Communication method, device and system, electronic equipment, storage medium and program product

By adjusting the granularity of message transmission in the satellite communication system and utilizing attribute information such as location and region, the problem of the system's inability to send messages in a targeted manner was solved, thereby improving communication security.

CN121509975APending Publication Date: 2026-02-10CHINA MOBILE COMM LTD RES INST +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411080170.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-08-07
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

In satellite communications, due to the wide coverage area, system messages cannot be specifically sent to authorized users, leading to communication security risks.

Method used

By flexibly adjusting the granularity of system message sending and utilizing attribute information such as location, region, service, communication type, and terminal capabilities, an appropriate sending granularity can be determined, enabling personalized sending of system messages.

Benefits of technology

This ensures that system messages are sent to authorized users in a targeted manner, thereby improving communication security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121509975A_ABST
    Figure CN121509975A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of communication, and particularly provides a communication method, device and system, electronic equipment, a storage medium and a program product. In the disclosure, a network node sends a system message by taking a first attribute of the system message as a sending granularity; a terminal receives a system message from a network node. In conclusion, according to the technical scheme provided by the invention, based on the actual sending scene of the system message, the first attribute matched with the actual scene is adopted as the sending granularity to carry out personalized sending, so that the system message can be ensured to be pointedly sent to the range of legal users, and the communication security is ensured. In conclusion, according to the technical scheme provided by the invention, the sending granularity of the system message can be flexibly adjusted, so that the system message can be pertinently sent to a legal user range.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of communication technology, and in particular to a communication method and apparatus, system, electronic device, storage medium and program product. Background Technology

[0002] Satellite networks are characterized by low latency, low cost, wide coverage, high reliability, and high flexibility. However, precisely because satellites have such a wide coverage area—for example, their coverage diameter can be as high as tens to thousands of kilometers—it is possible that a single satellite's coverage area includes multiple cross-regional and cross-national scenarios, and even a single cell may involve multiple different countries or regions.

[0003] This situation is particularly prominent in the scenario of sending system messages. In related technologies, system messages are sent specifically at the cell level. However, this is clearly unsuitable for situations in satellite communication where cells and countries / regions do not completely match, which means that system messages cannot be sent to the designated range of legitimate users. Summary of the Invention

[0004] This disclosure provides a communication method and apparatus, system, electronic device, storage medium and program product for flexibly adjusting the granularity of system message transmission, thereby enabling system messages to be sent to a targeted range of legitimate users.

[0005] According to one aspect of this disclosure, a communication method is provided, applied to a network node, comprising: transmitting the system message with a first attribute of the system message as the transmission granularity; wherein the first attribute includes at least one of the following: location or region, service, communication type, terminal capability, terminal status, transmitted waveform type, antenna and / or base station height, terminal height, beam and / or beam group, transmit / receive point (TRP), SSB index, one or more cells, cell type, and channel characteristics; wherein the channel characteristics include at least one of the following: Doppler frequency shift, Doppler spread, delay spread, average delay, and spatial reception parameters.

[0006] According to another aspect of this disclosure, another communication method is provided, applied to a terminal, comprising: receiving a system message from a network node, the system message being sent with a first attribute as the sending granularity; wherein the first attribute includes at least one of the following: location or region, service, communication type, terminal capability, terminal status, transmitted waveform type, antenna and / or base station height, terminal height, beam and / or beam group, TRP, SSB index, one or more cells, cell type, and channel characteristics; wherein the channel characteristics include at least one of the following: Doppler frequency shift, Doppler spread, delay spread, average delay, and spatial reception parameters.

[0007] According to another aspect of this disclosure, a communication apparatus is provided, comprising: a transceiver unit, configured to transmit the system message with a first attribute of the system message as the transmission granularity; wherein the first attribute includes at least one of the following: location or region, service, communication type, terminal capability, terminal status, transmitted waveform type, antenna and / or base station height, terminal height, beam and / or beam group, transmit / receive point (TRP), SSB index, one or more cells, cell type, and channel characteristics; wherein the channel characteristics include at least one of the following: Doppler frequency shift, Doppler spread, delay spread, average delay, and spatial reception parameters.

[0008] According to another aspect of this disclosure, another communication apparatus is provided, comprising: a transceiver unit for receiving system messages from a network node, the system messages being transmitted with a first attribute as the transmission granularity; wherein the first attribute includes at least one of the following: location or region, service, communication type, terminal capability, terminal status, transmitted waveform type, antenna and / or base station height, terminal height, beam and / or beam group, TRP, SSB index, one or more cells, cell type, and channel characteristics; wherein the channel characteristics include at least one of the following: Doppler frequency shift, Doppler spread, delay spread, average delay, and spatial reception parameters.

[0009] According to another aspect of this disclosure, a communication system is provided, comprising: a network node for performing the method executed on the network node side; and a terminal for performing the method executed on the terminal side.

[0010] According to another aspect of this disclosure, an electronic device is provided, including a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the method described in any of the above embodiments.

[0011] According to another aspect of this disclosure, a computer-readable storage medium is provided that stores a computer program / instructions thereon, which, when executed by a processor, implement the methods described in any of the above embodiments.

[0012] According to another aspect of this disclosure, a computer program product is provided, including a computer program / instructions that, when executed by a processor, implement the methods described in any of the above embodiments.

[0013] As will be described in detail below, a communication method, apparatus, system, electronic device, storage medium, and program product according to embodiments of this disclosure are disclosed. In this disclosure, the network side can send system messages using a first attribute of the system message as the sending granularity. Furthermore, the first attribute of the system message in this disclosure may include, but is not limited to, at least one of the following: location or region, service, communication type, terminal capability, terminal status, transmitted waveform type, antenna and / or base station height, terminal height, beam and / or beam group, transmit / receive point (TRP), SSB index, one or more cells, cell type, and channel characteristics. Moreover, the channel characteristics further consider at least one of Doppler shift, Doppler spread, delay spread, average delay, and spatial reception parameters. Thus, the transmission characteristics of the network side, the terminal side, and between them are fully considered to determine the first attribute adapted to the current situation as the sending granularity for sending system messages. In other words, the technical solution provided by this disclosure can perform personalized sending based on the actual sending scenario of the system message, using a first attribute adapted to the actual scenario as the sending granularity. This ensures that system messages are sent to the scope of legitimate users in a targeted manner, thus guaranteeing communication security. In summary, the technical solution provided in this disclosure can flexibly adjust the granularity of system message sending, thereby enabling system messages to be sent to the scope of legitimate users in a targeted manner.

[0014] It should be understood that both the foregoing general description and the following detailed description are exemplary and intended to provide further illustration of the claimed technology. Attached Figure Description

[0015] The above and other objects, features, and advantages of this disclosure will become more apparent from the more detailed description of the embodiments thereof in conjunction with the accompanying drawings. The drawings are provided to further illustrate the embodiments of this disclosure and form part of the specification. They are used together with the embodiments of this disclosure to explain the disclosure and do not constitute a limitation thereof. In the drawings, the same reference numerals generally represent the same components or steps.

[0016] Figure 1 A schematic diagram of a satellite communication scenario provided in this disclosure is shown.

[0017] Figure 2 A schematic diagram of the interaction flow of a communication method provided in this disclosure is shown.

[0018] Figure 3 A schematic diagram of the flow process of a system message provided in this disclosure is shown.

[0019] Figure 4 A schematic diagram of a key deduction algorithm provided in this disclosure is shown.

[0020] Figure 5 A schematic diagram of another key deduction algorithm provided in this disclosure is shown.

[0021] Figure 6 A schematic diagram of an area indication provided in this disclosure is shown.

[0022] Figure 7 A structural block diagram of a communication device provided in this disclosure is shown.

[0023] Figure 8 A structural block diagram of another communication device provided in this disclosure is shown.

[0024] Figure 9 A schematic diagram of a communication system provided in this disclosure is shown.

[0025] Figure 10 A hardware block diagram of an electronic device provided in this disclosure is shown.

[0026] Figure 11 A schematic diagram of a computer program product provided in this disclosure is shown. Detailed Implementation

[0027] To make the objectives, technical solutions, and advantages of this disclosure more apparent, exemplary embodiments according to this disclosure will now be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of this disclosure, and not all embodiments of this disclosure. It should be understood that this disclosure is not limited to the exemplary embodiments described herein.

[0028] This disclosure applies to scenarios where system messages are sent from the network side to the terminal side, i.e., the sending (or notification) of system messages.

[0029] In this scenario, the network side is also referred to as a network node, network device, network-side communication device, communication device, etc., with no particular restrictions on the naming. In an exemplary preferred embodiment, this disclosure can be used in a satellite network to send system messages to a terminal. In this scenario, the network node can specifically be a communication node in the satellite network (or it can be referred to as a satellite node). In addition, this disclosure can also be used in scenarios where a terrestrial core network or base station sends system messages to a terminal.

[0030] This disclosure does not impose any particular restrictions on the communication technologies used on the network side. Taking a network node as an example of a network device in a communication system, the communication system may include, but is not limited to: Global System for Mobile communication (GSM), Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), General Packet Radio Service (GPRS), Long Term Evolution (LTE), Advanced Long Term Evolution (LTE-A), New Radio (NR), evolution systems of NR, LTE-based access to unlicensed spectrum (LTE-U), NR-based access to unlicensed spectrum (NR-U), Non-Terrestrial Networks (NTN), Universal Mobile Telecommunication System (UMTS), and Wireless Local Area Networks (WLANs). Networks, WLAN, Wireless Fidelity (WiFi), 5th-Generation (5G) systems, or other communication systems, etc.

