Communication method and device based on key isolation between satellites

By sharing parameters between terminal devices and terrestrial networks, different satellite-specific keys are generated, which solves the network security risks caused by sharing security contexts between satellites, realizes key isolation between satellites, and improves the security of the communication system.

CN121508612APending Publication Date: 2026-02-10DATANG MOBILE COMM EQUIP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511594906.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-03
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

In non-terrestrial networks, the sharing of the same security context between satellites leads to cybersecurity vulnerabilities. For example, if one satellite is compromised, the services provided by other satellites are at risk of data decryption, eavesdropping, or tampering.

Method used

By introducing parameters shared between terminal devices and terrestrial networks, different keys are generated for different satellites, achieving key isolation between satellites and ensuring secure communication between each satellite and the terminal device.

Benefits of technology

It enhances network security, prevents the leakage and attack of inter-satellite keys, and protects the confidentiality and integrity of communication data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121508612A_ABST
    Figure CN121508612A_ABST
Patent Text Reader

Abstract

The invention provides a communication method and device based on key isolation between satellites, and relates to the technical field of communication. According to the invention, key isolation between satellites can be realized, so that different satellites can provide communication services with terminal equipment based on different keys, and the network security is improved. The method comprises the following steps: the terminal equipment generates a first key based on a first parameter; wherein the first parameter is preset in the ground network equipment and the terminal equipment; the first key is used for protecting the NAS message transmitted between the terminal equipment and the first satellite.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, specifically to a communication method and apparatus based on inter-satellite key isolation. Background Technology

[0002] In non-terrestrial networks (NTNs) proposed by the 3rd Generation Partnership Project (3GPP), satellites provide communication support for terminal devices through networking. For services that can tolerate a certain level of communication latency, such as some Internet of Things (IoT) applications, a store-and-forward (S&F) mode can be used for communication. In this mode, the service link between the satellite and the terminal device, or the power supply link between the satellite and the ground network equipment, will experience intermittent interruptions.

[0003] To support Security & Context (S&F) services, 3GPP introduced a split mobility management entity architecture, which divides the mobility management entity into a satellite portion and a terrestrial portion. After the terminal device completes authentication and registration, the terrestrial mobility management entity synchronizes the terminal device's security context to a set of satellites providing services to that terminal, so that the set of satellites can interact with the terminal device based on the security context.

[0004] However, a group of satellites providing services to a terminal device sharing the same security context poses significant security risks. For example, if one of the satellites is compromised, the services provided to that terminal device by other satellites using the same security context will face the risk of data decryption, eavesdropping, or even tampering and forgery. Summary of the Invention

[0005] This application provides a communication method and apparatus based on inter-satellite key isolation, which can realize key isolation between satellites, enabling different satellites to provide communication services to terminal devices based on different keys, thereby improving network security.

[0006] To achieve the above objectives, this application adopts the following technical solution: Firstly, a communication method based on inter-satellite key isolation is provided. This method can be applied to a terminal device or components within the terminal device, such as chips, chip systems, or other functional modules capable of calling and executing programs. For ease of understanding, a terminal device is used as an example for illustration. The method includes: the terminal device generating a first key based on a first parameter; wherein the first parameter is preset in the terrestrial network device and the terminal device; the first key is used to protect non-access stratum (NAS) messages transmitted between the terminal device and a first satellite.

[0007] Based on this, the first parameter is preset in the terrestrial network equipment and terminal equipment, that is, the first parameter is shared between the terrestrial network equipment and terminal equipment. The first satellite cannot obtain the key used by other satellites through the unknown first parameter. Similarly, other satellites cannot determine the first satellite's first key based on the unknown first parameter. Thus, key isolation between satellites is achieved during NAS transmission, thereby improving network security.

[0008] Secondly, a communication method based on inter-satellite key isolation is provided. This method can be applied to terrestrial network devices or components within terrestrial network devices, such as chips, chip systems, or other functional modules capable of calling and executing programs. For ease of understanding, a terminal device is used as an example for illustration. The method includes: the terrestrial network device generating a first key based on first parameters, the first parameters being preset in both the terrestrial network device and the terminal device; the first key being used to protect NAS messages transmitted between the terminal device and a first satellite; and sending the first key to the first satellite.

[0009] Thirdly, a communication device is provided, comprising a communication unit and a processing unit; the processing unit is configured to: generate a first key based on a first parameter; wherein the first parameter is preset in a terrestrial network device and a terminal device; the first key is used to protect non-access stratum (NAS) messages transmitted between the terminal device and a first satellite; and the communication unit is configured to perform NAS transmission based on the first key.

[0010] Fourthly, a communication device is provided, comprising a communication unit and a processing unit; the processing unit is configured to: generate a first key based on first parameters, the first parameters being preset in a terrestrial network device and a terminal device, the first key being used to protect NAS messages transmitted between the terminal device and a first satellite; the communication unit is configured to: send the first key to the first satellite.

[0011] Fifthly, a communication device is provided, comprising a memory, a transceiver, and a processor; the memory is used to store a computer program; the transceiver is used to send and receive data under the control of the processor; the processor is used to read the computer program in the memory and execute: generating a first key based on a first parameter; wherein the first parameter is preset in a terrestrial network device and a terminal device; the first key is used to protect non-access stratum (NAS) messages transmitted between the terminal device and a first satellite.

[0012] In a sixth aspect, a communication device is provided, the communication device including a memory, a transceiver, and a processor; the memory is used to store a computer program; the transceiver is used to send and receive data under the control of the processor; the processor is used to read the computer program in the memory and execute: generating a first key based on first parameters, the first parameters being preset in a terrestrial network device and a terminal device, the first key being used to protect NAS messages transmitted between the terminal device and a first satellite; and sending the first key to the first satellite.

[0013] In a seventh aspect, a processor-readable storage medium is provided, wherein the processor-readable storage medium stores a program for causing a processor to perform the methods involved in any of the designs of any of the preceding aspects.

[0014] Eighthly, a chip is provided, comprising a processor coupled to a memory for executing a computer program or instructions stored in the memory, wherein, when the processor executes the computer program or instructions, it performs the method as described in any of the designs of any of the preceding aspects.

[0015] The technical effects of the above aspects can be used for reference, and will not be elaborated further here. Attached Figure Description

[0016] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings.

