Communication method, entity, communication device, communication system, and storage medium

By initiating a message from the attachment process of the receiving terminal and sending a response message according to authentication and feeder link availability, the implementation problem of the attachment process in S&F mode is solved, and the success rate and accuracy of the attachment process are improved.

WO2025166656A1PCT designated stage Publication Date: 2025-08-14BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/076778
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-02-07
Publication Date
2025-08-14

AI Technical Summary

Technical Problem

In the storage and forwarding (S&F) mode, the attachment process cannot be effectively implemented in the satellite communication system.

Method used

By sending the attachment process initiation message sent by the receiving terminal, corresponding response messages are sent based on whether the authentication and key negotiation AKA process needs to be performed and the availability of the ground station feeder link are available to ensure the smooth progress of the attachment process.

Benefits of technology

It improves the success rate and accuracy of the attachment process, ensuring that the terminal can complete effective attachment under storage and forwarding operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024076778_14082025_PF_FP_ABST
    Figure CN2024076778_14082025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to a communication method, an entity, a communication device, a communication system, and a storage medium. The communication method comprises: a first entity receiving a first message sent by a terminal, wherein the first message is used for initiating an attachment process; and sending a second message to the terminal on the basis of whether an authentication and key agreement (AKA) process needs to be executed and / or whether a feeder link between the first entity and a ground station is available. Thus, an attachment process can be effectively implemented in an S&F mode.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method, entity and communication equipment, communication system, storage medium Technical Field

[0001] The present disclosure relates to the field of communication technology, and in particular to a communication method, entity and communication equipment, a communication system, and a storage medium. Background Art

[0002] Satellite communications can include "transparent satellite payloads" and "regenerated satellite payloads." In the "regenerated satellite payload" scenario, the satellite can support network layer protocols. If the satellite receives a signal from Earth, it can process the signal and regenerate the satellite payload. Because the satellite can process payloads, it can store and forward information. Satellites can establish communications with neighboring satellites via intersatellite links (ISLs). This communication method can be called store-and-forward (S&F) satellite service operation.

[0003] Summary of the Invention

[0004] The embodiments of the present disclosure provide a communication method, entity, communication device, communication system, chip system, storage medium, computer program and computer program product, which can be applied in the field of communication technology to solve the technical problem that "in related technologies, the attachment process cannot be effectively implemented in the S&F mode."

[0005] The present disclosure provides a communication method, an entity and a communication device, a communication system, and a storage medium.

[0006] According to a first aspect of an embodiment of the present disclosure, a communication method is proposed, which is executed by a first entity and includes: receiving a first message sent by a terminal, wherein the first message is used to initiate an attachment process; and sending a second message to the terminal based on whether an authentication and key agreement AKA process needs to be performed and / or whether a feeder link between the first entity and the ground station is available.

[0007] According to a second aspect of an embodiment of the present disclosure, a communication method is proposed, which is executed by a second entity, including: obtaining an authentication vector and / or contract data of a terminal based on a third message from a first entity, wherein the authentication vector and / or contract data are used for an attachment process, and the terminal sends a first message to the first entity, and the first message is used to initiate the attachment process; and storing context information of the terminal.

[0008] According to a third aspect of an embodiment of the present disclosure, a communication method is proposed, which is executed by a third entity, including: establishing a terminal session based on information of the second entity and / or information of the third entity, wherein the terminal sends a first message to the first entity, and the first message is used to initiate an attachment process.

[0009] According to a fourth aspect of an embodiment of the present disclosure, a communication method is proposed, including: a first entity receives a first message sent by a terminal, and sends a second message to the terminal based on whether an authentication and key agreement AKA process needs to be performed and / or whether a feeder link between the first entity and the ground station is available, wherein the first message is used to initiate an attachment process; the second entity obtains an authentication vector and / or subscription data of the terminal based on a third message from the first entity, and stores context information of the terminal, wherein the authentication vector and / or subscription data are used for the attachment process; the third entity establishes a session of the terminal based on the information of the second entity and / or the information of the third entity.

[0010] According to the fifth aspect of an embodiment of the present disclosure, a first entity is proposed, including: a transceiver module, used to receive a first message sent by a terminal, wherein the first message is used to initiate an attachment process, and send a second message to the terminal based on whether an authentication and key agreement AKA process needs to be performed and / or whether a feeder link between the first entity and the ground station is available.

[0011] According to the sixth aspect of an embodiment of the present disclosure, a second entity is proposed, including: a processing module, used to obtain an authentication vector and / or contract data of a terminal based on a third message of the first entity, wherein the authentication vector and / or contract data are used for an attachment process, and the terminal sends a first message to the first entity, the first message is used to initiate the attachment process, and store the context information of the terminal.

[0012] According to the seventh aspect of an embodiment of the present disclosure, a third entity is proposed, including: a processing module, used to establish a session of the terminal based on information of the second entity and / or information of the third entity, wherein the terminal sends a first message to the first entity, and the first message is used to initiate an attachment process.

[0013] According to the eighth aspect of the embodiment of the present disclosure, a communication device is proposed, comprising: one or more processors; wherein the processor is used to call instructions so that the communication device executes the communication method of any one of the first aspect, the second aspect, the third aspect, and the fourth aspect.

[0014] According to a ninth aspect of an embodiment of the present disclosure, a communication system is proposed, characterized in that it includes a first entity, a second entity and a third entity, wherein the first entity is configured to implement the communication method of the first aspect, the second entity is configured to implement the communication method of the second aspect, and the third entity is configured to implement the communication method of the third aspect.

[0015] According to the tenth aspect of the embodiment of the present disclosure, a storage medium is proposed, which stores instructions, and is characterized in that when the instructions are executed on a communication device, the communication device executes a communication method as described in any one of the first, second, third, and fourth aspects. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure or the background technology, the drawings required for use in the embodiments of the present disclosure or the background technology will be described below.

[0017] FIG1A is a schematic diagram illustrating an architecture of a communication system according to an embodiment of the present disclosure;

[0018] FIG1B is a schematic diagram of the system architecture of the S&F satellite service operation according to an embodiment of the present disclosure;

[0019] FIG2 is an interactive schematic diagram illustrating a communication method according to an embodiment of the present disclosure;

[0020] FIG3A is an interactive schematic diagram illustrating a communication method according to another embodiment of the present disclosure;

[0021] FIG3B is an interactive schematic diagram illustrating a communication method according to another embodiment of the present disclosure;

[0022] FIG3C is an interactive schematic diagram illustrating a communication method according to another embodiment of the present disclosure;

[0023] FIG3D is an interactive schematic diagram illustrating a communication method according to another embodiment of the present disclosure;

[0024] FIG3E is an interactive schematic diagram illustrating a communication method according to another embodiment of the present disclosure;

[0025] FIG3F is an interactive schematic diagram illustrating a communication method according to another embodiment of the present disclosure;

[0026] FIG3G is an interactive schematic diagram illustrating a communication method according to another embodiment of the present disclosure;

[0027] FIG4A is an interactive schematic diagram illustrating a communication method according to another embodiment of the present disclosure;

[0028] FIG4B is an interactive schematic diagram illustrating a communication method according to yet another embodiment of the present disclosure;

[0029] FIG4C is an interactive schematic diagram illustrating a communication method according to yet another embodiment of the present disclosure;

[0030] FIG5A is an interactive schematic diagram illustrating a communication method according to another embodiment of the present disclosure;

[0031] FIG5B is an interactive schematic diagram illustrating a communication method according to yet another embodiment of the present disclosure;

[0032] FIG6 is an interactive schematic diagram illustrating a communication method according to yet another embodiment of the present disclosure;

[0033] FIG7 is a schematic diagram of an attachment process according to an embodiment of the present disclosure;

[0034] FIG8A is a schematic structural diagram of a first entity proposed in an embodiment of the present disclosure;

[0035] FIG8B is a schematic structural diagram of a second entity proposed in another embodiment of the present disclosure;

[0036] FIG8C is a schematic structural diagram of a third entity proposed in another embodiment of the present disclosure;

[0037] FIG9A is a schematic structural diagram of a communication device proposed in an embodiment of the present disclosure;

[0038] FIG9B is a schematic diagram of the structure of the chip proposed in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0039] The present disclosure provides a communication method, communication device, communication system, and storage medium. In some embodiments, the terms "communication method," "information processing method," and "communication processing method" are interchangeable; the terms "communication device," "information processing device," and "communication processing device" are interchangeable; and the terms "information processing system," "communication system," and "communication system" are interchangeable.

[0040] The embodiments of the present disclosure are not exhaustive and are merely illustrative of some embodiments, and are not intended to be a specific limitation on the scope of protection of the present disclosure. In the absence of contradiction, each step in a certain embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a certain embodiment can also be implemented as an independent embodiment, and the order of the steps in a certain embodiment can be arbitrarily exchanged. In addition, the optional implementation methods in a certain embodiment can be arbitrarily combined; in addition, the embodiments can be arbitrarily combined. For example, some or all steps of different embodiments can be arbitrarily combined, and a certain embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.

[0041] In each embodiment of the present disclosure, unless otherwise specified or provided for by logic, the terms and / or descriptions between the embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form a new embodiment based on their inherent logical relationships.

[0042] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments and are not intended to limit the present disclosure.

[0043] In the embodiments of the present disclosure, unless otherwise specified, elements expressed in the singular, such as "a", "an", "the", "above", "said", "the", "the", etc., may mean "one and only one", or "one or more", "at least one", etc. For example, when using articles such as "a", "an", "the" in English in translation, the noun following the article may be understood as a singular expression or a plural expression.

[0044] In the embodiments of the present disclosure, “plurality” refers to two or more.

[0045] In some embodiments, the terms "at least one," "one or more," "a plurality of," "multiple," etc. may be used interchangeably.

[0046] In some embodiments, descriptions such as "at least one of A and B," "A and / or B," "A in one case, B in another case," or "in response to one case A, in response to another case B" may include the following technical solutions depending on the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); and in some embodiments, A and B (both A and B are executed). The above is also applicable when there are more branches such as A, B, and C.

[0047] In some embodiments, "A or B" and other descriptions may include the following technical solutions depending on the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed). The above is also applicable when there are more branches such as A, B, C, etc.

