Communication method, apparatus and system, and electronic device, storage medium and program product
By adjusting the transmission granularity and encrypting the system messages based on their attribute information in satellite communication, the problem of the inability to send system messages in a targeted manner in satellite communication is solved, thus achieving accurate transmission of system messages and improving communication security.
Patent Information
- Application Number
- PCT/CN2025/113190
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-08-07
- Filing Date
- 2025-08-07
- Publication Date
- 2026-02-12
AI Technical Summary
In satellite communications, due to the wide coverage area, system messages cannot be specifically sent to legitimate users, leading to communication security risks.
The network side determines the sending granularity based on the attribute information of the system message and flexibly adjusts the sending granularity of the system message to adapt to the actual situation, including attributes such as location, region, service, and communication type. Encryption processing is used to ensure that the system message is only received by legitimate users.
It enables accurate sending of system messages, prevents unauthorized users from receiving them, and improves communication security and efficiency.
Smart Images

Figure CN2025113190_12022026_PF_FP_ABST
Abstract
Description
Communication method and device, system, electronic device, storage medium and program product
[0001] Cross-reference to related applications
[0002] The present disclosure claims priority to Chinese patent application 202411080170.5, filed on August 7, 2024, the disclosure of which is incorporated herein by reference in its entirety. TECHNICAL FIELD
[0003] The present disclosure relates to the technical field of communication, and in particular to a communication method and device, system, electronic device, storage medium and program product. BACKGROUND
[0004] Satellite networks have the characteristics of low latency, low cost, wide coverage, high reliability, high flexibility, etc. However, because the coverage range of a satellite is too wide, for example, the coverage diameter can be tens to thousands of kilometers, it is possible that there are multiple cross-regional and cross-country scenarios within the coverage range of a satellite, and even a cell can involve multiple different countries or regions.
[0005] This situation is particularly prominent in the sending scenario of system messages. In the related art, system messages are sent in a targeted manner with a cell as the granularity. However, this obviously cannot adapt to the situation that the cell and the country / region do not completely match in the satellite communication scenario, which leads to the fact that system messages cannot be sent in a targeted manner within the range of legitimate users. SUMMARY
[0006] The present disclosure provides a communication method and device, system, electronic device, storage medium and program product.
[0007] According to one aspect of the present disclosure, a communication method is provided, applied to a network node, comprising: sending a system message with a first attribute of the system message as the sending granularity; wherein the first attribute comprises at least one of the following: location or region, service, communication type, terminal capability, terminal state, transmitted waveform type, height of antenna and / or base station, height of terminal, beam and / or beam group, transmission / reception point (TRP), SSB index, one or more cells, type of cell, channel characteristics; wherein the channel characteristics comprise at least one of the following: Doppler shift, Doppler spread, delay spread, average delay, spatial reception parameter.
[0008] According to another aspect of the present disclosure, another communication method is provided, applied to a terminal, comprising: receiving a system message from a network node, the system message being transmitted with a first attribute as a transmission granularity; wherein the first attribute comprises at least one of the following: location or region, service, communication type, terminal capability, terminal state, transmitted waveform type, height of antenna and / or base station, height of terminal, beam and / or beam group, TRP, SSB index, one or more cells, type of cell, channel characteristic; wherein the channel characteristic comprises at least one of the following: Doppler shift, Doppler spread, delay spread, average delay, spatial reception parameter.
[0009] According to another aspect of the present disclosure, a communication apparatus is provided, comprising: a transceiver configured to transmit a system message with a first attribute as a transmission granularity; wherein the first attribute comprises at least one of the following: location or region, service, communication type, terminal capability, terminal state, transmitted waveform type, height of antenna and / or base station, height of terminal, beam and / or beam group, TRP, SSB index, one or more cells, type of cell, channel characteristic; wherein the channel characteristic comprises at least one of the following: Doppler shift, Doppler spread, delay spread, average delay, spatial reception parameter.
[0010] According to another aspect of the present disclosure, another communication apparatus is provided, comprising: a transceiver configured to receive a system message from a network node, the system message being transmitted with a first attribute as a transmission granularity; wherein the first attribute comprises at least one of the following: location or region, service, communication type, terminal capability, terminal state, transmitted waveform type, height of antenna and / or base station, height of terminal, beam and / or beam group, TRP, SSB index, one or more cells, type of cell, channel characteristic; wherein the channel characteristic comprises at least one of the following: Doppler shift, Doppler spread, delay spread, average delay, spatial reception parameter.
[0011] According to another aspect of the present disclosure, a communication system is provided, comprising: a network node configured to perform the method performed by the network node as described above; and a terminal configured to perform the method performed by the terminal as described above.
[0012] According to another aspect of the present disclosure, an electronic device is provided, comprising a memory, a processor, and a computer program stored in the memory, the processor executing the computer program to implement the method described in any of the embodiments above.
[0013] According to another aspect of the present disclosure, a computer readable storage medium is provided, which stores computer programs / instructions, which, when executed by a processor, implement the method according to any of the above embodiments.
[0014] According to another aspect of the present disclosure, a computer program product is provided, which comprises computer programs / instructions, which, when executed by a processor, implement the method according to any of the above embodiments. BRIEF DESCRIPTION OF DRAWINGS
[0015] FIG. 1 shows a schematic diagram of a satellite communication scenario according to the present disclosure.
[0016] FIG. 2 shows a schematic diagram of an interaction flow of a communication method according to the present disclosure.
[0017] FIG. 3 shows a schematic diagram of a flow process of a system message according to the present disclosure.
[0018] FIG. 4 shows a schematic diagram of a key derivation algorithm according to the present disclosure.
[0019] FIG. 5 shows a schematic diagram of another key derivation algorithm according to the present disclosure.
[0020] FIG. 6 shows a schematic diagram of a region indication according to the present disclosure.
[0021] FIG. 7 shows a structural block diagram of a communication apparatus according to the present disclosure.
[0022] FIG. 8 shows a structural block diagram of another communication apparatus according to the present disclosure.
[0023] FIG. 9 shows a schematic diagram of a communication system according to the present disclosure.
[0024] FIG. 10 shows a hardware block diagram of an electronic device according to the present disclosure.
[0025] FIG. 11 shows a schematic diagram of a computer readable storage medium according to the present disclosure. DETAILED DESCRIPTION
[0026] In order to make the purpose, technical solutions and advantages of the present disclosure more obvious, the example embodiments according to the present disclosure will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present disclosure, not all the embodiments of the present disclosure, and it should be understood that the present disclosure is not limited by the example embodiments described herein.
[0027] The present disclosure is applied to the scenario where the network side sends system messages to the terminal side, i.e., the sending (or notification) scenario of system messages.
[0028] In this scenario, the network side, also recorded as network node, network device, network side communication device, communication device, etc., is not particularly limited in naming. In some exemplary embodiments, the present disclosure can be used in the system message sending scenario of a satellite network for a terminal, in which the network node can be specifically a communication node (also recorded as a satellite node) in the satellite network. In addition, the present disclosure can also be used in the scenario of a ground core network or base station sending system messages to a terminal.
[0029] The communication technology adopted by the network side is not particularly limited in the present disclosure. Taking a network node as an example, which is one network device in a communication system, the communication system can include but is not limited to: a Global System of Mobile communication (GSM) system, a Code Division Multiple Access (CDMA) system, a Wideband Code Division Multiple Access (WCDMA) system, a General Packet Radio Service (GPRS), a Long Term Evolution (LTE) system, an Advanced long term evolution (LTE-A) system, a New Radio (NR) system, an evolved system of the NR system, an LTE-based access to unlicensed spectrum (LTE-U) system, an NR-based access to unlicensed spectrum (NR-U) system, a Non-Terrestrial Networks (NTN) system, a Universal Mobile Telecommunication System (UMTS), a Wireless Local Area Networks (WLAN), a Wireless Fidelity (WiFi), a 5th-Generation (5G) system or other communication systems, etc.
[0030] In the present disclosure, the network side device can be specifically a base station, an evolved NodeB (eNodeB), a transmission reception point (TRP), a next generation NodeB (gNB) in a 5th generation (5G) mobile communication system, a next generation NodeB in a 6th generation (6G) mobile communication system, a base station in a future mobile communication system, or an access node in a wireless fidelity (WiFi) system, etc. The network side device can also be a module or unit that completes part of the functions of the base station, for example, it can be a central unit (CU) or a distributed unit (DU). The wireless access network device can be a macro base station, a micro base station or an indoor station, or a relay node, etc. The present disclosure does not have special restrictions on the specific technologies and specific device forms adopted by the wireless access network device. For ease of description, the following describes the base station as an example of the wireless access network device.
[0031] The terminal, which can also be referred to as a terminal device, user equipment (UE), mobile station, mobile terminal, etc., can communicate with the network side device. Specifically, the terminal can be widely applied to various scenarios, such as device-to-device (D2D) communication, vehicle to everything (V2X) communication, machine-type communication (MTC), internet of things (IOT), virtual reality, augmented reality, industrial control, autonomous driving, remote medical treatment, smart power grid, smart furniture, smart office, smart wear, smart transportation, smart city, etc. Based on this, the terminal can be, but is not limited to, a mobile phone, a tablet computer, a computer with wireless transceiver function, a wearable device, a vehicle, a drone, a helicopter, an airplane, a ship, a robot, a mechanical arm, a smart home device, etc. The present application embodiment does not have special restrictions on the specific technologies and specific device forms adopted by the terminal.
