Wireless communication method and communication device
By deploying the first network element of the core network on the satellite to store the key, the security threat caused by intermittent connection of the feeder link in the satellite communication system is resolved, the complete authentication between the terminal device and the network is achieved, and the security of satellite storage and forwarding communication is improved.
Patent Information
- Application Number
- PCT/CN2024/086648
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-04-08
- Publication Date
- 2025-10-16
AI Technical Summary
In satellite communication systems, the intermittent connection characteristics of feeder links lead to incomplete mutual authentication between terminal devices and the network, posing a security threat.
A first network element of the core network, such as an HSS, is deployed on the first satellite, for storing a key associated with the first terminal device, and implementing a mutual authentication process between the terminal device and the network based on the key, so that the authentication process does not depend on the availability of the feeder link.
Even if the feeder link is interrupted, the mutual authentication process between the terminal device and the network can still be guaranteed to be complete, improving the security of satellite store-and-forward communications.
Smart Images

Figure CN2024086648_16102025_PF_FP_ABST
Abstract
Description
Wireless communication method and communication device TECHNICAL FIELD
[0001] The present application relates to the field of communication technology, and more particularly, to a wireless communication method and a communication device. BACKGROUND
[0002] Currently, a satellite communication system can support a saving and forward (S&F) function. However, in the satellite S&F operation, due to the intermittent connection characteristics of the feeder link (for example, when the terminal device is connected to the satellite, the feeder link between the satellite and the ground network is interrupted), a security threat can be caused.
[0003] SUMMARY
[0004] The present application provides a wireless communication method and a communication device. The various aspects involved in the present application are described below.
[0005] In a first aspect, a wireless communication method is provided, comprising: receiving, by a first network element of a core network, a first request message sent by a second network element of the core network, the first request message being used to request authentication of a first terminal device; and sending, by the first network element, a first response message to the second network element, the first response message containing an authentication vector; wherein the first network element and the second network element are both deployed on a first satellite, and the authentication vector is generated based on a first key, and the first key is a key associated with the first terminal device and stored by the first network element.
[0006] In a second aspect, a wireless communication method is provided, comprising: sending, by a second network element of a core network, a first request message to a first network element of the core network, the first request message being used to request authentication of a first terminal device; and receiving, by the second network element, a first response message sent by the first network element, the first response message containing an authentication vector; wherein the first network element and the second network element are both deployed on a first satellite, and the authentication vector is generated based on a first key, and the first key is a key associated with the first terminal device and stored by the first network element.
[0007] In a third aspect, a wireless communication method is provided, comprising: receiving, by a first terminal device, a second request message sent by a second network element of a core network, the second request message containing an authentication vector generated based on a first key; and verifying, by the first terminal device, the authentication vector; wherein the first key is a key associated with the first terminal device and stored by a first network element of the core network, and the first network element and the second network element are both deployed on a first satellite.
[0008] In a fourth aspect, a communication device is provided, the communication device being a first network element of a core network, the communication device comprising: a receiving unit, configured to receive a first request message sent by a second network element of the core network, the first request message being used to request authentication of a first terminal device; and the first network element sends a first response message to the second network element, the first response message comprising an authentication vector; wherein the first network element and the second network element are both deployed on a first satellite, and the authentication vector is generated based on a first key, and the first key is a key associated with the first terminal device and stored by the first network element.
[0009] In a fifth aspect, a communication device is provided, the communication device being a second network element of a core network, the communication device comprising: a sending unit, configured to send a first request message to a first network element of the core network, the first request message being used to request authentication of a first terminal device; and the second network element receives a first response message sent by the first network element, the first response message comprising an authentication vector; wherein the first network element and the second network element are both deployed on a first satellite, and the authentication vector is generated based on a first key, and the first key is a key associated with the first terminal device and stored by the first network element.
[0010] In a sixth aspect, a communication device is provided, the communication device being a first terminal device, the communication device comprising: a receiving unit, configured to receive a second request message sent by a second network element of a core network, the second request message comprising an authentication vector generated based on a first key; and the first terminal device verifies the authentication vector; wherein the first key is a key associated with the first terminal device and stored by a first network element of the core network, and the first network element and the second network element are both deployed on a first satellite.
[0011] In a seventh aspect, a communication device is provided, comprising a processor, a memory and a communication interface, the memory being configured to store one or more computer programs, and the processor being configured to invoke the computer programs in the memory to cause the communication device to perform some or all of the steps described in the methods of the various aspects.
[0012] In an eighth aspect, an embodiment of the present application provides a communication system, which comprises the communication device described above. In another possible design, the system can further comprise other devices interacting with the communication device in the solutions provided by the embodiments of the present application.
[0013] In a ninth aspect, an embodiment of the present application provides a computer-readable storage medium, which stores a computer program, and the computer program causes a computer to perform some or all of the steps in the methods of the various aspects.
[0014] In a tenth aspect, an embodiment of the present application provides a computer program product. The computer program product includes a non-transitory computer readable storage medium storing a computer program. The computer program is operable to cause a computer to execute some or all of the steps of the methods of any of the aspects described above. In some implementations, the computer program product can be a software installation package.
[0015] In an eleventh aspect, an embodiment of the present application provides a chip. The chip includes a memory and a processor. The processor can invoke and run a computer program from the memory to implement some or all of the steps described in the methods of any of the aspects described above.
[0016] In a twelfth aspect, an embodiment of the present application provides an apparatus. The apparatus includes a memory and a processor. The processor can invoke and run a computer program from the memory to implement some or all of the steps described in the methods of any of the aspects described above.
[0017] The first network element (such as an HSS) of the core network is deployed on the first satellite. The first network element can be used to store a first key, which is associated with the first terminal device. Then, the mutual authentication process between the first terminal device and the network is implemented according to the first key stored by the first network element, so that the mutual authentication process between the first terminal device and the network does not depend on the availability of the feeder link. That is, even if the feeder link is interrupted, the present solution can still ensure the integrity of the mutual authentication process between the network and the terminal device, which helps to improve the security of satellite store-and-forward communication. BRIEF DESCRIPTION OF DRAWINGS
[0018] FIG. 1A is an example diagram of a system architecture of a wireless communication system to which embodiments of the present application can be applied.
[0019] FIG. 1B is an example diagram of a system architecture of an NTN system to which embodiments of the present application can be applied.
[0020] FIG. 1C is an example diagram of a system architecture of another NTN system to which embodiments of the present application can be applied.
[0021] FIG. 2 is an example diagram of a system architecture of yet another NTN system to which embodiments of the present application can be applied.
[0022] FIG. 3 is an example diagram of a system architecture of yet another NTN system to which embodiments of the present application can be applied.
[0023] FIG. 4 is an example diagram of an attach procedure provided by an embodiment of the present application.
[0024] FIG. 5 is an example diagram of multiple satellite deployment under store-and-forward function provided by an embodiment of the present application.
[0025] FIG. 6 is a flowchart of a wireless communication method provided by an embodiment of the present application.
[0026] Figure 7 is a flow diagram illustrating a method of wireless communication according to another embodiment of the present application.
[0027] Figure 8 is a flow diagram illustrating a method of wireless communication according to yet another embodiment of the present application.
[0028] Figure 9 is a schematic diagram illustrating the structure of a communication device according to an embodiment of the present application.
[0029] Figure 10 is a schematic diagram illustrating the structure of a communication device according to another embodiment of the present application.
[0030] Figure 11 is a schematic diagram illustrating the structure of a communication device according to yet another embodiment of the present application.
[0031] Figure 12 is a schematic diagram illustrating the structure of an apparatus according to an embodiment of the present application. DETAILED DESCRIPTION
[0032] Communication system architecture
[0033] The technical solutions of the embodiments of the present application can be applied to various communication systems, for example: a global system of mobile communication (GSM) system, a code division multiple access (CDMA) system, a wideband code division multiple access (WCDMA) system, a general packet radio service (GPRS), a long term evolution (LTE) system, an advanced long term evolution (LTE-A) system, a new radio (NR) system, an evolved system of the NR system, an LTE-based access to unlicensed spectrum (LTE-U) system, an NR-based access to unlicensed spectrum (NR-U) system, a non-terrestrial network (NTN) system, a universal mobile telecommunication system (UMTS), a wireless local area networks (WLAN), a wireless fidelity (WiFi), a 5th-generation (5G) system, or other communication systems, for example, a future communication system such as a 6th-generation mobile communication system, or a satellite communication system, and the like.
