establishing the security mechanism of NAS (Non-Access Stratum) and AS (Access Stratum) to ensure the confidentiality and integrity of air communication. Among them, KgNB key (base station key) is a key key in 5G network, which can derive other keys as the root key of AS layer, such as KUPint (User Plane Integrity Key), KUPenc (User Plane Encryption Key), KRRCint (RRC Integrity Key) and KRRCenc (RRC Encryption Key) and other keys. The non-terminal side source of KgNB key is the AMF (Access and Mobility Management Function) network element of core network.

[0003] In the ground network, the communication between the core network and the base station is often realized through wired connection. Due to the physical isolation characteristics of wired transmission, the security of data transmission is high, and the communication link is relatively controllable. Therefore, the communication security protection measures between the ground core network and the ground base station are relatively simple. The existing 5G standard stipulates that the KgNB key is sent to the base station by the AMF network element through the next generation application protocol (NGAP) message. Although the 5G standard supports using IPSec (Internet Protocol Security) on the N2 interface between the base station and the core network AMF network element for encryption protection, in actual deployment, IPSec is usually not enabled.

[0004] When the base station is assembled on a non-ground carrier such as a satellite, the communication environment has undergone a fundamental change. Since the communication between the satellite-borne base station and the ground core network is realized through a wireless link, the following security problems are caused: 1) The wireless link in satellite communication is exposed in open space, and the attacker can intercept the communication data between the satellite-borne base station and the ground core network within a certain range, thereby obtaining sensitive information; 2) Unlike the wired connection in the ground network, the wireless link in satellite communication cannot be effectively physically isolated and monitored, making it more difficult to guarantee the security of the communication link. In the scenario of a satellite-borne base station (S-gNB), the KgNB key needs to be synchronized between the ground core network and the satellite-borne base station.

[0005] Since the KgNB key is directly related to the security of subsequent communication, it cannot be transmitted in plaintext form between communication entities, and there is an urgent need to provide a key distribution method in a satellite communication scenario, aiming to solve the problem of secure transmission of the KgNB key between the ground core network and the satellite-borne base station, thereby guaranteeing the security of satellite communication.

[0006] It should be noted that the information disclosed in the above background section is only used to strengthen the understanding of the background of the present disclosure, and therefore can include information that does not constitute prior art known to those of ordinary skill in the art. SUMMARY

[0007] The present disclosure provides a key distribution method, a communication system and related equipment, which at least partially solves the technical problem of low security in the related art that the key is transmitted between the ground core network and the non-ground base station.

[0008] Other characteristics and advantages of the present disclosure will become apparent from the following detailed description, or will be learned by practice of the present disclosure.

[0009] According to one aspect of the present disclosure, a key distribution method is provided, applied to a core network element of a ground core network, the method comprising: receiving a non-access stratum message forwarded by an access network device, wherein the non-access stratum message is a signaling message sent by a terminal to the ground core network, and the non-access stratum message carries an access network device identifier of the access network device; querying a pre-configured shared key for secure communication between the access network device and the ground core network according to the access network device identifier carried in the non-access stratum message, encrypting an access stratum key to be encrypted for transmission using the shared key to obtain a ciphertext form of the access stratum key, wherein the access stratum key is a key for secure communication between the access network device and the terminal; and sending the ciphertext form of the access stratum key to the access network device, so that the access network device decrypts the ciphertext form of the access stratum key to obtain a plaintext form of the access stratum key.

[0010] In some embodiments, the encrypted access layer key is sent to the access network device via a Next Generation Application Protocol (NGAP) message, wherein the NGAP message is an interaction message between the terrestrial core network and the access network device.

[0011] In some embodiments, before encrypting the access layer key to be encrypted using the shared key to obtain the ciphertext access layer key, the method further includes: generating the access layer key to be encrypted in response to the completion of the two-way authentication process between the core network element and the terminal.

[0012] In some embodiments, the terrestrial core network is a 5G core network, and the core network element is an Access and Mobility Management Function (AMF) element.

[0013] In some embodiments, the access network device is a terrestrial access network device deployed on a ground infrastructure platform.

[0014] In some embodiments, the terrestrial access network device is a terrestrial base station.

[0015] In some embodiments, the access network device is a non-terrestrial access network device deployed on a non-terrestrial infrastructure platform.

[0016] In some embodiments, the non-access network device is a satellite-based base station.

[0017] According to another aspect of this disclosure, a key distribution method is also provided, applied to an access network device. The method includes: receiving a non-access stratum message from a terminal, wherein the non-access stratum message is a signaling message sent by the terminal to a terrestrial core network; adding an access network device identifier of the access network device to the non-access stratum message, and forwarding the non-access stratum message carrying the access network device identifier to a core network element of the terrestrial core network, wherein the core network element is used to query a pre-configured shared key for secure communication between the access network device and the terrestrial core network based on the access network device identifier carried in the non-access stratum message, and encrypting an access stratum key to be transmitted using the shared key to obtain a ciphertext access stratum key, wherein the access stratum key is the key for secure communication between the access network device and the terminal; receiving the ciphertext access stratum key returned by the core network element, and decrypting the ciphertext access stratum key to obtain a plaintext access stratum key.

[0018] In some embodiments, after receiving the encrypted access layer key returned by the core network element, the method further includes: obtaining a pre-configured shared key for secure communication between the access network device and the terrestrial core network; using the shared key to decrypt the encrypted access layer key; and storing the decrypted access layer key so that the access network device can use the access layer key to establish a secure connection at the access layer.

[0019] In some embodiments, after receiving the encrypted access layer key returned by the core network element, the method further includes: transmitting the encrypted access layer key to a security module, wherein the security module stores a shared key, and the security module is further configured to enable the security module to use the shared key to decrypt the encrypted access layer key and store the decrypted access layer key; obtaining the decrypted access layer key from the security module and using the access layer key to establish a secure connection at the access layer.

[0020] In some embodiments, the terrestrial core network is a 5G core network, and the core network element is an Access and Mobility Management Function (AMF) element.

