Communication method and device, equipment and storage medium

By generating unique keys for different satellites and performing secure authentication, the problem of secure access when the inter-satellite feeder link is unavailable is solved, enabling secure communication and efficient access of terminal devices in non-terrestrial networks.

CN121815264APending Publication Date: 2026-04-07HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-10-05
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

In non-terrestrial network communication scenarios, when the power supply links between satellites, terminal devices, and terrestrial networks are intermittently unavailable, how can we ensure that terminal devices can securely access the network and conduct secure communication? In particular, in store-and-forward service scenarios, how can we achieve secure isolation and key management between different satellites?

Method used

Unique keys are generated for different satellites through mobility management network elements in the terrestrial network to establish a secure connection between terminal devices and the network. These keys are used to isolate different satellites and ensure secure access to services. Specific steps include generating and distributing a second key, using an initial authentication vector and subscription data to achieve secure isolation between satellites, and using globally unique temporary identifiers and key identifiers for authentication and data exchange.

Benefits of technology

It improves the success rate of terminal equipment accessing the core network, reduces access latency, ensures communication security and efficiency, and avoids key leakage and reuse issues.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121815264A_ABST
    Figure CN121815264A_ABST
Patent Text Reader

Abstract

The invention provides a communication method and device, equipment and a storage medium. In the method, a first mobile management network element deployed in a ground network generates a second key for a first satellite based on a first key, and sends the second key to a mobile management network element deployed on the first satellite, so that the mobile management network element in the first satellite provides an access service for a terminal device based on the second key, wherein the first secret key is a secret key which is received by the first mobile management network element from the home subscriber service network element and aims at the terminal equipment, and on the basis, different secret keys are provided for different satellites, so that the security isolation between the different satellites is realized, and the security connection between the terminal equipment and the network is established.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a communication method, apparatus, device, and storage medium. Background Technology

[0002] In areas such as deserts, oceans, and remote regions where terrestrial networks cannot be deployed due to economic or environmental factors, the 3rd Generation Partnership Project (3GPP) proposed a communication architecture based on non-terrestrial networks (NTN) to provide better network coverage. NTN communication can utilize satellites for networking to provide network coverage for terminal devices. In NTN communication scenarios, satellites may not be able to simultaneously transmit data with both terminal devices and terrestrial network equipment. In this case, the satellite needs to provide store-and-forward (S&F) services. In the store-and-forward scenario, when the service link is available (i.e., when the satellite and terminal device can transmit data), the satellite receives and stores the data from the terminal device. Then, as the satellite moves, when it can transmit data with the terrestrial network, the satellite sends the stored data back to the terrestrial network. Alternatively, when the feed link is available (i.e., when the satellite and terrestrial network can communicate), the satellite receives and stores the data from the terrestrial network. Then, as the satellite moves, when it can communicate with the terminal device, the satellite sends the stored data back to the terminal device.

[0003] For S&F services, 3GPP defines a separated Mobility Management Entity (MME) architecture. In this architecture, the MME is split into MME-onboard and MME-ground. The access network and MME-onboard are deployed on satellite, while the MME-ground and other core network elements are deployed on the ground. The MME-onboard and MME-ground can communicate and interact via a radio connection. In this separated MME architecture based on S&F services, ensuring secure network access and communication for terminal devices is a problem that needs to be addressed due to the intermittent unavailability of the power supply link. Summary of the Invention

[0004] This application provides a communication method, apparatus, device, and storage medium to enable terminal devices to access the network for secure communication.

[0005] Firstly, embodiments of this application provide a communication method. The executing entity of this method may be a first mobility management network element in a terrestrial network, or a component configured in the mobility management network element (such as a chip, chip system, processor, etc.), or a logic module or software capable of implementing all or part of the functions of the mobility management network element. For ease of understanding, the following description uses the first mobility management network element as the executing entity.

[0006] In this method, a first mobility management network element deployed in the terrestrial network generates a second key for a first satellite based on a first key, and sends the second key to a mobility management network element deployed on the first satellite, so that the mobility management network element in the first satellite provides access services to the terminal device based on the second key. The first key is a key for the terminal device received by the first mobility management network element from the home subscriber service network element. Based on this, different keys are provided for different satellites, thereby achieving secure isolation between different satellites and establishing a secure connection between the terminal device and the network.

[0007] For example, before generating a second key for the first satellite based on the first key, the first Mobility Management Network (MMN) receives the identifier of the terminal device from the MMN on the initial satellite. In this case, when the first MMN determines that authentication of the terminal device is required, it sends an authentication data request to the Home Subscriber Service (NSS) element. The authentication data request includes the identifier of the terminal device. The first MMN then receives an authentication data response from the NSS element. The authentication data response includes an initial authentication vector for authenticating the terminal device. The initial authentication vector includes a random challenge (RAND), an authentication token (AUTN), an expected response (XRES), and the first key. Based on this, the first MMN obtains the first key from the NSS element to establish a secure connection between the terminal device and the network in a Security & Free (S&F) scenario.

[0008] For example, the first mobility management network element determines the second satellite as a candidate satellite for providing subsequent access services to the terminal device, and sends an initial authentication vector to the mobility management network element in the second satellite. The first mobility management network element provides different keys to the first and second satellites, thereby achieving key isolation between satellites. Furthermore, the first mobility management network element can send authentication vectors and subscription data to multiple candidate satellites of the terminal device, so that one of the satellites (such as the second satellite) can interact with the terminal device to complete the terminal device's access to the core network. The first key for the authentication vector of each candidate satellite is different. This method can improve the success rate of the terminal device accessing the core network or reduce the access latency.

[0009] For example, the authentication data request also includes instruction information related to S&F operations, and the authentication data response also includes subscription data related to S&F operations. The initial authentication vector is carried in a message sent by the first mobility management network element to the mobility management network element in the second satellite. This message also includes the subscription data related to S&F operations and a key identifier; the key identifier is used to identify the second key. The authentication vector, subscription data, and key identifier are simultaneously carried in the message sent by the first mobility management network element to the mobility management network element in the second satellite, so that the mobility management network element in the second satellite can authenticate the terminal device based on this message and establish a secure connection, thereby providing secure access services to the terminal device.

[0010] For example, the message also includes a globally unique temporary identity (GUTI), which allows the mobility management network element in the second satellite to configure the GUTI to the terminal device after authentication is successful.

[0011] For example, the authentication data request carries information indicating the acquisition of subscription data. The authentication data request simultaneously indicates the acquisition of authentication vector and subscription data, which reduces the number of interactions between the first mobility management network element and the home user service network element and improves communication efficiency.

[0012] For example, the authentication data request carries information indicating a satellite identifier used to determine the second key, and / or, the authentication data request carries information indicating the number of authentication vectors. This satellite identifier and / or the number of authentication vectors can implicitly indicate the acquisition of contractual data, thereby reducing signaling overhead.

[0013] For example, the first mobility management network element and the mobility management network element in the first satellite belong to different security domains or trust domains. That is, when the first mobility management network element is in a different security domain or trust domain than the first satellite, it sends a second key to the mobility management network element in the first satellite to achieve secure access for the terminal device. However, when it belongs to the same security domain or trust domain as the mobility management network element in the first satellite, the second key does not need to be derived; for example, the authentication process can be implemented based on any currently available implementation scheme. Similarly, when the first mobility management network element sends the corresponding second key to other candidate serving satellites, it can first determine whether the satellite belongs to a different security domain than the first mobility management network element.

[0014] For example, before sending the second key to the mobile management network element in the first satellite, the first mobile management network element may also receive an indication message from the mobile management network element in the second satellite. This indication message indicates that the authentication of the terminal device is successful, so that the first mobile management network element determines that the terminal device accesses the network through the access service provided by the second satellite. Then, it synchronizes the second key for the first satellite to the mobile management network element in the first satellite, thereby achieving key isolation between the first satellite and the second satellite, ensuring the security of the terminal device communicating through different satellites, and preventing key stream reuse.

[0015] For example, the indication information is also used to indicate the authentication vector corresponding to the second key, and then the first mobility management network element can delete the authentication vector corresponding to the first key to ensure the freshness of the authentication vector.

[0016] Optionally, the initial satellite and the second satellite may be different satellites or the same satellite; this application does not limit this.

[0017] Optionally, the first and second satellites can be different satellites to enable access services with satellite handover.

[0018] For example, the first mobility management network element can send a derived authentication vector to the mobility management network element in the first satellite. This derived authentication vector includes RAND, AUTN, XRES, and a second key. This prevents the first key from being leaked to the first satellite, thus enabling secure access for the terminal device.

[0019] Optionally, the initial satellite and the first satellite may be different satellites or the same satellite; this application does not limit this.

[0020] For example, the first mobility management network element can use a first key and first input parameters to generate a second key; wherein the first input parameters include one or more of the following: the identifier of the first satellite, the identifier of the mobility management network element in the first satellite, or a key identifier; wherein the key identifier is used to identify the second key. This enables the generation of different second keys for different satellites, achieving key isolation between satellites.

[0021] For example, the first key is the root key K shared between the terminal device and the first mobility management network element. ASME Therefore, in this embodiment, the second key sent by the first mobility management network element to the mobility management network element in the satellite is derived from the root key, thereby avoiding the leakage of the root key and ensuring that the terminal device can securely access the network.

[0022] Secondly, embodiments of this application provide a communication method. The executing entity of this method may be a terminal device, or a component configured in the terminal device (such as a chip, chip system, processor, etc.), or something capable of implementing all or part of the functions or software of the terminal device. For ease of understanding, the following description uses a terminal device as the executing entity.

[0023] In this method, during the process of connecting to a mobility management network element in a first satellite, the terminal device generates a second key for the first satellite based on a first key; wherein the first key is a key generated during the process of the terminal device attaching to a mobility management network element in the second satellite; and generates a Non-Access Stratum (NAS) key based on the second key, the NAS key being used to protect messages between the terminal device and the mobility management network element in the first satellite; wherein the NAS key includes a NAS encryption key and a NAS integrity protection key. Optionally, the terminal device generates the second key for the first satellite before connecting to the first satellite, and generates the NAS key based on the second key during the process of connecting to the mobility management network element in the first satellite.

[0024] For example, a terminal device can receive a first NAS message from a mobility management network element in a first satellite, the first NAS message indicating the establishment of a secure connection; the first NAS message includes a NAS integrity protection algorithm and a NAS encryption algorithm; and generates a NAS integrity protection key based on a second key and the NAS integrity protection algorithm, and generates a NAS encryption key based on the second key and the NAS encryption algorithm; the method further includes: the terminal device verifying the integrity of the first NAS message based on the NAS integrity protection key and the NAS integrity protection algorithm, and if the integrity verification passes, sending a second NAS message to the mobility management network element of the first satellite, the second NAS message responding to the indication to establish a secure connection. For example, the first NAS message can be a secure mode command message, and the second NAS message can be a secure mode completion message.

[0025] For example, the first NAS message also includes a key identifier, wherein the key identifier is used to identify the second key; the terminal device can generate the second key based on the first key and the key identifier.

[0026] For example, the first NAS message also includes the identifier of the mobility management network element of the second satellite; the terminal device can generate a second key for the first satellite based on the first key and the identifier of the mobility management network element of the first satellite.

[0027] For example, the terminal device can receive a broadcast message, which includes the identifier of the first satellite; and generate a second key for the first satellite based on the first key and the identifier of the first satellite.

[0028] For example, the method further includes: the terminal device storing the correspondence between the NAS key and the first satellite.

[0029] For example, the method further includes: when communicating with the mobility management network element in the first satellite again after leaving the first satellite, the terminal device uses the stored NAS key to communicate with the mobility management network element in the first satellite.

[0030] For example, the first satellite and the second satellite may be the same satellite or different satellites.

[0031] For example, the first key is the root key K shared between the terminal device and the first mobility management network element. ASME .

[0032] Thirdly, embodiments of this application provide a communication method. The executing entity of this method may be a mobility management network element in a first satellite, or a component configured in the mobility management network element (such as a chip, chip system, processor, etc.), or a logic module or software capable of implementing all or part of the functions of the mobility management network element. For ease of understanding, the following description uses the mobility management network element in the first satellite as the executing entity.

[0033] In one implementation of this method, a mobility management network element in the first satellite receives a second key from the first mobility management network element. This second key is a key for the first satellite generated based on the first key. The first key is a key for the terminal device received by the first mobility management network element from the home subscriber service network element. The first satellite is a candidate satellite for subsequently providing access services to the terminal device. The mobility management network element in the first satellite generates a NAS key based on the second key. This NAS key is used to protect messages between the terminal device and the mobility management network element in the first satellite. The NAS key includes a NAS encryption key and a NAS integrity protection key.

[0034] For example, the mobility management network element in the first satellite generates a NAS encryption key based on a second key and a NAS encryption algorithm, and generates a NAS integrity protection key based on the second key and a NAS integrity protection algorithm; and sends a first NAS message protected by the NAS encryption key and the NAS integrity protection key to the terminal device. The first NAS message is used to indicate the establishment of a secure connection. The first NAS message includes the NAS integrity protection algorithm and the NAS encryption algorithm; then it receives a second NAS message from the terminal device, which is used to indicate the establishment of a secure connection accordingly; finally, the mobility management network element of the first satellite verifies the integrity of the second NAS message based on the NAS integrity protection key and the NAS integrity protection algorithm, thereby completing the establishment of the secure mode.

[0035] In another implementation of the method, the mobility management network element in the first satellite receives a NAS key from the first mobility management network element. The NAS key is generated based on a second key for the first satellite. The second key is generated based on the first key for the first satellite. The first key is a key for the terminal device received by the first mobility management network element from the home subscriber service network element. The first satellite is a candidate satellite for providing access services to the terminal device.

[0036] For example, the mobility management network element in the first satellite sends a first NAS message protected by a NAS encryption key and a NAS integrity protection key to the terminal device. The first NAS message is used to indicate the establishment of a secure connection and includes a NAS integrity protection algorithm and a NAS encryption algorithm. Then, it receives a second NAS message from the terminal device, which is used to indicate the establishment of a secure connection. Finally, the mobility management network element of the first satellite verifies the integrity of the second NAS message according to the NAS integrity protection key and the NAS integrity protection algorithm, thereby completing the establishment of the secure mode.