[0032] Both the base station and the terminal can be collectively referred to as a communication device, wherein the base station can also be referred to as a communication device with a base station function, and the terminal can also be referred to as a communication device with a terminal function. The base station and the terminal can be fixed in position or mobile. The base station and the terminal can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; can also be deployed on the water surface; and can also be deployed on an airplane, a balloon and a man-made satellite in the air. The embodiments of the present application do not have special restrictions on the application scenarios of the base station and the terminal.
[0033] As described in the foregoing background, the system message in the related art is transmitted in units of cells, which leads to the problem that the system message cannot be effectively transmitted in a targeted manner when the cell does not match the country, region, etc.
[0034] On the one hand, in an actual satellite communication scenario, the beams under the coverage of a satellite are the same or different, but the physical cell identifier (PCI) is the same, and different areas can set different global cell identifiers (CGI) or eCGI. However, since it is in the same beam range, the UE cannot explicitly determine the boundary of the physical wireless coverage, and the system message in the related art is in units of cells, which cannot adapt to the current more application scenarios and diverse services, resulting in that a large amount of country / region-limited information cannot be transmitted in a targeted manner within the range of legitimate users. On the other hand, since the cell signal in the non-terrestrial network (NTN) system is a LOS path, the same frequency interference of the overlapping coverage is much stronger than that of the ground base station, and it is almost impossible to communicate normally. Moreover, in a moving scenario, the coverage range of the satellite is dynamically changing, and it is more difficult to control.
[0035] For example, please refer to FIG. 1, which shows a satellite communication scenario provided by the present disclosure. As shown in FIG. 1, in this communication scenario, the coverage range of the satellite (i.e., Satellite coverage) includes three countries, Country A (i.e., Country A), Country B and Country C, but actually, as shown in FIG. 1, the satellite backhaul of the satellite system earth station in the country (i.e., Satellite System Earth Station in Country) is for Country B. Then, if the system message is transmitted in units of cells according to the related art, the system message transmitted in a targeted manner for Country B will also be transmitted to Country A and Country C. This situation of not being able to effectively transmit in a targeted manner has a large communication security risk.
[0036] In view of the problem in the prior art that system messages cannot be sent to a range of legitimate users and the communication security risk caused thereby, the present disclosure provides a new design concept: before sending a system message, a network side determines a sending granularity of the system message based on attribute information of the system message, so that the sending granularity can be flexibly adjusted for different situations to achieve system message sending in a manner that fits actual situations, so that the system message can be sent to a range of legitimate users. The following is a specific description.
[0037] The present disclosure provides a communication method. Please refer to FIG. 2, which shows an interaction flow diagram of a communication method provided by the present disclosure. As shown in FIG. 2, the method comprises:
[0038] S202, the network node sends the system message with the first attribute as the sending granularity.
[0039] Specifically, the system message can have multiple attribute information, and when performing the operation, the first attribute needs to be determined from the multiple attribute information, and the first attribute is the sending granularity of the system message. Thus, after the operation determines the sending granularity, the system message is sent based on the sending granularity of the first attribute.
[0040] The present disclosure does not have special restrictions on the type of attribute information possessed by the system message, and the range at least includes the range of the first attribute determined by the present disclosure (specifically described below). In addition, the present disclosure does not have special restrictions on how the network node determines the sending granularity of the system message, and in actual scenarios, it can be actually determined based on the attribute information of the system message. For example, if the satellite communication scenario shown in FIG. 1 is considered, a cell can contain multiple countries, so at least the country (or region) needs to be used as the first attribute (at least one first attribute of the sending granularity) to send the system message.
[0041] When performing the system message sending, the system message can be sent respectively for different sending granularities. For example, if the system message is sent with the region as the sending granularity, system message 1 is sent for region A and system message 2 is sent for region B. For another example, the sending granularity determined by the operation is region granularity and service granularity, so when the system message is sent accordingly, different system messages are sent for different regions and services. This is not an exhaustive list.
[0042] As shown in FIG. 2, in the interaction flow, S202 is an action performed by the network side. In the process, the network side can first determine the sending granularity of the system message before sending the system message, and then send the system message according to the determined first attribute.
[0043] S204, the terminal receives the system message from the network node, and the system message is sent with the first attribute as the sending granularity.
[0044] S204 in FIG. 2 is an action performed by any one terminal. For the convenience of description, FIG. 2 only shows one terminal, and in the actual scenario, the number of terminals can be one or more, depending on the actual situation such as user behavior, and the present disclosure does not have special limitations on this.
[0045] The first attribute related to the sending granularity of the system message in the present disclosure can specifically include but is not limited to at least one of the following: location or region, service, communication type, terminal capability, terminal state, transmitted waveform type, height of antenna and / or base station, height of terminal, beam and / or beam group, transmit / receive point (TRP), SSB (Synchronization Signal / PBCH) index (i.e., SSB index), one or more cells, type of cell, channel characteristics.
[0046] The channel characteristics include at least one of the following: Doppler shift, Doppler spread, delay spread, average delay, spatial Rx parameter.
[0047] Specifically, the location or region granularity has a targeted improvement effect for the case where the satellite coverage region is wide. Compared with the prior art of sending the system message with the cell as the granularity, sending the system message with different location or region as the granularity, that is, the system message 1 corresponding to the region A can be sent to the terminals in the region A, and the system message 2 corresponding to the region B can be sent to the terminals in the region B, which can solve the problem that the system message cannot be sent to the range of legitimate users in a targeted manner when the cell is used as the granularity. The present disclosure does not have special limitations on the specific division method of the location or region, which can include but is not limited to at least one of the following: geographical location, area, height, country, etc. For example, the existing administrative division of provinces, cities, counties, and townships can be used as a basis for division, for example, one country shown in FIG. 1 is divided into one region; or a self-defined division mechanism can also be used, for example, the network side defines a preset range near a certain base station as a region; without being exhaustive.
[0048] In terms of service granularity, it means that a type of system message can be sent to a terminal supporting certain service(s), and terminals not supporting these services can not be sent, or not received, or received but unable to parse the system message. Among them, the service type can be customized, such as XR service, high-precision timing service, etc. In this way, the system message is bound to the service, and the system message corresponding to certain services is sent to the corresponding service terminal.
[0049] Similarly, in terms of communication type, it means that the system message is bound to the communication type, and the system message related to certain communication types can be sent to the corresponding communication type terminal. The communication type involved here is not limited, for example, it can include but is not limited to at least one of the following: SL (i.e., encrypted communication), NTN (i.e., non-terrestrial communication network), unmanned aerial vehicles (UAV), Air To Ground (ATG), MBS Multicast (i.e., MBS multicast service), MBS broadcast (i.e., MBS broadcast service), etc. without exhaustive enumeration.
[0050] Based on at least one of the service and the communication type, different services and / or communication types of terminals can be sent differently, so that UEs not supporting the service and the communication type reduce unnecessary SI / SI update reception.
[0051] In this disclosure, the sending granularity of the system message also considers the relevant situation of the terminal, which can include but is not limited to at least one of the terminal capability and the terminal state. Among them, the terminal state can include but is not limited to at least one of the UE speed, the UE height, and the UE angle. For example, if the UE state is used as the sending granularity, in the case of sending system message 1 to a terminal whose height is higher than 1km, for any terminal, if the height (i.e., a kind of UE state) of the terminal is higher than 1km, the terminal can successfully receive and parse the system message; but for any UE whose height is lower than 1km, it may not be able to receive the system message (here it can be that the network side does not send it, or the UE does not receive it) or the UE cannot successfully parse the system message after receiving it (the specific way will be explained later, here only an example is given). In this way, the system message can be sent to the appropriate UE in terms of UE state. In summary, the terminal capability and the terminal state can be used as the sending granularity to send system messages to terminals with different terminal capabilities and terminal states, so that UEs not supporting or not suitable for the terminal capability and the terminal state reduce unnecessary SI / SI update reception.
[0052] In the present disclosure, the transmission granularity of the system message also takes into account the type of the transmitted waveform. That is, different types of UEs, different states of UEs, can correspond to receiving different waveforms. The waveform types involved here can include but are not limited to at least one of the following: OFDM waveform, OOK waveform, etc., without being exhaustive. It should be understood that different types and states of UEs can correspond to receiving different waveforms, and therefore the configuration information and scheduling mode of the system message can be different.
[0053] In addition, in the present disclosure, the transmission granularity of the system message also takes into account the height of the antenna and / or base station, the height of the terminal, the beam and / or beam group, the TRP, the SSB index, one or more cells, the type of the cell, the channel characteristics, etc. These different attributes correspond to different cell configurations, different measurement configurations, different access behaviors of the UE, different measurement behaviors, and different behaviors of the mobility management.
[0054] It should be understood that the number of the first attributes can also be one or more as the transmission granularity of the system message. The present disclosure does not particularly limit the number of the first attributes, and the network side can transmit the system message based on one first attribute as the granularity, or can transmit the system message based on a combination of multiple first attributes as the granularity.