[0021] In some embodiments, the access network device is a terrestrial access network device deployed on a ground infrastructure platform.

[0022] In some embodiments, the terrestrial access network device is a terrestrial base station.

[0023] In some embodiments, the access network device is a non-terrestrial access network device deployed on a non-terrestrial infrastructure platform.

[0024] In some embodiments, the non-access network device is a satellite-based base station.

[0025] According to another aspect of this disclosure, a core network device is also provided, comprising: a non-terrestrial network communication module, configured to receive a non-access stratum message forwarded by an access network device, wherein the non-access stratum message is a signaling message sent by a terminal to a terrestrial core network, and the non-access stratum message carries an access network device identifier of the access network device; a key encryption module, configured to query a pre-configured shared key for secure communication between the access network device and the terrestrial core network based on the access network device identifier carried in the non-access stratum message, and encrypt an access stratum key to be encrypted using the shared key to obtain an ciphertext access stratum key, wherein the access stratum key is a key for secure communication between the access network device and the terminal; and an encryption key distribution module, configured to send the ciphertext access stratum key to the access network device, so that the access network device can decrypt the ciphertext access stratum key to obtain a plaintext access stratum key.

[0026] According to another aspect of this disclosure, an access network device is also provided, comprising: a non-access stratum message receiving module, configured to receive a non-access stratum message from a terminal, wherein the non-access stratum message is a signaling message sent by the terminal to a terrestrial core network; a non-access stratum message forwarding module, configured to add an access network device identifier of the access network device to the non-access stratum message, and forward the non-access stratum message carrying the access network device identifier to a core network element of the terrestrial core network, wherein the core network element is configured to query a pre-configured shared key for secure communication between the access network device and the terrestrial core network based on the access network device identifier carried in the non-access stratum message, and encrypt an access stratum key to be encrypted using the shared key to obtain an ciphertext access stratum key, wherein the access stratum key is the key for secure communication between the access network device and the terminal; and a key acquisition module, configured to receive the ciphertext access stratum key returned by the core network element, and decrypt the ciphertext access stratum key to obtain a plaintext access stratum key.

[0027] According to another aspect of this disclosure, a communication system is also provided, comprising: an access network device and a terrestrial core network; the terrestrial core network comprising: core network elements; wherein, the access network device is configured to receive non-access stratum messages from a terminal, and after adding an access network device identifier to the non-access stratum messages, forward them to the core network elements; the core network elements are configured to query a pre-configured shared key for secure communication between the access network device and the terrestrial core network based on the access network device identifier carried in the non-access stratum messages, encrypt the access stratum key to be encrypted using the shared key, obtain an ciphertext access stratum key, and send it to the access network device, so that the access network device can decrypt the ciphertext access stratum key to obtain a plaintext access stratum key, wherein the access stratum key is the key for secure communication between the access network device and the terminal.

[0028] According to another aspect of this disclosure, an electronic device is also provided, comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to perform the key distribution method described in any of the preceding claims by executing the executable instructions.

[0029] According to another aspect of this disclosure, a computer-readable storage medium is also provided, on which a computer program is stored, which, when executed by a processor, implements the key distribution method described in any of the preceding claims.

[0030] According to another aspect of this disclosure, a computer program product is also provided, comprising: a computer program or instructions that, when executed by a processor, implement the key distribution method described in any one of the preceding claims.

[0031] The key distribution method, communication system, and related equipment provided in this disclosure embodiment include a key distribution method, a communication system, and related equipment. When an access network device forwards a non-access stratum message from a terminal to a core network element of the terrestrial core network, the access network device carries an access network device identifier in the non-access stratum message. This allows the core network element to query a pre-configured shared key for secure communication between the access network device and the terrestrial core network based on the access network device identifier carried in the non-access stratum message. The core network element then uses this shared key to encrypt the access stratum key to be transmitted, obtaining a ciphertext access stratum key, which is then sent to the access network device. The access network device decrypts the ciphertext access stratum key to obtain a plaintext access stratum key.

[0032] The embodiments disclosed herein can improve the security of access layer key transmission between terrestrial core network and non-terrestrial access network devices.

[0033] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description

[0034] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure. It is obvious that the drawings described below are merely some embodiments of this disclosure, and those skilled in the art can obtain other drawings based on these drawings without any inventive effort.

[0035] Figure 1 This diagram illustrates a communication system architecture according to an embodiment of the present disclosure.

[0036] Figure 2 This diagram illustrates a key distribution method according to an embodiment of the present disclosure.

[0037] Figure 3 This diagram illustrates a flowchart of an access layer key derivation method according to an embodiment of the present disclosure;

[0038] Figure 4 This illustration shows a flowchart of yet another key distribution method in an embodiment of the present disclosure;

[0039] Figure 5 This diagram illustrates a flowchart of an access layer secure connection establishment process according to an embodiment of the present disclosure;

[0040] Figure 6 This diagram illustrates a flowchart of an access layer secure connection establishment process according to an embodiment of the present disclosure;

[0041] Figure 7 This diagram illustrates a key distribution flowchart for a satellite communication system according to an embodiment of the present disclosure.

[0042] Figure 8 This diagram illustrates a core network device according to an embodiment of the present disclosure.

[0043] Figure 9 This diagram illustrates an access network device according to an embodiment of the present disclosure;

[0044] Figure 10 A structural block diagram of an electronic device according to an embodiment of the present disclosure is shown. Detailed Implementation

[0045] Exemplary embodiments will now be described more fully with reference to the accompanying drawings. However, these exemplary embodiments can be implemented in many forms and should not be construed as limited to the examples set forth herein; rather, they are provided so that this disclosure will be more comprehensive and complete, and will fully convey the concept of the exemplary embodiments to those skilled in the art. The described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0046] Furthermore, the accompanying drawings are merely illustrative of this disclosure and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and therefore repeated descriptions of them will be omitted. Some block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor devices and / or microcontroller devices.

