5g nas signaling transparent transmission and adaptation method based on dvb system

CN122802903APending Publication Date: 2026-09-22COWAVE SATELLITE COMM TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611232209.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-08-14
Publication Date
2026-09-22

AI Technical Summary

Technical Problem

这种方式不仅带来了很大的协议头部开销,挤占了卫星受限的带宽资源;且其基于地面网络设计的信令交互机制,在面对卫星链路的长时延和高误码率时,容易引发信令超时重传风暴与状态失步

Benefits of technology

通过在底层通用流封装报文中自定义特定协议类型,并设计极简的控制报文承载格式,减少了信令传输的冗余字节,释放了卫星受限的带宽资源。面对脱离重度IP隧道后底层标识易被伪造的安全隐患,复用底层登录阶段协商的会话密钥生成跨层绑定验证令牌,在不引入额外协议开销的前提下,为高层鉴权构建了可靠的身份验证机制。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122802903A_ABST
    Figure CN122802903A_ABST
Patent Text Reader

Abstract

The application discloses a 5G NAS signaling transmission and adaptation method based on a DVB system. The method comprises the following steps: a satellite terminal station encapsulates non-access layer signaling to be sent in a general stream encapsulation message with a specific protocol type identifier and sends the general stream encapsulation message to a gateway station; the gateway station extracts a message payload based on the identifier, allocates a core network side identifier for the terminal station, encapsulates the non-access layer signaling and user location information into a first next generation application protocol message, and sends the first next generation application protocol message to the core network; and the gateway station receives a second next generation application protocol message issued by the core network, converts downlink non-access layer signaling into a general stream encapsulation message with the specific identifier, and issues the general stream encapsulation message to the terminal station. The application realizes efficient and low-cost connection of a satellite network and a 5G core network without changing a bottom layer communication system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the technology of satellite communication and terrestrial core network integration, and in particular to a 5GNAS signaling pass-through and adaptation method based on DVB system. Background Technology

[0002] As satellite networks evolve towards non-terrestrial networks, deep integration of satellite and terrestrial core networks has become a key trend. A unified core network architecture can provide standardized authentication and mobility management for massive numbers of satellite users, which has significant technical value in improving the collaborative efficiency of heterogeneous networks, reducing overall network control overhead, and ensuring underlying security.

[0003] In traditional satellite communications, the underlying DVB protocol stack is widely used. When connecting such terminals to the 5G core network, existing technologies typically rely on a heavily non-3GPP access architecture, requiring the terminals to implement a complete IP layer and complex secure tunneling protocols. This approach not only incurs significant protocol header overhead and consumes limited satellite bandwidth resources, but its terrestrial network-based signaling interaction mechanism is also prone to signaling timeout retransmission storms and state synchronization failures when facing the long latency and high error rate of satellite links. Furthermore, the fragmentation of location identification systems between heterogeneous networks makes it difficult for the core network to effectively track the physical location of terminals.

[0004] In summary, existing methods have significant limitations in heterogeneous network protocol integration and cross-layer state management. How to efficiently and reliably establish control plane interaction channels between terminals and the core network under stringent satellite channel constraints is a pressing technical challenge. Therefore, it is necessary to research an adaptive method that can improve the efficiency and robustness of signaling interaction in heterogeneous networks. Summary of the Invention

[0005] Purpose of the invention: In order to solve the above-mentioned problems in the existing technology, a 5G NAS signaling pass-through and adaptation method based on DVB system is provided.

[0006] Technical solution: A 5G NAS signaling pass-through and adaptation method based on DVB system, including: The satellite terminal station acquires the non-access stratum signaling to be sent, encapsulates the non-access stratum signaling in a general flow encapsulation message with a specific protocol type identifier, and sends it to the gateway station via the satellite link; The gateway station receives the generic stream encapsulation message, determines the signaling data carried by the generic stream encapsulation message based on the specific protocol type identifier, and extracts the corresponding message payload; The gateway station assigns a core network-side identifier to the satellite terminal station, encapsulates the non-access stratum signaling in the message payload and the acquired user location information into a first next-generation application protocol message, and sends it to the core network. The gateway station receives a second next-generation application protocol message containing downlink non-access stratum signaling from the core network, converts the downlink non-access stratum signaling into a general flow encapsulation message with the specific protocol type identifier, and sends it to the satellite terminal station through the forward link.

[0007] In one embodiment, the message payload includes a signaling header and a protocol data unit, wherein the protocol data unit is used to carry the non-access stratum signaling; The signaling header includes a control field, an addressing field, a sequence number field, and an acknowledgment field; The addressing field records the link layer device identifier of the satellite terminal station, and the sequence number field and the acknowledgment field are used for link layer retransmission control.

[0008] In one embodiment, the control field includes a message type indicator, the value types of which include at least: The data transmission type used to transmit the protocol data unit; The connection establishment request type used to trigger terminal access; The connection establishment response type used to provide feedback on access results; Connection release type used for disconnecting.

[0009] In one embodiment, when the message type indicates the connection establishment request type, the satellite station carries a binding verification token and a core network hidden identifier in the protocol data unit; After receiving the token, the gateway station verifies the binding verification token based on the pre-stored link layer session key. If the verification passes, the gateway station establishes a secure binding relationship between the link layer device identifier and the core network hidden identifier, and encapsulates the core network hidden identifier into the first next-generation application protocol message.

[0010] In one embodiment, the binding verification token is calculated by the satellite terminal based on the link layer session key, the link layer device identifier, the core network hidden identifier, and the current system timestamp, using a preset hash message authentication code algorithm.

[0011] In one embodiment, when the message type indicates a connection establishment request type, The satellite terminal station obtains the currently received physical layer frame header identifier and sends the physical layer frame header identifier to the gateway station along with the protocol data unit.

[0012] In one embodiment, the gateway station extracts the physical layer frame header identifier and queries a pre-built location mapping table based on the physical layer frame header identifier to obtain the corresponding virtual tracking area code and virtual cell identifier; The gateway station encapsulates the virtual tracking area code and the virtual cell identifier as the user location information into the first next-generation application protocol message.

[0013] In one embodiment, the location mapping table is pre-constructed in the following manner: The virtual tracking area code is calculated based on the satellite number, beam number, and pre-configured reference tracking area code; The virtual cell identifier is generated by combining the public network identifier, the virtual base station identifier, and the virtual cell number obtained by jointly encoding the satellite number and the beam number.

[0014] In one embodiment, the specific steps of the link layer retransmission control include: After sending the general stream encapsulation message, the sender starts a retransmission timer, wherein the sender is the satellite terminal station or the gateway station; After the receiver correctly receives the general stream encapsulation message, it generates an acknowledgment message based on the sequence number field and fills the acknowledgment message into the acknowledgment response field and returns it to the sender. If the sender does not receive a matching acknowledgment before the retransmission timer expires, then the message is retransmitted.