[0037] For example, the mobility management network element of the first satellite can store the correspondence between NAS keys and terminal devices.

[0038] For example, when a terminal device leaves the first satellite and then communicates with the mobility management network element in the first satellite again, the mobility management network element of the first satellite can use the stored NAS key to protect the messages between the terminal device and the terminal device.

[0039] Optionally, the first and second satellites can be the same satellite or different satellites.

[0040] For example, the first key is the root key K shared between the terminal device and the first mobility management network element. ASME .

[0041] Fourthly, embodiments of this application provide a communication method. The executing entity of this method may be a Home Subscriber Service (NSS) element, or a component configured in the NSS element (such as a chip, chip system, processor, etc.), or a logic module or software capable of implementing all or part of the functions of the NSS element. For ease of understanding, the following description uses the NSS element as the executing entity as an example.

[0042] In one implementation of this method, the Home Subscriber Service (NSS) element can receive an authentication data request from a first Mobility Management (MLM) element, the authentication data request including the identifier of the terminal device; and send an authentication data response to the first MLM element, the authentication data response including an initial authentication vector for authenticating the terminal device, the initial authentication vector including RAND, AUTN, XRES and a first key, the first key being a key for the terminal device received by the first MLM element from the NSS element.

[0043] In another implementation of this method, the Home Subscriber Service (NAS) element can receive an authentication data request from the first Mobility Management (MLM) element, the authentication data request including the identifier of the terminal device and a first input parameter; and send an authentication data response to the first MLM element, the authentication data response including a deduced authentication vector for authenticating the terminal device, the deduced authentication vector including RAND, AUTN, XRES and a second key, the second key being a key generated for the first satellite based on the first key.

[0044] For example, the authentication data request carries information indicating that the subscription data is to be obtained, and the authentication data response accordingly also includes the subscription data of the terminal device.

[0045] For example, the authentication data request carries information indicating the satellite identifier and / or information indicating the number of authentication vectors to be obtained.

[0046] For example, information indicating satellite identifiers and / or information indicating the number of authentication vectors to be obtained carried in the authentication data request can be used to implicitly indicate the acquisition of contractual data.

[0047] Fifthly, embodiments of this application provide a communication device, including: a module for performing methods such as those described in the first aspect, second aspect, third aspect, fourth aspect, or various possible implementations.

[0048] In a sixth aspect, embodiments of this application provide a communication device, including: a processor, configured to execute the methods described in the first, second, third, and fourth aspects or various possible implementations above by running a computer program or by using logic circuits.

[0049] In one possible implementation, the communication device further includes a memory for storing the computer program.

[0050] In one possible implementation, the communication device further includes a communication interface for inputting and / or outputting signals.

[0051] In a seventh aspect, embodiments of this application provide a chip, including: a processor, configured to retrieve and execute computer instructions from a memory, causing a device on which the chip is mounted to perform methods as described in the first aspect, second aspect, third aspect, fourth aspect, or various possible implementations.

[0052] Eighthly, embodiments of this application provide a computer-readable storage medium for storing computer program instructions that cause a computer to perform methods as described in the first, second, third, fourth, or various possible implementations.

[0053] Ninthly, embodiments of this application provide a computer program that causes a computer to perform the methods described in the first, second, third, and fourth aspects or various possible implementations above.

[0054] In a tenth aspect, embodiments of this application provide a computer program product including computer program instructions that cause a computer to perform methods as described in the first aspect, second aspect, third aspect, fourth aspect, or various possible implementations.

[0055] The beneficial effects of the contents of the second to tenth aspects and their various possible implementations can be found in the first aspect and the beneficial effects of their various possible implementations, and will not be repeated here. Attached Figure Description

[0056] Figure 1 A schematic diagram of an NTN network architecture is shown.

[0057] Figure 2 This is a schematic diagram of the network architecture of the split MME in the Evolved Packet System network provided in this application embodiment;

[0058] Figure 3 This application provides a schematic diagram of a communication link in an NTN scenario.

[0059] Figure 4 This is a schematic diagram illustrating the process of a terminal device accessing the core network according to an embodiment of this application;

[0060] Figure 5 This is a schematic diagram illustrating the process of a terminal device accessing the core network according to an embodiment of this application;

[0061] Figure 6 This is a schematic flowchart illustrating a communication method provided in an embodiment of this application;

[0062] Figure 7 This is a flowchart illustrating another communication method provided in an embodiment of this application;

[0063] Figure 8 This is a flowchart illustrating another communication method provided in an embodiment of this application;

[0064] Figure 9a This is a flowchart illustrating another communication method provided in an embodiment of this application;

[0065] Figure 9b This is a flowchart illustrating another communication method provided in an embodiment of this application;

[0066] Figure 10 This is a schematic diagram of a key generation method provided in an embodiment of this application;

[0067] Figure 11 This is a flowchart illustrating another communication method provided in an embodiment of this application;

[0068] Figure 12 This is a schematic block diagram of the communication device provided in the embodiments of this application;

[0069] Figure 13 This is another schematic block diagram of the communication device provided in the embodiments of this application. Detailed Implementation

[0070] The technical solutions in this application will now be described with reference to the accompanying drawings.

[0071] Figure 1 A schematic diagram of a non-terrestrial network (NTN) architecture is shown. Figure 1 As shown, the NTN network architecture can be divided into different architectures depending on the nodes deployed on the satellite. Taking the splitMME EPS architecture as an example, it can include terminal equipment, satellites with base stations and MME-onboards, ground stations, and a core network containing MME-ground. Terminal equipment accesses the core network through base stations deployed on satellites, MME-onboards, and ground stations deployed on the ground. The ground station can also be called a gateway station.

[0072] In such Figure 1 In the network architecture shown, the link between the terminal device and the satellite can be called a service link or business link, and the link between the satellite and the ground station can be called a feeder link or power supply link.

[0073] In the embodiments of this application, the terminal device may also be referred to as user equipment (UE), access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent, or user apparatus.

[0074] Terminal devices can be devices that provide voice / data, such as handheld devices with wireless connectivity, in-vehicle devices, etc. Currently, examples of terminals include: mobile phones, tablets, laptops, PDAs, mobile internet devices (MIDs), wearable devices, virtual reality (VR) devices, augmented reality (AR) devices, wireless terminals in industrial control, wireless terminals in self-driving, wireless terminals in remote medical surgery, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes, cellular phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs), handheld devices with wireless communication capabilities, computing devices or other processing devices connected to a wireless modem, wearable devices, terminal devices in 5G networks, or future public land mobile communication networks. Terminal devices in a network (PLMN), etc., are not limited to this in the embodiments of this application.

[0075] By way of example and not limitation, in this embodiment, the terminal device can also be a wearable device. Wearable devices, also known as wearable smart devices, are a general term for devices that utilize wearable technology to intelligently design and develop everyday wearables, such as glasses, gloves, watches, clothing, and shoes. Wearable devices are portable devices that are worn directly on the body or integrated into the user's clothing or accessories. Wearable devices are not merely hardware devices, but also achieve powerful functions through software support, data interaction, and cloud interaction. Broadly speaking, wearable smart devices include those that are feature-rich, large in size, and can achieve complete or partial functions without relying on a smartphone, such as smartwatches or smart glasses, as well as those that focus on a specific type of application function and require the use of other devices such as smartphones, such as various smart bracelets and smart jewelry for vital sign monitoring.

[0076] In this embodiment, the device for implementing the functions of the terminal device can be the terminal device itself, or it can be any device capable of supporting the terminal device in implementing those functions, such as a chip system. This device can be installed in or used in conjunction with the terminal device. In this embodiment, the chip system can be composed of chips or may include chips and other discrete components. This embodiment only uses the terminal device as an example to illustrate the device for implementing the functions of the terminal device, and does not constitute a limitation on the solution of this embodiment.

[0077] The base station in this application embodiment can be a device used for communicating with terminal devices. This base station can also be referred to as an access network device or a radio access network device. In this application embodiment, the base station can refer to a radio access network (RAN) node (or device) that connects the terminal device to the wireless network. A base station can broadly encompass, or be replaced by, various names including: NodeB, evolved NodeB (eNB), next-generation NodeB (gNB), relay station, access point, transmitting and receiving point (TRP), transmitting point (TP), master station, auxiliary station, multi-standard radio (MSR) node, home base station, network controller, access node, wireless node, access point (AP), transmission node, transceiver node, baseband unit (BBU), remote radio unit (RRU), active antenna unit (AAU), remote radio head (RRH), central unit (CU), distributed unit (DU), radio unit (RU), positioning node, etc. A base station can be a macro base station, micro base station, relay node, donor node, or similar entities, or combinations thereof. A base station can also refer to a communication module, modem, or chip installed within the aforementioned equipment or apparatus. A base station can also be a mobile switching center, equipment performing base station functions in D2D, V2X, and M2M communications, network-side equipment in 6G networks, and equipment performing base station functions in future communication systems. A base station can support networks using the same or different access technologies. Optionally, a RAN node can also be a server, wearable device, vehicle, or in-vehicle equipment. For example, the access network equipment in vehicle-to-everything (V2X) technology can be a roadside unit (RSU). The embodiments of this application do not limit the specific technologies or equipment forms used in the network equipment.In some deployments, the network devices mentioned in the embodiments of this application may be devices including CU, DU, or CU and DU, or devices with control plane CU nodes (central unit-control plane (CU-CP)) and user plane CU nodes (central unit-user plane (CU-UP)) and DU nodes. For example, the network devices may include gNB-CU-CP, gNB-CU-UP, and gNB-DU.

[0078] In some deployments, multiple RAN nodes collaborate to assist terminals in achieving wireless access, with different RAN nodes each implementing some of the base station's functions. For example, RAN nodes can be CUs, DUs, CU-CPs, CU-UPs, or RUs. CUs and DUs can be configured separately or included in the same network element, such as a BBU. RUs can be included in radio frequency equipment or radio frequency units, such as RRUs, AAUs, or RRHs.

[0079] RAN nodes can support one or more types of fronthaul interfaces, each corresponding to a DU and RU with different functions. If the fronthaul interface between the DU and RU is a common public radio interface (CPRI), the DU is configured to implement one or more baseband functions, and the RU is configured to implement one or more radio frequency functions. If the fronthaul interface between the DU and RU is another type of interface, relative to CPRI, some downlink and / or uplink baseband functions, such as, for downlink, precoding, digital beamforming (BF), or one or more of inverse fast Fourier transform (IFFT) / cyclic prefix addition (CP), are moved from the DU to the RU; and for uplink, digital beamforming (BF), or one or more of fast Fourier transform (FFT) / cyclic prefix removal (CP), are moved from the DU to the RU. In one possible implementation, the interface can be an enhanced common public radio interface (eCPRI). Under the eCPRI architecture, the segmentation between DU and RU differs, corresponding to different categories (Cat) of eCPRI, such as eCPRI Cat A, B, C, D, E, F.

[0080] In one possible design, the processing unit in the BBU used to implement baseband functions is called the baseband high (BBH) unit, and the processing unit in the RRU / AAU / RRH used to implement baseband functions is called the baseband low (BBL) unit.

[0081] In different systems, CU (or CU-CP and CU-UP), DU, or RU may have different names, but those skilled in the art will understand their meaning. For example, in an ORAN system, CU can also be called O-CU (open CU), DU can also be called O-DU, CU-CP can also be called O-CU-CP, CU-UP can also be called O-CU-UP, and RU can also be called O-RU. Any of the units among CU (or CU-CP, CU-UP), DU, and RU in this application can be implemented through software modules, hardware modules, or a combination of software modules and hardware modules.

[0082] In this embodiment, the device used to implement the function of a base station can be a base station itself; it can also be a device capable of supporting the base station in implementing this function, such as a chip system, hardware circuit, software module, or hardware circuit plus software module. This device can be installed in a base station or used in conjunction with a base station. This embodiment only uses a base station as an example for illustration and does not constitute a limitation on the solution of this embodiment.

[0083] Figure 2 This is a schematic diagram of the network architecture of the split MME in the Evolved Packet System (EPS) network provided in this application embodiment. Figure 2As shown, the network architecture of a split MME includes terminal equipment, n satellites (e.g., satellite 1 to satellite n), and a core network. Each satellite is equipped with: a radio access network, such as the evolved universal terrestrial radio access network (E-UTRAN), and an onboard MME (e.g., MME-onboard, or simply satellite-based MME). The core network deploys multiple network elements, including: MMEs (such as MME-ground, or simply terrestrial MMEs) in the terrestrial network, Serving Gateway (SGW), Home Subscriber Server (HSS), Short Message Service Gateway (SMS-GMSC), Interworking Mobile Switching Center (IW MSC), SMS Router, Interworking Function (IWF), Service Capability Exposure Function (SCEF), Policy and Charging Rules Function (PCRF), Packet Data Network Gateway (PGW), Data Network (DN), and Cellular Internet of Things (CLOT) services. Information exchange between the satellite and the core network can occur through ground stations. For example, after receiving signals from the satellite, the ground station can perform protocol conversion and signal modulation to ensure that data from the satellite can be successfully transmitted to network elements in the core network, such as the terrestrial MME.

[0084] See Figure 2 The link between MME-onboard and MME-ground is the feeder link. The link between the terminal equipment and E-UTRAN is the service link.

[0085] The MME-onboard processes signaling and / or data transmitted on the S1 interface between the MME and E-UTRAN, as well as non-access stratum (NAS) signaling and / or data received from the terminal equipment via the onboard E-UTRAN, or NAS signaling and / or data sent to the terminal equipment via the onboard E-UTRAN.

[0086] MME-ground processes signaling and / or data transmitted over interfaces with other core network functions (e.g., S6a to HSS, SGd to SMS-GMSC / IWMSC / SMS routers, T6a to SCEF, T6ai to IWF-SCEF, and S11 to SGW). One MME-ground can be associated with one or more MME-onboards.

