Communication method, network device, terminal, communication system, and storage medium
By using a first key and security algorithm in non-terrestrial network communication to securely protect messages between the terminal and the satellite, the problem of communication security in store-and-forward mode is solved, and secure communication between the terminal and the satellite is realized.
Patent Information
- Application Number
- PCT/CN2024/111202
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-08-09
- Publication Date
- 2026-02-12
AI Technical Summary
In non-terrestrial network communication, the security of communication between terminals and satellites in store-and-forward mode is difficult to guarantee, especially since information transmission lacks security protection before the initial authentication process.
The first key is used to securely protect and process messages between the terminal and the network device on the satellite in store-and-forward mode, including integrity protection, encryption protection and scrambling protection using the first key and security algorithms.
It ensures the security of terminal and satellite communication in store-and-forward mode, prevents information leakage and denial-of-service attacks, and improves the security and reliability of communication.
Smart Images

Figure CN2024111202_12022026_PF_FP_ABST
Abstract
Description
Communication method, network device, terminal, communication system and storage medium TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of communication, and in particular to a communication method, a network device, a terminal, a communication system and a storage medium. BACKGROUND
[0002] In a non-terrestrial network (NTN) communication structure, a transparent satellite mode and a regenerative satellite mode can be adopted. In the regenerative satellite mode, the satellite can store and forward information, and this communication mode can be referred to as a "store & forward" mode.
[0003] SUMMARY
[0004] How to ensure the security of communication between a terminal and a satellite in a store & forward mode is a problem to be solved.
[0005] Embodiments of the present disclosure provide a communication method, a network device, a terminal, a communication system and a storage medium.
[0006] According to a first aspect of embodiments of the present disclosure, a communication method is provided, the method comprising: a first network device performing security protection and / or security processing on a message between the first network device and a terminal in a store & forward mode based on a first key, wherein the first key is stored in the first network device, and the first network device is deployed on a satellite.
[0007] According to a second aspect of embodiments of the present disclosure, a communication method is provided, the method comprising: a terminal performing security protection and / or security processing on a message between a first network device and the terminal in a store & forward mode based on a first key, wherein the first key is stored in the terminal, and the first network device is deployed on a satellite.
[0008] According to a third aspect of embodiments of the present disclosure, a first network device is provided, comprising: a processing module configured to perform security protection and / or security processing on a message between the first network device and a terminal in a store & forward mode based on a first key, wherein the first key is stored in the first network device, and the first network device is deployed on a satellite.
[0009] According to a fourth aspect of embodiments of the present disclosure, a terminal is provided, comprising: a processing module configured to perform security protection and / or security processing on a message between a first network device and the terminal in a store & forward mode based on a first key, wherein the first key is stored in the terminal, and the first network device is deployed on a satellite.
[0010] According to a fifth aspect of the embodiments of the present disclosure, a first network device is provided, comprising: one or more processors; and wherein the first network device is configured to perform the communication method of the first aspect.
[0011] According to a sixth aspect of the embodiments of the present disclosure, a terminal is provided, comprising: one or more processors; and wherein the terminal is configured to perform the communication method of the second aspect.
[0012] According to a seventh aspect of the embodiments of the present disclosure, a communication system is provided, comprising a first network device and a terminal, wherein the first network device is configured to implement the communication method of the first aspect, and the terminal is configured to implement the communication method of the second aspect.
[0013] According to an eighth aspect of the embodiments of the present disclosure, a storage medium is provided, which stores instructions, when the instructions are executed on a communication device, causing the communication device to perform the method of the first aspect or the second aspect.
[0014] According to a ninth aspect of the embodiments of the present disclosure, a computer program is provided, which, when executed by a communication device, causes the communication device to perform the communication method of the first aspect or the second aspect.
[0015] According to the embodiments of the present disclosure, the first network device performs security protection and / or security processing on the messages between the first network device and the terminal in the store-and-forward mode based on the first key, thereby ensuring the security of the communication between the terminal and the first network device deployed on the satellite in the store-and-forward mode. BRIEF DESCRIPTION OF DRAWINGS
[0016] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following describes the drawings required for the embodiments, and the following drawings are only some embodiments of the present disclosure, and do not specifically limit the protection scope of the present disclosure.
[0017] FIG. 1 is an architecture schematic diagram of a communication system according to an embodiment of the present disclosure.
[0018] FIG. 2A is an interaction schematic diagram of a communication method according to an embodiment of the present disclosure.
[0019] FIG. 2B is an interaction schematic diagram of a communication method according to an embodiment of the present disclosure.
[0020] FIG. 2C is an interaction schematic diagram of a communication method according to an embodiment of the present disclosure.
[0021] FIG. 3A is a flow schematic diagram of a communication method according to an embodiment of the present disclosure.
[0022] FIG. 3B is a flow schematic diagram of a communication method according to an embodiment of the present disclosure.
[0023] FIG. 3C is a flow diagram of a communication method, according to an embodiment of the present disclosure.
[0024] FIG. 4A is a flow diagram of a communication method, according to an embodiment of the present disclosure.
[0025] FIG. 4B is a flow diagram of a communication method, according to an embodiment of the present disclosure.
[0026] FIG. 4C is a flow diagram of a communication method, according to an embodiment of the present disclosure.
[0027] FIG. 5A is a schematic diagram of a communication structure, according to an embodiment of the present disclosure.
[0028] FIG. 5B is a schematic diagram of an attach procedure in a store-and-forward mode, according to an embodiment of the present disclosure.
[0029] FIG. 5C is a schematic diagram of an attach procedure in a store-and-forward mode, according to an embodiment of the present disclosure.
[0030] FIG. 6A is a schematic diagram of a structure of a first network device, according to an embodiment of the present disclosure.
[0031] FIG. 6B is a schematic diagram of a structure of a terminal, according to an embodiment of the present disclosure.
[0032] FIG. 7A is a schematic diagram of a structure of a communication device, according to an embodiment of the present disclosure.
[0033] FIG. 7B is a schematic diagram of a structure of a chip, according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0034] The present disclosure provides a communication method, a network device, a terminal, a communication system, and a storage medium.
[0035] In a first aspect, the present disclosure provides a communication method, which includes: performing, by a first network device, security protection and / or security processing on a message between the first network device and a terminal in a store-and-forward mode based on a first key, wherein the first key is stored in the first network device, and the first network device is deployed on a satellite.
[0036] In the above embodiments, the first network device performs security protection and / or security processing on the message between the first network device and the terminal in the store-and-forward mode based on the first key, thereby ensuring the security of communication between the terminal and the first network device deployed on the satellite in the store-and-forward mode.
[0037] In some embodiments of the first aspect, the first network device performs security protection and / or security processing on the message based on the first key and a first security algorithm.
[0038] In some embodiments of the first aspect, the method further comprises: receiving, by the first network device, a first message sent by the terminal, the first message comprising a terminal security capability, the terminal security capability being used to determine the first security algorithm.
[0039] In some embodiments of the first aspect, the method further comprises: receiving, by the first network device, a second message sent by a second network device, the second network device being deployed on the ground; wherein the second message comprises a terminal security capability, the terminal security capability being used to determine the first security algorithm; or the second message comprises the first security algorithm.
[0040] In some embodiments of the first aspect, the method further comprises: determining, by the first network device, the first security algorithm based on the terminal security capability and a security algorithm supported by the first network device.
[0041] In some embodiments of the first aspect, the method further comprises: sending, by the first network device, the terminal security capability and / or the first security algorithm to a second network device.
[0042] In some embodiments of the first aspect, the method further comprises: storing, by the first network device, the first security algorithm.
[0043] In some embodiments of the first aspect, the method further comprises: sending, by the first network device, a third message to the terminal, the third message being obtained by security protection based on the first key and the first security algorithm; the security protection comprising at least one of the following: integrity protection, encryption protection, and scrambling protection.
[0044] In some embodiments of the first aspect, the third message is used to indicate an attach failure in a store-and-forward mode, or is used to instruct the terminal to perform authentication.
[0045] In some embodiments of the first aspect, the method further comprises: receiving, by the first network device, a fourth message sent by the terminal, the fourth message being obtained by security protection based on the first key; performing, by the first network device, security processing on the fourth message based on the first key and the first security algorithm; wherein the security processing comprises at least one of the following: integrity verification, decryption processing, and descrambling processing.
[0046] In some embodiments of the first aspect, the fourth message comprises an authentication response or an attach request.
[0047] With reference to some embodiments of the first aspect, in some embodiments, the method further includes: in response to the security processing of the fourth message by the first network device failing, rejecting the attachment of the terminal in the store-and-forward mode.
[0048] With reference to some embodiments of the first aspect, in some embodiments, the method further includes: the first network device preconfiguring the first key.
[0049] The second aspect, the embodiments of the present disclosure provide a communication method, the method comprising: a terminal performing security protection and / or security processing on a message between the terminal and a first network device in a store-and-forward mode based on a first key, wherein the first key is stored in the terminal, and the first network device is deployed on a satellite.
[0050] With reference to some embodiments of the second aspect, in some embodiments, the terminal performs the security protection and / or the security processing on the message based on the first key and a first security algorithm.
[0051] With reference to some embodiments of the second aspect, in some embodiments, the method further includes: the terminal sending a first message to the first network device, the first message comprising a terminal security capability, the terminal security capability being used by the first network device to determine the first security algorithm.
[0052] With reference to some embodiments of the second aspect, in some embodiments, the method further includes: the terminal receiving a third message sent by the first network device, the third message being obtained by performing security protection based on the first key and a first security algorithm; the security protection comprising at least one of: integrity protection, encryption protection, and scrambling protection.
[0053] With reference to some embodiments of the second aspect, in some embodiments, the third message is used to indicate that the attachment in the store-and-forward mode fails, or is used to indicate that the terminal performs authentication.
[0054] With reference to some embodiments of the second aspect, in some embodiments, the third message comprises at least one of: the terminal identifier; a store-and-forward indication; and the first security algorithm.
[0055] With reference to some embodiments of the second aspect, in some embodiments, the method further includes: performing security processing on the third message based on the first security algorithm and the first key; the security processing comprising at least one of: integrity verification, decryption processing, and descrambling processing.
[0056] In some embodiments of the second aspect, in some embodiments, the method further includes: in response to the terminal failing in the security processing of the third message, discarding the third message and / or aborting the attach procedure in the store-and-forward mode.
[0057] In some embodiments of the second aspect, in some embodiments, the method further includes: the terminal sending a fourth message to the first network device, the fourth message being secured based on the first key.
[0058] In some embodiments of the second aspect, in some embodiments, the fourth message includes an authentication response or an attach request.