[0015] In one embodiment, the step of the receiver returning confirmation information specifically includes: If the recipient has data to be sent, the confirmation information is returned along with the confirmation response field of the data to be sent; If there is no data to be sent, then send a separate acknowledgment message containing only the acknowledgment information to the sender; The method further includes: when the number of retransmissions by the sender reaches the preset maximum number of retransmissions, triggering an authentication failure notification for the non-access stratum signaling.

[0016] In one embodiment, the satellite station, while in a connected state, carries the currently received physical layer frame header identifier in the signaling header each time it sends the general stream encapsulation message; The gateway station continuously monitors the physical layer frame header identifier reported by the satellite terminal station; When a change in the physical layer frame header identifier is detected, the gateway station re-queries the location mapping table to obtain the updated user location information and triggers the terminal context modification process in the core network.

[0017] The beneficial effects of this invention are: By defining specific protocol types within the underlying general-purpose stream encapsulation messages and designing a minimalist control message bearer format, redundant bytes in signaling transmission are reduced, freeing up satellite-constrained bandwidth resources. Addressing the security vulnerability of the underlying identifier being easily forged after leaving a heavy IP tunnel, the session key negotiated during the underlying login phase is reused to generate a cross-layer binding verification token. This constructs a reliable authentication mechanism for higher-layer authentication without introducing additional protocol overhead.

[0018] By extracting the physical layer frame header identifier as a link and combining it with an offline constructed virtual mapping table, a transparent conversion from the underlying physical beam to the core network standard tracking area is achieved, ensuring effective tracking of terminal mobility on the network side.

[0019] In addition, to overcome the risk of state synchronization loss caused by long satellite latency and high bit error rate, a lightweight acknowledgment and retransmission mechanism combined with an adaptive timer is introduced at the link layer. This strictly controls the packet loss recovery period caused by channel fading within the timeout threshold of higher-layer protocols, thereby improving the robustness of control plane interaction under harsh operating conditions. Attached Figure Description

[0020] Figure 1 This is a schematic diagram of the overall process of the present invention.

[0021] Figure 2 This is a schematic diagram of the general stream encapsulation message sending and receiving mechanism of the present invention.

[0022] Figure 3 This is a schematic diagram of the authentication failure notification mechanism of the present invention.

[0023] Figure 4 This is a schematic diagram of the satellite terminal connection status mechanism of the present invention.

[0024] Figure 5 This is a flowchart of the NAS authentication signaling process of this invention. Detailed Implementation

[0025] Combination Figure 1 Description of Example 1: This describes a 5G NAS signaling pass-through and adaptation method based on the DVB system, mainly including the following steps: Step 101: The satellite terminal station acquires the non-access stratum signaling to be sent, encapsulates the non-access stratum signaling in a general flow encapsulation message with a specific protocol type identifier, and sends it to the gateway station through the satellite link; In practical implementation, this method is applicable to satellite network environments that operate in transparent forwarding mode, where the satellite itself does not have onboard baseband processing capabilities and only serves as a relay node for physical layer signals.

[0026] Since traditional satellite terminals follow the DVB system and do not have a standard 5G New Radio protocol stack, a security module is configured inside the satellite terminal in order to trigger the registration and authentication process of the 5G core network.

[0027] The security module can be implemented using a hardware USIM card slot or a software SIM solution, and connected to the terminal station's main control chip via a standard communication interface, such as an ISO7816 interface or an SPI interface. When network access is required, the terminal station's main control chip calls the security module to generate a hidden identity identifier and related authentication parameters, thereby constructing uplink non-access stratum signaling.

[0028] To carry this signaling at the link layer, the terminal station fills it into the payload area of ​​a general flow encapsulation message and writes a predefined specific protocol type identifier in the protocol type field of the message header. This identifier can be set to 0x0901, specifically used to declare to the network side that the current message carries not ordinary user data, but higher-layer control signaling. After encapsulation, the message is sent to the ground gateway station via the satellite backhaul link.

[0029] Step 102: The gateway station receives the general stream encapsulation message, determines the signaling data carried by the general stream encapsulation message based on the specific protocol type identifier, and extracts the corresponding message payload; After completing physical layer demodulation and decoding, the receiving module of the gateway station recovers a continuous stream of generic stream encapsulated messages. At this point, the parsing logic performs conditional branching judgments on the protocol type field in each message header.

[0030] In the first case, if the value of the field is detected to be equal to the specific protocol type identifier, it is determined that the current message carries non-access stratum signaling data. Then, the link layer message header is stripped, the internal message payload is extracted, and sent to the signaling processing unit.

[0031] In the second scenario, if the field is detected to be another regular value, such as 0x0800 representing an IPv4 service flow, the packet is directly forwarded to the corresponding service gateway as a regular user data flow. This cross-layer routing mechanism based on a specific identifier enables the gateway station to accurately capture scattered control signaling without changing the existing DVB broadband service processing logic.

[0032] Step 103: The gateway station assigns a core network side identifier to the satellite terminal station, encapsulates the non-access stratum signaling in the message payload and the acquired user location information into a first next-generation application protocol message, and sends it to the core network; In this step, the gateway station assumes a protocol conversion role similar to that of a non-3GPP access gateway. To enable the 5G core network's access and mobility management entities to identify and track the satellite terminal, the gateway station maintains a local terminal context mapping table and assigns a locally unique core network-side identifier to the terminal accessing the network for the first time. This core network-side identifier corresponds to the access network user equipment identifier in the next-generation application protocol interaction between the gateway station and the core network, and is used to uniquely identify the terminal's signaling connection context on the N2 interface.

[0033] The gateway station extracts the non-access stratum signaling stripped out in the aforementioned steps, combines it with the user location information dynamically obtained based on satellite beam coverage, and assembles it into a first next-generation application protocol message according to the standard interface protocol specification.

[0034] This message is typically an initial user equipment message. After assembly, the gateway station sends it to the core network through the underlying reliable transmission connection, thereby opening up the uplink signaling channel to the 5G core network while retaining the DVB air interface characteristics.

[0035] Step 104: The gateway station receives a second next-generation application protocol message containing downlink non-access stratum signaling issued by the core network, determines the target satellite terminal based on the core network side identifier carried in the second next-generation application protocol message, converts the downlink non-access stratum signaling into a general flow encapsulation message with the specific protocol type identifier, and sends it to the target satellite terminal through the forward link.

[0036] In response to authentication requests or registration acceptance responses returned by the core network, the gateway station receives the second-generation application protocol message containing these downlink non-access stratum signaling messages, parses out the core network-side identifier of the target terminal, and looks up the local context mapping table to determine the corresponding target satellite terminal.

[0037] To ensure that downlink signaling can be accurately received in a broadcast satellite forward link, the gateway station constructs a downlink generic stream encapsulation message, which not only fills in the specific protocol type identifier in the protocol type field, but also carries an address label bound to the target satellite terminal in the message header.