[0017] Figure 1 A schematic diagram of a non-terrestrial network architecture is shown. Figure 2 A schematic diagram illustrating a network access process provided in this application; Figure 3 This is a flowchart of a communication method provided in an embodiment of this application; Figure 4 This is a schematic diagram of key generation provided in an embodiment of this application; Figure 5 This is a flowchart of another communication method provided in an embodiment of this application; Figure 6 This is an interactive flowchart of a communication method provided in an embodiment of this application; Figure 7 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application; Figure 8 This is a schematic diagram of another communication device provided in an embodiment of this application. Detailed Implementation

[0018] In the embodiments of this application, the term "and / or" describes the relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent three cases: A alone, A and B simultaneously, and B alone. The character " / " generally indicates that the preceding and following associated objects have an "or" relationship.

[0019] In the embodiments of this application, the term "multiple" refers to two or more, and other quantifiers are similar.

[0020] To better understand the above-mentioned objectives, features, and advantages of this application, the application will be further described in detail below with reference to the accompanying drawings and embodiments. It is understood that the described embodiments are only some, not all, of the embodiments of this application. The specific embodiments described herein are merely for explaining this application and are not intended to limit it. All other embodiments obtained by those skilled in the art based on the described embodiments of this application are within the scope of protection of this application.

[0021] It should be noted that in this article, relational terms such as “first” and “second” are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations.

[0022] The methods and apparatus provided in this application are based on the same concept. Since the methods and apparatus solve problems in similar ways, the implementations of the apparatus and methods can refer to each other, and repeated parts will not be described again.

[0023] Figure 1 A schematic diagram of a non-terrestrial network (NTN) architecture is shown. Figure 1 As shown, the NTN network architecture includes terminal equipment 110, satellite 120, ground station 130, and core network 140. In... Figure 1 In the network architecture shown, the link between terminal device 110 and satellite 120 can be called a service link or business link, and the communication link connecting satellite 120 to core network 140 via ground station 130 can be called a feeder link or power supply link. The ground station, also known as a gateway station, is the connection node between satellite 120 and core network 140.

[0024] Understandably, in the NTN network architecture, the movement of serving satellites may result in the service link being connected but the feeder link being disconnected; or the feeder link being connected but the service link being disconnected. For example... Figure 1As shown, when satellite 120 moves to position 1, the service link is connected, but the feeder link is disconnected; when satellite 120 moves to position 2, both the service link and the feeder link are disconnected; when satellite 120 moves to position 3, the feeder link is connected, but the service link is disconnected. In other words, in the NTN network, the satellite's service link and / or feeder link may be intermittently interrupted.

[0025] In scenarios where the feeder link connectivity of a serving satellite is discontinuous, 3GPP Release 19 introduced S&F (Signal and Data Exchange) satellite operation, an operation that provides communication services to terminal devices when the serving satellite is not simultaneously connected to the terrestrial network (i.e., the terrestrial core network). In S&F satellite operation, end-to-end signaling / data exchange is processed as a combination of two or more time-discontinuous steps. First, signaling / data exchange occurs between the terminal device and the satellite, but at this time the satellite is not connected to the terrestrial network via the feeder link. Then, the satellite moves and establishes a connection with the terrestrial network, communication occurs between the satellite and the terrestrial network, and the end-to-end exchange is completed.

[0026] Satellite 120 can be equipped with network nodes to provide network services, such as radio access network (RAN) nodes and other functional network elements.

[0027] In S&F communication mode, subscription function network elements are supported, such as the Home Subscriber Server (HSS), deployed on satellite 120 or core network 140. These subscription function network elements can store subscription data and authentication data from terminal devices. Subscription data includes, for example, network access permissions and permitted service types, while authentication data includes, for example, key parameters.

[0028] When the subscription function network element is deployed on the core network 140, the entity implementing mobility management can be distributed across satellite 120 and core network 140. For example, in the 4th generation (4G) communication system, under the split MME architecture, the mobility management entity (MME) can include an onboard MME deployed on satellite 120 and a ground-based MME deployed on core network 140. Similarly, in the 5th generation (5G) communication system, the access and mobility management function (AMF) can include an onboard portion deployed on satellite 120 (e.g., AMF-onboard) and a ground portion deployed on core network 140 (e.g., AMF-ground). For ease of understanding, the following explanation uses the split MME architecture in 4G as an example.

[0029] The terminal devices involved in the embodiments of this application can be devices that provide voice and / or data connectivity to users, handheld devices with wireless connectivity, or other processing devices connected to a wireless modem. The names of the terminal devices may differ in different systems; for example, in 5G or 6G systems, the terminal device may be called User Equipment (UE). Wireless terminal devices can be USB storage devices, other personal computer memory devices, and dongles. They can also communicate with one or more core networks (CNs) via a Radio Access Network (RAN). Wireless terminal devices can be mobile terminal devices, such as mobile phones (or "cellular" phones) and computers with mobile terminal devices. For example, they can be portable, pocket-sized, handheld, computer-embedded, or vehicle-mounted mobile devices that exchange voice and / or data with the radio access network. Examples of such devices include Personal Communication Service (PCS) phones, cordless phones, Session Initiated Protocol (SIP) phones, Wireless Local Loop (WLL) stations, Personal Digital Assistants (PDAs), personal computers, tablets, and Machine-type Communication (MTC) terminal devices. Wireless terminal devices can also be referred to as systems, subscriber units, subscriber stations, mobile stations, mobile terminals, remote stations, access points, remote terminals, access terminals, user terminals, user agents, user devices, and wireless access devices and routers / modems that meet the limitations of this definition; however, this application does not limit the scope of the embodiments described.

[0030] The access network node involved in this application embodiment is also referred to as an access network device or base station. The base station may include multiple cells providing services to terminals. Depending on the specific application, the base station may also be called a device in the access network that communicates with the wireless terminal device through one or more sectors on the air interface, or other names. The network device can be used to exchange received air frames with Internet Protocol (IP) packets, acting as a router between the wireless terminal device and the rest of the access network, where the rest of the access network may include an Internet Protocol (IP) communication network. The network device can also coordinate the attribute management of the air interface. For example, the network device involved in this application embodiment may be an evolved Node B (eNB or e-NodeB) in a long term evolution (LTE) system, a 5G base station (gNB) in a next generation system, or a Home evolved Node B (HeNB), relay node, femto, pico, network testing equipment, etc., and is not limited in this application embodiment. In some network architectures, network devices may include centralized unit (CU) nodes and distributed unit (DU) nodes, which may also be geographically separated.

[0031] For ease of description, the term "base station" will be used to refer to base stations / access devices deployed on satellites. In other words, the base station mentioned below specifically refers to base stations / access devices deployed on satellites.

[0032] The embodiments of this application do not limit the number of terminal devices, satellites, etc. in the communication system. For example, in Figure 1 In the communication system shown, due to the mobility of satellites, a group of satellites deployed in the communication system can provide network services to terminal devices to ensure service continuity, and this group of satellites can provide network services to one or more terminal devices in the system.