[0048] The prefixes such as "first" and "second" in the embodiments of the present disclosure are only used to distinguish different description objects and do not constitute any restriction on the position, order, priority, quantity or content of the description objects. For the statement of the description object, please refer to the description in the context of the claims or embodiments, and no unnecessary restriction should be constituted due to the use of prefixes. For example, if the description object is a "field", the ordinal number before the "field" in the "first field" and the "second field" does not limit the position or order between the "fields". "First" and "second" do not limit whether the "fields" they modify are in the same message, nor do they limit the order of the "first field" and the "second field". For another example, if the description object is a "level", the ordinal number before the "level" in the "first level" and the "second level" does not limit the priority between the "levels". For another example, the number of description objects is not limited by the ordinal number and can be one or more. Taking "first device" as an example, the number of "devices" can be one or more. In addition, the objects modified by different prefixes can be the same or different. For example, if the description object is "device", then the "first device" and the "second device" can be the same device or different devices, and their types can be the same or different; for another example, if the description object is "information", then the "first information" and the "second information" can be the same information or different information, and their contents can be the same or different.

[0049] In some embodiments, “including A,” “comprising A,” “used to indicate A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.

[0050] In some embodiments, terms such as "in response to...", "in response to determining...", "in the case of...", "at the time of...", "when...", "if...", "if...", etc. can be used interchangeably.

[0051] In some embodiments, terms such as "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not less than", and "above" can be replaced with each other, and terms such as "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", and "below" can be replaced with each other.

[0052] In some embodiments, devices and equipment can be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments. In some cases, they can also be understood as "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "subject", etc.

[0053] In some embodiments, "network" can be interpreted as devices included in the network, such as access network equipment, core network equipment, etc.

[0054] In some embodiments, "access network device (AN device)" may also be referred to as "radio access network device (RAN device)", "base station (BS)", "radio base station", "fixed station", and in some embodiments may also be understood as "node", "access point", "transmission point (TP)", "reception point (RP)", "transmission and / or reception point (TRP)" "panel", "antenna panel", "antenna array", "cell", "macro cell", "small cell", "femto cell", "pico cell", "sector", "cell group", "serving cell", "carrier", "component carrier", "bandwidth part (BWP)", etc.

[0055] In some embodiments, "terminal" or "terminal device" may be referred to as "user equipment (UE)", "user terminal" "mobile station (MS)", "mobile terminal (MT)", subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, etc.

[0056] In some embodiments, obtaining data, information, etc. may comply with the laws and regulations of the country where the data is obtained.

[0057] In some embodiments, data, information, etc. may be obtained with the user's consent.

[0058] FIG1A is a schematic diagram illustrating an architecture of a communication system according to an embodiment of the present disclosure. As shown in FIG1A , a communication system 100 may include a terminal 101 , a core network device 102 , and an access network device 103 .

[0059] In some embodiments, the terminal 101 may include, for example, a mobile phone, a wearable device, an Internet of Things device, a car with communication function, a smart car, a tablet computer, a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in a smart grid, a wireless terminal device in transportation safety, a wireless terminal device in a smart city, and at least one of a wireless terminal device in a smart home, but is not limited thereto.

[0060] In some embodiments, the core network device 102 may be a single device including a first network element 1021, a second network element 1022, etc., or may be a plurality of devices or a device group including all or part of the first network element 1021 and the second network element 1022. The network element may be virtual or physical. The core network may include, for example, at least one of an evolved packet core (EPC), a 5G core network (5GCN), and a next generation core (NGC).

[0061] In some embodiments, the first network element 1021 is, for example, a Mobility Management Entity (MME) network element, which is not limited thereto. The MME network element is responsible for mobility management of the control plane, user context and mobility status management, and allocation of temporary user identities.

[0062] In some embodiments, the first network element 1021 is used to provide mobility management functions.

[0063] In some embodiments, the second network element 1022 is, for example, a serving gateway (S-GW) in the core network. The second network element 1022 can perform some tasks such as routing selection and resource allocation during the process of user accessing the network.

[0064] In some embodiments, the terminal 101 and the core network device 102 can be connected through an access network device 103. Optionally, the access network device is, for example, a node or device that accesses the terminal to a wireless network. The access network device may include an evolved NodeB (eNB), a next generation evolved NodeB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved nodeB (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, and at least one of an access node in a wireless fidelity (WiFi) system, but is not limited thereto.

[0065] In some embodiments, the access network device 103 can be composed of a centralized unit (CU) and a distributed unit (DU), where the CU can also be called a control unit. The CU-DU structure can be used to split the protocol layer of the access network device, with the functions of some protocol layers centrally controlled by the CU, and the functions of the remaining part or all of the protocol layers distributed in the DU, which is centrally controlled by the CU, but is not limited to this.

[0066] It can be understood that the communication system described in the embodiment of the present disclosure is for the purpose of more clearly illustrating the technical solution of the embodiment of the present disclosure, and does not constitute a limitation on the technical solution proposed in the embodiment of the present disclosure. Ordinary technicians in this field can know that with the evolution of the system architecture and the emergence of new business scenarios, the technical solution proposed in the embodiment of the present disclosure is also applicable to similar technical problems.

[0067] The following embodiments of the present disclosure may be applied to the communication system 100 shown in FIG1A , or a portion thereof, but are not limited thereto. The entities shown in FIG1A are illustrative only. The communication system may include all or part of the entities shown in FIG1A , or may include other entities other than those shown in FIG1A . The number and form of the entities may be arbitrary. The connection relationship between the entities is illustrative only. The entities may be connected or disconnected, and the connection may be in any manner, including direct or indirect, wired or wireless.

[0068] The embodiments of the present disclosure may be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G New Radio (NR), 6th generation mobile communication system (6G), Future Radio Access (FRA), New Radio Access Technology (RAT), New Radio (NR), New Radio Access (NX), Future Generation Radio Access (FX), Global System for Mobile Communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE802.20, Ultra-WideBand (UWB), Bluetooth (registered trademark)), Public Land Mobile Network (PLMN) network, Device-to-Device (D2D) system, Machine-to-Machine (M2M) system, Internet of Things (IoT) system, Vehicle-to-Everything (V2X), systems using other user plane connection establishment methods, and next-generation systems based on these systems. In addition, multiple systems can also be combined (for example, a combination of LTE or LTE-A with 5G, etc.) for application.

[0069] Optionally, in store-and-forward satellite service operations, the serving link between the UE and the satellite (SAT) and the feeder link between the SAT and the non-terrestrial network (NTN) gateway may not be available at the same time. When the serving link is available but the feeder link is unavailable, the SAT can temporarily store uplink (UL) data sent by the terminal. When the feeder link is available but the serving link is unavailable, the SAT can temporarily store downlink (DL) UE data from the core network.

[0070] The present disclosure defines an architecture for S&F satellite service operations, as shown in FIG1B , which is a schematic diagram of the architecture for S&F satellite service operations in the present disclosure. The architecture includes a terminal, a satellite SAT, an eNB, an MME, an MME agent, and an S-GW. The eNB and MME can be deployed on the satellite SAT. The MME deployed on the satellite can be used to implement most MME functions. The MME deployed on the satellite can also be called a Mobility Management Entity-Non Terrestrial (MME-NT). The MME agent can be used to implement a small portion of the MME functions. The MME agent can be deployed on the ground. The MME agent can also be replaced by a Mobility Management Entity-Terrestrial (MME-T). The MME (or MME-NT) and the MME agent (or MME-T) can be the same entity, for example, two different parts of the same entity, or the MME and the MME agent can be different entities.

[0071] In the embodiments of the present disclosure, the MME may be deployed on a satellite and may be used to implement the following functions:

[0072] Interacts with the Home Subscriber Server (HSS) to obtain subscription data and authentication vectors (AVs); performs terminal authentication and authorization processes; performs UL data decryption and integrity verification, and DL data encryption and integrity protection.

[0073] In the embodiment of the present disclosure, the MME agent is used to implement the following functions: receive a session creation request from the MME on the satellite SAT, and provide the MME information to the S-GW for session creation; record the MME identifier associated with the terminal identifier, and maintain the MME information and S-GW information.

[0074] Optionally, the MME information is, for example, an identifier (IDentifier, ID) of the MME and / or network information.

[0075] Optionally, the S-GW information is, for example, the ID of the S-GW.

[0076] Optionally, the terminal information includes, for example, the terminal ID, the terminal status, the terminal location, etc.

[0077] Optionally, the entity may be referred to as a network element, a device, etc., without limitation.

[0078] FIG2 is an interactive diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG2 , the present disclosure embodiment relates to a communication method that can be used in a communication system 100. The method includes:

[0079] Step S2101: The terminal sends a first message.

[0080] The first message is used to initiate an attach procedure.

[0081] In some embodiments, the first message is, for example, an attach request message, which may be referred to as an Attach Request message.

[0082] In some embodiments, the terminal may send the first message to a first entity, such as an MME or an MME-NT. For example, the terminal may send the first message to the MME or the MME-NT.

[0083] In some embodiments, the first message includes at least one of the following: terminal information and first indication information, wherein the terminal information is used to identify the terminal, and the first indication information is used to indicate that the terminal has the capability to support store-and-forward satellite service operations. This can effectively improve the comprehensiveness of the indication in the first message.

[0084] In some embodiments, the terminal information includes, for example, the terminal ID, the terminal status, the terminal location, etc.

[0085] Step S2102: The first entity sends a second message to the terminal according to whether an authentication and key agreement AKA process needs to be performed and / or whether a feeder link between the first entity and the ground station is available.

[0086] In some embodiments, the first entity can receive a first message sent by the terminal and determine whether an authentication and key agreement (AKA) process needs to be performed. The first entity can also determine whether the feeder link between the first entity and the ground station is available, and then refer to at least one aspect of the judgment result to determine the type of the second message and send a second message of the corresponding type to the terminal.

[0087] In some embodiments, the need to execute the AKA procedure is determined if at least one of the following conditions is met: the first entity does not store the terminal's context information; the first entity does not store the terminal's subscription data; the first message is not integrity protected; or the integrity check of the first message fails. This allows for accurate and efficient determination of the need to execute the AKA procedure.

[0088] The terminal context information may include the terminal identifier, MME identifier, security parameters, terminal status, S&F indication, authorization information, eNB identifier, SAT identifier, location, etc. The terminal subscription data is used for the attachment process.