[0059] In some embodiments of the second aspect, in some embodiments, the method further includes one of: the terminal pre-configuring the first key; the terminal pre-configuring a second key, the second key being used to generate the first key; the terminal receiving the first key distributed by a third network device, the third network device being deployed on the ground; the terminal receiving the second key distributed by the third network device.
[0060] In a third aspect, the embodiments of the present disclosure provide a first network device, including: a processing module configured to secure and / or process messages between the first network device and a terminal in a store-and-forward mode based on a first key, wherein the first key is stored in the first network device, and the first network device is deployed on a satellite.
[0061] In a fourth aspect, the embodiments of the present disclosure provide a terminal, including: a processing module configured to secure and / or process messages between a first network device and the terminal in a store-and-forward mode based on a first key, wherein the first key is stored in the terminal, and the first network device is deployed on a satellite.
[0062] In a fifth aspect, the embodiments of the present disclosure provide a first network device, including: one or more processors; wherein the first network device is configured to perform the communication method of the first aspect.
[0063] In a sixth aspect, the embodiments of the present disclosure provide a terminal, including: one or more processors; wherein the terminal is configured to perform the communication method of the second aspect.
[0064] In a seventh aspect, the embodiments of the present disclosure provide a communication system, including a first network device and a terminal, wherein the first network device is configured to implement the communication method of the first aspect, and the terminal is configured to implement the communication method of the second aspect.
[0065] In an eighth aspect, the embodiments of the present disclosure provide a storage medium, which stores instructions. When the instructions are executed on a communication device, the communication device performs any of the above communication methods.
[0066] In a ninth aspect, the embodiments of the present disclosure provide a program product. When the program product is executed on a communication device, the communication device performs any of the above communication methods.
[0067] In a tenth aspect, the embodiments of the present disclosure provide a computer program. When the computer program is executed on a communication device, the communication device performs any of the above communication methods.
[0068] In an eleventh aspect, the embodiments of the present disclosure provide a chip or chip system. The chip or chip system includes processing circuitry configured to perform any of the above communication methods.
[0069] It can be understood that the above network device, terminal, communication system, storage medium, program product, computer program, chip or chip system are all used to perform the method provided by the embodiments of the present disclosure. Therefore, the beneficial effects that can be achieved are referred to the beneficial effects in the corresponding method, which will not be described here.
[0070] The embodiments of the present disclosure provide a communication method, a network device, a terminal, a communication system and a storage medium. In some embodiments, the communication method and the information sending method, the information receiving method and the like can be replaced with each other.
[0071] The embodiments of the present disclosure are not exhaustive, but only illustrate some embodiments, and are not specific limitations on the protection scope of the present disclosure. In the case of no contradiction, each step in an embodiment can be implemented as an independent embodiment, and the steps can be combined arbitrarily, for example, the scheme after removing some steps in an embodiment can also be implemented as an independent embodiment, and the order of the steps in an embodiment can be exchanged arbitrarily, in addition, the optional implementation manners in an embodiment can be combined arbitrarily; in addition, the embodiments can be combined arbitrarily, for example, the steps of different embodiments or part or all of the steps of different embodiments can be combined arbitrarily, an embodiment can be combined with the optional implementation manners of other embodiments.
[0072] In each embodiment of the present disclosure, the terms and / or descriptions of the embodiments are consistent and can be referred to each other if there is no special description and logical conflict, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.
[0073] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments, and not as a limitation on the present disclosure.
[0074] In the embodiments of the present disclosure, an element expressed in singular form, such as "a", "an", "the", "said", "the aforementioned", "the foregoing", "this", and the like, unless otherwise specified, can represent "one and only one", or can represent "one or more", "at least one", and the like. For example, in the case of using an article such as "a", "an", "the" in English, the noun after the article can be understood as a singular expression, or can be understood as a plural expression.
[0075] In the embodiments of the present disclosure, "plurality" refers to two or more.
[0076] In some embodiments, the terms "at least one of", "one or more", "a plurality of", "multiple", and the like can be replaced with each other.
[0077] In some embodiments, the description modes such as "at least one of A, B", "A and / or B", "A in one case and B in another case", "in response to a case A, in response to a case B", and the like can include the following technical solutions according to the case: in some embodiments, A is executed regardless of B; in some embodiments, B is executed regardless of A; in some embodiments, A and B are selectively executed from A and B; in some embodiments, A and B are executed (A and B are both executed). When there are more branches such as A, B, C, and the like, it is similar to the above.
[0078] In some embodiments, the description modes such as "A or B" and the like can include the following technical solutions according to the case: in some embodiments, A is executed regardless of B; in some embodiments, B is executed regardless of A; in some embodiments, A and B are selectively executed from A and B; when there are more branches such as A, B, C, and the like, it is similar to the above.
[0079] The prefix words of "first", "second" and the like in the embodiments of the present disclosure are merely used to distinguish different description objects, and do not constitute limitation on the position, order, priority, quantity or content of the description objects. The description objects are described in the claims or embodiments, and should not be construed as redundant limitation because of the use of the prefix words. For example, the description object is "field", and the ordinal words before "field" in "first field" and "second field" do not limit the position or order between "fields". "First" and "second" do not limit whether the "fields" modified thereby are in the same message, nor do they limit the order of "first field" and "second field". For another example, the description object is "level", and the ordinal words before "level" in "first level" and "second level" do not limit the priority between "levels". For another example, the quantity of the description object is not limited by the ordinal words, and can be one or more. For example, "first device", wherein the quantity of "device" can be one or more. In addition, the objects modified by different prefix words can be the same or different. For example, the description object is "device", and "first device" and "second device" can be the same device or different devices, and their types can be the same or different. For another example, the description object is "information", and "first information" and "second information" can be the same information or different information, and their contents can be the same or different.
[0080] In some embodiments, "including A", "containing A", "for indicating A", "carrying A" can be interpreted as directly carrying A, or indirectly indicating A.
[0081] In some embodiments, the terms "in response to", "in response to determining", "in the case of", "when", "when", "if", "if" and the like can be replaced with each other.
[0082] In some embodiments, the terms "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not lower than", "above" and the like can be replaced with each other, and the terms "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", "below" and the like can be replaced with each other.
[0083] In some embodiments, an apparatus or the like can be interpreted as an entity, and can also be interpreted as virtual, and the name thereof is not limited to the name described in the embodiments, and the terms "apparatus", "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "subject" and the like can be replaced with each other.
[0084] In some embodiments, a "network" can be interpreted as an apparatus (for example, an access network device, a core network device, and the like) included in the network.
[0085] In some embodiments, the terms "access network device (AN device)", "radio access network device (RAN device)", "base station (BS)", "radio base station", "fixed station", "node", "access point", "transmission point (TP)", "reception point (RP)", "transmission / reception point (TRP)", "panel", "antenna panel", "antenna array", "cell", "macro cell", "small cell", "femto cell", "pico cell", "sector", "cell group", "serving cell", "carrier", "component carrier", "bandwidth part (BWP)" and the like can be replaced with each other.
[0086] In some embodiments, the terms "terminal," "terminal device," "user equipment (UE)," "user terminal," "mobile station (MS)," "mobile terminal (MT)," "subscriber station," "mobile unit," "subscriber unit," "wireless unit," "remote unit," "mobile device," "wireless device," "wireless communication device," "remote device," "mobile subscriber station," "access terminal," "mobile terminal," "wireless terminal," "remote terminal," "handset," "user agent," "mobile client," "client," and so on can be replaced with each other.
[0087] In some embodiments, the access network device, the core network device, or the network device can be replaced with a terminal. For example, the embodiments of the present disclosure can also be applied to a structure in which communication between the access network device, the core network device, or the network device and the terminal is replaced with communication between a plurality of terminals (e.g., device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, the terminal can also be configured to have all or part of the functions of the access network device. In addition, the terms "uplink," "downlink," and the like can also be replaced with terms corresponding to the inter-terminal communication (e.g., "side"). For example, the uplink channel, the downlink channel, and the like can be replaced with the side channel, and the uplink, the downlink, and the like can be replaced with the sidelink.
[0088] In some embodiments, the terminal can be replaced with the access network device, the core network device, or the network device. In this case, the access network device, the core network device, or the network device can also be configured to have all or part of the functions of the terminal.
[0089] In some embodiments, the data, information, etc. can be obtained in compliance with the laws and regulations of the country where the location is situated.
[0090] In some embodiments, the data, information, etc. can be obtained after obtaining the consent of the user.
[0091] In addition, each element, each row, or each column in the table of the embodiments of the present disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.
[0092] FIG. 1 is a schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure.
[0093] As shown in FIG. 1, the communication system 100 includes a terminal 101, a first network device 102, and a second network device 103. The communication system 100 can also include a third network device 104.
[0094] In some embodiments, the first network device 102 can be a network device deployed on a satellite. The first network device can include a RAN node and / or a core network function (CN function) deployed on a satellite. For example, the first network device can be an eNB, and the first network device can also be a Mobility Management Entity-Non Terrestrial (MME-NT).
[0095] In some embodiments, the second network device 103 can be a network device deployed on the ground. The second network device is, for example, a Mobility Management Entity-Terrestrial (MME-T).
[0096] In some embodiments, the first network device 102 (e.g., MME-NT) is configured to maintain terminal context and MME-T information, and the second network device 103 (MME-T) is configured to perform terminal authentication and terminal authorization.
[0097] In some other embodiments, the first network device 102 (e.g., MME-NT) is configured to perform terminal authentication and terminal authorization, and the second network device 103 (MME-T) is configured to maintain MME-NT information.
[0098] In some embodiments, the third network device 104 can be a network device deployed on the ground. The third network device 104 can distribute a key to the terminal.
[0099] In some embodiments, the terminal can be a user equipment (UE), including at least one of a mobile phone, a wearable device, an Internet of Things (IoT) device, a communication-capable automobile, a smart automobile, a tablet (Pad), a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in smart grid, a wireless terminal device in transportation safety, a wireless terminal device in smart city, a wireless terminal device in smart home, and the like, but is not limited thereto.
[0100] In some embodiments, the network device can be one functional network element in a core network device, which can be one device including the first network element, the second network element, and the like, or a plurality of devices or device groups including all or part of the first network element, the second network element, and the like. The network element can be virtual or physical. The core network includes at least one of an evolved packet core (EPC), a 5G core network (5GCN), a next generation core (NGC), and the like.
[0101] In some embodiments, the network device can include at least one of an access network device and a core network device.
