Self-service method and device for direct connection to cellular satellite network
By decoupling the cellular network functions and stateful sessions of satellites, a one-time token is designed to embed operator policy information, providing personalized services to user equipment, solving the scalability and security issues of multi-operators sharing direct-connected cellular satellite networks, and realizing self-service and network sharing of user equipment.
Patent Information
- Application Number
- PCT/CN2024/081019
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-01
- Filing Date
- 2024-03-11
- Publication Date
- 2025-08-07
AI Technical Summary
When the prior art is difficult to realize that multi-operators share direct connection cellular satellite networks, there are defects in scalability, flexibility and security. Especially under the dynamic and intermittent access of LEO satellites, it is difficult to meet the personalized network service needs of user equipment.
By decoupling the satellite's on-star cellular network function from the stateful session, a one-time token is designed and when the satellite receives the token after the decoupling, it provides services to the user equipment according to the embedded operator policy information, including two-way authentication and token management, to realize the self-service relationship between the user equipment and the mobile operator.
It realizes a flexible, scalable and secure multi-operator shared direct-connected cellular satellite network, supports user equipment to access the network on demand, reduces dependence on ground networks, and improves the scalability and security of the network.
Smart Images

Figure CN2024081019_07082025_PF_FP_ABST
Abstract
Description
Self-service method and device for directly connecting to cellular satellite network
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to Chinese patent application No. 2024101443975, filed on February 1, 2024, entitled “Self-service method and device for direct connection to cellular satellite network”, which is incorporated herein by reference in its entirety. Technical Field
[0003] The present application relates to the field of satellite communication technology, and in particular to a self-service method and device for directly connecting to a cellular satellite network. Background Art
[0004] Emerging direct-connect cellular low-orbit satellites (also known as LEO satellites) complement terrestrial network coverage and help close coverage gaps for the world's 2.7 billion "unconnected" users. Direct-connect cellular satellite networks allow commercial mobile phones and IoT devices to access satellites directly via cellular communication technology, significantly saving operators infrastructure construction costs in underserved areas and expanding mobile network services to anywhere on Earth, attracting new users and increasing revenue. Consequently, mobile network operators and satellite network operators are actively collaborating to deploy and standardize direct-connect cellular LEO satellite services.
[0005] Compared to each mobile network operator building its own dedicated satellite, building multi-tenant direct-connect cellular satellites for multi-operator sharing is a more practical and beneficial win-win solution for both mobile network operators and satellite operators. On the one hand, satellites are a scarce and competitive resource for mobile network operators. The highly congested near-Earth space means that all mobile network operators lack sufficient orbital slots to deploy new constellations. Furthermore, the cost of building a low-Earth orbit satellite constellation is prohibitive for mobile network operators. In contrast, leasing satellites is more affordable, lowering the barrier to entry for mobile operators and promoting market competition. Furthermore, satellite operators lack licensed cellular spectrum and cannot independently serve commercial mobile phones and IoT devices. Therefore, they have an incentive to collaborate with mobile network operators. Similar to cloud computing, satellite operators aim to lease satellites to as many mobile network operators as possible to maximize their revenue and return on investment through economies of scale.
[0006] However, cellular network functions on LEO satellites are not easily shared due to the requirement for tightly coupled functionality and stable service relationships between satellite operators, mobile operators, and user devices. This requirement is rooted in the stateful hop-by-hop conversations in the mobile cellular network architecture, which assume a fixed, always-on, trusted infrastructure. This is difficult to meet in multi-tenant LEO satellites due to their high mobility, intermittent access to remote terrestrial mobile networks, and the dynamic changes in LEO satellites acting as intermediate session nodes in three-party conversations. Therefore, finding a method to facilitate multi-operator sharing of services in directly connected cellular satellite networks has become a research hotspot.
[0007] Summary of the Invention
[0008] The present application provides a self-service method and apparatus for directly connecting to a cellular satellite network, which allows user equipment and mobile operators to establish a service relationship with a decoupled satellite on demand, so that the decoupled satellite can provide personalized network services for the user equipment.
[0009] The present application provides a self-service method for a directly connected cellular satellite network, the method comprising: decoupling an onboard cellular network function of a satellite from a stateful session to obtain a decoupled satellite, wherein the decoupled satellite has the ability to independently provide services; designing a one-time token, wherein the one-time token is embedded with operator policy information, wherein the operator policy information includes state information of an established session; and, when the decoupled satellite receives the one-time token, controlling the decoupled satellite to provide a service to a user device according to the operator policy information embedded in the one-time token, wherein the service matches the state information of the established session.
[0010] According to a self-service method for a directly connected cellular satellite network provided by the present application, before applying for satellite service, the user equipment uses channel associated signaling to send the one-time token to the decoupled satellite.
[0011] According to a self-service method for a directly connected cellular satellite network provided by the present application, before controlling the decoupled satellite to provide services to a user device according to the operator policy information embedded in the one-time token, the method further includes: performing bidirectional authentication on the decoupled satellite and the user device respectively; controlling the decoupled satellite to provide services to the user device according to the operator policy information embedded in the one-time token specifically includes: controlling the decoupled satellite to provide services to the user device according to the operator policy information embedded in the one-time token when the decoupled satellite and the user device pass bidirectional authentication.
[0012] According to a self-service method for a directly connected cellular satellite network provided in the present application, controlling the decoupled satellite to provide services to a user device based on the operator policy information embedded in the one-time token specifically includes: calling the decoupled satellite to parse and process the operator policy information embedded in the one-time token to obtain session establishment status information carried by the one-time token; and providing services to the user device based on the session establishment status information.
[0013] According to a self-service method for a directly connected cellular satellite network provided by the present application, the decoupled satellite is authenticated in the following manner: the user equipment derives the identity public key of the decoupled satellite based on the master public key published by the mobile operator and generates a random number, wherein the random number is used to verify the satellite legitimacy of the decoupled satellite; the user equipment is controlled to encrypt the one-time token and the random number using the identity public key to obtain an encrypted one-time token and an encrypted random number, and the encrypted one-time token and the encrypted random number are sent to the decoupled satellite; the decoupled satellite is controlled to decrypt the encrypted one-time token and the encrypted random number using the identity private key to obtain a decrypted one-time token and a decrypted random number; the user equipment is called to perform a consistency comparison between the decrypted random number sent back by the decoupled satellite and the random number; if the consistency comparison between the decrypted random number and the random number is passed, the user equipment completes the authentication of the decoupled satellite.