[0033] To facilitate understanding, let's first combine Figure 2 As shown, this provides an exemplary illustration of the process by which terminal devices access the core network in the current split MME architecture. Specifically, S1, random access.

[0034] When a terminal device joins the network, it first performs a cell search and selection. For example, the terminal device detects broadcast messages from the base station to perform a cell search, selects a cell after the search, and obtains downlink synchronization with the cell. Further, the terminal device executes a random access procedure, which achieves uplink synchronization between the terminal device and the cell.

[0035] S2, Authentication and Registration.

[0036] At time T1, the service link between satellite 1 and the terminal device is connected, but the feeder link with the core network may not be connected. The terminal device sends a registration request to the MME-onboard on satellite 1 through the base station on satellite 1 to request access to the core network. This registration request may carry the International Mobile Subscriber Identity (IMSI).

[0037] At time T2, the feeder link between Satellite 1 and the core network is established, and the processes for obtaining authentication and subscription data are executed between MME-onboard, MME-ground, and HSS. The authentication data may be, for example, an authentication vector (AV), which can include a random challenge (RAND), an authentication token (AUTN), an expected response (XRES), and the security management entity key K. ASME AV may also include: an encryption key (CK) and an integrity protection key (IK), where K... ASME It is the root key obtained based on CK / IK and the service network identifier.

[0038] At time T3, the service link between Satellite 1 and the terminal device is connected, but the feeder link with the core network may not be connected. The MME-onboard and MME-ground on Satellite 1 perform the authentication process based on the acquired authentication and subscription data. For example, the MME-onboard on Satellite 1 sends a user authentication request to the terminal device, carrying the RAND and AUTN from the aforementioned AV. The terminal device verifies the validity of AUTH. If the verification is successful, it calculates the response value based on the received RAND from the AV and sends a user authentication response carrying the response value to the MME-onboard on Satellite 1. The MME-onboard receives the RES from the terminal device and compares it with the XRES in the AV. If XRES and RES match, authentication is successful; otherwise, authentication fails. XRES and RES are generated based on the same algorithm and input parameters.

[0039] After successful authentication, the terminal device and MME-onboard have the same root key K. ASME MME-onboard will use the root key K ASME The core component of the terminal device's security context is stored within the terminal device's context. Furthermore, the MME-onboard can send a security mode command to the terminal device, informing it which encryption and integrity protection algorithm to use; the terminal device responds to the MME-onboard with this security mode command, sending a security mode completion message. Based on this, the MME-onboard completes the creation of the terminal device's context.

[0040] The context of a terminal device can include the aforementioned security context, location information, session management context, etc. The security context can also include information based on the root key K. ASME Derived keys, such as the NAS confidentiality protection key K NASenc and NAS integrity protection key K NASint Security context can also include counters, such as NAS counts; security context can also include encryption algorithms, security context states, etc. S3, Security Context Synchronization.

[0041] The MME-onboard on satellite 1 sends the context of the terminal device to the MME-ground, which then synchronizes this context with the candidate satellites for that terminal device, such as satellites 1 through m. It should be understood that because the terminal device can access the network or transmit data through the MME-onboards of different serving satellites at different times, it is necessary to synchronize the terminal device's context with multiple subsequent satellites that may provide communication services to the terminal device (i.e., candidate satellites). This ensures that any candidate satellite can communicate with the terminal device based on its context.

[0042] However, using the same security context on MME-onboards across different satellites can lead to key stream reuse issues. In this case, the network faces significant security vulnerabilities. For example, if one satellite is compromised, services provided to the terminal device by other satellites using the same security context are at risk of data decryption, eavesdropping, or even tampering and forgery.

[0043] To address the aforementioned technical problems, this application proposes an inter-satellite key spacing scheme. By introducing parameters shared only between the terminal device and the terrestrial network, different keys are generated for different satellites to replace the root key (such as K) in the security context. ASMEBased on this, different satellites communicate with the terminal device using different security contexts, achieving key isolation between satellites and thus improving network security.

[0044] The communication method provided in the embodiments of this application will now be described with reference to the accompanying drawings.

[0045] Figure 3 This is a flowchart of a communication method 200 provided in an embodiment of this application. Figure 3 The execution subject in the illustrated embodiment is a terminal device. However, it should be understood that this application does not limit the execution subject; for example, the terminal device can be replaced by components in the terminal device, such as a chip, a chip system, or other functional modules capable of calling and executing programs.

[0046] In some embodiments, the terrestrial network equipment involved can be implemented, for example, as... Figure 1 One or more network elements in the core network 140, involving satellites (such as the first satellite, the second satellite, etc.), can be implemented as Figure 1 Satellite 120 or Figure 1 Satellite not shown.

[0047] It should be noted that when the embodiments of this application are applied to the split-MME architecture, the relevant steps executed by the terrestrial network equipment can be specifically executed by the mobility management network elements in the terrestrial network. These terrestrial mobility management network elements can be, for example, the ground mobility management network elements mentioned above, such as MME-ground in 4G, or AMF-ground in 5G. Similarly, the relevant steps executed by the satellite can be specifically executed by the mobility management network elements in the satellite. These satellite mobility management network elements can be, for example, the spaceborne mobility management network elements mentioned above, such as MME-onboard in 4G, or AMF-onboard in 5G. It should be understood that some implementations of the embodiments of this application also involve base stations in the satellite. For example, the first satellite can interact with the terminal device through the base station, such as sending broadcast messages to the terminal device to achieve random access.

[0048] For ease of understanding, the following explanation primarily uses the interaction between terminal devices, satellites, and terrestrial network equipment as an example. Unless otherwise specified, the actions performed by the satellite can be implemented by any one or more functions within the satellite, and the actions performed by the terrestrial network equipment can be implemented by any one or more functions within the terrestrial network equipment. Unless otherwise specified, the satellites involved in the embodiments of this application belong to a group of satellites that provide network services to the terminal devices.

[0049] In this embodiment, the first satellite can be any one of a group of satellites. Other satellites providing network services to the terminal device can be found in the description of the first satellite, which will not be repeated here for brevity. In this embodiment, the second satellite is the satellite that provides initial authentication services to the terminal device. The second satellite may be the same as or different from the first satellite; this application does not limit this.

[0050] Optionally, mobility management network elements (such as terrestrial mobility management network elements and / or spaceborne mobility management network elements) can be replaced with components in mobility-associated network elements, such as chips, chip systems, or other functional modules capable of calling and executing programs. It should also be understood that the embodiments in this application are not limited to... like Figure 3 As shown, the method 200 may include the following S210.

[0051] S210, the terminal device generates a first key based on the first parameter.