[0034] Generally, a conventional communication system supports a limited number of connections, which is easy to implement. However, with the development of communication technology, a mobile communication system will not only support conventional communication, but also support, for example, device to device (D2D) communication, machine to machine (M2M) communication, machine type communication (MTC), vehicle to vehicle (V2V) communication, or vehicle to everything (V2X) communication, and the like. The embodiments of the present application can also be applied to these communication systems.
[0035] The communication system in the embodiments of the present application can be applied to a carrier aggregation (CA) scenario, can also be applied to a dual connectivity (DC) scenario, and can also be applied to a standalone (SA) network deployment scenario.
[0036] The communication system in the embodiments of the present application can be applied to an unlicensed spectrum, which can also be regarded as a shared spectrum, or can also be applied to a licensed spectrum, which can also be regarded as a dedicated spectrum.
[0037] The embodiments of the present application can be applied to an NTN system, and can also be applied to a terrestrial network (TN) system. As an example but not limitation, the NTN system includes an NR-based NTN system and an IOT-based NTN system.
[0038] The embodiments of the present application describe various embodiments in combination with network devices and terminal devices, wherein the terminal device can also be referred to as a user equipment (UE), an access terminal, a user unit, a user station, a mobile station, a mobile station (MS), a mobile terminal (MT), a remote station, a remote terminal, a mobile device, a user terminal, a terminal, a wireless communication device, a user agent or a user apparatus, etc.
[0039] In the embodiments of the present application, the terminal device can be a station (STATION, ST) in a WLAN, can be a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a wireless local loop (WLL) station, a personal digital assistant (PDA) device, a handheld device with wireless communication function, a computing device or other processing device connected to a wireless modem, a vehicle-mounted device, a wearable device, a terminal device in a next-generation communication system such as an NR network, or a terminal device in a future evolved public land mobile network (PLMN) network, etc.
[0040] In the embodiments of the present application, the terminal device can refer to a device providing voice and / or data connectivity to users, and can be used to connect people, things and machines, for example, handheld devices with wireless connection function, vehicle-mounted devices, etc. The terminal device in the embodiments of the present application can be a mobile phone, a tablet computer (Pad), a notebook computer, a palm computer, a mobile internet device (MID), a wearable device, a virtual reality (VR) device, an augmented reality (AR) device, a wireless terminal in industrial control, a wireless terminal in self driving, a wireless terminal in remote medical surgery, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, etc. Optionally, the terminal device can be used to act as a base station. For example, the terminal device can act as a scheduling entity, which provides sidelink signals between terminal devices in V2X or D2D, etc. For example, a cellular phone and a car communicate with each other using sidelink signals. The cellular phone and the smart home device communicate with each other without relaying the communication signals through the base station.
[0041] In the embodiments of the present application, the terminal device can be deployed on land, including indoor or outdoor, handheld, wearable or vehicle-mounted; can also be deployed on the water surface (such as ships, etc.); and can also be deployed in the air (such as on airplanes, balloons and satellites, etc.).
[0042] In the embodiments of the present application, the terminal device can be a mobile phone, a pad, a computer with wireless transceiving function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self driving, a wireless terminal device in remote medical, a wireless terminal device in smart grid, a wireless terminal device in transportation safety, a wireless terminal device in smart city, or a wireless terminal device in smart home, etc. The terminal device involved in the embodiments of the present application can also be referred to as a terminal, a user equipment (UE), an access terminal device, a vehicle-mounted terminal, an industrial control terminal, a UE unit, a UE station, a mobile station, a mobile station, a remote station, a remote terminal device, a mobile device, a UE, a wireless communication device, a UE agent, or a UE apparatus, etc. The terminal device can also be fixed or mobile.
[0043] By way of example and without limitation, the terminal device in the embodiments of the present application can also be a wearable device. The wearable device can also be referred to as a wearable smart device, which is a general term for devices that are designed and developed by applying wearable technology to daily wear, such as glasses, gloves, watches, clothing, and shoes, etc. The wearable device is a portable device that is directly worn on the body or integrated into the clothes or accessories of the user. The wearable device is not only a hardware device, but also has powerful functions through software support, data interaction, and cloud interaction. The general wearable smart device includes devices with full functions, large size, and the ability to realize complete or partial functions without relying on a smart phone, such as smart watches or smart glasses, etc., and devices that focus on a certain type of application function and need to be used in cooperation with other devices, such as smart phones, such as various smart wristbands, smart jewelry, and other devices for monitoring vital signs.
[0044] The network device in the embodiments of the present application can be a device for communicating with a terminal device, which can also be referred to as an access network device or a radio access network device, such as a network device, which can be a base station. The network device in the embodiments of the present application can refer to a radio access network (RAN) node (or device) that accesses a terminal device to a wireless network. The base station can broadly cover various names in the following or be replaced by the following names, such as: Node B (NodeB), evolved Node B (eNB), next generation Node B (gNB), relay station, access point, transmitting and receiving point (TRP), transmitting point (TP), master station MeNB, auxiliary station SeNB, multi-standard radio (MSR) node, home base station, network controller, access node, wireless node, access point (AP), transmission node, transceiver node, baseband unit (BBU), remote radio unit (RRU), active antenna unit (AAU), remote radio head (RRH), central unit (CU), distributed unit (DU), positioning node, etc. The base station can be a macro base station, a micro base station, a relay node, a donor node or the like, or a combination thereof. The base station can also refer to a communication module, modem or chip for being arranged in the foregoing device or apparatus. The base station can also be a mobile switching center and a device that undertakes a base station function in device-to-device (D2D), vehicle-to-everything (V2X), machine-to-machine (M2M) communication, network side device in 6G network, device that undertakes a base station function in future communication system, etc. The base station can support networks of the same or different access technologies. The embodiments of the present application do not limit the specific technology and specific device form adopted by the network device.
[0045] The base station can be fixed or mobile. For example, a helicopter or a drone can be configured to act as a mobile base station, and one or more cells can move according to the location of the mobile base station. In other examples, a helicopter or a drone can be configured to act as a device that communicates with another base station.
[0046] In some deployments, the network device in the embodiments of the present application can refer to a CU or a DU, or the network device includes a CU and a DU. The gNB can also include an AAU.
[0047] The network device and the terminal device can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; can also be deployed on water surface; can also be deployed on aircraft, balloons and satellites in the air. The scenarios in which the network device and the terminal device are located are not limited in the embodiments of the present application.
[0048] By way of example and not limitation, in the embodiments of the present application, the network device can have a mobile characteristic, for example, the network device can be a mobile device. In some embodiments of the present application, the network device can be a satellite, a balloon station. For example, the satellite can be a low earth orbit (LEO) satellite, a medium earth orbit (MEO) satellite, a geostationary earth orbit (GEO) satellite, a high elliptical orbit (HEO) satellite, etc. In some embodiments of the present application, the network device can also be a base station arranged at a position on land, water, etc.
[0049] In the embodiments of the present application, the network device can serve a cell, and the terminal device communicates with the network device through transmission resources (for example, frequency domain resources, or spectrum resources) used by the cell. The cell can be a cell corresponding to the network device (for example, a base station), and the cell can belong to a macro base station or a base station corresponding to a small cell. The small cell here can include a metro cell, a micro cell, a pico cell, a femto cell, etc., which have the characteristics of small coverage and low transmit power, and are suitable for providing high-speed data transmission services.
[0050] Exemplarily, FIG. 1A is a schematic diagram of an architecture of a communication system provided by the embodiments of the present application. As shown in FIG. 1A, the communication system 100 can include a network device 110, which can be a device communicating with a terminal device 120 (or a communication terminal, a terminal). The network device 110 can provide communication coverage for a specific geographic area, and can communicate with terminal devices located in the coverage area.
[0051] FIG. 1A exemplarily shows one network device and two terminal devices. In some embodiments of the present application, the communication system 100 can include multiple network devices and each network device can include other number of terminal devices within its coverage, which is not limited in the embodiments of the present application.
