Information storage method, device, and system
By performing authorization verification in satellite communications, the problem of malicious occupation of satellite storage space is solved, ensuring the security of data transmission and service quality.
Patent Information
- Application Number
- PCT/CN2025/070799
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-08
- Filing Date
- 2025-01-06
- Publication Date
- 2025-08-14
AI Technical Summary
In satellite communication, when a satellite cannot communicate with terminal equipment and ground stations at the same time, malicious terminal equipment or ground stations may occupy satellite storage space, resulting in a degradation in the quality of service for storing and forwarding data and the data source is unsafe.
By performing authorization verification before the satellite receives data, a storage and forwarding service is provided only when the verification is passed, and authorization information is sent during downlink communication to ensure that the terminal device parses the data, and access control and data security of the storage and forwarding service are realized.
It ensures the effective utilization of satellite storage space, improves the quality of storage and forwarding services and data security, and avoids the transmission of false or malicious data.
Smart Images

Figure CN2025070799_14082025_PF_FP_ABST
Abstract
Description
Information storage method, device and system
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on February 8, 2024, with application number 202410179368.2 and application name “Information Storage Method, Device and System”, all contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of communication technology, and in particular to an information storage method, device, and system. Background Art
[0003] With the development of communication technology, terrestrial communication technology has become highly advanced, enabling communication signals to cover most areas on the ground. However, in some areas, such as deserts, oceans, and remote areas, communication networks are still not available due to economic or environmental factors. To support wider communication signal coverage, base stations and even user and control plane network elements can be deployed on satellites.
[0004] In some satellite communication application scenarios, the satellite cannot simultaneously communicate with user-end devices (such as terminal devices) and ground-end devices (such as ground stations). In these cases, the satellite can provide a store-and-forward data service for the terminal devices and ground stations. For example, when the satellite is connected to the terminal device but not to the ground station, the satellite stores the uplink data from the terminal device and then forwards the stored uplink data to the ground station after a connection is established with the ground station. Alternatively, when the satellite is connected to the ground station but not to the terminal device, the satellite stores the downlink data from the ground station and then forwards the stored downlink data to the terminal device after a connection is established with the terminal device.
[0005] In this case, some malicious terminal devices or ground stations may send a large amount of information to the satellite, occupying the satellite's storage space and causing a decline in the service quality of the satellite's storage and forwarding data. Summary of the Invention
[0006] The present application provides an information storage method, device, and system, which help to ensure the service quality of satellite storage and forwarding data.
[0007] To achieve the above objectives, this application adopts the following technical solutions:
[0008] In a first aspect, a method for storing information is provided, which is applied to a first communication device, and the method includes: receiving first data and first authorization information from a terminal device, wherein the first data is data sent by the terminal device to a first network element; and storing the first data when verification of the first authorization information is passed.
[0009] Illustratively, in a satellite communication scenario, the first communication device may be a satellite or a module or unit on a satellite for providing storage and forwarding service authorization verification and data storage services, without limitation.
[0010] In the solution provided by the first aspect above, the first communication device performs authorization verification when receiving uplink data. The first communication device will provide storage and forwarding services to the terminal equipment only when the authorization information verification is passed. Based on this, access control of the storage and forwarding service can be implemented, ensuring the effective use of the storage space of the first communication device, which helps to ensure the quality of the storage and forwarding service provided by the first communication device; in addition, through authorization verification to ensure the security of the data source, it can avoid the terminal equipment from sending false data or malicious data, thereby improving the security of the first communication device or the ground station network element.
[0011] As one possible implementation, the first authorization information includes an authorization token, and the method further includes: verifying the authorization token based on verification information corresponding to the authorization token. This solution can support multiple authorization verification methods, such as authorization token-based verification, and has strong applicability and compatibility and is easy to implement.
[0012] Exemplarily, the verification information may include, but is not limited to, an operator's signature verification certificate or a signature verification public key, etc., without limitation.
[0013] As one possible implementation, the first authorization information includes a first password, and the method further includes: obtaining a password set, where the password set includes one or more passwords; and determining that verification of the first authorization information is successful if the password set includes the first password. Alternatively, the first authorization information includes a first verification code, and the method further includes: obtaining a verification code set, where the verification code set includes one or more verification codes; and determining that verification of the first authorization information is successful if the verification code set includes the first verification code. This solution can support multiple methods of authorization verification, such as password / verification code-based verification, and has strong applicability and compatibility, as well as ease of implementation.
[0014] Exemplarily, when the password set includes the first password, the first communication device stores the first data; when the password set does not include the first password, the first communication device does not store the first data; or, when the verification code set includes the first verification code, the first communication device stores the first data; when the verification code set does not include the first verification code, the first communication device does not store the first data.
[0015] As a possible implementation, the method further includes: receiving first authorization information from the second network element; and sending the first authorization information to the terminal device. The first communication device sends the first authorization information from the second network element to the terminal device, so that the terminal device uses a high-quality store-and-forward data service based on the first authorization information.
[0016] As a possible implementation, before receiving the first authorization information from the second network element, the method further includes: sending a first request message to the second network element, wherein the first request message includes an identifier of the terminal device and first information, the first information being used to indicate any of the following verification methods: authorization token-based verification, password-based verification, or verification code-based verification, wherein the first request message is used to subscribe the terminal device to a store-and-forward service or to request that the terminal device be registered with the network where the second network element is located. Based on this, the first communication device provides the first information indicating the verification method to the second network element, so that the first authorization information matches the verification method, which helps to improve the success rate of authorization verification.
[0017] Illustratively, the first request message, such as a registration request message or an attach request message, reuses an existing registration process to implement subscription to a store-and-forward service, which can reduce signaling overhead and save network transmission resources.
[0018] As one possible implementation, the first authorization information includes a first threshold, and the method further includes: determining that verification of the first authorization information has succeeded when the amount of stored data from the terminal device is less than the first threshold. This further ensures efficient use of storage space in the first communication device, thereby guaranteeing quality of service for storing and forwarding data.
[0019] As a possible implementation, the method further includes: sending the stored first data to the first network element. Based on this, the store-and-forward service can be successfully completed, the uplink data can be smoothly forwarded, and the normal and smooth operation of the business can be ensured.
[0020] As a possible implementation, the method further includes: receiving a third request message from the first network element, where the third request message includes the second data and an identifier of the terminal device; determining second authorization information based on the identifier of the terminal device; and sending the second data and the second authorization information to the terminal device, where the second authorization information is used to verify the second data. This ensures reliable authorization verification in downlink communication scenarios and improves the security of downlink data received by the terminal device.
[0021] As a possible implementation, the method further includes: sending a fourth request message to a third network element, the fourth request message being used to subscribe the first communication device to a store-and-forward service; and receiving second authorization information from the third network element. This allows for smooth implementation of authorized subscription to the store-and-forward service, ensuring reliable authorization verification in downlink communication scenarios and improving the security of downlink data received by the terminal device.
[0022] Optionally, as a possible implementation, the fourth request message includes a service scope of the first communication device, where the service scope of the first communication device includes identifiers of one or more terminal devices, where the one or more terminal devices include the terminal device described above. This is used by the third network element to generate authorization information for certain specific terminal devices, further improving the security of the terminal devices.
[0023] Optionally, as a possible implementation, the service scope of the first communication device also includes one or more of the following: one or more slice identifiers, one or more service country identifiers, and one or more service area identifiers. This is used by the third network element to generate authorization information for certain specific slices, service countries, and service areas, further improving the security of the terminal device.
[0024] In a second aspect, a method for storing information is provided, which is applied to a first communication device, and the method includes: receiving a third request message from a first network element, wherein the third request message includes second data and an identifier of a terminal device; determining second authorization information based on the identifier of the terminal device; and sending the second data and the second authorization information to the terminal device, wherein the second authorization information is used to verify the second data.
[0025] In the solution provided by the second aspect above, the first communication device sends authorization information and downlink data to the terminal device after receiving the downlink data, so that the terminal device can verify the authorization information and parse the downlink data only when the authorization information verification is passed. This can ensure the reliable implementation of authorization verification in the downlink communication scenario and improve the security of the terminal device receiving downlink data.
[0026] As a possible implementation, the method further includes: sending a fourth request message to a third network element, the fourth request message being used to subscribe the first communication device to a store-and-forward service; and receiving second authorization information from the third network element. Based on this, authorized subscription to the store-and-forward service can be successfully implemented, ensuring reliable authorization verification in downlink communication scenarios and improving the security of downlink data received by terminal devices. Furthermore, by sending the first communication device's service scope to the third network element, the first communication device can obtain authorization information applicable to a specific service scope, thereby improving the service quality of the store-and-forward data and the security of communications.
[0027] Optionally, as a possible implementation, the fourth request message includes a service scope of the first communication device, where the service scope of the first communication device includes identifiers of one or more terminal devices, where the one or more terminal devices include the terminal device described above. This is used by the third network element to generate authorization information for certain specific terminal devices, further improving the security of the terminal devices.
[0028] Optionally, as a possible implementation, the service scope of the first communication device also includes one or more of the following: one or more slice identifiers, one or more service country identifiers, and one or more service area identifiers. This is used by the third network element to generate authorization information for certain specific slices, service countries, and service areas, further improving the security of the terminal device.
[0029] As a possible implementation, the fourth request message includes first information indicating any one of the following authentication methods: authentication based on an authorization token, authentication based on a password, or authentication based on a verification code. Based on this, the first communications device provides the first information indicating the authentication method to the third network element, so that the second authorization information matches the authentication method, thereby improving the success rate of the authorization authentication.
[0030] In a third aspect, a method for storing information is provided. The method can be executed by a terminal device, or by a chip or circuit of the terminal device, and this application is not limited thereto. The method includes: sending first data and first authorization information to a first communication device, wherein the first data is data sent by the terminal device to a first network element, and the first authorization information is used to determine whether to store the first data; and receiving a first response message from the first communication device, wherein the first response message is used to indicate whether the first data was successfully stored.
[0031] In the solution provided by the third aspect above, the terminal device sends authorization information to the first communication device (such as a satellite) for authorization verification by the first communication device, thereby implementing access control of the storage and forwarding service, ensuring the effective use of the storage space of the first communication device, and helping to ensure the quality of the storage and forwarding service provided by the first communication device; in addition, by ensuring the security of the data source through authorization verification, the terminal device can be prevented from sending false or malicious data, thereby improving the security of the first communication device or the ground station network element.
[0032] As a possible implementation, the method further includes: sending a second request message to a second communication device, wherein the second request message includes an identifier of the terminal device and information indicating an authentication method supported by the terminal device, the authentication method including any of the following: authentication based on an authorization token, authentication based on a password, or authentication based on a verification code, and the second request message is used to subscribe the terminal device to a store-and-forward service or to request that the terminal device be registered with the network where the first network element is located; and receiving first authorization information from the second communication device. Based on this, the terminal device provides the first information indicating the authentication method to the second communication device, so that the first authorization information matches the authentication method, thereby helping to improve the success rate of the authorization authentication.
[0033] As a possible implementation, the second request message also includes a second threshold, and the second request message further requests that the terminal device's maximum data storage capacity be the second threshold. Based on this, by subscribing to the maximum data storage capacity, it is possible to ensure that the first communication device subsequently verifies the maximum storage capacity, further ensuring the efficient use of the first communication device's storage space, and thus ensuring the quality of service for storing and forwarding data.
[0034] As a possible implementation, the method further includes: receiving second data and second authorization information from a third communication device; and parsing the second data if verification of the second authorization information is successful. This can improve the security of downlink data received by the terminal device.
[0035] As a possible implementation, the second authorization information includes an authorization token, and the method further includes: verifying the authorization token according to verification information corresponding to the authorization token. This solution can support verification based on authorization tokens, has strong applicability and compatibility, and is easy to implement.
[0036] In a fourth aspect, a method for storing information is provided. This method can be executed by a terminal device, or by a chip or circuit in the terminal device, although this application is not limited thereto. The method includes: receiving second data and second authorization information from a third communication device; and parsing the second data if verification of the second authorization information is successful.
[0037] The solution provided in the fourth aspect above can improve the security of the terminal device receiving downlink data and enhance the user experience by enabling the terminal device to perform authorization verification in a downlink communication scenario.
[0038] As a possible implementation, the second authorization information includes an authorization token, and the method further includes: verifying the authorization token according to verification information corresponding to the authorization token. This solution can support verification based on authorization tokens, has strong applicability and compatibility, and is easy to implement.
[0039] As a possible implementation, the method further includes: sending a second request message to a second communication device, wherein the second request message includes an identifier of the terminal device and information indicating an authentication method supported by the terminal device, the authentication method including any of the following: authorization token-based authentication, password-based authentication, or verification code-based authentication, and the second request message is used to subscribe the terminal device to a store-and-forward service. Therefore, by providing the second communication device with information indicating the authentication method, the second authorization information matches the authentication method, thereby improving the success rate of authorization authentication.
[0040] In a fifth aspect, a method for storing information is provided. The method can be executed by a first network element, or by a chip or circuit of the first network element, and this application does not limit this. The method includes: receiving a first request message from a first communication device, wherein the first request message includes an identifier of a terminal device; and sending first authorization information to one or more second communication devices based on the identifier of the terminal device, wherein the first authorization information is used to determine whether to store data from the terminal device.
[0041] The solution provided in the fifth aspect above is that the first network element provides authorization information to the communication device based on the request to subscribe to the storage and forwarding service, which can support the communication device to perform authorization verification in the uplink communication scenario, ensure the effective use of the storage space of the communication device, and help to ensure the quality of the storage and forwarding service provided by the communication device; in addition, through authorization verification to ensure the security of the data source, it can avoid the terminal device from sending false data or malicious data, and improve the security of the communication device or ground station network element.
[0042] As one possible implementation, the first authorization information includes an authorization token, and the sending of the first authorization information to one or more second communication devices based on the terminal device's identifier includes sending the first authorization information to one second communication device based on the terminal device's identifier and ephemeris. This solution supports multiple authorization verification methods, such as authentication based on authorization tokens, and has strong applicability and compatibility, as well as ease of implementation. Furthermore, determining which communication device(s) to send the authorization information to based on ephemeris reduces signaling overhead and conserves network transmission resources.
[0043] As a possible implementation, the first authorization information includes a first password, and the sending of the first authorization information to one or more second communication devices based on the terminal device's identifier includes sending the first password to multiple second communication devices based on the terminal device's identifier. This solution can support multiple methods of authorization verification, such as password-based verification, and has strong applicability and compatibility, as well as ease of implementation. In addition, by sending the first password to multiple second communication devices, it is possible to ensure that the multiple second communication devices can update their password sets in a timely manner, thereby ensuring reliable and smooth authorization verification during subsequent communications.
[0044] As a possible implementation, the first authorization information includes a first verification code, and the sending of the first authorization information to one or more second communication devices based on the terminal device's identifier includes: sending the first verification code to multiple second communication devices based on the terminal device's identifier. This solution can support multiple methods of authorization verification, such as verification code-based verification, and has strong applicability and compatibility and is easy to implement. In addition, by sending the first verification code to multiple second communication devices, it can be ensured that the multiple second communication devices can update the verification code set in a timely manner, ensuring that the authorization verification is reliable and smooth during subsequent communications.
[0045] As a possible implementation, the method further includes: sending a fifth request message to a fourth network element, wherein the fifth request message includes an identifier of the terminal device and is used to subscribe the terminal device to the store-and-forward service; and receiving first authorization information from the fourth network element. Based on this, reliable implementation of the store-and-forward service subscription can be ensured.
[0046] As a possible implementation, the fifth request message further includes first information indicating any one of the following authentication methods: authorization token-based authentication, password-based authentication, or verification code-based authentication. This solution can thus support multiple authorization authentication methods, is highly adaptable and compatible, and is easy to implement.