[0031] In this disclosure, network-side equipment can specifically include base stations, evolved NodeBs (eNodeBs), transmission reception points (TRPs), next-generation NodeBs (gNBs) in 5G mobile communication systems, next-generation base stations in 6G mobile communication systems, base stations in future mobile communication systems, or access nodes in wireless fidelity (WiFi) systems; it can also be modules or units that perform some of the functions of a base station, such as centralized units (CUs) or distributed units (DUs). Radio access network equipment can be macro base stations, micro base stations, indoor stations, or relay nodes, etc. This disclosure does not impose any particular restrictions on the specific technologies or equipment forms used in the radio access network equipment. For ease of description, the following description uses a base station as an example of radio access network equipment.

[0032] A terminal, also known as a terminal device, user equipment (UE), mobile station, or mobile terminal, is capable of communicating with network-side devices. Specifically, terminals can be widely used in various scenarios, such as device-to-device (D2D), vehicle-to-everything (V2X) communication, machine-type communication (MTC), the Internet of Things (IoT), virtual reality, augmented reality, industrial control, autonomous driving, telemedicine, smart grids, smart furniture, smart offices, smart wearables, smart transportation, and smart cities. Therefore, terminals can be, but are not limited to, mobile phones, tablets, computers with wireless transceiver capabilities, wearable devices, vehicles, drones, helicopters, airplanes, ships, robots, robotic arms, and smart home devices. This application does not impose any particular restrictions on the specific technology or device form used in the terminal.

[0033] Both base stations and terminals can be collectively referred to as communication devices. A base station can also be called a communication device with base station functions, and a terminal can be called a communication device with terminal functions. Base stations and terminals can be fixed in location or mobile. They can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; they can also be deployed on water; and they can be deployed in the air on aircraft, balloons, and artificial satellites. This application embodiment does not impose any particular limitations on the application scenarios of base stations and terminals.

[0034] As mentioned in the background section, system messages in related technologies are sent at the cell level. This leads to the problem that system messages cannot be sent effectively and specifically when the cell does not match the country, region, etc.

[0035] On the one hand, in actual satellite communication scenarios, the beams within a satellite's coverage area may be the same or different, but the Physical Cell Identifier (PCI) is the same. Different regions can be assigned different Cell Global Identifiers (CGI) or eCGIs. However, because they are within the same beam range, the UE cannot clearly define the boundaries of the physical wireless coverage. Furthermore, system messages in related technologies are at the cell level, which cannot adapt to the increasing number of application scenarios and diverse services. This results in a large amount of country / region-restricted information not being sent to the designated range of legitimate users. On the other hand, because cell signals in non-terrestrial network (NTN) systems use LOS paths, co-channel interference from overlapping coverage is far stronger than that from terrestrial base stations, making normal communication almost impossible. Moreover, in moving scenarios, the satellite coverage area is dynamically changing, making management even more difficult.

[0036] For example, please refer to the following. Figure 1 , Figure 1 A schematic diagram of a satellite communication scenario provided in this disclosure is shown. For example... Figure 1 As shown, in this communication scenario, the satellite coverage includes three countries: Country A, Country B, and Country C. However, in reality, as... Figure 1 As shown, the satellite return route of the satellite system's national ground station (i.e., Satellite System Earth Station in Country) is directed to country B. Therefore, if system messages are sent on a cell-by-cell basis as per relevant technologies, system messages intended for country B might also be sent to countries A and C. This inability to effectively target messages poses a significant communication security risk.

[0037] To address the communication security risks arising from the inability of existing systems messages to be targeted to legitimate users, this disclosure provides a novel design concept: before sending a system message, the network side determines its sending granularity based on the message's attribute information. This allows for flexible adjustment of the sending granularity to suit different situations, enabling system message delivery in a practical manner and ensuring targeted delivery to legitimate users. The details are explained below.

[0038] This disclosure provides a communication method. Please refer to... Figure 2 , Figure 2 A schematic diagram of the interaction flow of a communication method provided in this disclosure is shown. For example... Figure 2 As shown, the method includes:

[0039] S202, the network node sends the system message with the first attribute of the system message as the sending granularity.

[0040] Specifically, system messages can have multiple attribute information. When performing this step, it is necessary to determine the first attribute among these attributes; the first attribute is the granularity of the system message transmission. Therefore, after determining the transmission granularity in this step, the system message is transmitted based on the transmission granularity of the first attribute.

[0041] This disclosure does not impose any particular restrictions on the types of attribute information possessed by system messages, but its scope includes at least the scope of the first attribute defined in this disclosure (described in detail below). Furthermore, this disclosure does not impose any particular restrictions on how network nodes determine the granularity of system message transmission; in practical scenarios, this can be determined based on the attribute information of the system message. For example, if for... Figure 1 In the satellite communication scenario shown, a cell may contain multiple countries, so at least the country (or region) needs to be used as the first attribute (i.e., at least one first attribute at the sending granularity) when sending system messages.

[0042] When sending system messages, different system messages can be sent for different granularities. For example, if system messages are sent at the region level, system message 1 is sent to region A, and system message 2 is sent to region B. Alternatively, if the granularity determined in this step is region-based and business-based, then different system messages are sent for different regions and businesses. This is not an exhaustive list.

[0043] like Figure 2As shown, in this interaction flow, S202 is the action performed by the network side. In this process, before sending the system message, the network side can first determine the granularity of the system message, and then send the system message according to the determined first attribute.

[0044] S204, the terminal receives a system message from a network node, the system message being sent with a first attribute as the sending granularity.

[0045] Figure 2 S204 in the diagram represents the action performed by any terminal. For ease of explanation, Figure 2 Only one terminal is shown. In actual scenarios, there can be one or more terminals, depending on the actual situation such as user behavior. This disclosure does not impose any special restrictions on this.

[0046] The first attribute that can be used as the granularity of system message transmission in this disclosure may include, but is not limited to, at least one of the following: location or region, service, communication type, terminal capability, terminal status, transmitted waveform type, antenna and / or base station height, terminal height, beam and / or beam group, transmit / receive point (TRP), SSB (Synchronization Signal / PBCH) index, one or more cells, cell type, and channel characteristics.

[0047] The channel characteristics include at least one of the following: Doppler shift, Doppler spread, delay spread, average delay, and spatial Rx parameter.

[0048] Specifically, location or geographic granularity offers targeted improvements for situations with wide satellite coverage. Compared to existing technologies that send system messages at the cell level, sending system messages at different location or geographic granularities—that is, sending system message 1 corresponding to region A to terminals in region A, and system message 2 corresponding to region B to terminals in region B—solves the problem of not being able to target legitimate users when sending system messages at the cell level. This disclosure does not impose any particular restrictions on the specific method of location or geographic area division, which may include, but is not limited to, at least one of: geographic location, region, altitude, country, etc. For example, it can be based on existing administrative divisions such as national, provincial, municipal, county, and township levels for subdivision, such as using... Figure 1The example shows a country as a region; alternatively, a custom division mechanism can be defined, such as the network side defining a preset area near a base station as a region; this is not exhaustive.

[0049] Using services as the granularity means that a type of system message can be sent to terminals that support certain services (one or more). Terminals that do not support these services may not receive, or may receive the message but be unable to parse it. The service type can be customized, such as XR services or high-precision time synchronization services. In this way, system messages are essentially bound to services, allowing specific system messages corresponding to certain services to be sent to the appropriate service terminals.

[0050] Communication types are similar, meaning that system messages are bound to communication types, allowing for the targeted sending of system messages related to specific communication types to terminals of those types. The communication types involved here are not limited; for example, they may include, but are not limited to, at least one of the following: SL (encrypted communication), NTN (non-terrestrial communication network), unmanned aerial vehicles (UAVs), Air-to-Ground (ATG), MBS Multicast, MBS broadcast, etc., without exhaustive list.

[0051] Based on at least one of the service and communication types, it is possible to send messages to terminals with different service and / or communication types in a differentiated manner, so that UEs that do not support the service and communication type reduce the reception of unnecessary SI / SI updates.

[0052] In this disclosure, the granularity of system message transmission also considers relevant terminal conditions, such as including but not limited to: at least one of terminal capabilities and terminal status. The terminal status may include, but is not limited to: at least one of UE speed, UE altitude, and UE angle. For example, if system message 1 is sent to a terminal with a UE altitude higher than 1km using UE status as the transmission granularity, then for any terminal, if its altitude (i.e., a UE status) is higher than 1km, it can successfully receive and parse the system message; however, for any UE with an altitude lower than 1km, it may not receive the system message (this could be due to the network not sending it or the UE not receiving it) or the UE may receive the system message but fail to parse it successfully (the specific method will be explained later; this is only an example). Thus, system messages can be sent to the appropriate UE using UE status as the transmission granularity. In summary, this transmission granularity of terminal capabilities and terminal status allows for differentiated transmission of system messages to terminals with different capabilities and statuses, reducing unnecessary SI / SI update reception for UEs that do not support or are not suitable for that capability or status.

