Mobile station communication method, satellite communication method and satellite communication system

By carrying mobile station capability identification cells and dynamic handover encryption algorithm in satellite communication, the problem of encryption negotiation and handover difficulties in satellite communication is solved, and security and flexibility are improved.

CN120474694AActive Publication Date: 2025-08-12CHINA TELECOM CORP LTD SATELLITE COMMUNICATIONS BRANCH
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510536450.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-25
Publication Date
2025-08-12
Estimated Expiration
2045-04-25

AI Technical Summary

Technical Problem

In satellite communication scenarios, existing protocols are difficult to efficiently negotiate or switch encryption algorithms, resulting in increased communication complexity and limited security policy flexibility.

Method used

By carrying mobile station capability identification cells in the initial direct message, indicating the supported encryption algorithm, the satellite network selects and activates the encryption algorithm, and supports dynamic switching of the encryption algorithm.

Benefits of technology

It improves communication security and system flexibility, can dynamically select encryption policies based on network needs, enhances response capabilities to potential threats, and improves the overall security performance of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474694A_ABST
    Figure CN120474694A_ABST
Patent Text Reader

Abstract

The invention discloses a mobile station communication method, a satellite communication method and a satellite communication system. Wherein the communication process comprises the following steps: the mobile station sends an initial direct transmission message to the satellite network, the initial direct transmission message carries a mobile station capability identification cell, and the mobile station capability identification cell is at least used for indicating at least one encryption algorithm supported by the mobile station; the satellite network determines a first encryption algorithm from encryption algorithms supported by the mobile station and sends a first encryption mode command message to the mobile station, and the first encryption mode command message carries an encryption starting parameter and the first encryption algorithm; the mobile station sends a first encryption mode completion message encrypted by the first encryption algorithm to the satellite network; and the satellite network continues to carry out signaling or data transmission with the mobile station, and the transmitted signaling or data is encrypted through the first encryption algorithm. The technical problem that it is difficult to negotiate or switch an encryption algorithm efficiently based on an existing protocol in a satellite communication scene is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of satellite communication technology, and in particular to a mobile station communication method, a satellite communication method, and a satellite communication system. Background Art

[0002] In current GMR (Geostationary Earth Orbit Mobile Radio interface) communication systems, encryption algorithm negotiation and selection are critical for ensuring communication security. According to the GMR protocol, when a terminal initiates a location update request to the network in idle mode, initial encryption algorithm negotiation is performed via the "Mobile Station Classmark 1" information element in the uplink "Location Update Request" message. However, this information element only contains information supporting the A5 / 1 encryption algorithm, while the GMR system can actually configure seven encryption algorithms, from A5 / 1 to A5 / 7. This limitation means that initially, the system can only select the A5 / 1 algorithm for encryption. If the network needs to switch to other encryption algorithms, such as A5 / 3 or A5 / 5, additional "Classmark Query" and "Classmark Change" signaling exchanges are required to query and update terminal capabilities, which undoubtedly increases network communication complexity and air interface signaling overhead.

[0003] In addition, if the network intends to change the encryption algorithm when encryption mode is already enabled, according to the existing GMR protocol, sending a "Cipher Mode Command" message carrying the new algorithm and the "Start Ciphering" parameter will be considered invalid. The terminal will directly discard such commands, resulting in the network being unable to dynamically adjust the encryption algorithm in the encryption state, thereby limiting the system's flexibility in adjusting security policies.

[0004] To address the above-mentioned problems, no effective solutions have been proposed so far. Summary of the Invention

[0005] The embodiments of the present application provide a mobile station communication method, a satellite communication method, and a satellite communication system to at least solve the technical problem that it is difficult to efficiently negotiate or switch encryption algorithms based on existing protocols in satellite communication scenarios.

[0006] According to one aspect of an embodiment of the present application, a mobile station communication method is provided, including: sending an initial direct transmission message to a satellite network, wherein the satellite network is a geosynchronous orbit satellite network, and the initial direct transmission message carries a mobile station capability identification information element, and the mobile station capability identification information element is at least used to indicate at least one encryption algorithm supported by the mobile station; receiving a first encryption mode command message sent by the satellite network, wherein the first encryption mode command message carries a startup encryption parameter and a first encryption algorithm, and the first encryption algorithm is an encryption algorithm supported by the mobile station; sending a first encryption mode completion message encrypted by the first encryption algorithm to the satellite network; and continuing signaling or data transmission with the satellite network, wherein the transmitted signaling or data are all encrypted by the first encryption algorithm.

[0007] Optionally, the mobile station capability identification information element includes: an extended mobile station category tag 1 information element, the extended mobile station category tag 1 information element includes an extended third byte, and the extended third byte is used to indicate the mobile station's support status for other encryption algorithms in the A5 series encryption algorithms except the A5 / 1 encryption algorithm.

[0008] Optionally, continuing to transmit signaling or data with the satellite network includes: receiving a second encryption mode command message encrypted by the first encryption algorithm sent by the satellite network, wherein the second encryption mode command message carries a startup encryption parameter and a second encryption algorithm, and the second encryption algorithm is another encryption algorithm supported by the mobile station in addition to the first encryption algorithm; sending a second encryption mode completion message encrypted by the second encryption algorithm to the satellite network; continuing to transmit signaling or data with the satellite network, wherein the transmitted signaling or data are all encrypted by the second encryption algorithm.

[0009] Optionally, before sending the initial direct transfer message to the satellite network, the above method also includes: sending a wireless resource control connection request message to the satellite network in an idle state; receiving a wireless resource control connection establishment message sent by the satellite network based on the established signal wireless bearer; and sending a wireless resource control connection establishment completion message to the satellite network based on the signal wireless bearer.

[0010] Optionally, sending the initial direct transfer message to the satellite network includes: sending the initial direct transfer message including a location update request message to the satellite network, wherein the location update request message carries a mobile station capability identification information element.

[0011] Optionally, after sending an initial direct transmission message carrying a location update request message to the satellite network, it also includes: receiving an identification request message sent by the satellite network; sending an identification response message carrying a mobile station identification to the satellite network; receiving an authentication request message carrying an authentication random number sent by the satellite network; and sending an authentication response message carrying a signature response to the satellite network.