[0089] For example, if the first entity does not store the context information of the terminal, and / or the first entity does not store the subscription data of the terminal, and / or the first message is not integrity protected, and / or the integrity check of the first message fails, it can be determined that the AKA process needs to be performed. If the first entity stores the context information and subscription data of the terminal, and the first message is integrity protected, and the integrity check of the first message succeeds, it can be determined that the AKA process does not need to be performed.

[0090] In some embodiments, the second message may include a first-type second message, a second-type second message, and a third-type second message. The first-type second message is used to indicate that initiation of the attachment process is not permitted, the second-type second message is used to request authentication of the terminal, and the third-type second message is used to establish a security process. Thus, the corresponding type of second message can be determined and sent based on whether an authentication and key agreement AKA process needs to be performed and / or whether the feeder link between the first entity and the ground station is available. In the S&F mode, a suitable second message can be effectively sent to the terminal to ensure that the terminal can complete the attachment process under the store and forward operation.

[0091] In some embodiments, the first type of second message may be, for example, an attach rejection message. The second type of second message may be, for example, an authentication request message. The third type of second message may be, for example, a security mode command. In the embodiments of the present disclosure, the names of the first type of first message, the second type of second message, and the third type of second message are not limited.

[0092] In some embodiments, the second message of the first type may include at least one of the following: fallback timing information and second indication information. The fallback timing information is used to trigger the terminal to resend the first message; the second indication information is used to indicate the reason why initiation of the attach procedure is not permitted. This effectively indicates the fallback timing information to the terminal, enabling the terminal to determine when to resend the first message based on the fallback timing information. If the second message of the first type includes the second indication information, the terminal can effectively be informed of the reason why initiation of the attach procedure is not permitted.

[0093] The fallback timing information may be a fallback timer or a fallback timing duration. The terminal may refer to the fallback timing information to determine a time to resend the first message.

[0094] In some embodiments, after receiving the second message of the first type, the terminal may determine a timing to resend the first message based on the backoff timing information included in the second message of the first type, and resend the first message to the first entity based on the determined timing.

[0095] In some embodiments, the first entity may receive the first message resent by the terminal in response to the second message, and, based on the resent first message, trigger the step of sending a second message to the terminal based on whether an authentication and key agreement (AKA) process needs to be performed and / or whether a feeder link between the first entity and the ground station is available. This effectively improves the success rate of the attachment process.

[0096] In some embodiments, the fallback timing information is related to coverage availability information and / or ephemeris information of a satellite to which the first entity belongs. That is, the first entity may be configured on a satellite, and the first entity may refer to the satellite's coverage availability information and / or ephemeris information to determine the fallback timing information, thereby improving the accuracy of the fallback timing information determination.

[0097] In some embodiments, the second message of the second type can be used to request authentication of the terminal. If the first entity sends the second message of the second type to the terminal, and the terminal receives the second message of the second type, the terminal can feedback an authentication response message to the first entity. Upon receiving the authentication response message, the first entity compares the response value (Response, RES) with XRES. If the comparison is unsuccessful (indicating authentication failure), the first entity sends a rejection message to the terminal. If the comparison is successful (indicating authentication success), the first entity can send a third type of second message to the terminal.

[0098] In some embodiments, if the first entity determines that the AKA process does not need to be performed, or if the first entity successfully authenticates the terminal, a second message of a third type may be sent to the terminal, where the second message of the third type is used to establish a security process. After receiving the second message of the third type, the terminal may enable a security mode and, after enabling the security mode, send a response message to the first entity to confirm the second message of the third type sent by the first entity.

[0099] In some embodiments, the first entity sends a first type of second message to the terminal (the first type of second message is used to indicate that initiation of the attachment process is not allowed) according to whether the authentication and key agreement AKA process needs to be performed and / or whether the feeder link between the first entity and the ground station is available. The implementation method is illustrated as follows:

[0100] In some embodiments, upon determining that an AKA procedure needs to be performed and that the feeder link is unavailable, a second message of the first type is sent to the terminal. That is, upon determining that an AKA procedure needs to be performed and that the feeder link between the first entity and the ground station is unavailable, the first entity may send the second message of the first type to the terminal.

[0101] In some embodiments, upon determining that an AKA procedure needs to be performed, a feeder link is unavailable, the terminal has the capability to support store-and-forward satellite service operations, and the first entity does not support store-and-forward satellite service operations, a first-type second message is sent to the terminal. In other words, upon determining that an AKA procedure needs to be performed, the feeder link between the first entity and the ground station is unavailable, the terminal has the capability to support store-and-forward satellite service operations, and the first entity does not support store-and-forward satellite service operations, the first entity may send the first-type second message to the terminal.

[0102] Therefore, the sending accuracy of the second message of the first type can be effectively improved, and the system is effectively applicable to personalized situations where an AKA process needs to be executed and a feeder link is unavailable.

[0103] In some embodiments, upon determining that the feeder link is unavailable, the first entity may send a second message of the first type. After sending the second message of the first type, the first entity may also store the terminal information. Thus, if the first entity subsequently detects that the feeder link is available, it may send a third message to the HSS based on the stored terminal information to obtain the terminal's authentication vector and / or subscription data. This enables timely acquisition of the terminal's authentication vector and / or subscription data, supporting efficient implementation of the attachment process.

[0104] In some embodiments, the first entity sends a second message of the second type to the terminal (the second message of the second type is used to request authentication of the terminal) according to whether the authentication and key agreement AKA process needs to be performed and / or whether the feeder link between the first entity and the ground station is available. The implementation method is illustrated as follows:

[0105] In some embodiments, it is determined that the AKA process needs to be executed, and the first entity has obtained the authentication vector and / or contract data of the terminal, and a second message of the second type is sent to the terminal. That is to say, if the first entity determines to execute the AKA process, and determines that the first entity has obtained the authentication vector and / or contract data of the terminal, the first entity may send a second message of the second type to the terminal to request authentication of the terminal. In this case, whether the feeder link between the first entity and the ground station is available can be ignored. As a result, the sending accuracy of the second type of second message can be effectively improved, and it is effectively applicable to personalized situations where the AKA process needs to be executed.

[0106] In some embodiments, the first entity may obtain the authentication vector of the terminal based on any of the following methods:

[0107] The first method is to obtain the stored authentication vector of the terminal.

[0108] For example, the first entity may retrieve a stored authentication vector corresponding to the terminal information according to the terminal information, and use the authentication vector corresponding to the terminal information as the authentication vector of the terminal.

[0109] The second method is to send a third message to the Home Subscriber Server HSS through the second entity, and receive an authentication vector of the terminal sent by the HSS in response to the third message and forwarded by the second entity.

[0110] The second entity is, for example, an MME agent or an MME-T.

[0111] For example, the first entity may send a third message to the second entity, the second entity forwards the third message to the HSS, the second entity receives the authentication vector of the terminal sent by the HSS in response to the third message, and then the second entity sends the authentication vector of the terminal to the first entity, the first entity receives the authentication vector of the terminal, and the first entity may also associate and store the terminal information and the authentication vector of the terminal.

[0112] In some embodiments, the first entity may obtain the subscription data of the terminal. The authentication vector of the terminal and / or the subscription data of the terminal may be used together in the attachment process.

[0113] In some embodiments, the first entity may obtain the subscription data of the terminal based on any of the following methods:

[0114] The first method is to obtain the stored contract data of the terminal.

[0115] For example, the first entity may retrieve the stored contract data corresponding to the terminal information based on the terminal information, and use the contract data corresponding to the terminal information as the contract data of the terminal.

[0116] The second method is to send a third message to the Home Subscriber Server HSS through the second entity, and receive the subscription data of the terminal sent by the HSS in response to the third message and forwarded by the second entity.

[0117] For example, the first entity can send a third message to the second entity, the second entity forwards the third message to the HSS, the second entity receives the terminal's subscription data sent by the HSS in response to the third message, and then the second entity sends the terminal's subscription data to the first entity, the first entity receives the terminal's subscription data, and the first entity can also associate and store the terminal information and the terminal's subscription data.

[0118] In some embodiments, the first entity may also obtain the terminal's authentication vector and the terminal's subscription data based on a combination of the above methods, thereby enabling flexible and effective acquisition of the terminal's authentication vector and / or the terminal's subscription data.

[0119] In some embodiments, the first entity sends a third type of second message to the terminal (the third type of second message is used to establish a security process) according to whether the authentication and key agreement AKA process needs to be performed. The following examples are provided:

[0120] In some embodiments, if it is determined that the AKA process does not need to be performed, a second message of the third type is sent to the terminal. In other words, if the first entity determines that the AKA process does not need to be performed, the second message of the third type may be sent to the terminal to establish a security process.

[0121] In some embodiments, upon determining that an AKA procedure is required and that the AKA procedure is successfully executed, a second message of the third type is sent to the terminal. That is, if the first entity determines that an AKA procedure is required, has executed the AKA procedure, and has successfully executed the AKA procedure, the second message of the third type may be sent to the terminal to establish a security procedure.

[0122] Thereby, the sending accuracy of the second message of the third type can be effectively improved, thereby establishing a security process in a timely manner.

[0123] Step S2103: Determine whether the first entity supports a store-and-forward satellite service operation, wherein the first message includes first indication information.

[0124] In some embodiments, if the first message includes first indication information, the first entity may determine whether the entity supports storage and forwarding satellite service operations. The first entity may also determine whether to allow the terminal to use storage and forwarding satellite service operations based on whether the storage and forwarding satellite service operations are supported.

[0125] That is to say, if the terminal has the capability to support storage and forwarding satellite service operations, and the terminal indicates to the first entity that the terminal has the capability to support storage and forwarding satellite service operations, the first entity can determine whether storage and forwarding satellite service operations are supported, and can also perform subsequent steps.

[0126] Step S2104: Determine whether the first entity supports the store-and-forward satellite service operation, and allow the terminal to use the store-and-forward satellite service operation.

[0127] In some embodiments, if the first entity determines that the entity supports the store-and-forward satellite service operation, the terminal may be allowed to use the store-and-forward satellite service operation.

[0128] Therefore, when both the terminal and the first entity support the store and forward satellite service operation, the first entity can allow the terminal to use the store and forward satellite service operation, thereby effectively ensuring that the terminal performs the store and forward satellite service operation.