[0014] According to a self-service method for a directly connected cellular satellite network provided by the present application, after obtaining the decrypted one-time token and the decrypted random number, the method authenticates the user device in the following manner: controlling the decoupled satellite to generate challenge information based on the token information in the decrypted one-time token and the published hash function, and sending the challenge information to the user device; calling the user device and the user identity card to collaboratively calculate the challenge information, and sending the challenge information to the decoupled satellite; controlling the decoupled satellite to verify whether the token information is token information issued by a mobile network operator based on the challenge information; and completing the authentication of the user device by the decoupled satellite if the token information is token information issued by a mobile network operator.
[0015] According to a self-service method for directly connecting to a cellular satellite network provided in the present application, token information issued by a mobile network operator is obtained in the following manner: calling the user device to calculate and generate the token information based on the metadata sent by the mobile network operator; calling the mobile network operator to use a private key to sign the token information to obtain the token information issued by the mobile network operator.
[0016] According to a self-service method for a directly connected cellular satellite network provided in the present application, the following method is used to decouple the satellite's on-board cellular network function from the stateful session: a complete access network function is deployed for the satellite, and a core network user plane function is integrated for the satellite to decouple the satellite's on-board cellular network function from the stateful session, so that the satellite has the ability to independently provide services.
[0017] According to a self-service method for a directly connected cellular satellite network provided by the present application, after obtaining the decoupled satellite, the method further includes: calling a mobile network operator to issue a digital certificate for the decoupled satellite, so that the decoupled satellite after obtaining the issued digital certificate can use a preset spectrum in an authorized geographical area.
[0018] According to a self-service method for a directly connected cellular satellite network provided by the present application, before the user device sends the one-time token to the satellite, the user device performs token replay detection locally in the following manner: the identity card (SIM / eSIM card) of the user device participates in the token generation process, and the mobile operator sends metadata to the identity card when generating the one-time token; during the process of the user device calculating the token information, the identity card signs the one-time token and stores the metadata; when the user device consumes the one-time token, the identity card checks whether the metadata corresponding to the one-time token is in the storage. If it is, it indicates that the one-time token is used for the first time, and the identity card returns a response message and deletes the corresponding metadata; otherwise, it indicates that the one-time token is reused, and the identity card refuses to return a response message to prevent malicious user devices from replaying the token.
[0019] According to a self-service method for a directly connected cellular satellite network provided by the present application, after controlling the decoupled satellite to provide services to the user device according to the operator policy information embedded in the one-time token, the method also includes: storing the one-time token consumed by the user device to a local preset location of the decoupled satellite; controlling the decoupled satellite to perform token settlement with the mobile operator in an online and / or offline manner based on the one-time token consumed by the user device; the mobile operator uses its locally maintained subscription user information database and consumption token database to perform token replay detection. If the one-time token is not replayed, it is recorded in the consumption token database, and the corresponding one-time token is consumed; if it is detected that the one-time token is replayed, the corresponding user account is inferred, the account is added to a blacklist and notified to all satellites, and the blacklisted user will not be able to obtain satellite services.
[0020] According to a self-service method for a direct-connected cellular satellite network provided by the present application, the operator policy information also includes authentication information and billing policy.
[0021] The present application also provides a self-service device directly connected to a cellular satellite network, the device comprising: a decoupling module for pre-decoupling the satellite's onboard cellular network function from a stateful session to obtain a decoupled satellite, wherein the decoupled satellite has the ability to independently provide services; a design module for designing a one-time token, wherein the one-time token is embedded with operator policy information, and the operator policy information includes status information for establishing a session; a processing module for controlling the decoupled satellite to provide services to a user device according to the operator policy information embedded in the one-time token when the decoupled satellite receives the one-time token, wherein the service matches the status information for establishing the session.
[0022] According to a self-service device directly connected to a cellular satellite network provided by the present application, the operator policy information also includes authentication information and billing policy.
[0023] The present application also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the self-service method for directly connecting to a cellular satellite network as described above is implemented.
[0024] The present application also provides a non-transitory computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the self-service method for directly connecting to a cellular satellite network as described above is implemented.
[0025] The present application also provides a computer program product, including a computer program, which, when executed by a processor, implements any of the above-described self-service methods for directly connecting to a cellular satellite network.
[0026] The present application provides a self-service method and device for a directly connected cellular satellite network. The method and device pre-decouple the satellite's onboard cellular network function from the stateful session to obtain a decoupled satellite, so that the decoupled satellite has the ability to independently provide services. A one-time token is designed, and when the decoupled satellite receives the one-time token, the decoupled satellite is controlled to provide a user device with a service that matches the state information of the established session based on the operator policy information embedded in the one-time token. This allows the user device and the mobile operator to establish a service relationship with the decoupled satellite on demand, so that the decoupled satellite provides self-service network services to the user device. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] In order to more clearly illustrate the technical solutions in the present application or the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0028] FIG1 is a flow chart of a self-service method for directly connecting to a cellular satellite network according to an embodiment of the present application;
[0029] FIG2 is a schematic diagram of a process for authenticating a decoupled satellite according to an embodiment of the present application;
[0030] FIG3 is a schematic diagram of a process for authenticating a user device according to an embodiment of the present application;
[0031] FIG4 is a second flow chart of a self-service method for directly connecting to a cellular satellite network provided in an embodiment of the present application;
[0032] FIG5 is a third flow chart of a self-service method for directly connecting to a cellular satellite network provided in an embodiment of the present application;
[0033] FIG6 is a schematic diagram of a process for generating a one-time token according to an embodiment of the present application;
[0034] FIG7 is a schematic diagram of a process for verifying a one-time token according to an embodiment of the present application;
[0035] FIG8 is a schematic diagram of a process for settling a one-time token according to an embodiment of the present application;
[0036] FIG9 is a schematic structural diagram of a self-service device directly connected to a cellular satellite network provided in an embodiment of the present application;
[0037] FIG10 is a schematic diagram of the physical structure of an electronic device. DETAILED DESCRIPTION
[0038] To make the objectives, technical solutions, and advantages of this application more clear, the technical solutions of this application will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only part of the embodiments of this application, not all of them. Based on the embodiments of this application, all other embodiments obtained by ordinary technicians in this field without making any creative efforts are within the scope of protection of this application.