[0052] Exemplarily, FIG. 1B is a schematic diagram of another architecture of a communication system provided by the embodiments of the present application. Please refer to FIG. 1B, which includes a terminal device 1101 and a satellite 1102, and the terminal device 1101 and the satellite 1102 can communicate wirelessly. The network formed by the terminal device 1101 and the satellite 1102 can also be referred to as NTN. In the architecture of the communication system shown in FIG. 1B, the satellite 1102 can have the function of a base station, and the terminal device 1101 and the satellite 1102 can communicate directly. Under the system architecture, the satellite 1102 can be referred to as a network device. In some embodiments of the present application, the communication system can include multiple network devices 1102, and each network device 1102 can include other number of terminal devices within its coverage, which is not limited in the embodiments of the present application.
[0053] Exemplarily, FIG. 1C is a schematic diagram of another architecture of a communication system provided by the embodiments of the present application. Please refer to FIG. 1C, which includes a terminal device 1201, a satellite 1202 and a base station 1203, and the terminal device 1201 and the satellite 1202 can communicate wirelessly, and the satellite 1202 and the base station 1203 can communicate. The network formed by the terminal device 1201, the satellite 1202 and the base station 1203 can also be referred to as NTN. In the architecture of the communication system shown in FIG. 1C, the satellite 1202 can not have the function of a base station, and the communication between the terminal device 1201 and the base station 1203 needs to be relayed by the satellite 1202. Under this system architecture, the base station 1203 can be referred to as a network device. In some embodiments of the present application, the communication system can include multiple network devices 1203, and each network device 1203 can include other number of terminal devices within its coverage, which is not limited in the embodiments of the present application.
[0054] It should be noted that FIGS. 1A-1C only schematically show the system to which the embodiments of the present application are applicable. Of course, the method shown in the embodiments of the present application can also be applicable to other systems, for example, 5G communication system, LTE communication system, etc., which is not limited in the embodiments of the present application.
[0055] In some embodiments of the present application, the wireless communication system shown in FIG. 1A-FIG. 1C can further include a mobility management entity (MME), an access and mobility management function (AMF), and other network entities, which are not limited in the embodiments of the present application.
[0056] It should be understood that the devices with communication functions in the network / system in the embodiments of the present application can be referred to as communication devices. For example, the communication system 100 shown in FIG. 1A can include network devices 110 and terminal devices 120 with communication functions, which can be specific devices as described above, and will not be described here again. The communication devices can also include other devices in the communication system 100, such as network controllers, mobility management entities, and other network entities, which are not limited in the embodiments of the present application.
[0057] It should be understood that the "indication" mentioned in the embodiments of the present application can be direct indication, indirect indication, or can represent an associated relationship. For example, A indicates B, which can mean that B can be obtained through A, or A indirectly indicates B, for example, A indicates C, and B can be obtained through C, or A and B have an associated relationship.
[0058] In the description of the embodiments of the present application, the term "corresponding" can represent a direct or indirect corresponding relationship between the two, or an associated relationship between the two, or an indication and being indicated, configuration and being configured relationship.
[0059] The "configuration" in the embodiments of the present application can include at least one of system message, radio resource control (RRC) signaling, and media access control control element (MAC CE).
[0060] In some embodiments of the present application, "predefined" or "preset" can be implemented by pre-storing corresponding codes, tables or other means for indicating related information in devices (such as terminal devices and network devices), and the specific implementation manner is not limited in the present application. For example, the pre-defined can refer to the definition in the protocol.
[0061] In some embodiments of the present application, the "protocol" can refer to a standard protocol in the communication field, which can include LTE protocol, NR protocol, and related protocols applied to future communication systems, which are not limited in the present application.
[0062] Satellite access study
[0063] In the 3rd generation partnership project (3GPP) Release 19 (R19), service and system aspects working group 2 (SA2) and SA3 respectively initiated the study of 5G satellite access.
[0064] In 3GPP TR 23.700-29 of SA2, the key issues of satellite store-and-forward are studied. The store-and-forward satellite operation is suitable for providing latency-tolerant / non-real-time satellite service scenarios, such as cellular internet of things (CIOT), machine type communication (MTC), and Short Message Service (SMS) satellite service scenarios. The following will illustrate the satellite default access mode and the satellite store-and-forward mode in combination with FIG. 2 and FIG. 3.
[0065] Exemplarily, FIG. 2 is a schematic diagram of an architecture of the NTN system mentioned above. The NTN system 200 shown in FIG. 2 takes a satellite 210 as an air platform. As shown in FIG. 2, the satellite radio access network includes the satellite 210, a service link 220, a feeder link 230, a terminal device 240, a gateway (GW) 250, and a network 260 including a base station and a core network. Among them, the service link 220 refers to the link between the satellite 210 and the terminal device 240. The feeder link 230 refers to the link between the gateway 250 and the satellite 210.
[0066] The NTN architecture shown in FIG. 2 can be referred to as a bent-pipe transponder architecture. In this architecture, the base station is located on the earth behind the gateway 250, and the satellite 210 acts as a relay. The satellite 210 operates as a repeater that forwards the feeder link 230 signal to the service link 220, or forwards the service link 220 signal to the feeder link 230. That is, the satellite 210 does not have the function of the base station (such as the data storage function), and only when the service link 220 and the feeder link 230 are connected at the same time, the terminal device 240 and the network 260 can interact with the data signal.
[0067] Exemplarily, FIG. 3 is another schematic diagram of an architecture of an NTN system. As shown in FIG. 3, the satellite radio access network 300 includes a satellite 310, a service link 320, a feeder link 330, a terminal device 340, a gateway 350, and a network 360. Different from the NTN system 200 in FIG. 2, in the NTN system 300, the satellite 310 has a base station (supporting the function of data storage).
[0068] The NTN architecture shown in FIG. 3 can be referred to as a regenerative transponder architecture. In this architecture, the data signal transmission between the service link 320 and the feeder link 330 can be separated. That is, the data signal interaction between the terminal device 340 and the network 360 is divided into two steps: step A and step B. In step A, if the service link 320 is connected, the data signal interaction between the terminal device 340 and the satellite 310 can be performed without requiring the feeder link 330 to be connected at the same time; in step B, if the feeder link 330 is connected, the data signal interaction between the satellite 310 and the network 360 can be performed without requiring the service link 320 to be connected at the same time. Of course, if the service link 320 and the feeder link 330 are connected at the same time, the satellite 310 can also operate as a repeater to forward the signal of the feeder link 330 to the service link 320, or forward the signal of the service link 320 to the feeder link 330.
[0069] It should be noted that the communication system in the architectures shown in FIG. 2 and FIG. 3 can include multiple network devices, and each network device can include other numbers of terminal devices within its coverage, which is not limited by the embodiments of the present application.
[0070] For the above-mentioned store-and-forward satellite operation, the main research contents of SA2 are as follows:
[0071] (1) What core network elements must be placed on the satellite to provide store-and-forward satellite services.
[0072] (2) Whether and how to trigger store-and-forward satellite operations, and how to perform store-and-forward satellite operations.
[0073] (3) What improvements are needed to related terminal devices and network procedures to support store-and-forward satellite operations (such as whether to notify the terminal device when the store-and-forward satellite service is applied).
[0074] It should be noted that the store-and-forward of IoT NTN in the evolved packet system (EPS) can be studied first, and if there is remaining time available, the store-and-forward of NR NTN can be studied. In the following, the above-mentioned main research contents of SA2 are exemplarily illustrated taking the 4G system as an example, and of course, the 5G system can also be extended.
[0075] For the core network element placement problem mentioned in (1) above, the current solution in TR23.700-29 can be divided into two categories, the first category is to place MME on the satellite, since the MME is located on the satellite, the MME is called non-terrestrial (NT) MME (MME-NT), the second category is to place MME-NT and non-terrestrial home subscriber server (HSS) (HSS-NT) on the satellite.
[0076] For example, in the related art, a scheme is proposed that when the MME and HSS are deployed on the satellite in the store-and-forward mode, the terminal device performs an attach procedure, and the basic assumptions are as follows:
[0077] The eNB, MME and HSS are placed on the same satellite; the eNB on board broadcasts that it is in the store-and-forward satellite operation mode; the terminal device has a subscription and a credential in the HSS on board, and the HSS on board synchronizes with the ground HSS when the feeder link is available; the single-satellite deployment use case, the terminal device only accesses one satellite, and the satellite maintains the non-access stratum (NAS) and access stratum (AS) state of the terminal device; roaming is not supported.