[0047] As a possible implementation, the fifth request message also includes a second threshold value, and the fifth request message further requests that the maximum data storage capacity of the terminal device be the second threshold value. Based on this, by subscribing to the maximum data storage capacity, it is possible to ensure that the first communication device subsequently verifies the maximum storage capacity, further ensuring the efficient use of the storage space of the first communication device, and thus ensuring the quality of service for storing and forwarding data.
[0048] As a possible implementation, the method further includes: determining the first authorization information based on the contract information of the terminal device. Based on this, the authorization result can be guaranteed to match the user's contract information while ensuring smooth subscription of the store-and-forward service.
[0049] As one possible implementation, the contract information includes a second verification method subscribed to by the terminal device, where the second verification method includes any of the following: authorization token-based verification, password-based verification, and verification code-based verification. Determining the first authorization information based on the contract information includes determining the first authorization information based on the second verification method. This ensures that the authorization result matches the user's contract information, helping to improve the success rate of authorization verification.
[0050] As a possible implementation, the first authorization information also includes a first threshold, which represents the maximum storage capacity of data on the terminal device. This ensures that the first communication device can subsequently verify the maximum storage capacity, further ensuring efficient use of the storage space on the first communication device and, consequently, ensuring the quality of service for storing and forwarding data.
[0051] As one possible implementation, the contract information includes a third threshold value for the terminal device's subscription, where the third threshold value is the maximum storage capacity of the data subscribed to by the terminal device. Determining the first authorization information based on the contract information includes: determining the first authorization information based on the third threshold value, where the first authorization information includes the first threshold value, and the first threshold value is the same as the third threshold value. This ensures that the authorization result matches the user's contract information, thereby improving the success rate of authorization verification.
[0052] In a sixth aspect, a communication device is provided, comprising: a memory for storing computer program instructions; and a processor for executing the computer program instructions to support the communication device in implementing a method in any possible implementation manner of the first aspect, the second aspect, the third aspect, the fourth aspect, or the fifth aspect.
[0053] In the seventh aspect, a communication device is provided, which includes: a unit or module for executing a method as in any possible implementation of the first aspect or the second aspect, or includes a unit or module for executing a method as in any possible implementation of the third aspect or the fourth aspect, or includes a unit or module for executing a method as in any possible implementation of the fifth aspect.
[0054] In an eighth aspect, a communication system is provided, which includes a unit or module for executing a method as in any possible implementation of the first aspect or the second aspect, and a unit or module for executing a method as in any possible implementation of the fifth aspect.
[0055] As a possible implementation manner, the above-mentioned communication system also includes a unit or module for executing the method in any possible implementation manner of the third aspect or the fourth aspect.
[0056] In the ninth aspect, a computer-readable storage medium is provided, on which computer program instructions are stored. When the computer program instructions are executed by a processor, the method in any possible implementation of the first aspect, the second aspect, the third aspect, the fourth aspect or the fifth aspect is implemented.
[0057] In the tenth aspect, a computer program product comprising instructions is provided, which, when run on a computer, enables the computer to implement a method in any possible implementation of the first, second, third, fourth or fifth aspects.
[0058] In an eleventh aspect, a chip system is provided, comprising a processing circuit and a storage medium storing computer program instructions; when the computer program instructions are executed by the processor, the method of any possible implementation of the first, second, third, fourth, or fifth aspects is implemented. The chip system may be composed of a chip alone or may include a chip and other discrete components. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] FIG1 is a schematic diagram of a satellite communication process;
[0060] FIG2 is a schematic diagram of a process of providing a store-and-forward service for uplink communication by a satellite;
[0061] FIG3 is a schematic diagram of a process of providing a store-and-forward service for downlink communication by a satellite;
[0062] FIG4 is a schematic diagram of a storage and forwarding service architecture according to an embodiment of the present application;
[0063] FIG5 is a second schematic diagram of a storage and forwarding service architecture provided in an embodiment of the present application;
[0064] FIG6 is a third schematic diagram of a storage and forwarding service architecture provided in an embodiment of the present application;
[0065] FIG7 is a fourth schematic diagram of a storage and forwarding service architecture provided in an embodiment of the present application;
[0066] FIG8 is a flow chart of a method for storing information in an uplink satellite communication scenario provided by an embodiment of the present application;
[0067] FIG9 is a flow chart of another method for storing information in an uplink satellite communication scenario provided by an embodiment of the present application;
[0068] FIG10 is a flow chart of a method for storing information in a downlink satellite communication scenario provided by an embodiment of the present application;
[0069] FIG11 is a flow chart of another method for storing information in a downlink satellite communication scenario provided by an embodiment of the present application;
[0070] FIG12 is an interactive diagram 1 of an implementation process of a method for storing information in an uplink satellite communication scenario provided by an embodiment of the present application;
[0071] FIG13 is a second interactive diagram of the implementation process of the information storage method in the uplink satellite communication scenario provided by an embodiment of the present application;
[0072] FIG14 is an interactive diagram 3 of the implementation process of the information storage method in the uplink satellite communication scenario provided by an embodiment of the present application;
[0073] FIG15 is an interactive diagram 4 of the implementation process of the information storage method in the uplink satellite communication scenario provided by an embodiment of the present application;
[0074] FIG16 is an interaction diagram of an implementation process of a method for storing information in a downlink satellite communication scenario provided by an embodiment of the present application;
[0075] FIG17 is an interactive diagram 5 during implementation of the information storage method in an uplink satellite communication scenario provided by an embodiment of the present application;
[0076] FIG18 is a schematic diagram of the hardware structure of a communication device provided in an embodiment of the present application;
[0077] FIG19 is a schematic diagram of the structure of a communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0078] The technical solutions in the embodiments of the present application will be described below in conjunction with the accompanying drawings in the embodiments of the present application. In the description of the embodiments of the present application, unless otherwise specified, " / " means or, for example, A / B can mean A or B; "and / or" in this article is merely a description of the association relationship of associated objects, indicating that three relationships can exist, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, in the description of the embodiments of the present application, "multiple" means two or more than two.
[0079] In the following, the terms "first," "second," and so on are used solely to distinguish different descriptive objects and do not limit the position, order, priority, quantity, or content of the described objects. For example, if the described object is a "field," the ordinal number preceding the "field" in "first field" and "second field" does not limit the position or order of the "fields." "First" and "second" do not limit whether the modified "fields" are in the same message, nor do they restrict the order of the "first field" and "second field." For another example, if the described object is a "level," the ordinal number preceding the "level" in "first level" and "second level" does not limit the priority of the "levels." For another example, the number of described objects is not limited by the ordinal number and can be one or more. For example, in the case of "first device," the number of "devices" can be one or more. Furthermore, the objects modified by different prefixes can be the same or different. For example, if the described object is a "device," the "first device" and "second device" can be devices of the same type or different types. For another example, if the described object is "information," the "first information" and "second information" can be information of the same content or different contents. In short, the use of prefixes such as ordinal numbers to distinguish the described objects in the embodiments of the present application does not constitute a restriction on the described objects. For the statement of the described objects, please refer to the description in the context of the claims or embodiments, and no unnecessary restrictions should be constituted due to the use of such prefixes.
[0080] Furthermore, in the embodiments of the present application, "connection" may be a direct connection or an indirect connection; in addition, it may refer to an electrical connection or a communication connection; for example, the connection between two electrical components A and B may refer to a direct connection between A and B, or it may refer to an indirect connection between A and B through other electrical components or connection media, or it may refer to an indirect connection between A and B through other communication devices or communication media, as long as communication between A and B can be achieved.
[0081] As described in the background technology, in some satellite communication application scenarios, the satellite may not be able to communicate with the terminal device and the ground station at the same time. Taking Figure 1 as an example, at time T1, the satellite can communicate with the terminal device but cannot communicate with the ground station, so the satellite cannot send the uplink data from the terminal device to the ground station in time; as the satellite moves, at time T2, the satellite cannot communicate with the terminal device but can communicate with the ground station, so the satellite cannot send the downlink data from the ground station to the terminal device in time. In this scenario, the satellite can store the uplink data from the terminal device at time T1 and forward the stored uplink data when it connects with the ground station at time T2; similarly, when the ground station has downlink data to send to the terminal device, the satellite can also store the downlink data from the ground station and forward the stored downlink data when it connects with the terminal device. This service provided by the satellite is called a store and forward data service (hereinafter referred to as "store and forward service").
[0082] As an example, please refer to Figure 2, which shows a schematic diagram of a process of providing a store-and-forward service when a satellite provides uplink communication. As shown in Figure 2, the store-and-forward service provided by the satellite during uplink communication can be implemented based on S201-S204:
[0083] S201: The terminal device accesses the satellite (SAT).
[0084] As an example, the terminal device may also determine that the satellite supports a store-and-forward service function.
[0085] As an example, a satellite can carry information in a broadcast message indicating that it supports the store-and-forward service function, such as a store-and-forward indicator, etc., without limitation; when a terminal device scans a broadcast message from a satellite, it can determine whether the satellite supports the store-and-forward service function based on the broadcast message. In this example, the satellite supporting the store-and-forward service function is used as an example.
[0086] S202: The terminal device sends a store-and-forward service request to the satellite, where the store-and-forward service request includes uplink data (the first data shown in FIG2 ).
[0087] As an example, the store-and-forward service request includes identification information of the terminal device, such as but not limited to the international mobile subscriber identity (IMSI), the subscription permanent identifier (SUPI), the terminal device temporary identifier, etc., without specific limitation.
[0088] As a possible implementation manner, the terminal device can send a store-and-forward service request to the satellite through a non-access stratum (NAS) message, including but not limited to directly sending the NAS message to the satellite or encapsulating the NAS message into a new message and then sending it to the satellite, without specific limitation.
[0089] S203: The satellite stores the first data.
[0090] S204: The satellite sends a store-and-forward service response to the terminal device.
[0091] As an example, the store-and-forward service response is used to notify the terminal device that the first data has been successfully stored. Afterwards, after the satellite establishes a connection with the ground station network element corresponding to the destination address of the first data, the satellite can send the stored first data from the terminal device to the ground station network element.
[0092] As an example, please refer to Figure 3, which shows a schematic diagram of a process of providing a store-and-forward service when a satellite provides downlink communication. As shown in Figure 3, the process of providing a store-and-forward service when a satellite provides downlink communication can be implemented based on S301-S304:
[0093] S301: After establishing communication with a ground station network element, the satellite receives a store-and-forward service request from the ground station network element. The store-and-forward service request includes downlink data (the second data shown in FIG3 ).
[0094] As an example, the store-and-forward service request includes identification information of the terminal device, such as but not limited to IMSI, SUPI, temporary identification of the terminal device, etc., which is not specifically limited.
[0095] As a possible implementation method, the ground station network element can send a store-and-forward service request to the satellite via a NAS message, including but not limited to directly sending the NAS message to the satellite or encapsulating the NAS message into a new message and then sending it to the satellite, without specific limitation.
[0096] S302: The satellite stores the second data.
[0097] S303: The satellite establishes a connection with the terminal device.
[0098] S304: The satellite sends the stored second data from the ground station network element to the terminal device.
[0099] As shown in Figures 2 and 3, when the satellites provide store-and-forward services, they store data sent by any terminal device or ground station network element that initiates a store-and-forward request. In this scenario, malicious terminal devices or ground stations could potentially send large amounts of information to the satellite, occupying its storage space. For satellites with limited storage capacity, preventing this excessive storage space from impacting the quality of the satellite's store-and-forward data service is crucial.
[0100] In order to ensure the quality of the storage and forwarding service provided by the satellite and the security of the communication process, an embodiment of the present application provides an information storage method. This method can implement subscription authorization and authorization verification of the storage and forwarding service. In an uplink satellite communication scenario where the satellite cannot communicate with the terminal device and the ground station network element at the same time, the method can implement access control of the storage and forwarding service by performing authorization verification when receiving uplink data and providing the terminal device with storage and forwarding service when the authorization information verification is passed. This ensures the effective use of the satellite's storage space, the quality of the storage and forwarding service provided by the satellite, the security of the data source, and avoids the terminal device from sending false or malicious data, thereby improving the security of the satellite or ground station network element; and, in a downlink satellite communication scenario, the method can implement reliable implementation of authorization verification in the downlink communication scenario and improve the security of the terminal device receiving downlink data by sending authorization information and downlink data to the terminal device.
[0101] As an example, a terminal device can subscribe to the satellite's uplink store-and-forward service from a ground station, and the ground station network element can provide the terminal device with authorization credentials, such as an authorization token, authorization password, or authorization verification code. Based on this, in an uplink satellite communication scenario, the satellite can verify the authorization credentials sent by the terminal device and provide the store-and-forward service to the terminal device if the verification is successful. Alternatively, in a downlink satellite communication scenario, the satellite can send authorization information (i.e., authorization credentials) to the terminal device when forwarding downlink data, and the terminal device can parse the downlink data forwarded by the satellite if the authorization information is verified.
[0102] The information storage method provided in the embodiment of the present application can be applied to, but not limited to, a communication system architecture that can provide a store-and-forward service, including but not limited to a long term evolution (LTE) system, a new radio (NR) system, a wireless fidelity (WiFi) system, a third generation partnership project (3GPP)-related communication system, a future communication network, or a system integrating multiple systems, etc., without limitation. Among them, the LTE system can also be called a 4G communication system, and the NR system can also be called a 5G communication system.
[0103] As an example, please refer to Figure 4, which uses a 4G communication system as an example to illustrate a schematic diagram of a store-and-forward service architecture provided by an embodiment of the present application. As shown in Figure 4, the store-and-forward service architecture may include a terminal device, a satellite, a ground station, a mobility management entity (MME), and a home subscriber server (HSS).
[0104] Among them, a terminal device is a device with wireless transceiver capabilities. The terminal device can be deployed on land, including indoors, outdoors, handheld or vehicle-mounted; it can also be deployed on the water (such as ships, etc.); it can also be deployed in the air (such as airplanes, balloons and satellites, etc.). The terminal device may include, but is not limited to, a user terminal (UE), a mobile station (MS), a mobile terminal (MT), etc., or a device used to provide voice or data connectivity to users. For example, the UE includes a handheld device with wireless communication capabilities, a vehicle-mounted device (such as a car, bicycle, electric vehicle, airplane, ship, train, high-speed rail, etc.), a wearable device (such as a smart watch, smart bracelet, pedometer, etc.), or a computing device. Exemplarily, the UE can be a mobile phone, a tablet computer, a laptop computer, a PDA, a mobile internet device (MID), a satellite terminal, or a computer with wireless transceiver capabilities. A UE may also be a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless modem, a smart point of sale (POS) machine, customer-premises equipment (CPE), an intelligent robot, a robotic arm, workshop equipment, smart home devices (e.g., refrigerators, televisions, air conditioners, electric meters, etc.), a wireless terminal in industrial control, a wireless terminal in unmanned driving, a wireless terminal in telemedicine, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, an in-vehicle terminal, a roadside unit (RSU) with terminal functions, or an aerial device (e.g., an intelligent robot, a hot air balloon, a drone, an airplane), etc. A UE may also be other devices with terminal functions, for example, a UE may also be a device that functions as a terminal in device-to-device (D2D) communication.
[0105] As an example and not a limitation, in this application, the terminal device may be a wearable device. Wearable devices may also be referred to as wearable smart devices, which are a general term for wearable devices that are intelligently designed and developed using wearable technology for daily wear, such as glasses, gloves, watches, clothing, and shoes. A wearable device is a portable device that is worn directly on the body or integrated into the user's clothes or accessories. For example, a wearable device is not only a hardware device, but also a device that achieves powerful functions through software support, data interaction, and cloud interaction. In a broad sense, wearable smart devices include devices that are fully functional, large in size, and can achieve complete or partial functions without relying on smartphones, such as smart watches or smart glasses, as well as devices that focus on a certain type of application function and need to be used in conjunction with other devices such as smartphones, such as various smart bracelets and smart jewelry for vital sign monitoring.