[0038] After being relayed by the satellite, the message covers the entire beam area. The underlying hardware receivers of each satellite station perform hard filtering based on the address tags in the message header, intercepting and receiving only the general stream encapsulation messages belonging to themselves, and then extracting the downlink non-access stratum signaling and handing it over to the upper layer protocol stack for processing, thus completing the closed loop of end-to-end bidirectional signaling interaction.

[0039] Example 2: A further detailed explanation of the specific format of the message payload and the terminal state management mechanism in the general stream encapsulation message is provided. In one possible implementation, it includes: The message payload includes a signaling header and a protocol data unit, the protocol data unit being used to carry the non-access stratum signaling.

[0040] In order to efficiently transmit higher-layer control signaling in satellite links with limited bandwidth resources and avoid the additional overhead caused by multi-layer header encapsulation in the standard NR protocol stack, this method has customized the internal structure of the general stream encapsulation message.

[0041] Specifically, after stripping the outer message header, the internal message payload is strictly divided into two parts: a front-end signaling header and a rear-end protocol data unit. The signaling header is used to maintain the logical connection and transmission reliability between the terminal station and the gateway station at the link layer, while the protocol data unit acts as a transparent carrier container, directly loading the non-access stratum signaling message body generated by the core network or terminal station security module. The actual byte length of this protocol data unit does not need to be explicitly indicated in the signaling header, but is calculated by the receiving end by subtracting the known fixed-length signaling header from the total length of the outer general stream encapsulated message, thereby reducing redundant fields.

[0042] The signaling header includes a control field, an addressing field, a sequence number field, and an acknowledgment field; wherein, the addressing field records the link layer device identifier of the satellite terminal station, and the sequence number field and the acknowledgment field are used for link layer retransmission control.

[0043] In practice, the signaling header is designed as a compact 5-byte structure to adapt to the satellite environment.

[0044] The control field in the first byte indicates the protocol version, transmission direction, and specific functional attributes of the current signaling. The addressing field that follows occupies 2 bytes and is filled with the link layer device identifier assigned to the satellite station when logging into the underlying physical network.

[0045] The existence of this addressing field enables gateway stations to perform accurate device-level routing of packet sources or destinations at the internal logic level when processing massive concurrent general flow encapsulation packets, without relying on potentially changing external network addresses.

[0046] The sequence number field and the acknowledgment field each occupy one byte. Together, they provide lightweight automatic retransmission request support for general stream encapsulation layers that originally lacked an acknowledgment mechanism. Each time the sender sends a message with protocol data units, the value of the sequence number field is incremented; the receiver then fills the correctly received sequence number into the acknowledgment field and returns it, thereby enabling fast packet loss detection and recovery at the underlying link level.

[0047] The control field includes a message type indicator, and the value types of the message type indicator include at least: a data transmission type for transmitting the protocol data unit; a connection establishment request type for triggering terminal access; a connection establishment response type for providing access results; and a connection release type for disconnection.

[0048] Since traditional digital video broadcasting systems lack a dedicated radio resource control layer, this method takes over the underlying connection control logic by using message type indicator bits within the control field. This indicator typically occupies 3 bits to distinguish between different stages of interaction.

[0049] When the indication value is data transmission type, it indicates that the protocol data unit of the current message carries actual non-access stratum signaling such as authentication and registration, and the receiver needs to perform protocol conversion on it.

[0050] When the terminal station wakes up for the first time or re-enters after disconnecting from the network, the message type indicator in the constructed message is set to the connection establishment request type, which is used to declare the access intention to the gateway station and request the allocation of core network side resources.

[0051] After processing, the gateway station informs the end station of the resource allocation result by sending a message with the value of a connection establishment response.

[0052] When the network initiates a registration process or the gateway detects a link anomaly, it forces the end station to clean up the locally maintained context connection parameters by sending a message with a value of connection release type.

[0053] A handshake mechanism based on message type indication is used to build a complete control plane connection management process with low byte overhead.

[0054] like Figure 4 As shown, the satellite terminal maintains a connection state model for signaling transmission; When the link layer login is completed but no registration is initiated, the satellite terminal is in an idle state; after sending the message corresponding to the connection establishment request type, the satellite terminal enters the connected state. After receiving a message or signaling interaction timeout corresponding to the connection release type, the satellite station falls back from the connected state to the idle state.

[0055] To coordinate with the aforementioned message type indications, the satellite terminal station internally operates a simplified two-state finite state machine. When the terminal station completes the underlying broadband interactive login process and has the communication capabilities of the physical layer and link layer, but has not yet generated a service requirement to register with the 5G core network, the terminal station resides in the idle state.

[0056] In this state, the terminal station only maintains the underlying time and frequency synchronization and does not send any non-access stratum signaling.

[0057] Once the upper-layer business triggers the registration requirement, the terminal station sends a connection establishment request, and its internal state immediately switches to the connected state.

[0058] In the connected state, the terminal station continuously monitors downlink generic flow encapsulation packets and exchanges authentication parameters and security modes with the gateway station.

[0059] If a connection release message is received from the gateway station during the interaction, or if the locally maintained signaling timeout timer reaches the set threshold, the terminal station determines that the current control plane connection has failed, then clears the cached security context, falls back from the connected state to the idle state, and waits for the conditions to be met before re-initiating access.

[0060] To support the connection state model of terminal stations, the gateway station synchronously maintains a terminal context mapping table. When the gateway station receives a connection establishment request from a terminal station, if there is no corresponding record in the table, it creates a new context entry for that terminal station, recording its link layer device identifier, the allocated core network side identifier, and the current state machine information, and starts the corresponding silent timer. If no uplink signaling is received from the terminal station within the set timeout period, or if a context release command is received from the core network, the gateway station deletes the entry and reclaims the relevant identifier resources, thereby ensuring the effective rotation of the gateway station's memory resources in high-concurrency scenarios.

[0061] The message type indicator also includes an acknowledgment-only type for independent link-layer acknowledgment. When the receiver needs to send acknowledgment information independently without carrying protocol data units, the message type indicator is configured to the acknowledgment-only type. In this case, the message only contains the signaling header, and the acknowledgment response field is filled with the acknowledged sequence number.

[0062] Example 3: A mechanism is provided to achieve cross-layer identity binding verification using underlying login credentials in the absence of network layer security protocol support.

[0063] In one possible implementation, the following steps are included: Step 301: When the message type indicates the connection establishment request type, the satellite terminal obtains the core network hidden identifier from the built-in security module and carries the binding verification token and the core network hidden identifier in the protocol data unit; In non-access stratum signaling pass-through scenarios, satellite terminals need to prove the legitimacy of their identity to the core network.

[0064] Due to the lack of secure tunneling mechanisms in traditional terrestrial networks, when constructing a connection establishment request message, the end station extracts the core network hidden identifier derived from the long-term key from the built-in security module.