[0052] The first key is used to protect NAS messages transmitted between the terminal device and the first satellite. In other words, the terminal device can generate the first key based on the first parameters and send NAS messages to the first satellite based on the first key, that is, encrypt the NAS messages through the first key. Correspondingly, the first satellite can receive the NAS messages sent by the terminal device based on the first key, that is, decrypt the received NAS messages through the first key. Alternatively, the first satellite can send NAS messages to the terminal device based on the first key, that is, encrypt the NAS messages through the first key. Correspondingly, the terminal device can generate the first key based on the first parameters and receive the NAS messages sent by the first satellite based on the first key, that is, decrypt the received NAS messages through the first key.

[0053] It should be noted that the above-mentioned generation of the first key based on the first parameter can also be described as obtaining the first key based on the first parameter, or deriving the first key based on the first parameter.

[0054] Based on the above understanding, both the terminal device and the first satellite possess a first key, thereby enabling NAS transmission based on the first key. NAS transmission can include uplink transmission of NAS messages and / or downlink transmission of NAS messages. To achieve key isolation between different satellites in the communication system, the first key must meet at least the following two conditions: Condition 1, the first key used by the first satellite is different from the key used by another satellite in the communication system; that is, the first key is the exclusive key of the first satellite and only applies to NAS transmission between the first satellite and the terminal device. Condition 2, the first satellite cannot obtain the keys used by other satellites in the communication system.

[0055] To satisfy condition one above, the terminal device can generate different dedicated keys for different satellites. For example, the terminal device can generate key A for the first satellite, key B for the second satellite, and key C for the third satellite, etc. This application does not limit the input parameters used when generating dedicated keys for different satellites. For example, the terminal device can use the identifier of the first satellite as an input parameter to generate a dedicated key for the first satellite. The key generation process will be described in detail below.

[0056] To satisfy condition two above, preventing the first satellite from obtaining the keys used by other satellites, the aforementioned first parameter is unknown to the first satellite, or in other words, the first satellite either does not have this first parameter preset or has not acquired it. In this case, the first satellite can perform NAS transmission with the terminal device using the first key configured by the terrestrial network equipment.

[0057] In one implementation that satisfies condition two above, the first parameter can be preset in the terrestrial network device and the terminal device; that is, the first parameter is a shared secret parameter between the terrestrial network device and the terminal device. This application embodiment does not limit the naming of the first parameter. The first parameter being preset in the terrestrial network device can be preset in a network element within the terrestrial network, such as in an HSS network element within the terrestrial network. The first parameter being preset in both the terrestrial network device and the terminal device can mean that the terrestrial network device and the terminal device store the first parameter, which can be agreed upon by a protocol.

[0058] For example, NAS transmission between the terminal device and the first satellite based on the first key can be either NAS transmission between the terminal device and the first satellite based on the security context of the terminal device, or NAS transmission between the terminal device and the first satellite based on the context of the terminal device. The context of the terminal device and the security context can be found in the preceding description. As mentioned earlier, the security context includes the first key, and the security context within the context includes the first key.

[0059] For example, the terminal device can also initialize a NAS COUNT value, which is used for transmitting NAS messages between the terminal device and the first satellite. The NAS COUNT is a monotonically increasing counter that encrypts and protects the integrity of each NAS message, preventing cryptographic attacks and replay attacks. The terminal device can initialize the NAS COUNT value when it first establishes a connection with the first satellite, or in other words, it can initialize the NAS COUNT value when generating the first key, and then count it during each subsequent NAS message transmission with the first satellite.

[0060] As previously mentioned, the NAS COUNT can be included in the security context of the end device. Optionally, the end device can place the generated first key and the initialized NAS COUNT into the security context, and perform NAS transfer with the network device based on the obtained security context.

[0061] As a first implementation, the first key may include a NAS confidentiality protection key, such as K. NASenc * and NAS integrity protection keys, such as K NASint For ease of description, the NAS confidentiality protection key and the NAS integrity protection key are collectively referred to as the NAS key. In the first implementation described above, the terminal device generates the NAS key based on the first parameter and performs NAS transmission with the first satellite based on this NAS key.

[0062] As a second implementation, the first key can be used to generate a NAS key. For example, the first key can be K in a 4G communication system. ASME *Or K in 5G communication systems AMF In the second implementation described above, the terminal device generates a first key based on the first parameter, generates a NAS key based on the first key, and then performs NAS transmission with the first satellite based on the NAS key.

[0063] Based on any of the above implementations of the first key, optionally, the first key can be the root key in the security context of the terminal device (such as the K key in 4G). ASME Or K in 5G AMF This is obtained by [the process]. The security context can refer to the security context obtained after completing the authentication and registration process of the terminal device. For ease of description, the root key in the secure uplink message of the terminal device is referred to as the second key.

[0064] Optionally, the terminal device can use the first parameter as input to the key derivation algorithm to generate the first key. In one implementation, the first parameter can be an input parameter of the key derivation algorithm; in another implementation, the first parameter can be a key, that is, the first parameter is the input key of the key derivation algorithm. Generally, the key is a string of fixed length, while the length of the parameter characters is not limited. It should be understood that the embodiments of this application do not limit the key derivation algorithm. For example, the key derivation parameter can be an HMAC-based extract-and-expand key derivation function (HKDF), where HMAC is an abbreviation for hash-based message authentication code. Another example is a password-based key derivation function 2 (PBKDF2), etc. The embodiments of this application also do not limit the naming of the key derivation algorithm; for example, it can also be called a key derivation cryptographic algorithm, etc.

[0065] In conjunction with the first implementation of the first key described above, i.e., the first key is a NAS key, the generation of the first key can include either Example 1 or Example 2: Example 1: The first parameter is used as the input parameter for the key derivation algorithm, and the second key (e.g., K) ASME Using K as the input key, a first key is generated. Combining this with the first implementation of the first key described above, the generated first key can be K. ASME * Combining the second implementation method of the first key described above, the generated first key can be a NAS key, see [link / reference]. Figure 4 (a) in the middle.

[0066] Example 2: The first parameter is used as the input key for the key derivation algorithm, K. ASME The first key is generated using K as an input parameter. Combining the first implementation method of the first key described above, the generated first key can be K. ASME * Combining the second implementation method of the first key described above, the generated first key can be a NAS key, see [link / reference]. Figure 4 (b) in the middle.

[0067] It is understandable that in Example 1 or Example 2 above, K is generated based on the same input parameters and input key. ASME The key derivation algorithm used for * and NAS keys is different.

[0068] Optionally, the input parameters of the key derivation algorithm may also include a second parameter, which is associated with the first satellite. For example, the second parameter may be the identifier of the first satellite, or any parameter used to distinguish different satellites, such as the identifier of the MME in the first satellite.