[0055] Based on this, for the terminal, if the terminal successfully receives and parses the system message, the terminal can determine some related information of the system message based on the system message.
[0056] For example, the terminal can determine at least one of the following information based on the system message: the position or region corresponding to the beam transmitting the system message, the type of the transmitted waveform, the height of the antenna and / or base station, the angle between the antenna and the ground, the height of the terminal, the information of the beam and / or beam group, the TRP information, the SSB index, the information of one or more cells, the type of the cell, and the information of the channel characteristics.
[0057] For example, if the terminal receives and parses the system message, it indicates that the terminal is flying at a height of 100-200 meters; or, for another example, if the terminal receives and parses the system message, it indicates that the coverage direction of the beam transmitting the system message is at a height of 150-300 meters; or, for another example, if the terminal receives and parses the system message, it indicates that the terminal is working within the range of region A; or, for another example, if the terminal receives and parses the system message, it indicates that the terminal is served by a low PAPR waveform, such as OOK, SC-OFDM, DFT-S-OFDM, etc., without being exhaustive.
[0058] In summary, regardless of the manner, the technical solution provided by the present disclosure fully considers the transmission characteristics of the network side, the terminal side and the transmission characteristics between the two to determine the first attribute that adapts to the current situation as the transmission granularity for transmitting the system message. In other words, in the technical solution provided by the present disclosure, the first attribute that adapts to the actual scene can be taken as the transmission granularity for personalized transmission based on the actual transmission scene of the system message, which can ensure that the system message can be transmitted to the range of legitimate users in a targeted manner and ensure communication security. In summary, the technical solution provided by the present disclosure can flexibly adjust the transmission granularity of the system message, so that the system message can be transmitted to the range of legitimate users in a targeted manner.
[0059] Further based on the embodiment shown in FIG. 2, in the technical solution provided by the present disclosure, the information carried by the system message is not particularly limited.
[0060] In an exemplary embodiment, the system message can carry at least one of the following: resource information, location information, area information, transmission time information, and capacity information of the relevant downlink (DL) beam and / or cell; and / or at least one of the following: resource information, location information, area information, transmission time information, and physical random access channel (PRACH) resource information of the relevant DL beam and / or cell corresponding to the uplink (UL) beam and / or cell. In other words, the system message in the present disclosure can be information related to the downlink beam and / or cell, or information related to the uplink beam and / or cell, or both downlink and uplink, which will not be described here.
[0061] In addition, in the present disclosure, the system message can include but is not limited to at least one system information (SI) or system information block (SIB).
[0062] In the present disclosure, the network node transmits the system message with the first attribute as the transmission granularity, which can have the following forms:
[0063] First, the network node determines the receiving end with the first attribute based on the determined transmission granularity, i.e., the first attribute, so as to transmit the system message to these target receiving ends in a targeted manner. For the network side, this way is slightly complex, but it can achieve accurate transmission of the system message and completely avoid the situation that the system message is incorrectly transmitted to other invalid terminals that do not have the first attribute.
[0064] Secondly, the network node sends a system message to the terminal (e.g. all or part of the terminals within its coverage range, the range is not limited), and the system message carries the relevant indication information of the first attribute. In this way, for the terminal, when receiving the system message, it can determine whether it is the receiving end of the system message based on its own attribute message (denoted as the second attribute), and thus, if yes, it parses the system message; otherwise, if no, it can be directly discarded.
[0065] Thirdly, the network node can send a system message to the terminal (e.g. all or part of the terminals within its coverage range, the range is not limited), and the system message can be securely processed. In this way, for any UE within the coverage of the network node, if the UE can successfully parse the system message after receiving it, it proves that it is the receiving end that meets the first attribute; otherwise, if it cannot successfully parse it, it proves that it is not the receiving end of the system message. In this way, for the network side, it does not need to accurately distinguish the receiving end of each system message, but can securely process the information related to the first attribute (denoted as the first security information) and send the securely processed system message externally, which is simple and easy to operate; for the terminal, the terminal can receive the message, but whether the terminal meets the first attribute determines whether the terminal can successfully parse the system message, which can ensure that the system message can be successfully received by the correct and effective receiving end, and avoid that the system message is obtained by the incorrect and ineffective receiving end.
[0066] It should be understood that the above three ways can also be combined. For example, the network side can determine the receiving end based on the first attribute and send the securely processed system message to it. No further description is made.
[0067] Hereinafter, the specific implementation of the scheme is mainly described in the third encryption sending mode.
[0068] In an exemplary embodiment, the network node needs to securely process the system message before sending it, which specifically includes the following process:
[0069] S304-1, the network node determines the first security information based on the first attribute.
[0070] In specific implementation, the first security information can correspond to the first attribute. If the first attribute determined by the sending granularity is multiple, the first security information can correspond to the first attribute group. That is, for different first attributes, their first security information is different, so as to protect the system message from being incorrectly parsed by the invalid terminal that does not meet the first attribute, and to protect the secure transmission of the system message.
[0071] Specifically, the network side can maintain a correspondence between the first attribute and the first security information. Alternatively, the network side can generate the first security information matching the current sending granularity in real time based on a preset encryption algorithm and / or a parameter derived from a key. Details are described below.
[0072] S304-2, the network node performs security processing on the system message using the first security information, and sends the security-processed system message.
[0073] In an exemplary embodiment, the system message includes at least one system information SI or system information block SIB; at this time, the first security information can also include: security information of at least one SI; and / or, security information of at least one SIB.
[0074] The security processing mode can include but is not limited to: performing encryption processing on the system message using a security key. In this case, the first security information at least includes: a security key.
[0075] It should be noted that in this implementation, in order to ensure that the receiving end satisfying the first attribute on the side can successfully parse the system message, there can be two specific schemes as follows: Scheme 1, the first security information is shared between the network node and the terminal with the first attribute; or, Scheme 2, the first security information is independently maintained by the network node.
[0076] Specifically, for Scheme 1, the network node needs to generate the first security information first, and share it synchronously with the corresponding receiving end (i.e., the terminal with the first attribute), so that the terminal can use the first security information shared with the network node to implement the parsing processing of the system message after receiving the system message. Details of the first security information and its generation method are described below.
[0077] For Scheme 2, the network node can independently generate and maintain the first security information without synchronizing with the terminal side. Then, in this case, the terminal side needs to generate the first security information using its own attribute information when implementing the parsing of the system message, and accordingly perform message parsing.
[0078] Correspondingly, for the terminal, after receiving the system message, the following operations are also included:
[0079] S308, performing parsing processing on the system message.
[0080] Specifically, based on different maintenance methods of the first security information, the terminal side can have different parsing methods. Specifically, they include:
[0081] Corresponding to the aforementioned scheme 1, if the first security information is shared between the network node and the terminal with the first attribute, for the terminal, the terminal can utilize the first security information shared with the network node to perform parsing processing on the system message.
[0082] In this embodiment, the first security information is determined by the network node based on the first attribute corresponding to the system message. That is, the first security information is generated by the network node based on the first attribute and shared with the corresponding receiving end. The corresponding receiving end can then store or maintain the first security information in other self-defined ways. For example, the terminal can save the first security information in the SIM card.
[0083] It should be understood that if the first security information maintained by the terminal side cannot successfully parse the system message, it means that the terminal is not the receiving end of the system message. For example, the network side determines that the receiving end corresponding to the first attribute 1 is terminal 1 and terminal 2, and generates the first security information 1 based on the first attribute 1 and shares it with terminal 1 and terminal 2; and the network side determines that the receiving end corresponding to the first attribute 2 is terminal 3, and generates the first security information 2 based on the first attribute 2 and shares it with terminal 3. In this case, when the network side sends a certain system message to terminals 1-3, terminals 1-3 can each utilize the first security information maintained by themselves to decrypt it. If the system message corresponds to the first attribute 2, terminal 3 can successfully parse the system message, but terminals 1 and 2 cannot parse the system message.
[0084] Alternatively, corresponding to the aforementioned scheme 2, if the network node does not synchronize the first security information to its receiving end, for the terminal, the terminal can generate the first security information using the second attribute of the terminal corresponding to the first attribute, and perform decryption processing on the system message; wherein the system message is securely processed by the network node based on the first attribute.
[0085] In this embodiment, the terminal needs to generate the first security information by itself, and the generation is based on the second attribute possessed by the terminal. It should be noted that the second attribute used by the terminal here corresponds to the first attribute of the network side. The network side can send the system message in a certain granularity, and the granularity can be synchronized with the terminal side in advance by negotiation, pre-setting, pre-notification, etc. For example, if the network side sends the system message in a geographical granularity, the system message received by the terminal is processed by the first security information corresponding to a certain region. Then, for the terminal, the terminal can determine the region where it is located after receiving the system message, and based on the region where it is located, the terminal determines the first security information in the same way as the network side and attempts to decrypt the system message. If the region where the terminal is located (i.e. the second attribute) is consistent with the region corresponding to the system message (i.e. the first attribute), the first security information determined by the terminal based on the second attribute is consistent with the first security information determined by the network based on the first attribute, and the terminal as the receiver of the system message can successfully parse the content of the system message. Otherwise, if the region where the terminal is located (i.e. the second attribute) is inconsistent with the region corresponding to the system message (i.e. the first attribute), the terminal cannot successfully parse the content of the system message.