[0106] In the present application, the terminal device may be a terminal in an Internet of Things (IoT) system. IoT is an important component of the future development of information technology. Its main technical feature is to connect objects to the network through communication technology, thereby realizing an intelligent network of human-machine interconnection and object-to-object interconnection. The terminal device in the present application may be a terminal in machine type communication (MTC). The terminal device of the present application may be an on-board module, on-board module, on-board component, on-board chip or on-board unit built into a vehicle as one or more components or units. The vehicle may implement the method of the present application through the built-in on-board module, on-board module, on-board component, on-board chip or on-board unit. The terminal device of the present application may be a vehicle, such as a car. Therefore, the present application can be applied to Internet of Vehicles, such as vehicle to everything (V2X), long term evolution vehicle (LTE-V), vehicle to vehicle (V2V), etc.
[0107] The embodiments of the present application do not impose any specific limitations on the specific structure, type, and function of the terminal device.
[0108] Satellites can be divided into the following four categories based on the altitude of their orbits: low earth orbit (LEO) satellites, whose orbital altitude is 500km to 2000km; medium earth orbit (MEO) satellites, whose orbital altitude is 2000km to 20000km; high earth orbit (HEO) satellites, whose orbit is an elliptical orbit with an altitude greater than 20000km; geostationary earth orbit (GEO) satellites, whose orbital altitude is 35800km.
[0109] As shown in FIG4 , the satellite includes a base station (such as a 4G base station, also called an LTE base station) and a store-and-forward service module (S&F function).
[0110] The base station is shown in Figure 4 as eNB (E-UTRAN NodeB), the evolved base station (next generation eNB, ng-eNB) in the next generation LTE, etc. As an example, the base station is used to provide wireless access services for terminal devices. For example, the base station corresponds to a service coverage area, and the terminal device entering the area can communicate with the base station through the air interface to receive the wireless access service provided by the base station. The terminal device and the base station can communicate through the air interface link. Among them, the air interface link can be divided into uplink (uplink, UL) and downlink (downlink, DL) according to the direction of the data transmitted thereon. Uplink data sent from the terminal device to the base station can be transmitted on the UL, and downlink data transmitted from the base station to the terminal device can be transmitted on the DL.
[0111] The store-and-forward service module is used to provide store-and-forward services, including storing uplink data from terminal devices and forwarding uplink data to ground station network elements, storing downlink data from ground station network elements and forwarding downlink data to terminal devices.
[0112] In some examples, the store-and-forward service module is further configured to obtain subscription authorization based on a request from a terminal device to subscribe to the store-and-forward service, and to perform authorization verification on an uplink store-and-forward service request from the UE. In some examples, the store-and-forward service module is further configured to obtain subscription authorization based on a request from a terminal device to subscribe to the store-and-forward service, and to cooperate with the terminal device in authorization verification on a downlink store-and-forward service request.
[0113] It should be noted that in some examples, the store-and-forward service module may not be aware of the authorization subscription process. For example, the store-and-forward service module may only be responsible for merging services and forwarding requests from terminal devices to subscribe to the store-and-forward service.
[0114] The ground station is responsible for forwarding signaling and business data between the satellite base station and the core network.
[0115] The MME is responsible for obtaining authorization credentials of the terminal device, such as authorization credentials including but not limited to authorization tokens, authorization passwords or authorization verification codes.
[0116] In some embodiments, the MME may obtain subscription information about a store-and-forward service of a terminal device, and then generate an authorization credential for the terminal device based on the subscription information and send the credential to the terminal device via a satellite.
[0117] In some embodiments, the MME may obtain the authorization credentials of the terminal device from other network elements. For example, the MME may obtain the authorization credentials of the terminal device from the HSS or other network elements that process store-and-forward services. For example, the HSS or other network elements that process store-and-forward services may also generate the authorization credentials of the terminal device based on the contract information of the store-and-forward service of the terminal device.
[0118] The HSS is responsible for managing and maintaining the subscription information of the store-and-forward service of terminal devices.
[0119] In some embodiments, the HSS may send subscription information about the store-and-forward service of the terminal device to other network elements, such as the MME, so that the MME can generate an authorization credential for the terminal device based on the subscription information.
[0120] In some embodiments, the HSS may generate an authorization credential for the terminal device based on the request of the MME and the subscription information of the store-and-forward service of the terminal device, and then send the credential to the MME.
[0121] As another example, please refer to Figure 5, which takes a 5G communication system as an example to show another schematic diagram of a storage and forwarding service architecture provided by an embodiment of the present application. As shown in Figure 5, the storage and forwarding service architecture may include a terminal device, a satellite, a ground station, an access and mobility management function (AMF) and a unified data management function (UDM). For the relevant introduction to the terminal device, the base station in the satellite, the storage and forwarding service module in the satellite, and the ground station shown in Figure 5, please refer to the above description of the terminal device, the base station in the satellite, the storage and forwarding service module in the satellite, and the ground station.
[0122] Among them, the base stations in the satellite shown in Figure 5 (such as 5G base stations, also called NR base stations) such as gNodeB (gNB) and the like.
[0123] The AMF is responsible for obtaining authorization credentials of the terminal device, such as but not limited to authorization tokens, authorization passwords, or authorization verification codes.
[0124] In some embodiments, the AMF may obtain contract information about the storage and forwarding service of the terminal device, and then generate an authorization certificate for the terminal device based on the contract information and send it to the terminal device via satellite.
[0125] In some embodiments, the AMF may obtain the authorization credential of the terminal device from other network elements. For example, the AMF may obtain the authorization credential of the terminal device from the UDM or other network elements that handle the store-and-forward service. For example, the UDM or other network elements that handle the store-and-forward service may also generate the authorization credential of the terminal device based on the contract information of the store-and-forward service of the terminal device.
[0126] UDM is responsible for managing and maintaining the contract information of the store-and-forward service of terminal devices.
[0127] In some embodiments, the UDM may send subscription information about the storage and forwarding service of the terminal device to other network elements, such as the AMF, so that the MME can generate authorization credentials for the terminal device based on this.
[0128] In some embodiments, the UDM may generate an authorization credential for the terminal device based on the request of the AMF and the contract information of the storage and forwarding service of the terminal device, and then send it to the AMF.
[0129] It should be noted that Figures 4 and 5 are merely examples of two storage and forwarding service architectures. In actual applications, the storage and forwarding service architecture in a 4G communication system may include fewer or more network elements than the structure shown in Figure 4, and the storage and forwarding service architecture in a 5G communication system may also include fewer or more network elements than the structure shown in Figure 5. For example, in some embodiments, other network elements may be responsible for obtaining the authorization credentials of the terminal device.
[0130] As an example, FIG6 takes the 4G communication system as an example to show another schematic diagram of the storage and forwarding service architecture provided by an embodiment of the present application. Among them, the network element for processing the storage and forwarding service shown in FIG6 is responsible for obtaining the authorization certificate of the terminal device, such as obtaining the contract information about the storage and forwarding service of the terminal device from the HSS, and then generating the authorization certificate of the terminal device based on the contract information and sending it to the terminal device via the satellite; or obtaining the authorization certificate of the terminal device from other network elements (such as HSS). For the relevant introduction of the terminal device, satellite and ground station shown in FIG6, please refer to the above description of the terminal device, satellite and ground station in FIG4 respectively.
[0131] As another example, FIG7 takes the 5G communication system as an example to show another schematic diagram of the storage and forwarding service architecture provided by an embodiment of the present application. Among them, the network element for processing the storage and forwarding service shown in FIG7 is responsible for obtaining the authorization certificate of the terminal device, such as obtaining the contract information about the storage and forwarding service of the terminal device from the UDM, and then generating the authorization certificate of the terminal device based on the contract information and sending it to the terminal device via the satellite; or obtaining the authorization certificate of the terminal device from other network elements (such as UDM). For the relevant introduction of the terminal device, satellite and ground station shown in FIG7, please refer to the above description of the terminal device, satellite and ground station in FIG4 respectively.
[0132] As another example, the 5G communication system can also have a network repository function (NRF) network element responsible for obtaining the authorization credentials of the terminal device, such as obtaining the contract information about the storage and forwarding service of the terminal device from the UDM, and then generating the authorization credentials of the terminal device based on the contract information and sending it to the terminal device via satellite; or obtaining the authorization credentials of the terminal device from other network elements (such as UDM).
[0133] The following will describe in detail the information storage method provided in the embodiments of the present application in conjunction with the accompanying drawings.
[0134] Please refer to Figure 8, which shows a flow chart of a method for storing information provided by an embodiment of the present application, taking an uplink satellite communication scenario as an example. As shown in Figure 8, the method for storing information provided by an embodiment of the present application can be implemented based on S801-S802 and S803A-S804, or based on S801-S802 and S803B:
[0135] S801: The terminal device sends first data and first authorization information to the first communication apparatus.
[0136] The first data is data sent by the terminal device to the first network element, that is, uplink data. As an example, the first network element may include but is not limited to any of the following: MME, AMF or other network elements that process store-and-forward services.
[0137] As an example, the first communication device is a satellite, and the satellite has the function of providing a store-and-forward service.
[0138] As an example, the first authorization information includes any one of the following: an authorization token, a first password, or a first verification code.
[0139] In some possible examples, the first authorization information also includes a first threshold, which is the storage capacity of data of the terminal device, such as the maximum storage capacity of data that the communication device can provide for the terminal device, such as 2kB, 5 NAS messages, etc., without limitation.
[0140] As one possible scenario, when the first communication device receives the first data and first authorization information from the terminal device, the first communication device has no communication connection with the first network element. In this case, the first communication device executes S802, or executes S802 after sending a response message to the terminal device. The response message is used to notify the terminal device to wait for a period of time. For example, the response message may include a timer to notify the terminal device of the waiting time. Exemplarily, the duration may be determined by the first communication device based on the time of connection with the first network element determined according to the ephemeris table, or based on other information, without specific limitation.
[0141] As a possible scenario, when the first communication device receives the first data and first authorization information from the terminal device, there is a communication connection between the first communication device and the first network element. In this case, the first communication device may not execute S802 and forward the first data to the first network element.
[0142] S802: The first communication device verifies the first authorization information.
[0143] The first communication device verifies the first authorization information to determine whether to provide a store-and-forward service for the terminal device, such as determining whether to store the first data and forward the first data to the first network element.
[0144] In some embodiments, the first authorization information includes an authorization token. In this case, the first communication device can verify the authorization token in the first authorization information based on verification information corresponding to the authorization token. As an example, the first communication device can be pre-configured with verification information corresponding to one or more authorization tokens. Exemplarily, the verification information corresponding to the authorization token includes an operator verification certificate or a verification public key.
[0145] In some embodiments, the first authorization information includes a first password. In this case, the first communication device may verify the first authorization information based on whether the first password is included in the password set. For example, if the first password is included in the password set, it is determined that the verification of the first authorization information is successful; if the first password is not included in the password set, it is determined that the verification of the first authorization information is unsuccessful.
[0146] As an example, the password set is generated by the first communication device based on the password sent by the ground station network element (such as the first network element, including but not limited to MME, AMF or other network elements that process store-and-forward services) and maintained in the first communication device. The ground station network element may periodically send one or more generated passwords to the first communication device, or may send a new password to the first communication device after generating it, or may generate multiple passwords in a centralized manner and send them together to the first communication device. This embodiment of the present application does not specifically limit this.
[0147] In some embodiments, the first authorization information includes a first verification code. In this case, the first communication device may verify the first authorization information based on whether the first verification code is included in a verification code set. For example, if the first verification code is included in the verification code set, the verification of the first authorization information is determined to be successful; if the first verification code is not included in the verification code set, the verification of the first authorization information is determined to be unsuccessful.
[0148] As an example, the verification code set is generated by the first communication device based on the verification code sent by the ground station network element (such as the first network element, including but not limited to MME, AMF or other network elements that process store-and-forward services) and maintained in the first communication device. Among them, the ground station network element can periodically send one or more generated verification codes to the first communication device, or send a new verification code to the first communication device after generating it, or send multiple verification codes together after generating them, which is not specifically limited in the embodiments of the present application.
[0149] In some embodiments, the first authorization information further includes a first threshold value, which is the amount of data stored in the terminal device. In this case, if the first authorization information is successfully verified and the amount of data from the terminal device stored by the first communication device is less than (or less than or equal to) the first threshold value, the first communication device may determine that the verification of the first authorization information is successful; if the first authorization information is successfully verified, but the amount of data from the terminal device stored by the first communication device is greater than or equal to (or greater than) the first threshold value, the first communication device may determine that the verification of the first authorization information is unsuccessful.
[0150] Optionally, as an example, one or more of the following verification processes may be performed when verifying the first authorization information: verifying whether the service scope (i.e., the authorization object) corresponding to the first authorization information is consistent with the terminal device that sends the first authorization information, verifying whether the signaling scope corresponding to the first authorization information includes the signaling that carries the first authorization information (or whether it is consistent with the signaling that carries the first authorization information), verifying whether the time of sending / receiving the first authorization information is within the authorization period corresponding to the first authorization information, and verifying whether the available communication device type corresponding to the first authorization information includes the type to which the first communication device belongs (or whether it is consistent with the class to which the first communication device belongs).
[0151] Optionally, in some examples, the first communication device may not perform authorization verification for messages of a preset type from the terminal device. Messages of the preset type include but are not limited to messages for subscribing to store-and-forward services, such as registration request messages, Attach request messages, and other NAS messages that do not include uplink data.
[0152] In some embodiments, the first authorization information is a password or a verification code, and the first communication device can verify the first authorization information from another communication device (recorded as a fourth communication device); the password set or the verification code set is generated by the first communication device based on the password or verification code sent by the ground station network element (such as the first network element, including but not limited to MME, AMF or other network elements that handle storage and forwarding services) and maintained in the fourth communication device. For example, the ground station network element can periodically send one or more generated passwords or verification codes to the fourth communication device, or send a new password or verification code to the fourth communication device after generating it, or send multiple passwords or verification codes together to the fourth communication device after collectively generating them. This embodiment of the present application does not make specific limitations.
[0153] S803A: When the verification of the first authorization information is successful, the first communication device stores the first data.
[0154] Among them, if the verification of the first authorization information is passed, it indicates that the terminal device has subscribed to the storage and forwarding service. In this case, the first communication device provides the terminal device with storage services for the first data, such as storing the first data and subsequently forwarding the first data to the first network element.
[0155] S804: The first communication device sends first data to the first network element.
[0156] As an example, the first communication device may send the first data to the first network element after establishing a communication connection with the first network element.
[0157] S803B: If the first authorization information fails to be verified, the first communication apparatus refuses to provide the store-and-forward service for the terminal device.
[0158] Among them, if the first authorization information fails to be verified, it indicates that the terminal device has not subscribed to the storage and forwarding service or has not subscribed to the storage and forwarding service that meets the special needs of the terminal device (such as verification method or data storage threshold, etc.). In this case, the first communication device refuses to provide storage services for the first data to the terminal device.
[0159] Of course, S803B shown in Figure 8 is only a possible example. In actual applications, when the first authorization information is not verified, the first communication device may also subscribe to a storage and forwarding service for the terminal device with the user's consent, and then provide the terminal device with storage services for the first data, such as storing the first data and subsequently forwarding the first data to the first network element. Alternatively, when the first authorization information is not verified, the first communication device may also upgrade or supplement the contract information of the terminal device with the user's consent, and then provide the terminal device with a storage and forwarding service that meets the special needs of the terminal device (such as verification method or data storage threshold, etc.). The embodiments of the present application are not specifically limited and may depend on the specific usage scenario, device function, usage requirements, etc.