[0069] Optionally, other input parameters, such as NAS COUNT, may be included when deriving the first key; this application does not limit this.

[0070] Therefore, in this embodiment, the terminal device generates a first key based on the first parameter. This first key is used to protect the NAS messages transmitted between the terminal device and the first satellite. The first parameter is preset in the terrestrial network device and the terminal device, that is, the first parameter is a shared secret parameter between the terrestrial network device and the terminal device. The keys used by other satellites are also determined based on the first parameter, so that the first satellite cannot determine the keys of other satellites based on the first parameter that has not been obtained. Similarly, other satellites cannot determine the first key of the first satellite based on the first parameter that has not been obtained, thereby achieving key isolation between satellites during NAS transmission.

[0071] Figure 5 This is a flowchart of another communication method 300 provided in the embodiments of this application. Figure 5 The implementation entity in the illustrated embodiment is a terrestrial network device. However, it should be understood that this application does not limit the implementation entity; for example, the terrestrial device can be replaced by components within the terrestrial network device, such as a chip, chip system, or other functional modules capable of calling and executing programs. A description of the terrestrial network device can be found in the foregoing examples, and will not be repeated here for brevity.

[0072] like Figure 5 As shown, the method 300 may include the following steps S310 and S320.

[0073] S310, the terrestrial network device generates a first key based on the first parameter. The first parameter is preset in the terrestrial network device and the terminal device. The first key is used to protect the NAS messages transmitted between the terminal device and the first satellite.

[0074] In S310 above, the method by which the terrestrial network device generates the first key based on the first parameter is similar to S210 in the above embodiments. That is, the terrestrial network device and the terminal device can use the same method to generate the first key based on the first parameter. The descriptions of the first parameter and the first key can be found in the descriptions of any of the foregoing embodiments, and will not be repeated here for the sake of brevity.

[0075] It should be noted that, for terrestrial network devices, if the first key is generated based on the first parameter and the second key, the second key may be sent to the terrestrial network device by the second satellite. For example, the second satellite may send the second key to the terrestrial network device after completing the authentication and registration process of the terminal device, or send the security context including the second key to the terrestrial network device, or send the context including the second key to the terrestrial network device.

[0076] S320, the ground network equipment sends the first key to the first satellite.

[0077] As previously mentioned, the first parameter is unknown to the first satellite. The first satellite cannot generate a key based on this unknown first parameter and requires the ground network device to send the first key to the first satellite. This application does not limit the method by which the ground network device sends the first key to the first satellite. For example, the ground network device can directly send the first key to the first satellite, or it can send a security context including the first key, or it can send a context including the first key to the first satellite.

[0078] As previously mentioned, the first key can be a NAS key, or it can be used to generate a NAS key. If the first key is used to generate a NAS key, the first satellite generates a NAS key based on the received first key, and then performs NAS transmission with the terminal device based on the NAS key.

[0079] Based on this, the terrestrial network device synchronizes a first key generated based on the first parameter to the first satellite. This first key is used to protect the NAS messages transmitted between the terminal device and the first satellite. The first parameter is preset in the terrestrial network device and the terminal device, that is, the first parameter is a shared secret parameter between the terrestrial network device and the terminal device. The keys used by other satellites are also determined based on the first parameter, so that the first satellite cannot determine the keys of other satellites based on the first parameter that has not been obtained. Similarly, other satellites cannot determine the first key of the first satellite based on the first parameter that has not been obtained, thereby achieving key isolation between satellites during NAS transmission.

[0080] Figure 6 This is an interactive flowchart of a communication method 400 provided in an embodiment of this application. Figure 6 The illustrated embodiment uses the interaction between a terminal device, a first satellite, a second satellite, and a ground network device as an example for explanation. The terminal device, the first satellite, the second satellite, and the ground network device are described in the foregoing embodiments, and will not be repeated here for brevity.

[0081] It should be noted that, for ease of understanding, some examples in this embodiment are only illustrated using the MME architecture in a 4G scenario, but it should be understood that it can be applied to separate mobility management entities / functions in other communication scenarios (such as 5G communication or future communication).

[0082] like Figure 6 As shown, the method 400 may include some or all of the following steps: S410, random access.

[0083] For example, the base station in the second satellite can send broadcast messages, and the terminal device can perform cell search and selection by detecting the broadcast messages, and achieve downlink synchronization with the cell. Furthermore, the terminal device performs random access to achieve uplink synchronization with the cell.

[0084] In some implementations, the broadcast message sent by the base station in the second satellite may include a second parameter associated with the second satellite. This second parameter could be an identifier of the second satellite, or an identifier of a mobility management network element within the second satellite. This second parameter can be used for subsequent key generation for that second satellite.

[0085] For details regarding this step, please refer to S1 above.

[0086] S420, Authentication and Registration.

[0087] For example, the terminal device sends a registration request to the mobility management network element in the second satellite via a base station in the second satellite to request access to the core network. In response to the registration request, the second satellite obtains the terminal device's authentication data and subscription data from the home subscriber server in the terrestrial network. The authentication data may include a second key, such as a security management entity key K. ASME The mobile management network element on the second satellite executes the authentication process based on the acquired authentication and subscription data. After successful authentication, the terminal device and the mobile association network element on the second satellite possess the same root key K. ASME The second satellite will use the root key K ASME The core component of the security context of this terminal device is stored within the terminal device's context. The terminal device's context is obtained upon completing the authentication and registration process.

[0088] For details not explained in this step, please refer to S2 above.

[0089] S430, the second satellite sends a security context to the ground network equipment, which includes a second key, such as K. ASME .

[0090] In this step, the second satellite sends a security context to the ground network device, enabling the ground network device to determine the second key used by the terminal device. Besides sending the security context, the second satellite can synchronize the second key with the ground network device in two other ways: first, the second satellite directly sends the second key to the ground network device; second, the second satellite sends the terminal device's context, which includes the aforementioned security context, i.e., the second key, to the ground network device.

[0091] In the S&F scenario, with the feeder link between the second satellite and the ground network equipment connected, the second satellite synchronizes the second key to the ground network equipment.

[0092] S440, Ground network equipment updates security context.

[0093] In this step, the terrestrial network device can determine the security context for each satellite, such as updating the second key in the security context to the key corresponding to each satellite. For example, when updating the security context for the first satellite, the terrestrial network device can generate a first key for the first satellite based on the second key, the second parameter, and the preset first parameter in the security context, and then use the first key as the root key of the security context.