[0047] To facilitate understanding, before introducing the embodiments of this disclosure, the following explanations are provided for several terms involved in the embodiments of this disclosure:

[0048] AMF: Access and Mobility Management Function, is a functional entity in the 5G core network responsible for handling user equipment (UE) access and mobility management tasks, such as registration management and connection management.

[0049] AS SMC: Access Security Command, is a command used to manage and execute access layer security operations to ensure the security of user equipment (UE) when accessing the network.

[0050] NGAP: Next Generation Application Protocol, is a protocol used for control plane signaling transmission in 5G systems. It defines the various message types exchanged between the 5G core network and gNB (5G base station).

[0051] KgNB: gNB Key, the base station key, is a crucial key in the 5G system. As the root key, it can generate various other keys to ensure the security and privacy of communication.

[0052] SUCI: Subscription Concealed Identifier, is an identifier used to hide user subscription information and ensure user privacy.

[0053] NAS: Non-Access Stratum, is a protocol layer in 5G systems responsible for handling non-access stratum signaling between the UE and the core network, such as registration, authentication, and session management.

[0054] NAS SMC: Non-Access Stratum Security Mode Command. In mobile communication networks (such as LTE), the Non-Access Stratum (NAS) handles access-independent signaling interactions between the UE (User Equipment) and the core network. The security mode command is an important part of NAS signaling, primarily used to initiate the security mode process between the UE and the network, including security operations such as encryption and integrity protection of signaling and user data.

[0055] AKA: Authentication and Key Agreement, is a protocol used for authentication and key negotiation to ensure the authentication of both communicating parties and the secure exchange of keys.

[0056] KSEAF: Security Anchor Function Key, is a key used for security anchor functions to ensure secure communication between the UE and the core network.

[0057] KAMF: Access and Mobility Management Function Key, is a key used by the AMF functional entity to ensure the security of access and mobility management processes.

[0058] The specific implementation methods of the embodiments of this disclosure will now be described in detail with reference to the accompanying drawings.

[0059] Figure 1 A schematic diagram of a communication system architecture to which the key distribution method of the embodiments of this disclosure can be applied is shown. For example... Figure 1 As shown, the system includes: access network equipment (non-terrestrial access network equipment 20 or terrestrial access network equipment 50) and terrestrial core network 10; the terrestrial core network 10 includes: core network element 101.

[0060] The access network device (non-terrestrial access network device 20 or terrestrial access network device 50) is connected to the terminal 30 and the terrestrial core network 10, respectively. It is used to receive non-access stratum messages from the terminal 30, add the access network device identifier to the non-access stratum message, and forward it to the core network element 101 in the terrestrial core network 10. The core network element 101 queries the pre-configured shared key for secure communication between the access network device and the terrestrial core network based on the access network device identifier carried in the non-access stratum message. It uses the shared key to encrypt the access stratum key to be transmitted, obtains the ciphertext access stratum key, and sends it to the access network device (non-terrestrial access network device 20 or terrestrial access network device 50) so that the access network device (non-terrestrial access network device 20 or terrestrial access network device 50) can decrypt the ciphertext access stratum key to obtain the plaintext access stratum key. The access stratum key is the key for secure communication between the access network device (non-terrestrial access network device 20 or terrestrial access network device 50) and the terminal 30.

[0061] It should be noted that the ground gateway station 40 is a critical infrastructure in non-terrestrial communication systems (such as satellite communication systems), responsible for establishing data links between non-terrestrial networks (such as satellite networks) and terrestrial networks (such as the Internet, mobile communication networks, etc.), realizing signal relay, protocol conversion, and data exchange. In this embodiment, the non-terrestrial access network device 20 refers to access network equipment (such as satellite-borne base stations) mounted or deployed on a non-terrestrial infrastructure platform (such as a satellite, high-altitude platform, etc.), responsible for establishing communication connections with the terminal 30 and forwarding relevant signaling / data. The non-terrestrial access network device 20 needs to communicate with the terrestrial core network 10 through the ground gateway station 40.

[0062] In this embodiment of the disclosure, the terrestrial network access network device 50 refers to an access network device (such as a terrestrial base station, relay, or access point) mounted or deployed on a terrestrial infrastructure platform, which is responsible for establishing a communication connection with the terminal 30 and forwarding relevant signaling / data.

[0063] In this embodiment of the disclosure, the terrestrial core network refers to a core network deployed on the ground, and its core network elements (which may also be referred to as "functional entities") may be, but are not limited to, AMF network elements. In some other embodiments, the terrestrial core network 10 may also include SMF network elements and other core network elements.

[0064] In some embodiments, when the access network device is a base station, the base station can be a base station of any communication standard, such as a new radio base station (gNB) in a fifth-generation mobile communication (5G) system, a 6G base station in a sixth-generation mobile communication system, and an evolved Node base station (eNB) in a Long Term Evolution (LTE) system. It is worth emphasizing that the technical solution described in this disclosure does not limit the physical form or communication standard of the access network device; it is applicable to various base station devices defined by current standards and is also compatible with future evolving base station architectures.

[0065] Accordingly, Figure 1 The terrestrial core network shown can be any type of communication core network, such as a 5G core network or a 6G core network.

[0066] Optionally, the terminal 30 in this embodiment can also be referred to as UE (User Equipment). In specific implementation, the terminal 30 can be a mobile phone, tablet computer, laptop computer, personal digital assistant (PDA), mobile internet device (MID), wearable device, or vehicle-mounted device, etc. It should be noted that the specific type of terminal 30 is not limited in this embodiment of the invention.

[0067] Those skilled in the art will know that Figure 1 The number of terminals, non-terrestrial access network equipment, terrestrial gateway stations, terrestrial access network equipment, and core network elements shown in this disclosure is merely illustrative. Depending on actual needs, any number of terminals, non-terrestrial access network equipment, terrestrial gateway stations, terrestrial access network equipment, and core network elements can be included. This disclosure does not limit the number of these components.