[0129] In some embodiments, if it is determined that the first entity supports the store-and-forward satellite service operation, it is further possible to determine whether the terminal is authorized to use the store-and-forward satellite service operation based on the terminal's subscription data. If the terminal is authorized to use the store-and-forward satellite service operation, it is possible to determine whether the terminal is permitted to use the store-and-forward satellite service operation. This allows for accurate and efficient determination of whether the terminal is permitted to use the store-and-forward satellite service operation.

[0130] Step S2105: The first entity sends a fourth message to the terminal.

[0131] In some embodiments, when the first entity successfully authenticates the terminal and establishes security protection, it may send a fourth message to the terminal, where the fourth message is used to indicate acceptance of initiating the attachment procedure.

[0132] In some embodiments, the first entity may send a fourth message to the terminal when security protection is established, where the fourth message is used to indicate acceptance of initiating an attachment procedure.

[0133] In some embodiments, the fourth message is a message that has been protected by a non-access stratum (NAS). The fourth message may be protected based on security parameters determined in a security mode command (SMC).

[0134] In some embodiments, if the first entity determines that the terminal is allowed to use the store-and-forward satellite service operation, the first entity may further indicate to the terminal that the store-and-forward satellite service operation is allowed.

[0135] In some embodiments, the first entity may include third indication information in the fourth message, and indicate to the terminal through the third indication information that the use of the store-and-forward satellite service operation is permitted. This enables timely indication to the terminal of the permission to use the store-and-forward satellite service operation, thereby supporting the terminal in effectively performing the store-and-forward satellite service operation.

[0136] Step S2106: The first entity sends the context information of the terminal to the second entity.

[0137] In some embodiments, after successfully authenticating the terminal and establishing security protection, the first entity may send the terminal's context information to the second entity, and the second entity may maintain the terminal's context information. The terminal's context information may include the terminal's identifier, the MME's identifier, security parameters, the terminal's status, S&F indication information, authorization information, the eNB identifier, the SAT identifier, and the location. The terminal's context information may be generated by the first entity, for example, after the terminal completes the attachment process, generating the terminal's context information. The first entity may then send the terminal's context information to the second entity.

[0138] Step S2107: The second entity stores the context information of the terminal.

[0139] In some embodiments, the second entity may receive the terminal context information sent by the first entity and store the terminal context information. The second entity does not actively update the terminal context information. Once the terminal context information is updated, the first entity again sends the updated terminal context information to the second entity.

[0140] In some embodiments, the second entity may obtain the terminal's authentication vector and / or subscription data based on the third message from the first entity, where the authentication vector and / or subscription data are used in the attachment process, thereby enabling timely acquisition of the terminal's authentication vector and / or subscription data.

[0141] An implementation method for obtaining the authentication vector and / or subscription data of the terminal according to the third message of the first entity can be described as follows:

[0142] In some embodiments, the second entity may receive a third message sent by the first entity, send the third message to a home subscriber server (HSS), receive the authentication vector and / or subscription data of the terminal sent by the HSS in response to the third message, and send the authentication vector and / or subscription data of the terminal to the first entity. This effectively and timely obtains the authentication vector and / or subscription data of the terminal, and timely sends the authentication vector and / or subscription data of the terminal to the first entity, effectively supporting the first entity to perform an attachment process based on the authentication vector and / or subscription data.

[0143] In some embodiments, the first entity may send the first entity's information and / or terminal information to the second entity, and the second entity may receive the first entity's information and / or terminal information sent by the first entity.

[0144] The information of the first entity may be, for example, the ID of the first entity, for example, the ID of the MME, or the ID of the MME-NT. The information of the first entity may also be network information corresponding to the first entity, for example, the network ID or network address information.

[0145] In some embodiments, the second entity may store the information of the first entity and / or the terminal information and / or the context information of the terminal, thereby enabling the information of the first entity and / or the terminal information and / or the context information of the terminal to be effectively maintained in the second entity.

[0146] Step S2108: The second entity sends the information of the second entity to the third entity.

[0147] The third entity is, for example, an S-GW.

[0148] The information of the second entity is, for example, the ID of the second entity, for example, the ID of the MME agent or the ID of the MME-T.

[0149] In some embodiments, if the first message includes an Evolved Packet System Session Management (ESM) message container, the second entity may further send the second entity's information to the third entity. The third entity may establish a session with the terminal based on the second entity's information.

[0150] In some embodiments, during the establishment of the terminal session, the third entity may also send information of the third entity to the second entity, and the second entity may also receive the information of the third entity and maintain and manage the information of the third entity.

[0151] The information of the third entity may be, for example, the ID and address of the third entity, for example, the ID and address of the S-GW.

[0152] Step S2109: The third entity establishes a session with the terminal according to the information of the second entity and / or the information of the third entity.

[0153] In some embodiments, the third entity may receive the information of the second entity and establish a terminal session based on the information of the second entity and / or the information of the third entity, thereby effectively establishing the terminal session.

[0154] In some embodiments, the third entity may send information about the third entity to the second entity. After receiving the information about the third entity, the second entity may send the information about the third entity to the first entity, thereby enabling the first entity to effectively and timely obtain information about the third entity.

[0155] In some embodiments, a third entity may generate a session management context for a terminal. The session management context for the terminal includes at least one of the following: information about the second entity; information about the terminal; or information about the third entity. The session management context is used to record the terminal's session information. This allows the third entity to timely generate and maintain the terminal's session management context.

[0156] The communication method involved in the embodiments of the present disclosure may include at least one of steps S2101 to S2109. For example, step S2101 can be implemented as an independent embodiment, step S2102 can be implemented as an independent embodiment, and so on, but the present invention is not limited thereto. Steps S2101+S2102 can be implemented as independent embodiments, and steps S2101+S2102+S2103 can be implemented as independent embodiments, but the present invention is not limited thereto.

[0157] In this embodiment or example, unless there is any contradiction, each step can be independent, arbitrarily combined or exchanged in order, the optional methods or optional examples can be arbitrarily combined, and can be arbitrarily combined with any steps of other embodiments or other examples.

[0158] FIG3A is an interactive diagram of a communication method according to another embodiment of the present disclosure. As shown in FIG3A , the present disclosure embodiment relates to a communication method that can be used by a first entity. The method includes:

[0159] Step S3101: Receive a first message sent by a terminal, where the first message is used to initiate an attachment process.

[0160] Step S3102: Send a second message to the terminal based on whether an authentication and key agreement AKA process needs to be performed and / or whether a feeder link between the first entity and the ground station is available.

[0161] The communication method involved in the embodiments of the present disclosure may include at least one of steps S3101 and S3102. For example, step S3101 may be implemented as an independent embodiment, step S3102 may be implemented as an independent embodiment, and so on, but the present disclosure is not limited thereto. Steps S3101 and S3102 may be implemented as independent embodiments, but the present disclosure is not limited thereto.

[0162] In this embodiment or example, unless there is any contradiction, each step can be independent, arbitrarily combined or exchanged in order, the optional methods or optional examples can be arbitrarily combined, and can be arbitrarily combined with any steps of other embodiments or other examples.

[0163] FIG3B is an interactive diagram of a communication method according to another embodiment of the present disclosure. As shown in FIG3B , the present disclosure embodiment relates to a communication method that can be used by a first entity. The method includes:

[0164] Step S3201: Receive a first message sent by a terminal, where the first message is used to initiate an attachment process.

[0165] Step S3202: Determine that the AKA process needs to be executed and the feeder link between the first entity and the ground station is unavailable, and send a second message of the first type to the terminal, wherein the second message of the first type is used to indicate that initiation of the attachment process is not allowed.

[0166] Step S3203: Determine that the feeder link is unavailable and store the terminal information.

[0167] Step S3204: The receiving terminal sends the first message again in response to the second message.

[0168] The communication method involved in the embodiments of the present disclosure may include at least one of steps S3201 to S3204. For example, step S3201 may be implemented as an independent embodiment, step S3202 may be implemented as an independent embodiment, and so on, but the present disclosure is not limited thereto. Steps S3201+S3202 may be implemented as independent embodiments, but the present disclosure is not limited thereto.

[0169] In this embodiment or example, unless there is any contradiction, each step can be independent, arbitrarily combined or exchanged in order, the optional methods or optional examples can be arbitrarily combined, and can be arbitrarily combined with any steps of other embodiments or other examples.

[0170] FIG3C is an interactive diagram of a communication method according to another embodiment of the present disclosure. As shown in FIG3C , the present disclosure embodiment relates to a communication method that can be used by a first entity. The method includes:

[0171] Step S3301: Receive a first message sent by a terminal, where the first message is used to initiate an attachment process.

[0172] Step S3302: Determine that the AKA process needs to be executed, the feeder link between the first entity and the ground station is unavailable, the terminal has the ability to support storage and forwarding satellite service operations, and the first entity does not support storage and forwarding satellite service operations, and send a second message of the first type to the terminal, wherein the second message of the first type is used to indicate that initiation of the attachment process is not allowed.

[0173] Step S3303: Determine that the feeder link is unavailable and store the terminal information.

[0174] Step S3304: The receiving terminal sends the first message again in response to the second message.

[0175] The communication method involved in the embodiments of the present disclosure may include at least one of steps S3301 to S3304. For example, step S3301 can be implemented as an independent embodiment, step S3302 can be implemented as an independent embodiment, and so on, but the present disclosure is not limited thereto. Steps S3301+S3302 can be implemented as independent embodiments, but the present disclosure is not limited thereto.

[0176] In this embodiment or example, unless there is any contradiction, each step can be independent, arbitrarily combined or exchanged in order, the optional methods or optional examples can be arbitrarily combined, and can be arbitrarily combined with any steps of other embodiments or other examples.

[0177] FIG3D is an interactive diagram of a communication method according to another embodiment of the present disclosure. As shown in FIG3D , the present disclosure embodiment relates to a communication method that can be used by a first entity. The method includes:

[0178] Step S3401: Receive a first message sent by a terminal, where the first message is used to initiate an attachment process.

[0179] Step S3402: Determine that the AKA process needs to be executed, and the first entity has obtained the authentication vector and / or subscription data of the terminal, and send a second message of the second type to the terminal, wherein the second message of the second type is used to request authentication of the terminal.

[0180] The manner in which the first entity obtains the authentication vector and / or subscription data of the terminal includes any one of the following:

[0181] Obtaining stored authentication vectors and / or contract data of the terminal;

[0182] A third message is sent to the Home Subscriber Server HSS through the second entity, and the authentication vector and / or subscription data of the terminal sent by the HSS in response to the third message and forwarded by the second entity are received.

