Communication method and apparatus
By using satellite broadcast messages to determine the security algorithm in non-terrestrial networks, terminal devices establish a secure connection with satellites, solving the problems of signaling overhead and latency, and achieving efficient and secure communication.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- HUAWEI TECH CO LTD
- Filing Date
- 2025-10-27
- Publication Date
- 2026-05-07
AI Technical Summary
In non-terrestrial network scenarios, terminal devices need to frequently establish secure connections with different satellites, and existing technologies cannot effectively solve the problems of signaling overhead and latency.
The terminal device determines the security algorithm based on the satellite's broadcast messages and uses the negotiated security algorithm to protect the communication with the satellite, avoiding the NAS security negotiation process, thereby saving signaling overhead and latency.
It enables a secure connection between terminal devices and satellites, reduces signaling overhead and latency, and improves communication security.
Smart Images

Figure CN2025130241_07052026_PF_FP_ABST
Abstract
Description
Communication methods and devices
[0001] This application claims priority to Chinese patent application filed on November 3, 2024, with application number 202411565881.1 and entitled "Communication Method and Apparatus", the entire contents of which are incorporated herein by reference. Technical Field
[0002] This application relates to the field of communication technology, and more specifically, to a communication method and apparatus. Background Technology
[0003] In non-terrestrial network (NTN) scenarios, aircraft (e.g., airplanes or drones) or satellites are incorporated into the communication system. As satellites move, their coverage areas constantly change, requiring the satellites providing services to terminal devices to also change. Furthermore, core network elements may be hosted on different satellites. Consequently, terminal devices need to frequently establish secure connections with core network elements on different satellites.
[0004] Therefore, in NTN scenarios, how terminal devices can establish a secure connection with satellites is an urgent problem to be solved. Summary of the Invention
[0005] This application provides a communication method and apparatus that enables a secure connection between a terminal device and a satellite, while saving the signaling overhead of establishing a secure connection.
[0006] Firstly, a communication method is provided. The method provided in this application can be executed by a terminal-side device. Unless otherwise specified, the terminal-side device in this application can be a terminal device, a component within a terminal device (e.g., a processor, apparatus, chip, or chip system), or a logic module or software capable of implementing all or part of the functions of the terminal device. For ease of description, the following description uses a terminal-side device as an example.
[0007] The method includes: receiving a broadcast message from a first satellite; determining a first security algorithm corresponding to the first satellite based on the broadcast message; and using the first security algorithm to protect the communication security between the first satellite and the terminal device; wherein the first security algorithm is negotiated and selected by the terminal device with a second satellite before receiving the broadcast message from the first satellite.
[0008] Based on the above scheme, the terminal device can determine the first security algorithm according to the broadcast message, and use the first security algorithm to protect the communication security between the first satellite and the terminal device, thereby realizing the establishment of a secure connection with the first satellite. Furthermore, the above scheme eliminates the need for the terminal device to perform NAS security negotiation with the first satellite, and eliminates the need to send and receive NAS security negotiation signaling, thus saving signaling overhead and latency in establishing a secure connection.
[0009] In some implementations, the first satellite and the second satellite are configured with the same list of security algorithms, and the first security algorithm is determined based on the list of security algorithms and the security capability information of the terminal-side device.
[0010] In some implementations, the broadcast message includes an identifier corresponding to the first satellite or an identifier corresponding to a network element carried on the first satellite. Determining the first security algorithm corresponding to the first satellite based on the broadcast message includes: determining the first security algorithm corresponding to the first satellite based on the identifier corresponding to the first satellite; or, determining the first security algorithm corresponding to the first satellite based on the identifier corresponding to the network element carried on the first satellite.
[0011] In some implementations, determining the first security algorithm corresponding to the first satellite based on the identifier corresponding to the first satellite includes: determining that the first satellite belongs to a first group based on the identifier corresponding to the first satellite; and determining the security algorithm shared by satellites in the first group as the first security algorithm, wherein the first group includes the first satellite and the second satellite.
[0012] In some implementations, determining the first security algorithm corresponding to the first satellite based on the identifier of the first satellite includes: determining that the first satellite and the second satellite belong to the same group based on the identifier of the first satellite; and determining the security algorithm corresponding to the second satellite as the first security algorithm.
[0013] In some implementations, determining the first security algorithm corresponding to the first satellite based on the identifier of the first satellite includes: determining that the security algorithm list configured for the first satellite and the second satellite is the same based on the identifier of the first satellite; and determining the security algorithm corresponding to the second satellite as the first security algorithm.
[0014] In some implementations, determining the first security algorithm corresponding to the first satellite based on the identifier of the network element carried on the first satellite includes: determining that the network element carried on the first satellite belongs to a second group based on the identifier of the network element carried on the first satellite; and determining the security algorithm shared by the network elements in the second group as the first security algorithm, wherein the second group includes the network elements carried on the first satellite and the network elements carried on the second satellite.
[0015] In some implementations, the first security algorithm corresponding to the first satellite is determined based on the identifier of the network element carried on the first satellite, including: determining that the network element carried on the first satellite and the network element carried on the second satellite belong to the same group based on the identifier of the network element carried on the first satellite; and determining the security algorithm corresponding to the network element carried on the second satellite as the first security algorithm.
[0016] In some implementations, the first security algorithm corresponding to the first satellite is determined based on the identifier of the network element carried on the first satellite, including: determining that the identifier of the network element carried on the first satellite is the same as the identifier of the network element carried on the second satellite; and determining the security algorithm corresponding to the network element carried on the second satellite as the first security algorithm.
[0017] In some implementations, determining the first security algorithm corresponding to the first satellite based on the identifier of the network element carried on the first satellite includes: determining that the security algorithm list configured for the network element carried on the first satellite is the same as that configured for the network element carried on the second satellite, based on the identifier of the network element carried on the first satellite; and determining the security algorithm corresponding to the network element carried on the second satellite as the first security algorithm.
[0018] In some implementations, the first security algorithm is used to protect the communication security between the first satellite and the terminal device, including: using the first security algorithm to provide security protection for the first uplink non-access stratum (NAS) message sent by the terminal device to the first satellite.
[0019] Based on the above scheme, the terminal-side device can reuse the negotiated security algorithm, thus eliminating the need for a security negotiation process. Therefore, the terminal-side device can provide security protection for the first uplink NAS message, thereby improving security.
[0020] In some implementations, before using the first security algorithm to securely protect the first uplink NAS message sent by the terminal device to the first satellite, the method further includes enabling encryption and / or integrity protection for the NAS message.
[0021] In some implementations, the first uplink NAS message includes indication information for the first security algorithm.
[0022] In some implementations, the first security algorithm is used to provide security protection for the first uplink NAS message sent by the terminal device to the first satellite, including: using the first security algorithm to provide security protection for the first uplink NAS message sent by the terminal device to the Mobility Management Element (MME) carried on the first satellite.
[0023] In some implementations, the network elements carried on the first satellite include MME.
[0024] Secondly, a communication method is provided. The method provided in this application can be executed by a first satellite. Unless otherwise specified, the first satellite in this application can be the satellite itself, a component within the satellite (e.g., a processor, device, chip, or chip system), or a logic module or software capable of implementing all or part of the satellite's functions. For ease of description, the following description uses a first satellite as an example.
[0025] The method includes: receiving instruction information of a first security algorithm and the identifier of a terminal device from a ground network element, wherein the ground network element is a core network element located on the ground; and using the first security algorithm to protect the communication security between the first satellite and the terminal device.
[0026] Based on the above scheme, the first satellite can obtain the first security algorithm from the ground network element and use the first security algorithm to protect the communication security between the first satellite and the terminal-side equipment, thereby establishing a secure connection with the terminal-side equipment. Furthermore, the above scheme eliminates the need for NAS security negotiation between the first satellite and the terminal-side equipment, and eliminates the need to send and receive NAS security negotiation signaling, thus saving signaling overhead and latency in establishing a secure connection.
[0027] In some implementations, the first security algorithm is used to protect the communication security between the first satellite and the terminal-side device, including enabling the decryption and / or integrity verification of non-access stratum (NAS) messages.
[0028] In some implementations, after enabling NAS message decryption and / or integrity verification, the method further includes: receiving a first uplink NAS message from the terminal device; and decrypting and / or verifying the integrity of the first uplink NAS message.
[0029] In some implementations, the first uplink NAS message is decrypted and / or its integrity is verified, including: if the first uplink NAS message is not protected for integrity, and / or if the integrity verification of the first uplink NAS message fails, the first uplink NAS message is discarded.
[0030] In some implementations, before enabling encryption and / or integrity protection for non-access stratum (NAS) messages, the method further includes: determining a first NAS key based on the first security algorithm; or receiving relevant information about the first NAS key from the terrestrial network element; wherein the first NAS key is used to decrypt and / or verify the integrity of NAS messages.
[0031] For the beneficial effects of any aspect of the second aspect mentioned above, please refer to the first aspect and the beneficial effects of any implementation of the first aspect.
[0032] Thirdly, a communication method is provided. The subject executing the method provided in this application can be a terrestrial network element. Unless otherwise specified, the terrestrial network element in this application can be the device itself capable of implementing the terrestrial network element, a component within the device (e.g., a processor, apparatus, chip, or chip system), or a logic module or software capable of implementing all or part of the functions of the terrestrial network element. For ease of description, the following description uses a terrestrial network element as an example.
[0033] The method includes: obtaining a first security algorithm from a second satellite, wherein the first security algorithm is selected through negotiation between the terminal device and the second satellite; and sending indication information of the first security algorithm to a first satellite, wherein the first security algorithm is used to protect the communication security between the first satellite and the terminal device.
[0034] In some implementations, before sending the instruction information of the first security algorithm to the first satellite, the method further includes: determining the first satellite according to a satellite list, the satellite list being used to indicate the satellites that the terminal-side device will subsequently access.
[0035] In some implementations, determining the first satellite based on a satellite list includes: determining that both the first satellite and the second satellite in the satellite list are allowed to communicate with the terminal device using the same security algorithm.
[0036] In some implementations, the first satellite and the second satellite are configured with the same list of security algorithms, which is used to determine the security algorithm for the first satellite or the second satellite to communicate with the terminal.
[0037] For the beneficial effects of any aspect of the third aspect mentioned above, please refer to the first aspect and the beneficial effects of any implementation of the first aspect.
[0038] Fourthly, a communication method is provided. The method provided in this application can be executed by a first satellite. Unless otherwise specified, the first satellite in this application can be the satellite itself, a component within the satellite (e.g., a processor, device, chip, or chip system), or a logic module or software capable of implementing all or part of the satellite's functions. For ease of description, the following description uses a first satellite as an example.
[0039] The method includes: receiving indication information of a first security algorithm from a terminal-side device; and using the first security algorithm to protect the communication security between the first satellite and the terminal-side device.
[0040] In some implementations, the indication information of the first security algorithm is carried in the first non-access stratum (NAS) message sent by the terminal device to the first satellite.
[0041] In some implementations, the indication information of the first security algorithm is carried in the random access message sent by the terminal device to the first satellite.
[0042] In some implementations, the first security algorithm is used to protect the communication security between the first satellite and the terminal device, including enabling NAS message decryption and / or integrity verification.
[0043] In some implementations, after enabling the decryption and / or integrity verification of NAS messages, the method further includes: receiving a first uplink NAS message from the terminal device; and decrypting and / or verifying the integrity of the first uplink NAS message.
[0044] In some implementations, the first uplink NAS message is decrypted and / or its integrity is verified, including: if the first uplink NAS message is not protected for integrity, and / or if the integrity verification of the first uplink NAS message fails, the first uplink NAS message is discarded.
[0045] Fifthly, a communication method is provided. The method provided in this application can be executed by a terminal-side device. Unless otherwise specified, the terminal-side device in this application can be a terminal device, a component within a terminal device (e.g., a processor, apparatus, chip, or chip system), or a logic module or software capable of implementing all or part of the functions of the terminal device. For ease of description, the following description uses a terminal-side device as an example.
[0046] The method includes: receiving a broadcast message from a third satellite, the broadcast message including an identifier of the third satellite; determining a second security algorithm based on the identifier of the third satellite and a first mapping relationship, wherein the first mapping relationship includes a mapping relationship between at least one satellite and at least one security algorithm, the at least one satellite including the third satellite, the at least one security algorithm including the second security algorithm, and the second security algorithm corresponding to the third satellite; and using the second security algorithm to protect the communication security between the third satellite and the terminal-side device.
[0047] In some implementations, the method further includes receiving indication information of the first mapping relationship from a fourth satellite before receiving the broadcast message from the third satellite.
[0048] In some implementations, the second security algorithm is used to protect the communication security between the third satellite and the terminal device, including: using the first security algorithm to provide security protection for the first uplink non-access stratum (NAS) message sent by the terminal device to the third satellite.
[0049] In some implementations, before using the first security algorithm to securely protect the first uplink NAS message sent by the terminal device to the first satellite, the method further includes enabling encryption and / or integrity protection for the NAS message.
[0050] In some implementations, the first security algorithm is used to provide security protection for the first uplink non-access stratum (NAS) message sent by the terminal device to the third satellite, including: using the first security algorithm to provide security protection for the first uplink NAS message sent by the terminal device to the mobility management network element (MME) carried on the third satellite.
[0051] Sixthly, a communication method is provided. The execution entity of the method provided in the sixth aspect can be a terrestrial network element. Unless otherwise specified, the terrestrial network element in this application can be the device itself capable of implementing the terrestrial network element, a component within the device (e.g., a processor, apparatus, chip, or chip system), or a logic module or software capable of implementing all or part of the functions of the terrestrial network element. For ease of description, the following description uses a terrestrial network element as an example.
[0052] The method includes: obtaining a first mapping relationship, the first mapping relationship including a mapping relationship between at least one satellite and at least one security algorithm; sending first information to a fourth satellite, the first information being used to instruct the fourth satellite to send indication information of the first mapping relationship to a terminal-side device, the at least one security algorithm being used to protect the communication security between the at least one satellite and the terminal-side device.
[0053] In some implementations, obtaining the first mapping relationship includes: determining the at least one security algorithm based on the security capability information of the terminal-side device and the security algorithm list of the at least one satellite.
[0054] In some implementations, before sending the first information to the fourth satellite, the method further includes: determining the fourth satellite based on a satellite list, which indicates the satellites that the terminal device will subsequently access.
[0055] In some implementations, the method further includes sending instruction information of the second security algorithm to a third satellite, the second security algorithm being used to protect the communication security between the third satellite and the terminal-side device.
[0056] In some implementations, before sending the instruction information for the second security algorithm to the third satellite, the method further includes: determining the third satellite based on a satellite list, which indicates the satellites that the terminal device will subsequently access.
[0057] In a seventh aspect, a communication method is provided. The method provided in the seventh aspect can be implemented by a third satellite. Unless otherwise specified, the third satellite in this application can be the satellite itself, a component within the satellite (e.g., a processor, device, chip, or chip system), or a logic module or software capable of implementing all or part of the satellite's functions. For ease of description, the following description uses a third satellite as an example.
[0058] The method includes: receiving instruction information of a second security algorithm and the identifier of a terminal device from a ground network element, wherein the ground network element is a core network element located on the ground; and using the second security algorithm to protect the communication security between the third satellite and the terminal device.
[0059] In some implementations, the second security algorithm is used to protect the communication security between the third satellite and the terminal device, including enabling decryption and / or integrity verification of non-access stratum (NAS) messages.
[0060] In some implementations, after enabling NAS message decryption and / or integrity verification, the method further includes: receiving a first uplink NAS message from the terminal device; and decrypting and / or verifying the integrity of the first uplink NAS message.
[0061] In some implementations, the first uplink NAS message is decrypted and / or its integrity is verified, including: if the first uplink NAS message is not protected for integrity, and / or if the integrity verification of the first uplink NAS message fails, the first uplink NAS message is discarded.
[0062] In some implementations, before enabling encryption and / or integrity protection for non-access stratum (NAS) messages, the method further includes: determining a second NAS key based on the second security algorithm; or receiving information related to the second NAS key from the terrestrial network element; wherein the second NAS key is used to decrypt and / or verify the integrity of NAS messages.
[0063] Eighthly, a communication method is provided. The method provided in this application can be executed by a fifth satellite. Unless otherwise specified, the fifth satellite in this application can be the satellite itself, a component within the satellite (e.g., a processor, device, chip, or chip system), or a logic module or software capable of implementing all or part of the satellite's functions. For ease of description, the following description uses a fifth satellite as an example.
[0064] The method includes: sending an indication of a third security algorithm to the terminal device before receiving the first non-access stratum (NAS) message from the terminal device; using the third security algorithm to protect the communication security between the fifth satellite and the terminal device; wherein the third security algorithm is negotiated and selected between the ground network element and the third satellite.
[0065] Based on the above scheme, the fifth satellite can negotiate and determine the security algorithm with ground network elements and instruct the terminal-side device to implement the security algorithm, thereby enabling a secure connection between the satellite and the terminal-side device. Furthermore, this scheme eliminates the need for the terminal-side device to perform NAS security negotiation with the fifth satellite, and avoids sending and receiving NAS security negotiation signaling, thus saving signaling overhead and latency in establishing a secure connection.
[0066] In some implementations, the method further includes: receiving security capability information of the terminal-side device from the ground network element; and determining a third security algorithm based on the security capability information of the terminal-side device.
[0067] In some implementations, before using the third security algorithm to protect the communication security between the fifth satellite and the terminal device, the method further includes: receiving a first random access message from the terminal device, the first random access message including the identifier of the terminal device; and determining the third security algorithm corresponding to the identifier of the terminal device.
[0068] In some implementations, the indication information of the third security algorithm is carried in the second random access message.
[0069] In some implementations, the third security algorithm is used to protect the communication security between the fifth satellite and the terminal device, including enabling decryption and / or integrity verification of non-access stratum (NAS) messages.
[0070] In some implementations, after enabling NAS message decryption and / or integrity verification, the method further includes: receiving a first uplink NAS message from the terminal device; and decrypting and / or verifying the integrity of the first uplink NAS message.
[0071] In some implementations, the first uplink NAS message is decrypted and / or its integrity is verified, including: if the first uplink NAS message is not protected for integrity, and / or if the integrity verification of the first uplink NAS message fails, the first uplink NAS message is discarded.
[0072] In a ninth aspect, a communication method is provided. The subject executing the method provided in the ninth aspect can be a terrestrial network element. Unless otherwise specified, the terrestrial network element in this application can be the device itself capable of implementing the terrestrial network element, a component within the device (e.g., a processor, apparatus, chip, or chip system), or a logic module or software capable of implementing all or part of the functions of the terrestrial network element. For ease of description, the following description uses a terrestrial network element as an example.
[0073] The method includes: acquiring security capability information of a terminal-side device; and sending the security capability information of the terminal-side device to a fifth satellite, wherein the security capability information of the terminal-side device is used to determine a security algorithm for protecting the communication between the fifth satellite and the terminal-side device.
[0074] In some implementations, before sending the security capability information of the terminal device to the fifth satellite, the method further includes: determining the fifth satellite based on a satellite list, which indicates the satellites that the terminal device will subsequently access.
[0075] In a tenth aspect, a communication method is provided. The method provided in the tenth aspect can be executed by a terminal-side device. Unless otherwise specified, the terminal-side device in this application can be a terminal device, a component within a terminal device (e.g., a processor, apparatus, chip, or chip system), or a logic module or software capable of implementing all or part of the functions of the terminal device. For ease of description, the following description uses a terminal-side device as an example.
[0076] The method includes: receiving indication information of the third security algorithm from the fifth satellite before sending the first non-access stratum NAS message; and using the third security algorithm to protect the communication security between the fifth satellite and the third terminal-side device.
[0077] In some implementations, the indication information of the third security algorithm is carried in the second random access message.
[0078] In some implementations, the third security algorithm is used to protect the communication security between the fifth satellite and the terminal device, including: using the third security algorithm to provide security protection for the first uplink non-access stratum (NAS) message sent by the terminal device to the fifth satellite.
[0079] In some implementations, before using the third security algorithm to secure the first uplink NAS message sent by the terminal device to the fifth satellite, the method further includes enabling encryption and / or integrity protection for the NAS message.
[0080] In some implementations, the third security algorithm is used to provide security protection for the first uplink non-access stratum (NAS) message sent by the terminal device to the fifth satellite. This includes using the third security algorithm to provide security protection for the first uplink NAS message sent by the terminal device to the mobility management network element (MME) carried on the fifth satellite.
[0081] Eleventhly, a communication device is provided, comprising a processing circuit (or processor) and an input / output interface (also referred to as an interface circuit), the input / output interface being used for inputting and / or outputting signals, the processing circuit being used to perform the first aspect and any possible method of the first aspect, or the processing circuit being used to perform the second aspect and any possible method of the second aspect, or the processing circuit being used to perform the third aspect and any possible method of the third aspect, or the processing circuit being used to perform the fourth aspect and any possible method of the fourth aspect, or the processing circuit being used to perform the fifth aspect and any possible method of the fifth aspect, or the processing circuit being used to perform the sixth aspect and any possible method of the sixth aspect, or the processing circuit being used to perform the seventh aspect and any possible method of the seventh aspect, or the processing circuit being used to perform the eighth aspect and any possible method of the eighth aspect, or the processing circuit being used to perform the ninth aspect and any possible method of the ninth aspect, or the processing circuit being used to perform the tenth aspect and any possible method of the tenth aspect.
[0082] In some implementations, the processing circuit is used to communicate with other devices through the interface circuit and to perform the first aspect and any possible method of the first aspect, or to perform the second aspect and any possible method of the second aspect, or to perform the third aspect and any possible method of the third aspect, or to perform the fourth aspect and any possible method of the fourth aspect, or to perform the fifth aspect and any possible method of the fifth aspect, or to perform the sixth aspect and any possible method of the sixth aspect, or to perform the seventh aspect and any possible method of the seventh aspect, or to perform the eighth aspect and any possible method of the eighth aspect, or to perform the ninth aspect and any possible method of the ninth aspect, or to perform the tenth aspect and any possible method of the tenth aspect.
[0083] In a twelfth aspect, a communication device is provided. This communication device may include units or modules for performing the functions of the communication device.
