Communication method and apparatus, and readable storage medium
By setting up modules in terminal devices and utilizing instruction information and key encryption technology, the problem of communication between terminal devices and different NTN networks is solved, achieving flexible access and improved security, strong adaptability, and reducing modifications and resource waste.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-09-04
- Publication Date
- 2026-03-19
AI Technical Summary
How to support communication between terminal devices and different non-terrestrial networks (NTNs), especially to enable flexible access and improve security of terminal devices in NTN networks.
By setting up a first module and a second module in the terminal device, and using instruction information and keys to encrypt the identification information of the terminal device, the architecture and identification of the terminal device and the NTN network are matched, supporting the access of the terminal device in different NTN networks, and improving security through security context and key mechanisms.
It enables flexible access for terminal devices in different NTN networks, reduces modifications to existing solutions, improves access security and adaptability, and avoids resource waste.
Smart Images

Figure CN2025118987_19032026_PF_FP_ABST
Abstract
Description
Communication method, apparatus, and readable storage medium
[0001] The present application claims priority from the Chinese patent application No. 202411270473.3 filed on September 10, 2024, and entitled "Communication method, apparatus and readable storage medium", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD
[0002] The present application relates to the field of communication technology, in particular to a communication method, apparatus and readable storage medium. BACKGROUND
[0003] Non-terrestrial network (NTN) has the advantages of wide coverage, long communication distance, high reliability, great flexibility, high throughput, etc., and can provide communication services for areas that are difficult to be covered by terrestrial networks, such as oceans, forests, etc., and enhance the reliability of communication. In the NTN network, access network devices and / or core network elements can be deployed on satellites.
[0004] Currently, how to support the communication between terminal devices and different NTN networks is a problem to be solved. SUMMARY
[0005] The embodiments of the present application provide a communication method, apparatus and readable storage medium, which can support the communication between terminal devices and different NTN networks.
[0006] To achieve the above-mentioned purpose, the embodiments of the present application adopt the following technical solutions:
[0007] In a first aspect, a communication method is provided, which can be executed by a first module (such as a processor, a chip, or a chip system, etc.) in a terminal device. The method includes: the first module sends first indication information to a second module in the terminal device, the first indication information being used to indicate the architecture of a non-terrestrial network, and / or the first indication information being used to indicate the identity of the non-terrestrial network. The first module receives first information from the second module, the first information being determined according to the first indication information, and the first information being used to access the non-terrestrial network.
[0008] Based on the communication method provided by the embodiments of the present application, the first module in the terminal device can obtain the first information for accessing the non-terrestrial network from the second module, the first information corresponding to the architecture of the non-terrestrial network, and / or the first information corresponding to the identity of the non-terrestrial network, thereby realizing the access of the terminal device to different NTN networks, and this process is flexible and simple, and has good adaptability.
[0009] In a possible design of the first aspect, the first information includes first identification information, the first identification information being obtained by encrypting identification information of the terminal device in the non-terrestrial network according to a first key, and the first key corresponding to the first indication information.
[0010] In the solution, the first information is the first identification information obtained by encrypting the identification information of the terminal device in the non-terrestrial network based on the first key, and the first key corresponds to the architecture of the non-terrestrial network and / or the identification of the non-terrestrial network, which can improve security while enabling the terminal device to access different NTN networks.
[0011] In a possible design of the first aspect, the first information includes identification information of the terminal device in the non-terrestrial network.
[0012] In a possible design of the first aspect, the first information includes a first key, the first key corresponding to the first indication information, and the method further includes: the first module encrypts identification information of the terminal device in the non-terrestrial network according to the first key to obtain first identification information, and the first identification information is used to access the non-terrestrial network. This solution helps to improve the security of the terminal device accessing different NTN networks.
[0013] In a possible design of the first aspect, the first information further includes at least one of the following: a routing indication, a non-terrestrial network public key identifier, a protection scheme identifier, or identification information of the terminal device in the non-terrestrial network; and the first module encrypts the identification information of the terminal device in the non-terrestrial network according to the first key and at least one of the following: the routing indication, the non-terrestrial network public key identifier, or the protection scheme identifier.
[0014] Based on the solution, the first module can also encrypt the identification information of the terminal device in the non-terrestrial network in combination with other information.
[0015] In a possible design of the first aspect, the first module sends the first indication information to a second module in the terminal device, including: sending an identification acquisition message to the second module in the terminal device, the identification acquisition message including the first indication information.
[0016] Based on the solution, the first module can send the first indication information to the second module by carrying the first indication information in the existing identification acquisition message, which can reduce changes to the existing solution.
[0017] In a possible design of the first aspect, the method further includes: the first module receives user parameter update data, and the user parameter update data includes the first key.
[0018] The method provided in the scheme enables a first module to obtain a first key by transmitting the first key through user parameter update data, and is compatible with an existing process of transmitting user parameter update data.
[0019] With reference to the first aspect, in a possible design, the identification information of the terminal device in the non-terrestrial network is different from the identification information of the terminal device in the terrestrial network.
[0020] In the scheme, the identification information of the terminal device in the non-terrestrial network is different from the identification information of the terminal device in the terrestrial network, which can avoid other devices from accessing the non-terrestrial network by using the identification information of the terminal device in the terrestrial network in the case that the identification information of the terminal device in the terrestrial network has a risk of being leaked, and helps to improve the security of the terminal device accessing the non-terrestrial network.
[0021] With reference to the first aspect, in a possible design, the method further includes: the first module receives a security context from the second module, where the security context is determined according to the first indication information.
[0022] Based on the scheme, the first module can obtain the security context corresponding to the architecture of the non-terrestrial network and / or the identification of the non-terrestrial network from the second module, and implement the terminal device accessing different non-terrestrial networks through the security context.
[0023] With reference to the first aspect, in a possible design, the first information includes the security context.
[0024] Based on the scheme, the first module can obtain the security context corresponding to the architecture of the non-terrestrial network and / or the identification of the non-terrestrial network from the second module, and implement the terminal device accessing different non-terrestrial networks through the security context.
[0025] With reference to the first aspect, in a possible design, the method further includes: the first module encrypts the identification information of the terminal device in the non-terrestrial network according to the first key to obtain first identification information, where the first identification information is used for accessing the non-terrestrial network, and the first key corresponds to the first indication information.
[0026] Based on the scheme, the first module can also encrypt the identification information of the terminal device according to the first key to obtain the first identification information used for accessing the non-terrestrial network, thereby improving the security.
[0027] With reference to the first aspect, in a possible design, the first module sends the first indication information to a second module in the terminal device, including: in the case that the terminal device supports a service provided by the non-terrestrial network, the first module sends the first indication information to the second module.
[0028] Based on the scheme, the first module can obtain the first information in the case that it is determined that the terminal device supports the service provided by the non-terrestrial network, thereby avoiding the waste of resources caused by the fact that the terminal device cannot access the non-terrestrial network due to the fact that the terminal device does not support the service of the non-terrestrial network.
[0029] With reference to the first aspect, in a possible design, the method further includes: the first module sends the first indication information to a second module in the terminal device, including: in the case that the non-terrestrial network supports the store-and-forward architecture and the terminal device supports the store-and-forward architecture, the first module sends the first indication information to the second module.
[0030] Based on the scheme, the first module can obtain the first information in the case that it is determined that the terminal device also supports the architecture of the non-terrestrial network, thereby avoiding the waste of resources caused by the fact that the terminal device cannot access the non-terrestrial network due to the fact that the terminal device does not support the architecture of the non-terrestrial network.
[0031] In a second aspect, a communication method is provided, which can be performed by a second module (for example, a processor, a chip, or a chip system, etc.) in a terminal device. The method includes: the second module receives first indication information from a first module in the terminal device; the first indication information is used to indicate the architecture of the non-terrestrial network, and / or the first indication information is used to indicate the identity of the non-terrestrial network. The second module sends first information to the first module according to the first indication information, and the first information is used to access the non-terrestrial network.
[0032] Based on the communication method provided by the embodiments of the present application, the second module can determine the first information used to access the NTN network according to the indication information from the first module, which indicates the identity and / or architecture of the NTN network, so as to realize the access of the terminal device to different NTN networks, and the process is flexible and simple, and has good adaptability.
[0033] With reference to the second aspect, in a possible design, the first information includes first identity information, and the second module determines the first information according to the first indication information, including: encrypting the identity information of the terminal device in the non-terrestrial network according to a first key corresponding to the first indication information to obtain the first identity information.
[0034] Based on the scheme, the second module can provide the encrypted identity information of the terminal device to the first module, and the encrypted identity information of the terminal device is used to help the terminal device access the non-terrestrial network, thereby improving the security.
[0035] With reference to the second aspect, in a possible design, the first information includes the identity information of the terminal device in the non-terrestrial network.
[0036] Based on the scheme, the second module can provide the identity information of the terminal device in the non-terrestrial network to the first module, so as to help the terminal device access the non-terrestrial network.
[0037] With reference to the second aspect above, in a possible design of the second aspect, the first information includes a first key corresponding to the first indication information, and the first key is used to encrypt the identification information of the terminal device in the non-terrestrial network to obtain the first identification information.
[0038] Based on this solution, the second module can provide the first key to the first module, so that the first module can encrypt the identification information of the terminal device according to the first key, thereby improving security while enabling the terminal device to access different NTN networks.
[0039] With reference to the second aspect above, in a possible design of the second aspect, the method further includes: receiving, by the second module, user parameter update data, where the user parameter update data includes the first key.
[0040] This solution provides a method for the second module to obtain the first key: the first key is transmitted by transmitting user parameter update data, which can be compatible with the existing process of transmitting user parameter update data.
[0041] With reference to the second aspect above, in a possible design of the second aspect, the second module receives the first indication information from the first module in the terminal device, including: receiving an identification obtaining message from the first module, where the identification obtaining message includes the first indication information.
[0042] Based on this solution, the first indication information can be sent to the second module by carrying the first indication information in the existing identification obtaining message, which can reduce changes to the existing solution.
[0043] With reference to the second aspect above, in a possible design of the second aspect, the identification information of the terminal device in the non-terrestrial network is different from the identification information of the terminal device in the terrestrial network.
[0044] In this solution, the identification information of the terminal device in the non-terrestrial network is different from the identification information of the terminal device in the terrestrial network, which can avoid other devices from accessing the non-terrestrial network using the identification information of the terminal device in the terrestrial network in the case that the identification information of the terminal device in the terrestrial network has a risk of leakage, and helps to improve the security of the terminal device accessing the non-terrestrial network.
[0045] With reference to the second aspect above, in a possible design of the second aspect, the method further includes: determining, by the second module, a security context according to a second key corresponding to the first indication information, and sending, by the second module, the security context to the first module.
[0046] Based on this solution, the second module can also provide the first module with a security context corresponding to the architecture of the non-terrestrial network and / or the identification of the non-terrestrial network, to support the terminal device to access different non-terrestrial networks through the security context.
[0047] With reference to the second aspect above, in a possible design, the first information includes a security context, and the second module determining the first information according to the first indication information includes: determining the security context according to a second key corresponding to the first indication information.
[0048] Based on this solution, the second module can provide the first module with a security context corresponding to the architecture of the non-terrestrial network and / or the identity of the non-terrestrial network, and the terminal device can access different non-terrestrial networks through the security context.
[0049] With reference to the first aspect or the second aspect above, in a possible design, the security context includes an authentication parameter and / or a third key, the authentication parameter being used for authentication between the terminal device and the non-terrestrial network, and the third key being used for secure communication between the terminal device and the non-terrestrial network.
[0050] This solution provides information that the security context for accessing a non-terrestrial network can include, and the information can be compatible with an existing security context for accessing a terrestrial network.
[0051] With reference to the first aspect or the second aspect above, in a possible design, the first indication information is used to indicate the architecture of the non-terrestrial network, and the architecture of the non-terrestrial network includes: an architecture in which all core network elements are deployed on a satellite or an architecture in which part of core network elements are deployed on a satellite.
[0052] Based on this solution, the terminal device can determine information for accessing a non-terrestrial network in the architecture in which all core network elements are deployed on a satellite according to the first indication information, or the terminal device can determine information for accessing a non-terrestrial network in the architecture in which part of core network elements are deployed on a satellite according to the first indication information, thereby supporting the terminal device to access a non-terrestrial network in the architecture in which all core network elements are deployed on a satellite or the architecture in which part of core network elements are deployed on a satellite.
[0053] With reference to the first aspect or the second aspect above, in a possible design, the first module is a mobile device module, and the second module is a user service identification or user identification module.
[0054] A third aspect provides a communication method, which can be performed by interaction between a first module and a second module (for example, a processor, a chip, or a chip system) in a terminal device. The method includes: the first module sending first indication information to the second module, the first indication information being used to indicate an architecture of a non-terrestrial network and / or the first indication information being used to indicate an identity of the non-terrestrial network; the second module sending first information to the first module according to the first indication information, the first information being used to access the non-terrestrial network; and the first module receiving the first information from the second module.
[0055] Based on the communication method provided in the embodiments of the present application, the second module can determine the first information for accessing the NTN network according to the indication information from the first module, which indicates the identity and / or architecture of the NTN network, so as to realize the access of the terminal device to different NTN networks, and the process is flexible and simple, and has good adaptability.
[0056] With reference to the third aspect, in a possible design, the first module can perform the method in any of the possible designs of the first aspect.
[0057] With reference to the third aspect, in a possible design, the second module can perform the method in any of the possible designs of the second aspect.
[0058] In a fourth aspect, a communication method is provided, which can be performed by a second network element, or can also be performed by a module (for example, a processor, a chip, or a chip system, etc.) applied to the second network element. The following takes the second network element as an example to perform the communication method, which includes: determining, by the second network element, second information, the second information corresponding to an architecture of a non-terrestrial network, and / or the second information corresponding to an identity of the non-terrestrial network. The second network element sends the second information to a terminal device, and the second information is used for the terminal device to access the non-terrestrial network.