[0094] In S450, terrestrial network equipment can send a corresponding security context to each of a group of satellites providing network services to terminal devices. For example, see... Figure 6 In S450-1, the ground network device can send an updated security context corresponding to the first satellite to the first satellite, which includes the first key; for example, see S450-1. Figure 6 In the S450-2, the ground network device can send an updated security context corresponding to the second satellite to the second satellite. This security context includes a key that can be used for NAS transmission.

[0095] For example, a terrestrial network device can determine a group of satellites (such as a list of candidate satellites) to provide network services to a terminal device based on ephemeris information and the location of the terminal device. Ephemeris information refers to the satellite's motion characteristics, such as orbital parameters, angular velocity, and / or speed. The terrestrial network device can use this information to calculate the satellite's position in its orbit at each moment.

[0096] It should be understood that this embodiment is only used as an example of a terrestrial network device updating its security context, and is not intended to limit the scope of the embodiment. For example, a terrestrial network device can update the security context... In one possible implementation, the terrestrial network device can update the context of the terminal device for each satellite. For example, after receiving the context of the terminal device sent by the second satellite, the terrestrial network device generates a first key for the first satellite based on the second key, first parameter, and second parameter in the context, and uses this first key as the root key of the security context in the context. Then, the terrestrial network device sends the updated context to the first satellite.

[0097] In another possible implementation, the terrestrial network can update the root key for each satellite. For example, the terrestrial network device can generate a first key for the first satellite based on a second key, a first parameter, and a second parameter, and send this first key to the first satellite as the root key for the security context of the first satellite. Furthermore, the first satellite can update the security context and / or context of the terminal device based on the received first key.

[0098] During the S&F process, ground network equipment can send updated security context (or context, or first key) to a satellite (such as the first satellite) while the feeder link is connected.

[0099] In some implementations, the terrestrial network device can send information to the first satellite indicating the validity period of the first key. During the validity period of the first key, the first satellite can use the first key to perform NAS transmissions with the terminal device; outside the validity period of the first key, the first satellite will not use the first key to perform NAS transmissions with the terminal device. The first satellite not using the first key to perform NAS transmissions with the terminal device can be understood as the first satellite using another key (such as a second key) to perform NAS transmissions with the terminal device, or, for example, the first satellite ceasing NAS transmissions with the terminal device until the terrestrial network device provides a valid first key.

[0100] The information indicating the validity period of the first key can be included in the security context for the first satellite. The ground network device indicates the validity period of the first key by sending an updated security context to the first satellite. However, this application does not limit this; for example, the information regarding the validity period of the first key can be encapsulated independently and sent to the first satellite.

[0101] In some implementations, the first satellite can send information indicating the validity period of the first key to the terminal device. Optionally, the first satellite can send information indicating the validity period of the first key to the terminal device based on the validity period of the first key indicated by the terrestrial network device. During the validity period of the first key, the terminal device can use the first key to perform NAS transmission with the first satellite; outside the validity period of the first key, the terminal device will not use the first key to perform NAS transmission with the first satellite. The terminal device not using the first key to perform NAS transmission with the first satellite can be understood as the terminal device using another key (such as a second key) to perform NAS transmission with the first satellite, or, for example, the terminal device stopping NAS transmission with the first satellite until the first key becomes valid (e.g., updating the validity period of the first key).

[0102] Based on the above implementation, the first satellite can send information indicating the validity period of the first key to the terminal device through NAS message transmission. For example, the first satellite can carry information indicating the validity period of the first key in the first NAS message sent to the terminal device.

[0103] This application does not limit the validity period of the first key to be implemented through dynamic configuration. For example, the validity period of the first key can also be agreed upon by the protocol, or the validity period of the first key can be preset in the terminal device and the first satellite.

[0104] S460, the terminal device generates a first key based on the first parameter.

[0105] This process has been described in the preceding examples, such as S210 above. It should be noted that the embodiments of this application do not limit the execution order between S460 and S430. For example, S460 and S430 can be executed synchronously or sequentially. When S460 and S430 are executed sequentially, S460 can be executed before or after S430. Similarly, the embodiments of this application do not limit the execution order between S460 and S440, nor do they limit the execution order between S460 and S450.

[0106] S470, NAS messages are transmitted between the terminal device and the first satellite based on a security context.

[0107] The security context includes a first key. The terminal device and the first satellite transmit NAS messages based on the security context, or the terminal device and the first satellite transmit NAS messages based on the first key, or the terminal device and the first satellite transmit NAS messages based on a context, where the security context includes the first key.

[0108] In the S&F scenario, the terminal device and the first satellite can transmit NAS messages based on the security context, provided that the service link is connected (the feeder link is connected or not).

[0109] This application does not limit the NAS messages transmitted between the terminal device and the first satellite. For example, the NAS message may include data or signaling transmitted via NAS. When the NAS message includes data transmitted via NAS, the NAS message sent by the first satellite to the terminal device may, for example, carry downlink data sent by the application function (AF) network element to the terminal device, or the NAS message sent by the terminal device to the first satellite may carry uplink data sent by the terminal device to the AF network element. When the NAS message includes signaling transmitted via NAS, the NAS message sent by the first satellite to the terminal device may, for example, indicate the establishment of a secure connection, and the NAS message sent by the terminal device to the first satellite may, for example, be used to respond to the establishment of a secure connection.

[0110] For example, when the terminal device and the first satellite first transmit NAS via a secure connection based on the first key, the terminal device and the first satellite can respectively initialize the NAS COUNT value in their own stored security context. For example, the first satellite can initialize the NAS COUNT value after receiving an updated security context (or receiving the first key or receiving an updated context), and the terminal device can initialize the NAS COUNT value when generating the first key.

[0111] Understandably, during NAS transmissions after a secure connection is established between the terminal device and the first satellite, the terminal device can perform NAS transmissions based on the generated first key, and the first satellite can perform NAS transmissions based on the acquired first key. That is, the terminal device does not need to generate a new first key for each NAS transmission, and the first satellite does not need to acquire a new first key for each NAS transmission. Similarly, during NAS transmissions after a secure connection is established between the terminal device and the first satellite, the NAS COUNT value does not need to be initialized.

[0112] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art will understand that the embodiments of this application are not limited to the described order of actions, because according to the embodiments of this application, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art will understand that the embodiments described in the specification are all optional embodiments.

[0113] It should also be understood that, unless otherwise specified or logically conflicting, the terminology and / or descriptions in the various embodiments of this application are consistent and can be referenced by each other. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.

[0114] This application also provides a communication device that can be used to implement the functions of the terminal device or terrestrial network device described in the above method embodiments. (See also...) Figure 7 This is a schematic diagram of the structure of a communication device 500 provided in an embodiment of this application. Figure 7 As shown, the communication device 500 includes a communication unit 501 and a processing unit 502.

