Communication method and apparatus

By receiving satellite identifiers and parameters to generate the corresponding key stream and message authentication code for the satellite, the problem of reusing key streams and message authentication codes between satellites in non-terrestrial networks is solved, and NAS secure communication and data transmission security between terminal devices and satellites are realized.

WO2026092533A1PCT designated stage Publication Date: 2026-05-07HUAWEI TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
HUAWEI TECH CO LTD
Filing Date
2025-10-29
Publication Date
2026-05-07

AI Technical Summary

Technical Problem

In non-terrestrial networks, how can we ensure a secure non-access stratum (NAS) connection between terminal devices and satellites, and avoid the reuse of key streams and message authentication codes between satellites?

Method used

By receiving the satellite's identifier and parameters, a key stream and message authentication code corresponding to the satellite are generated, ensuring that each satellite uses different parameters for secure NAS communication.

Benefits of technology

It enables secure NAS communication between terminal devices and different satellites, ensuring the security of data transmission and avoiding the reuse of key streams and message authentication codes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025130983_07052026_PF_FP_ABST
    Figure CN2025130983_07052026_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the present application are a communication method and an apparatus. The method comprises: when a communication link between a terminal device and a first satellite is available, receiving a broadcast message from the first satellite, the broadcast message comprising an identifier of the first satellite; and, on the basis of a first parameter indicating the first satellite and / or a network element carried on the first satellite, a non-access stratum (NAS) key and a NAS security algorithm, performing NAS secure communication with the first satellite. In the present application, different parameters are determined for different satellites, so that different key streams and / or MACs are generated when the different satellites communicate with a terminal device, thereby implementing NAS secure communication between the terminal device and the different satellites.
Need to check novelty before this filing date? Find Prior Art

Description

A communication method and apparatus

[0001] This application claims priority to Chinese Patent Application No. 202411559875.5, filed on November 2, 2024, entitled "A Communication Method and Apparatus", the entire contents of which are incorporated herein by reference. Technical Field

[0002] This application relates to the field of communication technology, and more specifically, to a communication method and apparatus. Background Technology

[0003] In non-terrestrial networks (NTNs), terminal devices can communicate with satellites. For example, in an NTN store-and-forward (S&F) scenario, some core network elements are deployed on satellites, while others are deployed on terrestrial equipment. In this deployment scheme, terminal devices attach to the satellite network via satellite to communicate with the satellites. Terminal devices can access different satellites, and information exchange between satellites can be completed through terrestrial equipment. During communication, a secure non-access stratum (NAS) connection is established between the terminal device and the core network elements to ensure secure data transmission.

[0004] In the above deployment scheme, some core network elements can be deployed on the satellite. Therefore, how to ensure a secure NAS connection between the terminal equipment and the satellite is an urgent problem to be solved. Summary of the Invention

[0005] This application provides a communication method and apparatus to achieve secure NAS communication between terminal devices and satellites.

[0006] In a first aspect, a communication method is provided, which can be executed by a terminal device or a component of the terminal device (e.g., a chip, a chip system, a circuit, or a communication module).

[0007] The method includes: receiving a broadcast message from the first satellite, the broadcast message including the identifier of the first satellite, when a communication link between the terminal device and the first satellite is available; and conducting NAS secure communication with the first satellite based on first parameters indicating the first satellite and / or network elements carried on the first satellite, a non-access stratum NAS key, and a NAS security algorithm.

[0008] Based on the above scheme, the terminal device and the first satellite conduct NAS secure communication based on the first parameters corresponding to the first satellite. When the satellite communicates securely with the terminal device via NAS, the parameters corresponding to that satellite are used as input to the NAS security algorithm, generating a keystream and / or message authentication code specific to that satellite. Therefore, different satellites generate different keystreams and / or message authentication codes when communicating with the terminal device, avoiding the problem of keystream and / or message authentication code reuse between satellites. This achieves NAS secure communication between the terminal device and different satellites, ensuring the security of data transmission between the terminal device and the satellites.

[0009] In conjunction with the first aspect, in certain implementations of the first aspect, before conducting NAS secure communication with the first satellite based on the first parameter indicating the first satellite and / or the network element carried on the first satellite, the non-access stratum NAS key, and the NAS security algorithm, the method further includes: obtaining a correspondence between the first parameter and the information of the first satellite, wherein the information of the first satellite includes the identifier of the first satellite and / or the identifier of the network element carried on the first satellite; and determining the first parameter based on the correspondence.

[0010] Based on the above scheme, the terminal device can obtain the correspondence between the first satellite and the information of the first satellite, and based on the correspondence, the terminal device can determine the first parameter corresponding to the first satellite.

[0011] In conjunction with the first aspect, in some implementations of the first aspect, obtaining the correspondence between the first parameter and the information of the first satellite includes: receiving the correspondence from a second satellite, the second satellite being a satellite that the terminal device accessed before accessing the first satellite.

[0012] Based on the above scheme, the above correspondence is received from the second satellite previously accessed by the terminal device.

[0013] In conjunction with the first aspect, in some implementations of the first aspect, receiving the correspondence from the second satellite includes: receiving a first correspondence from the second satellite, the first correspondence including a correspondence between at least one parameter and information of at least one satellite, the at least one satellite including the first satellite, the at least one parameter including the first parameter, and the information of the at least one satellite including information of the first satellite.

[0014] Based on the above scheme, the terminal device obtains the correspondence between at least one parameter and at least one satellite information, thereby enabling the terminal device to determine the parameter corresponding to each satellite based on the information of each satellite.

[0015] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: determining the first parameter for the first satellite; and sending the first parameter to the first satellite.

[0016] Based on the above scheme, the terminal equipment determines different parameters for different satellites.

[0017] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: receiving the first parameter from the first satellite.

[0018] In conjunction with the first aspect, in certain implementations of the first aspect, NAS secure communication between the first satellite and / or the network elements carried on the first satellite, a NAS key, and a NAS security algorithm includes: using the first parameter and the NAS key as input to the NAS security algorithm to generate a first key stream and / or a first message authentication code (MAC); and performing NAS secure communication between the first satellite and the first satellite based on the first key stream or the first MAC, wherein the first parameter is included in a bearer and / or a counter used as input to the NAS security algorithm.

[0019] In conjunction with the first aspect, in some implementations of the first aspect, the first parameter is included in a first field, which is different from the bearer, counter, transmission direction, length, or message used as input to the NAS security algorithm.

[0020] Based on the above scheme, a new field, different from the bearer, counter, transmission direction, length, or message used as input to the NAS security algorithm, is introduced to carry the first parameter mentioned above, and the parameters corresponding to different satellites are carried based on this new field.

[0021] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: conducting NAS secure communication with the second satellite based on a second parameter, the NAS key, and the NAS security algorithm, wherein the second parameter is different from the first parameter.

[0022] In conjunction with the first aspect, in some implementations of the first aspect, the second parameter is used to indicate the second satellite and / or the network elements carried on the second satellite; or the second parameter is a default value.

[0023] In conjunction with the first aspect, in some implementations of the first aspect, the second parameter is included in the bearer and / or counter used as input to the NAS security algorithm; or the second parameter is included in a first field that is different from the bearer, NAS counter, transmission direction, length, or message used as input to the NAS security algorithm.

[0024] Secondly, a communication method is provided, which can be executed by a first satellite or a component of the first satellite (e.g., a chip, a chip system, a circuit, or a communication module).

[0025] The method includes: obtaining a first parameter, which is used to indicate the first satellite and / or the network element carried on the first satellite; and conducting NAS secure communication with a terminal device based on the first parameter, a non-access stratum NAS key, and a NAS security algorithm.

[0026] In conjunction with the second aspect, in some implementations of the second aspect, obtaining the first parameter includes: receiving the first parameter from the terminal device when the communication link between the first satellite and the terminal device is available.

[0027] In conjunction with the second aspect, in some implementations of the second aspect, obtaining the first parameter includes: receiving the first parameter from the ground network element when the communication link between the first satellite and the ground network element is available.

[0028] In conjunction with the second aspect, in some implementations of the second aspect, the method further includes: sending the first parameter to the terminal device.

[0029] In conjunction with the second aspect, in some implementations of the second aspect, the first parameter is determined by the first satellite; the method further includes: sending the first parameter to the terminal device.

[0030] In conjunction with the second aspect, in some implementations of the second aspect, NAS secure communication with a terminal device is performed based on the first parameter, the NAS key, and the NAS security algorithm, including: using the first parameter and the NAS key as inputs to the NAS security algorithm to generate a first key stream and / or a first message authentication code (MAC), and performing NAS secure communication with the terminal device based on the first key stream and / or the first MAC, wherein the first parameter is included in the bearer and / or counter used as inputs to the NAS security algorithm.

[0031] In conjunction with the second aspect, in some implementations of the second aspect, the first parameter is included in a first field, which is different from the bearer, counter, transmission direction, length, or message used as input to the NAS security algorithm.

[0032] Thirdly, a communication method is provided, which can be executed by a terrestrial network element or a component of a terrestrial network element (such as a chip, chip system, circuit, or communication module).

[0033] The method includes: obtaining a first correspondence, the first correspondence including a correspondence between at least one parameter and information of at least one satellite; and, if a communication link between the first satellite and the ground network element is available, sending the first correspondence to the first satellite, the at least one parameter including a first parameter for indicating the first satellite and / or the network element carried on the first satellite, the first parameter being used for the first satellite to conduct secure communication with a terminal device.