[0059] Based on the present solution, the second network element can provide the terminal device with the second information corresponding to the architecture of the non-terrestrial network and / or the identity of the non-terrestrial network, which helps the terminal device to access different NTN networks according to the second information.
[0060] With reference to the fourth aspect, in a possible design, the second information is used to determine the first information, and the first information is used for the terminal device to access the non-terrestrial network.
[0061] With reference to the fourth aspect, in a possible design, the second information is contained in user parameter update data corresponding to the terminal device.
[0062] The present solution provides a way to issue the second information: the second information is sent through the user parameter update data, which can be compatible with the existing process of transmitting the user parameter update data.
[0063] With reference to the fourth aspect, in a possible design, the second information belongs to data signed by the terminal device and the non-terrestrial network.
[0064] The present solution provides a way to determine the second information: the second information is determined according to the data signed by the terminal device and the non-terrestrial network, which can dynamically determine the second information through dynamic configuration of the signed data, and is flexible and easy to expand.
[0065] With reference to the fourth aspect above, in a possible design of the fourth aspect, the second information includes at least one of the following: the first key, the second key, the first parameter, or identification information of the terminal device in the non-terrestrial network, where the first parameter is used to generate the second key, the first key is used to encrypt the second identification information, the second identification information is the identification information of the terminal device in the non-terrestrial network, and the second key is used to determine the security context.
[0066] Based on this solution, the second network element can provide various keys or parameters for generating keys to the terminal device, and can be compatible with existing information for accessing a terrestrial network.
[0067] With reference to the fourth aspect above, in a possible design of the fourth aspect, the security context includes an authentication parameter and / or a third key, the authentication parameter is used for authentication between the terminal device and the non-terrestrial network, and the third key is used for secure communication between the terminal device and the non-terrestrial network.
[0068] This solution provides information that can be included in a security context for accessing a non-terrestrial network, and can be compatible with an existing security context for accessing a terrestrial network.
[0069] With reference to the fourth aspect above, in a possible design of the fourth aspect, when the second information includes the second key, the method further includes: the second network element encrypting the second key in the second information.
[0070] Based on this solution, the second network element can encrypt the second key for transmission, and security of transmission of the second key can be improved.
[0071] With reference to the fourth aspect above, in a possible design of the fourth aspect, the second information includes identification information of the terminal device in the non-terrestrial network; and the identification information of the terminal device in the non-terrestrial network is different from identification information of the terminal device in the terrestrial network.
[0072] The identification information of the terminal device in the non-terrestrial network is different from the identification information of the terminal device in the terrestrial network, and security of the terminal device accessing the non-terrestrial network can be improved.
[0073] With reference to the fourth aspect above, in a possible design of the fourth aspect, the second information includes at least one of the following: routing indication information, a non-terrestrial network public key identifier, a protection scheme identifier, or a user hidden identifier calculation indication.
[0074] Based on this solution, the second network element can further provide various information that can be used to encrypt the identification information of the terminal device in the non-terrestrial network to the terminal device, and can be compatible with an existing scheme for encrypting the identification information of the terminal device in the terrestrial network.
[0075] With reference to the fourth aspect above, in a possible design, the second network element sends the second information to the terminal device, including: the second network element sends the second information to the terminal device in a case where the third indication information is received; and the third indication information indicates that the terminal device subscribes to the first service, and the first service is provided by at least one non-ground network including the non-ground network; or the third indication information indicates that the second information is updated.
[0076] Based on the solution, an implementation of triggering the second network element to send the second information is provided, and the second network element can send the second information to the terminal device in a case where it is determined that the terminal device subscribes to a service of the non-ground network, or it is determined that the second information needs to be updated, so that information for accessing the non-ground network is provided for the terminal device in a timely and flexible manner.
[0077] In a fifth aspect, a communication apparatus is provided for implementing the method implemented by the first module in the first aspect.
[0078] The communication apparatus includes modules, units, or means corresponding to the method, and the modules, units, or means can be implemented by hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the above functions.
[0079] With reference to the fifth aspect above, in a possible design, the communication apparatus includes a first module: the first module is configured to send first indication information to a second module in a terminal device, the first indication information being used to indicate an architecture of a non-ground network, and / or the first indication information being used to indicate an identity of the non-ground network; and the first module is further configured to receive first information from the second module, the first information being determined according to the first indication information, and the first information being used to access the non-ground network.
[0080] With reference to the fifth aspect above, in a possible design, the first module is further configured to implement the method in any of the possible designs of the first aspect.
[0081] In a sixth aspect, a communication apparatus is provided for implementing the method implemented by the second module in the second aspect.
[0082] The communication apparatus includes modules, units, or means corresponding to the method, and the modules, units, or means can be implemented by hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the above functions.
[0083] With reference to the above sixth aspect, in a possible design of the communication apparatus, the second module is further configured to: receive, from the first module in the terminal device, first indication information, the first indication information being used to indicate an architecture of the non-terrestrial network, and / or the first indication information being used to indicate an identity of the non-terrestrial network; determine first information according to the first indication information, the first information being used to access the non-terrestrial network; and send the first information to the first module.
[0084] With reference to the above sixth aspect, in a possible design of the communication apparatus, the second module is further configured to implement the method in any of the possible designs of the above second aspect.
[0085] According to a seventh aspect, a communication apparatus is provided to implement the method implemented by the first module in the above first aspect and the method implemented by the second module in the above second aspect.
[0086] The communication apparatus includes modules, units, or means corresponding to the above method, which can be implemented by hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the above functions.
[0087] With reference to the above seventh aspect, in a possible design of the communication apparatus, the communication apparatus includes a first module and a second module, where the first module is configured to send first indication information to the second module, the first indication information being used to indicate an architecture of the non-terrestrial network, and / or the first indication information being used to indicate an identity of the non-terrestrial network; the second module is configured to determine first information according to the first indication information, the first information being used to access the non-terrestrial network; the second module is further configured to send the first information to the first module; and the first module is further configured to receive the first information.
[0088] With reference to the above seventh aspect, in a possible design of the communication apparatus, the first module is further configured to implement the method in any of the possible designs of the above first aspect.
[0089] With reference to the above seventh aspect, in a possible design of the communication apparatus, the second module is further configured to implement the method in any of the possible designs of the above second aspect.
[0090] According to an eighth aspect, a communication apparatus is provided to implement the method implemented by the second network element in the above fourth aspect.
[0091] The communication apparatus includes modules, units, or means corresponding to the above method, which can be implemented by hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the above functions.
[0092] With reference to the eighth aspect above, in a possible design, the communication apparatus includes a transceiver and a processing module, where the processing module is configured to determine second information, the second information corresponding to an architecture of the non-ground network and / or the second information corresponding to an identity of the non-ground network; and the transceiver is configured to send the second information to the terminal device, the second information being used by the terminal device to access the non-ground network.
[0093] With reference to the eighth aspect above, in a possible design, the second information is used to determine the first information, the first information being used by the terminal device to access the non-ground network.
[0094] With reference to the eighth aspect above, in a possible design, the second information is included in user parameter update data corresponding to the terminal device.
[0095] With reference to the eighth aspect above, in a possible design, the second information belongs to data signed by the terminal device and the non-ground network.
[0096] With reference to the eighth aspect above, in a possible design, the second information includes at least one of the following: a first key, a second key, a first parameter, or identity information of the terminal device in the non-ground network, where the first parameter is used to generate the second key, the first key is used to encrypt the second identity information, the second identity information is identity information of the terminal device in the non-ground network, and the second key is used to determine a security context.
[0097] With reference to the eighth aspect above, in a possible design, the security context includes an authentication parameter and / or a third key, the authentication parameter being used for authentication between the terminal device and the non-ground network, and the third key being used for secure communication between the terminal device and the non-ground network.
[0098] With reference to the eighth aspect above, in a possible design, the processing module is further configured to encrypt the second key in the second information.
[0099] With reference to the eighth aspect above, in a possible design, the second information includes identity information of the terminal device in the non-ground network; and the identity information of the terminal device in the non-ground network is different from identity information of the terminal device in a ground network.
[0100] With reference to the eighth aspect above, in a possible design, the second information includes at least one of the following: routing indication information, a non-ground network public key identifier, a protection scheme identifier, or a user hidden identifier calculation indication.
[0101] With the eighth aspect above, in a possible design, the transceiver is specifically configured to: send, to the terminal device, the second information in a case where the third indication information is received; and the third indication information indicates that the terminal device subscribes to a first service, and the first service is provided by at least one non-ground network, and the at least one non-ground network includes the non-ground network; or the third indication information indicates that the second information is updated.
[0102] The ninth aspect provides a communication apparatus, including: a processor configured to execute instructions stored in a memory, and when the processor executes the instructions, the communication apparatus performs the method in any of the aspects above. The communication apparatus can be the first module (for example, a chip) in the first aspect or any of the possible designs of the first aspect. Alternatively, the communication apparatus can be the second module (for example, a chip) in the second aspect or any of the possible designs of the second aspect. Alternatively, the communication apparatus can be the terminal device including the first module and the second module in the third aspect or any of the possible designs of the third aspect. Alternatively, the communication apparatus can be the second network element in the fourth aspect or any of the possible designs of the fourth aspect.
[0103] In a possible design, the communication apparatus further includes a memory configured to store computer instructions. Optionally, the processor and the memory are integrated together, or the processor and the memory are separately arranged.
[0104] In a possible design, the memory is coupled with the processor and is outside the communication apparatus.
[0105] The tenth aspect provides a communication apparatus, including: a processor and an interface circuit configured to communicate with a module outside the communication apparatus; and the processor is configured to perform the method in any of the aspects above by a logic circuit, or by running computer programs or instructions. The communication apparatus can be the first module (for example, a chip) in the first aspect or any of the possible designs of the first aspect. Alternatively, the communication apparatus can be the second module (for example, a chip) in the second aspect or any of the possible designs of the second aspect. Alternatively, the communication apparatus can be the terminal device including the first module and the second module in the third aspect or any of the possible designs of the third aspect. Alternatively, the communication apparatus can be the second network element in the fourth aspect or any of the possible designs of the fourth aspect.
[0106] Alternatively, the interface circuit can be a code / data read-write interface circuit configured to receive computer execution instructions (the computer execution instructions are stored in a memory, and can be directly read from the memory or can pass through other devices) and transmit to the processor, so that the processor runs the computer execution instructions to perform the method in any of the aspects above.
[0107] In a possible design of the communication apparatus, the communication apparatus further includes a memory configured to store the computer program or the instructions. Optionally, the processor and the memory are integrated together, or the processor and the memory are separately arranged.
[0108] In a possible design of the communication apparatus, the memory is coupled with the processor and is located outside the communication apparatus.
[0109] In some possible designs of the communication apparatus, the communication apparatus can be a chip or a chip system.
[0110] In a first aspect, a method is provided, including: receiving, by a terminal device, a first message from a first network element, the first message being used to trigger the terminal device to perform a first operation; and performing, by the terminal device, the first operation according to the first message.
[0111] In a twelfth aspect, a computer program product is provided, including instructions, when the instructions are executed on a computer, the computer can perform the method in the first aspect to the fourth aspect or any possible design of the first aspect to the fourth aspect.
[0112] In a thirteenth aspect, a communication apparatus (for example, the communication apparatus can be a chip or a chip system) is provided, the communication apparatus including a processor configured to implement functions of the first aspect to the fourth aspect or any possible design of the first aspect to the fourth aspect. In a possible design of the communication apparatus, the communication apparatus further includes a memory configured to store necessary program instructions and data. When the communication apparatus is a chip system, the communication apparatus can be composed of a chip or can include the chip and other discrete components.
[0113] In a fourteenth aspect, a communication system is provided, in a possible design of the communication system, the communication system includes a second network element and a terminal device, the second network element is configured to perform the method in the fourth aspect or any possible design of the fourth aspect, and the terminal device includes a first module and a second module, the first module is configured to perform the method in the first aspect or any possible design of the first aspect, and the second module is configured to perform the method in the second aspect or any possible design of the second aspect.
[0114] The technical effects brought by any design of the fifth aspect to the fourteenth aspect can refer to the technical effects brought by different designs of the first aspect to the fourth aspect, which will not be repeated here. BRIEF DESCRIPTION OF DRAWINGS
[0115] FIG. 1 is a schematic diagram of a network architecture provided by an embodiment of the present application;
[0116] FIG. 2 is a schematic diagram of another network architecture according to an embodiment of the present application;
[0117] FIG. 3 is a flow diagram of a communication method according to an embodiment of the present application;
[0118] FIG. 4 is a flow diagram of a communication method according to an embodiment of the present application;
[0119] FIG. 5 is a flow diagram of a communication method according to an embodiment of the present application;
[0120] FIG. 6 is a flow diagram of another communication method according to an embodiment of the present application;
[0121] FIG. 7 is a flow diagram of a communication method according to an embodiment of the present application;
[0122] FIG. 8 is a schematic diagram of a communication apparatus according to an embodiment of the present application;
[0123] FIG. 9 is a schematic diagram of another communication apparatus according to an embodiment of the present application;
[0124] FIG. 10 is a schematic diagram of yet another communication apparatus according to an embodiment of the present application;
[0125] FIG. 11 is a schematic diagram of a chip system according to an embodiment of the present application. DETAILED DESCRIPTION
[0126] To facilitate understanding of the technical solutions of the embodiments of the present application, first, a brief introduction of the related art of the present application is given as follows.
[0127] 1. Store and forward (S&F) architecture in NTN network:
[0128] In the S&F architecture of NTN, the satellite cannot simultaneously connect the user link (service link) and the feeder link, i.e., the satellite cannot simultaneously connect the terminal device and the ground station.
