Terminal access authentication system and method for space-ground integrated network

By carrying satellite-borne base stations and AMF network elements, and using the hash chain and 5G standard process authentication methods, the authentication delay and high computing complexity caused by the interruption of feed links in the world-wide integrated network are solved, and fast and secure terminal authentication and attack protection are achieved.

CN120302287APending Publication Date: 2025-07-11BEIJING UNIV OF POSTS & TELECOMM
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510540184.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-27
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

In the integrated world network, the existing authentication mechanism has high latency in the state of interrupted feed links, resulting in authentication failure and high computational complexity, which cannot effectively prevent malicious terminal attacks and affect network security.

Method used

By carrying satellite-borne base stations and satellite-borne AMF network elements, pre-authentication of terminal identity is realized, hash chains are generated and hash functions are used for authentication, and combined with 5G standard processes, pre-authentication and formal authentication are completed to avoid the impact of interruption of feed links.

Benefits of technology

Effectively prevent DoS attacks when the feed link is unavailable, ensure the rapid completion of terminal authentication and network security, reduce computing complexity, and be compatible with existing standard authentication mechanisms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120302287A_ABST
    Figure CN120302287A_ABST
Patent Text Reader

Abstract

The invention discloses a terminal access authentication system and method for a space-ground integrated network. The system comprises a terminal, a satellite, a gateway station and a ground core network, the satellite carries a satellite-borne base station and a satellite-borne AMF network element; the terminal is used for initializing access authentication, creating a pre-authentication request under the condition that the initialization is finished, and sending the pre-authentication request to the satellite; the satellite is used for pre-authenticating the terminal identity carried by the received pre-authentication request through the satellite-borne AMF network element to obtain a pre-authentication response, and sending the pre-authentication response to the terminal; the terminal is also used for verifying the satellite identity information carried by the received pre-authentication response, creating a formal authentication request under the condition that the satellite identity information passes verification, and sending the formal authentication request to the satellite; and the satellite is also used for storing the request message carried by the received formal authentication request under the condition that the feed link is not available. By adopting the method and the device, the DoS attack risk caused by a large number of access requests sent by a malicious terminal can be effectively prevented in the unavailable state of the feed link.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and particularly to a terminal access authentication system and method for a space-ground integrated network. Background Art

[0002] With the continuous development of communication technologies, the space-ground integrated network, as a new network architecture that integrates terrestrial mobile communication networks and space-based satellite networks, has gradually become an important means to achieve global seamless coverage and ubiquitous connection. In scenarios where terrestrial networks are difficult to cover, such as remote areas, the ocean, and aviation, the space-ground integrated network can provide reliable communication services for users.

[0003] In terrestrial mobile communication networks, when a terminal (UE) accesses the network, it usually completes the mutual authentication with the network using the authentication and key agreement protocol (AKA) defined by the 3GPP standard, thereby establishing trust between the terminal and the network. The working process of this mechanism is as follows: The terrestrial core network generates an authentication vector based on preset algorithms and parameters, and forwards it to the UE via the terrestrial base station; after receiving the authentication vector, the UE verifies the identity of the network, generates an authentication response, and sends it back to the core network, which verifies the correctness of the response, thereby completing the user's identity authentication. However, due to the long space-ground link, the delay of the authentication process is relatively high. When applying the existing traditional authentication mechanism directly to the space-ground integrated network, especially in the state of a feeder link interruption, the authentication process may not be completed completely or may take a long time to complete, resulting in terminal authentication failure. Authentication failure provides an opportunity for illegal users, who may carry out malicious behaviors such as impersonating user identities and tampering with information. Moreover, in the case of a feeder link interruption, if the satellite does not have an authentication function, when a malicious terminal launches a denial-of-service attack (DoS), a large number of false access requests will occupy the satellite storage space and further consume the computing resources of the core network after the link is restored, causing a bad impact on the entire network.

[0004] In addition, in the space-ground integrated network, existing solutions mostly use the public key cryptosystem to authenticate the terminal identity, which will introduce a relatively high computational complexity in the authentication process and cannot be well compatible with the existing standard authentication mechanism. Summary of the Invention

[0005] Embodiments of this application provide a terminal access authentication system for a space-ground integrated network. To provide a basic understanding of some aspects of the disclosed embodiments, a simple summary is given below. This summary part is not a general review, nor is it intended to identify key / important constituent elements or delineate the protection scope of these embodiments. Its sole purpose is to present some concepts in a simple form as a preamble to the subsequent detailed description.