[0039] The self-service method for a directly connected cellular satellite network provided in this application can solve the defects of the prior art in scalability, flexibility, and security when multiple operators share a directly connected cellular satellite network, and realize a flexible, scalable, and secure multi-operator shared directly connected cellular satellite network, supporting user devices to access the network on demand.
[0040] FIG1 is a flow chart of a self-service method for directly connecting to a cellular satellite network provided in the present application.
[0041] The process of the self-service method for directly connecting to a cellular satellite network provided by the present application will be described below with reference to FIG1 .
[0042] In an exemplary embodiment of the present application, as can be seen from FIG. 1 , a self-service method for directly connecting to a cellular satellite network may include steps 110 to 130 , each of which will be described below.
[0043] In step 110, the onboard cellular network function of the satellite is decoupled from the stateful session to obtain a decoupled satellite.
[0044] In one embodiment, the on-board cellular network function of the satellite can be decoupled from the stateful session to obtain a decoupled satellite. The decoupled satellite re-divides the on-board cellular network function, so that the decoupled satellite has the ability to independently provide services.
[0045] In step 120 , a one-time token is designed, wherein the one-time token is embedded with operator policy information, and the operator policy information includes state information of establishing a session.
[0046] In another embodiment, a one-time token can be designed for the user device. It is understood that the one-time token can be used only once, meaning it is considered invalid after a single use. The one-time token is embedded with operator policy information, including session establishment status information. The one-time token embedded with operator policy information and capable of supporting authentication allows the user device to use this one-time token to self-service and access satellite services on demand.
[0047] In one embodiment, the operator policy information further includes authentication information and charging policy.
[0048] In step 130 , when the decoupled satellite receives the one-time token, the decoupled satellite is controlled to provide a service to the user equipment according to the operator policy information embedded in the one-time token, wherein the service matches the state information of the established session.
[0049] In one embodiment, the user equipment may use channel associated signaling to hand over a one-time token to the decoupled satellite to request satellite services.
[0050] In another embodiment, the user device can locally maintain a usable one-time token, where the one-time token embeds state information required to establish a session. When the user device desires satellite service, it can use channel-associated signaling to send the one-time token to the decoupled satellite. This can be achieved by, but is not limited to, utilizing 5G NAS signaling.
[0051] In another example, the process of obtaining satellite services on demand by using channel associated signaling care-of tokens proposed in this application is introduced by taking uplink session establishment and downlink session establishment as examples.
[0052] Uplink establishment:
[0053] When a user (user device) needs to send data, it first establishes a radio connection with the satellite (corresponding to the decoupled satellite). The user can obtain the satellite's identity information based on the satellite's broadcast messages. Using identity-based encryption, the user can derive the satellite's identity public key from the master public key published by the mobile operator.
[0054] The user encrypts the token (corresponding to the one-time token) and the challenge information with the satellite identity public key and sends it to the satellite using channel-associated signaling. If the satellite is an authorized satellite, it can use its own identity private key to decrypt the corresponding challenge information and token.
[0055] The satellite will decrypt the challenge information and inform the user via channel-associated signaling. The user can then compare and verify the satellite's legitimacy. At the same time, the satellite uses the mobile operator's public key to verify the legitimacy of the token submitted by the user to verify the legitimacy of the user.
[0056] After the legitimacy verification is passed, the state agent on the satellite extracts the user status information in the token and provides services to the user on demand.
[0057] Downlink establishment:
[0058] The Earth's fixed geographic cells are used as the terminal location reference for downlink services. The IP address of each user device is assigned as PLMN.cell-ID.UE-identity. PLMN is the 4G / 5G public land mobile network identity of the user's mobile operator, cell-ID is the geographic cell identity of the user, and UE-identity is the user's globally unique identity (for example, IMSI in 4G and SUCI in 5G).
[0059] This IP address is globally unique and locates the user device at the cell level. Given a data packet containing the user device's geographic IP address, the satellite can easily detect whether it serves that cell and, if so, initiate a paging call. Otherwise, the packet is routed to a satellite serving that cell based on its geographic location. After receiving the paging message, the user establishes a connection with the satellite using a signaling process and receives downlink data.
[0060] In this embodiment, since the on-board cellular network function does not need to maintain session state, sessions can be established on demand based on the policy information embedded in the token and authenticated on demand, thereby promoting multi-operator sharing of the directly connected cellular satellite network and improving network scalability.
[0061] In order to avoid signaling storms caused by state migration and improve the scalability of multi-tenant direct-connected satellite networks, on-board functions and stateful sessions are decoupled. On-board functions are connectionless and stateless, and services are provided to users on demand based on the status information in the user token.
[0062] The self-service method and device for a directly connected cellular satellite network provided in the present application pre-decouple the satellite's onboard cellular network function from the stateful session to obtain a decoupled satellite, so that the decoupled satellite has the ability to independently provide services; a one-time token is designed, and when the decoupled satellite receives the one-time token, the decoupled satellite is controlled to provide a user device with a service that matches the state information of the established session based on the operator policy information embedded in the one-time token, thereby allowing the user device and the mobile operator to establish a service relationship with the decoupled satellite on demand, so that the decoupled satellite can provide personalized network services for the user device.
[0063] In one embodiment, before applying for satellite service, the user equipment uses channel associated signaling to send the one-time token to the decoupled satellite.