[0129] Currently, S&F supports two satellite architectures, one is an architecture in which a core network (CN) is all deployed (or referred to as carried) on a satellite, which can also be referred to as a whole CN architecture, and the other is an architecture in which a core network is partially deployed on a satellite and partially deployed on the ground, which can also be referred to as a mobile management entity (MME) split (MME-Split) architecture in a 4th generation (4G) mobile communication system. This paper takes the name of the MME-Split architecture as an example to introduce the architecture in which a core network is partially deployed on a satellite and partially deployed on the ground.
[0130] In an NTN network, a core network deployed on a satellite can be referred to as a satellite core network. In the whole CN or MME-Split architecture, the satellite core network can be deployed on one satellite or multiple satellites.
[0131] Currently, there is no solution for how to support communication of a terminal device and different NTN networks, for example, how a terminal device accesses different architectures of NTN networks. To solve this problem, the embodiments of the present application provide a communication method, device and system. A terminal device can determine the identity of an NTN network and / or the architecture of an NTN network according to indication information, and determine information that can be used to access an NTN network based on the identity of the NTN network and / or the architecture of the NTN network, which can support a terminal device to access different NTN networks, is relatively simple and flexible, and has good adaptability.
[0132] In the description of the embodiments of the present application, unless otherwise specified, " / " represents a "or" relationship between the objects associated in front and behind, for example, A / B can represent A or B; "and / or" in the embodiments of the present application is only a description of the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B, which can represent: A exists alone, A and B exist simultaneously, and B exists alone, where A, B can be singular or plural. And in the description of the present application, unless otherwise specified, "multiple" means two or more than two. "At least one of the following" or similar expressions means any combination of these items, including any combination of single item or multiple items. For example, at least one of a, b, or c, can represent: a, b, c, a-b, a-c, b-c, or a-b-c, where a, b, c can be single or multiple. In addition, in order to clearly describe the technical solutions of the embodiments of the present application, in the embodiments of the present application, "first", "second" and the like are used to distinguish the same items or similar items with basically the same function and role. The skilled in the art can understand that "first", "second" and the like do not limit the quantity and execution order, and "first", "second" and the like do not necessarily mean different. At the same time, in the embodiments of the present application, "exemplary" or "for example" means to present relevant concepts in a specific way for understanding.
[0133] In the embodiments of the present application, "indication" can include direct indication and indirect indication, and can also include explicit indication and implicit indication. The information indicated by a certain information is called to-be-indicated information, and there are many ways to indicate the to-be-indicated information in the specific implementation process, for example, but not limited to, the to-be-indicated information can be directly indicated, such as the to-be-indicated information itself or the index of the to-be-indicated information. The to-be-indicated information can also be indirectly indicated by indicating other information, where the other information and the to-be-indicated information have an association relationship. The to-be-indicated information can also be indicated only by a part, and the other part of the to-be-indicated information is known or agreed in advance. For example, the indication of a specific information can also be realized by means of the arrangement order of each information agreed in advance (for example, a protocol stipulates), thereby reducing the indication overhead to a certain extent. At the same time, the common part of each information can be identified and uniformly indicated to reduce the indication overhead caused by separately indicating the same information.
[0134] It should be understood that the to-be-indicated information can be sent together as a whole, or can be sent separately in multiple sub-information, and the sending period and / or sending occasion of the sub-information can be the same or different. The specific sending method is not limited in the embodiments of the present application. The sending period and / or sending occasion of the sub-information can be predefined, for example, predefined according to a protocol, or configured by the sending end device to the receiving end device by sending configuration information.
[0135] In the embodiments of the present application, “predefined”, “predefinition”, “preconfigured”, “preconfiguration” or “local configuration” can be implemented by pre-storing corresponding codes, tables or other information indicating methods in the device, for example, burned in the device when the device is manufactured, or configured when the device accesses the network for the first time, and the specific implementation manner is not limited in the embodiments of the present application. The “storing” can mean storing in one or more memories. The one or more memories can be separately set, or integrated in the encoder or decoder, processor or communication device. The one or more memories can be partially separately set and partially integrated in the decoder, processor or communication device. The type of the memory can be any form of storage medium, which is not limited in the embodiments of the present application.
[0136] In the embodiments of the present application, “when”, “in the case of”, “if” and the like all refer to that the device will make corresponding processing under certain objective conditions, and are not limited in time, and do not require the device to have a judgment action when implemented, and do not mean that there are other limitations.
[0137] In the embodiments of the present application, “sending information to … (for example, a terminal device)” can be understood as that the destination of the information is the terminal device. It can include directly or indirectly sending information to the terminal device. “Receiving information from … (for example, a terminal device)” can be understood as that the source of the information is the terminal device, and can include directly or indirectly receiving information from the terminal device. The information can be processed as necessary between the source and the destination, for example, format change, but the destination can understand the valid information from the source. Similar expressions in the embodiments of the present application can be understood similarly, which will not be repeated here.
[0138] The technical solutions provided in the present application can be applied to various communication systems, for example, a long term evolution (LTE) system, a 4G mobile communication system, a 5th generation (5G) mobile communication system and an evolved system thereof, a 5th generation advanced (5GA), a non-terrestrial network (NTN) system, a vehicle to everything (V2X) system, a system of LTE and new radio (NR) hybrid networking, or a device-to-device (D2D) system, a machine to machine (M2M) communication system, an internet of things (IoT), and a future communication system, etc. In addition, the term "system" can be replaced by "network".
[0139] It should be noted that the network architecture and service scenarios described in the embodiments of the present application are for more clearly illustrating the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art can know that, with the evolution of network architecture and the appearance of new service scenarios, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems.
[0140] It should be noted that the network elements appearing in the present article are only possible example names. If the actual name used by the network element in the subsequent communication network is different from the name appearing in the present article, it does not affect the application of the communication method provided by the embodiments of the present application.
[0141] If the embodiments of the present application are applied to an NTN network, the embodiments of the present application can be applied to an S&F architecture, for example, an MME-Split architecture, or a Whole CN architecture.
[0142] In the MME-Split architecture supported by the 4G network, the MME can be divided into two parts, one part is deployed on the satellite, and the other part is deployed on the ground. If the S&F architecture also supports the architecture of the core network part on the satellite in the 5G network, in one possible case, in this architecture, the access and mobility management function (AMF) network element can be divided into two parts, one part is deployed on the satellite, and the other part is deployed on the ground. If the future network also supports the architecture of the core network part on the satellite, in one possible case, in this architecture, the network element responsible for the mobility management function can be partially deployed on the satellite and partially deployed on the ground.
[0143] FIG. 1 and FIG. 2 are schematic diagrams of non-limiting Whole CN architecture to which embodiments of the present application are applicable. For example, as shown in FIG. 1, if the Whole CN architecture is applied in a 4G network, an access network (AN), an MME and a home subscriber server (HSS) can be deployed on a satellite. The AN can be a radio access network (RAN), which can be referred to as (R)AN. A terminal device on the ground can access the (R)AN through an LTE-Uu interface.
[0144] For example, as shown in FIG. 2, if the Whole CN architecture is applied in a 5G network, a (R)AN, an AMF, an authentication server function (AUSF) network element and a unified data management (UDM) network element can be deployed on a satellite.
[0145] Optionally, in the Whole CN architecture, the core network can further include other network elements not shown in FIG. 1 or FIG. 2.
[0146] In the MME-Split architecture or the Whole CN architecture, the (R)AN and the core network can be deployed on the same satellite or on different satellites. FIG. 1 and FIG. 2 are taken as examples in which the (R)AN and the core network are deployed on the same satellite.
[0147] Optionally, the communication system to which embodiments of the present application are applicable can further include an Internet. The Internet can be connected to the core network or the RAN.
[0148] In the communication system to which embodiments of the present application are applicable, the RAN can be a 3rd generation partnership project (3GPP)-related cellular system. The RAN can also be an open RAN (O-RAN or ORAN), a cloud radio access network (CRAN), or a wireless fidelity (WiFi) system. The RAN can also be a communication system in which two or more of the above systems are fused.
[0149] In a communication system to which embodiments of the present application are applicable, a terminal device can access a network through a RAN node. The terminal device refers to a device providing voice and / or data connectivity to a user, and can also be referred to as a terminal, user equipment (UE), mobile station, mobile terminal, etc. The terminal device can be widely used in various scenarios. For example, D2D, V2X communication, machine-type communication (MTC), internet of things (IOT), virtual reality, augmented reality, industrial control, autonomous driving, remote medical treatment, smart grid, smart furniture, smart office, smart wear, smart transportation, smart city, etc. The terminal device can be a mobile phone, a tablet computer, a computer with wireless transceiver function, a wearable device, a vehicle, a drone, a helicopter, an airplane, a ship, a robot, a mechanical arm, a smart home device, etc. Embodiments of the present application do not limit the device form of the terminal device.
[0150] The RAN node can also be referred to as an access network device, a network device, a RAN entity, or an access node, etc., and constitutes a part of the communication system. In a possible scenario, the RAN node implements the function of a base station. For example, the RAN node can be a Node B (also referred to as a base station), an evolved Node B (eNode B) in an LTE system, a next generation Node B (gNB) in a 5G system, an access point (AP), a transmission reception point (TRP), a base station in a future mobile communication system, or an access node in a WiFi system, etc. The RAN node can be a macro base station, a micro base station, or an indoor station, a relay node or a donor node, or a wireless controller in a CRAN scenario. Optionally, the RAN node can also be a server, a wearable device, a vehicle or a vehicle-mounted device, etc. For example, the RAN node in V2X technology can be a road side unit (RSU).
[0151] In another possible scenario, a terminal is assisted by multiple RAN nodes to implement wireless access, and different RAN nodes respectively implement part of functions of a base station. For example, a RAN node can be a central unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), a radio unit (RU), or the like. The CU and the DU can be separately arranged, or can be included in the same network element, for example, a base band unit (BBU). The RU can be included in a radio frequency device or a radio frequency unit, for example, included in a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH).
[0152] In different systems, the CU (or CU-CP and CU-UP), DU, or RU can also have different names, but those skilled in the art can understand their meanings. For example, in an ORAN system, the CU can also be referred to as an O-CU (open CU), the DU can also be referred to as an O-DU, the CU-CP can also be referred to as an O-CU-CP, the CU-UP can also be referred to as an O-CU-UP, and the RU can also be referred to as an O-RU. For the convenience of description, the CU, CU-CP, CU-UP, DU, and RU are taken as examples for description in this application. Any one of the CU (or CU-CP, CU-UP), DU, and RU in this application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.
[0153] The network element in this application, for example, all or part of the functions of a core network network element or a RAN node, can also be implemented by a software function running on hardware, or by a virtualized function instantiated on a platform (for example, a cloud platform). The network element in this application can also be a logical node, a logical module, or software that can implement all or part of the network element functions.
[0154] It should be noted that the names of various network elements, interfaces between various network elements, names of messages between various network elements, or names of various parameters in the messages in the embodiments of this application are only examples, and other names can also be used in specific implementations, and the embodiments of this application do not make specific limitations.
[0155] In embodiments of the present application, the architecture of the NTN network can also be referred to as the scenario of the NTN network. For example, the MME-Split architecture can also be referred to as the MME-Split scenario, and the Whole CN architecture can also be referred to as the Whole CN scenario.
[0156] The communication method provided by the embodiments of the present application will be described below in combination with FIG. 1 or FIG. 2.
[0157] FIG. 3 is a flowchart of a communication method provided by an embodiment of the present application. In FIG. 3, a first module and a second module in a terminal device are taken as an example to illustrate the execution subject of the flowchart, but the present application does not limit the execution subject of the flowchart. The first module or the second module in FIG. 3 can be a chip, a chip system, or a processor, and can also be a logic node, a logic module, or software.
[0158] S301, the first module in the terminal device sends first indication information to the second module in the terminal device, and correspondingly, the second module receives the first indication information. The first indication information is used to indicate the architecture of the NTN network, and / or the first indication information is used to indicate the identity of the NTN network.
[0159] The first module can be a mobile equipment (ME) module, and the second module can be an application program for accessing mobile network services located on a universal integrated circuit card (UICC), which can register on a mobile network. For example, the second module can be a universal subscriber identity module (USIM) / subscriber identity module (SIM).
[0160] In the case where the first indication information indicates the architecture of the NTN network, optionally, the first indication information can indicate whether the NTN network is an architecture in which all core network network elements are deployed on a satellite (which can also be referred to as an architecture in which all core networks are deployed on a satellite). For example, the first indication information can indicate whether the NTN network is a Whole CN architecture.
[0161] Alternatively, the first indication information can indicate whether the NTN network is an architecture in which all core network network elements are deployed on a satellite, or an architecture in which part of the core network network elements are deployed on a satellite and part of the core network network elements are deployed on the ground (which can also be referred to as an architecture in which part of the core network is deployed on a satellite). For example, the first indication information can indicate whether the NTN network is a Whole CN architecture or a MME-Split architecture.
[0162] It can be understood that the Whole CN architecture is a name of an architecture in which all core network elements are on the satellite in the S&F architecture of the NTN network, and the MME-Split architecture is a name of an architecture in which part of the core network elements are on the satellite in the S&F architecture of the NTN network. The embodiments of the present application take the Whole CN architecture and the MME-Split architecture as examples for introduction. If the architecture in which all or part of the core network elements are on the satellite is named as other names in actual application, the communication method provided by the embodiments of the present application can still be applied.
[0163] In the case where the first indication information indicates the architecture of the NTN network, the first indication information can directly indicate the architecture of the NTN network (or referred to as explicit indication), or indirectly indicate (or referred to as implicit indication) the architecture of the NTN network. The form of the first indication information is not limited by the embodiments of the present application. The following introduces several possible implementation manners provided by the embodiments of the present application.
[0164] In a possible implementation, the first indication information can be a newly defined information used for indicating the architecture of the NTN network. For example, the first indication information can be a pre-defined bit. When the value of the bit is a first value, it represents that the NTN network is the Whole CN architecture. When the value of the bit is a second value, it represents that the NTN network is the MME-Split architecture.
[0165] In another possible implementation, the first indication information can be a newly defined information used for indicating that the NTN network is the Whole CN architecture.