[0053] In this disclosure, the granularity of system message transmission also considers the waveform type. That is, different types of UEs and UEs in different states can receive different waveforms. The waveform types involved here may include, but are not limited to, at least one of the following: OFDM waveform, OOK waveform, etc., without exhaustive list. It should be understood that since different types and states of UEs can receive different waveforms, the configuration information and scheduling methods of the system messages can also be different.

[0054] Furthermore, in this disclosure, the granularity of system message transmission also considers the antenna and / or base station height, terminal height, beam and / or beam group, TRP, SSB index, one or more cells, cell type, channel characteristics, etc. These different attributes correspond to different cell configurations, different measurement configurations, and thus different UE access behavior, measurement behavior, and mobility management behavior.

[0055] It should be understood that, as the granularity of system message transmission, the type and number of the first attribute can be one or more. This disclosure does not impose any particular limitation on the number of first attributes. The network side can send system messages based on one type of first attribute as the granularity, or it can send system messages based on a combination of multiple first attributes as the granularity.

[0056] Therefore, for the terminal, if it successfully receives and parses the system message, it can determine some relevant information about the system message.

[0057] For example, based on the system message, the terminal can determine at least one of the following information: the location or region corresponding to the beam that sent the system message, the type of waveform sent, the height of the antenna and / or base station, the angle between the antenna and the ground, the height of the terminal, information about the beam and / or beam group, TRP information, SSB index, information about one or more cells, the type of cell, and information about channel characteristics.

[0058] For example, if the terminal receives and decrypts the system message, it indicates that the terminal is flying at an altitude of 100-200 meters; or, for another example, if the terminal receives and decrypts the system message, it indicates that the coverage direction of the beam sending the system message is at an altitude of 150-300 meters; or, for another example, if the terminal receives and decrypts the system message, it indicates that the terminal is operating within area A; or, for another example, if the terminal receives and decrypts the system message, it indicates that the terminal is being served by a low PAPR waveform, such as OOK waveform, SC-OFDM waveform, DFT-S-OFDM waveform, etc., without exhaustive list.

[0059] In summary, regardless of the method used, the technical solution provided in this disclosure fully considers the transmission characteristics of the network side, the terminal side, and between them, determining a first attribute adapted to the current situation as the sending granularity for system message transmission. In other words, the technical solution provided in this disclosure can personalize the transmission based on the actual system message transmission scenario, using a first attribute adapted to the actual scenario as the sending granularity. This ensures that system messages are sent targeted to the scope of legitimate users, guaranteeing communication security. In conclusion, the technical solution provided in this disclosure can flexibly adjust the sending granularity of system messages, thereby enabling system messages to be sent targeted to the scope of legitimate users.

[0060] In such Figure 2 Furthermore, based on the embodiments shown, the technical solutions provided in this disclosure do not impose any special restrictions on the information carried by system messages.

[0061] In one exemplary embodiment, the system message may carry at least one of the following: resource information, location information, area information, transmission time information, and capacity information of the relevant downlink DL beam and / or cell; and / or, the system message may carry at least one of the following: resource information, location information, area information, transmission time information, physical random access channel (PRACH) resource information, and capacity information of the corresponding uplink UL beam and / or cell. In other words, the system message in this disclosure may be information about downlink-related beams and / or cells, or information about uplink-related beams and / or cells, or both; further details will not be elaborated here.

[0062] Furthermore, in this disclosure, system messages may include, but are not limited to, at least one System Information (SI) or System Information Block (SIB).

[0063] In this disclosure, network nodes send system messages with the first attribute as the sending granularity, which can take at least the following forms:

[0064] The first method involves network nodes determining the receiving terminals possessing a specific first attribute based on the defined transmission granularity. Then, they selectively send system messages to these target receiving terminals. While slightly more complex from the network side, this method ensures accurate transmission of system messages, completely preventing them from being mistakenly sent to invalid terminals lacking the first attribute.

[0065] The second method involves network nodes sending system messages to terminals (e.g., all or some terminals within their coverage area, the range is unlimited). These system messages carry relevant indication information about the first attribute. Thus, upon receiving this system message, a terminal can determine whether it is the recipient of the system message based on its own attribute information (denoted as the second attribute). If so, it parses the system message; otherwise, it discards it.

[0066] Thirdly, network nodes can send system messages to terminals (e.g., all or some terminals within their coverage area, the range is unlimited). These system messages can be securely processed. Thus, for any UE within the network node's coverage area, if it can successfully parse the system message, it proves itself to be a receiver satisfying the first attribute; otherwise, if it cannot parse it successfully, it proves it is not a receiver of the system message. In this way, the network side does not need to precisely distinguish the receivers of each system message; instead, it can perform secure processing using information related to the first attribute (denoted as first security information) and send the securely processed system message outwards. This method is simple and easy to implement. For the terminal, while it can receive messages, whether the terminal satisfies the first attribute determines whether it can successfully parse the system message. This ensures that the system message is successfully received by the correct and valid receiver and prevents the system message from being obtained by the wrong and invalid receiver.

[0067] It should be understood that the above three methods can also be used in combination. For example, the network side can determine the receiving end based on the first attribute and send a securely processed system message to it. Further details are omitted.

[0068] The following section will focus on the third encrypted transmission method mentioned above to explain the specific implementation of this scheme.

[0069] In one exemplary embodiment, before sending system messages, network nodes need to perform security processing on the system messages, specifically including the following process:

[0070] S304-1, The network node determines the first security information based on the first attribute.

[0071] In practical implementation, the first security information can correspond to the first attribute. If there are multiple first attributes determined by the sending granularity, then the first security information can correspond to a group of first attributes. That is, the first security information is different for different first attributes, so as to ensure that system messages are not erroneously parsed by invalid terminals that do not meet the first attribute, and to ensure the secure transmission of system messages.

[0072] Specifically, the network side can maintain the correspondence between the first attribute and the first security information. Alternatively, the network side can generate first security information matching the current sending granularity in real time based on preset encryption algorithms and / or parameters derived from the key. This will be explained in detail later.

[0073] S304-2, the network node uses the first security information to perform security processing on the system message and sends the security-processed system message.

[0074] In one exemplary embodiment, the system message includes at least one system information SI or system information block SIB; in this case, the first security information may also include: security information of at least one of the SIs; and / or, security information of at least one of the SIBs.

[0075] Security processing methods may include, but are not limited to, encrypting system messages using a security key. In this case, the primary security information includes at least the security key.

[0076] It should be noted that, in this implementation, to ensure that the receiving end that meets the first attribute can successfully parse the system message, there are two specific solutions: Solution 1, the first security information is shared between the network node and the terminal with the first attribute; or, Solution 2, the first security information is maintained independently by the network node.

[0077] Specifically, for Scheme 1, the network node needs to generate the first security information first and then synchronize and share it with the corresponding receiving end (i.e., the terminal possessing the first attribute). Thus, after receiving the system message, the terminal can use the first security information shared with the network node to parse and process the system message. The first security information and its generation method will be explained in detail below.

[0078] In Scheme 2, network nodes can independently generate and maintain the first security information without synchronizing it with the terminal. Therefore, in this scenario, the terminal needs to use its own attribute information to generate the first security information and then parse the message accordingly when parsing system messages.

[0079] Accordingly, for the terminal, after receiving the system message, the following steps are also included:

[0080] S308 parses and processes system messages.

[0081] Specifically, depending on the method of maintaining the primary security information, the terminal side can have different parsing methods. These include:

[0082] Corresponding to the aforementioned scheme 1, if the first security information is shared between the network node and the terminal possessing the first attribute, then for the terminal, the terminal can use the first security information shared with the network node to parse and process the system message.

[0083] In this embodiment, the first security information is determined by the network node based on a first attribute corresponding to the system message. That is, the first security information is generated by the network node based on the first attribute and shared with the corresponding receiving end. The corresponding receiving end can store or maintain the first security information in other custom ways. For example, the terminal can store the first security information in the SIM card.

[0084] It should be understood that if the first security information maintained by the terminal cannot successfully parse the system message, it indicates that the terminal is not the recipient of the system message. For example, the network side determines that the recipient corresponding to the first attribute 1 is terminal 1 and terminal 2; and generates first security information 1 based on the first attribute 1, sharing it with terminal 1 and terminal 2; and the network side determines that the recipient corresponding to the first attribute 2 is terminal 13; and generates first security information 2 based on the first attribute 2, sharing it with terminal 3. In this case, when the network side sends a certain system message to terminals 1-3, terminals 1-3 can each use their own maintained first security information to decrypt it. If the system message corresponds to the first attribute 2, then terminal 3 can successfully parse the system message, but terminals 1 and 2 cannot parse the system message.

[0085] Alternatively, corresponding to the aforementioned scheme 2, if the network node does not synchronize the first security information to its receiving end, then for the terminal, the terminal can use the second attribute of the terminal corresponding to the first attribute to generate the first security information and decrypt the system message; wherein, the system message is security-processed by the network node based on the first attribute.