[0086] The first security information involved in the present disclosure can include but is not limited to at least one of the following: a security key, an encryption algorithm, an integrity algorithm, an intermediate key, an anchor key, a key parameter;
[0087] The key parameter includes at least one of the following: an encoding key, a count, a system message block sequence number, a system message block length, a country code, a region code, a service code, a terminal capability label, a terminal state label, a transmitted waveform type label, an antenna and / or base station height label, a terminal height label, a beam and / or beam group label, a TRP label, an SSB index, one or more cell labels, a cell type label, a channel characteristic label.
[0088] The security key is actually used for encrypting the system message, that is, the key obtained by key derivation based on the key parameter. Specifically, the present disclosure does not have special restrictions on the key derivation algorithm, but the key parameter involved in the key derivation algorithm is related to the actual scenario.
[0089] For example, FIG. 3 shows a schematic diagram of a flow process of a system message provided by the present disclosure. As shown in FIG. 3, NEA represents a key derivation process, and KEYSTREAM BLOCK represents a derived security key; and the five items of KEY (representing an encoding key, for example, a 128-bit encoding key), COUNT (representing a count, for example, a 32-bit count), SIB-number (representing an SIB number), LENGTH (the length of a system message block), and Area code / Service code / Country code (representing at least one of an area code, a service code, and a country code) are used as derivation parameters (i.e., the key parameters mentioned above) of a security key, and are used as input parameters of the key derivation process and are used to derive the security key.
[0090] As shown in FIG. 3, Sender represents a sending end, i.e., a network side in the present disclosure; and Receiver represents a receiving end, i.e., a terminal side in the present disclosure. As shown in FIG. 3, the network side and the terminal side can each perform key derivation based on the input parameters mentioned above, and can thereby implement encryption and decryption. Specifically, as the sending end, the network side uses a security key (i.e., KEYSTREAM BLOCK, i.e., the first security information) derived by using the first attribute to encrypt plaintext (PLAINTEXT BLOCK, i.e., a system message or information carried in the system message) into ciphertext (CIPHERTEXT BLOCK); the ciphertext is transmitted between the sending end and the receiving end; and as the receiving end of the system message, the terminal uses a security key (i.e., KEYSTREAM BLOCK, i.e., the first security information) derived by using the second attribute to decrypt the ciphertext (CIPHERTEXT BLOCK, i.e., the received system message) into plaintext (PLAINTEXT BLOCK, i.e., a system message or information carried in the system message). In this way, the secure transmission of the system message between the network node and the terminal is achieved.
[0091] It should be understood that FIG. 3 is only a schematic diagram, and the key parameters used to derive the security key in an actual scenario can be more or less, and the range can be one or more of the key parameters mentioned above, and no further description is given. The key derivation algorithm used by the network side and / or the terminal side should be consistent, and in an actual scenario, the key derivation algorithm can have multiple different forms, or the related key derivation algorithm in the prior art can be reused, and the key parameters mentioned above provided by the present disclosure are used as inputs of the key derivation algorithm to determine the security key. For ease of illustration, FIG. 4 and FIG. 5 show schematic diagrams of two different key derivation algorithms provided by the present disclosure.
[0092] As shown in FIG. 4 and FIG. 5, the key derivation algorithm can be based on the seed key K, first generate the encryption key CK and the integrity key IK, then after ARPE (an authentication credential storage and processing function, used to save authentication credentials) processing, the intermediate key is authenticated by the authentication function AUSF, and after the processing of the security anchor function SEAF, KAMF is obtained, and then the final security key can be obtained after some transformation processing.
[0093] As shown in FIG. 5, for the terminal, the general user identity module USIM in the terminal can generate the encryption key CK and the integrity key IK based on the seed key K, and provide them to the mobile device ME. Then, the ME performs AUSF, SEAF and other processing on these keys, and finally obtains the security key.
[0094] In the embodiment shown in FIG. 3, the network side can send the key derivation algorithm of the security key and the required key parameters (i.e. as the first security information) to the terminal side in advance, for example, the application layer of the core network can send the above information to the matching terminal in advance. Or, refer to the other ways described above, no longer described.
[0095] It should be noted that in any one of the above third encryption sending methods, the network side performs security processing on the system message, which means that part or all of the information in the system message can be encrypted using the security key. For example, in a system message, part of the SI can be encrypted and part of it can be disclosed. As described above, the security key used for the system message that is securely processed between the network node and the terminal can be determined based on the first security information.
[0096] Specifically, for the network side, the network side determines the first security information based on the first attribute, which can be specifically implemented as follows: mapping the first attribute into an attribute label, and then performing key derivation generation on the attribute label as an input parameter of the key derivation to obtain the security key.
[0097] And for the scenario that the terminal needs to perform key derivation, the terminal needs to map the second attribute of the terminal corresponding to the first attribute into an attribute label, and then perform key derivation generation on the attribute label as an input parameter of the key derivation to obtain the security key.
[0098] In addition, before the implementation of the present scheme, the network side can also synchronize the first security information to the terminal side in order to realize the targeted system message transmission of the present scheme. At this time, in this embodiment, the communication method further comprises:
[0099] Operation 1: The network node sends the first security information corresponding to the first attribute of the system message according to the second attribute of the terminal to the terminal with the second attribute.
[0100] The second attribute is used to describe the attribute information of the terminal.
[0101] For the network side, the network side can obtain the second attribute of each terminal based on the terminal registration process and / or the terminal initial access process, and / or the connection establishment process of the terminal and the network node. For the terminal, the terminal can send the second attribute to the network node in the terminal registration process and / or the terminal initial access process; wherein the second attribute is used to describe the attribute information of the terminal; or in the connection establishment process of the terminal and the network node, the second attribute is sent to the network node.
[0102] It should be understood that the terminal needs to be registered with the network and access the network when using network services. In the process of interaction between the terminal and the network node for registration and / or access to the network, the terminal can report its own second attribute to the network side. For example, at least one of the communication type, subscription service, terminal capability, etc. of the terminal is reported. When specifically implemented, the above-mentioned second attribute can be carried in any one message initiated by the terminal to the network side, for example, the second attribute of the terminal can be carried in the registration request, or the second attribute can be carried in any one message sent to the network node in the registration interaction process, or the terminal can also send its own second attribute to the network node in response to the request of the network side, all of which are not exhaustive.
[0103] When specifically implemented, the first attribute of the system message corresponding to the second attribute of the terminal can be simply understood as the case where they are consistent, or the case where the second attribute fully meets the first attribute. In this case, the receiving end of the first security information corresponding to the first attribute is the terminal with the second attribute. For example, if the first attribute is area 1, which includes a specific geographical range of about fifty square meters, and the second attribute of a certain terminal is a location point within area 1, the first security information corresponding to the first attribute (i.e. area 1) can be sent to the terminal. For example, if the second attribute of the terminal is broadcast service 1, and the first attribute of the system message to be sent by the network side is also broadcast service 1, the network side can send the first security information corresponding to the first attribute of broadcast service 1 to the terminal. For example, if the second attribute of the terminal is the flight height of the terminal of 100 meters, and the coverage height of the cell or beam provided by the first attribute of the network node is 80-120 meters, the second attribute meets the required range of the first attribute, and the first security information corresponding to the first attribute of "coverage height is 80-120 meters" can be sent to the terminal.
[0104] Of course, the first attribute can also be multiple, and then the receiving end of the first security information corresponding to the multiple first attributes (which can be regarded as a first attribute group) is the terminal with the second attribute capable of meeting the multiple first attributes. For example, if the first attribute is region 1 and broadcast service 2, the sending end of the first security information corresponding to the first attribute is the terminal located in the region 1 and having subscribed to the broadcast service 2. At this time, if the second attribute of a certain terminal 1 is a certain position point located in the region 1 and having subscribed to the broadcast service 2, the network side can send the first security information corresponding to the first attribute to the terminal 1. Or, if the second attribute of a certain terminal 2 is located in region 2 and has subscribed to the broadcast service 2, or if the second attribute of a certain terminal 3 is located in region 1 and has not subscribed to the broadcast service 2, neither the terminal 2 nor the terminal 3 is the receiving end of the first security information corresponding to the first attribute, and the network side does not need to send the first security information to the terminal 2 and the terminal 3.
[0105] Here, the first security information sent by the network node can be a security key determined by the network side, or can also be a key derivation algorithm and a key parameter.
[0106] For example, in operation 1, the network node informs the terminal of the first security information, which can also be achieved by means of the registration and / or access process of the terminal, that is, the first security information is carried in the message sent from the network side to the terminal side.
[0107] In an exemplary embodiment, the network node can send the first security information corresponding to the first attribute to the terminal with the second attribute by at least one of the NAS message, the RRC message, the MAC signaling, and the DCI signaling. For the terminal, the first security information from the network node can also be received by at least one of the NAS message, the RRC message, the MAC signaling, and the DCI signaling.
[0108] Operation 2, the terminal receives the first security information from the network node.