[0166] In yet another possible implementation, the first indication information can indicate the identity of the NTN network, for example, can indicate the public land mobile network (PLMN) identity (ID) (PLMN ID) of the NTN network. In this implementation, the first indication information can indirectly indicate the architecture of the NTN network by indicating the identity of the NTN network.
[0167] Optionally, in the case where the first indication information does not indicate the identity of the NTN network, that is, the first indication information is information independent of the identity information of the NTN network, the first module can further send the identity information of the NTN network to the second module.
[0168] Optionally, if the first module sends the identity information of the NTN network and the first indication information to the second module, the first indication information can be carried in the same message as the identity information of the NTN network, for example, the PLMN ID. Alternatively, the first indication information can be carried in different messages from the identity information of the NTN network.
[0169] The embodiment of the present application does not limit the message carrying the first indication information sent by the first module to the second module. Optionally, the first indication information can be carried in the first message, and the first message can trigger the second module to return the first information. The embodiment of the present application does not limit the form of the first message. For example, the first message can be a get identity message used to request a subscription concealed identifier (SUCI) of the terminal device. For another example, the first message can be an authentication message used to request a security context.
[0170] Optionally, the first indication information can also indicate that the NTN network supports the S&F architecture. Alternatively, the first module can send information indicating that the NTN network supports the S&F architecture to the second module independently of the first indication information. For example, the first module can send an S&F indication and the first indication information to the second module, where the S&F indication can indicate that the NTN network supports the S&F architecture, and if the first indication information can indicate the architecture of the NTN network, the second module can determine whether the NTN network is the Whole CN architecture or the MME-Split architecture in combination with the S&F indication and the first indication information.
[0171] Optionally, if the first module sends information indicating that the NTN network supports the S&F architecture and the first indication information to the second module, the first indication information can be carried in the same message as the information indicating that the NTN network supports the S&F architecture. Alternatively, the first indication information can be carried in a different message from the information indicating that the NTN network supports the S&F architecture.
[0172] Optionally, before S301, the communication method provided by the embodiment of the present application can include the step of: receiving, by the terminal device, second indication information, where the second indication information is used to indicate the architecture of the NTN network, and / or the second indication information is used to indicate the identity of the NTN network.
[0173] The embodiment of the present application does not limit the form of the second indication information, and specific reference can be made to the description of the first indication information above.
[0174] The second indication information can be transmitted by a satellite in the NTN network to the terminal device. For example, the satellite in the NTN network can broadcast the second indication information. In a case where the second indication information does not indicate the identification information of the NTN network, the satellite can further transmit the identification information of the NTN network to the terminal device. For example, the satellite can broadcast the PLMN ID of the NTN network and the second indication information. Alternatively, if the satellite transmits the identification information of the NTN network and the second indication information to the terminal device, the second indication information can be carried in the same message as the identification information of the NTN network, for example, the PLMN ID. Alternatively, the second indication information can be carried in different messages from the identification information of the NTN network.
[0175] After the terminal device receives the second indication information, the first module can obtain the second indication information. Further, the first module can transmit the second indication information to the second module, that is, the second indication information is the same information as the first indication information. Alternatively, the first module can determine the architecture of the NTN network according to the second indication information, and then determine (for example, generate) the first indication information indicating the architecture of the NTN network. For example, assuming that the second indication information indicates the PLMN ID of the NTN network, the first module determines that the NTN network is a Whole CN architecture according to the second indication information, and generates the first indication information indicating the Whole CN architecture.
[0176] Alternatively, before S301, the communication method provided by the embodiment of the present application can include the step of: the first module determining whether the terminal device supports the service of the NTN network.
[0177] Further, the first module can transmit the first indication information to the second module in a case where it is determined that the terminal device supports the service of the NTN network. If the first module determines that the terminal device does not support the service of the NTN network, the first module can not transmit the first indication information to the second module.
[0178] Alternatively, before S301, the communication method provided by the embodiment of the present application can include the step of: the first module determining whether the terminal device supports the S&F architecture in a case where it is determined that the NTN network supports the S&F architecture. Optionally, the first module can determine that the NTN network supports the S&F architecture according to the indication information indicating that the NTN network supports the S&F architecture received by the terminal device. The indication information indicating that the NTN network supports the S&F architecture can be transmitted by a satellite in the NTN network to the terminal device. For example, the indication information can be an S&F indication.
[0179] Further, the first module can send the first indication information to the second module in a case where it is determined that the terminal device supports the S&F architecture. If the first module determines that the terminal device does not support the S&F architecture, the first module can not send the first indication information to the second module.
[0180] The embodiments of the present application do not limit the implementation of the first module determining whether the terminal device supports the service of the NTN network and / or whether the S&F architecture is supported. For example, the first module can determine whether the terminal device supports the service of the NTN network or whether the S&F architecture is supported according to the subscription data of the terminal device or the capability information of the terminal device.
[0181] Optionally, if the satellite sends the indication information indicating that the NTN network supports the S&F architecture and the second indication information to the terminal device, the first module can determine the architecture of the NTN network according to the indication information and the second indication information. Further, the first module can determine the first indication information indicating the architecture of the NTN network according to the architecture of the NTN network. For example, assuming that the satellite sends the PLMN ID and the S&F indication to the terminal device, the first module can determine whether the NTN network is the Whole CN architecture according to the PLMN ID. If the first module determines that the NTN network is not the Whole CN architecture according to the PLMN ID, the first module can determine that the NTN network is the MME-Split architecture in combination with the S&F indication.
[0182] Optionally, for the information sent by the satellite to the terminal device, such as the identification information of the NTN network, the second indication information or the indication information indicating that the NTN network supports the S&F architecture, the terminal device can determine that the satellite sends the related information of the NTN network rather than the related information of the ground network. The embodiments of the present application do not limit how the terminal device determines that the satellite sends the related information of the NTN network.
[0183] S302, the second module sends the first information to the first module according to the first indication information, and correspondingly, the first module receives the first information. The first information is used to access the non-ground network.
[0184] Based on the communication method provided by the embodiments of the present application, the first module can obtain the information for accessing the NTN network determined according to the indication information from the second module by sending the indication information indicating the architecture and / or the identification of the NTN network to the second module. The embodiments of the present application provide a scheme for the terminal device to determine the information for accessing the NTN network, which can support the terminal device to access different NTN networks, and the process is flexible and simple, and has good adaptability.
[0185] In S302, in a case where the first indication information indicates the architecture of the NTN network, after receiving the first indication information, the second module can determine the architecture of the NTN network according to the first indication information.
[0186] The embodiments of the present application do not limit the specific implementation of the second module determining the architecture of the NTN network according to the first indication information. The following describes several possible implementations of the second module determining the architecture of the NTN network according to the first indication information, in combination with different implementations of the first indication information in S301.
[0187] In a case where the first indication information is a newly defined information for indicating the architecture of the NTN network, the second module can determine the architecture of the NTN network according to the first indication information. For example, it is assumed that the first indication information is a pre-defined bit, and when the value of the bit is a first value, it represents that the NTN network is the all-satellite architecture of the core network network element, and when the value of the bit is a second value, it represents that the NTN network is the partial-satellite architecture of the core network network element. The second module can determine whether the NTN network is the all-satellite architecture or the partial-satellite architecture of the core network network element according to the value of the bit of the first indication information.
[0188] In a case where the first indication information is a newly defined information for indicating that the NTN network is the all-satellite architecture of the core network, if the second module receives the first indication information, it can be determined that the NTN network is the all-satellite architecture of the core network network element. If the second module receives the first message without carrying the first indication information, it can be determined that the NTN network is the partial-satellite architecture of the core network network element. For example, it is assumed that the first indication information can be carried in the identity acquisition message, and if the identity acquisition message sent by the first module to the second module does not carry the first indication information, the second module can determine that the NTN network is not the all-satellite architecture of the core network network element.
[0189] In a case where the first indication information indicates the identity of the NTN network, the second module can determine the architecture of the NTN network according to the identity of the NTN network indicated by the first indication information and the pre-defined / defined association relationship. This implementation can also be understood as that the first indication information can simultaneously indicate the identity of the NTN network and indicate the architecture of the NTN network.
[0190] For example, a list of PLMN IDs can be predefined by protocol definition / agreement, etc., and the architecture of the NTN network corresponding to the PLMN ID in the list is defined as the whole-satellite architecture of the core network element, i.e., the PLMN ID in the list can indicate that the corresponding NTN network is the whole-satellite architecture of the core network. After the second module receives the first indication information, if it is determined that the PLMN ID indicated by the first indication information is in the list, it can be determined that the NTN network is the whole-satellite architecture of the core network. If the second module determines that the PLMN ID indicated by the first indication information is not in the list, it can be determined that the core network element in the NTN network is not the whole-satellite architecture of the core network.
[0191] For another example, a PLMN ID dedicated to an isolated E-UTRAN operation for public safety (IOPS) mode can be predefined by protocol definition / agreement, etc., where E-UTRAN is an abbreviation of evolved universal mobile telecommunications system (UMTS) RAN. In the case where the Whole CN architecture can support the IOPS mode, after the second module receives the first indication information, it can be determined that the NTN network is the Whole CN architecture according to the following conditions: the PLMN ID indicated by the first indication information is the PLMN ID dedicated to the IOPS, and the Whole CN architecture can support the IOPS mode.
[0192] Optionally, if the first indication information is used to indicate whether the NTN network is an architecture in which all core network elements are deployed on satellites, the second module can determine that the NTN network is an architecture in which core network elements are partially deployed on satellites and partially deployed on the ground if it is determined that the NTN network is not an architecture in which all core network elements are deployed on satellites.
[0193] For example, assuming that the first module sends a PLMN ID and an S&F indication to the second module, the second module can determine whether the NTN network is the Whole CN architecture according to the PLMN ID. If the second module determines that the NTN network is not the Whole CN architecture according to the PLMN ID, the first module can determine that the NTN network is the MME-Split architecture in combination with the S&F indication.
[0194] In S302, the second module can determine the first information according to the first indication information. In a case where the first indication information indicates the architecture of the NTN network, after the second module determines the architecture of the NTN network according to the first indication information, the second module can determine the first information according to the architecture of the NTN network. In a case where the first indication information indicates the identity of the NTN network, the second module can determine the identity of the NTN network according to the first indication information, and determine the first information according to the identity of the NTN network.
[0195] The second module determining the first information according to the first indication information is described below in different scenarios.
[0196] Scenario one: the first indication information indicates the architecture of the NTN network.
[0197] Optionally, in scenario one, the first indication information can also indicate the identity of the NTN network.
[0198] In scenario one, the second module stores information corresponding to at least one architecture of the NTN network. After the second module determines the architecture of the NTN network according to the first indication information, the second module can determine the information corresponding to the architecture of the NTN network from the stored information, and then determine the first information according to the information corresponding to the architecture of the NTN network.
[0199] Optionally, the second module can also store information corresponding to the ground network. The information corresponding to the architecture of the NTN network (for example, the Whole CN architecture or the MME-Split architecture) can be different from the information corresponding to the ground network, or can be the same.
[0200] For example, the second module can store information corresponding to the ground network, information corresponding to the MME-Split architecture, and information corresponding to the Whole CN architecture. If the first indication information indicates the MME-Split architecture, the second module can determine the first information according to the information corresponding to the MME-Split architecture. If the first indication information indicates the Whole CN architecture, the second module can determine the first information according to the information corresponding to the Whole CN architecture.
[0201] For example, the second module can store information corresponding to the ground network and / or the MME-Split architecture (i.e., the same information corresponding to the ground network and the MME-Split architecture), and information corresponding to the Whole CN architecture. After the terminal device determines the architecture of the NTN network according to the first indication information, the terminal device determines the first information according to the information corresponding to the architecture. If the first indication information indicates the MME-Split architecture, the second module can determine the first information according to the information corresponding to the ground network / MME-Split architecture. If the first indication information indicates the Whole CN architecture, the second module can determine the first information according to the information corresponding to the Whole CN architecture.
[0202] Optionally, for a certain architecture of the NTN network, such as the Whole CN architecture, the second module can store multiple sets of information, and a correspondence between each set of information and the identity of at least one NTN network. If the second module determines that the NTN network is of the architecture (such as the Whole CN architecture) according to the first indication information, the second module can further determine the information corresponding to the identity of the NTN network from the multiple sets of information according to the identity of the NTN network (the identity of the NTN network can be indicated by the first indication information, or the first module can send the identity information of the NTN network to the second module), and determine the first information according to the corresponding information.
[0203] For example, it is assumed that the second module stores a set of information corresponding to the ground network and the MME-Split architecture: information 1, and three sets of information corresponding to the Whole CN architecture: information 2, information 3, and information 4, wherein information 2 corresponds to PLMN ID1, information 3 corresponds to PLMN ID2, and information 4 corresponds to PLMN ID3. The second module receives the get identity message from the first module, which carries PLMN ID2. The second module determines that the NTN network is of the Whole CN architecture according to PLMN ID2, further determines information 3 according to PLMN ID2, and determines the first information according to information 3.
[0204] In scenario two, the first indication information indicates the identity of the NTN network.
[0205] In scenario two, the second module can store information corresponding to the identity of at least one NTN network. After the second module determines the identity of the NTN network according to the first indication information, the second module can determine the information corresponding to the identity of the NTN network from the stored information, and determine the first information according to the information corresponding to the identity of the NTN network.
[0206] For example, assume that the second module stores information 1 corresponding to PLMN ID 1, information 2 corresponding to PLMN ID 2, and information 3 corresponding to PLMN ID 3. The second module receives the get identity message from the first module, which carries PLMN ID 2. The second module determines information 2 corresponding to PLMN ID 2 according to PLMN ID 2, and determines the first information according to information 2.
[0207] Hereinafter, the information corresponding to the architecture of the NTN network or the information corresponding to the identity of the NTN network determined by the second module according to the first indication information is referred to as the information corresponding to the first indication information. That is, in S302, the second module can determine the information corresponding to the first indication information according to the first indication information, and determine the first information according to the information corresponding to the first indication information.