[0183] The communication method involved in the embodiments of the present disclosure may include at least one of steps S3401 and S3402. For example, step S3401 can be implemented as an independent embodiment, step S3402 can be implemented as an independent embodiment, and so on, but the present invention is not limited thereto. Steps S3401 and S3402 can be implemented as independent embodiments, but the present invention is not limited thereto.

[0184] In this embodiment or example, unless there is any contradiction, each step can be independent, arbitrarily combined or exchanged in order, the optional methods or optional examples can be arbitrarily combined, and can be arbitrarily combined with any steps of other embodiments or other examples.

[0185] FIG3E is an interactive diagram of a communication method according to another embodiment of the present disclosure. As shown in FIG3E , the present disclosure embodiment relates to a communication method that can be used by a first entity. The method includes:

[0186] Step S3501: Receive a first message sent by a terminal, where the first message is used to initiate an attachment process.

[0187] Step S3502: Determining that the AKA process does not need to be performed, sending a second message of the third type to the terminal, wherein the second message of the third type is used to establish a security process.

[0188] The communication method involved in the embodiments of the present disclosure may include at least one of steps S3501 and S3502. For example, step S3501 can be implemented as an independent embodiment, step S3502 can be implemented as an independent embodiment, and so on, but the present disclosure is not limited thereto. Steps S3501 and S3502 can be implemented as independent embodiments, but the present disclosure is not limited thereto.

[0189] In this embodiment or example, unless there is any contradiction, each step can be independent, arbitrarily combined or exchanged in order, the optional methods or optional examples can be arbitrarily combined, and can be arbitrarily combined with any steps of other embodiments or other examples.

[0190] FIG3F is an interactive diagram of a communication method according to another embodiment of the present disclosure. As shown in FIG3F , the present disclosure embodiment relates to a communication method that can be used by a first entity. The method includes:

[0191] Step S3601: Receive a first message sent by a terminal, where the first message is used to initiate an attachment process.

[0192] Step S3602: Determine that the AKA process needs to be executed and the AKA process is successfully executed, and send a second message of the third type to the terminal, wherein the second message of the third type is used to establish a security process.

[0193] The communication method involved in the embodiments of the present disclosure may include at least one of steps S3601 and S3602. For example, step S3601 can be implemented as an independent embodiment, step S3602 can be implemented as an independent embodiment, and so on, but the present disclosure is not limited thereto. Steps S3601 and S3602 can be implemented as independent embodiments, but the present disclosure is not limited thereto.

[0194] In this embodiment or example, unless there is any contradiction, each step can be independent, arbitrarily combined or exchanged in order, the optional methods or optional examples can be arbitrarily combined, and can be arbitrarily combined with any steps of other embodiments or other examples.

[0195] FIG3G is an interactive diagram of a communication method according to another embodiment of the present disclosure. As shown in FIG3G , the present disclosure embodiment relates to a communication method that can be used by a first entity. The method includes:

[0196] Step S3701: Receive a first message sent by a terminal, where the first message is used to initiate an attachment process.

[0197] Step S3702: Send a second message to the terminal based on whether an authentication and key agreement AKA process needs to be performed and / or whether a feeder link between the first entity and the ground station is available.

[0198] Step S3703: The first message includes first indication information to determine whether the first entity supports the store-and-forward satellite service operation.

[0199] Step S3704: Determine whether the first entity supports the store-and-forward satellite service operation, and allow the terminal to use the store-and-forward satellite service operation.

[0200] In some embodiments, determining that the first entity supports the store-and-forward satellite service operation and allowing the terminal to use the store-and-forward satellite service operation further includes:

[0201] Determining that the first entity supports a store-and-forward satellite service operation, and determining, based on subscription data of the terminal, that the terminal is authorized to perform the store-and-forward satellite service operation;

[0202] Determines whether the terminal is allowed to operate using store-and-forward satellite services.

[0203] Step S3705: Send a fourth message to the terminal, wherein the fourth message is used to indicate acceptance of initiating the attach process, and the fourth message includes third indication information, and the third indication information is used to indicate permission to use the store and forward satellite service operation.

[0204] Step S3706: Send the context information of the terminal to the second entity.

[0205] The communication method involved in the embodiments of the present disclosure may include at least one of steps S3701 to S3706. For example, step S3701 can be implemented as an independent embodiment, step S3702 can be implemented as an independent embodiment, and so on, but the present disclosure is not limited thereto. Steps S3701+S3702 can be implemented as independent embodiments, but the present disclosure is not limited thereto.

[0206] In this embodiment or example, unless there is any contradiction, each step can be independent, arbitrarily combined or exchanged in order, the optional methods or optional examples can be arbitrarily combined, and can be arbitrarily combined with any steps of other embodiments or other examples.

[0207] FIG4A is an interactive diagram of a communication method according to another embodiment of the present disclosure. As shown in FIG4A , the present disclosure embodiment relates to a communication method that can be used by a second entity. The method includes:

[0208] Step S4101: Obtain the authentication vector and / or subscription data of the terminal according to the third message of the first entity, wherein the authentication vector and / or subscription data are used for the attachment process. The terminal sends a first message to the first entity, and the first message is used to initiate the attachment process.

[0209] Step S4102: Store the context information of the terminal.

[0210] The communication method involved in the embodiments of the present disclosure may include at least one of steps S4101 and S4102. For example, step S4101 may be implemented as an independent embodiment, step S4102 may be implemented as an independent embodiment, and so on, but the present disclosure is not limited thereto. Steps S4101 and S4102 may be implemented as independent embodiments, but the present disclosure is not limited thereto.

[0211] In this embodiment or example, unless there is any contradiction, each step can be independent, arbitrarily combined or exchanged in order, the optional methods or optional examples can be arbitrarily combined, and can be arbitrarily combined with any steps of other embodiments or other examples.

[0212] FIG4B is an interactive diagram of a communication method according to another embodiment of the present disclosure. As shown in FIG4B , the present disclosure embodiment relates to a communication method that can be used by a second entity. The method includes:

[0213] Step S4201: Receive a third message sent by the first entity, and send the third message to a home subscriber server HSS.

[0214] Step S4202: Receive the authentication vector and / or subscription data of the terminal sent by the HSS in response to the third message, wherein the authentication vector and / or subscription data are used for the attachment process, and the terminal sends a first message to the first entity, and the first message is used to initiate the attachment process.

[0215] Step S4203: Send the authentication vector and / or subscription data of the terminal to the first entity.

[0216] Step S4204: Receive context information of the terminal sent by the first entity.

[0217] Step S4205: Store the information of the first entity and / or the terminal information and the context information of the terminal.

[0218] The communication method involved in the embodiments of the present disclosure may include at least one of steps S4201 to S4205. For example, step S4201 may be implemented as an independent embodiment, step S4202 may be implemented as an independent embodiment, and so on, but the present disclosure is not limited thereto. Steps S4201+S4202 may be implemented as independent embodiments, but the present disclosure is not limited thereto.

[0219] In this embodiment or example, unless there is any contradiction, each step can be independent, arbitrarily combined or exchanged in order, the optional methods or optional examples can be arbitrarily combined, and can be arbitrarily combined with any steps of other embodiments or other examples.

[0220] FIG4C is an interactive diagram of a communication method according to another embodiment of the present disclosure. As shown in FIG4C , the present disclosure embodiment relates to a communication method that can be used by a second entity. The method includes:

[0221] Step S4301: Obtain the authentication vector and / or subscription data of the terminal according to the third message of the first entity, wherein the authentication vector and / or subscription data are used for the attachment process. The terminal sends a first message to the first entity, and the first message is used to initiate the attachment process.

[0222] Step S4302: Store the context information of the terminal.

[0223] Step S4303: Send the information of the second entity to the third entity, where the information of the second entity is used to establish a session of the terminal.

[0224] Step S4304: Receive information of the third entity and send the information of the third entity to the first entity, wherein the information of the third entity is used to establish a session of the terminal.

[0225] The communication method involved in the embodiments of the present disclosure may include at least one of steps S4301 to S4304. For example, step S4301 can be implemented as an independent embodiment, step S4302 can be implemented as an independent embodiment, and so on, but the present disclosure is not limited thereto. Steps S4301+S4302 can be implemented as independent embodiments, but the present disclosure is not limited thereto.

[0226] In this embodiment or example, unless there is any contradiction, each step can be independent, arbitrarily combined or exchanged in order, the optional methods or optional examples can be arbitrarily combined, and can be arbitrarily combined with any steps of other embodiments or other examples.

[0227] FIG5A is an interactive diagram of a communication method according to another embodiment of the present disclosure. As shown in FIG5A , the present disclosure embodiment relates to a communication method that can be used by a third entity. The method includes:

[0228] Step S5101: Establish a terminal session based on the information of the second entity and / or the information of the third entity, wherein the terminal sends a first message to the first entity, and the first message is used to initiate an attachment process.

[0229] The communication method involved in the embodiment of the present disclosure may include step S5101. For example, step S5101 may be implemented as an independent embodiment, but is not limited thereto.

[0230] In this embodiment or example, unless there is any contradiction, each step can be independent, arbitrarily combined or exchanged in order, the optional methods or optional examples can be arbitrarily combined, and can be arbitrarily combined with any steps of other embodiments or other examples.

[0231] FIG5B is an interactive diagram of a communication method according to another embodiment of the present disclosure. As shown in FIG5B , the present disclosure embodiment relates to a communication method that can be used by a third entity. The method includes:

[0232] Step S5201: Establish a terminal session based on the information of the second entity and / or the information of the third entity, wherein the terminal sends a first message to the first entity, and the first message is used to initiate an attachment process.

[0233] Step S5202: receiving information of the second entity sent by the second entity; and / or sending information of the third entity to the second entity.

[0234] Step S5203: Generate a session management context of the terminal, wherein the session management context of the terminal includes at least one of the following: information of the second entity; terminal information; and information of the third entity.

[0235] The communication method involved in the embodiments of the present disclosure may include at least one of steps S5201 to S5203. For example, step S5201 can be implemented as an independent embodiment, step S5202 can be implemented as an independent embodiment, and so on, but the present disclosure is not limited thereto. Steps S5201+S5203 can be implemented as independent embodiments, but the present disclosure is not limited thereto.