[0087] The above description of the various network elements in the NTN network and the interfaces between them is merely illustrative and should not constitute any limitation on this application. Furthermore, Figure 2 The network elements shown can be independent devices or integrated into the same device to perform different functions. This application does not limit the specific form of the network elements. Network elements used in future communication systems that have the same or similar functions as the network elements described above are all within the scope of protection of this application.

[0088] Understandably, in the NTN network architecture, the movement of serving satellites may result in the service link being connected but the feeder link being disconnected; or the feeder link being connected but the service link being disconnected. For example... Figure 3 As shown, at time T1, when the satellite moves to position 1, the service link is connected, but the feeder link is not connected; at time T2, when the satellite moves to position 2, both the service link and the feeder link are not connected; at time T3, when the satellite moves to position 3, the feeder link is connected, but the service link is not connected. In other words, in an NTN network, the satellite's service link and / or feeder link may not be available at all times.

[0089] In scenarios where the feeder link of a serving satellite is not continuously connected, 3GPP Release 19 introduced a Satellite & Flight (S&F) operation, which provides communication services to terminal devices during periods and / or physical areas when the serving satellite is not simultaneously connected to the terrestrial network. The mode in which terminal devices, radio access network elements, and core network elements perform S&F operations can be referred to as S&F mode.

[0090] In S&F satellite operations, end-to-end switching of signaling / data traffic is handled as a combination of two or more time-discontinuous steps. First, signaling / data exchange occurs between the terminal equipment and the satellite, but at this point the satellite is not connected to the ground network via a feeder link. Next, the satellite moves and establishes a connection with the ground network, communication takes place between the satellite and the ground network, and the end-to-end switching is completed.

[0091] For ease of description, the term "base station" will be used to refer to base stations / access devices deployed on satellites. In other words, the base station mentioned below specifically refers to base stations / access devices deployed on satellites.

[0092] After a terminal device initiates the core network access process, in an MME split architecture based on S&F services, due to intermittent unavailability of the feeder link, the MME-ground needs to synchronize the communication context with the MME-onboard of the serving satellite during the terminal device's access to the core network. Since the terminal device can access the network and transmit data through different serving satellites' MME-onboards at different times, in this scenario, the MME-ground needs to synchronize the terminal device's context with the MME-onboards of different serving satellites in advance. Using the same security context on different MME-onboards can lead to key stream reuse issues. Therefore, ensuring secure data transmission between the terminal device and different satellites is a problem that needs to be solved in this situation.

[0093] It should be noted that, for ease of description, the interaction between the terminal device and the MME via the base station can be described as the interaction between the terminal device and the MME. For example, if the terminal device sends information to the MME-onboard via the base station, it can be described as the terminal device sending information to the MME-onboard; and if the MME-onboard sends information to the terminal device via the base station, it can be described as the MME-onboard sending information to the terminal device.

[0094] In this embodiment, the terms "first," "second," etc., distinguish between identical or similar items with essentially the same function and purpose, without limiting their order or quantity. Furthermore, the terms "first" and "second" are not necessarily different. In this embodiment, "first," "second," etc., can also distinguish between different keys, messages, indication information, network elements, requests, etc., as mentioned below.

[0095] In this application embodiment, "at least one" may include one or more, and "multiple" in this application embodiment includes two or more.

[0096] The communication method provided in this application is described below with reference to the accompanying drawings. MME-ground achieves secure isolation between different satellites by providing different keys for different satellites, thereby establishing a secure connection between terminal devices and the network.

[0097] Before describing the communication method provided in this application in detail, the following will first combine... Figure 4 and Figure 5 This document provides a detailed explanation of the process by which terminal devices access the core network, also known as the terminal device network access process.

[0098] Figure 4 This is a schematic diagram illustrating the process of a terminal device accessing the core network according to an embodiment of this application. Figure 4 The method shown includes S410 to S440. The details are as follows. Figure 4 Each step in the process.

[0099] S410: When a terminal device joins the network, it first performs a cell search and selection.

[0100] Optionally, cell search involves the terminal device detecting broadcast messages from the base station. These broadcast messages may include the Physical Cell Identifier (PCI), Master Information Block (MIB), and System Information Block / System Information Broadcast. The PCI is used to determine the cell, and one or more of the PCI, MIB, and System Information Block / System Information Broadcast are necessary information for the terminal device to camp on the cell and initiate initial access.

[0101] After the cell search is completed, the terminal device selects the cell and achieves downlink synchronization with the cell.

[0102] For NTN scenarios, the terminal device can perceive network information through the aforementioned broadcast messages, such as network support for S&F satellite operation and the identification of the satellite where the base station is located.

[0103] S420, the terminal device executes the random access procedure.

[0104] The random access procedure is used for the terminal device to achieve uplink synchronization with the cell.

[0105] For example, in this process, the base station will allocate uplink resources to the terminal device for sending an RRC Setup Request. The terminal device can only initiate uplink transmission after obtaining the uplink resources.

[0106] S430: After the terminal device successfully accesses the base station, it establishes an RRC connection with the base station.

[0107] For example, the terminal device sends an RRC Setup Request to the base station on the signaling radio bearer (SRB) 0 (SRB0); after receiving the RRC Setup Request, the base station sends an RRC Setup to the terminal device, which carries detailed information about the SRB1 resource configuration; after receiving the RRC Setup, the terminal device sends an RRC Setup Complete to the base station to indicate that the terminal device and the base station have successfully established an RRC connection.

[0108] SRB0 does not need to be established and is always present. SRB0 is used to carry RRC signaling before the RRC connection is successfully established and is transmitted through the common control channel (CCCH).

[0109] SRB1 carries RRC signaling after a successful RRC connection establishment and non-access stratum (NAS) signaling before SRB2 is established, transmitted via a dedicated control channel (DCCH). SRB2 carries NAS signaling, transmitted via the DCCH logical channel. SRB2 has lower priority than SRB1 and can only be established after security mode is activated. SRB2 is established via RRC reconfiguration. NAS signaling is the signaling used for information transmission between terminal equipment and core network elements; the base station is only responsible for forwarding it. This signaling occurs above the RRC layer, meaning it only happens after a successful RRC connection establishment.

[0110] That is, the purpose of establishing an RRC connection is to establish SRB1, and then transmit the RRC signaling after the RRC connection is successfully established through SRB1.

[0111] After an RRC connection is successfully established, both the terminal device and the base station will save an RRC context, including the terminal device's identifier, such as the cell radio network temporary identifier (C-RNTI) and SRB resource information.

[0112] Steps 410 to 430 can also be referred to as the process of terminal equipment accessing the base station. That is, the process of terminal equipment accessing the base station includes: cell selection, random access, and establishment of RRC connection.

[0113] S440: The terminal device establishes a connection with the core network to access the core network.

[0114] For example, the process of establishing a connection between the terminal device and the core network is as follows: Figure 5 As shown. In 4G, the process of establishing a connection between a terminal device and the core network is also called the attach process, while in 5G, it is also called the registration process. The embodiments of this application can be applied to the attach process in 4G and the registration process in 5G, as well as other named access processes in future communication systems. Figure 5 The attachment process implemented in 4G will be used as an example for explanation.

[0115] like Figure 5 As shown, the process of establishing a connection between the terminal equipment and the core network includes S510 to S570.

[0116] At time T1, the service link between the terminal equipment and the satellite is available, but the feeder link between the satellite and the ground core network is unavailable.

[0117] In step S510, the terminal device sends a first attach request to the MME-onboard to request access to the core network. This first attach request can be an initial attach request or an initial access request. Optionally, the attach request information may include: International Mobile Subscriber Identity (IMSI), Security and Freedom (S&F) capability information, and / or the terminal device's security capabilities. The S&F capability information may indicate whether the terminal device has S&F capabilities, or whether the terminal device supports S&F operations; or, the S&F capability information may indicate that the terminal device has S&F capabilities, or that the terminal device supports S&F operations. In this case, the attach request information carries the S&F capability information if the terminal device has S&F capabilities. The terminal device's security capabilities are used to indicate the encryption algorithms and / or integrity protection algorithms supported by the terminal device.

[0118] The terminal device can determine to send a first attach request to the MME-onboard based on the broadcast message in S410, and include S&F capability information in the first attach request.

[0119] S520, MME-onboard sends first attachment response.

[0120] During the initial access process of the terminal device, there is no context for the terminal device on the MME-onboard, and the first attach response may specifically be an Attach Reject message. Optionally, based on the S&F capability information in the first attach request, the MME-onboard may include information such as an S&F wait timer and / or a listening list in the attach rejection message. The terminal device can initiate a new attach request after the S&F wait timer expires, but cannot initiate a new attach request before the S&F wait timer expires. The aforementioned listening list includes information on at least one NTN device that the terminal device can access, such as satellite identifiers, frequency bands, cell information, etc., which one or more terminal devices use to determine whether access is possible. After receiving an attach rejection message containing the listening list, the terminal device can perform listening operations as required to re-initiate the attach request or obtain other necessary network information at an appropriate time.

[0121] The S&F wait timer and listener list can be determined based on ephemeris information. Ephemeris information is information about the satellite's motion patterns, such as orbital parameters, angular velocity, and / or speed. Based on this information, the MME-onboard can calculate the satellite's position in its orbit at any given time. Ephemeris information can be represented as a simple correspondence, such as the satellite position information for each time / time period. Ephemeris information can also be represented as a satellite coverage map, such as satellite coverage availability information. A satellite coverage map divides the Earth's surface into multiple grid points and shows which grid points are covered and which are not covered by the satellite at any given time.

[0122] At time T2, the feeder link between the satellite and the ground core network is available, but the service link between the terminal equipment and the satellite is unavailable.

[0123] The S530 executes a process of obtaining authentication information and contract data between MME-onboard, MME-ground, and HSS.

[0124] S530 may include the following steps S531 to S536:

[0125] S531, the MME-onboard sends an attach request or trigger message to the MME-ground. The information carried in this attach request or trigger message can be obtained from the first attach request mentioned above, such as the terminal device's IMSI and / or S&F capability information. Alternatively, the attach request or trigger message is the first attach request mentioned above, meaning the MME-onboard forwards the first attach request received from the terminal device to the MME-ground. Optionally, the MME-onboard also sends the identifier of the network selected by the terminal device, such as the PLMN ID, to the MME-ground.

[0126] S532, MME-ground sends an authentication data request to HSS, which includes part or all of the terminal device's IMSI, serving network identity (SN ID), or network type.

[0127] S533, HSS sends an authentication data response to MME-ground. HSS obtains the authentication vector (AV) and sends an authentication data response carrying the AV to MME-ground.

[0128] Optionally, AV may include: RAND, AUTN, XRES, and the security management entity key K. ASME AV may also include: an encryption key (CK) and an integrity protection key (IK), where K... ASME It is the root key derived from CK / IK and the service network identifier.

[0129] S534, when the terminal device is in a communication scenario operating on the S&F satellite, the MME-ground sends an update location request to the HSS to update the terminal device's location in order to obtain the terminal device's subscription data.

[0130] Optionally, the location update request may include an indication that the location update is temporary, meaning that the HSS will not consider the terminal device as registered until it receives a final location update request.

[0131] S535, HSS sends an updated location response to MME-ground. This updated location response carries the subscription data of the terminal device.

[0132] S536, MME-ground sends a response message to MME-onboard, which may include the terminal device's IMSI, authentication information (such as AV), and subscription data.

[0133] At time T3, the service link between the terminal equipment and the satellite is available, but the feeder link between the satellite and the ground core network is unavailable.

[0134] S540, the terminal device sends a second attach request to the MME-onboard. This second attach request can carry the same information as the first attach request.

[0135] Optionally, after the aforementioned S&F timer expires, the terminal device may send an initial attach request to the MME-onboard to attempt to re-register with the network.

[0136] The S550 performs an authentication process between the terminal device and the MME-onboard.

[0137] Optionally, MME-onboard uses stored AV from MME-ground to authenticate or authorize terminal devices.

[0138] S550 may include the following steps S551 to S552:

[0139] S551, MME-onboard sends a user authentication request to the terminal device.

[0140] Optionally, the user authentication request may carry the RAND and AUTN from the above AV.

[0141] S552, the terminal device sends a user authentication response to the MME-onboard.

[0142] After receiving the RAND and AUTN, the terminal device checks the validity of the AUTN, including verifying whether the sequence number (SQN) is within an acceptable range. If the sequence number is out of range, it may indicate that the authentication token has expired or that a replay attack may be occurring. In this case, the terminal device will abandon the registration process and send an authentication failure message to the MME-onboard.

[0143] The terminal device can also use a stored key and a specific algorithm to verify certain information in the AUTN to validate the network's legitimacy. If the calculation result matches certain fields in the AUTN, the network is considered legitimate; otherwise, the terminal device will refuse authentication and send an authentication failure message to the MME-onboard.

[0144] When the terminal device deems the AUTN valid and the verification successful, it continues the identity authentication process, such as calculating a response value (RES) based on the received RAND and sending the RES to the MME-onboard. The RES can be carried in the aforementioned user authentication response. Further, after receiving the terminal device's RES, the MME-onboard compares it with the XRES in the AV. The XRES and RES are generated based on the same algorithm and input parameters. For example, the HSS is calculated based on the root key (e.g., K) shared between the terminal device and the network, using a specific algorithm to obtain the XRES; similarly, the terminal device calculates the RES based on the root key (e.g., K) shared with the network, using a specific algorithm. This application does not limit the algorithms used to generate XRES and RES, such as the MILENAGE algorithm specified by 3GPP for authentication and key generation in mobile communication networks. If XRES and RES match, identity authentication is successful; otherwise, authentication fails.

[0145] S553, the MME-onboard sends a security mode command with integrity protection to the terminal device. This security mode command negotiates the security algorithm and instructs the terminal device to activate security protection to safeguard subsequent communications. The security mode command may include, for example, security algorithm instructions and / or key identification information.

[0146] S554, the terminal device sends a secure mode response protected by integrity and encryption to the MME-onboard. Optionally, the secure mode response may include confirmation information, such as acknowledging successful receipt and processing of the secure mode command.

[0147] S560, MME-onboard sends a second attach response to the terminal device, such as attach accept.

[0148] The attachment acceptance information is used to instruct the core network side to accept the terminal device's network access request, or in other words, the core network side allows the terminal device to access the network.