[0160] As a possible implementation method, the first authorization information (such as a password or verification code) sent by the terminal device to the first communication device is generated by the terminal device itself; the first communication device sends the first authorization information to the first network element, and the first network element performs authorization verification on the first authorization information, such as authorization verification based on but not limited to the contract information of the terminal device. If the verification is successful, the first network element sends the first authorization information to multiple communication devices (including the first communication device) for multiple communication devices to perform authorization verification in subsequent uplink communication scenarios regarding the terminal device.
[0161] As a possible implementation method, the first authorization information sent by the terminal device to the first communication device is a password in encrypted form, such as a hash value of a password, and the hash value of the password is generated by the terminal device itself; the first communication device sends the hash value of the password to the first network element, and the first network element performs authorization verification on the hash value of the password, such as authorization verification based on but not limited to the contract information of the terminal device. If the verification is successful, the first network element sends the hash value of the password or the verification value of the password to multiple communication devices (including the first communication device), which is used for multiple communication devices to update the hash value set of the password or the verification value set of the password, and then perform authorization verification in subsequent communication scenarios regarding the terminal device.
[0162] As a possible implementation, the first authorization information sent by the terminal device to the first communication device is obtained by the terminal device from the communication device (such as the second communication device). The first communication device and the second communication device may be the same or different, without limitation. For example, taking the second communication device as the same as the first communication device (i.e., the same communication device) and the second network element as the first network element (i.e., the same network element) as an example, as shown in Figure 9, before executing S801, the process of the terminal device obtaining the first authorization information may include S901-S904 shown in Figure 9:
[0163] S901: The terminal device sends a request message, such as a second request message, to the second communication apparatus, where the second request message includes an identifier of the terminal device.
[0164] The second request message is used to subscribe the terminal device to the store-and-forward service. The identification information of the terminal device includes, but is not limited to, IMSI, SUPI, subscription concealed identifier (SUCI), or temporary identifier of the terminal device, etc., which is not specifically limited.
[0165] As a possible example, the second request message is also used to request that the terminal device be registered with the network where the first network element is located. For example, the second request message may include but is not limited to a registration request message or an attach request message, etc., for requesting that the terminal device be registered with the network element.
[0166] In one possible example, the second request message sent by the terminal device to the second communication apparatus further includes information indicating an authentication method supported / requested by the terminal device or information indicating an authentication method requested by the terminal device, for reference by the second communication apparatus when determining the first authorization information. The authentication method includes any of the following: authentication based on an authorization token, authentication based on a password, or authentication based on a verification code.
[0167] In one possible example, the second request message sent by the terminal device to the second communication apparatus also includes a second threshold, and the maximum storage capacity of the terminal device's data requested is the second threshold. The second threshold is the maximum storage capacity of the data requested by the terminal device, such as 2 KB, 5 NAS messages, etc., and is not limited.
[0168] The second communication device and the first communication device may be the same communication device or different communication devices, without specific limitation ( FIG. 9 takes the second communication device and the first communication device as the same communication device as an example).
[0169] S902: The second communication device sends a request message, such as the first request message, to the first network element according to the second request message, where the first request message includes an identifier of the terminal device.
[0170] The first request message is used to subscribe the terminal device to the store-and-forward service. The identification information of the terminal device includes, but is not limited to, IMSI, SUPI, SUCI, or a temporary identification of the terminal device, etc., which is not specifically limited.
[0171] As an example, the first network element may include but is not limited to any one of the following: MME, AMF or other network elements that process store-and-forward services.
[0172] As a possible example, the second request message also includes information for indicating the verification method supported / requested by the terminal device or information for indicating the verification method requested by the terminal device. In this case, after receiving the second request message from the terminal device, the second communication device can determine the first verification method based on the information included therein for indicating the verification method supported / requested by the terminal device or the information for indicating the verification method requested by the terminal device, and then send the first verification method to the first network element through the first request message for reference by the first network element when determining the first authorization information. For example, the first request message may include first information (such as including but not limited to a character string, a bit, etc.), and the first information is used to indicate the first verification method. The first verification method includes but is not limited to any of the following verification methods: verification based on an authorization token, verification based on a password, or verification based on a verification code.
[0173] Exemplarily, when determining the first verification method, the second communication device may determine the first verification method based on information indicating the verification method supported / requested by the terminal device or information indicating the verification method requested by the terminal device, and the verification method supported by the second communication device. For example, the first verification method is a verification method supported by both the terminal device and the second communication device, or the first verification method is a verification method supported / requested by the terminal device and supported by the second communication device. As a possible scenario, the verification method supported / requested by the terminal device or the verification method requested by the terminal device is different from the verification method supported by the second communication device. In this case, the second communication device may reject the second request message of the terminal device, that is, reject the terminal device's request to subscribe to the store-and-forward service.
[0174] As one possible example, the second request message also includes a second threshold value, which is the maximum storage capacity of the data requested by the terminal device. In this case, after receiving the second request message from the terminal device, the second communication device may send the second threshold value to the first network element via the first request message, for the first network element to refer to when determining the first authorization information.
[0175] As a possible example, in the case where the second request message is used to request that the terminal device be registered with the network where the first network element is located, the first request message may also be used to request that the terminal device be registered with the network where the first network element is located. For example, the first request message may include, but is not limited to, a registration request message or an attach request message, etc., for requesting that the terminal device be registered with a network element.
[0176] Optionally, when the second request message is a preset type of message, the first communication device may not perform authorization verification. The preset type of message includes but is not limited to messages for subscribing to store-and-forward services, such as registration request messages, Attach request messages, and other NAS messages that do not include uplink data.
[0177] S903: The first network element determines first authorization information of the terminal device.
[0178] In some embodiments, the first network element may obtain contract information of the terminal device and generate the first authorization information based on the contract information, wherein the contract information of the terminal device indicates that the terminal device has subscribed to the store-and-forward service or indicates that the terminal device has not subscribed to the store-and-forward service.
[0179] For example, if the contract information indicates that the terminal device has subscribed to the store-and-forward service, the first network element may generate first authorization information; if the contract information indicates that the terminal device has not subscribed to the store-and-forward service or the first network element has not successfully obtained the contract information of the terminal device, the first network element may reject the first request message, that is, reject the terminal device's request to subscribe to the store-and-forward service; or, if the contract information indicates that the terminal device has not subscribed to the store-and-forward service or the first network element has not successfully obtained the contract information of the terminal device, the first network element may also, with the user's consent, subscribe the terminal device to the store-and-forward service and then generate first authorization information. The reason why the first network element has not successfully obtained the contract information of the terminal device may be that the terminal device has not subscribed to the store-and-forward service.
[0180] As a possible example, in the case where the first request message includes first information for indicating a first verification method, the first network element may generate first authorization information according to the first verification method, such as the verification method corresponding to the first authorization information is the first verification method.
[0181] As a possible example, when the contract information of the terminal device indicates that the terminal device has subscribed to the second verification method, the first network element may generate first authorization information according to the second verification method, if the verification method corresponding to the first authorization information is the second verification method.
[0182] As a possible example, in the case where the first request message includes first information for indicating a first verification method, and the contract information of the terminal device indicates that the terminal device has subscribed to a second verification method, if the first verification method is the same as the second verification method, the verification method corresponding to the first authorization information generated by the first network element is the second verification method (i.e., the first verification method); if the first verification method is different from the second verification method, the first network element may reject the first request message, that is, reject the terminal device's request to subscribe to the storage and forwarding service, or generate the first authorization information based on the second verification method, or modify the verification method subscribed by the terminal device with the user's consent and then generate the first authorization information based on the first verification method, depending on the specific usage scenario, device function, usage requirements, etc.
[0183] In some embodiments, the first authorization information includes a first threshold value, which is the storage capacity of data of the terminal device.
[0184] As a possible example, when the terminal device's subscription information includes a third threshold for the terminal device's subscription, the first network element may generate first authorization information based on the third threshold, where the first authorization information includes the first threshold. The third threshold is the maximum storage capacity of the data subscribed by the terminal device, such as 2 KB, 5 NAS messages, etc., and is not limited. The first threshold is the same as the third threshold.
[0185] As a possible example, in a case where the first request message includes a second threshold, the first network element may generate first authorization information based on the second threshold, where the first authorization information includes the first threshold. The second threshold is a maximum storage capacity of data requested by the terminal device, and the first threshold is the same as the second threshold.
[0186] As a possible example, in the case where the first request message includes a second threshold and the contract information of the terminal device includes a third threshold subscribed by the terminal device, if the second threshold is less than the third threshold, the first network element can generate first authorization information based on the second threshold, wherein the first authorization information includes the first threshold, and the first threshold is the same as the second threshold; if the second threshold is greater than or equal to the third threshold, the first network element can generate first authorization information based on the third threshold, wherein the first authorization information includes the first threshold, and the first threshold is the same as the third threshold; or if the second threshold is greater than or equal to the third threshold, the first network element can modify the storage capacity threshold of the data subscribed by the terminal device with the user's consent and generate the first authorization information based on the second threshold, depending on the specific usage scenario, device function, usage requirements, etc.
[0187] In some embodiments, the first network element may obtain the first authorization information from another network element, such as a fourth network element. For example, the first network element may send a fifth request message to the fourth network element, where the fifth request message includes an identifier of the terminal device and is used to subscribe the terminal device to a store-and-forward service. The fourth network element may generate the first authorization information and send it to the first network element. The fourth network element may include, but is not limited to, any of the following: an HSS, a UDM, or other network element that processes store-and-forward services.
[0188] As a possible example, the fourth network element may generate the first authorization information based on the subscription information, wherein the subscription information of the terminal device indicates that the terminal device has subscribed to the store-and-forward service or indicates that the terminal device has not subscribed to the store-and-forward service.
[0189] For example, if the contract information indicates that the terminal device has subscribed to the store-and-forward service, the fourth network element may generate the first authorization information; if the contract information indicates that the terminal device has not subscribed to the store-and-forward service or the fourth network element does not include the contract information of the terminal device, the fourth network element may reject the fifth request message, that is, reject the request of the terminal device to subscribe to the store-and-forward service; or, if the contract information indicates that the terminal device has not subscribed to the store-and-forward service or the fourth network element does not include the contract information of the terminal device, the fourth network element may also subscribe the terminal device to the store-and-forward service with the user's consent and then generate the first authorization information. The reason why the fourth network element does not include the contract information of the terminal device may be that the terminal device has not subscribed to the store-and-forward service.
[0190] As a possible example, in the case where the fifth request message includes first information for indicating the first verification method, the fourth network element can generate first authorization information according to the first verification method, such as the verification method corresponding to the first authorization information is the first verification method.
[0191] As a possible example, when the contract information of the terminal device indicates that the terminal device has subscribed to the second verification method, the fourth network element may generate first authorization information based on the second verification method, if the verification method corresponding to the first authorization information is the second verification method.
[0192] As a possible example, in the case where the fifth request message includes first information for indicating the first verification method, and the contract information of the terminal device indicates that the terminal device has subscribed to the second verification method, if the first verification method is the same as the second verification method, the verification method corresponding to the first authorization information generated by the fourth network element is the second verification method (i.e., the first verification method); if the first verification method is different from the second verification method, the fourth network element may reject the first request message, that is, reject the terminal device's request to subscribe to the storage and forwarding service, or generate the first authorization information based on the second verification method, or modify the verification method subscribed by the terminal device with the user's consent and then generate the first authorization information based on the first verification method, depending on the specific usage scenario, device function, usage requirements, etc.
[0193] In some embodiments, the first authorization information includes a first threshold value, which is the storage capacity of data of the terminal device.
[0194] As a possible example, when the contract information of the terminal device includes a third threshold value for the terminal device's subscription, the fourth network element may generate first authorization information based on the third threshold value, where the first authorization information includes the first threshold value. The third threshold value is a maximum storage capacity of data subscribed by the terminal device, and the first threshold value is the same as the third threshold value.
[0195] As a possible example, in a case where the first request message includes a second threshold, the fourth network element may generate first authorization information based on the second threshold, where the first authorization information includes the first threshold. The second threshold is a maximum storage capacity of data requested by the terminal device, and the first threshold is the same as the second threshold.
[0196] As a possible example, in the case where the first request message includes a second threshold and the contract information of the terminal device includes a third threshold subscribed by the terminal device, if the second threshold is less than the third threshold, the fourth network element can generate first authorization information based on the second threshold, wherein the first authorization information includes the first threshold, and the first threshold is the same as the second threshold; if the second threshold is greater than or equal to the third threshold, the fourth network element can generate first authorization information based on the third threshold, wherein the first authorization information includes the first threshold, and the first threshold is the same as the third threshold; or if the second threshold is greater than or equal to the third threshold, the fourth network element can modify the storage capacity threshold of the data subscribed by the terminal device with the user's consent and generate the first authorization information based on the second threshold, depending on the specific usage scenario, device function, usage requirements, etc.
[0197] Optionally, in some embodiments, the first authorization information also includes one or more of the following: the service scope corresponding to the first authorization information (i.e., the authorization object), the signaling scope corresponding to the first authorization information (such as the signaling class type that can carry the first authorization information), the authorization period corresponding to the first authorization information\the available communication device type corresponding to the first authorization information, which is used for reference by the second communication device when verifying the authorization.
[0198] S904: The first network element sends first authorization information to the second communication device, and the second communication device sends the first authorization information to the terminal device.
[0199] In some embodiments, when the first authorization information is an authorization token, the first network element may send the first authorization information to a second communication device. For example, the second communication device may be a communication device that the first network element determines by querying the ephemeris table and is about to connect to the terminal device, which is not limited in this embodiment of the present application.
[0200] In some embodiments, if the first authorization information is a password or a verification code, the first network element may send the first authorization information to one or more second communication devices (including the first communication device), so that the multiple second communication devices can update the password set or verification code set they maintain. Correspondingly, after receiving the first authorization information from the first network element, the second communication device can update the password set or verification code set it maintains based on the first authorization information.
[0201] As a possible example, the way in which the first network element sends passwords / verification codes to multiple second communication devices may be, but is not limited to, any of the following: periodically sending one or more generated passwords (including the first password) / verification codes (including the first verification code) to multiple second communication devices, sending a new password (such as the first password) / verification code (such as the first verification code) to multiple second communication devices after generating it, and sending multiple passwords (including the first password) / verification codes (including the first verification code) together after centrally generating them to multiple second communication devices. The embodiments of the present application do not make specific limitations.
[0202] Please refer to Figure 10, which shows a flow chart of a method for storing information provided by an embodiment of the present application, taking a downlink satellite communication scenario as an example. As shown in Figure 10, the method for storing information provided by an embodiment of the present application can be implemented based on S1001-S1004 and S1005A, or based on S1001-S1004 and S1005B:
[0203] S1001: A first communication device receives a third request message from a first network element, where the third request message includes second data and an identifier of a terminal device.
[0204] The second data is data sent by the first network element to the terminal device, that is, downlink data.
[0205] As a possible scenario, when the first communication device receives the third request message from the first network element, the first communication device has no communication connection with the terminal device. In this case, the first communication device executes S1002, or executes S1002 after sending a response message to the first network element. The response message is used to notify the first network element to wait for a period of time. For example, the response message may include a timer to notify the first network element of the waiting time. Exemplarily, the duration may be determined by the first communication device based on the time of connection with the terminal device determined according to the ephemeris table, or based on other information, without specific limitation.