[0102] In some embodiments, the access network device is, for example, a node or device that accesses a terminal to a wireless network, and can include at least one of an evolved NodeB (eNB) in a 5G communication system, a next generation eNB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, an access node in a Wi-Fi system, but is not limited thereto.
[0103] In some embodiments, the technical solutions of the present disclosure can be applied to an Open RAN architecture, at which time the interfaces between or within the access network devices involved in the embodiments of the present disclosure can become internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be realized through software or programs.
[0104] In some embodiments, the access network device can be composed of a central unit (CU) and a distributed unit (DU), where the CU can also be referred to as a control unit. The CU-DU structure can split the protocol layers of the access network device, with part of the protocol layer functions being controlled by the CU, and the remaining part or all of the protocol layer functions being distributed in the DU and controlled by the CU, but is not limited thereto.
[0105] In some embodiments, the core network device can be one device including one or more network elements, or a plurality of devices or device groups including all or part of the above one or more network elements. The network element can be virtual or physical. The core network includes, for example, at least one of an evolved packet core (EPC), a 5G core network (5GCN), and a next generation core (NGC).
[0106] It can be understood that the communication system described in the embodiments of the present disclosure is for more clearly illustrating the technical solutions of the embodiments of the present disclosure, and does not constitute a limitation on the technical solutions proposed by the embodiments of the present disclosure. Those skilled in the art can know that, with the evolution of system architecture and the appearance of new business scenarios, the technical solutions proposed by the embodiments of the present disclosure are also applicable to similar technical problems.
[0107] The following embodiments of the present disclosure can be applied to the communication system 100 shown in FIG. 1 or part of the subjects, but are not limited thereto. The subjects shown in FIG. 1 are exemplary, and the communication system can include all or part of the subjects in FIG. 1, or other subjects other than FIG. 1. The number and form of each subject is arbitrary, each subject can be physical or virtual, the connection relationship between each subject is exemplary, each subject can not be connected or can be connected, the connection can be in any way, can be direct connection or indirect connection, can be wired connection or wireless connection.
[0108] Embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), 6th generation mobile communication system (6G), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (Bluetooth (registered trademark)), Public Land Mobile Network (PLMN) network, Device-to-Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle-to-Everything (V2X), system using other communication methods, next-generation system expanded based on them, and the like. Further, a plurality of systems can be applied in combination (for example, combination of LTE or LTE-A and 5G, and the like).
[0109] In some embodiments, both "transparent satellite payload" and "regenerative satellite payload" can be used for satellite communication. In the "regenerative satellite payload" scenario, the satellite supports all wireless network layer protocols, so "regeneration is achieved if a signal is received from the earth". Due to the fact that the satellite is processing the payload, the satellite can "store" and "forward" information, and the satellite can establish communication with adjacent satellites through "Inter Satellite Link (ISL)". This mode of communication can also be referred to as "Store&Forward" satellite service operation.
[0110] In the Store&Forward service operation, the service link between the UE and the SAT (satellite) and the feeder link between the SAT and the NTN gateway can not be available at the same time. If the service link is available while the feeder link is not, the SAT can temporarily store the uplink (UL) data from the UE. If the feeder link is available while the service link is not, the SAT can temporarily store the downlink (DL) data from the CN.
[0111] However, before completing the initial authentication procedure and establishing security between the UE and the SAT, all information is transmitted without security protection. Therefore, how to ensure the integrity and / or confidentiality of the signaling in the S&F attach procedure is a technical problem to be solved.
[0112] In the related art, ECCSI (Elliptic Curves Cryptography) is used to perform mutual authentication between the UE and the satellite and protect the privacy of the UE. However, the asymmetric encryption mechanism increases the energy consumption of undoing security protection and brings risks (such as DoS (Denial of Service) attack) to the satellite.
[0113] Therefore, the embodiments of the present disclosure provide a communication method, a first network device performs security protection and / or security processing on a message between the first network device and a terminal in a store-and-forward mode based on a first key, so as to ensure the security of communication between the terminal and the first network device deployed on a satellite in the store-and-forward mode.
[0114] FIG. 2A is an interaction schematic diagram of a communication method according to an embodiment of the present disclosure.
[0115] In the embodiments of the present disclosure, the first network device can be a network device deployed on a satellite, and the first network device can include an eNB and / or a Mobility Management Entity-Non Terrestrial (MME-NT) deployed on a satellite.
[0116] In the embodiments of the present disclosure, the second network device can be a network device deployed on the ground, and the second network device is, for example, a Mobility Management Entity-Terrestrial (MME-T).
[0117] In some embodiments, the MME-NT is configured to maintain a terminal context and MME-T information, and the MME-T is configured to perform terminal authentication and terminal authorization.
[0118] As shown in FIG. 2A, the embodiments of the present disclosure relate to a communication method, and the method includes:
[0119] In step S2101, the terminal determines a first key.
[0120] In some embodiments, the terminal can be preconfigured with the first key, and the first key can be a key for communication with the satellite.
[0121] In other embodiments, the terminal can be preconfigured with a second key, the second key can be a root key, the second key is used to generate the first key, and the first key can be a key for communication with the satellite. The terminal can derive the first key based on the second key, for example, the terminal can derive the key for communication with the satellite based on a satellite identifier (or a Public Land Mobile Network (PLMN) identifier) and the root key.
[0122] In still other embodiments, a third network device can distribute the first key to the terminal, and the terminal can receive the first key distributed by the third network device, the third network device is a network device deployed on the ground, and the first key can be a key for communication with the satellite.
[0123] In still other embodiments, a third network device can distribute the second key to the terminal, and the terminal can receive the second key distributed by the third network device, the second key can be a root key, the second key is used to generate the first key, and the first key can be a key for communication with the satellite. The terminal can derive the key for communication with the satellite based on a satellite identifier (or a PLMN identifier) and the root key.
[0124] In some embodiments, the terminal can store the first key, i.e., the first key is stored in the terminal.
[0125] In some embodiments, the terminal can store the second key, i.e., the second key is stored in the terminal.
[0126] At step S2102, the first network device preconfigures the first key.
[0127] In some embodiments, the first network device can store the first key, i.e., the first key is stored in the first network device.
[0128] In some embodiments, the first key can be a root key, and different satellites have the same root key.
[0129] In some other embodiments, the first key can be a satellite key, and different satellites have different satellite keys.
[0130] In some embodiments, the order of steps S2101 and S2102 can be exchanged or performed at the same time, and the disclosure does not limit the execution order of steps S2101 and S2102.
[0131] At step S2103, the terminal sends a first message to the first network device.
[0132] In some embodiments, the first network device receives the first message sent by the terminal.
[0133] In some embodiments, the first message can be, for example, an attach request. The first message is used to initiate an attach process, i.e., the terminal can request to be attached to a mobile communication system to which the first core network device belongs.
[0134] In some embodiments, the first message includes a terminal security capability.
[0135] In some embodiments, the terminal security capability can include a security algorithm supported by the terminal, and the security algorithm supported by the terminal can include an integrity algorithm and / or an encryption algorithm.
[0136] In some embodiments, the terminal security capability is used to determine a first security algorithm.
[0137] In some embodiments, the first message can also include a terminal identifier and a store-and-forward indication (S&F indication).
[0138] The terminal identifier included in the first message can be a subscription concealed identifier (SUCI) or a globally unique temporary UE identity (GUTI).
[0139] In step S2104, the first network device determines the first security algorithm based on the security capability of the terminal and the security algorithms supported by the first network device.
[0140] In some embodiments, the security capability supported by the first network device can include the security algorithms supported by the first network device, and the security algorithms supported by the terminal can include integrity algorithms and / or encryption algorithms.
[0141] In some embodiments, the first security algorithm can be any security algorithm supported by both the terminal and the first network device. For example, the terminal supports algorithm 1 and algorithm 2, and the first network device supports algorithm 2 and algorithm 3. Algorithm 2 supported by both the terminal and the first network device can be determined as the first security algorithm.
[0142] In step S2105, the first network device performs security protection on the attach failure message.
[0143] In the store-and-forward mode, the terminal sends an attach request to the first network device. At this time, the first network device is in an unconnected state with the second network device. The first network device can reject the attach request of the terminal and send an attach failure message to the terminal. Before the first network device sends the attach failure message to the terminal, the attach failure message can be first protected to ensure the security of the communication.
[0144] In some embodiments, the attach failure message includes at least one of the following: a terminal identifier; a store-and-forward indication; the first security algorithm.
[0145] In some embodiments, the terminal identifier included in the attach failure message can be a temporary GUTI generated by the first network device in response to the first message.
[0146] In some embodiments, the first security algorithm included in the attach failure message is a security algorithm determined by the first network device based on the security capability of the terminal and the security capability of the network device.
[0147] In some embodiments, the attach failure message can also include a waiting timer, a satellite identifier list, etc.
[0148] In some embodiments, the first network device performs security protection on the attach failure message based on the first key and the first security algorithm.
[0149] For example, the first network device processes the attach failure message using the first security algorithm based on the first key.
[0150] In some embodiments, the security protection includes at least one of the following: integrity protection, encryption protection, and scrambling protection.
[0151] For example, the first network device performs integrity protection on the attach failure message as a whole.
[0152] For example, the first network device performs encryption protection and / or scrambling protection on part of the content in the attach failure message. For example, additional encryption protection and / or scrambling protection is performed on the GUTI IE in the message.
[0153] At step S2106, the first network device sends an attach failure message to the terminal.
[0154] In some embodiments, the terminal receives the attach failure message sent by the first network device.
[0155] In some embodiments, the attach failure message sent by the first network device to the terminal is an attach failure message that is security protected based on the first key and the first security algorithm.
[0156] In some embodiments, the attach failure message is used to indicate an attach failure in the store-and-forward mode. The attach failure message can also be referred to as an attach rejection message, which is used to reject the attach request of the terminal.
[0157] At step S2107, the terminal performs security processing on the attach failure message.
[0158] In some embodiments, the terminal performs security processing on the attach failure message based on the first security algorithm and the first key.
[0159] In some embodiments, the security processing includes at least one of the following: integrity verification, decryption processing, descrambling processing.
[0160] In some embodiments, after receiving the attach failure message, the terminal verifies the security of the attach failure message based on the first key and the received first security algorithm. For example, after receiving the attach failure message, the terminal obtains the first security algorithm determined by the first network device included in the message, and verifies the security of the attach failure message using the first security algorithm and the first key.
[0161] For example, the terminal can verify the integrity of the attach failure message.
[0162] For example, the terminal can perform decryption processing and / or descrambling processing on the encrypted / scrambled content in the attach failure message.
