Communication method and device and computer readable storage medium
By generating keys based on satellite association information in satellite communication, the security protection problem of NAS messages under the MME-separation architecture is solved, the secure transmission and location verification of NAS messages are realized, the key generation process is simplified, and the security and resource utilization efficiency are improved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-05
- Publication Date
- 2026-04-07
AI Technical Summary
In satellite communication scenarios, how can we achieve secure protection of NAS messages in an MME-separated architecture, especially when MME-NT and MME-T are deployed on satellite and ground respectively, and how can we ensure the security of NAS messages between terminal devices and satellites?
A first key is generated by obtaining information associated with the first satellite, and NAS security protection is performed between the terminal device and the second network element of the satellite based on the key. This ensures that the keys between different satellites and the terminal device are different, thereby achieving security protection of NAS messages, and data storage and forwarding are performed after the location verification is passed.
It improves the security of NAS messages, reduces the number of NAS security contexts that terminal devices need to maintain, saves resources, avoids cross-service area services, simplifies the key generation process, and improves generation efficiency.
Smart Images

Figure CN121815257A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of communication, and in particular to a communication method, device and computer readable storage medium. BACKGROUND
[0002] Due to economic or environmental factors, etc., the ground network may not cover areas such as deserts, oceans, remote areas, etc., and the data transmission needs of these areas usually need to be met through satellite communication. However, in the satellite communication scenario, the satellite may not be able to simultaneously perform data transmission with the terminal device and the ground network, in which case the satellite needs to provide a store-and-forward service.
[0003] Under the store-and-forward service, when the satellite can perform data transmission with the terminal device, the satellite receives data from the terminal device and stores it, and then, when the satellite can perform data transmission with the ground network, the satellite sends the stored data to the ground network. Alternatively, when the satellite can perform communication with the ground network, the satellite receives data from the ground network and stores it, and then, when the satellite can perform communication with the terminal device, the satellite sends the stored data to the terminal device.
[0004] There are two possible architectures for the store-and-forward service. In the first architecture, the satellite carries the base station and all network elements of the core network, including the mobility management entity (MME) and the like. The second architecture is also referred to as an MME-split architecture, in which the MME is split into a non-terrestrial mobility management entity (MME-NT) and a terrestrial mobility management entity (MME-T). The satellite carries the base station and the MME-NT, and the ground network deploys the MME-T and other core network network elements. There is a connection between the MME-NT and the MME-T.
[0005] In the prior art, the terminal device can perform security protection on the NAS message according to the key shared by the terminal device and the MME, thereby improving the security of NAS message transmission. However, in the second architecture, the MME is split into two parts, MME-NT and MME-T, and the MME-NT and MME-T are deployed on the satellite and the ground, respectively. In this case, how to implement security protection of the NAS message is a problem to be solved. SUMMARY
[0006] Embodiments of the present application disclose a communication method, device and computer readable storage medium to implement security protection of the NAS message under the MME-split architecture.
[0007] The first aspect discloses a communication method, which can be applied to a terminal device, a module (e.g., a processor or a chip) in the terminal device, and a logic module or software capable of realizing all or part of the functions of the terminal device. The communication method is described below by taking the terminal device as an example. The communication method can include: obtaining first information associated with a first satellite, the first information associated with different satellites being different; generating a first key based on the first information associated with the first satellite; and performing NAS security protection between a second network element and the terminal device based on the first key, the second network element being deployed at the first satellite.
[0008] In the embodiments of the present application, the terminal device can obtain the first information associated with the first satellite, and can generate the first key based on the first information associated with the first satellite. Then, the terminal device can perform the NAS security protection between the second network element of the first satellite and the terminal device based on the first key. Since the first key is generated based on the first information associated with the first satellite, and the first information associated with different satellites is different, the keys (e.g., integrity keys and / or encryption keys) for the NAS security protection between different satellites and the terminal device can be different, thereby ensuring the NAS security of various NAS messages between the terminal device and the second network element in the store-and-forward service. Further, in the satellite communication scenario, the location of the terminal device usually needs to be verified. The first satellite can provide the store-and-forward service for the terminal device only when the location verification of the terminal device is passed. In the above-mentioned manner, the terminal device and the second network element of the first satellite can include independent keys for the NAS security protection. Therefore, the second network element of the first satellite and the terminal device can transmit the messages related to the location verification based on the first key, thereby facilitating the location verification of the terminal device by the second network element of the first satellite, and avoiding the service of the first satellite across service areas. In addition, when the location verification of the terminal device is passed, the store-and-forward of the uplink and downlink data between the terminal device and the first network element can be supported.
[0009] For example, the first key can be a key shared between the terminal device and the second network element.
[0010] In combination with the first aspect, in a possible implementation, the obtaining the first information associated with the first satellite includes: receiving a second key set identifier and the first information associated with the first satellite from the second network element, the second key set identifier being used to identify the first key.
[0011] In the embodiments of the present application, the terminal device can receive the first information associated with the first satellite and the second key set identifier from the second network element, then can generate the first key based on the first information associated with the first satellite, and associate the first key with the second key set identifier, so that when the terminal device and the second network element use the first key for NAS security protection later, the key used for NAS message encryption can be determined.
[0012] In combination with the first aspect, in a possible implementation, the NAS security protection between the second network element and the terminal device based on the first key includes: receiving a first downlink message after NAS security protection and the second key set identifier from the second network element; determining the first key based on the second key set identifier; performing NAS security processing on the first downlink message after NAS security protection based on the first key, to obtain the first downlink message.
[0013] In combination with the first aspect, in a possible implementation, the NAS security protection between the second network element and the terminal device based on the first key includes: performing NAS security protection on a first uplink message based on the first key; and sending the second key set identifier and the first uplink message after NAS security protection to the second network element.
[0014] In the embodiments of the present application, for the uplink message (such as the first uplink message) of the terminal device to the first network element, and the downlink message (such as the first downlink message) of the first network element to the terminal device, the first key can be used for NAS security protection, which can protect the security of the first uplink message and the first downlink message when transmitted between the terminal device and the first satellite, and in this case, the second network element and the first network element can transmit the first downlink message and the first uplink message in plaintext, the first network element and the terminal device can not need to establish NAS security context, the number of NAS security contexts that the terminal device needs to maintain can be reduced, and relevant resources (such as storage resources) can be saved.
[0015] In combination with the first aspect, in a possible implementation, the method further includes: receiving the second key set identifier and a first NAS message from the second network element; determining the first key based on the second key set identifier, and performing NAS security processing on the first NAS message based on the first key to obtain a location request message, the location request message being used for requesting location information of the terminal device; performing NAS security protection on a location request response message based on the first key to obtain a second NAS message, the location request response message including the location information of the terminal device; and sending the second NAS message and the second key set identifier to the second network element.
[0016] In the embodiments of the present application, the second network element and the terminal device can include an independent NAS security key (the first key). In this case, the terminal device can receive the second key set identifier and the first NAS message from the second network element, determine the first key based on the second key set identifier, perform NAS security processing on the first NAS message based on the first key to obtain the location request message. Then, the terminal device can feed back its own location (such as the current location) to the second network element based on the location request message, and perform NAS security protection on the location request response message to obtain the second NAS message, and return the second NAS message to the second network element, so that the second network element can check (such as real-time check) the location of the terminal device based on the first key.
[0017] With reference to the first aspect, in a possible implementation, the method further includes: receiving the first downlink message protected by NAS security and the first key set identifier from the second network element, the first key set identifier being used to identify the second key; determining the second key based on the first key set identifier; and performing NAS security processing on the first downlink message protected by NAS security based on the second key to obtain the first downlink message.
[0018] With reference to the first aspect, in a possible implementation, the method further includes: performing NAS security protection on the first uplink message based on the second key; and sending the first key set identifier and the first uplink message protected by NAS security to the second network element, the first key set identifier being used to identify the second key.
[0019] In the embodiments of the present application, the terminal device and the first network element can establish an NAS security context, which can include an independent NAS security key (the second key). In this case, in the process of storage and forwarding by the first satellite, the terminal device and the first network element can protect the security of the first uplink message and the first downlink message based on the second key.
[0020] With reference to the first aspect, in a possible implementation, the method further includes: updating the downlink count value corresponding to the first key in the case of performing NAS security processing on the NAS message from the second network element based on the first key; and / or updating the uplink count value corresponding to the first key in the case of performing NAS security protection on the NAS message sent to the second network element based on the first key.
[0021] With reference to the first aspect, in a possible implementation, the generating the first key based on the first information associated with the first satellite comprises: generating a first intermediate key based on the first information associated with the first satellite and a first intermediate key, the first intermediate key also being used to generate a second key, the second key being used for NAS security protection between the first network element and the terminal device, the first network element being deployed on the ground.
[0022] In the case where the NAS security context is established between the terminal device and the first network element, the first intermediate key can be included in the NAS security context between the terminal device and the first network element. Therefore, in this case, if the terminal device generates the first key based on the first information associated with the first satellite and the first intermediate key, the process of generating the first key can be simplified, and thus the efficiency of generating the first key can be improved.
[0023] With reference to the first aspect, in a possible implementation, before the generating the first key based on the first information associated with the first satellite and the first intermediate key, the method further comprises: receiving a first key set identifier from the second network element; and determining the first intermediate key based on the first key set identifier.
[0024] In the case where the first key is generated based on the first information associated with the first satellite and the first intermediate key, the terminal device can also receive the first key set identifier from the second network element, and can determine the first intermediate key based on the first key set identifier, and then generate the first key based on the first intermediate key and the first information associated with the first satellite.
[0025] With reference to the first aspect, in a possible implementation, the generating the first key based on the first information associated with the first satellite comprises: generating a second intermediate key based on the first information associated with the first satellite; and generating the first key based on the second intermediate key.
[0026] In the embodiments of the present application, the terminal device can first generate an intermediate key (such as a second intermediate key) based on the first information associated with the first satellite, and then generate the first key based on the second intermediate key, which has high flexibility.
[0027] The second aspect discloses a communication method, which can be applied to a first network element, a module (for example, a processor or a chip) in the first network element, and a logic module or software capable of realizing all or part of the functions of the first network element. The communication method can include the following steps: obtaining first information associated with a first satellite, the first satellite being a satellite to be accessed by a terminal device, the first information associated with different satellites being different; obtaining a first key based on the first information associated with the first satellite, the first key being used for NAS security protection between a second network element and the terminal device, the second network element being deployed on the first satellite; and sending an identifier of the terminal device and the first key to the second network element.
[0028] In the embodiments of the present application, the first network element can obtain the first information associated with the first satellite, then obtain the first key based on the first information associated with the first satellite, and then send the first key and the identifier of the terminal device to the second network element of the first satellite, so that the second network element can perform NAS security protection between the second network element and the terminal device based on the first key.
[0029] In combination with the second aspect, in a possible implementation, the method further includes: performing NAS security protection on the first downlink message based on the second key; and sending the first downlink message after the NAS security protection and a first key set identifier to the second network element, the first key set identifier being used to identify the second key.
[0030] In the embodiments of the present application, the NAS security context between the terminal device and the first network element can be established, and can include an independent NAS security key (the second key). In this case, in the process of storage and forwarding through the first satellite, the first network element can perform NAS security protection on the first downlink message based on the second key in advance, and then send the first downlink message after the NAS security protection and a first key set identifier to the second network element, so that the second network element can forward the first downlink message to the terminal device when the second network element can communicate with the terminal device.
[0031] In combination with the second aspect, in a possible implementation, the method further includes: receiving the first uplink message after the NAS security protection and the first key set identifier from the second network element; determining the second key based on the first key set identifier; and performing NAS security processing on the first uplink message after the NAS security protection based on the second key, to obtain the first uplink message.
[0032] In the embodiments of the present application, the NAS security context can be established between the terminal device and the first network element, and can include an independent NAS security key (second key). In this case, during the storage and forwarding process through the first satellite, the first network element can receive the first key set identifier from the second network element and the first uplink message protected by the NAS security generated by the terminal device in advance, and the security protection of the first uplink message during the storage and forwarding process can be implemented.
[0033] With reference to the second aspect, in a possible implementation, the method further includes: sending, to the second network element, uplink count value and downlink count value corresponding to the first key, the uplink count value and the downlink count value corresponding to the first key being used for NAS security protection between the second network element and the terminal device.
[0034] With reference to the second aspect, in a possible implementation, the first key is obtained based on the first information associated with the first satellite, and the obtaining includes: sending a key request to a third network element, the key request including the first information associated with the first satellite; and receiving a key request response from the third network element, the key request response including the first key.
[0035] With reference to the second aspect, in a possible implementation, the first key is obtained based on the first information associated with the first satellite, and the obtaining includes: generating the first key based on the first information associated with the first satellite.
[0036] With reference to the second aspect, in a possible implementation, the first key is generated based on the first information associated with the first satellite, and the generating includes: generating the first key based on the first information associated with the first satellite and a first intermediate key, the first intermediate key also being used to generate a second key, the second key being used for NAS security protection between the first network element and the terminal device.
[0037] In the embodiments of the present application, in the case where the NAS security context is established between the terminal device and the first network element, the first intermediate key can be included in the NAS security context between the terminal device and the first network element. Therefore, in this case, if the first network element generates the first key based on the first information associated with the first satellite and the first intermediate key, the process of generating the first key can be simplified, and thus the efficiency of generating the first key can be improved.
[0038] With reference to the second aspect, in a possible implementation, the method further includes: sending, to the second network element, a first key set identifier, the first key set identifier being used to identify the first intermediate key.
[0039] In the embodiments of the present application, in the case that the first key is generated based on the first intermediate key and the first information associated with the first satellite, the second network element can receive the first key set identifier from the first network element, and then can further send the first key set identifier to the terminal device, so that the terminal device can determine the first intermediate key based on the first key set identifier, and then can generate the first key based on the first intermediate key and the first information associated with the first satellite.
[0040] In combination with the second aspect, in a possible implementation, the first key is acquired based on the first information associated with the first satellite, including: generating a second intermediate key based on the first information associated with the first satellite; and generating the first key based on the second intermediate key.
[0041] The terminal device can first generate an intermediate key (such as a second intermediate key) based on the first information associated with the first satellite, and then can generate the first key based on the second intermediate key, which has high flexibility.
[0042] It should be noted that the technical solutions of the first aspect, the technical solutions of the second aspect and the technical solutions of the third aspect correspond to each other, and the related beneficial effects can be mutually referred.
[0043] The third aspect discloses a communication method, which can be applied to a second network element, a module (for example, a processor or a chip) in the second network element, or a logic module or software capable of realizing all or part of the functions of the second network element. The second network element can be deployed on a first satellite. The communication method applied to the second network element can include: receiving an identifier of a terminal device and a first key from a first network element, the first key being generated based on first information associated with the first satellite, and the first information associated with different satellites being different; and performing NAS security protection between the second network element and the terminal device based on the first key.
[0044] In the embodiments of the present application, the second network element can receive the first key and the identifier of the terminal device from the first network element, and can determine that the first key is associated with the corresponding terminal device based on the identifier of the terminal device. Then, the second network element can perform NAS security protection between the second network element and the terminal device based on the first key. Since the first key is generated based on the first information associated with the first satellite, and the first information associated with different satellites is different, the key (such as an integrity key and / or an encryption key) used for NAS security protection between different satellites and the terminal device can be different, thereby ensuring the NAS security of various NAS messages in the store-and-forward service. Further, in the satellite communication scenario, the location of the terminal device usually needs to be verified, and the satellite can provide the store-and-forward service for the terminal device only when the location verification of the terminal device is passed. In the above-mentioned manner, the terminal device and the second network element of the first satellite can include an independent key for NAS security protection, so that the second network element of the first satellite and the terminal device can transmit messages related to location verification based on the first key, thereby enabling the second network element of the first satellite to verify the location of the terminal device, and further avoiding the first satellite to provide service across service areas. In addition, when the location verification of the terminal device is passed, the first satellite can support the store-and-forward of uplink and downlink data between the terminal device and the first network element.
[0045] In combination with the third aspect, in a possible implementation, the method further includes: sending, to the terminal device, a second key set identifier and the first information associated with the first satellite, the second key set identifier being used to identify the first key.
[0046] In the embodiments of the present application, the second network element can send the first information associated with the first satellite to the terminal device, so that the terminal device can generate the first key based on the first information associated with the first satellite, thereby facilitating the terminal device to perform NAS security protection between the second network element and the terminal device based on the first key. In addition, the second network element can send the second key set identifier to the terminal device, so that when the terminal device and the second network element perform NAS security protection using the first key, the key used for encryption of the NAS message can be determined.
[0047] In combination with the third aspect, in a possible implementation, the method further includes: receiving a first downlink message from the first network element; and performing the NAS security protection between the second network element and the terminal device based on the first key, including: performing NAS security protection on the first downlink message based on the first key; and sending the first downlink message after the NAS security protection and the second key set identifier to the terminal device.
[0048] In combination with the third aspect, in a possible implementation, the NAS security protection between the second network element and the terminal device based on the first key comprises: receiving the second key set identifier and the first uplink message after NAS security protection from the terminal device; determining the first key based on the second key set identifier; performing NAS security processing on the first uplink message after NAS security protection based on the first key to obtain the first uplink message; and sending the identifier of the terminal device and the first uplink message to the first network element.
[0049] In the embodiments of the present application, the uplink message (such as the first uplink message) from the terminal device to the first network element and the downlink message (such as the first downlink message) from the first network element to the terminal device can be protected by the first key, which can protect the security of the first uplink message and the first downlink message during transmission between the terminal device and the first satellite. In this case, the first downlink message and the first uplink message can be transmitted in plaintext between the second network element and the first network element, and the NAS security context does not need to be established between the first network element and the terminal device, which can reduce the number of NAS security contexts that the terminal device needs to maintain, thereby saving relevant resources (such as storage resources) and the like.
[0050] In combination with the third aspect, in a possible implementation, the method further comprises: performing NAS security protection on a location request message based on the first key to obtain a first NAS message, the location request message being used to request to obtain the location information of the terminal device; sending the second key set identifier and the first NAS message to the terminal device; receiving the second key set identifier and a second NAS message from the terminal device; determining the first key based on the second key set identifier, and performing NAS security processing on the second NAS message based on the first key to obtain a location request response message, the location request response message comprising the location information of the terminal device; and performing location verification on the terminal device based on the location information of the terminal device.
[0051] In the embodiments of the present application, the second network element and the terminal device can include an independent NAS security key (the first key). In this case, the second network element can perform NAS security protection on a location request message based on the first key, and then send the second key set identifier and the first NAS message to the terminal device. Subsequently, the second network element can receive the second NAS message and the second key set identifier from the terminal device, determine the first key based on the second key set identifier, perform NAS security processing on the second NAS message based on the first key to obtain the location information of the terminal device, and thus perform location verification (such as real-time verification) on the terminal device based on the location information of the terminal device.
[0052] With reference to the third aspect, in a possible implementation, the NAS security protection between the second network element and the terminal device based on the first key comprises: performing, based on the first key, the NAS security protection between the second network element and the terminal device in a case where the location check of the terminal device is passed.
[0053] In the embodiments of the present application, the second network element can perform the NAS security protection between the second network element and the terminal device based on the first key only in a case where the location check of the terminal device is passed, so that cross-service-area service can be avoided.
[0054] With reference to the third aspect, in a possible implementation, the method further comprises: receiving a first downlink message after NAS security protection and a first key set identifier from the first network element, the first downlink message after NAS security protection being based on a second key for NAS security protection, the first key set identifier being used to identify the second key, the second key being used for the NAS security protection between the first network element and the terminal device; and sending, to the terminal device, the first downlink message after NAS security protection and the first key set identifier in a case where the location check of the terminal device is passed.