[0236] In this embodiment or example, unless there is any contradiction, each step can be independent, arbitrarily combined or exchanged in order, the optional methods or optional examples can be arbitrarily combined, and can be arbitrarily combined with any steps of other embodiments or other examples.

[0237] FIG6 is an interactive diagram of a communication method according to another embodiment of the present disclosure. As shown in FIG6 , the present disclosure embodiment relates to a communication method that can be used in a communication system. The method includes:

[0238] In step S6101, the first entity receives a first message sent by the terminal, and sends a second message to the terminal based on whether an authentication and key agreement AKA process needs to be performed and / or whether the feeder link between the first entity and the ground station is available, wherein the first message is used to initiate an attachment process.

[0239] In step S6102, the second entity obtains the authentication vector and / or subscription data of the terminal according to the third message of the first entity, and stores the context information of the terminal, wherein the authentication vector and / or subscription data are used for the attachment process.

[0240] Step S6103: The third entity establishes a session with the terminal according to the information of the second entity and / or the information of the third entity.

[0241] The communication method involved in the embodiments of the present disclosure may include at least one of steps S6101 to S6103. For example, step S6101 can be implemented as an independent embodiment, step S6102 can be implemented as an independent embodiment, and so on, but the present disclosure is not limited thereto. Steps S6101+S6102 can be implemented as independent embodiments, but the present disclosure is not limited thereto.

[0242] In this embodiment or example, unless there is any contradiction, each step can be independent, arbitrarily combined or exchanged in order, the optional methods or optional examples can be arbitrarily combined, and can be arbitrarily combined with any steps of other embodiments or other examples.

[0243] The following is an exemplary introduction to the above method.

[0244] Optional embodiment:

[0245] As shown in Figure 7, Figure 7 is a schematic diagram of the attachment process in an embodiment of the present disclosure. Figure 7 includes a UE, a Radio Access Network (RAN) node, an MME, an MME agent, an S-GW, and an HSS. The RAN node and MME are deployed on a satellite (SAT). Of course, the MME can also be replaced by an MME-NT, and the MME agent can also be replaced by an MME-T, without limitation.

[0246] 1. Send an attach request message.

[0247] In some embodiments, the attach request message may be referred to as an Attach Request message.

[0248] In some embodiments, the UE initiates the attach procedure by sending an Attach Request message (which may include the International Mobile Subscriber Identity (IMSI) or the legacy Globally Unique Temporary UE Identity (GUTI)) to the eNodeB (RAN node). The eNodeB forwards the Attach Request message to the MME.

[0249] 2. Send an attach reject message.

[0250] In some embodiments, the attach reject message may be referred to as an Attach Reject message.

[0251] In some embodiments, if the UE context / UE subscription data of the terminal does not exist in the MME, and if the attach request message is not integrity protected, or the integrity check fails, an authentication and key agreement (AKA) process and NAS security establishment are performed to activate integrity protection and NAS encryption.

[0252] In some embodiments, if an AKA process is required and the feeder link between the MME and the ground station is unavailable, the MME sends an Attach Reject message to the terminal, which may carry a backoff timer and a rejection reason. The MME may determine the backoff timer based on SAT coverage availability information or ephemeris information.

[0253] In some embodiments, if the feeder link between the MME and the ground station is available, no attach reject message is sent to the terminal.

[0254] In some embodiments, if it is determined that the AKA process does not need to be performed, the following steps 2 to 6 may be skipped.

[0255] 3a. AV request message / response message.

[0256] In some embodiments, the AV request message / response message can be used to request an interactive random number (Random Challenge, RAND), XRES (representing authentication information, i.e., expected response (Expected Response)), authentication token (Authentication Token, AUTN), K ASME (Intermediate Key).

[0257] In some embodiments, if the MME does not store the authentication vector AV, the MME may send an AV request message to the HSS. The MME may store the AV associated with the UE identity (eg, IMSI or old GUTI).

[0258] 3b. Contract data request message / response message.

[0259] In some embodiments, if the MME does not store the subscription data of the terminal, the MME sends a subscription data request message to the HSS. The MME may store the terminal subscription data associated with the UE identity (eg, IMSI or old GUTI).

[0260] 4. Send an attach request message.

[0261] In some embodiments, based on a backoff timer, the terminal may attempt to resend an attach request message to the MME via the eNodeB.

[0262] In some embodiments, based on the paging message, the terminal may attempt to resend the attach request message to the MME through the eNodeB.

[0263] In some embodiments, the MME may trigger the eNodeB to send a paging request after acquiring the AV or subscription data. After receiving the paging request, the terminal resends the attach request message.

[0264] 5. Send an authentication request message.

[0265] In some embodiments, the MME sends an authentication request message to perform the AKA procedure.

[0266] 6. Send authentication response message.

[0267] In some embodiments, the terminal feeds back an authentication response message. Upon receiving the authentication response message, the MME compares the response value (RES) with the XRES. If the comparison is unsuccessful, the MME sends a rejection message to the terminal.

[0268] 7. Send the safe mode command.

[0269] In some embodiments, if the terminal passes authentication, the MME may initiate the security mode by sending a security mode command.

[0270] 8. Send Safe Mode Response.

[0271] In some embodiments, after the terminal enables the security mode, it confirms the security mode command sent by the MME.

[0272] In some embodiments, if the S&F capability is specified in the "Attach Request Message", the MME may check whether the MME supports S&F satellite service operations and check whether the terminal is allowed to use S&F satellite service operations based on the terminal subscription data.

[0273] 9. Send an attach accept message.

[0274] In some embodiments, if both the terminal and the MME support S&F satellite service operations and the terminal is authorized to use S&F satellite service operations, the MME may include an indication of support for S&F satellite service operations in the Attach Accept message. Otherwise, the MME may not include an indication of support for S&F in the Attach Accept message.

[0275] 10. Send an attach complete message.

[0276] In some embodiments, the terminal may send an attach complete message.

[0277] 11. Create session request message / response message.

[0278] In some embodiments, if the terminal includes an ESM message container in the attach request message, the MME may send a create session request to the S-GW via the MME proxy. The MME may also provide the MME proxy with context information of the terminal, such as whether the terminal supports S&F satellite service operations.

[0279] In some embodiments, the MME agent locally records the MME information and the terminal information in the terminal context information, and forwards the session creation request to the S-GW.

[0280] In some embodiments, when creating a Session Management (SM) context, the S-GW records information of the MME agent instead of the MME information. The S-GW may also feed back the S-GW information to the MME agent.

[0281] In some embodiments, the MME proxy maintains the S-GW information in the UE context and responds to the MME by sending a Create Session Response message.

[0282] In some embodiments, after receiving the create session response message, the MME provides the "address of the S-GW" to the terminal.

[0283] In the embodiment of the present disclosure, when the feeder link is unavailable and an AKA process needs to be performed, the MME may send an attach reject message to the terminal.

[0284] In the disclosed embodiment, the MME can determine the fallback time according to the coverage availability information.

[0285] In the embodiment of the present disclosure, when the feeder link is available, the MME can request the HSS for the AV of the terminal through the MME agent.

[0286] In the embodiment of the present disclosure, when the feeder link is available, the MME can request the HSS for the subscription data of the terminal through the MME agent.

[0287] In the disclosed embodiment, the MME can trigger the attach process after receiving the AV and subscription data of the terminal.

[0288] In the disclosed embodiment, the MME can check whether the terminal is authorized to use the S&F satellite service operation through the terminal subscription data.

[0289] In the embodiment of the present disclosure, when the feeder link is unavailable, the MME should be able to store the UE identity that sends the attach request.

[0290] In the embodiment of the present disclosure, the MME agent can forward the AV request and AV response to the HSS and the MME.

[0291] In the disclosed embodiment, the MME agent can forward the subscription data request and subscription data response to the HSS and the MME.

[0292] In the embodiment of the present disclosure, the MME agent can provide its identity to the S-GW.

[0293] In the embodiment of the present disclosure, the MME agent can provide the S-GW address to the MME.

[0294] In the embodiment of the present disclosure, the S-GW should be able to create an SM context by using the identity of the MME proxy identity.

[0295] FIG8A is a schematic diagram of the structure of the first entity proposed in one embodiment of the present disclosure. As shown in FIG8A , the first entity 8100 may include at least one of a transceiver module 8101 and a processing module 8102. The first entity 8100 may include:

[0296] The transceiver module 8101 is used to receive a first message sent by the terminal, wherein the first message is used to initiate an attachment process, and send a second message to the terminal based on whether an authentication and key agreement AKA process needs to be performed and / or whether the feeder link between the first entity and the ground station is available.

[0297] In some embodiments of the present disclosure, the first message includes at least one of the following:

[0298] Terminal information, where the terminal information is used to identify the terminal;

[0299] The first indication information is used to indicate that the terminal has the capability of supporting storage and forwarding satellite service operations.

[0300] In some embodiments of the present disclosure, the processing module 8102 is configured to determine that the AKA process needs to be executed when at least one of the following conditions is satisfied:

[0301] The first entity does not store the context information of the terminal;

[0302] The first entity does not store the subscription data of the terminal;

[0303] The first message is not integrity protected;

[0304] The integrity check of the first message failed.

[0305] In some embodiments of the present disclosure, the second message is a second message of a first type, wherein the second message of the first type is used to indicate that initiation of an attach procedure is not allowed;

[0306] Among them, the transceiver module 8101 is specifically used to determine that the AKA process needs to be executed and the feeder link is unavailable, and send a first type of second message to the terminal; wherein, determining that the AKA process needs to be executed and the feeder link is unavailable, and sending a first type of second message to the terminal includes: determining that the AKA process needs to be executed, the feeder link is unavailable, the terminal has the ability to support storage and forwarding satellite service operations, and the first entity does not support storage and forwarding satellite service operations, and sending a first type of second message to the terminal.

[0307] In some embodiments of the present disclosure, the transceiver module 8101 is specifically configured to:

[0308] Determine that the feeder link is unavailable and store the terminal information.

[0309] In some embodiments of the present disclosure, the second message of the first type includes at least one of the following:

[0310] Fallback timing information, wherein the fallback timing information is used to trigger the terminal to resend the first message;

[0311] The second indication information is used to indicate the reason why initiation of the attachment process is not allowed.

[0312] In some embodiments of the present disclosure, the back-off timing information is related to coverage availability information and / or ephemeris information of a satellite to which the first entity belongs.