[0065] To prevent the identifier from being forged or tampered with by malicious nodes during air interface transmission, the end station synchronously attaches a binding verification token to the reserved field of the protocol data unit and reports it together as a digital signature credential for identity verification.

[0066] Step 302: The binding verification token is calculated by the satellite terminal based on the link layer session key, the link layer device identifier, the core network hidden identifier, and the current system timestamp obtained from the system broadcast signal, using a preset hash message authentication code algorithm.

[0067] The purpose of this step is to construct high-level identity anchors by reusing low-level security parameters across layers.

[0068] During the broadband interactive login phase at the bottom layer, the terminal station has negotiated and generated a link layer session key with the network side to protect physical layer data.

[0069] The session key is extracted as the input key for cryptographic operations, and the currently received system broadcast time is obtained as a timestamp. Combined with the device's link layer identifier and core network hidden identifier, a preset hash message authentication code algorithm is executed. The specific calculation formula is as follows: BVT=HMAC-SHA256(K_logon,Terminal_ID||SUCI||Timestamp); Wherein, BVT is the binding verification token, HMAC-SHA256 is the preset hash message authentication code algorithm, K_logon is the link layer session key, Terminal_ID is the link layer device identifier, SUCI is the core network hidden identifier, Timestamp is the current system timestamp, and || represents the string concatenation operation.

[0070] By introducing a timestamp parameter into the above operational logic, it is possible to resist replay attacks targeting connection establishment requests and ensure the uniqueness of each request message.

[0071] Step 303: After receiving the token, the gateway station verifies the binding verification token based on the pre-stored link layer session key. After receiving a message with a connection establishment request indication, the gateway station parses out the link layer device identifier.

[0072] Query the locally deployed login credential database and extract the link layer session key that the device synchronously saves during the underlying login process.

[0073] Using the extracted key and the timestamp and hidden identifier carried in the message, the gateway station recalculates a local test token according to the same hash message authentication code algorithm, and compares the local test token with the binding verification token carried in the message byte by byte.

[0074] Based on the comparison results, the gateway station executes the corresponding branch processing procedure.

[0075] In the first operating condition, step 304 is executed. If the verification passes, the gateway station establishes a secure binding relationship between the link layer device identifier and the core network hidden identifier, and encapsulates the core network hidden identifier into the first next-generation application protocol message.

[0076] If the calculated local test token matches the binding verification token carried in the message, the verification is considered successful.

[0077] At this point, the gateway station confirms that the link layer device identifier has not been misused and that its association with the hidden identifier in the core network is legitimate.

[0078] The gateway station solidifies this security binding relationship in the terminal context mapping table, extracts the core network hidden identifier and fills it into the corresponding field of the initial user equipment message, and then initiates a formal registration request to the core network.

[0079] The cross-layer verification mechanism blocks the path for malicious terminals to consume core network authentication resources by forging underlying identifiers.

[0080] In the second scenario, step 305 is executed. If the verification of the binding authentication token fails, the gateway station returns a connection establishment response carrying an error code to the satellite station. After receiving the error code or the authentication failure notification triggered by the link layer retransmission failure, the satellite station suspends the current signaling interaction and re-initiates access with a delay according to the preset exponential backoff algorithm.

[0081] If the two tokens do not match, the verification is deemed to have failed. The gateway station refuses to allocate core network resources to the terminal and constructs a connection establishment response message, writing a specific error code indicating authentication failure into the message payload.

[0082] When the satellite station parses the error code, or receives an authentication failure notification from the core network in a subsequent process, it clears the current temporary session parameters and stops signaling transmission. To avoid a signaling storm caused by frequent retries from a large number of failed authentication stations, the station internally triggers backoff control logic. An initial backoff duration is set, and then the waiting time increases exponentially with each failure until the set maximum backoff duration is reached. In one optional implementation, before the backoff timer expires, the initial backoff duration is set to 2 seconds, and the backoff duration doubles after each failure, with a maximum backoff duration of 60 seconds. Those skilled in the art can adaptively adjust the above backoff parameters according to the round-trip delay characteristics of the satellite link and system capacity requirements, and determine suitable values ​​without creative effort. The station is prohibited from sending any new connection establishment requests to the network side.

[0083] Example 4: Based on the above examples, this example provides a method for constructing and mapping core network standard location information in a digital video broadcasting system without the concept of cells. In one possible implementation, the location mapping table is pre-constructed in the following way: Step 401, the location mapping table is pre-constructed in the following way: the virtual tracking area code is calculated based on the satellite number, beam number and pre-configured reference tracking area code; the virtual cell identifier is generated by combining the public network identifier, virtual base station identifier and virtual cell number obtained by jointly encoding the satellite number and the beam number.

[0084] During the configuration phase before system operation, to address the incompatibility issue of heterogeneous network location identifiers, an offline data structure reflecting the correspondence between satellite physical coverage areas and core network logical areas was established. Specifically, virtual location parameters were assigned to each transponder beam of each satellite. The formula for calculating the virtual tracking area code is as follows: vTAC=Base_TAC+Satellite_Index*256+Beam_Index; Where vTAC is the virtual tracking area code, Base_TAC is the pre-configured baseline tracking area code, Satellite_Index is the satellite number, and Beam_Index is the beam number. 256 is the beam number addressing space reserved for each satellite, meaning that a single satellite is assumed to support a maximum of 256 independent beams.

[0085] Meanwhile, to generate a global identifier that conforms to the next-generation application protocol specification, a joint encoding method is adopted. The specific formula is as follows: vNR-CGI=(PLMN_ID,gNB_ID_virtual,Cell_ID_virtual); Wherein, vNR-CGI is the virtual cell identifier, PLMN_ID is the public network identifier, gNB_ID_virtual is the virtual base station identifier, and Cell_ID_virtual is the virtual cell number.

[0086] Through the above calculations, a beam-to-tracking area mapping table is solidified locally at the gateway station, providing data support for subsequent online location queries.

[0087] Step 402: When the message type indicates the connection establishment request type, the satellite terminal obtains the currently received physical layer frame header identifier and sends the physical layer frame header identifier to the gateway station in the protocol data unit.

[0088] When initiating an access process, the terminal station needs to provide evidence representing its current geographical location.

[0089] Considering that the underlying physical link contains beam attribute information, the end station baseband processing module extracts the input stream identifier from the currently locked downlink physical layer frame header as the physical layer frame header identifier. This identifier is inherent in the digital video broadcasting standard and is used to distinguish independent data streams sent by different transponders.

[0090] After extraction, it is filled into the reserved position of the protocol data unit and sent up along with the connection establishment request, thereby reporting coarse-grained location clues to the network side without adding additional positioning hardware.

[0091] Step 403: The gateway station extracts the physical layer frame header identifier and queries a pre-built location mapping table based on the physical layer frame header identifier to obtain the corresponding virtual tracking area code and virtual cell identifier; the gateway station encapsulates the virtual tracking area code and the virtual cell identifier as the user location information into the first next-generation application protocol message.