[0055] In the embodiments of the present application, the NAS security context between the terminal device and the first network element can be established, and can include an independent NAS security key (the second key). In this case, after receiving the first downlink message after NAS security protection and the first key set identifier from the first network element, the second network element can send the first downlink message after NAS security protection and the first key set identifier to the terminal device in a case where the location check of the terminal device is passed, so that the first downlink message can be protected based on the second key.
[0056] With reference to the third aspect, in a possible implementation, the method further comprises: receiving a first downlink message after NAS security protection and a first key set identifier from the first network element, the first downlink message after NAS security protection being based on a second key for NAS security protection, the first key set identifier being used to identify the second key, the second key being used for the NAS security protection between the first network element and the terminal device; and sending, to the terminal device, the first downlink message after NAS security protection and the first key set identifier in a case where the location check of the terminal device is passed.
[0057] In the embodiments of the present application, the terminal device and the first network element can establish a NAS security context, which can include an independent NAS security key (second key). In this case, in the process of forwarding by the first satellite, after the second network element receives the first uplink message and the first key set identifier from the terminal device, and the location of the terminal device is verified, the second network element can send the first uplink message and the first key set identifier to the first network element, so that the first uplink message can be protected based on the second key.
[0058] In combination with the third aspect, in a possible implementation, the method further includes: receiving an uplink count value and a downlink count value corresponding to the first key from the first network element, the uplink count value and the downlink count value corresponding to the first key being used for NAS security protection between the second network element and the terminal device; updating the uplink count value corresponding to the first key in a case that the first key is used for NAS security processing of a NAS message from the terminal device; and / or updating the downlink count value corresponding to the first key in a case that the first key is used for NAS security protection of a NAS message sent to the terminal device.
[0059] In combination with the third aspect, in a possible implementation, the method further includes: sending one or more of the updated uplink count value corresponding to the first key, the updated downlink count value corresponding to the first key, and the first information associated with the first satellite to the first network element.
[0060] In combination with the third aspect, in a possible implementation, the method further includes: receiving a first key set identifier from the first network element; and sending the first key set identifier to the terminal device, the first key set identifier being used to identify a first intermediate key, the first intermediate key being used to generate the first key and a second key, the second key being used for NAS security protection between the first network element and the terminal device.
[0061] In the embodiments of the present application, in a case that the first key is generated based on the first intermediate key and the first information associated with the first satellite, the first network element can send a first key set identifier to the second network element, so that the second network element can send the first key set identifier to the terminal device, thereby facilitating the terminal device to determine the first intermediate key based on the first key set identifier, and then generate the first key based on the first intermediate key and the first information associated with the first satellite. It should be noted that the technical solutions of the first aspect, the second aspect and the third aspect of the present application correspond to each other, and the related beneficial effects can be referred to each other.
[0062] The fourth aspect discloses a communication method, which can be applied to a terminal device, a module (for example, a processor or a chip) in the terminal device, and a logic module or software capable of realizing all or part of the functions of the terminal device. The communication method is described below by taking the terminal device as an example. The communication method can include: obtaining a first key, the first key being used for NAS security protection between a first network element and the terminal device; the first network element being deployed on the ground; performing NAS security protection on location information of the terminal device and a first uplink message based on the first key; and sending the NAS security protected location information of the terminal device to a second network element and sending the NAS security protected first uplink message to the second network element, the second network element being deployed on a first satellite.
[0063] In the embodiments of the present application, the terminal device can perform NAS security protection on the location information of the terminal device and the uplink message based on the key between the terminal device and the first network element, and can send the NAS security protected location information of the terminal device and the NAS security protected uplink message to the second network element of the first satellite, so that the second network element of the first satellite can send the NAS security protected location information of the terminal device and the NAS security protected uplink message to the first network element. It can be seen that in the above manner, when the terminal device needs to send the uplink message to the first network element through the second network element of the first satellite, the NAS security in the store-and-forward service can be ensured based on the key between the terminal device and the first network element, and the store-and-forward of the uplink data between the terminal device and the first network element can be supported.
[0064] In combination with the fourth aspect, in a possible implementation, the method further includes: sending a first key set identifier to the second network element, the first key set identifier being used for identifying the first key.
[0065] In the embodiments of the present application, when the terminal device performs NAS security protection on the location information of the terminal device and the first uplink message using the key between the terminal device and the first network element, the terminal device can also send the corresponding first key set identifier to the second network element when sending the NAS security protected location information of the terminal device and the NAS security protected first uplink message to the second network element, so that the second network element can also send the corresponding first key set identifier to the terminal device when sending the NAS security protected location information of the terminal device and the NAS security protected first uplink message to the terminal device, thereby the terminal device can determine the first key based on the first key set identifier, and then the terminal device can perform NAS security processing on the NAS security protected location information of the terminal device and the NAS security protected first uplink message based on the first key.
[0066] In a possible implementation of the fourth aspect, the method further includes: receiving the identifier of the terminal device and a first key set identifier from the second network element, the first key set identifier being used to identify the first key; and obtaining the first key includes: obtaining the first key based on the first key set identifier.
[0067] In the embodiments of the present application, the terminal device can receive the identifier of the terminal device and the first key set identifier from the second network element, then determine the corresponding first key based on the first key set identifier, then perform NAS security processing on the location information of the terminal device and the first uplink message based on the first key, and obtain the NAS security protected location information of the terminal device and the NAS security protected first uplink message, so that the terminal device can send the NAS security protected location information of the terminal device and the NAS security protected first uplink message to the first network element through the second network element.
[0068] In a possible implementation of the fourth aspect, the method further includes: receiving the NAS security protected location request message from the second network element, the NAS security protected location request message being NAS security protected based on the first key, and the NAS security protected location request message being used to request to obtain the location information of the terminal device; and sending the NAS security protected location information of the terminal device to the second network element includes: sending the NAS security protected location information of the terminal device to the second network element based on the NAS security protected location request message.
[0069] In the embodiments of the present application, the terminal device can receive the NAS security protected location request message generated by the first network element in advance from the second network element, then perform NAS security processing on the NAS security protected location request message based on the first key, and obtain the location request message, and then send the NAS security protected location information of the terminal device to the second network element based on the location request message, so that the second network element can send the NAS security protected location information of the terminal device to the first network element later.
[0070] The fifth aspect discloses a communication method, which can be applied to a first network element, a module (for example, a processor or a chip) in the first network element, or a logic module or software capable of realizing all or part of the functions of the first network element. The first network element can be deployed on the ground. The communication method applied to the first network element can include the following steps: receiving location information of a terminal device after NAS security protection and a first uplink message after NAS security protection from a second network element; the location information of the terminal device after NAS security protection and the first uplink message after NAS security protection are subjected to NAS security protection based on a first key; the second network element is deployed on a first satellite, and the first key is used for NAS security protection between the first network element and the terminal device; performing NAS security processing on the location information of the terminal device after NAS security protection based on the first key to obtain the location information of the terminal device; performing location verification on the terminal device based on the location information of the terminal device; and performing processing based on the first uplink message when the location verification on the terminal device is passed.
[0071] In the embodiments of the present application, the first network element can receive the location information of the terminal device after NAS security protection and the first uplink message after NAS security protection generated by the terminal device and forwarded by the second network element, and then can perform NAS security processing on the location information of the terminal device after NAS security protection based on the first key to obtain the location information of the terminal device, so as to perform location verification on the terminal device based on the location information of the terminal device, and then perform processing based on the first uplink message when the location verification on the terminal device is passed. It can be seen that in the above manner, the location of the terminal device can be verified by the first network element, and the first network element can process the first uplink message only when the location verification on the terminal device is passed, so that the first satellite can avoid cross-service-area service.
[0072] In combination with the fifth aspect, in a possible implementation manner, before the NAS security processing on the location information of the terminal device after NAS security protection based on the first key, the method further includes: receiving a first key set identifier from the second network element; and determining the first key based on the first key set identifier.
[0073] In the embodiments of the present application, when the location information of the terminal device after NAS security protection is subjected to NAS security processing based on the first key, the first network element can further receive a first key set identifier from the second network element, so that the first network element can quickly and accurately determine the first key based on the first key set identifier.
[0074] In a possible implementation of the fifth aspect, the method further includes: sending, to the second network element, an identifier of the terminal device and a first key set identifier, the first key set identifier being used to identify the first key, and the first satellite being a satellite to be accessed by the terminal device.
[0075] In the embodiments of the present application, when the first network element needs the terminal device to feed back an uplink message, the first network element can send an identifier of the terminal device and a first key set identifier to the second network element, so that the second network element can send the identifier of the terminal device and the first key set identifier to the terminal device, thereby facilitating the terminal device to obtain the NAS security protected terminal device location information and the NAS security protected uplink message based on the first key corresponding to the first key set identifier, and send the NAS security protected terminal device location information and the NAS security protected uplink message to the first network element through the second network element.
[0076] In a possible implementation of the fifth aspect, the method further includes: sending, to the second network element, a NAS security protected location request message, the NAS security protected location request message being NAS security protected based on the first key, and the NAS security protected location request message being used to request to obtain the location information of the terminal device.
[0077] In the embodiments of the present application, the first network element can pre-protect a location request message based on the first key between the terminal device, and then send the NAS security protected location request message to the second network element, so that the second network element can send the NAS security protected location request message to the terminal device to obtain the NAS security protected location information of the terminal device.
[0078] It should be noted that the technical solutions of the fourth aspect, the fifth aspect and the sixth aspect of the present application correspond to each other, and the related beneficial effects can be mutually referred.
[0079] The sixth aspect discloses a communication method, which can be applied to a second network element, a module (for example, a processor or a chip) in the second network element, or a logic module or software capable of realizing all or part of the functions of the second network element. The second network element can be deployed on a first satellite. The communication method applied to the second network element can include the following steps: receiving NAS security protected location information of a terminal device from the terminal device, and receiving a NAS security protected first uplink message from the terminal device; the NAS security protected location information of the terminal device and the NAS security protected first uplink message are NAS security protected based on a first key; the first key is used for NAS security protection between the first network element and the terminal device; and sending the NAS security protected location information of the terminal device and the NAS security protected first uplink message to the first network element, wherein the first network element is deployed on the ground.
[0080] In the embodiments of the present application, after the second network element receives the NAS security protected location information of the terminal device and the NAS security protected first uplink message from the terminal device, the second network element can send the NAS security protected location information of the terminal device and the NAS security protected first uplink message to the first network element, so that the first network element can perform location verification on the terminal device based on the first key and the NAS security protected location information of the terminal device, and process the first uplink message based on the location verification result, thereby avoiding cross-service area service of the first satellite.
[0081] In combination with the sixth aspect, in a possible implementation, the method further includes: receiving a first key set identifier from the terminal device, the first key set identifier being used to identify the first key; and sending the first key set identifier to the first network element.
[0082] In the embodiments of the present application, in the case that the NAS security protected location information of the terminal device is NAS security protected based on the first key, the second network element can further receive a first key set identifier from the terminal device, so that the second network element can send the first key set identifier to the first network element, and then the terminal device can quickly and accurately determine the first key based on the first key set identifier.
[0083] In combination with the sixth aspect, in a possible implementation, before the receiving of the NAS security protected location information of the terminal device and the NAS security protected first uplink message from the terminal device, the method further includes: receiving an identifier of the terminal device and a first key set identifier from the first network element; and sending the identifier of the terminal device and the first key set identifier to the terminal device.
[0084] In the embodiments of the present application, after receiving the identifier of the terminal device and the first key set identifier from the first network element, the second network element can send the identifier of the terminal device and the first key set identifier to the terminal device, so that the terminal device obtains the NAS security protected location information of the terminal device and the NAS security protected uplink message based on the first key corresponding to the first key set identifier, and sends the NAS security protected location information of the terminal device and the NAS security protected uplink message to the first network element through the second network element.
[0085] In combination with the sixth aspect, in a possible implementation, before receiving the NAS security protected location information of the terminal device and the NAS security protected first uplink message from the terminal device, the method further includes: receiving a NAS security protected location request message from the first network element, the NAS security protected location request message being NAS security protected based on the first key, the NAS security protected location request message being used to request to obtain the location information of the terminal device; and sending the NAS security protected location request message to the terminal device.
[0086] In the embodiments of the present application, after receiving the NAS security protected location request message generated in advance by the first network element, the second network element can send the NAS security protected location request message to the terminal device to obtain the NAS security protected location information of the terminal device.
[0087] It should be noted that the technical solutions of the fourth aspect, the technical solutions of the fifth aspect and the technical solutions of the sixth aspect of the present application correspond to each other, and the related beneficial effects can be mutually referred.
[0088] The seventh aspect discloses a communication apparatus having the functions of the first aspect or the fourth aspect, for example, the communication apparatus includes a module or unit for performing the method of the first aspect or any possible implementation of the first aspect, or a module or unit for performing the method of the fourth aspect or any possible implementation of the fourth aspect. The module or unit can be implemented by software, or by hardware, or by a combination of software and hardware.
[0089] For example, the communication apparatus disclosed in the seventh aspect can be a terminal device or a chip in a terminal device.
[0090] The eighth aspect discloses a communication apparatus having the functions of the second aspect or the fifth aspect, for example, the communication apparatus includes a module or unit for performing the method in the second aspect or any possible implementation of the second aspect, or a module or unit for performing the method in the fifth aspect or any possible implementation of the fifth aspect, which can be implemented by software, or by hardware, or by a combination of software and hardware.
[0091] For example, the communication apparatus of the eighth aspect can be a first network element or a chip in the first network element.
[0092] The ninth aspect discloses a communication apparatus having the functions of the third aspect or the sixth aspect, for example, the communication apparatus includes a module or unit for performing the method in the third aspect or any possible implementation of the third aspect, or a module or unit for performing the method in the sixth aspect or any possible implementation of the sixth aspect, which can be implemented by software, or by hardware, or by a combination of software and hardware.
[0093] For example, the communication apparatus of the ninth aspect can be a second network element or a chip in the second network element.
[0094] The tenth aspect discloses a communication system including at least two of a terminal device, a first network element and a second network element, the first network element can be deployed on the ground, the second network element can be deployed on a first satellite, the terminal device is configured to implement the method provided in the first aspect and any possible implementation of the first aspect, the first network element is configured to implement the method provided in the second aspect and any possible implementation of the second aspect, and the second network element is configured to implement the method provided in the third aspect and any possible implementation of the third aspect; or the terminal device is configured to implement the method provided in the fourth aspect and any possible implementation of the fourth aspect, the first network element is configured to implement the method provided in the fifth aspect and any possible implementation of the fifth aspect, and the second network element is configured to implement the method provided in the sixth aspect and any possible implementation of the sixth aspect.
[0095] The eleventh aspect discloses a communication apparatus, comprising a processor and a communication interface; the communication interface is configured to receive and / or send data; the processor invokes a computer program or computer instructions stored in a memory to implement the method provided in the first aspect and any possible implementation of the first aspect, or implement the method provided in the second aspect and any possible implementation of the second aspect, or implement the method provided in the third aspect and any possible implementation of the third aspect, or implement the method provided in the fourth aspect and any possible implementation of the fourth aspect, or implement the method provided in the fifth aspect and any possible implementation of the fifth aspect, or implement the method provided in the sixth aspect and any possible implementation of the sixth aspect.
[0096] As a possible implementation, the communication apparatus disclosed in the eleventh aspect comprises one or more processors.
[0097] Optionally, the communication apparatus disclosed in the eleventh aspect further comprises one or more memories.
[0098] The twelfth aspect discloses a computer readable storage medium, the computer readable storage medium stores a computer program or computer instructions, when the computer program or computer instructions are executed, implement the method provided in the first aspect and any possible implementation of the first aspect, or implement the method provided in the second aspect and any possible implementation of the second aspect, or implement the method provided in the third aspect and any possible implementation of the third aspect, or implement the method provided in the fourth aspect and any possible implementation of the fourth aspect, or implement the method provided in the fifth aspect and any possible implementation of the fifth aspect, or implement the method provided in the sixth aspect and any possible implementation of the sixth aspect.
[0099] The thirteenth aspect discloses a chip, comprising a processor, configured to execute a program stored in a memory, when the program is executed, make the chip execute the method provided in the first aspect and any possible implementation of the first aspect, or execute the method provided in the second aspect and any possible implementation of the second aspect, or execute the method provided in the third aspect and any possible implementation of the third aspect, or execute the method provided in the fourth aspect and any possible implementation of the fourth aspect, or execute the method provided in the fifth aspect and any possible implementation of the fifth aspect, or execute the method provided in the sixth aspect and any possible implementation of the sixth aspect.
[0100] As a possible implementation, the memory is located outside the chip.
[0101] A fourteenth aspect discloses a computer program product comprising computer program code which, when executed by a computer, causes the method provided in the first aspect and any possible implementation of the first aspect to be performed, or causes the method provided in the second aspect and any possible implementation of the second aspect to be performed, or causes the method provided in the third aspect and any possible implementation of the third aspect to be performed, or causes the method provided in the fourth aspect and any possible implementation of the fourth aspect to be performed, or causes the method provided in the fifth aspect and any possible implementation of the fifth aspect to be performed, or causes the method provided in the sixth aspect and any possible implementation of the sixth aspect to be performed.
[0102] It should be understood that the implementation and beneficial effects of the above aspects or any possible implementation of the present application can be mutually referred to. BRIEF DESCRIPTION OF DRAWINGS
[0103] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0104] Figure 1 is a storage and forwarding scenario schematic diagram disclosed by the embodiments of the present application;
[0105] Figure 2 is a flow process schematic diagram of establishing NAS security in a ground scenario disclosed by the embodiments of the present application;
[0106] Figure 3 is a system architecture schematic diagram disclosed by the embodiments of the present application;
[0107] Figure 4 is a flow process schematic diagram of a communication method disclosed by the embodiments of the present application;
[0108] Figure 5 is a flow process schematic diagram of another communication method disclosed by the embodiments of the present application;
[0109] Figure 6 is a flow process schematic diagram of still another communication method disclosed by the embodiments of the present application;
[0110] Figure 7 is a flow process schematic diagram of still another communication method disclosed by the embodiments of the present application;
[0111] Figure 8 is a flowchart of another communication method disclosed by an embodiment of the present application;
[0112] Figure 9 is a flowchart of another communication method disclosed by an embodiment of the present application;
[0113] Figure 10 is a structural diagram of a communication device disclosed by an embodiment of the present application;
[0114] Figure 11 is a hardware structural diagram of a communication device disclosed by an embodiment of the present application. DETAILED DESCRIPTION
[0115] The embodiments of the present application disclose a communication method, device and computer readable storage medium, and can realize security protection of a NAS message under an MME-split architecture. The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings.
[0116] In order to better understand the embodiments of the present application, the related contents, terms or names involved in the present application will be briefly introduced below.
[0117] I. Store and forward, and store and forward related network architecture
[0118] Desert, ocean, forest, remote area and other special areas of uncovered ground network also generally have the demand of data transmission. For example, various Internet of Things devices (such as temperature sensors, humidity sensors, cameras, etc.) can be deployed in these areas to realize environmental monitoring (air quality, humidity, temperature, water quality, etc.), animal monitoring, resource management, etc. The data transmission demand of these areas usually needs to be supported by satellite communication.
[0119] However, in some satellite communication application scenarios, the satellite can not be able to communicate with the terminal device and the ground station at the same time. For example, Figure 1 As shown in FIG. 1, at T1, the satellite can communicate with the terminal device but cannot communicate with the ground station, and as the satellite moves, at T2, the satellite cannot communicate with the terminal device but can communicate with the ground station.