[0006] In a first aspect, an embodiment of the present application provides a terminal access authentication system for a space-ground integrated network. The system includes:

[0007] A terminal, a satellite, and a ground core network; the terminal and the satellite communicate through a service link, and the satellite and the ground core network communicate through a feeder link; wherein,

[0008] The satellite is equipped with an on-board base station and an on-board AMF network element. The on-board base station is used to implement the base station communication function, and the on-board AMF network element is used to implement the AMF network element function of the ground core network;

[0009] The terminal is used to initialize access authentication. When the initialization is completed, a pre-authentication request is created and sent to the satellite;

[0010] The satellite is used to pre-authenticate the terminal identity carried in the received pre-authentication request through the on-board AMF network element, obtain a pre-authentication response, and send it to the terminal;

[0011] The terminal is further used to verify the satellite identity information carried in the received pre-authentication response. When the satellite identity information is verified, a formal authentication request is created and sent to the satellite;

[0012] The satellite is further used to store the request message carried in the received formal authentication request when the feeder link is unavailable; or send the formal authentication request to the ground core network when the feeder link is available for terminal access authentication of the space-ground integrated network.

[0013] Optionally, initializing access authentication includes:

[0014] Transmitting the subscription hidden identifier of the terminal to the ground core network;

[0015] Selecting an initial seed value and a one-way hash function;

[0016] Generating a hash chain based on the initial seed value;

[0017] Transmitting the initial seed value and the one-way hash function to the UDM network element of the ground core network so that the UDM network element generates a hash chain based on the initial seed value and stores it in the ground core network;

[0018] Synchronizing the anchor value of the hash chain to the on-board AMF network element;

[0019] Transmitting the terminal identity to the ground core network and sharing a secret key.

[0020] Optionally, creating a pre-authentication request includes:

[0021] Obtaining the current first timestamp;

[0022] Calculate a first message authentication code using a hash function based on the anchor value of the hash chain, the known satellite identity information, and the first timestamp;

[0023] Mask the next adjacent hash value on the hash chain using the anchor value of the hash chain to obtain a first ciphertext;

[0024] Include the subscription hidden identifier, the first message authentication code, the first ciphertext, and the first timestamp in an attach request message in the non-access stratum to obtain a pre-authentication request.

[0025] Optionally, perform pre-authentication on the terminal identity carried in the received pre-authentication request to obtain a pre-authentication response, including:

[0026] When it is checked that the timestamp in the pre-authentication request meets the preset conditions, query the corresponding pre-stored anchor value locally from the on-board AMF network element based on the terminal identity carried in the pre-authentication request;

[0027] Calculate an expected second message authentication code to be received using a hash function with the pre-stored anchor value, satellite identity information, and the first timestamp carried in the pre-authentication request;

[0028] Compare whether the second message authentication code is consistent with the first message authentication code carried in the pre-authentication request. If they are consistent, decrypt the first ciphertext carried in the pre-authentication request to obtain the next adjacent hash value;

[0029] Verify whether the next adjacent hash value and the pre-stored anchor value are adjacent hash values through hash operation;

[0030] If so, calculate a third message authentication code at the satellite side based on the next adjacent hash value, satellite identity information, and the second timestamp;

[0031] Combine the third message authentication code and the current second timestamp into a pre-authentication response and send it to the terminal.

[0032] Optionally, verify the satellite identity information carried in the received pre-authentication response. When the satellite identity information is verified successfully, create a formal authentication request, including:

[0033] Calculate an expected fourth message authentication code to be received according to the next adjacent hash value to the anchor value of the hash chain, satellite identity information, and the second timestamp carried in the pre-authentication response;

[0034] Compare whether the second message authentication code carried in the pre-authentication response is consistent with the fourth message authentication code. If they are consistent, calculate a fifth message authentication code for formal authentication according to the shared key, random number, next adjacent hash value, and terminal serial number;

[0035] Calculate a new key based on the shared key, random number, combined with the 5G standard authentication process;

[0036] Calculate a hiding flag for hiding the terminal serial number based on the terminal serial number and the new key;

[0037] Assemble the hiding flag and the fifth message authentication code for formal authentication into an authentication token;

[0038] Generate an expected response value according to the local key, random number, and satellite identity information, and store the expected response value locally;

[0039] Encapsulate the local subscription hiding identifier, authentication token, and random number into a formal authentication request.

[0040] Optionally, the system further includes:

[0041] The ground core network is used to verify whether the terminal identity is legal according to the received formal authentication request. If it is legal, generate an authentication response value; generate an anchor key based on the 5G key derivation process, encrypt the anchor key and the authentication response value through symmetric encryption to obtain a second ciphertext, and send it to the satellite;

[0042] The satellite is further used to obtain the anchor key from the received second ciphertext for key derivation, obtain the response value to be matched, obtain the final authentication response, and send it to the terminal;

[0043] The terminal is further used to verify the home network identity based on the received final authentication response.