[0092] At the receiving end, the gateway station parses the uplink message to obtain the physical layer frame header identifier, and uses it as an index key to perform a matching search in a pre-built location mapping table.

[0093] After finding the corresponding table entry, extract the corresponding virtual tracking area code and virtual cell identifier.

[0094] To meet the core network's format requirements for terminal location tracking, the gateway station converts these two virtual parameters into standard user location information cells and embeds them into the initial user equipment message sent to access and mobility management functions. This conversion process remains transparent to the core network, allowing it to operate according to the established rules for processing standard terrestrial logical cells.

[0095] Step 404: During the connection state, the satellite station carries the currently received physical layer frame header identifier in the signaling header each time it sends the general stream encapsulation message; The gateway station continuously monitors the physical layer frame header identifier reported by the satellite terminal station; When a change in the physical layer frame header identifier is detected, the gateway station re-queries the location mapping table to obtain the updated user location information and triggers the terminal context modification process in the core network.

[0096] To support the mobility management of terminals between different satellite beams, the gateway station's control logic dynamically tracks the terminal stations in the connected state.

[0097] While the satellite terminal is in a connected state, when sending each uplink general stream encapsulation message, the satellite terminal carries the currently received physical layer frame header identifier in the reserved position of the protocol data unit.

[0098] When the gateway station extracts the protocol data unit of each uplink message, it synchronously reads the physical layer frame header identifier in the reserved location and compares it with the most recent identifier value recorded in the terminal context mapping table.

[0099] Due to the orbital motion of the satellite constellation or the geographical displacement of the terminal station itself, the terminal station may switch to an adjacent beam, causing a change in the physical layer frame header identifier it reports.

[0100] If the comparison reveals that the currently reported identifier is inconsistent with the historical value recorded in the terminal context mapping table, the gateway station uses the updated identifier to query the location mapping table again to obtain the new virtual location parameters.

[0101] The gateway station sends a terminal context modification message to the core network, carrying the updated user location information, thereby triggering the mobility update process on the network side and ensuring the routing validity when the core network issues paging messages.

[0102] like Figure 2 and Figure 3 As shown in Example 5, the link layer retransmission control mechanism in the general stream encapsulation message transmission process is further described in detail.

[0103] In one possible implementation, the specific steps of the link layer retransmission control include the following steps: Step 501, the specific steps of the link layer retransmission control include: After sending the general stream encapsulation message, the sender starts a retransmission timer, wherein the sender is the satellite terminal station or the gateway station; After the receiver correctly receives the general stream encapsulation message, it generates an acknowledgment message based on the sequence number field and fills the acknowledgment message into the acknowledgment response field and returns it to the sender. If the sender does not receive a matching acknowledgment response before the retransmission timer expires, i.e., does not receive an acknowledgment message containing the corresponding acknowledgment information, then message retransmission is performed.

[0104] When the sending end injects a message containing non-access stratum signaling into the physical layer sending queue, it simultaneously stores a copy of the message in the local retransmission buffer and starts timing logic for the message.

[0105] Because signaling interaction is bidirectional and symmetrical, the roles of the sender and receiver dynamically switch between the terminal station and the gateway station.

[0106] After verifying message integrity at the underlying layer, the receiver extracts the sequence number from the message header and uses it as confirmation information to fill the acknowledgment field of the reverse link message. If the sender's timing logic fails to capture the corresponding acknowledgment before reaching a preset threshold, it retrieves a copy from the buffer and retransmits it.

[0107] Step 502: The duration of the retransmission timer is determined based on the satellite one-way propagation delay and the receiving end processing delay, so that the link layer retransmission period is less than the timeout threshold of the non-access layer signaling.

[0108] To adapt to the long latency characteristics of satellite links and avoid unnecessary timeouts in higher-layer protocols caused by lower-layer transmission delays, the retransmission timer duration is calculated by multiplying the satellite one-way propagation delay by two times and adding it to the receiver processing delay. The specific calculation formula is as follows: T_GSE_ARQ = 2 * T_prop + T_proc; Where T_GSE_ARQ is the retransmission timer duration, T_prop is the satellite one-way propagation delay, and T_proc is the receiver processing delay.

[0109] The timer duration determined by the above formula ensures that the automatic retransmission request cycle of the general stream encapsulation layer is limited to the default timeout threshold range of the non-access stratum signaling, thereby quickly absorbing packet loss events caused by channel degradation within the link layer.

[0110] Step 503: When receiving the general stream encapsulation message, the receiver extracts the sequence number field; If the currently received sequence number is the same as the latest sequence number that has been successfully received, the receiver determines that the current message is a duplicate message, discards the payload data of the current message, but still returns the corresponding confirmation information based on the currently received sequence number.

[0111] In the event of reverse link packet loss, the receiver may receive messages with the same sequence number.

[0112] The processing logic extracts the sequence number of the current message and compares it with the locally recorded received sequence number status. If the two values ​​match, it means that the higher-layer signaling has been successfully processed. At this time, in order to avoid repeated delivery to the upper layer and causing state machine chaos, the receiver actively discards the non-access stratum signaling payload in the current message.

[0113] Meanwhile, in order to break the deadlock state where the sender keeps retransmitting due to not receiving an acknowledgment, the receiver forces the construction of an acknowledgment message containing the sequence number and sends it back.

[0114] Step 504, the step of the receiver returning confirmation information specifically includes: If the recipient has data to be sent, the confirmation information is returned along with the confirmation response field of the data to be sent; If no data is to be sent, a separate acknowledgment message containing only the acknowledgment information is sent to the sender; the method further includes: When the number of retransmissions by the sender reaches the preset maximum number of retransmissions, it reports the authentication failure notification of the non-access stratum signaling to the local non-access stratum protocol stack.

[0115] For the feedback path of confirmation information, this method designs two parallel branch logics.

[0116] In the first operating condition, if there are protocol data units to be sent in the receiver's sending queue, the control logic will directly write the confirmation information into the confirmation response field in the signaling header of the message to be sent, and achieve a zero-overhead response through the piggyback confirmation mechanism.

[0117] In the second scenario, if the receiver does not send any higher-level data within the preset delay window, an independent acknowledgment message is constructed with the message type indicator in the control field configured as an acknowledgment-only type to ensure that the sender receives feedback in a timely manner.

[0118] In addition, the sender internally maintains a retransmission counter. The counter increments each time a retransmission is performed. When the counter reaches the preset maximum retransmission count, the sender determines that the current physical link is in a state of severe fading or interruption. At this point, the sender clears the retransmission buffer and reports an authentication failure notification to the non-access layer protocol stack, thereby terminating meaningless lower-level retry operations.

[0119] Example 6: Further describes the signaling interaction sequence for a complete non-access stratum authentication and registration process between the satellite terminal and the core network.