[0149] Optionally, the second attachment response may also include the GUTI of the terminal device.

[0150] Understandably, after the terminal device receives the attach acceptance information sent by the MME-onboard, it replies with an initial access completion message to the MME through the base station. After the MME receives this message and performs actions such as configuring the bearer, the initial access process is completed.

[0151] In S&F satellite operations, S510 and S520 can be executed when the service link is connected, S530 can be executed when the feeder link is connected, and S540 to S560 can be executed when the service link is connected.

[0152] The communication method provided in this application is described in detail below.

[0153] Figure 6 This is a schematic flowchart of a communication method provided in an embodiment of this application. Figure 6 The explanation is based on the interaction between the terminal equipment, the mobility management network element in the first satellite, the first mobility management network element, and the home user service network element, and does not constitute any limitation on the subject of this application.

[0154] For example, Figure 6 The terminal equipment in the terminal equipment can be replaced with components configured in the terminal equipment (such as chips, chip systems, processors, etc.), or logical modules or software capable of realizing all or part of the functions of the terminal equipment; the mobility management network element (such as the mobility management network element in the first satellite or the first mobility management network element) can be replaced with components configured in the mobility management network element (such as chips, chip systems, processors, etc.), or logical modules or software capable of realizing all or part of the functions of the first mobility management network element; the home subscriber service network element can be replaced with components configured in the home subscriber service network element (such as chips, chip systems, processors, etc.), or logical modules or software capable of realizing all or part of the functions of the home subscriber service network element.

[0155] The first mobility management network element can be, for example, an MME deployed in the terrestrial network, such as MME-ground, and the mobility management network element in the first satellite can be, for example, an MME-onboard deployed in the first satellite. The first satellite can be a candidate satellite that provides access services to terminal devices.

[0156] Figure 6 The method shown includes S601 to S604, which are described in detail below. Figure 6 The steps of the method shown.

[0157] S601, the home subscriber service network element sends the first key to the first mobility management network element.

[0158] The first key can be any key synchronized between the first mobility management network element and the terminal device. For example, the first key can be the root key between the terminal device and the first mobility management network element, such as K. ASME K ASME The deduction method can be found in the explanation in the previous example, and will not be repeated here for the sake of brevity.

[0159] S602, the first mobility management network element generates a second key for the first satellite based on the first key.

[0160] S603, the first mobility management network element sends the second key to the mobility management network element in the first satellite.

[0161] To ensure the security of terminal devices communicating via different satellites, the first mobility management network element uses a first key, such as K. ASME Generate a second key for the first satellite, such as K. ASME* That is, K AMSE* =KDF{K ASME}, KDF is the key derivation function (KDF). This is then used to carry the second key K. ASME* The first message is sent to the mobile management network element in the first satellite, so that the mobile management network element in the first satellite is unaware of the first key, thereby achieving secure isolation of the communication key between satellites.

[0162] This application does not limit the algorithm for generating a second key for a first satellite based on a first key, nor does it limit the input parameters (such as the first input parameters) for generating the second key. For example, the first input parameters may include, but are not limited to, at least one of the following: the satellite identifier corresponding to the first satellite, the identifier of the mobility management network element in the first satellite, and a key identifier (such as the key set identifier for access security management entity, KSI). ASME This can be one or more of the following: )) or a fixed string. For example, the second key can satisfy: K AMSE* =KDF{K ASME The key identifier is defined as follows: ,SAT ID}, where SAT ID is the satellite identifier of the first satellite. The key identifier is used to identify the second key generated for the first satellite.

[0163] Optionally, the first mobility management network element can generate the aforementioned key identifier, such as KSI. ASME .

[0164] Optionally, the first mobility management network element can obtain the identifier of the mobility management network element or the satellite identifier of the first satellite by interacting with the mobility management network element in the first satellite. Alternatively, the first mobility management network element can determine the satellite identifier of the first satellite where the mobility management network element it is interacting with is located and / or the identifier of the mobility management network element in the first satellite based on pre-configured information.

[0165] S604, the mobility management network element and terminal equipment in the first satellite generate a NAS key, and protect the messages of the terminal equipment and the mobility management network element in the first satellite based on the NAS key.

[0166] For the mobility management network element in the first satellite, the NAS key can be generated based on the received second key. The NAS key is used to encrypt and / or protect the integrity of information transmitted between the terminal device and the mobility management network element in the first satellite, such as NAS signaling / data. For example, the NAS key may include an integrity protection key K. NASint and / or encryption key K NASenc Integrity protection key K NASint It can be used to protect the integrity of information transmitted between terminal equipment and mobility management network elements in the first satellite, with encryption key K. NASenc It can be used to encrypt and protect information transmitted between terminal devices and second mobile associated network elements.

[0167] This application does not limit the method of generating the NAS key. For example, you can refer to Appendix A.7 of 3GPP TS33.501, where the input of the NAS key is the root key K. ASME Replace with the first key K ASME* This yields the NAS key in this embodiment.

[0168] For the terminal device, it can deduce the second key and, based on the second key, deduce the NAS key. For example, the terminal device uses the same method as the first mobility management network element, such as the same deduction algorithm and the same input parameters, to deduce the second key from the first key. Further, the terminal device can use the same method as the mobility management network element in the first satellite, such as the same deduction algorithm and the same input parameters, to deduce the NAS key from the second key.

[0169] Optionally, the terminal device may generate a second key for the first satellite before connecting to the first satellite, and generate a NAS key based on the second key during the process of connecting to the mobility management network element in the first satellite.

[0170] For example, when the terminal device determines that it is in S&F mode, it generates the aforementioned NAS key. For example, the terminal device determines that it is in S&F mode based on S&F mode indication information received from a broadcast message from the first satellite, and thus derives the aforementioned NAS key. Optionally, the terminal device derives the aforementioned NAS key based on whether the accessed satellite and the home terrestrial network are in different security domains (or trust domains).

[0171] Based on this, the mobility management network element in the first satellite encrypts NAS messages sent to the terminal device using the NAS key, and decrypts NAS messages received from the terminal device using the NAS key. Correspondingly, the terminal device encrypts NAS messages sent to the first satellite using the NAS key, and decrypts NAS messages received from the first satellite using the NAS key. Thus, NAS key-protected communication transmission is achieved between the terminal device and the mobility management network element in the first satellite.

[0172] Furthermore, the terminal device can store the mapping between NAS security contexts and the first satellite. This mapping includes, for example, a SAT ID and the corresponding NAS security context for each SAT ID. The NAS security context may include, but is not limited to, at least one of the following: a NAS encryption key and an encryption algorithm; a NAS integrity protection key and an integrity protection algorithm; and a key identifier. That is, the terminal device can obtain the corresponding NAS key, algorithm, and other security information used to protect NAS messages based on the satellite identifier and the locally stored mapping. When the terminal device leaves the third satellite and reconnects to it, it can obtain the NAS key based on the third satellite's identifier and directly use this NAS key to protect NAS messages with the mobility management entity in the third satellite.

[0173] In this embodiment, when the service link is connected, the terminal device and the mobility management network element of the first satellite can transmit NAS messages protected by NAS keys.

[0174] For example, during the process of a terminal device accessing the core network, the terminal device and the mobility management network element in the first satellite can execute a NAS security mode command (SMC) process to activate NAS security. Relevant examples will be described below.

[0175] Optionally, in this embodiment of the application, the process of the terminal device accessing the core network may also include other related steps. For example, before S601, it may also include... Figure 5 S510 and S520 in the S510 and S520, and may also include S640 before that. Figure 5 The authentication process in S540 and S550 (such as interactive user authentication requests and user authentication responses) may further include S640 and beyond. Figure 5 S560 in the example. It should be noted that this application does not limit whether other related steps are performed or how they are implemented.

[0176] Based on the above process, after receiving the attach accept message, the terminal device can send an initial access completion message to the mobility management network element in the first satellite. The mobility management network element in the first satellite can forward the initial access completion message to the first mobility management network element, thereby completing the access process. In this embodiment, it can be the initial access process of the terminal device, or it can be the access process after the initial access, such as access caused by the switching of the serving satellite. This application does not limit it to this.

[0177] Optionally, after the terminal device completes the access process, it can send NAS data protected by the NAS key, such as NAS Protocol Data Unit (PDU), to the mobility management network element in the first satellite. The mobility management network element in the first satellite can verify the integrity of the NAS data based on the NAS key and decrypt the data packet.

[0178] Therefore, in this embodiment of the application, the first mobility management network element deployed in the terrestrial network generates a second key for the first satellite based on the first key, and sends the second key to the mobility management network element deployed on the first satellite, so that the mobility management network element in the first satellite provides access services to the terminal device based on the second key. The first key is a key for the terminal device received by the first mobility management network element from the home subscriber service network element. Based on this, different keys are provided for different satellites, thereby achieving secure isolation between different satellites and establishing a secure connection between the terminal device and the network.

[0179] Figure 7 This is a flowchart illustrating another communication method provided in an embodiment of this application. Figure 7 The explanation is based on the interaction between the terminal equipment, the mobility management network element in the initial satellite, the mobility management network element in the first satellite, the first mobility management network element, and the home user service network element, and does not constitute any limitation on the subject of this application.

[0180] It is understandable that the serving satellite of the terminal device may switch during the attach process. For example, the initial satellite may be the serving satellite when the terminal device initiates the attach request process, and the first satellite may be the serving satellite that interacts with the terminal device to complete authentication and access to the core network. Of course, the serving satellite of the terminal device may not switch during the attach process. In this case, the first satellite and the initial satellite may be the same satellite, that is, the mobility management network element in the first satellite and the mobility management network element in the initial satellite are the same network element.

[0181] This embodiment may include Figure 7 The method shown may include some or all of the steps.

[0182] See Figure 7In S701, the mobility management network element in the initial satellite can send an attach request message to the first mobility management network element. This attach request message instructs the terminal device to request access to the core network. The information carried in this attach request message may include, but is not limited to, at least one of the following: the terminal device's identifier (e.g., IMSI), S&F capability information, or security capability information. The mobility management network element in the initial satellite can also send the identifier of the network selected by the terminal device, such as the PLMN ID, to the first mobility management network element.

[0183] The information carried in the attach request message can be obtained through the interaction between the mobility management network element in the initial satellite and the terminal device. For example, before the mobility management network element in the initial satellite sends the attach request message to the first mobility management network element, the terminal device can send a first attach request to the mobility management network element of the initial satellite. The mobility management network element of the initial satellite responds to the first attach request by sending a first attach response to the terminal device. This process can involve... Figure 5 The specific implementation methods of S510 and S520 in the document will not be elaborated here for the sake of brevity.

[0184] The above S701 is executed when the feeder link is connected. If the feeder link is not connected, the initial satellite mobility management network element storage information (such as at least one of the terminal equipment's IMSI, S&F capability information, or security capability information) will be sent when the feeder link is connected.

[0185] See Figure 7 In S702, the first mobility management network element can send authentication data requests to the home subscriber service network element.

[0186] For example, if it is determined from the attach request message that authentication of the terminal device is required, an authentication data request is sent to the home subscriber network element. This authentication data request includes the identifier of the terminal device, such as the IMSI. The authentication data request may also include the identifier of the serving network, such as the PLMN ID.

[0187] See Figure 7 In S703, the Home Subscriber Service (NAS) element can send an authentication data response to the First Mobility Management (MLM) element. The authentication data response includes an initial authentication vector for authenticating the terminal device. The initial authentication vector includes RAND, AUTN, XRES, and a first key, such as K. ASME Understandably, in S703, the Home Subscriber Service (NSS) element sends the initial authentication vector to the First Mobility Management (MLM) element, which means sending the first key to the MLM element.

[0188] In the first implementation, the authentication data request is used to request at least one authentication vector, such as AV. In this case, the authentication data response carries at least one authentication vector. Furthermore, the first mobility management network element also sends an update location request to the home subscriber service network element to obtain the terminal device's subscription data. At this time, no two-way authentication process is performed between the network and the terminal device.

[0189] In the second and third implementation methods below, the authentication data request also includes instruction information related to S&F operations, and the authentication data response also includes contract data related to S&F operations.

[0190] In the second implementation, the authentication data request is used to request at least one authentication vector and the terminal device's subscription data. In this case, the authentication data request may carry first indication information, which indicates the need to obtain the terminal device's subscription data. Correspondingly, the authentication data response carries at least one authentication vector and subscription data.

[0191] Optionally, the first indication information may be called an S&F indication, and if the terminal device has S&F capability, the S&F indication may be carried in the authentication data request.

[0192] Optionally, the home subscriber service network element obtains the subscription data of the terminal device based on the first instruction information. When it determines that the terminal device is authorized to operate the S&F satellite based on the subscription data, the subscription data is included in the authentication data response. The subscription data carried in the authentication data response may be part or all of the subscription data of the terminal device obtained by the home subscriber service network element.

[0193] In the third implementation, the authentication data request can implicitly indicate the acquisition of contracted data through the second indication information. In one possible example of the third implementation, the second indication information indicates the satellite identifier of the serving satellite (such as the first satellite), in which case the satellite identifier can implicitly indicate the acquisition of contracted data; in another possible example of the third implementation, the second indication information indicates the number of authentication vectors N (an integer greater than 1), in which case the acquisition of contracted data is implicitly indicated by the number of authentication vectors.

[0194] It is understandable that, in the third implementation described above, if the second indication information indicates the satellite identifier of the serving satellite, the home user service network element can also generate a first key based on the satellite identifier. This process will be described in detail below. In the third implementation described above, if the second indication information indicates the number of authentication vectors, the home user service network element can generate the corresponding number of N authentication vectors according to the indication of the second indication information and obtain the subscription data.

[0195] The second and third implementation methods described above can be combined. For example, the first instruction information indicates the acquisition of contracted data, and the second instruction information indicates the number of satellite identifiers and / or authentication vectors. In other words, the second instruction information can implicitly indicate the contracted data.

[0196] Based on the second or third implementation method mentioned above, the authentication data request simultaneously indicates the acquisition of authentication vector and subscription data, which reduces the number of interactions between the first mobility management network element and the home user service network element and improves communication efficiency.