[0078] The above-mentioned scheme of the terminal device performing the attach procedure will be described in detail below in conjunction with FIG. 4.
[0079] Referring to FIG. 4, in step S402, the eNB on board broadcasts that it is in the store-and-forward satellite operation mode.
[0080] In step S404, after receiving the above-mentioned broadcast message, the terminal device (UE) sends an attach request message to the eNB on board, and the attach request message carries the store-and-forward capability of the terminal device.
[0081] In step S406, the eNB on board forwards the above-mentioned attach request message to the MME on board.
[0082] In step S408, the authentication / security procedure is performed between the terminal device and the MME on board through the HSS on board.
[0083] In step S410, the MME on board sends an attach accept message to the terminal device, and the attach accept message carries the store-and-forward capability.
[0084] In step S412, the terminal device sends an attach complete message to the MME on board.
[0085] At step S414, if the terminal device includes an Evolved Packet System Session Management (ESM) message container in the attach request at step S404, the onboard MME sends a create session request message and a modify bearer request message to the service gateway (SGW) when the feeder link is available, as specified in section 5.3.2.1 of TS 23.401.
[0086] At step S416, the packet data network gateway (PGW) sends a create session request message and a modify bearer request message to the PGW, as specified in section 5.3.2.1 of TS 23.401.
[0087] At step S418, the PGW returns a create session request message and a modify bearer request message to the SGW, as specified in section 5.3.2.1 of TS 23.401.
[0088] At step S420, the SGW returns a create session request message and a modify bearer request message to the onboard MME, as specified in section 5.3.2.1 of TS 23.401.
[0089] At step S422, downlink data can be sent from the S / PGW to the onboard MME. The onboard MME receives and stores the downlink data for the terminal device.
[0090] At step S424, when the service link is available, i.e., the satellite covers the tracking area in which the terminal device is registered, the onboard MME sends a paging message to the onboard eNB. If the onboard eNB receives the paging message from the onboard MME, the terminal device is paged by the onboard eNB.
[0091] At step S426, the terminal device establishes a radio bearer for downlink data transmission.
[0092] At step S428, an S1-MME path is established for downlink data transmission.
[0093] At step S430, the onboard MME sends the downlink data to the terminal device.
[0094] At step S432, uplink data can also be sent to the onboard MME.
[0095] In 3GPP TR 33.700-29, SA3 studies the key issues for satellite store-and-forward security. It should be understood that without authentication, confidentiality, integrity, and anti-replay protection, the communication between terminal devices, satellite-borne 3GPP systems, and ground 3GPP systems is not secured.
[0096] In the satellite store-and-forward operation, due to the intermittent connection characteristics of the feeder link (e.g., when the terminal device is connected to the satellite, the feeder link between the satellite and the ground network is interrupted), security threats can be caused. On the one hand, the existing EPS / 5G authentication and key agreement (AKA) procedure can not be completed completely, resulting in an incomplete mutual authentication process between the network and the terminal device. On the other hand, due to the interruption of the NAS connection between the terminal device and the MME / AMF, the NAS security mode command (SMC) procedure is not completed completely, resulting in an incomplete security capability negotiation between the terminal device and the EPS / 5G core network.
[0097] Therefore, the complete mutual authentication of the terminal device and the 3GPP network in the satellite store-and-forward operation is a technical problem to be solved.
[0098] To solve the above problems, the embodiment of the present application deploys a first network element (such as an HSS) of a core network on a first satellite. The first network element can be used to store a first key, and the first key is associated with a first terminal device. Then, the mutual authentication process between the first terminal device and the network is implemented according to the first key stored by the first network element, so that the mutual authentication process between the first terminal device and the network is not dependent on the availability of the feeder link. That is, even if the feeder link is interrupted, the present solution can still ensure that the mutual authentication process between the network and the terminal device is complete, which helps to improve the security of satellite store-and-forward communication.
[0099] The embodiment of the present application deploys a first network element of a core network on a first satellite. That is, the first network element can be an airborne network element or a satellite-borne network element. The first network element can be used to store a first key, or the first network element can be preconfigured with the first key. The first key is associated with a first terminal device. Taking a 4G network as an example, the first network element can be an HSS. Taking a 5G network as an example, the first network element can be a user data management (UDM), or an authentication server function (AUSF), etc. Of course, in addition to using existing network elements, the first network element can also be a newly defined network element.
[0100] The first network element can be configured to implement authentication (or security authentication) between the first terminal device and the network (3GPP network or core network). The authentication mentioned herein can be implemented based on an authentication and key agreement procedure. For example, in a 4G network, the authentication between the first terminal device and the network can be implemented based on EPS AKA. For example, in a 5G network, the authentication between the first terminal device and the network can be implemented based on a 5G AKA procedure. Illustratively, an AKA procedure can be run on the first network element, and the authentication between the first terminal device and the network can be implemented based on the AKA procedure.
[0101] The first key can also be referred to as a security credential associated with the first terminal device. The first key can be used to generate one or more of an authentication vector (AUTH), an expected response (XRES), and the like. For example, after the first network element receives a first request message (such as an authentication request message), a random number (RAND) can be generated, and parameters such as AUTH, XRES, and the like can be generated based on the first key.
[0102] Embodiments of the present application deploy the first network element on a satellite, so that the first terminal device can be authenticated based on the first key stored by the first network element. That is, based on the first network element deployed on the satellite, complete authentication of the first terminal device can be implemented when the service link is available, thereby providing security protection for communication between the first terminal device and the network.
[0103] In addition to deploying the first network element on the first satellite, in order to facilitate communication between the first network element and the first terminal device, an access network element and a second network element (which can be the same network element as the first network element or a different network element) of the core network can also be deployed on the first satellite. The access network element can be, for example, an eNB or a gNB. The second network element can be, for example, a mobility management network element such as an MME or an AMF. The first request message (such as an authentication request message) mentioned above can be sent by the second network element to the first network element.
[0104] The first satellite can be any one of a plurality of satellites deployed by a satellite company or operator. In addition to the first satellite, the first network element can also be deployed on other satellites (of course, in addition to the first network element, an access network element and a second network element can also be deployed on other satellites). The first network element on other satellites can also be used to store the key associated with the first terminal device. The following will be described illustratively in conjunction with FIG. 5.
[0105] Exemplarily, referring to FIG. 5, the plurality of satellites can include a first satellite and a second satellite. The first satellite can deploy network elements such as HSS, MME and eNB. Among them, the HSS deployed on the satellite can be referred to as HSS-NT, and the MME deployed on the satellite can be referred to as MME-NT. In some implementations, the HSS, MME and eNB and the like network elements can also be deployed on the third satellite. It should be understood that in the NTN system shown in FIG. 5, a ground station (such as a gateway) and a terminal device are also included.
[0106] The embodiments of the present application do not make specific limitations on the configuration mode of the key associated with the first terminal device on different satellites, and the configuration mode of the key associated with the first terminal device on different satellites is exemplarily illustrated below by taking the second satellite as an example. In the following, the key associated with the first terminal device stored by the first network element on the second satellite is referred to as the second key.
[0107] Implementation one: the first key is the same as the second key
[0108] The implementation one sets the keys associated with the terminal device stored on different satellites to the same key, which can simplify the authentication process.
[0109] In some implementations, the first key can be the same as the third key. The third key mentioned here is the key stored by the first terminal device, and the third key can be used for authentication between the first terminal device and the network. For example, after the first terminal device receives the authentication vector (generated based on the first key mentioned above) sent by the network, the authentication vector can be verified based on the third key.
[0110] In some implementations, the first key can be the permanent root key K of the first terminal device. Further, in some implementations, the second key and / or the third key can also be the permanent root key K of the first terminal device.
[0111] In some implementations, the first key can be the key MK (such as a key specially used for the satellite store-and-forward mode) of the first terminal device for the satellite store-and-forward mode. Further, in some implementations, the second key and / or the third key can also be the key MK. The key MK can be determined based on the permanent root key K of the first terminal device (such as an intermediate key derived based on the permanent root key K).
[0112] Implementation two: the first key is different from the second key
[0113] The implementation two sets the keys associated with the terminal device stored on different satellites to different keys, which is equivalent to securely isolating different satellites. When one satellite is hijacked, it will not affect the security of other satellites.
[0114] In some implementations, the first key and the second key can be designed such that the second key cannot be derived based on the first key.