[0120] In a scenario where the satellite cannot communicate with the terminal device and the ground station at the same time, if the terminal device expects to communicate with the ground station through the satellite, the satellite needs to store the information from the terminal device after receiving the information, and then forward the information to the ground station when the satellite runs to a position that can be connected to the ground station. Alternatively, the satellite stores the information from the ground station after receiving the information, and then forwards the information to the terminal device when the satellite runs to a position that can be connected to the terminal device. This service provided by the satellite can be referred to as store-and-forward service.
[0121] In a satellite communication scenario, due to the wide coverage of the satellite, at some moments, the coverage of the satellite may span across regions, causing some coverage not to be within the service range of the satellite. Therefore, in general, for a terminal device that needs to be served by the satellite, the position of the terminal device needs to be checked, that is, it needs to be checked whether the position of the terminal device is within the service range of the satellite, and only in the case that the position check of the terminal device is passed (the position of the terminal device is within the service range of the satellite), the terminal device can be served. Since the related information (such as the current position information of the terminal device) in the terminal device position checking process involves user privacy, the related information in the terminal device position checking process needs to be protected. In a possible implementation manner, the terminal device can send a coarse-grained position to the satellite through a security mode command (NAS SMC) message. In another possible implementation manner, the satellite can check the fine-grained position of the terminal device through a long term evolution (LTE) positioning protocol (LPP) procedure, but essentially, the two manners are both implemented by delivering related NAS messages, and are protected based on NAS security context.
[0122] Further, there are two possible architectures for the store-and-forward service. Architecture one: all network elements of the radio access network (RAN) and the LTE core network, including MME, HSS, etc., are borne on the satellite. Architecture two (MME-split architecture): the base station and part of the MME function (MME-NT) are borne on the satellite, and the MME-T and other core network network elements are deployed on the ground network, and there is a connection between the MME-NT and the MME-T. In the embodiments of the present application, the MME-NT can also be referred to as MME-onboard, and the MME-T can also be referred to as MME-ground.
[0123] For architecture one, each satellite has a full core network, and in this architecture, when the terminal device obtains coverage from a new satellite, the UE and the MME on the new satellite can transmit messages through non-access stratum (NAS) protocols, and after the UE completes primary authentication, the UE and the MME on the new satellite can establish a NAS security context, which can include a security key (encryption key and / or integrity key), which can be used for confidentiality and / or integrity protection of NAS messages between the UE and the MME. For the MME-split architecture, the MME is divided into MME-NT and MME-T, and the HSS is located in the ground network, so the location of the NAS security context and the impact on the system need to be reconsidered for this architecture to ensure NAS security in the store-and-forward service.
[0124] II. NAS security establishment process in a ground scenario
[0125] The following exemplary describes the process of establishing NAS security between the terminal device and the MME in a ground scenario, that is, a scenario in which the terminal device accesses the network through a ground base station. In the embodiments of the present application, establishing NAS security can also be referred to as establishing a NAS security context, establishing a secure NAS connection, establishing a secure context, etc., which are not limited in the embodiments of the present application.
[0126] Please refer to Figure 2 , Figure 2 is a flowchart of a process of establishing NAS security in a ground scenario disclosed by the embodiments of the present application. As Figure 2 shown, the process can include but is not limited to the following steps:
[0127] 201. The UE sends a registration request to the MME.
[0128] When the UE needs to register to the network, it can send a registration request to the MME.
[0129] 202. The MME sends an authentication data request to the HSS.
[0130] After the MME receives the registration request from the UE, the MME can send an authentication data request to the HSS of the UE, the authentication data request can include a UE identity, a network type, etc. The UE identity can be an international mobile subscriber identity (IMSI), a globally unique temporary identity (GUTI), etc. The authentication data request can be used to obtain an authentication vector and a derived key.
[0131] 203. The HSS sends an authentication data response to the MME.
[0132] After the HSS receives the authentication data request from the MME, the HSS can obtain the authentication data related to the UE based on the UE identity carried in the authentication data request, and can send an authentication data response to the MME, the authentication data response can include the authentication data related to the UE, the authentication data related to the UE can include a random number RAND, an authentication vector AUTN, a verification parameter XRES, and a derived key K_ASME. In an example, the request in the embodiment of the present application can also be referred to as a request message, and the response can also be referred to as a response message.
[0133] 204. The MME stores the K_ASME and the eKSI.
[0134] After the MME receives the authentication data response from the HSS, the MME can store the derived key K_ASME, and can generate a corresponding key set identifier eKSI, and store the key set identifier eKSI. The MME can also store the verification parameter XRES, etc.
[0135] 205. The MME sends a user authentication request to the UE.
[0136] The user authentication request can include a random number RAND, an authentication vector AUTN, and a key indicator eKSI.
[0137] 206. The UE sends a user authentication response to the MME.
[0138] After the UE receives the user authentication request from the MME, the UE can verify the authentication vector AUTN, and can generate a response value RES based on the random number RAND and the long-term key K, and then can send a user authentication response to the MME, the user authentication response can include the response value RES.
[0139] 207. The UE generates K_ASME.
[0140] The UE can generate a derived key K_ASME and associate K_ASME with eKSI.
[0141] 208. The MME generates K_NASenc and K_NASint based on K_ASME.
[0142] The MME can generate NAS security keys K_NASenc and K_NASint based on K_ASME, K_NASenc can be an encryption key and can be used for ciphering protection / confidentiality protection, and K_NASint can be an integrity key and can be used for integrity protection.
[0143] The MME can also synchronize uplink NAS COUNT corresponding to an uplink NAS message and downlink NAS COUNT corresponding to a downlink NAS message.
[0144] 209. The MME sends a NAS security mode command message to the UE.
[0145] After the MME generates K_NASenc and K_NASint, the MME can send a NAS security mode command message to the UE, the NAS security mode command message can activate integrity protection, and the NAS security mode command message can include a key indicator eKSI, UE security capabilities, an encryption algorithm, and an integrity algorithm.
[0146] 210. The UE generates K_NASenc and K_NASint based on K_ASME.
[0147] After the UE receives the NAS security mode command message from the MME, the UE can generate a NAS security context according to information in the message, including NAS security keys K_NASenc and K_NASint.
[0148] The MME can also synchronize the uplink NAS COUNT corresponding to the uplink NAS message and the downlink NAS COUNT corresponding to the downlink NAS message. It should be understood that the NAS COUNT can be used for encryption protection together with K_NASenc, or for integrity protection together with K_NASint, that is, the NAS COUNT can be used as an input of the encryption algorithm together with K_NASenc, or as an input of the integrity protection algorithm together with K_NASint. Moreover, the corresponding NAS COUNT should be increased by 1 each time the sender sends the "NAS message protected by security". In addition, both parties (such as the UE and the MME) including the corresponding NAS security context or NAS key can carry the relevant information of the NAS COUNT in the "NAS message protected by security". For more detailed description of the NAS COUNT, reference can be made to the relevant description in the standard, which will not be described here. The NAS COUNT can also be referred to as a NAS counter.
[0149] For example, the derivation parameters of K_NASenc\K_NASint can include K_ASME, FC, P0, L0, P1, L1, wherein FC is a constant value, P0 identifies that the derived key belongs to K_NASint\K_NASenc, etc., L0 represents the length of P0, P1 represents the identifier of the encryption or integrity protection algorithm, and L1 represents the length of P1. For more detailed description of the derivation parameters of K_NASenc\K_NASint, reference can be made to the relevant description in the standard.
[0150] 211. The UE sends a NAS security mode complete message (NASsecuritymodecomplete) to the MME.
[0151] After the UE generates K_NASenc and K_NASint and the integrity check of the NAS security mode command message is passed, the UE can send a NAS security mode complete message to the MME. The NAS security mode complete message can activate the integrity and confidentiality protection, that is, the confidentiality and integrity protection can be performed based on K_NASenc and K_NASint.
[0152] It should be understood that one key identifier, that is, a key set identifier (KSI), can be included in one NAS security context, such as the eKSI included in the NAS security context between the UE and the MME described above. The KSI can identify a set of NAS security parameters, such as K_ASME, K_NASenc, K_NASint, and the corresponding uplink\downlink NAS COUNT, etc.
[0153] To better understand the embodiments of this application, the system architecture of the embodiments of this application will be described below.
[0154] Please see Figure 3 , Figure 3 This is a schematic diagram of a system architecture disclosed in an embodiment of this application. For example... Figure 3 As shown, each satellite in this architecture can include an MME-NT and a RAN, as illustrated by satellites 1 and 2 in the example. The terrestrial network can include MME-T and core network elements such as HSS. The MME-NT on the satellite and the MME-T on the terrestrial network can have an interface (as shown by the dotted line in the figure). When the terrestrial station is within the satellite's coverage area, the MME-NT on the satellite can communicate with the MME-T through the terrestrial station. When the terminal device is within the satellite's coverage area, the MME-NT on the satellite can also communicate with the terminal device.
[0155] It should be understood that Figure 3 In the example, satellite 1 can communicate with the terminal device but not with the ground station. However, as satellite 1 moves, the terminal device may be outside its coverage area, while the ground station remains within its coverage. In this case, satellite 1 cannot communicate with the terminal device but can communicate with the ground station. Satellite 1's MME-NT can also communicate with the MME-T or terrestrial network through the ground station. Similarly, Figure 3 In the example, satellite 2 can communicate with the ground station but not with the terminal device. However, as satellite 2 moves, the ground station may be outside the coverage area of satellite 2, but the terminal device may be within the coverage area of satellite 2. In this case, satellite 2 cannot communicate with the ground station but can communicate with the terminal device.
[0156] The following section introduces the terminal devices and various network entities.
[0157] A terminal device, which can also be referred to as a user equipment (UE), a terminal, a mobile station (MS), a mobile terminal (MT), a customer premise equipment (CPE), etc., is a device with wireless communication function, which can provide voice and / or data connectivity to users. A terminal device can be a handheld device having more than one function, e.g., at least one of voice or data connectivity, a notebook with or without a keyboard, an RSU (road side unit), a subscriber unit, a cellular phone, a smart phone, a wireless data card, a PDA (personal digital assistant) computer, a tablet computer, a label, a wireless modem, another processing device connected to a wireless modem, a handheld device, a laptop computer, a cordless phone, or a WLL (wireless local loop) station, an MTC (machine type communication) terminal, a wearable device (e.g., a smart watch, a smart bracelet, a pedometer, etc.), a vehicle-mounted device (e.g., a car, a bicycle, an electric vehicle, an airplane, a ship, a train, a high-speed rail, etc.), a VR (virtual reality) device, an AR (augmented reality) device, a wireless terminal in industrial control, a smart home device (e.g., a refrigerator, a television, an air conditioner, an electricity meter, etc.), a smart robot, a plant device, a wireless terminal in self driving, a wireless terminal in remote medical surgery, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, or a wireless terminal in a smart home, a flight device (e.g., a smart robot, a hot air balloon, a drone, an airplane, etc.), or other devices that can access a network. A terminal device can be fixed or mobile, and can be deployed on land, including indoors or outdoors, handheld, wearable, or vehicle-mounted; can be deployed on water (e.g., a ship, etc.); or can be deployed in air (e.g., an airplane, a balloon, and a satellite, etc.). In embodiments of the present application, a UE can transmit a sensing signal, and can also receive a sensing signal.For example, the UE can receive a sensing request from the sensing function network element, and then send and / or receive a sensing signal based on the sensing request to obtain relevant sensing data.
[0158] The RAN can be a radio access network function or a radio access network device, which can be used to implement radio physical layer functions, resource scheduling, radio resource management, radio access control, etc. The RAN can provide access for terminal devices. Exemplarily, the radio access network device can include various forms of base stations.
[0159] The MME-T and / or the MME-NT can be responsible for authentication of the UE, UE mobility management, etc.
[0160] The public data network (PDN) gateway (PGW) can serve as a connection point to provide transmission between the UE and the PDN. One UE can access multiple PDNs through multiple PGWs at the same time. The PGW can implement implementation of control policies, packet filtering for users, charging and packet screening. Another key role of the PGW is to serve as a mobility management anchor point between 3GPP and non-3GPP networks (such as WiMAX and 3GPP2 CDMA 1X and EvDO).
[0161] The PCRF can provide configuration policy information to provide policy information for controlling the UE for the control plane network element (such as the MME, the PGW) of the network, such as the PCC policy.
[0162] The home subscriber server (HSS) can be used to store the subscription information of the user, and provide the subscription information of the terminal device to other network elements, etc.
[0163] The serving gateway (SGW) has functions of local mobility anchor point for inter-access network device (such as eNodeB) switching, mobility anchor for inter-3GPP mobility, packet routing and forwarding, transmission level packet marking, inter-operator charging, etc.
[0164] The service capability exposure function (SCEF) is responsible for the functions of mobile exposure of the telecommunications network, facing the third-party service platform, supporting access control, interface encapsulation, routing conversion, etc.
[0165] The data network (DN) network element is used to provide a network for transmitting data.
[0166] It should be understood that Figure 3 is only a schematic diagram,Figure 3 More or fewer devices, network elements, etc. can also be included in the illustrated architecture, without limitation.
[0167] It should also be understood that the above network elements or functions can be implemented in hardware, computer software or a combination of hardware and computer software. For example, the above network elements or functions can be implemented by one device, or by multiple devices together, or by a functional module within one device, and the embodiments of the present application do not make specific limitations in this regard. In addition, the above "network element" can also be referred to as an entity, a functional entity, a device or a module, and the present application does not make specific limitations in this regard.
[0168] It should be understood that although the above illustrates the architecture of the LTE core network, and the MME of the LTE core network is split, it should be understood that the technical solutions provided by the embodiments of the present application can also be applied to the fifth generation (5th generation, 5G) communication system, the transition system between the 5G communication system and the future communication system, the network of multiple system integration, and the future communication system. When applied in other communication networks, the corresponding device / network element name can also be replaced by the name of the corresponding function / device in other communication networks. For example, when applied in the fifth generation communication network, the MME can be replaced by the access and mobility management function (access and mobility management function, AMF), and accordingly, the MME-NT on the satellite can be replaced by the AMF-NT, the MME-T in the ground network can be replaced by the AMF-T, and the HSS, PCRF, etc. in the ground network can also be replaced by the name of the corresponding function / device in the 5G network.
[0169] It should be noted that the system architecture, network architecture and business scenarios (or application scenarios) described in the embodiments of the present application are for more clearly illustrating the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art can know that, as the communication network architecture evolves and new business scenarios appear, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems.
[0170] As can be known from the above description, in the MME-split architecture, the setting of the NAS security context needs to be reconsidered to ensure the NAS security in the store-and-forward service. Since the same NAS security key is shared by multiple entities, it is easy to cause security problems such as key leakage and replay attack, and therefore, when considering the setting of the NAS security context, it is also necessary to avoid the same NAS security key being shared by multiple entities. In the embodiments of the present application, in order to solve the above problems, two possible technical solutions are proposed.
[0171] In the first technical solution, the ground network (such as MME-T, HSS, etc.) can establish an independent NAS security context between the MME-NT of the satellite and the terminal device. In the case that the MME-NT of the satellite and the terminal device include an independent NAS security context, the MME-NT of the satellite and the terminal device can perform security protection on the NAS message based on the NAS security context. For example, the MME-NT of the satellite can perform a location verification process of the terminal device based on the NAS security context between the MME-NT of the satellite and the terminal device. In this case, the MME-NT of the satellite can verify the location of the terminal device. If the location verification of the terminal device is passed, the MME-NT of the satellite can provide a store-and-forward service for the terminal device. The MME-NT of the satellite can support the store-and-forward of the uplink data of the terminal device to the MME-T, and can also support the store-and-forward of the downlink data of the MME-T to the terminal device. In addition, the NAS security key between the terminal device and the satellite can be generated based on satellite-related information. Different satellite-related information can be different. In this way, the NAS security key between the terminal device and different satellites can be different, so that the same NAS security key can be avoided by multiple entities, and the security can be improved.
[0172] In the second technical solution, the NAS security context can be established between the MME-T and the terminal device. When the terminal device needs to send uplink data to the MME-T, the terminal device can perform NAS security protection on the uplink data based on the NAS security key between the terminal device and the MME-T, and the terminal device can perform NAS security protection on the location information of the terminal device based on the NAS security key between the terminal device and the MME-T. After the MME-NT of the satellite receives the NAS security protected uplink data and the location information of the terminal device from the terminal device, the MME-NT can send the NAS security protected uplink data and the location information of the terminal device to the MME-T when the MME-NT can communicate with the ground network. After the MME-T receives the NAS security protected uplink data and the location information of the terminal device, the MME-T can perform NAS security processing (such as integrity verification and decryption) on the NAS security protected location information of the terminal device based on the NAS security key between the terminal device and the MME-T, and can obtain the location information of the terminal device. Then, the MME-T can perform location verification on the terminal device based on the location information of the terminal device. If the location verification of the terminal device is passed, the MME-T can process the uplink data, such as collecting service data in the uplink data and forwarding the service data to a corresponding application function (AF). It can be seen that in the above manner, the terminal device and the MME-NT of the satellite can not establish an independent NAS security context, and the NAS security in the store-and-forward service can be ensured based on the NAS security context established between the MME-T and the terminal device, and the store-and-forward of the uplink data of the terminal device to the MME-T can be supported. In this case, the MME-NT of the satellite and the terminal device do not need to establish an NAS security context, and the same NAS security key can be shared by multiple entities.
[0173] First, the overall flow of the first technical solution provided by the embodiments of the present application will be exemplarily described.
[0174] Please refer to Figure 4 , Figure 4 The flowchart of the communication method disclosed by the embodiments of the present application is shown. Figure 4 In the first network element, the first network element can send the first key to the second network element of the satellite (the first satellite) to be accessed by the terminal device, so that when the terminal device and the first satellite can communicate, the second network element of the first satellite can help the terminal device to establish the NAS security context between the second network element of the first satellite and the terminal device. The first network element can be a MME-T deployed on the ground, and the second network element can be a MME-NT. Alternatively, in the architecture of the 5G core network, the first network element can be an AMF-T, and the second network element can be an AMF-NT. For example, as shown in Figure 4 The method can include but is not limited to the following steps:
[0175] 401. The first network element obtains first information associated with a first satellite, the first satellite being a satellite to be accessed by the terminal device, the first information associated with different satellites being different.
[0176] To ensure the NAS security in the store-and-forward service, the first network element can determine the satellite to be accessed by the terminal device, i.e., the first satellite. Illustratively, the first network element can determine the satellite to be accessed by the terminal device based on the ephemeris trajectory and the access policy of the terminal device. In some possible implementation manners, the first satellite can be the satellite to be accessed by the terminal device next time.
[0177] After the first network element determines the first satellite, the first network element can obtain the first information associated with the first satellite, the first information associated with different satellites being different. Illustratively, the first information can be an identifier (ID) of an MME-NT on the satellite, or can be an identifier of the satellite, or can be other information associated with the satellite. Correspondingly, the first information associated with the first satellite can be an identifier of an MME-NT on the first satellite (denoted as MME-NT ID), or can be an identifier of the first satellite, or can be other information associated with the first satellite, such as a temporary sequence number generated by the first satellite, a temporary sequence number generated by the ground for the first satellite, and the like.
[0178] 402. The first network element obtains a first key based on the first information associated with the first satellite, the first key being used for NAS security protection between the second network element and the terminal device, the second network element being deployed on the first satellite.