[0086] In this embodiment, the terminal needs to generate its own first security information, based on its own second attribute. It's important to note that the terminal uses the second attribute corresponding to the first attribute on the network side. The granularity at which the network sends system messages can be negotiated, preset, or notified in advance to synchronize with the terminal. For example, if the network sends system messages at the regional level, the system message received by the terminal will be securely processed using the first security information corresponding to a specific region. Upon receiving the system message, the terminal can determine its own region and, based on that region, determine the first security information and attempt to decrypt the system message using the same method as the network side. If the terminal's region (i.e., the second attribute) matches the region corresponding to the system message (i.e., the first attribute), the first security information determined by the terminal based on the second attribute is consistent with the first security information determined by the network based on the first attribute, and the terminal, as the receiver of the system message, can successfully parse its content. Conversely, if the terminal's region (i.e., the second attribute) does not match the region corresponding to the system message (i.e., the first attribute), the terminal's region will be different. The terminal will then be unable to successfully parse the content of the system message.

[0087] The first security information involved in this disclosure may include, but is not limited to, at least one of the following: security key, encryption algorithm, integrity algorithm, intermediate key, anchor key, and key parameters;

[0088] The key parameters include at least one of the following: encoding key, count, system message block sequence number, system message block length, country code, region code, service code, terminal capability label, terminal status label, transmitted waveform type label, antenna and / or base station altitude label, terminal altitude label, beam and / or beam group label, TRP label, SSB index, label of one or more cells, label of cell type, and label of channel characteristics.

[0089] The security key is the key actually used to encrypt system messages, which is obtained by deducing the key parameters. Specifically, this disclosure does not impose any particular restrictions on the key deduction algorithm, but the key parameters involved in the key deduction algorithm are related to the actual scenario.

[0090] For example, Figure 3 A schematic diagram illustrating the flow of system messages provided in this disclosure is shown. For example... Figure 3As shown, NEA represents the key derivation process, and KEYSTREAM BLOCK represents the derivation of the security key. The five items KEY (representing the encoded key, for example, a 128-bit encoded key), COUNT (representing the counter, the size of which can be, for example, 32 bits), SIB-number (representing the SIB sequence number), LENGTH (the length of the system message block), and Area code / Service code / Country code (representing at least one of the area code, service code, and country code) are used as derivation parameters for the security key (i.e., the key parameters mentioned above). They are used as input parameters for the key derivation process to deduce the security key.

[0091] like Figure 3 As shown, Sender represents the sending end, i.e., the network side in this disclosure; while Receiver represents the receiving end, i.e., the terminal side in this disclosure. Figure 3 As shown, both the network side and the terminal side can perform key deduction based on the aforementioned input parameters to achieve encryption and decryption. Specifically, the network side, as the sender, uses the security key (KEYSTREAM BLOCK, also known as the first security information) derived from the first attribute to encrypt the plaintext (PLAINTEXT BLOCK, i.e., the system message or the information carried in the system message) into ciphertext (CIPHERTEXT BLOCK); the ciphertext is transmitted between the sender and receiver. The terminal, as the receiver of the system message, uses the security key (KEYSTREAM BLOCK, also known as the first security information) derived from the second attribute to decrypt the ciphertext (CIPHERTEXT BLOCK, i.e., the received system message) back into plaintext (PLAINTEXT BLOCK, i.e., the system message or the information carried in the system message). In this way, secure transmission of system messages between network nodes and terminals is achieved.

[0092] It should be understood that Figure 3 This is merely illustrative; in real-world scenarios, the number of key parameters used to derive the security key may vary, and the range may include one or more of the key parameters mentioned above, which will not be elaborated further. The key derivation algorithm used on the network side and / or the terminal side should be consistent. In real-world scenarios, key derivation algorithms can take many different forms, and existing key derivation algorithms can be reused, using the key parameters provided in this disclosure as inputs to determine the security key. For ease of explanation, Figure 4 and Figure 5 Schematic diagrams of two different key deduction algorithms provided in this disclosure are shown.

[0093] like Figure 4 and Figure 5As shown, the key derivation algorithm can be based on the seed key K. First, it generates the encryption key CK and the integrity key IK. Then, after processing by ARPE (an authentication credential storage and processing function used to store authentication credentials), the intermediate key is authenticated by the authentication function AUSF, and then processed by the security anchor function SEAF to obtain K. AMF After that, the final security key can be obtained through some transformation processing.

[0094] like Figure 5 As shown, for the terminal, the Universal User Identity Module (USIM) in the terminal can generate an encryption key CK and an integrity key IK based on the seed key K, and provide them to the mobile device ME. Then, the ME processes these keys using AUSF, SEAF, etc., to finally obtain the security key.

[0095] In such Figure 3 In the illustrated embodiment, the network side can send the security key derivation algorithm and the required key parameters (i.e., as the first security information) to the terminal side in advance. For example, the application layer of the core network can send the above information to the matched terminal in advance. Alternatively, refer to the other methods described above, which will not be repeated here.

[0096] It is important to note that in any embodiment of the third encrypted transmission method described above, the network side performs secure processing on the system message, meaning that some or all of the information in the system message can be encrypted using a security key. For example, in a system message, part of the SI can be encrypted and part can be made public. As mentioned earlier, the security key used for the securely processed system message between the network node and the terminal can be determined based on the first security information.

[0097] Specifically, for the network side, the determination of the first security information based on the first attribute can be implemented as follows: the first attribute is mapped to an attribute label, and then the attribute label is used as the input parameter for key derivation to generate the security key.

[0098] For scenarios where the terminal needs to perform key deduction, the terminal needs to map the second attribute of the terminal corresponding to the first attribute to an attribute label, and then use the attribute label as the input parameter for key deduction to generate the security key.

[0099] Furthermore, before this solution is implemented, the first security information can be synchronized from the network side to the terminal side to enable targeted system message sending and receiving in this solution. In this embodiment, the communication method further includes:

[0100] Step 1: The network node sends the first security information corresponding to the first attribute to the terminal that possesses the second attribute, based on the first attribute of the system message corresponding to the second attribute of the terminal.

[0101] The second attribute is used to describe the terminal's attribute information.

[0102] From the network side's perspective, the network side can obtain the second attribute of each terminal based on the terminal registration process and / or the terminal initial access process, and / or the connection establishment process between the terminal and the network node. From the terminal's perspective, the terminal can send the second attribute to the network node during the terminal registration process and / or the terminal initial access process; wherein the second attribute is used to describe the terminal's attribute information; or, during the connection establishment process between the terminal and the network node, the second attribute can be sent to the network node.

[0103] It should be understood that for a terminal to use network services, it needs to register with the network and access the network. During the interaction between the terminal and the network node regarding registration and / or network access, the terminal can report its own secondary attributes to the network side. For example, it can report at least one of its communication type, subscribed services, and terminal capabilities. In specific implementations, the aforementioned secondary attributes can be carried in any message initiated by the terminal to the network side. For example, the terminal's secondary attributes can be carried in the registration request, or in any message sent to the network node during the registration interaction process. Alternatively, the terminal can also respond to a request from the network side and send its own secondary attributes to the network node separately. All of these are possible, and no exhaustive list is provided.

[0104] In practical implementation, the first attribute of the system message corresponding to the second attribute of the terminal can be simply understood as the case where the two are consistent, or the case where the second attribute completely satisfies the first attribute. In this case, the receiving end of the first security information corresponding to the first attribute is: the terminal possessing the second attribute. For example, if the first attribute is region 1, its range includes a geographical area of ​​approximately fifty square meters, and the second attribute of a terminal is a location point within region 1, then the first security information corresponding to the first attribute (i.e., region 1) can be sent to that terminal. Another example: if the second attribute of the terminal is broadcast service 1, and the first attribute of the system message to be sent by the network side is also broadcast service 1, then the network side can send the first security information corresponding to the first attribute of broadcast service 1 to that terminal. Yet another example: if the second attribute of the terminal is the terminal's flight altitude of 100 meters, and the coverage altitude of the cell or beam provided by the first attribute of the network node is 80-120 meters, then the second attribute meets the requirements of the first attribute, and the first security information corresponding to the first attribute, "coverage altitude is 80-120 meters," can be sent to that terminal.

[0105] Of course, there can be multiple first attributes. In this case, the receiving end of the first security information corresponding to multiple first attributes (which can be regarded as a group of first attributes) is a terminal that has a second attribute that can satisfy multiple first attributes. For example, if the first attribute is area 1 and broadcast service 2, then the sending end of the first security information corresponding to this first attribute is a terminal located in area 1 and subscribed to broadcast service 2. At this time, if the second attribute of a terminal 1 is: located at a certain location in area 1 and subscribed to broadcast service 2, then the network side can send the first security information corresponding to the first attribute to terminal 1. Alternatively, if the second attribute of a terminal 2 is: located in area 2 and subscribed to broadcast service 2, or if the second attribute of a terminal 3 is: located in area 1 and not subscribed to broadcast service 2, then neither terminal 2 nor terminal 3 is the receiving end of the first security information corresponding to the first attribute, and the network side does not need to send the first security information to terminal 2 and terminal 3.

[0106] The first security information sent by the network node here can be a security key determined by the network side, or it can be a key derivation algorithm and key parameters.

[0107] For example, the network node notifying the terminal of the first security information in step 1 can also be achieved through the terminal's registration and / or access process, that is, by carrying the aforementioned first security information in the message sent from the network side to the terminal side.