[0208] Optionally, the information corresponding to the first indication information can include at least one of the following: a first key, a second key, or identity information of the terminal device in the NTN network (also referred to as the identity information of the terminal device in the NTN network). The first key is used to encrypt the identity information of the terminal device in the NTN network to obtain the first identity information (for ease of description, hereinafter the identity information of the terminal device in the NTN network is referred to as the second identity information) for accessing the NTN network, and the second key is used to determine a security context, which will be described in detail below.
[0209] Optionally, the information corresponding to the first indication information can further include at least one of the following information: routing indicator, core network public key identifier for the NTN network, protection scheme identifier, or SUCI calculation indication, etc. The routing indicator can constitute part of the first identity information, and the terminal device can find a network element for authenticating the terminal device, such as a UDM network element or an AUSF network element in the NTN network, according to the routing indicator. The core network public key identifier for the NTN network is used to identify the first key, the protection scheme identifier is used to identify an encryption method for encrypting the second identity information into the first identity information, and the SUCI calculation indication is used to indicate whether the second identity information is encrypted by the first module or the second module in the terminal device.
[0210] It can be understood that the name of the information that the first indication information corresponds to can include an exemplary name provided by the embodiments of the present application. In actual applications, other names can also be used, for example, a core network public key identifier for an NTN network, which can also be referred to as an NTN network public key identifier.
[0211] For the second module to determine the first information according to the first indication information, in a possible implementation, the information that the first indication information corresponds to can include the first information. In another possible implementation, the second module can generate the first information according to the information that the first indication information corresponds to. The specific implementation of the second module to determine the first information according to the first indication information is described below.
[0212] Implementation I: The second module determines the information that the first indication information corresponds to according to the first indication information, which includes the first key. The second module encrypts the second identification information according to the first key to obtain the first identification information, and sends the first identification information, that is, the first information, to the first module.
[0213] Exemplarily, the second identification information can be a subscription permanent identifier (SUPI), and in this case, the first identification information can be a subscription concealed identifier (SUCI).
[0214] In the embodiments of the present application, the second identification information can be the same as the identification information (which can be referred to as third identification information) used to identify the terminal device in the ground network, or can be different.
[0215] Optionally, in the case where the second identification information is different from the third identification information, the information corresponding to the architecture of the NTN network and / or the identification of the NTN network can include the second identification information.
[0216] Optionally, in implementation I, the first message carrying the first indication information sent by the first module to the second module can be a get identity message.
[0217] Optionally, the first key can be one of the keys used to encrypt the second identification information. For example, the second module can encrypt the second identification information according to the first key and a private key of the terminal device.
[0218] Optionally, the first key saved by different terminal devices can be the same, in other words, different terminal devices can encrypt their respective second identification information according to the same first key. In this case, the first key can be understood as a public key of the NTN network, or a satellite core network public key.
[0219] Optionally, the information corresponding to the first indication information saved by the second module can further include other information used for encrypting the second identification information, such as at least one of the following: routing indication information, a core network public key identifier for the NTN network, or a protection scheme identifier, and the like. The second module can encrypt the second identification information according to these information.
[0220] Optionally, the information corresponding to the first indication information saved by the second module can further include a second key. Optionally, the second module can calculate a security context according to the second key, and send the security context to the first module. Alternatively, the information corresponding to the first indication information can further include a first parameter, and the second module can generate the second key according to the first parameter, and calculate the security context based on the second key, and send the security context to the first module. The present embodiment does not limit the first parameter, and the first parameter can be a random number (rand) by way of example.
[0221] Optionally, the second key can be used for key derivation, and the second module can generate a third key according to the second key, and send the third key to the first module. The third key can be used for secure communication between the terminal device and the NTN network. Optionally, the third key can be included in the security context.
[0222] Optionally, the second key can be used for authentication and authorization between the terminal device and the NTN network. The second module can generate an authentication and authorization parameter according to the second key, and send the authentication and authorization parameter to the first module, and the authentication and authorization parameter can be used for authentication and authorization between the terminal device and the NTN network. Optionally, the authentication and authorization parameter can be included in the security context.
[0223] Optionally, the second key saved by different terminal devices can be different, in which case the second key can be understood as a root key of the terminal device.
[0224] Implementation II: The second module determines information corresponding to the first indication information according to the first indication information, wherein the information includes a first key. The second module sends the first key to the first module, that is, the first information includes the first key. After receiving the first key, the first module can encrypt the second identification information according to the first key to obtain the first identification information.
[0225] Optionally, the information corresponding to the first indication information saved by the second module can further include second identification information, and the first information sent by the second module can further include the second identification information. Alternatively, the first module can save the second identification information. For example, the first module can save information corresponding to the architecture of the NTN network and / or the identification of the NTN network, which includes the second identification information. The first module can determine the corresponding second identification information according to the second indication information, and details can be referred to the description of the second module determining the information corresponding to the first indication information above.
[0226] Optionally, the information corresponding to the first indication information saved by the second module can further include other information used to encrypt the second identification information, such as at least one of the following: routing indication information, a core network public key identifier for the NTN network, or a protection scheme identifier, etc. The first information sent by the second module can further include these information, and the first module can encrypt the second identification information according to these information. Alternatively, the first module can save other information used to encrypt the second identification information, and the first module can encrypt the second identification information according to these information. For example, the first module can save information corresponding to the architecture of the NTN network and / or the identification of the NTN network, which includes the other information used to encrypt the second identification information. The first module can determine the corresponding information according to the second indication information, and details can be referred to the description of the second module determining the information corresponding to the first indication information above.
[0227] Optionally, in the second implementation, the information corresponding to the first indication information saved by the second module can further include a second key or a first parameter. The second module can further obtain a security context according to the second key or the first parameter, and send the security context to the first module. Optionally, the second key can be used for key derivation, authentication and authorization, etc., and details can be referred to the description of the first implementation above.
[0228] Optionally, in the first implementation or the second implementation above, the second module can obtain the security context according to the second key, which can be triggered by a message sent by the first module to the second module to request the security context. Optionally, the message can carry the first indication information.
[0229] In the third implementation, the second module can determine the information corresponding to the first indication information according to the first indication information, which includes a second key. The second module can calculate a security context according to the second key, and send the security context to the first module. Alternatively, the information corresponding to the first indication information can include a first parameter. The second module can generate the second key according to the first parameter, calculate the security context based on the second key, and send the security context to the first module. That is, in the third implementation, the first information includes the security context.
[0230] Optionally, in the third implementation, the second module determines the second key and calculates the security context, which can be triggered by different messages from the first module. For example, the first module can send a first message to the second module, where the first message carries the first indication information, and the second module determines the second key according to the first indication information. Then, the first module sends another message to the second module, where the another message is used to request the security context, and the second module calculates the security context according to the second key after receiving the another message, and sends the security context to the first module.
[0231] Alternatively, in the third implementation, the second module can determine the second key and calculate the security context according to the first message from the first module. For example, the first module can send a first message to the second module, where the first message carries the first indication information, and the first message is used to request the security context. The second module determines the second key according to the first indication information and calculates the security context according to the second key, and sends the security context to the first module.
[0232] Optionally, the second key can be used for key derivation, authentication, and the like, which can be referred to the description of the first implementation.
[0233] Optionally, in the third implementation, the first module can save information corresponding to the architecture of the NTN network and / or the identifier of the NTN network, where the information includes the first key. The first module can determine the first key according to the second indication information, and encrypt the second identifier information according to the first key to obtain the first identifier information. Optionally, the information corresponding to the architecture of the NTN network and / or the identifier of the NTN network saved by the first module can further include the second identifier information.
[0234] Optionally, the first module can not encrypt the second identifier information, and the second identifier information can be used as information for accessing the NTN network. In one possible implementation, the second module saves information corresponding to the architecture of the NTN network and / or the identifier of the NTN network, where the information further includes the second identifier information. The first module can send the first indication information to the second module to trigger the second module to return the second identifier information (at this time, the first information can be considered to include the second identifier information). For example, the first module can send an identifier acquisition message carrying the first indication information to the second module, which can be referred to the description of the first implementation or the second implementation. In another possible implementation, the first module saves information corresponding to the architecture of the NTN network and / or the identifier of the NTN network, where the information includes the second identifier information. The first module can determine the second identifier information from the saved information according to the second indication information.
[0235] Before S301, the terminal device can obtain the architecture of the NTN network and / or the information corresponding to the identifier of the NTN network. The first module and / or the second module can store the architecture of the NTN network and / or the information corresponding to the identifier of the NTN network. The embodiments of the present application do not limit the specific implementation of the terminal device obtaining the architecture of the NTN network and / or the information corresponding to the identifier of the NTN network. Illustratively, the terminal device can obtain the architecture of the NTN network and / or the information corresponding to the identifier of the NTN network from a core network element of a home public land mobile network (HPLMN).
[0236] Optionally, after S302, the following steps can be included:
[0237] S303, the terminal device (for example, the first module is executed in FIG. 3) can send the first information or the information determined according to the first information to the first network element, for example, the terminal device can send the first identifier information and / or the security context to the first network element. The first network element can authenticate and authorize the terminal device according to the received information, and determine whether the terminal device can access the NTN network.
[0238] Among them, the first network element can be a network element in the NTN network for authentication and authorization. For example, the first network element can include at least one of the following network elements: HSS, UDM or AUSF network element.
[0239] Optionally, the first network element can pre-configure all or part of the information in the architecture of the NTN network and / or the information corresponding to the identifier of the NTN network. For example, the first network element can pre-configure the first key and / or the second key.
[0240] Optionally, the first network element can be deployed on a satellite. Alternatively, the first network element can also be deployed on the ground, and the embodiments of the present application do not limit this.
[0241] In addition, optionally, the terminal device can also send the second identifier information to the first network element, without having to send the encrypted first identifier information. For example, in a 4G network, the terminal device can send the international mobile subscriber identity (IMSI) of the terminal device in the NTN network to the first network element. Among them, the IMSI of the terminal device in the NTN network can be the same as the IMSI of the terminal device in the ground network, or it can be different. Optionally, in the case that the IMSI of the terminal device in the NTN network is different from the IMSI of the terminal device in the ground network, the information stored by the terminal device, including the architecture of the NTN network and / or the information corresponding to the identifier of the NTN network, can include the IMSI of the terminal device in the NTN network.
[0242] For example, assuming that the first network element is a UDM network element, the terminal device is a UE, the first module is an ME module, and the second module is a USIM module, if the method embodiments of S301-S303 are applied to a 5G network, a possible, non-limiting flow is shown in FIG. 4, including the following steps:
[0243] S400a, the UE acquires information corresponding to the NTN network (which can be information corresponding to the architecture of the NTN network and / or the identifier of the NTN network), including the first key and the second key.
[0244] S400b, the UDM network element preinstalls the first key and the second key. The UDM network element can be deployed on the ground or on a satellite. The first key preinstalled by the UDM network element can be used to decrypt the SUCI of the UE, which is described in detail in S409. The second key preinstalled by the UDM network element can be used for authentication and authorization between the UDM network element and the terminal device, which is described in detail in S416.
[0245] In addition, the AUSF network element in FIG. 4 can be deployed on the ground or on a satellite. The AMF network element can be all deployed on the ground, all deployed on a satellite, or partially deployed on the ground and partially deployed on a satellite.
[0246] S401, the satellite (or an access network device deployed on a satellite, which is exemplified by a satellite in FIG. 4) broadcasts the PLMN ID of the NTN network and the S&F indication. The S&F indication can indicate that the NTN network supports the S&F architecture.
[0247] Optionally, the PLMN ID can indicate the architecture of the NTN network.
[0248] S402 (optional step), the UE determines whether it supports the service of the NTN network and whether it supports the S&F architecture according to the message broadcast by the satellite. The UE can continue to execute the following flow in the case of determining that it supports the service of the NTN network and supports the S&F architecture, and terminate the flow in the case of determining that it does not support the service of the NTN network or does not support the S&F architecture.
[0249] In FIG. 4, the ME in the UE is exemplified to execute S402.
[0250] S402 can refer to the description of the first module determining whether the terminal device supports the service of the NTN network and / or the architecture of the NTN network in S301.
[0251] S403, the UE completes the random access procedure. For example, the random access procedure can refer to the protocol: 3GPP TS 38.300.
[0252] In the case where the calculation of SUCI is performed by the USIM, S403 is followed by S404a-S406a, and in the case where the calculation of SUCI is performed by the ME, S403 is followed by S404b-S405b.
[0253] S404a-S406a include the following steps:
[0254] S404a, the ME sends a get identity message to the USIM, which includes the PLMN ID.
[0255] For example, the ME sends a get identity message to the USIM in the case where the calculation of SUCI is determined by the USIM.
[0256] S405a, the USIM determines the SUPI of the UE in the NTN network and the first key according to the PLMN ID.
[0257] Optionally, the USIM can determine the second key in S405a. If the second key is not determined in S405a, the USIM can determine the second key in the subsequent S412.
[0258] S406a, the USIM encrypts the SUPI of the UE in the NTN network according to the first key, generates the SUCI of the UE in the NTN network, and sends the SUCI of the UE to the ME.
[0259] S404a-S406a can refer to the description of the second module determining the first information according to the first indication information in S302.
[0260] S404b-S405b include the following steps:
[0261] S404b, the ME obtains the SUPI of the UE in the NTN network and the first key according to the PLMN ID. The ME can read the SUPI of the UE in the NTN network and the first key in the information stored by itself, or the ME can send the PLMN ID to the USIM to read the SUPI of the UE in the NTN network and the first key in the information stored by the USIM.
[0262] Optionally, in S404b, if the ME sends the PLMN ID to the USIM, the USIM can determine the second key according to the PLMN ID. If the second key is not determined by the USIM in S405b, the second key can be determined in the subsequent S412.