[0197] It should be understood that the embodiments of this application do not limit the number of authentication vectors. As previously mentioned, each authentication vector may include RAND, AUTN, XRES, and K. ASME That is, in the authentication data response sent by the Home Subscriber Service (NAS) to the First Mobility Management (MLM) NAS, each authentication vector may include the root key between the terminal device and the First MLM NAS, such as K. ASME .

[0198] See Figure 7 S704 in the first mobility management network element is used to deduce the authentication vector.

[0199] Optionally, the first mobility management network element can deduce the second key based on the first key in the authentication vector, and then combine the second key with other elements in the authentication information, such as RAND, AUTN and XRES, to form a new authentication vector. The new authentication vector can be called, for example, on-board AV.

[0200] In one implementation, when the authentication data response sent by the Home Subscriber Service (NAS) to the First Mobility Management (MLM) includes multiple initial authentication vectors, the First MLM can determine one or more initial authentication vectors from the multiple initial authentication vectors, and generate a new authentication vector for each of the initial authentication vectors, such as based on the first key K in the initial authentication vector. ASME The second key K was obtained through deduction. ASME* Then use the second key K ASME* Together with other elements in the authentication vector, it forms a new authentication vector, or the derived authentication vector.

[0201] Optionally, the first mobility management network element may determine one or more initial authentication vectors with the smallest SQN from multiple initial authentication vectors to deduce the second key.

[0202] See Figure 7 In S705, the first mobility management network element can send the derived authentication vector to the mobility management network element in the first satellite. It can be understood that when the first mobility management network element sends the derived authentication vector to the mobility management network element in the first satellite, it effectively sends the second key to the mobility management network element in the first satellite.

[0203] For example, the first mobility management network element can first determine the serving satellite of the terminal device. When the first satellite is determined to be the serving satellite of the terminal device, and the feeder link between the first mobility management network element and the first satellite is available, a first message is sent to the first satellite. For example, the first mobility management network element can determine the serving satellite of the terminal device based on ephemeris information. Ephemeris information has been explained in the previous example and will not be repeated for the sake of brevity. Optionally, the serving satellite of the terminal device is determined by the first mobility management network element based on the information sent by the initial satellite, such as the candidate satellite information of the terminal device being included in the information sent by the initial satellite in step S701. It is understood that the serving satellite of the terminal device may not have changed, that is, it may still be the initial satellite that sent the attach request message. In this case, the first mobility management network element can send the first message to the initial satellite when the feeder link with the initial satellite is available, and then the initial satellite and the terminal device will interact to execute the relevant procedures for the terminal device to access the core network.

[0204] Optionally, the new authentication vector obtained from the above deduction can be carried in the first message sent by the first mobility management network element to the mobility management network element in the first satellite. In this case, S705 can realize the sending of the first message by the first mobility management network element to the mobility management network element in the first satellite.

[0205] Optionally, the first message may also include subscription data related to S&F operations, such as the first mobility management network element may obtain the subscription data related to S&F operations from the authentication data response.

[0206] Optionally, the first message may also include a key identifier, such as a KSI. ASME This key identifier is used to represent the second key.

[0207] Optionally, the first mobility management network element can generate a GUTI, which can be carried in the first message.

[0208] It is understandable that the first mobility management network element and the mobility management network element in the first satellite can belong to the same or different security domains (or trust domains). For example, if the first mobility management network element and the mobility management network element in the first satellite belong to the same operator, then they are considered to belong to the same security domain (or trust domain). Of course, this application does not limit the definition of security domain (or trust domain). For example, security domains or trust domains can be limited based on dimensions such as encryption algorithms and access control. To reduce processing complexity, the first mobility management network element can deduce the second key, or in other words, deduce a new authentication vector, even if it belongs to a different security domain (or trust domain) than the mobility management network element in the first satellite.

[0209] In this embodiment, the first mobility management network element executes S704 and S705 when the feeder link is connected; or when the feeder link is not connected, it executes S704 first and then executes S705 after the feeder link is connected.

[0210] Furthermore, after receiving the deduced authentication vector, the mobility management network element in the first satellite generates a NAS key based on the second key therein. The terminal device then deduces the second key using the same deduction method as the first mobility management network element, and further deduces the NAS key using the same deduction method as the mobility management network element in the first satellite. Finally, the message is protected based on the NAS key to achieve secure communication.

[0211] For example, in the process of a terminal device accessing the core network by interacting with the first satellite, it may also include, for instance, the following: Figure 7 The steps S706 to S709 shown are as follows:

[0212] In S706, the mobility management network element in the first satellite generates a NAS key based on the second key.

[0213] In S707, the mobility management network element in the first satellite sends a first NAS message protected by a NAS key to the terminal device.

[0214] The first NAS message is used to instruct the terminal device to establish a secure connection. For example, the first NAS message could be a secure mode command as described in the previous example.

[0215] Optionally, the first NAS message includes the NAS integrity protection algorithm and the NAS encryption algorithm.

[0216] Optionally, in this embodiment, the first NAS message may further include a key identifier (such as a KSI). ASME The first NAS message may include an encryption key set identifier (eKSI) and / or the identifier of the mobility management network element of the first satellite. Specifically, the first NAS message may include an encryption key set identifier (eKSI), which can be set to a key identifier (such as KSI). ASME The value of ) or generated by the mobile management network element of the first satellite.

[0217] Optionally, the first NAS message may include a message authentication code (MAC), such as NAS-MAC.

[0218] S708, the terminal device generates the NAS key.

[0219] For example, the deduction method by which the terminal device generates the second key based on the first key is consistent with the method by which the first mobility management network element deduces the second key based on the first key. For simplicity, it will not be described in detail again. Optionally, the first input parameter when deducing the second key can be indicated to the terminal device by the mobility management network element in the first satellite, such as the key identifier (e.g., KSI) carried in the first NAS message. ASME The identifiers of the mobile management network elements in the first satellite and / or the mobile management network elements in the first satellite can be used as input parameters for the terminal equipment to deduce the second key.

[0220] Optionally, when the first input parameter for deriving the second key includes the satellite identifier of the first satellite, the terminal device can receive a broadcast message sent by a base station in the first satellite, which includes the identifier of the first satellite. For example, the terminal device, based on... Figure 4 During the establishment of the RRC connection in S410 to S430 of the illustrated embodiment, the satellite identifier can be received from the base station, such as when the terminal device receives a broadcast message from the base station during the cell search and selection process to obtain the satellite identifier.

[0221] For example, after the terminal device derives the second key using the same deduction method as the first mobility management network element, it can derive the second key to obtain the NAS integrity protection key according to the NAS integrity protection algorithm indicated in the first NAS message, and derive the second key to obtain the NAS encryption key according to the NAS encryption algorithm indicated in the first NAS message.

[0222] Based on this, the terminal device can decode the first NAS message using the NAS encryption key and NAS algorithm, and verify the integrity of the first NAS message using the NAS integrity protection key and NAS integrity protection algorithm. Then, if the integrity verification passes, a secure connection is established based on the instructions in the first NAS message.

[0223] In one implementation, the terminal device can execute the following S709 if the integrity verification passes.

[0224] S709, the terminal device sends a second NAS message protected by the NAS key to the mobility management network element of the first satellite.

[0225] The second NAS message is used to respond to an indication of establishing a secure connection. For example, the second NAS message may include an indication of successful secure connection establishment or an indication of failed secure connection establishment. For instance, the second NAS message could be a secure mode response as described in the previous example; the secure mode response is explained in the previous example and will not be repeated here for brevity.

[0226] The mobility management network element in the first satellite can decode the second NAS message and perform integrity verification on the second NAS message based on the NAS key. If the integrity verification is successful, the security establishment process and authentication process can be completed based on the second NAS message.

[0227] It is understood that, in the embodiments of this application, the process of terminal equipment accessing the core network may also include other related steps. For example, before S701, it may also include... Figure 5 In S510 and S520, the terminal device sends a first attach request to the mobility management network element in the initial satellite, and the mobility management network element in the initial satellite sends a first attach response to the terminal device; before S706, it may also include Figure 5 In S540, the terminal device sends a second attach request to the mobility management network element in the first satellite, and in S550, the authentication process includes the mobility management network element in the first satellite sending a user authentication request to the terminal device, and the terminal device sending a user authentication response to the mobility management network element in the first satellite; further steps after S709 may include... Figure 5 In the S560, such as the mobility management network element of the first satellite, a second attach response is sent to the terminal device. It should be noted that this application does not limit whether other related steps are performed or how they are implemented.

[0228] Optionally, the terminal device stores the mapping between the NAS security context and the first satellite, such as SATID, and the NAS security context (e.g., NAS encryption key, encryption algorithm; integrity protection key, integrity protection algorithm, key identifier, etc.). This means the terminal device can obtain the corresponding NAS key, algorithm, and other security information used to protect NAS messages based on the mapping between the satellite identifier and its locally stored information. When the terminal device reconnects to the third satellite after leaving it, it can obtain the NAS key based on the third satellite's identifier and directly use this NAS key to protect NAS messages between itself and the mobility management entity on the third satellite.

[0229] As previously mentioned, the IMSI of the terminal device can be carried in the first attach request, which is sent by the terminal device to the mobility management network element in the initial satellite. The mobility management network element in the initial satellite then sends the attach request message to the first mobility management network element, which in turn carries it in the first message and sends it to the mobility management network element in the first satellite. This method exposes the user's permanent identity multiple times in the air interface, posing a risk to user information security. Based on this, in some embodiments, the mobility management network element in the initial satellite can assign a temporary user identifier to the terminal device. For example, the mobility management network element in the initial satellite can send the temporary user identifier to the terminal device by carrying the temporary user identifier in the first attach response, and also carry the temporary user identifier in the attach request message sent by the mobility management network element in the initial satellite to the first mobility management network element. The temporary user identifier is also carried in the first message sent by the first mobility management network element to the mobility management network element in the first satellite. Furthermore, the terminal device carries the temporary user identifier obtained from the first attach response in the second attach request and sends it to the mobility management network element in the first satellite, thereby reducing the number of times the user's permanent identity is exposed in the air interface. In this case, the mobility management network element in the first satellite will obtain the local authentication vector based on the temporary identifier.

[0230] Other elements in the derived authentication vector, such as RAND, AUTN, and XRES, can be used to implement the user authentication process, which can be based on RAND, AUTN, and XRES in the derived authentication vector. For example, the user authentication request can carry RAND and AUTN. It should be understood that if the mobility management network element of the first satellite receives multiple authentication vectors sent by the first mobility management network element, the first satellite's mobility management network element can determine one authentication vector from the multiple authentication vectors, such as the authentication vector with the smallest SQN, and then carry RAND and AUTN from that authentication vector in the user authentication request.

[0231] As previously mentioned, the second key can be derived from the first input parameters and the first key. The first input parameters include a key identifier (such as KSI). ASME When authenticating, the user authentication request can carry the key identifier (such as KSI). ASME To synchronize key identifiers (such as KSI) with terminal devices. ASME This facilitates key deduction by the terminal device. In some embodiments, the aforementioned key identifier (such as KSI) ASME The key identifier (KSI) can be indicated by the first mobility management element, such as by being carried in a first message sent by the first mobility management element. In other embodiments, the mobility management element in the first satellite can generate the key identifier (KSI). ASME ).

[0232] The implementation of the authentication process can be found in S551 and S552 of the previous embodiment, and will not be repeated for the sake of brevity.

[0233] Optionally, the second attach response may carry a GUTI to allocate a GUTI to the terminal device. The GUTI may be obtained from a first message received by a mobility management network element in the first satellite, or the mobility management network element in the first satellite may generate the GUTI, for example, based on the identifier of the first mobility management network element.

[0234] The above-described derivation of the second key from the first mobility management element is merely one possible example. In other embodiments, the home subscriber service (NAS) sends the first key along with the authentication data response to the first NAS. This means the NAS can deduce the second key based on the first key in the authentication vector, and then carry the deduced new authentication vector, such as the on-board authentication vector (AV), in the authentication data response to the first NAS. The implementation method of the NAS deduce the second key is similar to that of the first NAS, and will not be elaborated further for simplicity.

[0235] Optionally, when deriving the second key for Home Subscriber Service, if the satellite identifier of the first satellite is used as an input parameter, the authentication data request sent by the first mobility management network element to the Home Subscriber Service network element may carry the satellite identifier of the first satellite.

[0236] Optionally, when deriving the first key for the home user service, if the key identifier (such as KSI) is used... ASME As an input parameter, the authentication data request sent by the first mobility management network element to the home subscriber service network element may carry this key identifier (such as KSI). ASME ).

[0237] Figure 8 This is a flowchart illustrating another communication method provided in an embodiment of this application. Figure 8 The explanation is based on the interaction between the terminal equipment, the mobility management network element in the first satellite, the mobility management network element in the second satellite, the first mobility management network element, and the home user service network element, and does not constitute any limitation on the subject of this application.

[0238] To improve the success rate of terminal equipment accessing the core network or reduce access latency, the first mobility management network element can simultaneously send authentication vectors and subscription data to multiple candidate serving satellites of the terminal equipment, enabling one of the satellites (such as the second satellite) to interact with the terminal equipment to complete the terminal equipment's access to the core network. Based on this, Figure 8The first satellite and the second satellite in the above examples are different candidate satellites. The first satellite may be the same satellite as the initial satellite in the aforementioned examples or it may be a different satellite. The second satellite may be the same satellite as the initial satellite in the aforementioned examples or it may be a different satellite. This application does not limit this. Figure 8 The example given is the first mobility management network element sending authentication information and subscription data to the first and second satellites. However, it should be understood that when the first mobility management network element sends authentication vectors and subscription data to more satellites, the implementation method of the first and second satellites can be referred to.

[0239] It should also be understood that this embodiment can be combined with the above. Figure 6 or Figure 7 Implemented in any of the embodiments shown, Figure 8 Based on Figure 7 The embodiment shown is used as an example for explanation.

[0240] See Figure 8 The method may include the following steps S801 to S806.