[0115] In one design, a communication device 500 is used to implement the functions of a terminal device in the method embodiment. A processing unit 502 is used to: generate a first key based on first parameters; wherein the first parameters are preset in the terrestrial network device and the terminal device; the first key is used to protect NAS messages transmitted between the terminal device and a first satellite; and a communication unit 503 is used to perform NAS transmission based on the first key.

[0116] In some embodiments, the first key is generated based on the first parameter and the second key, and the second key is used to authenticate the terminal device by the second satellite, which is a satellite that provides initial authentication for the terminal device.

[0117] In some embodiments, the first key is determined based on a first parameter, a second key, and a second parameter, wherein the second parameter is associated with a first satellite.

[0118] In some embodiments, the first key is a NAS key, or the first key is used to generate a NAS key, which includes a NAS confidentiality protection key and a NAS integrity protection key.

[0119] In some embodiments, the method further includes: initializing a non-access stratum count (NAS COUNT) value, which is used to transmit NAS messages between the terminal device and the first satellite.

[0120] In some embodiments, the method further includes receiving information transmitted by a first satellite indicating the validity period of the first key.

[0121] In another design, the communication device 500 is used to implement the functions of the terrestrial network device in the method embodiment. The processing unit 502 is used to: generate a first key based on a first parameter, the first parameter being preset in the terrestrial network device and the terminal device, the first key being used to protect NAS messages transmitted between the terminal device and the first satellite; the communication unit 501 is used to: send the first key to the first satellite.

[0122] In some embodiments, the first key is generated based on the first parameter and the second key, and the second key is used to authenticate the terminal device by the second satellite, which is a satellite that provides initial authentication for the terminal device.

[0123] In some embodiments, the first key is determined based on a first parameter, a second key, and a second parameter, wherein the second parameter is associated with a first satellite.

[0124] In some embodiments, the first key is a NAS key, or the first key is used to generate a NAS key, which includes a NAS confidentiality protection key and a NAS integrity protection key.

[0125] In some embodiments, the method further includes sending information to the first satellite indicating the validity period of the first key.

[0126] Optionally, the communication unit 501 can also be used to support the communication device 500 in performing its functions. Figures 3 to 6 The communication function involved in any of the above. And / or, the processing unit 502 may also be used to support the communication device 500 in performing the following functions. Figures 3 to 6 The processing functions involved in any one of them.

[0127] It is understood that the division of units in the embodiments of this application is illustrative and only represents a logical functional division. In actual implementation, there may be other division methods. Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated units described above can be implemented in hardware or as software functional units.

[0128] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a processor-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute all or part of the steps of the methods of the various embodiments of this application.

[0129] This application also provides another communication device. See [link / reference] Figure 8 This is a schematic diagram of another communication device 600 provided in an embodiment of this application. Figure 8 As shown, the communication device 600 includes a memory 601, a transceiver 602, and a processor 603.

[0130] In one design, a communication device 600 is used to implement the functions of the terminal device in the method embodiment. In this design, a memory 601 is used to store a computer program; a transceiver 602 is used to send and receive data under the control of a processor 603; the processor 603 is used to read the computer program in the memory 601 and execute it: generating a first key based on first parameters; wherein the first parameters are preset in the terrestrial network device and the terminal device; the first key is used to protect non-access stratum (NAS) messages transmitted between the terminal device and a first satellite.

[0131] In some embodiments, the first key is generated based on the first parameter and the second key, and the second key is used to authenticate the terminal device by the second satellite, which is a satellite that provides initial authentication for the terminal device.

[0132] In some embodiments, the first key is determined based on a first parameter, a second key, and a second parameter, wherein the second parameter is associated with a first satellite.

[0133] In some embodiments, the first key is a NAS key, or the first key is used to generate a NAS key, which includes a NAS confidentiality protection key and a NAS integrity protection key.

[0134] In some embodiments, the method further includes: initializing a non-access stratum count (NAS COUNT) value, which is used to transmit NAS messages between the terminal device and the first satellite.

[0135] In some embodiments, the method further includes receiving information transmitted by a first satellite indicating the validity period of the first key.

[0136] In another design, the communication device 600 is used to implement the functions of the terrestrial network device in the method embodiment. In this design, the memory 601 is used to store computer programs; the transceiver 602 is used to send and receive data under the control of the processor 603; the processor 603 is used to read the computer program in the memory 601 and execute: generating a first key based on a first parameter, the first parameter being preset in the terrestrial network device and the terminal device, the first key being used to protect NAS messages transmitted between the terminal device and the first satellite; and sending the first key to the first satellite.

[0137] In some embodiments, the first key is generated based on the first parameter and the second key, and the second key is used to authenticate the terminal device by the second satellite, which is a satellite that provides initial authentication for the terminal device.

[0138] In some embodiments, the first key is determined based on a first parameter, a second key, and a second parameter, wherein the second parameter is associated with a first satellite.

[0139] In some embodiments, the first key is a NAS key, or the first key is used to generate a NAS key, which includes a NAS confidentiality protection key and a NAS integrity protection key.

[0140] In some embodiments, the method further includes sending information to the first satellite indicating the validity period of the first key.

[0141] In the above embodiments, the transceiver is used to receive and transmit data under the control of the processor. The bus architecture can include any number of interconnected buses and bridges, specifically linking various circuits of one or more processors (represented by the processor) and memories (represented by the memory). The bus architecture can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. The transceiver can be multiple components, including a transmitter and a receiver, providing a unit for communicating with various other devices over a transmission medium, including wireless channels, wired channels, optical fibers, and other transmission media.

[0142] The processor manages the bus architecture and general processing, while the memory stores the data used by the processor during operation. The processor can be a central processing unit (CPU), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a complex programmable logic device (CPLD). Processors can also employ a multi-core architecture.

[0143] It should be noted that the communication device provided in this application embodiment can implement all the method steps implemented in the above method embodiment and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.

[0144] Based on the same concept, embodiments of this application also provide a processor-readable storage medium storing a program for causing a processor to perform the steps involved in the above-described method embodiments. The processor-readable storage medium can be any available medium or data storage device accessible to a processor, including but not limited to RAM, ROM, EEPROM, CD-ROM or other optical storage (e.g., CD, DVD, BD, HVD, etc.), disk storage media or other magnetic storage devices (e.g., floppy disk, hard disk, magnetic tape, magneto-optical disk (MO), or any other medium capable of carrying or storing desired program code having an instruction or data structure form and accessible by a computer).

[0145] Based on the same concept, this application also provides a computer program product, which includes a computer program or instructions that, when run on a computer, cause the computer to perform the methods provided in the above embodiments.