[0012] Optionally, continuing signaling or data transmission with the satellite network includes: receiving a location update acceptance message sent by the satellite network and encrypted by a first encryption algorithm and carrying a temporary mobile user identity; and sending a temporary mobile user identity reallocation completion message encrypted by the first encryption algorithm to the satellite network.

[0013] Optionally, the method also includes: receiving a wireless resource control connection release message encrypted by a first encryption algorithm sent by a satellite network; sending a wireless resource control connection release completion message encrypted by the first encryption algorithm to the satellite network, and entering an idle state.

[0014] According to another aspect of an embodiment of the present application, a satellite communication method is also provided, which is applied to a geosynchronous orbit satellite network, including: receiving an initial direct transmission message sent by a mobile station, wherein the initial direct transmission message carries a mobile station capability identification element, and the mobile station capability identification element is at least used to indicate at least one encryption algorithm supported by the mobile station; determining a first encryption algorithm from the encryption algorithms supported by the mobile station, and sending a first encryption mode command message to the mobile station, wherein the first encryption mode command message carries a startup encryption parameter and a first encryption algorithm; receiving a first encryption mode completion message sent by the mobile station and encrypted by the first encryption algorithm; continuing signaling or data transmission with the mobile station, wherein the transmitted signaling or data are all encrypted by the first encryption algorithm.

[0015] Optionally, the mobile station capability identification information element includes: an extended mobile station category tag 1 information element, the extended mobile station category tag 1 information element includes an extended third byte, and the extended third byte is used to indicate the mobile station's support status for other encryption algorithms in the A5 series encryption algorithms except the A5 / 1 encryption algorithm.

[0016] Optionally, continuing signaling or data transmission with the mobile station includes: in response to an encryption algorithm switching instruction, determining a second encryption algorithm other than the first encryption algorithm from the encryption algorithms supported by the mobile station; sending a second encryption mode command message encrypted by the first encryption algorithm to the mobile station, wherein the second encryption mode command message carries startup encryption parameters and the second encryption algorithm; receiving a second encryption mode completion message encrypted by the second encryption algorithm sent by the mobile station; continuing signaling or data transmission with the mobile station, wherein the transmitted signaling or data are all encrypted by the second encryption algorithm.

[0017] According to another aspect of an embodiment of the present application, a satellite communication system is also provided, including: a mobile station and a satellite network, the satellite network being a geosynchronous orbit satellite network, wherein the mobile station is used to send an initial direct transmission message to the satellite network, wherein the initial direct transmission message carries a mobile station capability identification information element, and the mobile station capability identification information element is at least used to indicate at least one encryption algorithm supported by the mobile station; the satellite network is used to determine a first encryption algorithm from the encryption algorithms supported by the mobile station, and send a first encryption mode command message to the mobile station, wherein the first encryption mode command message carries a startup encryption parameter and a first encryption algorithm; the mobile station is also used to send a first encryption mode completion message encrypted by the first encryption algorithm to the satellite network; the satellite network is also used to continue signaling or data transmission with the mobile station, wherein the transmitted signaling or data are all encrypted by the first encryption algorithm.

[0018] Optionally, the mobile station capability identification information element includes: an extended mobile station category tag 1 information element, the extended mobile station category tag 1 information element includes an extended third byte, and the extended third byte is used to indicate the mobile station's support status for other encryption algorithms in the A5 series encryption algorithms except the A5 / 1 encryption algorithm.

[0019] Optionally, the satellite network is also used to respond to the encryption algorithm switching instruction, determine a second encryption algorithm other than the first encryption algorithm from the encryption algorithms supported by the mobile station, and send a second encryption mode command message encrypted by the first encryption algorithm to the mobile station, wherein the second encryption mode command message carries the startup encryption parameters and the second encryption algorithm; the mobile station is also used to send a second encryption mode completion message encrypted by the second encryption algorithm to the satellite network; the satellite network is also used to continue signaling or data transmission with the mobile station, wherein the transmitted signaling or data are all encrypted by the second encryption algorithm.

[0020] According to another aspect of an embodiment of the present application, a computer program product is further provided, the computer program product comprising: a computer program, wherein when the computer program is executed by a processor, the above-mentioned mobile station communication method or satellite communication method is implemented.

[0021] According to another aspect of an embodiment of the present application, an electronic device is also provided, which includes: a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to execute the above-mentioned mobile station communication method or satellite communication method through the computer program.

[0022] In this embodiment of the present application, by including a mobile station capability identification element in the initial direct transmission message, the satellite network can understand the encryption algorithms supported by the mobile station and intelligently select an encryption algorithm for communication. This approach not only improves communication security but also enhances system flexibility, enabling dynamic selection of encryption strategies based on network requirements and mobile station capabilities. Furthermore, the dynamic switching mechanism for encryption algorithms enables the mobile station to promptly respond to satellite network instructions to switch encryption algorithms and update the encryption algorithm, effectively addressing potential security threats and improving the overall security performance of the system. This addresses the technical issue of the difficulty in efficiently negotiating or switching encryption algorithms based on existing protocols in satellite communication scenarios. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0024] Figure 1 is a schematic structural diagram of an optional satellite communication system according to an embodiment of the present application;

[0025] Figure 2 It is an interactive flow chart of negotiating encryption algorithms in a satellite communication system according to relevant technologies;

[0026] Figure 3 This is an interactive flow chart of an optional optimized satellite communication system negotiation encryption algorithm according to an embodiment of the present application;

[0027] Figure 4 This is a flow chart for switching encryption algorithms in a satellite communication system according to related technologies;

[0028] Figure 5 This is an interactive diagram of a process for switching encryption algorithms in a satellite communication system according to an optional optimization embodiment of the present application;

[0029] Figure 6 This is a schematic diagram of the interaction flow of various modules of an optional complete satellite communication system according to an embodiment of the present application;

[0030] Figure 7 is a flow chart of an optional mobile station communication method according to an embodiment of the present application;

[0031] Figure 8 is a flowchart of an optional satellite communication method according to an embodiment of the present application;

[0032] Figure 9 It is a schematic structural diagram of an optional electronic device according to an embodiment of the present application. DETAILED DESCRIPTION

[0033] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of this application.