[0109] Operation 3, the terminal stores the first security information.
[0110] In this way, after the terminal side receives the first security information, it can be stored securely. The storage mode and location are not limited. For example, it can be stored in the memory or the SIM card.
[0111] To sum up, in the present disclosure, the network side can obtain the second attribute of each terminal through the registration and / or network access process of the terminal with the network side, and / or the connection establishment process of the terminal and the network node, and / or can also realize the interactive storage of the first security information. In this process, the terminal can even not have established a connection with the network side, and the interaction and further application of the security information can be realized. Compared with the traditional technology in which the security information is only generated and established when the terminal enters the connected state, the present scheme can exchange security information between the terminal and the network side earlier, realize the secure encryption and targeted sending of system messages, and maintain the system communication security to a greater extent.
[0112] Taking an actual scenario as an example, first, the network side can determine the region (including at least one of a geographical position, a height, a region, and a country), a service type (such as an XR service, a high-precision timing service, and the like), a communication type (such as SL, NTN, UAV, VTG, MBS Multicast, MBS broadcast, and the like), a capability of a UE, a state of the UE (such as a speed of the UE, a height of the UE, and an angle of the UE), and the like corresponding to the SIB / SI. In this way, the first attribute corresponding to the system message is determined. In addition, the network side can also determine the region, the supported service, the subsequent communication type, the capability of the UE, and the state of the UE, and the like, according to the UE capability, the UE state, and the coarse position information reported in the terminal registration and / or initial access process, as the second attribute. Then, the network side can further send the first security information to the terminal through at least one of a NAS message, an RRC message, MAC signaling, and DCI signaling during the terminal registration and / or initial access process, based on the first attribute and the second attribute of each terminal, that is, inform the terminal of the encryption algorithm, the key parameter, and the security key corresponding to the encrypted system message (for example, SIB) of the network side matched with the terminal. In this way, the terminal can determine the security key according to the first security information corresponding to the SIB, and use the security key to parse the received system message.
[0113] In addition, it should be further pointed out that the first security information used by the network side and the terminal side in the present disclosure can be dynamic.
[0114] Specifically, the first security information can be based on a dynamic update initiated by the network side, or can also be a dynamic update requested by the terminal side.
[0115] In a possible scenario, the network side can also actively initiate dynamic updating of the first security information. For example, the key parameter can be dynamically updated due to changes in the actual communication scenario. For example, the area code can be a dynamic code that can be dynamically updated, and for another example, the channel characteristic label can also be dynamically changed or changed based on actual conditions, without being exhaustive. When the key parameter is dynamically changed, the network side can dynamically update the first security information corresponding to each system message or each first attribute based on this, and notify the corresponding receiving end. For example, the network side can also actively update the key derivation algorithm, key parameter, security key, and the like based on its business needs or other reasons.
[0116] In the scenario described above, the security information update actively initiated by the network side can be implemented by the network side sending the updated security information to the terminal. In specific implementation, each terminal that has changed can be sent individually, or group notification can be performed through group paging.
[0117] In an example embodiment, the method can further include the following operations:
[0118] Operation a1, the network node updates the first security information corresponding to the first attribute to obtain updated third security information.
[0119] Operation a2, the network node sends a group paging message, and the group paging message carries the third security information and a radio network temporary identity (RNTI). The RNTI is shared between the network node and the receiving end of each system message corresponding to the first attribute.
[0120] The group paging message can also carry the first security information, and the first security information can be used as an encoding key (i.e., KEY in FIG. 3) to determine a security key.
[0121] The RNTI is shared information between the network node and the receiving end of each system message. When the RNTI is carried in the group paging message, it means that only the UE that saves the matching RNTI can decipher the paging message of the security information of the specific SIB.
[0122] Operation a3, the terminal receives the group paging message from the network node.
[0123] Operation a4, the terminal parses and processes the group paging message using the RNTI to obtain the third security information. The third security information is updated by the network node from the first security information corresponding to the first attribute.
[0124] Operation a4, the terminal determines a security key based on the third security information and stores; or, stores the third security information.
[0125] In a specific implementation, if the first security information is also carried in the group paging message, the terminal can take the first security information as an encoding key, determine a security key in a manner indicated by the third security information, and store the security key.
[0126] In addition, in another possible scenario, the first security information can also be dynamically updated in response to an active request from the terminal side. For example, the terminal can request the network side to update the first security information at a regular time, or can request the network side to update the first security information based on a change in the second attribute of the terminal.
[0127] For example, in a possible scenario, the foregoing area code can be a dynamic code. When the UE registers the network (before the UE switches to idle), the network side can send the first security information to the UE through NAS according to the second attribute of the UE; or, before the UE enters a certain cell, the first security information is acquired through another network node in a connected state. After the UE acquires the first security information, the UE can start a timer, and the duration of the timer can be customized. When the timer expires, the UE can request the network side to reacquire updated security information.
[0128] For another example, in another possible scenario, one or more of the location of the UE, the supported service, the communication type, the UE capability, the UE state, and the like can dynamically change in an actual scenario. For example, a user moves from country A to country B, for another example, the UE newly subscribes to service A and cancels service B, for another example, the state of the UE changes from ground to high altitude, and the like, without being exhaustive. When the second attribute of the UE changes, the UE can also actively request the network side to update or synchronize new security information.
[0129] At this time, the method can further include the following process:
[0130] Operation b1, the terminal sends a first request message to the network node, where the first request message is used to request to acquire or update or synchronize security information.
[0131] As described above, the terminal can actively send the first request message to the network side based on a change in the second attribute of the terminal, or based on the expiration of a timer, or for other reasons, so that the network side feeds back security information adapted to the current second attribute of the terminal.
[0132] That is, for the terminal: when the timer expires, the terminal sends the first request message to the network node; wherein the timer is started from receiving the first security information; or when the second attribute of the terminal changes, the terminal sends the first request message to the network node.
[0133] Operation b2, the network node receives the first request message from any one terminal, and the first request message is used to request to obtain or update or synchronize security information.
[0134] Operation b3, the network node determines the second security information corresponding to the current second attribute of the terminal based on the first attribute of the system message corresponding to the second attribute of the terminal.
[0135] It should be noted that the first security information and the second security information can be the same or different, which depends on whether at least one of the second attribute of the terminal, the first attribute, the correspondence between the first attribute and the second attribute, the encryption algorithm key parameter changes. If all these information do not change, for example, only the timer on the terminal side expires, then the first security information and the second security information do not change, and the network side can directly feedback to it. If any of these information changes, the network side can determine the second security information corresponding to the first attribute of the network node based on the foregoing method, and send the updated second security information to the terminal. In other words, the second security information is determined based on the second attribute of the terminal and the first attribute of each system message.
[0136] Operation b4, the network node sends the second security information to the terminal.
[0137] Operation b5, the terminal receives and stores the second security information from the network node; the second security information is determined based on the second attribute of the terminal and the first attribute of each system message.
[0138] In addition, in a further possible embodiment, the first request message in operation b1 can carry the first security information, which can be used by the network node for security verification of the terminal. Taking the timing update scenario as an example, the UE can request the network side to reacquire the security information after the timer expires, and the last security information can be carried in the request. In this way, the network side can confirm the identity of the UE and realize the identity verification of the UE.
[0139] Further, further, the security information updating procedure can be initiated actively when the UE is in connected state or inactive state. For example, if the terminal initiates the security information updating procedure actively based on the change of the second attribute of the terminal, and the UE is in idle state, the UE can first enter the connected state to perform the above operations, or perform the above operations in the inactive state.
[0140] Through the above embodiments, the targeted security transmission of system messages is realized.
[0141] In an exemplary embodiment, when the first information content of the system message is applicable to the first area, the system message carries the area indication information of the first area of the first information content;
[0142] The area indication information is indicated by at least one of the following: a reference location point plus a radius, a region identifier, a country identifier, a list of cells and / or beams, a list of TPRs, a set of location coordinates of multiple boundary points, a shape indication of a polygon, a mapping cell identifier.
[0143] In addition, when the system message is for a specific SIB and / or SI area, the system message can further carry the area indication information of the specific SIB and / or SI area. In this disclosure, the area indication information can be indicated by at least one of the following: geographical (e.g., at least one of geographical location, altitude, region, country) indication, SI and service (e.g., previous XR service, high-precision timing service, etc.) indication, SI and communication type (e.g., previous SL, NTN, UAV, ATG, MBS Multicast, MBS broadcast, etc.) indication.
[0144] When the specific SIB and / or SI area is circular, the area indication information carries mapping cell information; or when the specific SIB and / or SI area is polygonal, the area indication information carries at least boundary point location.
[0145] For example, the content of the system message can be at least one service area information, such as but not limited to at least one of MBS, ETWS and CMAS service area information. It should be understood that the first service area information corresponds to the first area, the second service area information corresponds to the second area, the third service area information corresponds to the third area, and so on.
[0146] Specifically, please refer to FIG. 6, which shows a region indication diagram provided by the present disclosure. As shown in FIG. 6, the region indication can be at least as follows:
[0147] Circle, used to indicate the type of ground cell, can be specifically indicated by mapping cell information. Among them, as shown in the left part of FIG. 6, the mapping cell information can include but is not limited to at least one of the mapped cell ID, the virtual cell, one reference location point plus a radius.