[0044] Optionally, verifying whether the terminal identity is legal according to the received formal authentication request and generating an authentication response value if it is legal includes:

[0045] Calculate a new key based on the shared key, random number, and in combination with the 5G standard authentication process;

[0046] Perform an exclusive OR operation on the hiding flag in the authentication token carried in the formal authentication request and the new key to obtain the received terminal serial number;

[0047] Calculate the sixth message authentication code according to the received terminal serial number, shared key, random number, and the next hash value adjacent to the anchor value of the hash chain;

[0048] Compare whether the sixth message authentication code is the same as the fifth message authentication code in the authentication token in the formal authentication request. If they are the same, calculate the authentication response value according to the shared key, random number, and satellite identity information.

[0049] Optionally, obtaining the anchor key from the received second ciphertext for key derivation and obtaining the response value to be matched includes:

[0050] Decrypt the received second ciphertext using the symmetric key to obtain the decrypted anchor key;

[0051] Derive the key at the AMF using the decrypted anchor key;

[0052] Use the derived key at the AMF to encrypt the authentication response value in the received second ciphertext again to obtain the response value to be matched.

[0053] Optionally, verify the home network identity based on the received final authentication response, including:

[0054] Process the received final authentication response based on the 5G key hierarchy to derive the AMF key;

[0055] Use the derived AMF key to decrypt the authentication response value carried in the final authentication response to obtain the response value to be matched;

[0056] Compare whether the response value to be matched is consistent with the expected response value stored locally. If they are consistent, the home network identity authentication passes.

[0057] In a second aspect, a terminal access authentication method for a space-ground integrated network, the method includes:

[0058] The terminal initializes access authentication. When the initialization ends, a pre-authentication request is created and sent to the satellite;

[0059] The satellite pre-authenticates the terminal identity carried in the received pre-authentication request through the on-board AMF network element, obtains a pre-authentication response, and sends it to the terminal;

[0060] The terminal verifies the satellite identity information carried in the received pre-authentication response. If the satellite identity information is verified successfully, a formal authentication request is created and sent to the satellite;

[0061] When the feeder link is unavailable, the satellite stores the request message carried in the received formal authentication request; or when the feeder link is available, the satellite sends the formal authentication request to the ground core network for terminal access authentication of the space-ground integrated network.

[0062] In the embodiments of the present application, on the one hand, the satellite is equipped with an on-board base station and an on-board AMF network element, so that the base station communication function and the AMF network element function of the ground core network are deployed down to the satellite. By pre-authenticating the terminal identity at the AMF network element on the satellite, in the state where the feeder link is unavailable, the pre-authentication can effectively prevent the risk of DoS attacks caused by malicious terminals launching a large number of access requests. On the other hand, sinking the AMF network element function of the ground core network to the satellite side can facilitate non-access stratum security negotiation to avoid the interruption of the NAS security mode command transmission process in the state where the feeder link is unavailable.

[0063] It should be understood that the above general description and the following detailed description are merely exemplary and explanatory, and do not limit this application. BRIEF DESCRIPTION OF THE DRAWINGS

[0064] The drawings herein are incorporated into and constitute a part of this specification, showing embodiments consistent with this application, and are used together with the specification to explain the principles of this application.

[0065] Figure 1 is a schematic structural diagram of a terminal access authentication system for a space-ground integrated network provided by an embodiment of this application;

[0066] Figure 2 is a schematic process block diagram of a terminal access process for a space-ground integrated network provided by an embodiment of this application;

[0067] Figure 3 is a schematic flow diagram of a terminal access authentication method for a space-ground integrated network provided by an embodiment of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0068] The following description and the drawings fully illustrate the specific embodiments of this application, enabling those skilled in the art to practice them.

[0069] It should be clear that the described embodiments are only some embodiments of this application, not all of them. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts belong to the scope of protection of this application.

[0070] When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. On the contrary, they are merely examples of systems and methods consistent with some aspects of this application as detailed in the appended claims.

[0071] In the description of this application, it should be understood that terms such as "first", "second", etc. are only used for descriptive purposes and cannot be construed as indicating or implying relative importance. For those of ordinary skill in the art, the specific meanings of the above terms in this application can be understood according to specific circumstances. In addition, in the description of this application, unless otherwise specified, "a plurality" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after.