[0115] In some implementations, the first key can be different from a third key. The third key mentioned herein is a key stored by the first terminal device, and the third key can be used for authentication between the first terminal device and the network. For example, after the first terminal device receives an authentication vector (generated based on the first key mentioned above) sent by the network, the authentication vector can be verified based on the third key.
[0116] In some implementations, the third key can be a permanent root key K of the first terminal device. Further, in some implementations, the first key and / or the second key can be determined based on the permanent root key K. For example, the first key and / or the second key can be derived based on the permanent root key K.
[0117] In some implementations, the third key can be a key MK (such as a key specifically used for the satellite store-and-forward mode) of the first terminal device for the satellite store-and-forward mode. The key MK can be determined based on the permanent root key K of the first terminal device (such as an intermediate key derived based on the permanent root key K). Further, in some implementations, the first key and / or the second key can be determined based on the key MK. For example, the first key and / or the second key can be derived based on the key MK.
[0118] In some implementations, in the case where the first key is different from the third key, the first terminal device can determine the third key based on the first key (such as derive the first key based on the third key) in order to verify the authentication vector generated based on the first key.
[0119] For example, the first terminal device can be pre-configured with a table of functions f(n), different satellites can correspond to different f(n) values, and n represents the nth satellite. The first key can be derived based on the third key and f(n), and the authentication vector can be verified based on the first key.
[0120] For another example, the network (such as the second network element mentioned above) can carry information used to derive the first key (such as identification information of the first satellite) in a message (such as an authentication request message) sent to the first terminal device.
[0121] The above mainly takes the first terminal device as an example to introduce the key storage mode on the satellite in detail. It can be understood that, in addition to the first terminal device, the core network service can also serve other terminal devices. In some implementation manners, all keys (or subscription information) associated with terminal devices of the core network service can be stored on one satellite. In this way, when the service link is available, the satellite can implement security authentication of any terminal device without obtaining the key of the terminal device from the network element (such as HSS) deployed on the ground when the feeder link is available, thereby simplifying the implementation of the authentication process.
[0122] However, since the storage space on the satellite is limited, directly storing the subscription information of all terminal devices in the same satellite has a higher requirement on the storage capacity of the satellite and is difficult to be managed and maintained. Therefore, in other implementation manners, one satellite can only store the keys (or subscription information) associated with part of terminal devices of the core network service.
[0123] If one satellite only stores the keys associated with part of terminal devices of the core network service, the satellite can only serve the part of terminal devices. In this way, the satellite does not need to obtain the key of the terminal device from the network element (such as HSS) deployed on the ground when the feeder link is available, thereby simplifying the implementation of the authentication process.
[0124] Or, if one satellite only stores the keys associated with part of terminal devices of the core network service, the satellite can serve more (such as all) terminal devices by dynamically updating the stored keys. For example, the satellite can interact with the network element (such as HSS) deployed on the ground when the feeder link is available, so as to obtain the required key of the terminal device in time.
[0125] Next, combined with FIG. 6, the embodiments of the present application are illustrated in detail from the perspective of network element interaction.
[0126] Referring to FIG. 6, in step S610, the second network element sends a first request message to the first network element. The first request message can be referred to as an authentication request message, and the first request message is used to request to authenticate the first terminal device.
[0127] In some implementation manners, the first request message can carry first indication information and / or identification information of the first terminal device. The first indication information can be used to indicate that the first terminal device supports the storage forwarding mode of the satellite. The identification information of the first terminal device can be, for example, an international mobile subscriber identity (IMSI).
[0128] In some implementations, the first request message can be sent by the first network element after receiving an attach request or a registration request from the terminal device.
[0129] Continuing to refer to FIG. 6, at step S620, the first network element sends a first response message to the second network element. The first response message is a response message to the first request message mentioned above. The first response message can include an authentication vector (AUTH). The authentication vector is generated by the first network element based on the first key. In addition to the authentication vector, the first response message can also include RAND and / or XRES generated by the first network element.
[0130] In some implementations, the method of FIG. 6 can further include step S630, i.e., the second network element sends a second request message to the first terminal device. The second request message can contain an authentication vector generated based on the first key. The second request message can be an authentication request message. In addition to the authentication vector, the second request message can also contain RAND generated by the first network element. The second request message can be sent by the second network element after receiving the first response message.
[0131] In some implementations, the method of FIG. 6 can further include step S640, i.e., the first terminal device verifies the authentication vector. For example, if the third key stored by the first terminal device is the same as the first key, the first terminal device can directly verify the authentication vector based on the third key. For another example, if the third key stored by the first terminal device is different from the first key, the first terminal device can derive the first key based on the third key, and then verify the authentication vector based on the first key.
[0132] The embodiments in the present application will be described in more detail below with reference to FIG. 7 and FIG. 8. It should be noted that the examples of FIG. 7 and FIG. 8 are only to help those skilled in the art understand the embodiments of the present application, and are not intended to limit the embodiments of the present application to the specific values or specific scenarios illustrated. Those skilled in the art can obviously make various equivalent modifications or changes to the examples given in FIG. 7 and FIG. 8, and such modifications or changes also fall within the scope of the embodiments of the present application.
[0133] Example One
[0134] As shown in FIG. 7, the terminal device can interact with the satellite to complete the authentication process based on satellite-based broadcast information when the service link is available. In this embodiment, the HSS on the satellite stores the subscription data and security credentials of all terminal devices, so there is no need to obtain the security credentials of the terminal device from the HSS deployed on the ground through the feeder link. Specifically, it can include the following steps.
[0135] In step S701, the security credential pre-configuration is performed on the terminal device (UE) and HSS-NT side respectively.
[0136] The security credential pre-configuration on the terminal device side is as follows:
[0137] a. Pre-configure a first key, which can be a master key (MK) specially allocated for the store-and-forward satellite service (refer to 33.401 IOPS), or a user permanent root key K, or a key K_sat derived based on the root key K.
[0138] b. A PLMN identity (ID) allocated for the store-and-forward satellite operation.
[0139] c. A terminal device ID, such as IMSI.
[0140] d. A satellite ID.
[0141] e. In the user service identity module (USIM) of the terminal device, store a function f(n) table dedicated to the store-and-forward satellite operation, which is used to derive the second key. The function f(n) refers to TS 33.401 Appendix A.17 and Appendix F. The table can be updated through over the air technology (OTA).
[0142] It should be understood that if the terminal device side does not have the function f(n) table for the nth satellite, the f(n) value (or satellite identification information of the nth satellite) carried by the authentication return message can also be used to generate the second key.
[0143] The security credential pre-configuration on the HSS-NT side is as follows:
[0144] a. Pre-configure a second key, which can be derived from the first key. If there are n satellites with different HSS-NTs, such as HSS-NT_1, …, HSS-NT_n (nth HSS-NT), each satellite-borne HSS-NT_n configures a second key K_n. Where a certain function value f(n) of n and the first key (such as K, MK, K_sat, etc.) can be used as input to derive the key K_n, so all K_n are different, and K_n cannot be inferred from MK, nor can any K_m (m is different from n) be inferred. The key derivation function can be determined based on the key derivation function (KDF) in TS 33.401 F.4.2 section.
[0145] b. PLMN ID allocated for store-and-forward satellite operation.
[0146] c. Terminal device ID, such as IMSI.
[0147] d. Satellite ID.
[0148] At step S702, when the service link between the satellite and the terminal device is available, the satellite broadcasts one or more of the following messages to the target area:
[0149] a. Store-and-forward satellite operation indication, which can be used to indicate that the satellite is in store-and-forward mode, or that the satellite supports store-and-forward mode.
[0150] b. Satellite identification information.
[0151] c. Terminal device identification information or terminal device group identification served by the satellite.
[0152] At step S703, if the terminal device supports store-and-forward mode, the terminal device sends an attach request message to the satellite. The terminal device can identify a satellite that serves it in one or more of the following ways.
[0153] a. The terminal device is locally configured with all satellite identification information (such as serving satellite ID list) that serves it, and the satellite identification that the terminal device listens to from the broadcast message is in its locally pre-configured serving satellite ID list.
[0154] b. The terminal device listens to its identification information or the identification information of the group it belongs to.
[0155] The above-mentioned attach request message contains one or more of the following information.
[0156] a. Whether to support store-and-forward satellite operation.