[0034] It should be noted that the terms "first", "second", etc. in the specification, claims, and drawings of the present application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product, or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products, or devices.

[0035] In order to better understand the embodiments of the present application, some nouns or terms that appear in the description of the embodiments of the present application are first translated and explained as follows:

[0036] A geosynchronous satellite network is a satellite communications system that utilizes the geosynchronous orbit of the Earth. In geosynchronous orbit, satellites orbit the Earth at the same speed as the Earth's rotation, allowing them to remain stationary relative to a specific point on the Earth's surface, thus providing continuous coverage for that area. Geosynchronous satellite networks are widely used in broadcasting, television transmission, long-distance communications, and mobile communications.

[0037] Mobile Station Classmark 1: Usually abbreviated as MSCM1 or simply using the full name, it is a parameter used in mobile communication systems to describe the functions and capabilities of mobile devices (such as mobile phones and data terminals). It includes multiple key attributes of the device, such as revision level, encryption algorithm, radio frequency power capability, and other capabilities. Among them, revision level: indicates the software version or feature set of the terminal; Enhanced Full Rate: indicates whether the terminal supports enhanced full rate voice coding; encryption algorithm: indicates the encryption algorithm supported by the terminal, for example, in the global mobile communication system, A5 / 1 is the most common encryption standard; radio frequency power capability: describes the maximum transmit power of the terminal in different frequencies and operating modes; other capabilities: may include support for specific services or functions, such as data transmission rate, frequency range, network access technology, etc.

[0038] Example 1

[0039] According to an embodiment of the present application, a satellite communication system is provided, such as Figure 1 As shown, the mobile station communication system includes at least: a mobile station 11, a satellite network 12, wherein:

[0040] The mobile station 11 may send an initial direct transfer message to the satellite network, wherein the initial direct transfer message carries a mobile station capability identification information element, and the mobile station capability identification information element is used to indicate at least one encryption algorithm supported by the mobile station;

[0041] The satellite network 12 may determine a first encryption algorithm from encryption algorithms supported by the mobile station, and send a first encryption mode command message to the mobile station, wherein the first encryption mode command message carries a startup encryption parameter and the first encryption algorithm;

[0042] The mobile station 11 may also send a first encryption mode completion message encrypted by the first encryption algorithm to the satellite network;

[0043] The satellite network 12 can also continue to transmit signaling or data with the mobile station, wherein the transmitted signaling or data is encrypted using the first encryption algorithm.

[0044] Among them, the satellite network is a geosynchronous orbit satellite network, and the mobile station can be a vehicle-mounted communication device, a mobile phone, a portable wireless terminal, etc. that can communicate through the geosynchronous orbit satellite network. The solution in this application is mainly based on the GMR protocol for interaction, and some of the intermediate interaction processes have been optimized accordingly. The following describes the functions of each module of the satellite communication system in combination with the specific implementation process.

[0045] Figure 2 An interactive flow chart of a satellite communication system negotiation encryption algorithm is shown in FIG. Figure 2As shown, the negotiation of encryption algorithms between the mobile station and the satellite network is mainly implemented through steps S1 to S5.

[0046] Step S1: The mobile station sends an initial direct transfer message to the satellite network (mobile station category label 1).

[0047] First, the mobile station sends an initial direct transmission message with mobile station category mark 1 to the satellite network. The initial direct transmission message contains mobile station category mark 1, and mobile station category mark 1 contains indication information of whether the A5 / 1 encryption algorithm is supported. Specifically, the structure of the mobile station category mark 1 identifier is shown in Table 1.

[0048] Table 1 Mobile Station Category Tag 1 Identifier

[0049]

[0050] As shown in the table above, the mobile station category mark 1 identifier only carries a flag indicating whether A5 / 1 is supported, while the A5 series encryption algorithms include 7 encryption algorithms, namely A5 / 1-A5 / 7.

[0051] Step S2: The satellite network sends a category flag query message to the mobile station.

[0052] Due to the nature of the mobile station's Class Flag 1 identifier, it cannot indicate whether the terminal supports encryption algorithms other than A5 / 1. Suppose, after receiving the Initial Direct Message, the satellite network wishes to instruct the mobile station to use the A5 / 3 algorithm for encryption, but is unclear whether the mobile terminal supports it. Therefore, a Class Flag Query message must be sent to the mobile station.

[0053] Step S3: The mobile station sends a category flag change message (mobile station category flag 2) to the satellite network.

[0054] When the mobile station receives the Class Flag Query message from the satellite network, it sends a Class Flag Change message to the satellite network, carrying the mobile station's Class Flag 2. The Mobile Station Class Flag 2 indicates whether the A5 / 3 encryption algorithm is supported. If the Class Flag Change message received by the satellite network indicates that the terminal supports the A5 / 3 algorithm, the process proceeds to step S4.

[0055] Step S4: The satellite network sends an encryption mode command message to the mobile station.

[0056] The satellite network sends an encryption mode command message to the mobile station, wherein the encryption mode command message carries the activation encryption parameters and the A5 / 3 encryption algorithm. Upon receiving the encryption mode command message, the mobile station enters the A5 / 3 encryption mode according to the A5 / 3 encryption algorithm indicated in the message, and then proceeds to step S5.

[0057] Step S5: The mobile station sends an encryption mode completion message to the satellite network.

[0058] The mobile station sends an encryption mode completion message to the satellite network to complete the encryption algorithm negotiation, and then uses the A5 / 3 algorithm to encrypt the information sent subsequently.

[0059] In the above steps, since the mobile station category mark 1 cannot indicate whether the terminal supports encryption algorithms other than A5 / 1, assuming that the encryption algorithm the satellite network wants to use is the A5 / 3 encryption algorithm, the satellite network needs to send an additional category mark query message to the mobile station, and the terminal needs to additionally indicate whether it supports the A5 / 3 algorithm by carrying a category mark change message carrying the mobile station category mark 2. This undoubtedly increases the resource consumption of the network interaction process. Based on this problem, the present application optimizes the content in the above mobile station category mark 1, based on the optimized mobile station category mark 1.