[0072] Please refer to Figure 1 ,Figure 1 It is a schematic structural diagram of a terminal access authentication system for a space-ground integrated network provided by an embodiment of the present application. The system includes: a terminal, a satellite, a gateway station, and a terrestrial core network; the terminal and the satellite communicate through a service link, and the satellite and the terrestrial core network communicate through a feeder link; the satellite is equipped with an on-board base station and an on-board AMF network element. The on-board base station is used to implement the base station communication function, and the on-board AMF network element is used to implement the AMF network element function of the terrestrial core network; the gateway station only has the function of forwarding data between space and ground; the terrestrial core network has the functions of calculating authentication parameters and authentication results and performing primary authentication on the terminal identity.

[0073] Among them, the terminal (UE, User Equipment) refers to user equipment, such as a smart phone, a tablet computer, a laptop computer, or other mobile devices that can access the network. The satellite refers to an artificial satellite operating in space, which can carry various devices, such as communication devices, for realizing communication between space and ground. The terrestrial core network is the central part of the terrestrial mobile communication network, responsible for processing functions such as data transmission, user authentication, and charging. The Access and Mobility Management Function (AMF) network element is a key function in the 5G core network, undertaking the access and mobility management functions. The service link refers to the communication link between the terminal and the satellite, used to provide user services, such as voice calls, data transmission, etc. The feeder link refers to the communication link between the satellite and the terrestrial core network, used to transmit control signals, data, and instructions to support the operation and maintenance of the satellite.

[0074] In the embodiment of the present application, the terminal is used to initialize access authentication. When the initialization is completed, a pre-authentication request is created and sent to the satellite; the satellite is used to perform pre-authentication on the terminal identity carried in the received pre-authentication request through the on-board AMF network element, obtain a pre-authentication response, and send it to the terminal; the terminal is also used to verify the satellite identity information carried in the received pre-authentication response. When the satellite identity information is verified, a formal authentication request is created and sent to the satellite; the satellite is also used to store the request message carried in the received formal authentication request when the feeder link is unavailable; or send the formal authentication request to the terrestrial core network when the feeder link is available, for terminal access authentication of the space-ground integrated network.

[0075] Specifically, the initialization access authentication process specifically includes: transmitting the subscription concealed identifier of the terminal to the terrestrial core network; selecting an initial seed value and a one-way hash function; generating a hash chain based on the initial seed value; transmitting the initial seed value and the one-way hash function to the UDM network element of the terrestrial core network so that the UDM network element generates a hash chain based on the initial seed value and stores it in the terrestrial core network; synchronizing the anchor value of the hash chain to the on-board AMF network element; transmitting the terminal identity to the terrestrial core network and sharing a secret key.

[0076] For example, before the authentication starts, the terminal has completed the initialization phase of the authentication according to the steps in the 3GPP 5G standard authentication process, that is, the transmission of the subscription concealed identifier (SUCI) of the terminal has been completed between the terminal and the unified data management network element (UDM) of the core network.

[0077] This application introduces the hash chain technology and completes the identity authentication based on the operation of the hash function and the link relationship of the hash values. Therefore, in the initialization phase, the terminal needs to select an initial seed value Seed and one-way hash functions f6 and f7, and generate a hash chain based on the initial seed value:

[0078] H0 = Seed, H1 = f6(H0), H2 = f6(H1), ……, H n = f6(H n-1 );

[0079] where H n is the anchor value of the hash chain. In the initialization process, the Seed value and the hash function f6 also need to be transmitted to the core network UDM network element, and the UDM network element can generate a corresponding hash chain based on the seed value. In addition, to complete the user pre-authentication on the satellite, the anchor value H n needs to be securely synchronized to the on-board AMF network element. The known satellite identity information SAT ID has also been sent to the terrestrial core network in the initialization phase. To protect the legality of the feeder link message, there is a shared secret key K Sat between the satellite and the terrestrial core network. The setting of the remaining parameters refers to the 5G AKA standard.

[0080] Specifically, the specific process for the terminal to create a pre-authentication request includes: obtaining the current first timestamp; calculating the first message authentication code using the hash function based on the anchor value of the hash chain, the known satellite identity information, and the first timestamp; masking the next adjacent hash value on the hash chain with the anchor value of the hash chain to obtain the first ciphertext; including the subscription concealed identifier, the first message authentication code, the first ciphertext, and the first timestamp in the non-access stratum attachment request message to obtain the pre-authentication request.