[0241] S801, the first mobility management network element sends an authentication data request to the home user service network element;

[0242] S802, the home user service network element sends an authentication data response to the first mobility management network element;

[0243] S803-1, the first mobility management network element simulates the authentication vector for the first satellite;

[0244] S804-1, The first mobility management network element sends the authentication vector derived for the first satellite to the mobility management network element of the first satellite;

[0245] S803-2, the first mobility management network element simulates the authentication vector for the second satellite;

[0246] S804-2, the first mobility management network element sends the authentication vector derived for the second satellite to the mobility management network element of the second satellite;

[0247] S805, the terminal device and the mobility management network element of the second satellite generate a NAS key, and protect the messages between the terminal device and the mobility management network element in the second satellite based on the NAS key;

[0248] S806, the second satellite's mobility management network element sends a third instruction message to the first mobility management network element, indicating that the authentication of the terminal device was successful.

[0249] Regarding S801 and S802 above:

[0250] In the first implementation, the authentication data request is used to request the acquisition of multiple authentication vectors. In this case, the authentication data response carries multiple authentication vectors. Further, the first mobility management network element sends an update location request to the home subscriber service network element to update the location of the terminal device and obtain the terminal device's subscription data.

[0251] In the second implementation, the authentication data request is used to request the acquisition of multiple authentication vectors and the terminal device's subscription data. In this case, the authentication data request may carry first indication information, which indicates the acquisition of the terminal device's subscription data. Correspondingly, the response message of the authentication data request carries multiple authentication vectors and subscription data.

[0252] The methods by which the home user service network element obtains the contracted data of the terminal device based on the first instruction information and the methods by which it obtains the contracted data of the terminal device based on the implicit instruction of the second instruction information have been explained in the previous examples and will not be repeated here for the sake of brevity.

[0253] The multiple authentication vectors may include one or more authentication vectors corresponding to each candidate serving satellite of the terminal device, such as the first satellite and the second satellite.

[0254] As one example, the number of authentication vectors carried in the authentication data response can be determined based on the number of candidate serving satellites. For instance, the authentication data request can also carry information indicating the number of authentication vectors, and the home user service network element can carry the corresponding authentication vectors in the authentication data response. As another example, the number of authentication vectors carried in the authentication data response can be preset, such as by agreement or pre-configuration. In this case, some or all of the candidate serving satellites can be selected based on the number of authentication vectors, and authentication vectors and subscription data can be sent to them. A description of authentication vectors can be found in the aforementioned examples, and will not be repeated here for brevity.

[0255] In the above steps, the execution order of S803-1, S803-2, S804-1 and S804-2 is not limited.

[0256] In S803-1 to S804-2, to ensure the security of terminal equipment communicating through different satellites, the first mobility management network element deduces a second key for the first satellite based on the first key in the authentication vector corresponding to the first satellite, and then sends the deduced authentication vector including the second key to the mobility management network element in the first satellite; similarly, the first mobility management network element deduces a second key for the second satellite based on the first key in the authentication vector corresponding to the second satellite, and then sends the deduced authentication vector including the second key to the mobility management network element in the second satellite. This ensures that the mobility management network elements on each satellite are unaware of the root key, achieving secure isolation of the root key between satellites.

[0257] The derivation method for the second key has already been explained in the previous example and will not be repeated for the sake of brevity. It should be noted that since the second key for the first satellite and the second key for the second satellite are derived from the root keys in different authentication vectors, for example, the second key generated for the first satellite is derived from the first key in the first AV, and replacing the first key in the first AV with the second key results in the first on-satellite AV including the second key; similarly, the second key generated for the second satellite is derived from the first key in the second AV, and replacing the first key in the second AV with the second key results in the second on-satellite AV including the second key.

[0258] To achieve secure isolation between satellites, the second key generated for the first satellite and the second key generated for the second satellite are different. For example, the second key generated for the first satellite and the second key generated for the second satellite can be determined based on different types of input parameters. For example, the second key generated for the first satellite is derived from the first key, while the second key generated for the second satellite is derived from the satellite identifier of the second satellite and the first key. Alternatively, the parameter values ​​of the input parameters for the second key generated for the first satellite and the second key generated for the second satellite are different. For example, the second key generated for the first satellite is derived from the satellite identifier of the first satellite and the first key, while the second key generated for the second satellite is derived from the satellite identifier of the second satellite and the first key.

[0259] Optionally, one of the second key for the first satellite and the second key for the second satellite can be the first key, such as the root key K. ASME For example, the second key for the second satellite can be the first key, and the second key for the first satellite can be a second key derived from the first key. Correspondingly, the authentication vector for the second satellite can be the initial authentication vector.

[0260] Optionally, the first mobility management network element may send one or more second keys corresponding to the first satellite to the mobility management network element in the first satellite, or the first mobility management network element may send one or more authentication vectors corresponding to the first satellite to the mobility management network element in the first satellite, each authentication vector including a second key.

[0261] Optionally, the first mobility management network element may send one or more second keys corresponding to the second satellite to the mobility management network element in the second satellite, or the first mobility management network element may send one or more authentication vectors corresponding to the second satellite to the mobility management network element in the second satellite, each authentication vector including a second key.

[0262] Optionally, the authentication vector derived for the first satellite can be carried in a second message sent by the first mobility management network element to the mobility management network element in the first satellite; the authentication vector derived for the second satellite can be carried in a third message sent by the first mobility management network element to the mobility management network element in the second satellite.

[0263] Optionally, the second message may carry fourth indication information, which indicates the identifier of each authentication vector in at least one authentication vector corresponding to the first satellite, such as AV ID.

[0264] Optionally, the third message may carry fifth indication information, which indicates the identifier of each authentication vector in at least one authentication vector corresponding to the second satellite, such as AV ID.

[0265] Optionally, the first mobility management network element may store the identifier of the authentication vector corresponding to each candidate serving satellite.

[0266] Optionally, the first mobility management element can generate a key identifier, such as a KSI. ASME The key identifier can be carried in both the second and third messages.

[0267] Understandably, the second message may also include Figure 7 In the illustrated embodiment, the third message may also include relevant information in the first message, such as contract data related to S&F operations. Figure 7 The first message in the illustrated embodiment contains relevant information, such as contract data related to S&F operations. Correspondingly, the authentication data request may also include... Figure 7 The relevant information in the authentication data request in the illustrated embodiment, such as instruction information related to S&F operation, etc.

[0268] In one implementation, the first mobility management network element can determine one or more authentication vectors corresponding to each candidate serving satellite from multiple authentication vectors carried in the authentication data response, and generate a new authentication vector for each of the determined authentication vectors. Optionally, the first mobility management network element can determine one or more authentication vectors with the smallest SQN from multiple authentication vectors corresponding to the first satellite to deduce the second key; the first mobility management network element can determine one or more authentication vectors with the smallest SQN from multiple authentication vectors corresponding to the second satellite to deduce the second key.

[0269] The first mobility management network element can first determine the candidate serving satellites for the terminal device. When it determines that the first satellite and the second satellite are the candidate serving satellites for the terminal device, it sends a second message to the first satellite and a third message to the second satellite. For example, the first mobility management network element can determine the candidate serving satellites for the terminal device based on ephemeris information. Ephemeris information has already been explained in the previous example and will not be repeated for brevity.

[0270] In this embodiment, when the feeder link between the first mobility management network element and the first satellite is connected, the first mobility management network element can send a second message to the mobility management network element in the first satellite. When the feeder link between the first mobility management network element and the second satellite is connected, the first mobility management network element can send a third message to the mobility association network element in the second satellite.

[0271] In this embodiment, the implementation method of S805 is the same as... Figure 6 S604 or Figure 7 The S707 to S709 are similar, and will not be described in detail for the sake of brevity.

[0272] Furthermore, the terminal device can interact with one of the candidate serving satellites, such as a second satellite, to complete the initial attachment process.

[0273] In S806, the mobility management network element in the second satellite can send a sixth indication message to the first mobility management network element, which indicates that the authentication of the terminal device has been successful.

[0274] Optionally, the sixth indication information may include a fourth message sent by the mobility management network element in the second satellite to the first mobility management network element.

[0275] Optionally, the fourth message may also include the context of the terminal device, which may also be called the security context. This can be understood as the information required for message decryption and / or integrity verification. For example, it may include the NAS key mentioned above. Optionally, it may also include the first key, the security capabilities of the terminal device, and the uplink and downlink NAS COUNT values.

[0276] For example, the mobility management network element in the second satellite can send the aforementioned fourth message to the first mobility management network element when the feeder link is connected. In this case, the mobility management network element in the second satellite can store the context of the terminal device. For the mobility management network element in the second satellite, storing the context of the terminal device also enables the terminal device to access services again when it reattaches to the mobility management network element in the second satellite using the stored NAS key.

[0277] Figure 9a and Figure 9bThis is a flowchart illustrating another communication method provided in an embodiment of this application. Figure 9a and Figure 9b The explanation is based on the interaction between the terminal equipment, the mobility management network element in the first satellite, the mobility management network element in the second satellite, the first mobility management network element, and the home user service network element, and does not constitute any limitation on the subject of this application.

[0278] In this embodiment, the second satellite can be a satellite providing access services to the terminal device, and the first satellite can be a satellite that provides access services to the terminal device after the terminal device's service satellite has switched. It is understood that the access service provided by the second satellite to the terminal device can be initial access, but this application does not limit this. In the case where the second satellite provides initial access services to the terminal device, the first satellite can be a satellite that provides subsequent access services to the terminal device after the terminal device has completed initial access. The first satellite and the second satellite can be different satellites, or the first satellite can be the same satellite as the second satellite. For example, if the terminal device leaves the second satellite and then reattaches to the mobility management network element on the second satellite, the second satellite in this embodiment may be replaced with... Figure 6 The first satellite in the illustrated embodiment. The first satellite may be the same as or different from the first satellite in the aforementioned examples, and the first satellite may be the same as or different from the initial satellite in the aforementioned examples; this application does not limit this.

[0279] It should also be understood that this embodiment can be combined with the above. Figure 6 to Figure 8 Implementation of any of the embodiments shown.

[0280] See Figure 9a The method may include the following S901a to S903a.

[0281] S901a, the mobility management network element in the second satellite sends a sixth instruction message to the first mobility management network element, indicating that the authentication of the terminal device was successful;

[0282] S902a, the first mobility management network element sends the NAS key for the first satellite to the mobility management network element in the first satellite;

[0283] S903a, the terminal equipment and the mobility management network element in the first satellite protect the messages between the terminal equipment and the mobility management network element in the second satellite based on the NAS key.

[0284] The above S901a can be referred to as S806 in the previous example, and will not be repeated for the sake of brevity.

[0285] In S902a, the first mobility management network element can respond to the aforementioned sixth instruction information by sending a NAS key for the first satellite to the management network element in the first satellite.

[0286] For example, the first mobility management network element can determine a third key based on the second input parameters and the first key. The third key can also be understood as the second key generated for the first satellite. Further, the first mobility management network element generates a NAS key for the first satellite based on the third key. In some embodiments, the second input parameters may include, but are not limited to, at least one of the following: the satellite identifier corresponding to the first satellite, the identifier of the mobility management network element in the first satellite, and a key identifier, such as a KSI. ASME Or a fixed string. In other embodiments, the third key is the same as the second key generated for the second satellite. In this case, the second input parameter may include, but is not limited to, at least one of the following: the satellite identifier corresponding to the second satellite, the identifier of the mobility management network element in the second satellite, and a key identifier, such as KSI. ASME , or a fixed string.

[0287] It should be noted that the implementation method of deriving the third key by the first mobility management network element is similar to that of deriving the second key. To achieve secure isolation between satellites, the third key and the second key can be different. Therefore, the second input parameter for deriving the third key and the first input parameter for deriving the second key should be different. In some embodiments, the difference between the first and second input parameters can be in the parameter types. For example, the second input parameter may include a satellite identifier, such as the satellite identifier of the first satellite, while the first input parameter does not include the satellite identifier. Another example is that the first input parameter includes a fixed string, while the second input parameter includes a key identifier, such as a KSI. ASME In other embodiments, the first input parameter and the second input parameter may differ in their parameter values. For example, both the first input parameter and the second input parameter may include a satellite identifier, with the first input parameter including the satellite identifier of the first satellite and the second parameter including the satellite identifier of the first satellite.

[0288] Optionally, the first mobility management network element can obtain the second key for the second satellite by acquiring the context of the terminal device, and then determine the NAS key for the first satellite based on the second key for the second satellite.

[0289] For example, the fourth message carrying the aforementioned sixth instruction information also carries the context of the terminal device. The first mobility management network element can obtain the context of the terminal device through this fourth message, or the first mobility management network element can update the context of the terminal device stored in the terrestrial network based on the context carried in the fourth message to obtain the context of the terminal device. Specifically, sending the NAS key for the first satellite to the mobility management network element in the first satellite can be achieved by sending part or all of the context of the terminal device to the mobility management network element in the first satellite, with the sent context carrying the NAS key for the first satellite. This facilitates secure transmission after the terminal device and the mobility management network element in the second satellite are connected.

[0290] For example, in the case where the first satellite and the second satellite are the same satellite, the NAS key for the first satellite sent by the first mobility management network element to the mobility management network element in the first satellite, that is, the NAS key for the second satellite sent to the mobility management network element in the second satellite, can be obtained by the first mobility management network element based on the following possible implementation methods:

[0291] One implementation method is to obtain the NAS key from the fourth message sent by the mobility management network element in the second satellite.

[0292] In the second implementation method, the first mobility management network element generates a NAS key based on the second key generated for the second satellite. This second key can be derived by the first mobility management network element in S602 above. The method by which the first mobility management network element generates the NAS key based on the second key can be found in the NAS key generation method in the previous example, and will not be repeated here for the sake of simplicity.

[0293] Optionally, the first mobility management network element can deduce a new second key for the second satellite based on the first key, and then generate a NAS key based on the new second key. For example, the input parameters for deduce the new second key may be different from the input parameters for deduce the second key in S602 above. For instance, the satellite identifier of the second satellite may be used as an input parameter when deduce the new second key, while the input parameters for deduce the first key in S602 above may not include the satellite identifier.