[0064] In another exemplary embodiment of the present application, continuing with the embodiment described in FIG. 1 above as an example, before controlling the decoupled satellite to provide services to the user equipment according to the operator policy information embedded in the one-time token (corresponding to step 130), the self-service method for directly connecting to a cellular satellite network may further include:
[0065] Perform bidirectional authentication on the decoupled satellite and user equipment respectively;
[0066] The satellite provides services to the user equipment according to the operator policy information embedded in the one-time token after control decoupling (corresponding to step 130), which can be implemented in the following manner:
[0067] When the decoupled satellite and the user equipment pass bidirectional authentication, the decoupled satellite is controlled to provide services to the user equipment according to operator policy information embedded in the one-time token.
[0068] In one embodiment, in order to protect the respective rights and interests of the satellite and the user equipment, bidirectional authentication is performed on the decoupled satellite and the user equipment respectively, that is, the user equipment is required to pass the authentication of the decoupled satellite, and the decoupled satellite is required to pass the authentication of the user equipment.
[0069] Furthermore, when both the decoupled satellite and the user equipment pass bidirectional authentication, the decoupled satellite is controlled to provide services to the user equipment according to the operator policy information embedded in the one-time token.
[0070] In another exemplary embodiment of the present application, continuing with the embodiment described in FIG. 1 above as an example, after controlling the decoupling, the satellite provides services to the user equipment according to the operator policy information embedded in the one-time token (corresponding to step 130) can be implemented in the following manner:
[0071] The decoupled satellite is called to parse the operator policy information embedded in the one-time token to obtain the session establishment status information carried by the one-time token;
[0072] Provide services to user devices based on the status information of the established session.
[0073] In another embodiment, a stateful proxy function is deployed on the decoupled satellite. Based on the stateful proxy function, state information can be extracted from the one-time token and the onboard network function can be activated to provide services to the user equipment on demand.
[0074] In one embodiment, the decoupled satellite can be called upon to parse the operator policy information embedded in the one-time token, thereby obtaining the session establishment status information carried by the one-time token. Furthermore, because different session establishment status information corresponds to different services, on-demand personalized services can be provided to the user device based on the session establishment status information.
[0075] FIG2 is a schematic diagram of the process of authenticating a decoupled satellite provided by this application.
[0076] The process of authenticating the decoupled satellite provided by this application will be described below with reference to FIG. 2 .
[0077] In an exemplary embodiment of the present application, as can be seen from FIG. 2 , authenticating the decoupled satellite may include steps 210 to 250 , each of which will be described below.
[0078] In step 210, the user equipment derives the identity public key of the decoupled satellite based on the master public key published by the mobile operator and generates a random number.
[0079] In one embodiment, the user equipment can extract the satellite identity information of the decoupled satellite from satellite broadcast information. Based on the master public key published by the mobile operator, the user equipment can derive the identity public key of the decoupled satellite and generate a random number. The random number can be used to verify the legitimacy of the decoupled satellite.
[0080] In yet another example, the user device may locally store the master public key published by the mobile operator.
[0081] In step 220, the user equipment is controlled to encrypt the one-time token and the random number using the identity public key to obtain an encrypted one-time token and an encrypted random number, and the encrypted one-time token and the encrypted random number are sent to the decoupled satellite.
[0082] In one embodiment, the user device may be called to encrypt the one-time token and the random number using the identity public key to obtain an encrypted one-time token and an encrypted random number, and the encrypted one-time token and the encrypted random number may be sent to the decoupled satellite.
[0083] In yet another example, the encrypted one-time token and the encrypted random number may be sent to the decoupled satellite via channel-associated signaling.
[0084] In step 230, the decoupled satellite is controlled to decrypt the encrypted one-time token and the encrypted random number using the identity private key to obtain a decrypted one-time token and a decrypted random number.
[0085] In one embodiment, the decoupled satellite can be controlled to decrypt the encrypted one-time token and the encrypted random number using the identity private key to obtain a decrypted one-time token and the decrypted random number. Furthermore, the decrypted one-time token and the decrypted random number can be sent to the user device.
[0086] In step 240, the user equipment is called to perform consistency comparison between the decrypted random number and the random number sent back by the decoupled satellite.
[0087] In step 250, when the decrypted random number and the random number consistency comparison pass, the user equipment completes the authentication of the decoupled satellite.
[0088] In one embodiment, the user device may be called to perform a consistency comparison between the decrypted random number and the random number sent back by the decoupled satellite. If they are consistent, that is, the consistency comparison between the decrypted random number and the random number passes, the user device completes authentication of the decoupled satellite.
[0089] FIG3 is a schematic diagram of a process for authenticating a user device provided in this application.
[0090] The process of authenticating a user device provided by this application will be described below with reference to FIG3 .
[0091] In an exemplary embodiment of the present application, as can be seen from FIG. 3 , authenticating the user equipment may include steps 310 to 340 , and each step will be described below.
[0092] In step 310 , the decoupled satellite is controlled to generate challenge information according to the token information in the decrypted one-time token and the published hash function, and then send the challenge information to the user equipment.
[0093] In one embodiment, the decoupled satellite can be called to generate a challenge message based on the token information in the decrypted one-time token and a hash function published by the mobile operator, and the challenge message can be sent to the user device. The challenge message can include the token information; the challenge message can be used to indicate whether the token information has been issued by the mobile network operator.
[0094] In step 320, the user equipment and the user identification card are called to collaboratively calculate challenge information, and the challenge information is sent to the decoupled satellite.
[0095] In one embodiment, the user equipment and the SIM / eSIM card (corresponding to the user identity card) may be called to collaboratively calculate the challenge information and send the challenge information to the decoupled satellite. The user identity card is an identity card related to the user equipment.
[0096] In another embodiment, response information to the challenge information may be calculated collaboratively based on the user equipment and the SIM / eSIM card, and sent to the satellite.
[0097] In step 330 , the decoupled satellite is controlled to verify whether the token information is the token information issued by the mobile network operator based on the challenge information.
[0098] In step 340 , when the token information is token information issued by the mobile network operator, the authentication of the user equipment by the decoupled satellite is completed.
[0099] In one embodiment, after receiving the challenge message, the decoupled satellite can be controlled to verify whether the token information is token information issued by the mobile network operator based on the challenge message. If the token information is detected to be token information issued by the mobile network operator, the decoupled satellite can complete authentication of the user equipment.