[0108] In one exemplary embodiment, a network node can send the first security information corresponding to the first attribute to a terminal possessing the second attribute via at least one of NAS messages, RRC messages, MAC signaling, and DCI signaling. The terminal can also receive the first security information from the network node via at least one of NAS messages, RRC messages, MAC signaling, and DCI signaling.

[0109] Step 2: The terminal receives the first security information from the network node.

[0110] Step 3: The terminal stores the first security information.

[0111] Thus, once the terminal receives the initial security information, it can securely store it. The storage method and location are not limited. For example, it can be stored in memory or on a SIM card.

[0112] In summary, this disclosure, through the registration and / or network access process between the terminal and the network side, and / or the connection establishment process between the terminal and the network node, allows the network side to obtain the second attributes of each terminal. Furthermore, through the registration and / or network access process between the terminal and the network side, and / or the connection establishment process between the terminal and the network node, the interactive storage of first security information can also be achieved. During this process, the terminal may not even have established a connection with the network side before the interaction and further application of security information can be realized. Compared to traditional technologies where security information is only generated and established when the terminal enters the connected state, this solution enables earlier communication of security information between the terminal and the network side, achieving secure encryption and targeted transmission of system messages, and thus maintaining system communication security to a greater extent.

[0113] Let's illustrate this with a real-world example. First, the network side can determine the region (including at least one of geographical location, altitude, area, and country) corresponding to the SIB / SI, the service type (such as XR service, high-precision time synchronization, etc.), the communication type (such as SL, NTN, UAV, VTG, MBS Multicast, MBS broadcast, etc.), the UE's capabilities, and the UE's status (e.g., UE speed, UE altitude, UE angle). This is equivalent to determining the first attribute corresponding to the system message. Furthermore, the network side can also determine the second attribute, such as the UE's region, supported services, subsequent communication types, UE capabilities, and UE status, based on the UE capabilities, UE status, and coarse location information reported during terminal registration and / or initial access. Then, based on the first attribute and the second attribute of each terminal, the network side can further send first security information to the terminal during terminal registration and / or initial access through at least one message / signaling method among NAS messages, RRC messages, MAC signaling, and DCI signaling. This information informs the terminal of the encryption algorithm, key parameters, and security key corresponding to the encrypted system message (e.g., SIB) from the network side that matches it. In this way, the terminal can determine the security key based on the first security information corresponding to the SIB, and use the security key to parse the received system messages.

[0114] Furthermore, it should be noted that the first security information used by the network side and the terminal side in this disclosure can be dynamic.

[0115] Specifically, the first security information can be a dynamic update initiated by the network side, or it can be a dynamic update requested by the terminal side.

[0116] In one possible scenario, the network side can also proactively initiate dynamic updates to the first security information. For example, key parameters may be dynamically updated due to changes in the actual communication scenario. For instance, the area code can be a dynamically updated code, and the channel characteristic labels can also change dynamically or based on actual conditions, without exhaustive listing. When key parameters change dynamically, the network side can dynamically update the first security information corresponding to each system message or each first attribute and notify the corresponding receiving end. For example, the network side can also proactively and dynamically update the key derivation algorithm, key parameters, security keys, etc., based on its own business needs or other reasons.

[0117] In the scenario described above, security information updates initiated by the network side can be implemented by sending the updated security information to the terminals. Specifically, this can be done by sending the updated information individually to each terminal that has experienced the change, or by group notification via group paging.

[0118] In one exemplary embodiment, the method may further include the following steps:

[0119] Step a1: The network node updates the first security information corresponding to the first attribute to obtain the updated third security information.

[0120] Step a2, the network node sends a group paging message, which carries the third security information and the Radio Network Temporary Identity (RNTI); wherein the RNTI is shared between the network node and the receiving end of each system message corresponding to the first attribute.

[0121] The group paging message may also carry the first security information; the first security information can be used as an encoding key (i.e. Figure 3 The KEY in the key is used to determine the security key.

[0122] Among them, RNTI serves as shared information between network nodes and the receiving end of each system message. When the RNTI is carried in the group paging message, it means that only the UE that saves the matching RNTI can decrypt the paging message that updates the security information of a specific SIB.

[0123] Step a3: The terminal receives a group paging message from the network node.

[0124] Step a4: The terminal uses the RNTI to parse the group paging message to obtain the third security information; wherein, the third security information is obtained by the network node updating the first security information corresponding to the first attribute.

[0125] Step a4: The terminal determines and stores the security key based on the third security information; or, stores the third security information.

[0126] In a specific implementation, if the group paging message also carries first security information, the terminal can use the first security information as an encoding key, determine the security key in accordance with the method indicated by the third security information, and store the security key.

[0127] In another possible scenario, the first security information can also be dynamically updated in response to an active request from the terminal. For example, the terminal can periodically request the network to update the first security information, or it can request the network to update the first security information based on changes in its own second attribute.

[0128] For example, in one possible scenario, the aforementioned area code could be a dynamic code. When the UE registers with the network (i.e., before the UE becomes idle), the network side can send the first security information to the UE via NAS based on the UE's second attribute; or, before the UE enters a certain cell, it can obtain the first security information through another network node while in connected state. After obtaining the first security information, the UE can start a timer, the duration of which can be customized; when the timer expires, the UE can request updated security information from the network side again.

[0129] For example, in another possible scenario, one or more of the UE's location, supported services, communication types, UE capabilities, and UE status can change dynamically in real-world situations. For instance, a user might move from country A to country B, a UE might subscribe to service A and cancel service B, or the UE's status might change from ground level to high altitude, and so on. When the UE's secondary attributes change, the UE can also proactively request updates or synchronization of new security information from the network side.

[0130] At this point, the method may also include the following steps:

[0131] Step b1: The terminal sends a first request message to the network node. The first request message is used to request to obtain, update or synchronize security information.

[0132] As mentioned above, the terminal can proactively send a first request message to the network side based on changes in its own second attribute, the expiration of a timer, or other reasons, so that the network side can provide security information that is compatible with the terminal's current second attribute.

[0133] That is, for the terminal: when the timer expires, the terminal sends the first request message to the network node; wherein the timer starts when the first security information is received; or, when the second attribute of the terminal changes, the terminal sends the first request message to the network node.

[0134] Step b2: The network node receives a first request message from any terminal, the first request message being used to request to obtain, update or synchronize security information.

[0135] Step b3: The network node determines the second security information currently corresponding to the terminal based on the first attribute of the system message corresponding to the second attribute of the terminal.

[0136] It should be noted that the first security information and the second security information may be the same or different, depending on whether at least one of the following changes: the terminal's second attribute, the first attribute, the correspondence between the first and second attributes, or the encryption algorithm key parameters. If none of these information changes, for example, if only the terminal's timer expires, then the first and second security information remain unchanged, and the network side can directly provide feedback. If any of these pieces of information changes, the network side can, based on the aforementioned method, re-determine the second security information corresponding to the first attribute that is compatible with the terminal's current second attribute, and send the updated second security information to the terminal. In other words, the second security information is determined based on the terminal's second attribute and the first attributes of each system message.

[0137] Step b4: The network node sends the second security information to the terminal.

[0138] Step b5: The terminal receives and stores the second security information from the network node; the second security information is determined based on the second attribute of the terminal and the first attribute of each system message.

[0139] Furthermore, in another possible embodiment, the first request message in step b1 above may carry the first security information, which can be used by the network node to perform security verification on the terminal. Taking a timed update scenario as an example, the UE can request the network side to re-acquire the security information after the timer expires. This request may carry the previous security information, so that the network side can confirm the UE's identity and perform identity verification on the UE.

[0140] Furthermore, the aforementioned security information update process can be initiated proactively when the UE is in connected or inactive mode. For example, if the terminal initiates the aforementioned security information update process proactively based on a change in its second attribute, and the UE is in idle mode, then the UE can first enter connected mode to perform the aforementioned operation, or perform the aforementioned operation in inactive mode.

[0141] Through the above embodiments, targeted and secure transmission of system messages has been achieved.

[0142] In one exemplary embodiment, when the first information content of the system message applies to a first region, the system message carries region indication information of the first region containing the first information content;

[0143] The area indication information is indicated by at least one of the following: a reference location point plus radius, a region identifier, a country identifier, a list of cells and / or beams, a list of TPRs, a combination of the position coordinates of multiple boundary points, a polygon shape indication, or a mapped cell identifier.

[0144] Furthermore, when the system message is for a specific SIB and / or SI region, the system message may further carry region indication information for that specific SIB and / or SI region. In this disclosure, the region indication information may be indicated in at least one of the following ways, but not limited to: region (e.g., at least one of geographic location, altitude, area, and country), SI and service (e.g., XR service, high-precision time synchronization, etc. mentioned above) indication, SI and communication type (e.g., SL, NTN, UAV, ATG, MBS Multicast, MBS broadcast, etc. mentioned above) indication.

[0145] Wherein, when the region of the specific SIB and / or SI is circular, the region indication information carries mapped cell information; or, when the region of the specific SIB and / or SI is polygonal, the region indication information carries at least the boundary point location.

[0146] For example, the content of the system message may be at least one service area information, such as, but not limited to, service area information of at least one of MBS, ETWS, and CMAS. It should be understood that the first service area information corresponds to the first region, the second service area information corresponds to the second region, the third service area information corresponds to the third region, and so on, without further elaboration.