[0068] Under the above system architecture, this disclosure provides a key distribution method, which, in principle, can be executed by any electronic device with computing capabilities. In some embodiments, the key distribution method provided in this disclosure can be executed by the core network elements of the terrestrial core network in the above system architecture; in other embodiments, the key distribution method provided in this disclosure can be implemented by the core network elements of the terrestrial core network and access network devices (non-terrestrial access network devices or terrestrial access network devices) in the above system architecture through interaction.

[0069] Figure 2 A flowchart of a key distribution method according to an embodiment of this disclosure is shown, such as Figure 2 As shown, the method includes the following steps:

[0070] S202, Receive a non-access stratum message forwarded by the access network device. The non-access stratum message is a signaling message sent by the terminal to the terrestrial core network. The non-access stratum message carries the access network device identifier of the access network device.

[0071] In this embodiment of the disclosure, Non-Access Stratum (NAS) messages refer to signaling messages that are directly exchanged between the terminal and the core network, including but not limited to terminal registration messages or network handover messages. The access network device identifier can be any character or number information that can uniquely identify the access network device; this embodiment of the disclosure does not limit the specific form of the access network device identifier.

[0072] Normally, for non-access stratum messages sent directly from a terminal to the core network, the access network device only forwards them without performing any processing. In this embodiment, when forwarding non-access stratum messages from a terminal to the terrestrial core network, the access network device adds its own access network device identifier to the non-access stratum message. This allows the terrestrial core network to query a pre-configured shared key used for secure communication between the access network device and the terrestrial core network based on the access network device identifier. The access stratum key used for secure communication between the access network device and the terminal is then encrypted, enabling secure transmission of the access stratum key.

[0073] S204. Based on the access network device identifier carried in the non-access stratum message, query the pre-configured shared key for secure communication between the access network device and the terrestrial core network, and use the shared key to encrypt the access stratum key to be transmitted to obtain the ciphertext access stratum key. The access stratum key is the key for secure communication between the access network device and the terminal.

[0074] It should be noted that the access layer key in this embodiment can be any key used for secure communication between the access network device and the terminal, and can be, but is not limited to, the root key used by the access layer to derive other keys. For example, in one embodiment, when the non-terrestrial access network device is a satellite-based base station, the access layer key to be encrypted in S204 above is the KgNB key (base station key), which can be used to derive, but is not limited to, keys such as KUPint (User Plane Integrity Key), KUPenc (User Plane Encryption Key), KRRCint (RRC Integrity Key), and KRRCenc (RRC Encryption Key).

[0075] S206, the encrypted access layer key is sent to the access network device so that the access network device can decrypt the encrypted access layer key to obtain the plaintext access layer key.

[0076] In this embodiment, the access layer key is sent to the access network device in encrypted form by the terrestrial core network. This avoids the security risks associated with transmitting the access layer key in plaintext between the terrestrial core network and the access network device. Upon receiving the encrypted access layer key, the access network device decrypts it using a pre-configured shared key for secure communication between the access network device and the terrestrial core network, obtaining the plaintext access layer key. Furthermore, non-access network devices can derive other access layer keys using the decrypted access layer key.

[0077] For non-terrestrial access network devices (such as spaceborne base stations) that are mounted or deployed on non-terrestrial infrastructure platforms, they communicate with the terrestrial core network via wireless links, which has low security. Therefore, the key distribution method provided in this disclosure ensures the security of the access layer key (such as the KgNB key) transmission by transmitting the access layer key (such as the KgNB key) between the non-terrestrial access network device and the terrestrial core network in encrypted form.

[0078] For terrestrial access network equipment (such as terrestrial base stations) mounted or deployed on terrestrial infrastructure platforms, they communicate with the terrestrial core network via wired links, which provides high security. However, for some scenarios with high security communication requirements (such as high-security networks in specific industries), it may be necessary for the terrestrial base station and the terrestrial core network to securely protect the access layer key. Therefore, the key distribution method provided in this disclosure is applied to the transmission of keys between the terrestrial base station and the core network, so that the access layer key transmitted between the terrestrial base station and the core network is encrypted, which can ensure the security of the transmission of the access layer key (such as the KgNB key).

[0079] In some embodiments, in S206 above, the access layer key in encrypted form can be sent to the access network device via a Next Generation Application Protocol (NGAP) message, wherein the NGAP message is an interaction message between the terrestrial core network and the access network device.

[0080] In some embodiments, before encrypting the access layer key to be encrypted using a shared key to obtain the ciphertext form of the access layer key, such as Figure 3 As shown, the method provided in this embodiment can also obtain the access layer key to be encrypted through the following steps:

[0081] S200, in response to the completion of the two-way authentication process between the core network element and the terminal, generates an access layer key to be encrypted for transmission.

[0082] In some embodiments of this disclosure, the access network device is a terrestrial access network device deployed on a ground infrastructure platform.

[0083] In some embodiments, the terrestrial access network equipment is a terrestrial base station.

[0084] In other embodiments, the access network device in this disclosure is a non-terrestrial access network device deployed on a non-terrestrial infrastructure platform.

[0085] In some embodiments, the non-access network device is a satellite-based base station.

[0086] In some embodiments of this disclosure, the terrestrial core network is a 5G core network, and the core network element is an Access and Mobility Management Function (AMF) element.

[0087] Based on the same inventive concept, this disclosure also provides a key distribution method, which, in principle, can be executed by any electronic device with computing capabilities. In some embodiments, the key distribution method provided in this disclosure can be executed by the access network device in the above-described system architecture; in other embodiments, the key distribution method provided in this disclosure can be implemented by the access network device in the above-described system architecture interacting with the core network elements of the terrestrial core network.

[0088] Figure 4 A flowchart of a key distribution method according to an embodiment of this disclosure is shown, such as Figure 4 As shown, the method includes the following steps:

[0089] S402, Receive non-access stratum messages from the terminal, wherein the non-access stratum messages are signaling messages sent by the terminal to the ground core network;

[0090] S404, add the access network device identifier of the access network device to the non-access stratum message, and forward the non-access stratum message carrying the access network device identifier to the core network element of the ground core network. The core network element is used to query the pre-configured shared key for secure communication between the access network device and the ground core network based on the access network device identifier carried in the non-access stratum message, and use the shared key to encrypt the access stratum key to be transmitted to obtain the ciphertext access stratum key. The access stratum key is the key for secure communication between the access network device and the terminal.