[0060] As an optional implementation, the mobile station capability identification information element includes: an extended mobile station category tag 1 information element, the extended mobile station category tag 1 information element includes an extended third byte, and the extended third byte is used to indicate the mobile station's support status for other encryption algorithms in the A5 series encryption algorithms except the A5 / 1 encryption algorithm.

[0061] Specifically, Table 3 shows the extended mobile station category tag 1 identifier.

[0062] Table 3 Extended Mobile Station Category Tag 1 Identifier

[0063]

[0064] As listed in Table 3, the extended mobile station category mark 1 identifier carries not only the A5 / 1 encryption algorithm, but also the A5 / 2 to A5 / 7 encryption algorithms. The extended third byte is filled according to the terminal's support capability for the encryption algorithm. If the terminal does not support the A5 / 6 encryption algorithm, the A5 / 6 encryption algorithm is not reflected in the third byte.

[0065] Based on the above extended mobile station category mark 1 identifier, Figure 3 An interactive flow chart of an optimized satellite communication system negotiation encryption algorithm is shown.

[0066] Step S1: The mobile station sends an initial direct transfer message (extended mobile station category tag 1) to the satellite network.

[0067] In the optimized process, the Mobile Station Category Flag 1 information element has been expanded to include more encryption algorithm identifiers, such as any combination of A5 / 2 to A5 / 7. In this way, by carrying the expanded Mobile Station Category Flag 1 in the initial direct transfer message, the terminal can use this information element to declare its encryption algorithm capabilities to the target satellite network at an early stage, without the need for additional signaling to determine the terminal's encryption algorithm support.

[0068] Step S2: The satellite network sends an encryption mode command message to the mobile station.

[0069] The satellite network determines the encryption algorithm to use from the encryption algorithms indicated by the terminal and sends a Cipher Mode Command message to the mobile station. The Cipher Mode Command message contains the network-specified encryption algorithm (e.g., A5 / 3) and an encryption activation indication. By including the encryption algorithm information directly in the Cipher Mode Command message, the network can directly instruct the terminal to activate a specific encryption algorithm and begin encrypted communications.

[0070] Step S3: The mobile station sends an encryption mode completion message to the satellite network.

[0071] Once the terminal receives the satellite network's Encryption Mode Command message and successfully applies the specified encryption algorithm, it responds with an Encryption Mode Complete message, informing the network that it is ready to begin communications using the selected encryption algorithm. At this point, all subsequent control signaling and user data will be transmitted using the negotiated encryption format, protecting communications from unauthorized eavesdropping and interference.

[0072] The above steps S1 to S3 reflect how to negotiate and start the encryption algorithm more efficiently and securely in the encryption algorithm negotiation process based on the GMR protocol. By including the declaration of the encryption algorithm in the initial direct transmission message and directly sending the encryption mode command on the network side to activate encryption, the entire process becomes smoother and more reliable.

[0073] In specific implementation, the communication process between the mobile station and the satellite network may involve switching encryption algorithms. Figure 4 A flow chart showing the interaction of switching encryption algorithms in a satellite communication system is shown.

[0074] When the mobile station uses the A5 / 3 encryption algorithm for subsequent data transmission or signaling interaction, and the satellite network needs to switch the encryption algorithm based on the configuration policy, the following steps are performed.

[0075] Step S1: The satellite network sends an encryption mode command message (carrying the A5 / 5 algorithm) to the mobile station.

[0076] Among them, the encryption mode command message is used to instruct the terminal's mobile station to switch the encryption algorithm from A5 / 3 to A5 / 5. However, because the terminal is running in the encryption mode of the A5 / 3 algorithm, it does not actually perform the algorithm switch. Instead, it directly discards and ignores the encryption model command message sent by the satellite network and continues to use A5 / 3 encryption.

[0077] Step S2: The terminal initiates a management service request message to the satellite network.

[0078] The terminal continues to use the A5 / 3 encryption algorithm to continue the previous service or establish a new service connection.

[0079] In the above process, once the terminal starts encryption, whether it is updating the location to accept the message allocation or continuing other services such as calls or data, it can only use the same encryption algorithm. The encryption algorithm switching expected by the network side itself does not occur, resulting in a potentially unsafe state or reducing the encryption quality of the service.

[0080] Based on the above problems, an embodiment of the present application proposes an optimized encryption algorithm switching mechanism, which can be implemented in the following way: the satellite network responds to the encryption algorithm switching instruction, determines a second encryption algorithm other than the first encryption algorithm from the encryption algorithms supported by the mobile station, and sends a second encryption mode command message encrypted by the first encryption algorithm to the mobile station, wherein the second encryption mode command message carries the startup encryption parameters and the second encryption algorithm; the mobile station sends a second encryption mode completion message encrypted by the second encryption algorithm to the satellite network; the satellite network continues to transmit signaling or data with the mobile station, wherein the transmitted signaling or data are all encrypted by the second encryption algorithm.

[0081] By introducing a dynamic encryption algorithm switching mechanism during communication, the satellite network can adjust the encryption algorithm in real time based on needs or changes in the threat model. For example, upon detecting a potential security threat, the satellite network can send a second encryption mode command message, instructing the mobile station to switch to a higher-level encryption algorithm, such as switching from A5 / 3 to A5 / 5. Upon receiving the command, the mobile station uses the new encryption algorithm (i.e., the second encryption algorithm) to encrypt subsequent communication data, ensuring adequate protection even in challenging security environments. This mechanism overcomes the limitations of fixed encryption algorithms in traditional satellite communications and improves the system's resilience and adaptability.

[0082] Specifically, Figure 5 A schematic diagram of the interaction process of switching encryption algorithms in an optimized satellite communication system is shown. Figure 5 As shown,

[0083] Step S1: The satellite network sends an encryption mode command message (carrying the A5 / 5 algorithm) to the mobile station.

[0084] Different from Figure 4 In the interaction process described above, the terminal can also receive and process the encryption mode command message carrying the start encryption in encryption mode. The terminal updates the security context and enables the new encryption algorithm. It directly updates its own encryption mode from the A5 / 3 encryption algorithm to the A5 / 5 encryption algorithm, that is, responds to the switching instruction from the network side.