[0147] For details, please refer to Figure 6 , Figure 6 A schematic diagram of an area indication provided in this disclosure is shown. For example... Figure 6 As shown, area indication can be in at least the following ways:

[0148] A circle is used to indicate the type of ground cell, which can be specifically indicated by mapping cell information. For example, Figure 6 As shown in the left side, the mapped cell information may include, but is not limited to, at least one of the following: mapped cellID, virtual cell, and a reference location point plus radius.

[0149] Polygons, such as Figure 6 As shown on the right, it can consist of the position coordinates of multiple boundary points; furthermore, it can also include a polygon shape indicator. For example, an indicator that it is a quadrilateral.

[0150] Furthermore, for example, the SIB broadcasts the resource pool of the matching UE. If a non-matching UE uses the resources in the resource pool to send data, the UE's RRC connection is interrupted, and the UE's identifier is informed to the core network, further restricting the UE's service.

[0151] The communication method provided in this disclosure can be applied to satellite networks. This may involve scenarios where at least two satellites have overlapping coverage, particularly in soft-switch scenarios, especially in quasi-fixed scenarios. For example, if the multi-satellite overlapping coverage scenario is a co-channel coverage scenario, because the cell signals within the NTN system are LOS paths, the co-channel interference from overlapping coverage is much stronger than that from terrestrial base station co-channel overlapping coverage, making normal communication almost impossible. Moreover, in moving scenarios, the satellite coverage area is dynamically changing, making management even more difficult.

[0152] To address this situation, specifically when the system message is a multi-satellite merging message in a co-frequency coverage scenario, this disclosure adopts a strategy of time-division multiplexing the system messages corresponding to each satellite. Specifically, the system messages for any two satellites are sent at different times.

[0153] In other words, system message content from multiple satellites is sent in overlapping coverage areas, with time-sharing transmission between the satellites; meanwhile, SSB transmissions are staggered. Furthermore, the transmission delay differences between different UEs and multiple satellites need to be considered, and data transmission can also be differentiated through scheduling constraints.

[0154] This disclosure also provides a communication device. Figure 7 A structural block diagram of a communication device provided in this disclosure is shown, such as... Figure 7 As shown, the communication device 700 includes:

[0155] Transceiver unit 701 is used to send the system message with the first attribute of the system message as the sending granularity;

[0156] The first attribute includes at least one of the following: location or region, service, communication type, terminal capability, terminal status, transmitted waveform type, antenna and / or base station height, terminal height, beam and / or beam group, transmit / receive point (TRP), SSB index, one or more cells, cell type, and channel characteristics; wherein the channel characteristics include at least one of the following: Doppler frequency shift, Doppler spread, delay spread, average delay, and spatial reception parameters.

[0157] In one exemplary embodiment, the communication device 700 is further configured to carry at least one of the following in the system message: resource information, location information, area information, transmission time information, and capacity information of the relevant downlink DL beam and / or cell;

[0158] and / or;

[0159] The system message carries at least one of the following: resource information, location information, area information, transmission time information, physical random access channel (PRACH) resource information, and capacity information of the relevant DL beam and / or cell corresponding uplink UL beam and / or cell.

[0160] In one exemplary embodiment, the transceiver unit 701 is further configured to: determine first security information based on the first attribute; perform security processing on the system message using the first security information, and send the security-processed system message; wherein the first security information is shared between the network node and the terminal having the first attribute; or, the first security information is maintained independently by the network node.

[0161] In one exemplary embodiment, the transceiver unit 701 is further configured such that the first security information includes at least one of the following: a security key, an encryption algorithm, an integrity algorithm, an intermediate key, an anchor key, and key parameters; wherein the key parameters include at least one of the following: an encoding key, a counter, a system message block sequence number, a system message block length, a country code, a region code, a service code, a terminal capability label, a terminal status label, a transmitted waveform type label, an antenna and / or base station altitude label, a terminal altitude label, a beam and / or beam group label, a TRP label, an SSB index, a label for one or more cells, a cell type label, and a channel characteristic label.

[0162] In one exemplary embodiment, the transceiver unit 701 is further configured such that some or all of the information in the system message is encrypted using a security key; wherein the security key is determined based on the first security information.

[0163] In one exemplary embodiment, the transceiver unit 701 is further configured to: map the first attribute to an attribute label; and use the attribute label as an input parameter for key derivation to generate the security key.

[0164] In one exemplary embodiment, the transceiver unit 701 is further configured such that: the system message includes at least one system information SI or system information block SIB; the first security information includes: security information of at least one of the SIs; and / or, security information of at least one of the SIBs.

[0165] In one exemplary embodiment, the transceiver unit 701 is further configured to: send first security information corresponding to the first attribute to a terminal having the second attribute, based on the first attribute of the system message corresponding to the second attribute of the terminal; wherein the second attribute is used to describe the attribute information of the terminal.

[0166] In one exemplary embodiment, the transceiver unit 701 is further configured to: obtain the second attribute of each terminal based on the terminal registration process and / or the terminal initial access process;

[0167] Based on the connection establishment process between the terminal and network nodes, the second attribute of each terminal is obtained.

[0168] In one exemplary embodiment, the transceiver unit 701 is further configured to send first security information corresponding to the first attribute to a terminal having the second attribute via at least one of NAS message, RRC message, MAC signaling, and DCI signaling.

[0169] In one exemplary embodiment, the communication device 700 is further configured to: receive a first request message from any terminal, the first request message being used to request to obtain, update, or synchronize security information;

[0170] Based on the first attribute of the system message corresponding to the second attribute of the terminal, determine the second security information currently corresponding to the terminal; send the second security information to the terminal; wherein the first security information is the same as or different from the second security information.

[0171] In one exemplary embodiment, the communication device 700 is further configured to perform security verification on the terminal based on the first security information.

[0172] In one exemplary embodiment, the communication device 700 is further configured to: update the first security information corresponding to the first attribute to obtain updated third security information; send a group paging message, the group paging message carrying the third security information and a Radio Network Temporary Identifier (RNTI); wherein the RNTI is shared between the network node and the receiving end of each system message corresponding to the first attribute; wherein the group paging message also carries the first security information; the first security information is used as an encoding key to determine a security key.

[0173] In one exemplary embodiment, the communication device 700 is further configured to: transmit system messages corresponding to each satellite in a time-division manner; wherein the transmission times of system messages corresponding to any two satellites are different.

[0174] In one exemplary embodiment, the communication device 700 is further configured to: when the first information content of the system message applies to a first region, the system message carries region indication information of the first region containing the first information content;

[0175] The area indication information is indicated by at least one of the following: a reference location point plus radius, a region identifier, a country identifier, a list of cells and / or beams, a list of TPRs, a combination of the position coordinates of multiple boundary points, a polygon shape indication, or a mapped cell identifier.

[0176] This disclosure also provides a communication device. Figure 8 A structural block diagram of a communication device provided in this disclosure is shown, such as... Figure 8 As shown, the communication device 800 includes:

[0177] Transceiver unit 801 is used to receive system messages from network nodes, wherein the system messages are sent with a first attribute as the sending granularity.

[0178] The first attribute includes at least one of the following: location or region, service, communication type, terminal capability, terminal status, transmitted waveform type, antenna and / or base station height, terminal height, beam and / or beam group, TRP, SSB index, one or more cells, cell type, and channel characteristics; wherein the channel characteristics include at least one of the following: Doppler frequency shift, Doppler spread, delay spread, average delay, and spatial reception parameters.

[0179] In one exemplary embodiment, the communication device 800 is further configured to determine, based on the system message, at least one of the following: the location or region corresponding to the beam that sent the system message, the type of waveform sent, the height of the antenna and / or base station, the angle between the antenna and the ground, the height of the terminal, information about the beam and / or beam group, TRP information, SSB index, information about one or more cells, the type of cell, and information about channel characteristics.

[0180] In one exemplary embodiment, the communication device 800 is further configured to carry at least one of the following in the system message: resource information, location information, area information, transmission time information, and capacity information of the associated DL beam and / or cell;

[0181] and / or;

[0182] The system message carries at least one of the following: resource information, location information, area information, transmission time information, PRACH resource information, and capacity information of the DL beam and / or the corresponding UL beam and / or cell.

[0183] In one exemplary embodiment, the communication device 800 is further configured to parse the system message using first security information shared with the network node; wherein the first security information is determined by the network node based on a first attribute corresponding to the system message.

[0184] or,

[0185] First security information is generated using the second attribute of the terminal corresponding to the first attribute, and the system message is decrypted; wherein the system message is security-processed by the network node based on the first attribute.

[0186] In one exemplary embodiment, the communication device 800 is further configured such that the first security information includes at least one of the following: a security key, an encryption algorithm, an integrity algorithm, an intermediate key, an anchor key, and key parameters; wherein the key parameters include at least one of the following: an encoding key, a counter, a system message block sequence number, a system message block length, a country code, a region code, a service code, a terminal capability label, a terminal status label, a waveform type label transmitted by the base station, an antenna and / or base station altitude label, a terminal altitude label, a beam and / or beam group label, a TRP label, an SSB index, a label of one or more cells, a cell type label, and a channel characteristic label.