[0100] It is understandable that after steps 210 to 250 and steps 310 to 340, the two-way authentication between the user equipment and the decoupled satellite can be completed. Otherwise, the decoupled satellite may refuse to provide services.
[0101] In another embodiment, the decoupled satellite can locally verify that the token is signed by the mobile operator's private key based on the public key information published by the mobile operator. After successful bidirectional authentication, the decoupled satellite can provide services to the user based on the state information carried in the token. In this embodiment, the one-time token designed in this application embeds session state information issued by the mobile operator. The onboard cellular network function can directly extract the state from the token, enabling instant access without maintaining user state.
[0102] In another embodiment, the user device can also initiate a service request to any satellite (corresponding to the decoupled satellite). The satellite can locally verify the legitimacy of the token and complete two-way authentication with the user device on demand. Since the on-board cellular network function does not need to request status from other satellites or remote terrestrial mobile networks, it reduces dependence on terrestrial mobile networks and improves scalability. At the same time, the stateless and connectionless on-board cellular network function can move with the satellite, serving different terrestrial mobile network operators, and supports multi-operator sharing of directly connected cellular satellite networks.
[0103] In another exemplary embodiment of the present application, the token information issued by the mobile network operator can be obtained in the following manner:
[0104] Invoke the user device to calculate and generate token information based on the metadata sent by the mobile network operator;
[0105] The mobile network operator is called to use the private key to sign the token information, and the token information issued by the mobile network operator is obtained.
[0106] In one embodiment, the mobile operator may establish two databases to respectively maintain subscriber information and consumed tokens (including but not limited to 4G HSS or 5G UDM). In another embodiment, the mobile operator may also generate public and private keys for token generation and a hash function for token verification.
[0107] In one example, the user device can be called to calculate and generate token information based on the metadata sent by the mobile operator, and then the mobile operator can be called to sign the token using a private key to complete a token issuance, thereby obtaining the token information issued by the mobile network operator.
[0108] In another embodiment (as shown in FIG6 ), the one-time token may also be generated in the following manner:
[0109] The mobile operator first generates a pair of random numbers and informs the user, and then generates a random number and informs the SIM / eSIM card; the user calculates a token based on the hash function published by the operator, the pair of random numbers and the result returned by the SIM / eSIM card; the user sends the token to the operator, and the operator signs the token with its own private key to verify its legitimacy.
[0110] In another exemplary embodiment of the present application, decoupling the satellite's onboard cellular network function from the stateful session may also be achieved in the following manner:
[0111] Deploy complete access network functions for the satellite and integrate core network user plane functions for the satellite to decouple the satellite's onboard cellular network functions from stateful sessions, enabling the satellite to independently provide services.
[0112] In one embodiment, the complete access network functionality can be deployed on the satellite to meet radio processing latency and bandwidth requirements, and the core network user plane functionality can be deployed on the satellite to support data forwarding over the satellite network. This allows the satellite's onboard cellular network functionality to be decoupled from stateful sessions.
[0113] In another embodiment, a state proxy function may be deployed on the decoupled satellite to parse the state information (such as access policy, QoS, and billing information) carried in the user token.
[0114] Furthermore, the state proxy processing logic on the satellite can parse the user token, obtain the state information carried therein, and provide services to the user on demand based on the state information.
[0115] In another exemplary embodiment of the present application, continuing with the embodiment shown in FIG. 1 as an example, after obtaining the decoupled satellite (corresponding to step 110), the self-service method for directly connecting to a cellular satellite network further includes:
[0116] The mobile network operator is called upon to issue a digital certificate for the decoupled satellite, so that the decoupled satellite, after obtaining the issued digital certificate, can use the preset spectrum in the authorized geographical area.
[0117] In one embodiment, a terrestrial mobile network operator can be called upon to issue a digital certificate for each authorized satellite (decoupled satellite), allowing the satellite to use a specific spectrum within the authorized geographic area. Because the satellite stores the certificate locally, there is no need to store session state, supporting multi-operator sharing. When a token containing the user's session state is received, services can be provided on demand based on the state information in the token.
[0118] In another embodiment, during the cooperation between a terrestrial mobile network operator and a satellite operator, the terrestrial mobile network operator can issue a digital certificate for the cooperating satellite to grant the right to use a specific spectrum. Users of the corresponding operator can arbitrarily choose to access the authorized satellite.
[0119] FIG4 is a second flow chart of the self-service method for directly connecting to a cellular satellite network provided by the present application.
[0120] The process of another self-service method for directly connecting to a cellular satellite network provided by the present application will be described below with reference to FIG. 4 .
[0121] In an exemplary embodiment of the present application, as shown in FIG4 , before the user equipment sends a token to the satellite to apply for service, the self-service method for directly connecting to a cellular satellite network may further include steps 410 to 430. Each step will be described below.
[0122] In step 410, the user identity card participates in the token (corresponding to the one-time token) generation process. When the mobile operator generates the one-time token, it sends separate metadata to the user identity card.
[0123] In one embodiment, the SIM / eSIM card (corresponding to the user identity card) is controlled to participate in the token (corresponding to the one-time token) generation process, and the mobile operator sends separate metadata to the SIM / eSIM card when generating the token.
[0124] In step 420 , during the process of calculating the token information on the user device, the user identification card signs the token information and stores the metadata.
[0125] In one embodiment, during the process of calculating token information by the user equipment, the SIM / eSIM card is controlled to sign the token information and store metadata locally.
[0126] In step 430, when the user device consumes the one-time token, the user identification card checks whether the token has been replayed.
[0127] In one embodiment (as shown in FIG7 ), when a user device consumes a one-time token, the SIM / eSIM card checks whether the metadata corresponding to the token (corresponding to the one-time token consumed by the user device) is stored. If so, it indicates that the one-time token is being used for the first time, and a response message is returned. Upon receiving a token authentication success message from the satellite, the corresponding metadata is deleted. Otherwise, it indicates that the one-time token has been reused, and the identity card refuses to return a response message to prevent malicious user devices from replaying the token. It is understood that when the satellite receives a response message, it indicates that the one-time token consumed by the user device has not been replayed.