[0085] Step S2: The mobile station sends an encryption mode completion message (updated to the A5 / 5 algorithm) to the satellite network.

[0086] After the mobile station updates its internal encryption algorithm settings and switches to A5 / 5, it needs to reply to the network side with an encryption mode completion message, indicating that it has completed the algorithm switch as instructed and all communications will now be encrypted using A5 / 5.

[0087] Step S3: Manage service request message (using A5 / 5 algorithm).

[0088] The terminal uses the newly switched encryption algorithm to continue the previous service or establish a new service connection.

[0089] In the above steps S1 and S2, the limitation of the original GMR protocol that once the terminal is in encryption mode, it will no longer respond to any message carrying the encryption start and encryption mode command. By adding an encryption algorithm switching mechanism, the network can still flexibly change the encryption algorithm even in encryption mode, further improving the security and performance of the GMR system.

[0090] Based on the above-mentioned extended mobile station category mark 1 and encryption algorithm switching mechanism, the embodiment of the present application is Figure 6 A more complete schematic diagram of the interaction process of each module of the satellite communication system is shown in FIG. , and the specific interaction process refers to steps S1 to S15.

[0091] Step S1: In idle state, the mobile station sends a radio resource control connection (RRC) request message ConectionRquest to the satellite network based on the RACH (Random Access Channel). The request message carries the S-RNTI (Secondary Cell Radio Network Temporary Identifier).

[0092] Step S2: The satellite network sends an Immediate Assignment message to the mobile station based on the RACH, carrying the S-RNTI for identifying the terminal, and establishes SRB2 (Signalling Radio Bearer 2).

[0093] Step S3: The satellite network sends a radio resource control connection establishment message RRC Connection to the mobile station based on the established signal radio bearer SRB2.

[0094] Step S4: The mobile station sends a radio resource control connection setup complete message "Connection Setup Complete" to the satellite network based on the established signaling radio bearer SRB2.

[0095] Step S5: The mobile station sends an initial direct message including a location updating request message Location Updating Request to the satellite network. The location updating request message carries a mobile station capability identification information element. This is the first uplink message of the mobility management layer.

[0096] Step S6: The satellite network sends an identification request message to the mobile station;

[0097] Step S7: The mobile station sends an identification response message carrying the mobile station identification to the satellite network;

[0098] Step S8: The satellite network sends an authentication request message with an authentication random number to the mobile station;

[0099] Step S9, the mobile station sends an authentication response message carrying a signature response to the satellite network;

[0100] Step S10, the satellite network sends an encryption mode command message to the mobile station;

[0101] Step S11, the mobile station sends an encryption mode completion message to the satellite network;

[0102] Step S12: The satellite network sends a location update acceptance message encrypted by a first encryption algorithm and carrying a temporary mobile user identity to the mobile station;

[0103] Step S13: The mobile station sends a temporary mobile subscriber identity reallocation TMSI completion message encrypted by the first encryption algorithm to the satellite network.

[0104] Step S14, the satellite network sends a radio resource control connection release message encrypted by the first encryption algorithm to the mobile station;

[0105] In step S15, the mobile station sends a radio resource control connection release completion message encrypted by the first encryption algorithm to the satellite network, enters an idle state, and completes the location update process.

[0106] In the above process, the satellite communication system's mobile station carries an extended mobile station capability identification element in its initial direct message, enabling the satellite network to understand the encryption algorithms supported by the mobile station and intelligently select an encryption algorithm for communication. This approach not only improves communication security but also enhances system flexibility, enabling dynamic selection of encryption strategies based on network requirements and mobile station capabilities. Furthermore, the proposed dynamic encryption algorithm switching mechanism allows the mobile station to respond in real time to the satellite network's instructions regarding encryption algorithm switching, ensuring that it switches its current mode to the encryption algorithm that best matches the network transmission status. This improves the security of information transmission during system interactions and addresses the technical issue of the difficulty in efficiently negotiating or switching encryption algorithms based on existing protocols in satellite communication scenarios.

[0107] Example 2

[0108] According to an embodiment of the present application, a mobile station communication method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0109] Figure 7 FIG. 1 is a flow chart of a mobile station communication method provided according to an embodiment of the present application, such as Figure 7 As shown, the method includes the following steps:

[0110] Step S702: Send an initial direct transfer message to a satellite network, where the satellite network is a geosynchronous orbit satellite network. The initial direct transfer message carries a mobile station capability identification information element, where the mobile station capability identification information element is used to indicate at least one encryption algorithm supported by the mobile station.

[0111] Step S704: receiving a first encryption mode command message sent by the satellite network, wherein the first encryption mode command message carries a startup encryption parameter and a first encryption algorithm, where the first encryption algorithm is an encryption algorithm supported by the mobile station;

[0112] Step S706, sending a first encryption mode completion message encrypted by the first encryption algorithm to the satellite network;

[0113] Step S708: Continue signaling or data transmission with the satellite network, wherein the transmitted signaling or data is encrypted using the first encryption algorithm.

[0114] The following describes each step of the mobile station communication method in conjunction with a specific implementation process.

[0115] As an optional implementation, the mobile station capability identification information element includes: an extended mobile station category tag 1 information element, the extended mobile station category tag 1 information element includes an extended third byte, and the extended third byte is used to indicate the mobile station's support status for other encryption algorithms in the A5 series encryption algorithms except the A5 / 1 encryption algorithm.

[0116] As an optional implementation method, the mobile station continues to transmit signaling or data with the satellite network, which can be specifically achieved in the following manner: receiving a second encryption mode command message encrypted by the first encryption algorithm sent by the satellite network, wherein the second encryption mode command message carries a startup encryption parameter and a second encryption algorithm, and the second encryption algorithm is another encryption algorithm supported by the mobile station in addition to the first encryption algorithm; sending a second encryption mode completion message encrypted by the second encryption algorithm to the satellite network; continuing to transmit signaling or data with the satellite network, wherein the transmitted signaling or data are all encrypted by the second encryption algorithm.