[0148] Polygon, as shown in the right part of FIG. 6, can be composed of position coordinates of multiple boundary points; further, it can also include shape indication of the polygon. For example, the indication that it is a quadrilateral.
[0149] Further, for example, the resource pool matching the UE is broadcast in the SIB, if the non-matching UE uses the resource in the resource pool to send data later, the RRC connection of the UE is interrupted, and the identity of the UE is informed to the core network, and the service of the UE is further limited.
[0150] The communication method provided by the present disclosure can be applied to a satellite network. Therefore, it may involve a scenario of an area where at least two satellites have overlapping coverage, for example, in a soft switch scenario, especially in a quasi-fixed scenario, the satellite overlapping coverage is particularly prominent. For example, if the multi-satellite overlapping coverage scenario is a same frequency coverage scenario, since the cell signal in the NTN system is a LOS path, the same frequency interference of the overlapping coverage is much stronger than that of the same frequency overlapping coverage of the ground base station, and almost cannot communicate normally. Moreover, in the moving scenario, the coverage range of the satellite is dynamically changing, and the control is more difficult.
[0151] For this case, that is, when the system message is a multi-satellite merging message in a same frequency coverage scenario, the present disclosure adopts the strategy of sending the system messages corresponding to each satellite respectively in time division. Among them, the sending time of the system messages corresponding to any two satellites is different.
[0152] In other words, the merged system message content of multiple satellites is sent in the overlapping coverage area, and the multiple satellites are sent in time division; at the same time, the sending of the SSB is staggered. In addition, the problem of transmission delay difference between different UEs and multiple satellites also needs to be considered, and the sending of data can also be distinguished by scheduling restriction.
[0153] The present disclosure also provides a communication device. FIG. 7 shows a structural block diagram of a communication device provided by the present disclosure, as shown in FIG. 7, the communication device 700 includes:
[0154] The transceiver unit 701 is configured to send the system message with the first attribute of the system message as the sending granularity;
[0155] The first attribute includes at least one of the following: position or region, service, communication type, terminal capability, terminal state, transmitted waveform type, height of antenna and / or base station, height of terminal, beam and / or beam group, transmission / reception point (TRP), SSB index, one or more cells, cell type, and channel characteristic; and the channel characteristic includes at least one of the following: Doppler shift, Doppler spread, delay spread, average delay, and spatial reception parameter.
[0156] In an example embodiment, the communication apparatus 700 is further configured to carry at least one of the following in the system message: resource information of the related downlink (DL) beam and / or cell, position information, region information, transmission time information, and capacity information.
[0157] and / or
[0158] The system message carries at least one of the following: resource information of the related DL beam and / or cell, position information, region information, transmission time information, and capacity information.
[0159] In an example embodiment, the transceiver 701 is further configured to determine first security information based on the first attribute, perform security processing on the system message by using the first security information, and transmit the security-processed system message; the first security information is shared between the network node and the terminal with the first attribute; or the first security information is independently maintained by the network node.
[0160] In an example embodiment, the transceiver 701 is further configured to determine first security information based on the first attribute, perform security processing on the system message by using the first security information, and transmit the security-processed system message; the first security information is shared between the network node and the terminal with the first attribute; or the first security information is independently maintained by the network node.
[0161] In an example embodiment, the transceiver 701 is further configured to perform encryption processing on part or all of the information in the system message by using a security key; the security key is determined based on the first security information.
[0162] In an example embodiment, the transceiver 701 is further configured to map the first attribute into an attribute label, and perform key derivation on the attribute label as an input parameter to generate the security key.
[0163] In an example embodiment, the transceiver 701 is further configured to: the system message comprises at least one system information (SI) or system information block (SIB); and the first security information comprises: security information of at least one SI; and / or, security information of at least one SIB.
[0164] In an example embodiment, the transceiver 701 is further configured to: according to the first attribute of the system message corresponding to the second attribute of the terminal, send the first security information corresponding to the first attribute to the terminal with the second attribute; wherein the second attribute is used to describe the attribute information of the terminal.
[0165] In an example embodiment, the transceiver 701 is further configured to at least one of: based on a terminal registration process and / or a terminal initial access process, obtain the second attribute of each terminal.
[0166] based on a connection establishment process of the terminal and the network node, obtain the second attribute of each terminal.
[0167] In an example embodiment, the transceiver 701 is further configured to: send the first security information corresponding to the first attribute to the terminal with the second attribute through at least one of: NAS message, RRC message, MAC signaling, and DCI signaling.
[0168] In an example embodiment, the communication device 700 is further configured to: receive a first request message from any one terminal, the first request message being used to request to obtain or update or synchronize security information.
[0169] based on the first attribute of the system message corresponding to the second attribute of the terminal, determine the second security information currently corresponding to the terminal; and send the second security information to the terminal; wherein the first security information and the second security information are the same or different.
[0170] In an example embodiment, the communication device 700 is further configured to: based on the first security information, perform security check on the terminal.
[0171] In an example embodiment, the communication apparatus 700 is further configured to update the first security information corresponding to the first attribute to obtain updated third security information, and send a group paging message carrying the third security information and a radio network temporary identifier (RNTI), wherein the RNTI is shared between the network node and a receiving end of each system message corresponding to the first attribute, and wherein the group paging message further carries the first security information, and the first security information is used as an encoding key to determine a security key.
[0172] In an example embodiment, the communication apparatus 700 is further configured to send each system message corresponding to each satellite in time division respectively, and the sending time of the system messages corresponding to any two satellites is different.
[0173] In an example embodiment, the communication apparatus 700 is further configured to, when the first information content of the system message is applicable to a first area, carry area indication information of the first information content of the first area in the system message.
[0174] The area indication information is indicated by at least one of the following: a reference location point plus a radius, a geographical identifier, a country identifier, a list of cells and / or beams, a list of TPRs, a plurality of boundary points, a shape indication of a polygon, a mapping cell identifier.
[0175] The present disclosure also provides a communication apparatus. FIG. 8 shows a structural block diagram of another communication apparatus provided by the present disclosure. As shown in FIG. 8, the communication apparatus 800 includes:
[0176] A transceiver unit 801 configured to receive a system message from a network node, wherein the system message is sent with a first attribute as a sending granularity.
[0177] The first attribute includes at least one of the following: a location or a geographical area, a service, a communication type, a terminal capability, a terminal state, a sending waveform type, an antenna and / or base station height, a terminal height, a beam and / or beam group, a TRP, an SSB index, one or more cells, a cell type, and a channel characteristic, wherein the channel characteristic includes at least one of the following: a Doppler shift, a Doppler spread, a delay spread, an average delay, and a spatial reception parameter.
[0178] In an example embodiment, the communication apparatus 800 is further configured to determine at least one of the following information based on the system message: a location or a geographical area corresponding to a beam sending the system message, a sending waveform type, an antenna and / or base station height, an angle between an antenna and the ground, a terminal height, a beam and / or beam group information, TRP information, an SSB index, one or more cell information, a cell type, and a channel characteristic information.
[0179] In an example embodiment, the communication apparatus 800 is further configured to carry at least one of resource information, location information, area information, transmission time information, capacity information of the related DL beam and / or cell in the system message.
[0180] and / or;
[0181] carry at least one of resource information, location information, area information, transmission time information, PRACH resource information, capacity information of the related UL beam and / or cell corresponding to the DL beam and / or cell in the system message.
[0182] In an example embodiment, the communication apparatus 800 is further configured to parse the system message by using first security information shared with the network node; wherein the first security information is determined by the network node based on a first attribute corresponding to the system message.
[0183] or,
[0184] generate the first security information by using a second attribute of the terminal corresponding to the first attribute, and decrypt the system message; wherein the system message is securely processed by the network node based on the first attribute.
[0185] In an example embodiment, the communication apparatus 800 is further configured to include at least one of the following in the first security information: security key, encryption algorithm, integrity algorithm, intermediate key, anchor key, key parameter; wherein the key parameter includes at least one of the following: encoding key, count, system message block sequence number, system message block length, country code, area code, service code, terminal capability label, terminal state label, base station transmitted waveform type label, antenna and / or base station height label, terminal height label, beam and / or beam group label, TRP label, SSB index, one or more cell labels, cell type label, channel characteristic label.
[0186] In an example embodiment, the communication apparatus 800 is further configured to map the second attribute of the terminal corresponding to the first attribute to an attribute label; and perform key derivation by using the attribute label as an input parameter of key derivation to obtain the security key.
[0187] In an example embodiment, the communication apparatus 800 is further configured to encrypt part or all of the information in the system message by using a security key; wherein the security key is determined based on the first security information.
[0188] In an example embodiment, the communication apparatus 800 is further configured to: the system message comprises at least one system information (SI) or system information block (SIB); the first security information comprises: security information of at least one of the SI; and / or, security information of at least one of the SIB.
[0189] In an example embodiment, the communication apparatus 800 is further configured to: receive the first security information from the network node; and store the first security information.
[0190] In an example embodiment, the communication apparatus 800 is further configured to: send, to the network node, a second attribute in at least one of: a terminal registration procedure and / or a terminal initial access procedure; wherein the second attribute is used to describe an attribute information of the terminal.