[0034] Based on the above scheme, the ground network element obtains different parameters corresponding to different satellites, so that when the satellite communicates with the terminal device, the corresponding parameters are used as input to the NAS security algorithm, thereby generating the corresponding key stream and / or integrity message authentication code, thus realizing NAS secure communication between the terminal device and different satellites and ensuring the security of data transmission between the terminal device and the satellite.

[0035] In conjunction with the third aspect, in some implementations of the third aspect, the method further includes: sending the first correspondence to a second satellite, the second satellite being a satellite that the terminal device accessed before accessing the first satellite.

[0036] Based on the above scheme, the ground network element will also send the obtained first correspondence to the second satellite, so that the second satellite can forward the first correspondence to the terminal device.

[0037] In conjunction with the third aspect, in some implementations of the third aspect, the method further includes: the first correspondence includes a correspondence between the second parameter and the information of the second satellite, the second parameter is used to indicate the second satellite and / or the network elements carried on the second satellite, and the second parameter is used for NAS secure communication between the second satellite and the terminal device.

[0038] In conjunction with the third aspect, in some implementations of the third aspect, the first parameter is included in the bearer and / or counter used as input to the NAS security algorithm; or the first parameter is included in a first field that is different from the bearer, counter, transmission direction, length, or message used in the NAS security algorithm.

[0039] Optionally, the second parameter is included in the bearer and / or counter used as input to the NAS security algorithm; or the second parameter is included in a first field that is different from the bearer, counter, transmission direction, length, or message used as input to the NAS security algorithm.

[0040] The technical effects of the technical solutions not detailed in the second and third aspects can be referred to the description of the corresponding technical effects in the first aspect, and will not be repeated here.

[0041] Fourthly, a communication method is provided, which can be executed by a terminal device or a component of the terminal device (e.g., a chip, chip system, circuit, or communication module).

[0042] The method includes: securing an uplink NAS message based on the value information of an uplink counter and a NAS key, the NAS message including the value information of the uplink counter and the value information of a downlink counter; and, if the communication link between the terminal device and the first satellite is available, sending the secure uplink NAS message to the first satellite.

[0043] Based on the above scheme, the terminal device transmits the uplink counter and downlink counter values ​​it maintains to the satellite via uplink NAS messages, thereby synchronizing the uplink and downlink counter values ​​with the satellite. This enables secure communication between the terminal device and the satellite.

[0044] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the value of the uplink counter is determined based on the NAS message between the terminal device and the second satellite. The second satellite is a satellite that the terminal device accessed before accessing the first satellite and that has sent uplink NAS messages with the terminal device. Furthermore, the value of the uplink counter is different from the value of the uplink counter corresponding to the uplink NAS message between the terminal device and the second satellite.

[0045] Based on the above scheme, the terminal device obtains the downlink counter value information from satellites that accessed the terminal device before the current satellite and have sent downlink NAS messages to the terminal device.

[0046] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the value information of the downlink counter is determined based on the downlink NAS message between the terminal device and the third satellite, including: the value information of the downlink counter is determined based on the sequence number SQN in the downlink NAS message between the terminal device and the third satellite. Specifically, the sequence number SQN in the downlink NAS message received from the third satellite is used as the downlink NAS SQN of the downlink counter value information; or the value information of the downlink counter is obtained by adding 1 to the SQN in the downlink NAS message received from the third satellite.

[0047] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the value of the downlink counter is the first value of the downlink counter stored locally by the terminal device plus 1; or the value of the downlink counter is the first value of the downlink NAS counter stored locally by the terminal device.

[0048] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the first value of the downlink counter stored locally by the terminal device is determined based on the SQN in the downlink NAS message received from the third satellite. For example, the SQN of the first value of the downlink counter stored locally by the terminal device is the SQN in the downlink NAS message received from the third satellite. Alternatively, the SQN of the first value of the downlink counter stored locally by the terminal device is obtained based on SQN+1 in the downlink NAS message received from the third satellite.

[0049] In conjunction with the fourth aspect, in some implementations of the fourth aspect, sending the security-protected uplink NAS message to the first satellite includes: sending the uplink NAS message to the first satellite when the terminal device receives a paging message from the first satellite; or sending the uplink NAS message to the first satellite when there will be a downlink NAS message between the terminal device and the first satellite. This allows the first satellite to determine the accurate value information of the downlink counter.

[0050] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the sending of the secure uplink NAS message to the first satellite includes: sending the secure uplink NAS message to the first satellite if the NAS key is the same as the NAS key used when the second satellite and the terminal device conduct NAS secure communication, wherein the second satellite is a satellite that the terminal device accessed before accessing the first satellite.

[0051] Based on the above scheme, when different satellites use the same NAS key, the uplink counter value information and downlink counter value information are synchronized to the satellite, so that the input of the NAS security algorithm used by different satellites is different, and the generated key stream and / or integrity message authentication code are different.

[0052] In conjunction with the fourth aspect, in some implementations of the fourth aspect, sending the security-protected uplink NAS message to the first satellite includes: sending the security-protected uplink NAS message to the first satellite when the first satellite and the second satellite belong to the same satellite group or set, wherein the second satellite is a satellite that the terminal device accessed before accessing the first satellite.

[0053] Based on the above scheme, satellites belonging to the same satellite group or set use the same NAS key when communicating securely with terminal devices. At this time, the uplink counter value and downlink counter value are synchronized to the satellite, so that the input of the NAS security algorithm used by different satellites is different, and the generated key stream and / or integrity message authentication code are different.

[0054] In conjunction with the fourth aspect, in some implementations of the fourth aspect, before sending the security-protected uplink NAS message to the first satellite, the method further includes: determining the value information of the uplink counter and the value information of the downlink counter.

[0055] In conjunction with the fourth aspect, in some implementations of the fourth aspect, determining the value information of the uplink counter and the value information of the downlink counter includes: determining the value information of the uplink counter and the value information of the downlink counter based on the ground network element to which the first satellite belongs or is connected.

[0056] Fifthly, a communication method is provided, which can be executed by a first satellite or a component of the first satellite (e.g., a chip, a chip system, a circuit, or a communication module).

[0057] The method includes: when a communication link between a terminal device and the first satellite is available, receiving a secure uplink NAS message from the terminal device, the uplink NAS message including uplink counter value information and downlink counter value information; and desecure the uplink NAS message between the terminal device and the first satellite based on the uplink counter value information and the NAS key.

[0058] In conjunction with the fifth aspect, in some implementations of the fifth aspect, the value information of the uplink counter and the value information of the downlink counter are stored. Specifically, this can be done by storing the value information of the uplink counter and the value information of the downlink counter only after successful decryption.

[0059] In conjunction with the fifth aspect, in some implementations of the fifth aspect, based on the value information of the uplink counter and the NAS key, the uplink NAS message between the terminal device and the first satellite is de-secured, including: determining a first value of the uplink counter based on the value information of the uplink counter; and de-secured based on the first value of the uplink counter and the NAS key.

[0060] In conjunction with the fifth aspect, in certain implementations of the fifth aspect, determining the first value of the uplink counter based on the value information of the uplink counter includes: when the value information of the uplink counter includes the uplink NAS SQN, the first satellite determines the first value of the uplink counter based on the local uplink NAS overflow value and the uplink NAS SQN; or when the NAS message also includes information for indicating an increment of the uplink NAS overflow value, and the value information of the uplink counter includes the uplink NAS SQN, the first satellite determines the first value of the uplink counter based on the local uplink NAS overflow value plus 1 and the uplink NAS SQN; or when the value information of the uplink counter includes both the uplink NAS SQN and the uplink NAS overflow value, the first satellite determines the first value of the uplink counter based on both the uplink NAS overflow value and the uplink NAS SQN.

[0061] In conjunction with the fifth aspect, in some implementations of the fifth aspect, the downlink NAS messages between the terminal device and the first satellite are securely protected based on the downlink counter value information and the NAS key, including: determining the first value of the uplink counter based on the downlink counter value information; and securing the uplink NAS messages between the terminal device and the first satellite based on the first value of the downlink counter and the NAS key.

[0062] In conjunction with the fifth aspect, in certain implementations of the fifth aspect, determining a first value of the uplink counter based on the downlink counter value information includes: when the downlink counter value information includes a downlink NAS SQN, the first satellite determines a second value of the downlink counter based on the local downlink NAS overflow value and the downlink NAS SQN; or when the NAS message also includes information indicating an increment of the downlink NAS overflow value, and the downlink counter value information includes a downlink NAS SQN, the first satellite determines a second value of the downlink counter based on the local downlink NAS overflow value plus 1 and the downlink NAS SQN; or when the downlink counter value information includes both the downlink NAS SQN and the downlink NAS overflow value, the first satellite determines a second value of the downlink counter based on the downlink NAS overflow value and the downlink NAS SQN.

[0063] In conjunction with the fifth aspect, in some implementations of the fifth aspect, the downlink NAS message between the terminal device and the first satellite is securely protected based on the value information of the downlink counter and the NAS key; the secure downlink NAS message is sent to the terminal device, the downlink NAS message including the third value of the downlink counter, the third value being the second value of the downlink counter, or the third value being the second value of the downlink counter + 1.

[0064] In conjunction with the fourth or fifth aspect, in some implementations, the value information of the uplink counter includes the uplink NAS overflow value and the uplink NAS SQN; the value information of the downlink counter includes the downlink NAS overflow value and / or the downlink NAS SQN.

[0065] Based on the above scheme, the uplink NAS overflow value and uplink NAS SQN are sent to the satellite, and / or the downlink NAS overflow value and downlink NAS SQN are sent to the satellite, so that the terminal device can send the complete uplink counter value and / or downlink counter synchronization to the satellite.