[0084] In some implementations, the communication device may include modules, units, or means for performing the methods / operations / steps / actions described in the first aspect and any possible implementation of the first aspect. These modules, units, or means may be hardware circuits, software, or a combination of hardware circuits and software.
[0085] The device includes a processing unit and a transceiver unit. The transceiver unit is used to receive broadcast messages from a first satellite; the processing unit is used to determine a first security algorithm corresponding to the first satellite based on the broadcast message; the processing unit is also used to use the first security algorithm to protect the communication security between the first satellite and the terminal device; wherein, the first security algorithm is negotiated and selected by the terminal device with a second satellite before receiving the broadcast message from the first satellite.
[0086] In some implementations, the first satellite and the second satellite are configured with the same list of security algorithms, and the first security algorithm is determined based on the list of security algorithms and the security capability information of the terminal-side device.
[0087] In some implementations, the broadcast message includes an identifier corresponding to the first satellite or an identifier corresponding to a network element carried on the first satellite. Specifically, the processing unit is used to: determine the first security algorithm corresponding to the first satellite based on the identifier corresponding to the first satellite; or, determine the first security algorithm corresponding to the first satellite based on the identifier corresponding to the network element carried on the first satellite.
[0088] In some implementations, the processing unit is specifically used to: determine that the first satellite belongs to a first group based on the identifier corresponding to the first satellite; and determine the security algorithm shared by the satellites in the first group as the first security algorithm, wherein the first group includes the first satellite and the second satellite.
[0089] In some implementations, the processing unit is specifically used to: determine, based on the identifier of the first satellite, that the first satellite and the second satellite belong to the same group; and determine the security algorithm corresponding to the second satellite as the first security algorithm.
[0090] In some implementations, the processing unit is specifically used to: determine, based on the identifier of the first satellite, that the security algorithm list configured for the first satellite and the second satellite are the same; and determine the security algorithm corresponding to the second satellite as the first security algorithm.
[0091] In some implementations, the processing unit is specifically used to: determine, based on the identifier corresponding to the network element carried on the first satellite, that the network element carried on the first satellite belongs to a second group; and determine the security algorithm shared by the network elements in the second group as the first security algorithm, wherein the second group includes the network elements carried on the first satellite and the network elements carried on the second satellite.
[0092] In some implementations, the processing unit is specifically used to: determine, based on the identifier of the network element carried on the first satellite, that the network element carried on the first satellite and the network element carried on the second satellite belong to the same group; and determine the security algorithm corresponding to the network element carried on the second satellite as the first security algorithm.
[0093] In some implementations, the processing unit is specifically used to: determine that the identifier of the network element carried on the first satellite is the same as the identifier of the network element carried on the second satellite; and determine the security algorithm corresponding to the network element carried on the second satellite as the first security algorithm.
[0094] In some implementations, the processing unit is specifically used to: determine, based on the identifier corresponding to the network element carried on the first satellite, that the security algorithm list configured for the network element carried on the first satellite is the same as that configured for the network element carried on the second satellite; and determine the security algorithm corresponding to the network element carried on the second satellite as the first security algorithm.
[0095] In some implementations, the processing unit is specifically used to: use the first security algorithm to provide security protection for the first uplink non-access stratum (NAS) message sent by the terminal device to the first satellite.
[0096] In some implementations, the processing unit is also used to enable encryption and / or integrity protection for NAS messages.
[0097] In some implementations, the first uplink NAS message includes indication information for the first security algorithm.
[0098] In some implementations, the processing unit is specifically used to: use the first security algorithm to provide security protection for the first uplink NAS message sent by the terminal device to the Mobility Management Element (MME) carried on the first satellite.
[0099] In some implementations, the network elements carried on the first satellite include MME.
[0100] In some implementations, the communication device may include modules, units, or means for performing the methods / operations / steps / actions described in the second aspect and any possible implementation of the second aspect. These modules, units, or means may be hardware circuits, software, or a combination of hardware circuits and software implementations.
[0101] The device includes a processing unit and a transceiver unit. The transceiver unit is used to receive instruction information of the first security algorithm and the identifier of the terminal device from a ground network element, which is a core network element located on the ground; the processing unit is used to use the first security algorithm to protect the communication security between the first satellite and the terminal device.
[0102] In some implementations, the processing unit is specifically used to: enable decryption and / or integrity verification of non-access stratum NAS messages.
[0103] In some implementations, the transceiver unit is also used to: receive the first uplink NAS message from the terminal device; the processing unit is also used to decrypt and / or verify the integrity of the first uplink NAS message.
[0104] In some implementations, the processing unit is specifically used to: discard the first uplink NAS message if the first uplink NAS message is not protected for integrity, and / or if the integrity verification of the first uplink NAS message fails.
[0105] In some implementations, the processing unit is further configured to: determine a first NAS key based on the first security algorithm; or, the transceiver unit is further configured to receive information related to the first NAS key from the ground network element; wherein the first NAS key is used to decrypt and / or verify the integrity of NAS messages.
[0106] In some implementations, the communication device may include modules, units, or means for performing the methods / operations / steps / actions described in the third aspect and any possible implementation of the third aspect. These modules, units, or means may be hardware circuits, software, or a combination of hardware circuits and software.
[0107] The device includes a transceiver unit. The transceiver unit is used to obtain a first security algorithm from a second satellite, wherein the first security algorithm is selected through negotiation between the terminal device and the second satellite; the transceiver unit is also used to send indication information of the first security algorithm to a first satellite, wherein the first security algorithm is used to protect the communication security between the first satellite and the terminal device.
[0108] In some implementations, the device further includes a processing unit. This processing unit is used to: determine the first satellite based on a satellite list, which indicates the satellites that the terminal device will subsequently access.
[0109] In some implementations, the processing unit is specifically used to: determine that both the first satellite and the second satellite in the satellite list are allowed to communicate with the terminal device using the same security algorithm.
[0110] In some implementations, the first satellite and the second satellite are configured with the same list of security algorithms, which is used to determine the security algorithm for the first satellite or the second satellite to communicate with the terminal.
[0111] In some implementations, the communication device may include modules, units, or means for performing the methods / operations / steps / actions described in the fourth aspect and any possible implementation of the fourth aspect. These modules, units, or means may be hardware circuits, software, or a combination of hardware circuits and software.
[0112] The device includes a processing unit and a transceiver unit. The transceiver unit is used to receive instruction information of a first security algorithm from the terminal-side device; the processing unit is used to use the first security algorithm to protect the communication security between the first satellite and the terminal-side device.
[0113] In some implementations, the indication information of the first security algorithm is carried in the first non-access stratum (NAS) message sent by the terminal device to the first satellite.
[0114] In some implementations, the indication information of the first security algorithm is carried in the random access message sent by the terminal device to the first satellite.
[0115] In some implementations, the processing unit is specifically used to: enable NAS message decryption and / or integrity verification.
[0116] In some implementations, the transceiver unit is also used to: receive the first uplink NAS message from the terminal device; the processing unit is also used to decrypt and / or verify the integrity of the first uplink NAS message.
[0117] In some implementations, the processing unit is specifically used to: discard the first uplink NAS message if the first uplink NAS message is not protected for integrity, and / or if the integrity verification of the first uplink NAS message fails.
[0118] In some implementations, the communication device may include modules, units, or means for performing the methods / operations / steps / actions described in the fifth aspect and any possible implementation of the fifth aspect. These modules, units, or means may be hardware circuits, software, or a combination of hardware circuits and software.
[0119] The device includes a processing unit and a transceiver unit. The transceiver unit is used to receive broadcast messages from a third satellite, the broadcast messages including the identifier of the third satellite; the processing unit is used to determine a second security algorithm based on the identifier of the third satellite and a first mapping relationship, wherein the first mapping relationship includes a mapping relationship between at least one satellite and at least one security algorithm, the at least one satellite including the third satellite, the at least one security algorithm including the second security algorithm, and the second security algorithm corresponding to the third satellite; the processing unit is also used to use the second security algorithm to protect the communication security between the third satellite and the terminal-side device.
[0120] In some implementations, the transceiver unit is also used to receive indication information of the first mapping relationship from the fourth satellite.
[0121] In some implementations, the processing unit is specifically used to: use the first security algorithm to provide security protection for the first uplink non-access stratum (NAS) message sent by the terminal device to the third satellite.
[0122] In some implementations, the processing unit is also used to enable encryption and / or integrity protection for NAS messages.
[0123] In some implementations, the processing unit is specifically used to: use the first security algorithm to provide security protection for the first uplink non-access stratum (NAS) message sent by the terminal device to the mobility management network element (MME) carried on the third satellite.
[0124] In some implementations, the communication device may include modules, units, or means for performing the methods / operations / steps / actions described in the sixth aspect and any possible implementation of the sixth aspect, which may be hardware circuits, software, or a combination of hardware circuits and software.
[0125] The device includes a processing unit and a transceiver unit. The processing unit is used to obtain a first mapping relationship, which includes a mapping relationship between at least one satellite and at least one security algorithm; the transceiver unit is used to send first information to a fourth satellite, which instructs the fourth satellite to send indication information of the first mapping relationship to a terminal device, and the at least one security algorithm is used to protect the communication security between the at least one satellite and the terminal device.
[0126] In some implementations, the processing unit is specifically used to: determine the at least one security algorithm based on the security capability information of the terminal-side device and the security algorithm list of the at least one satellite.
[0127] In some implementations, the processing unit is also used to: determine the fourth satellite based on a satellite list, which indicates the satellites that the terminal device will subsequently access.
[0128] In some implementations, the transceiver unit is also used to: send indication information of the second security algorithm to the third satellite, the second security algorithm being used to protect the communication security between the third satellite and the terminal-side device.
[0129] In some implementations, the processing unit is also used to: determine the third satellite based on a satellite list, which indicates the satellites that the terminal device will subsequently access.
[0130] In some implementations, the communication device may include modules, units, or means for performing the methods / operations / steps / actions described in the seventh aspect and any possible implementation of the seventh aspect. These modules, units, or means may be hardware circuits, software, or a combination of hardware circuits and software.
[0131] The device includes a processing unit and a transceiver unit. The transceiver unit is used to receive instruction information of the second security algorithm and the identifier of the terminal device from a ground network element, which is a core network element located on the ground; the processing unit is used to use the second security algorithm to protect the communication security between the third satellite and the terminal device.
[0132] In some implementations, the processing unit is specifically used to: enable decryption and / or integrity verification of non-access stratum NAS messages.
[0133] In some implementations, the transceiver unit is also used to: receive the first uplink NAS message from the terminal device; the processing unit is also used to decrypt and / or verify the integrity of the first uplink NAS message.
[0134] In some implementations, the processing unit is specifically used to: discard the first uplink NAS message if the first uplink NAS message is not protected for integrity, and / or if the integrity verification of the first uplink NAS message fails.
[0135] In some implementations, the processing unit is further configured to: determine a second NAS key based on the second security algorithm; or, the transceiver unit is further configured to receive information related to the second NAS key from the ground network element; wherein the second NAS key is used to decrypt and / or verify the integrity of NAS messages.
[0136] In some implementations, the communication device may include modules, units, or means for performing the methods / operations / steps / actions described in the eighth aspect and any possible implementation of the eighth aspect, which may be hardware circuits, software, or a combination of hardware circuits and software implementations.
[0137] The device includes a processing unit and a transceiver unit. Before receiving the first Non-Access Stratum (NAS) message from the terminal device, the transceiver unit sends an indication of a third security algorithm to the terminal device; the processing unit uses the third security algorithm to protect the communication security between the fifth satellite and the terminal device; wherein, the third security algorithm is negotiated and selected between the ground network element and the third satellite.
[0138] In some implementations, the transceiver unit is also used to: receive security capability information of the terminal-side device from the ground network element; the processing unit is also used to determine a third security algorithm based on the security capability information of the terminal-side device.
[0139] In some implementations, the transceiver unit is further configured to: receive a first random access message from the terminal-side device, the first random access message including the identifier of the terminal-side device; the processing unit is further configured to determine the third security algorithm corresponding to the identifier of the terminal-side device.
[0140] In some implementations, the indication information of the third security algorithm is carried in the second random access message.
[0141] In some implementations, the processing unit is specifically used to: enable decryption and / or integrity verification of non-access stratum NAS messages.
[0142] In some implementations, the transceiver unit is also used to receive the first uplink NAS message from the terminal device; the processing unit is also used to decrypt and / or verify the integrity of the first uplink NAS message.
[0143] In some implementations, the processing unit is specifically used to: discard the first uplink NAS message if the first uplink NAS message is not protected for integrity, and / or if the integrity verification of the first uplink NAS message fails.
[0144] In some implementations, the communication device may include modules, units, or means for performing the methods / operations / steps / actions described in the ninth aspect and any possible implementation of the ninth aspect, which may be hardware circuits, software, or a combination of hardware circuits and software.
[0145] The device includes a transceiver unit. The transceiver unit is used to acquire security capability information of the terminal-side device; the transceiver unit is also used to transmit the security capability information of the terminal-side device to the fifth satellite, and the security capability information of the terminal-side device is used to determine a security algorithm to protect the communication between the fifth satellite and the terminal-side device.
[0146] In some implementations, the device further includes a processing unit for determining the fifth satellite based on a satellite list, the satellite list indicating the satellites that the terminal device will subsequently access.
[0147] In some implementations, the communication device may include modules, units, or means for performing the methods / operations / steps / actions described in the tenth aspect and any possible implementation of the tenth aspect, which may be hardware circuits, software, or a combination of hardware circuits and software.
[0148] The device includes a transceiver unit and a processing unit. Before sending the first Non-Access Stratum (NAS) message, the transceiver unit receives indication information of the third security algorithm from the fifth satellite; the processing unit uses the third security algorithm to protect the communication security between the fifth satellite and the third terminal device.
[0149] In some implementations, the indication information of the third security algorithm is carried in the second random access message.
[0150] In some implementations, the processing unit is specifically used to: use the third security algorithm to provide security protection for the first uplink non-access stratum (NAS) message sent by the terminal device to the fifth satellite.
[0151] In some implementations, the processing unit is also used to enable encryption and / or integrity protection for NAS messages.
[0152] In some implementations, the processing unit is specifically used to: use the third security algorithm to provide security protection for the first uplink non-access stratum (NAS) message sent by the terminal device to the mobility management network element (MME) carried on the fifth satellite.
[0153] In a thirteenth aspect, a computer-readable storage medium is provided, on which a computer program or instructions are stored, which, when executed, cause the first aspect and any possible method of the first aspect to be performed (or implemented), or cause the second aspect and any possible method of the second aspect to be performed (or implemented), or cause the third aspect and any possible method of the third aspect to be performed (or implemented), or cause the fourth aspect and any possible method of the fourth aspect to be performed (or implemented), or cause the fifth aspect and any possible method of the fifth aspect to be performed (or implemented), or cause the sixth aspect and any possible method of the sixth aspect to be performed (or implemented), or cause the seventh aspect and any possible method of the seventh aspect to be performed (or implemented), or cause the eighth aspect and any possible method of the eighth aspect to be performed (or implemented), or cause the ninth aspect and any possible method of the ninth aspect to be performed (or implemented), or cause the tenth aspect and any possible method of the tenth aspect to be performed (or implemented).
[0154] In a fourteenth aspect, a computer program product is provided, comprising a computer program or instructions that, when executed, cause the first aspect and any possible method of the first aspect to be performed (or implemented), or cause the second aspect and any possible method of the second aspect to be performed (or implemented), or cause the third aspect and any possible method of the third aspect to be performed (or implemented), or cause the fourth aspect and any possible method of the fourth aspect to be performed (or implemented), or cause the fifth aspect and any possible method of the fifth aspect to be performed (or implemented), or cause the sixth aspect and any possible method of the sixth aspect to be performed (or implemented), or cause the seventh aspect and any possible method of the seventh aspect to be performed (or implemented), or cause the eighth aspect and any possible method of the eighth aspect to be performed (or implemented), or cause the ninth aspect and any possible method of the ninth aspect to be performed (or implemented), or cause the tenth aspect and any possible method of the tenth aspect to be performed (or implemented).
[0155] In a fifteenth aspect, a communication apparatus is provided, comprising a processor configured to execute (or implement) any of the possible methods of the first aspect, or any of the possible methods of the second aspect, or any of the possible methods of the third aspect, or any of the possible methods of the fourth aspect, or any of the possible methods of the fifth aspect, or any of the possible methods of the sixth aspect, or any of the possible methods of the seventh aspect, or any of the possible methods of the eighth aspect, or any of the possible methods of the ninth aspect, or any of the possible methods of the tenth aspect by executing a computer program (or computer-executable instructions) stored in a memory, and / or by logic circuitry.
[0156] In one possible implementation, the device also includes a memory. In another possible implementation, the processor and memory are integrated together. In yet another possible implementation, the memory is located outside the communication device. The processor may include one or more processors.
[0157] In one possible implementation, the communication device further includes a communication interface for communicating with other devices, such as transmitting or receiving data and / or signals. Exemplarily, the communication interface may be a transceiver, circuit, bus, module, or other type of communication interface.
[0158] In one implementation, the communication device described in the eleventh, twelfth, or fifteenth aspect above may be a chip or a chip system.
[0159] In a sixteenth aspect, a chip is provided, including a processor for calling a computer program or computer instructions in a memory to execute (or implement) any of the implementations of the first aspect, or to execute (or implement) any of the implementations of the second aspect, or to execute (or implement) any of the implementations of the third aspect, or to execute (or implement) any of the implementations of the fourth aspect, or to execute (or implement) any of the implementations of the fifth aspect, or to execute (or implement) any of the implementations of the sixth aspect, or to execute (or implement) any of the implementations of the seventh aspect, or to execute (or implement) any of the implementations of the eighth aspect, or to execute (or implement) any of the implementations of the ninth aspect, or to execute (or implement) any of the implementations of the tenth aspect.
[0160] In some implementations, the processor is coupled to the memory via an interface.
[0161] In a seventeenth aspect, a communication system is provided, comprising a first satellite, a ground network element, and a terminal-side device, wherein the terminal-side device is configured to perform the first aspect and any possible implementation thereof, the first satellite is configured to perform the second aspect and any possible implementation thereof, and the ground network element is configured to perform the third aspect and any possible implementation thereof.
[0162] Alternatively, the communication system may include a first satellite and a terminal-side device, the terminal-side device being used to perform the first aspect described above and any possible implementation thereof, and the first satellite being used to perform the fourth aspect described above and any possible implementation thereof.
[0163] Alternatively, the communication system may include terminal-side equipment, ground network elements, and a third satellite. The terminal-side equipment is used to perform the fifth aspect and any possible implementation thereof, the ground network elements are used to perform the sixth aspect and any possible implementation thereof, and the third satellite is used to perform the seventh aspect and any possible implementation thereof.
[0164] Alternatively, the communication system may include a fifth satellite, ground network elements, and terminal-side equipment. The fifth satellite is used to perform the eighth aspect and any possible implementation thereof, the ground network elements are used to perform the ninth aspect and any possible implementation thereof, and the terminal-side equipment is used to perform the tenth aspect and any possible implementation thereof.
[0165] The description of the beneficial effects of any one of the eleventh to seventeenth aspects can be found in the description of the beneficial effects of the first to tenth aspects and any implementation method. Attached Figure Description
[0166] Figure 1 is a schematic diagram of a communication system.
[0167] Figure 2 is a schematic flowchart of a non-access stratum (NAS) security negotiation method.
[0168] Figure 3 is a schematic diagram of another communication system.
[0169] Figure 4 is a schematic flowchart of a communication method provided in an embodiment of this application.
[0170] Figure 5 is a schematic flowchart of another communication method provided in an embodiment of this application.
[0171] Figure 6 is a schematic flowchart of a communication method provided in an embodiment of this application.
[0172] Figure 7 is a schematic flowchart of another communication method provided in an embodiment of this application.
[0173] Figure 8 is a schematic flowchart of a communication method provided in an embodiment of this application.
[0174] Figure 9 is a schematic flowchart of another communication method provided in an embodiment of this application.
[0175] Figure 10 is a schematic flowchart of a communication method provided in an embodiment of this application.
[0176] Figure 11 is a schematic flowchart of another communication method provided in an embodiment of this application.
[0177] Figure 12 is a schematic block diagram of a communication device according to an embodiment of this application.
[0178] Figure 13 is a schematic block diagram of another communication device according to an embodiment of this application.
[0179] Figure 14 is an exemplary block diagram of another communication device provided in an embodiment of this application.
[0180] Figure 15 is a schematic block diagram of another communication device provided in an embodiment of this application. Detailed Implementation
[0181] In this application, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of different embodiments are consistent and can be referenced by each other. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.
[0182] I. In this application, "at least one" means one or more, and "more than one" means two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, or B exists alone, where A and B can be singular or plural. In the textual description of this application, the character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, and c can mean: a, or, b, or, c, or, a and b, or, a and c, or, b and c, or, a, b, and c. Here, a, b, and c can each be single or multiple.
[0183] II. In this application, the terms "first," "second," and various numerical designations (e.g., #1, #2, etc.) indicate distinctions made for ease of description and are not intended to limit the scope of the embodiments of this application. For example, they may distinguish different messages, rather than describing a specific order or sequence. It should be understood that such descriptions can be interchanged where appropriate to describe solutions other than those in the embodiments of this application.
[0184] Third, in this application, descriptions such as "when," "under the circumstances," and "if" all refer to the device making corresponding processing under certain objective circumstances, and are not time-limited, nor do they require the device to make a judgment action when implementing it, nor do they imply any other limitations.
[0185] IV. In this application, "instruction" or "for instruction" can include both direct (or explicit) and indirect (or implicit) instruction. When describing instruction information as indicating A, it can include whether the instruction information directly or indirectly indicates A, but does not necessarily mean that the instruction information carries A. For example, in the case of indirect (or implicit) instruction, the receiving end of the instruction information can obtain A based on the parameters indicated by the instruction information, combined with other rules or parameters, or through deduction.
[0186] V. The indication methods involved in the embodiments of this application should be understood to cover various methods that enable the party to be indicated to obtain the information to be indicated. The information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately. Moreover, the sending period and / or sending time of these sub-information can be the same or different. This application does not limit the sending method, for example.