[0163] In some embodiments, in response to the security processing of the attach failure message by the terminal failing, the attach failure message is discarded and / or the attach procedure in the store-and-forward mode is aborted.
[0164] In some embodiments, if the verification of the attach failure message by the terminal fails, the terminal discards the attach failure message, and / or the terminal aborts the attach procedure in the store-and-forward mode.
[0165] In some embodiments, if the terminal succeeds in verifying the attach failure message, the terminal can continue the subsequent procedure, the terminal can initiate an attach request again, and the subsequent procedure of the terminal can refer to the communication method shown in FIG. 2B.
[0166] In step S2108, the first network device sends the terminal security capability and / or the first security algorithm to the second network device.
[0167] In some embodiments, the second network device receives the terminal security capability and / or the first security algorithm sent by the first network device.
[0168] In some embodiments, the terminal security capability and / or the first security algorithm can be carried in the attach request of the terminal forwarded by the first network device to the second network device, or can be sent separately.
[0169] In some embodiments, the first network device can send the terminal security capability and / or the first security algorithm to the second network device when a feeder link between the first network device and the second network device is available.
[0170] In some embodiments, the first network device can be a network device deployed on a current satellite in communication with the terminal, the second network device can determine a next satellite in communication with the terminal and determine a network device deployed on the next satellite, and the second network device can send a second message to the network device deployed on the next satellite to send the terminal security capability and / or the first security algorithm to the network device on the next satellite.
[0171] The communication method provided by the embodiments of the present disclosure can ensure the security of communication between the terminal and the first network device deployed on the satellite in the store-and-forward mode, by the first network device performing security protection and / or security processing on messages between the first network device and the terminal in the store-and-forward mode based on the first key.
[0172] The communication method related to the embodiments of the present disclosure can include at least one of steps S2101-S2108. For example, step S2104 can be implemented as an independent embodiment, and step S2107 can be implemented as an independent embodiment, but is not limited thereto.
[0173] In some embodiments, steps S2101 and S2102 can be exchanged in order or performed simultaneously.
[0174] In some embodiments, steps S2106 and S2108 can be exchanged in order or performed simultaneously.
[0175] In some embodiments, step S2101 is optional, and one or more of the steps can be omitted or replaced in different embodiments.
[0176] In some embodiments, step S2103 is optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0177] In some embodiments, step S2108 is optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0178] In some embodiments, other optional implementations described before or after the description of FIG. 2A can be referred to.
[0179] FIG. 2B is an interaction diagram of a communication method according to an embodiment of the present disclosure.
[0180] In an embodiment of the present disclosure, the first network device in FIG. 2A and the first network device in FIG. 2B can be the same network device, or can be different network devices respectively deployed on different satellites.
[0181] For example, the first network device in FIG. 2A is a network device deployed on a current satellite in communication with the terminal, and the first network device in FIG. 2B is a network device deployed on a next satellite in communication with the terminal.
[0182] As shown in FIG. 2B, an embodiment of the present disclosure relates to a communication method, and the method comprises:
[0183] Step S2201: The first network device preconfigures a first key.
[0184] In an embodiment of the present disclosure, optional implementations of preconfiguring the first key in step S2201 can refer to the optional implementations of step S2102 of FIG. 2A, which will not be described herein.
[0185] Step S2202: The second network device sends a second message to the first network device.
[0186] In some embodiments, the first network device receives the second message sent by the second network device.
[0187] The second message comprises a terminal security capability, and the terminal security capability is used to determine a first security algorithm; or the second message comprises the first security algorithm.
[0188] In some embodiments, the second network device can send the terminal security capability to the first network device, and the first network device determines the first security algorithm based on the terminal security capability.
[0189] In another embodiment, the second network device can send the first security algorithm to the first network device.
[0190] In some embodiments, the second message can be an Authentication Vector (AV) response message, for example.
[0191] In some embodiments, the first network device can send an AV request message to the second network device, the second network device sends the AV request message to a Home Subscriber Server (HSS), the HSS sends an AV response message to the second network device, and the second network device sends the AV response to the first network device.
[0192] In step S2203, the second network device determines the first security algorithm.
[0193] In some embodiments, the second network device receives a terminal security capability sent by the first network device, and the first network device determines the first security algorithm based on the terminal security capability and a security algorithm supported by the first network device. For example, the first network device stores the terminal security capability, the first security capability, and the identification information of the terminal in association.
[0194] In some other embodiments, the second network device receives a first security capability sent by the first network device, and the first network device stores the first security capability. For example, the first network device stores the first security capability in association with the identification information of the terminal.
[0195] In step S2204, the terminal performs security protection on the attach request.
[0196] In some embodiments, after receiving an attach failure message sent by the network device on the current satellite, the terminal can send an attach request to the network device on the next satellite again after the waiting timer ends. Before sending the attach request again, the terminal can perform security protection on the attach request, thereby ensuring the security of the communication.
[0197] In some embodiments, the terminal receives a paging message from the first network device and sends an attach request to the first network device again. Before sending the attach request again, the terminal can perform security protection on the attach request, thereby ensuring the security of the communication.
[0198] In some embodiments, the terminal performs security protection on the attach request based on the first key and the first security algorithm.
[0199] In some embodiments, the security protection includes at least one of integrity protection, encryption protection, and scrambling protection.
[0200] For example, the first network device can perform security protection on the entire attach request, or can perform security protection on part of the content (e.g., the terminal identification) in the attach request.
[0201] For example, the first network device performs integrity protection on the attach request message.
[0202] For example, the first network device performs encryption protection and / or scrambling protection on the terminal identifier in the attach request message.
[0203] At step S2205, the terminal sends an attach request to the first network device.
[0204] In some embodiments, the first network device receives the attach request sent by the terminal.
[0205] In some embodiments, the attach request sent by the terminal to the first network device is a secure attach request based on the first security algorithm and the first key.
[0206] Alternatively, the first network device can actively page the terminal, in which case the terminal does not need to send an attach request to the first network device.
[0207] At step S2206, the first network device performs security processing on the attach request.
[0208] In some embodiments, the first network device performs security processing on the attach request based on the first security algorithm and the first key.
[0209] In some embodiments, the security processing includes at least one of the following: integrity verification, decryption processing, and descrambling processing.
[0210] In some embodiments, after receiving the attach request message, the first network device verifies the security of the attach request message based on the first key and the first security algorithm. For example, after receiving the attach request message, the first network device verifies the security of the attach request message using the stored first security algorithm and the first key.
[0211] For example, the first network device can verify the integrity of the attach request message.
[0212] For example, the first network device can perform decryption processing and / or descrambling processing on the encrypted / scrambled content in the attach request message.
[0213] In some embodiments, in response to the security processing on the attach request message by the first network device failing, the attach request message is discarded and / or the attach procedure in the store-and-forward mode is aborted.
[0214] In some embodiments, if the first network device fails to verify the attach request message, the first network device discards the attach request message and / or the first network device aborts the attach procedure in the store-and-forward mode.
[0215] In some embodiments, if the first network device succeeds in verifying the attach request message, the first network device can continue the subsequent procedure, and proceed to step S2207.
[0216] In step S2207, the first network device performs security protection on the authentication request.
[0217] In some embodiments, the first network device can send an authentication request (authentication attach) to the terminal. Before sending the authentication request, the first network device can perform security protection on the authentication request based on the first key and the first security algorithm, so as to ensure the security of the communication.
[0218] In some embodiments, the first network device performs security protection on the authentication request message based on the first key and the first security algorithm.
[0219] For example, the first network device processes the authentication request message using the first security algorithm based on the first key.
[0220] In some embodiments, the security protection includes at least one of integrity protection, encryption protection, and scrambling protection.
[0221] For example, the first network device performs integrity protection on the authentication request message as a whole.
[0222] For example, the first network device performs encryption protection and / or scrambling protection on part of the content in the authentication request message.
[0223] In step S2208, the first network device sends the authentication request to the terminal.
[0224] In step S2209, the terminal performs security processing on the authentication request.
[0225] In some embodiments, the terminal can perform security processing on the authentication request based on the first key and the first security algorithm.
[0226] In some embodiments, after receiving the authentication request message, the terminal verifies the security of the authentication request message based on the first key and the first security algorithm. For example, after receiving the authentication request message, the terminal verifies the security of the authentication request message using the stored first security algorithm and first key.
[0227] For example, the terminal can verify the integrity of the authentication request message.
[0228] For example, the terminal can perform decryption processing and / or descrambling processing on the encrypted / scrambled content in the authentication request message.
[0229] In some embodiments, in response to the security processing of the authentication request message by the terminal failing, the authentication request message is discarded and / or the attach procedure in the store-and-forward mode is aborted.
[0230] In some embodiments, if the authentication request message is verified by the terminal to fail, the terminal discards the authentication request message and / or the terminal aborts the attach procedure in the store-and-forward mode.
[0231] In some embodiments, if the authentication request message is verified by the terminal to succeed, the terminal can continue the subsequent procedure, such as performing step S2210.
[0232] Step S2210, the terminal performs security protection on the authentication response.
[0233] In some embodiments, the terminal can send an authentication response to the first network device, and before sending the authentication response, the first network device can perform security protection on the authentication response based on the first key and the first security algorithm, so as to ensure the security of the communication.
[0234] For example, the terminal processes the authentication response message based on the first key using the first security algorithm.
[0235] In some embodiments, the security protection includes at least one of the following: integrity protection, encryption protection, and scrambling protection.
[0236] For example, the terminal performs integrity protection on the authentication response message as a whole.
[0237] For example, the terminal performs encryption protection and / or scrambling protection on part of the content in the authentication response message.
[0238] Step S2211, the terminal sends the authentication response to the first network device.
[0239] In some embodiments, the first network device receives the authentication response sent by the terminal.
[0240] Step S2212, the first network device performs security processing on the authentication response.
[0241] In some embodiments, the first network device performs security processing on the authentication response based on the first key and the first security algorithm; wherein the security processing includes at least one of the following: integrity verification, decryption processing, and descrambling processing.
[0242] In some embodiments, in response to the security processing of the authentication response by the first network device failing, the terminal is rejected to attach in the store-and-forward mode.
[0243] In some embodiments, in response to successful security processing of the authentication response by the first network device, the terminal continues the attach procedure in the store-and-forward mode.
[0244] The communication method provided by the embodiments of the present disclosure is that the first network device performs security protection and / or security processing on the messages between the first network device and the terminal in the store-and-forward mode based on the first key, so as to ensure the security of the communication between the terminal and the first network device deployed on the satellite in the store-and-forward mode.