[0179] After the first network element obtains the first information associated with the first satellite, the first network element can obtain the first key based on the first information associated with the first satellite. The first key can be generated based on the first information associated with the first satellite, and the first key can be used for NAS security protection between the second network element and the terminal device. Illustratively, the first key can be a key shared between the terminal device and the second network element.
[0180] In the embodiments of the present application, the first key can be a NAS security key between the second network element and the terminal device, or can be an intermediate key (hereinafter referred to as a second intermediate key) used for generating the NAS security key between the second network element and the terminal device. The intermediate key can also be referred to as a derived key. The NAS security key can include an integrity key and / or an encryption key, that is, the first key can be an integrity key (hereinafter denoted as K_SAT_NASint) and / or an encryption key (hereinafter denoted as K_SAT_NASenc) between the second network element and the terminal device, the integrity key between the second network element and the terminal device can be used for integrity protection between the second network element and the terminal device, and the encryption key between the second network element and the terminal device can be used for confidentiality protection between the second network element and the terminal device.
[0181] The first network element can obtain the first key based on the first information associated with the first satellite in various ways, and two examples are provided below.
[0182] Method 1: The first network element generates the first key based on the first information associated with the first satellite.
[0183] For example, the first network element can generate a first key based on the first information associated with the first satellite and other relevant information.
[0184] For example, the first network element can generate a first key based on the first information associated with the first satellite and a first intermediate key. The first intermediate key can be an intermediate key used to generate a second key, which can be used for NAS security protection between the first network element and the terminal device. The second key can be a NAS security key between the first network element and the terminal device, including an integrity key (hereinafter referred to as K_NASint) and / or an encryption key (hereinafter referred to as K_NASenc) between the first network element and the terminal device. It should be understood that the terminal device can initiate registration with the first network element via satellite to register with the terrestrial network. During the registration process, the terminal device and the first network element can generate a first intermediate key (hereinafter referred to as K_ASME), which can be a key shared between the terminal device and the first network element. It should be noted that the process of the terminal device registering with the terrestrial network via satellite is similar to the above. Figure 2 The process shown is similar and can be referred to above. Figure 2 The process shown in this application is not limited to the specific steps described in the embodiments.
[0185] When the first key is the NAS security key between the second network element and the terminal device, the derivation algorithm for the first key generated by the first network element based on the first information associated with the first satellite and the first intermediate key can be as follows:
[0186] K_SAT_NASenc\K_SAT_NASint = KDF(First intermediate key, first information associated with the first satellite, FC||P0||L0||P1||L1)
[0187] Wherein, KDF is the key derivation function, FC is a constant value, P0 indicates that the derived key belongs to K_NASint, K_NASenc, etc., L0 represents the length of P0, P1 can be an identifier of encryption algorithm or integrity protection algorithm (abbreviated as integrity protection algorithm), and L1 represents the length of P1.
[0188] In the case that the first key is a second intermediate key (which can be denoted as K SAT below), the derivation algorithm for the first key generated by the first network element based on the first information associated with the first satellite and the first intermediate key can be as follows:
[0189] K SAT = KDF (the first intermediate key, the first information associated with the first satellite)
[0190] For another example, the first network element can generate a second intermediate key based on the first information associated with the first satellite, and then generate the first key based on the second intermediate key.
[0191] In the case that the first key is a NAS security key between the second network element and the terminal device, the derivation algorithm for the first key generated by the first network element based on the second intermediate key can be as follows:
[0192] K SAT NASenc\K SAT NASint = KDF (K SAT, FC||P0||L0||P1||L1)
[0193] In the above example, the first network element can use the first information associated with the first satellite as a parameter, and the first intermediate key and the like as a key to generate K SAT, K SAT NASenc, K SAT NASint and the like. It can be understood that the first network element can also consider more parameters when generating the first key, such as one or more of the uplink NAS COUNT between the terminal device and the MME-T, the downlink NAS COUNT between the terminal device and the MME-T, the uplink NAS COUNT between the terminal device and the satellite, and the downlink NAS COUNT between the terminal device and the satellite. In the embodiments of the present application, the terminal device and different satellites can maintain unified uplink NAS COUNT and downlink NAS COUNT.
[0194] In the second way, the first network element sends the first information associated with the first satellite to the third network element, and requests the third network element to generate the first key based on the first information associated with the first satellite. In some possible implementation manners, the third network element can be an HSS.
[0195] Exemplarily, the first network element can send a key request to the third network element, the key request can comprise the first information associated with the first satellite. After receiving the key request from the first network element, the third network element can generate the first key based on the first information associated with the first satellite in the key request, and then can send a key request response to the first network element, the key request response can comprise the first key. Wherein, the generation manner of the first key can refer to the manner that the first network element generates the first key based on the first information associated with the first satellite. In addition, since the third network element can obtain the upper-layer key corresponding to the first intermediate key and other related information such as an integrity key (IK), a cipher key (CK), a sequence number (SQN), an anonymity key (AK), etc., therefore, the first network element can generate the first key more flexibly.
[0196] In the case that the first key is the second intermediate key, the derivation algorithm that the third network element generates the first key based on the first information associated with the first satellite can be as follows:
[0197] Derivation algorithm 1: K_SAT = KDF (CK, IK, MME-NT ID, SQN, AK)
[0198] Derivation algorithm 2: K_SAT = KDF (K_ASME, MME-NT ID, SQN, AK)
[0199] In some possible implementation manners, the first key generated by the third network element can also be the NAS security key between the second network element and the terminal device, and the embodiments of the present application do not limit this.
[0200] It should be understood that in the case that the first key is generated by using the first intermediate key, the first network element can send a first key set identifier to the second network element of the first satellite, correspondingly, the second network element of the first satellite can receive the first key set identifier from the first network element, and subsequently the second network element of the first satellite can send the first key set identifier to the terminal device, so as to facilitate the terminal device to determine the first intermediate key based on the first key set identifier, thereby facilitating the terminal device to generate the first key based on the first information associated with the first satellite, the first intermediate key, etc. Wherein, the first key set identifier is used to identify the first intermediate key.
[0201] 403. The first network element sends the identifier of the terminal device and the first key to the second network element.
[0202] After the first network element obtains the first key based on the first information associated with the first satellite, the first network element can send the identity of the terminal device and the first key to the second network element of the first satellite. Correspondingly, the second network element can receive the identity of the terminal device and the first key from the first network element. Exemplarily, the identity of the terminal device can be IMSI, GUTI, or other information that can be used to identify the terminal device. It should be understood that the identity of the terminal device is mainly used to indicate that the first key is the key corresponding to the terminal device. For example, assuming that the first network element obtains the key 1 corresponding to UE1 and the key 2 corresponding to UE2 based on the first information associated with the first satellite, in this case, when the first network element sends the key 1 to the second network element, the identity of UE1 corresponding to the key 1 can also be sent to indicate that the key 1 is the key corresponding to UE1 for the second network element. Similarly, when the first network element sends the key 2 to the second network element, the identity of UE1 corresponding to the key 2 can also be sent to indicate that the key 2 is the key corresponding to UE2 for the second network element.
[0203] In some possible implementation manners, the first network element can also allocate a second key set identifier for the terminal device and the second network element, the second key set identifier can be used to identify the second intermediate key and / or the NAS security key between the second network element and the terminal device, and can also be used to identify the uplink NAS COUNT and the downlink NAS COUNT corresponding to the NAS security key between the second network element and the terminal device, etc. When the first network element sends the identity of the terminal device and the first key to the second network element, the second network element can also be sent the second key set identifier to indicate the corresponding relationship between the identity of the terminal device, the first key, and the second key set identifier.
[0204] In some possible implementation manners, the first network element can also allocate a second key set identifier for the terminal device and the second network element, the second key set identifier can be used to identify the second intermediate key and / or the NAS security key between the second network element and the terminal device, and can also be used to identify the uplink NAS COUNT and the downlink NAS COUNT corresponding to the NAS security key between the second network element and the terminal device, etc. When the first network element sends the identity of the terminal device and the first key to the second network element, the second network element can also be sent the second key set identifier to indicate the corresponding relationship between the identity of the terminal device, the first key, and the second key set identifier.
[0205] In some possible implementation, in the case that the uniform uplink NAS COUNT and downlink NAS COUNT are maintained between the terminal device and different satellites, the first network element can further send the uplink NAS COUNT and downlink NAS COUNT between the terminal device and the satellite to the second network element when sending the identity of the terminal device and the first key to the second network element, so as to indicate the corresponding relationship between the identity of the terminal device, the first key, and the uplink NAS COUNT and downlink NAS COUNT. For example, the uplink NAS COUNT and downlink NAS COUNT between the terminal device and the satellite sent by the first network element to the second network element can be the uplink NAS COUNT and downlink NAS COUNT received from the satellite on which the terminal device accesses / service last time. It should be understood that, in the case that the uniform uplink NAS COUNT and downlink NAS COUNT are maintained between the terminal device and different satellites, the uplink NAS COUNT and downlink NAS COUNT between the terminal device and the satellite sent by the first network element to the second network element can also be understood as the uplink NAS COUNT and downlink NAS COUNT corresponding to the first key. The uplink NAS COUNT and downlink NAS COUNT corresponding to the first key can be used for NAS security protection between the second network element and the terminal device, that is, when confidentiality protection is based on K_SAT_NASenc and integrity protection is based on K_SAT_NASint, the uplink NAS COUNT or downlink NAS COUNT can be used as a parameter of an encryption algorithm or an integrity protection algorithm. For specific implementation of confidentiality protection based on an encryption key (such as K_SAT_NASenc) and the uplink NAS COUNT or downlink NAS COUNT, reference can be made to the description in the related art (such as a related standard), which will not be repeated here. Similarly, for specific implementation of integrity protection based on an integrity key (such as K_SAT_NASint) and the uplink NAS COUNT or downlink NAS COUNT, reference can be made to the description in the related art (such as a related standard), which will not be repeated here.It can be understood that, in the case that the unified uplink NAS COUNT and downlink NAS COUNT are not maintained between the terminal device and different satellites, the uplink NAS COUNT and downlink NAS COUNT corresponding to the first key can be reinitialized between the terminal device and the first satellite.
[0206] In yet some possible implementation, the first network element can need to send a downlink message to the terminal device, in which case, in one possible implementation, the first network element can send the downlink message in plaintext to the second network element, and in another possible implementation, the first network element can perform NAS security protection on the downlink message based on the second key between the terminal device, and can send the downlink message after the NAS security protection to the second network element, that is, the downlink message after the integrity protection based on the integrity key and / or the encryption protection based on the encryption key between the terminal device. For example, taking that the first network element needs to send a first downlink message to the terminal device, in one possible implementation, the first network element can directly send the first downlink message (such as the first downlink message in plaintext) to the second network element, and in another possible implementation, the first network element can perform NAS security protection on the first downlink message based on the second key, and can then send the first downlink message after the NAS security protection and a first key set identifier to the second network element. The first key set identifier can be used to identify the second key, which can be used for the NAS security protection between the first network element and the terminal device, and can be the NAS security key between the first network element and the terminal device. It should be understood that the first downlink message is associated with the corresponding terminal device, and therefore, when the first network element sends the first downlink message to the second network element, or the first network element sends the first downlink message after the NAS security protection and the first key set identifier to the second network element, the identifier of the terminal device can also be sent to indicate the terminal device corresponding to the first downlink message or the first downlink message after the NAS security protection. It can be understood that, in the embodiments of the present application, in one case, the NAS security context can be established between the first network element and the terminal device, in which case, when the first network element and the terminal device are stored and forwarded through the satellite, the uplink message from the terminal device to the first network element can be protected by the NAS security protection based on the second key, and the downlink message (such as the first downlink message) from the first network element to the terminal device can also be protected by the NAS security protection based on the second key, and in another case, the NAS security context can not be established between the first network element and the terminal device, and when the first network element and the terminal device are stored and forwarded through the satellite, the uplink message from the terminal device to the first network element can be protected by the NAS security context between the second network element and the terminal device, and the downlink message from the first network element to the terminal device can also be protected by the NAS security context between the second network element and the terminal device.
[0207] Optionally, one or more of the terminal device identifier, the first key, the second key set identifier, the first key set identifier, the uplink NAS COUNT between the terminal device and the satellite, the downlink NAS COUNT between the terminal device and the satellite, the first downlink message, and the first downlink message after NAS security protection can be carried in the same message (e.g., the first message). For example, the first network element can send the first message to the second network element, and the first message can include the terminal device identifier, the first key, the second key set identifier, the first key set identifier, the uplink NAS COUNT between the terminal device and the satellite, the downlink NAS COUNT between the terminal device and the satellite, and the first downlink message. For another example, the first network element can send the first message to the second network element, and the first message can include the terminal device identifier, the first key, the second key set identifier, the first key set identifier, the uplink NAS COUNT between the terminal device and the satellite, the downlink NAS COUNT between the terminal device and the satellite, and the first downlink message after NAS security protection. It should be understood that in some possible implementations, the first network element can also send the above information to the second network element in multiple times, and the embodiments of the present application do not limit this, but when the above information is sent in multiple times, the association / correspondence relationship between the information needs to be considered. For example, when the first network element sends the uplink NAS COUNT between the terminal device and the satellite or the downlink NAS COUNT between the terminal device and the satellite to the second network element through a separate message, the corresponding terminal device identifier can also be carried in the message.
[0208] In an embodiment of the present application, after receiving the identifier of the terminal device and the first key from the first network element, the second network element can store the identifier of the terminal device and the first key. In the case that the first key is the second intermediate key, the second network element can further generate K_SAT_NASenc and / or K_SAT_NASint based on the second intermediate key. For example, in the case that the second network element further receives the second key set identifier from the first network element, the second network element can associate the second key set identifier with K_SAT_NASenc and / or K_SAT_NASint. In the case that the second network element does not receive the second key set identifier from the first network element, the second network element can assign a second key set identifier and can associate the second key set identifier with K_SAT_NASenc and / or K_SAT_NASint. For another example, in the case that the second network element further receives the uplink NAS COUNT between the terminal device and the satellite and the downlink NAS COUNT between the terminal device and the satellite from the first network element, the second network element can associate the second key set identifier with the uplink NAS COUNT between the terminal device and the satellite and the downlink NAS COUNT between the terminal device and the satellite.
[0209] It should be understood that the NAS security context stored by the second network element for the terminal device can include one or more of the second key set identifier, K_SAT, K_SAT_NASenc, K_SAT_NASint, the uplink NAS COUNT corresponding to the first key, the downlink NAS COUNT corresponding to the first key, and the like. It should be noted that in an embodiment of the present application, the NAS security protection between the second network element and the terminal device can include integrity protection and / or confidentiality protection.
[0210] 404. The terminal device acquires the first information associated with the first satellite.
[0211] For example, there are various cases for the terminal device to acquire the first information associated with the first satellite, some of which are described below.
[0212] In the first case, the first satellite can broadcast the first information associated with the first satellite, such as periodically broadcasting the first information associated with the first satellite. In this case, the terminal device within the coverage of the first satellite can receive the first information associated with the first satellite.
[0213] In case two, the second network element can trigger to send (e.g., broadcast) the second key set identifier and the first information associated with the first satellite after receiving the identifier of the terminal device and the first key from the first network element, and can also send the identifier of the terminal device, so that the terminal device corresponding to the identifier of the terminal device generates the first key based on the first information associated with the first satellite, and can associate the first key with the second key set identifier.
[0214] In case three, the second network element of the first satellite can carry the first information associated with the first satellite in a paging message. For example, the second network element can trigger to send a paging message after receiving the identifier of the terminal device and the first key from the first network element, and the paging message can include the identifier of the terminal device and the first information associated with the first satellite. The paging message can also include the second key set identifier, etc., which is not limited in the embodiments of the present application.
[0215] In case four, the second network element of the first satellite can send the first information associated with the first satellite to the terminal device after receiving the service request sent by the terminal device. For example, when the terminal device needs the service provided by the second network element of the first satellite, the terminal device can send a service request to the second network element of the first satellite, and the second network element of the first satellite can send the first information associated with the first satellite to the terminal device after receiving the service request sent by the terminal device.
[0216] 405. The terminal device generates the first key based on the first information associated with the first satellite.
[0217] After the terminal device obtains the first information associated with the first satellite, the terminal device can generate the first key based on the first information associated with the first satellite.
[0218] The terminal device generates the first key based on the first information associated with the first satellite in the same way as the first network element or the third network element generates the first key based on the first information associated with the first satellite, and details can be referred to the above description. The following is a simple example.
[0219] For example, the terminal device can generate the first key based on the first information associated with the first satellite and the first intermediate key. The first intermediate key can also be used to generate the second key, and the second key can be used for NAS security protection between the first network element and the terminal device. In some possible implementation, the terminal device can first receive the first key set identifier from the second network element before generating the first key based on the first information associated with the first satellite and the first intermediate key, and then determine the first intermediate key based on the first key set identifier, and then generate the first key based on the first information associated with the first satellite and the first intermediate key.
[0220] For another example, the terminal device can generate the second intermediate key based on the first information associated with the first satellite, and then can generate the first key based on the second intermediate key.
[0221] It should be understood that, in the case that the first key is the second intermediate key, the terminal device can generate the NAS security key between the terminal device and the second network element based on the second intermediate key, i.e., K_SAT_NASenc and / or K_SAT_NASint.
[0222] It can be understood that the NAS security context stored by the terminal device and associated with the second network element can include one or more of the following: the second key set identifier, K_SAT, K_SAT_NASenc, K_SAT_NASint, the uplink NAS COUNT corresponding to the first key, and the downlink NAS COUNT corresponding to the first key. The second key set identifier can be received from the second network element. The uplink NAS COUNT corresponding to the first key and the downlink NAS COUNT corresponding to the first key can be the uplink NAS COUNT and the downlink NAS COUNT between the terminal device and the satellite last accessed / served by the terminal device.
[0223] 406. The terminal device and the second network element perform NAS security protection between the second network element and the terminal device based on the first key.
[0224] In the embodiments of the present application, after the terminal device and the second network element obtain the first key, the terminal device and the second network element can perform NAS security protection between the second network element and the terminal device based on the first key. For example, in the case that the first key is the NAS security key (K_SAT_NASenc and / or K_SAT_NASint) between the terminal device and the second network element, the terminal device and the second network element can directly perform NAS security protection between the second network element and the terminal device based on the first key. In the case that the first key is the second intermediate key, the terminal device and the second network element perform NAS security protection between the second network element and the terminal device based on the first key, which can be understood as that the terminal device and the second network element perform NAS security protection between the second network element and the terminal device based on the K_SAT_NASenc and / or K_SAT_NASint generated based on the first key. Further, the NAS security protection between the second network element and the terminal device can include NAS security protection of the downlink (NAS) message from the second network element to the terminal device, and NAS security protection of the uplink (NAS) message from the terminal device to the second network element.
[0225] The following exemplary describes the NAS security protection between the terminal device and the second network element. Since there are two cases of establishing the NAS security context and not establishing the NAS security context between the first network element and the terminal device, the following can be described for the two cases respectively.