[0187] VI. In this application, "protocol" can refer to standard protocols in the field of communications, such as 5G protocols, new radio (NR) protocols, and related protocols applied to future communication systems; this application does not limit this term. "Predefined" can include predefined terms, such as protocol definitions. "Preconfiguration" can be implemented by pre-storing corresponding codes, tables, or other means that can be used to indicate relevant information in the device; this application does not limit the implementation method.
[0188] VII. In this application, "communication" can also be described as "data transmission," "information transmission," "data processing," etc. "Transmission" includes "sending" and "receiving." For example, transmission can be uplink transmission, such as a terminal device sending a signal to a network device; transmission can also be downlink transmission, such as a network device sending a signal to a terminal device; transmission can also be sidelink transmission, such as a terminal device sending a signal to another terminal device. For example, "transmission" can be air interface level transmission, or it can be signal transmission from a chip input (I) / output (O) port, rather than air interface level transmission.
[0189] 8. In this application, terms such as “message,” “information,” “signal,” or “information element (IE)” can be used interchangeably. There are no restrictions on the name of the message or information, as long as it can achieve the corresponding function.
[0190] 9. "Sending information to XX (device)" can be understood as the destination of the information being that device. This can include sending information directly or indirectly to that device. "Receiving information from XX (device), or receiving information from XX (device)" can be understood as the source of the information being that device. This can include receiving information directly or indirectly from that device. Information may undergo necessary processing between the source and destination, such as format changes, but the destination can understand the valid information from the source. Similar expressions in this application can be understood in a similar way, and will not be repeated here. Furthermore, "sending" can also be understood as the "output" of the chip interface, and "receiving" can also be understood as the "input" of the chip interface. In other words, "sending" or "receiving" can occur between devices, for example, between network devices and terminal devices via an air interface. "Sending" or "receiving" can also occur within a device, for example, between components, modules, chips, software modules, or hardware modules within the device via a bus, wiring, or interface.
[0191] 10. In this application, terms such as "exemplarily" and "for example" are used to indicate examples, illustrations, or descriptions to present concepts in a specific manner. Any embodiment or design described as an "example" in this application should not be construed as being more preferred or advantageous than other embodiments or designs. In the embodiments of this application, the terms "of," "corresponding (relevant)," "corresponding," and "associate" may sometimes be used interchangeably, and it should be noted that their intended meanings are consistent unless their distinctions are emphasized.
[0192] XI. In this application, configuration can be signaling configuration or can be described as configuring signaling. For example, signaling configuration includes configuration using signaling sent by network devices, which can be radio resource control (RRC) messages, downlink control information (DCI) messages, or system information blocks (SIBs). Another example is signaling configuration between network devices. These network devices can include access network devices, core network devices, or management plane devices, etc. Optionally, signaling configuration can also be configured to terminal devices or network devices using pre-configured signaling, or configured to terminal devices or network devices through pre-configuration. Here, pre-configuration means defining or configuring the values of corresponding parameters in advance using a protocol, and storing them in the terminal device or network device during communication. Pre-configured messages can be modified or updated when the terminal device or network device is connected to the network.
[0193] 12. This application will present various aspects, embodiments, or features relating to systems that may include multiple devices, components, modules, etc. Each system may include devices, components, modules, etc., other than those illustrated, and / or may not include all and all of the devices, components, modules, etc. discussed in conjunction with the accompanying drawings.
[0194] Thirteen, the business scenarios described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.
[0195] XIV. In the various embodiments of this application, the sequence number of each process does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application. The terms "comprising," "including," "having," and their variations all mean "including but not limited to," unless otherwise specifically emphasized.
[0196] The technical solutions of this application embodiment can be applied to various communication systems, including but not limited to: Long Term Evolution (LTE) systems, NR systems, and other fifth-generation (5G) communication systems. th This includes various mobile communication systems such as 5G, narrowband Internet of Things (NB-IoT), enhanced machine-type communication (eMTC), enhanced mobile broadband (eMBB), ultra-reliable low-latency communications (URLLC), satellite communication systems, LTE-machine-to-machine (LTE-M) systems, and other systems that evolve after 5G, such as future mobile communication systems.
[0197] For example, satellite communication systems can include high altitude platform station (HAPS) communication or NTN systems such as unmanned aerial vehicles (UAVs). As another example, satellite communication systems can include integrated communication and navigation (ICAN) systems, global navigation satellite systems (GNSS), or ultra-dense low-Earth orbit (LEO) satellite communication systems.
[0198] The embodiments of this application are described below with reference to the accompanying drawings.
[0199] Figure 1 is a schematic diagram of a communication system 100. As shown in Figure 1, the communication system 100 includes a wireless access network 110 and a core network 120. Optionally, the communication system 100 may also include an Internet 130. The wireless access network 110 may include at least one access network device (111a and 111b in Figure 1) and at least one terminal device (112a-112j in Figure 1). The terminal device is connected to the access network device wirelessly. The access network device is connected to the core network 120 wirelessly or via a wired connection. The core network 120 may include one or more core network devices. The core network device and the access network device may be independent physical devices, or the functions of the core network device and the logical functions of the access network device may be integrated on the same physical device, or a single physical device may integrate some of the functions of the core network device and some of the functions of the access network device. Terminal devices and access network devices may be interconnected via wired or wireless connections. Wireless communication can occur between terminal devices, between access network devices, and between terminal devices and access network devices via air interface resources. For example, air interface resources may include at least one of time-domain resources, frequency-domain resources, code resources, and spatial resources. It should be noted that Figure 1 is a schematic diagram; the communication system 100 may also include other access network devices, such as wireless relay devices and wireless backhaul devices, which are not shown in Figure 1.
[0200] Access network equipment can be any device with wireless transceiver capabilities. For example, access network equipment can be a base station used to connect terminal devices to a radio access network (RAN). Access network equipment is sometimes also referred to as an access network node, RAN device, AN device, RAN, or AN. It is understood that the names of devices with access network equipment functions may differ in systems employing different wireless access technologies. For ease of description, the apparatus providing wireless communication access functionality to terminal devices in this application embodiment is collectively referred to as RAN. In this application embodiment, access network equipment includes, but is not limited to: various forms of macro base stations (as shown in Figure 1, 111a), micro base stations or indoor stations (as shown in Figure 1, 111b), pico base stations, small stations, balloon stations, relay stations, access points, etc. Access network equipment can include evolved node Bs (eNBs or eNodeBs) in LTE, access points (APs), wireless relay nodes, wireless backhaul nodes, transmission points (TPs), or transmission reception points (TRPs) in Wi-Fi systems. It can also include next-generation NodeBs (gNBs) or transmission points (TRPs or TPs) in 5G systems, one or a group of antenna panels (including multiple antenna panels) of a base station in a 5G system, and network nodes constituting a gNB or transmission point, such as baseband units (BBUs) or distributed units (DUs). Furthermore, it can include access network equipment, servers, or vehicle-mounted equipment in networks evolving after 5G. Access network equipment can also be modules or units that perform some of the functions of a base station; for example, it can be a central unit (CU) or a DU.
[0201] For example, access network equipment can be deployed on satellites. For instance, the satellites can be low Earth orbit (LEO) satellites, medium Earth orbit (MEO) satellites, geostationary Earth orbit (GEO) satellites, or non-geostationary Earth orbit (NGEO) satellites, and so on.
[0202] For example, core network elements or some functions of core network elements can be deployed on satellites. For instance, satellites can be low Earth orbit (LEO) satellites, medium Earth orbit (MEO) satellites, geostationary Earth orbit (GEO) satellites, or non-geostationary Earth orbit (NGEO) satellites, and so on.
[0203] In this embodiment, the apparatus for implementing the functions of the access network device can be the access network device itself, or it can be an apparatus capable of supporting the access network device in implementing the functions, such as a chip system, which can be installed in the access network device. The chip system can be composed of chips, or it can include chips and other discrete components.
[0204] In another possible scenario, multiple access network devices collaborate to assist the terminal in achieving wireless access, with each device performing a portion of the base station's functions. For example, the access network devices could be a CU, DU, CU (control plane, CP), CU (user plane, UP), or a radio unit (RU). The CU and DU can be separate entities or included in the same network element, such as a BBU. The RU can be included in radio equipment or radio units, such as a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH).
[0205] In different systems, CU (or CU-CP and CU-UP), DU, or RU may have different names, but those skilled in the art will understand their meaning. For example, in an open radio access network (O-RAN) system, CU can also be called O-CU (open CU), DU can also be called O-DU, CU-CP can also be called O-CU-CP, CU-UP can also be called O-CU-UP, and RU can also be called O-RU. For ease of description, this application uses CU, CU-CP, CU-UP, DU, and RU as examples. Any of the units among CU (or CU-CP, CU-UP), DU, and RU in this application can be implemented through software modules, hardware modules, or a combination of software modules and hardware modules. The embodiments of this application do not limit the specific technology or specific device form used in the access network equipment.
[0206] Terminal equipment can be a device that provides voice and / or data connectivity to users; it can also be a device with wireless connectivity. Terminal equipment can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; it can also be deployed on water (such as on ships); and it can also be deployed in the air (such as on airplanes, balloons, and satellites). Terminal equipment can also be referred to as user equipment (UE), access terminal, terminal, subscriber unit, user station, mobile station, mobile station (MS), mobile terminal (MT), remote station, remote terminal, mobile device, user terminal, wireless network equipment, user agent, or user device. In this application embodiment, terminal devices include, but are not limited to: cellular phones, mobile phones, wireless data cards, wireless modems, tablets, laptop computers, notebook computers, handheld computers, mobile internet devices (MIDs), computers with wireless transceiver capabilities, cordless phones, session initiation protocol (SIP) phones, smartphones, wireless local loop (WLL) stations, personal digital assistants (PDAs), handsets with wireless communication capabilities, computing devices or other devices connected to wireless modems, in-vehicle devices (e.g., cars, bicycles, electric vehicles, airplanes, ships, trains, high-speed trains, etc.), wearable devices (e.g., smartwatches, smart bracelets, pedometers, smart glasses, etc.), satellite terminals, terminal devices in the Internet of Things or the Internet of Vehicles, as well as any form of terminal in future networks, relay user equipment, or terminals in future evolved public land mobile networks (PLMNs), etc.Terminal devices can also be virtual reality (VR) devices, augmented reality (AR) devices, smart point-of-sale (POS) machines, customer-premises equipment (CPE), light UE, reduced capability UE (REDCAP UE), machine-type communication (MTC) terminals, terminal devices in industrial control, terminal devices in self-driving, terminal devices in telemedicine, terminal devices in smart grids, wireless terminals in transportation safety, terminal devices in smart cities, terminal devices in smart homes, tactile terminal devices, smart home devices (e.g., refrigerators, televisions, air conditioners, electricity meters, etc.), smart robots, robotic arms, workshop equipment, wireless terminals in self-driving, or flying devices (e.g., smart robots, hot air balloons, drones, airplanes), etc. The terminal device can also be a vehicle device, such as a complete vehicle device, an in-vehicle module, an in-vehicle chip, an on-board unit (OBU), or a telematics box (T-BOX). The terminal device can also be other devices with terminal functions; for example, it can be a device that functions as a terminal in device-to-device (D2D) communication. This application does not limit the scope of the embodiments in this regard.
[0207] In this application embodiment, the device for implementing the functions of the terminal device can be the terminal device itself, or it can be any device capable of supporting the terminal device in implementing the functions, such as a chip or chip system. This device can be installed in the terminal device. The chip system can consist of chips or include chips and other discrete components. In the technical solution of this application embodiment, the device for implementing the functions of the terminal device is referred to as the terminal device, which can also be called a terminal. The following description may use a UE (User Equipment) as an example to illustrate the technical solution provided in this application embodiment.
[0208] The roles of base stations and terminals can be relative. For example, the helicopter or drone 112i in Figure 1 can be configured as a mobile base station. For terminals 112j that access the wireless access network 110 via 112i, terminal 112i is a base station; however, for base station 111a, 112i is a terminal, meaning that 111a and 112i communicate via a wireless air interface protocol. Of course, 111a and 112i can also communicate via a base station-to-base station interface protocol. In this case, relative to 111a, 112i is also a base station. Therefore, both base stations and terminals can be collectively referred to as communication devices. 111a and 111b in Figure 1 can be called communication devices with base station functions, and 112a-112j in Figure 1 can be called communication devices with terminal functions.
[0209] Access network devices and terminal devices can communicate via wireless links. The transmission link from the access network device to the terminal device can be called a downlink (DL) or downlink channel, used for transmitting downlink signals. The transmission link from the terminal device to the access network device can be called an uplink (UL) or uplink channel, used for transmitting uplink signals. The transmission link from one terminal device to another can be called a sidelink (SL) or sidelink channel, used for transmitting sidelink signals.
[0210] Figure 2 is a schematic flowchart of a non-access stratum (NAS) security negotiation method 200. The following is a brief introduction to method 200 with reference to Figure 2. For other details, please refer to the 4G NAS security negotiation flowchart in 3GPP standard TS 33.401. The various operations in method 200 are described below.
[0211] S205, MME enables integrity protection.
[0212] S210, the MME sends a NAS security mode command to the UE. Correspondingly, the UE receives the NAS security mode command from the MME.
[0213] For example, the UE may include mobile equipment (ME). The ME can be used to receive the NAS security mode command described above.
[0214] The NAS secure mode command has integrity protection. For example, the MME can protect the integrity of the NAS secure mode command, and the UE can perform integrity verification on the received NAS secure mode command to determine whether the received NAS secure mode command message has been tampered with.
[0215] For example, the NAS security mode command may include parameters such as UE security capabilities, NAS security algorithm, or Evolved Packet System (EPS) key set identifier (eKSI). The eKSI can be used to indicate key parameters, such as K... ASME etc. Among them, K ASME This can be a key generated by both the UE and MME, used to derive the encryption key and / or integrity protection (hereinafter referred to as "integrity protection") key at the NAS layer. The subscript "ASME" indicates an access security management entity. The NAS security algorithm can be a security algorithm selected by the MME based on the UE's security capabilities and the security algorithm list configured by the MME. The NAS security algorithm can include encryption algorithms and / or integrity protection algorithms. Specifically, the NAS security algorithm can be used to determine the key used for encryption and / or the key used for integrity protection. Furthermore, the NAS security algorithm can be used to perform encryption and / or integrity protection. Correspondingly, the NAS security algorithm can be used to determine the key used for decryption and / or the key used for integrity verification. Additionally, the NAS security algorithm can be used to perform decryption and / or integrity verification (or integrity check).
[0216] S212, MME enables uplink decryption.
[0217] For example, after the MME sends the aforementioned NAS security mode command, the MME begins decrypting the uplink messages.
[0218] S214, UE verification command for NAS security mode. If successful, uplink encryption, downlink decryption, and integrity protection are enabled.
[0219] After receiving the NAS security mode command message, the UE can obtain the NAS security algorithm from the message. Furthermore, the UE can generate a NAS key for encryption based on the ID of the encryption algorithm within the NAS security algorithm. The UE can also generate a NAS key for integrity protection based on the ID of the integrity protection algorithm within the NAS security algorithm.
[0220] For example, the UE can perform integrity verification on received messages (i.e., NAS security mode commands) based on the integrity-protected NAS key. If the verification passes, the UE enables encryption and integrity protection for uplink messages, as well as decryption and integrity protection verification for downlink messages. Further, the UE can execute S220.
[0221] S220, the UE sends a NAS safe mode complete message to the MME. Correspondingly, the MME receives the NAS safe mode complete message from the UE.
[0222] For example, the UE may include an ME. The ME can be used to send the aforementioned NAS security complete message.
[0223] After receiving the NAS safe mode completion message, the MME can execute S225.
[0224] S225, MME enables encryption of downlink messages.
[0225] Furthermore, the embodiments of this application can also be applied to the NAS security negotiation process of 5G, for example, refer to TS 33.501. Specific details will not be elaborated further.
[0226] For store-and-forward (S&F) scenarios in NTN networks, currently, the 3rd Generation Partnership Project (3GPP) rd The Generation Partnership Project (3GPP) standard proposes two architectures for 4G scenarios: one is a whole core network (Whole CN) architecture; the other is a mobility management entity (MME) split architecture, where the MME can be divided into two parts. One part is deployed on satellites, which can be called an onboard MME; the other part can be deployed on the ground, which can be called a ground MME. These will be further explained below with reference to Figure 3.
[0227] The embodiments in this application are not limited to the architectural assumptions of 4G scenarios, but are applicable to architectures with partial core network satellite connectivity. A partial core network satellite connectivity architecture includes the satellite connectivity of some core network elements, or the satellite connectivity of some functions of core network elements. Non-terrestrial network equipment, i.e., satellites, should carry core network elements with all or some of the functions of NAS endpoints.
[0228] Figure 3 is a schematic diagram of another communication system. Figure 3 shows multiple nodes that can communicate with each other. The solid line connecting two nodes in Figure 3 indicates that communication is possible between those two nodes. Figure 3 is only an example; the communication system in this embodiment may include more nodes, and there may be other communication paths between the nodes. This application is not limited to this. Furthermore, Figure 3 uses a 4G network as an example, but this embodiment is not limited to 4G networks. For example, this embodiment can also be applied to 5G networks or future communication networks.
[0229] The communication system shown in Figure 3 may include satellite-based functions, ground-based functions, and at least one UE.
[0230] The functions deployed on satellites can be deployed on multiple satellites. Figure 3 shows N satellites among the aforementioned multiple satellites, where N can be a positive integer. Different satellites can have different satellite identifiers (IDs). For example, Figure 3 shows two satellites deployed with onboard MMEs, namely the satellite with satellite ID n and the satellite with satellite ID m. Here, n and m can be different natural numbers. However, this application is not limited to this, and embodiments of this application may also include more or fewer satellites deployed with onboard MMEs.
[0231] The following description uses a satellite with satellite ID n as an example. This satellite may include an E-UTRAN and an onboard MME. The satellite may also include other functions, not shown in Figure 3, but this application does not limit them. Furthermore, the E-UTRAN and the onboard MME may be deployed on different satellites.
[0232] The UE can access the E-UTRAN via the Uu interface, thereby accessing the network.
[0233] As shown in Figure 3, each on-board MME instance can be associated with a satellite ID.
[0234] In the S&F scenario, the satellite cannot simultaneously connect to the UE and the ground station. The ground station can deploy certain functions; for example, the network element deployed on the ground shown in Figure 3 has the functions of a mobility management network element. However, this application is not limited to this, and the ground station can also deploy functions other than those shown in Figure 3.
[0235] In this context, the communication link between the satellite and the UE can be called the service link, and the communication link between the satellite and the ground station can be called the feeder link. This also means that in a Service & Fiber (S&F) scenario, the service link and the feeder link are not simultaneously available. For example, referring to Figure 3, in an S&F scenario, the satellite cannot simultaneously establish communication connections with both the UE and the ground MME. Taking downlink transmission as an example, when the service link is available, the UE can send data to the satellite. When the feeder link is available, the satellite can send the UE's data to the ground MME.
[0236] In the MME-Split architecture of the S&F scenario, the control plane of the evolved packet system (EPS) for cellular internet of things (CIoT) can be optimized. For example, user data or short message service (SMS) messages can be encapsulated in NAS signaling (such as RRC connection requests and / or RRC service requests) for transmission, thus eliminating the need to wait for the user plane to be fully established and enabling rapid packet transmission by the UE. Downlink data can be encapsulated in RRC DL messages, thereby supporting rapid downlink data transmission.
[0237] In the MME-split architecture of the S&F scenario, the UE can attach to a satellite network via multiple satellites. The UE can communicate with different satellites. During communication, the UE and MME need to establish a NAS secure connection to ensure secure data transmission.
[0238] Different satellites each carry a portion of the MME, i.e., on-board MME. How the UE can establish a secure NAS connection with the on-board MME on different satellites is a problem that needs to be solved.
[0239] For example, if the scheme shown in method 200 is adopted, the UE needs to perform NAS security negotiation with different on-board MMEs separately, resulting in a large signaling overhead.
[0240] Unless otherwise specified, in the embodiments of this application, "satellite" and "network element carried on the satellite" can be understood and used interchangeably. For example, communication between a satellite and a terminal device can be understood as communication between a network element carried on the satellite and a terminal device.
[0241] The following description uses the MME (Mobile Equipment Management) as an example of a network element carried on a satellite. It is understood that the MME can be replaced by the access and mobility management function (AMF) or other network elements.
[0242] Furthermore, the monitoring list and the satellite list are interchangeable and can be used interchangeably. The satellite list may be called the monitoring list or other names, which are not limited in this application.
[0243] Figure 4 is a schematic flowchart of a communication method 400 provided in an embodiment of this application. Method 400, by reusing a negotiated security algorithm, can save the signaling overhead of establishing a secure connection between the terminal device and the satellite. Method 400 is described below with reference to Figure 4.
[0244] S430, the terminal device receives broadcast messages from the first satellite.
[0245] Unless otherwise specified, the terminal-side device in this application can be a terminal device, a component within a terminal device (e.g., a processor, device, chip, or chip system), or a logic module or software capable of implementing all or part of the functions of the terminal device. For ease of description, the following description uses a terminal-side device as an example.
[0246] Unless otherwise specified, the first satellite in this application may be the satellite itself, a component of the satellite (e.g., a processor, device, chip, or chip system), or a logic module or software capable of implementing all or part of the satellite's functions. For ease of description, the following description uses the first satellite as an example.
[0247] A broadcast message can be a message broadcast by the first satellite. For example, a broadcast message can be a system message, a paging message, or another message. As an example, a broadcast message can be a message broadcast by the RAN carried on the first satellite.
[0248] In some examples, the broadcast message in S430 may be the first message received by the terminal device from the first satellite (e.g., the first system message).
[0249] In other examples, the broadcast message in S430 may be a paging message broadcast by the first satellite to the terminal device.
[0250] This application does not limit the information content carried by the broadcast message. For example, the broadcast message may include at least one of the following: the identifier of the first satellite, the identifier of the network element carried on the first satellite, or other information. The broadcast message may also include other information.
[0251] S440, the terminal device determines the first security algorithm corresponding to the first satellite based on the broadcast message.