[0187] In one exemplary embodiment, the communication device 800 is further configured to map the second attribute of the terminal corresponding to the first attribute to an attribute label; and to use the attribute label as an input parameter for key derivation to generate the security key.

[0188] In one exemplary embodiment, the communication device 800 is further configured to encrypt some or all of the information in the system message using a security key; wherein the security key is determined based on the first security information.

[0189] In one exemplary embodiment, the communication device 800 is further configured such that the system message includes at least one system information SI or system information block SIB; the first security information includes: security information of at least one of the SIs; and / or, security information of at least one of the SIBs.

[0190] In one exemplary embodiment, the communication device 800 is further configured to receive the first security information from the network node and store the first security information.

[0191] In one exemplary embodiment, the communication device 800 is further configured to: send a second attribute to the network node during the terminal registration process and / or the terminal initial access process; wherein the second attribute is used to describe the attribute information of the terminal;

[0192] or,

[0193] During the connection establishment process between the terminal and the network node, a second attribute is sent to the network node.

[0194] In one exemplary embodiment, the communication device 800 is further configured to receive the first security information from the network node via at least one of NAS messages, RRC messages, MAC signaling, and DCI signaling.

[0195] In one exemplary embodiment, the communication device 800 is further configured to send a first request message to the network node, the first request message being used to request the acquisition, update, or synchronization of security information; receive and store second security information from the network node; the second security information is determined based on a second attribute of the terminal and a first attribute of each system message; wherein the first security information and the second security information may be the same as or different.

[0196] In one exemplary embodiment, the communication device 800 is further configured to send the first request message to the network node when the timer expires; wherein the timer is started upon receiving the first security information;

[0197] or,

[0198] When the second attribute of the terminal changes, the first request message is sent to the network node.

[0199] In one exemplary embodiment, the communication device 800 is further configured to carry the first security information in the first request message, the first security information being used by the network node for security verification of the terminal.

[0200] In one exemplary embodiment, the communication device 800 is further configured to: receive a group paging message from the network node; the group paging message carries third security information and a Radio Network Temporary Identifier (RNTI); wherein the RNTI is shared between the network node and the receiving end of each system message corresponding to the first attribute; parse the group paging message using the RNTI to obtain the third security information; wherein the third security information is obtained by the network node updating the first security information corresponding to the first attribute; determine and store a security key based on the third security information; or, store the third security information.

[0201] In one exemplary embodiment, the communication device 800 is further configured to: use the first security information as an encoding key, determine a security key in accordance with the manner indicated by the third security information, and store the security key.

[0202] In one exemplary embodiment, the communication device 800 is further configured to: when the first information content of the system message applies to a first region, the system message carries region indication information of the first region containing the first information content;

[0203] The area indication information is indicated by at least one of the following: a reference location point plus radius, a region identifier, a country identifier, a list of cells and / or beams, a list of TPRs, a combination of the position coordinates of multiple boundary points, a polygon shape indication, or a mapped cell identifier.

[0204] This disclosure also provides a communication system. Figure 9 A schematic diagram of a communication system provided in this disclosure is shown. For example... Figure 9 As shown, the communication system includes network nodes and terminals.

[0205] The terminal is used to execute the communication method executed on the terminal side in any of the foregoing embodiments;

[0206] A network node is used for the communication method executed by the network node in any of the foregoing embodiments.

[0207] In one exemplary embodiment, the aforementioned network node may specifically be a network node of a satellite network.

[0208] Figure 10 This is a hardware block diagram of an electronic device provided according to an embodiment of the present disclosure. The electronic device 1000 according to an embodiment of the present disclosure includes at least a memory, a processor, and a computer program stored in the memory. The processor executes the computer program to implement the communication method described in any of the above embodiments.

[0209] Figure 10 The illustrated electronic device 1000 specifically includes a central processing unit (CPU) 1001, a graphics processing unit (GPU) 1002, and a memory 1003. These units are interconnected via a bus 1004. The CPU 1001 and / or GPU 1002 can function as the aforementioned processor, and the memory 1003 can function as the aforementioned memory storing computer-readable instructions. Furthermore, the electronic device 1000 may also include a communication unit 1005, a storage unit 1006, an output unit 10010, an input unit 1008, and an external device 1009, all of which are also connected to the bus 1004.

[0210] Figure 11 This is a schematic diagram of a computer-readable storage medium provided in an embodiment of this disclosure. (As shown...) Figure 11 As shown, a computer-readable storage medium 1100 according to an embodiment of this disclosure stores a computer program / instructions 1101 thereon. When executed by a processor, the computer program / instructions 1101 implements the communication method described in any of the preceding embodiments of this disclosure. The computer-readable storage medium includes, but is not limited to, volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and / or cache memory. Non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, optical disk, magnetic disk, etc. This disclosure further provides a computer program product, including a computer program / instructions, characterized in that, when executed by a processor, the computer program / instructions implement the communication method described in any of the preceding embodiments of this disclosure.

[0211] The basic principles of this disclosure have been described above with reference to specific embodiments. However, it should be noted that the advantages, benefits, and effects mentioned in this disclosure are merely examples and not limitations, and should not be considered as essential features of each embodiment of this disclosure. Furthermore, the specific details disclosed above are for illustrative and facilitative purposes only, and are not limitations. These details do not limit the scope of this disclosure to the necessity of employing the aforementioned specific details for implementation.

[0212] The block diagrams of devices, apparatuses, devices, and systems disclosed herein are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, devices, and systems can be connected, arranged, and configured in any manner. Words such as “comprising,” “including,” “having,” etc., are open-ended terms meaning “including but not limited to,” and are used interchangeably with them. The terms “or” and “and” as used herein refer to the terms “and / or,” and are used interchangeably with them unless the context clearly indicates otherwise. The term “such as” as used herein refers to the phrase “such as but not limited to,” and is used interchangeably with it.

[0213] Additionally, as used herein, the “or” used in a list of items beginning with “at least one” indicates a separate list, such that a list of, for example, “at least one of A, B, or C” means A or B or C, or AB or AC or BC, or ABC (i.e., A and B and C). Furthermore, the word “exemplary” does not imply that the described example is preferred or better than other examples.

[0214] It should also be noted that in the systems and methods of this disclosure, the components or steps can be decomposed and / or recombined. These decompositions and / or recombinations should be considered as equivalent solutions to this disclosure.

[0215] Various changes, substitutions, and modifications can be made to the technology described herein without departing from the teachings defined by the appended claims. Furthermore, the scope of the claims of this disclosure is not limited to the specific aspects of the processes, machines, manufactures, events, means, methods, and actions described above. Currently existing or later-developed processes, machines, manufactures, events, means, methods, or actions that perform substantially the same function or achieve substantially the same result as the corresponding aspects described herein can be utilized. Therefore, the appended claims include such processes, machines, manufactures, events, means, methods, or actions within their scope.

[0216] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use this disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects without departing from the scope of this disclosure. Therefore, this disclosure is not intended to be limited to the aspects shown herein, but rather to be carried out within the widest scope consistent with the principles and novel features disclosed herein.

[0217] The above description has been given for purposes of illustration and description. Furthermore, this description is not intended to limit the embodiments of this disclosure to the forms disclosed herein. Although numerous exemplary aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations therein.

Claims

1. A communication method, characterized in that, Applied to network nodes, the method includes: The system message is sent using its first attribute as the sending granularity. The first attribute includes at least one of the following: location or region, service, communication type, terminal capability, terminal status, transmitted waveform type, antenna and / or base station height, terminal height, beam and / or beam group, transmit / receive point (TRP), SSB index, one or more cells, cell type, and channel characteristics. The channel characteristics include at least one of the following: Doppler frequency shift, Doppler spread, delay spread, average delay, and spatial reception parameters.

2. The method according to claim 1, characterized in that, The system message carries at least one of the following: relevant downlink DL beam and / or cell resource information, location information, area information, transmission time information, and capacity information; and / or; The system message carries at least one of the following: resource information, location information, area information, transmission time information, physical random access channel (PRACH) resource information, and capacity information of the relevant DL beam and / or cell corresponding uplink UL beam and / or cell.

3. The method according to claim 1 or 2, characterized in that, Sending the system message with the first attribute of the system message as the sending granularity includes: Based on the first attribute, the first security information is determined; The system message is processed using the first security information, and the processed system message is then sent.

4. The method according to claim 3, characterized in that, The first security information includes at least one of the following: security key, encryption algorithm, integrity algorithm, intermediate key, anchor key, and key parameters; The key parameters include at least one of the following: encoding key, counter, system message block sequence number, system message block length, country code, region code, service code, terminal capability label, terminal status label, transmitted waveform type label, antenna and / or base station altitude label, terminal altitude label, beam and / or beam group label, TRP label, SSB index, label of one or more cells, label of cell type, and label of channel characteristics.

5. The method according to claim 3, characterized in that, Some or all of the information in the system message is encrypted using a security key; The security key is determined based on the first security information.

6. The method according to claim 5, characterized in that, The determination of the first security information based on the first attribute includes: Map the first attribute to an attribute label; The security key is obtained by using the attribute label as the input parameter for key derivation.