[0117] Figure 6 A more complete schematic diagram of the interaction process of each module of the satellite communication system is shown in FIG. , and the specific interaction process refers to steps S1 to S15.

[0118] Step S1: In idle state, the mobile station sends a radio resource control connection (RRC) request message ConectionRquest to the satellite network based on the RACH (Random Access Channel). The request message carries the S-RNTI (Secondary Cell Radio Network Temporary Identifier).

[0119] In step S2, the mobile station receives an Immediate Assignment message sent by the satellite network based on RACH, which carries the S-RNTI for identifying the terminal, and establishes SRB2 (Signalling Radio Bearer 2).

[0120] Step S3, the mobile station receives a radio resource control connection establishment message RRC Connection sent by the satellite network based on the established signal radio bearer SRB2;

[0121] Step S4: The mobile station sends a radio resource control connection setup complete message "Connection Setup Complete" to the satellite network based on the established signaling radio bearer SRB2.

[0122] Step S5: The mobile station sends an initial direct message including a location updating request message Location Updating Request to the satellite network. The location updating request message carries a mobile station capability identification information element. This is the first uplink message of the mobility management layer.

[0123] Step S6, the mobile station receives an identification request message sent by the satellite network;

[0124] Step S7: The mobile station sends an identification response message carrying the mobile station identification to the satellite network;

[0125] Step S8, the mobile station receives an authentication request message with an authentication random number sent by the satellite network;

[0126] Step S9, the mobile station sends an authentication response message carrying a signature response to the satellite network;

[0127] Step S10, the mobile station receives an encryption mode command message sent by the satellite network;

[0128] Step S11, the mobile station sends an encryption mode completion message to the satellite network;

[0129] Step S12: The mobile station receives a location update accept message encrypted by a first encryption algorithm and carrying a temporary mobile user identity, sent by the satellite network;

[0130] Step S13: The mobile station sends a temporary mobile subscriber identity reallocation TMSI completion message encrypted by the first encryption algorithm to the satellite network.

[0131] Step S14, the mobile station receives a radio resource control connection release message encrypted by the first encryption algorithm and sent by the satellite network;

[0132] In step S15, the mobile station sends a radio resource control connection release completion message encrypted by the first encryption algorithm to the satellite network, enters an idle state, and completes the location update process.

[0133] Through the above steps, the mobile station carries the extended mobile station capability identification information element in the initial direct transmission message, allowing the satellite network to understand the encryption algorithms supported by the mobile station and intelligently select an encryption algorithm for communication. This method not only improves communication security but also enhances system flexibility, enabling dynamic selection of encryption strategies based on network requirements and mobile station capabilities. Furthermore, the proposed dynamic encryption algorithm switching mechanism allows the mobile station to respond in real time to the satellite network's instructions regarding encryption algorithm switching, ensuring that its current mode is switched to the encryption algorithm that best suits the network transmission status. This improves the security of information transmission during system interactions and addresses the technical issue of the difficulty in efficiently negotiating or switching encryption algorithms based on existing protocols in satellite communication scenarios.

[0134] Example 3

[0135] According to an embodiment of the present application, a satellite communication method applied to a geosynchronous orbit satellite network is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0136] Figure 8 is a flow chart of a satellite communication method provided according to an embodiment of the present application, such as Figure 8 As shown, the method includes the following steps:

[0137] Step S802: Receive an initial direct transfer message sent by a mobile station, wherein the initial direct transfer message carries a mobile station capability identification information element, and the mobile station capability identification information element is used to indicate at least one encryption algorithm supported by the mobile station;

[0138] Step S804: Determine a first encryption algorithm from the encryption algorithms supported by the mobile station, and send a first encryption mode command message to the mobile station, wherein the first encryption mode command message carries a startup encryption parameter and the first encryption algorithm;

[0139] Step S806: receiving a first encryption mode completion message encrypted by the first encryption algorithm from the mobile station;

[0140] Step S808: Continue signaling or data transmission with the mobile station, wherein the transmitted signaling or data is encrypted using the first encryption algorithm.

[0141] The following describes each step of the mobile station communication method in conjunction with a specific implementation process.

[0142] As an optional implementation, the mobile station capability identification information element includes: an extended mobile station category tag 1 information element, the extended mobile station category tag 1 information element includes an extended third byte, and the extended third byte is used to indicate the mobile station's support status for other encryption algorithms in the A5 series encryption algorithms except the A5 / 1 encryption algorithm.

[0143] As an optional implementation, the satellite network continues to transmit signaling or data with the mobile station, which can be specifically achieved in the following manner: in response to an encryption algorithm switching instruction, determine a second encryption algorithm other than the first encryption algorithm from the encryption algorithms supported by the mobile station; send a second encryption mode command message encrypted by the first encryption algorithm to the mobile station, wherein the second encryption mode command message carries startup encryption parameters and the second encryption algorithm; receive a second encryption mode completion message encrypted by the second encryption algorithm sent by the mobile station; continue to transmit signaling or data with the mobile station, wherein the transmitted signaling or data are all encrypted by the second encryption algorithm.

[0144] During specific implementation, the authentication, update and encryption process based on the GMR protocol can refer to the interactive process in Example 1, which will not be described in detail here.

[0145] In the above process, the satellite network receives the mobile station by including an extended mobile station capability identification element in the initial direct message, enabling the satellite network to understand the encryption algorithms supported by the mobile station and intelligently select an encryption algorithm for communication. This approach not only improves communication security but also enhances system flexibility, enabling dynamic selection of encryption strategies based on network requirements and mobile station capabilities. Furthermore, the proposed dynamic encryption algorithm switching mechanism allows the satellite network to issue an encryption algorithm switching instruction to the mobile station based on its own needs, instructing the mobile station to switch from the current encryption mode to the encryption algorithm that best suits the network transmission status. This improves the security of information transmission during system interactions and addresses the technical issue of the difficulty in efficiently negotiating or switching encryption algorithms based on existing protocols in satellite communication scenarios.

[0146] Example 4

[0147] According to an embodiment of the present application, a computer program product is also provided, which includes a computer program, wherein when the computer program is executed by a processor, it implements the mobile station communication method in Example 2 or the satellite communication method applied to the geosynchronous orbit satellite network in Example 3.