[0128] FIG5 is a third flow chart of the self-service method for directly connecting to a cellular satellite network provided in the present application.
[0129] The process of another self-service method for directly connecting to a cellular satellite network provided by the present application will be described below with reference to FIG. 5 .
[0130] In an exemplary embodiment of the present application, as shown in FIG5 , after the satellite provides services to the user equipment according to the operator policy information embedded in the one-time token after control decoupling, the self-service method for directly connecting to the cellular satellite network may further include steps 510 to 520. Each step will be described below.
[0131] In step 510, the one-time token consumed by the user equipment is stored in a local preset location of the decoupled satellite.
[0132] In one embodiment, the satellite may be called to store the one-time token consumed by the user equipment in a local preset location of the decoupled satellite.
[0133] In step 520, when the one-time token consumed by the user equipment is not replayed, the decoupled satellite is controlled to perform token settlement with the mobile operator in an online and / or offline manner based on the one-time token consumed by the user equipment.
[0134] In one embodiment (as shown in Figure 8), if a one-time token consumed by a user device is not replayed, it is recorded in the consumed token database, confirming the corresponding one-time token as consumed. Based on the one-time token consumed by the user device, token settlement between the decoupled satellite and the mobile operator is controlled online or offline. If a token replay is detected, the corresponding account is inferred, the account is blacklisted, and the satellite is notified. Blacklisted users will not be able to obtain service.
[0135] In another embodiment, the satellite (corresponding to the decoupled satellite) can store the tokens consumed by users locally and send them to the terrestrial mobile operator for settlement when passing through the ground station. The mobile operator first performs a replay check. If the token has not been replayed, it records it in the spent token database. If it detects that the token has been replayed, it infers the corresponding account, blacklists the account, and notifies the satellite. The blacklisted user will be unable to obtain service.
[0136] Specifically, a token bucket can be set up on the satellite to store tokens consumed by users served by the satellite during its movement. If an intersatellite link or direct access to a terrestrial mobile network is available, the satellite can notify the terrestrial mobile network of the tokens in the token bucket online. Otherwise, after a period of movement, when the satellite can access a terrestrial mobile network, the token bucket information is notified to the terrestrial mobile network.
[0137] In one embodiment, the mobile operator maintains a database of used tokens. When receiving token information sent by the satellite, the operator compares each token to see if it is in the database. If not, a record is added; otherwise, it indicates that the corresponding token has been reused.
[0138] In another embodiment, the mobile operator can also use the two duplicate tokens to infer account information, add the account to a blacklist, and notify all satellites of the updated user blacklist. Users on the blacklist will subsequently be unable to obtain satellite network services.
[0139] The self-service direct-connect cellular satellite network service mechanism provided by this application can decouple on-board cellular network functions from stateful sessions, redistribute on-board cellular network functions so that they can independently provide services without relying on the ground network. By designing a one-time token, embedding policy information in the token, and supporting self-authentication, it allows user devices and satellites to complete two-way authentication locally on demand, allowing user devices to obtain services from any satellite on demand and reducing the requirement for a stable service relationship. By embedding user policy information in the token, the satellite is allowed to independently provide operator-level services to users based on the status information in the token, avoiding signaling storms, improving scalability, and promoting multi-operator sharing of the direct-connect cellular satellite network.
[0140] According to the above description, the self-service method and device for a directly connected cellular satellite network provided in the present application decouples the satellite's on-board cellular network function from the stateful session in advance to obtain a decoupled satellite so that the decoupled satellite has the ability to independently provide services; a one-time token is designed, and when the decoupled satellite receives the one-time token, the decoupled satellite is controlled to provide the user device with a service that matches the state information of the established session based on the operator policy information embedded in the one-time token, thereby allowing the user device and the mobile operator to establish a service relationship with the decoupled satellite on demand, so that the decoupled satellite can provide personalized network services to the user device.
[0141] Based on the same concept, the present application also provides a self-service device directly connected to a cellular satellite network.
[0142] The following describes a self-service device for directly connecting to a cellular satellite network provided by the present application. The self-service device for directly connecting to a cellular satellite network described below and the self-service method for directly connecting to a cellular satellite network described above can be referenced to each other.
[0143] FIG9 is a schematic structural diagram of a self-service device directly connected to a cellular satellite network provided by the present application.
[0144] In an exemplary embodiment of the present application, as shown in FIG9 , the self-service device directly connected to the cellular satellite network may include a decoupling module 910 , a design module 920 , and a processing module 930 , each of which will be described below.
[0145] The decoupling module 910 may be configured to decouple the onboard cellular network function of the satellite from the stateful session to obtain a decoupled satellite, wherein the decoupled satellite has the capability to independently provide services;
[0146] The design module 920 may be configured to design a one-time token, wherein the one-time token is embedded with operator policy information, the operator policy information including state information of establishing a session;
[0147] The processing module 930 may be configured to control the decoupled satellite to provide a service to the user equipment according to the operator policy information embedded in the one-time token when the decoupled satellite receives the one-time token, wherein the service matches the state information of the established session.
[0148] In an exemplary embodiment of the present application, the operator policy information further includes authentication information and charging policy.
[0149] In an exemplary embodiment of the present application, the processing module 930 may also be configured to:
[0150] performing bidirectional authentication on the decoupled satellite and the user equipment respectively;
[0151] The processing module 930 may control the decoupled satellite to provide services to the user equipment according to the operator policy information embedded in the one-time token in the following manner:
[0152] In a case where the decoupled satellite and the user equipment pass bidirectional authentication, the decoupled satellite is controlled to provide services to the user equipment according to the operator policy information embedded in the one-time token.
[0153] In an exemplary embodiment of the present application, the processing module 930 may control the decoupled satellite to provide services to the user equipment according to the operator policy information embedded in the one-time token in the following manner:
[0154] Invoking the decoupled satellite to parse the operator policy information embedded in the one-time token to obtain session establishment status information carried by the one-time token;
[0155] Provide services to the user equipment based on the state information of the established session.