[0066] In conjunction with the fourth or fifth aspect, in some implementations, the value information of the uplink counter includes the uplink NAS SQN. If the value of the uplink counter has undergone an SQN flip, the value information of the uplink counter also includes the uplink NAS overflow value. Alternatively, the uplink NAS message may also include information indicating that the uplink NAS SQN has flipped. Or, the uplink NAS message may also include information indicating that the uplink NAS overflow value is incremented.

[0067] Based on the above scheme, whenever the uplink NAS SQN flips, the uplink NAS overflow value is incremented by 1. At this time, the uplink NAS overflow value, or information indicating that the uplink NAS SQN has flipped, or information indicating that the uplink NAS overflow value is incremented, is sent to the satellite so that the satellite can also obtain the uplink NAS overflow value.

[0068] In conjunction with the fourth or fifth aspect, in some implementations, the value information of the downlink counter includes the downlink NAS SQN. When the value of the downlink counter changes due to an SQN flip, the value information of the downlink counter also includes the downlink NAS overflow value, or the uplink NAS message includes information indicating that the downlink NAS SQN has flipped, or the uplink NAS message also includes information indicating that the downlink NAS overflow value is incremented.

[0069] Based on the above scheme, whenever the downlink NAS SQN flips, the downlink NAS overflow value is incremented by 1. At this time, the downlink NAS overflow value, or information indicating that the downlink NAS SQN has flipped, or information indicating that the downlink NAS overflow value is incremented, is sent to the satellite so that the satellite can also obtain the downlink NAS overflow value.

[0070] In conjunction with the fourth or fifth aspect, in some implementations, the NAS key is the same as the NAS key used when the second satellite and the terminal device conduct NAS secure communication, wherein the second satellite is a satellite that the terminal device accesses before accessing the first satellite.

[0071] In conjunction with the fourth or fifth aspect, in some implementations, satellites in the same group or set or connected to the same ground network element have the same NAS key.

[0072] The technical effects of the technical solutions not detailed in the fifth aspect can be found in the description of the corresponding technical effects in the fourth aspect, and will not be repeated here.

[0073] Sixthly, a communication apparatus is provided for performing the methods of any one of the first to fifth aspects and any possible implementation thereof. Specifically, the apparatus may include units and / or modules for performing the methods of any one of the first to fifth aspects and any possible implementation thereof, such as processing units and / or communication units.

[0074] In one implementation, the device is a communication device (such as a terminal device, a first satellite, or a ground network element). When the device is a communication device, the communication unit can be a transceiver or an input / output interface; the processing unit can be at least one processor. Optionally, the transceiver can be a transceiver circuit. Optionally, the input / output interface can be an input / output circuit.

[0075] In another implementation, the device is a chip, chip system, circuit, or communication module for communication equipment (such as terminal equipment, a first satellite, or a terrestrial network element). When the device is a chip, chip system, or circuit for communication equipment, the communication unit can be an input / output interface, interface circuit, output circuit, input circuit, pin, or related circuit on the chip, chip system, or circuit; the processing unit can be at least one processor, processing circuit, or logic circuit.

[0076] A seventh aspect provides a communication device comprising: at least one processor configured to cause the device to perform any of the first to fifth aspects and any possible implementation thereof.

[0077] Optionally, the at least one processor is configured to execute computer programs or instructions to perform the methods of any of the first to fifth aspects and any possible implementation thereof.

[0078] Optionally, the device further includes a memory for storing the computer program or instructions.

[0079] Optionally, the at least one processor is coupled to a memory for storing the computer program or instructions. The memory may be located externally to the device.

[0080] Optionally, the device also includes a communication interface through which the processor reads instructions from memory. This can be understood as the communication interface being coupled to the processor and used to input computer programs or instructions to the processor, or to output information from the processor.

[0081] Unless otherwise specified, or if the transmission and acquisition / reception operations involved do not contradict their actual function or internal logic in the relevant description, they can be understood as output, input, or other operations, or as transmission and reception operations performed by radio frequency circuits and antennas. This application does not limit them in this regard.

[0082] In one implementation, the device is a communication device (such as a terminal device or a network device).

[0083] In another implementation, the device is a chip, chip system, circuit, or communication module for communication equipment (such as terminal equipment or network equipment). Optionally, the chip is a modem chip, also known as a baseband chip, or a system-on-chip (SoC) chip containing a modem core, or a system-in-package (SIP) chip.

[0084] Eighthly, a computer-readable storage medium is provided that stores a computer program (e.g., program code) or instructions that, when executed on a communication device, cause the communication device to perform the methods of any one of the first to fifth aspects and any possible implementation thereof.

[0085] Ninth aspect, a computer program product containing instructions is provided, which, when run on a computer, causes the computer to perform the methods of any one of the first to fifth aspects and any possible implementation thereof.

[0086] A tenth aspect provides a communication system including a terminal device, a first satellite, and / or a ground network element. The terminal device is configured to execute the method provided in any implementation of the first aspect, the first satellite is configured to execute the method provided in any implementation of the second aspect, and the ground network element is configured to execute the method provided in any implementation of the third aspect; or, the terminal device is configured to execute the method provided in any implementation of the fourth aspect, and the first satellite is configured to execute the method provided in any implementation of the fifth aspect.

[0087] The technical effects of the solutions in aspects six through ten can be referred to the descriptions of the corresponding technical effects in aspects one through five, and will not be repeated here. Attached Figure Description

[0088] Figure 1 is a schematic diagram of a communication system applicable to an embodiment of this application.

[0089] Figure 2 is a schematic block diagram of a communication architecture applicable to an embodiment of this application.

[0090] Figure 3 is a schematic diagram of the input parameters for the NAS encryption / decryption algorithm and the NAS integrity protection algorithm.

[0091] Figure 4 is a schematic flowchart of a NAS security negotiation method.

[0092] Figure 5 is a schematic flowchart of a communication method provided in an embodiment of this application.

[0093] Figure 6 is a schematic flowchart of another communication method provided in an embodiment of this application.

[0094] Figure 7 is a schematic flowchart of another communication method provided in an embodiment of this application.

[0095] Figure 8 is a schematic flowchart of another communication method provided in an embodiment of this application.

[0096] Figure 9 is a schematic flowchart of another communication method provided in an embodiment of this application.

[0097] Figure 10 is a schematic flowchart of another communication method provided in an embodiment of this application.

[0098] Figure 11 is a schematic flowchart of another communication method provided in an embodiment of this application.

[0099] Figure 12 is a schematic flowchart of a communication device provided in an embodiment of this application.

[0100] Figure 13 is a schematic flowchart of another communication device provided in an embodiment of this application.

[0101] Figure 14 is a schematic flowchart of another chip system provided in an embodiment of this application. Detailed Implementation

[0102] The technical solutions in this application will now be described with reference to the accompanying drawings.

[0103] Before introducing the scheme of this application, the following points should be noted.

[0104] (1) In this application, unless otherwise specified or logically conflicting, the terms and / or descriptions of different embodiments are consistent and can be referenced by each other. The technical features of different embodiments can be combined to form new embodiments according to their inherent logical relationship.

[0105] (2) In this application, "first," "second," and "#1," "#2" are merely for descriptive convenience and are used to distinguish objects, and are not intended to limit the scope of the embodiments of this application. For example, they are used to distinguish different messages, rather than to describe a specific order or sequence. It should be understood that such described objects can be interchanged where appropriate so as to describe solutions other than those in the embodiments of this application.

[0106] (3) In this application, "instruction" can include direct instruction, indirect instruction, explicit instruction, implicit instruction, etc. When describing an instruction information as indicating A, it can be understood as the instruction information carrying A, carrying the identifier of A, carrying B which is associated with A, carrying the identifier of B which is associated with A, etc. In other words, if the receiving side of an instruction information can determine A based on the instruction information, it can be described as the instruction information indicating A, and the specific method of determination is not limited. When it is understood that the instruction information carries A, "instruction" can be replaced with "includes". In this case, a statement such as "send / receive instruction information, the instruction information indicates A" can be replaced with "send / receive A".

[0107] In this application, the information indicated by the instruction information is called the information to be instructed. In specific implementations, there are many ways to indicate the information to be instructed, such as, but not limited to, directly indicating the information to be instructed, such as the information to be instructed itself or its index. It can also indirectly indicate the information to be instructed by indicating other information, where there is a relationship between the other information and the information to be instructed. It can also indicate only a part of the information to be instructed, while the other parts are known or pre-agreed upon. For example, the instruction of specific information can be achieved by using a pre-agreed (e.g., protocol-defined) arrangement of various pieces of information, thereby reducing instruction overhead to some extent. Furthermore, the information to be instructed can be sent as a whole or divided into multiple sub-information pieces, and the sending period and / or timing of these sub-information pieces can be the same or different.

[0108] (4) In this application, "predefined" may refer to a standard protocol predefined, or it may refer to a pre-agreed or pre-negotiated agreement between devices. "Pre-configuration" can be achieved by pre-storing corresponding codes, tables, or other means that can be used to indicate relevant information in the device, and this application does not limit its implementation method. "Protocol" may refer to a standard protocol in the field of communication, such as fourth-generation (4G) protocols. th Generation 4G network, fifth generation (5G) network thThis application does not limit the scope to network protocols such as 5G (generation, 5G), New Radio (NR), 5.5G, and related protocols used in future communication networks.