[0091] S406: Receive the ciphertext access layer key returned by the core network element, decrypt the ciphertext access layer key to obtain the plaintext access layer key.

[0092] In some embodiments of this disclosure, the access network device is a terrestrial access network device deployed on a ground infrastructure platform.

[0093] In some embodiments, the terrestrial access network equipment is a terrestrial base station.

[0094] In other embodiments, the access network device in this disclosure is a non-terrestrial access network device deployed on a non-terrestrial infrastructure platform.

[0095] In some embodiments, the non-access network device is a satellite-based base station.

[0096] In some embodiments, such as Figure 5 As shown, after receiving the encrypted access layer key returned by the core network element, the method provided in this embodiment may further include the following steps:

[0097] S502, obtain the pre-configured shared key for secure communication between the access network device and the terrestrial core network;

[0098] S504, using a shared key to decrypt the encrypted access layer key;

[0099] S506 stores the decrypted access layer key so that access network devices can use the access layer key to establish a secure connection at the access layer.

[0100] In some embodiments, such as Figure 6 As shown, after receiving the encrypted access layer key returned by the core network element, the method provided in this embodiment may further include the following steps:

[0101] S602, transmits the encrypted access layer key to the security module, wherein the non-terrestrial security module stores a shared key, and the security module is also used to enable the security module to use the shared key to decrypt the encrypted access layer key and store the decrypted access layer key.

[0102] S604: Obtain the decrypted access layer key from the security module and use the access layer key to establish a secure connection at the access layer.

[0103] It should be noted that when the access network device is not a terrestrial access network device, the above-mentioned security module is a non-terrestrial security module mounted or deployed on a non-terrestrial infrastructure platform; when the access network device is a terrestrial access network device, the above-mentioned security module is a terrestrial security module mounted or deployed on a terrestrial infrastructure platform.

[0104] In some embodiments, the terrestrial core network is a 5G core network, and the core network elements are Access and Mobility Management Function (AMF) network elements.

[0105] Figure 7 This invention discloses a key distribution flowchart of a satellite communication system according to an embodiment of the present disclosure, as shown below. Figure 7As shown, this satellite communication system carries an onboard security module that pre-configures a shared key for communication with the ground core network for encryption and decryption operations. Within the AMF network element, a key module and a cryptographic operation module are added. The key module stores the pre-configured upper-level shared key and its corresponding key identifier with the onboard base station. The cryptographic operation module performs key derivation (KDF) operations, including deriving the key KgNB from the key KAMF, and deriving the keys KNASint and KNASenc from KAMF; encrypting the key KgNB to generate the ciphertext KgNB*. In specific implementation, the key distribution process of this satellite communication system includes the following steps:

[0106] The S700 uses a pre-set symmetric shared key between the satellite-based base station and the ground core network. This shared key is used to encrypt the access layer key transmitted between the ground core network and the satellite-based base station.

[0107] S702, the satellite terminal sends a registration request message (NAS message) carrying the terminal identifier (SUCI or 5G GUTI, etc.) to the satellite base station.

[0108] In S702, the satellite-based base station forwards the registration request message from the satellite terminal to the AMF network element of the ground core network via the gateway station. The satellite-based base station forwards the registration request message (NAS message) to the gateway station and adds the satellite base station identifier to the message. The gateway station then sends the registration request message (NAS message) carrying the satellite base station identifier to the AMF network element of the core network.

[0109] S706, the satellite terminal and the core network complete the standard 5G AKA authentication process, and complete the two-way authentication between the satellite terminal and the core network. After the AKA authentication process is completed, the AMF network element stores the KAMF key derived from the KSEAF key.

[0110] S708, the satellite terminal and AMF network element perform the NAS security establishment process.

[0111] In the S710, the AMF network element retrieves the pre-set shared key based on the satellite base station identifier.

[0112] In S712, the AMF network element derives the KgNB key based on the KAMF key, and encrypts the KgNB key using a preset shared key to obtain the ciphertext KgNB*. The algorithm used to encrypt the KgNB key using the shared key is an algorithm supported by both the AMF network element in the core network and the onboard security module, including but not limited to encryption algorithms such as AES.

[0113] S714, the AMF network element sends the key ciphertext KgNB* to the satellite base station via NGAP message.

[0114] In the S716, after receiving the encrypted key, the onboard base station forwards it to the onboard security module. The onboard security module has a pre-configured shared key with the core network.

[0115] S718, the onboard security module uses a pre-set shared key to decrypt and obtain the KgNB key, and stores the KgNB key in the onboard security module.

[0116] The S720 satellite terminal and the onboard base station execute the standard AS SMC (Security Command) procedure. In specific implementations, other keys at the AS layer can be derived from the key KgNB.

[0117] As can be seen from the above, existing terrestrial communication standards do not provide a protection scheme for the secure transmission of base station keys (KgNB), and cannot cope with the network security risks of future integrated air-space-ground communication. The key distribution method provided in this disclosure can ensure the secure distribution of KgNB keys between the terrestrial core network and the satellite base station, realizing secure and efficient key encryption and transmission between the satellite terminal and the terrestrial core network, and ensuring the security of subsequent RRC and UP planes. This not only improves the security of satellite internet communication, but also provides a solution for the formulation of 6G-related standards. By encrypting the transmission of KgNB, operators can control the security of key distribution on the N2 link. Regardless of whether IPSEC encryption or a dedicated on-board encryption channel is enabled, KgNB is sent in encrypted form, ensuring the security of the key and subsequent RRC signaling.

[0118] The key distribution system provided in this embodiment is simple in structure and requires little modification. It only requires presetting the key in the AMF network element and completing the key encryption operation, without affecting the functions and standard processes of other core network elements.