[0245] The communication method related to the embodiments of the present disclosure can include at least one of steps S2201-S2212. For example, step S2204 can be implemented as an independent embodiment, step S2206 can be implemented as an independent embodiment, and step S2207 can be implemented as an independent embodiment, but is not limited thereto.
[0246] In some embodiments, steps S2203 and S2204 can be exchanged in order or performed simultaneously.
[0247] In some embodiments, step S2101 is optional, and one or more of the steps can be omitted or replaced in different embodiments.
[0248] In some embodiments, step S2203 is optional, and one or more of the steps can be omitted or replaced in different embodiments.
[0249] In some embodiments, steps S2204 and S2205 are optional, and one or more of the steps can be omitted or replaced in different embodiments.
[0250] In some embodiments, other optional implementations described before or after the corresponding description of FIG. 2B can be referred to.
[0251] FIG. 2C is an interaction schematic diagram of a communication method according to an embodiment of the present disclosure.
[0252] In the embodiments of the present disclosure, in the embodiments corresponding to FIG. 2A and FIG. 2B, the first network device is configured to maintain the terminal context and the MME-T information, and the second network device is configured to perform terminal authentication and terminal authorization. In the embodiments corresponding to FIG. 2C, the first network device is configured to perform terminal authentication and terminal authorization, and the second network device (not shown) is configured to maintain the MME-NT information.
[0253] As shown in FIG. 2C, the embodiments of the present disclosure relate to a communication method, and the method includes:
[0254] In step S2301, the terminal determines the first key.
[0255] In the embodiments of the present disclosure, the optional implementation of step S2301 can refer to the optional implementation of step S2101 in FIG. 2A, and details are not described herein again.
[0256] In step S2302, the first network device preconfigures the first key.
[0257] In the embodiments of the present disclosure, the optional implementation of step S2302 can refer to the optional implementation of step S2102 in FIG. 2A, and details are not described herein again.
[0258] In step S2303, the terminal sends a first message to the first network device.
[0259] In the embodiments of the present disclosure, the optional implementation of step S2303 can refer to the optional implementation of step S2103 in FIG. 2A, and details are not described herein again.
[0260] In step S2304, the first network device determines a first security algorithm based on the security capability of the terminal and the security algorithm supported by the first network device.
[0261] In some embodiments, the first network device stores the determined first security algorithm.
[0262] In some embodiments, the first network device stores the determined first security algorithm in association with the identification information of the terminal.
[0263] In the embodiments of the present disclosure, the optional implementation of step S2304 can refer to the optional implementation of step S2104 in FIG. 2A, and details are not described herein again.
[0264] In step S2305, the first network device performs security protection on the attach failure message.
[0265] In the embodiments of the present disclosure, the optional implementation of step S2305 can refer to the optional implementation of step S2105 in FIG. 2A, and details are not described herein again.
[0266] In step S2306, the first network device sends the attach failure message to the terminal.
[0267] In the embodiments of the present disclosure, the optional implementation of step S2306 can refer to the optional implementation of step S2106 in FIG. 2A, and details are not described herein again.
[0268] In step S2307, the terminal performs security processing on the attach failure message.
[0269] In the embodiments of the present disclosure, the optional implementation of step S2307 can refer to the optional implementation of step S2107 in FIG. 2A, and details are not described herein again.
[0270] Step S2308: The terminal performs security protection on the attach request.
[0271] In the embodiments of the present disclosure, the optional implementation of step S2308 can refer to the optional implementation of step S2204 in FIG. 2B, which will not be repeated here.
[0272] Step S2309: The terminal sends the attach request to the first network device.
[0273] In the embodiments of the present disclosure, the optional implementation of step S2309 can refer to the optional implementation of step S2205 in FIG. 2B, which will not be repeated here.
[0274] Step S2310: The first network device performs security processing on the attach request.
[0275] In the embodiments of the present disclosure, the optional implementation of step S2310 can refer to the optional implementation of step S2206 in FIG. 2B, which will not be repeated here.
[0276] Step S2311: The first network device performs security protection on the authentication request.
[0277] In the embodiments of the present disclosure, the optional implementation of step S2311 can refer to the optional implementation of step S2207 in FIG. 2B, which will not be repeated here.
[0278] Step S2312: The first network device sends the authentication request to the terminal.
[0279] In the embodiments of the present disclosure, the optional implementation of step S2312 can refer to the optional implementation of step S2208 in FIG. 2B, which will not be repeated here.
[0280] Step S2313: The terminal performs security processing on the authentication request.
[0281] In the embodiments of the present disclosure, the optional implementation of step S2313 can refer to the optional implementation of step S2209 in FIG. 2B, which will not be repeated here.
[0282] Step S2314: The terminal performs security protection on the authentication response.
[0283] In the embodiments of the present disclosure, the optional implementation of step S2314 can refer to the optional implementation of step S2210 in FIG. 2B, which will not be repeated here.
[0284] Step S2315: The terminal sends the authentication response to the first network device.
[0285] In the embodiments of the present disclosure, the optional implementation of step S2315 can refer to the optional implementation of step S2211 in FIG. 2B, which will not be repeated here.
[0286] At step S2316, the first network device performs security processing on the authentication response.
[0287] In the embodiments of the present disclosure, the optional implementation of step S2316 can refer to the optional implementation of step S2212 in FIG. 2B, which will not be repeated here.
[0288] The communication method related to the embodiments of the present disclosure can include at least one of steps S2301-S2316. For example, step S2304 can be implemented as an independent embodiment, step S2307 can be implemented as an independent embodiment, step S2308 can be implemented as an independent embodiment, and step S2310 can be implemented as an independent embodiment, but is not limited thereto.
[0289] In some embodiments, steps S2301 and S2302 can be exchanged in order or performed simultaneously.
[0290] In some embodiments, step S2303 is optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0291] In some embodiments, steps S2308 and S2309 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0292] In some embodiments, steps S2314 and S2315 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0293] In some embodiments, other optional implementations can be described before or after the corresponding description of FIG. 2C.
[0294] In some embodiments, the names of information and the like are not limited to the names described in the embodiments, and terms such as "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "field", "symbol", "codebook", "codeword", "codepoint", "bit", "data", "program", "chip", and the like can be replaced with each other.
[0295] In some embodiments, terms such as "time", "time point", "time instant", and the like can be replaced with each other, and terms such as "duration", "period", "time window", "window", and "time" can be replaced with each other.
[0296] In some embodiments, "acquire", "obtain", "get", "receive", "transmit", "bidirectional transmission", "send and / or receive", and the like can be replaced with each other, and can be interpreted as receiving from another subject, acquiring from a protocol, obtaining from a higher layer, obtaining by self-processing, autonomously implementing, and the like.
[0297] In some embodiments, terms such as "send", "transmit", "report", "issue", "transmit", "bidirectional transmission", "send and / or receive", and the like can be replaced with each other.
[0298] In some embodiments, terms such as "certain", "preset", "pre-set", "set", "indicated", "a certain", "arbitrary", "first", and the like can be replaced with each other, and "certain A", "preset A", "pre-set A", "set A", "indicated A", "a certain A", "arbitrary A", "first A" can be interpreted as A specified in advance in a protocol and the like, can be interpreted as A obtained by setting, configuring, or indicating, and the like, and can be interpreted as certain A, a certain A, arbitrary A, or first A, but are not limited thereto.
[0299] In some embodiments, the determining or judging can be performed by a value represented by 1 bit (0 or 1), a true or false value (Boolean value) represented by true or false, or a comparison of numerical values (for example, a comparison with a predetermined value), but is not limited thereto.
[0300] In some embodiments, "not expecting to receive" can be interpreted as not receiving on the time domain resource and / or the frequency domain resource, or as not performing subsequent processing on the data, etc. after receiving the data, etc.; "not expecting to send" can be interpreted as not sending, or as sending but not expecting the receiver to respond to the content of the sending.
[0301] FIG. 3A is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 3A, the embodiment of the present disclosure relates to a communication method, which is performed by a first network device, and the above method comprises:
[0302] In step S3101, the first network device preconfigures a first key.
[0303] The optional implementation of step S3101 can be referred to the optional implementation of step S2102 in FIG. 2A, step S2302 in FIG. 2C, and other associated parts in the embodiments related to FIG. 2A and FIG. 2C, which are not described here again.
[0304] In step S3102, the first network device determines a first security algorithm based on a terminal security capability and a security algorithm supported by the first network device.
[0305] The optional implementation of step S3102 can be referred to the optional implementation of step S2104 in FIG. 2A, step S2304 in FIG. 2C, and other associated parts in the embodiments related to FIG. 2A and FIG. 2C, which are not described here again.
[0306] In step S3103, the first network device performs security protection on the attach failure message.
[0307] The optional implementation of step S3103 can be referred to the optional implementation of step S2105 in FIG. 2A, step S2305 in FIG. 2C, and other associated parts in the embodiments related to FIG. 2A and FIG. 2C, which are not described here again.
[0308] In step S3104, the first network device sends the attach failure message to the terminal.
[0309] The optional implementation of step S3104 can be referred to the optional implementation of step S2106 in FIG. 2A, step S2306 in FIG. 2C, and other associated parts in the embodiments related to FIG. 2A and FIG. 2C, which are not described here again.
[0310] In step S3105, the first network device sends the terminal security capability to the second network device.
[0311] The optional implementation of step S3105 can refer to step S2108 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.
[0312] FIG. 3B is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 3B, the embodiment of the present disclosure relates to a communication method, which is performed by a first network device, and the above method comprises the following steps:
[0313] In step S3201, the first network device preconfigures a first key.
[0314] The optional implementation of step S3201 can refer to the optional implementation of step S2201 in FIG. 2B and other associated parts in the embodiments involved in FIG. 2B, which will not be repeated here.
[0315] In step S3202, the first network device receives a second message sent by the second network device.
[0316] The optional implementation of step S3202 can refer to the optional implementation of step S2202 in FIG. 2B and other associated parts in the embodiments involved in FIG. 2B, which will not be repeated here.
[0317] In step S3203, the first network device determines a first security algorithm.
[0318] The optional implementation of step S3203 can refer to step S2203 in FIG. 2B, the optional implementation of step S2304 in FIG. 2C, and other associated parts in the embodiments involved in FIG. 2B and FIG. 2C, which will not be repeated here.
[0319] In step S3204, the first network device performs security processing on the attachment request.
[0320] The optional implementation of step S3204 can refer to step S2206 in FIG. 2B, the optional implementation of step S2310 in FIG. 2C, and other associated parts in the embodiments involved in FIG. 2B and FIG. 2C, which will not be repeated here.