[0081] For example Figure 2 , the terminal UE generates the current first timestamp T1, and calculates the first message authentication code based on the anchor value H of the local hash chain n and the known satellite identity information SAT ID Calculate the first message authentication code

[0082] MAC1 = f7(H n ||SAT ID ||T1)(1), and then uses the current anchor value H n to mask the next adjacent hash value H on the hash chain n-1 to generate the first ciphertext Include the above parameters in the attach request message of the non-access stratum {SUCI, MAC1, C1, T1} to obtain a pre-authentication request, and forward it to the satellite

[0083] Specifically, the specific process of pre-authenticating the terminal identity carried in the received pre-authentication request to obtain a pre-authentication response includes: when it is checked that the timestamp in the pre-authentication request meets the preset conditions, the on-board AMF network element queries the corresponding pre-stored anchor value locally based on the terminal identity carried in the pre-authentication request; uses the pre-stored anchor value, satellite identity information, and the first timestamp carried in the pre-authentication request, and uses a hash function to calculate the expected second message authentication code to be received; compares whether the second message authentication code is consistent with the first message authentication code carried in the pre-authentication request. If they are consistent, decrypt the first ciphertext carried in the pre-authentication request to obtain the next adjacent hash value; verify whether the next adjacent hash value and the pre-stored anchor value are adjacent hash values through a hash operation; if so, calculate the third message authentication code at the satellite side based on the next adjacent hash value, satellite identity information, and the second timestamp; combine the third message authentication code and the current second timestamp into a pre-authentication response and send it to the terminal

[0084] For example Figure 2 As shown, after the satellite receives the pre-authentication request, the satellite first checks the freshness of the timestamp to prevent message replay. Then, the AMF network element queries the corresponding pre-stored anchor value H n locally based on the terminal identity carried in the pre-authentication request, combines the first timestamp T1 carried in the pre-authentication request and the known satellite identity information SAT ID , calculates the expected second message authentication code xMAC1 = f7(H n ||SAT ID ||T1), and compares whether the first message authentication code MAC1 carried in the pre-authentication request is consistent with the second message authentication code xMAC1 based on the equation If they are consistent, decrypt the first ciphertext C1 carried in the pre-authentication request to obtain the next hash value and through a hash operation Verify whether they are adjacent hash values on the hash chain. If so, based on the next adjacent hash value H n-1 , satellite identity information SAT ID and the current second timestamp T2, calculate the third message authentication code MAC on the satellite side based on this adjacent hash value Sat = f7(H (n-1) ||SAT ID ||T2), attach the third message authentication code MAC sat and the current second timestamp T2 as the response to obtain the pre-authentication response {MAC sat , T2}, and send it to the terminal UE.

[0085] Specifically, verify the satellite identity information carried in the received pre-authentication response. In the case where the satellite identity information verification passes, the specific process of creating a formal authentication request includes: calculating the expected fourth message authentication code according to the next hash value adjacent to the anchor value of the hash chain, satellite identity information, and the second timestamp carried in the pre-authentication response; comparing whether the second message authentication code carried in the pre-authentication response is consistent with the fourth message authentication code. If so, calculate the fifth message authentication code for formal authentication according to the shared key, random number, next adjacent hash value, and terminal serial number; calculate a new key based on the shared key, random number, and in combination with the 5G standard authentication process; calculate a hiding mark for hiding the terminal serial number based on the terminal serial number and the new key; assemble the hiding mark and the fifth message authentication code for formal authentication into an authentication token; generate an expected response value according to the local key, random number, and satellite identity information, and store the expected response value locally; encapsulate the local subscription hiding identifier, authentication token, and random number into a formal authentication request.

[0086] For example Figure 2 as shown, after the terminal receives the pre-authentication response {MAC sat , T2}, the terminal UE calculates the expected fourth message authentication code xMAC n-1 according to the next hash value H ID adjacent to the anchor value of the hash chain, satellite identity information SAT Sat and the second timestamp T2 carried in the pre-authentication response, where xMAC (n-1) = f7(H ID ||SAT sat ||T2), and compares whether the third message authentication code MAC sat in the pre-authentication response is consistent with the fourth message authentication code xMAC n-1 . If the comparison is consistent, according to the shared key K, random number Rand, next adjacent hash value H UE and terminal serial number SQNCalculate the fifth message authentication code MAC2 for formal authentication = f1(K, SQN UE , Rand, H (n-1) ), calculate the new key AK and the hiding tag CONC for hiding the terminal serial number based on the shared key K, random number Rand, and in combination with the 5G standard authentication process, and assemble the hiding tag CONC and the fifth message authentication code MAC2 into the authentication token AUTN; according to the local key K, random number Rand, and satellite identity information SAT ID , generate the expected response value XRES = Challenge(K, Rand, SAT ID ), and store the expected response value. Package the local subscription hiding identifier SUCI, authentication token AUTN, and random number Rand as a formal authentication request.