[0120] During the initial access phase, the satellite station constructs a protocol data unit containing a registration request message. Combining the currently extracted physical layer frame header identifier with the calculated binding verification token, this protocol data unit is encapsulated into a generic flow encapsulation message. In the signaling header of this message, the protocol type identifier is set to a specific value, and the message type indicator in the control field is configured as a connection establishment request type. This message is transparently forwarded to the gateway station via the satellite link. Upon receiving the message, the gateway station executes cross-layer identity binding verification logic. If verification is successful, the gateway station extracts the physical layer frame header identifier and queries its local mapping table to obtain virtual location information. It then encapsulates the registration request message and this location information together into an initial user equipment message, which is sent to the access and mobility management function entity of the core network through the next-generation application protocol interface.

[0121] Upon receiving the initial registration request, the core network triggers the network-side authentication process, sending a downlink application protocol message containing the authentication request message. The gateway station extracts this authentication request message, converts it into a downlink general flow encapsulation packet with a specific protocol type identifier, and broadcasts it via the forward link. The target satellite station filters and receives the packet based on the address label in the packet header, extracts the authentication request message, and hands it over to the built-in security module for processing. The security module performs cryptographic operations and outputs authentication response parameters. Based on these parameters, the station constructs an uplink packet containing the authentication response message and returns it to the gateway station. The gateway station transparently forwards this authentication response to the core network using the uplink application protocol message. Throughout these bidirectional interactions, the sequence number field and acknowledgment field of the general flow encapsulation layer continuously work together to provide underlying automatic retransmission request guarantees for long-latency links.

[0122] After the core network verifies the authentication response parameters, it generates and sends a security mode command message. The gateway station converts this command message into a downlink general flow encapsulation message and sends it to the target terminal station. Upon receiving and parsing the command, the terminal station activates its local non-access stratum security context, protects subsequent signaling according to the negotiated algorithm, and constructs a security mode completion message to report to the network side. The gateway station then transparently transmits this completion message to the core network according to predetermined rules.

[0123] After receiving the security mode completion message, the core network confirms that the terminal-side security mechanism is ready and then sends a registration acceptance message. The gateway station encapsulates this message into a downlink general flow encapsulation message and sends it to the terminal station. Upon receiving the registration acceptance message, the terminal station updates its local connection state model parameters and terminates the access process. Through the above timing sequence, the system achieves complete migration and synchronization of the standard 5G non-access stratum control state without changing the underlying physical characteristics of digital video broadcasting.

[0124] We will conduct a comparative analysis of signaling overhead using a complete 5G registration process as an example. In traditional non-3GPP access architecture, a single NAS signaling message needs to be transmitted through an IPsec tunnel established by IKEv2 negotiation. Its protocol header overhead includes an outer IP header (20 bytes), a UDP header (8 bytes), an ESP header (at least 8 bytes), and an ESP trailer (including padding and authentication data, typically more than 20 bytes), totaling an additional encapsulation overhead of no less than 56 bytes per signaling message.

[0125] In this method, NAS signaling only requires a general stream encapsulation header (typically 12 bytes) plus a 5-byte signaling header, totaling 17 bytes. Considering the approximately 8 NAS signaling interactions involved in a single registration process, this method saves over 300 bytes of protocol header overhead compared to traditional solutions, significantly improving the payload ratio of the satellite backhaul link. Furthermore, the maximum recovery time of the link layer retransmission mechanism is approximately 2.4 seconds (taking 3 retransmissions in a GEO scenario as an example), far less than the default 15-second timeout threshold of the NAS layer, ensuring that the link layer can complete packet loss recovery before the NAS state machine times out.

[0126] In some alternative implementations, for specific scenarios where the satellite link may already have a conditional access encryption mechanism deployed, this embodiment provides an alternative solution for secure collaboration between the underlying link and the non-access layer.

[0127] In traditional digital video broadcasting networks, some systems utilize Conditional Access Systems (MACS) at the physical layer deployment, employing underlying hardware to perform link-layer encryption on transmitted service data and control flow. Under these conditions, activating the encryption function of non-access layer protocols via a security mode command issued from the core network according to standard procedures would result in the same signaling message undergoing two independent and overlapping cryptographic operations within the terminal station, increasing the computational load and processing latency of the terminal station processor.

[0128] To optimize the allocation of system computing resources, the terminal station is configured with cross-layer security status monitoring logic. When it receives a downlink packet containing a security mode command and is preparing to activate the higher-layer security context, the terminal station extracts the lower-layer broadband login status parameters to determine whether the current physical link is already under conditional access encryption protection.

[0129] If encryption is detected to be enabled on the underlying link, the terminal will trigger a security collaboration policy.

[0130] In a specific execution logic, when the terminal returns a security mode completion message to the gateway, it uses the extended field of the protocol data unit to carry the underlying encryption ready indication, and negotiates with the network side to disable the non-access stratum payload encryption function, retaining only the non-access stratum signaling integrity protection function.

[0131] As another parallel collaborative branch, the terminal station can, after confirming the activation of the non-access stratum standard encryption system, issue a suspension command to the underlying baseband processing module through its internal communication interface, bypassing the repeated encryption operations of the digital video broadcast link layer. Through the above-mentioned cross-layer state awareness and control collaboration, redundant encryption operation steps are reduced without compromising the confidentiality requirements of data transmission.

[0132] According to one aspect of this application, such as Figure 5 As shown, the complete processing flow after the gateway station receives the GSE message is as follows: Uplink processing (terminal station → AMF): S1: The DVB-S2 receiver at the gateway station demodulates and decodes the GSE message stream.

[0133] S2: The GSE decapsulation module parses the Protocol Type field. If PT=0x0901, it is determined to be NAS signaling, and the NAS PDU in the payload is extracted; if it is another PT value (such as 0x0800 IPv4), it is processed as a regular data stream.

[0134] S3: Extract the source terminal identifier DVBTerminalID from the Label field of the GSE message header.

[0135] S4: Query the Terminal Context Table, indexed by DVBTerminalID: - If a corresponding entry exists, retrieve the allocated RANUENGAPID, construct an NGAP Uplink NAS Transport message, fill in AMFUENGAPID, RANUENGAPID, and NAS PDU, and send it to AMF via SCTP connection. - If a corresponding entry does not exist (first access), allocate a new RANUENGAPID, create a terminal context entry, construct an NGAP Initial UEMessage, fill in RANUENGAP_ID, NAS PDU, and user location information, and send it to AMF.

[0136] S5: Wait for AMF response and update the terminal context (e.g., record AMFUENGAP_ID).

[0137] Downlink processing (AMF → Terminal): S6: The gateway station's SCTP interface receives the NGAP Downlink NAS Transport message sent by the AMF.

[0138] S7: Parse the NGAP message and extract the RANUENGAP_ID and NAS PDU.

[0139] S8: Query the terminal context table using RANUENGAPID as the index to obtain the corresponding DVBTerminal_ID.

[0140] S9: Construct GSE message: Enter 0x0901 in Protocol Type, enter the target DVBTerminalID in Label field, and enter NAS PDU in Payload field.