[0109] (5) In this application, no restrictions are placed on the name of the message or information, as long as it can achieve the corresponding function.

[0110] "Sending information to XX (device)" can be understood as the destination of the information being that device. This can include sending information to that device directly or indirectly. "Receiving information from XX (device), or receiving information from XX (device)" can be understood as the source of the information being that device. This can include receiving information from that device directly or indirectly. Information may undergo necessary processing between the source and destination, such as format changes, but the destination can understand the valid information from the source. Similar expressions in this application can be interpreted similarly, and will not be elaborated further here.

[0111] "Communication" can also be described as data transmission, information transmission, data processing, etc. "Transmission" includes sending and / or receiving. "Transmission" can be described as output. "Sending" can also be understood as the output of a chip interface, and "receiving" can be understood as the input of a chip interface. In other words, "sending" or "receiving" can occur between devices, for example, between network devices and terminal devices via an air interface. "Sending" or "receiving" can also occur within a device, for example, between components, modules, chips, software modules, or hardware modules within a device via a bus, wiring, or interface.

[0112] For example, "sending information" can be understood as one device sending information to another device, or it can also be understood as one logical module within a device sending information to another logical module. For instance, "terminal device sending information" can be understood as a terminal device sending information to another device (such as a satellite device), or it can be understood as logical module 1 in the terminal device sending information to logical module 2 in the network device. Similarly, "receiving information" can be understood as one device receiving information from another device, or it can also be understood as one logical module within a device receiving information from another logical module. For instance, "terminal device receiving information" can be understood as a terminal device receiving information from another device (such as a satellite device), or it can be understood as logical module 1 in the terminal device receiving information from logical module 2 in the satellite.

[0113] (6) In this application, the words “exemplary,” “for example,” etc., are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as an “example” in this application should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of the word “example” is intended to present a concept in a concrete manner. In the embodiments of this application, “of,” “corresponding, relevant,” “corresponding,” and “associate” may sometimes be used interchangeably, and it should be noted that their intended meanings are consistent unless their distinctions are emphasized.

[0114] The technical solution of this application can be applied to NTN systems such as satellite communication systems and high altitude platform station (HAPS) communication, for example, integrated communication and navigation (ICaN) systems, global navigation satellite systems (GNSS), etc.

[0115] Satellite communication systems can be integrated with traditional mobile communication systems. These mobile communication systems can be 5G or NR systems, Long Term Evolution (LTE) systems, LTE Frequency Division Duplex (FDD) systems, LTE Time Division Duplex (TDD) systems, Universal Mobile Telecommunication System (UMTS), etc. The technical solutions provided in this application can also be applied to future communication systems, such as future mobile communication systems. Furthermore, the technical solutions provided in this application can also be applied to device-to-device (D2D) communication, vehicle-to-everything (V2X) communication, machine-to-machine (M2M) communication, machine-type communication (MTC), Internet of Things (IoT) communication systems, NTN communication systems, or other communication systems.

[0116] Figure 1 is a schematic diagram of a communication system 100 applicable to an embodiment of this application. As shown in Figure 1, the communication system 100 may include at least one satellite device (e.g., satellite device 110, satellite device 120, and satellite device 130), a terminal device 140, and a ground device 150. Satellite devices 110 to 130 deploy some functions of the core network elements, and the ground device 150 deploys some functions of the core network elements. The terminal device 140 connects to the satellite device via a Uu interface; for example, the terminal device 140 communicates with one of satellite devices 110, 120, and 130 and transmits data to the satellite device; then the satellite device forwards the data to the ground device 150.

[0117] Figure 1 is for illustrative purposes only. Satellite equipment 110 to satellite equipment 130 deploy some functions of core network elements or access network elements, and ground equipment 150 deploys some functions of core network elements or access network elements. Core network elements can be mobility management function network elements, and access network elements can be base stations.

[0118] Figure 1 is only a schematic diagram. The communication system 100 may also include a serving gateway (SGW), a home subscriber server (HHS), a short message service gateway mobile switching center (SMS-GMSC) or a short message service interworking mobile switching center (SMS-IWMSC) or a short message service (SMS) router, an inter-working function-service capability exposure function (IWF-SCEF) network element or an SCEF network element, etc., connected to the ground equipment 150, which are not shown in Figure 1. In this application, the terminal equipment 140 may be referred to as user equipment (UE). The terminal equipment 140 in this application is a device with wireless transceiver capabilities, which can communicate with one or more satellite devices. The terminal equipment 140 may also be referred to as an access terminal, terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, user agent or user equipment, etc. Terminal device 110 can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; it can also be deployed on water (e.g., ships); and it can be deployed in the air (e.g., airplanes, balloons, and satellites). Terminal device 140 can be a cellular phone, cordless phone, session initiation protocol (SIP) phone, smartphone, mobile phone, wireless local loop (WLL) station, personal digital assistant (PDA), etc. Alternatively, terminal device 110 can also be a handheld device with wireless communication capabilities, a computing device or other device connected to a wireless modem, vehicle-mounted device, wearable device, unmanned aerial vehicle (UAV) device, or a terminal in the Internet of Things (IoT), vehicle-to-everything (V2X) network, 5G network, or any form of terminal in future networks, relay user equipment, or a terminal in future evolved networks. Relay user equipment can be, for example, a 5G residential gateway (RG).For example, terminal device 140 can be a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in autonomous driving, a wireless terminal in telemedicine, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, etc. Alternatively, terminal device 140 can also be a logical entity, a smart device (such as a mobile phone), a smart terminal, or other terminal devices, or communication equipment such as a server, gateway, base station, or controller, or IoT devices such as IoT devices, sensors, electricity meters, and water meters. This application embodiment does not limit the type or category of terminal device.

[0119] Figure 2 is a schematic diagram of a communication architecture 200 applicable to an embodiment of this application. As shown in Figure 2, the communication architecture 200 includes satellites 1 to N and ground network elements. Each satellite deploys some functions of a core network element. For example, each satellite carries a mobility management entity (MME). When an MME is carried (or deployed) on a satellite, it can be referred to as an onboard MME or MME-onboard. For ease of description, the following description uses the network element carried on a satellite as the MME and the MME carried on a satellite as the onboard MME. Other possible network elements can be substituted for the description. Specifically, each satellite simultaneously carries the evolved-Universal Mobile Telecommunications System Terrestrial Radio Access Network (E-UTRAN) and the onboard MME, where E-UTRAN can also be RAN. Alternatively, the MME and RAN are independently carried on each satellite, that is, the MME and RAN are deployed on different satellites. Any one of satellites 1 to N communicates with the UE via the Uu interface. The link formed between the satellite and the UE is called a service link. A ground network element can be understood as a ground device that carries core network elements, such as an MME. In this case, the ground network element can also be called a ground MME. The ground MME communicates with the onboard MME, and the link formed between the ground MME and the onboard MME is called a power supply link.

[0120] The terrestrial MME connects to the SGW via the S11 interface, to the Home Subscriber Server (HSS) via the S6a interface, to the SMS-GMSC, SMS-IWMSC, or SMS router via the SGd interface, and to the IWF-SCEF or SCEF via the T6a or T6ai interface. Furthermore, the IWF-SCEF or SCEF connects to the data network (DN) or cellular internet of things (CIoT) server via the T8 interface. The SGW connects to the packet data network gateway (PGW) via the S5 or S8 interface. The PGW connects to the policy and charging rules function (PCRF) unit via the Gx interface and also connects to the DN or CIoT server via the SGi interface.

[0121] To facilitate understanding of the embodiments of this application, the terminology used in this application will be briefly explained. Furthermore, for ease of description, the network elements carried on the satellite will be described below using MME, MME carried on the satellite, and MME-onboard as examples of on-board MME.

[0122] 1. NAS secure communication

[0123] NAS secure communication includes NAS encryption / decryption and / or NAS integrity protection / verification. During NAS secure communication between terminal devices and core network elements, NAS security algorithms are required, including NAS encryption / decryption algorithms and / or NAS integrity protection / verification algorithms. The sequence generated by the NAS encryption / decryption security algorithm and its inputs, known as a keystream, is used to encrypt plaintext or plaintext blocks, or to decrypt ciphertext or ciphertext blocks. The NAS integrity protection algorithm and its inputs generate a message authentication code (MAC), specifically, an integrity message authentication (MAC-integrity, MAC-I) or NAS-MAC, which is used to protect the integrity of NAS messages. The NAS integrity verification algorithm and its inputs generate a MAC, specifically, an expected MAC (expected MAC-I, XMAC-I) / XNAS-MAC, which is used to verify the integrity of NAS messages. The NAS integrity protection algorithm and the NAS integrity verification algorithm can be the same algorithm, and the NAS encryption algorithm and the NAS decryption algorithm can be the same algorithm.

[0124] Figure 3 is a schematic diagram of the inputs to the NAS encryption / decryption algorithm and the NAS integrity protection / verification algorithm. As shown in Figure 3(a), the Evolved Packet System (EPS) encryption algorithm (EEA) is the encryption algorithm used for EPS. The inputs of this algorithm include: key, counter, bearer, direction of transmission, and length. On the left side of Figure 3(a), KEY, COUNT, BEARER, DIRECTION, and LENGTH serve as the inputs to EEA, generating an encryption keystream. The sender then combines the plaintext block and the keystream to encrypt the NAS message, obtaining a ciphertext block which is sent to the receiver. On the receiver's side, KEY, COUNT, BEARER, DIRECTION, and LENGTH serve as the inputs to EEA, generating a decryption keystream. This decryption keystream is used to decrypt the received ciphertext block, obtaining the plaintext block.