[0157] b. Terminal device identification information, such as a subscription permanent identifier (SUPI), a subscription concealed identifier (SUCI), a permanent equipment identifier (PEI), a temporary mobile subscriber identity (TMSI), a globally unique temporary UE identity (GUTI), a 5G standalone equipment (SAE) temporary mobile subscriber identity (5G-S-TMSI), a globally unique AMF identity (GUAMI), and the like, used to identify terminal devices.
[0158] c. Group identification information, such as identification information of a group to which the terminal device belongs.
[0159] d. Satellite identification information.
[0160] At step S704, the access network device on the satellite sends the above-mentioned attach request message to the MME (MME-NT) deployed on the satellite. The MME-NT checks whether the terminal device has the capability to support store-and-forward satellite operation, and if not, rejects the above-mentioned attach request using an appropriate cause value.
[0161] At step S705, the MME-NT sends an authentication request message to the HSS-NT on the satellite, the authentication request message including the store-and-forward capability, the IMSI, and a service node (SN) ID.
[0162] At step S706, the HSS-NT generates an authentication vector (AV), the AV including: an authentication vector AUTH generated based on a pre-configured second key K_n, a random number RAND, an XRES, and the like; (other than the key used, the same as the existing EPS AKA protocol).
[0163] At step S707, the HSS-NT returns an authentication response message to the MME-NT, the message carrying the RAND, the AUTH, the XRES, derived keys, and the like. If the terminal device does not have a function f(n) table, the authentication response message can optionally also include the function f(n) table and the like; (the same as the existing EPS AKA protocol).
[0164] At step S708, the MME-NT stores the XRES, and then sends an authentication request message to the ground terminal device, which will carry the RAND, AUTH, etc.; of course, the authentication request message can also carry the function f(n) table.
[0165] At step S709, steps S709a, S709b and S709c are included.
[0166] At step S709a, the ground terminal device looks up the table if there is a function f(n) table, and then derives the second key based on the first key; if there is no function f(n) table, the function f(n) table carried in the authentication request message at step S708 is used; if neither the function f(n) table nor the authentication request message at step S708 carries the function f(n) table, the identity of the nth satellite can also be used as an output parameter to derive the second key K_n.
[0167] At step S709b, the terminal device verifies the AUTH.
[0168] At step S709c, the terminal device calculates a response (RES).
[0169] At step S710, if the terminal device verifies the network successfully, an authentication response message is sent to the MME-NT, which carries the RES; if not, an authentication failure message is sent.
[0170] At step S711, the MME-NT verifies the RES and the XRES.
[0171] At step S712, the MME-NT sends a NAS SMC to the terminal device.
[0172] At step S713, the terminal device derives the NAS key.
[0173] At step S714, the terminal device sends a NAS SMC complete message to the MME-NT.
[0174] At step S715, the eNB sends an RRC SMC to the UE.
[0175] At step S716, the terminal device derives the RRC key.
[0176] At step S717, the terminal device sends an RRC SMC complete message to the eNB.
[0177] It should be noted that steps S710-S717 are the same as the existing EPS AKA protocol.
[0178] Example Two
[0179] The terminal device can interact with the satellite to complete the authentication process based on the satellite broadcast information when the service link is available. In this embodiment, the HSS on the satellite stores the security credentials of part of the terminal devices, and the satellite can only serve these part of the terminal devices, so it is not necessary to obtain the security credentials of the terminal device from the ground-deployed HSS through the feeder link.
[0180] The security credential pre-configuration on the terminal device and the HSS-NT is the same as that in Example One, except that this Example Two only stores the security credentials of part of the terminal devices.
[0181] It should be noted that the other steps are different from those in Example One in that, if the HSS-NT does not store the security credentials of the requesting terminal device, and the satellite can only serve the terminal devices storing the security credentials, an authentication failure message is returned after the above step S705.
[0182] Example Three
[0183] As shown in FIG. 8, the security credentials of part of the terminal devices are stored on each satellite, and if the satellite can serve all the terminal devices, the satellite needs to interact with the ground-deployed HSS in time to obtain the required security credentials of the terminal devices.
[0184] The difference between Example Three and Example One is that, when the terminal device accesses the nth satellite (such as the first satellite), if there is no security credential, an authentication failure message is sent (such as step S806 in FIG. 8). At this time, the following operations can be performed:
[0185] (1) When the feeder link of the first satellite is available, the first satellite obtains the security credentials of the failed terminal device from the ground HSS (such as step S807 in FIG. 8); then, the terminal device will continue to connect to the second satellite.
[0186] (2) When the terminal device and the feeder link of the mth satellite (such as the second satellite) are available, the authentication process is continued; if the second satellite still does not have the security credentials of the terminal device, the second satellite continues to obtain the security credentials of the terminal device from the ground. Of course, if the second satellite has the security credentials, the authentication is completed in the manner of Example One. It should be understood that if connected to the mth satellite, the satellite m can be the nth satellite in the last round.
[0187] It should be noted that if all the satellites do not have the security credentials, after a round, the terminal device re-finds the first satellite for authentication, at this time all the satellites have the security credentials of the terminal device.
[0188] It should be noted that in FIG. 8, the steps before step S806 and after step S814 are the same as the corresponding steps in FIG. 7.
[0189] The method embodiments of the present application are described in detail above in combination with FIGS. 1 to 8, and the device embodiments of the present application are described in detail below in combination with FIGS. 9 to 12. It should be understood that the description of the method embodiments and the description of the device embodiments correspond to each other, and therefore, the parts not described in detail can be referred to the foregoing method embodiments.
[0190] FIG. 9 is a structural schematic diagram of a communication device provided by an embodiment of the present application. The communication device 900 shown in FIG. 9 can be a first network element of a core network, and the communication device 900 can include a receiving unit 910. The receiving unit 910 is configured to receive a first request message sent by a second network element of the core network, the first request message being used to request authentication of a first terminal device; the first network element sends a first response message to the second network element, the first response message containing an authentication vector; wherein the first network element and the second network element are both deployed on a first satellite, the authentication vector is generated based on a first key, and the first key is a key associated with the first terminal device and stored by the first network element.
[0191] Optionally, the first key is the same as a second key, and the second key is a key associated with the first terminal device and stored by a first network element on a second satellite.
[0192] Optionally, the first key is the same as a third key, the third key is a key stored by the first terminal device, and the third key is used to verify the authentication vector.
[0193] Optionally, the first key is a permanent root key of the first terminal device.
[0194] Optionally, the first key is a key of the first terminal device for a satellite store-and-forward mode.
[0195] Optionally, the first key is different from a second key, and the second key is a key associated with the first terminal device and stored by a first network element on a second satellite.
[0196] Optionally, the first key is different from a third key, the third key is a key stored by the first terminal device, and the third key is used to verify the authentication vector.
[0197] Optionally, the third key is a permanent root key of the first terminal device, and the first key is determined based on the third key.
[0198] Optionally, the third key is a key of the first terminal device for a satellite store-and-forward mode, and the first key is determined based on the third key.
[0199] Optionally, the first key is determined based on identification information of the first satellite and the third key.
[0200] Optionally, the first satellite stores keys associated with all terminal devices served by the core network.
[0201] Optionally, the first satellite stores keys associated with some terminal devices served by the core network.
[0202] Optionally, the first satellite only serves some of the terminal devices.
[0203] Optionally, the first key is obtained by the first satellite from a network element deployed on the ground when a feeder link of the first satellite is available.
[0204] Optionally, the first network element and the second network element are the same network element or different network elements.
[0205] Optionally, the receiving unit 910 may be a processor 910. The communication device 1200 may further include a memory 1220 and a transceiver 1230, as specifically shown in FIG12 .
[0206] Figure 10 is a schematic diagram of the structure of a communication device provided in an embodiment of the present application. The communication device 1000 shown in Figure 10 may be a second network element of a core network, and the communication device 1000 may include a sending unit 1010. The sending unit 1010 is configured to send a first request message to a first network element of the core network, wherein the first request message is used to request authentication of a first terminal device; the second network element receives a first response message sent by the first network element, wherein the first response message includes an authentication vector; wherein the first network element and the second network element are both deployed on a first satellite, and the authentication vector is generated based on a first key, wherein the first key is a key stored by the first network element and associated with the first terminal device.
[0207] Optionally, the first key is the same as the second key, and the second key is a key associated with the first terminal device and stored by the first network element on the second satellite.