[0252] The first satellite corresponds to the first security algorithm, which can be understood as the first security algorithm protecting the communication security between the terminal device and the first satellite. For example, the terminal device can use this first security algorithm to protect the communication security between the terminal device and the first satellite.
[0253] In one implementation, the non-access NAS layer security between the terminal device and the first satellite is protected by a first security algorithm. For example, the terminal device can use this first security algorithm to protect the non-access NAS layer security between the terminal device and the first satellite.
[0254] The first satellite corresponds to the first security algorithm, which can also be understood as, or replaced by, the network element (e.g., MME) carried on the first satellite corresponding to the first security algorithm. The description of "the network element carried on the first satellite corresponds to the first security algorithm" will not be repeated here; please refer to the example of the first satellite corresponding to the first security algorithm for details.
[0255] In some examples, the terminal device can be configured to use only the first security algorithm. Thus, after receiving a broadcast message from the first satellite, the terminal device can determine that the security algorithm corresponding to the first satellite (or the MME carried on the first satellite) is the first security algorithm.
[0256] In other examples, the first security algorithm may be negotiated and selected by the terminal-side device with the second satellite (or the MME carried on the second satellite) before S430.
[0257] In some possible implementations, the second satellite may be a satellite that the terminal device accesses before S430. The second satellite (or the MME carried on the second satellite) can perform a NAS security negotiation process with the terminal device, such as method 200. The security algorithm selected by the terminal device and the second satellite (or the MME carried on the second satellite) can be referred to as the first security algorithm.
[0258] The second satellite (or the MME carried on the second satellite) can use the same security algorithm as the first satellite (or the MME carried on the first satellite) to communicate with the terminal device. For example, the second satellite (or the MME carried on the second satellite) and the first satellite (or the MME carried on the first satellite) can be configured with the same list of security algorithms, so that for the same terminal device, the second satellite (or the MME carried on the second satellite) and the first satellite (or the MME carried on the first satellite) select the same security algorithm.
[0259] In the above S440, the terminal device can determine, based on the broadcast message, that it will access the first satellite (or the RAN on the first satellite) and determine the first security algorithm corresponding to the first satellite (or the MME carried on the first satellite).
[0260] The terminal-side device determines the first security algorithm corresponding to the first satellite (or the MME carried on the first satellite). This can be done after the terminal-side device accesses the first satellite (or the RAN on the first satellite) or before the terminal-side device accesses the first satellite (or the RAN on the first satellite). This application does not limit this process.
[0261] For further descriptions of the S440, please refer to the following text; they will not be repeated here.
[0262] S450, the terminal device uses the first security algorithm to protect the communication security between the first satellite and the terminal device.
[0263] The above-mentioned S450 can be executed after the terminal device accesses the first satellite (or the RAN on the first satellite) or before the terminal device accesses the first satellite (or the RAN on the first satellite), and this application does not limit it in this way.
[0264] As an example, the terminal-side device can generate a NAS key based on a first security algorithm. The terminal-side device can then use the first security algorithm and the NAS key to securely protect NAS messages between the first satellite (or the MME carried on the first satellite) and the terminal-side device.
[0265] Based on the above scheme, the terminal device can determine the first security algorithm according to the broadcast message, and use the first security algorithm to protect the communication security between the first satellite and the terminal device, thereby establishing a secure connection with the first satellite. Furthermore, the above scheme eliminates the need for the terminal device to perform NAS security negotiation with the first satellite, and eliminates the need to send and receive NAS security negotiation signaling, thus saving the signaling overhead of establishing a secure connection.
[0266] Optionally, the first satellite and the second satellite are configured with the same list of security algorithms.
[0267] The first security algorithm can be determined based on the list of security algorithms and the security capability information of the terminal-side device. For example, the second satellite can determine the first security algorithm based on the list of security algorithms and the security capability information of the terminal-side device.
[0268] The following are some examples of S440.
[0269] Optionally, the broadcast message includes an identifier corresponding to the first satellite or an identifier corresponding to a network element carried on the first satellite.
[0270] In some possible implementations, S440 includes: S442, where the terminal device determines the first security algorithm corresponding to the first satellite based on the identifier corresponding to the first satellite.
[0271] In some other possible implementations, S440 includes: S444, where the terminal device determines the first security algorithm corresponding to the first satellite based on the identifier corresponding to the network element carried on the first satellite.
[0272] The following are some examples of S442.
[0273] In some possible implementations, S442 includes: the terminal device determining that the first satellite belongs to a first group based on the identifier corresponding to the first satellite; the terminal device determining the security algorithm shared by the satellites in the first group as the first security algorithm, wherein the first group includes the first satellite and the second satellite.
[0274] In this case, the satellites in the first group can be configured with the same list of security algorithms, so that the satellites in the first group can select the same security algorithm for the same terminal device.
[0275] In some examples, the identifier corresponding to the first satellite can be the identifier of the first satellite. The terminal device can pre-store the correspondence between the identifier of the first satellite and the first group. In this way, the terminal device can determine that the first satellite belongs to the first group.
[0276] In other examples, the identifier corresponding to the first satellite can be the identifier of the first group. In this way, the terminal device can determine that the first satellite belongs to the first group.
[0277] In some possible implementations, S442 includes: the terminal device determining, based on the identifier of the first satellite, that the first satellite and the second satellite belong to the same group; and the terminal device determining the security algorithm corresponding to the second satellite as the first security algorithm.
[0278] The security algorithm corresponding to the second satellite can be a security algorithm negotiated and determined between the second satellite and the terminal-side equipment.
[0279] In some possible implementations, S442 includes: the terminal device determining, based on the identifier of the first satellite, that the first satellite has the same list of security algorithms configured as the second satellite; and the terminal device determining the security algorithm corresponding to the second satellite as the first security algorithm.
[0280] In some examples, the terminal device can determine, based on its local configuration, that the first satellite and the second satellite have the same list of security algorithms.
[0281] In other examples, the terminal device can obtain indication information from the terrestrial network or the first satellite, which can be used to indicate that the first satellite has the same list of security algorithms configured as the second satellite.
[0282] The following is an example of S444.
[0283] In some possible implementations, S444 includes: the terminal device determining that the network element carried on the first satellite belongs to a second group based on the identifier corresponding to the network element carried on the first satellite; the terminal device determining the security algorithm shared by the network elements in the second group as the first security algorithm, wherein the second group includes the network element carried on the first satellite and the network element carried on the second satellite.
[0284] In this group, the network elements can be configured with the same list of security algorithms, so that the network elements in the second group can select the same security algorithm for the same terminal device.
[0285] In some examples, the identifier corresponding to the network element carried on the first satellite can be the identifier of the network element carried on the first satellite. The terminal device can pre-store the correspondence between the identifiers of the network elements carried on the satellite and the second group. In this way, the terminal device can determine that the network element carried on the first satellite belongs to the second group.
[0286] In other examples, the identifier corresponding to the network element carried on the first satellite can be an identifier of the second group. In this way, the terminal device can determine that the network element carried on the first satellite belongs to the second group.
[0287] For example, the identifier corresponding to the network element carried on the first satellite can be carried in a globally unique temporary identity (GUTI).
[0288] For example, the broadcast message in S430 can be a paging message. This paging message can include a GUTI. The GUTI can contain a portion identifying the MME and a portion identifying the UE. For instance, the GUTI can include a globally unique MME identity (GUMMEI) and a Mobility Management Entity - Temporary Mobile Subscriber Identity (M-TMSI).
[0289] GUMMEI can include MME code and MME group code.
[0290] In some examples, the identifier for the network element carried on the first satellite can be an MME code. The identifier for the second group can be an MME group code.
[0291] In other examples, the identifier of the network element carried on the first satellite can be GUMMEI. The identifier of the second group can be other identifiers. For example, the identifier of the second group can be the Mobility Management Entity Group Identifier (MMEGI), the AMF Region ID, or the AMF Set ID, or other identifiers.
[0292] For example, in order to globally and uniquely identify a group, the group identifier may also include a mobile country code (MCC) and a mobile network code (MNC).
[0293] This application does not limit the specific form of the identifier corresponding to the network element carried on the first satellite. The identifier of the network element carried on the first satellite or the identifier of the second group can also be other identifiers.
[0294] In some possible implementations, S444 includes: the terminal device determining, based on the identifier of the network element carried on the first satellite, that the network element carried on the first satellite and the network element carried on the second satellite belong to the same group; and the terminal device determining the security algorithm corresponding to the network element carried on the second satellite as the first security algorithm.
[0295] The security algorithm corresponding to the network element carried on the second satellite can be a security algorithm negotiated and determined by the network element (e.g., MME) carried on the second satellite and the terminal-side equipment.
[0296] In some possible implementations, S444 includes: the terminal device determining that the identifier of the network element carried on the first satellite is the same as the identifier of the network element carried on the second satellite; and the terminal device determining the security algorithm corresponding to the network element carried on the second satellite as the first security algorithm.
[0297] The identifier of a network element carried on the first satellite is the same as the identifier of a network element carried on the second satellite. This can be understood as meaning that the network elements carried on the first and second satellites can be connected to the same ground network element (e.g., a ground-based MME); or it can be understood as considering the network elements carried on the first and second satellites and the same ground network element as a single network element. For example, a network element carried on the first satellite and a certain ground network element can be considered as a single network element. Similarly, a network element carried on the second satellite and that ground network element can be considered as a single network element.
[0298] In some possible implementations, S444 includes: the terminal device determining, based on the identifier corresponding to the network element carried on the first satellite, that the security algorithm list configured for the network element carried on the first satellite is the same as that configured for the network element carried on the second satellite; and the terminal device determining the security algorithm corresponding to the network element carried on the second satellite as the first security algorithm.
[0299] In some examples, the terminal device can determine, based on its local configuration, that the security algorithm list configured for the network elements carried on the first satellite is the same as that configured for the network elements carried on the second satellite.
[0300] In other examples, the terminal device can obtain indication information from the terrestrial network or the first satellite, which can be used to indicate that the network elements carried on the first satellite have the same list of security algorithms configured as the network elements carried on the second satellite.
[0301] The following are some examples related to S450.
[0302] In some possible implementations, S450 includes: the terminal device using the first security algorithm to provide security protection for the first uplink non-access stratum (NAS) message sent by the terminal device to the first satellite.
[0303] For example, the terminal device can use the first security algorithm to provide security protection for the first uplink NAS message sent by the terminal device to the MME carried on the first satellite.
[0304] Understandably, since method 400 skips the NAS security negotiation process between the terminal device and the first satellite, the terminal device can provide security protection for the first uplink non-access stratum NAS message.
[0305] The first uplink non-access stratum (NAS) message can be understood as the first NAS message between the terminal device and the first satellite. For example, the first NAS message can follow the broadcast message and the random access message.
[0306] For example, the NAS message in S210 of method 200 may not be the first NAS message. Before S210, there may be NAS messages used for authentication and authorization, and NAS messages used for initial registration requests. Understandably, in method 200, S210 is the first NAS message with security protection (S210 has integrity protection but is not encrypted). Therefore, NAS messages before S210 (e.g., the first NAS message) are not securely protected. In other words, method 200 cannot provide security protection for the first NAS message.
[0307] Based on the above scheme, the terminal-side device can reuse the negotiated security algorithm, thus eliminating the need for a security negotiation process. Therefore, the terminal-side device can provide security protection for the first uplink NAS message, thereby improving security.
[0308] In some possible implementations, prior to S450, the method 400 also includes: enabling encryption and / or integrity protection for NAS messages on the terminal side device.
[0309] For example, the terminal device may enable encryption and / or integrity protection of NAS messages at any time between negotiating and determining the first security algorithm with the second satellite and S450.
[0310] The following section presents an example of how the first satellite obtains the first security algorithm.
[0311] In some possible implementations, the first uplink NAS message mentioned above includes indication information for the first security algorithm. That is, the terminal device can indicate the first security algorithm to the first satellite.
[0312] Optionally, the indication information of the first security algorithm is protected for integrity and is not encrypted.
[0313] In some other possible implementations, the first satellite can obtain the first security algorithm from a ground network element (e.g., a ground-based MME). These will be described in detail below.
[0314] Optionally, prior to S430, method 400 also includes S420 and S425.
[0315] S420, the first satellite (or the network element carried on the first satellite) receives the instruction information of the first security algorithm from the ground network element. Correspondingly, the ground network element sends the instruction information of the first security algorithm to the first satellite (or the network element carried on the first satellite).
[0316] Optionally, the first satellite (or the network element carried on the first satellite) also obtains the identifier of the terminal-side device from the ground network element. Correspondingly, the ground network element also sends the identifier of the terminal-side device to the first satellite (or the network element carried on the first satellite).
[0317] For example, the identifier of the terminal-side device may be the International Mobile Subscriber Identity (IMSI), GUTI, or other identifiers.
[0318] Among them, the ground network element can be a core network element located on the ground.
[0319] S425, the first satellite (or the network element carried on the first satellite) uses the first security algorithm to protect the communication security between the first satellite (or the network element carried on the first satellite) and the terminal-side device.
[0320] Based on the above scheme, the first satellite can obtain the first security algorithm from the ground network element and use the first security algorithm to protect the communication security between the first satellite and the terminal-side equipment, thereby establishing a secure connection with the terminal-side equipment. Furthermore, the above scheme eliminates the need for NAS security negotiation between the first satellite and the terminal-side equipment, and eliminates the need to send and receive NAS security negotiation signaling, thus saving signaling overhead and latency in establishing a secure connection.
[0321] In some possible implementations, S425 includes: enabling the decryption and / or integrity verification of non-access stratum (NAS) messages by the first satellite.
[0322] For example, the first satellite may initiate the decryption and / or integrity verification of NAS messages at any time between receiving the instruction information from the first security algorithm and S470.
[0323] In some possible implementations, after the first satellite initiates the decryption and / or integrity verification of the NAS message, the method 400 further includes: S460, the first satellite receives the first uplink NAS message from the terminal device; S470, the first satellite decrypts and / or verifies the integrity of the first uplink NAS message.
[0324] In some possible implementations, S470 includes: if the first uplink NAS message is not protected for integrity, and / or if integrity verification of the first uplink NAS message fails, the first satellite discards the first uplink NAS message.
[0325] Understandably, after the first satellite enables the decryption and / or integrity verification of NAS messages, the first satellite can discard NAS messages that are not protected by integrity, or discard NAS messages that fail integrity verification.
[0326] In some possible implementations, before the first satellite enables encryption and / or integrity protection for non-access stratum (NAS) messages, the method 400 further includes: the first satellite determining a first NAS key based on the first security algorithm; or, the first satellite receiving information related to the first NAS key from the ground network element.
[0327] The first NAS key can be used to decrypt NAS messages and / or verify their integrity.
[0328] The information related to the first NAS key may include the identifier of the first NAS key, information used to determine the first NAS key (e.g., key parameters) or other information, which are not limited in this application.
[0329] The following are examples of terrestrial network elements.
[0330] S410, the ground network element obtains the first security algorithm from the second satellite.
[0331] In some possible implementations, prior to S420 (i.e., the ground network element sends the indication information of the first security algorithm to the first satellite), the method 400 further includes: the ground network element determining the first satellite based on a satellite list (or monitoring list).
[0332] The satellite list can be used to indicate which satellites the terminal device will subsequently connect to. For example, the satellite list may include identifiers of the satellites that the terminal device will subsequently connect to.
[0333] It is understood that the satellite list serves to indicate at least one satellite that the terminal device will subsequently access; however, this application does not limit the content of the satellite list. For example, as the terminal device moves and the satellites move, the satellites that the terminal device may subsequently access will also change.
[0334] For example, when the first satellite establishes a connection with a ground network element (e.g., a power supply link), the ground network element can determine whether the first satellite is in the satellite list. If the first satellite is in the satellite list, then the first satellite can execute S420.
[0335] However, this application does not limit this, and the ground network element can determine whether to execute S420 based on other judgment logic.
[0336] In some possible implementations, the ground network element determines the first satellite based on the satellite list, including: the ground network element determines that both the first satellite and the second satellite in the satellite list are allowed to communicate with the terminal device using the same security algorithm.
[0337] The method by which the ground network element determines that both the first satellite and the second satellite are allowed to use the same security algorithm to communicate with the terminal device can be found in the example of S440, which will not be repeated here.
[0338] Other descriptions of the above method 400 are provided below and will not be repeated here.
[0339] Figure 5 is a schematic flowchart of another communication method 500 provided in an embodiment of this application. Method 500 can be used as a specific example of method 400. The various nodes of method 500 are described below.
[0340] Unless otherwise specified, the terminal-side device in this application can be the terminal device itself, a component within the terminal device (e.g., a processor, chip, or chip system), or a logic module or software capable of implementing all or part of the terminal device's functions. For ease of description, UE#1 will be used as an example below.
[0341] Unless otherwise specified, the RAN in this application can be the access network device itself, a component within the access network device (e.g., a processor, chip, or chip system), or a logical module or software capable of implementing all or part of the functions of the access network device. For ease of description, the RAN will be used as an example below.
[0342] Unless otherwise specified, the on-board MME in this application can be the device itself capable of implementing MME functions on a satellite, a component within the device (e.g., a processor, chip, or chip system), or a logic module or software capable of implementing MME functions on a satellite. For ease of description, the following description uses an on-board MME as an example.
[0343] Unless otherwise specified, the terrestrial MME in this application can be the device itself capable of implementing MME functions on the ground, a component within the device (e.g., a processor, chip, or chip system), or a logic module or software capable of implementing MME functions on the ground. For ease of description, the following description uses a terrestrial MME as an example.
[0344] Unless otherwise specified, the home subscriber server (HSS) in this application can be the device itself capable of implementing HSS functionality, a component within the device (e.g., a processor, chip, or chip system), or a logical module or software capable of implementing HSS functionality. For ease of description, the following description uses HSS as an example.
[0345] The following section describes the various operations of method 500 with reference to Figure 5.
[0346] S510, the onboard MME of satellite #1 sends an attach accept message to UE #1.
[0347] For example, the attach accept message includes a globally unique temporary identity (GUTI), a monitoring list (including at least one satellite ID), and a wait timer. The monitoring list is optional. In other words, the attach accept message may or may not include a monitoring list; this application does not limit this. Specific examples of GUTIs are given above and will not be repeated here.
[0348] The waiting time can be used to indicate the waiting time for UE#1. For example, the waiting time can indicate the waiting time for UE#1 to access the next satellite. During this period, UE#1 can refrain from receiving broadcast information from the satellite frequency band, thereby saving energy.
[0349] It is understood that prior to S510, UE#1 has already completed the authentication and authorization process, as well as NAS security negotiation (e.g., via method 200). Assume that UE#1 negotiates with satellite #1 using NAS security algorithm #1. Exemplarily, NAS security algorithm #1 may include encryption algorithm #1 and / or integrity protection algorithm #1.
[0350] The aforementioned S510 can be executed when the service link (or communication link) between satellite #1 and UE #1 is available.
[0351] S520, the onboard MME of satellite #1 sends UE-related information to the ground MME.
[0352] This UE-related information includes information about NAS security algorithm #1. Thus, the ground-based MME can obtain this NAS security algorithm #1.
[0353] Optionally, the UE-related information may include authentication information. This authentication information can be used to prove that the UE#1 is legitimately authenticated, or in other words, that the UE#1 is not an attacker.
[0354] Optionally, the UE-related information also includes the security capabilities of UE#1. These security capabilities can be verified during the NAS security negotiation process between UE#1 and Satellite #1 to be genuine security capabilities reported by UE#1 and unaffected by security attacks.
[0355] Optionally, the UE-related information also includes a GUTI. This GUTI can be used for satellite paging of UE#1 or for addressing the MME indicated by the GUTI.
[0356] Optionally, the UE-related information may also include data (e.g., uplink data of UE#1).
[0357] Optionally, the UE-related information may also include a monitoring list.
[0358] S530, the ground MME sends UE-related information to satellite #2.
[0359] The UE-related information may include NAS security algorithm #1, UE #1's identifier (e.g., IMSI, GUTI, or other identifiers), International Mobile Subscriber Identity (IMSI), GUTI, data (e.g., UE #1's downlink data), and key parameters (e.g., K...). ASME K AMF (or other keys used to derive NAS keys for satellites), NAS keys, or at least one of the following:
[0360] In some possible implementations, prior to S530, method 500 further includes: the ground MME determining that satellite #2 belongs to the monitoring list. Optionally, the ground MME obtains the monitoring list. This monitoring list may come from satellite #1, from a third-party network element, or be determined by the ground MME; this application does not impose any limitations.
[0361] In some examples, satellite #1 can send a monitoring list to the ground MME. The ground MME can use this monitoring list, or obtain a new monitoring list based on or not based on this monitoring list. The ground MME can then use this new monitoring list, for example, to determine whether satellite #2 belongs to the new monitoring list.
[0362] For example, the ground MME can determine whether each passing satellite, or in other words, whether each satellite with an available feed link to the ground MME, belongs to a monitoring list. If a satellite belongs to the monitoring list, the aforementioned UE-related information is sent to that satellite.
[0363] In some other possible implementations, the ground-based MME can send UE-related information to satellites belonging to the same satellite group.
[0364] In some other possible implementations, the MME carried on the satellite and the ground MME belong to the same MME, and the ground MME can send UE-related information to the satellite.
[0365] In some other possible implementations, the ground MME can send UE-related information to any passing satellite, or determine whether to send UE-related information to passing satellites through other means; this application does not impose any limitations on this.
[0366] In some possible implementations, prior to S530, method 500 further includes: the ground MME determining that satellite #2 and satellite #1 belong to the same group; or, the ground MME determining that the on-board MMEs carried on satellite #2 and satellite #1 belong to the same group; or, the ground MME determining that the on-board MMEs carried on satellite #2 and satellite #1 are connected to the same ground MME. In the case that satellite #2 and satellite #1 belong to the same group, or the mobility management network elements carried on satellite #2 and satellite #1 belong to the same group, or the MMEs carried on satellite #2 and satellite #1 are connected to the same ground MME, the UE-related information may include NAS security algorithm #1.
[0367] In some other possible implementations, prior to S530, method 500 further includes: the ground MME determining that satellite #2 belongs to satellite group #1, and the UE-related information 'may include NAS security algorithm #1'. Here, NAS security algorithm #1 is the NAS security algorithm corresponding to satellite group #1.