[0206] As a possible scenario, when the first communication device receives the third request message from the first network element, there is a communication connection between the first communication device and the terminal device. In this case, the first communication device may not execute S1002 and forward the second data to the terminal device.
[0207] S1002: The first communication apparatus determines second authorization information according to the identification of the terminal device.
[0208] As an example, the first communication apparatus may pre-store a correspondence between one or more terminal devices and authorization information, and the first communication apparatus may determine the second authorization information therefrom according to an identifier of the terminal device.
[0209] S1003: The first communication device sends second data and second authorization information to the terminal device.
[0210] The second authorization information is used to verify the second data.
[0211] S1004: The terminal device verifies the second authorization information.
[0212] The terminal device verifies the second authorization information to determine the legitimacy of the source of the second data, and then determines whether to parse the second data.
[0213] As an example, the terminal device may be pre-configured with verification information corresponding to one or more authorization tokens. For example, the verification information corresponding to the authorization token may include an operator verification certificate or a verification public key. The terminal device may use the verification information corresponding to the second authorization information to verify the second authorization information.
[0214] Optionally, as an example, one or more of the following verification processes may be performed when verifying the second authorization information: verifying whether the service scope (i.e., the authorization object) corresponding to the second authorization information is consistent with the terminal device, verifying whether the signaling scope corresponding to the second authorization information includes the signaling carrying the second authorization information (or whether it is consistent with the signaling carrying the second authorization information), verifying whether the time of sending / receiving the second authorization information is within the usage period corresponding to the second authorization information, and verifying whether the type of available communication device corresponding to the second authorization information includes the type to which the first communication device belongs (or whether it is consistent with the class to which the first communication device belongs).
[0215] S1005A: When the second authorization information is verified successfully, the terminal device parses the second data.
[0216] Wherein, if the second authorization information is verified successfully, it indicates that the source of the second data is legal. In this case, the terminal device can parse the second data.
[0217] S1005B: If the second authorization information is not verified, the terminal device does not parse the second data.
[0218] If the second authorization information fails to be verified, it indicates that the source of the second data is illegal. In this case, the terminal device does not parse the second data to ensure the security of the terminal device.
[0219] As a possible implementation, the second authorization information sent by the first communication device to the terminal device is obtained by the first communication device from the third network element according to the request of the terminal device. For example, as shown in FIG11 , before executing S1001, S1101-S1105 shown in FIG11 may also be included:
[0220] S1101: The terminal device sends a request message, such as a sixth request message, to the second communication apparatus, where the sixth request message includes an identifier of the terminal device.
[0221] The sixth request message is used to subscribe the terminal device to the store-and-forward service. The identification information of the terminal device includes, but is not limited to, IMSI, SUPI, subscription concealed identifier (SUCI), or temporary identifier of the terminal device, etc., which is not specifically limited.
[0222] As a possible example, the sixth request message is also used to request that the terminal device be registered with the network where the third network element is located. For example, the sixth request message may include but is not limited to a registration request message or an attach request message, etc., for requesting that the terminal device be registered with the network.
[0223] In one possible example, the sixth request message sent by the terminal device to the second communication apparatus further includes information indicating an authentication method supported / requested by the terminal device or information indicating an authentication method requested by the terminal device, for reference by the second communication apparatus when determining the first authorization information. The authentication method includes any of the following: authentication based on an authorization token, authentication based on a password, or authentication based on a verification code.
[0224] In a possible example, the sixth request message sent by the terminal device to the second communication apparatus further includes a second threshold value for requesting that the maximum storage capacity of the terminal device's data be the second threshold value. The second threshold value is the maximum storage capacity of the data requested by the terminal device.
[0225] The second communication device and the first communication device may be the same communication device or different communication devices, without specific limitation ( FIG. 11 takes the second communication device and the first communication device as the same communication device as an example).
[0226] S1102: The second communication device sends a request message, such as the fourth request message, to the third network element according to the sixth request message, wherein the fourth request message includes a network function (NF) instance identifier (NF instance id) for identifying the storage and forwarding service module.
[0227] Exemplarily, the third network element may include but is not limited to an NRF or other network elements that process store-and-forward services.
[0228] Optionally, the fourth request message may also include one or more of the following: the service scope of the second communication device (such as one or more of the terminal equipment identification, slice identification, service country identification, service area identification, etc.), first information used to indicate the first verification method (such as including but not limited to a string, bit, etc.) or a second threshold.
[0229] S1103: The third network element determines the second authorization information.
[0230] As an example, the third network element may determine the second authorization information according to the registration information of the second communication device and the fourth request message.
[0231] As an example, the registration information of the second communication device includes a network function instance identifier (NF instance id) for identifying a storage and forwarding service module; optionally, the registration information may further include one or more of the following: an identifier for indicating whether the second communication device supports the storage and forwarding service function, an identifier for indicating the verification method supported by the second communication device, a second communication device identifier, a storage capacity of data supported by the second communication device, a service scope of the second communication device (such as one or more of a terminal device identifier, a slice identifier, a service country identifier, a service area identifier, etc.). In the case where the fourth request message does not include the service scope of the second communication device, the first information, or the second threshold value, the third network element may determine the second authorization information based on the registration information of the second communication device.
[0232] As an example, the registration information of the second communication device is pre-registered by the second communication device in the third network element for reference when subsequently generating the authorization information. Exemplarily, the registration information of the second communication device can be stored in the NF profile of the third network element.
[0233] As an example, when the registration information of the second communication device indicates that the second communication device supports the fourth verification method and the fourth request message includes a second threshold, if the fourth verification method is the same as the first verification method, the third network element can generate second authorization information based on the fourth verification method, wherein the second authorization information includes the second threshold.
[0234] As an example, when the registration information of the second communication device indicates that the second communication device supports the fourth verification method, and the fourth request message includes the first verification method and the second threshold, if the fourth verification method is the same as the first verification method, the third network element can generate second authorization information based on the first verification method (i.e., the fourth verification method), wherein the second authorization information includes the second threshold; if the fourth verification method is different from the first verification method, the third network element may reject the request, or generate second authorization information based on the fourth verification method, depending on the specific usage scenario, device function, usage requirements, etc.
[0235] As an example, when the registration information of the second communication device indicates that the second communication device supports the fourth verification method and the storage capacity of the data supported by the second communication device is a third threshold, and the fourth request message includes the first verification method, if the fourth verification method is the same as the first verification method, the third network element can generate second authorization information based on the first verification method (i.e., the fourth verification method), wherein the second authorization information includes the third threshold; if the fourth verification method is different from the first verification method, the third network element may reject the request, or generate second authorization information based on the fourth verification method, depending on the specific usage scenario, device function, usage requirements, etc.
[0236] As an example, when the registration information of the second communication device indicates that the second communication device supports the fourth verification method and the storage capacity of the stored data supported by the second communication device is a third threshold, and the fourth request message includes the first verification method and the second threshold, if the fourth verification method is the same as the first verification method and the second threshold is less than or equal to the third threshold, the third network element may generate second authorization information according to the first verification method (i.e., the fourth verification method), wherein the second authorization information includes the second threshold; if the fourth verification method is the same as the first verification method and the second threshold is greater than the third threshold, the third network element may generate second authorization information according to the first verification method (i.e., the fourth verification method), wherein the second authorization information includes the third threshold; if the fourth verification method is different from the first verification method and the second threshold is less than or equal to the third threshold, the third network element may reject the request, or generate second authorization information including the second threshold according to the fourth verification method; if the fourth verification method is different from the first verification method and the second threshold is greater than the third threshold, the third network element may reject the request, or generate second authorization information including the third threshold according to the fourth verification method.
[0237] Optionally, in some embodiments, the second authorization information also includes one or more of the following: the signaling scope corresponding to the second authorization information (such as the signaling class type that can carry the second authorization information), the authorization period corresponding to the second authorization information\the type of available communication device corresponding to the second authorization information, for reference by the terminal device when verifying the authorization.
[0238] S1104: The third network element sends second authorization information to the second communication device.
[0239] Optionally, the second authorization information includes an authorization scope corresponding to the second authorization information. The authorization scope corresponding to the second authorization information may include the identification of one or more terminal devices, which is used by the second communication device to send to the corresponding terminal device in a downlink communication scenario, and is used for the terminal device to perform authorization verification. The one or more terminal devices include the terminal device shown in Figure 11.
[0240] Optionally, the authorization scope corresponding to the second authorization information may also include one or more of the following: one or more slice identifiers, one or more service country identifiers, and one or more service area identifiers, which are sent by the second communication device to the corresponding device in a downlink communication scenario for the device to perform authorization verification.
[0241] Optionally, the second authorization information does not include the authorization scope corresponding to the second authorization information. The third network element sends the authorization scope corresponding to the second authorization information and the second authorization information to the second communication device, which is used by the second communication device to send to the corresponding terminal device in a downlink communication scenario, for the terminal device to perform authorization verification.
[0242] S1105: The second communication device saves the second authorization information.
[0243] The second communication device stores the second authorization information for subsequent transmission to the terminal device together with the downlink data when forwarding the downlink data (such as the second data) to the terminal device, so as to enable the terminal device to verify the legitimacy of the source of the downlink data.
[0244] It can be understood that the solution provided by the embodiment of the present application can perform authorization verification based on the subscription authorization when the satellite cannot communicate with the terminal device and the ground station network element at the same time, and choose whether to provide the storage and forwarding service based on whether the authorization verification is successful. For example, the terminal device can subscribe to the satellite's uplink storage and forwarding service from the ground station, and the ground station network element can provide the terminal device with authorization credentials for the storage and forwarding service, such as authorization tokens, passwords, or verification codes. Based on this, in the uplink satellite communication scenario, the satellite can verify the authorization information (i.e., authorization credentials) sent by the terminal device and provide the storage and forwarding service to the terminal device if the verification is successful. In this way, access control of the storage and forwarding service can be achieved, ensuring the effective use of the satellite's storage space, and helping to ensure the quality of the storage and forwarding service provided by the satellite. In addition, by ensuring the security of the data source through authorization verification, the terminal device can be prevented from sending false or malicious data, thereby improving the security of the satellite or ground station network element. Alternatively, in the downlink satellite communication scenario, the satellite can send authorization information (i.e., authorization credentials) to the terminal device when forwarding downlink data, and the terminal device can parse the downlink data forwarded by the satellite if the authorization information is verified. In this way, the reliable implementation of authorization verification in downlink communication scenarios can be guaranteed, and the security of terminal devices receiving downlink data can be improved.
[0245] As an example, the second authorization information includes an identifier of the terminal device. In this case, the second communication device may store the corresponding relationship between the second authorization information and the terminal device after receiving the second authorization information.
[0246] As an example, the second authorization information does not include the authorization scope corresponding to the second authorization information. The third network element sends the authorization scope corresponding to the second authorization information and the second authorization information to the second communication device. In this case, the second communication device can directly store the authorization scope corresponding to the second authorization information and the second authorization information.
[0247] The following will illustrate the possible implementation process of the information storage method provided in the embodiments of the present application with reference to several specific embodiments.
[0248] As a possible embodiment, please refer to Figure 12. Figure 12 takes the first communication device as satellite 1, the second communication device is satellite 2, satellite 2 and satellite 3 are the same satellite, the first network element (the same as the second network element) is MME, the fourth network element is HSS, HSS is responsible for generating the first authorization information, and the first authorization information is an authorization token as an example, showing an interaction diagram of the implementation process of the information storage method in an uplink satellite communication scenario provided by an embodiment of the present application.
[0249] As shown in FIG12 , the solution provided in the embodiment of the present application may include S1201 to S1214:
[0250] S1201: Satellite 1 and Satellite 2 configure verification information, such as the operator's verification certificate or verification public key.
[0251] The configuration verification information of satellite 1 and satellite 2 is used for subsequent verification of the authorization token to perform authorization verification on the store-and-forward service.
[0252] It should be noted that FIG12 only shows the relevant satellites 1 and 2. In actual applications, one or more other satellites may also be included. These satellites may also provide storage and forwarding services for terminal devices, and these satellites may also be pre-configured with verification information.
[0253] S1202: After accessing satellite 2, the terminal device sends a second request message to satellite 2. The second request message includes an identifier of the terminal device, information indicating a verification method supported / requested by the terminal device, and a second threshold.
[0254] The second request message is used to subscribe the terminal device to the store-and-forward service.
[0255] Exemplarily, the identification information of the terminal device includes but is not limited to IMSI, SUPI, SUCI or a temporary identification of the terminal device, etc., which is not specifically limited.
[0256] Exemplarily, the authentication methods supported / requested by the terminal device may include any one of the following: authentication based on an authorization token, authentication based on a password, or authentication based on a verification code.
[0257] Exemplarily, the second threshold is the maximum storage capacity of data requested by the terminal device, such as 2kB, 5 NAS messages, etc., which is not limited.
[0258] S1203: Satellite 2 sends a second response message to the terminal device.
[0259] The second response message is used to notify the terminal device to wait for a period of time. For example, the second response message may include a timer to notify the terminal device of the waiting time.
[0260] S1204: Satellite 2 determines the first verification method.
[0261] Exemplarily, satellite 2 may determine the first authentication method based on information indicating authentication methods supported / requested by the terminal device and the authentication methods supported by satellite 2. For example, the first authentication method is an authentication method supported by both the terminal device and satellite 2, or the first authentication method is an authentication method requested by the terminal device and supported by satellite 2. For example, if the authentication methods supported / requested by the terminal device include authentication based on authorization tokens and authentication based on passwords, but satellite 2 only supports authentication based on authorization tokens, then the first authentication method determined by satellite 2 is the authorization token.
[0262] As a possible scenario, the authentication method supported by the terminal device or the authentication method requested by the terminal device is different from the authentication method supported by satellite 2. In this case, satellite 2 may reject the second request message of the terminal device, that is, reject the terminal device's request to subscribe to the store-and-forward service.
[0263] S1205: When satellite 2 is connected to the MME, it sends a first request message to the MME. The first request message includes an identifier of the terminal device, first information for indicating a first verification method, and a second threshold.
[0264] The first request message is used to subscribe the terminal device to the store-and-forward service.
[0265] S1206: The MME sends a fifth request message to the HSS, where the fifth request message includes an identifier of the terminal device, first information for indicating the first verification method, and a second threshold.
[0266] The fifth request message is used to subscribe the terminal device to the store-and-forward service.
[0267] As an example, the HSS maintains subscription information of the terminal device.
[0268] S1207: The HSS obtains the contract information of the terminal device according to the identifier of the terminal device, and generates an authorization token according to the contract information of the terminal device and the fifth request message.
[0269] The contract information of the terminal device indicates that the terminal device has subscribed to the store-and-forward service or indicates that the terminal device has not subscribed to the store-and-forward service.
[0270] Optionally, the contract information of the terminal device may also indicate that the terminal device has subscribed to the second verification method.
[0271] Optionally, the subscription information of the terminal device may further indicate a third threshold value subscribed by the terminal device. The third threshold value is a maximum storage capacity of data subscribed by the terminal device.
[0272] As an example, if the subscription information indicates that the terminal device is not subscribed to the store-and-forward service or the HSS does not include the subscription information for the terminal device, the HSS may, with the user's consent, subscribe the terminal device to the store-and-forward service and then generate an authorization token. The reason why the HSS does not include the subscription information for the terminal device may be that the terminal device is not subscribed to the store-and-forward service.
[0273] As an example, when the contract information indicates that the terminal device has subscribed to the store-and-forward service, but does not indicate that the terminal device has subscribed to the second verification method and the terminal device has subscribed to the third threshold, the HSS can generate first authorization information based on the first information (such as but not limited to a string, bits, etc.) used to indicate the first verification method in the fifth request message and the second threshold (Figure 12 takes the first verification method as an example of verification based on the authorization token), that is, generates an authorization token, wherein the authorization token includes the third threshold.