[0087] The above process is stage 1 of the communication between the terminal and the satellite when the feeder link is unavailable. The overall process can be referred to in Figure 2 Processes 1, 2, and 3 therein.

[0088] In some embodiments of the present application, the terrestrial core network is used to verify whether the terminal identity is legal according to the received formal authentication request, and generate an authentication response value in the case of being legal; generate an anchor key based on the 5G key derivation process, encrypt the anchor key and the authentication response value through symmetric encryption to obtain the second ciphertext, and send it to the satellite; the satellite is further used to obtain the anchor key from the received second ciphertext for key derivation to obtain the response value to be matched, obtain the final authentication response, and send it to the terminal; the terminal is further used to verify the home network identity based on the received final authentication response.

[0089] Specifically, the specific process of verifying whether the terminal identity is legal according to the received formal authentication request and generating an authentication response value in the case of being legal includes: calculating a new key based on the shared key and random number in combination with the 5G standard authentication process; performing an exclusive OR operation on the hiding tag in the authentication token carried in the formal authentication request and the new key to obtain the received terminal serial number; calculating the sixth message authentication code according to the received terminal serial number, shared key, random number, and the next hash value adjacent to the anchor value of the hash chain; comparing whether the sixth message authentication code is consistent with the fifth message authentication code in the authentication token in the formal authentication request, and if consistent, calculating the authentication response value according to the shared key, random number, and satellite identity information.

[0090] For example Figure 2 as shown, the terrestrial core network calculates the new key AK based on the shared key K and random number Rand, and performs an exclusive OR operation on the hiding tag xCONC in the authentication token carried in the formal authentication request and the new key AK to obtain the terminal serial number xSQN UE. Based on the terminal serial number xSQN UE , shared key K, random number Rand, and the next hash value H adjacent to the anchor value of the hash chain n-1 Calculate the sixth message authentication code xMAC2 = f1(K, xSQN UE , Rand, H (n-1) ) and compare it with the fifth message authentication code MAC2 in the authentication token in the received formal authentication request In addition, since the duration of the unavailable state of the power supply link is uncertain, to prevent message replay, it is also necessary to judge the size relationship of the serial numbers included in the message. If the terminal serial number is greater than the home network serial number, the authentication of the terminal is completed. If the terminal authentication is successful, calculate the authentication response value RES = Challenge(K, Rand, SAT ID ). The home network generates the anchor key K based on the 5G key derivation process SEAF , and encrypts the anchor key and the authentication response value through symmetric encryption and sends them to the satellite

[0091] Specifically, the specific process of obtaining the anchor key from the received second ciphertext for key derivation to obtain the response value to be matched includes: decrypting the received second ciphertext using the symmetric key to obtain the decrypted anchor key; deriving the key at the AMF using the decrypted anchor key; using the derived key at the AMF to encrypt the authentication response value in the received second ciphertext again to obtain the response value to be matched

[0092] For example Figure 2 As shown, the on-board AMF network element decrypts using the symmetric key K Sat to obtain the anchor key, and derives the key K at the AMF based on the 5G key hierarchy AMF . Use this key to encrypt the authentication response value again to obtain the response value to be matched RES · , and send it to the terminal UE

[0093] Specifically, the specific process of verifying the identity of the home network based on the received final authentication response includes: processing the received final authentication response based on the 5G key hierarchy to derive the AMF key; decrypting the authentication response value carried in the final authentication response using the derived AMF key to obtain the response value to be matched; comparing whether the response value to be matched is consistent with the expected response value stored locally. If they are consistent, the authentication of the home network is passed

[0094] For example Figure 2 As shown, the satellite sends the response value RES to be matched · to the UE, and the UE derives K based on the 5G key hierarchy AMF , and then decrypts to obtain the authentication response value Compare it with the expected response value xRES stored locally in the first stage, that is If the comparison is successful, the authentication of the home network is completed. So far, the authentication and authorization process between the UE and the network has been completed. After that, the UE can negotiate the NAS security capabilities with the on-board AMF network element, and perform key derivation based on the key hierarchy to protect the integrity and confidentiality of NAS messages.

[0095] In the embodiment of the present application, on the one hand, the satellite is equipped with an on-board base station and an on-board AMF network element, so that the base station communication function and the AMF network element function of the ground core network are deployed down to the satellite. By pre-authenticating the terminal identity at the on-board AMF network element of the satellite, in the state where the feeder link is unavailable, the pre-authentication can effectively prevent the risk of DoS attacks caused by malicious terminals launching a large number of access requests. On the other hand, sinking the AMF network element function of the ground core network to the satellite side can facilitate non-access layer security negotiation to avoid the interruption of the NAS security mode command transmission process in the state where the feeder link is unavailable.