[0191] Or,
[0192] In an example embodiment, the communication apparatus 800 is further configured to: send, to the network node, a second attribute in a connection establishment procedure between the terminal and the network node.
[0193] In an example embodiment, the communication apparatus 800 is further configured to: receive the first security information from the network node via at least one of: a NAS message, a RRC message, MAC signaling, and DCI signaling.
[0194] In an example embodiment, the communication apparatus 800 is further configured to: send, to the network node, a first request message, wherein the first request message is used to request to acquire or update or synchronize security information; receive and store second security information from the network node, wherein the second security information is determined based on a second attribute of the terminal and a first attribute of each system message; and wherein the first security information is the same as or different from the second security information.
[0195] In an example embodiment, the communication apparatus 800 is further configured to: send, to the network node, the first request message when a timer expires; wherein the timer is started when the first security information is received.
[0196] Or,
[0197] In an example embodiment, the communication apparatus 800 is further configured to: send, to the network node, the first request message when the second attribute of the terminal changes.
[0198] In an example embodiment, the communication apparatus 800 is further configured to: carry the first security information in the first request message, wherein the first security information is used for security verification of the terminal by the network node.
[0199] In an example embodiment, the communication apparatus 800 is further configured to: receive a group paging message from the network node; the group paging message carries third security information and a radio network temporary identifier (RNTI); wherein the RNTI is shared between the network node and a receiving end of each system message corresponding to the first attribute; parse the group paging message using the RNTI to obtain the third security information; wherein the third security information is obtained by the network node updating the first security information corresponding to the first attribute; determine a security key based on the third security information and store the security key; or store the third security information.
[0200] In an example embodiment, the communication apparatus 800 is further configured to: determine a security key using the first security information as an encoding key in a manner indicated by the third security information; and store the security key.
[0201] In an example embodiment, the communication apparatus 800 is further configured to: when the first information content of the system message is applicable to a first region, carry region indication information of the first region in which the first information content is located in the system message.
[0202] The region indication information is indicated by at least one of the following: a reference location point plus a radius, a geographical identifier, a country identifier, a list of cells and / or beams, a list of TPRs, a plurality of boundary point position coordinates, a shape indication of a polygon, and a mapping cell identifier.
[0203] The present disclosure also provides a communication system. FIG. 9 shows a schematic diagram of a communication system provided by the present disclosure. As shown in FIG. 9, the communication system includes a network node and a terminal.
[0204] The terminal is configured to perform the communication method performed by the terminal in any of the preceding embodiments.
[0205] The network node is configured to perform the communication method performed by the network node in any of the preceding embodiments.
[0206] In an example embodiment, the network node can be a network node of a satellite network.
[0207] FIG. 10 is a hardware block diagram of an electronic device according to an embodiment of the present disclosure. The electronic device 1000 according to the embodiment of the present disclosure includes at least a memory, a processor, and a computer program stored on the memory, and the processor executes the computer program to implement the communication method described in any of the preceding embodiments.
[0208] The electronic device 1000 shown in FIG. 10 specifically includes a central processing unit (CPU) 1001, a graphics processing unit (GPU) 1002, and a memory 1003. These units are connected to each other through a bus 1004. The central processing unit (CPU) 1001 and / or the graphics processing unit (GPU) 1002 can be used as the above-mentioned processor, and the memory 1003 can be used as the above-mentioned memory storing computer readable instructions. In addition, the electronic device 1000 can further include a communication unit 1005, a storage unit 1006, an output unit 1007, an input unit 1008, and an external device 1009, which are also connected to the bus 1004.
[0209] FIG. 11 is a schematic diagram of a computer readable storage medium according to an embodiment of the present disclosure. As shown in FIG. 11, the computer readable storage medium 1100 according to the embodiment of the present disclosure has computer program / instructions 1101 stored thereon. The computer program / instructions 1101, when executed by a processor, implement the communication method described in any of the preceding embodiments of the present disclosure. The computer readable storage medium includes, but is not limited to, for example, volatile memory and / or non-volatile memory. The volatile memory may, for example, include random access memory (RAM) and / or cache memory, etc. The non-volatile memory may, for example, include read-only memory (ROM), hard disk, flash memory, optical disc, magnetic disc, etc.
[0210] The present disclosure further provides a computer program product, including computer program / instructions, wherein the computer program / instructions, when executed by a processor, implement the communication method described in any of the preceding embodiments of the present disclosure.
[0211] The basic principles of the present disclosure are described above in combination with specific embodiments, but it should be noted that the advantages, benefits, effects, etc. mentioned in the present disclosure are only examples and are not limiting, and these advantages, benefits, effects, etc. cannot be considered as mandatory for each embodiment of the present disclosure. In addition, the above-mentioned specific details are only for the purpose of example and understanding, and are not limiting, and the above-mentioned details do not limit the present disclosure to the above-mentioned specific details.
[0212] The block diagrams of devices, apparatuses, equipment, systems referred to in the present disclosure are merely illustrative examples and are not intended to require or imply that the connection, arrangement, configuration must be as shown in the block diagrams. These devices, apparatuses, equipment, systems can be connected, arranged, configured in any manner as will be appreciated by those skilled in the art. Words such as "include," "contain," "have," etc. are open-ended words that are to be interpreted to mean "including but not limited to," and are to be interpreted not to exclude other items. The words "or" and "and" as used herein are to be interpreted as the word "and / or," and are to be interpreted not to exclude other items. The word "such as" as used herein is to be interpreted as the phrase "such as but not limited to," and is to be interpreted not to exclude other items.
[0213] Also, as used herein, the "or" as used in the context of "at least one of A, B or C" is to be interpreted as "at least one of A, at least one of B, or at least one of C," and not as "at least one of AB, at least one of AC, or at least one of BC." Further, the phrase "example of" as used herein is to be interpreted as "one example of, among other examples," and not to be interpreted as "one example of, and not other examples."
[0214] It is also to be noted that in the systems and methods of the present disclosure, various components or operations can be split and / or recombined. Such splitting and / or recombining is to be considered as an equivalent of the present disclosure.
[0215] Various changes, modifications and alterations in the teachings and techniques described herein can be made without departing from the teachings defined by the appended claims. Moreover, the scope of the claims of the present disclosure is not limited to specific aspects described herein. The processes, machines, manufactures, compositions of matter, means, methods, and steps for accomplishing the same contained herein can be practiced or implemented in various ways, including as current existing means or methods or as later developed equivalents. Thus, the present disclosure is not intended to be limited to the aspects shown, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
[0216] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use the disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the generic principles defined herein can be applied to other aspects without departing from the scope of the disclosure. Thus, the present disclosure is not intended to be limited to the aspects shown herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
[0217] The foregoing description has been presented for the purposes of illustration and description. Furthermore, the description is not intended to limit the embodiments of the disclosure to the forms disclosed herein. Although the various example aspects and embodiments have been described herein with regard to particular aspects and embodiments, those skilled in the art will recognize that certain modifications, changes, substitutions, additions and sub-combinations can be made without departing from the spirit of the disclosure.
Claims
1. A communication method, wherein, The method is applied to a network node, and the method comprises: sending a system message with a first attribute of the system message as a sending granularity; wherein the first attribute comprises at least one of the following: location or region, service, communication type, terminal capability, terminal state, transmitted waveform type, height of antenna and / or base station, height of terminal, beam and / or beam group, transmission / reception point (TRP), SSB index, one or more cells, type of cell, channel characteristic; wherein the channel characteristic comprises at least one of the following: Doppler shift, Doppler spread, delay spread, average delay, spatial reception parameter.
2. The method of claim 1, wherein, at least one of the following is carried in the system message: resource information of a related downlink (DL) beam and / or cell, location information, region information, transmission time information, capacity information; and / or; at least one of the following is carried in the system message: resource information of an uplink (UL) beam and / or cell corresponding to the related DL beam and / or cell, location information, region information, transmission time information, physical random access channel (PRACH) resource information, capacity information.
3. The method of claim 1 or 2, wherein, The method comprises: determining first security information based on the first attribute; performing security processing on the system message by using the first security information, and sending the system message after security processing.
4. The method of claim 3, wherein, The first security information comprises at least one of the following: security key, encryption algorithm, integrity algorithm, intermediate key, anchor key, key parameter; wherein the key parameter comprises at least one of the following: encoding key, count, system message block sequence number, system message block length, country code, region code, service code, terminal capability label, terminal state label, transmitted waveform type label, height of antenna and / or base station label, height of terminal label, beam and / or beam group label, TRP label, SSB index, one or more cell labels, type of cell label, channel characteristic label.
5. The method of claim 3, wherein, Part or all of the information in the system message is encrypted by using a security key; wherein the security key is determined based on the first security information.
6. The method of claim 5, wherein, The method comprises: mapping the first attribute into an attribute label; performing key derivation by using the attribute label as an input parameter of key derivation to obtain the security key.
7. The method of claim 3, wherein, The system message comprises at least one system information (SI) or system information block (SIB); The first security information comprises: security information of at least one SI; and / or, security information of at least one SIB.