[0226] In the first case, the NAS security context is not established between the first network element and the terminal device. In this case, for a downlink message from the first network element to the terminal device, taking a first downlink message as an example, after receiving the first downlink message from the first network element, the second network element can perform NAS security protection on the first downlink message based on the first key, that is, perform NAS security protection on the first downlink message based on K_SAT_NASenc and / or K_SAT_NASint, and then send the first downlink message after NAS security protection and the second key set identifier to the terminal device. Correspondingly, the terminal device can receive the first downlink message after NAS security protection and the second key set identifier from the second network element, then determine the first key based on the second key set identifier, and then perform NAS security processing on the first downlink message after NAS security protection based on the first key to obtain the first downlink message. It should be understood that in the case where the first key is the second intermediate key, determining the first key based on the second key set identifier can be determining K_SAT_NASenc and / or K_SAT_NASint based on the second key set identifier, and correspondingly, performing NAS security processing on the first downlink message after NAS security protection based on the first key can be performing NAS security processing based on K_SAT_NASenc and / or K_SAT_NASint. Wherein, performing NAS security processing based on K_SAT_NASenc and / or K_SAT_NASint can include integrity verification and / or decryption. In this case, it is uniformly stated that in the embodiments of the present application, performing NAS security protection on a message (uplink message or downlink message) based on the first key can be understood as performing NAS security processing on the message based on K_SAT_NASenc and / or K_SAT_NASint to generate a corresponding integrity verification code and / or encryption, and performing NAS security processing on the message (uplink message or downlink message) after NAS security protection based on the first key can be understood as performing integrity verification and / or decryption on the message based on K_SAT_NASenc and / or K_SAT_NASint. Similarly, performing NAS security protection on a message (uplink message or downlink message) based on the second key can be understood as performing NAS security processing on the message based on K_NASenc and / or K_NASint to generate a corresponding integrity verification code and / or encryption, and performing NAS security processing on the message (uplink message or downlink message) after NAS security protection based on the second key can be understood as performing integrity verification and / or decryption on the message based on K_NASenc and / or K_NASint.
[0227] For an uplink message from the terminal device to the first network element, taking the first uplink message as an example, the terminal device can perform NAS security protection on the first uplink message based on the first key, and then can send the second key set identifier and the NAS security protected first uplink message to the second network element. Correspondingly, the second network element can receive the second key set identifier and the NAS security protected first uplink message from the terminal device, and then can determine the first key based on the second key set identifier, and then can perform NAS security processing on the NAS security protected first uplink message based on the first key to obtain the first uplink message, and then can send the identifier of the terminal device and the first uplink message to the first network element. Correspondingly, the first network element can receive the identifier of the terminal device and the first uplink message from the second network element, and then can perform relevant processing based on the first uplink message, such as forwarding the first uplink message to the corresponding data network.
[0228] In some possible implementation manners, the terminal device can send the second key set identifier and the NAS security protected first uplink message to the second network element again after determining that the self-location check passes. Alternatively, the terminal device can perform NAS security protection on the first uplink message based on the first key again after determining that the self-location check passes, and send the second key set identifier and the NAS security protected first uplink message to the second network element. For example, the terminal device can determine that the self-location check passes based on the NAS security protected first downlink message and the second key set identifier from the second network element. For another example, the second network element can send first indication information to the terminal device in the case that the location check of the terminal device passes, and the first indication information can be used to indicate that the location check of the terminal device passes, and correspondingly, the terminal device can determine that the self-location check passes based on the first indication information. It can be seen that the terminal device performs relevant processing (such as performing NAS security protection, sending relevant information to the second network element, etc.) again after determining that the self-location check passes, which can avoid unnecessary processing and / or unnecessary information sending, thereby saving processing resources, transmission resources, etc., and also reducing the power consumption of the terminal device.
[0229] Further, in the embodiments of the present application, the terminal device and the second network element can perform NAS security protection between the second network element and the terminal device based on the first key only in the case that the location check of the terminal device passes. That is, the terminal device and the second network element can send the NAS security protected first uplink message and the NAS security protected first downlink message only in the case that the location check of the terminal device passes.
[0230] In the second case, the NAS security context is established between the first network element and the terminal device. In this case, for the NAS-protected downlink message from the first network element to the terminal device, taking the first NAS-protected downlink message as an example, after the second network element receives the first NAS-protected downlink message and the first key set identifier from the first network element, and the location check of the terminal device is passed, the second network element can send the first NAS-protected downlink message and the first key set identifier to the terminal device. Correspondingly, the terminal device can receive the first NAS-protected downlink message and the first key set identifier from the second network element, and then determine the second key based on the first key set identifier, and then perform NAS security processing on the first NAS-protected downlink message based on the second key to obtain the first downlink message. The first NAS-protected downlink message is protected by the second key, and the first key set identifier is used to identify the second key.
[0231] For the NAS-protected uplink message from the terminal device to the first network element, taking the first NAS-protected uplink message as an example, the terminal device can perform NAS protection on the first uplink message based on the second key, and then send the first key set identifier and the first NAS-protected uplink message to the second network element. Correspondingly, the second network element can receive the first key set identifier and the first NAS-protected uplink message from the terminal device, and then send the first key set identifier and the first NAS-protected uplink message to the first network element when the location check of the terminal device is passed. Correspondingly, the first network element can receive the first key set identifier and the first NAS-protected uplink message from the second network element, and then determine the second key based on the first key set identifier, and then perform NAS security processing on the first NAS-protected uplink message based on the second key to obtain the first uplink message. The first NAS-protected uplink message is protected by the second key. In some possible implementation, when the location check of the terminal device is passed, the terminal device can perform NAS protection on the first uplink message based on the second key, and then send the first key set identifier and the first NAS-protected uplink message to the second network element.
[0232] In some possible implementation, the terminal device can send the first key set identifier and the first uplink message protected by NAS security to the second network element after determining that the self-location verification is passed. Alternatively, the terminal device can perform NAS security protection on the first uplink message based on the second key after determining that the self-location verification is passed, and send the first key set identifier and the first uplink message protected by NAS security to the second network element. For example, the terminal device can determine that the self-location verification is passed based on the first downlink message protected by NAS security and the first key set identifier received from the second network element. For another example, the second network element can send first indication information to the terminal device in a case where the self-location verification of the terminal device is passed, and the first indication information can be used to indicate that the self-location verification of the terminal device is passed. Accordingly, the terminal device can determine that the self-location verification is passed based on the first indication information. It can be seen that the terminal device performs relevant processing (such as performing NAS security protection, sending relevant information to the second network element, and the like) after determining that the self-location verification is passed, which can avoid unnecessary processing and / or unnecessary information sending, thereby saving processing resources, transmission resources, and the like, and also reducing power consumption of the terminal device.
[0233] The process of location verification between the terminal device and the second network element based on the first key is described below. For example, the second network element can perform NAS security protection on the location request message based on the first key to obtain a first NAS message, and then send the first NAS message and a second key set identifier to the terminal device. Accordingly, the terminal device can receive the first NAS message and the second key set identifier from the second network element, determine the first key based on the second key set identifier, perform NAS security protection on the first NAS message based on the first key to obtain a location request message, and then send the second key set identifier and a second NAS message to the second network element. The location request message can be used to request location information of the terminal device. The second NAS message is obtained by performing NAS security protection on a location request response message based on the first key, and the location request response message includes the location information (such as current location information) of the terminal device. Accordingly, the second network element can receive the second key set identifier and the second NAS message from the terminal device, determine the first key based on the second key set identifier, perform NAS security protection on the second NAS message based on the first key to obtain the location request response message, and then perform location verification on the terminal device based on the location information of the terminal device included in the location request response message.
[0234] It can be understood that, in a case where the terminal device performs NAS security processing on the NAS message from the second network element based on the first key, the terminal device can update the downlink count value corresponding to the first key; and / or, in a case where the terminal device performs NAS security protection on the NAS message sent to the second network element based on the first key, the uplink count value corresponding to the first key is updated (for example, increased by 1). Correspondingly, in a case where the second network element performs NAS security processing on the NAS message from the terminal device based on the first key, the second network element can update the uplink count value corresponding to the first key; and / or, in a case where the second network element performs NAS security protection on the NAS message sent to the terminal device based on the first key, the second network element can update the downlink count value corresponding to the first key (for example, increased by 1). More detailed descriptions about the update of the uplink count value and the downlink count value can be referred to the descriptions in the related technologies (for example, related standards), which will not be described here in detail.
[0235] In a case where the terminal device maintains a unified uplink NAS COUNT and downlink NAS COUNT between the terminal device and different satellites, the second network element can further send, to the first network element, the updated uplink count value corresponding to the first key and the updated downlink count value corresponding to the first key. When the second network element sends, to the first network element, the updated uplink count value corresponding to the first key and the updated downlink count value corresponding to the first key, the second network element can further send, to the first network element, the identifier of the terminal device and / or the first information associated with the first satellite, and the identifier of the terminal device can be used to indicate the terminal device associated with the updated uplink count value corresponding to the first key and the updated downlink count value corresponding to the first key.
[0236] It should be noted that the above descriptions about generating K_SAT_NASenc and / or K_SAT_NASint are only exemplary and do not constitute a limitation. In some possible implementation manners, more information can be further included in the process of generating K_SAT_NASenc and / or K_SAT_NASint, and part of the information can be dynamically generated by the HSS or the first network element, in which case the terminal device can not know the part of information, and the first network element needs to send the part of information to the terminal device through the first satellite.
[0237] It can be understood that in the store-and-forward scenario, the above-mentioned first network element, the second network element of the first satellite, and the terminal device can not be able to communicate at the same time, that is, the second network element of the first satellite can not be able to communicate with the first network element and the terminal device at the same time. When the first network element and the second network element of the first satellite can communicate, the first network element can send relevant information to the second network element of the first satellite, such as the identifier of the terminal device, the first key, the first uplink message, or the first uplink message after NAS security protection in the above-mentioned step 403. When the terminal device and the second network element of the first satellite can communicate, the second network element of the first satellite can send relevant information to the terminal device, such as the above-mentioned first NAS message, the first downlink message after NAS security protection, and the like. The terminal device can also send relevant information to the second network element of the first satellite, such as the above-mentioned second NAS message, the first uplink message after NAS security protection, and the like. When the first network element and the second network element of the first satellite can communicate again, the second network element of the first satellite can send relevant information to the first network element, such as the above-mentioned first uplink message after NAS security protection or the first uplink message, and the like.
[0238] In the above-mentioned process flow, the NAS security context can be established between the first satellite and the terminal device, so that the location verification of the terminal device can be performed based on the established NAS security context between the first satellite and the terminal device, and then the store-and-forward service can be provided for the terminal device after the location verification of the terminal device is passed.
[0239] The above-mentioned Figure 4 The overall flow of the first scheme provided by the embodiments of the present application is introduced, and then an example implementation manner of the first scheme is introduced by taking the first network element as MME-T and the second network element as MME-NT of the first satellite as an example. Please refer to Figure 5 , Figure 5 In the above-mentioned method, the terminal device and the MME-NT of the first satellite can establish the NAS security context, and the terminal device and the MME-T can also establish the NAS security context, that is, in this case, the terminal device can maintain two sets of NAS security contexts, that is, the NAS security context with the MME-NT of the first satellite and the NAS security context with the MME-T. Figure 5 The related description in the above-mentioned Figure 4 The related description in the above-mentioned Figure 5 The method can include but is not limited to the following steps:
[0240] 501. The terminal device accesses the network through the satellite and establishes the NAS security context with the MME-T.
[0241] In the embodiments of the present application, the related procedures of establishing the NAS security context between the terminal device and the MME-T through the satellite access network (such as the LTE core network) are not limited, and can be referred to the procedures shown in FIG. 2, for example, which can include steps 201-211 in FIG. 2. Figure 2 Figure 2
[0242] The NAS security context between the terminal device and the MME-T can include KSI (first key set identifier), K_ASME, K_NASenc, K_NASint, uplink NAS COUNT, downlink NAS COUNT, and the like.
[0243] 502. The MME-T obtains first information associated with a first satellite, and the first satellite is a satellite to be accessed by the terminal device.
[0244] 503. The MME-T obtains a first key based on the first information associated with the first satellite, and the first key is used for the NAS security protection between the MME-NT of the first satellite and the terminal device.
[0245] Steps 502 and 503 are similar to steps 401 and 402 described above, and the related descriptions in steps 401 and 402 described above can be referred to.
[0246] 504. The MME-T sends a first message to the MME-NT of the first satellite, and the first message can include the identifier of the terminal device and the first key.
[0247] When the MME-T can communicate with the first satellite, the MME-T can send the first message to the MME-NT of the first satellite. The first message can also include one or more of KSI, NATKSI (second key set identifier), uplink NAS COUNT corresponding to the first key, downlink NAS COUNT corresponding to the first key, and the first downlink message after the NAS security protection.
[0248] Step 504 can refer to the related descriptions in step 403 described above, and will not be described in detail here.
[0249] 505. The MME-NT of the first satellite sends a second message to the terminal device, and the second message can include the first information associated with the first satellite and the NATKSI.
[0250] After the MME-NT of the first satellite receives the first message from the MME-T, the MME-NT can store the related information in the first message, such as the identifier of the terminal device, the first key, and the like.
[0251] The MME-NT of the first satellite can send a second message to the terminal device when the first satellite is able to communicate with the terminal device. The second message can be a satellite broadcast message or a downlink NAS message (e.g., a NAS SMC message) that is not encrypted. The second message can include the first information associated with the first satellite and a NATKSI (a second key set identifier). Alternatively, in some possible implementations, the first information associated with the first satellite can not be included in the second message and can be sent separately, such as being periodically broadcast by the first satellite. In some cases, the second message can be used to instruct the terminal device to access.
[0252] In some possible implementations, the second message can further include an identifier of the terminal device, a KSI, and / or the like.
[0253] 506. The terminal device generates K_SAT_NASenc and / or K_SAT_NASint based on the first information associated with the first satellite.
[0254] After receiving the second message, the terminal device can generate K_SAT_NASenc and / or K_SAT_NASint based on the first information associated with the first satellite in the second message and can associate K_SAT_NASenc and / or K_SAT_NASint with the NATKSI.
[0255] 507. The terminal device accesses the first satellite.
[0256] In the embodiments of the present application, the process of the terminal device accessing the first satellite is not limited. For example, after the terminal device accesses the first satellite, a connection / channel can be established between the terminal device and the RAN of the first satellite, and a connection / channel can also be established between the terminal device and the MME-NT of the first satellite.
[0257] Optionally, step 507 can be performed.
[0258] 508. The MME-NT of the first satellite sends a location request message to the terminal device, including the NATKSI and a first NAS message that is NAS security protected.
[0259] After the terminal device accesses the first satellite, the MME-NT of the first satellite can trigger a location check for the terminal device and can send a location request message to the terminal device. The location request message can include the NATKSI and a first NAS message that is NAS security protected. The first NAS message that is NAS security protected can be based on information related to the location request. For example, the MME-NT of the first satellite can perform NAS security protection on the information related to the location request based on K_SAT_NASenc and / or K_SAT_NASint to obtain the first NAS message that is NAS security protected.
[0260] 509. The terminal device sends a location request response message to the MME-NT of the first satellite, including the NATKSI and the NAS security protected location information of the terminal device.
[0261] After receiving the location request message, the terminal device can determine K_SAT_NASenc and / or K_SAT_NASint based on the NATKSI in the location request message, and then can perform integrity check and / or decryption on the NAS security protected first NAS message based on K_SAT_NASenc and / or K_SAT_NASint. After the integrity check passes and the decryption, the information related to the location request can be obtained, and the terminal device can send a location request response message to the MME-NT of the first satellite based on the information related to the location request. The location request response message can include the NATKSI and the NAS security protected location information of the terminal device.
[0262] 510. The MME-NT of the first satellite performs location check on the terminal device based on the location information of the terminal device.
[0263] After receiving the location request response message from the terminal device, the MME-NT of the first satellite can determine K_SAT_NASenc and / or K_SAT_NASint based on the NATKSI in the location request response message, and then can perform integrity check and / or decryption on the NAS security protected location information of the terminal device based on K_SAT_NASenc and / or K_SAT_NASint. After the integrity check passes and the decryption, the location information of the terminal device can be obtained, and then the MME-NT of the first satellite can perform location check on the terminal device based on the location information of the terminal device. In the case that the MME-NT of the first satellite determines that the terminal device is located in the service area of the first satellite based on the location information of the terminal device, the terminal device location check can be determined to pass, otherwise, the terminal device location check can be determined to fail.
[0264] 511. In the case that the terminal device location check passes, the MME-NT of the first satellite sends a first downlink NAS message to the terminal device, including the KSI and the NAS security protected first downlink message.
[0265] Correspondingly, the terminal device can receive the first downlink NAS message from the MME-NT of the first satellite, and then can determine K_NASenc and / or K_NASint based on the KSI in the first downlink NAS message. After that, the terminal device can perform integrity check and / or decryption on the NAS security protected first downlink message based on K_NASenc and / or K_NASint. After the integrity check passes and the decryption, the first downlink message can be obtained.
[0266] 512. The terminal device sends a first uplink NAS message to the MME-NT of the first satellite, including the KSI and the first uplink message after NAS security protection.
[0267] In some possible implementation, the terminal device can send the first uplink NAS message to the MME-NT of the first satellite after determining that the self-position check is passed, so as to avoid unnecessary sending. For example, after receiving the first downlink NAS message from the MME-NT of the first satellite, the terminal device can determine that the self-position check is passed based on the first downlink NAS message. Alternatively, in some possible implementation, the MME-NT of the first satellite can send first indication information to the terminal device in the case that the position check of the terminal device is passed, and the first indication information can be used to indicate that the position check of the terminal device is passed.
[0268] 513. The MME-NT of the first satellite sends a second message to the MME-T, including the identity of the terminal device, the KSI and the first uplink message after NAS security protection.
[0269] In some possible implementation, after receiving the first uplink NAS message from the terminal device, the MME-NT of the first satellite can first determine whether the position of the terminal device is passed, and then send the second message to the MME-T in the case that the position check of the terminal device is passed.
[0270] The MME-NT of the first satellite can send the second message to the MME-T when the satellite has a connection with the ground. In some possible implementation, after sending the second message to the MME-T, the MME-NT of the first satellite can delete the locally stored NAS security context related to the terminal device.
[0271] For example, the second message can further include first information associated with the first satellite, which can be used to indicate that the second message is sent by the MME-NT of the first satellite. The second message can further include the uplink NAS COUNT corresponding to the updated first key, the downlink NAS COUNT corresponding to the updated first key, and the like.
[0272] After receiving the second message from the MME-NT of the first satellite, the MME-T can determine the K_NASenc and / or K_NASint based on the KSI in the second message, and then perform integrity check and / or decryption on the first uplink message after NAS security protection based on the K_NASenc and / or K_NASint. After the integrity check and decryption are passed, the first uplink message can be obtained.
[0273] In the above procedure, the two different NAS security keys can be distinguished by KSI or NAT KSI in the NAS message. In some possible implementation, the two different NAS security keys can also be distinguished by the type of the NAS message, for example, a special type of the NAS message can be defined to indicate that the corresponding key is K_SAT_NASenc and / or K_SAT_NASint.
[0274] It should be understood that steps 511-513 are optional.
[0275] It can be understood that after the storage and forwarding of the uplink and downlink data between the terminal device and the MME-T based on the first satellite is completed, the MME-T can determine the next satellite to be accessed by the terminal device, and then can perform storage and forwarding based on the next satellite to be accessed by the terminal device. For details, reference can be made to steps 502-513 described above.
[0276] It can be understood that in the above procedure, two sets of NAS security keys can be included, the location-related NAS message can be protected by the NAS security key between the terminal device and the MME-NT of the first satellite, and the uplink and downlink message between the terminal device and the MME-T can be protected by the NAS security key between the terminal device and the MME-T.