[0263] S405b, the ME encrypts the SUPI of the UE in the NTN network according to the first key to generate the SUCI of the UE in the NTN network.
[0264] S404b-S405b can refer to the description of the second module in S302 according to the first indication information to determine the first information in the foregoing description.
[0265] After S404a-S406a or S404b-S405b, the following steps are included:
[0266] S407, the ME sends a registration request message to the AMF network element, and the message carries the SUCI of the UE.
[0267] S408, the AMF network element forwards the registration request message carrying the SUCI to the AUSF network element, and the AUSF network element forwards the message to the UDM network element.
[0268] S409, the UDM network element decrypts the SUCI according to the preconfigured first key, obtains the SUPI of the UE, and generates a security authentication vector (SEAV).
[0269] S410, the UDM network element sends an authentication response message (authenticate_get response) carrying the security authentication vector and the SUPI to the AUSF network element.
[0270] S411, the AUSF network element calculates a parameter for authentication and authorization, such as HXRES*.
[0271] S412, the AUSF network element sends an authentication response (authenticate response) message carrying the security authentication vector and HXRES* to the AMF network element.
[0272] S413, the AMF network element sends an authentication request (authenticate request) message carrying the security authentication vector to the UE.
[0273] S414, the ME sends an authentication message to the USIM, which is used to request a security context from the USIM.
[0274] Optionally, if the USIM does not determine the second key according to the PLMN ID in S405a or S404b, the ME can carry the PLMN ID in an authentication message sent to the USIM in S414 to determine the second key.
[0275] In S415, after the USIM receives the authentication message, the USIM calculates a security context according to the second key and returns an authentication response message to the ME, where the authentication response message includes the security context. The security context includes parameters for authentication and authorization, such as a response (RES).
[0276] S414 can refer to the description of the second module determining the first information in S302.
[0277] In S416, the ME sends the RES in the security context to the UDM network element, and the UE and the on-board core network in the NTN network continue the authentication and authorization process to complete the authentication and authorization. In the authentication and authorization process, the UDM network element can perform authentication and authorization according to the preset second key and the RES in the security context. For example, the authentication and authorization process can refer to the protocol TS 33.501.
[0278] For example, assuming that the first network element is a core network element in EPS, the terminal device is a UE, the first module is an ME module, and the second module is a USIM module, if the method embodiments of S301-S303 are applied to a 4G network, a possible, non-limiting process is shown in FIG. 5, including the following steps:
[0279] In S500a, the UE obtains information corresponding to the NTN network (which can be information corresponding to the architecture of the NTN network and / or the identifier of the NTN network), including the second key.
[0280] In S500b, the EPS presets the second key. The EPS can be deployed on the ground, on a satellite, or partially on a satellite and partially on the ground.
[0281] In S501, the satellite (or an access network device deployed on a satellite, which is exemplified by a satellite in FIG. 5) broadcasts the PLMN ID of the NTN network and the S&F indication. The S&F indication can indicate that the NTN network supports the S&F indication architecture. Optionally, the PLMN ID can indicate the architecture of the NTN network.
[0282] S502 (optional step), the UE determines whether it supports the service of the NTN network and whether it supports the S&F architecture according to the message broadcasted by the satellite. The UE can continue to execute the following flow in the case that it determines that it supports the service of the NTN network and supports the S&F architecture, and the flow terminates in the case that it determines that it does not support the service of the NTN network or does not support the S&F architecture.
[0283] In some embodiments, the S502 is executed by the ME module in the UE.
[0284] The S402 can refer to the description of the first module determining whether the terminal device supports the service of the NTN network and / or the architecture of the NTN network in S301.
[0285] S503, the UE completes the random access procedure. For example, the random access procedure can refer to the protocol: 3GPP TS 38.300.
[0286] S504, the UE sends an attach request message to the EPS, wherein the IMSI of the UE in the NTN network is carried.
[0287] Optionally, if the IMSI of the UE in the NTN network is different from the IMSI of the UE in the terrestrial network, the UE can determine the identity of the NTN network and / or the information corresponding to the architecture of the NTN network according to the PLMN ID before the UE sends the IMSI, and determine the IMSI of the UE in the corresponding information. For example, the determination of the identity of the NTN network and / or the information corresponding to the architecture of the NTN network according to the second indication information by the first module in S301 can be referred to.
[0288] S505, the EPS sends an authentication response message to the UE.
[0289] S506, the ME sends an authentication message to the USIM, for requesting a security context from the USIM, wherein the PLMN ID of the NTN network is carried in the message.
[0290] S507, the USIM determines a second key according to the PLMN ID. The USIM calculates the security context according to the second key, and returns the security context to the ME. For example, the security context contains parameters used in authentication and authorization, such as RES.
[0291] The S507 can refer to the description of the second module determining the first information in S302.
[0292] S508, the ME sends the RES in the security context to the EPS, the on-board core network in the UE and the NTN network continues the authentication and authorization process, and completes the authentication and authorization. For example, the authentication and authorization process can refer to the protocol TS 33.501.
[0293] Optionally, in the case where the PLMN ID can indicate the architecture of the NTN network, after the first module receives the PLMN ID broadcast by the satellite, the first module can further generate another information indicating the architecture of the NTN network (for example, information indicating the architecture of the NTN network by a bit value), in which case the first module sending the PLMN ID to the second module can be replaced by: the first module sending the PLMN ID and / or the information indicating the architecture of the NTN network to the second module.
[0294] In addition, the embodiments of the present application also provide a communication method, which is illustrated by taking the second network element as the execution subject of the flowchart in FIG. 6, but the present application does not limit the execution subject of the flowchart. For example, the second network element in FIG. 6 can also be a module applied to the second network element, such as a chip, a chip system, or a processor, and can also be a logical node, a logical module or software capable of realizing all or part of the functions of the second network element. As shown in FIG. 6, the communication method comprises the following steps:
[0295] S601, the second network element determines second information. Wherein, the second information corresponds to the architecture of the NTN network, and / or the second information corresponds to the identifier of the NTN network. The second information is used for the terminal device to access the NTN network.
[0296] Wherein, the second network element determines the second information, which can also be understood as the second network element obtaining the second information.
[0297] Wherein, the second network element can be a network element in the HPLMN of the terminal device. For example, the second network element can be an HSS or a UDM network element in the HPLMN of the terminal device. Optionally, the HPLMN of the terminal device can be a ground network or an NTN network (for example, an NTN network storing information of the terminal device), and the embodiments of the present application do not limit this.
[0298] Wherein, the information included in the second information can be specifically referred to the description of the information corresponding to the architecture of the NTN network or the information corresponding to the identifier of the NTN network in S301 above.
[0299] Optionally, if the embodiment as shown in FIG. 6 is combined with the embodiment as shown in FIG. 3, the second network element can be the same network element as the first network element, or can be a different network element.
[0300] S602, the second network element sends the second information to the terminal device.
[0301] Optionally, the second information may belong to the data subscribed between the terminal device and the NTN network, or in other words, the second information may be included in the data subscribed between the terminal device and the NTN network.
[0302] Optionally, the NTN network may correspond to at least one set of second information. For example, assuming that an NTN network can provide services from multiple operators, and a terminal device has subscribed to services from multiple operators, then the data subscribed by the terminal device to the NTN network may include the second information corresponding to each operator.
[0303] Optionally, the second information may include at least one of the following: a first key, a second key (or a first parameter), and the identification information of the terminal device in the NTN network. For details regarding the first key, the second key, the first parameter, or the identification information of the terminal device in the NTN network, please refer to the descriptions of S301-S302 above, which will not be elaborated upon here.
[0304] Optionally, the second information may also include at least one of the following: routing indication information, core network public key identifier for the NTN network, protection scheme identifier, or SUCI calculation indication, etc. For details on these information, please refer to the description above of the architecture and / or identification information corresponding to the NTN network in S301, which will not be elaborated upon here.
[0305] Optionally, if the identification information of the terminal device in the NTN network is different from that in the terrestrial network, for example, if the SUPI of the terminal device in the NTN network is different from that in the terrestrial network, the first information may also include the identification information of the terminal device in the NTN network.
[0306] Optionally, when the second network element sends the second information to the terminal device, it may also send first indication information. The first indication information may indicate the architecture of the NTN network and / or the identifier of the NTN network, as detailed in the description of S301 above. That is, the first indication information may be carried in the same message as the second information. Optionally, in this case, the first indication information may also be considered as information in the second information, or the second information may be considered to correspond to the architecture of the NTN network and / or the identifier of the NTN network.
[0307] The following describes the implementation of the second network element acquiring the second information in S601.
[0308] If the second information includes the first key, the first key may be determined and sent to the second network element by the NTN network operator. Alternatively, the first key may be determined by the second network element itself. Optionally, if the second network element determines the first key itself, the second network element may also send the first key to the NTN network operator.
[0309] If the second information includes the second key, the second key can be pre-stored in the second network element (or configured in the second network element). Alternatively, the second network element can generate the second key. For example, the second network element can generate the second key according to a root key of the terminal device in the ground network. For another example, the second network element can generate the second key according to a random number.
[0310] Optionally, if the second key is pre-stored in the second network element, the second network element can also store a mapping relationship between a root key of the terminal device in the ground network and the second key, which represents that the two keys correspond to the same terminal device.
[0311] Optionally, the second key pre-stored in the second network element can be sent to the second network element by a core network element in the NTN network, for example, a UDM network element in the NTN network.
[0312] Optionally, if the second key is generated by the second network element, the second network element can send the second key to a core network element in the NTN network, for example, a UDM network element in the NTN network.
[0313] If the second information includes the first parameter, the second network element can obtain the first parameter based on any possible manner, for example, generating a random number. Optionally, the second network element can generate the second key according to the first parameter and store the second key. For example, the second network element can generate the second key according to the first parameter, a PLMN ID of the NTN network, and a root key of the terminal device in the ground network.
[0314] Optionally, the second network element determines the second information, or the second network element sends the second information to the terminal device, which can be triggered by the terminal device. For example, the terminal device opens (or subscribes to) a service provided by the NTN network, such as the user of the terminal device triggers the second network element to send the second information to the terminal device by means of a short message, a telephone call, or a visit to a business hall to apply for a service provided by the NTN network.
[0315] Optionally, the second network element can update the second information and send the updated second information to the terminal device. For example, the second network element can periodically update the second information. For another example, the terminal device can instruct the second network element to update the second information. Optionally, the terminal device can periodically instruct the second network element to update the second information. Alternatively, the terminal device can instruct the second network element to update the second information when it is found that there is no second information corresponding to a certain architecture and / or a certain identifier of the NTN network in the second information stored by the terminal device.
[0316] In a possible implementation, before S601, the second network element can receive indication information, which can indicate that the terminal device subscribes to a first service, the first service can be provided by the NTN network, or the indication information can indicate that the second network element updates the second information. The second network element determines the second information and sends the second information to the terminal device upon receiving the indication information. That is, the indication information can trigger the second network element to determine the second information and send the second information to the terminal device.
[0317] Optionally, the second network element can also determine and send information corresponding to other NTN networks to the terminal device, which is used for accessing the other NTN networks. For example, if the service subscribed by the terminal device can also be provided by other NTN networks, the second network element can determine information corresponding to the other NTN networks (which can be specifically referred to as the second information) and send the information corresponding to the other NTN networks to the terminal device. That is, the terminal device can receive information corresponding to at least one NTN network. The method embodiments of S601-S602 are described by taking the second network element determining the second information and sending the second information to the terminal device as an example. It can be understood that if the second network element also determines and sends information corresponding to other NTN networks to the terminal device, the specific implementation can refer to the implementation of the second network element determining the second information and sending the second information to the terminal device in the method embodiments.
[0318] The second network element sending the second information to the terminal device in S602 is described below.
[0319] The present application does not limit the implementation of the second network element sending the second information to the terminal device. In a possible implementation, the second network element can send the second information to the terminal device through a user parameter update (UE parameters update, UPU) process. In this implementation, the second information can be included in UPU data (UPU data).
[0320] Optionally, a new data type can be added in the UPU data, and the second information can be carried in the new data type. For example, assuming that a satellite subscription data type (NTN / Satellite related data) is added in the UPU data, the second information can be issued through the satellite subscription data type. In the UPU data, the bit indicating the data type has a value of 0101, which can indicate that the data type of the UPU data is the satellite subscription data type.
[0321] Optionally, the second network element can encrypt information in the second information before sending the second information to the terminal device (i.e., the information in the first information can be transmitted in an encrypted manner). The second network element can encrypt at least one of the information in the second information, such as at least one of the first key, the second key, or the identification information of the NTN network.
[0322] Embodiments of the present application do not limit the manner in which the second network element encrypts the information in the second information. For example, the second network element can generate a key based on the root key of the terminal device in the terrestrial network, and use the generated key to encrypt the information in the second information, such as the second key.
[0323] Correspondingly, after receiving the second information, if the information in the second information is encrypted, the terminal device can generate a key that is the same as the key used by the second network element to encrypt the information in the second information, and use the key to decrypt the information in the first information.
[0324] Optionally, the transmission of the second information can also be integrity protected. In one possible implementation, the second network element can integrity protect the second information by itself. In another possible implementation, the second network element can send the second information to a third network element, which integrity protects the second information after receiving the second information and generates information for integrity protection verification. The third network element returns the information for integrity protection verification to the second network element. The second network element then sends the second information and the information for integrity protection verification to the terminal device.
[0325] Embodiments of the present application do not limit the third network element, which can be an AUSF network element, for example.
[0326] The information for integrity protection verification can include information for integrity protection verification of the second information by the terminal device, and / or information for integrity protection verification of the second information by the second network element.
[0327] If the information for integrity protection verification sent by the third network element to the second network element includes information for integrity protection verification of the second information by the terminal device (hereinafter referred to as first verification information), the second network element can send the first verification information together with the second information when sending the second information to the terminal device. After receiving the second information and the first verification information, the terminal device can verify the first verification information based on the second information to determine whether the transmission of the second information is integrity protected.