[0368] In some other possible implementations, prior to S530, method 500 further includes: the ground MME determining that the on-board MME carried by satellite #2 belongs to MME group #1, and the UE-related information may include NAS security algorithm #1. Here, NAS security algorithm #1 is the NAS security algorithm corresponding to MME group #1.
[0369] In some other possible implementations, prior to S530, method 500 further includes: the ground MME determining that the MME on satellite #2 and the ground MME belong to the same MME. If the MME on satellite #2 and the ground MME belong to the same MME, the UE-related information may include NAS security algorithm #1.
[0370] It is understood that among the satellites that UE#1 may access, there may be satellites configured with the same NAS security algorithm list as satellite #1 or the network elements (e.g., MME) carried on satellite #1. These satellites will select the NAS security algorithm that UE#1 can support and that has the highest priority in the NAS security algorithm list, based on UE#1's security capabilities (e.g., including the NAS security algorithms supported by UE#1). The priority of each NAS security algorithm in the NAS security algorithm list can be configured by the operator or determined by other means, which is not limited in this application.
[0371] Therefore, satellites configured with the same NAS security algorithm list as satellite #1 or the network elements carried on satellite #1 will also choose NAS security algorithm #1 to communicate with UE #1. For ease of description, satellites configured with the same NAS security algorithm list as satellite #1 will be referred to as a satellite group (denoted as satellite group #1). Satellites in satellite group #1 are configured with the same NAS security algorithm list and will use NAS security algorithm #1 to communicate with UE #1. Furthermore, the on-board MMEs carried by each satellite in the same satellite group can also belong to the same MME group. For example, the on-board MMEs carried by each satellite in the aforementioned satellite group #1 can belong to MME group #1.
[0372] For example, the mobility management network elements carried on each satellite in a satellite group may have an MME group identifier.
[0373] For example, mobility management network elements carried on satellites in a satellite constellation are connected to the same ground MME. For instance, the on-board MMEs on satellites in satellite constellation #1 can be connected to the same ground MME (denoted as ground MME #1). Connecting to the same ground MME can use a globally unique MME identifier (GUMMEI) as a group identifier (e.g., GUMMEI #1) or other identifiers.
[0374] For example, in a 5G scenario, the mobile management network elements carried on each satellite in a satellite constellation are connected to the same ground AMF. Connecting to the same ground AMF can use a globally unique AMF identifier (GUAMF) as a group identifier (e.g., GUAMF#1) or other identifiers. For example, each satellite in a satellite constellation can have a satellite group identifier. For instance, each satellite in satellite constellation #1 can have satellite group identifier #1.
[0375] For example, satellites in a group or network elements carried on satellites can have a group identifier. For instance, each satellite in satellite group #1 can have a satellite group identifier #1. For instance, network elements carried on satellites can have a satellite network element group identifier #1.
[0376] For example, satellites or network elements carried on satellites in a group may not have a group identifier, but belong to the same group, and their group relationship is stored in the ground MME or terminal equipment.
[0377] For example, when the power supply link between satellite group #1 and ground MME #1 is available, the onboard MMEs on each or some of the satellites in satellite group #1 can communicate with ground MME #1.
[0378] For example, when the feed link between satellite #1 and ground MME #1 is available, satellite #1 can communicate with ground MME #1, and satellite #1 belongs to satellite group #1.
[0379] In the embodiments of this application, "group" can also be understood as or replaced by "set," "layer," or other similar expressions, and this application does not limit it. For example, a satellite group can also be understood as or replaced by a set of satellites, a satellite layer, or other similar expressions. The understanding and substitution of other terms related to "group" will not be elaborated further.
[0380] Among them, the key parameter can be used to determine the NAS key.
[0381] In some examples, UE-related information may include key parameters. Thus, the onboard MME of satellite #2 can determine the NAS key based on the aforementioned key parameters and NAS security algorithm #1.
[0382] In other examples, UE-related information may include the NAS key. This allows the onboard MME of satellite #2 to obtain the NAS key.
[0383] In some possible implementations, the onboard MME of the aforementioned satellite #2 can enable downlink NAS message encryption and integrity protection after determining or obtaining the NAS key.
[0384] The various pieces of information included in the UE-related information can be carried in one message or in different messages; this application does not impose any restrictions on this.
[0385] S540, the onboard RAN of satellite #2 sends a broadcast message to UE #1.
[0386] The broadcast information may include the identifier of satellite #2 and an S&F indication. The S&F indication can be used to indicate that satellite #2 supports S&F mode (or, S&F scenario, or, S&F architecture). Further descriptions of S540 are given in S430 above and will not be repeated here.
[0387] S550, UE#1 accesses the onboard RAN of satellite #2.
[0388] In some examples, UE#1 determines whether satellite #2 belongs to the monitoring list based on information about satellite #2 in the broadcast message. If satellite #2 belongs to the monitoring list, UE#1 can access satellite #2.
[0389] In other examples, UE#1 can directly access satellite #2. For instance, if UE#1 has not accessed a satellite in the monitoring list for a period of time, it can access satellite #2 that passes through UE#1. Yet another example is that UE#1 directly accesses satellite #2 without any other conditions.
[0390] In some possible implementations, UE#1 and satellite #2 can perform a 4-step random access process to enable UE#1 to access satellite #2.
[0391] In some other possible implementations, UE#1 and satellite #2 can perform a two-step random access, thereby enabling UE#1 to access satellite #2.
[0392] S560, UE#1 determines NAS security algorithm #1.
[0393] For example, UE#1 can determine whether satellite #2 belongs to the same satellite group as the satellite with which NAS security negotiation has been completed (e.g., satellite #1). If they belong to the same satellite group, UE#1 can derive the NAS key for satellite #2 based on the aforementioned NAS security algorithm #1. Further, UE#1 can enable uplink NAS message encryption and / or integrity protection. If they do not belong to the same satellite group, UE#1 can perform NAS security negotiation with satellite #2 (e.g., execute method 200).
[0394] For example, UE#1 can determine the satellite group to which satellite #2 belongs (e.g., satellite group #1) and obtain NAS security algorithm #1 based on the satellite group to which satellite #2 belongs. UE#1 can derive the NAS key for satellite #2 based on the aforementioned NAS security algorithm #1. Furthermore, UE#1 can enable uplink NAS message encryption and / or integrity protection. If satellite #2 does not belong to the satellite group to which UE#1 has already completed security negotiation (e.g., satellite group #1), then UE#1 can perform NAS security negotiation with satellite #2 (e.g., execute method 200).
[0395] For example, after obtaining NAS security algorithm #1 and deriving the NAS layer key, the UE enables encryption and / or integrity protection of uplink NAS messages.
[0396] For further descriptions of S560 above, please refer to S440, which will not be repeated here.
[0397] S570, UE#1 sends a NAS message to the onboard MME of satellite #2.
[0398] This NAS message can be a NAS message with security protection. This security protection can be encryption and / or integrity protection. Further details can be found in S460 and will not be repeated here.
[0399] For example, a NAS message can be an RRC connection request and / or an RRC control service request. NAS messages can be used to carry NAS protocol data units (PDUs). A NAS PDU can include data (e.g., uplink data from UE#1).
[0400] In addition, NAS messages may not contain uplink data from the UE, but instead be a request message, such as a service request.
[0401] S580, the onboard MME of satellite #2 decrypts and / or verifies the integrity of the aforementioned NAS messages.
[0402] When a secure uplink NAS message is received, the MME on satellite #2 enables uplink decryption and / or integrity verification for the NAS message.
[0403] If the security verification fails, satellite #2 can negotiate NAS security with UE #1.
[0404] If the integrity verification passes, enable downlink encryption and / or integrity protection for NAS messages. Other details can be found in S470 and will not be repeated here.
[0405] S590, the onboard MME of satellite #2 sends a NAS message (NAS PDU) to UE #1.
[0406] The downlink NAS message is protected by information obtained from NAS security algorithm #1 in S530.
[0407] The NAS message in S590 can also be called a NASDL message or other names, and this application does not limit it. For example, the onboard MME of satellite #2 can send the above-mentioned NASDL message to UE #1.
[0408] In S590, the NAS message can carry a NAS PDU. This NAS PDU can include data (e.g., downlink data for UE#1).
[0409] The NAS message may also not contain downlink data from the UE, but instead be a response message.
[0410] S595, UE#1 decrypts and / or verifies the integrity of NAS messages received by S590 based on NAS security algorithm #1.
[0411] For example, UE#1 receives a downlink NAS message with security protection and enables downlink decryption and / or integrity verification.
[0412] For example, the UE can begin downlink decryption and / or integrity verification after sending the uplink NAS message, i.e., after sending S570.
[0413] For example, when the UE enables uplink encryption and / or integrity verification, it simultaneously or subsequently enables downlink decryption and / or integrity verification.
[0414] Depending on the security requirements, Method 500 may use only encryption (and decryption) or integrity protection (and integrity verification), or it may use both encryption (and decryption) and integrity protection (and integrity verification).
[0415] Based on the above scheme, after UE#1 completes a NAS security negotiation with satellite #1, satellite #1 can send the negotiated NAS security algorithm #1 to the ground MME. The ground MME can then synchronize the NAS security algorithm #1 with passing satellites, avoiding UE#1 needing to negotiate NAS security with multiple satellites separately. This allows UE#1 to quickly establish NAS security connections with onboard MMEs deployed on different satellites. Furthermore, this scheme reduces signaling interactions between the UE and the onboard MMEs; for example, the UE does not need to negotiate NAS security with some onboard MMEs, thus eliminating the need to send that portion of the signaling. In addition, this scheme supports UE#1's need for rapid data transmission and reception.
[0416] Figure 6 is a schematic flowchart of a communication method 600 provided in an embodiment of this application. In method 600, the satellite can instruct the terminal device to select a security algorithm before the first NAS message, which can save the signaling overhead of establishing a secure connection between the terminal device and the satellite. Method 600 is described below with reference to Figure 6.
[0417] S650, the fifth satellite sends an instruction message for the third security algorithm to the terminal device. Correspondingly, the terminal device receives the instruction message for the third security algorithm from the fifth satellite.
[0418] The above-described S650 can be executed before the fifth satellite receives the first Non-Access Stratum (NAS) message from the terminal-side device. In other words, the above-described S650 can be executed before the terminal-side device sends the first NAS message to the fifth satellite.
[0419] The third security algorithm can be a security algorithm determined by the fifth satellite. For example, this third security algorithm is negotiated and selected between the ground network element and the fifth satellite. This third security algorithm can be used to protect the communication security between the fifth satellite and the terminal-side equipment.
[0420] For example, the indication information for a third security algorithm may include the identifier of the third security algorithm.
[0421] S670, the fifth satellite uses the third security algorithm to protect the communication security between the fifth satellite and the terminal-side equipment.
[0422] For example, S670 can be executed at any time between S630 and S690.
[0423] Based on the above scheme, the fifth satellite can negotiate and determine the security algorithm with ground network elements and instruct the terminal-side device to implement the security algorithm, thereby enabling a secure connection between the satellite and the terminal-side device. Furthermore, this scheme eliminates the need for the terminal-side device to perform NAS security negotiation with the fifth satellite, and avoids sending and receiving NAS security negotiation signaling, thus saving signaling overhead and latency in establishing a secure connection.
[0424] In some possible implementations, prior to S650, the method 600 further includes: S620, where the fifth satellite receives security capability information of the terminal-side device from the ground network element; S630, where the fifth satellite determines a third security algorithm based on the security capability information of the terminal-side device.
[0425] In some possible implementations, prior to S670, method 600 further includes: S640, whereby the fifth satellite receives a first random access message from the terminal-side device, the first random access message including an identifier of the terminal-side device. Further, the fifth satellite can determine the third security algorithm corresponding to the identifier of the terminal-side device.
[0426] For example, the fifth satellite can determine multiple security algorithms corresponding to multiple terminal-side devices based on the security capability information of multiple terminal-side devices. In S640, the terminal-side device can obtain the identifier of the terminal-side device from the first random access message, thereby determining which security algorithm to use to protect the communication security with that terminal-side device.
[0427] Random access messages can be used for random access. For example, random access messages can include messages 1 (message 1, Msg1) through 4 (message 4, Msg4). It is understood that random access messages are exchanged before the first NAS message.
[0428] In some possible implementations, the indication information of the third security algorithm is carried in the second random access message.
[0429] In some possible implementations, S670 includes: enabling the decryption and / or integrity verification of non-access stratum (NAS) messages by the fifth satellite.
[0430] In some implementations, after enabling NAS message decryption and / or integrity verification, the method 600 further includes: S680, the fifth satellite receives the first uplink NAS message from the terminal device; S690, the first uplink NAS message is decrypted and / or its integrity is verified (or checked).
[0431] In some implementations, S690 includes: if the first uplink NAS message is not protected for integrity, and / or if integrity verification of the first uplink NAS message fails, the fifth satellite discards the first uplink NAS message. The above scheme is similar to the scheme in method 400; please refer to the description of method 400 for details, which will not be repeated here.
[0432] The following section presents examples of terrestrial network elements.
[0433] S610: Ground network elements acquire security capability information of terminal-side devices.
[0434] For example, ground network elements can obtain security capability information of terminal-side devices from satellites.
[0435] S620, the ground network element sends the security capability information of the terminal-side equipment to the fifth satellite.
[0436] In some possible implementations prior to S620, the method further includes: the ground network element determining the fifth satellite based on a monitoring list, wherein the monitoring list is used to indicate the satellites that the terminal-side device will subsequently access.
[0437] For example, the ground network element determines whether a fifth satellite exists in the monitoring list. If the monitoring list includes information about a fifth satellite, step S620 is executed.
[0438] The following is an example of a terminal-side device.
[0439] S655, the terminal-side device uses the third security algorithm to protect the communication security between the fifth satellite and the third terminal-side device.
[0440] S655 can be executed after S650.
[0441] For example, S655 can be executed at any time between S650 and S680.
[0442] In some possible implementations, S655 includes: the terminal device using the third security algorithm to provide security protection for the first uplink non-access stratum (NAS) message sent by the terminal device to the fifth satellite.
[0443] In some implementations, before the terminal device uses the third security algorithm to securely protect the first uplink NAS message sent by the terminal device to the fifth satellite, the method 600 further includes: the terminal device enabling encryption and / or integrity protection for the NAS message.
[0444] In some possible implementations, the third security algorithm is used to provide security protection for the first uplink non-access stratum (NAS) message sent by the terminal device to the fifth satellite, including: using the third security algorithm to provide security protection for the first uplink NAS message sent by the terminal device to the mobility management network element (MME) carried on the fifth satellite.
[0445] Figure 7 is a schematic flowchart of another communication method 700 provided in an embodiment of this application. The various operations of method 700 are described below with reference to Figure 7.
[0446] S710, the onboard MME of satellite #1 sends an attach accept message to UE #1.
[0447] The description of S710 above is the same as that in S510, and will not be repeated here.
[0448] S720, the onboard MME of satellite #1 sends UE-related information to the ground MME.
[0449] This UE-related information includes information about the security capabilities of UE#1. Specifically, the UE security capabilities can indicate the NAS security algorithms supported by UE#1.
[0450] In one possible implementation, the MME of satellite #1 can send UE-related information to the ground MME after receiving the UE's attach acceptance message. This UE-related information includes information about the security capabilities of UE #1, which may be initially reported by the UE and are susceptible to security attacks.
[0451] For example, this UE#1 security capability can be used for NAS security negotiation between terrestrial MMEs and satellite MMEs. The terrestrial MME can use this UE#1 security capability to conduct NAS security negotiation with satellites passing through the terrestrial MME.
[0452] For example, this UE#1 security capability can be used to verify the security of UE#1. For instance, during the NAS security negotiation process between UE#1 and satellite #1, this security capability can be verified as a genuine security capability reported by UE#1, and has not been subjected to security attacks.
[0453] Optionally, the UE-related information also includes information about NAS security algorithm #1. In this way, the ground MME can deduce the NAS key of satellite #1 based on NAS security algorithm #1, and thus indicate the NAS key to satellite #1; or, the ground MME can perform security protection or desecurity protection on NAS messages communicating with satellite #1 based on the information of NAS security algorithm #1.
[0454] Optionally, the UE-related information may also include at least one of the following: GUTI, data, or a monitoring list. See the preceding text for a detailed description (e.g., the description of S520), and it will not be repeated here.
[0455] S730, the ground MME sends UE-related information to the onboard MME on satellite #2.
[0456] The UE-related information may include the security capabilities of UE#1. Thus, the onboard MME of satellite #2 can select a NAS security algorithm (denoted as NAS security algorithm #2) based on these UE#1 security capabilities.
[0457] Optionally, the UE-related information may also include at least one of IMSI, GUTI, data (e.g., downlink data of UE#1), or key parameters.
[0458] Optionally, the ground MME can send UE-related information to the on-board MME on satellite #2 in one or more messages.
[0459] In some possible implementations, prior to S730, method 700 also includes: the ground MME determining that satellite #2 belongs to the monitoring list.
[0460] For example, the ground MME can determine whether each passing satellite, or in other words, whether each satellite with an available feed link to the ground MME, belongs to a monitoring list. If a satellite belongs to the monitoring list, the aforementioned UE-related information is sent to that satellite.
[0461] In some other possible implementations, the ground MME can send UE-related information to any passing satellite, or determine whether to send UE-related information to passing satellites through other means; this application does not impose any limitations on this.
[0462] S740, the onboard MME of satellite #2 selects NAS security algorithm #2 based on the security capabilities of UE #1. NAS security algorithm #2 is used for NAS secure communication between satellite #2 and UE #1.
[0463] S750, the onboard MME of satellite #2 obtains the NAS key based on NAS security algorithm #2.
[0464] In some examples, the onboard MME of satellite #2 already has key parameters, and satellite #2 can obtain the NAS key based on the key parameters and NAS security algorithm #2. For example, the key parameters can be obtained by satellite #2 from UE-related information in S730. Alternatively, the key parameters can be obtained by satellite #2 from other information.
[0465] In other examples, the NAS key is indicated by the ground-based MME. For instance, the onboard MME of satellite #2 can send a request message to the ground-based MME, which may carry information about the NAS security algorithm #2 (e.g., an identifier). The ground-based MME can then determine the NAS key based on this information and the key parameters. Furthermore, the ground-based MME can send the indication information of the NAS key to satellite #2.
[0466] S760, the onboard RAN of satellite #2 sends a broadcast message to UE #1.
[0467] For an example of S760, please refer to the previous description of S550, which will not be repeated here.
[0468] S770, UE#1 accesses the onboard RAN of satellite #2.
[0469] In some examples, UE#1 determines whether satellite #2 belongs to the monitoring list based on information about satellite #2 in the broadcast message. If satellite #2 belongs to the monitoring list, UE#1 can access satellite #2.
[0470] In other examples, UE#1 can directly access satellite #2. For instance, if UE#1 has not accessed a satellite in the monitoring list for a period of time, it can access satellite #2 that passes through UE#1.
[0471] S772, UE#1 sends its identifier to the onboard MME on satellite #2.
[0472] For example, the identifier of UE#1 may be a temporary mobile subscriber identity (TMSI) or other identifiers.
[0473] Optionally, the identifier of UE#1 can be carried in the access message; in other words, S772 can be executed during S770. For example, the identifier of UE#2 can be carried in message 3 (message 3, Msg3).
[0474] Optionally, the identifier of UE#1 can be carried in the uplink NAS message, and the identifier of UE#1 can be GUTI.
[0475] S774, the on-board MME on satellite #2 sends information (e.g., identifier) of NAS layer security algorithm #2 to UE #1.
[0476] Optionally, the information of the aforementioned NAS layer security algorithm #2 is carried in the access message; in other words, S774 can be executed during S770. For example, the information of the aforementioned NAS layer security algorithm #2 can be carried in message 4 (message 4, Msg4).
[0477] In some possible implementations, satellite #2 can determine the identifier of NAS layer security algorithm #2 corresponding to UE #1 based on the mapping relationship between the information of NAS layer security algorithm and the UE identifier (denoted as mapping relationship #1).
[0478] In some possible implementations, the onboard RAN of satellite #2 can obtain the above mapping relationship #1. For example, the above mapping relationship #1 can be obtained from the onboard MME of satellite #2 and the mapping relationship #1 can be indicated to the onboard RAN.
[0479] In some possible implementations, the onboard MME can determine the mapping relationship #1 based on the mapping relationship between the identifier of UE#1 (e.g., M-TMSI) included in the GUTI of UE-related information in S730 and the NAS layer security algorithm information.
[0480] Optionally, the identifier of UE#1 can be carried in the uplink NAS message, and the identifier of UE#1 can be GUTI.
[0481] In some possible implementations, the onboard MME obtains the mapping relationship between GUTI and NAS layer security algorithm, and determines the identifier of NAS layer security algorithm #2 corresponding to UE#1 based on the GUTI reported by UE#1.
[0482] S780, UE#1 determines the NAS key based on the information from NAS layer security algorithm #2.
[0483] In some examples, UE#1 can determine the NAS layer security algorithm #2 based on the information obtained from S774. Furthermore, UE#1 can generate a NAS key based on the NAS layer security algorithm #2 and the key parameters.
[0484] In other examples, if UE#1 does not obtain the NAS layer security algorithm, it performs NAS security negotiation with satellite #2. For instance, if UE#1's identifier is not within the range of mapping relationship #1 obtained by satellite #2, then satellite #2 cannot determine the NAS layer security algorithm based on UE#1's identifier. Thus, after UE#1 accesses satellite #2, since UE#1 has not obtained the NAS layer security algorithm, UE#1 can perform NAS security negotiation with satellite #2.
[0485] S790, UE#1 enables encryption and / or integrity protection for uplink NAS messages.
[0486] S792, UE#1 sends a NAS message to the onboard MME of satellite #2.
[0487] The description of S792 above is the same as that in S570 above, and will not be repeated here.
[0488] S794, the onboard MME of satellite #2 decrypts and / or verifies the integrity of the aforementioned NAS messages.
[0489] If the verification fails, satellite #2 can perform NAS security negotiation with UE #1. A description of S794 can be found in S580 above, and will not be repeated here.