[0321] In step S3205, the first network device performs security protection on the authentication request.
[0322] The optional implementation of step S3205 can refer to step S2207 in FIG. 2B, the optional implementation of step S2311 in FIG. 2C, and other associated parts in the embodiments involved in FIG. 2B and FIG. 2C, which will not be repeated here.
[0323] At step S3206, the first network device sends an authentication request to the terminal.
[0324] The optional implementation of step S3206 can be referred to the optional implementation of step S2208 in FIG. 2B, the optional implementation of step S2312 in FIG. 2C, and other associated parts in the embodiments of FIG. 2B and FIG. 2C, which will not be repeated here.
[0325] At step S3207, the first network device receives an authentication response sent by the terminal.
[0326] The optional implementation of step S3207 can be referred to step S2211 in FIG. 2B, the optional implementation of step S2315 in FIG. 2C, and other associated parts in the embodiments of FIG. 2B and FIG. 2C, which will not be repeated here.
[0327] At step S3208, the first network device performs security processing on the authentication response.
[0328] The optional implementation of step S3208 can be referred to step S2212 in FIG. 2B, the optional implementation of step S2316 in FIG. 2C, and other associated parts in the embodiments of FIG. 2B and FIG. 2C, which will not be repeated here.
[0329] FIG. 3C is a flow diagram of a communication method according to the embodiments of the present disclosure. As shown in FIG. 3C, the embodiments of the present disclosure relate to a communication method, which is performed by a first network device, and the above method comprises:
[0330] At step S3301, the first network device performs security protection and / or security processing on the message.
[0331] In some embodiments, the first network device performs security protection and / or security processing on the message based on the first key and the first security algorithm.
[0332] In some embodiments, the first network device performs security protection on a third message, which can be the above-mentioned attach failure message, or the above-mentioned authentication request.
[0333] In some embodiments, the first network device performs security processing on a fourth message, which can be the above-mentioned attach request, or the above-mentioned authentication response.
[0334] FIG. 4A is a flow diagram of a communication method according to the embodiments of the present disclosure. As shown in FIG. 4A, the embodiments of the present disclosure relate to a communication method, which is performed by a terminal, and the above method comprises:
[0335] At step S4101, the terminal determines a first key.
[0336] The optional implementation of step S4101 can be referred to the optional implementation of step S2101 in FIG. 2A, step S2301 in FIG. 2C, and other associated parts in the embodiments of FIG. 2A and FIG. 2C, which are not described here again.
[0337] In step S4102, the terminal sends a first message to the first network device.
[0338] The optional implementation of step S4102 can be referred to the optional implementation of step S2103 in FIG. 2A, step S2303 in FIG. 2C, and other associated parts in the embodiments of FIG. 2A and FIG. 2C, which are not described here again.
[0339] In step S4103, the terminal receives an attach failure message sent by the first network device.
[0340] The optional implementation of step S4103 can be referred to the optional implementation of step S2106 in FIG. 2A, step S2306 in FIG. 2C, and other associated parts in the embodiments of FIG. 2A and FIG. 2C, which are not described here again.
[0341] In step S4104, the terminal performs security processing on the attach failure message.
[0342] The optional implementation of step S4104 can be referred to the optional implementation of step S2107 in FIG. 2A, step S2307 in FIG. 2C, and other associated parts in the embodiments of FIG. 2A and FIG. 2C, which are not described here again.
[0343] FIG. 4B is a flow diagram of a communication method according to some embodiments of the present disclosure. As shown in FIG. 4B, the embodiments of the present disclosure relate to a communication method, which is performed by a terminal, and the above method comprises:
[0344] In step S4201, the terminal performs security protection on the attach request.
[0345] The optional implementation of step S4201 can be referred to the optional implementation of step S2204 in FIG. 2B, step S2308 in FIG. 2C, and other associated parts in the embodiments of FIG. 2B and FIG. 2C, which are not described here again.
[0346] In step S4202, the terminal sends the attach request to the first network device.
[0347] The optional implementation of step S4202 can be referred to the optional implementation of step S2205 in FIG. 2B, step S2309 in FIG. 2C, and other associated parts in the embodiments of FIG. 2B and FIG. 2C, which are not described here again.
[0348] In step S4204, the terminal receives an authentication request sent by the first network device.
[0349] The optional implementation of step S4204 can be referred to the optional implementation of step S2208 in FIG. 2B, step S2312 in FIG. 2C, and other associated parts in the embodiments related to FIG. 2B and FIG. 2C, which are not described here again.
[0350] In step S4204, the terminal performs security protection on the authentication request.
[0351] The optional implementation of step S4204 can be referred to the optional implementation of step S2209 in FIG. 2B, step S2313 in FIG. 2C, and other associated parts in the embodiments related to FIG. 2B and FIG. 2C, which are not described here again.
[0352] In step S4205, the terminal performs security protection on the authentication response.
[0353] The optional implementation of step S4205 can be referred to the optional implementation of step S2210 in FIG. 2B, step S2314 in FIG. 2C, and other associated parts in the embodiments related to FIG. 2B and FIG. 2C, which are not described here again.
[0354] In step S4206, the terminal sends the authentication response to the first network device.
[0355] The optional implementation of step S4206 can be referred to the optional implementation of step S2211 in FIG. 2B, step S2315 in FIG. 2C, and other associated parts in the embodiments related to FIG. 2B and FIG. 2C, which are not described here again.
[0356] FIG. 4C is a flow diagram of a communication method according to the embodiments of the present disclosure. As shown in FIG. 4C, the embodiments of the present disclosure relate to a communication method, which is performed by a terminal, and the above method comprises:
[0357] In step S4301, the terminal performs security protection and / or security processing on the message.
[0358] In some embodiments, the terminal performs security protection and / or security processing on the message based on the first key and the first security algorithm.
[0359] In some embodiments, the terminal performs security processing on the third message, which can be the above-mentioned attach failure message, or the above-mentioned authentication request.
[0360] In some embodiments, the terminal performs security protection on the fourth message, which can be the above-mentioned attach request, or the above-mentioned authentication response.
[0361] In some embodiments, the above method can include the method of the embodiments of the above communication system side, network device side, terminal side, etc., which are not described here again.
[0362] The communication method provided by the embodiments of the present disclosure can protect the privacy of the UE in the S&F attachment process. And the integrity and / or confidentiality of the signaling between the UE and the satellite is ensured before the establishment of the Non-access stratum (NAS) security.
[0363] FIG. 5A is a schematic diagram of a communication structure according to an embodiment of the present disclosure.
[0364] As shown in FIG. 5A, the UE communicates with the SAT (satellite), which can include an eNB and an MME-NT, the MME-NT communicates with an MME-T located on the ground, and the MME-T communicates with a satellite gateway (S-GW).
[0365] In some embodiments, the MME-NT is placed on the satellite, and the MME-T is placed on the ground network. It is assumed that the communication between the MME-NT and the MME-T is guaranteed.
[0366] In some embodiments, for example, the attachment process shown in FIG. 5B, the MME-T is responsible for performing UE authentication and UE authorization, and the MME-NT is responsible for maintaining UE context and MME-T information.
[0367] In some other embodiments, for example, the attachment process shown in FIG. 5C, the MME-NT is responsible for performing UE authentication and UE authorization, and the MME-T is responsible for maintaining MME-NT information.
[0368] In some embodiments, new keys for S&F communication need to be equipped on the satellite and the UE. For the satellite, the S&F key can be pre-configured by the operator. For the UE subscribed to the S&F service, the S&F key can be provided in the registration process, or can be pre-configured by the operator.
[0369] The use of the S&F key can be to protect the privacy of the UE and to ensure the confidentiality and / or integrity of the signaling between the satellite and the UE. An example of the S&F key is shown in Table 1.
[0370] Table 1
[0371] For example 1, the UE can derive the satellite key based on the root key. Key derivation: use the satellite ID / PLMN ID and the root key as input.
[0372] For example 2: the root key is shared between the satellite and the UE, and no key derivation is needed.
[0373] FIG. 5B is a schematic diagram of an attachment process in a store-and-forward mode according to an embodiment of the present disclosure.
[0374] As shown in FIG. 5B, the attach procedure in store-and-forward mode includes the following steps.
[0375] Step S5101, key provisioning.
[0376] In some embodiments, the S&F keys are provisioned on the UE and the satellites SAT-1 and SAT-2 using the above methods.
[0377] Step S5102, the UE sends an attach request to SAT-1.
[0378] In some embodiments, the UE sends an attach request to the MME-NT-1 including SUCI / GUTI, S&F indication, UE security capabilities, etc.
[0379] Step S5103, SAT-1 sends an attach reject to the UE.
[0380] In some embodiments, if the MME-NT-1 has not established contact with the ground station upon receiving the message, the MME-NT-1 stores the attach request and generates a temporary GUTI for future NAS transactions.
[0381] In some embodiments, based on the obtained UE capabilities and its own configured security algorithms, the MME-NT-1 selects the security algorithm to be applied and uses the S&F key to protect the attach reject message. The attach reject message can include a wait timer, a temporary GUTI, a list of satellite IDs, and the selected security algorithm.
[0382] In some embodiments, upon receiving the protected attach reject message, the UE verifies its security by using the S&F key and the received security algorithm. If the verification fails, the UE aborts the attach reject and resends the attach request.
[0383] In some embodiments, the protection can be integrity and / or confidentiality. For example, the attach reject can be integrity protected, and the temporary GUTI IE can be additionally confidentiality protected.
[0384] In some embodiments, the S&F keys can be stored in the eNB or MME-NT on the satellite.
[0385] In some embodiments, if the S&F keys are stored in the MME-NT, the MME-NT performs security protection and security verification. The protection is for NAS messages or NAS IEs (non-access stratum NAS protocol).
[0386] In some embodiments, if the S&F keys are stored in the on-board eNB, the MME-NT sends an attach reject message to the eNB, which includes the attach reject message in a RRC message and security protects and verifies the RRC message.
[0387] At step S5104, SAT-1 sends an AV request to MME-T, which sends an AV request to HSS.
[0388] In some embodiments, when the feeder link between MME-NT and MME-T is available, MME-NT-1 forwards the attach request, International Mobile Subscriber Identity (IMSI), and temporary GUTI and UE security capabilities to MME-T. MME-T requests authentication data of the UE by sending an AV request message to HSS.
[0389] At step S5105, HSS sends an AV response to MME-T, which sends the AV response to SAT-2.
[0390] In some embodiments, HSS returns the authentication data by sending an AV response message. After obtaining the authentication keys from HSS, MME-T shall attempt to determine the next available satellite that can connect to the UE and provide the temporary GUTI and UE security capabilities to MME-NT-2 (the next available satellite where the UE is to camp).