[0274] As an example, when the contract information indicates that the terminal device has subscribed to the store-and-forward service and that the terminal device has subscribed to the second verification method, but does not indicate that the terminal device has subscribed to the third threshold, the HSS can choose whether to generate the first authorization information based on the second verification method, the first information indicating the first verification method in the fifth request message, and the second threshold (Figure 12 takes the first verification method as an example of verification based on the authorization token) and what verification method to generate the first authorization information, that is, to generate an authorization token, wherein the authorization token includes the second threshold. For example, if the first verification method is the same as the second verification method, the HSS can generate an authorization token based on the first verification method (that is, the second verification method); if the first verification method is different from the second verification method, the HSS may reject the terminal device's request to subscribe to the store-and-forward service, or generate the first authorization information based on the second verification method, or generate the first authorization information based on the first verification method after modifying the verification method subscribed by the terminal device with the user's consent, depending on the specific usage scenario, device function, usage requirements, etc.
[0275] As an example, when the contract information indicates that the terminal device has subscribed to a store-and-forward service, and indicates that the terminal device has subscribed to a second verification method and that the terminal device has subscribed to a third threshold, the HSS may generate first authorization information based on the first information, the second threshold, and the third threshold used to indicate the first verification method in the fifth request message ( FIG. 12 takes the first verification method as an example of verification based on an authorization token), i.e., generate an authorization token, wherein the authorization token includes a first threshold, and the first threshold is the same as the second threshold or the same as the third threshold. For example, if the second threshold is less than or equal to the third threshold, the first threshold is the same as the second threshold; if the second threshold is greater than the third threshold, the first threshold is the same as the third threshold.
[0276] Optionally, the authorization token may also include identifiers of one or more satellites capable of providing store-and-forward services for the terminal device. This identifier is used by the MME to determine which satellites to send the authorization token to, and by the terminal device to determine which satellites to send uplink data to. As an example, the one or more satellites capable of providing store-and-forward services for the terminal device may be determined by the HSS based on one or more of the following information: the terminal device's subscription information, the store-and-forward service capabilities of multiple satellites, and the ephemeris table.
[0277] S1208: The HSS sends the terminal device identifier and authorization token to the MME.
[0278] S1209: The MME sends the terminal device's identifier and authorization token to satellite 3.
[0279] Illustratively, satellite 3 is determined by the MME based on one or more of the following: determining the satellite to which the terminal device will connect by querying the ephemeris table, or determining the satellite based on satellite identification information included in the authorization token. Satellite 3 may or may not be the same as satellite 2. Figure 12 uses the example of satellite 3 being the same as satellite 2.
[0280] S1210: Satellite 3 sends an authorization token to the corresponding terminal device according to the identifier of the terminal device.
[0281] Optionally, in some embodiments, if the terminal device does not receive the authorization token, the terminal device may send a request message again, such as to Satellite 1, Satellite 2, or another satellite, to subscribe to the store-and-forward service. After receiving the request message, the satellite may check whether the authorization information of the terminal device is stored locally. If so, the satellite will no longer request the MME to subscribe the terminal device to the store-and-forward service and / or send the found authorization information of the terminal device to the terminal device.
[0282] S1211: Satellite 1 receives first data and an authorization token from the terminal device.
[0283] The first data is the data sent by the terminal device to the MME, that is, uplink data.
[0284] S1212: Satellite 1 verifies the authorization token and storage capacity using the configured verification information, and stores the first data when the verification is successful.
[0285] Exemplarily, if the satellite 1 verifies that the authorization token passes using the configured verification information and the amount of data from the terminal device stored in the satellite 1 is less than (or less than or equal to) a first threshold, the satellite 1 determines that the verification is successful.
[0286] Optionally, the satellite 1 may also start timing when storing the first data to record the duration for which the satellite 1 stores the first data.
[0287] S1213: Satellite 1 sends a first response message to the terminal device, where the first response message is used to indicate that the first data is successfully stored.
[0288] S1214: When satellite 1 is connected to the MME, it sends first data to the MME.
[0289] As a possible embodiment, please refer to Figure 13. Figure 13 takes the first communication device as satellite 1, the second communication device is satellite 2, satellite 2 and satellite 3 are the same satellite, the first network element (the same as the second network element) is MME, the fourth network element is HSS, MME is responsible for generating the first authorization information, and the first authorization information is an authorization token as an example, showing an interaction diagram of the implementation process of the information storage method in an uplink satellite communication scenario provided by an embodiment of the present application.
[0290] As shown in FIG13 , compared to the interaction process shown in FIG12 , the solution provided in the embodiment of the present application may include S1201-S1205, S1301-S1302, and S1209-S1214. For a detailed description of S1201-S1205 and S1209-S1214, reference may be made to the above description; S1301-S1302 are described as follows:
[0291] S1301: MME obtains the subscription information of the terminal device from HSS.
[0292] Exemplarily, the MME may send a contract information query request to the HSS, where the request carries an identifier of the terminal device; the HSS may send the contract information of the corresponding terminal device to the MME based on the identifier of the terminal device carried in the request.
[0293] The contract information of the terminal device indicates that the terminal device has subscribed to the store-and-forward service or indicates that the terminal device has not subscribed to the store-and-forward service.
[0294] Optionally, the contract information of the terminal device may also indicate that the terminal device has subscribed to the second verification method.
[0295] Optionally, the subscription information of the terminal device may further indicate a third threshold value subscribed by the terminal device. The third threshold value is a maximum storage capacity of data subscribed by the terminal device.
[0296] S1302: The MME generates an authorization token based on the subscription information of the terminal device and the first request message.
[0297] As an example, if the subscription information indicates that the terminal device is not subscribed to the store-and-forward service or the HSS does not include the subscription information of the terminal device, the MME may, with the user's consent, subscribe the terminal device to the store-and-forward service and then generate an authorization token. The reason why the HSS does not include the subscription information of the terminal device may be that the terminal device is not subscribed to the store-and-forward service.
[0298] As an example, when the contract information indicates that the terminal device has subscribed to the store-and-forward service, and does not indicate that the terminal device has subscribed to the second verification method and the terminal device has subscribed to the third threshold, the MME can generate first authorization information based on the first information and the second threshold used to indicate the first verification method in the first request message (Figure 13 takes the first verification method as an example of verification based on the authorization token), that is, generate an authorization token, wherein the authorization token includes the third threshold.
[0299] As an example, when the contract information indicates that the terminal device has subscribed to the store-and-forward service and the second verification method, but does not indicate that the terminal device has subscribed to the third threshold, the MME may select whether to generate first authorization information based on the second verification method, the first information indicating the first verification method in the first request message, and the second threshold ( FIG13 uses the first verification method as an example of verification based on an authorization token), and which verification method to generate first authorization information, i.e., generate an authorization token, wherein the authorization token includes the second threshold. For example, if the first verification method is the same as the second verification method, the MME may generate an authorization token based on the first verification method (i.e., the second verification method); if the first verification method is different from the second verification method, the MME may reject the terminal device's request to subscribe to the store-and-forward service, or generate the first authorization information based on the second verification method, or, with the user's consent, modify the verification method subscribed by the terminal device and then generate the first authorization information based on the first verification method, depending on the specific usage scenario, device function, usage requirements, etc.
[0300] As an example, when the contract information indicates that the terminal device has subscribed to a store-and-forward service, and indicates that the terminal device has subscribed to a second verification method and that the terminal device has subscribed to a third threshold, the MME may generate first authorization information based on the first information indicating the first verification method in the first request message, the second threshold, and the third threshold ( FIG12 takes the first verification method as an example of verification based on an authorization token), i.e., generate an authorization token, wherein the authorization token includes a first threshold, and the first threshold is the same as the second threshold or the same as the third threshold. For example, if the second threshold is less than or equal to the third threshold, the first threshold is the same as the second threshold; if the second threshold is greater than the third threshold, the first threshold is the same as the third threshold.
[0301] Optionally, the authorization token may also include identifiers of one or more satellites capable of providing store-and-forward services for the terminal device, which are used by the MME to determine which satellites to send the authorization token to and by the terminal device to determine which satellites to send uplink data to. As an example, the one or more satellites capable of providing store-and-forward services for the terminal device may be determined by the MME based on one or more of the following information: the terminal device's subscription information, the store-and-forward service capabilities of multiple satellites, and ephemeris.
[0302] As a possible embodiment, please refer to Figure 14. Figure 14 takes the first communication device as satellite 1, the second communication device is satellite 2, satellite 2 and satellite 3 are the same satellite, the first network element (the same as the second network element) is MME, the fourth network element is HSS, HSS is responsible for generating the first authorization information, and the first authorization information is a password or a verification code as an example, showing an interaction diagram of the implementation process of the information storage method in an uplink satellite communication scenario provided by an embodiment of the present application.
[0303] As shown in FIG14 , compared to the interaction process shown in FIG12 , the solution provided in the embodiment of the present application may include S1202-S1206, S1401-S1407, and S1213-S1214. For a detailed description of S1202-S1206 and S1213-S1214, reference can be made to the description of S1401-S1407 above. The description is as follows:
[0304] S1401: The HSS obtains the contract information of the terminal device according to the identifier of the terminal device, and generates a first password / first verification code according to the contract information of the terminal device and the fifth request message.
[0305] The contract information of the terminal device indicates that the terminal device has subscribed to the store-and-forward service or indicates that the terminal device has not subscribed to the store-and-forward service.
[0306] Optionally, the contract information of the terminal device may also indicate that the terminal device has subscribed to the second verification method.
[0307] Optionally, the subscription information of the terminal device may further indicate a third threshold value subscribed by the terminal device. The third threshold value is a maximum storage capacity of data subscribed by the terminal device.
[0308] As an example, if the subscription information indicates that the terminal device has not subscribed to the store-and-forward service or the HSS does not include the subscription information of the terminal device, the HSS may, with the user's consent, subscribe the terminal device to the store-and-forward service and then generate a first password / first verification code. The reason why the HSS does not include the subscription information of the terminal device may be that the terminal device has not subscribed to the store-and-forward service.
[0309] As an example, when the contract information indicates that the terminal device has subscribed to the store-and-forward service, and does not indicate that the terminal device has subscribed to the second verification method and the terminal device has subscribed to the third threshold, the HSS can generate first authorization information based on the first information and the second threshold used to indicate the first verification method in the fifth request message (Figure 14 takes the first verification method as an example of password / verification code-based verification), that is, generate a first password / first verification code, where the first password / first verification code includes the third threshold.
[0310] As an example, when the contract information indicates that the terminal device has subscribed to the store-and-forward service and the second verification method, but does not indicate that the terminal device has subscribed to the third threshold, the HSS may select whether to generate first authorization information based on the second verification method, the first information indicating the first verification method in the fifth request message, and the second threshold ( FIG14 uses password / verification code-based verification as an example of the first verification method), and which verification method to generate first authorization information, i.e., generate a first password / first verification code, where the first password / first verification code includes the second threshold. For example, if the first verification method is the same as the second verification method, the HSS may generate the first password / first verification code based on the first verification method (i.e., the second verification method); if the first verification method is different from the second verification method, the HSS may reject the terminal device's request to subscribe to the store-and-forward service, generate the first authorization information based on the second verification method, or, with the user's consent, modify the verification method subscribed by the terminal device and then generate the first authorization information based on the first verification method, depending on the specific usage scenario, device function, usage requirements, etc.
[0311] As an example, when the contract information indicates that the terminal device has subscribed to a store-and-forward service, and indicates that the terminal device has subscribed to a second verification method and that the terminal device has subscribed to a third threshold, the HSS may generate first authorization information based on the first information indicating the first verification method in the fifth request message, the second threshold, and the third threshold ( FIG. 14 takes the first verification method as an example of password / verification code-based verification), i.e., generate a first password / first verification code, wherein the first password / first verification code includes a first threshold, and the first threshold is the same as the second threshold or the same as the third threshold. For example, if the second threshold is less than or equal to the third threshold, the first threshold is the same as the second threshold; if the second threshold is greater than the third threshold, the first threshold is the same as the third threshold.
[0312] Optionally, the first password / first verification code may also include identifiers of one or more satellites capable of providing a store-and-forward service for the terminal device, which is used by the MME to determine which satellites to send the first password / first verification code to and by the terminal device to determine which satellites to send uplink data to. As an example, the one or more satellites capable of providing a store-and-forward service for the terminal device may be determined by the HSS based on one or more of the following information: the terminal device's subscription information, the store-and-forward service capabilities of multiple satellites, and the ephemeris.
[0313] S1402: The HSS sends the terminal device identifier and the first password / first verification code to the MME.
[0314] S1403: The MME sends the terminal device identifier and the first password / first verification code to multiple satellites (including satellite 1 and satellite 2).
[0315] Exemplarily, the above-mentioned multiple satellites are determined by the MME based on one or more of the following methods: satellites to be connected to the terminal device determined by querying the ephemeris table, and determined based on identification information of the satellite included in the authorization token.
[0316] For example, the MME may send the first password / first verification code to multiple satellites after obtaining it, or may periodically send one or more passwords / verification codes obtained in the most recent period to multiple satellites, or may centrally generate multiple passwords / verification codes and send them together to multiple satellites. This embodiment of the present application does not make specific limitations.
[0317] S1404: Multiple satellites (including satellite 1 and satellite 2) update a password set according to the first password / update a verification code set according to the first verification code.
[0318] Illustratively, multiple satellites (including Satellite 1 and Satellite 2) may add the first password into a locally maintained password set, or add the first verification code into a locally maintained verification code set.
[0319] S1405: Satellite 2 sends a first password / first verification code to the corresponding terminal device according to the identifier of the terminal device.
[0320] Optionally, in some embodiments, if the terminal device does not receive the password / verification code, the terminal device may send a request message again, such as to Satellite 1, Satellite 2, or another satellite, to subscribe to the store-and-forward service. After receiving the request message, the satellite may check whether the authorization information of the terminal device is stored locally. If so, the satellite will no longer request the MME to subscribe the terminal device to the store-and-forward service and / or send the found authorization information of the terminal device to the terminal device.
[0321] S1406: The terminal device sends the first data and the first password / first verification code to satellite 1.
[0322] The first data is the data sent by the terminal device to the MME, that is, uplink data.
[0323] S1407: Satellite 1 determines that the verification is successful when the first password is in the password set / the first verification code is in the verification code set and the storage amount meets the conditions, and stores the first data.
[0324] Exemplarily, if the storage amount satisfies a condition such as the amount of stored data from the terminal device is less than (or less than or equal to) a first threshold, the satellite 1 determines that the verification is successful.
[0325] Optionally, the satellite 1 may also start timing when storing the first data to record the duration for which the satellite 1 stores the first data.
[0326] As a possible embodiment, please refer to Figure 15. Figure 15 takes the first communication device as satellite 1, the second communication device is satellite 2, satellite 2 and satellite 3 are the same satellite, the first network element (the same as the second network element) is MME, the fourth network element is HSS, MME is responsible for generating the first authorization information, and the first authorization information is a password / verification code as an example, showing an interaction diagram of the implementation process of the information storage method in an uplink satellite communication scenario provided by an embodiment of the present application.
[0327] As shown in FIG15 , compared to the interaction process shown in FIG14 , the solution provided in the embodiment of the present application may include S1202-S1205, S1501-S1502, S1403-S1407, and S1213-S1214. For a detailed description of S1202-S1205, S1403-S1407, and S1213-S1214, reference may be made to the above description; S1501-S1502 are described as follows:
[0328] S1501: MME obtains the subscription information of the terminal device from HSS.
[0329] Exemplarily, the MME may send a contract information query request to the HSS, where the request carries an identifier of the terminal device; the HSS may send the contract information of the corresponding terminal device to the MME based on the identifier of the terminal device carried in the request.