[0328] If the information for integrity protection check sent by the third network element to the second network element includes information for the second network element to perform integrity protection check on the second information (hereinafter referred to as second check information), the second network element can retain the second check information, and send indication information (ACK indication) indicating that the terminal device returns a response message together with the second information when sending the second information to the terminal device. If the terminal device receives the indication information together with the second information, the terminal device can generate check information based on the second information (the check information is used for the second network element to check the second check information), and send the check information to the second network element. The second network element can determine whether the second check information is consistent with the check information from the terminal device according to the second check information and the check information from the terminal device, and if it is determined that the second check information is consistent with the check information from the terminal device, it can be determined that the transmission of the second information is integrity protected, and if it is determined that the second check information is not consistent with the check information from the terminal device, it can be determined that the transmission of the second information is not integrity protected.
[0329] Based on the scheme for integrity protection of the second information provided in the embodiments of the present application, the security of the transmission of the second information can be improved, and the second information can be prevented from being tampered with by an intermediate network element on the transmission path from the second network element to the terminal device.
[0330] Optionally, if the information for integrity protection check includes the first check information and the second check information, the terminal device can generate check information and send the check information to the second network element after receiving the second information and the first check information, under the condition that the check on the first check information is passed.
[0331] Optionally, after receiving the second information, the third network element can also generate and send information for anti-replay to the second network element. For example, the information for anti-replay can be a parameter generated based on a counter (counter) each time the third network element performs integrity protection on the second information. The third network element generates a parameter with a different value each time, which can be used for anti-replay. The second network element can also send the information for anti-replay when sending the second information to the terminal device.
[0332] In another possible implementation, the second network element can send the second information to the terminal device through an over-the-air (OTA) procedure.
[0333] Optionally, information can be transmitted between the second network element and the terminal device through an intermediate network element, such as an AMF network element. The intermediate network element can be located on the ground or on a satellite.
[0334] Optionally, the second information can be in a secured packet format.
[0335] Optionally, after receiving the second information, the terminal device can store the second information. If the information in the second information is encrypted, the terminal device can store the first information after decrypting the second information.
[0336] Optionally, after receiving the second information, if the second information includes the first parameter, the terminal device can generate a second key according to the first parameter, and then store the second key and other information in the first information. The embodiments of the present application do not limit the implementation of the terminal device generating the second key according to the first parameter, and exemplarily, the terminal device can generate the second key according to the first parameter (such as a random number) and a root key of the terminal device in the ground network.
[0337] Optionally, if the terminal device also receives the first indication information sent together with the second information, in the case that the first indication information indicates the architecture of the NTN network, the terminal device can determine the architecture of the NTN network according to the first indication information, and store the mapping relationship between the architecture of the NTN network and the second information. Or, in the case that the first indication information indicates the identity of the NTN network, the terminal device can store the mapping relationship between the identity of the NTN network and the second information.
[0338] Exemplarily, assuming that the second network element is a UDM network element and the terminal device is a UE, one possible, non-limiting flow of the method embodiments of S601-S602 is shown in FIG. 7, including the following steps:
[0339] S700a, the UE opens a satellite service. The satellite service can be provided by the NTN network.
[0340] S700b, the UDM network element learns that the UE opens the satellite service, and sends data of the UE and the NTN network subscription (which can also be referred to as satellite subscription data) to the UE through the UPU process, for example, carries the satellite subscription data in the UPU data and sends it to the UE. The satellite subscription data includes the second key (or the first parameter), the first key, the PLMN ID of the NTN network and the SUPI of the UE in the NTN network. Optionally, the PLMN ID of the NTN network can indicate the architecture of the NTN network.
[0341] S701, the UDM network element determines the first key and the PLMN ID of the NTN network.
[0342] Based on whether the UPU data carries the second key or the second parameter, the UDM network element performs S702a-S703a or S702b-S703b.
[0343] In the case that the UPU data carries the second key, the UDM network element performs S702a-S703a:
[0344] S702a, the UDM network element determines a second key and encrypts the second key. For example, the UDM network element can generate a key for encrypting the second key according to a root key of the UE in the ground network.
[0345] S702a can refer to the description of S601 of determining the second information by the second network element and S602 of encrypting the information in the second information by the second network element.
[0346] S703a, the UDM network element sends an UPU protection message (Nausf_UPUProtection) to the AUSF network element, which carries the SUPI of the UE (the SUPI of the UE in the ground network), UPU data and ACK indication (ACK Indication). The UPU data includes the first key, the encrypted second key and the PLMN ID of the NTN network. The ACK indication is used to indicate whether the UE needs to feed back a response message.
[0347] In the case that the UPU data carries the first parameter, the UDM network element performs S702b-S703b:
[0348] S702b, the UDM network element determines the first parameter and generates the second key according to the first parameter.
[0349] S703b, the UDM network element sends Nausf_UPUProtection to the AUSF network element, which carries the SUPI of the UE, UPU data and ACK indication. The UPU data includes the first key, the first parameter and the PLMN ID of the NTN network.
[0350] After S702a-S703a or S702b-S703b, the flow includes the following steps:
[0351] S704, the AUSF network element performs integrity protection on the UPU data and generates information for integrity protection verification: UPU-MAC-I AUSF and UPU-XMAC-I UE , and generates information for anti-replay: Counter UPU . The AUSF network element sends an UPU protection response message (Nausf_UPUProtection Response) to the UDM network element, which carries UPU-MAC-I AUSF , UPU-XMAC-I UE , and Counter UPU .
[0352] S705, the UDM network element sends the UPU data, the UPU-MAC-I, and the Counter to the AMF network element. AUSF UPU .
[0353] S706, the AMF network element sends a down link (DL) non-access stratum (NAS) message (DL NAS Transport) to the UE, wherein the DL NAS Transport carries the UPU data, the UPU-MAC-I, and the Counter. AUSF UPU Optionally, the DL NAS Transport can also carry an ACK Indication.
[0354] S707, the UE checks the UPU-MAC-I. AUSF .
[0355] Optionally, if the UE receives the DL NAS Transport also carrying the ACK Indication, S707 can further include the following steps S708-S710:
[0356] S708, in the case that the UE passes the check of the UPU-MAC-I, the UE generates a UPU-MAC-I based on the UPU data. AUSF UE The UE sends an uplink NAS message (UL NAS Transport) to the AMF network element, wherein the UL NAS Transport carries the UPU-MAC-I. UE .
[0357] S709, the AMF network element sends the UPU-MAC-I to the UDM network element. UE
[0358] S710, the UDM network element checks the UPU-MAC-I received in S709 based on the UPU-XMAC-I received in S704. UE UE If the UPU-XMAC-I is determined to be the same as the UPU-MAC-I, it is determined that the UE correctly receives the UPU data. UE UE If the UPU-XMAC-I is determined to be different from the UPU-MAC-I, it is determined that the UE does not correctly receive the UPU data. UE UE .
[0359] Optionally, the UDM network element can retransmit the UPU data to the UE in a case where it is determined that the UE has not correctly received the UPU data.
[0360] S711, in a case where the UE passes the verification of the UPU-MAC-I AUSF , the UE performs corresponding processing on the received UPU data. If the verification of the UPU-MAC-I AUSF fails, the UE can terminate the flow and discard the received UPU data. If the flow includes S702a-S703a, the corresponding processing performed by the UE on the received UPU data can be S711a:
[0361] S711a, the UE generates a key, which is the same as the key used by the UDM network element to encrypt the second key in S702a. The UE decrypts the second key through the key, stores the second key, the first key, and the PLMN ID.
[0362] If the flow includes S702b-S703b, the corresponding processing performed by the UE on the received UPU data can be S711b:
[0363] S711b, the UE generates a second key through the first parameter, and stores the second key, the first key, and the PLMN ID.
[0364] It can be understood that the flow shown in the flowchart in the embodiments of the present application, for example, the flow shown in FIG. 4, FIG. 5, or FIG. 7, is only a logical schematic flow provided for the purpose of facilitating the understanding of the embodiments of the present application, and does not represent the actual timing of the embodiments of the present application. The embodiments of the present application do not limit the timing between different steps in the flowchart.
[0365] Each of the above method embodiments can be independently applied or combined. For example, the method embodiment shown in FIG. 3 can be combined with the method embodiment shown in FIG. 6. After the terminal device receives the second information from the second network element, the second module in the terminal device can save the information in the second information. Optionally, the first module can also save the information in the second information. After the first module sends the first indication information to the second module, the second module can determine the second information according to the first indication information, and further determine the first information according to the second information (i.e., the second information can include the information corresponding to the architecture of the NTN network and / or the identifier of the NTN network in S301). The second module sends the first information to the first module. For details, reference can be made to the description of the above method embodiments.
[0366] The above describes the solutions provided by the embodiments of the present application from the perspective of different modules in the terminal device or the interaction between the network element and the terminal device. Correspondingly, the embodiments of the present application also provide a communication apparatus for implementing the above methods. The communication apparatus can be various modules (for example, the first module, the second module) in the above method embodiments, or an apparatus containing the above modules (for example, an apparatus containing the first module, an apparatus containing the second module, or an apparatus containing the first module and the second module), or the above network elements (for example, the second network element).
[0367] It can be understood that the communication apparatus contains the hardware structure and / or software module for implementing the above functions. Those skilled in the art should easily realize that, in combination with the units and algorithm steps of the examples described in the embodiments disclosed in the present application, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is implemented in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0368] The embodiments of the present application can divide the functions of the communication apparatus according to the above method embodiments, for example, each function module can be divided according to each function, or two or more functions can be integrated into one processing module. The above integrated module can be realized in the form of hardware or software function module. It should be noted that the division of the modules in the embodiments of the present application is illustrative, and is only a logical function division. Actual implementation can have another division manner.
[0369] FIG. 8 shows a structural schematic diagram of a communication apparatus 800. The communication apparatus 800 includes a first module 801 and a second module 802. The first module 801 can also be referred to as a first unit 801. The second module 802 can also be referred to as a second unit 802.
[0370] The first module 801 and / or the second module 802 can implement receiving and / or sending functions. The first module 801 and / or the second module 802 can also implement processing functions.
[0371] Optionally, the first module 801 and / or the second module 802 can also implement storage functions.
[0372] Optionally, the communication apparatus 800 can also include other modules.
[0373] The first module 801 can implement the functions of the first module in the method embodiments. The second module 802 can implement the functions of the second module in the method embodiments. In a possible design, the first module 801 can send first indication information to the second module 802. The second module 802 can receive the first indication information. The second module 802 can further send first information to the first module 801 according to the first indication information. The first module 801 can further receive the first information. The first module 801 sends the first indication information to the second module 802, and the second module 802 receives the first indication information, which can refer to the description of S301. The second module 802 sends the first information to the first module according to the first indication information, and the first module 801 receives the first information, which can refer to the description of S302, and details are not described herein.
[0374] Optionally, in the communication apparatus shown in FIG. 8, the names of the modules can not be the names shown in the figure.
[0375] FIG. 9 shows a structural diagram of another communication apparatus 900. The communication apparatus 900 includes a transceiver module 901 and a processing module 902. The transceiver module 901, which can also be referred to as a transceiver unit 901, is configured to implement receiving and / or sending functions. The processing module 902, which can also be referred to as a processing unit 902, is configured to implement processing functions.
[0376] Optionally, the communication apparatus 900 can further include other modules, for example, a storage module 903.
[0377] In a possible design, the communication apparatus 900 can implement the functions of the second network element in the method embodiments. The processing module 902 is configured to determine second information. The transceiver module 901 is configured to send the second information to a terminal device. The processing module 902 determines the second information, which can refer to the description of S601. The transceiver module 901 sends the second information to the terminal device, which can refer to the description of S602.
[0378] Optionally, in the communication apparatus shown in FIG. 9, the names of the modules can not be the names shown in the figure. For example, the transceiver module can also be referred to as a communication module or a communication unit.
[0379] Each of the modules in FIG. 8 or FIG. 9, if implemented in the form of a software functional module and sold or used as an independent product, can be stored in a computer readable storage medium. Based on such an understanding, the technical solutions of the embodiments of the present application essentially or partially or entirely in the form of a software product can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to perform all or part of the steps of the methods described in the embodiments of the present application. The storage medium storing the computer software product includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, and various other media capable of storing program codes.
[0380] In the embodiments of the present application, the communication device 800 or the communication device 900 is presented in the form of dividing various functional modules in an integrated manner. The "module" here can refer to an application-specific integrated circuit (ASIC), a circuit, a processor and a memory executing one or more software or firmware programs, an integrated logic circuit, and / or other devices that can provide the above functions.
[0381] FIG. 10 shows a structural schematic diagram of another communication device 1000. As shown in FIG. 10, the communication device 1000 includes one or more processors 1001, a communication line 1002, and at least one communication interface (only an example of a communication interface 1004 is shown in FIG. 10, and one processor 1001 is taken as an example for description), and optionally further includes a memory 1003.
[0382] The processor 1001 can be a general central processing unit (CPU), a microprocessor, an ASIC, or one or more integrated circuits for controlling the execution of programs of the solutions of the present application.
[0383] The communication line 1002 can include a channel for connecting different components.
[0384] The communication interface 1004 can be a transceiver module for communicating with other modules, other devices or communication networks, such as Ethernet, RAN, terminal, wireless local area networks (WLAN), etc. For example, the transceiver module can be a transceiver, a transceiver-like device, etc. Alternatively, the communication interface 1004 can also be a transceiver circuit or an input / output interface within the processor 1001 for implementing signal input and signal output of the processor.
[0385] The memory 1003 can be a device with a storage function. For example, it can be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disk storage, a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer, but is not limited to this. The memory can exist independently and be connected to the processor through the communication line 1002. The memory can also be integrated with the processor.