[0313] In some embodiments of the present disclosure, the transceiver module 8101 is further configured to:

[0314] The receiving terminal resends the first message in response to the second message.

[0315] In some embodiments of the present disclosure, the second message is a second message of a second type, wherein the second message of the second type is used to request authentication of the terminal;

[0316] The transceiver module 8101 is also used for:

[0317] It is determined that the AKA process needs to be performed, and the first entity has obtained the authentication vector and / or subscription data of the terminal, and sends a second message of the second type to the terminal.

[0318] In some embodiments of the present disclosure, the first entity has obtained the authentication vector and / or subscription data of the terminal, wherein the processing module 8102 obtains the authentication vector and / or subscription data of the terminal based on any one of the following:

[0319] Obtaining stored authentication vectors and / or contract data of the terminal;

[0320] A third message is sent to the Home Subscriber Server HSS through the second entity, and the authentication vector and / or subscription data of the terminal sent by the HSS in response to the third message and forwarded by the second entity are received.

[0321] In some embodiments of the present disclosure, the second message is a second message of a third type, wherein the second message of the third type is used to establish a security procedure;

[0322] The transceiver module 8101 is also used for:

[0323] Determining that there is no need to perform the AKA process, and sending a second message of the third type to the terminal;

[0324] It is determined that the AKA process needs to be executed and the AKA process is executed successfully, and a second message of the third type is sent to the terminal.

[0325] In some embodiments of the present disclosure, the processing module 8102 is further configured to:

[0326] The first message includes first indication information to determine whether the first entity supports store-and-forward satellite service operations;

[0327] It is determined that the first entity supports the store-and-forward satellite service operation, and the terminal is allowed to use the store-and-forward satellite service operation.

[0328] In some embodiments of the present disclosure, the processing module 8102 is further configured to:

[0329] Determining that the first entity supports a store-and-forward satellite service operation, and determining, based on subscription data of the terminal, that the terminal is authorized to perform the store-and-forward satellite service operation;

[0330] Determines whether the terminal is allowed to operate using store-and-forward satellite services.

[0331] In some embodiments of the present disclosure, the transceiver module 8101 is further configured to:

[0332] A fourth message is sent to the terminal, wherein the fourth message is used to indicate acceptance of initiating the attach process, and the fourth message includes third indication information, and the third indication information is used to indicate permission to use the store and forward satellite service operation.

[0333] In some embodiments of the present disclosure, the transceiver module 8101 is further configured to:

[0334] The context information of the terminal is sent to the second entity.

[0335] In some embodiments of the present disclosure, the first entity is deployed on a satellite.

[0336] FIG8B is a schematic diagram of the structure of a second entity proposed in another embodiment of the present disclosure. As shown in FIG8B , the second entity 8200 may include: at least one of a transceiver module 8201 and a processing module 8202. The second entity 8200 may include:

[0337] The transceiver module 8201 is used to obtain the authentication vector and / or contract data of the terminal based on the third message of the first entity, wherein the authentication vector and / or contract data are used for the attachment process. The terminal sends a first message to the first entity, and the first message is used to initiate the attachment process and store the context information of the terminal.

[0338] In some embodiments of the present disclosure, the transceiver module 8201 is further configured to:

[0339] receiving a third message sent by the first entity, and sending the third message to a home subscriber server HSS;

[0340] receiving an authentication vector and / or subscription data of the terminal sent by the HSS in response to the third message;

[0341] An authentication vector and / or subscription data of the terminal is sent to the first entity.

[0342] In some embodiments of the present disclosure, the transceiver module 8201 is further configured to:

[0343] Receive context information of the terminal sent by the first entity.

[0344] In some embodiments of the present disclosure, the processing module 8202 is configured to:

[0345] The information of the first entity and / or the terminal information of the terminal is stored.

[0346] In some embodiments of the present disclosure, the transceiver module 8201 is further configured to:

[0347] Sending information of the second entity to a third entity, wherein the information of the second entity is used to establish a session of the terminal; and / or

[0348] Receive information of the third entity and send the information of the third entity to the first entity, wherein the information of the third entity is used to establish a session of the terminal.

[0349] In some embodiments of the present disclosure, the second entity is deployed on the ground.

[0350] FIG8C is a schematic diagram of the structure of a third entity proposed in another embodiment of the present disclosure. As shown in FIG8C , the third entity 8300 may include: at least one of a transceiver module 8301 and a processing module 8302. The third entity 8300 may include:

[0351] The processing module 8302 is configured to establish a terminal session according to the information of the second entity and / or the information of the third entity, wherein the terminal sends a first message to the first entity, and the first message is used to initiate an attachment process.

[0352] In some embodiments of the present disclosure, the transceiver module 8301 is configured to:

[0353] receiving information of the second entity sent by the second entity; and / or

[0354] The information of the third entity is sent to the second entity.

[0355] In some embodiments of the present disclosure, the processing module 8302 is further configured to:

[0356] A session management context of the terminal is generated, wherein the session management context of the terminal includes at least one of the following: information of the second entity; terminal information; and information of the third entity.

[0357] In some embodiments, the transceiver module may include a transmitting module and / or a receiving module, and the transmitting module and the receiving module may be separate or integrated. Optionally, the transceiver module may be interchangeable with the transceiver.

[0358] In some embodiments, the processing module can be a single module or can include multiple submodules. Optionally, the multiple submodules respectively execute all or part of the steps required to be executed by the processing module. Optionally, the processing module can be interchangeable with the processor.

[0359] It should be understood that the division of the various units or modules in the above device is merely a division of logical functions. In actual implementation, they may be fully or partially integrated into a physical entity, or they may be physically separated. In addition, the units or modules in the device may be implemented in the form of a processor calling software: for example, the device includes a processor, the processor is connected to a memory, and the memory stores instructions. The processor calls the instructions stored in the memory to implement any of the above methods or implement the functions of the various units or modules of the above device, wherein the processor is, for example, a general-purpose processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory within the device or a memory outside the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits, and the functions of some or all of the units or modules can be realized by designing the hardware circuits. The above-mentioned hardware circuits can be understood as one or more processors; for example, in one implementation, the above-mentioned hardware circuit is an application-specific integrated circuit (ASIC), which realizes the functions of some or all of the above units or modules by designing the logical relationship of the components in the circuit; for example, in another implementation, the above-mentioned hardware circuit can be realized by a programmable logic device (PLD). Taking a field programmable gate array (FPGA) as an example, it can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by configuring the configuration file, thereby realizing the functions of some or all of the above units or modules. All units or modules of the above devices can be realized in the form of software called by the processor, or in the form of hardware circuits, or in part by the form of software called by the processor, and the rest by hardware circuits.

[0360] In the embodiment of the present disclosure, the processor is a circuit with signal processing capability. In one implementation, the processor can be a circuit with instruction reading and execution capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP); in another implementation, the processor can implement certain functions through the logical relationship of the hardware circuit, and the logical relationship of the above hardware circuit is fixed or reconfigurable, such as a hardware circuit implemented by a processor as an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and implementing the hardware circuit configuration can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), etc.

[0361] Figure 9A is a schematic diagram of the structure of a communication device proposed in an embodiment of the present disclosure. Communication device 9100 can be a terminal, a network device, a chip, a chip system, or a processor that supports a terminal implementing any of the above methods, or a chip, a chip system, or a processor that supports a network device implementing any of the above methods. Communication device 9100 can be used to implement the methods described in the above method embodiments. For details, please refer to the description of the above method embodiments.

[0362] As shown in Figure 9A, the communication device 9100 includes one or more processors 9101. The processor 9101 can be a general-purpose processor or a dedicated processor, for example, a baseband processor or a central processing unit. The baseband processor can be used to process communication protocols and communication data, and the central processing unit can be used to control the communication device (such as a base station, a baseband chip, a terminal device, a terminal device chip, a DU or a CU, etc.), execute programs, and process program data. The communication device 9100 is used to perform any of the above methods.

[0363] In some embodiments, the communication device 9100 further includes one or more memories 9102 for storing instructions. Optionally, all or part of the memories 9102 may be located outside the communication device 9100.

[0364] In some embodiments, the communication device 9100 further includes one or more transceivers 9103. When the communication device 9100 includes one or more transceivers 9103, the transceiver 9103 performs at least one of the communication steps such as sending and / or receiving in the above method, and the processor 9101 performs the other steps.

[0365] In some embodiments, a transceiver may include a receiver and / or a transmitter. The receiver and transmitter may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, and transceiver circuit may be used interchangeably; the terms transmitter, transmitting unit, transmitter, and transmitting circuit may be used interchangeably; and the terms receiver, receiving unit, receiver, and receiving circuit may be used interchangeably.

[0366] In some embodiments, the communication device 9100 may include one or more interface circuits 9104. Optionally, the interface circuit 9104 is connected to the memory 9102. The interface circuit 9104 may be configured to receive signals from the memory 9102 or other devices, and may be configured to send signals to the memory 9102 or other devices. For example, the interface circuit 9104 may read instructions stored in the memory 9102 and send the instructions to the processor 9101.

[0367] The communication device 9100 described in the above embodiments may be a terminal, a network device, or a third entity, but the scope of the communication device 9100 described in the present disclosure is not limited thereto, and the structure of the communication device 9100 may not be limited by FIG. 9A . The communication device may be an independent device or may be part of a larger device. For example, the communication device may be: 1) an independent integrated circuit IC, or a chip, or a chip system or subsystem; (2) a collection of one or more ICs, optionally, the above IC collection may also include a storage component for storing data or programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, an intelligent terminal device, a cellular phone, a wireless device, a handheld device, a mobile unit, an in-vehicle device, a network device, a cloud device, an artificial intelligence device, etc.; (6) others, etc.

[0368] FIG9B is a schematic diagram of the structure of a chip proposed in an embodiment of the present disclosure. If the communication device 9100 can be a chip or a chip system, please refer to the schematic diagram of the structure of the chip 9200 shown in FIG9B , but the present disclosure is not limited thereto.

[0369] The chip 9200 includes one or more processors 9201 , and the chip 9200 is configured to execute any of the above methods.

[0370] In some embodiments, the chip 9200 further includes one or more interface circuits 9202. Optionally, the interface circuit 9202 is connected to the memory 9203. The interface circuit 9202 can be used to receive signals from the memory 9203 or other devices, and can be used to send signals to the memory 9203 or other devices. For example, the interface circuit 9202 can read instructions stored in the memory 9203 and send the instructions to the processor 9201.