[0156] In an exemplary embodiment of the present application, the processing module 930 may implement authentication of the decoupled satellite in the following manner:
[0157] Based on the published master public key, deriving the identity public key of the decoupled satellite and generating a random number, wherein the random number is used to verify the satellite legitimacy of the decoupled satellite;
[0158] controlling the user equipment to encrypt the one-time token and the random number using the identity public key to obtain an encrypted one-time token and an encrypted random number, and sending the encrypted one-time token and the encrypted random number to the decoupled satellite;
[0159] Controlling the decoupled satellite to decrypt the encrypted one-time token and the encrypted random number using an identity private key to obtain a decrypted one-time token and a decrypted random number;
[0160] Calling the user equipment to perform consistency comparison between the decrypted random number sent back by the decoupled satellite and the random number;
[0161] When the decrypted random number passes the consistency comparison with the random number, the authentication of the decoupled satellite by the user equipment is completed.
[0162] In an exemplary embodiment of the present application, the processing module 930 may implement authentication of the user equipment in the following manner:
[0163] controlling the decoupled satellite to generate challenge information according to the token information in the decrypted one-time token and a published hash function, and sending the challenge information to the user equipment;
[0164] calling the user equipment and the user identification card to collaboratively calculate the challenge information, and sending the challenge information to the decoupled satellite;
[0165] Controlling the decoupled satellite to verify whether the token information is token information issued by a mobile network operator based on the challenge information;
[0166] In a case where the token information is token information issued by a mobile network operator, the authentication of the user equipment by the decoupled satellite is completed.
[0167] In an exemplary embodiment of the present application, the processing module 930 may obtain the token information issued by the mobile network operator in the following manner:
[0168] Invoking the user equipment to calculate and generate the token information based on the metadata sent by the mobile network operator;
[0169] The mobile network operator is called to use a private key to sign the token information to obtain token information issued by the mobile network operator.
[0170] In an exemplary embodiment of the present application, the decoupling module 910 may implement decoupling of the satellite's onboard cellular network function from the stateful session in the following manner:
[0171] Complete access network functions are deployed for the satellite, and core network user plane functions are integrated for the satellite to decouple the satellite's onboard cellular network functions from stateful sessions.
[0172] In an exemplary embodiment of the present application, the processing module 930 may also be configured to:
[0173] The mobile network operator is called to issue a digital certificate for the decoupled satellite, so that the decoupled satellite after the issuance of the digital certificate can use the preset spectrum in the authorized geographical area.
[0174] In an exemplary embodiment of the present application, the processing module 930 may also be configured to:
[0175] storing the one-time token consumed by the user equipment in a local preset location of the decoupled satellite;
[0176] In a case where the one-time token consumed by the user equipment is not replayed, the decoupled satellite is controlled to perform token settlement with the mobile operator in an online and / or offline manner based on the one-time token consumed by the user equipment.
[0177] FIG10 illustrates a schematic diagram of the physical structure of an electronic device. As shown in FIG10 , the electronic device may include: a processor 1010, a communications interface 1020, a memory 1030, and a communications bus 1040. The processor 1010, the communications interface 1020, and the memory 1030 communicate with each other via the communications bus 1040. The processor 1010 may invoke logic instructions in the memory 1030 to execute a self-service method for directly connecting to a cellular satellite network. The method includes: pre-decoupling a satellite's onboard cellular network functionality from a stateful session to obtain a decoupled satellite, wherein the decoupled satellite has the ability to independently provide services; designing a one-time token, wherein the one-time token is embedded with operator policy information, including session establishment state information, authentication information, and billing policy; and upon receiving the one-time token, controlling the decoupled satellite to provide a service to a user device based on the operator policy information embedded in the one-time token, wherein the service matches the session establishment state information.
[0178] In addition, the logic instructions in the above-mentioned memory 1030 can be implemented in the form of a software functional unit and can be stored in a computer-readable storage medium when sold or used as an independent product. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0179] On the other hand, the present application also provides a computer program product, which includes a computer program, which can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the self-service method for the directly connected cellular satellite network provided by the above methods, the method including: pre-decoupling the satellite's on-board cellular network function from the stateful session to obtain a decoupled satellite, wherein the decoupled satellite has the ability to independently provide services; designing a one-time token, wherein the one-time token is embedded with operator policy information, and the operator policy information includes status information of establishing a session; when the decoupled satellite receives the one-time token, controlling the decoupled satellite to provide services to the user equipment according to the operator policy information embedded in the one-time token, wherein the service matches the status information of the established session.
[0180] On the other hand, the present application also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to execute the self-service method for the directly connected cellular satellite network provided by the above-mentioned methods, the method comprising: pre-decoupling the satellite's onboard cellular network function from the stateful session to obtain a decoupled satellite, wherein the decoupled satellite has the ability to independently provide services; designing a one-time token, wherein the one-time token is embedded with operator policy information, and the operator policy information includes status information of establishing a session; when the decoupled satellite receives the one-time token, controlling the decoupled satellite to provide services to the user equipment according to the operator policy information embedded in the one-time token, wherein the service matches the status information of the established session.
[0181] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.
[0182] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, or of course, by hardware. Based on this understanding, the essence of the above technical solution or the part that contributes to the existing technology can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or certain parts of the embodiments.
[0183] It should be further understood that although operations are described in a particular order in the drawings in the embodiments of the present application, this should not be construed as requiring that these operations be performed in the particular order shown or in a serial order, or that all of the illustrated operations be performed to obtain the desired results. In certain circumstances, multitasking and parallel processing may be advantageous.
[0184] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the embodiments of the present application.
Claims
1. A self-service method for directly connecting to a cellular satellite network, comprising: Decoupling the satellite's onboard cellular network function from the stateful session to obtain a decoupled satellite, wherein the decoupled satellite has the capability to independently provide services; Designing a one-time token, wherein the one-time token is embedded with operator policy information, wherein the operator policy information includes state information of establishing a session; When the decoupled satellite receives the one-time token, the decoupled satellite is controlled to provide a service for the user equipment according to the operator policy information embedded in the one-time token, wherein the service matches the state information of the established session.
2. The self-service method for directly connecting to a cellular satellite network according to claim 1, wherein: Before applying for satellite service, the user equipment sends the one-time token to the decoupled satellite using channel associated signaling.