[0096] Please refer to Figure 3 , which is a schematic flowchart of a terminal access authentication method for a space-ground integrated network provided by an embodiment of the present application. As Figure 3 shown, the detection method of the embodiment of the present application may include the following steps:

[0097] S101, the terminal initializes access authentication. When the initialization ends, a pre-authentication request is created and sent to the satellite;

[0098] S102, the satellite pre-authenticates the terminal identity carried in the received pre-authentication request through the on-board AMF network element, obtains a pre-authentication response, and sends it to the terminal;

[0099] S103, the terminal verifies the satellite identity information carried in the received pre-authentication response. If the satellite identity information is verified, a formal authentication request is created and sent to the satellite;

[0100] S104, when the feeder link is unavailable, the satellite stores the request message carried in the received formal authentication request; or when the feeder link is available, the satellite sends the formal authentication request to the ground core network for terminal access authentication of the space-ground integrated network.

[0101] In the embodiments of the present application, on the one hand, the satellite is equipped with an on-board base station and an on-board AMF network element, enabling the sinking deployment of the base station communication function and the AMF network element function of the ground core network to the satellite. By pre-authenticating the terminal identity at the AMF network element on the satellite, in the state where the power supply link is unavailable, the pre-authentication can effectively prevent the risk of DoS attacks caused by malicious terminals launching a large number of access requests. On the other hand, sinking the AMF network element function of the ground core network to the satellite side can facilitate non-access stratum security negotiation to avoid the interruption of the NAS security mode command transfer process in the state where the power supply link is unavailable.

[0102] The present application also provides a computer-readable medium, on which program instructions are stored. When the program instructions are executed by a processor, the terminal access authentication method for the space-ground integrated network provided by each of the above method embodiments is implemented.

[0103] The present application also provides a computer program product containing instructions. When it runs on a computer, it enables the computer to execute the terminal access authentication method for the space-ground integrated network provided by each of the above method embodiments.

[0104] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The program for terminal access authentication for the space-ground integrated network can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, the storage medium for the program for terminal access authentication for the space-ground integrated network can be a magnetic disk, an optical disk, a read-only memory, or a random access memory, etc.

[0105] The above-disclosed are only the preferred embodiments of the present application. Of course, the scope of the rights of the present application cannot be limited thereby. Therefore, equivalent changes made according to the claims of the present application still fall within the scope covered by the present application.

Claims

1. A terminal access authentication system for the space-ground integrated network, characterized in that, The system includes: a terminal, a satellite, and a terrestrial core network; the terminal and the satellite communicate through a service link, and the satellite and the terrestrial core network communicate through a feeder link; wherein, The satellite is equipped with an on-board base station and an on-board AMF network element. The on-board base station is used to implement the base station communication function, and the on-board AMF network element is used to implement the AMF network element function of the terrestrial core network; The terminal is used to initialize access authentication. When the initialization is completed, a pre-authentication request is created and sent to the satellite; The satellite is used to pre-authenticate the terminal identity carried in the received pre-authentication request through the on-board AMF network element, obtain a pre-authentication response, and send it to the terminal; The terminal is further used to verify the satellite identity information carried in the received pre-authentication response. When the satellite identity information is verified, a formal authentication request is created and sent to the satellite; The satellite is further used to store the request message carried in the received formal authentication request when the feeder link is unavailable; or send the formal authentication request to the terrestrial core network when the feeder link is available, for terminal access authentication in the space-ground integrated network.

2. The system according to claim 1, wherein The initialization access authentication includes: Transmitting the subscription hidden identifier of the terminal to the terrestrial core network; Selecting an initial seed value and a one-way hash function; Generating a hash chain based on the initial seed value; Transmitting the initial seed value and the one-way hash function to the UDM network element of the terrestrial core network, so that the UDM network element generates a hash chain based on the initial seed value and stores it in the terrestrial core network; Synchronizing the anchor value of the hash chain to the on-board AMF network element; Transmitting the terminal identity to the terrestrial core network and sharing a secret key.

3. The system according to claim 2, wherein The creation of the pre-authentication request includes: Obtaining the current first timestamp; Calculating a first message authentication code using the hash function based on the anchor value of the hash chain, the known satellite identity information, and the first timestamp; Masking the next adjacent hash value on the hash chain with the anchor value of the hash chain to obtain a first ciphertext; Including the subscription hidden identifier, the first message authentication code, the first ciphertext, and the first timestamp in an attachment request message in the non-access stratum to obtain a pre-authentication request.