[0125] As shown in Figure 3(b), the EPS integrity algorithm (EIA) is an integrity protection algorithm for EPS. The inputs to this algorithm include: a key, a counter, a bearer, a direction of transmission, and a message. On the left side of Figure 3(b), the key, counter, bearer, direction of transmission, and message are used as inputs to the EIA to generate MAC-I / NAS-MAC, which protects the integrity of the message. On the receiver side, the key, counter, bearer, direction of transmission, and length are used as inputs to the EIA to generate XMAC-I / XNAS-MAC, which is used to verify the integrity of the message.

[0126] 2. NAS security negotiation

[0127] During NAS secure communication between terminal devices and core network elements, the two devices need to negotiate the security algorithm they use and generate a key. The negotiated security algorithm and key are then used to securely protect the communication between the terminal devices and core network elements. Specifically, a key for encryption / decryption is generated based on the encryption algorithm ID; a key for integrity protection / verification is generated based on the integrity algorithm ID.

[0128] Figure 4 is a schematic flowchart of a NAS security negotiation method 400. As shown in Figure 4, the method 400 includes the following steps. For ease of description, the core network element is taken as an example, specifically the MME.

[0129] S401, MME sends a NAS security mode command message to UE.

[0130] Accordingly, the UE receives a NAS security mode command message from the MME.

[0131] The NAS security mode command message is a NAS message that has undergone integrity protection. The NAS security mode command message includes the UE's security capabilities, the selected NAS security algorithm, and the E-UTRAN key set identifier (eKSI). The eKSI is used to identify the key (K... ASME The selected NAS security algorithms include encryption / decryption algorithms and / or integrity protection / verification algorithms.

[0132] For example, both the UE side and the MME side will generate K. ASME Through K ASMEThe NAS encryption / decryption key and NAS integrity protection / verification key can be derived. On the MME side, the MME performs integrity protection on the NAS security mode command message based on the NAS integrity protection key and NAS integrity protection algorithm. Furthermore, after sending the NAS security mode command message to the UE, the MME initiates decryption of uplink messages.

[0133] S402, UE verifies the integrity of the NAS security mode command message.

[0134] Specifically, the integrity of NAS security mode command messages is verified using the integrity protection algorithm in the selected NAS security algorithm and the key used for NAS integrity protection.

[0135] If the NAS security mode command message passes the integrity verification, the UE enables encryption / decryption and integrity protection / verification of subsequent NAS messages, and executes step S403. Details are as follows.

[0136] S403, UE sends a NAS security mode completion message to MME.

[0137] Accordingly, the MME receives a NAS security mode completion message from the UE.

[0138] After receiving the NAS security mode completion message, the MME performs integrity verification on the NAS security mode completion message using the selected NAS integrity protection algorithm and NAS integrity verification key; and decrypts the NAS security mode completion message using the selected NAS encryption / decryption algorithm and NAS encryption / decryption key.

[0139] When the MME resends the downlink NAS message to the UE, it encrypts and protects the integrity of the downlink NAS message using the selected NAS protection algorithm and NAS key.

[0140] The NAS security described in Figure 4 is not applicable to scenarios where a terminal device communicates with network elements carried on multiple satellites. For example, it is not applicable to the MME-Split architecture in the S&F scenario. In the MME-Split architecture, when MMEs carried on different satellites communicate securely with a terminal device, using the same NAS key (or KEY) as input to the NAS security algorithm, COUNT, BEARER, DIRECTION, and LENGTH or MESSAGE also need to be input. If KEY, COUNT, BEARER, DIRECTION, and LENGTH or MESSAGE are also the same, the key stream and / or MAC generated by the NAS security algorithm will also be identical. Therefore, when the UE communicates securely with MMEs carried on different satellites, the key stream and / or MAC will be reused, failing to guarantee secure NAS communication between the UE and MMEs on different satellites, and consequently, compromising the security of data transmission between the UE and different satellites.

[0141] Therefore, this application proposes a communication method that enables a terminal device to conduct NAS secure communication with a first satellite based on a first parameter corresponding to the first satellite. When the satellite communicates securely with the terminal device via NAS, the parameter corresponding to the satellite is used as input to the NAS security algorithm to generate a keystream and / or message authentication code corresponding to that satellite. Thus, different keystreams and / or message authentication codes are generated when different satellites communicate with the terminal device, avoiding the problem of keystream and / or message authentication code reuse between satellites. This achieves NAS secure communication between the terminal device and different satellites, improving the security of data transmission between the terminal device and the satellite.

[0142] The methods provided by the embodiments of this application will be described in detail below with reference to the accompanying drawings. The embodiments provided by this application can be applied to the communication system shown in FIG1 and the communication architecture described in FIG2, and are not limited thereto.

[0143] The method provided in the embodiments of this application will first be described with reference to Figures 5 and 6.

[0144] It should be noted that Figure 5 uses terminal equipment, a first satellite, a second satellite, and ground network elements as examples for illustrative purposes. The terminal equipment can be replaced with a terminal or its components (e.g., a chip, chip system, circuit, or communication module); the first satellite can be replaced with its components (e.g., a chip, chip system, circuit, or communication module), and the first satellite carries the first RAN and the first network element; the second satellite can be replaced with its components (e.g., a chip, chip system, circuit, or communication module), and the second satellite carries the second RAN and the second network element; the ground network element can be replaced with its components (e.g., a chip, chip system, circuit, or communication module), where the ground network element can be understood as a core network element carried on ground communication equipment.

[0145] Furthermore, the steps described below as being performed by a single execution entity can also be divided into being performed by multiple execution entities, which may be logically and / or physically separate.

[0146] In the embodiments of this application, the first network element and the second network element can be core network elements. The core network element can be one of the following: access and mobile management function (AMF), MME network element, etc. Alternatively, the core network element can be other core network elements / nodes / devices that can be carried on satellites. This application does not limit the name of the core network element.

[0147] Figure 5 is a schematic diagram of a communication method 500 provided in an embodiment of this application. As shown in Figure 5, the method 500 may include the following steps.

[0148] S510, the first satellite, sends a broadcast message to the terminal equipment.

[0149] Accordingly, the terminal device receives broadcast messages from the first satellite.

[0150] Specifically, when the communication link between the terminal device and the first satellite is available, the first satellite sends a broadcast message to the terminal device.

[0151] The broadcast message includes the identifier of the first satellite, which uniquely identifies the first satellite. Therefore, when the terminal device receives the identifier of the first satellite, it can determine that the satellite currently communicating with the terminal device is the first satellite.

[0152] Optionally, the broadcast message may also include S&F indication information for the first satellite, which indicates that the first satellite supports S&F operation.

[0153] S520: Based on the first parameters indicating the first satellite and / or the network elements carried on the first satellite, the NAS key, and the NAS security algorithm, the terminal device performs NAS secure communication with the first satellite.

[0154] The first parameter, which indicates the network element carried on the first satellite and / or the first satellite, or in other words, the first parameter is used to indicate the network element carried on the first satellite and / or the first satellite. It can be understood that the first parameter corresponds to the network element carried on the first satellite and / or the first satellite.

[0155] For example, the network element carried on the first satellite can be an MME, an AMF, or other core network elements. This application does not limit this. When the network element carried on the first satellite is an MME, it can also be referred to as the first-satellite-on-MME.

[0156] Optionally, NAS secure communication is performed between the first satellite and / or the network element carried on the first satellite, based on the first parameter, NAS key, and NAS security algorithm, including: using the first parameter and NAS key as input to the security algorithm to generate a first key stream and / or a first MAC; and performing NAS secure communication between the first satellite and the first satellite based on the first key stream and / or the first MAC.

[0157] The NAS secure communication between the terminal device and the first satellite includes: NAS encryption and / or integrity protection of NAS messages between the terminal device and the first satellite; or NAS decryption and / or integrity verification of NAS messages between the terminal device and the first satellite.

[0158] For example, the first keystream includes a first encryption keystream or a first decryption keystream; the first MAC includes a first MAC-I / NAS-MAC or a first XMAC-I / XNAS-MAC. The first encryption keystream is used to instruct the terminal device and the first satellite to encrypt NAS messages, and the first decryption keystream is used to instruct the terminal device and the first satellite to decrypt NAS messages. The first MAC-I / NAS-MAC is used to instruct the terminal device and the first satellite to perform NAS message integrity protection, and the first XMAC-I / XNAS-MAC is used to instruct the terminal device and the first satellite to perform NAS message integrity verification.

[0159] As an example, when a terminal device sends an uplink NAS message to a first satellite, the terminal device encrypts and / or protects the integrity of the uplink NAS based on a first parameter, the NAS key, and the NAS security algorithm. For example, the NAS key is the NAS encryption cipher key (K).NAS_enc If the NAS security algorithm is a NAS encryption algorithm, then the first parameter and K... NAS_enc As input to the NAS encryption algorithm, a first encryption key stream is generated, and then the uplink NAS message is encrypted based on this first encryption key stream. The NAS key is the NAS integrity key (K). NAS_int If the NAS security algorithm is a NAS integrity protection algorithm, then the first parameter and K... NAS_int As input to the NAS integrity protection algorithm, a first MAC-I / NAS-MAC is generated, and then integrity protection is performed on the uplink NAS message based on the first MAC-I / NAS-MAC.