3. The self-service method for directly connecting to a cellular satellite network according to claim 1, wherein: Before controlling the decoupled satellite to provide services to the user equipment according to the operator policy information embedded in the one-time token, the method further includes: performing bidirectional authentication on the decoupled satellite and the user equipment respectively; The controlling the decoupled satellite to provide services for the user equipment according to the operator policy information embedded in the one-time token specifically includes: In a case where the decoupled satellite and the user equipment pass bidirectional authentication, the decoupled satellite is controlled to provide services to the user equipment according to the operator policy information embedded in the one-time token.
4. The self-service method for directly connecting to a cellular satellite network according to any one of claims 1 to 3, wherein: The controlling the decoupled satellite to provide services for the user equipment according to the operator policy information embedded in the one-time token specifically includes: Invoking the decoupled satellite to parse the operator policy information embedded in the one-time token to obtain session establishment status information carried by the one-time token; Provide services to the user equipment based on the state information of the established session.
5. The self-service method for directly connecting to a cellular satellite network according to claim 3, wherein: The decoupled satellite is authenticated in the following manner: The user equipment derives the identity public key of the decoupled satellite based on the master public key published by the mobile operator, and generates a random number, wherein the random number is used to verify the satellite legitimacy of the decoupled satellite; controlling the user equipment to encrypt the one-time token and the random number using the identity public key to obtain an encrypted one-time token and an encrypted random number, and sending the encrypted one-time token and the encrypted random number to the decoupled satellite; Controlling the decoupled satellite to decrypt the encrypted one-time token and the encrypted random number using an identity private key to obtain a decrypted one-time token and a decrypted random number; Calling the user equipment to perform consistency comparison between the decrypted random number sent back by the decoupled satellite and the random number; When the decrypted random number passes the consistency comparison with the random number, the authentication of the decoupled satellite by the user equipment is completed.
6. The self-service method for directly connecting to a cellular satellite network according to claim 5, wherein: After obtaining the decrypted one-time token and the decrypted random number, the method authenticates the user equipment in the following manner: controlling the decoupled satellite to generate challenge information according to the token information in the decrypted one-time token and a published hash function, and sending the challenge information to the user equipment; calling the user equipment and the user identification card to collaboratively calculate the challenge information, and sending the challenge information to the decoupled satellite; Controlling the decoupled satellite to verify whether the token information is token information issued by a mobile network operator based on the challenge information; In the case where the token information is token information issued by a mobile network operator Next, the authentication of the user equipment by the decoupled satellite is completed.
7. The self-service method for directly connecting to a cellular satellite network according to claim 6, wherein: The token information issued by the mobile network operator is obtained in the following way: Invoking the user equipment to calculate and generate the token information based on the metadata sent by the mobile network operator; The mobile network operator is called to use a private key to sign the token information to obtain token information issued by the mobile network operator.
8. The self-service method for directly connecting to a cellular satellite network according to claim 1, wherein: The following methods are used to decouple the satellite's onboard cellular network functions from stateful sessions: Complete access network functions are deployed for the satellite, and core network user plane functions are integrated for the satellite to decouple the satellite's onboard cellular network functions from stateful sessions.
9. The self-service method for directly connecting to a cellular satellite network according to claim 1, wherein: After obtaining the decoupled satellite, the method further includes: The mobile network operator is called to issue a digital certificate for the decoupled satellite, so that the decoupled satellite, after obtaining the issued digital certificate, can use the preset spectrum in the authorized geographical area.
10. The self-service method for directly connecting to a cellular satellite network according to claim 1, wherein before the user equipment sends the one-time token to the satellite, the user equipment performs token replay detection locally in the user equipment in the following manner: The identity card of the user equipment participates in the token generation process, and the mobile operator sends metadata to the identity card when generating the one-time token; During the process of calculating token information by the user device, the identity recognition card signs the one-time token and stores the metadata; When the user device consumes the one-time token, the identity card checks whether the metadata corresponding to the one-time token is in the storage. If it is found, it indicates that the one-time token is used for the first time. The identity card returns a response message and deletes the corresponding metadata. otherwise, it indicates that the one-time token has been reused, and the identity card refuses to return the response information.
11. The self-service method for directly connecting to a cellular satellite network according to claim 1, wherein: After controlling the decoupled satellite to provide services for the user equipment according to the operator policy information embedded in the one-time token, the method further includes: storing the one-time token consumed by the user equipment in a local preset location of the decoupled satellite; When the one-time token consumed by the user equipment is not replayed, controlling the decoupled satellite to perform token settlement with the mobile operator in an online and / or offline manner based on the one-time token consumed by the user equipment; The mobile operator uses its locally maintained subscription user information database and consumption token database to perform token replay detection. If the one-time token is not replayed, it is recorded in the consumption token database and the corresponding one-time token is consumed. If the one-time token is detected to be replayed, the corresponding user account is inferred, the account is added to the blacklist and notified to all satellites. Users added to the blacklist will not be able to obtain satellite services.
12. The self-service method for directly connecting to a cellular satellite network according to any one of claims 1 to 11, wherein: The operator policy information also includes authentication information and charging policy.
13. A self-service device directly connected to a cellular satellite network, comprising: a decoupling module, configured to pre-decouple the satellite's onboard cellular network function from the stateful session to obtain a decoupled satellite, wherein the decoupled satellite has the capability to independently provide services; a design module for designing a one-time token, wherein the one-time token is embedded with operator policy information, and the operator policy information includes state information of establishing a session; A processing module is configured to control the decoupled satellite to provide a service to the user equipment according to the operator policy information embedded in the one-time token when the decoupled satellite receives the one-time token, wherein the service is related to the state of the established session. The information matches.
14. The self-service device for direct connection to a cellular satellite network according to claim 13, wherein: The operator policy information also includes authentication information and charging policy.
Citation Information
Patent Citations
Operator information updating method and device
CN112073996A
Consensus authentication method for LEO low earth orbit satellite network
CN114173342A
Satellite control method, device and system and storage medium
CN116886163A
Communication service switching and request sending method and device, equipment and storage medium
CN117319930A
Synchronized Satellite Communications
US20220352976A1