[0119] Based on the same inventive concept, this disclosure also provides a core network device, as described in the following embodiments. Since the principle by which this core network device embodiment solves the problem is similar to that of the above method embodiments, the implementation of this core network device embodiment can refer to the implementation of the above method embodiments, and repeated details will not be elaborated further.

[0120] Figure 8 This diagram illustrates a core network device according to an embodiment of the present disclosure, such as... Figure 8 As shown, the core network equipment includes: a non-terrestrial network communication module 801, a key encryption module 802, and an encryption key distribution module 803.

[0121] The non-terrestrial network communication module 801 is used to receive non-access stratum messages forwarded by the access network device. The non-access stratum message is a signaling message sent by the terminal to the terrestrial core network, and the non-access stratum message carries the access network device identifier of the access network device. The key encryption module 802 is used to query the pre-configured shared key for secure communication between the access network device and the terrestrial core network based on the access network device identifier carried in the non-access stratum message, and use the shared key to encrypt the access stratum key to be transmitted to obtain the ciphertext access stratum key. The access stratum key is the key for secure communication between the access network device and the terminal. The encryption key distribution module 803 is used to send the ciphertext access stratum key to the access network device so that the access network device can decrypt the ciphertext access stratum key to obtain the plaintext access stratum key.

[0122] In some embodiments, the access layer key in encrypted form is sent to the access network device via Next Generation Application Protocol (NGAP) messages, wherein the NGAP message is an interaction message between the terrestrial core network and the access network device.

[0123] In some embodiments of the present disclosure, the core network device may further include: a key generation module 800, used to generate an access layer key to be encrypted for transmission in response to the completion of the two-way authentication process between the core network element and the terminal.

[0124] In some embodiments of this disclosure, the access network device is a terrestrial access network device deployed on a ground infrastructure platform.

[0125] In some embodiments, the terrestrial access network equipment is a terrestrial base station.

[0126] In other embodiments, the access network device in this disclosure is a non-terrestrial access network device deployed on a non-terrestrial infrastructure platform.

[0127] In some embodiments, the non-access network device is a satellite-based base station.

[0128] In some embodiments, the terrestrial core network is a 5G core network, and the core network elements are Access and Mobility Management Function (AMF) network elements.

[0129] Based on the same inventive concept, this disclosure also provides an access network device. This access network device can be a non-terrestrial access network device (such as a satellite-borne base station) mounted or deployed on a non-terrestrial infrastructure platform (such as a satellite, high-altitude platform, etc.), or a terrestrial access network device (such as a terrestrial base station, relay, or access point, etc.) mounted or deployed on a terrestrial infrastructure platform, as shown in the following embodiments. Since the principle by which this access network device embodiment solves the problem is similar to that of the above method embodiments, the implementation of this access network device embodiment can refer to the implementation of the above method embodiments, and repeated details will not be elaborated further.

[0130] Figure 9 This diagram illustrates an access network device according to an embodiment of the present disclosure, such as... Figure 9 As shown, the device includes: a non-access stratum message receiving module 901, a non-access stratum message forwarding module 902, and a key acquisition module 903.

[0131] The non-access stratum message receiving module 901 is used to receive non-access stratum messages from the terminal, wherein the non-access stratum messages are signaling messages sent by the terminal to the ground core network; the non-access stratum message forwarding module 902 is used to add the access network device identifier of the access network device to the non-access stratum message, and forward the non-access stratum message carrying the access network device identifier to the core network element of the ground core network, wherein the core network element is used to query the pre-configured shared key for secure communication between the access network device and the ground core network based on the access network device identifier carried in the non-access stratum message, and uses the shared key to encrypt the access stratum key to be transmitted, to obtain the ciphertext access stratum key, which is the key for secure communication between the access network device and the terminal; the key acquisition module 903 is used to receive the ciphertext access stratum key returned by the core network element, and decrypt the ciphertext access stratum key to obtain the plaintext access stratum key.

[0132] In some embodiments, the access network device provided in this disclosure may further include: a key decryption module 904, configured to obtain a pre-configured shared key for secure communication between the access network device and the terrestrial core network; use the shared key to decrypt the encrypted access layer key; and store the decrypted access layer key so that the access network device can use the access layer key to establish a secure connection at the access layer.

[0133] In some embodiments, the key decryption module 904 is further configured to: transmit the ciphertext access layer key to the non-terrestrial security module, wherein the non-terrestrial security module stores a shared key, and the non-terrestrial security module is further configured to enable the non-terrestrial security module to use the shared key to decrypt the ciphertext access layer key and store the decrypted access layer key; obtain the decrypted access layer key from the non-terrestrial security module and use the access layer key to establish a secure connection of the access layer.

[0134] In some embodiments of this disclosure, the access network device is a terrestrial access network device deployed on a ground infrastructure platform.

[0135] In some embodiments, the terrestrial access network equipment is a terrestrial base station.

[0136] In other embodiments, the access network device in this disclosure is a non-terrestrial access network device deployed on a non-terrestrial infrastructure platform.

[0137] In some embodiments, the non-access network device is a satellite-based base station.

[0138] In some embodiments, the terrestrial core network is a 5G core network, and the core network elements are Access and Mobility Management Function (AMF) network elements.

[0139] It should be noted that the examples and application scenarios implemented by the modules in the above device embodiments and the corresponding steps in the method embodiments are the same, but are not limited to the content disclosed in the above method embodiments. It should also be noted that the above modules, as part of the device, can be executed in a computer system such as a set of computer-executable instructions.

[0140] Those skilled in the art will understand that various aspects of this disclosure can be implemented in the following forms: a completely hardware implementation, a completely software implementation (including firmware, microcode, etc.), or a combination of hardware and software implementations, which can be collectively referred to herein as a "circuit", "module" or "system".

[0141] Based on the same inventive concept, this disclosure also provides an electronic device, which includes: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute the key distribution method described above by executing the executable instructions. Since the principle by which this electronic device solves the problem is similar to that of the above method embodiments, the implementation of this electronic device embodiment can refer to the implementation of the above method embodiments, and repeated details will not be described again.