[0490] S796, the onboard MME of satellite #2 sends a NASDL message to UE #1.
[0491] For example, the onboard MME of satellite #2 can send the aforementioned NASDL message to the onboard RAN of satellite #2, and then the onboard RAN of satellite #2 can send the aforementioned RRC DL message to UE #1. The NASDL information is carried within the RRC DL message.
[0492] In particular, the NASDL message may not carry downlink data of the UE, but instead be a response message.
[0493] S798, UE#1 decrypts and / or verifies the integrity of downlink NAS messages based on NAS security algorithm #2.
[0494] For example, UE#1 receives a downlink NAS message with security protection and enables downlink decryption and / or integrity verification.
[0495] For example, the UE can begin downlink decryption and / or integrity verification after sending the uplink NAS message, i.e., after sending S792.
[0496] For example, when the UE enables uplink encryption and / or integrity verification (S790), it simultaneously or subsequently enables downlink decryption and / or integrity verification.
[0497] Depending on the security requirements, Method 700 may use only encryption (and decryption) or integrity verification (and integrity verification), or it may use both encryption and integrity verification.
[0498] Based on the above scheme, the ground MME can send UE#1's security capabilities to satellite #2. Satellite #2 can then select the NAS security algorithm #2 for communication with UE#1 and obtain the NAS key based on these capabilities. This eliminates the need for UE#1 to report its capabilities to satellite #2 again. Furthermore, satellite #2 can reuse messages from random access to indicate the selected NAS security algorithm #2 to UE#1 without needing to send a NAS message. Therefore, this scheme reduces signaling interactions between UE#1 and the onboard MME. Additionally, this scheme allows uplink and downlink data transmission via NAS PDUs, supporting UE#1's need for rapid data transmission and reception.
[0499] Figure 8 is a schematic flowchart of a communication method 800 provided in an embodiment of this application. In method 800, the satellite can receive an instruction from the terminal device in the first NAS message and select a security algorithm, thereby saving the signaling overhead of establishing a secure connection between the terminal device and the satellite. Method 800 is described below with reference to Figure 8.
[0500] S810, the first satellite receives instruction information for the first security algorithm from the terminal-side equipment.
[0501] Optionally, the indication information of the first security algorithm is carried in the random access message.
[0502] Optionally, the indication information of the first security algorithm is carried in the first non-access stratum (NAS) message sent by the terminal device to the first satellite. This indication information of the first security algorithm can be protected for integrity and is not encrypted.
[0503] In some possible implementations, the terminal device can determine, as in S440, that the first satellite also uses the first security algorithm to securely communicate with the terminal device. See S440 for details, which will not be elaborated further.
[0504] S820, the first satellite uses the first security algorithm to protect the communication security between the first satellite and the terminal-side equipment.
[0505] In some possible implementations, S820 includes: enabling the decryption and / or integrity verification of NAS messages by the first satellite.
[0506] In some possible implementations, after the first satellite initiates the decryption and / or integrity verification of the NAS message, the method 800 further includes: S830, the first satellite receives the first uplink NAS message from the terminal device; S840, the first satellite decrypts and / or verifies the integrity of the first uplink NAS message.
[0507] In another possible implementation, the indication information of the first security algorithm is carried in the first Non-Access Stratum (NAS) message sent by the terminal device to the first satellite. The method 800 includes: S830, the first satellite receives the first uplink NAS message from the terminal device; the first satellite initiates decryption and / or integrity verification of the NAS message; S840, the first satellite decrypts and / or verifies the integrity of the first uplink NAS message.
[0508] In some possible implementations, the above S840 includes: if the first uplink NAS message is not protected for integrity, and / or if integrity verification of the first uplink NAS message fails, the first satellite discards the first uplink NAS message.
[0509] Other descriptions of method 800 (e.g., the operation of the terminal-side device and the ground network element) can be found in method 400, the difference being that in method 800, the first satellite receives indication information of the first security algorithm from the terminal-side device. Figure 9 is a schematic flowchart of another communication method 900 provided in an embodiment of this application. The various operations of method 900 are described below with reference to Figure 9.
[0510] S910, the onboard MME of satellite #1 sends an attach accept message to UE #1.
[0511] For a detailed description of S910, please refer to the aforementioned S510, which will not be repeated here.
[0512] S920, the onboard MME of satellite #1 sends UE-related information to the ground MME.
[0513] The UE-related information may include information about NAS security algorithm #1, UE #1 security capabilities, GUTI, data (e.g., uplink data of UE #1), or at least one item from the monitoring list.
[0514] S930, the ground MME sends UE-related information to satellite #2.
[0515] The UE-related information may include key parameters (e.g., K). ASME K AMF Or other parameters used to generate the NAS key).
[0516] Optionally, the UE-related information also includes at least one of the following: the identifier of NAS security algorithm #1, IMSI, GUTI, or data (e.g., downlink data of UE #1).
[0517] In some possible implementations, prior to S930, method 900 also includes: the ground MME determining that satellite #2 belongs to the monitoring list.
[0518] For example, the ground MME can determine whether each passing satellite, or in other words, whether each satellite with an available feed link to the ground MME, belongs to a monitoring list. If a satellite belongs to the monitoring list, the aforementioned UE-related information is sent to that satellite.
[0519] In some other possible implementations, the ground-based MME can send UE-related information to satellites belonging to the same satellite group.
[0520] In some other possible implementations, the ground MME can send UE-related information to any passing satellite, or determine whether to send UE-related information to passing satellites through other means; this application does not impose any limitations on this.
[0521] S940, the onboard RAN of satellite #2 sends a broadcast message to UE #1.
[0522] For a detailed description of S940, please refer to the aforementioned S540, which will not be repeated here.
[0523] S950, UE#1 accesses satellite #2.
[0524] In some examples, UE#1 determines whether satellite #2 belongs to the monitoring list based on information about satellite #2 in the broadcast message. If satellite #2 belongs to the monitoring list, UE#1 can access satellite #2.
[0525] In other examples, UE#1 can directly access satellite #2. For instance, if UE#1 has not accessed a satellite in the monitoring list for a period of time, it can access satellite #2 that passes through UE#1.
[0526] In some possible implementations, UE#1 and satellite #2 can perform a 4-step random access process to enable UE#1 to access satellite #2.
[0527] In some other possible implementations, UE#1 and satellite #2 can perform a two-step random access, thereby enabling UE#1 to access satellite #2.
[0528] S960, UE#1 sends information about NAS security algorithm #2 to satellite #2.
[0529] Among them, NAS security algorithm #2 is used for NAS secure communication between UE and satellite #2.
[0530] In some possible implementations, UE#1 can determine whether satellite #2 belongs to the same satellite group as satellite #1 (e.g., whether GUMMEI or GUAMF are consistent).
[0531] In some other possible implementations, UE#1 can determine whether the satellite group to which satellite #2 belongs (e.g., satellite group #1) has a NAS security algorithm obtained after NAS security negotiation.
[0532] If satellite #2 and satellite #1 belong to the same satellite group, or if satellite #2 belongs to a satellite group to which NAS security negotiation has been completed, UE #1 can determine the NAS key based on NAS security algorithm #2. This NAS key can be used for communication between UE #1 and satellite #2.
[0533] If satellite #2 and satellite #1 do not belong to the same satellite group, or if satellite #2 does not belong to the satellite group to which satellites that have completed NAS security negotiation belong, UE #1 can conduct NAS security negotiation with satellite #2.
[0534] The triggering condition of S960 can also be other conditions, for example, see S440, the way the terminal device determines the first security algorithm corresponding to the first satellite.
[0535] This application does not limit the execution order of S960. For example, the above-mentioned S960 can be executed after S950. As another example, the above-mentioned S960 can be executed after UE#1 enables encryption and / or integrity protection of uplink NAS messages.
[0536] In some possible implementations, the information of NAS security algorithm #2 in S960 can be carried in the NAS message sent by the UE. This information of NAS security algorithm #2 is not encrypted and has integrity protection.
[0537] In some possible implementations, UE#1 may enable decryption and / or integrity verification of downlink NAS messages before or after S960 execution.
[0538] S970, Satellite #2 determines the NAS key based on the information and key parameters of NAS security algorithm #2.
[0539] The NAS key is used for communication between satellite #2 and UE #1.
[0540] In some possible implementations, before or after S970, satellite #2 can enable decryption and / or integrity verification of uplink NAS messages. Satellite #2 can decrypt and / or verify the integrity of received NAS messages. If the integrity verification fails, satellite #2 can perform NAS security negotiation with UE #1.
[0541] S980, Satellite #2 sends a NAS message to UE #1.
[0542] For details, please refer to the descriptions in S590 and S595 above, which will not be repeated here.
[0543] Figure 10 is a schematic flowchart of a communication method 1000 provided in an embodiment of this application. In method 1000, the terminal device can obtain the mapping relationship between at least one satellite and at least one security algorithm before the first NAS message, and select the security algorithm corresponding to the satellite to be accessed, which can save the signaling overhead of establishing a secure connection between the terminal device and the satellite. Method 1000 is described below with reference to Figure 10.
[0544] S1050, the terminal device receives a broadcast message from a third satellite. This broadcast message includes the identifier of the third satellite.
[0545] S1060, the terminal device determines the second security algorithm based on the identifier of the third satellite and the first mapping relationship.
[0546] The first mapping relationship can be pre-acquired by the terminal device. This first mapping relationship can include a mapping between at least one satellite and at least one security algorithm. One satellite can correspond to one security algorithm. One security algorithm can correspond to one or more satellites. In other words, in the first mapping relationship, the number of satellites can be equal to or greater than the number of security algorithms; this application does not limit this.
[0547] The aforementioned at least one satellite may include the third satellite, and the aforementioned at least one security algorithm may include the second security algorithm.
[0548] This second security algorithm can correspond to the third satellite. The above example can be understood as the second security algorithm being used to protect the communication security between the terminal device and the third satellite.
[0549] In some possible implementations, prior to S1050, the method further includes: S1030, whereby the terminal device receives indication information of the first mapping relationship from the fourth satellite.
[0550] The fourth satellite can be a satellite that the terminal-side equipment accessed before S1050.
[0551] In some possible implementations, the terminal device can determine the second security algorithm by searching within the scope of the first mapping relationship based on the identifier of the third satellite.
[0552] S1070, the terminal device uses the second security algorithm to protect the communication security between the third satellite and the terminal device.
[0553] In some possible implementations, S1070 includes: the terminal device using the first security algorithm to provide security protection for the first uplink non-access stratum (NAS) message sent by the terminal device to the third satellite.
[0554] In some possible implementations, before using the first security algorithm to securely protect the first uplink NAS message sent by the terminal device to the first satellite, the method 1000 further includes: the terminal device enabling encryption and / or integrity protection for the NAS message.
[0555] In some possible implementations, the terminal device uses the first security algorithm to provide security protection for the first uplink non-access stratum (NAS) message sent by the terminal device to the third satellite, including: the terminal device uses the first security algorithm to provide security protection for the first uplink NAS message sent by the terminal device to the mobility management network element (MME) carried on the third satellite.
[0556] For a specific example of the above scheme, please refer to method 400, which will not be repeated here.
[0557] The following section presents examples of terrestrial network elements.
[0558] S1010, the ground network element obtains the first mapping relationship.
[0559] In some possible implementations, the ground network element can configure the first mapping relationship locally, or it can obtain the first mapping relationship from other network elements.
[0560] In some possible implementations, S1010 includes: the ground network element determining the at least one security algorithm based on the security capability information of the terminal-side device and a list of security algorithms for at least one satellite.
[0561] For example, a ground network element can determine the security algorithm corresponding to a satellite based on a list of security algorithms for that satellite and the security capability information of the terminal-side equipment.
[0562] S1020, the ground network element sends first information to the fourth satellite, which instructs the fourth satellite to send indication information of the first mapping relationship to the terminal device.
[0563] Furthermore, the fourth satellite can send the indication information of the first mapping relationship mentioned above to the terminal device.
[0564] In some possible implementations, prior to S1020, the method further includes: the ground network element determining the fourth satellite based on a monitoring list. This monitoring list can be used to indicate the satellites that the terminal device will subsequently access.
[0565] For example, a ground network element can determine whether the fourth satellite belongs to the monitoring list. If the information of the fourth satellite is within the scope of the monitoring list, the ground network element can execute S1020.
[0566] In some possible implementations, the method 1000 further includes: S1040, the ground network element sends the indication information of the second security algorithm to the third satellite, the second security algorithm being used to protect the communication security between the third satellite and the terminal-side device.
[0567] In some possible implementations, prior to S1040, the method 1000 further includes: the ground network element determining the third satellite based on a monitoring list, the monitoring list being used to indicate the satellites that the terminal-side device will subsequently access.
[0568] For example, a ground network element can determine whether a third satellite belongs to the monitoring list. If the information of the third satellite is within the scope of the monitoring list, the ground network element can execute S1040.
[0569] Furthermore, after executing S1040, the third satellite can enable at least one of the following: encryption, decryption, integrity protection, or integrity verification of NAS messages.
[0570] In some possible implementations, prior to S1040, the method 1000 further includes: the ground network element receiving the identifier of the third satellite from the third satellite; the ground network element determining the second security algorithm based on the identifier of the third satellite and the first mapping relationship.
[0571] The following is an example of a third satellite.
[0572] S1040, the third satellite receives indication information of the second security algorithm from the ground network element. Optionally, the third satellite also receives the identifier of the terminal-side device from the ground network element. In this way, the third satellite can determine that the second security algorithm corresponds to the terminal-side device.
[0573] S1045, the third satellite uses the second security algorithm to protect the communication security between the third satellite and the terminal-side equipment.
[0574] In some possible implementations, S1045 includes: enabling the decryption and / or integrity verification of non-access stratum (NAS) messages by the third satellite.
[0575] In some possible implementations, after the third satellite enables the decryption and / or integrity verification of the NAS message, the method 1000 further includes: S1080, the third satellite receives the first uplink NAS message from the terminal device; S1090, the third satellite decrypts and / or verifies the integrity of the first uplink NAS message.
[0576] In some possible implementations, S1090 includes: if the first uplink NAS message is not protected for integrity, and / or if integrity verification of the first uplink NAS message fails, the third satellite discards the first uplink NAS message.
[0577] In some possible implementations, before the third satellite enables encryption and / or integrity protection of non-access stratum (NAS) messages, the method 1000 further includes: the third satellite determining a second NAS key based on the second security algorithm; or, the third satellite receiving information related to the second NAS key from the ground network element; wherein the second NAS key is used to decrypt and / or verify the integrity of NAS messages.
[0578] For a description of information related to NAS keys, please refer to the previous text; it will not be repeated here.
[0579] Figure 11 is a schematic flowchart of another communication method 1100 provided in an embodiment of this application. The various nodes of method 1100 are described below with reference to Figure 11.
[0580] S1110, Satellite #1 sends a broadcast message to UE #1.
[0581] For an example of S1110 above, please refer to the aforementioned S540, which will not be repeated here.
[0582] S1112, UE#1 sends an attach request message to satellite #1.
[0583] The attach request message may include the UE#1 identifier (e.g., IMSI), S&F capabilities, and UE#1 security capabilities.
[0584] Among them, S&F capability can be used to indicate that the UE supports the S&F architecture. UE#1 security capability can indicate the security algorithms supported by UE#1.
[0585] S1114, Satellite #1 sends an attach rejection message to UE #1.
[0586] The attached rejection message may include the waiting time and the monitoring list.
[0587] For example, if satellite #1 does not have a UE #1 context, satellite #1 can execute the above S1114.
[0588] When satellite #1 has the security context of UE #1, satellite #1 can send an attach accept message to UE #1.
[0589] The following description uses the case of UE#1 without a security context as an example.
[0590] S1120, Satellite #1 sends an attach request message to the ground MME.
[0591] The attach request message may be sent by UE#1 in S1112 above. S1120 above can also be understood as satellite #1 forwarding the attach request message from UE#1 to the ground MME.
[0592] S1124, the ground-based MME determines the NAS security algorithm for the P on-board MMEs based on the security capabilities of UE#1 and the list of NAS security algorithms for the P on-board MMEs. Here, P is a positive integer.
[0593] Each on-board MME can correspond to one NAS security algorithm. That is, P on-board MMEs can each correspond to P NAS security algorithms.
[0594] Onboard MMEs on different satellites may correspond to different NAS security algorithms or the same NAS security algorithm; this application does not impose any limitations. In other words, in the above description (denoted as, description 1), two onboard MMEs among the P onboard MMEs may each correspond to two identical NAS security algorithms among the P NAS security algorithms.
[0595] In another formulation (denoted as Formulation 2), P on-board MMEs can correspond to Q NAS security algorithms. Here, Q can be a positive integer less than or equal to P. As an example, one on-board MME among the P on-board MMEs can correspond to multiple NAS security algorithms among the Q NAS security algorithms. As another example, one NAS security algorithm among the Q NAS security algorithms can correspond to multiple on-board MMEs on the P on-board MMEs.
[0596] In other words, this application does not limit the number of correspondences between P on-board MMEs and Q NAS security algorithms; they can be one-to-one, one-to-many, or many-to-one.
[0597] For ease of understanding and description, the following description will take P on-board MMEs corresponding to P NAS security algorithms (i.e., Statement 1) as an example.
[0598] In some examples, the ground-based MME can pre-obtain a list of NAS security algorithms for P on-board MMEs. For instance, the ground-based MME can obtain the list of NAS security algorithms for P on-board MMEs from OAM or from on-board MMEs of different satellites. Alternatively, the ground-based MME can locally configure the aforementioned list of NAS security algorithms for the P on-board MMEs. The ground-based MME can also obtain more NAS security algorithm lists from on-board MMEs; this application does not limit this.
[0599] Information from some or all of the above P on-board MMEs can be included in the monitoring list of UE#1.
[0600] For example, the P on-board MMEs can be all the on-board MMEs in the monitoring list of UE#1. In some possible implementations, the above S1124 may include: the ground MME determining the NAS security algorithm of the P on-board MMEs in the monitoring list of UE#1 based on the security capabilities of UE#1, the monitoring list of UE#1, and the NAS security algorithm list of the P on-board MMEs in the monitoring list of UE#1.
[0601] In some examples, the ground MME can generate a monitoring list for UE#1 based on UE#1's location and ephemeris information (e.g., including satellite orbit information).
[0602] In other examples, the onboard MME of satellite #1 can generate a monitoring list for UE #1 based on UE #1's location and ephemeris information. Satellite #1 can then transmit the indication information of this monitoring list to the ground MME.
[0603] In other examples, the ground-based MME can obtain the monitoring list of UE#1 from other network elements. For example, the aforementioned "other network elements" could be network elements used to predict satellite orbits or network elements that maintain ephemeris information.
[0604] This application does not limit the method by which the ground MME obtains the monitoring list of UE#1. The ground MME can also obtain the monitoring list of UE#1 through other methods.
[0605] For example, some of the P on-board MMEs can be all the on-board MMEs in UE#1's monitoring list. In other words, the P on-board MMEs are not limited to the on-board MMEs in UE#1's monitoring list; that is, the P on-board MMEs can extend beyond the scope of UE#1's monitoring list. For example, the satellites in UE#1's monitoring list are satellites capable of covering a first region, where UE#1 is located in the first region. The P on-board MMEs can be satellites capable of covering a second region, where UE#1 is located in the second region, and the second region includes the first region. The area of the second region can be larger than that of the first region.
[0606] In other words, the ground MME can select only the NAS security algorithm corresponding to the satellite in the monitoring list of UE#1, or it can select the NAS security algorithm corresponding to other satellites that UE#1 may access.
[0607] In some possible implementations, prior to S1124, method 1100 further includes: the ground MME sending an authentication data request (carrying the IMSI of UE#1) to the HSS; and the HSS sending an authentication data response (carrying an authentication vector (AV) and UE subscription information) to the ground MME.
[0608] Among them, AV vectors can be used for authentication.
[0609] In some possible implementations, prior to S1124, method 1100 also includes: ground MME storage K ASME and eKSI. eKSI can be used to identify K. ASME For example, a ground-based MME can store multiple K... ASME A single eKSI can indicate multiple Ks mentioned above. ASME One of the K ASME .
[0610] S1126, the ground MME sends the NAS security algorithm information of P on-board MMEs to the on-board MME of satellite #1.
[0611] In some possible implementations, the ground-based MME also sends UE subscription information and K to the onboard MME of satellite #1. ASME At least one of eKSI or IMSI. UE subscription information includes information such as the slices and networks supported by the UE. ASME It can be used to derive NAS keys; eKSI is used to identify K. ASME IMSI can be a permanent identifier for a user.
[0612] In one possible implementation, the ground-based MME sends P satellite identifiers and their corresponding NAS security algorithm information to satellite #1.
[0613] In S1126, satellite #1 can also be replaced by other satellites (e.g., satellite #3), so that the related operations in S1130 below can be the interaction between satellite #3 and UE #1.
[0614] S1130, Satellite #1 sends P NAS security algorithm information of on-satellite MMEs to UE #1.
[0615] In one possible implementation, satellite #1 sends P satellite identifiers and their corresponding NAS security algorithm information to UE #1.
[0616] In some possible implementations, UE#1 can store the mapping relationship between satellite identifiers and NAS security algorithm identifiers (denoted as mapping relationship #2) based on the NAS security algorithm information of at least one on-board MME. For example, if P on-board MMEs belong to satellite a, satellite b, and satellite c respectively (assuming P = 3), the identifier of satellite a can correspond to NAS security algorithm #a; the identifier of satellite b can correspond to NAS security algorithm #b; and the identifier of satellite c can correspond to NAS security algorithm #c. For example, the satellites corresponding to NAS security algorithm #a include satellite a, satellite d, and satellite e.
[0617] Optionally, the NAS security algorithm information in S1130 is transmitted after being encrypted and / or fully protected.
[0618] In some possible implementations, before S1130, authentication and authorization can be completed interactively between satellite #1 and UE #1.
[0619] If UE#1 does not store mapping relationship #2, UE#1 can perform NAS security negotiation with satellite #1.
[0620] For example, satellite #1 and UE #1 can select NAS security algorithm #1 and complete the verification of the security capabilities of UE #1.
[0621] In some examples, the information about the NAS security algorithm of the aforementioned P on-board MMEs can be carried in the NAS security mode completion message.