[0208] Optionally, the first key is the same as the third key, the third key is a key stored in the first terminal device, and the third key is used to verify the authentication vector.
[0209] Optionally, the first key is a permanent root key of the first terminal device.
[0210] Optionally, the first key is a key of the first terminal device for a satellite store-and-forward mode.
[0211] Optionally, the first key is different from a second key, the second key being a key associated with the first terminal device and stored by a first network element on a second satellite.
[0212] Optionally, the first key is different from a third key, the third key being a key stored by the first terminal device, and the third key being used to verify the authentication vector.
[0213] Optionally, the third key is a permanent root key of the first terminal device, and the first key is determined based on the third key.
[0214] Optionally, the third key is a key of the first terminal device for a satellite store-and-forward mode, and the first key is determined based on the third key.
[0215] Optionally, the first key is determined based on identification information of the first satellite and the third key.
[0216] Optionally, the first satellite stores keys associated with all terminal devices of the core network service.
[0217] Optionally, the first satellite stores keys associated with part of terminal devices of the core network service.
[0218] Optionally, the first satellite only serves the part of terminal devices.
[0219] Optionally, the first key is acquired by the first satellite from a network element deployed on the ground when a feeder link of the first satellite is available.
[0220] Optionally, the first network element and the second network element are the same network element or different network elements.
[0221] Optionally, the sending unit 1010 can be the processor 1010. The communication device 1200 can further include a memory 1220 and a transceiver 1230, as shown in FIG. 12.
[0222] FIG. 11 is a structural schematic diagram of a communication device provided by an embodiment of the present application. The communication device 1100 shown in FIG. 11 can be a first terminal device, and the communication device 1100 can include a receiving unit 1110. The receiving unit 1110 is configured to receive a second request message sent by a second network element of a core network, the second request message including an authentication vector generated based on a first key; the first terminal device verifies the authentication vector; wherein the first key is a key associated with the first terminal device and stored by a first network element of the core network, and the first network element and the second network element are both deployed on a first satellite.
[0223] Optionally, the first key is the same as a second key, and the second key is a key associated with the first terminal device and stored by a first network element on a second satellite.
[0224] Optionally, the first key is the same as a third key, and the third key is a key stored by the first terminal device, and the third key is used to verify the authentication vector.
[0225] Optionally, the first key is a permanent root key of the first terminal device.
[0226] Optionally, the first key is a key of the first terminal device for a satellite store-and-forward mode.
[0227] Optionally, the first key is different from a second key, and the second key is a key associated with the first terminal device and stored by a first network element on a second satellite.
[0228] Optionally, the first key is different from a third key, and the third key is a key stored by the first terminal device, and the third key is used to verify the authentication vector.
[0229] Optionally, the third key is a permanent root key of the first terminal device, and the first key is determined based on the third key.
[0230] Optionally, the third key is a key of the first terminal device for a satellite store-and-forward mode, and the first key is determined based on the third key.
[0231] Optionally, the second request message further includes first information, and the first information is used for the first terminal device to derive the first key based on the third key.
[0232] Optionally, the first key is determined based on identification information of the first satellite and the third key.
[0233] Optionally, the first satellite stores keys associated with all terminal devices of the core network service.
[0234] Optionally, the first satellite stores a part of terminal device associated key of the core network service.
[0235] Optionally, the first satellite only serves the part of terminal device.
[0236] Optionally, the first key is acquired by the first satellite from a network element deployed on the ground when a feeder link of the first satellite is available.
[0237] Optionally, the first network element and the second network element are the same network element or different network elements.
[0238] Optionally, the receiving unit 1110 can be the processor 1110. The communication device 1200 can further include a memory 1220 and a transceiver 1230, as shown in FIG. 12.
[0239] FIG. 12 is a schematic structural diagram of an apparatus according to an embodiment of the present application. The dashed line in FIG. 12 indicates that the unit or module is optional. The apparatus 1200 can be used to implement the method described in the foregoing method embodiments. The apparatus 1200 can be a chip or a communication device.
[0240] The apparatus 1200 can include one or more processors 1210. The processor 1210 can support the apparatus 1200 to implement the method described in the foregoing method embodiments. The processor 1210 can be a general purpose processor or a dedicated processor. For example, the processor can be a central processing unit (CPU). Alternatively, the processor can also be other general purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic components, discrete hardware components, etc. The general purpose processor can be a microprocessor or the processor can also be any conventional processor.
[0241] The apparatus 1200 can further include one or more memories 1220. The memory 1220 stores a program, which can be executed by the processor 1210, so that the processor 1210 performs the method described in the foregoing method embodiments. The memory 1220 can be independent of the processor 1210 or integrated in the processor 1210.
[0242] The apparatus 1200 can further include a transceiver 1230. The processor 1210 can communicate with other devices or chips through the transceiver 1230. For example, the processor 1210 can perform data transceiving with other devices or chips through the transceiver 1230.
[0243] The embodiment of the present application further provides a computer readable storage medium for storing a program. The computer readable storage medium can be applied to the terminal device provided by the embodiment of the present application, and the program causes the computer to execute the method performed by the terminal device in the various embodiments of the present application.
[0244] The embodiment of the present application further provides a computer program product. The computer program product includes a program. The computer program product can be applied to the terminal device provided by the embodiment of the present application, and the program causes the computer to execute the method performed by the terminal device in the various embodiments of the present application.
[0245] The embodiment of the present application further provides a computer program. The computer program can be applied to the terminal device provided by the embodiment of the present application, and the computer program causes the computer to execute the method performed by the terminal device in the various embodiments of the present application.
[0246] It should be understood that the terms "system" and "network" can be used interchangeably in the present application. In addition, the terms used in the present application are only used to explain the specific embodiments of the present application, and are not intended to limit the present application. The terms "first", "second", "third", and "fourth" and the like in the specification and claims of the present application and the drawings are used to distinguish different objects, and are not used to describe a particular order. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion.
[0247] In the embodiments of the present application, the "indication" mentioned can be direct indication, or indirect indication, or can be an indication with an associated relationship. For example, A indicates B, which can mean that B can be obtained by A; or A indirectly indicates B, for example, A indicates C, and B can be obtained by C; or A and B have an associated relationship.
[0248] In the embodiments of the present application, "B corresponding to A" means that B is associated with A, and B can be determined according to A. However, it should also be understood that determining B according to A does not mean that B is determined only according to A, but B can also be determined according to A and / or other information.
[0249] In the embodiments of the present application, the term "corresponding" can mean that there is a direct or indirect corresponding relationship between the two, or can mean that there is an associated relationship between the two, or can mean an indication and being indicated, configuration and being configured, and the like.
[0250] In the embodiments of the present application, the "predefined" or "preconfigured" can be implemented by pre-storing corresponding codes, tables or other manners that can be used to indicate relevant information in devices (for example, including terminal devices and network devices), and the specific implementation manners are not limited in the present application. For example, the predefinition can refer to the definition in a protocol.
[0251] In the embodiments of the present application, the "protocol" can refer to a standard protocol in the communication field, for example, can include the LTE protocol, the NR protocol and the related protocol applied to the future communication system, and the present application is not limited to this.
[0252] In the embodiments of the present application, the term "and / or" is only used to describe the association relationship of the associated objects, that is, there can be three relationships, for example, A and / or B can represent the following three cases: A exists alone, A and B exist together, and B exists alone. In addition, the " / " in the present application generally represents an "or" relationship between the front and rear associated objects.
[0253] In various embodiments of the present application, the size of the serial number of the above processes does not mean the order of execution, and the execution order of the processes should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0254] In several embodiments provided by the present application, it should be understood that the disclosed system, device and method can be implemented in other ways. For example, the device embodiments described above are only schematic. The division of the units is only a logical function division. There can be another division manner in actual implementation. For example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between the units can be indirect couplings or communication connections through some interfaces, devices or units, and can be electrical, mechanical or in other forms.
[0255] The units described as separate components can or can not be physically separate, and the components displayed as units can or can not be physical units, that is, can be located in one place, or can be distributed on a plurality of network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiments of the present application.
[0256] In addition, each functional unit in the various embodiments of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit.