[0330] The contract information of the terminal device indicates that the terminal device has subscribed to the store-and-forward service or indicates that the terminal device has not subscribed to the store-and-forward service.
[0331] Optionally, the contract information of the terminal device may also indicate that the terminal device has subscribed to the second verification method.
[0332] Optionally, the subscription information of the terminal device may further indicate a third threshold value subscribed by the terminal device. The third threshold value is a maximum storage capacity of data subscribed by the terminal device.
[0333] S1502: The MME generates a first password / first verification code according to the subscription information of the terminal device and the first request message.
[0334] As an example, if the subscription information indicates that the terminal device is not subscribed to the store-and-forward service or the HSS does not include the subscription information of the terminal device, the MME may, with the user's consent, subscribe the terminal device to the store-and-forward service and then generate a first password / first verification code. The reason why the HSS does not include the subscription information of the terminal device may be that the terminal device is not subscribed to the store-and-forward service.
[0335] As an example, when the contract information indicates that the terminal device has subscribed to the store-and-forward service, and does not indicate that the terminal device has subscribed to the second verification method and the terminal device has subscribed to the third threshold, the MME can generate first authorization information based on the first information and the second threshold used to indicate the first verification method in the first request message (Figure 15 takes the first verification method as an example of password / verification code-based verification), that is, generate a first password / first verification code, where the first password / first verification code includes the third threshold.
[0336] As an example, if the subscription information indicates that the terminal device has subscribed to the store-and-forward service and the second authentication method, but does not indicate that the terminal device has subscribed to the third threshold, the MME may select whether to generate first authorization information based on the second authentication method, the first information indicating the first authentication method in the fifth request message, and the second threshold ( FIG15 uses password / verification code-based authentication as an example), and which authentication method to generate first authorization information for, i.e., a first password / first verification code, where the first password / first verification code includes the second threshold. For example, if the first authentication method is the same as the second authentication method, the MME may generate the first password / first verification code based on the first authentication method (i.e., the second authentication method). If the first authentication method is different from the second authentication method, the MME may reject the terminal device's request to subscribe to the store-and-forward service, generate the first authorization information based on the second authentication method, or, with the user's consent, modify the authentication method subscribed to the terminal device and then generate the first authorization information based on the first authentication method, depending on the specific usage scenario, device functionality, and usage requirements.
[0337] As an example, when the contract information indicates that the terminal device has subscribed to a store-and-forward service, and indicates that the terminal device has subscribed to a second verification method and a third threshold, the MME may generate first authorization information based on the first information indicating the first verification method in the first request message, the second threshold, and the third threshold ( FIG15 takes the first verification method as an example of password / verification code-based verification), that is, generate a first password / first verification code, where the first password / first verification code includes a first threshold, and the first threshold is the same as the second threshold or the same as the third threshold. For example, if the second threshold is less than or equal to the third threshold, the first threshold is the same as the second threshold; if the second threshold is greater than the third threshold, the first threshold is the same as the third threshold.
[0338] Optionally, the first password / first verification code may also include identifiers of one or more satellites capable of providing a store-and-forward service for the terminal device, which is used by the MME to determine which satellites to send the first password / first verification code to and by the terminal device to determine which satellites to send uplink data to. As an example, the one or more satellites capable of providing a store-and-forward service for the terminal device may be determined by the HSS based on one or more of the following information: the terminal device's subscription information, the store-and-forward service capabilities of multiple satellites, and the ephemeris.
[0339] It should be noted that Figures 12-15 only use the 4G communication structure as an example, and the embodiments of this application do not limit the communication architecture used by the information storage method. For example, for a 5G communication architecture, the MME shown in Figures 12-15 can be replaced by an AMF, and the HSS can be replaced by a UDM; for example, in some examples, the MME shown in Figures 12-15 can be replaced by a network element that processes store-and-forward services, etc., without limitation.
[0340] Similar to the uplink satellite communication scenario, in the downlink satellite communication scenario, information storage can also be completed based on a similar interaction process.
[0341] As a possible embodiment, please refer to Figure 16. Figure 16 takes the first communication device as satellite 1, the second communication device is satellite 2, satellite 2 and satellite 3 are the same satellite, the first network element is AMF, the third network element is NRF, NRF is responsible for generating the second authorization information, and the second authorization information is an authorization token as an example, showing an interaction diagram of the implementation process of a method for storing information in a downlink satellite communication scenario provided by an embodiment of the present application.
[0342] As shown in FIG16 , the solution provided in this embodiment of the application may include S1601 to S1614:
[0343] S1601: The terminal device configures verification information, such as the operator's verification certificate or verification public key.
[0344] The terminal device configuration verification information is used for subsequent verification of the authorization token to verify the security of the data source.
[0345] S1602: Satellite 1 and Satellite 2 register the store-and-forward service module (S&F function) with the NRF.
[0346] Exemplarily, satellite 1 and satellite 2 may send registration information to the NRF. The registration information includes a network function instance identifier (NF instance ID) for identifying the store-and-forward service module. Optionally, the registration information may also include one or more of the following: an identifier indicating whether the satellite supports the store-and-forward service function, an identifier indicating the verification method supported by the satellite, a satellite identifier, the storage capacity of data supported by the satellite, and the service scope of the satellite (such as one or more of the terminal device identifier, slice identifier, service country identifier, and service region identifier). Correspondingly, the NRF may store the registration information of satellite 1 and satellite 2 locally, such as in an NF profile, for reference when subsequently generating authorization information.
[0347] It should be noted that Figure 16 only shows the relevant satellites 1 and 2. In actual applications, one or more other satellites may also be included. These satellites may also provide storage and forwarding services for terminal devices, and these satellites can also register the storage and forwarding service module (S&F function) with the NRF.
[0348] S1603: After accessing satellite 2, the terminal device sends a sixth request message to satellite 2. The sixth request message includes an identifier of the terminal device, information indicating a verification method supported / requested by the terminal device, and a second threshold.
[0349] The sixth request message is used to subscribe the terminal device to the store-and-forward service.
[0350] Exemplarily, the identification information of the terminal device includes but is not limited to IMSI, SUPI, SUCI or a temporary identification of the terminal device, etc., which is not specifically limited.
[0351] Exemplarily, the authentication methods supported / requested by the terminal device may include any one of the following: authentication based on an authorization token, authentication based on a password, or authentication based on a verification code.
[0352] Exemplarily, the second threshold is the maximum storage capacity of data requested by the terminal device, such as 2kB, 5 NAS messages, etc., which is not limited.
[0353] S1604: Satellite 2 sends a third response message to the terminal device.
[0354] The third response message is used to notify the terminal device to wait for a period of time. For example, the third response message may include a timer to notify the terminal device of the waiting time.
[0355] S1605: Satellite 2 determines the first verification method.
[0356] For a detailed introduction to S1605, please refer to the description of S1205 above.
[0357] S1606: When satellite 2 is connected to NRF, it sends a fourth request message to NRF. The fourth request message includes the network function instance identifier, the service scope of satellite 2 (such as one or more of the terminal device identifier, slice identifier, service country identifier, service area identifier, etc.), the first information for indicating the first verification method, and the second threshold.
[0358] The fourth request message is used to subscribe to the store-and-forward service.
[0359] S1607: The NRF generates an authorization token according to the registration information of satellite 2 and the fourth request message.
[0360] Among them, the authorization token includes the service scope corresponding to the authorization token, such as one or more of the terminal device identification, slice identification, service country identification, service area identification, etc. Figure 16 takes the authorization token including the terminal device identification as an example.
[0361] As an example, when the registration information of satellite 2 indicates that the satellite supports the fourth verification method and the fourth request message includes the second threshold, if the fourth verification method is the same as the first verification method, the NRF can generate second authorization information according to the fourth verification method (Figure 16 takes the fourth verification method as an example of verification based on the authorization token), that is, generate an authorization token, wherein the authorization token includes the second threshold.
[0362] As an example, when the registration information of satellite 2 indicates that the satellite supports the fourth verification method, and the fourth request message includes the first verification method and the second threshold, if the fourth verification method is the same as the first verification method, the NRF can generate the second authorization information according to the first verification method (that is, the fourth verification method) (Figure 16 takes the first verification method as an example of verification based on the authorization token), that is, generate an authorization token, wherein the authorization token includes the second threshold; if the fourth verification method is different from the first verification method, the NRF may reject the request, or generate the second authorization information according to the fourth verification method, depending on the specific usage scenario, device function, usage requirements, etc.
[0363] As an example, when the registration information of satellite 2 indicates that the satellite supports the fourth verification method and the storage capacity of the data supported by the satellite is the third threshold, and the fourth request message includes the first verification method, if the fourth verification method is the same as the first verification method, the NRF can generate the second authorization information according to the first verification method (that is, the fourth verification method) (Figure 16 takes the first verification method as an example of verification based on the authorization token), that is, generate an authorization token, wherein the authorization token includes the third threshold; if the fourth verification method is different from the first verification method, the NRF may reject the request, or generate the second authorization information according to the fourth verification method, depending on the specific usage scenario, device function, usage requirements, etc.
[0364] As an example, when the registration information of satellite 2 indicates that the satellite supports the fourth verification method and the storage capacity of the data supported by the satellite is the third threshold, and the fourth request message includes the first verification method and the second threshold, if the fourth verification method is the same as the first verification method and the second threshold is less than or equal to the third threshold, the NRF can generate the second authorization information according to the first verification method (i.e., the fourth verification method) (Figure 16 takes the first verification method as an example of verification based on the authorization token), that is, generate an authorization token, wherein the authorization token includes the second threshold; if the fourth verification method is the same as the first verification method and the second threshold is greater than the third threshold, the NRF can generate the second authorization information according to the first verification method (i.e., the fourth verification method) (Figure 16 takes the first verification method as an example of verification based on the authorization token), that is, generate an authorization token, wherein the authorization token includes the third threshold; if the fourth verification method is different from the first verification method and the second threshold is less than or equal to the third threshold, the NRF may reject the request, or generate the second authorization information including the second threshold according to the fourth verification method; if the fourth verification method is different from the first verification method and the second threshold is greater than the third threshold, the NRF may reject the request, or generate the second authorization information including the third threshold according to the fourth verification method.
[0365] S1608: NRF sends an authorization token to Satellite 1.
[0366] S1609: Satellite 1 saves the authorization token.
[0367] S1610: Satellite 1 receives a third request message from AMF, where the third request message includes the second data and an identifier of the terminal device.
[0368] Among them, the second data is the data sent by AMF to the terminal device, that is, downlink data.
[0369] As a possible scenario, when satellite 1 receives the third request message from the AMF, satellite 1 has no communication connection with the terminal device. In this case, satellite 1 executes S1611, or executes S1611 after sending a response message to the AMF. The response message is used to notify the AMF to wait for a period of time. For example, the response message may include a timer to notify the AMF of the waiting time. Exemplarily, the waiting time may be determined by the first communication device satellite 1 based on the time of connection with the terminal device determined according to the ephemeris, or based on other information, without specific limitation.
[0370] As a possible scenario, when satellite 1 receives the third request message from AMF, there is a communication connection between satellite 1 and the terminal device. In this case, the first communication device may not execute S1611 and forward the second data to the terminal device.
[0371] S1611: Satellite 1 determines second authorization information, such as an authorization token, based on the identifier of the terminal device.
[0372] As an example, the satellite 1 may store authorization information of one or more terminal devices, and the satellite 1 may determine the second authorization information therefrom according to an identification of the terminal device.
[0373] S1612: Satellite 1 sends second data and an authorization token to the terminal device.
[0374] The authorization token is used to verify the second data.
[0375] S1613: The terminal device verifies the authorization token.
[0376] The terminal device verifies the authorization token to determine the legitimacy of the source of the second data, and then determines whether to parse the second data.
[0377] As an example, the terminal device may be pre-configured with verification information corresponding to one or more authorization tokens. For example, the verification information corresponding to the authorization token may include an operator verification certificate or a verification public key. The terminal device may use the verification information corresponding to the authorization token to verify the authorization token.
[0378] S1614: When the authorization token verification is successful, the terminal device parses the second data.
[0379] It should be noted that Figure 16 only uses the 5G communication structure as an example, and the embodiments of this application do not limit the communication architecture used by the information storage method. For example, for the 4G communication architecture, the AMF shown in Figure 16 can be replaced by the MME; for example, in some examples, the NRF shown in Figure 16 can be replaced by other network elements E that handle store-and-forward services, etc., without limitation.
[0380] Optionally, S1202-S1210 shown in Figure 12, or S1202-S1205, S1301-S1302 and S1209-S1210 shown in Figure 13, or S1202-S1206, S1401-S1405 shown in Figure 14, or S1202-S1205, S1501-S1502 and S1404-S1405 shown in Figure 15 may also occur during the process of the terminal device registering with the network where the MME is located.
[0381] For example, please refer to Figure 17. Figure 17 takes the first communication device as satellite 1, the second communication device is satellite 2, satellite 2 and satellite 3 are the same satellite, the first network element (the same as the second network element) is MME, the fourth network element is HSS, HSS is responsible for generating the first authorization information, and the first authorization information is an authorization token as an example, showing an interaction diagram of the implementation process of a method for storing information in a network registration process provided by an embodiment of the present application.
[0382] As shown in FIG17 , the solution provided in the embodiment of the present application may include S1701-S1705 and S1206-S1214. For a detailed description of S1206-S1214, please refer to the above description; S1701-S1705 are described as follows:
[0383] S1701: Satellite 1 and satellite 2 configure verification information, such as the operator's verification certificate or verification public key.
[0384] S1702: After accessing satellite 2, the terminal device sends a first registration request message to satellite 2. The first registration request message includes an identifier of the terminal device, information indicating a verification method supported / requested by the terminal device, and a second threshold.
[0385] S1703: Satellite 2 sends a first registration response message to the terminal device.
[0386] S1704: Satellite 2 determines the first verification method.
[0387] S1705: When satellite 2 is connected to the MME, it sends a second registration request message to the MME. The second registration request message includes an identifier of the terminal device, first information for indicating the first verification method, and a second threshold.
[0388] For a detailed introduction to S1701-S1705, please refer to the description of S1201-S1205 above.
[0389] Optionally, each registration request message shown in FIG17 may be replaced by an Attch request message, and the registration response message shown in FIG17 may be replaced by an Attch response message.
[0390] Optionally, the first request message and the second request message shown in Figure 13, Figure 14, Figure 15, or Figure 16 may also be a registration request message or an Attch request message, and the second response message shown in Figure 13, Figure 14, Figure 15, or Figure 16 may also be a registration response message or an Attch response message. The fifth request message shown in Figure 15 may also be a registration request message or an Attch request message.
[0391] In specific implementations, each communication device in the embodiments of the present application (e.g., terminal equipment, satellite equipment, or ground station network elements) may adopt the structure shown in Figure 18, or include the components shown in Figure 18. Figure 18 is a schematic diagram of the hardware structure of a communication device applicable to the present application. The communication device includes at least one processor 1801 and at least one communication interface 1804 for implementing the method provided in the present application. The communication device may also include a communication line 1802 and a memory 1803.
[0392] The processor 1801 can be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits used to control the execution of the program of the present application.
[0393] The communication link 1802 may include a path for transmitting information between the above components, such as a bus.
[0394] Communication interface 1804 is used to communicate with other devices or communication networks. Communication interface 1804 can be any transceiver-like device, such as an Ethernet interface, a radio access network (RAN) interface, a wireless local area network (WLAN) interface, a transceiver, a pin, a bus, an interface circuit, or a transceiver circuit.
[0395] The memory 1803 may be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory may be independent and coupled to the processor 1801 via a communication line 1802. The memory 1803 may also be integrated with the processor 1801. The memory provided in this application may generally be non-volatile.