[0148] According to an embodiment of the present application, a non-volatile storage medium is also provided, which includes a stored computer program, wherein the device where the non-volatile storage medium is located executes the mobile station communication method in Example 2 or the satellite communication method applied to the geosynchronous orbit satellite network in Example 3 by running the computer program.

[0149] According to an embodiment of the present application, a processor is also provided, which is used to run a computer program, wherein when the computer program is running, the mobile station communication method in Example 2 or the satellite communication method applied to the geosynchronous orbit satellite network in Example 3 is executed.

[0150] According to an embodiment of the present application, an electronic device is also provided, which includes: a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to execute the mobile station communication method in Example 2 or the satellite communication method applied to the geosynchronous orbit satellite network in Example 3 through the computer program.

[0151] Specifically, when the computer program is running, the following steps of the mobile station communication method in Example 2 are executed: an initial direct transmission message is sent to a satellite network, wherein the satellite network is a geosynchronous orbit satellite network, and the initial direct transmission message carries a mobile station capability identification information element, and the mobile station capability identification information element is at least used to indicate at least one encryption algorithm supported by the mobile station; a first encryption mode command message is received from the satellite network, wherein the first encryption mode command message carries a startup encryption parameter and a first encryption algorithm, and the first encryption algorithm is an encryption algorithm supported by the mobile station; a first encryption mode completion message encrypted by the first encryption algorithm is sent to the satellite network; and signaling or data transmission with the satellite network is continued, wherein the transmitted signaling or data is encrypted by the first encryption algorithm.

[0152] Specifically, when the computer program is running, the following steps of the satellite communication method applied to the geosynchronous orbit satellite network in Example 3 are executed: receiving an initial direct transmission message sent by a mobile station, wherein the initial direct transmission message carries a mobile station capability identification element, and the mobile station capability identification element is at least used to indicate at least one encryption algorithm supported by the mobile station; determining a first encryption algorithm from the encryption algorithms supported by the mobile station, and sending a first encryption mode command message to the mobile station, wherein the first encryption mode command message carries a startup encryption parameter and a first encryption algorithm; receiving a first encryption mode completion message sent by the mobile station that is encrypted by the first encryption algorithm; continuing signaling or data transmission with the mobile station, wherein the transmitted signaling or data are all encrypted by the first encryption algorithm.

[0153] As an optional implementation, the electronic device may be in the form of a mobile terminal, a computer terminal or a similar computing device. Figure 9 FIG1 shows a hardware structure block diagram of an electronic device for implementing a mobile station communication method. Figure 9As shown, the electronic device 90 may include one or more (902a, 902b, ..., 902n are used to illustrate) processors 902 (the processor 902 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory 904 for storing data, and a transmission device 906 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply and / or a camera. It will be understood by those skilled in the art that Figure 9 The structure shown is only for illustration and does not limit the structure of the above electronic device. Figure 9 More or fewer components than shown, or with Figure 9 Different configurations shown.

[0154] It should be noted that the one or more processors 902 and / or other data processing circuits described above may generally be referred to herein as "data processing circuitry". The data processing circuitry may be embodied in whole or in part as software, hardware, firmware, or any other combination thereof. In addition, the data processing circuitry may be a single independent processing module, or may be incorporated in whole or in part into any of the other components of the electronic device 90. As described in the embodiments of the present application, the data processing circuitry serves as a processor control (e.g., selection of a variable resistor terminal path connected to an interface).

[0155] The memory 904 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the mobile station communication method in the embodiments of the present application. The processor 902 executes the software programs and modules stored in the memory 904 to perform various functional applications and data processing, thereby implementing the aforementioned application vulnerability detection method. The memory 904 may include high-speed random access memory and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some examples, the memory 904 may further include memory remotely located relative to the processor 902, and these remote memories may be connected to the electronic device 90 via a network. Examples of such networks include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0156] The transmission device 906 is used to receive or send data via a network. Specific examples of the aforementioned network may include a wireless network provided by the communication provider of the electronic device 90. In one embodiment, the transmission device 906 includes a network interface controller (NIC), which can be connected to other network devices via a base station to enable communication with the Internet. In one embodiment, the transmission device 906 may be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0157] The display may be, for example, a touch screen liquid crystal display (LCD) that enables a user to interact with a user interface of the electronic device 90 .

[0158] The serial numbers of the above embodiments are for description only and do not represent the advantages or disadvantages of the embodiments.

[0159] In the above embodiments of the present application, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.

[0160] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only exemplary. For example, the division of units can be a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.

[0161] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple units. Some or all of the units may be selected to achieve the purpose of the present embodiment according to actual needs.

[0162] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0163] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk and other media that can store program code.

[0164] The above is only a preferred embodiment of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.

Claims

1. A mobile station communication method, characterized in that: include: Sending an initial direct transfer message to a satellite network, wherein the satellite network is a geosynchronous orbit satellite network, the initial direct transfer message carrying a mobile station capability identification information element, the mobile station capability identification information element being used to indicate at least one encryption algorithm supported by the mobile station; receiving a first encryption mode command message sent by the satellite network, wherein the first encryption mode command message carries a startup encryption parameter and a first encryption algorithm, and the first encryption algorithm is an encryption algorithm supported by the mobile station; Sending a first encryption mode completion message encrypted by the first encryption algorithm to the satellite network; Continue signaling or data transmission with the satellite network, wherein the transmitted signaling or data is encrypted using the first encryption algorithm.

2. The method according to claim 1, characterized in that The mobile station capability identification information element includes: an extended mobile station category tag 1 information element, the extended mobile station category tag 1 information element includes an extended third byte, and the extended third byte is used to indicate the mobile station's support status for other encryption algorithms in the A5 series encryption algorithm except the A5 / 1 encryption algorithm.