[0277] The following describes another exemplary implementation of the first scheme, taking the first network element as the MME-T and the second network element as the MME-NT of the first satellite as an example. Please refer to Figure 6 , Figure 6 In the above procedure, the NAS security context can be established between the terminal device and the MME-NT of the first satellite, and the NAS security context can not be established between the terminal device and the MME-T. In this case, the terminal device can maintain a set of NAS security contexts, that is, the NAS security context of the MME-NT of the first satellite. Figure 6 The related description in the above Figure 4 and Figure 5 may refer to the corresponding related description in the above Figure 6 . For example, as shown in the above
[0278] 601. The terminal device accesses the network through the satellite.
[0279] In the embodiments of the present application, the related procedure of the terminal device accessing the network (such as the LTE core network) through the satellite is not limited, and can refer to the procedure shown in the above Figure 2 , for example, can include steps 201-207 in the above Figure 2 .
[0280] 602. The MME-T obtains first information associated with the first satellite, the first satellite being a satellite to be accessed by the terminal device.
[0281] 603. The MME-T obtains a first key based on the first information associated with the first satellite, the first key being used for NAS security protection between the MME-NT of the first satellite and the terminal device.
[0282] The steps 602 and 603 are similar to the steps 401 and 402 described above, and the related descriptions in the steps 401 and 402 can be referred to.
[0283] 604. The MME-T sends a first message to the MME-NT of the first satellite, the first message comprising the identity of the terminal device and the first key.
[0284] The first message can further comprise one or more of the following: KSI, NATKSI (second key set identifier), uplink NAS COUNT corresponding to the first key, downlink NAS COUNT corresponding to the first key, first downlink message, etc.
[0285] The step 604 can refer to the related descriptions in the step 403 described above, and will not be described in detail here.
[0286] 605. The MME-NT of the first satellite sends a second message to the terminal device, the second message comprising the first information associated with the first satellite and NATKSI.
[0287] After receiving the first message from the MME-T, the MME-NT of the first satellite can store the relevant information in the first message, such as the identity of the terminal device, the first key, etc.
[0288] Illustratively, the second message can be a satellite broadcast message, or a downlink NAS message (such as NAS SMC message), which is not encrypted. The second message can comprise the identity of the terminal device, the first information associated with the first satellite, and NATKSI (second key set identifier). Alternatively, in some possible implementations, the first information associated with the first satellite can not be included in the second message, and can be sent separately, such as being periodically broadcast by the first satellite. In some cases, the second message can be used to indicate terminal device access.
[0289] In some possible implementations, the second message can further comprise the identity of the terminal device, KSI, etc.
[0290] 606. The terminal device generates K_SAT_NASenc and / or K_SAT_NASint based on the first information associated with the first satellite.
[0291] 607. The terminal device accesses the first satellite.
[0292] Wherein, step 607 is optional.
[0293] 608. The MME-NT of the first satellite sends a location request message to the terminal device, including the NATKSI and the first NAS message after NAS security protection.
[0294] 609. The terminal device sends a location request response message to the MME-NT of the first satellite, including the NATKSI and the terminal device's location information after NAS security protection.
[0295] 610. The MME-NT of the first satellite performs location verification on the terminal device based on the terminal device's location information.
[0296] 611. In the case that the terminal device's location verification is passed, the MME-NT of the first satellite sends a first downlink NAS message to the terminal device, including the NATKSI and the first downlink message after NAS security protection.
[0297] For example, in the case that the terminal device's location verification is passed, the MME-NT of the first satellite can perform NAS security protection on the received first downlink message from the MME-T based on K_SAT_NASenc and / or K_SAT_NASint, and can obtain the first downlink message after NAS security protection, and then can send a first downlink NAS message to the terminal device, which can include the NATKSI and the first downlink message after NAS security protection. Correspondingly, the terminal device can receive the first downlink NAS message from the MME-NT of the first satellite, and then can determine K_SAT_NASenc and / or K_SAT_NASint based on the NATKSI in the first downlink NAS message, and then can perform integrity verification and / or decryption on the first downlink message after NAS security protection based on K_SAT_NASenc and / or K_SAT_NASint, and after the integrity verification is passed and the decryption is passed, the first downlink message can be obtained.
[0298] 612. The terminal device sends a first uplink NAS message to the MME-NT of the first satellite, including the NATKSI and the first uplink message after NAS security protection.
[0299] In some possible implementation, after determining that the location of the terminal device is verified, the terminal device can send the first uplink NAS message to the MME-NT of the first satellite, so as to avoid unnecessary sending. For example, after determining that the location of the terminal device is verified, the terminal device can perform NAS security protection on the first uplink message based on the K_SAT_NASenc and / or the K_SAT_NASint to obtain the first uplink message after NAS security protection, and then send the first uplink NAS message to the MME-NT of the first satellite. The first uplink NAS message can include the NATKSI and the first uplink message after NAS security protection. Correspondingly, the MME-NT of the first satellite can receive the first uplink NAS message from the terminal device, and then determine the K_SAT_NASenc and / or the K_SAT_NASint based on the NATKSI in the first uplink NAS message. After that, the MME-NT of the first satellite can perform integrity verification and / or decryption on the first uplink NAS message after NAS security protection based on the K_SAT_NASenc and / or the K_SAT_NASint. After the integrity verification and / or decryption, the first uplink message can be obtained.
[0300] 613. The MME-NT of the first satellite sends a second message to the MME-T, including the identity of the terminal device and the first uplink message.
[0301] In some possible implementation, after receiving the first uplink NAS message from the terminal device, the MME-NT of the first satellite can first determine whether the location of the terminal device is verified. If the location of the terminal device is verified, the MME-NT of the first satellite can perform related processing. For example, after determining that the location of the terminal device is verified, the MME-NT of the first satellite can determine the K_SAT_NASenc and / or the K_SAT_NASint based on the NATKSI in the first uplink NAS message, and perform integrity verification and / or decryption on the first uplink NAS message after NAS security protection based on the K_SAT_NASenc and / or the K_SAT_NASint.
[0302] When the satellite has a connection with the ground, the MME-NT of the first satellite can send a second message to the MME-T. In some possible implementation, after sending the second message to the MME-T, the MME-NT of the first satellite can delete the locally stored NAS security context related to the terminal device.
[0303] For example, the second message can further include first information associated with the first satellite, which can be used to indicate that the second message is sent by the MME-NT of the first satellite.
[0304] In some possible implementation manners, the NAS security context can be established between the MME-NT and the MME-T of the first satellite, for example, a NAS security key between the MME-NT and the MME-T of the first satellite is a third key. The messages transmitted between the MME-NT and the MME-T of the first satellite can be NAS security protected based on the third key, for example, the first message and the second message can be NAS security protected based on the third key.
[0305] It should be understood that steps 611-613 are optional.
[0306] It can be understood that after the storage and forwarding of the uplink and downlink data between the terminal device and the MME-T based on the first satellite is completed, the MME-T can determine the next satellite to be accessed by the terminal device, and then the storage and forwarding can be performed based on the next satellite to be accessed by the terminal device. For details, reference can be made to steps 602-613.
[0307] It can be understood that in the above flow, a set of NAS security keys can be included, the location-related NAS message can be NAS security protected by the NAS security key between the terminal device and the MME-NT of the first satellite, and the uplink and downlink message between the terminal device and the MME-T can also be NAS security protected by the NAS security key between the terminal device and the MME-NT of the first satellite.
[0308] The overall flow of the second technical solution provided by the embodiments of the present application will be exemplarily described below.
[0309] Please refer to Figure 7 , Figure 7 The flowchart of still another communication method disclosed by the embodiments of the present application is shown in FIG. 13. Figure 7In some embodiments, the terminal device and the first network element can establish a security context, and in the store-and-forward process, the terminal device can use the NAS security context between the terminal device and the first network element to perform NAS security protection on the location information of the terminal device, and can use the NAS security context between the terminal device and the first network element to perform NAS security protection on the uplink message of the terminal device to the first network element. The terminal device can send the NAS security protected location information of the terminal device and the NAS security protected uplink message to the second network element of the first satellite. The second network element of the first satellite can send the NAS security protected location information of the terminal device and the NAS security protected uplink message to the first network element. The first network element can perform NAS security processing on the NAS security protected location information of the terminal device based on the security context between the terminal device and the first network element, and obtain the location information of the terminal device. Then, the first network element can perform location verification on the terminal device based on the location information of the terminal device. If the verification is passed, the first network element can perform relevant processing on the uplink message of the terminal device to the first network element. In some embodiments, the first network element can be deployed on the ground, such as a MME-T deployed on the ground. The second network element can be a MME-NT. Alternatively, in the architecture of a 5G core network, the first network element can be an AMF-T deployed on the ground, and the second network element can be an AMF-NT. For example, as shown in FIG. 7, the method can include, but is not limited to, the following steps: Figure 7
[0310] 701. The terminal device obtains a first key, which is used for NAS security protection between the first network element and the terminal device.
[0311] In some embodiments, the terminal device and the first network element can establish a NAS security context through a satellite. For related procedures of establishing a NAS security context between the terminal device and the first network element through a satellite, reference can be made to the procedure shown in FIG. 6, which can include, for example, steps 201-211 in FIG. 6. Figure 2 Figure 2
[0312] It should be understood that the NAS security context stored by the terminal device and the first network element can include one or more of the following: a first key set identifier, K_ASME (a first intermediate key), K_NASenc, K_NASint, an uplink NAS COUNT corresponding to the first key, a downlink NAS COUNT corresponding to the first key, and the like. The first key can be K_NASenc and / or K_NASint.
[0313] In some possible embodiments, the terminal device can obtain the first key from the NAS security context between the terminal device and the first network element.
[0314] 702. The terminal device performs NAS security protection on the location information of the terminal device and the first uplink message based on the first key.
[0315] After the terminal device acquires the first key, the terminal device can perform NAS security protection on the location information of the terminal device (such as the current location information of the terminal device) and the first uplink message based on the first key, to obtain the NAS security protected location information of the terminal device and the NAS security protected first uplink message.
[0316] For example, in some possible implementation manners, when the terminal device needs to feed back the uplink message, the first network element can send the identifier of the terminal device and the first key set identifier to the second network element, and the first key set identifier can be used to identify the first key. Correspondingly, the second network element can receive the identifier of the terminal device and the first key set identifier from the first network element, and then the second network element can send the identifier of the terminal device and the first key set identifier to the terminal device. Correspondingly, the terminal device can receive the identifier of the terminal device and the first key set identifier from the second network element, and can determine that the terminal device needs to feed back the uplink message to the first network element based on the identifier of the terminal device and the first key set identifier. For example, the identifier of the terminal device and the first key set identifier sent by the second network element to the terminal device can be carried in a first message, and the first message can be used to instruct the terminal device to feed back the uplink message or access the first satellite. The second network element can be deployed on the first satellite, and the first satellite can be the satellite to be accessed by the terminal device.
[0317] 703. The terminal device sends the NAS security protected location information of the terminal device to the second network element, and sends the NAS security protected first uplink message to the second network element.
[0318] It should be noted that in the embodiments of the present application, the NAS security protected location information of the terminal device and the NAS security protected first uplink message can be sent to the second network element through one message, or the NAS security protected location information of the terminal device and the NAS security protected first uplink message can be sent to the second network element through two messages respectively.
[0319] In some possible implementation, the first network element can pre-generate the NAS security protected location request message with the first key between the terminal device, and then can send the NAS security protected location request message to the second network element, so that the second network element sends the NAS security protected location request message to the terminal device to obtain the NAS security protected location information of the terminal device. For example, the first network element can send the NAS security protected location request message to the second network element, and the NAS security protected location request message can be NAS security protected based on the first key. Accordingly, the second network element can receive the NAS security protected location request message from the first network element, and then the second network element can send the NAS security protected location request message to the terminal device. Accordingly, the terminal device can receive the NAS security protected location request message from the second network element, and the terminal device can send the NAS security protected location information of the terminal device to the second network element based on the NAS security protected location request message. For example, the terminal device can perform NAS security processing on the NAS security protected location request message based on the first key, and can obtain a location request message, and the location request message can be used to request to obtain the location information of the terminal device. The terminal device can send the NAS security protected location information of the terminal device to the second network element based on the location request message, and the NAS security protected location information of the terminal device can be NAS security protected based on the first key, that is, the terminal device can perform NAS security protection on the location information of the terminal device based on the first key.
[0320] It can be understood that when the first network element sends the NAS security protected location request message to the second network element, the first network element can also send the first key set identifier to the second network element. Accordingly, when the second network element sends the NAS security protected location request message to the terminal device, the second network element can also send the first key set identifier to the terminal device, so that the terminal device determines the first key based on the first key set identifier, and then the terminal device can perform NAS security processing on the NAS security protected location request message based on the first key.
[0321] 704. The second network element sends the NAS security protected location information of the terminal device and the NAS security protected first uplink message to the first network element, and the first network element is deployed on the ground. After the second network element receives the NAS security protected location information of the terminal device and the NAS security protected first uplink message from the terminal device, when the second network element can communicate with the first network element, the second network element can send the NAS security protected location information of the terminal device and the NAS security protected first uplink message to the first network element.
[0322] 705. The first network element performs NAS security processing on the NAS security protected location information of the terminal device based on the first key, to obtain the location information of the terminal device.
[0323] After receiving the NAS security protected location information of the terminal device and the NAS security protected first uplink message from the second network element, the first network element can perform NAS security processing (such as integrity verification and / or decryption) on the NAS security protected location information of the terminal device based on the first key, to obtain the location information of the terminal device.
[0324] 706. The first network element performs location verification on the terminal device based on the location information of the terminal device.
[0325] After obtaining the location information of the terminal device, the first network element can perform location verification on the terminal device based on the location information of the terminal device. The first network element can obtain the service range of the first satellite, and the specific implementation of the first network element performing location verification on the terminal device based on the location information of the terminal device can refer to the related description in the above step 405, which will not be described here.
[0326] 707. In the case that the location verification of the terminal device is passed, the first network element performs processing based on the first uplink message.
[0327] For example, in the case that the location verification of the terminal device is passed, the first network element can forward the first uplink message to the corresponding data network.
[0328] It can be understood that the above first uplink message and the location information of the terminal device can be subjected to NAS security protection as a whole, such as integrity protection and / or encryption, or can be subjected to NAS security protection respectively. In the case of the two different situations, the processing flow of the first network element can be different.
[0329] In a case that the first uplink message and the location information of the terminal device are both NAS security protected, the first network element can perform NAS security processing on the NAS security protected location information of the terminal device and the NAS security protected first uplink message as a whole based on the first key, and can obtain the location information of the terminal device and the first uplink message. In a case that the first uplink message and the location information of the terminal device are separately NAS security protected, the first network element can perform NAS security processing on the NAS security protected location information of the terminal device and the NAS security protected first uplink message separately based on the first key, and can obtain the location information of the terminal device and the first uplink message separately. In some possible implementation, in a case that the first uplink message and the location information of the terminal device are separately NAS security protected, the first network element can perform NAS security processing on the NAS security protected first uplink message based on the first key after the location of the terminal device is verified.
[0330] It can be understood that, when the terminal device sends the NAS security protected location information of the terminal device to the second network element, and sends the NAS security protected first uplink message to the second network element, the terminal device can further send an identifier of the terminal device and / or a first key set identifier to the second network element. Correspondingly, when the second network element sends the NAS security protected location information of the terminal device and the NAS security protected first uplink message to the first network element, the second network element can further send the identifier of the terminal device and / or the first key set identifier to the first network element, so that the first network element determines the first key based on the first key set identifier, and / or determines the terminal device corresponding to the first uplink message based on the identifier of the terminal device.
[0331] It can be understood that, in a store-and-forward scenario, the first network element, the second network element of the first satellite and the terminal device can not be able to communicate at the same time, that is, the second network element of the first satellite can not be able to communicate with the first network element and the terminal device at the same time. When the first network element and the second network element of the first satellite can communicate, the first network element can send relevant information, such as the above-mentioned NAS security protected location request message, to the second network element of the first satellite. When the terminal device and the second network element of the first satellite can communicate, the terminal device can send relevant information, such as the above-mentioned NAS security protected location information of the terminal device and the NAS security protected first uplink message, to the second network element of the first satellite. When the first network element and the second network element of the first satellite can communicate again, the second network element of the first satellite can send relevant information, such as the above-mentioned NAS security protected location information of the terminal device and the NAS security protected first uplink message, to the first network element.
[0332] It should be noted that, in the second scheme, the first network element verifies the position of the terminal device, but there is a certain time interval in the first satellite storage and forwarding process. In this case, even if the first network element sends the first downlink message after NAS security protection to the second network element of the first satellite, due to the mobility of the terminal device, the second network element of the first satellite cannot determine whether the terminal device is located within the service range of the first satellite. In some possible implementation manners, the second network element of the first satellite can decide whether to send the first downlink message after NAS security protection to the terminal device according to a local policy.
[0333] In the above processing flow, the NAS security in the storage and forwarding service can be ensured based on the NAS security key between the first network element and the terminal device, and the transmission of uplink data of the terminal device to the first network element can be supported.
[0334] The above Figure 7 The overall flow of the second scheme provided by the embodiments of the present application is introduced, and an exemplary implementation manner of the second scheme is introduced below by taking the first network element as MME-T and the second network element as MME-NT of the first satellite as an example. Please refer to Figure 8 , Figure 8 In the above processing flow, the NAS security in the storage and forwarding service can be ensured based on the NAS security key between the first network element and the terminal device, and the transmission of uplink data of the terminal device to the first network element can be supported. Figure 8 The related description in the above Figure 7 The corresponding related description in the above Figure 8 The method can include but is not limited to the following steps:
[0335] 801. The terminal device accesses the network through the satellite and establishes the NAS security context with the MME-T.
[0336] In the embodiments of the present application, the related flow of the terminal device accessing the network through the satellite (such as the LTE core network) and establishing the NAS security context with the MME-T is not limited, and can refer to the flow shown in Figure 2 For example, the flow can include steps 201-211 in the above Figure 2
[0337] One or more of the following can be included in the NAS security context between the terminal device and the MME-T: KSI (first key set identifier), K_ASME, K_NASenc, K_NASint, uplink NAS COUNT, downlink NAS COUNT, and the like.
[0338] 802. The MME-T determines the first satellite, which is the satellite to be accessed by the terminal device.
[0339] 803. The MME-T performs NAS security protection on the location request message based on the first key.
[0340] 804. The MME-T sends a first message to the MME-NT of the first satellite, which can include the identity of the terminal device and the NAS security protected location request message.
[0341] When the MME-T and the first satellite can communicate, the MME-T can send the first message to the MME-NT of the first satellite. The first message can also include KSI, and the like.
[0342] 805. The MME-NT of the first satellite sends a second message to the terminal device, which can include the identity of the terminal device.
[0343] After receiving the first message from the MME-T, the MME-NT of the first satellite can store relevant information in the first message, such as the identity of the terminal device and the NAS security protected location request message.
[0344] When the first satellite and the terminal device can communicate, the MME-NT of the first satellite can send the second message to the terminal device. The second message can be a satellite broadcast message or a downlink NAS message (such as a NAS SMC message), which is not encrypted. The second message can include the identity of the terminal device and can be used to instruct the terminal device to access the first satellite or the MME-NT of the first satellite.
[0345] 806. The terminal device accesses the first satellite.
[0346] In the embodiments of the present application, the process of the terminal device accessing the first satellite is not limited. After the terminal device accesses the first satellite, the terminal device and the RAN of the first satellite can establish a connection / channel, and the terminal device and the MME-NT of the first satellite can also establish a connection / channel.
[0347] The steps 805 and 806 are optional.
[0348] 807. The MME-NT of the first satellite sends a first downlink NAS message to the terminal device, including the KSI and the NAS security protected location request message.