[0396] Among them, the memory 1803 is used to store computer-executable instructions involved in executing the solution provided by this application, and the execution is controlled by the processor 1801. The processor 1801 is used to execute the computer-executable instructions stored in the memory 1803, thereby implementing the method provided by this application. Alternatively, optionally, in this application, the processor 1801 may also perform the processing-related functions of the method provided below in this application, and the communication interface 1804 is responsible for communicating with other devices or communication networks, which is not specifically limited in this application.
[0397] Optionally, the computer-executable instructions in this application may also be referred to as application code, which is not specifically limited in this application.
[0398] The coupling in this application is an indirect coupling or communication connection between devices, units or modules, which can be electrical, mechanical or other forms, and is used for information exchange between devices, units or modules.
[0399] As an embodiment, the processor 1801 may include one or more CPUs, such as CPU0 and CPU1 in FIG18 .
[0400] As an embodiment, the communication device may include multiple processors, such as processor 1801 and processor 1807 in Figure 18. Each of these processors may be a single-core (single-CPU) processor or a multi-core (multi-CPU) processor. The processor here may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0401] As an embodiment, the communication device may further include an output device 1805 and / or an input device 1806. The output device 1805 is coupled to the processor 1801 and can display information in a variety of ways. For example, the output device 1805 can be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector. The input device 1806 is coupled to the processor 1801 and can receive user input in a variety of ways. For example, the input device 1806 can be a mouse, a keyboard, a touch screen device, or a sensor device.
[0402] It can be understood that the composition structure shown in Figure 18 does not constitute a limitation on the communication device. In addition to the components shown in Figure 18, the communication device may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.
[0403] It should be understood that the various schemes of the embodiments of the present application can be reasonably combined and used, and the explanations or descriptions of the various terms appearing in the embodiments can be referenced or explained with each other in the various embodiments, without limitation to this.
[0404] It should also be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0405] It is understandable that, in order to implement the functions of any of the above-mentioned embodiments, the terminal equipment, communication device or ground station network element includes the hardware structure and / or software module corresponding to the execution of each function. It should be easily appreciated by those skilled in the art that, in combination with the units and algorithm steps of each example described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0406] In the embodiments of the present application, electronic equipment, communication devices, or ground station network elements can be divided into functional modules. For example, different functional modules can be divided according to different functions, or two or more functions can be integrated into one processing module. The above-mentioned integrated modules can be implemented in the form of hardware or software functional modules.
[0407] For example, FIG19 illustrates a schematic diagram of the structure of a communication device, where the functional modules are divided in an integrated manner. The communication device includes an interface module 1901 and a processing module 1902. Interface module 1901, also known as an interface unit, performs transceiver operations and may be, for example, an interface circuit, a transceiver, a transceiver, or a communication interface. Processing module 1902, also known as a processing unit, performs operations other than transceiver operations and may be, for example, a processing circuit or a processor.
[0408] In some embodiments, the communication device may further include a storage module (not shown in FIG. 19 ) for storing program instructions and data.
[0409] Exemplarily, the communication device is used to implement the functions of a ground station network element (such as a first network element, a second network element, a third network element, etc.); or, the communication device is used to implement the functions of a communication device (such as a first communication device, a second communication device, a third communication device, etc.); or, the communication device is used to implement the functions of a terminal device.
[0410] When the communication device is used to implement the functions of a ground station network element, interface module 1901 is configured to receive a first request message, the first request message including an identifier of a terminal device; and to send first authorization information to the communication device, the first authorization information being used to determine whether to store data from the terminal device. For example, interface module 1901 may be configured to receive the first request message sent by the communication device in S902 and to execute S904.
[0411] In a possible implementation, the interface module 1901 is configured to send first authorization information to a second communication apparatus according to an identifier and an ephemeris of the terminal device.
[0412] In a possible implementation, the interface module 1901 is configured to send a fifth request message, where the fifth request message includes an identifier of the terminal device and is used to subscribe the terminal device to a store-and-forward service; and receive first authorization information.
[0413] In a possible implementation, the processing module 1902 is configured to determine the first authorization information according to the contract information of the terminal device.
[0414] When the communication device is used to implement the functions of the communication device, interface module 1901 is configured to receive first data and first authorization information, where the first data is data sent by the terminal device to the first network element. For example, interface module 1901 can be configured to execute S801. Processing module 1902 is configured to verify the first authorization information. For example, processing module 1902 can be configured to execute S802.
[0415] In a possible implementation, the interface module 1901 is configured to receive first authorization information from a ground station network element and send the first authorization information to a terminal device.
[0416] In a possible implementation, the interface module 1901 is configured to send a first request message to a ground station network element.
[0417] In a possible implementation, the processing module 1902 is configured to verify whether the amount of stored data from the terminal device is less than a first threshold.
[0418] In a possible implementation, the interface module 1901 is configured to send the stored first data to a ground station network element.
[0419] In one possible implementation, interface module 1901 is configured to receive a third request message from a ground station network element, the third request message including the second data and an identifier of the terminal device. Processing module 1902 is configured to determine second authorization information based on the identifier of the terminal device. Interface module 1901 is further configured to send the second data and second authorization information to the terminal device, the second authorization information being used to verify the second data.
[0420] In a possible implementation, the interface module 1901 is configured to send a fourth request message to the ground station network element, and receive second authorization information from the ground station network element.
[0421] When the communication device is used to implement the function of the terminal equipment, the interface module 1901 is used to: send first data and first authorization information to the communication device, the first data is the data sent by the terminal equipment to the first network element, and the first authorization information is used to determine whether to store the first data; and receive a first response message from the communication device, the first response message is used to indicate whether the first data is successfully stored.
[0422] In a possible implementation, the interface module 1901 is configured to send a second request message to the communication device, and receive first authorization information from the communication device.
[0423] In a possible implementation, the interface module 1901 is configured to receive the second data and the second authorization information from the communication device; and the processing module 1902 is configured to perform verification on the second authorization information.
[0424] It should be noted that the division of modules in the embodiments of the present application is schematic and is only a logical functional division. In actual implementation, there may be other division methods. It should also be understood that each module in the terminal equipment, communication device or ground station network element can be implemented in the form of software and / or hardware, and there is no specific limitation on this. In other words, the terminal equipment, communication device or ground station network element is presented in the form of functional modules. The "module" here can refer to a specific application integrated circuit ASIC, a circuit, a processor and memory that executes one or more software or firmware programs, an integrated logic circuit, and / or other devices that can provide the above functions.
[0425] In an optional manner, when data transmission is implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is implemented in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a digital video disk (DVD)), or a semiconductor medium (e.g., a solid state disk (SSD)).
[0426] The steps of the method or algorithm described in conjunction with the embodiments of the present application can be implemented in hardware or by executing software instructions by a processor. The software instructions can be composed of corresponding software modules, which can be stored in random access memory (RAM), flash memory, read-only memory (ROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM) memory, registers, hard disk, mobile hard disk, compact disc read-only memory (CD-ROM) or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and the storage medium can be located in an application specific integrated circuit (ASIC). In addition, the ASIC can be located in a terminal device, a communication device or a ground station network element. Of course, the processor and the storage medium can also exist as discrete components.
[0427] Through the description of the above implementation methods, technical personnel in the relevant field can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
Claims
1. A method for storing information, characterized in that: Applied to a first communication device, the method includes: receiving first data and first authorization information from a terminal device, where the first data is data sent by the terminal device to a first network element; The first data is stored when the verification of the first authorization information is successful.
2. The method according to claim 1, characterized in that The first authorization information includes an authorization token, and the method further includes: The authorization token is verified according to the verification information corresponding to the authorization token.
3. The method according to claim 1, characterized in that The first authorization information includes a first password, and the method further includes: obtaining a password set, the password set including one or more passwords; and determining that verification of the first authorization information is successful if the password set includes the first password; or, The first authorization information includes a first verification code, and the method further includes: obtaining a verification code set, where the verification code set includes one or more verification codes; and determining that verification of the first authorization information is successful if the verification code set includes the first verification code.
4. The method according to any one of claims 1 to 3, characterized in that The method further comprises: receiving the first authorization information from the second network element; Send the first authorization information to the terminal device.
5. The method according to claim 4, characterized in that Before receiving the first authorization information from the second network element, the method further includes: A first request message is sent to the second network element, where the first request message includes an identifier of the terminal device and first information, where the first information is used to indicate any one of the following: authentication based on an authorization token, authentication based on a password, or authentication based on a verification code, and the first request message is used to subscribe the terminal device to a store-and-forward service or to request that the terminal device be registered with the network where the second network element is located.
6. The method according to any one of claims 1 to 5, characterized in that The first authorization information includes a first threshold, and the method further includes: When the amount of stored data from the terminal device is less than the first threshold, it is determined that the verification of the first authorization information is successful.
7. The method according to any one of claims 1 to 6, characterized in that The method further comprises: Send the stored first data to the first network element.
8. The method according to any one of claims 1 to 7, characterized in that The method further comprises: receiving a third request message from the first network element, where the third request message includes second data and an identifier of the terminal device; determining second authorization information according to the identification of the terminal device; The second data and the second authorization information are sent to the terminal device, where the second authorization information is used to verify the second data.
9. The method according to claim 8, characterized in that The method further comprises: Sending a fourth request message to a third network element, where the fourth request message is used to subscribe the first communication device to a store-and-forward service; Receive the second authorization information from the third network element.
10. A method for storing information, characterized in that: Applied to a first communication device, the method includes: receiving a third request message from the first network element, where the third request message includes the second data and an identifier of the terminal device; determining second authorization information according to the identification of the terminal device; The second data and the second authorization information are sent to the terminal device, where the second authorization information is used to verify the second data.
11. The method according to claim 10, characterized in that The method further comprises: Sending a fourth request message to a third network element, where the fourth request message is used to subscribe the first communication device to a store-and-forward service; Receive second authorization information from the third network element.
12. The method according to claim 11, characterized in that The fourth request message includes first information, where the first information is used to indicate any one of the following verification methods: verification based on an authorization token, verification based on a password, or verification based on a verification code.
13. A method for storing information, characterized in that: Applied to a terminal device, the method includes: Sending first data and first authorization information to a first communication device, where the first data is data sent by the terminal device to a first network element, and the first authorization information is used to determine whether to store the first data; A first response message is received from the first communication device, where the first response message is used to indicate whether the first data is successfully stored.
14. The method according to claim 13, characterized in that The method further comprises: Sending a second request message to a second communication device, where the second request message includes an identifier of the terminal device and information indicating an authentication method supported by the terminal device, where the authentication method includes any one of the following: authentication based on an authorization token, authentication based on a password, or authentication based on a verification code, and the second request message is used to subscribe the terminal device to a store-and-forward service or to request that the terminal device be registered with the network where the first network element is located; The first authorization information is received from the second communication device.
15. The method according to claim 14, characterized in that The second request message also includes a second threshold, and the second request message is further used to request that the maximum storage capacity of data of the terminal device be the second threshold.
16. The method according to any one of claims 13 to 15, characterized in that The method further comprises: receiving second data and second authorization information from a third communication device; If the verification of the second authorization information is successful, the second data is parsed.
17. The method according to claim 16, characterized in that The second authorization information includes an authorization token, and the method further includes: The authorization token is verified according to the verification information corresponding to the authorization token.
18. A method for storing information, characterized in that: Applied to a terminal device, the method includes: receiving second data and second authorization information from a third communication device; If the verification of the second authorization information is successful, the second data is parsed.
19. The method according to claim 18, characterized in that The second authorization information includes an authorization token, and the method further includes: The authorization token is verified according to the verification information corresponding to the authorization token.
20. The method according to claim 19, characterized in that The method further comprises: A second request message is sent to a second communication device, wherein the second request message includes an identifier of the terminal device and information indicating a verification method supported by the terminal device, wherein the verification method includes any one of the following: authorization token-based verification, password-based verification, or verification code-based verification, and the second request message is used to subscribe the terminal device to a store-and-forward service.
21. A method for storing information, characterized in that: Applied to a first network element, the method includes: receiving a first request message from a first communication device, where the first request message includes an identifier of a terminal device; First authorization information is sent to one or more second communication devices according to the identification of the terminal device, where the first authorization information is used to determine whether to store data from the terminal device.
22. The method according to claim 21, characterized in that The first authorization information includes an authorization token, and the sending of the first authorization information to one or more second communication devices according to the identifier of the terminal device includes: The first authorization information is sent to a second communication device according to the identification and ephemeris of the terminal device.
23. The method according to claim 21, characterized in that The first authorization information includes a first password, and sending the first authorization information to one or more second communication devices according to the identification of the terminal device includes: sending the first password to multiple second communication devices according to the identification of the terminal device.
24. The method according to claim 21, characterized in that The first authorization information includes a first verification code, and sending the first authorization information to one or more second communication devices according to the identification of the terminal device includes: sending the first verification code to multiple second communication devices according to the identification of the terminal device.
25. The method according to any one of claims 21 to 24, characterized in that The method further comprises: Sending a fifth request message to a fourth network element, where the fifth request message includes an identifier of the terminal device, and the fifth request message is used to subscribe the terminal device to a store-and-forward service; Receive the first authorization information from the fourth network element.
26. The method according to claim 25, characterized in that The fifth request message further includes first information, where the first information is used to indicate any one of the following verification methods: verification based on an authorization token, verification based on a password, or verification based on a verification code.
27. The method according to claim 25 or 26, characterized in that The fifth request message also includes a second threshold, and the fifth request message is further used to request that the maximum storage capacity of data of the terminal device be the second threshold.
28. The method according to any one of claims 21 to 24, characterized in that The method further comprises: The first authorization information is determined according to the contract information of the terminal device.
29. The method according to claim 28, characterized in that The contract information includes a second verification method subscribed by the terminal device, where the second verification method includes any one of the following: verification based on an authorization token, verification based on a password, and verification code based on verification; The determining the first authorization information according to the contract information includes: The first authorization information is determined according to the second verification method.
30. The method according to any one of claims 21 to 29, characterized in that The first authorization information further includes a first threshold value, which is the maximum storage capacity of data of the terminal device.
31. The method according to claim 30, wherein The contract information includes a third threshold value subscribed by the terminal device, where the third threshold value is a maximum storage capacity of data subscribed by the terminal device. The determining the first authorization information according to the contract information includes: The first authorization information is determined according to the third threshold, where the first authorization information includes the first threshold, and the first threshold is the same as the third threshold.
32. A communication device, characterized in that: The communication device comprises: a memory for storing computer program instructions; A processor, configured to execute the computer program instructions to support the communication device in implementing the method according to any one of claims 1-9, 10-12, 13-17, 18-20, or 21-31.
33. A communication device, characterized in that: The communication device includes a unit or module for executing the method according to any one of claims 1-9 or 10-12, or includes a unit or module for executing the method according to any one of claims 13-17 or 18-20, or includes a unit or module for executing the method according to any one of claims 21-31.
34. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer program instructions, which, when executed by a processing circuit, implement the method according to any one of claims 1-9, 10-12, 13-17, 18-20, or 21-31.
35. A computer program product comprising instructions, characterized in that When the computer program product is run on a computer, the computer is caused to perform the method according to any one of claims 1 to 9, 10 to 12, 13 to 17, 18 to 20, or 21 to 31.
Citation Information
Patent Citations
Data storage method and equipment and computer readable storage medium
CN110351364A
Satellite communication method and system based on broadband store-and-forward mode
CN112332898A
Internet of Things information transmission method, terminal and system in low earth orbit satellite Internet of Things
CN113271558A
Authorization verification method and device
CN115706997A
Satellite antenna ground station service system
US20200007224A1