[0386] The memory 1003 is configured to store computer-executed instructions for implementing the solutions of the present application, and the processor 1001 is configured to control the execution of the computer-executed instructions. The processor 1001 is configured to execute the computer-executed instructions stored in the memory 1003, so as to implement the communication method provided in the embodiments of the present application.
[0387] Alternatively, in the embodiments of the present application, the processor 1001 can execute the functions related to processing in the communication method provided in the above embodiments of the present application, and the communication interface 1004 is responsible for communication with other devices or communication networks, which is not limited in the embodiments of the present application.
[0388] Alternatively, in the embodiments of the present application, the computer-executed instructions can also be referred to as application program codes, which are not limited in the embodiments of the present application.
[0389] In a specific implementation, as an embodiment, the processor 1001 can include one or more CPUs, such as CPU0 and CPU1 in FIG. 10.
[0390] In a particular implementation, as an example, the communication apparatus 1000 can include multiple processors, such as the processor 1001 and the processor 1007 in FIG. 10. Each of these processors can be a single-core processor or a multi-core processor. The processor herein can include, but is not limited to, at least one of the following: a CPU, a microprocessor, a digital signal processor (DSP), a microcontroller unit (MCU), or an artificial intelligence processor, and the like computing devices running software, each of which can include one or more cores for executing software instructions to perform calculations or processing.
[0391] In a particular implementation, as an example, the communication apparatus 900 can further include an output device 1005 and an input device 1006. The output device 1005 communicates with the processor 1001 and can display information in various ways. For example, the output device 1005 can be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector, and the like. The input device 1006 communicates with the processor 1001 and can receive user input in various ways. For example, the input device 1006 can be a mouse, a keyboard, a touch screen device, a sensor device, and the like.
[0392] The communication apparatus 1000 described above can also be referred to as a communication device, which can be a general-purpose device or a special-purpose device. For example, the communication apparatus 1000 can be the first module, the second module, the terminal device including the first module and the second module, the second network element, or a device having a similar structure to that in FIG. 10. The embodiments of the present application do not limit the type of the communication apparatus 1000.
[0393] In addition, the constituent structure shown in FIG. 10 does not constitute a limitation on the communication apparatus, and the communication apparatus 1000 can include more or fewer components than those shown in the figure, or combine certain components, or different component arrangements, in addition to the components shown in FIG. 10.
[0394] Optionally, the functions / realization procedures of the first module 801 and / or the second module 802 in the communication apparatus 800 in FIG. 8 can be implemented by invoking the computer-executed instructions stored in the memory 1003 by the processor 1001 in the communication apparatus 1000 shown in FIG. 10. Alternatively, the functions / realization procedures of the first module 801 and / or the second module 802 can be implemented by the communication interface 1004 in the communication apparatus 1000 shown in FIG. 10.
[0395] Optionally, the functions / realization procedures of the transceiving module 901 and the processing module 902 in FIG. 9 can be implemented by invoking the computer-executed instructions stored in the memory 1003 by the processor 1001 in the communication apparatus 1000 shown in FIG. 10. Alternatively, the functions / realization procedures of the processing module 902 in FIG. 9 can be implemented by invoking the computer-executed instructions stored in the memory 1003 by the processor 1001 in the communication apparatus 1000 shown in FIG. 10, and the functions / realization procedures of the transceiving module 901 in FIG. 9 can be implemented by the communication interface 1004 in the communication apparatus 1000 shown in FIG. 10.
[0396] It should be understood that one or more of the above modules or units can be implemented in software, hardware, or a combination of both. When any of the above modules or units is implemented in software, the software exists in the form of computer program instructions, and is stored in a memory, and a processor can be used to execute the program instructions and implement the above method flow. The processor can be built in a SoC or an ASIC, or be a separate semiconductor chip. The processor further includes a core for executing software instructions to perform operations or processing, and can further include necessary hardware accelerators, such as an FPGA, a programmable logic device (PLD), or a logic circuit implementing special logic operations.
[0397] When any of the above modules or units is implemented in hardware, the hardware can be any one or any combination of a CPU, a microprocessor, a DSP chip, an MCU, an artificial intelligence processor, an ASIC, a SoC, an FPGA, a PLD, a special digital circuit, a hardware accelerator, or a non-integrated discrete device, which can run necessary software or be independent of software to execute the above method flow.
[0398] Optionally, the embodiment of the present application further provides a communication device (for example, the communication device can be a chip or a chip system), which comprises a processor for implementing the method in any of the method embodiments. In a possible design, the communication device further comprises a memory. The memory is used to store necessary program instructions and data, and the processor can invoke the program code stored in the memory to instruct the communication device to execute the method in any of the method embodiments. Of course, the memory can also not be in the communication device. When the communication device is a chip system, the chip system can be composed of a chip or can comprise a chip and other discrete devices, and the embodiment of the present application does not make a specific limitation in this regard.
[0399] For example, FIG. 11 shows a structural schematic diagram of a chip system. The chip system can implement the functions of the first module or the second module in the method embodiments, or the chip system can implement the functions of the terminal device comprising the first module and the second module in the method embodiments. As shown in FIG. 11, the chip system comprises a processor module, a storage module, a power supply module and a radio frequency / antenna module.
[0400] The processor module is used for various calculations, in which the CPU is responsible for executing various instructions, including the instructions of application programs, operating systems and other software; the graphic processing unit (GPU) is mainly responsible for graphic processing, but the CPU can also process some graphic tasks, for example, the rendering of an application interface; the modem is used for modulating or demodulating signals, so that digital signals can be transmitted in space.
[0401] In the storage module, the RAM is a temporary storage space, which is used to temporarily store data in use, for example, if the chip system is located in a mobile phone, the RAN can store opened web pages, messages of chat applications, game states and the like. The ROM is a read-only storage space, for example, if the chip system is located in a mobile phone, the ROM can store system files, pre-installed application programs and firmware.
[0402] The power supply module is used to provide voltage and current for other modules, so as to maintain the normal operation of the chip.
[0403] The radio frequency / antenna module is used to amplify signals and radiate them into space, or receive wireless signals in space.
[0404] Optionally, the embodiment of the present application further provides a computer readable storage medium, which stores computer programs or instructions, when the computer programs or instructions run on the communication device, the communication device can execute the method in any of the method embodiments or the method in any of the implementation manners of the method embodiments.
[0405] Optionally, the embodiment of the present application further provides a computer program product, which stores the computer program or instructions, and when the computer program product runs on the communication device, the communication device can execute the method according to any one of the method embodiments or any implementation manner thereof.
[0406] Optionally, the embodiment of the present application further provides a communication system, which comprises the second network element according to the method embodiment, and the terminal device comprising the first module and the second module.
[0407] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented by software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions according to the embodiments of the present application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer readable storage medium or transmitted from one computer readable storage medium to another computer readable storage medium, for example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center through wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) mode. The computer readable storage medium can be any available medium that can be accessed by a computer or data storage device such as one or more servers, data centers, etc. integrated with one or more media. The available media can be magnetic media (such as floppy disk, hard disk, magnetic tape), optical media (such as DVD), or semiconductor media (such as solid state drive (SSD)) and the like.
[0408] Although the present application is described herein in conjunction with various embodiments, other variations of the disclosed embodiments can be understood and implemented by those skilled in the art through viewing the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "one" does not exclude a plurality. A single processor or other unit can implement several functions listed in the claims. Some measures are described in mutually different dependent claims, but this does not mean that these measures cannot be combined to produce good results.
[0409] Although the present application has been described in connection with specific embodiments thereof, it will be evident that many modifications and changes can be made thereto without departing from the scope of the application. Accordingly, it is intended to cover all modifications, alterations, combinations, equivalents, and alternatives falling within the scope of the application. It will be apparent to those skilled in the art that various modifications and variations can be made to the present application without departing from the scope or spirit of the application. Thus, it is intended that the present application cover the modifications and variations of this application provided they come within the scope of the appended claims and their equivalents.
Claims
1. A communication method characterized by comprising: The method is applied to a first module in a terminal device, and the method comprises: sending first indication information to a second module in the terminal device, the first indication information being used for indicating an architecture of a non-terrestrial network, and / or the first indication information being used for indicating an identity of the non-terrestrial network; receiving first information from the second module, the first information being determined according to the first indication information, and the first information being used for accessing the non-terrestrial network.
2. The method of claim 1, wherein, The first information comprises first identity information or identity information of the terminal device in the non-terrestrial network, the first identity information being obtained by encrypting the identity information of the terminal device in the non-terrestrial network according to a first key, and the first key corresponding to the first indication information.
3. The method of claim 1, wherein, The first information comprises a first key, the first key corresponding to the first indication information, and the method further comprises: encrypting the identity information of the terminal device in the non-terrestrial network according to the first key to obtain first identity information, the first identity information being used for accessing the non-terrestrial network.
4. The method according to claim 2 or 3, characterized in that, The method further comprises: receiving user parameter update data, the user parameter update data comprising the first key.
5. The method according to any one of claims 2-4, characterized in that, The identity information of the terminal device in the non-terrestrial network is different from identity information of the terminal device in a terrestrial network. The method further comprises:
6. The method according to any one of claims 2-5, characterized in that, receiving a security context from the second module, the security context being determined according to the first indication information.
7. The method according to any one of claims 2 to 6, characterized in that, The first information comprises the security context. The method further comprises:
8. The method of claim 1, wherein, encrypting the identity information of the terminal device in the non-terrestrial network according to a first key to obtain first identity information, the first identity information being used for accessing the non-terrestrial network, and the first key corresponding to the first indication information.
9. The method of claim 8, wherein, The method further comprises: in a case where the terminal device supports a service provided by the non-terrestrial network, sending the first indication information to the second module.
10. The method according to any one of claims 1 to 9, characterized in that, The method further comprises: sending first indication information to a second module in the terminal device, the method comprising:
11. The method according to any one of claims 1 to 10, characterized in that, in a case where the non-terrestrial network supports a store-and-forward architecture and the terminal device supports the store-and-forward architecture, sending the first indication information to the second module. The method is applied to a second module in a terminal device, and the method comprises: receiving first indication information from a first module in the terminal device; the first indication information being used for indicating an architecture of a non-terrestrial network, and / or the first indication information being used for indicating an identity of the non-terrestrial network; 12. A communication method characterized by comprising: sending first information to the first module according to the first indication information, the first information being used for accessing the non-terrestrial network. The first information comprises first identity information, and the first information is determined according to the first indication information, comprising: 13. The method of claim 12, wherein, According to a first key corresponding to the first indication information, encryption is performed on identification information of the terminal device in the non-ground network, to obtain the first identification information.
14. The method of claim 12, wherein, The first information includes a first key corresponding to the first indication information, and the first key is used for encrypting identification information of the terminal device in the non-ground network to obtain first identification information.
15. The method according to claim 13 or 14, characterized in that, The first indication information is received from a first module in the terminal device, including: An acquisition identification message is received from the first module, and the acquisition identification message includes the first indication information.
16. The method according to any one of claims 13-15, characterized in that, The identification information of the terminal device in the non-ground network is different from identification information of the terminal device in a ground network.
17. The method according to any one of claims 12-16, characterized in that, The method further includes: According to a second key corresponding to the first indication information, a security context is determined; The security context is sent to the first module.
18. The method of claim 12, wherein, The first information includes a security context, and the first information is determined according to the first indication information, including: According to a second key corresponding to the first indication information, the security context is determined.
19. The method of any one of claims 7, 8, 17, or 18, wherein, The security context includes an authentication parameter and / or a third key, the authentication parameter is used for authentication between the terminal device and the non-ground network, and the third key is used for secure communication between the terminal device and the non-ground network.
20. The method of any one of claims 1-19, wherein, The first indication information is used to indicate an architecture of a non-ground network, and the architecture of the non-ground network includes: an architecture in which all core network elements are deployed on a satellite or an architecture in which part of the core network elements are deployed on the satellite.
21. The method of any one of claims 1-20, wherein, The first module is a mobile device module, and the second module is a user service identification or user identification module.
22. A method of communication, comprising: The method includes: A first module in a terminal device sends first indication information to a second module in the terminal device, the first indication information is used to indicate an architecture of a non-ground network, and / or the first indication information is used to indicate identification of the non-ground network; The second module sends first information to the first module according to the first indication information, and the first information is used for accessing the non-ground network; The second module receives the first information from the second module.
23. A method of communication, comprising: The method includes: A second network element determines second information, the second information corresponds to an architecture of a non-ground network, and / or the second information corresponds to identification of the non-ground network; The second network element sends the second information to a terminal device, and the second information is used for the terminal device to access the non-ground network.
24. The method of claim 23, wherein, The second information is used to determine first information, and the first information is used for the terminal device to access the non-ground network.
25. The method of claim 23 or 24, wherein, The second information is included in user parameter update data corresponding to the terminal device.
26. The method of any one of claims 23-25, wherein, The second information belongs to data signed by the terminal device and the non-ground network.
27. The method of any one of claims 23-26, wherein, The second information includes at least one of the following: a first key, a second key, a first parameter, or identification information of the terminal device in the non-ground network, wherein the first parameter is used to generate the second key, the first key is used to encrypt the identification information of the terminal device in the non-ground network, and the second key is used to determine a security context.
28. A communications device, characterized by The communication apparatus comprises modules or units for implementing the method of any one of claims 1-27.
29. A communications device, characterized by The communication apparatus comprises a first module and a second module; wherein the first module is configured to perform the method of any one of claims 1-11, 19-21, and the second module is configured to perform the method of any one of claims 12-21.
30. A computer program product, characterised in that, The computer program product contains computer programs or instructions, which, when executed on a computer, cause the computer to perform the communication method as claimed in any one of claims 1-27.
31. A computer readable storage medium, characterized in that, The computer readable storage medium comprises computer programs or instructions, which, when executed on a computer, cause the computer to perform the method as claimed in any one of claims 1-27.
Citation Information
Patent Citations
Key management method and communication device
CN117062051A
Terminal, network node and communication method
CN117397302A
Terminal and communication method
WO2023079663A1