[0160] Correspondingly, the first satellite decrypts and verifies the integrity of the uplink NAS based on the first parameter, the NAS key, and the NAS security algorithm. For example, if the NAS key is the NAS decryption key and the NAS security algorithm is the NAS decryption algorithm, then the first parameter and the NAS decryption key are used as inputs to the NAS decryption algorithm to generate a first decryption key stream. The downlink NAS message is then decrypted based on this first decryption key stream. The NAS key is K. NAS_int If the NAS security algorithm is a NAS integrity protection algorithm, then the first parameter and K... NAS_int As input to the NAS integrity protection algorithm, a first XMAC-I / XNAS-MAC is generated, and then the integrity of downlink NAS messages is verified based on the first XMAC-I / XNAS-MAC.

[0161] As an example, when the first satellite sends a downlink NAS message to the terminal device, the first satellite encrypts and / or protects the integrity of the downlink NAS based on the first parameter, the NAS key, and the NAS security algorithm. The terminal device decrypts and / or verifies the integrity of the downlink NAS based on the first parameter, the NAS key, and the NAS security algorithm. The specific implementation details can be found in the description of uplink NAS message encryption / decryption, integrity protection, and integrity verification, and will not be elaborated upon here.

[0162] For example, the first parameter may be included in the bearer and / or counter used as input to the NAS security algorithm. Alternatively, the first parameter may be included in a first field, which is different from the bearer, counter, transmission direction, length, or message used as input to the NAS security algorithm. The first field can be understood as a newly introduced parameter. In this case, the first parameter may be the identifier of the first satellite, or the identifier of a network element carried on the first satellite, or an index corresponding to the identifier of the first satellite or the identifier of a network element carried on the first satellite.

[0163] It should be noted that the first parameter is included in the bearer and / or counter used as input to the NAS security algorithm. This can be understood as the first parameter being carried within the bearer and / or counter, or the first parameter being one of the corresponding numerical ranges of the 5 bits of the bearer and / or the 32 bits of the NAS counter. The first field is included within the first field. This can be understood as the first parameter being carried within the first field, or the first parameter being one of the numerical ranges of the number of bits occupied by the first field.

[0164] As an example, this first parameter is carried in the NAS bearer. Specifically, the first parameter is carried within one of the 5 bits of the NAS bearer's numerical range. In this case, the bearer can carry parameters corresponding to a maximum of 32 satellites. For example, the parameters corresponding to these 32 satellites could be values ​​from 0 to 31. Therefore, the first parameter corresponding to the first satellite could carry the value 1.

[0165] As another example, the first parameter is carried within the NAS counter (COUNT). Specifically, the first parameter is carried within one of the numerical ranges corresponding to the idle 8 bits of the COUNT. For example, the first parameter is carried within the idle 8 bits of the COUNT. In this case, the COUNT can carry parameters corresponding to a maximum of 256 satellites, and the first parameter is carried within one of these 256 values, for example, the first parameter is carried within the value 1.

[0166] As another example, the first parameter is carried in one of the 5 bits of the NAS bearer (BEARER) and the 8 free bits of the COUNT, to carry 2 ^13 The parameters corresponding to each satellite. Then, at this point, the first parameter carries the information of 2 satellites. ^13 One of the values.

[0167] As another example, the first parameter is carried within a NAS counter (COUNT). Specifically, the first parameter is carried within one of the numerical ranges corresponding to the 32 bits of the COUNT. For example, the first parameter is carried within the 32 bits of the COUNT, specifically the 32 bits corresponding to the 2... ^32 The values ​​are divided into segments, and a segment of these segments is used to carry the first parameter. For example, if there are 8 satellites that can be connected to the terminal device, the range of values ​​corresponding to the 32 bits of COUNT is evenly divided to carry the parameters corresponding to these 8 satellites, or the range of values ​​corresponding to the 32 bits of COUNT is non-uniformly divided to carry the parameters corresponding to these 8 satellites.

[0168] One example of equally dividing the COUNT values ​​is to use 2. ^32The value is divided into 8 parts, each part carrying one parameter. For ease of description, we will use the 8 free bits of COUNT as an example. Let 2... ^8 The data is divided into eight equal parts: 0-32, 33-64, 65-96, 97-128, 129-161, 162-193, 193-224, and 224-256. Specifically, 0-32 corresponds to parameter #A, which indicates satellite #A and / or network element #A carried on satellite #A; 33-64 corresponds to parameter #B, which indicates satellite #B and / or network element #B carried on satellite #B; 65-96 corresponds to parameter #3, which indicates satellite #3 and / or network element #3 carried on satellite #3; 97-128 corresponds to parameter #4, which indicates satellite #4 and / or MME #4 carried on satellite #4; 12 9-161 correspond to parameter #5, which indicates satellite #5 and / or network element #5 carried on satellite #5; 162-193 correspond to parameter #6, which indicates satellite #6 and / or network element #6 carried on satellite #6; 193-224 correspond to parameter #7, which indicates satellite #7 and / or network element #3 carried on satellite #7; 224-256 correspond to parameter #8, which indicates satellite #8 and / or network element #8 carried on satellite #8.

[0169] One example of evenly dividing the value of COUNT is to determine the 2 bits of COUNT using its 32 bits. ^32 Divide the values ​​into several categories; specifically, you can also divide 2... ^32 The values ​​are not uniformly divided. Assume there are 8 satellites capable of accessing the terminal device: satellite #A, satellite #B, satellite #3, satellite #4, satellite #5, satellite #6, satellite #7, and satellite #8. Then, the COUNT value of 2... ^32 The value is non-uniformly divided into 8 parts, with each part treated as a parameter. For ease of description, we will use the 8 idle bits of COUNT as an example. Let 2... ^8The data is non-uniformly divided into 8 parts: 0-33, 34-64, 65-100, 101-128, 129-165, 165-193, 193-220, and 221-256. Specifically, 0-33 corresponds to parameter #A, which indicates satellite #A and / or network element #A carried on satellite #A; 34-64 corresponds to parameter #B, which indicates satellite #B and / or network element #B carried on satellite #B; 65-100 corresponds to parameter #3, which indicates satellite #3 and / or network element #3 carried on satellite #3; 101-128 corresponds to parameter #4, which indicates satellite #4 and / or network element #4 carried on satellite #4; 1 29-165 corresponds to parameter #5, which indicates satellite #5 and / or network element #5 carried on satellite #5; 165-193 corresponds to parameter #6, which indicates satellite #6 and / or network element #6 carried on satellite #6; 193-220 corresponds to parameter #7, which indicates satellite #7 and / or network element #3 carried on satellite #7; 221-256 corresponds to parameter #8, which indicates satellite #8 and / or network element #8 carried on satellite #8.

[0170] In another implementation, the 32 bits of COUNT are divided according to the data of the terminal device; that is, the size of the terminal device data determines the division of the 32 bits of COUNT.

[0171] For example, before conducting NAS secure communication with the first satellite based on the first parameter, NAS key, and NAS security algorithm of the network element carried on the first satellite and / or the first satellite, the terminal device needs to obtain the first parameter. For instance, the terminal device may determine the correspondence between the first parameter or at least one parameter and the information of at least one satellite, and then send it to the first satellite; or the terminal device may obtain the correspondence between at least one parameter and the information of at least one satellite from the first satellite or the second satellite. The terminal device obtaining the first parameter can occur before step S510, or after step S510 and before step S520.

[0172] The terminal device obtains the first parameter, either by determining the first parameter itself or by obtaining it from a satellite (e.g., a first satellite or a second satellite). Specifically, the terminal device can obtain the first parameter in the following two ways (Method 1 and Method 2).

[0173] Method 1: The terminal device determines the first parameter itself.

[0174] Scenario 1: The terminal device determines the correspondence between at least one parameter and information from at least one satellite. This specifically includes step S511.

[0175] S511, The terminal device determines the first correspondence.

[0176] The first correspondence includes a correspondence between at least one parameter and information from at least one satellite.

[0177] The information for each satellite in the at least one satellite information includes the identifier of each satellite and / or the identifier of the network element carried on each satellite. In this case, the correspondence between at least one parameter and the information of at least one satellite can be understood as a one-to-one correspondence between at least one parameter and the identifier of at least one satellite, or a one-to-one correspondence between at least one parameter and the identifier of the network element carried on at least one satellite. Therefore, the information for the first satellite includes the identifier of the first satellite and / or the identifier of the network element carried on the first satellite.

[0178] Optionally, the at least one satellite includes the first satellite, the at least one parameter includes the first parameter, and the information of the at least one satellite includes the information of the first satellite.

[0179] It should be noted that the at least one satellite refers to a satellite capable of accessing the terminal device, and in this case, the at least one satellite is a satellite in the monitoring list. That is, the terminal device can determine the corresponding parameters for the information of each satellite in the monitoring list. The terminal device can obtain the monitoring list itself or obtain it from other satellites.

[0180] It should also be noted that if the terminal device determines the first correspondence, it is considered that the terminal device obtains the correspondence between the first parameter and the information of the first satellite.

[0181] For example, suppose the monitoring list includes three satellites, such as satellite #1, satellite #2, and satellite #3. Then the first correspondence includes the correspondence between the information of satellite #1 and the first parameter, the correspondence between the information of satellite #2 and the second parameter, and the correspondence between the information of satellite #3 and parameter #3. For instance, the identifier of satellite #1 corresponds to the first parameter, the identifier of satellite #2 corresponds to the second parameter, and the identifier of satellite #3 corresponds to parameter #3. Another example is that the identifiers of network elements carried on satellite #1 correspond to the first parameter, the identifiers of network elements carried on satellite #2 correspond to the second parameter, and the identifiers of network elements carried on satellite #3 correspond to parameter #3.