[0294] In the third implementation method, the NAS key generated for the second satellite includes a terminal device verification code and a network device verification code. These verification codes can be determined based on a MAC address, such as the NAS-MAC. This MAC address may be the same as or different from the MAC address carried in the first NAS message mentioned above; this application does not impose any restrictions on this.

[0295] The first mobility management network element can generate terminal device verification codes and network device verification codes according to an agreed-upon method. For example, the MAC address includes M bits, the terminal device verification code can be the first X bits, and the network verification code can be the last MX bits, or the network verification code can be the first X bits, and the terminal device verification code can be the last MX bits. For instance, in a 32-bit MAC address, 16 bits are the terminal device verification code, and the last 16 bits are the network verification code.

[0296] Understandably, when the NAS key for the second satellite includes a terminal device verification code and a network verification code, the use of the terminal device verification code and the network verification code to verify the integrity of the transmitted information can include: the NAS message sent by the terminal device to the mobility management network element in the second satellite can carry the terminal device verification code, and the mobility management network element in the second satellite performs integrity verification on the NAS message based on the terminal device verification code; the NAS message sent by the mobility management network element in the second satellite to the terminal device can carry the network verification code, and the terminal device performs integrity verification on the NAS message based on the network verification code, thereby ensuring that the identities of both communicating parties are legitimate and that the transmitted information is complete.

[0297] This application does not limit the method of obtaining the MAC address. For example, see [link to relevant documentation]. Figure 10 The MAC can be generated based on an algorithm related to the integrity key, network identity and authentication information (NIA). Input parameters can include some or all of the following: message, bearer identifier, transmission direction, or bearer-specific and direction-related counter value (COUNT). The message can be a satellite identifier; the transmission direction indicates whether it is uplink or downlink transmission; the BEARER is the identifier of the dedicated radio bearer (DRB), and its value allocation method is defined by 3GPP TS 38.323; the COUNT is used to prevent replay attacks and ensure the order of transmitted data packets.

[0298] Furthermore, the terminal device can store the mapping between NAS security contexts and the first satellite. This mapping includes, for example, a SAT ID and the corresponding NAS security context for each SAT ID. The NAS context may include, but is not limited to, at least one of the following: a NAS encryption key and encryption algorithm; a NAS integrity protection key and integrity protection algorithm; and a key identifier. That is, the terminal device can obtain the corresponding NAS key, algorithm, and other security information used to protect NAS messages based on the satellite identifier and the locally stored mapping. When the terminal device leaves the first satellite and reconnects to it, it can obtain the NAS key based on the first satellite's identifier and directly use this NAS key to protect NAS messages with the mobility management entity in the first satellite.

[0299] The above S903a and Figure 6 S604 in the illustrated embodiment is similar and will not be described again for the sake of brevity.

[0300] See Figure 9b The method may include the following S901b to S903b.

[0301] S901b, the mobility management network element in the second satellite sends a sixth instruction message to the first mobility management network element, indicating that the authentication of the terminal device was successful;

[0302] S902b, the first mobility management network element sends a second key for the first satellite to the mobility management network element in the first satellite;

[0303] S903b-1, the mobility management network element in the first satellite sends a first NAS message based on NAS key protection to the terminal device;

[0304] S903b-2, the terminal device generates a second key for the third satellite;

[0305] S903b-3, The terminal device generates a NAS key based on the second key;

[0306] S903b-4, the terminal device sends a second NAS message protected by a NAS key to the mobility management network element in the first satellite.

[0307] Figure 9b With the above Figure 9a The difference is that after the second satellite provides access services to the terminal device, the first mobility management network element can synchronize the second key for the second satellite to the first satellite. Then, the terminal device and the mobility management network element in the first satellite can activate the NAS key of the first satellite by executing the NAS SMC procedure.

[0308] For example, during the process of a terminal device attaching to a mobility management network element in a first satellite, the mobility management network element in the first satellite can deduce a NAS key based on a received second key, protect a first NAS message based on the NAS key, and then send the first NAS message protected by the NAS key to the terminal device; the terminal device can generate a second key based on the first key, deduce a NAS key based on the second key, verify the integrity of the first NAS message based on the NAS key, protect the second NAS message based on the NAS key, and finally send the second NAS message protected by the NAS key to the mobility management network element in the first satellite; the mobility management network element in the first satellite performs integrity verification on the second NAS based on the NAS key.

[0309] In one example, the second key for the first satellite sent by the first mobility management network element to the mobility management network element in the first satellite can be the same as the second key for the second satellite. For example, the input parameters used in generating the second key for the first satellite may include, but are not limited to, the satellite identifier corresponding to the second satellite and / or the identifier of the mobility management network element in the second satellite. Correspondingly, the terminal device derives the second key for the first satellite based on the same algorithm and input parameters, such as the input parameters which may include, but are not limited to, the satellite identifier corresponding to the second satellite and / or the identifier of the mobility management network element in the second satellite.

[0310] In another example, the second key for the first satellite sent by the first mobility management network element to the mobility management network element in the first satellite may differ from the second key for the second satellite. For instance, the input parameters used in generating the second key for the first satellite may include, but are not limited to, the satellite identifier corresponding to the first satellite and / or the identifier of the mobility management network element in the first satellite. Correspondingly, the terminal device derives the second key for the first satellite based on the same algorithm and input parameters, such as the input parameters which may include, but are not limited to, the satellite identifier corresponding to the first satellite and / or the identifier of the mobility management network element in the first satellite.

[0311] It should be noted that S903b-1 to S903b-4 in this embodiment are only for illustrating the NAS key used by the first satellite when providing access services subsequently. The NAS SMC process implemented in S903b-1 to S903b-4 can be found in the foregoing. Figure 7 S707 to S709 in the illustrated embodiments and related embodiments will not be described in detail for the sake of brevity.

[0312] Furthermore, the terminal device can store the mapping between NAS security contexts and the first satellite. This mapping includes, for example, a SAT ID and the corresponding NAS security context for each SAT ID. The NAS context may include, but is not limited to, at least one of the following: a NAS encryption key and encryption algorithm; a NAS integrity protection key and integrity protection algorithm; and a key identifier. That is, the terminal device can obtain the corresponding NAS key, algorithm, and other security information used to protect NAS messages based on the satellite identifier and the locally stored mapping. When the terminal device leaves the first satellite and reconnects to it, it can obtain the NAS key based on the first satellite's identifier and directly use this NAS key to protect NAS messages with the mobility management entity in the first satellite.

[0313] It is understandable that the above Figure 9a S901a can be executed when the feeder link between the second satellite and the first mobility management network element is connected; S902a can be executed when the feeder link between the first satellite and the first mobility management network element is connected; S903a can be executed when the service link between the terminal equipment and the first satellite is connected. Figure 9b S901b can be executed when the feeder link between the second satellite and the first mobility management network element is connected; S902b can be executed when the feeder link between the first satellite and the first mobility management network element is connected; S903b-1 to S903b-4 can be executed when the service link between the terminal equipment and the first satellite is connected.

[0314] In this embodiment, after the serving satellite is switched, the first mobility management network element can synchronize the context of the terminal device, such as the NAS key or a second key used to generate the NAS key, with the satellite that subsequently provides access services, thereby facilitating the terminal device to quickly access the network after the serving satellite is switched.

[0315] In the above S901a or S901b, the sixth indication information sent by the mobility management network element in the second satellite to the first mobility management network element can be carried in the fourth message, that is, the mobility management network element in the second satellite sends the fourth message to the first mobility management network element to realize the transmission of the sixth indication information.

[0316] In some embodiments, the fourth message sent by the mobility management network element in the second satellite to the first mobility management network element may further include seventh indication information, which indicates the authentication vector corresponding to the second key generated for the second satellite, such as including the identifier of the authentication vector corresponding to the first key, such as AV ID.

[0317] Continuing with the example above, the first mobility management network element, based on the seventh indication information, determines that the corresponding authentication vector is an invalid authentication vector, i.e., an authentication vector that has already been used, and then deletes the authentication vector. Furthermore, to ensure the freshness of the authentication vector, the first mobility management network element may consider any locally stored authentication vectors with an SQN less than the SQN indicated by the seventh indication information as invalid authentication vectors and delete these wireless authentication vectors.

[0318] In this embodiment, the operation is performed when the feeder link between the second satellite and the first mobility management network element is connected, and the mobility management network element in the second satellite sends a fourth message to the first mobility management network element.

[0319] Figure 11 This is a schematic flowchart of a communication method provided in an embodiment of this application. Figure 11 The explanation is based on the interaction between the terminal equipment, the mobility management network element in the first satellite, the first mobility management network element, and the home user service network element, and does not constitute any limitation on the subject of this application.

[0320] For example, Figure 11 The terminal equipment in the terminal equipment can be replaced with components configured in the terminal equipment (such as chips, chip systems, processors, etc.), or logical modules or software capable of realizing all or part of the functions of the terminal equipment; the mobility management network element (such as the mobility management network element in the first satellite or the first mobility management network element) can be replaced with components configured in the mobility management network element (such as chips, chip systems, processors, etc.), or logical modules or software capable of realizing all or part of the functions of the first mobility management network element; the home subscriber service network element can be replaced with components configured in the home subscriber service network element (such as chips, chip systems, processors, etc.), or logical modules or software capable of realizing all or part of the functions of the home subscriber service network element.

[0321] Figure 11 The embodiment shown also includes a second satellite, which can be another satellite that provides access services to the terminal device. For example, it can provide access services to the terminal device when the terminal device's service satellite is switched from the first satellite to the second satellite.

[0322] Figure 11 The method shown includes some or all of S1001 to S1018, which are described in detail below. Figure 11 The steps of the method shown.

[0323] When the service link between the first satellite and the terminal equipment is connected, but the feeder link between the satellite and the EPC is not connected, the following steps S1001 to S1003 can be executed.

[0324] In S1001, if the terminal device identifies that the current serving cell supports S&F mode and the user equipment is allowed to use S&F mode, then the terminal device sends a first attach request to the network (such as the mobility management element in the first satellite). This request includes IMSI and S&F capability information.

[0325] In S1002, if the mobility management network element in the first satellite does not have a terminal device context to authenticate the terminal device, the mobility management network element in the first satellite will store the first attach request, or in other words, store the information in the first attach request (such as IMSI and S&F capability information).

[0326] In S1003, the mobility management network element in the first satellite rejects attachment by sending an attach rejection message with an S&F wait timer and a monitoring list to the terminal device.

[0327] When the service link between the first satellite and the terminal equipment is not connected, but the feeder link between the satellite and the EPC is connected, the following steps S1004 to S1008 can be executed.

[0328] In S1004, the mobility management network element in the first satellite sends an attach request message (or registration request message) to the first mobility management network element.

[0329] In S1005, the first mobility management network element sends an authentication data request to the home subscriber service network element. The authentication data request includes IMSI, SN ID, network type, and S&F indication.

[0330] In S1006, when the home user service network element determines that the terminal device supports S&F operation, it generates one or more authentication vectors in accordance with the convention in 3GPP TS33.401[3], and then sends an authentication data response, which includes one or more authentication vectors and subscription data related to S&F operation.

[0331] In S1007, the first mobility management network element determines that it will use the first satellite to provide access service to the user equipment. To prevent the acquisition of the key of the first mobility management network element (i.e., the first key) or the key of the mobility management network element on other satellites (i.e., the second key for that satellite) when multiple satellites provide access service to the terminal equipment, the first mobility management network element stores the first key, such as K. ASME And by using the first key and the satellite identifier of the first satellite, a second key targeting the first satellite is deduced, such as K. ASME* Optionally, the mobility management network elements in the first satellite are also assigned GUTI and KSI. ASME .

[0332] In S1008, the first mobility management network element sends a terminal equipment information notification message to the mobility management network element in the first satellite. This message includes IMSI, authentication vectors (such as RAND, AUTN, XRES, and K). ASME* ), contract data, GUTI and KSI ASME .

[0333] When the service link between the first satellite and the terminal equipment is connected, but the feeder link between the satellite and the EPC is not connected, the following steps S1009 to S1016 can be executed.

[0334] In S1009, the terminal device sends a second attach request to the network (such as the mobility management network element in the first satellite), which includes IMSI and S&F capability information.

[0335] In S1010, the mobility management network element in the first satellite determines that it possesses the authentication vector of the terminal device and initiates the authentication process by sending a user authentication request to the terminal device. This user authentication request includes RAND, AUTN, and KSI. ASME .

[0336] In S1011, the terminal device sends a user authentication response containing RES to the mobility management network element in the first satellite.

[0337] In S1012, the mobility management network element in the first satellite, according to the 3GPP TS33.401[3] convention, is based on the second key, such as K ASME* , and deduce the NAS key.

[0338] In S1013, the mobility management network element in the first satellite sends a NAS security mode command with integrity protection.

[0339] In S1014, the terminal device uses the same method as the mobility management network element in the first satellite to deduce the second key for the first satellite, such as K. ASME* The NAS key was deduced using the same method as the mobility management network element in the first satellite.

[0340] In S1015, the terminal device verifies the NAS security mode command. If verification is successful, the terminal device should use this security context to initiate NAS integrity protection and encryption / decryption, and send an encrypted and integrity-protected NAS security mode completion message to the mobility management element in the first satellite.

[0341] In S1016, the mobility management network element in the first satellite sends a second attach response to the terminal device, which carries the GUTI received in S1008 above.

[0342] When the service link between the first satellite and the terminal equipment is not connected, but the feeder link between the satellite and the EPC is connected, the following steps S1017 to S1018 can be executed.

[0343] In S1017, the mobility management network element in the first satellite verifies the NAS message and decrypts the protocol data unit (PDU). If a data protocol data unit (data PDU) is received from the terminal device, a terminal device information synchronization (UE info Sync) carrying the data protocol data unit is sent.

[0344] In S1018, the first mobility management network element sends a location update indication to the home subscriber service network element, indicating that the terminal device has been successfully authenticated. Furthermore, if a data protocol data unit (dataPDU) is received from the mobility management network element in the first satellite, the arbitrary data transmission process is further executed.

[0345] It should be understood that Figure 11 The steps in the illustrated embodiments can also be explained in conjunction with the descriptions in any of the foregoing embodiments, and will not be repeated here for the sake of brevity. It should also be understood that the embodiments in this application can be combined with each other to implement the communication method proposed in this application, provided there is no logical conflict.