[0146] Based on the same concept, this application also provides a chip including a processor coupled to a memory for executing a computer program or instructions stored in the memory. When the processor executes the computer program or instructions, the method provided in the above embodiments is implemented.

[0147] It should also be understood that the memory mentioned in the embodiments of this application can be volatile memory and / or non-volatile memory. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM). For example, RAM can be used as an external cache. By way of example and not limitation, RAM includes various forms such as: static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM). It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA, or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, the memory (storage module) can be integrated into the processor.

[0148] This application also provides a chip system. The chip system (or processing system) includes logic circuits and an input / output interface. The logic circuits can be processing circuits within the chip system. The logic circuits can be coupled to memory units, calling instructions stored in the memory units, enabling the chip system to implement the methods and functions of the various embodiments of this application. The input / output interface can be input / output circuits within the chip system, outputting processed information or inputting data or signaling information to be processed into the chip system for processing.

[0149] As one approach, this chip system is used to implement the operations described in the various method embodiments above. For example, logic circuits are used to implement the relevant operations in the method embodiments above; input / output interfaces are used to implement the sending and / or receiving related operations in the method embodiments above.

[0150] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.

[0151] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-executable instructions. These computer-executable instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0152] These processor-executable instructions may also be stored in a processor-readable memory that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the processor-readable memory produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0153] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. A communication method based on inter-satellite key isolation, characterized in that, Applied to terminal devices, including: A first key is generated based on the first parameter; where... The first parameter is preset in the terrestrial network device and the terminal device; the first key is used to protect the non-access stratum (NAS) messages transmitted between the terminal device and the first satellite.

2. The method according to claim 1, characterized in that, The first key is generated based on the first parameter and the second key. The second key is used to authenticate the terminal device by a second satellite, which is a satellite that provides initial authentication for the terminal device.

3. The method according to claim 2, characterized in that, The first key is determined based on the first parameter, the second key, and the second parameter, the second parameter being associated with the first satellite.

4. The method according to any one of claims 1 to 3, characterized in that, The first key is a NAS key, or the first key is used to generate a NAS key, the NAS key including a NAS confidentiality protection key and a NAS integrity protection key.

5. The method according to any one of claims 1 to 4, characterized in that, Also includes: Initialize the non-access stratum counter (NAS COUNT) value, which is used to transmit NAS messages between the terminal device and the first satellite.

6. The method according to any one of claims 1 to 5, characterized in that, Also includes: Receive information sent by the first satellite indicating the validity period of the first key.

7. A communication method based on inter-satellite key isolation, characterized in that, Applications in terrestrial network equipment, including: A first key is generated based on a first parameter, which is preset in the terrestrial network device and the terminal device. The first key is used to protect NAS messages transmitted between the terminal device and the first satellite. Send the first key to the first satellite.

8. The method according to claim 7, characterized in that, The first key is generated based on the first parameter and the second key. The second key is used to authenticate the terminal device by a second satellite, which is a satellite that provides initial authentication for the terminal device.

9. The method according to claim 8, characterized in that, The first key is determined based on the first parameter, the second key, and the second parameter, wherein the second parameter is associated with the first satellite.

10. The method according to any one of claims 7 to 9, characterized in that, The first key is a NAS key, or the first key is used to generate a NAS key, the NAS key including a NAS confidentiality protection key and a NAS integrity protection key.

11. The method according to claim 10, characterized in that, Also includes: Send information to the first satellite indicating the validity period of the first key.

12. A communication device, characterized in that, The communication device includes a processing unit; The processing unit is used to: generate a first key based on a first parameter; wherein... The first parameter is preset in the terrestrial network equipment and the terminal equipment; the first key is used to protect the NAS messages transmitted between the terminal equipment and the first satellite.

13. A communication device, characterized in that, The communication device includes a communication unit and a processing unit; The processing unit is used to: generate a first key based on a first parameter, wherein the first parameter is preset in the terrestrial network device and the terminal device, and the first key is used to protect NAS messages transmitted between the terminal device and the first satellite; The communication unit is used to send the first key to the first satellite.

14. A communication device, characterized in that, The communication device includes a memory, a transceiver, and a processor; The memory is used to store computer programs; the transceiver is used to send and receive data under the control of the processor; the processor is used to read the computer programs in the memory and execute them. A first key for the first satellite is generated based on the first parameters; whereby... The first parameter is preset in the terrestrial network equipment and the terminal equipment; the first key is used to protect the NAS messages transmitted between the terminal equipment and the first satellite.

15. The apparatus according to claim 14, characterized in that, The first key is generated based on the first parameter and the second key. The second key is used to authenticate the terminal device by a second satellite, which is a satellite that provides initial authentication for the terminal device.

16. The apparatus according to claim 15, characterized in that, The first key is determined based on the first parameter, the second key, and the second parameter, the second parameter being associated with the first satellite.

17. The apparatus according to any one of claims 14 to 16, characterized in that, The first key is a NAS key, or the first key is used to generate a NAS key, the NAS key including a NAS confidentiality protection key and a NAS integrity protection key.

18. The apparatus according to any one of claims 14 to 17, characterized in that, Also execute: Initialize the NAS COUNT value, which is used to transmit NAS messages between the terminal device and the first satellite.

19. The apparatus according to any one of claims 14 to 18, characterized in that, Also execute: Receive information sent by the first satellite indicating the validity period of the first key.

20. A communication device, characterized in that, The communication device includes a memory, a transceiver, and a processor; The memory is used to store computer programs; the transceiver is used to send and receive data under the control of the processor; the processor is used to read the computer programs in the memory and execute them. A first key is generated based on a first parameter, which is preset in the terrestrial network device and the terminal device. The first key is used to protect NAS messages transmitted between the terminal device and the first satellite. Send the first key to the first satellite.

21. The apparatus according to claim 20, characterized in that, The first key is generated based on the first parameter and the second key. The second key is used to authenticate the terminal device by a second satellite, which is a satellite that provides initial authentication for the terminal device.

22. The apparatus according to claim 21, characterized in that, The first key is determined based on the first parameter, the second key, and the second parameter, wherein the second parameter is associated with the first satellite.

23. The apparatus according to any one of claims 20 to 22, characterized in that, The first key is a NAS key, or the first key is used to generate a NAS key, the NAS key including a NAS confidentiality protection key and a NAS integrity protection key.

24. The apparatus according to claim 23, characterized in that, Also execute: Send information to the first satellite indicating the validity period of the first key.

25. A processor-readable storage medium, characterized in that, The processor-readable storage medium stores a program for causing the processor to perform the method as described in any one of claims 1 to 11.