[0142] The following reference Figure 10 To describe an electronic device 1000 according to such an embodiment of the present disclosure. Figure 10The electronic device 1000 shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments disclosed herein.

[0143] like Figure 10 As shown, the electronic device 1000 is manifested in the form of a general-purpose computing device. The components of the electronic device 1000 may include, but are not limited to: at least one processing unit 1010, at least one storage unit 1020, and a bus 1030 connecting different system components (including storage unit 1020 and processing unit 1010).

[0144] The storage unit stores program code that can be executed by the processing unit 1010, causing the processing unit 1010 to perform the steps described in the "Exemplary Methods" section of this specification according to various exemplary embodiments of this disclosure. For example, the processing unit 1010 can perform the following steps of the above method embodiment: receiving a non-access stratum message from a terminal, wherein the non-access stratum message is a signaling message sent by the terminal to the ground core network; adding an access network device identifier of the access network device to the non-access stratum message, and forwarding the non-access stratum message carrying the access network device identifier to a core network element of the ground core network, wherein the core network element is used to query a pre-configured shared key for secure communication between the access network device and the ground core network based on the access network device identifier carried in the non-access stratum message, and encrypt the access stratum key to be encrypted using the shared key to obtain an ciphertext access stratum key, wherein the access stratum key is the key for secure communication between the access network device and the terminal; receiving the ciphertext access stratum key returned by the core network element, and decrypting the ciphertext access stratum key to obtain a plaintext access stratum key.

[0145] Storage unit 1020 may include readable media in the form of volatile storage units, such as random access memory (RAM) 10201 and / or cache memory 10202, and may further include read-only memory (ROM) 10203.

[0146] Storage unit 1020 may also include a program / utility 10204 having a set (at least one) program module 10205, such program module 10205 including but not limited to: operating system, one or more application programs, other program modules and program data, each or some combination of these examples may include an implementation of a network environment.

[0147] Bus 1030 can represent one or more of several types of bus structures, including a memory cell bus or memory cell controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any of the multiple bus structures.

[0148] Electronic device 1000 can also communicate with one or more external devices 1040 (e.g., keyboard, pointing device, Bluetooth device, etc.), one or more devices that enable a user to interact with electronic device 1000, and / or any device that enables electronic device 1000 to communicate with one or more other computing devices (e.g., router, modem, etc.). This communication can be performed via input / output (I / O) interface 1050. Furthermore, electronic device 1000 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 1060. As shown, network adapter 1060 communicates with other modules of electronic device 1000 via bus 1030. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with electronic device 1000, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0149] From the above description of the embodiments, those skilled in the art will readily understand that the exemplary embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solutions according to the embodiments of this disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, external hard drive, etc.) or on a network, including several instructions to cause a computing device (such as a personal computer, server, terminal device, or network device, etc.) to execute the methods according to the embodiments of this disclosure.

[0150] Based on the same inventive concept, this disclosure also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements any of the above-described key distribution methods. Since the principle by which this computer-readable storage medium embodiment solves the problem is similar to that of the above-described method embodiments, the implementation of this computer-readable storage medium embodiment can refer to the implementation of the above-described method embodiments, and repeated details will not be elaborated further.

[0151] More specific examples of computer-readable storage media in this disclosure may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0152] In this disclosure, a computer-readable storage medium may include a data signal propagated in baseband or as part of a carrier wave, carrying readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium, capable of transmitting, propagating, or transmitting a program for use by or in connection with an instruction execution system, apparatus, or device.

[0153] Optionally, the program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.

[0154] In practical implementation, program code for performing the operations of this disclosure can be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java and C++, and conventional procedural programming languages ​​such as C or similar languages. The program code can execute entirely on the user's computing device, partially on the user's device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0155] Based on the same inventive concept, this disclosure also provides a computer program product, including a computer program or instructions, which, when executed by a processor, implements the key distribution method of any one of the above method embodiments. Since the principle by which this computer program product embodiment solves the problem is similar to that of the above method embodiments, the implementation of this computer program product embodiment can refer to the implementation of the above method embodiments, and repeated details will not be elaborated further.

[0156] It should be noted that although several modules or units for the device used to perform actions have been mentioned in the detailed description above, this division is not mandatory. In fact, according to embodiments of this disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.

[0157] Furthermore, although the steps of the method in this disclosure are described in a specific order in the accompanying drawings, this does not require or imply that the steps must be performed in that specific order, or that all the steps shown must be performed to achieve the desired result. Additional or alternative steps may be omitted, multiple steps may be combined into one step, and / or a step may be broken down into multiple steps.

[0158] From the above description of the embodiments, those skilled in the art will readily understand that the exemplary embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solutions according to the embodiments of this disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, external hard drive, etc.) or on a network, including several instructions to cause a computing device (such as a personal computer, server, mobile terminal, or network device, etc.) to execute the methods according to the embodiments of this disclosure.

[0159] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the appended claims.

Claims

1. A key distribution method characterized by comprising: A core network element applied to a ground core network, comprising: receiving a non-access stratum message forwarded by an access network device, wherein the non-access stratum message is a signaling message sent by a terminal to a ground core network, and the non-access stratum message carries an access network device identifier of the access network device; querying a pre-configured shared key for secure communication between the access network device and the ground core network according to the access network device identifier carried in the non-access stratum message, encrypting an access stratum key to be encrypted and transmitted using the shared key to obtain a ciphertext form of the access stratum key, wherein the access stratum key is a key for secure communication between the access network device and the terminal; sending the ciphertext form of the access stratum key to the access network device, so that the access network device decrypts the ciphertext form of the access stratum key to obtain a plaintext form of the access stratum key.

2. The key distribution method according to claim 1, wherein, sending the ciphertext form of the access stratum key to the access network device through a next generation application protocol (NGAP) message, wherein the NGAP message is an interactive message between the ground core network and the access network device.