8. The method of claim 3, wherein, The method further comprises: sending, to a terminal with a second attribute, first security information corresponding to a first attribute of a system message corresponding to the second attribute of the terminal; wherein the second attribute is used to describe attribute information of the terminal.
9. The method of claim 8, wherein, The method further comprises at least one of the following: obtaining the second attribute of each terminal based on a terminal registration process and / or a terminal initial access process; obtaining the second attribute of each terminal based on a connection establishment process of the terminal and the network node.
10. The method of claim 8, wherein, The sending the first security information corresponding to the first attribute to the terminal with the second attribute comprises: The sending the first security information corresponding to the first attribute to the terminal with the second attribute comprises at least one of the following: NAS message, RRC message, MAC signaling, and DCI signaling.
11. The method of any one of claims 1-10, wherein, The method further comprises: receiving a first request message from any terminal, the first request message being used to request to obtain or update or synchronize security information; determining second security information currently corresponding to the terminal based on a first attribute of a system message corresponding to a second attribute of the terminal; sending the second security information to the terminal; wherein the first security information is the same as or different from the second security information.
12. The method of claim 11, wherein, The first request message carries the first security information. Before the sending the second security information to the terminal, the method further comprises: performing security verification on the terminal based on the first security information.
13. The method of any one of claims 1-12, wherein, The method further comprises: updating the first security information corresponding to the first attribute to obtain third security information after the update; sending a group paging message, the group paging message carrying the third security information and a radio network temporary identifier (RNTI); wherein the RNTI is shared between the network node and a receiving end of each system message corresponding to the first attribute; wherein the group paging message further carries the first security information; and the first security information is used as an encoding key to determine a security key.
14. The method of any one of claims 1-13, wherein, When the system message is a multi-satellite combined message in a same-frequency coverage scenario, the sending the security-processed system message comprises: sending the system message corresponding to each satellite in time division respectively; wherein the sending time of the system message corresponding to any two satellites is different.
15. The method of any one of claims 1-14, wherein, When the first information content of the system message is applicable to a first area, the system message carries area indication information of the first area of the first information content; The area indication information is indicated by at least one of the following: a reference location point plus a radius, a region identifier, a country identifier, a list of cells and / or beams, a list of TPRs, a plurality of boundary points, a shape indication of a polygon, and a mapping cell identifier.
16. A communication method, wherein, The method applied to a terminal comprises: receiving a system message from a network node, the system message being sent with a first attribute as a sending granularity; wherein the first attribute comprises at least one of the following: location or region, service, communication type, terminal capability, terminal state, waveform type of sending, height of antenna and / or base station, height of terminal, beam and / or beam group, TRP, SSB index, one or more cells, type of cell, and channel characteristics; wherein the channel characteristics comprise at least one of the following: Doppler shift, Doppler spread, delay spread, average delay, and spatial reception parameter.
17. The method of claim 16, wherein, The method comprises: Based on the system message, at least one of the following information is determined: the location or region corresponding to the beam for sending the system message, the type of the waveform sent, the height of the antenna and / or base station, the angle between the antenna and the ground, the height of the terminal, the information of the beam and / or beam group, TRP information, SSB index, the information of one or more cells, the type of the cell, and the information of the channel characteristics.
18. The method of claim 16, wherein, The system message carries at least one of the following information of the related DL beam and / or cell: resource information, location information, region information, sending time information, and capacity information. And / or The system message carries at least one of the following information of the related DL beam and / or cell: resource information, location information, region information, sending time information, PRACH resource information, and capacity information.
19. The method of any one of claims 16-18, wherein, The method further comprises: The first security information shared with the network node is used to parse and process the system message; wherein the first security information is determined by the network node based on the first attribute corresponding to the system message. Or The first security information is generated by using the second attribute of the terminal corresponding to the first attribute, and the system message is decrypted; wherein the system message is separately processed by the network node based on the first attribute.
20. The method of claim 19, wherein, The first security information comprises at least one of the following: security key, encryption algorithm, integrity algorithm, intermediate key, anchor key, and key parameter. The key parameter comprises at least one of the following: encoding key, count, system message block sequence number, system message block length, country code, region code, service code, terminal capability label, terminal state label, waveform type label sent by the base station, height label of the antenna and / or base station, height label of the terminal, beam and / or beam group label, TRP label, SSB index, one or more cell labels, cell type label, and channel characteristic label.
21. The method of claim 19, wherein, The first security information comprises a security key; and the generation of the first security information by using the second attribute of the terminal corresponding to the first attribute comprises: The second attribute of the terminal corresponding to the first attribute is mapped to an attribute label; The attribute label is used as an input parameter for key derivation to generate the security key.
22. The method of claim 19, wherein, Part or all of the information in the system message is encrypted by using the security key. The security key is determined based on the first security information.
23. The method of claim 19, wherein, The system message comprises at least one system information (SI) or system information block (SIB). The first security information comprises: security information of at least one SI; and / or, security information of at least one SIB.
24. The method of any one of claims 16-23, wherein, The method further comprises: The first security information is received from the network node; The first security information is stored.
25. The method of claim 24, wherein, The method further comprises at least one of the following: In the terminal registration process and / or terminal initial access process, the second attribute is sent to the network node; wherein the second attribute is used to describe the attribute information of the terminal. Or In a connection establishment procedure between the terminal and the network node, a second attribute is sent to the network node.
26. The method of claim 24, wherein, The first security information received from the network node includes: The first security information received from the network node is received through at least one of the following: NAS message, RRC message, MAC signaling, and DCI signaling.
27. The method of any one of claims 16-26, wherein, The method further includes: A first request message is sent to the network node, and the first request message is used to request to obtain or update or synchronize security information. Second security information is received and stored from the network node, and the second security information is determined based on the second attribute of the terminal and the first attribute of each system message. The first security information is the same as or different from the second security information.
28. The method of claim 27, wherein, The first request message sent to the network node includes: When a timer expires, the first request message is sent to the network node, and the timer is started when the first security information is received. Or, When the second attribute of the terminal changes, the first request message is sent to the network node.
29. The method of claim 27, wherein, The first security information is carried in the first request message, and the first security information is used for security verification of the terminal by the network node.
30. The method of any one of claims 16-29, wherein, The method further includes: A group paging message is received from the network node, and the group paging message carries third security information and a radio network temporary identifier (RNTI); the RNTI is shared between the network node and the receiving end of each system message corresponding to the first attribute; The third security information is obtained by parsing the group paging message using the RNTI; the third security information is updated by the network node from the first security information corresponding to the first attribute; A security key is determined and stored based on the third security information, or the third security information is stored.
31. The method of claim 30, wherein, The group paging message further carries the first security information. The first security information is used as an encoding key to determine a security key. The security key is determined based on the first security information as an encoding key and in a manner indicated by the third security information. The security key is stored. When the first information content of the system message is applicable to a first area, the system message carries area indication information of the first area of the first information content; 32. The method of any one of claims 16-31, wherein, The area indication information is indicated by at least one of the following: a reference location point plus a radius, a regional identifier, a country identifier, a list of cells and / or beams, a list of TPRs, a plurality of boundary point position coordinates, a shape indication of a polygon, and a mapping cell identifier. The network node includes:
33. A communications device, wherein, A transceiver unit is configured to send the system message with the first attribute of the system message as a sending granularity. The first attribute comprises at least one of the following: position or region, service, communication type, terminal capability, terminal state, transmitted waveform type, height of antenna and / or base station, height of terminal, beam and / or beam group, transmission / reception point (TRP), SSB index, one or more cells, cell type, and channel characteristic. The channel characteristic comprises at least one of the following: Doppler shift, Doppler spread, delay spread, average delay, and spatial reception parameter.
34. A communications device, comprising: The terminal comprises: a transceiver configured to receive a system message from a network node, the system message being transmitted with a first attribute as a transmission granularity; The first attribute comprises at least one of the following: position or region, service, communication type, terminal capability, terminal state, transmitted waveform type, height of antenna and / or base station, height of terminal, beam and / or beam group, TRP, SSB index, one or more cells, cell type, and channel characteristic. The channel characteristic comprises at least one of the following: Doppler shift, Doppler spread, delay spread, average delay, and spatial reception parameter.
35. A communication system, wherein, The network node comprises: a network node configured to perform the method of any one of claims 1-15; a terminal configured to perform the method of any one of claims 16-32.
36. The communication system of claim 35, wherein, The network node is a network node of a satellite network.
37. An electronic device comprising a memory, a processor, and a computer program stored on the memory, wherein, The processor executes the computer program to implement the method of any one of claims 1-32.
38. A computer readable storage medium having stored thereon computer programs / instructions, wherein, The computer program / instruction, when executed by the processor, implements the method of any one of claims 1-32.
39. A computer program product comprising computer programs / instructions, wherein, The computer program / instruction, when executed by the processor, implements the method of any one of claims 1-32.
Citation Information
Patent Citations
Method, system equipment for receiving and sending system message
CN101207844A
System message receiving and sending method and device, and storage medium
CN114389774A
System information transmitting and receiving method and device and storage medium
CN116963109A
System message transmission method and device, network side equipment and terminal
CN117714015A
Method for transmitting information and network device
WO2018171781A1