7. The method according to claim 3, characterized in that, The system message includes at least one system information SI or system information block SIB; The first security information includes: security information of at least one of the SIs; and / or, security information of at least one of the SIBs.

8. The method according to claim 3, characterized in that, The method further includes: Based on the first attribute of the system message corresponding to the second attribute of the terminal, send the first security information corresponding to the first attribute to the terminal that has the second attribute; The second attribute is used to describe the terminal's attribute information.

9. The method according to claim 8, characterized in that, The method further includes at least one of the following: Based on the terminal registration process and / or the terminal initial access process, obtain the second attribute of each terminal; Based on the connection establishment process between the terminal and network nodes, the second attribute of each terminal is obtained.

10. The method according to claim 8, characterized in that, Sending the first security information corresponding to the first attribute to a terminal possessing the second attribute includes: The first security information corresponding to the first attribute is sent to a terminal possessing the second attribute via at least one of NAS messages, RRC messages, MAC signaling, and DCI signaling.

11. The method according to any one of claims 1-10, characterized in that, The method further includes: Receive a first request message from any terminal, the first request message being used to request to obtain, update, or synchronize security information; Based on the first attribute of the system message corresponding to the second attribute of the terminal, determine the second security information currently corresponding to the terminal; Send the second security information to the terminal; The first security information may be the same as or different from the second security information.

12. The method according to claim 11, characterized in that, The first request message carries the first security information; before sending the second security information to the terminal, the method further includes: The terminal is subjected to security verification based on the first security information.

13. The method according to any one of claims 1-12, characterized in that, The method further includes: Update the first security information corresponding to the first attribute to obtain the updated third security information; Send a group paging message, the group paging message carrying the third security information and the Radio Network Temporary Identifier (RNTI); wherein, the RNTI is shared between the network node and the receiving end of each system message corresponding to the first attribute; The group paging message also carries the first security information; the first security information is used as an encoding key to determine the security key.

14. The method according to any one of claims 1-13, characterized in that, When the system message is a multi-satellite merging message in a co-frequency coverage scenario, the transmission of the security-processed system message includes: The system messages for each satellite are sent at different times; however, the system messages for any two satellites are sent at different times.

15. The method according to any one of claims 1-14, characterized in that, When the first information content of the system message applies to the first region, the system message carries the region indication information of the first region containing the first information content; The area indication information is indicated by at least one of the following: a reference location point plus radius, a region identifier, a country identifier, a list of cells and / or beams, a list of TPRs, a combination of the position coordinates of multiple boundary points, a polygon shape indication, or a mapped cell identifier.

16. A communication method, characterized in that, Applied to a terminal, the method includes: Receive system messages from network nodes, wherein the system messages are sent with a first attribute as the sending granularity; The first attribute includes at least one of the following: location or region, service, communication type, terminal capability, terminal status, transmitted waveform type, antenna and / or base station height, terminal height, beam and / or beam group, TRP, SSBindex, one or more cells, cell type, and channel characteristics. The channel characteristics include at least one of the following: Doppler frequency shift, Doppler spread, delay spread, average delay, and spatial reception parameters.

17. The method according to claim 16, characterized in that, The method includes: Based on the system message, at least one of the following information is determined: the location or region corresponding to the beam that sent the system message, the type of waveform sent, the height of the antenna and / or base station, the angle between the antenna and the ground, the height of the terminal, information about the beam and / or beam group, TRP information, SSB index, information about one or more cells, the type of cell, and information about channel characteristics.

18. The method according to claim 16, characterized in that, The system message carries at least one of the following: resource information, location information, area information, transmission time information, and capacity information of the relevant DL beam and / or cell. and / or; The system message carries at least one of the following: resource information, location information, area information, transmission time information, PRACH resource information, and capacity information of the DL beam and / or the corresponding UL beam and / or cell.

19. The method according to any one of claims 16-18, characterized in that, The method further includes: The system message is parsed using first security information shared with the network node; wherein the first security information is determined by the network node based on a first attribute corresponding to the system message. or, First security information is generated using the second attribute of the terminal corresponding to the first attribute, and the system message is decrypted; wherein the system message is security-processed by the network node based on the first attribute.

20. The method according to claim 19, characterized in that, The first security information includes at least one of the following: security key, encryption algorithm, integrity algorithm, intermediate key, anchor key, and key parameters; The key parameters include at least one of the following: encoding key, counter, system message block sequence number, system message block length, country code, region code, service code, terminal capability label, terminal status label, waveform type label transmitted by the base station, antenna and / or base station altitude label, terminal altitude label, beam and / or beam group label, TRP label, SSB index, label of one or more cells, label of cell type, and label of channel characteristics.

21. The method according to claim 19, characterized in that, The first security information includes a security key; generating the first security information using the second attribute of the terminal corresponding to the first attribute includes: Map the second attribute of the terminal corresponding to the first attribute to an attribute label; The security key is obtained by using the attribute label as the input parameter for key derivation.

22. The method according to claim 19, characterized in that, Some or all of the information in the system message is encrypted using a security key; The security key is determined based on the first security information.

23. The method according to claim 19, characterized in that, The system message includes at least one system information SI or system information block SIB; The first security information includes: security information of at least one of the SIs; and / or, security information of at least one of the SIBs.

24. The method according to any one of claims 16-23, characterized in that, The method further includes: Receive first security information from the network node; Store the first security information.

25. The method according to claim 24, characterized in that, The method further includes at least one of the following: During the terminal registration process and / or the initial access process of the terminal, a second attribute is sent to the network node; wherein the second attribute is used to describe the attribute information of the terminal; or, During the connection establishment process between the terminal and the network node, a second attribute is sent to the network node.

26. The method according to claim 24, characterized in that, The receipt of the first security information from the network node includes: The first security information is received from the network node via at least one of NAS messages, RRC messages, MAC signaling, and DCI signaling.

27. The method according to any one of claims 16-26, characterized in that, The method further includes: Send a first request message to the network node, the first request message being used to request to obtain, update, or synchronize security information; Receive and store second security information from the network node; the second security information is determined based on the second attribute of the terminal and the first attribute of each system message. The first security information may be the same as or different from the second security information.

28. The method according to claim 27, characterized in that, Sending the first request message to the network node includes: When the timer expires, the first request message is sent to the network node; wherein the timer starts upon receiving the first security information; or, When the second attribute of the terminal changes, the first request message is sent to the network node.

29. The method according to claim 27, characterized in that, The first request message carries the first security information, which is used by the network node to perform security verification on the terminal.

30. The method according to any one of claims 16-29, characterized in that, The method further includes: Receive a group paging message from the network node; the group paging message carries third security information and a Radio Network Temporary Identifier (RNTI); wherein the RNTI is shared between the network node and the receiving end of each system message corresponding to the first attribute; The group paging message is parsed using the RNTI to obtain the third security information; wherein the third security information is obtained by the network node updating the first security information corresponding to the first attribute; A security key is determined and stored based on the third security information; or, the third security information is stored.

31. The method according to claim 30, characterized in that, The group paging message also carries the first security information; The first security information is used as an encoding key to determine the security key; The step of determining and storing the security key based on the third security information includes: The first security information is used as the encoding key, and the security key is determined in accordance with the method indicated by the third security information; Store the security key.

32. The method according to any one of claims 16-31, characterized in that, When the first information content of the system message applies to the first region, the system message carries the region indication information of the first region containing the first information content; The area indication information is indicated by at least one of the following: a reference location point plus radius, a region identifier, a country identifier, a list of cells and / or beams, a list of TPRs, a combination of the position coordinates of multiple boundary points, a polygon shape indication, or a mapped cell identifier.

33. A communication device, characterized in that, Configured on network nodes, including: The transceiver unit is used to send the system message with the first attribute of the system message as the sending granularity; The first attribute includes at least one of the following: location or region, service, communication type, terminal capability, terminal status, transmitted waveform type, antenna and / or base station height, terminal height, beam and / or beam group, transmit / receive point (TRP), SSB index, one or more cells, cell type, and channel characteristics. The channel characteristics include at least one of the following: Doppler frequency shift, Doppler spread, delay spread, average delay, and spatial reception parameters.

34. A communication device, characterized in that, Settings on the terminal include: The transceiver unit is used to receive system messages from network nodes, wherein the system messages are sent with a first attribute as the sending granularity. The first attribute includes at least one of the following: location or region, service, communication type, terminal capability, terminal status, transmitted waveform type, antenna and / or base station height, terminal height, beam and / or beam group, TRP, SSBindex, one or more cells, cell type, and channel characteristics. The channel characteristics include at least one of the following: Doppler frequency shift, Doppler spread, delay spread, average delay, and spatial reception parameters.

35. A communication system, characterized in that, include: Network nodes, configured to perform the method as described in any one of claims 1-15; A terminal for performing the method as described in any one of claims 16-32.

36. The communication system according to claim 35, characterized in that, The network node is a network node of a satellite network.

37. An electronic device comprising a memory, a processor, and a computer program stored in the memory, characterized in that, The processor executes the computer program to implement the method according to any one of claims 1-32.

38. A computer-readable storage medium having a computer program / instructions stored thereon, characterized in that, When the computer program / instructions are executed by the processor, they implement the method described in any one of claims 1-32.

39. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by the processor, they implement the method described in any one of claims 1-32.