[0257] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented by software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer can be a general purpose computer, a special purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer readable storage medium or transmitted from one computer readable storage medium to another computer readable storage medium, for example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center through wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) mode. The computer readable storage medium can be any available medium that can be read by a computer or a data storage device such as a server, data center and the like integrated with one or more available media sets. The available media can be magnetic media (for example, floppy disk, hard disk, magnetic tape), optical media (for example, digital video disc (DVD)) or semiconductor media (for example, solid state disk (SSD)) and the like.
[0258] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical range disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A wireless communication method, characterized in that: include: The first network element of the core network receives a first request message sent by the second network element of the core network, where the first request message is used to request authentication of the first terminal device; The first network element sends a first response message to the second network element, where the first response message includes an authentication vector; The first network element and the second network element are both deployed on a first satellite, and the authentication vector is generated based on a first key, which is a key associated with the first terminal device and stored in the first network element.
2. The method according to claim 1, characterized in that The first key is the same as the second key, and the second key is a key associated with the first terminal device and stored by the first network element on the second satellite.
3. The method according to claim 2, characterized in that The first key is the same as a third key, the third key is a key stored in the first terminal device, and the third key is used to verify the authentication vector.
4. The method according to claim 2 or 3, characterized in that The first key is a key of the first terminal device for a satellite store-and-forward mode.
5. The method according to claim 1, wherein The first key is different from the second key, and the second key is a key associated with the first terminal device and stored by the first network element on the second satellite.
6. The method according to claim 5, characterized in that The first key is different from a third key, the third key is a key stored in the first terminal device, and the third key is used to verify the authentication vector.
7. The method according to claim 6, characterized in that The third key is a key of the first terminal device for a satellite store-and-forward mode, and the first key is determined based on the third key.
8. The method according to any one of claims 1 to 7, characterized in that The first satellite stores keys associated with all terminal devices served by the core network.
9. The method according to any one of claims 1 to 7, characterized in that The first satellite stores keys associated with some terminal devices served by the core network.
10. The method according to claim 9, characterized in that The first key is obtained by the first satellite from a network element deployed on the ground when a feeder link of the first satellite is available.
11. The method according to any one of claims 1 to 10, characterized in that The first network element and the second network element are the same network element or different network elements.
12. A wireless communication method, characterized in that: include: The first terminal device receives a second request message sent by a second network element of the core network, where the second request message includes an authentication vector generated based on the first key; Verifying, by the first terminal device, the authentication vector; The first key is a key associated with the first terminal device and stored in a first network element of the core network, and both the first network element and the second network element are deployed on a first satellite.
13. The method according to claim 12, characterized in that The first key is the same as the second key, and the second key is a key associated with the first terminal device and stored by the first network element on the second satellite.
14. The method according to claim 13, wherein: The first key is the same as a third key, the third key is a key stored in the first terminal device, and the third key is used to verify the authentication vector.
15. The method according to claim 13 or 14, characterized in that The first key is a key of the first terminal device for a satellite store-and-forward mode.
16. The method according to claim 12, characterized in that The first key is different from the second key, and the second key is a key associated with the first terminal device and stored by the first network element on the second satellite.
17. The method according to claim 16, characterized in that The first key is different from a third key, the third key is a key stored in the first terminal device, and the third key is used to verify the authentication vector.
18. The method according to claim 17, characterized in that The third key is a key of the first terminal device for a satellite store-and-forward mode, and the first key is determined based on the third key.
19. The method according to claim 17 or 18, characterized in that The second request message also includes first information, where the first information is used by the first terminal device to derive the first key based on the third key.
20. The method according to any one of claims 12 to 19, characterized in that The first satellite stores keys associated with all terminal devices served by the core network.
21. The method according to any one of claims 12 to 19, characterized in that The first satellite stores keys associated with some terminal devices served by the core network.
22. The method according to claim 21, characterized in that The first key is obtained by the first satellite from a network element deployed on the ground when a feeder link of the first satellite is available.
23. The method according to any one of claims 12 to 22, characterized in that The first network element and the second network element are the same network element or different network elements.
24. A communication device, characterized in that: The communication device is a first network element of a core network, and the communication device includes: A receiving unit, configured to receive a first request message sent by a second network element of the core network, where the first request message is used to request authentication of the first terminal device; The first network element sends a first response message to the second network element, where the first response message includes an authentication vector; The first network element and the second network element are both deployed on a first satellite, and the authentication vector is generated based on a first key, which is a key associated with the first terminal device and stored in the first network element.
25. The communication device according to claim 24, characterized in that The first key is the same as the second key, and the second key is a key associated with the first terminal device and stored by the first network element on the second satellite.
26. The communication device according to claim 25, characterized in that The first key is the same as a third key, the third key is a key stored in the first terminal device, and the third key is used to verify the authentication vector.
27. The communication device according to claim 25 or 26, characterized in that The first key is a key of the first terminal device for a satellite store-and-forward mode.
28. The communication device according to claim 24, wherein: The first key is different from the second key, and the second key is a key associated with the first terminal device and stored by the first network element on the second satellite.
29. The communication device according to claim 28, wherein The first key is different from a third key, the third key is a key stored in the first terminal device, and the third key is used to verify the authentication vector.
30. The communication device according to claim 29, wherein The third key is a key of the first terminal device for a satellite store-and-forward mode, and the first key is determined based on the third key.
31. The communication device according to any one of claims 24 to 30, characterized in that The first satellite stores keys associated with all terminal devices served by the core network.
32. The communication device according to any one of claims 24 to 30, characterized in that The first satellite stores keys associated with some terminal devices served by the core network.
33. The communication device according to claim 32, wherein: The first key is obtained by the first satellite from a network element deployed on the ground when a feeder link of the first satellite is available.
34. The communication device according to any one of claims 24 to 33, characterized in that The first network element and the second network element are the same network element or different network elements.
35. A communication device, characterized in that: The communication device is a first terminal device, and the communication device includes: a receiving unit, configured to receive a second request message sent by a second network element of the core network, where the second request message includes an authentication vector generated based on the first key; Verifying, by the first terminal device, the authentication vector; The first key is a key associated with the first terminal device and stored in a first network element of the core network, and both the first network element and the second network element are deployed on a first satellite.
36. The communication device according to claim 35, characterized in that The first key is the same as the second key, and the second key is a key associated with the first terminal device and stored by the first network element on the second satellite.
37. The communication device according to claim 36, wherein: The first key is the same as a third key, the third key is a key stored in the first terminal device, and the third key is used to verify the authentication vector.
38. The communication device according to claim 36 or 37, characterized in that The first key is a key of the first terminal device for a satellite store-and-forward mode.
39. The communication device according to claim 35, wherein: The first key is different from the second key, and the second key is a key associated with the first terminal device and stored by the first network element on the second satellite.
40. The communication device according to claim 39, wherein The first key is different from a third key, the third key is a key stored in the first terminal device, and the third key is used to verify the authentication vector.
41. The communication device according to claim 40, wherein: The third key is a key of the first terminal device for a satellite store-and-forward mode, and the first key is determined based on the third key.
42. The communication device according to claim 40 or 41, characterized in that The second request message also includes first information, where the first information is used by the first terminal device to derive the first key based on the third key.
43. The communication device according to any one of claims 35 to 42, characterized in that The first satellite stores keys associated with all terminal devices served by the core network.
44. The communication device according to any one of claims 35 to 42, characterized in that The first satellite stores keys associated with some terminal devices served by the core network.
45. The communication device according to claim 44, characterized in that The first key is obtained by the first satellite from a network element deployed on the ground when a feeder link of the first satellite is available.
46. The communication device according to any one of claims 35 to 45, characterized in that The first network element and the second network element are the same network element or different network elements.
47. A communication device, characterized in that The communication device comprises a transceiver, a memory and a processor, wherein the memory is used to store a program, and the processor is used to call the program in the memory and control the transceiver to receive or send a signal, so that the communication device executes the method according to any one of claims 1 to 23.
48. A device, characterized in that The device comprises a processor configured to call a program from a memory so as to enable the device to execute the method according to any one of claims 1 to 23.
Citation Information
Patent Citations
Cellular core network and radio access network infrastructure and space management
CN116366130A
Communication method and device for integrated trusted measurement
CN116419223A
Method and System for Providing Authentication of a Wireless Device and Cell Broadcast Service Between Wireless Mobile Devices and a Satellite Network
US20220240084A1
Security implementation method and apparatus, device, and network element
WO2023178689A1