[0349] After the terminal device accesses the first satellite, the MME-NT of the first satellite can trigger the location verification of the terminal device, and can send a first downlink NAS message to the terminal device. The first downlink NAS message can include the KSI and the NAS security protected location request message, which can be obtained based on the information related to the location request. Illustratively, the MME-NT of the first satellite can perform NAS security protection on the information related to the location request based on K_NASenc and / or K_NASint, and can obtain the NAS security protected location request message.
[0350] Illustratively, the first downlink NAS message can further include the identifier of the terminal device.
[0351] 808. The terminal device sends a first uplink NAS message to the MME-NT of the first satellite, including the KSI and the NAS security protected location information of the terminal device.
[0352] After the terminal device receives the first downlink NAS message, it can determine K_NASenc and / or K_NASint based on the KSI in the first downlink NAS message, and then perform integrity verification and / or decryption on the NAS security protected location request message based on K_NASenc and / or K_NASint. After the integrity verification passes and the decryption is successful, the location request message can be obtained, and the terminal device can send a first uplink NAS message to the MME-NT of the first satellite based on the location request message, which can include the KSI and the NAS security protected location information of the terminal device.
[0353] Illustratively, the first uplink NAS message can further include the identifier of the terminal device.
[0354] 809. The terminal device sends a second uplink NAS message to the MME-NT of the first satellite, including the KSI and the NAS security protected first uplink message.
[0355] After the terminal device sends the first uplink NAS message to the MME-NT of the first satellite, it can further send a second uplink NAS message to the MME-NT. Illustratively, when the terminal device needs to send a first uplink message to the first network element, it can process the first uplink message based on the first key, and can obtain the NAS security protected first uplink message.
[0356] In some possible implementation, the terminal device can carry the first uplink message after NAS security protection in the first uplink NAS message, and can not send the second uplink NAS message to the MME-NT of the first satellite separately. In this case, the terminal device can perform NAS security protection on the location information of the terminal device and the first uplink message as a whole, or perform NAS security protection separately.
[0357] For example, the second uplink NAS message can further include the identifier of the terminal device.
[0358] 810. The MME-NT of the first satellite sends a third message to the MME-T, including the KSI, the location information of the terminal device after NAS security protection, and the first uplink message after NAS security protection.
[0359] When the satellite has a connection with the ground, the MME-NT of the first satellite can send the third message to the MME-T.
[0360] For example, the third message can further include the identifier of the terminal device, the first information associated with the first satellite, and the like. The identifier of the terminal device can be used to indicate the terminal device associated with the KSI, the location information of the terminal device after NAS security protection, and the first uplink message after NAS security protection. The first information associated with the first satellite can be used to indicate that the third message is sent by the MME-NT of the first network element.
[0361] 811. The MME-T performs location verification on the terminal device based on the location information of the terminal device.
[0362] After the MME-T receives the third message from the MME-NT of the first satellite, the MME-T can determine K_NASenc and / or K_NASint based on the KSI in the third message, and then perform integrity verification and / or decryption on the location information of the terminal device after NAS security protection based on K_NASenc and / or K_NASint. After the integrity verification passes and the decryption is successful, the location information of the terminal device can be obtained, and then the MME-T can perform location verification on the terminal device based on the location information of the terminal device.
[0363] 812. In the case where the location verification of the terminal device passes, the MME-T performs relevant processing based on the first uplink message.
[0364] It can be understood that after the storage and forwarding of the uplink and downlink data between the terminal device and the MME-T based on the first satellite is completed, the MME-T can determine the next satellite to be accessed by the terminal device, and then perform storage and forwarding based on the next satellite to be accessed by the terminal device. For details, reference can be made to steps 802-812.
[0365] The following describes another exemplary implementation of the second scheme, taking the first network element as MME-T and the second network element as MME-NT of the first satellite as an example. Please refer to Figure 9 , Figure 9 In the method, when the terminal device can communicate with the MME-NT of the first satellite and needs to transmit uplink data to the MME-T, the terminal device can directly send the NAS security-protected location information of the terminal device and the NAS security-protected first uplink message to the MME-NT of the first satellite. When the MME-NT of the first satellite can communicate with the MME-T, the MME-NT of the first satellite can send the NAS security-protected location information of the terminal device and the NAS security-protected first uplink message to the MME-T. Figure 9 The related description in the method can refer to the corresponding description in the above Figure 7 and Figure 8 For example, as shown in Figure 9 , the method can include but is not limited to the following steps:
[0366] 901. The terminal device accesses the network through the satellite and establishes the NAS security context with the MME-T.
[0367] 902. The MME-T determines the first satellite, which is the satellite to be accessed by the terminal device.
[0368] 903. The MME-T sends a first message to the MME-NT of the first satellite, which can include the identifier of the terminal device.
[0369] When the MME-T can communicate with the first satellite, if the MME-T needs the terminal device to feed back the uplink message, the MME-T can send a first message to the MME-NT of the first satellite. For example, the first message can also include KSI, etc.
[0370] 904. The MME-NT of the first satellite sends a second message to the terminal device, which can include the identifier of the terminal device.
[0371] When the first satellite can communicate with the terminal device, the MME-NT of the first satellite can send a second message to the terminal device. For example, the second message can be a satellite broadcast message or a downlink NAS message (such as NAS SMC message), which is not encrypted. The second message can include the identifier of the terminal device, and the second message can be used to instruct the terminal device to access the first satellite or the MME-NT of the first satellite.
[0372] 905. The terminal device accesses the first satellite.
[0373] For example, steps 903-905 are optional.
[0374] 906. The terminal device sends a first uplink NAS message to the MME-NT of the first satellite, including the KSI, the NAS security protected location information of the terminal device, and the NAS security protected first uplink message.
[0375] For example, in some possible implementation manners, after the terminal device receives the relevant information from the first satellite, such as the second message or the first information associated with the first satellite, it can be determined that the corresponding access mode is satellite access, or it can be determined that the terminal device can communicate with the satellite. In this case, the terminal device can send a first uplink NAS message to the MME-NT of the first satellite.
[0376] For example, the first uplink NAS message can further include the identifier of the terminal device, the first information associated with the first satellite, and the like.
[0377] It should be understood that the terminal device can perform NAS security protection on the location information of the terminal device and the first uplink message as a whole, or can perform NAS security protection on the location information of the terminal device and the first uplink message respectively.
[0378] 907. The MME-NT of the first satellite sends a third message to the MME-T, including the KSI, the NAS security protected location information of the terminal device, and the NAS security protected first uplink message.
[0379] When the satellite has a connection with the ground, the MME-NT of the first satellite can send the third message to the MME-T.
[0380] For example, the third message can further include the identifier of the terminal device, the first information associated with the first satellite, and the like.
[0381] 908. The MME-T performs location verification on the terminal device based on the location information of the terminal device.
[0382] 909. In the case where the terminal device passes the location verification, the MME-T performs relevant processing based on the first uplink message.
[0383] It can be understood that after the storage and forwarding of the uplink and downlink data between the terminal device and the MME-T based on the first satellite is completed, the MME-T can determine the next satellite to be accessed by the terminal device, and then can perform storage and forwarding based on the next satellite to be accessed by the terminal device. For details, reference can be made to steps 902-909.
[0384] It should be noted that the relevant information and relevant description in the above different embodiments can be mutually referred to.
[0385] The above mainly introduces the communication method provided by the embodiments of the present application. It can be understood that the terminal device, the first network element and the second network element can contain the hardware structure and / or software module corresponding to the execution of each function in order to realize the above corresponding functions. The units and steps of each example described in combination with the embodiments disclosed herein can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed by hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the embodiments of the present application.
[0386] The embodiments of the present application can divide the functional modules of the terminal device, the first network element and the second network element according to the above method examples, for example, each functional module can be divided according to each function, or two or more functions can be integrated in one module. The above integrated module can be realized in the form of hardware or software functional module. It should be noted that the division of the modules by the embodiments of the present application is illustrative, and is only a logical functional division. There can be another division method when actually implemented.
[0387] In the case of dividing each functional module according to each function, Figure 10 A possible structure schematic diagram of the communication apparatus 1000 is shown. The communication apparatus 1000 includes a processing unit 1001, a communication unit 1002. Optionally, the communication unit 1002 can also be called a transceiver unit, an output unit, or an interface unit, etc. In a possible implementation manner, the communication unit 1002 includes at least one of a sending unit or a receiving unit. The sending unit and the receiving unit can be integrated together, or two independent units, etc. In a possible design, the communication apparatus 1000 can be the terminal device described above, or can be a component (for example, a processor, a chip, a chip system, a circuit or a functional module) in the terminal device, or can be a processing system in the terminal device, etc.
[0388] When the communication apparatus 1000 is used for the function of the terminal device in the embodiments shown above, Figure 4 The exemplary function of the terminal device in the embodiments shown above is:
[0389] The processing unit 1001 is configured to obtain first information associated with a first satellite, and the first information associated with different satellites is different.
[0390] The processing unit 1001 is further configured to generate a first key based on the first information.
[0391] The communication unit 1002 is configured to perform NAS security protection between the second network element and the terminal device based on the first key, the second network element being deployed on the first satellite.
[0392] For example, the processing unit 1001 can obtain the first information associated with the first satellite by the communication unit 1002 or generate the first information associated with the first satellite by the processing unit 1001.
[0393] For example, the communication unit 1002 can perform NAS security protection between the second network element and the terminal device based on the first key, the processing unit 1001 can encrypt and / or integrity protect the NAS message between the second network element and the terminal device based on the first key, and the communication unit 1002 can send and / or receive the NAS message after the NAS security protection to and / or from the second network element.
[0394] In a possible implementation, the communication unit 1002 is further configured to receive the second key set identifier and the first information associated with the first satellite from the second network element, and the second key set identifier is used to identify the first key.
[0395] In a possible implementation, the communication unit 1002 is further configured to receive the first downlink message after the NAS security protection and the second key set identifier from the second network element, the processing unit 1001 is further configured to determine the first key based on the second key set identifier, and the processing unit 1001 is further configured to perform NAS security processing on the first downlink message after the NAS security protection based on the first key to obtain the first downlink message.
[0396] In a possible implementation, the processing unit 1001 is further configured to perform NAS security protection on the first uplink message based on the first key, and the communication unit 1002 is further configured to send the second key set identifier and the first uplink message after the NAS security protection to the second network element.
[0397] In a possible implementation, the communication unit 1002 is further configured to receive the second key set identifier and the first NAS message from the second network element, the processing unit 1001 is further configured to determine the first key based on the second key set identifier, perform NAS security processing on the first NAS message based on the first key to obtain a location request message, and the location request message is used to request location information of the terminal device, the processing unit 1001 is further configured to perform NAS security protection on a location request response message based on the first key to obtain a second NAS message, and the location request response message includes the location information of the terminal device, and the communication unit 1002 is further configured to send the second NAS message and the second key set identifier to the second network element.
[0398] In a possible implementation, the communication unit 1002 is further configured to receive the first downlink message and a first key set identifier from the second network element after NAS security protection; the processing unit 1001 is further configured to determine the second key based on the first key set identifier; and the processing unit 1001 is further configured to perform NAS security processing on the first downlink message after NAS security protection based on the second key, to obtain the first downlink message.
[0399] In a possible implementation, the processing unit 1001 is further configured to perform NAS security protection on the first uplink message based on the second key; and the communication unit 1002 is further configured to send the first key set identifier and the first uplink message after NAS security protection to the second network element, where the first key set identifier is used to identify the second key.
[0400] In a possible implementation, the processing unit 1001 is further configured to update a downlink count value corresponding to the first key, in a case where the first key is used to perform NAS security processing on a NAS message from the second network element; and / or update an uplink count value corresponding to the first key, in a case where the first key is used to perform NAS security protection on a NAS message sent to the second network element.
[0401] In a possible implementation, the processing unit 1001 is further configured to generate the first key based on the first information associated with the first satellite and a first intermediate key, and the first intermediate key is further used to generate a second key, which is used for NAS security protection between the first network element and the terminal device.
[0402] In a possible implementation, the communication unit 1002 is further configured to receive the first key set identifier from the second network element; and the processing unit 1001 is further configured to determine the first intermediate key based on the first key set identifier.
[0403] In a possible implementation, the processing unit 1001 is further configured to generate a second intermediate key based on the first information associated with the first satellite; and the processing unit 1001 is further configured to generate the first key based on the second intermediate key.
[0404] The specific operations of each unit in the communication apparatus 1000 described above can be referred to the descriptions of the terminal device in the embodiments shown in the above Figure 4 , which will not be repeated here.
[0405] When the communication apparatus 1000 is configured to perform the functions of the terminal device in the embodiments shown in the above Figure 7 , exemplary implementation is as follows:
[0406] The processing unit 1001 is configured to obtain a first key, which is used for NAS security protection between a first network element and the terminal device; and the first network element is deployed on the ground.
[0407] The processing unit 1001 is also used to perform NAS security protection on the location information of the terminal device and the first uplink message based on the first key;
[0408] The communication unit 1002 is used to send the location information of the terminal device after the NAS security protection to the second network element, and to send the first uplink message after the NAS security protection to the second network element, which is deployed on the first satellite.
[0409] In one possible implementation, the communication unit 1002 is further configured to send a first key set identifier to the second network element, the first key set identifier being used to identify the first key.
[0410] In one possible implementation, the communication unit 1002 is further configured to receive the identifier of the terminal device and the identifier of the first key set from the second network element, the identifier of the first key set being used to identify the first key; and the processing unit 1001 is configured to obtain the first key based on the identifier of the first key set.
[0411] In one possible implementation, the communication unit 1002 is further configured to receive a NAS-secured location request message from the second network element, wherein the NAS-secured location request message is NAS-secured based on the first key and is used to request the location information of the terminal device; the communication unit 1002 is further configured to send the NAS-secured location information of the terminal device to the second network element based on the NAS-secured location request message.
[0412] For specific operation details of each unit in the aforementioned communication device 1000, please refer to the above. Figure 7 The description of the terminal device in the illustrated embodiment will not be repeated here.
[0413] In one possible design, the communication device 1000 may be the aforementioned first network element, or a component within the first network element (e.g., a processor, chip, chip system, circuit, or functional module), or a processing system within the first network element, etc. The first network element may be deployed on the ground.
[0414] When the communication device 1000 is used for the above Figure 4 In the embodiment shown, the function of the first network element is exemplified as follows:
[0415] Processing unit 1001 is used to obtain first information associated with a first satellite, wherein the first satellite is the satellite to be accessed by the terminal device, and the first information associated with different satellites is different;
[0416] The processing unit 1001 is further configured to obtain a first key based on the first information associated with the first satellite, the first key being used for NAS security protection between the second network element and the terminal device, the second network element being deployed at the first satellite.
[0417] The communication unit 1002 is configured to send, to the second network element, an identifier of the terminal device and the first key.
[0418] In a possible implementation, the processing unit 1001 is further configured to perform NAS security protection on the first downlink message based on a second key; and the communication unit 1002 is further configured to send, to the second network element, the first downlink message after the NAS security protection and a first key set identifier, the first key set identifier being used for identifying the second key.
[0419] In a possible implementation, the communication unit 1002 is further configured to receive, from the second network element, the first uplink message after the NAS security protection and the first key set identifier; the processing unit 1001 is further configured to determine the second key based on the first key set identifier; and the processing unit 1001 is further configured to perform NAS security processing on the first uplink message after the NAS security protection based on the second key, to obtain the first uplink message.
[0420] In a possible implementation, the communication unit 1002 is further configured to send, to the second network element, an uplink count value and a downlink count value corresponding to the first key, the uplink count value and the downlink count value corresponding to the first key being used for NAS security protection between the second network element and the terminal device.
[0421] In a possible implementation, the communication unit 1002 is further configured to send, to a third network element, a key request, the key request including the first information associated with the first satellite; and the communication unit 1002 is further configured to receive, from the third network element, a key request response, the key request response including the first key.
[0422] In a possible implementation, the processing unit 1001 is further configured to generate the first key based on the first information associated with the first satellite.
[0423] In a possible implementation, the processing unit 1001 is further configured to generate the first key based on the first information associated with the first satellite and a first intermediate key, the first intermediate key also being used for generating a second key, the second key being used for NAS security protection between the first network element and the terminal device.
[0424] In a possible implementation, the communication unit 1002 is further configured to send, to the second network element, a first key set identifier, the first key set identifier being used for identifying the first intermediate key.
[0425] In a possible implementation, the processing unit 1001 is further configured to generate a second intermediate key based on the first information associated with the first satellite; and the processing unit 1001 is further configured to generate the first key based on the second intermediate key.
[0426] The specific operations of the various units in the communication apparatus 1000 described above can refer to the descriptions of the corresponding units in the embodiments of the first network element shown in FIG. 2, which are not described herein again. Figure 4 The specific operations of the various units in the communication apparatus 1000 described above can refer to the descriptions of the corresponding units in the embodiments of the first network element shown in FIG. 2, which are not described herein again.
[0427] When the communication apparatus 1000 is configured to perform the functions of the first network element in the embodiments of the first network element shown in FIG. 2, the exemplary functions are as follows: Figure 7
[0428] The communication unit 1002 is configured to receive, from a second network element, NAS security protected location information of a terminal device and a NAS security protected first uplink message; the NAS security protected location information of the terminal device and the NAS security protected first uplink message are NAS security protected based on a first key; the second network element is deployed on a first satellite, and the first key is used for NAS security protection between the first network element and the terminal device.
[0429] The processing unit 1001 is configured to perform NAS security processing on the NAS security protected location information of the terminal device based on the first key, to obtain location information of the terminal device.
[0430] The processing unit 1001 is configured to perform location verification on the terminal device based on the location information of the terminal device.
[0431] The processing unit 1001 is configured to perform processing based on the first uplink message when the location verification on the terminal device is passed.
[0432] In a possible implementation, the communication unit 1002 is further configured to receive, from the second network element, a first key set identifier; and the processing unit 1001 is configured to determine the first key based on the first key set identifier.
[0433] In a possible implementation, the communication unit 1002 is further configured to send, to the second network element, an identifier of the terminal device and a first key set identifier, the first key set identifier being used to identify the first key, and the first satellite being a satellite to be accessed by the terminal device.
[0434] In a possible implementation, the communication unit 1002 is further configured to send, to the second network element, a NAS security protected location request message, the NAS security protected location request message being NAS security protected based on the first key, and the NAS security protected location request message being used to request to obtain the location information of the terminal device.
[0435] The specific operations of each unit in the communication apparatus 1000 described above can be seen from the above Figure 7 The description of the first network element in the embodiment shown above will not be repeated here.
[0436] In a possible design, the communication apparatus 1000 can be the second network element described above, or can be a component (for example, a processor, a chip, a chip system, a circuit, or a functional module) in the second network element, or can be a processing system in the second network element, and the like. The second network element can be deployed on the first satellite.
[0437] When the communication apparatus 1000 is used for the function of the second network element described above Figure 4 When the communication apparatus 1000 is used for the function of the second network element described above
[0438] The communication unit 1002 is configured to receive, from the first network element, an identifier of a terminal device and a first key, where the first key is generated based on first information associated with the first satellite, and the first information associated with different satellites is different;
[0439] The processing unit 1001 is configured to perform NAS security protection between the second network element and the terminal device based on the first key.
[0440] In a possible implementation, the communication unit 1002 is further configured to send, to the terminal device, a second key set identifier and the first information associated with the first satellite, where the second key set identifier is used to identify the first key.