[0346] Figure 12 This is a schematic block diagram of a communication device provided in an embodiment of this application. The communication device 1100 can correspond to the first mobility management network element, a mobility management network element in any satellite, a home subscriber service network element, or a terminal device in the above method embodiments. For example... Figure 12 As shown, the device 1100 may include a transceiver module 1110 and a processing module 1120.

[0347] When the communication device 1100 corresponds to the first mobility management network element in the above method embodiment, the processing module 1120 can be used to generate a second key for the first satellite based on the first key; wherein, the first satellite is a candidate satellite for providing access services to the terminal device; the first key is a key for the terminal device received by the first mobility management network element from the home subscriber service network element; the transceiver module 1110 can be used to send the second key to the mobility management network element in the first satellite.

[0348] When the communication device 1100 corresponds to the terminal device in the above method embodiment, the processing module 1120 can be used to generate a second key for the first satellite based on a first key during the process of connecting to the mobility management network element in the first satellite; wherein, the first key is a key generated during the process of the terminal device attaching to the mobility management network element in the second satellite; and generate a non-access stratum (NAS) key based on the second key, wherein the NAS key is used to protect the messages between the terminal device and the mobility management network element in the first satellite; wherein, the NAS key includes a NAS encryption key and a NAS integrity protection key.

[0349] When the communication device 1100 corresponds to the mobility management network element in the first satellite in the above method embodiment, the transceiver module 1110 can receive a second key from the first mobility management network element. The second key is a key for the first satellite generated based on the first key. The first key is a key for the terminal device received by the first mobility management network element from the home subscriber service network element. The first satellite is a candidate satellite for providing access services to the terminal device. The processing module 1120 can be used to generate a NAS key based on the second key. The NAS key is used to protect the messages between the terminal device and the mobility management network element in the first satellite. The NAS key includes a NAS encryption key and a NAS integrity protection key.

[0350] When the communication device 1100 corresponds to the Home Subscriber Service (NSS) element in the above method embodiment, the transceiver module 1110 can be used to receive an authentication data request from the first Mobility Management (MLM) element, the authentication data request including the identifier of the terminal device; the transceiver module 1110 can also send an authentication data response to the first MLM element, the authentication data response including an initial authentication vector for authenticating the terminal device, the initial authentication vector including RAND, AUTN, XRES and a first key, the first key being a key for the terminal device received by the first MLM element from the SLS element.

[0351] It should be understood that the specific execution process of each module has been described in detail in the above method embodiments, and will not be repeated here for the sake of brevity.

[0352] The transceiver module 1110 in the communication device 1100 can be implemented using a transceiver, for example, it can correspond to... Figure 13 The transceiver 1220 in the communication device 1200 shown, and the processing module 1120 in the communication device 1100, can be implemented by at least one processor, for example, corresponding to Figure 13 The processor 1210 in the communication device 1200 shown in the figure.

[0353] When the communication device 1100 is a chip or chip system configured in a communication device, the transceiver module 1110 in the communication device 1100 can be implemented through input / output interfaces, circuits, etc., and the processing module 1120 in the communication device 1100 can be implemented through a processor, microprocessor, or integrated circuit integrated on the chip or chip system.

[0354] Figure 13 This is another schematic block diagram of the communication device provided in the embodiments of this application. For example... Figure 13 As shown, the communication device 1200 may include a processor 1210. The processor 1210 may be used to execute the methods executed by the first mobility management network element, any mobility management network element in a satellite, the home subscriber service network element, or the terminal device in the above method embodiments.

[0355] In some possible implementations, the communication device 1200 may include a transceiver 1220. The transceiver 1220 may communicate with the processor 1210 via an internal connection path. The processor 1210 may control the transceiver 1220 to transmit and / or receive signals.

[0356] In some possible implementations, the communication device 1200 may include a memory 1230. The memory 1230 may communicate with the processor 1210 via an internal connection. The memory 1230 and the processor 1210 may be integrated together or disposed separately. The memory 1230 may also be an external memory. The memory 1230 is used to store instructions, and the processor 1210 is used to execute the instructions stored in the memory 1230 to perform the methods described in the above method embodiments.

[0357] It should be understood that the communication device 1200 may correspond to the first mobility management network element, a mobility management network element in any satellite, a home subscriber service network element, or a terminal device in the above method embodiments, and may be used to execute the various steps and / or processes executed by the first mobility management network element, a mobility management network element in any satellite, a home subscriber service network element, or a terminal device in the above method embodiments. Optionally, the memory 1230 may include a read-only memory and a random access memory, and provide instructions and data to the processor. A portion of the memory may also include non-volatile random access memory. The memory 1230 may be a separate device or integrated into the processor 1210. The processor 1210 may be used to execute the instructions stored in the memory 1230, and when the processor 1210 executes the instructions stored in the memory, the processor 1210 is used to execute the various steps and / or processes of the above method embodiments corresponding to the first mobility management network element, a mobility management network element in any satellite, a home subscriber service network element, or a terminal device.

[0358] The transceiver 1220 may include a transmitter and a receiver. The transceiver 1220 may further include an antenna, and the number of antennas may be one or more. The processor 1210 and memory 1230 may be integrated with the transceiver 1220 on different chips. For example, the processor 1210 and memory 1230 may be integrated in a baseband chip, and the transceiver 1220 may be integrated in a radio frequency chip. Alternatively, the processor 1210 and memory 1230 may be integrated with the transceiver 1220 on the same chip. This application does not limit this.

[0359] Alternatively, transceiver 1220 can also be a communication interface, such as an input / output interface or circuit. This transceiver 1220, along with processor 1210 and memory 1230, can all be integrated into the same chip, such as within a baseband chip.

[0360] This application also provides a communication device including at least one processor. The at least one processor executes a computer program or logic circuit to cause the processing device to perform the method executed by the first mobility management network element, a mobility management network element in any satellite, a home subscriber service network element, or a terminal device in the above-described method embodiments. The communication device may further include a memory for storing the computer program.

[0361] This application also provides a communication device, including a processor and an input / output interface. The input / output interface is coupled to the processor. The input / output interface is used for inputting and / or outputting information. The information includes at least one of instructions and data. The processor is used to execute a computer program to cause the processing device to perform the method executed by the first mobility management network element, the mobility management network element in any satellite, the home subscriber service network element, or the terminal device in the above method embodiments.

[0362] This application also provides a communication device, including a processor and a memory. The memory stores a computer program, and the processor retrieves and runs the computer program from the memory, causing the processing device to execute the method executed by the first mobility management network element, a mobility management network element in any satellite, a home subscriber service network element, or a terminal device in the above method embodiments.

[0363] It should be understood that the aforementioned processing device can be one or more chips. For example, the processing device can be a field-programmable gate array (FPGA), an application-specific integrated circuit (ASIC), a system-on-chip (SoC), a central processor unit (CPU), a network processor (NP), a digital signal processor (DSP), a microcontroller unit (MCU), a programmable logic device (PLD), or other integrated chips.

[0364] In implementation, each step of the above method can be completed by integrated logic circuits in the processor's hardware or by instructions in software. The steps of the method disclosed in the embodiments of this application can be directly implemented by a hardware processor, or by a combination of hardware and software modules in the processor. The software modules can reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method. To avoid repetition, detailed descriptions are omitted here.

[0365] It should be noted that the processor in the embodiments of this application can be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method embodiments can be completed by the integrated logic circuitry in the processor's hardware or by instructions in software form. The processor can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly embodied as being executed by a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules can be located in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. This storage medium is located in memory, and the processor reads the information in the memory and, in conjunction with its hardware, completes the steps of the above methods.

[0366] It is understood that the memory in the embodiments of this application can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM). It should be noted that the memory used in the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0367] According to the method provided in the embodiments of this application, this application also provides a computer program product, which includes: a computer program or a set of instructions, which, when the computer program or set of instructions is run on a computer, causes the computer to execute the method executed by the first mobility management network element, the mobility management network element in any satellite, the home subscriber service network element, or the terminal device in the above method embodiments.

[0368] According to the method provided in the embodiments of this application, this application also provides a computer-readable storage medium storing a program that, when run on a computer, causes the computer to execute the method executed by the first mobility management network element, the mobility management network element in any satellite, the home subscriber service network element, or the terminal device in the above method embodiments.

[0369] According to the method provided in the embodiments of this application, this application also provides a communication system, which may include the aforementioned first mobility management network element, mobility management network element in any satellite, home subscriber service network element, or terminal equipment.

[0370] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0371] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0372] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A communication method, characterized in that, The first mobility management network element applied in the terrestrial network includes: A second key is generated for the first satellite based on the first key; wherein the first satellite is a candidate satellite for subsequently providing access services to the terminal device; and the first key is a key for the terminal device received by the first mobility management network element from the home subscriber service network element. The second key is sent to the mobility management network element in the first satellite.

2. The method according to claim 1, characterized in that, Before generating the second key for the first satellite based on the first key, the method further includes: Receive the identifier of the terminal device from the mobility management network element on the initial satellite; If it is determined that authentication of the terminal device is required, an authentication data request is sent to the home user service network element, wherein the authentication data request includes the identifier of the terminal device; The system receives an authentication data response from the home user service network element. The authentication data response includes an initial authentication vector for authenticating the terminal device. The initial authentication vector includes a random number RAND, an authentication token AUTN, an expected response XRES, and the first key.

3. The method according to claim 2, characterized in that, The method further includes: Identify the second satellite as a candidate satellite to provide subsequent access services to the terminal device; The initial authentication vector is sent to the mobility management network element in the second satellite.

4. The method according to claim 3, characterized in that, The authentication data request also includes instruction information related to S&F operations; the authentication data response also includes contract data related to S&F operations. The initial authentication vector is carried in a message sent by the first mobility management network element to the mobility management network element in the second satellite. The message also includes the subscription data and key identifier related to the S&F operation. The key identifier is used to identify the second key.

5. The method according to claim 3 or 4, characterized in that, Before sending the second key to the mobility management network element in the first satellite, the method further includes: The system receives an indication from a mobility management network element in the second satellite, the indication indicating that authentication for the terminal device was successful.

6. The method according to claim 5, characterized in that, The initial satellite and the second satellite are either different satellites or the same satellite, and the first satellite and the second satellite are different satellites.

7. The method according to claim 2, characterized in that, The specific steps of sending the second key to the mobility management network element in the first satellite are as follows: The deduced authentication vector is sent to the mobility management network element in the first satellite; the deduced authentication vector includes RAND, AUTN, XRES and the second key.

8. The method according to claim 7, characterized in that, The initial satellite and the first satellite may be different satellites or the same satellite.

9. The method according to any one of claims 1-8, characterized in that, The step of generating a second key for the first satellite based on the first key includes: The second key is generated using the first key and the first input parameters; wherein the first input parameters include one or more of the following: The identifier of the first satellite, the identifier of the mobility management network element in the first satellite, or the key identifier; wherein the key identifier is used to identify the second key.

10. The method according to any one of claims 1-9, characterized in that, The first key is the root key K shared between the terminal device and the first mobility management network element. ASME .

11. A communication method, characterized in that, The method is applied to a terminal device and includes: A second key for the first satellite is generated based on the first key; wherein the first key is a key generated during the process of the terminal device attaching to the mobility management network element in the second satellite; and A non-access stratum (NAS) key is generated based on the second key. The NAS key is used to protect messages between the terminal device and the mobility management network element in the first satellite. The NAS key includes a NAS encryption key and a NAS integrity protection key.

12. The method according to claim 11, characterized in that, The step of generating the NAS key based on the second key includes: Receive a first NAS message from the mobility management network element in the first satellite. The first NAS message is used to indicate the establishment of a secure connection. The first NAS message includes a NAS integrity protection algorithm and a NAS encryption algorithm. The NAS integrity protection key is generated based on the second key and the NAS integrity protection algorithm, and the NAS encryption key is generated based on the second key and the NAS encryption algorithm. The method further includes: The integrity of the first NAS message is verified based on the NAS integrity protection key and the NAS integrity protection algorithm; If the integrity verification passes, a second NAS message is sent to the mobility management network element of the first satellite. The second NAS message is used in response to an instruction to establish a secure connection.

13. The method according to claim 12, characterized in that, The first NAS message also includes a key identifier, wherein the key identifier is used to identify the second key; The step of generating a second key for the first satellite based on the first key includes: The second key is generated based on the first key and the key identifier.

14. The method according to claim 12, characterized in that, The first NAS message also includes the identifier of the mobility management network element of the second satellite; The step of generating a second key for the first satellite based on the first key includes: A second key for the first satellite is generated based on the first key and the identifier of the mobility management network element of the first satellite.

15. The method according to claim 12, characterized in that, The method further includes: Receive a broadcast message, the broadcast message including the identifier of the first satellite; The step of generating a second key for the first satellite based on the first key includes: A second key for the first satellite is generated based on the first key and the identifier of the first satellite.

16. The method according to any one of claims 11-15, characterized in that, The method further includes: Store the correspondence between the NAS key and the first satellite.

17. The method according to claim 16, characterized in that, The method further includes: When the device leaves the first satellite and communicates with the mobility management network element in the first satellite again, it uses the stored NAS key to communicate with the mobility management network element in the first satellite.

18. The method according to any one of claims 11-17, characterized in that, The first satellite and the second satellite may be the same satellite or different satellites.

19. The method according to any one of claims 11-18, characterized in that, The first key is the root key K shared between the terminal device and the first mobility management element in the terrestrial network. ASME .

20. A communication device, characterized in that, include: A module for performing the method as described in any one of claims 1 to 10, or a module for performing the method as described in any one of claims 11 to 19.

21. A communication system, characterized in that, include: A communication device for performing the method as described in any one of claims 1 to 10, and a communication device for performing the method as described in any one of claims 11 to 19.

22. A computer-readable storage medium, characterized in that, Used to store computer program instructions, the computer program causing a computer to perform the method as described in any one of claims 1 to 19.

23. A computer program product, characterized in that, It includes computer program instructions that cause a computer to perform the method as described in any one of claims 1 to 19.