4. The system according to claim 2, wherein The pre-authentication of the terminal identity carried in the received pre-authentication request to obtain a pre-authentication response includes: When it is checked that the timestamp in the pre-authentication request meets the preset condition, querying the corresponding pre-stored anchor value locally through the on-board AMF network element based on the terminal identity carried in the pre-authentication request; Calculating the expected received second message authentication code using the hash function with the pre-stored anchor value, satellite identity information, and the first timestamp carried in the pre-authentication request; Comparing whether the second message authentication code is consistent with the first message authentication code carried in the pre-authentication request. If they are consistent, decrypting the first ciphertext carried in the pre-authentication request to obtain the next adjacent hash value; Verifying whether the next adjacent hash value and the pre-stored anchor value are adjacent hash values through hash operation; If so, calculate the third message authentication code at the satellite end based on the adjacent next hash value, the satellite identity information, and the second timestamp; Combine the third message authentication code and the current second timestamp into a pre - authentication response, and send it to the terminal.

5. The system according to claim 2, wherein Verify the satellite identity information carried in the received pre - authentication response. If the satellite identity information verification passes, create a formal authentication request, including: Calculate the expected fourth message authentication code according to the next hash value adjacent to the anchor value of the hash chain, satellite identity information, and the second timestamp carried in the pre - authentication response; Compare whether the second message authentication code carried in the pre - authentication response is the same as the fourth message authentication code. If so, calculate the fifth message authentication code for formal authentication according to the shared key, random number, adjacent next hash value, and terminal serial number; Based on the shared key and random number, calculate a new key in combination with the 5G standard authentication process; Based on the terminal serial number and the new key, calculate a hidden mark for hiding the terminal serial number; Assemble the hidden mark and the fifth message authentication code for formal authentication into an authentication token; Generate an expected response value according to the local key, random number, and satellite identity information, and store the expected response value locally; Encapsulate the local subscription hidden identifier, the authentication token, and the random number into a formal authentication request.

6. The system according to any one of claims 1-5, characterized in that, The system further includes: The ground core network is used to verify whether the terminal identity is legal according to the received formal authentication request. If it is legal, generate an authentication response value; generate an anchor key based on the 5G key derivation process, encrypt the anchor key and the authentication response value through symmetric encryption to obtain a second ciphertext, and send it to the satellite; The satellite is further used to obtain the anchor key from the received second ciphertext for key derivation, obtain a response value to be matched, obtain a final authentication response, and send it to the terminal; The terminal is further used to verify the home network identity based on the received final authentication response.

7. The system according to claim 6, wherein The step of verifying whether the terminal identity is legal according to the received formal authentication request and generating an authentication response value if it is legal includes: Calculate a new key in combination with the 5G standard authentication process based on the shared key and random number; Perform an exclusive - OR operation on the hidden mark in the authentication token carried in the formal authentication request and the new key to obtain the received terminal serial number; Calculate the sixth message authentication code according to the received terminal serial number, the shared key, random number, and the next hash value adjacent to the anchor value of the hash chain; Compare whether the sixth message authentication code is the same as the fifth message authentication code in the authentication token in the formal authentication request. If they are the same, calculate the authentication response value according to the shared key, random number, and satellite identity information.

8. The system according to claim 6, characterized in that, The step of obtaining the anchor key from the received second ciphertext for key derivation and obtaining a response value to be matched includes: Decrypt the received second ciphertext using the symmetric key to obtain the decrypted anchor key; Derive the key at the AMF using the decrypted anchor key; Use the derived key at the AMF to encrypt the authentication response value in the received second ciphertext again to obtain the response value to be matched.

9. The system according to claim 6, wherein Verifying the home network identity based on the received final authentication response includes: Processing the received final authentication response based on the 5G key hierarchy to derive the AMF key; Using the derived AMF key to decrypt the authentication response value carried in the final authentication response to obtain the response value to be matched; Comparing whether the response value to be matched is consistent with the expected response value stored locally. If they are consistent, the home network identity authentication passes.

10. A terminal access authentication method for a space-ground integrated network implemented using the system according to any one of claims 1-9, characterized in that, The method includes: The terminal initializes access authentication. At the end of the initialization, a pre-authentication request is created and sent to the satellite; The satellite pre-authenticates the terminal identity carried in the received pre-authentication request through the on-board AMF network element to obtain a pre-authentication response and sends it to the terminal; The terminal verifies the satellite identity information carried in the received pre-authentication response. If the satellite identity information is verified successfully, a formal authentication request is created and sent to the satellite; The satellite stores the request message carried in the received formal authentication request in the case where the feeder link is unavailable; or sends the formal authentication request to the terrestrial core network in the case where the feeder link is available for terminal access authentication in the space-ground integrated network.