[0622] In some examples, the NAS security algorithm information for the P on-board MMEs mentioned above can be carried in the attach accept message or other downlink NAS messages. Optionally, the attach accept information may also include other information, such as GUTI, monitoring list, or wait time. See the description in S510 above for details, which will not be repeated here.
[0623] In some examples, the P NAS security algorithm information corresponds to P satellites in a monitoring list. The attached receive message may include a monitoring list, which may include a mapping between the identifiers of the P satellites and the identifiers of the P NAS security algorithms.
[0624] In other examples, the satellites corresponding to the P NAS security algorithm information are not limited to those in the monitoring list. The attach accept message may include a mapping between the identifiers of the P satellites and the identifiers of the P NAS security algorithms. This mapping may be independent of the monitoring list; in other words, the attach accept message may include the monitoring list (including the identifier of at least one satellite) and the mapping described above.
[0625] This application does not limit the message carried by the mapping relationship between the identifiers of the P satellites and the identifiers of the P NAS security algorithms. For example, the mapping relationship can be carried in other NAS messages, such as TA Update (TAU) accept messages or downlink messages in NAS security negotiation (e.g., NAS security mode completion messages).
[0626] For example, satellite #1 in S1130 above can be replaced with other satellites (e.g., satellite #3).
[0627] S1150, Ground MME sends UE-related information to satellite #2.
[0628] Among them, UE-related information may include information about NAS security algorithm #2.
[0629] In some possible implementations, the ground-based MME can determine the NAS security algorithm corresponding to satellite #2 (denoted as NAS security algorithm #2) based on the correspondence between P on-board MMEs and P NAS security algorithms (i.e., mapping relationship #2).
[0630] Furthermore, in some possible implementations, the ground MME can execute the above-mentioned S1150, and the UE-related information may include NAS security algorithm #2. The satellite #2 can determine the NAS key based on NAS security algorithm #2.
[0631] Optionally, the UE-related information may also include at least one of the following: IMSI, GUTI, data (e.g., downlink data of UE#1), key parameters, NAS key, or UE subscription information.
[0632] In some possible implementations, prior to S1150, method 1100 also includes: the ground MME determining that satellite #2 belongs to the monitoring list.
[0633] For example, the ground MME can determine whether each passing satellite, or in other words, whether each satellite with an available feed link to the ground MME, belongs to a monitoring list. If a satellite belongs to the monitoring list, the aforementioned UE-related information is sent to that satellite.
[0634] In some other possible implementations, the ground MME can send UE-related information to any passing satellite, or determine whether to send UE-related information to passing satellites through other means; this application does not impose any limitations on this.
[0635] This application does not limit the execution order of S1130 and S1150. For example, S1130 can be executed before or after S1150, or they can be executed simultaneously. In some possible implementations, if the feed link between the ground MME and satellite #2 is available, the ground MME can execute S1150.
[0636] After obtaining the NAS key from satellite #2, encryption and / or integrity verification of downlink NAS messages, as well as decryption and / or integrity verification of uplink NAS messages, can be enabled.
[0637] S1160, the onboard RAN of satellite #2 sends a broadcast message to UE #1.
[0638] For details, please refer to the description in S540, which will not be repeated here.
[0639] S1165, UE#1 accesses satellite #2.
[0640] In some examples, UE#1 determines whether satellite #2 belongs to the monitoring list based on information about satellite #2 in the broadcast message. If satellite #2 belongs to the monitoring list, UE#1 can access satellite #2.
[0641] In other examples, UE#1 can directly access satellite #2. For instance, if UE#1 has not accessed a satellite in the monitoring list for a period of time, it can access satellite #2 that passes through UE#1. Or, for another example, UE#1 can directly access satellite #2 without going through any other decision-making steps.
[0642] In some possible implementations, UE#1 and satellite #2 can perform a 4-step random access process to enable UE#1 to access satellite #2.
[0643] In some other possible implementations, UE#1 and satellite #2 can perform a two-step random access, thereby enabling UE#1 to access satellite #2.
[0644] S1170, UE#1 determines the NAS key according to NAS security algorithm #2.
[0645] For example, UE#1 can determine the NAS security algorithm (i.e., NAS security algorithm #2) corresponding to satellite #2 based on the information of satellite #2 received by S1160 and the mapping relationship #2. UE#1 can then generate a NAS key based on NAS security algorithm #2.
[0646] In some possible implementations, after obtaining the NAS key, UE#1 can enable encryption and / or integrity protection of uplink NAS messages.
[0647] In some other possible implementations, if UE#1 does not obtain the NAS security algorithm (e.g., satellite #2 is not within the range of the pre-obtained mapping relationship #2), then UE#1 can negotiate NAS security with satellite #2.
[0648] This application does not limit the execution order between S1160 and S1170. For example, S1160 can be executed before or after S1170, or they can be executed simultaneously. In some possible implementations, after receiving the mapping relationship #2 between P satellites and P NAS security algorithms, UE#1 can determine different NAS keys according to different NAS security algorithms. In this way, after UE#1 accesses satellite #2, UE#1 does not need to generate a NAS key and can directly enable encryption and / or integrity protection of uplink NAS messages.
[0649] S1180, UE#1 sends a NAS message to satellite #2.
[0650] In some possible implementations, after S1180, UE#1 can enable decryption and / or integrity verification of downlink NAS messages.
[0651] In some other possible implementations, after S1170, UE#1 may enable decryption and / or integrity verification of downlink NAS messages.
[0652] In some other possible implementations, UE#1 may enable decryption and / or integrity verification of downlink NAS messages after receiving them.
[0653] S1182, the onboard MME of satellite #2 decrypts and / or verifies the integrity of the aforementioned NAS message.
[0654] If the security verification fails, satellite #2 can negotiate NAS security with UE #1.
[0655] S1184, Satellite #2 sends a NAS message to UE #1.
[0656] The NAS message in S1184 above can also be called a downlink NAS message. For example, the on-board MME of satellite #2 can send the downlink NAS message to the on-board RAN of satellite #2, and then the on-board RAN of satellite #2 can send the RRC DL message (including the downlink NAS message) to UE #1.
[0657] S1186, UE#1 decrypts and / or verifies the integrity of the aforementioned NAS PDU based on NAS security algorithm #2.
[0658] Depending on the security requirements, method 1100 may use only encryption (and decryption) or integrity verification (and integrity verification), or it may use either encryption or integrity verification.
[0659] The following describes the apparatus embodiments corresponding to the method embodiments of this application. Only a brief description of the apparatus is provided below; for specific implementation steps and details, please refer to the preceding method embodiments.
[0660] To achieve the functions of the methods provided in this application, the communication device may include hardware structures and / or software modules, implementing the aforementioned functions in the form of hardware structures, software modules, or a combination of hardware structures and software modules. Whether a particular function is implemented in the form of hardware structures, software modules, or a combination of hardware structures and software modules depends on the specific application and design constraints of the technical solution.
[0661] Figure 12 is a schematic block diagram of a communication device 1000 according to an embodiment of this application. The communication device 1000 includes a processor 1010 and a communication interface 1020. Optionally, the processor 1010 and the communication interface 1020 can be interconnected via a bus. The communication device 1000 can be a terminal-side device, a first satellite, a ground network element, a third satellite, or a fifth satellite.
[0662] Optionally, the communication device 1000 may further include a memory 1040. The memory 1040 includes, but is not limited to, random access memory (RAM), read-only memory (ROM), cache, erasable programmable read-only memory (EPROM), synchronous dynamic random access memory (SDRAM), hard disk drive (HDD), solid-state drive (SSD), or compact disc read-only memory (CD-ROM). The memory 1040 is used to store related instructions and / or data. The memory 1040 may be integrated with the processor 1010 or disposed separately.
[0663] Processor 1010 may include one or more of the following: central processing unit (CPU), application-specific integrated circuit (ASIC), digital signal processor (DSP), microprocessor unit (MPU), microcontroller unit (MCU), GPU, field-programmable gate array (FPGA), artificial intelligence processor (AI processor), or neural processing unit (NPU). If processor 1010 is a CPU, it can be a single-core CPU or a multi-core CPU. However, this application is not limited in this respect; processor 1010 may also be one or more GPUs, or one or more tensor processing units (TPUs). Processor 1010 may be a signal processor, a chip, or other integrated circuit capable of implementing the methods of this application, or a portion of the circuitry within the aforementioned processor, chip, or integrated circuit used for processing functions. Additionally, communication interface 1020 may be an input / output interface, used for inputting or outputting signals or data, or it may be an input / output circuit.
[0664] For example, the communication device 1000 is a terminal-side device, and the processor 1010 is configured to perform the following operations: receive a broadcast message from a first satellite; determine a first security algorithm corresponding to the first satellite based on the broadcast message; and use the first security algorithm to protect the communication security between the first satellite and the terminal-side device; wherein the first security algorithm is negotiated and selected by the terminal-side device with a second satellite before receiving the broadcast message from the first satellite.
[0665] For example, the communication device 1000 is a first satellite, and the processor 1010 is used to perform the following operations: receive instruction information of a first security algorithm and the identifier of a terminal-side device from a ground network element, the ground network element being a core network element located on the ground; and use the first security algorithm to protect the communication security between the first satellite and the terminal-side device.
[0666] For example, the communication device 1000 is a terrestrial network element, and the processor 1010 is used to perform the following operations: obtain a first security algorithm from a second satellite, wherein the first security algorithm is selected by the terminal device in consultation with the second satellite; send instruction information of the first security algorithm to the first satellite, wherein the first security algorithm is used to protect the communication security between the first satellite and the terminal device.
[0667] For example, the communication device 1000 is a first satellite, and the processor 1010 is used to perform the following operations: receive instruction information of a first security algorithm from a terminal-side device; and use the first security algorithm to protect the communication security between the first satellite and the terminal-side device.
[0668] For example, the communication device 1000 is a terminal-side device, and the processor 1010 is configured to perform the following operations: receive a broadcast message from a third satellite, the broadcast message including the identifier of the third satellite; determine a second security algorithm based on the identifier of the third satellite and a first mapping relationship, wherein the first mapping relationship includes a mapping relationship between at least one satellite and at least one security algorithm, the at least one satellite including the third satellite, the at least one security algorithm including the second security algorithm, and the second security algorithm corresponding to the third satellite; and use the second security algorithm to protect the communication security between the third satellite and the terminal-side device.
[0669] For example, the communication device 1000 is a terrestrial network element, and the processor 1010 is used to perform the following operations: obtain a first mapping relationship, which includes a mapping relationship between at least one satellite and at least one security algorithm; send first information to a fourth satellite, which is used to instruct the fourth satellite to send indication information of the first mapping relationship to the terminal device, and the at least one security algorithm is used to protect the communication security between the at least one satellite and the terminal device.
[0670] For example, the communication device 1000 is a third satellite, and the processor 1010 is used to perform the following operations: receive instruction information of the second security algorithm and the identifier of the terminal device from a ground network element, the ground network element being a core network element located on the ground; and use the second security algorithm to protect the communication security between the third satellite and the terminal device.
[0671] For example, the communication device 1000 is a fifth satellite, and the processor 1010 is used to perform the following operations: before receiving the first non-access stratum (NAS) message from the terminal-side device, send an indication of a third security algorithm to the terminal-side device; use the third security algorithm to protect the communication security between the fifth satellite and the terminal-side device; wherein the third security algorithm is negotiated and selected between the ground network element and the third satellite.
[0672] For example, the communication device 1000 is a terrestrial network element, and the processor 1010 is used to perform the following operations: obtain security capability information of the terminal-side device; send the security capability information of the terminal-side device to the fifth satellite, wherein the security capability information of the terminal-side device is used to determine a security algorithm for security protection of the communication between the fifth satellite and the terminal-side device.
[0673] For example, the communication device 1000 is a terminal-side device, and the processor 1010 is used to perform the following operations: before sending the first non-access stratum NAS message, receive indication information of the third security algorithm from the fifth satellite; and use the third security algorithm to protect the communication security between the fifth satellite and the third terminal-side device.
[0674] The above description is for illustrative purposes only. The communication device 1000 is responsible for executing the methods or steps related to the terminal-side device, the first satellite, the ground network element, the third satellite, or the fifth satellite in the aforementioned method embodiments.
[0675] In one possible implementation, the communication interface 1020 can be a transceiver. The transceiver may include a transmitter and a receiver, with the transmitter performing a transmission operation and the receiver performing a reception operation. For example, the processor 1010 is used to control the transceiver to receive and / or transmit signals.
[0676] In one possible implementation, the communication interface 1020 can also be a communication circuit, pins, input / output interfaces, bus, etc.
[0677] It should be noted that the communication device 1000 may include a transmitter but not a receiver. Alternatively, the communication device 1000 may include a receiver but not a transmitter. Specifically, it depends on whether the above-described scheme performed by the communication device 1000 includes both transmitting and receiving actions.
[0678] The above description is merely exemplary. For details, please refer to the methods illustrated in the above embodiments. The implementation of each operation in Figure 12 can also be found in the corresponding descriptions of the methods illustrated in Figures 4 to 11.
[0679] For example, the communication device 1000 can be used to execute the scheme shown in Figures 4 to 11.
[0680] For example, the communication device 1000 is a terminal-side device, and the communication interface 1020 can be used to receive a first reference signal, etc.
[0681] For example, the communication device 1000 is a first satellite, a ground network element, a third satellite, or a fifth satellite, and the communication interface 1020 can be used to transmit a first reference signal, etc.
[0682] For details on other implementation methods, please refer to the detailed descriptions of the embodiments shown in Figures 4 to 11 above, which will not be repeated here. It should be understood that the specific processes by which each component performs the corresponding processes described above have been described in detail in the above method embodiments, and will not be repeated here for the sake of brevity.
[0683] Figure 13 is a schematic block diagram of another communication device 1100 according to an embodiment of this application. The communication device 1100 can be a terminal-side device, a first satellite, a ground network element, a third satellite, or a fifth satellite, or it can be a chip or module in the terminal-side device, the first satellite, the ground network element, the third satellite, or the fifth satellite, used to implement the methods involved in the embodiments shown in Figures 4 to 11. Please refer to the relevant descriptions in the above method embodiments for details.
[0684] The communication device 1100 includes a transceiver unit 1110 and a processing unit 1120. The transceiver unit 1110 will be described exemplarily below.
[0685] The transceiver unit 1110 may include a sending unit and a receiving unit. The sending unit is used to perform the sending action of the communication device, and the receiving unit is used to perform the receiving action of the communication device. For ease of description, the sending unit and the receiving unit are combined into one transceiver unit in this embodiment. This will be explained uniformly here and will not be repeated later. The transceiver unit 1110 can implement the corresponding communication functions. The transceiver unit 1110 may also be referred to as a communication interface or a communication module.
[0686] The communication device 1100 may include a transmitting unit but not a receiving unit. Alternatively, the communication device 1100 may include a receiving unit but not a transmitting unit. Specifically, it depends on whether the above-described scheme performed by the communication device 1100 includes both transmitting and receiving actions.
[0687] The above description is for illustrative purposes only. The communication device 1100 will be responsible for executing the relevant methods or steps in the foregoing method embodiments.
[0688] Optionally, the communication device 1100 further includes a storage unit 1130 for storing programs or code for executing the aforementioned methods. Alternatively, the storage unit 1130 can store instructions and / or data, and the processing unit 1120 can read the instructions and / or data from the storage unit 1130 to enable the communication device 1100 to implement the aforementioned method embodiments. For example, the communication device 1100 can be used to execute the schemes shown in Figures 4 to 11.
[0689] For example, the transceiver unit 1110 can be used to receive a broadcast message from the first satellite; the processing unit 1120 can be used to determine a first security algorithm corresponding to the first satellite based on the broadcast message; the processing unit 1120 can be used to use the first security algorithm to protect the communication security between the first satellite and the terminal device; wherein, the first security algorithm is negotiated and selected by the terminal device with the second satellite before receiving the broadcast message from the first satellite.
[0690] For details on other implementation methods, please refer to the detailed descriptions of the embodiments shown in Figures 4 to 11 above, which will not be repeated here. The specific processes by which each component performs the corresponding processes described above have been described in detail in the above method embodiments, and will not be repeated here for the sake of brevity.
[0691] When the communication device 1000 in Figure 12 is a chip, the communication interface 1020 can be a transceiver, input / output circuit, or communication interface of the chip. The processor 1010 can be a processor integrated on the chip, a microprocessor, or an integrated circuit. In the above method embodiments, the transmission operations of the terminal-side device, the first satellite, the ground network element, the third satellite, or the fifth satellite can be understood as the output of the chip, and the reception operations of the terminal-side device, the first satellite, the ground network element, the third satellite, or the fifth satellite in the above method embodiments can be understood as the input of the chip.
[0692] When the communication device 1100 in Figure 13 is a chip, the transceiver unit 1110 can be a transceiver, input / output circuit, or communication interface of the chip. The processing unit 1120 can be a processor, microprocessor, or integrated circuit integrated on the chip. In the above method embodiments, the transmission operations of the terminal-side device, the first satellite, the ground network element, the third satellite, or the fifth satellite can be understood as the output of the chip, and the reception operations of the terminal-side device, the first satellite, the ground network element, the third satellite, or the fifth satellite in the above method embodiments can be understood as the input of the chip.
[0693] Figure 14 is an exemplary block diagram of another communication device 10 provided in an embodiment of this application.
[0694] As shown in FIG14, for example, the communication device 10 may include a chip system 110, a memory 120, a bus 130, a power management module 140, or a transceiver 150, etc.
[0695] The chip system 110 can be an integrated circuit chip with signal processing capabilities. In implementation, each step of the above method can be completed through integrated logic circuits in the hardware of the chip system 110 or through software instructions.
[0696] By way of example and not limitation, chip system 110 may include circuitry or chips responsible for signal processing (such as a modem chip, also known as a baseband chip, or a system-on-chip (SoC) chip or system-in-package (SIP) chip containing a modem core).
[0697] Optionally, the chip system 110 may also include a memory (such as a cache) for storing instructions and data. In some embodiments, the memory in the chip system 110 is a cache memory. This memory can store instructions or data that the chip system 110 has just used or that are used repeatedly. If the chip system 110 needs to use the instruction or data again, it can directly retrieve it from the memory. This avoids repeated accesses, reduces the waiting time of the chip system 110, and thus improves the efficiency of the system.
[0698] In some embodiments, the chip system 110 may include one or more interfaces. Interfaces may include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface, etc.
[0699] Memory 120 may include RAM and ROM. Memory 120 may store computer-readable, computer-executable code, including instructions that, when executed, cause the processor to perform the various functions described in this application.
[0700] Optionally, the code may include instructions for implementing various aspects of the embodiments of this application. The code may be stored in a non-transitory computer-readable medium such as system memory or other types of memory. In some cases, the code may not be directly executable by the chip system 110, but may instead enable a computer (e.g., at compile and execution time) to perform the functions described in this application. In some cases, memory 120 may contain a basic I / O system that controls basic hardware or software operations, such as interaction with peripheral components or devices.
[0701] For example, the chip system 110 executes various functional applications and data processing of the communication device 10 by running instructions stored in the memory 120. For instance, when the communication device 10 transfers files with other devices (which may also be terminals or network devices), the chip system 110 of the communication device 10 can call the computer-executable program code stored in the memory 120 to implement the communication method provided in the embodiments of this application.
[0702] In addition, the memory 120 can be integrated into the chip system 110 or independent of the chip system 110.
[0703] For example, bus 130 may be USB for supporting communication between various parts of communication device 10.
[0704] The power management module 140 is used to receive charging input from the charger. Optionally, the power management module 140 can also supply power to the communication device 10 while charging it (e.g., the battery module of the communication device 10). By way of example and not limitation, the power management module 140 can also supply power to other devices besides the communication device 10.
[0705] Transceiver 150 can communicate bidirectionally via one or more antennas, wired links, or wireless links. For example, transceiver 150 can represent a wireless transceiver and can communicate bidirectionally with another wireless transceiver. Transceiver 150 may also include a modem for modulating packets and providing the modulated packets to the antenna for transmission, and for demodulating packets received from the antenna. Transceiver 150 may include a receiver and a transmitter, the receiver performing the function of receiving information and the transmitter performing the function of transmitting information.
[0706] In some cases, a wireless device may include a single antenna. However, in other cases, the device may have more than one antenna, such as antenna 1 and antenna 2 shown in FIG. 14, which may be capable of simultaneously transmitting or receiving multiple wireless transmissions. Exemplarily, antenna 1 and antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in communication device 10 can be used to cover one or more communication frequency bands. Different antennas can also be multiplexed to improve antenna utilization. For example, antenna 1 can be multiplexed as a diversity antenna for a wireless local area network. In other embodiments, the antennas can be used in conjunction with a tuning switch. Communication device 10 can transfer files to other devices via wireless communication functions.
[0707] In one design, the communication device 10 may correspond to the terminal-side device in the above method embodiments.
[0708] The device 10 can implement the steps or processes corresponding to those executed by the terminal-side device in the above method embodiments, wherein the transceiver 150 can be used to perform the transmission and reception related operations of the terminal-side device in the above method embodiments; and the chip system 110 can be used to perform the processing related operations of the terminal-side device in the above method embodiments.
[0709] In another design, the communication device 10 may correspond to the first satellite in the above method embodiment. The device 10 may implement the steps or processes performed by the first satellite in the above method embodiment, wherein the transceiver 150 may be used to perform the transmission and reception related operations of the first satellite in the above method embodiment; and the chip system 110 may be used to perform the processing related operations of the first satellite in the above method embodiment.
[0710] In another design, the communication device 10 may correspond to the terrestrial network element in the above method embodiments. The device 10 can implement the steps or processes performed by the terrestrial network element in the above method embodiments, wherein the transceiver 150 can be used to perform the transmission and reception related operations of the terrestrial network element in the above method embodiments; and the chip system 110 can be used to perform the terrestrial network element in the above method embodiments.
[0711] In another design, the communication device 10 may correspond to the third satellite in the above method embodiments. The device 10 can implement the steps or processes performed by the third satellite in the above method embodiments, wherein the transceiver 150 can be used to perform the transmission and reception related operations of the third satellite in the above method embodiments; and the chip system 110 can be used to perform the processing related operations of the third satellite in the above method embodiments.