[0182] In case 1, step S511 occurs before S510. That is, the terminal device can first determine the first correspondence. If the communication link between the terminal device and the first satellite is available, the terminal device receives a broadcast message from the first satellite and then obtains the identifier of the first satellite. Then, based on the identifier of the first satellite, the terminal device determines the first parameter.

[0183] In other words, the terminal device determines the first parameter based on the correspondence between the first parameter and the information of the first satellite. Then, the terminal device conducts NAS secure communication with the first satellite based on the first parameter, the NAS key, and the NAS security algorithm.

[0184] In one implementation, after determining the first parameter, the terminal device sends the first parameter to the first satellite via an uplink message.

[0185] In one implementation, the terminal device sends the first correspondence to the first satellite, and the first satellite determines the first parameter based on its own identifier.

[0186] For example, before the first satellite is connected to the terminal device, the terminal device first conducts NAS secure communication with the second satellite. That is, the second satellite is the satellite that is connected before the terminal device. At this time, after the terminal device determines the first correspondence, it can determine the second parameter corresponding to the second satellite based on the identifier of the second satellite.

[0187] Furthermore, the terminal device communicates securely with the second satellite based on the second parameter, the NAS key, and the NAS security algorithm.

[0188] The detailed implementation of the terminal device communicating securely with the second satellite based on the second parameter, NAS key, and NAS security algorithm can be found in the description of the terminal device communicating securely with the first satellite based on the first parameter, NAS key, and NAS security algorithm in step S520 above. Simply replace the first parameter with the second parameter, the first satellite with the second satellite, the first key stream with the second key stream, and the first MAC with the second MAC.

[0189] It should be noted that after the terminal device determines the first correspondence, it can determine the second parameter corresponding to the second satellite based on the identifier of the second satellite. This can be understood as the terminal device determining the second parameter for the second satellite. In this case, the second parameter is used to indicate the second satellite and / or the network elements carried on the second satellite. Alternatively, the second parameter may be included in the bearer and / or counter used as input to the NAS security algorithm; or the second parameter may be included in a first field, where the first field differs from the bearer, counter, transmission direction, and length used as input to the NAS security algorithm.

[0190] The description of the second parameter included in the bearer and / or counter used as input to the NAS security algorithm, and the description of the second parameter included in the first field, can be found in the description of the first parameter above. Simply replace the first parameter with the second parameter, and it will not be repeated here.

[0191] In one implementation, if the second satellite is the initially registered satellite—that is, the second satellite is the first satellite to access the terminal device—the terminal device may not assign parameters to the second satellite. In this case, the second parameter is a default value. For example, the second parameter could be a default BEARER value and / or COUNT value, which is used as input to the NAS security algorithm.

[0192] Scenario 2: The terminal device determines parameters for each accessed satellite. This specifically includes steps S511a and S512a.

[0193] S511a, the terminal equipment determines the first parameters for the first satellite.

[0194] In case 2, step S511a occurs after step S510.

[0195] For example, the terminal device obtains the identifier of the first satellite through a broadcast message, and based on the identifier of the first satellite, the terminal device generates the corresponding first parameter for the first satellite.

[0196] Furthermore, the terminal device communicates securely with the first satellite based on the first parameter, the NAS key, and the NAS security algorithm.

[0197] For a detailed description of the first parameter, please refer to the description of step S520 above, which will not be repeated here.

[0198] S512a, The terminal equipment sends the first parameter to the first satellite.

[0199] Correspondingly, the first satellite receives the first parameters from the terminal equipment.

[0200] It should be noted that steps S511a and S512a occur when the communication link between the terminal device and the first satellite is available.

[0201] Furthermore, the first satellite stores the corresponding first parameters.

[0202] In one implementation, when the communication link between the terminal device and the second satellite is available, the terminal device obtains the identifier of the second satellite through a broadcast message sent by the second satellite. Then, the terminal device can determine second parameters for the second satellite and send these second parameters to the second satellite. Furthermore, the second satellite stores the corresponding second parameters.

[0203] For a detailed description of the second parameter, please refer to step S520 above, which will not be repeated here.

[0204] Method 2: The terminal device obtains the first parameter from the accessed satellite. This includes scenarios 1, 2, and 3.

[0205] In Method 2, the parameters corresponding to each satellite are determined by the ground network element and then sent to the terminal device via the first or second satellite.

[0206] Scenario 1: The ground network element obtains the first correspondence and then sends it to the second satellite. This includes steps S501 to S503.

[0207] S501, Ground network elements obtain the first correspondence.

[0208] The description of the first correspondence can be found in step S511 above, and will not be repeated here.

[0209] For example, before the ground network element obtains the first correspondence, it also obtains a monitoring list, which includes at least one satellite, all of which are satellites that the terminal device can access. Then, the ground network element can determine the corresponding parameters for the information of each satellite in the monitoring list.

[0210] For example, the monitoring list can be generated by the second satellite and then sent to the ground network element if a communication link between the second satellite and the ground network element is available. Alternatively, the ground network element can generate the monitoring list itself. Or, the monitoring list can be generated by a network element other than the first and second satellites, for example, by a network element specifically responsible for predicting satellite paths, and then that network element sends the monitoring list to the ground network element.

[0211] It should be noted that satellite sets can also be obtained through other means in this application, and the embodiments of this application do not limit the method of obtaining satellite sets by ground MME.

[0212] S502, the ground network element sends the first correspondence to the second satellite.

[0213] Correspondingly, the second satellite receives the first correspondence from the ground network element.

[0214] Specifically, when the communication link between the ground network element and the second satellite is available, the ground network element sends the first correspondence to the second satellite.

[0215] It should be noted that if the second satellite is the initially registered satellite, meaning it is the first satellite to access the terminal device, the ground network element may not need to assign parameters to the second satellite. The second parameter is a default value. In this case, the first correspondence does not include the correspondence between the second parameter and the information of the second satellite, but it does include the correspondence between the first parameter and the information of the first satellite.

[0216] S503, the second satellite sends the first correspondence to the terminal equipment.

[0217] Accordingly, the terminal device receives the first correspondence from the second satellite.

[0218] Step S503 occurs when the communication link between the terminal device and the second satellite is available.

[0219] At this point, the terminal device obtains the first correspondence. For example, the terminal device receives the correspondence between the first parameter from the second satellite and the information from the first satellite.

[0220] Furthermore, if the communication link between the ground network element and the first satellite is available, the ground network element sends the first parameter to the first satellite. Then, if the communication link between the terminal device and the first satellite is available, step S510 is executed. Afterwards, the terminal device determines the first parameter based on the correspondence between the first parameter and the information of the first satellite. Specifically, the terminal device determines the first parameter based on this correspondence and the identifier of the first satellite. Then, the terminal device and the first satellite conduct NAS secure communication based on the first parameter, the NAS key, and the NAS security algorithm.

[0221] It should be noted that if the second satellite is connected to the terminal device before the first satellite, then step S503 is executed before the terminal device connects to the first satellite. In other words, step S503 occurs before step S511a.

[0222] Scenario 2: The ground network element obtains the first correspondence and then sends it to the first satellite. This specifically includes steps S501a to S503a.

[0223] S501a, Ground network elements obtain the first correspondence.

[0224] For a detailed description of step S501a, please refer to step S501 above, which will not be repeated here.

[0225] S502a, the ground network element sends the first correspondence to the first satellite.

[0226] Correspondingly, the first satellite receives the first correspondence from the ground network element.

[0227] Specifically, when the communication link between the ground network element and the first satellite is available, the ground network element sends the first correspondence to the first satellite. At this time, the first satellite obtains the first parameter corresponding to it.

[0228] S503a, The first satellite sends the first correspondence to the terminal equipment.

[0229] Accordingly, the terminal device receives the first correspondence from the first satellite.

[0230] Step S503a occurs when the communication link between the terminal device and the first satellite is available.

[0231] At this point, the terminal device obtains the first correspondence. Or, in other words, the terminal device obtains the correspondence between the first parameter and the information of the first satellite.

[0232] Furthermore, the terminal device determines the first parameter based on the correspondence between the first parameter and the information of the first satellite. Specifically, if the communication link between the terminal device and the first satellite is available, step S510 is executed, after which the terminal device determines the first parameter based on the correspondence and the identifier of the first satellite. Then, the terminal device and the first satellite conduct NAS secure communication based on the first parameter, the NAS key, and the NAS security algorithm.

[0233] It should be noted that before communicating with the first satellite, the terminal device first connects to the second satellite and communicates with it. Therefore, the time the terminal device connects to the second satellite may differ from the time it connects to the first satellite. Consequently, the terminal device's location, satellite orbit parameters, etc., may change, and the satellites in the monitoring list obtained by the ground network element may also differ. Thus, it is necessary to send the first correspondence obtained by the ground network element to each connected satellite separately. That is, the ground network element sends the first correspondence to the second satellite, which then forwards it to the terminal device.

[0234] For a detailed description of the second satellite, please refer to step S503 above, which will not be repeated here.

[0235] Scenario 3: The ground network element determines parameters for each currently accessing satellite and then sends them to the satellite. This specifically includes steps S501b to S503b.

[0236] S501b, the ground network element determines the first parameter.

[0237] Specifically, the ground network element acquires information from the first satellite and determines the first parameter based on that information.

[0238] For a detailed description of the first parameter, please refer to step S520 above, which will not be repeated here.

[0239] S502b, the ground network element sends the first parameter to the first satellite.

[0240] Correspondingly, the first satellite receives the first parameters from the ground network element.