3. The key distribution method according to claim 1, wherein, Before encrypting the access stratum key to be encrypted and transmitted using the shared key to obtain the ciphertext form of the access stratum key, the method further comprises: generating the access stratum key to be encrypted and transmitted in response to completion of a two-way authentication process between the core network element and the terminal.

4. The key distribution method according to claim 1, wherein, The ground core network is a 5G core network, and the core network element is an access and mobility management function (AMF) network element.

5. The key distribution method according to any one of claims 1 to 4, characterized by, The access network device is a ground access network device deployed on a ground infrastructure platform.

6. The key distribution method according to claim 5, wherein, The ground access network device is a ground base station.

7. The key distribution method according to any one of claims 1 to 4, wherein, The access network device is a non-ground access network device deployed on a non-ground infrastructure platform.

8. The key distribution method according to claim 7, wherein, The non-ground access network device is a spaceborne base station.

9. A key distribution method characterized by comprising: An access network device, comprising: receiving a non-access stratum message from a terminal, wherein the non-access stratum message is a signaling message sent by the terminal to a ground core network; adding an access network device identifier of the access network device in the non-access stratum message, and forwarding the non-access stratum message carrying the access network device identifier to a core network element of the ground core network, wherein the core network element is configured to query a pre-configured shared key for secure communication between the access network device and the ground core network according to the access network device identifier carried in the non-access stratum message, and encrypt an access stratum key to be encrypted and transmitted using the shared key to obtain a ciphertext form of the access stratum key, wherein the access stratum key is a key for secure communication between the access network device and the terminal; receiving the ciphertext form of the access stratum key returned by the core network element, and decrypting the ciphertext form of the access stratum key to obtain a plaintext form of the access stratum key.

10. The key distribution method according to claim 9, wherein, After receiving the ciphertext form of the access stratum key returned by the core network element, the method further comprises: obtaining the pre-configured shared key for secure communication between the access network device and the ground core network; decrypting the ciphertext form of the access stratum key using the shared key; store the decrypted access layer key, so that the access network device uses the access layer key to establish a secure connection of an access layer.

11. The key distribution method according to claim 9, wherein, After receiving the access layer key in the form of ciphertext returned by the core network element, the method further comprises: transmitting the access layer key in the form of ciphertext to a security module, wherein the security module stores a shared key, and the security module is further configured to decrypt the access layer key in the form of ciphertext using the shared key, and store the decrypted access layer key; obtaining the decrypted access layer key from the security module, and using the access layer key to establish a secure connection of an access layer.

12. The key distribution method according to claim 9, wherein, The ground core network is a 5G core network, and the core network element is an access and mobility management function (AMF) element.

13. The key distribution method according to any one of claims 9 to 12, characterized by, The access network device is a ground access network device deployed on a ground infrastructure platform.

14. The key distribution method according to claim 13, wherein, The ground access network device is a ground base station.

15. The key distribution method according to any one of claims 9 to 12, wherein, The access network device is a non-ground access network device deployed on a non-ground infrastructure platform.

16. The key distribution method according to claim 15, wherein, The non-ground access network device is a spaceborne base station.

17. A core network device, comprising: Comprise: a non-ground network communication module configured to receive a non-access layer message forwarded by an access network device, wherein the non-access layer message is a signaling message sent by a terminal to a ground core network, and the non-access layer message carries an access network device identifier of the access network device; a key encryption module configured to query a pre-configured shared key for secure communication between the access network device and the ground core network according to the access network device identifier carried in the non-access layer message, encrypt an access layer key to be encrypted and transmitted using the shared key, and obtain an access layer key in the form of ciphertext, wherein the access layer key is a key for secure communication between the access network device and the terminal; an encrypted key distribution module configured to send the access layer key in the form of ciphertext to the access network device, so that the access network device decrypts the access layer key in the form of ciphertext and obtains an access layer key in the form of plaintext.

18. An access network device, comprising: Comprise: a non-access layer message receiving module configured to receive a non-access layer message from a terminal, wherein the non-access layer message is a signaling message sent by the terminal to a ground core network; a non-access layer message forwarding module configured to add an access network device identifier of the access network device in the non-access layer message, and forward the non-access layer message carrying the access network device identifier to a core network element of the ground core network, wherein the core network element is configured to query a pre-configured shared key for secure communication between the access network device and the ground core network according to the access network device identifier carried in the non-access layer message, and encrypt an access layer key to be encrypted and transmitted using the shared key, to obtain an access layer key in the form of ciphertext, wherein the access layer key is a key for secure communication between the access network device and the terminal; a key obtaining module configured to receive the access layer key in the form of ciphertext returned by the core network element, and decrypt the access layer key in the form of ciphertext to obtain an access layer key in the form of plaintext.

19. A communication system, characterized by Comprise: an access network device and a ground core network; The ground core network comprises a core network element; The access network device is configured to receive a non-access layer message from a terminal, and forward the non-access layer message to the core network element after adding an access network device identifier in the non-access layer message; The core network element is configured to query a pre-configured shared key for secure communication between the access network device and the ground core network according to the access network device identifier carried in the non-access layer message, encrypt an access layer key to be encrypted and transmitted using the shared key to obtain a ciphertext form of the access layer key, and send the ciphertext form of the access layer key to the access network device, so that the access network device decrypts the ciphertext form of the access layer key to obtain a plaintext form of the access layer key, the access layer key being a key for secure communication between the access network device and the terminal.

20. An electronic device, comprising: comprise: a processor; and a memory configured to store executable instructions of the processor; wherein the processor is configured to perform the key distribution method of any one of claims 1 to 16 via execution of the executable instructions.

21. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the key distribution method of any one of claims 1 to 16.

22. A computer program product, comprising: Computer programs or instructions, characterized in that the computer programs or instructions are executed by the processor to implement the key distribution method of any one of claims 1 to 16.

Citation Information

Patent Citations

  • AMF network element redirection method and device, medium and electronic equipment

    CN117062212A

  • Communication method and device

    CN118138100A