[0391] In some embodiments, SAT-1 and SAT-2 can be the same satellite or different satellites.
[0392] At step S5106, the UE attempts to attach with SAT-2 via the temporary GUTI or SAT-2 pages the UE for connection via the temporary GUTI.
[0393] In some embodiments, when MME-NT-2 arrives over the UE’s area, it can page the UE using the IMSI or temporary GUTI. Based on the UE capabilities received from MME-NT-1 and its own configured security algorithms, MME-NT-2 selects the security algorithm to apply and uses the S&F keys to protect the paging message containing the IMSI / temporary GUTI.
[0394] Alternatively, the UE can resend an attach request message containing the previously obtained temporary GUTI. The entire attach request or the UE identifier portion can be protected by using the S&F keys and the selected security algorithm.
[0395] At step S5107, SAT-2 sends an authentication request to the UE, which sends an authentication response to SAT-2.
[0396] In some embodiments, the MME-NT-2 sends an authentication request to the UE protected by the S&F key. If the verification is passed, the UE returns an authentication response protected by a security algorithm selected by using the S&F key.
[0397] Step S5108, a subsequent attach procedure.
[0398] In some embodiments, the UE, MME-NE and MME-T perform the following attach request (e.g. Security Mode Control (SMC)) defined by the standard.
[0399] FIG. 5C is a schematic diagram illustrating an attach procedure in a store-and-forward mode according to an embodiment of the present disclosure.
[0400] As shown in FIG. 5C, the attach procedure in the store-and-forward mode specifically includes the following steps.
[0401] Step S5201, key provisioning.
[0402] In some embodiments, the S&F key is provisioned on the UE and the satellite SAT using the above method.
[0403] Step S5202, the UE sends an attach request to the SAT.
[0404] Step S5203, the SAT sends an attach reject to the UE.
[0405] Step S5204, the SAT sends an AV request to the MME-T, and the MME-T sends an AV request to the HSS.
[0406] Step S5205, the HSS sends an AV response to the MME-T, and the MME-T sends an AV response to the SAT.
[0407] Step S5206, the UE attempts to attach with the SAT or the SAT pages the UE for connection.
[0408] Step S5207, the SAT sends an authentication request to the UE, and the UE sends an authentication response to the SAT.
[0409] Step S5208, a subsequent attach procedure.
[0410] In the embodiment shown in FIG. 5C, the temporary GUTI and the selected security algorithm will not be transmitted between the MME-NT and the MME-T. After the MME-NT determines the selected security algorithm, the MME-NT stores it in the UE context identified by the temporary GUTI. By retrieving the selected security algorithm stored in the UE context, the MME-NT can protect and verify the signaling between the UE and the SAT.
[0411] In an embodiment of the disclosure, the MME-NT / eNB can obtain the S&F key to protect the signaling transmitted over the service link.
[0412] In an embodiment of the disclosure, the MME-NT / eNB can protect the signaling transmitted over the service link.
[0413] In an embodiment of the disclosure, the MME-NT / eNB can verify the protected signaling by using the S&F key.
[0414] In an embodiment of the disclosure, the MME-NT / eNB can determine the selected security algorithm and send it to the MME-T.
[0415] In an embodiment of the disclosure, the MME-NT / eNB can obtain the selected security algorithm from the MME-T.
[0416] In an embodiment of the disclosure, the UE can obtain the S&F key by pre-configuration or during the registration procedure to protect the signaling transmitted over the service link.
[0417] In an embodiment of the disclosure, the UE can protect the signaling transmitted over the service link.
[0418] In an embodiment of the disclosure, the UE can verify the protected signaling by using the S&F key.
[0419] In an embodiment of the disclosure, the UE can obtain the selected security algorithm from the MME-NT / eNB.
[0420] In an embodiment of the disclosure, part or all of the steps, and optional implementation manners thereof, can be combined with part or all of the steps in other embodiments, or can be combined with optional implementation manners of other embodiments.
[0421] An embodiment of the disclosure also proposes an apparatus for implementing any of the above methods, for example, proposes an apparatus including units or modules for implementing each step performed by a terminal in any of the above methods. For another example, another apparatus is also proposed, including units or modules for implementing each step performed by a network device (such as an access network device, a core network function node, a core network device, etc.) in any of the above methods.
[0422] It should be understood that the division of each unit or module in the above apparatus is only a logical function division, and all or part of them can be integrated into a physical entity or physically separated in actual implementation. In addition, the units or modules in the apparatus can be implemented in the form of processor calling software: for example, the apparatus includes a processor, the processor is connected with a memory, the memory stores instructions, and the processor calls the instructions stored in the memory to realize any of the above methods or realize the functions of each unit or module of the above apparatus, wherein the processor is a general processor such as a central processing unit (CPU) or a microprocessor, and the memory is a memory in the apparatus or a memory outside the apparatus. Alternatively, the units or modules in the apparatus can be implemented in the form of hardware circuit, and the functions of part or all of the units or modules can be realized by the design of hardware circuit. The above hardware circuit can be understood as one or more processors; for example, in one implementation, the above hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the units or modules are realized by the design of the logical relationship of elements in the circuit; for another example, in another implementation, the above hardware circuit is a programmable logic device (PLD), and a field programmable gate array (FPGA) is taken as an example, which can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, so as to realize the functions of part or all of the above units or modules. All units or modules of the above apparatus can be all implemented in the form of processor calling software, or all implemented in the form of hardware circuit, or part implemented in the form of processor calling software and the remaining part implemented in the form of hardware circuit.
[0423] In the embodiments of the present disclosure, the processor is a circuit with signal processing capability. In one implementation, the processor can be a circuit with instruction reading and running capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), a digital signal processor (DSP), or the like. In another implementation, the processor can implement certain functions through a logical relationship of a hardware circuit, and the logical relationship of the hardware circuit is fixed or can be reconfigured. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In the reconfigurable hardware circuit, the processor loads a configuration document to implement the configuration of the hardware circuit. It can be understood that the processor loads instructions to implement the functions of the above part or all units or modules. In addition, the hardware circuit can also be designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), or the like.
[0424] FIG. 6A is a structural schematic diagram of a first network device according to an embodiment of the present disclosure. As shown in FIG. 6A, the first network device 6100 can include a processing module 6101. In some embodiments, the processing module 6101 is configured to process a message. Optionally, the processing module is configured to perform at least one of the processing steps performed by the first network device in any of the above methods, details of which are not repeated here.
[0425] In some embodiments, the first network device can further include a transceiver module.
[0426] In some embodiments, the first network device performs security protection and / or security processing on the message based on the first key and the first security algorithm.
[0427] In some embodiments, the transceiver module is configured to receive a first message sent by the terminal, and the first message includes a terminal security capability, and the terminal security capability is used to determine the first security algorithm.
[0428] In some embodiments, the transceiving module is configured to receive a second message sent by a second network device, the second network device being deployed on the ground; wherein the second message comprises a terminal security capability, the terminal security capability being used to determine the first security algorithm; or the second message comprises the first security algorithm.
[0429] In some embodiments, the processing module is configured to determine the first security algorithm based on the terminal security capability and security algorithms supported by the first network device.
[0430] In some embodiments, the transceiving module is configured to send the terminal security capability to the second network device.
[0431] In some embodiments, the processing module is configured to store the first security algorithm by the first network device.
[0432] In some embodiments, the transceiving module is configured to send a third message to the terminal, the third message being obtained by security protection based on the first key and the first security algorithm; the security protection comprises at least one of the following: integrity protection, encryption protection, and scrambling protection.
[0433] In some embodiments, the third message is used to indicate an attach failure in a store-and-forward mode, or is used to instruct the terminal to perform authentication.
[0434] In some embodiments, the transceiving module is configured to receive a fourth message sent by the terminal, the fourth message being obtained by security protection based on the first key; the first network device performs security processing on the fourth message based on the first key and the first security algorithm; wherein the security processing comprises at least one of the following: integrity verification, decryption processing, and descrambling processing.
[0435] In some embodiments, the fourth message comprises an authentication response or an attach request.
[0436] In some embodiments, the processing module is configured to reject the attach of the terminal in a store-and-forward mode in response to the security processing failure of the first network device on the fourth message.
[0437] In some embodiments, the method further comprises: preconfiguring the first key by the first network device.
[0438] FIG. 6B is a structural schematic diagram of a terminal according to an embodiment of the present disclosure. As shown in FIG. 6B, the terminal 6200 can comprise a processing module 6201. In some embodiments, the processing module 6201 is configured to process a message. Optionally, the processing module is configured to perform at least one of the processing steps performed by the terminal in any of the above methods, and details are not repeated here.
[0439] In some embodiments, the terminal further includes a transceiver module.
[0440] In some embodiments, the terminal secures and / or processes the message based on the first key and the first security algorithm.
[0441] In some embodiments, the transceiver module is configured to send a first message to the first network device, the first message including a terminal security capability, the terminal security capability being used by the first network device to determine the first security algorithm.
[0442] In some embodiments, the transceiver module is configured to receive a third message sent by the first network device, the third message being secured based on the first key and the first security algorithm; the securing including at least one of: integrity protection, encryption protection, scrambling protection.
[0443] In some embodiments, the third message is used to indicate an attach failure in the store-and-forward mode, or is used to indicate that the terminal is authenticated.
[0444] In some embodiments, the third message includes at least one of: the terminal identifier; a store-and-forward indication; the first security algorithm.
[0445] In some embodiments, the processing module is configured to process the third message based on the first security algorithm and the first key; the processing including at least one of: integrity verification, decryption processing, descrambling processing.
[0446] In some embodiments, the processing module is configured to discard the third message and / or abort an attach procedure in the store-and-forward mode in response to a failure of the terminal to process the third message securely.
[0447] In some embodiments, the transceiver module is configured to send a fourth message by the terminal to the first network device, the fourth message being secured based on the first key.
[0448] In some embodiments, the fourth message includes an authentication response or an attach request.
[0449] In some embodiments, the processing module is configured to perform at least one of: the terminal is preconfigured with the first key; the terminal is preconfigured with a second key, the second key being used to generate the first key; the terminal receives the first key distributed by a third network device, the third network device being deployed on the ground; the terminal receives the second key distributed by the third network device.
[0450] FIG. 7A is a structural schematic diagram of a communication device 7100 according to an embodiment of the present disclosure. The communication device 7100 can be a network device (e.g., an access network device, a core network device, etc.), a terminal (e.g., a user equipment, etc.), a chip, a chip system, or a processor supporting the network device to implement any of the above methods, or a chip, a chip system, or a processor supporting the terminal to implement any of the above methods. The communication device 7100 can be used to implement the methods described in the above method embodiments, which can be referred to the descriptions in the above method embodiments.