[0441] In a possible implementation, the communication unit 1002 is further configured to receive a first downlink message from the first network element; the processing unit 1001 is further configured to perform NAS security protection on the first downlink message based on the first key; and the communication unit 1002 is further configured to send, to the terminal device, the first downlink message after the NAS security protection and the second key set identifier.
[0442] In a possible implementation, the communication unit 1002 is further configured to receive, from the terminal device, the second key set identifier and a first uplink message after NAS security protection; the processing unit 1001 is further configured to determine the first key based on the second key set identifier; the processing unit 1001 is further configured to perform NAS security processing on the first uplink message after the NAS security protection based on the first key, to obtain the first uplink message; and the communication unit 1002 is further configured to send, to the first network element, the identifier of the terminal device and the first uplink message.
[0443] In a possible implementation, the processing unit 1001 is further configured to perform NAS security protection on a location request message based on the first key, to obtain a first NAS message, the location request message being used to request to obtain location information of the terminal device; the communication unit 1002 is further configured to send the second key set identifier and the first NAS message to the terminal device; the communication unit 1002 is further configured to receive the second key set identifier and a second NAS message from the terminal device; the processing unit 1001 is further configured to determine the first key based on the second key set identifier, perform NAS security processing on the second NAS message based on the first key, to obtain a location request response message, the location request response message including the location information of the terminal device; and the processing unit 1001 is further configured to perform location verification on the terminal device based on the location information of the terminal device.
[0444] In a possible implementation, the processing unit 1001 is further configured to perform, in a case where the location verification on the terminal device is passed, NAS security protection between the second network element and the terminal device based on the first key.
[0445] In a possible implementation, the communication unit 1002 is further configured to receive, from the first network element, a first downlink message subjected to NAS security protection and a first key set identifier, the first downlink message subjected to NAS security protection being subjected to NAS security protection based on a second key, and the first key set identifier being used to identify the second key; and the processing unit 1001 is further configured to send, in a case where the location verification on the terminal device is passed, the first downlink message subjected to NAS security protection and the first key set identifier to the terminal device.
[0446] In a possible implementation, the communication unit 1002 is further configured to receive, from the terminal device, a first key set identifier and a first uplink message subjected to NAS security protection, the first uplink message subjected to NAS security protection being subjected to NAS security protection based on a second key, and the first key set identifier being used to identify the second key; and the communication unit 1002 is further configured to send, in a case where the location verification on the terminal device is passed, the first key set identifier and the first uplink message subjected to NAS security protection to the first network element.
[0447] In a possible implementation, the communication unit 1002 is further configured to receive, from the first network element, an uplink count value and a downlink count value corresponding to the first key, the uplink count value and the downlink count value corresponding to the first key being used for NAS security protection between the second network element and the terminal device; and the processing unit 1001 is further configured to update the uplink count value corresponding to the first key in a case where the first key is used for NAS security processing of a NAS message from the terminal device; and / or update the downlink count value corresponding to the first key in a case where the first key is used for NAS security protection of a NAS message sent to the terminal device.
[0448] In a possible implementation, the communication unit 1002 is further configured to send, to the first network element, one or more of the updated uplink count value corresponding to the first key, the updated downlink count value corresponding to the first key, and the first information associated with the first satellite.
[0449] In a possible implementation, the communication unit 1002 is further configured to receive, from the first network element, a first key set identifier; and the communication unit 1002 is further configured to send, to the terminal device, the first key set identifier, the first key set identifier being used to identify a first intermediate key, the first intermediate key being used to generate the first key and a second key, the second key being used for NAS security protection between the first network element and the terminal device.
[0450] The specific operations of the various units of the communication apparatus 1000 described above can refer to the descriptions of the second network element in the embodiments shown in Figure 4 and will not be described here.
[0451] In a possible design, the communication apparatus 1000 can be the second network element described above, or can be a component (for example, a processor, a chip, a chip system, a circuit, or a functional module) in the second network element, or can be a processing system in the second network element, and the like. The second network element can be deployed on the first satellite.
[0452] When the communication apparatus 1000 is used for the functions of the second network element in the embodiments shown in Figure 7 , exemplary implementations are as follows:
[0453] The communication unit 1002 is configured to receive, from a terminal device, terminal device location information after NAS security protection, and receive a first uplink message after NAS security protection from the terminal device; the terminal device location information after NAS security protection and the first uplink message after NAS security protection are subjected to NAS security protection based on a first key; and the first key is used for NAS security protection between the first network element and the terminal device.
[0454] The communication unit 1002 is further configured to send the NAS security protected location information of the terminal device and the NAS security protected first uplink message to a first network element, wherein the first network element is deployed on the ground.
[0455] In a possible implementation, the communication unit 1002 is further configured to receive a first key set identifier from the terminal device, wherein the first key set identifier is used to identify the first key; and the communication unit 1002 is further configured to send the first key set identifier to the first network element.
[0456] In a possible implementation, the communication unit 1002 is further configured to receive the identifier of the terminal device and the first key set identifier from the first network element; and the communication unit 1002 is further configured to send the identifier of the terminal device and the first key set identifier to the terminal device.
[0457] In a possible implementation, the communication unit 1002 is further configured to receive a NAS security protected location request message from the first network element, wherein the NAS security protected location request message is NAS security protected based on the first key, and the NAS security protected location request message is used to request to obtain the location information of the terminal device; and the communication unit 1002 is further configured to send the NAS security protected location request message to the terminal device.
[0458] The specific operations of each unit in the communication apparatus 1000 described above can refer to the descriptions of the second network element in the embodiments shown in the above Figure 7 The specific operations of each unit in the communication apparatus 1000 described above can refer to the descriptions of the second network element in the embodiments shown in the above
[0459] In a possible implementation, Figure 7In the communication apparatus shown, the processing unit can be one or more processors / logic circuits, and the communication unit can be a transceiver, or the communication unit can also be a transmitting unit and a receiving unit, the transmitting unit can be a transmitter, and the receiving unit can be a receiver, and the transmitting unit and the receiving unit are integrated into one device, for example, a transceiver. In the embodiments of the present application, the processor and the transceiver can be coupled, and the present application does not limit the connection mode of the processor and the transceiver. In the process of executing the above method, the process of sending information (such as sending the first message, the second key set identifier, etc.) in the above method can be understood as the process of outputting the above information by the processor. When the above information is output, the processor outputs the above information to the transceiver, so that the transceiver transmits. After the above information is output by the processor, it can also need to be processed further, and then reach the transceiver. Similarly, the process of receiving information (such as receiving the first message, the second key set identifier, etc.) in the above method can be understood as the process of receiving the input above information by the processor. When the processor receives the input information, the transceiver receives the above information and inputs it to the processor. Further, after the transceiver receives the above information, the above information can need to be processed further, and then input to the processor.
[0460] In another possible implementation manner, Figure 7 In the communication apparatus shown, the processing unit can be one or more processors / logic circuits. The communication unit can be an input / output interface, or the communication unit can also be an input interface and an output interface. The input / output interface can also be referred to as a communication interface, or an interface circuit, or an interface, etc.
[0461] Figure 11 The communication apparatus 1100 provided by the embodiments of the present application is shown as a possible hardware structure schematic diagram. The communication apparatus 1100 can include a communication interface 1104 and at least one processor 1102. Optionally, a bus 1103 can also be included. Further optionally, at least one memory 1101 can also be included, wherein the memory 1101, the processor 1102 and the communication interface 1104 can be connected through the bus 1103.
[0462] The memory 1101 is configured to provide a storage space, and data such as an operating system and a computer program can be stored in the storage space. The memory 1101 can be one or a combination of a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a compact disc read-only memory (CD-ROM), and the like.
[0463] The processor 1102 is a module configured to perform arithmetic operations and / or logical operations, and can be one or a combination of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor unit (MPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a complex programmable logic device (CPLD), a co-processor (assisting a central processor to complete corresponding processing and application), a microcontroller unit (MCU), and the like. For example, the processor 1102 can be configured to process a communication protocol and communication data.
[0464] The communication interface 1104 is configured to receive data sent by an external device and / or send data to the external device. Optionally, the communication interface 1104 can further include a transmitter (such as a radio frequency transmitter, an antenna, and the like) and / or a receiver coupled with the interface, and the like. For example, the communication interface 1104 can include a control circuit and an antenna, and the control circuit is mainly configured to convert a baseband signal and a radio frequency signal and process the radio frequency signal. The antenna is mainly configured to transceive a radio frequency signal in the form of an electromagnetic wave. When it is necessary to send data wirelessly, the processor 1102 performs baseband processing on data to be sent, and then outputs the baseband signal to the control circuit. The control circuit converts the baseband signal into a radio frequency signal, and transmits the radio frequency signal in the form of an electromagnetic wave to the outside through the antenna. When data is sent to the communication device, the control circuit receives a radio frequency signal through the antenna, converts the radio frequency signal into a baseband signal, and outputs the baseband signal to the processor 1102. The processor 1102 converts the baseband signal into data and processes the data.
[0465] In a possible implementation, the control circuit and the antenna can be arranged independently of the processor that performs baseband processing, for example, in a distributed scenario, the control circuit and the antenna can be arranged remotely from the communication apparatus.
[0466] In one design, the communication apparatus 1100 can be configured to perform the functions of the terminal device in the above-described Figures 4-9 embodiments. Details can be referred to the above-described Figures 4-9 embodiments of the terminal device, which are not repeated here.
[0467] In another design, the communication apparatus 1100 can be configured to perform the functions of the first network element in the above-described Figures 4-9 embodiments. Details can be referred to the above-described Figures 4-9 embodiments of the first network element, which are not repeated here.
[0468] In yet another design, the communication apparatus 1100 can be configured to perform the functions of the second network element in the above-described Figures 4-9 embodiments. Details can be referred to the above-described Figures 4-9 embodiments of the second network element, which are not repeated here.
[0469] In one possible design, the memory 1101 can store instructions, which can be a computer program, and the computer program can be run on the processor 1102 to cause the communication apparatus 1100 to perform operations performed by the terminal device, or operations performed by the first network element, or operations performed by the second network element, in any of the method embodiments described above. Details can be referred to the above-described Figures 4-9 embodiments, which are not repeated here.
[0470] It is noted that the communication apparatus 1100 shown in the above is merely an implementation manner of the embodiments of the present application, and in actual applications, the communication apparatus 1100 can include more or fewer components, which are not limited here. Figure 11 It is understood that the sending in the embodiments of the present application can be direct sending or indirect sending. The direct sending means that one device or module sends information / data directly to a corresponding device or module, and the indirect sending means that one device or module sends information / data to a corresponding device or module through other devices or modules.
[0471]
[0472] It is apparent that the described embodiments are only some but not all of the embodiments of the present application. In this document, the term "embodiment" refers to a specific example embodiment of the present application that can include a particular feature, structure, or characteristic. A discussion of an embodiment in this document does not mean that all embodiments include the discussed feature, structure, or characteristic. The phrases "in one embodiment," "in some embodiments," or the like do not imply that a feature is essential to one or more embodiments, that the feature is constitutively, collectively present in each embodiment, or that the feature is present at all. The various embodiments described herein can be combined to provide further embodiments. The phrase "associated with," as used herein, means to have a relevant, expected, or otherwise functionally relationship with a reference element and does not imply a physical or causal relationship. The terms "first," "second," "third," etc. are used herein to distinguish one element from another, and do not imply a particular order, sequence, or chronology. The terms "comprises," "comprising," "includes," "including," and the like can be used in the sense of "including but not limited to." A list of steps or components followed by "and / or" indicates that individual steps or components can be taken or used either singularly or in any combination with one or more of the other steps or components. It is further understood that the use of "and / or," "including," "comprising," or "having" and variations thereof, does not preclude the presence of zero, one, or more of the enumerated items. It is understood that the use of the term "or" in the examples described herein is the inclusive, and not the exclusive use, unless explicitly indicated otherwise. It is further understood that the use of the term "comprise" or "comprises" or "comprising" or "comprises" or "comprising" in the examples described herein, unless specifically stated to the contrary, means that additional, optional steps or components can be added to the described examples. It is further understood that the use of the term "based on" in the examples described herein is the inclusive, and not the exclusive use, unless explicitly indicated otherwise. It is further understood that the use of the term "based on" in the examples described herein is the inclusive, and not the exclusive use, unless explicitly indicated otherwise.
[0473] It is understood that the drawings are only schematic and that they do not limit the present application. It is further understood that some of the examples described herein can include various components that can be implemented, for example, using a programmed processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other integrated circuit, a hardware component, software component or a combination thereof. It is further understood that, where the examples include more than one processing unit, system or component, such processing units, systems or components can be implemented using either a single integrated circuit or a plurality of integrated circuits. It is further understood that one or more of the processing units, systems or components can implement their respective functions using software instructions or a combination of hardware and software. It is further understood that the term "software" as used herein includes but is not limited to firmware, resident software, microcode, etc. It is further understood that the methods, techniques and modules described herein can be integrated into a data processing system along with other devices and components as desired in order to create an overall system.
[0474] The terms “component,” “module,” “system,” “unit,” etc., used in this specification are used to refer to computer-related entities, hardware, firmware, combinations of hardware and software, software, or software in execution. For example, a unit can be, but is not limited to, a process running on a processor, a processor, an object, an executable file, a thread of execution, a program, and / or distributed between two or more computers. Furthermore, these units can be executed from various computer-readable media on which various data structures are stored. For example, a unit can communicate via local and / or remote processes based on signals having one or more data packets (e.g., data from a second unit interacting with another unit between a local system, a distributed system, and / or a network; for example, the Internet interacting with other systems via signals).
[0475] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of this application. It should be understood that the above description is only a specific embodiment of this application and is not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, improvements, etc., made on the basis of the technical solution of this application should be included within the scope of protection of this application.
Claims
1. A communication method, characterized in that, The method includes: (The method is applied to a terminal device or a chip in a terminal device.) Obtain the first information associated with the first satellite; the first information associated with different satellites is different. A first key is generated based on the first information associated with the first satellite; Non-access stratum (NAS) security protection is performed between the second network element and the terminal device based on the first key, and the second network element is deployed on the first satellite.
2. The method according to claim 1, characterized in that, The acquisition of the first information associated with the first satellite includes: Receive a second key set identifier from the second network element and first information associated with the first satellite; the second key set identifier is used to identify the first key.
3. The method according to claim 2, characterized in that, The NAS security protection between the second network element and the terminal device based on the first key includes: Receive the first downlink message and the second key set identifier from the second network element after NAS security protection; The first key is determined based on the identifier of the second key set; Based on the first key, the first downlink message after NAS security protection is processed to obtain the first downlink message.
4. The method according to claim 2 or 3, characterized in that, The NAS security protection between the second network element and the terminal device based on the first key includes: NAS security protection is applied to the first uplink message based on the first key; Send the second key set identifier and the first uplink message after the NAS security protection to the second network element.
5. The method according to any one of claims 2-4, characterized in that, The method further includes: Receive the second key set identifier and the first NAS message from the second network element; The first key is determined based on the second key set identifier, and the first NAS message is processed for NAS security based on the first key to obtain a location request message. The location request message is used to request the location information of the terminal device. Based on the first key, a second NAS message is obtained by performing NAS security protection on the location request response message, wherein the location request response message includes the location information of the terminal device; Send the second NAS message and the second key set identifier to the second network element.
6. The method according to any one of claims 1-5, characterized in that, The generation of the first key based on the first information associated with the first satellite includes: The first key is generated based on the first information associated with the first satellite and the first intermediate key. The first intermediate key is also used to generate a second key. The second key is used for NAS security protection between the first network element and the terminal device. The first network element is deployed on the ground.
7. The method according to any one of claims 1-6, characterized in that, The generation of the first key based on the first information associated with the first satellite includes: A second intermediate key is generated based on the first information associated with the first satellite; The first key is generated based on the second intermediate key.
8. A communication method, characterized in that, Applied to the first network element, the method includes: Obtain the first information associated with the first satellite, where the first satellite is the satellite that the terminal device needs to access, and the first information associated with different satellites is different; A first key is obtained based on the first information associated with the first satellite. The first key is used for non-access stratum NAS security protection between the second network element and the terminal device. The second network element is deployed on the first satellite. The identifier of the terminal device and the first key are sent to the second network element.
9. The method according to claim 8, characterized in that, The step of obtaining the first key based on the first information associated with the first satellite includes: Send a key request to a third network element, the key request including first information associated with the first satellite; Receive a key request response from the third network element, the key request response including the first key.
10. The method according to claim 8, characterized in that, The step of obtaining the first key based on the first information associated with the first satellite includes: The first key is generated based on the first information associated with the first satellite.
11. The method according to claim 10, characterized in that, The generation of the first key based on the first information associated with the first satellite includes: The first key is generated based on the first information associated with the first satellite and the first intermediate key. The first intermediate key is also used to generate a second key, which is used for NAS security protection between the first network element and the terminal device.
12. The method according to claim 8, characterized in that, The step of obtaining the first key based on the first information associated with the first satellite includes: A second intermediate key is generated based on the first information associated with the first satellite; The first key is generated based on the second intermediate key.
13. A communication method, characterized in that, Applied to a second network element, which is deployed on the first satellite, the method includes: Receive the identifier and first key of the terminal device from the first network element. The first key is generated based on the first information associated with the first satellite. The first information associated with different satellites is different. Non-access stratum (NAS) security protection is performed between the second network element and the terminal device based on the first key.
14. The method according to claim 13, characterized in that, The method further includes: Send the second key set identifier and the first information associated with the first satellite to the terminal device, wherein the second key set identifier is used to identify the first key.
15. The method according to claim 14, characterized in that, The method further includes: Receive the first downlink message from the first network element; The NAS security protection between the second network element and the terminal device based on the first key includes: The first downlink message is protected by NAS security based on the first key; Send the first downlink message after the NAS security protection and the second key set identifier to the terminal device.
16. The method according to claim 14 or 15, characterized in that, The NAS security protection between the second network element and the terminal device based on the first key includes: Receive the second key set identifier and the first uplink message after NAS security protection from the terminal device; The first key is determined based on the identifier of the second key set; Based on the first key, the first uplink message after NAS security protection is processed to obtain the first uplink message; The identifier of the terminal device and the first uplink message are sent to the first network element.
17. The method according to claim 14, characterized in that, The method further includes: Based on the first key, the location request message is protected by NAS security to obtain a first NAS message, which is used to request the location information of the terminal device. Send the second key set identifier and the first NAS message to the terminal device; Receive the second key set identifier and the second NAS message from the terminal device; The first key is determined based on the second key set identifier, and the second NAS message is processed for NAS security based on the first key to obtain a location request response message, the location request response message including the location information of the terminal device; The location of the terminal device is verified based on its location information.
18. The method according to claim 17, characterized in that, The NAS security protection between the second network element and the terminal device based on the first key includes: If the location verification of the terminal device passes, NAS security protection between the second network element and the terminal device is performed based on the first key.
19. A communication system, characterized in that, It includes a first network element and a second network element, wherein the first network element is used to implement the method described in any one of claims 8-12, and the second network element is used to implement the method described in any one of claims 13-18.
20. The system according to claim 19, characterized in that, The system further includes a terminal device for implementing the method according to any one of claims 1-7.
21. A communication device, characterized in that, Includes modules for implementing the method as described in any one of claims 1-18.
22. A communication device, characterized in that, The device includes a processor and a transceiver, the transceiver being used to send and receive information, and the processor being used to enable the communication device to implement the method as described in any one of claims 1-18.
23. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program or computer instructions that are executed by a processor to implement the method as described in any one of claims 1-18.
24. A computer program product, characterized in that, The computer program product includes computer program code or computer instructions, which, when executed, implement the method described in any one of claims 1-18.