3. The method according to claim 1, characterized in that Continuing signaling or data transmission with the satellite network, including: receiving a second encryption mode command message sent by the satellite network and encrypted using the first encryption algorithm, wherein the second encryption mode command message carries a startup encryption parameter and a second encryption algorithm, and the second encryption algorithm is another encryption algorithm supported by the mobile station in addition to the first encryption algorithm; Sending a second encryption mode completion message encrypted by the second encryption algorithm to the satellite network; Continue signaling or data transmission with the satellite network, wherein the transmitted signaling or data is encrypted using the second encryption algorithm.

4. The method according to claim 1, wherein Before sending the initial direct message to the satellite network, the method further includes: sending a radio resource control connection request message to the satellite network in an idle state; receiving a radio resource control connection establishment message sent by the satellite network based on the established signal radio bearer; A radio resource control connection establishment complete message is sent to the satellite network based on the signal radio bearer.

5. The method according to claim 1, wherein Send an initial direct message to the satellite network, including: An initial direct transfer message including a location update request message is sent to the satellite network, wherein the location update request message carries the mobile station capability identification information element.

6. The method according to claim 5, characterized in that After sending the initial direct transfer message carrying the location update request message to the satellite network, the method further includes: receiving an identification request message sent by the satellite network; Sending an identification response message carrying an identification of the mobile station to the satellite network; receiving an authentication request message carrying an authentication random number sent by the satellite network; An authentication response message carrying a signature response is sent to the satellite network.

7. The method according to claim 5, characterized in that Continuing signaling or data transmission with the satellite network, including: receiving a location update acceptance message sent by the satellite network and encrypted by the first encryption algorithm and carrying a temporary mobile user identity; Sending a temporary mobile user identity reallocation completion message encrypted by the first encryption algorithm to the satellite network.

8. The method according to claim 4, characterized in that The method further comprises: receiving a radio resource control connection release message encrypted by the first encryption algorithm and sent by the satellite network; Send a radio resource control connection release completion message encrypted by the first encryption algorithm to the satellite network and enter an idle state.

9. A satellite communication method, applied to a geosynchronous orbit satellite network, characterized in that: include: receiving an initial direct transfer message sent by a mobile station, wherein the initial direct transfer message carries a mobile station capability identification information element, and the mobile station capability identification information element is used to indicate at least one encryption algorithm supported by the mobile station; Determining a first encryption algorithm from encryption algorithms supported by the mobile station, and sending a first encryption mode command message to the mobile station, wherein the first encryption mode command message carries a startup encryption parameter and the first encryption algorithm; receiving a first encryption mode completion message sent by the mobile station and encrypted by the first encryption algorithm; Continue signaling or data transmission with the mobile station, wherein the transmitted signaling or data is encrypted using the first encryption algorithm.

10. The method according to claim 9, characterized in that The mobile station capability identification information element includes: an extended mobile station category tag 1 information element, the extended mobile station category tag 1 information element includes an extended third byte, and the extended third byte is used to indicate the mobile station's support status for other encryption algorithms in the A5 series encryption algorithm except the A5 / 1 encryption algorithm.

11. The method according to claim 9, characterized in that Continuing signaling or data transmission with the mobile station includes: In response to the encryption algorithm switching instruction, determining a second encryption algorithm other than the first encryption algorithm from encryption algorithms supported by the mobile station; Sending a second encryption mode command message encrypted by the first encryption algorithm to the mobile station, wherein the second encryption mode command message carries a startup encryption parameter and the second encryption algorithm; receiving a second encryption mode completion message sent by the mobile station and encrypted by the second encryption algorithm; Continue signaling or data transmission with the mobile station, wherein the transmitted signaling or data is encrypted using the second encryption algorithm.

12. A satellite communication system, characterized in that: include: A mobile station and a satellite network, wherein the satellite network is a geosynchronous orbit satellite network, wherein: The mobile station is configured to send an initial direct transfer message to the satellite network, wherein the initial direct transfer message carries a mobile station capability identification information element, and the mobile station capability identification information element is used to indicate at least one encryption algorithm supported by the mobile station; The satellite network is configured to determine a first encryption algorithm from encryption algorithms supported by the mobile station, and send a first encryption mode command message to the mobile station, wherein the first encryption mode command message carries a startup encryption parameter and the first encryption algorithm; The mobile station is further configured to send a first encryption mode completion message encrypted by the first encryption algorithm to the satellite network; The satellite network is further configured to continue signaling or data transmission with the mobile station, wherein the transmitted signaling or data is encrypted using the first encryption algorithm.

13. The system according to claim 12, wherein: The mobile station capability identification information element includes: an extended mobile station category tag 1 information element, the extended mobile station category tag 1 information element includes an extended third byte, and the extended third byte is used to indicate the mobile station's support status for other encryption algorithms in the A5 series encryption algorithm except the A5 / 1 encryption algorithm.

14. The system according to claim 12, wherein: The satellite network is further configured to, in response to the encryption algorithm switching instruction, determine a second encryption algorithm other than the first encryption algorithm from encryption algorithms supported by the mobile station, and send a second encryption mode command message encrypted by the first encryption algorithm to the mobile station, wherein the second encryption mode command message carries a startup encryption parameter and the second encryption algorithm; The mobile station is further configured to send a second encryption mode completion message encrypted by the second encryption algorithm to the satellite network; The satellite network is further configured to continue signaling or data transmission with the mobile station, wherein the transmitted signaling or data is encrypted using the second encryption algorithm.

15. A computer program product, characterized in that include: A computer program, wherein when the computer program is executed by a processor, it implements the mobile station communication method according to any one of claims 1 to 8 or the satellite communication method according to any one of claims 9 to 11.

16. An electronic device, characterized in that: include: A memory and a processor, wherein the memory stores a computer program, and the processor is configured to execute the mobile station communication method according to any one of claims 1 to 8 or the satellite communication method according to any one of claims 9 to 11 through the computer program.

Citation Information

Patent Citations

  • Access verification method, satellite, gateway station and storage medium

    CN117728880A

  • Self-service method and device of direct connection cellular satellite network

    CN118102261A

  • Method of inertial data estimation and its correction according to measurement of satellite navigation system

    RU2617565C1

  • Method and system for providing enhanced data encryption protocols in a mobile satellite communications system

    US20150052360A1

  • Routing data through satellite network in accordance with a data sovereignty policy

    US20240259089A1