[0712] In another design, the communication device 10 may correspond to the fifth satellite in the above method embodiments. The device 10 can implement the steps or processes performed by the fifth satellite in the above method embodiments, wherein the transceiver 150 can be used to perform the transmission and reception related operations of the fifth satellite in the above method embodiments; and the chip system 110 can be used to perform the processing related operations of the fifth satellite in the above method embodiments.
[0713] In some possible implementations, the communication device 10 may be a terminal-side device. For example, the communication device 10 may include modules such as the short-range communication module 164, sensor 161, display 162, or camera 163 as shown in FIG14.
[0714] The short-range communication module 164 may include modules that support short-range communication, such as Wi-Fi and Bluetooth.
[0715] For example, sensor 161 may include pressure sensor, gyroscope sensor, barometric pressure sensor, magnetic sensor, accelerometer, distance sensor, proximity sensor, fingerprint sensor, temperature sensor, touch sensor, ambient light sensor, bone conduction sensor, etc.
[0716] For example, display 162 is used to display images, videos, etc. The display includes a display panel. The display panel may be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a mini light-emitting diode (LED), a micro LED, a micro OLED, a quantum dot light-emitting diode (QLED), etc. For example, in this embodiment, the display can be used to display the interface required by the communication device 10. For example, the communication device 10 implements display functions through a GPU, a display, and an application processor. The GPU is a microprocessor for image processing, connected to the display and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. The chip system 110 may include one or more GPUs that execute program instructions to generate or modify display information.
[0717] For example, camera 163 is used to acquire images, videos, etc.
[0718] It is understood that the structure shown in Figure 14 does not constitute a specific limitation on the communication device 10, and the specific structure of the terminal device and / or network device can be referred to Figure 14. In some embodiments, the communication device 10 may also include more or fewer components than shown in Figure 14, or combine some components, or split some components, or have different component arrangements, etc. Alternatively, some components shown in Figure 14 may be implemented in hardware, software, or a combination of software and hardware, and the terminal device and / or network device may add or remove components based on the structure given in Figure 14.
[0719] Figure 15 is a schematic block diagram of another communication device 20 provided in an embodiment of this application.
[0720] As shown in Figure 15, the communication device 20 may include a baseband unit 210, which can communicate with external devices via a cellular radio frequency (RF) transceiver 220 (e.g., if the communication device 20 is a terminal device, the baseband unit 210 can communicate with network devices or terminal devices via the cellular RF transceiver 220; or, if the communication device 20 is a network device, the baseband unit 210 can communicate with terminal devices and / or core network devices via the cellular RF transceiver 220).
[0721] Exemplarily, baseband unit 210 may include a computer-readable medium / memory. Baseband unit 210 may be responsible for general processing, including the execution of software stored on the computer-readable medium / memory. When executed by baseband unit 304, the software causes baseband unit 210 to perform the various functions described above. The computer-readable medium / memory may also be used to store data manipulated by baseband unit 210 during software execution.
[0722] Optionally, the baseband unit 210 further includes a receiving unit 201, a management unit 202, and a transmitting unit 203. The management unit 202 includes one or more sub-units shown in FIG. 15 (e.g., a NAS security protection sub-unit, wherein the NAS security protection sub-unit can be used for the operation of security protection of the first NAS message in the above method embodiments). Units within the management unit 201 can be stored in a computer-readable medium / memory and / or configured as hardware within the baseband unit 210. The receiving unit 201 and the transmitting unit 203 can be referred to as transceiver units.
[0723] When the communication device 20 is used to implement the functions of the terminal-side device in the above method embodiments, the receiving unit 201 is used to execute the receiving step of the terminal-side device, the sending unit 203 is used to execute the sending step of the terminal-side device, and the management unit 202 is used to execute the processing step of the terminal-side device. The management unit 202 may also be called a processing unit or other names, which are not limited in this application.
[0724] For example, the receiving unit 201 is used to receive a broadcast message from the first satellite; the management unit 202 is used to determine a first security algorithm corresponding to the first satellite based on the broadcast message; the management unit 202 is used to use the first security algorithm to protect the communication security between the first satellite and the terminal device; wherein, the first security algorithm is negotiated and selected by the terminal device with the second satellite before receiving the broadcast message from the first satellite.
[0725] For example, when the device 20 is used to perform the methods in Figures 4 to 11, the receiving unit 201 can be used to perform the step of receiving information in the method; the management unit 202 can be used to perform the processing step in the method; and the sending unit 203 can be used to perform the step of sending information in the method.
[0726] When the communication device 20 is used to implement the functions of the first satellite in the above-described method embodiments, the receiving unit 201 is used to perform the receiving step of the first satellite, the transmitting unit 203 is used to perform the transmitting step of the first satellite, and the management unit 202 is used to perform the processing step of the first satellite. The management unit 202 may also be called a processing unit or other names, which are not limited in this application.
[0727] For example, the receiving unit 201 is used to receive the indication information of the first security algorithm and the identifier of the terminal-side device from the ground network element, which is a core network element located on the ground; the management unit 202 is used to use the first security algorithm to protect the communication security between the first satellite and the terminal-side device.
[0728] For example, when the device 20 is used to perform the methods in Figures 4 to 11, the receiving unit 201 can be used to perform the step of receiving information in the method; the management unit 202 can be used to perform the processing step in the method; and the sending unit 203 can be used to perform the step of sending information in the method.
[0729] When the communication device 20 is used to implement the functions of the ground network element in the above method embodiments, the receiving unit 201 is used to perform the receiving step of the ground network element, the transmitting unit 203 is used to perform the transmitting step of the ground network element, and the management unit 202 is used to perform the processing step of the ground network element. The management unit 202 may also be called a processing unit or other names, which are not limited in this application.
[0730] For example, the receiving unit 201 is used to obtain a first security algorithm from the second satellite, wherein the first security algorithm is selected through negotiation between the terminal device and the second satellite; the receiving unit 201 is used to send indication information of the first security algorithm to the first satellite, wherein the first security algorithm is used to protect the communication security between the first satellite and the terminal device.
[0731] For example, when the device 20 is used to perform the methods in Figures 4 to 11, the receiving unit 201 can be used to perform the step of receiving information in the method; the management unit 202 can be used to perform the processing step in the method; and the sending unit 203 can be used to perform the step of sending information in the method.
[0732] When the communication device 20 is used to implement the functions of the first satellite in the above-described method embodiments, the receiving unit 201 is used to perform the receiving step of the first satellite, the transmitting unit 203 is used to perform the transmitting step of the first satellite, and the management unit 202 is used to perform the processing step of the first satellite. The management unit 202 may also be called a processing unit or other names, which are not limited in this application.
[0733] For example, the receiving unit 201 is used to receive indication information of the first security algorithm from the terminal-side device; the management unit 202 is used to use the first security algorithm to protect the communication security between the first satellite and the terminal-side device.
[0734] For example, when the device 20 is used to perform the methods in Figures 4 to 11, the receiving unit 201 can be used to perform the step of receiving information in the method; the management unit 202 can be used to perform the processing step in the method; and the sending unit 203 can be used to perform the step of sending information in the method.
[0735] When the communication device 20 is used to implement the functions of the terminal-side device in the above method embodiments, the receiving unit 201 is used to execute the receiving step of the terminal-side device, the sending unit 203 is used to execute the sending step of the terminal-side device, and the management unit 202 is used to execute the processing step of the terminal-side device. The management unit 202 may also be called a processing unit or other names, which are not limited in this application.
[0736] For example, receiving unit 201 is used to receive a broadcast message from a third satellite, the broadcast message including the identifier of the third satellite; management unit 202 is used to determine a second security algorithm based on the identifier of the third satellite and a first mapping relationship, wherein the first mapping relationship includes a mapping relationship between at least one satellite and at least one security algorithm, the at least one satellite including the third satellite, the at least one security algorithm including the second security algorithm, and the second security algorithm corresponding to the third satellite; management unit 202 is used to use the second security algorithm to protect the communication security between the third satellite and the terminal-side device.
[0737] For example, when the device 20 is used to perform the methods in Figures 4 to 11, the receiving unit 201 can be used to perform the step of receiving information in the method; the management unit 202 can be used to perform the processing step in the method; and the sending unit 203 can be used to perform the step of sending information in the method.
[0738] When the communication device 20 is used to implement the functions of the ground network element in the above method embodiments, the receiving unit 201 is used to perform the receiving step of the ground network element, the transmitting unit 203 is used to perform the transmitting step of the ground network element, and the management unit 202 is used to perform the processing step of the ground network element. The management unit 202 may also be called a processing unit or other names, which are not limited in this application.
[0739] For example, the receiving unit 201 is used to obtain a first mapping relationship, which includes a mapping relationship between at least one satellite and at least one security algorithm; the sending unit 203 is used to send first information to a fourth satellite, which is used to instruct the fourth satellite to send indication information of the first mapping relationship to the terminal device, and the at least one security algorithm is used to protect the communication security between the at least one satellite and the terminal device.
[0740] For example, when the device 20 is used to perform the methods in Figures 4 to 11, the receiving unit 201 can be used to perform the step of receiving information in the method; the management unit 202 can be used to perform the processing step in the method; and the sending unit 203 can be used to perform the step of sending information in the method.
[0741] When the communication device 20 is used to implement the function of the third satellite in the above-described method embodiments, the receiving unit 201 is used to perform the receiving step of the third satellite, the transmitting unit 203 is used to perform the transmitting step of the third satellite, and the management unit 202 is used to perform the processing step of the third satellite. The management unit 202 may also be called a processing unit or other names, which are not limited in this application.
[0742] For example, the receiving unit 201 is used to receive the indication information of the second security algorithm and the identifier of the terminal device from the ground network element, which is a core network element located on the ground; the management unit 202 is used to use the second security algorithm to protect the communication security between the third satellite and the terminal device.
[0743] For example, when the device 20 is used to perform the methods in Figures 4 to 11, the receiving unit 201 can be used to perform the step of receiving information in the method; the management unit 202 can be used to perform the processing step in the method; and the sending unit 203 can be used to perform the step of sending information in the method.
[0744] When the communication device 20 is used to implement the function of the fifth satellite in the above-described method embodiments, the receiving unit 201 is used to perform the receiving step of the fifth satellite, the transmitting unit 203 is used to perform the transmitting step of the fifth satellite, and the management unit 202 is used to perform the processing step of the fifth satellite. The management unit 202 may also be called a processing unit or other names, which are not limited in this application.
[0745] For example, before receiving the first Non-Access Stratum (NAS) message from the terminal-side device, the sending unit 203 is used to send an indication of a third security algorithm to the terminal-side device; the management unit 202 is used to use the third security algorithm to protect the communication security between the fifth satellite and the terminal-side device; wherein, the third security algorithm is negotiated and selected between the ground network element and the third satellite.
[0746] For example, when the device 20 is used to perform the methods in Figures 4 to 11, the receiving unit 201 can be used to perform the step of receiving information in the method; the management unit 202 can be used to perform the processing step in the method; and the sending unit 203 can be used to perform the step of sending information in the method.
[0747] When the communication device 20 is used to implement the functions of the ground network element in the above method embodiments, the receiving unit 201 is used to perform the receiving step of the ground network element, the transmitting unit 203 is used to perform the transmitting step of the ground network element, and the management unit 202 is used to perform the processing step of the ground network element. The management unit 202 may also be called a processing unit or other names, which are not limited in this application.
[0748] For example, the receiving unit 201 is used to obtain the security capability information of the terminal-side device; the sending unit 203 is used to send the security capability information of the terminal-side device to the fifth satellite, and the security capability information of the terminal-side device is used to determine the security algorithm for security protection of the communication between the fifth satellite and the terminal-side device.
[0749] For example, when the device 20 is used to perform the methods in Figures 4 to 11, the receiving unit 201 can be used to perform the step of receiving information in the method; the management unit 202 can be used to perform the processing step in the method; and the sending unit 203 can be used to perform the step of sending information in the method.
[0750] When the communication device 20 is used to implement the functions of the terminal-side device in the above method embodiments, the receiving unit 201 is used to execute the receiving step of the terminal-side device, the sending unit 203 is used to execute the sending step of the terminal-side device, and the management unit 202 is used to execute the processing step of the terminal-side device. The management unit 202 may also be called a processing unit or other names, which are not limited in this application.
[0751] For example, before sending the first non-access stratum NAS message, the receiving unit 201 is used to receive the indication information of the third security algorithm from the fifth satellite; the management unit 202 is used to use the third security algorithm to protect the communication security between the fifth satellite and the third terminal-side device.
[0752] For example, when the device 20 is used to perform the methods in Figures 4 to 11, the receiving unit 201 can be used to perform the step of receiving information in the method; the management unit 202 can be used to perform the processing step in the method; and the sending unit 203 can be used to perform the step of sending information in the method.
[0753] For a more detailed description of the receiving unit 201, management unit 202 and sending unit 203, please refer to the relevant descriptions in the above method embodiments, which will not be repeated here.
[0754] This application also provides a chip, including a processor, for calling and executing instructions stored in a memory, causing a communication device on which the chip is mounted to perform the methods described in the examples above.
[0755] This application also provides another chip, including: an input interface, an output interface, and a processor, wherein the input interface, the output interface, and the processor are connected via an internal connection path, and the processor is used to execute code in a memory. When the code is executed, the processor is used to perform the methods in the examples described above. Optionally, the chip further includes a memory for storing computer programs or code.
[0756] This application also provides a processor for coupling with a memory for performing the methods and functions of the communication apparatus involved in any of the above embodiments.
[0757] In another embodiment of this application, a computer program product comprising a computer program or instructions is provided, wherein the method of the foregoing embodiments is implemented when the computer program product is run on a computer.
[0758] This application also provides a computer program that, when run on a computer, enables the implementation of the methods described in the foregoing embodiments.
[0759] In another embodiment of this application, a computer-readable storage medium is provided, which stores a computer program that, when executed by a computer, implements the methods described in the foregoing embodiments.
[0760] This application also provides a communication system, which includes a terminal-side device, a first satellite, and a ground network element. Alternatively, the communication system includes a terminal-side device, a third satellite, and a ground network element. Alternatively, the communication system includes a terminal-side device, a ground network element, and a fifth satellite.
[0761] The terminal-side device, the first satellite, the ground network element, the third satellite, or the fifth satellite are respectively used to execute the methods executed by the terminal-side device, the first satellite, the ground network element, the third satellite, or the fifth satellite in the foregoing embodiments.
[0762] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0763] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0764] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0765] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0766] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0767] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.
[0768] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A communication method, characterized in that, The method is applied to a terminal-side device, and the method includes: Receive broadcast messages from the first satellite; Based on the broadcast message, determine the first security algorithm corresponding to the first satellite; The first security algorithm is used to protect the communication security between the first satellite and the terminal-side device. The first security algorithm is selected by the terminal device in consultation with the second satellite before receiving the broadcast message from the first satellite.
2. The method according to claim 1, characterized in that, The first satellite and the second satellite are configured with the same list of security algorithms, and the first security algorithm is determined based on the list of security algorithms and the security capability information of the terminal-side device.
3. The method according to claim 1 or 2, characterized in that, The broadcast message includes the identifier corresponding to the first satellite or the identifier corresponding to the network element carried on the first satellite. The step of determining the first security algorithm corresponding to the first satellite based on the broadcast message includes: Based on the identifier corresponding to the first satellite, determine the first security algorithm corresponding to the first satellite; or, Based on the identifier corresponding to the network element carried on the first satellite, the first security algorithm corresponding to the first satellite is determined.
4. The method according to claim 3, characterized in that, The step of determining the first security algorithm corresponding to the first satellite based on the identifier corresponding to the first satellite includes: Based on the identifier corresponding to the first satellite, it is determined that the first satellite belongs to the first group; The security algorithm shared by the satellites in the first group is determined as the first security algorithm, wherein the first group includes the first satellite and the second satellite.
5. The method according to claim 3, characterized in that, The step of determining the first security algorithm corresponding to the first satellite based on the identifier corresponding to the first satellite includes: Based on the identifier of the first satellite, it is determined that the first satellite and the second satellite belong to the same group; The security algorithm corresponding to the second satellite is determined to be the first security algorithm.
6. The method according to claim 3, characterized in that, The step of determining the first security algorithm corresponding to the first satellite based on the identifier corresponding to the first satellite includes: Based on the identifier of the first satellite, it is determined that the security algorithm lists configured for the first satellite and the second satellite are the same; The security algorithm corresponding to the second satellite is determined to be the first security algorithm.
7. The method according to claim 3, characterized in that, The step of determining the first security algorithm corresponding to the first satellite based on the identifier corresponding to the network element carried on the first satellite includes: Based on the identifiers corresponding to the network elements carried on the first satellite, it is determined that the network elements carried on the first satellite belong to the second group; The security algorithm shared by network elements in the second group is determined as the first security algorithm, wherein the second group includes network elements carried on the first satellite and network elements carried on the second satellite.
8. The method according to claim 3, characterized in that, The step of determining the first security algorithm corresponding to the first satellite based on the identifier corresponding to the network element carried on the first satellite includes: Based on the identifier of the network element carried on the first satellite, it is determined that the network element carried on the first satellite and the network element carried on the second satellite belong to the same group; The security algorithm corresponding to the network element carried on the second satellite is determined as the first security algorithm.
9. The method according to claim 3, characterized in that, The step of determining the first security algorithm corresponding to the first satellite based on the identifier corresponding to the network element carried on the first satellite includes: It is determined that the identifier of the network element carried on the first satellite is the same as the identifier of the network element carried on the second satellite; The security algorithm corresponding to the network element carried on the second satellite is determined as the first security algorithm.
10. The method according to claim 3, characterized in that, The step of determining the first security algorithm corresponding to the first satellite based on the identifier corresponding to the network element carried on the first satellite includes: Based on the identifiers corresponding to the network elements carried on the first satellite, it is determined that the security algorithm lists configured for the network elements carried on the first satellite and the network elements carried on the second satellite are the same. The security algorithm corresponding to the network element carried on the second satellite is determined as the first security algorithm.
11. The method according to any one of claims 1 to 10, characterized in that, The step of using the first security algorithm to protect the communication security between the first satellite and the terminal-side device includes: The first security algorithm is used to provide security protection for the first uplink non-access stratum (NAS) message sent by the terminal device to the first satellite.
12. The method according to claim 11, characterized in that, Before using the first security algorithm to provide security protection for the first uplink NAS message sent by the terminal-side device to the first satellite, the method further includes: Enable encryption and / or integrity protection for NAS messages.
13. The method according to claim 12, characterized in that, The first uplink NAS message includes indication information for the first security algorithm.
14. The method according to any one of claims 11 to 13, characterized in that, The step of using the first security algorithm to provide security protection for the first uplink NAS message sent by the terminal device to the first satellite includes: The first security algorithm is used to provide security protection for the first uplink NAS message sent by the terminal device to the Mobility Management Element (MME) carried on the first satellite.
15. The method according to claim 3 or any one of 7 to 10, characterized in that, The network elements carried on the first satellite include mobility management network elements.
16. A communication method, characterized in that, The method is applied to a first satellite, and the method includes: Receive instruction information for the first security algorithm and the identifier of the terminal device from the ground network element; The first security algorithm is used to protect the communication security between the first satellite and the terminal-side device.
17. The method according to claim 16, characterized in that, The step of using the first security algorithm to protect the communication security between the first satellite and the terminal-side device includes: Enable decryption and / or integrity verification of non-access NAS messages.
18. The method according to claim 17, characterized in that, After enabling NAS message decryption and / or integrity verification, the method further includes: Receive the first uplink NAS message from the terminal-side device; Decrypt and / or verify the integrity of the first uplink NAS message.
19. The method according to claim 18, characterized in that, The process of decrypting and / or verifying the integrity of the first uplink NAS message includes: If the first uplink NAS message is not protected for integrity, and / or if integrity verification of the first uplink NAS message fails, the first uplink NAS message shall be discarded.
20. The method according to any one of claims 17 to 19, characterized in that, Before enabling encryption and / or integrity protection for non-access stratum NAS messages, the method further includes: Based on the first security algorithm, determine the first NAS key; or... Receive information related to the first NAS key from the ground network element; The first NAS key is used to decrypt and / or verify the integrity of NAS messages.
21. A communication method, characterized in that, The method is applied to terrestrial network elements, and the method includes: The first security algorithm is obtained from the second satellite, wherein the first security algorithm is selected through negotiation between the terminal device and the second satellite; The system sends an instruction message for the first security algorithm to the first satellite. The first security algorithm is used to protect the communication security between the first satellite and the terminal-side device.
22. The method according to claim 21, characterized in that, Before sending the indication information of the first security algorithm to the first satellite, the method further includes: The first satellite is determined based on the satellite list, which indicates the satellites that the terminal device will subsequently connect to.
23. The method according to claim 22, characterized in that, The step of determining the first satellite based on the satellite list includes: It is determined that both the first satellite and the second satellite in the satellite list are allowed to communicate with the terminal device using the same security algorithm.
24. The method according to claim 23, characterized in that, The first satellite and the second satellite are configured with the same list of security algorithms, which is used to determine the security algorithm for communication between the first satellite or the second satellite and the terminal.
25. A communication device, characterized in that, It includes at least one module or at least one unit, said at least one module or at least one unit being used to perform the method of any one of claims 1 to 24.
26. A communication device, characterized in that, include: At least one processor, the at least one processor being configured to execute a computer program or instructions to cause the method of any one of claims 1 to 24 to be performed.
27. The communication device according to claim 26, characterized in that, The communication device further includes a memory for storing the computer program or the instructions.
28. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program or instructions that, when executed, cause the method of any one of claims 1 to 24 to be performed.
29. A computer program product, characterized in that, Includes a computer program or instructions, which, when executed, implement the method as described in any one of claims 1 to 24.
Citation Information
Patent Citations
Systems and methods for context aware network security
CN114650162A
Verification method, data transmission method and device and communication equipment
CN117997404A
Emergency satellite call method and satellite communication system
CN118473506A
NAS signaling optimization method and system
CN118646998A
Systems and methods for supporting location based mobility for 5g satellite access to a wireless network
US20240171267A1