[0141] S10: The GSE message is sent on the forward link via the DVB-S2 modulator.

[0142] According to one aspect of this application, the gateway maintains a Terminal Context Table, as shown in Table 1, with each entry containing the following fields: Table 1 Terminal Context Table.

[0143]

[0144] The lifecycle management of context tables is as follows: Creation timing: When the first NAS signaling (Registration Request) is received from the terminal.

[0145] Deletion timing: Deleted when a UE Context Release Command is received from the AMF, or released when there is no activity for a timeout (default 30 minutes).

[0146] Capacity limit: Set an upper limit based on the gateway station's processing capacity. Typical value: 10,000 concurrent terminal contexts.

[0147] According to one aspect of this application, the terminal station adopts a simplified two-state model: NAS-IDLE state: The terminal station has completed the DVB-RCS2 Logon process and has DVB link layer communication capabilities, but has not yet registered with the 5G core network or has entered the idle state after registration. In this state, the terminal station does not send NAS signaling.

[0148] NAS-CONNECTED state: The terminal station is interacting with the AMF via NAS signaling (registration / authentication / deregistration process). In this state, the terminal station sends and receives NAS PDUs via GSE (PT=0x0901).

[0149] State transition trigger condition: IDLE → CONNECTED The terminal business layer or management layer triggers the NAS registration requirement - CONNECTED → IDLE: Received Registration Accept or Authentication Reject, or signaling timeout.

[0150] When signaling times out and retransmission occurs: After the terminal sends the NAS signal, it starts a timer TNAS (considering the approximately 540ms one-way latency of a GEO satellite, TNAS is set to 6 seconds). If no response is received within the timeout period, it will retransmit a maximum of 3 times. After 3 timeouts, authentication is considered to have failed, and the system will fall back to the NAS-IDLE state.

[0151] When authentication fails: If the AMF returns Authentication Reject, the gateway station will send the NAS PDU to the end station via GSE. After receiving it, the end station will clear its local security context, enter the NAS-IDLE state, and wait according to the backoff algorithm (initially 10 seconds, increasing exponentially, up to a maximum of 640 seconds) before re-initiating registration.

[0152] As shown in Table 2, when the Protocol Type field of the GSE message is 0x0901, its payload adopts the following NAS signaling bearer format: Table 2 NAS Signaling Bearer Format Table.

[0153]

[0154] Detailed explanation of the values ​​and formats for each field: Byte 0: Control byte.

[0155] Ver (bit[7:4]): Protocol version number, currently fixed at 0x01.

[0156] Dir (bit[3]): Transmission direction indicator.

[0157] 0: Uplink (terminal station → gateway station).

[0158] 1: Downlink (gateway station → terminal station).

[0159] Msg_Type (bit[2:0]): Message type encoding.

[0160] 000: NAS PDU transmission (carrying NAS message body).

[0161] 001: ACK confirmation (only confirms, does not carry NAS message body).

[0162] 010: Connection establishment request (used when the terminal station connects for the first time).

[0163] 011: Connection establishment response (gateway station replies, carrying the assigned Terminal Context ID).

[0164] 100: Connection release notification.

[0165] 101 ~ 111: Reserved fields.

[0166] Byte 1 ~ 2: Terminal_ID (16 bit): Uplink message: Fill in the DVB terminal identifier of the terminal station itself (derived from the lower 16 bits of RCST_ID allocated by DVB-RCS2 Logon).

[0167] Downlink message: Enter the DVB terminal identifier of the target terminal station.

[0168] Design purpose: To enable gateway stations to directly identify and route terminals at the GSE layer without relying on the 3-byte label of the GSE address, thereby saving transmission overhead.

[0169] Byte 3: Sequence Number (8 bit): The cyclic sequence number (range 0~255) increments by 1 for each NAS PDU message sent and is used for signaling deduplication and acknowledgment.

[0170] Byte 4: ACK (8 bits): The value is the most recently correctly received Sequence Number from the other end.

[0171] When Msg_Type = 001: Only ACK confirmation is included, and subsequent NAS PDU fields are empty.

[0172] When Msg_Type = 000: Piggybacking mechanism is used, and a new NASPDU is carried along at the same time.

[0173] Byte 5 ~ N: NAS PDU: It directly carries NAS message bodies defined by 3GPP, such as Registration Request and Authentication Response.

[0174] The length is implicitly determined by the Total Length field in the GSE message header, and is calculated using the following formula: NAS PDU Length = GSE Payload Length - 5; The entire NAS signaling header occupies only 5 bytes, which is a significant reduction compared to the tens of bytes of overhead generated by the multi-layer encapsulation of PDCP / RLC / MAC in the standard 5G air interface SRB2, making it suitable for scenarios where satellite link bandwidth is limited.

[0175] Lightweight and reliable transmission is achieved at the GSE layer through an 8-bit Sequence Number and ACK mechanism, avoiding unnecessary retransmissions triggered by the NAS layer due to the long latency of GEO satellites (approximately 540ms one way). (The typical value of the NAS layer T3510 timer is 15s, while the GSE layer ARQ can complete retransmissions quickly within 1.2s).

[0176] The connection establishment / release message (010 / 011 / 100) in Msg_Type replaces the traditional RRCConnection Setup / Release function in 5G, enabling the gateway station to directly perceive the signaling connection status of the terminal and perform context management.

[0177] According to one aspect of this application, a two-way identity binding method based on DVB login credentials, When creating a context entry for a terminal, the gateway performs an identity binding verification process to prevent terminal identifier spoofing attacks. The specific method is as follows: S4-1: When the end station sends a connection establishment request (Msg_Type=010), it carries a "Binding Verification Token" (BVT) in the NAS PDU field, and the calculation method is as described above.

[0178] S4-2: After receiving the connection establishment request, the gateway station queries the local DVB login database based on the Terminal_ID to obtain the corresponding K_logon, and recalculates BVT' using the same algorithm.

[0179] S4-3: Comparison of BVT and BVT': If they match, the binding verification is successful. The gateway station confirms that the association between the Terminal_ID and SUCI is valid, creates a terminal context entry, and records the SUCI in the context. If there is a discrepancy, the connection establishment request is rejected, and a connection establishment response is returned (carrying error code 0x01: authentication failed).

[0180] S4-4: When constructing the NGAP Initial UE Message, the gateway station fills the verified SUCI into the 5G-S-TMSI / SUCI field in the NASPDU to ensure that the registration request received by the AMF is indeed from a legitimate terminal.

[0181] Even if an attacker forges the DVB Terminal_ID, they cannot obtain the K_logon negotiated during the terminal's Logon phase, thus failing to construct the correct BVT and consequently failing the gateway station's binding verification. This establishes a cross-layer security anchor between the DVB link layer and the NAS layer, a mechanism not found in existing N3IWF (based on IKEv2) and standard NTN schemes (based on NR RRC security).