[0371] In some embodiments, the interface circuit 9202 performs at least one of the communication steps such as sending and / or receiving in the above method, and the processor 9201 performs the other steps.

[0372] In some embodiments, terms such as interface circuit, interface, transceiver pin, and transceiver may be used interchangeably.

[0373] In some embodiments, the chip 9200 further includes one or more memories 9203 for storing instructions. Alternatively, all or part of the memories 9203 may be located outside the chip 9200.

[0374] The present disclosure also proposes a storage medium having instructions stored thereon, which, when executed on the communication device 9100, causes the communication device 9100 to execute any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but is not limited thereto and may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but is not limited thereto and may also be a temporary storage medium.

[0375] The present disclosure also provides a program product, which, when executed by the communication device 9100, enables the communication device 9100 to perform any of the above methods. Optionally, the program product is a computer program product.

[0376] The present disclosure also proposes a computer program, which, when executed on a computer, causes the computer to perform any one of the above methods.

[0377] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented using software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer programs. When the computer program is loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present disclosure are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer program can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer program can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media integrated therein. The available medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a high-density digital video disc (DVD)), or a semiconductor medium (eg, a solid state disk (SSD)).

[0378] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this disclosure.

[0379] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0380] The above description is merely a specific embodiment of the present disclosure, but the scope of protection of the present disclosure is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this disclosure should be included in the scope of protection of the present disclosure. Therefore, the scope of protection of the present disclosure should be based on the scope of protection of the claims.

Claims

1. A communication method, characterized in that: Executed by a first entity, the method includes: Receiving a first message sent by a terminal, wherein the first message is used to initiate an attachment process; A second message is sent to the terminal according to whether an authentication and key agreement AKA process needs to be performed and / or whether a feeder link between the first entity and the ground station is available.

2. The method according to claim 1, wherein The first message includes at least one of the following: Terminal information, wherein the terminal information is used to identify the terminal; First indication information, wherein the first indication information is used to indicate that the terminal has the capability of supporting storage and forwarding satellite service operations.

3. The method according to any one of claims 1 to 2, characterized in that If at least one of the following conditions is met, the AKA process must be executed: The first entity does not store the context information of the terminal; The first entity does not store the subscription data of the terminal; The first message is not integrity protected; The integrity check of the first message fails.

4. The method according to any one of claims 1 to 3, wherein The second message is a second message of the first type, wherein the second message of the first type is used to indicate that initiation of the attachment procedure is not allowed; The sending a second message to the terminal according to whether the AKA process needs to be executed and / or whether the feeder link between the first entity and the ground station is available includes: determining that an AKA process needs to be performed and that the feeder link is unavailable, and sending a second message of the first type to the terminal; The determining that the AKA process needs to be executed and the feeder link is unavailable, and sending the second message of the first type to the terminal includes: Determining that an AKA process needs to be performed, the feeder link is unavailable, the terminal has the capability of supporting storage and forwarding satellite service operations, and the first entity does not support storage and forwarding satellite service operations, sending a second message of the first type to the terminal.

5. The method according to claim 4, wherein The method further comprises: It is determined that the feeder link is unavailable, and the terminal information is stored.

6. The method according to any one of claims 4 to 5, characterized in that The second message of the first type includes at least one of the following: Fallback timing information, wherein the fallback timing information is used to trigger the terminal to send the first message again; Second indication information, wherein the second indication information is used to indicate the reason why initiation of the attachment process is not allowed.

7. The method according to claim 6, wherein The fallback timing information is related to coverage availability information and / or ephemeris information of a satellite to which the first entity belongs.

8. The method according to any one of claims 4 to 7, wherein: The method further comprises: receiving a first message resent by the terminal in response to the second message.

9. The method according to any one of claims 1 to 3, wherein: The second message is a second message of a second type, wherein the second message of the second type is used to request authentication of the terminal; The sending a second message to the terminal according to whether the AKA process needs to be executed and / or whether the feeder link between the first entity and the ground station is available includes: It is determined that the AKA process needs to be performed, and the first entity has obtained the authentication vector and / or subscription data of the terminal, and sends a second message of the second type to the terminal.

10. The method according to claims 1 to 9, characterized in that The first entity has obtained the authentication vector and / or subscription data of the terminal, wherein the manner in which the first entity obtains the authentication vector and / or subscription data of the terminal includes any one of the following: Obtaining stored authentication vector and / or subscription data of the terminal; Sending a third message to the Home Subscriber Server HSS through the second entity, and receiving the HSS response forwarded by the second entity The authentication vector and / or subscription data of the terminal sent in the third message.

11. The method according to any one of claims 1 to 3, wherein: The second message is a second message of a third type, wherein the second message of the third type is used to establish a security procedure; The sending of the second message to the terminal according to whether the AKA process needs to be performed and / or whether the feeder link between the first entity and the ground station is available includes any one of the following: Determining that there is no need to perform the AKA process, and sending the second message of the third type to the terminal; It is determined that an AKA process needs to be executed and the AKA process is successfully executed, and the second message of the third type is sent to the terminal.

12. The method according to any one of claims 2 to 11, wherein: The method further comprises: The first message includes the first indication information, determining whether the first entity supports store-and-forward satellite service operations; It is determined that the first entity supports the store-and-forward satellite service operation, and the terminal is allowed to use the store-and-forward satellite service operation.

13. The method according to claim 12, wherein: The determining that the first entity supports the store-and-forward satellite service operation and allowing the terminal to use the store-and-forward satellite service operation further includes: Determining that the first entity supports the store-and-forward satellite service operation, and determining, based on subscription data of the terminal, that the terminal is authorized to operate the store-and-forward satellite service; It is determined that the terminal is allowed to use the store-and-forward satellite service operation.

14. The method according to any one of claims 12 to 13, wherein: The method further comprises: A fourth message is sent to the terminal, wherein the fourth message is used to indicate acceptance of initiating an attach process, and the fourth message includes third indication information, and the third indication information is used to indicate permission to use a store and forward satellite service operation.

15. The method according to claim 14, wherein The method further comprises: The context information of the terminal is sent to the second entity.

16. The method according to any one of claims 1 to 15, wherein: The first entity is deployed on a satellite.

17. A communication method, characterized in that: Executed by a second entity, the method includes: Obtaining, according to the third message from the first entity, an authentication vector and / or subscription data of the terminal, wherein the authentication vector and / or subscription data are used for an attach procedure, and the terminal sending a first message to the first entity, wherein the first message is used to initiate the attach procedure; The context information of the terminal is stored.

18. The method according to claim 17, wherein The acquiring, according to the third message from the first entity, the authentication vector and / or subscription data of the terminal includes: receiving a third message sent by the first entity, and sending the third message to a home subscriber server HSS; receiving an authentication vector and / or subscription data of the terminal sent by the HSS in response to the third message; Sending the authentication vector and / or subscription data of the terminal to the first entity.

19. The method according to any one of claims 17 to 18, wherein: The method further comprises: Receive context information of the terminal sent by the first entity.

20. The method according to any one of claims 17 to 19, wherein: The method further comprises: The information of the first entity and / or the terminal information of the terminal is stored.

21. The method according to any one of claims 17 to 20, wherein: The method further comprises: Sending information of the second entity to a third entity, wherein the information of the second entity is used to establish a session of the terminal; and / or Receive information about the third entity, and send the information about the third entity to the first entity, wherein the information about the third entity is used to establish a session of the terminal.

22. The method according to any one of claims 17 to 21, wherein: The second entity is deployed on the ground.

23. A communication method, characterized in that: Executed by a third entity, the method includes: A session of the terminal is established according to the information of the second entity and / or the information of the third entity, wherein the terminal sends a first message to the first entity, where the first message is used to initiate an attachment process.

24. The method according to claim 23, wherein The method further comprises: receiving information of the second entity sent by the second entity; and / or The information of the third entity is sent to the second entity.

25. The method according to any one of claims 23 to 24, wherein: The method further comprises: A session management context of the terminal is generated, wherein the session management context of the terminal includes at least one of the following: information of the second entity; terminal information; and information of the third entity.

26. A communication method, characterized in that: The method comprises: The first entity receives the first message sent by the terminal, and sends a second message to the terminal according to whether an authentication and key agreement AKA process needs to be performed and / or whether a feeder link between the first entity and the ground station is available, wherein the first message is used to initiate an attachment process; The second entity obtains, according to the third message from the first entity, an authentication vector and / or subscription data of the terminal, and stores context information of the terminal, wherein the authentication vector and / or subscription data are used for an attachment process; The third entity establishes a session of the terminal according to the information of the second entity and / or the information of the third entity.

27. A first entity, characterized in that The first entity includes: A transceiver module is used to receive a first message sent by a terminal, wherein the first message is used to initiate an attachment process, and send a second message to the terminal based on whether an authentication and key agreement AKA process needs to be performed and / or whether the feeder link between the first entity and the ground station is available.

28. A second entity, characterized in that: The second entity includes: A transceiver module is used to obtain the authentication vector and / or contract data of the terminal based on the third message of the first entity, wherein the authentication vector and / or contract data are used for the attachment process, and the terminal sends a first message to the first entity, the first message is used to initiate the attachment process, and store the context information of the terminal.

29. A third entity, characterized in that: The third entity includes: The processing module is configured to establish a session of the terminal according to the information of the second entity and / or the information of the third entity, wherein the terminal sends a first message to the first entity, and the first message is used to initiate an attachment process.

30. A communication device, characterized in that: include: one or more processors; The processor is configured to execute the communication method according to any one of claims 1 to 26.

31. A storage medium storing instructions, characterized in that: When the instruction is executed on a communication device, the communication device is caused to execute the communication method according to any one of claims 1 to 26.

32. A communication system, characterized in that: The method comprises a first entity, a second entity and a third entity, wherein the first entity is used to execute the communication method according to any one of claims 1 to 16, the second entity is used to execute the communication method according to any one of claims 17 to 22, and the third entity is used to execute the communication method according to any one of claims 23 to 25.

Citation Information

Patent Citations

  • Secret key processing method for switching between different mobile access systems

    CN101102600A

  • Network operator-neutral provisioning of mobile devices

    US20130157673A1

  • Registration pending state

    WO2023229793A1