[0451] As shown in FIG. 7A, the communication device 7100 includes one or more processors 7101. The processor 7101 can be a general processor or a special-purpose processor, for example, a baseband processor or a central processing unit. The baseband processor can be used to process communication protocols and communication data, and the central processing unit can be used to control the communication device (e.g., a base station, a baseband chip, a terminal device, a terminal device chip, a DU or a CU, etc.), execute programs, and process data of the programs. Optionally, the communication device 7100 is configured to perform any of the above methods. Optionally, the one or more processors 7101 are configured to invoke instructions to cause the communication device 7100 to perform any of the above methods.
[0452] In some embodiments, the communication device 7100 further includes one or more transceivers 7102. When the communication device 7100 includes the one or more transceivers 7102, the transceiver 7102 performs at least one of the communication steps (e.g., transmitting and / or receiving) in the above methods, and the processor 7101 performs at least one of the other steps. In optional embodiments, the transceiver can include a receiver and / or a transmitter, which can be separate or integrated together. Optionally, the terms of transceiver, transceiving unit, transceiver, transceiving circuit, interface circuit, interface, etc. can be replaced by each other, and the terms of transmitter, transmitting unit, transmitter, transmitting circuit, etc. can be replaced by each other, and the terms of receiver, receiving unit, receiver, receiving circuit, etc. can be replaced by each other.
[0453] In some embodiments, the communication device 7100 further includes one or more memories 7103 configured to store data. Optionally, all or part of the memory 7103 can also be outside the communication device 7100. In optional embodiments, the communication device 7100 can include one or more interface circuits 7104. Optionally, the interface circuit 7104 is connected to the memory 7103, and the interface circuit 7104 can be configured to receive data from the memory 7103 or other devices, and can be configured to send data to the memory 7103 or other devices. For example, the interface circuit 7104 can read the data stored in the memory 7103 and send the data to the processor 7101.
[0454] The communication device 7100 described in the above embodiments can be a network device or a terminal, but the scope of the communication device 7100 described in the present disclosure is not limited thereto, and the structure of the communication device 7100 can not be limited by FIG. 7A. The communication device can be a standalone device or can be part of a larger device. For example, the communication device can be: 1) a standalone integrated circuit (IC), or a chip, or a chip system or subsystem; (2) a set of one or more ICs, which can optionally also include storage components for storing data, programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, a smart terminal device, a cellular phone, a wireless device, a handset, a mobile unit, a vehicle-mounted device, a network device, a cloud device, an artificial intelligence device, and the like; (6) other devices, and the like.
[0455] FIG. 7B is a structural diagram of a chip 7200 according to an embodiment of the present disclosure. For the case where the communication device 7100 is a chip or a chip system, the structural diagram of the chip 7200 shown in FIG. 7B can be referred to, but is not limited thereto.
[0456] The chip 7200 includes one or more processors 7201. The chip 7200 is configured to perform any of the above methods.
[0457] In some embodiments, the chip 7200 further includes one or more interface circuits 7202. Optionally, the terms interface circuit, interface, transceiver pin, and the like can be replaced with each other. In some embodiments, the chip 7200 further includes one or more memories 7203 for storing data. Optionally, all or part of the memory 7203 can be outside the chip 7200. Optionally, the interface circuit 7202 is connected to the memory 7203, and the interface circuit 7202 can be configured to receive data from the memory 7203 or other devices, and the interface circuit 7202 can be configured to send data to the memory 7203 or other devices. For example, the interface circuit 7202 can read data stored in the memory 7203 and send the data to the processor 7201.
[0458] In some embodiments, the interface circuit 7202 performs at least one of the communication steps (such as step S2101, but not limited thereto) of transmitting and / or receiving in the above methods. The interface circuit 7202 performing the communication steps such as transmitting and / or receiving in the above methods means that the interface circuit 7202 performs data interaction between the processor 7201, the chip 7200, the memory 7203, or a transceiver device. In some embodiments, the processor 7201 performs at least one of the other steps.
[0459] The modules and / or devices described in various embodiments of the virtual device, the physical device, the chip, etc. can be combined or separated according to circumstances. Alternatively, part or all of the steps can also be performed by multiple modules and / or devices in cooperation, which is not limited here.
[0460] The disclosure further provides a storage medium having instructions stored thereon, which, when executed on the communication device 7100, causes the communication device 7100 to perform any of the above methods. Alternatively, the storage medium is an electronic storage medium. Alternatively, the storage medium is a computer readable storage medium, but is not limited to this, and it can also be a storage medium readable by other devices. Alternatively, the storage medium can be a non-transitory storage medium, but is not limited to this, and it can also be a transitory storage medium.
[0461] The disclosure further provides a program product, which, when executed by the communication device 7100, causes the communication device 7100 to perform any of the above methods. Alternatively, the program product is a computer program product.
[0462] The disclosure further provides a computer program, which, when executed on a computer, causes the computer to perform any of the above methods.
Claims
1. A communication method characterized by comprising: The method comprises: The first network device performs security protection and / or security processing on a message between the first network device and a terminal in a store-and-forward mode based on a first key, wherein the first key is stored in the first network device, and the first network device is deployed on a satellite.
2. The method of claim 1, wherein, The first network device performs security protection and / or security processing on the message based on the first key and a first security algorithm.
3. The method of claim 2, wherein, The method further comprises: The first network device receives a first message sent by the terminal, and the first message comprises terminal security capability used to determine the first security algorithm.
4. The method of claim 2, wherein, The method further comprises: The first network device receives a second message sent by a second network device, and the second network device is deployed on the ground. The second message comprises terminal security capability used to determine the first security algorithm. Alternatively, The second message comprises the first security algorithm.
5. The method according to claim 3 or 4, characterized in that, The method further comprises: The first network device determines the first security algorithm based on the terminal security capability and security algorithms supported by the first network device.
6. The method according to any one of claims 3 to 5, characterized in that, The method further comprises: The first network device sends the terminal security capability and / or the first security algorithm to the second network device.
7. The method according to any one of claims 2 to 5, characterized in that, The method further comprises: The first network device stores the first security algorithm.
8. The method of claim 1, wherein, The method further comprises: The first network device sends a third message to the terminal, and the third message is obtained by performing security protection based on the first key and the first security algorithm. The security protection comprises at least one of integrity protection, encryption protection, and scrambling protection.
9. The method of claim 8, wherein, The third message is used to indicate attachment failure in the store-and-forward mode or is used to instruct the terminal to perform authentication.
10. The method of claim 1, wherein, The method further comprises: The first network device receives a fourth message sent by the terminal, and the fourth message is obtained by performing security protection based on the first key. The first network device performs security processing on the fourth message based on the first key and the first security algorithm, and the security processing comprises at least one of integrity verification, decryption processing, and descrambling processing.
11. The method of claim 10, wherein, The fourth message comprises an authentication response or an attachment request.
12. The method according to claim 10 or 11, characterized in that, The method further comprises: In response to failure of the first network device in security processing on the fourth message, the terminal is rejected in attachment in the store-and-forward mode.
13. The method of claim 1, wherein, The method further comprises: The first network device preconfigures the first key.
14. A communication method, comprising: The method comprises: A terminal performs security protection and / or security processing on a message between a first network device and the terminal in a store-and-forward mode based on a first key, wherein the first key is stored in the terminal, and the first network device is deployed on a satellite.
15. The method of claim 14, wherein, The terminal performs security protection and / or security processing on the message based on the first key and a first security algorithm.
16. The method of claim 15, wherein, The method further comprises: The terminal sends a first message to the first network device, and the first message comprises terminal security capability used by the first network device to determine the first security algorithm.
17. The method of claim 14, wherein, The method further comprises: The terminal receives a third message sent by the first network device, the third message being obtained by security protection based on the first key and a first security algorithm. The security protection comprises at least one of integrity protection, encryption protection, and scrambling protection.
18. The method of claim 17, wherein, The third message is used to indicate an attachment failure in the store-and-forward mode, or is used to instruct the terminal to perform authentication.
19. The method of claim 17, wherein, The third message comprises at least one of: The terminal identifier; A store-and-forward indication; The first security algorithm.
20. The method according to any one of claims 17 to 19, characterized in that, The method further comprises: security processing the third message based on the first security algorithm and the first key; The security processing comprises at least one of integrity verification, decryption processing, and descrambling processing.
21. The method of claim 19, wherein, The method further comprises: In response to the security processing of the third message by the terminal failing, discarding the third message and / or aborting an attachment procedure in the store-and-forward mode.
22. The method of claim 14, wherein, The method further comprises: The terminal sends a fourth message to the first network device, the fourth message being obtained by security protection based on the first key.
23. The method of claim 22, wherein, The fourth message comprises an authentication response or an attachment request.
24. The method of claim 14, wherein, The method further comprises one of: The terminal is preconfigured with the first key; The terminal is preconfigured with a second key, the second key being used to generate the first key; The terminal receives the first key distributed by a third network device, the third network device being deployed on the ground; The terminal receives the second key distributed by the third network device.
25. A first network device, comprising: Comprise: A processing module configured to perform security protection and / or security processing on messages between the first network device and a terminal in a store-and-forward mode based on a first key, wherein the first key is stored in the first network device, and the first network device is deployed on a satellite.
26. A terminal, characterized by Comprise: A processing module configured to perform security protection and / or security processing on messages between the first network device and a terminal in a store-and-forward mode based on a first key, wherein the first key is stored in the terminal, and the first network device is deployed on a satellite.
27. A first network device, comprising: Comprise: One or more processors; The first network device is configured to perform the method of any one of claims 1-13.
28. A terminal, characterized by Comprise: One or more processors; The terminal is configured to perform the method of any one of claims 14-24.
29. A communication system, characterized by Comprise a first network device and a terminal, wherein the first network device is configured to implement the method of any one of claims 1-13, and the terminal is configured to implement the method of any one of claims 14-24.
30. A storage medium, the storage medium storing instructions, wherein, When the instructions run on a communication device, the communication device is caused to perform the method of any one of claims 1-13 or the method of any one of claims 14-24.
31. A program product, characterized by Comprise: A computer program, which, when executed by a communication device, causes the communication device to perform the method of any one of claims 1-13 or the method of any one of claims 14-24.
Citation Information
Patent Citations
Communication method, device and system of non-ground network
CN117411533A
Apparatus, method, and computer program
WO2024026640A1