[0182] According to one aspect of this application, the dynamic mapping method for DVB beam coverage to 5G TAC is as follows: When constructing the NGAP Initial UE Message, the gateway station needs to fill in the ULI (User Location Information). Since the DVB system does not have the concepts of NR Cell ID and TAC, the gateway station uses the following mapping method: S5-1: The satellite system pre-establishes a "Beam-TAC Mapping Table". Each transponder beam of each satellite is assigned a virtual TAC value (vTAC) and a virtual NR Cell Global Identity (vNR-CGI). The mapping rules have been described above and will not be elaborated further.

[0183] S5-2: When sending a connection establishment request, the terminal station carries the ISI value from the currently received DVB-S2 frame header in a reserved location within the protocol data unit. The gateway station determines the beam coverage area where the terminal is currently located based on the ISI value.

[0184] S5-3: The gateway station queries the beam-TAC mapping table to obtain the corresponding vTAC and vNR-CGI, and fills them into the User Location Information IE of the NGPINITial UE Message.

[0185] S5-4: When the satellite constellation is switched (the terminal moves from one beam to another), the gateway detects the change in the terminal's ISI value and updates the terminal's location information to the AMF through the NGAP UE Context Modification message, triggering the AMF's mobility management procedure (such as TAU).

[0186] like Figure 5 As shown, according to one aspect of this application, the lightweight signaling acknowledgment retransmission mechanism of the GSE layer specifically includes: SARQ-1: After the sender (end station or gateway station) sends the NAS PDU, it buffers the message in the retransmission buffer and starts the retransmission timer TGSEARQ.

[0187] SARQ-2: After the receiver correctly receives the NAS PDU, it replies with an ACK at the next available transmission opportunity. The ACK can be transmitted in two ways: Piggybacking: If the receiver has a NAS PDU to be sent (MsgType=000), fill the ACK field with the already acknowledged SeqNo; Independent acknowledgment: If the receiver has no data to send within TACKDelay (value is 200ms), it sends an independent ACK message (MsgType=001).

[0188] SARQ-3: If the sender receives an ACK (ACK value ≥ the sent SeqNo) before the TGSEARQ timeout, the message is deleted from the retransmission buffer.

[0189] SARQ-4: If TGSEARQ times out without receiving an ACK, immediately retransmit the packets in the buffer, with a maximum of N_max = 3 retransmissions. If no ACK is received after N_max is reached, notify the upper-layer NAS of authentication failure.

[0190] SARQ-5: The receiver performs deduplication using the Sequence Number: If the received SeqNo is equal to the last received Seq_No, it is determined to be a duplicate message, the NAS PDU is discarded, but an ACK is still sent back.

[0191] The retransmission interval of the GSE layer ARQ is much shorter than that of the NAS layer timer (e.g., T3510 = 15 seconds), allowing the link layer to recover before the NAS layer times out. If the GSE layer ARQ fails after three retransmissions, it indicates that the satellite link has been interrupted, and only then is the NAS layer timeout triggered, avoiding unnecessary waiting by the NAS layer during temporary link interference.

Claims

1. A 5G NAS signaling pass-through and adaptation method based on DVB system, characterized in that, include: The satellite terminal station acquires the non-access stratum signaling to be sent, encapsulates the non-access stratum signaling in a general flow encapsulation message with a specific protocol type identifier, and sends it to the gateway station via the satellite link; The gateway station receives the generic stream encapsulation message, determines the signaling data carried by the generic stream encapsulation message based on the specific protocol type identifier, and extracts the corresponding message payload; The gateway station assigns a core network-side identifier to the satellite terminal station, encapsulates the non-access stratum signaling in the message payload and the acquired user location information into a first next-generation application protocol message, and sends it to the core network. The gateway station receives a second next-generation application protocol message containing downlink non-access stratum signaling from the core network, converts the downlink non-access stratum signaling into a general flow encapsulation message with the specific protocol type identifier, and sends it to the satellite terminal station through the forward link.

2. The method according to claim 1, characterized in that, The message payload includes a signaling header and a protocol data unit, wherein the protocol data unit is used to carry the non-access stratum signaling; The signaling header includes a control field, an addressing field, a sequence number field, and an acknowledgment field; The addressing field records the link layer device identifier of the satellite terminal station, and the sequence number field and the acknowledgment field are used for link layer retransmission control.

3. The method according to claim 2, characterized in that, The control field includes a message type indicator, and the value types of the message type indicator include at least: The data transmission type used to transmit the protocol data unit; The connection establishment request type used to trigger terminal access; The connection establishment response type used to provide feedback on access results; Connection release type used for disconnecting.

4. The method according to claim 3, characterized in that, When the message type indicates the connection establishment request type, the satellite terminal carries a binding verification token and a core network hidden identifier in the protocol data unit; After receiving the token, the gateway station verifies the binding verification token based on the pre-stored link layer session key. If the verification passes, the gateway station establishes a secure binding relationship between the link layer device identifier and the core network hidden identifier, and encapsulates the core network hidden identifier into the first next-generation application protocol message.

5. The method according to claim 3, characterized in that, The binding verification token is calculated by the satellite terminal based on the link layer session key, the link layer device identifier, the core network hidden identifier, and the current system timestamp, using a preset hash message authentication code algorithm.

6. The method according to claim 3, characterized in that, When the message type indicates the connection establishment request type, the satellite station obtains the currently received physical layer frame header identifier and sends the physical layer frame header identifier to the gateway station in the protocol data unit.

7. The method according to claim 6, characterized in that, The gateway station extracts the physical layer frame header identifier and queries a pre-built location mapping table based on the physical layer frame header identifier to obtain the corresponding virtual tracking area code and virtual cell identifier; The gateway station encapsulates the virtual tracking area code and the virtual cell identifier as the user location information into the first next-generation application protocol message.

8. The method according to claim 7, characterized in that, The location mapping table is pre-built in the following manner: The virtual tracking area code is calculated based on the satellite number, beam number, and pre-configured reference tracking area code; The virtual cell identifier is generated by combining the public network identifier, the virtual base station identifier, and the virtual cell number obtained by jointly encoding the satellite number and the beam number.

9. The method according to claim 2, characterized in that, The specific steps of the link layer retransmission control include: After sending the general stream encapsulation message, the sender starts a retransmission timer, wherein the sender is the satellite terminal station or the gateway station; After the receiver correctly receives the general stream encapsulation message, it generates an acknowledgment message based on the sequence number field and fills the acknowledgment message into the acknowledgment response field and returns it to the sender. If the sender does not receive a matching acknowledgment before the retransmission timer expires, then the message is retransmitted.

10. The method according to claim 9, characterized in that, The recipient returns confirmation information, specifically including: If the recipient has data to be sent, the confirmation information is returned along with the confirmation response field of the data to be sent; If there is no data to be sent, a separate acknowledgment message containing only the acknowledgment information is sent to the sender.