[0241] Specifically, when the communication link between the ground network element and the first satellite is available, the ground network element sends the first parameter to the first satellite.

[0242] For example, the ground network element can also determine a second parameter for the second satellite and send the second parameter to the second satellite when the communication link between the ground network element and the second satellite is available. The terminal device and the second satellite then perform NAS secure communication based on the second parameter, the NAS key, and the NAS security algorithm.

[0243] It should be noted that if the second satellite is the initially registered satellite, meaning it is the first satellite to access the terminal device, the ground network element does not need to assign parameters to the second satellite. The second parameter is the default value. In this case, the ground network element does not need to send the second parameter to the second satellite.

[0244] S503b: The first satellite sends the first parameter to the terminal equipment.

[0245] Accordingly, the terminal equipment receives the first parameters from the first satellite.

[0246] Step S503b occurs when the communication link between the terminal device and the first satellite is available.

[0247] At this point, the terminal device acquires the first parameter. Then, the terminal device and the first satellite conduct NAS secure communication based on the first parameter, the NAS key, and the NAS security algorithm.

[0248] In this application, in addition to methods one and two, the terminal device can also obtain the first parameter in the following way. Specifically, the first satellite determines the first parameter, and then, if the communication link between the terminal device and the first satellite is available, sends the first parameter to the terminal device. Correspondingly, the terminal device receives the first parameter from the first satellite.

[0249] In this scenario, the first satellite determines the first parameter, or it can configure the first parameter itself. If the second satellite also determines its own parameter, then the second satellite configures its own second parameter.

[0250] In this embodiment, the terminal device communicates securely with the first satellite based on first parameters corresponding to the first satellite, and communicates securely with the second satellite based on second parameters corresponding to the second satellite. This ensures that different satellites use different parameters as input to the NAS security algorithm when communicating securely with the terminal device, generating different keystreams and / or message authentication codes, thus avoiding the reuse of keystreams and / or message authentication codes between satellites. This achieves secure NAS communication between the terminal device and different satellites, guaranteeing the security of data transmission between the terminal device and the satellites.

[0251] The above-described communication method 500 corresponds to communication methods 700 to 1000 below. Specifically, communication method 700 is a detailed description of steps S501 to S503, communication method 800 is a detailed description of steps S501b to S503b, communication method 900 is a detailed description of steps S511a to S512a, and communication method 1000 is a detailed description of step S511.

[0252] Figure 6 is a schematic diagram of a communication method 600 provided in an embodiment of this application. Figure 6 uses a terminal device and a first satellite as examples for illustrative purposes. The terminal device can be replaced by a terminal or a component of a terminal device (e.g., a chip, chip system, circuit, or communication module); the first satellite can be replaced by a component of a first satellite (e.g., a chip, chip system, circuit, or communication module), and the first satellite carries a first RAN and a first network element. Communication method 600 corresponds to communication method 1100 hereinafter referred to as communication method 600.

[0253] As shown in Figure 6, the method 600 shown in Figure 6 may include the following steps.

[0254] S610: The terminal device provides security protection for uplink NAS messages based on the uplink counter value and NAS key.

[0255] It should be understood that in this application, security protection may specifically be encryption / decryption, and / or integrity protection / integrity verification.

[0256] For example, the terminal device uses the uplink counter value and the NAS key as input to the NAS encryption algorithm to generate a first uplink keystream. The uplink NAS message is then encrypted based on this first uplink keystream. The terminal device also uses the uplink counter value and the NAS key as input to the NAS integrity protection algorithm to generate a first uplink MAC. This is followed by MAC-I / NAS-MAC. The uplink NAS message is then protected for integrity based on this first uplink MAC.

[0257] For example, the first uplink keystream includes a first uplink encryption keystream or a first uplink decryption keystream; the first uplink MAC includes a first uplink MAC-I / NAS-MAC or a first uplink XMAC-I / XNAS-MAC. The first encryption keystream is used to instruct the terminal device and the first satellite to encrypt NAS messages, and the first decryption keystream is used to instruct the terminal device and the first satellite to decrypt NAS messages. The first uplink MAC-I / NAS-MAC is used to instruct the terminal device and the first satellite to perform NAS message integrity protection, and the first uplink XMAC-I / XNAS-MAC is used to instruct the terminal device and the first satellite to perform NAS message integrity verification. The uplink counter value information is the uplink counter value information #B in the following method embodiment 1100. The first uplink MAC-I / NAS-MAC is the uplink MAC-I / NAS-MAC#B in the following method embodiment 1100.

[0258] The description of the value information of the uplink counter can be found in step S620 below, and will not be repeated here.

[0259] S620, the terminal equipment sends an uplink NAS message for security protection to the first satellite.

[0260] Accordingly, the first satellite receives a NAS message from the terminal device regarding security protection.

[0261] Specifically, when the communication link between the terminal device and the first satellite is available, the terminal device sends a secure uplink NAS message to the first satellite.

[0262] The uplink NAS message includes the values ​​of the uplink counter and the downlink counter. Upon receiving the uplink NAS message, the first satellite stores the values ​​of both the uplink and downlink counters.

[0263] Optionally, the uplink counter value is determined based on the uplink NAS message between the terminal device and the second satellite, which is a satellite that the terminal device accessed before accessing the first satellite and that has sent uplink NAS messages to the terminal device; the downlink counter value is determined based on the downlink NAS message between the terminal device and the third satellite, which is a satellite that the terminal device accessed before accessing the first satellite and that has sent downlink NAS messages to the terminal device, and the value of the uplink counter is different from the value of the uplink counter corresponding to the uplink NAS message between the terminal device and the second satellite.

[0264] For example, the downlink counter value corresponding to the downlink NAS message between the third satellite and the terminal device is different from the downlink counter value corresponding to the downlink NAS message between the first satellite and the terminal device. For instance, the downlink counter value corresponding to the downlink NAS message between the first satellite and the terminal device is the downlink counter value corresponding to the downlink NAS message between the third satellite and the terminal device plus 1.

[0265] For example, the second and third satellites can be the same satellite or different satellites. When the second and third satellites are the same satellite, it can be understood that either the second or third satellite will receive uplink NAS messages and also send downlink NAS messages. When the second and third satellites are different satellites, it can be understood that the second satellite receives uplink NAS messages but does not send downlink NAS messages. The downlink NAS messages are sent by the third satellite.

[0266] For example, before the terminal device connects to the first satellite, it first connects to a second satellite, which may be the satellite initially registered by the terminal device. The terminal device and the second satellite perform NAS secure communication. During this process, the terminal device and the second satellite exchange secure NAS messages. Each time the terminal device sends a secure uplink NAS message to the second satellite, the value of the uplink counter maintained locally on the terminal device is incremented by 1. The terminal device determines the value of the uplink counter only after the last uplink NAS message.

[0267] For example, each time the third satellite sends a security protection downlink NAS message to the terminal device, the value of the downlink counter maintained locally by the third satellite will be incremented by 1, and then the terminal device will determine the value information of the downlink counter through the last downlink NAS message.

[0268] Optionally, the downlink counter value is determined based on the downlink NAS message between the terminal device and the third satellite, including: the downlink counter value is determined based on the SQN in the downlink NAS message between the terminal device and the third satellite. Specifically, the sequence number SQN in the downlink NAS message received from the third satellite is used as the downlink NAS SQN of the downlink counter value; or the downlink counter value is obtained by adding 1 to the SQN in the downlink NAS message received from the third satellite.

[0269] For example, when the downlink NAS message received by the terminal device from the third satellite is the last downlink NAS message, the SQN in that last NAS message is used as the downlink NAS SQN of the downlink counter value information. In other words, the downlink counter value information includes the SQN in that downlink NAS message.

[0270] For example, when the downlink NAS message received by the terminal device from the third satellite is the last downlink NAS message, the downlink counter value information is obtained by adding 1 to SQN in that last NAS message. For instance, if the downlink NAS SQN has not flipped when SQN is added by 1, the downlink counter value information includes the downlink NAS SQN. As another example, if the downlink NAS SQN has flipped when SQN is added by 1, the downlink counter value information includes the downlink NAS SQN and downlink NAS overflow value related information. The downlink NAS overflow value related information can be the downlink NAS overflow value, information indicating an increment of the downlink NAS overflow value, or information indicating a flip of the downlink SQN.

[0271] The situation regarding the downlink NAS SQN flipping can be found in step S1109 below, and will not be repeated here.

[0272] Optionally, the value of the downlink counter is a first value of the downlink counter maintained or stored by the terminal device plus 1; or the value of the downlink counter is a first value of the downlink counter locally stored or recorded by the terminal device.

[0273] For example, the value of the downlink counter can be 1 plus a first value of the downlink counter maintained or stored by the terminal device, and then sent to the first satellite via a NAS message; or, the value of the downlink counter can be the same as the first value of the downlink counter maintained or stored by the terminal device, and then sent to the first satellite by the terminal device via a NAS message. In this case, when the first satellite receives the downlink counter value information in the NAS message, it can use the downlink counter value information as input to the NAS security algorithm to perform security protection on the uplink NAS message.

[0274] Optionally, the first value of the downlink counter stored locally by the terminal device is obtained based on SQN+1 in the downlink NAS message received from the third satellite. The SQN of the first value of the downlink counter stored locally by the terminal device is the sequence number SQN in the downlink NAS message received from the third satellite. Alternatively, the SQN of the first value of the downlink counter stored locally by the terminal device is obtained based on the sequence number SQN+1 in the downlink NAS message received from the third satellite.

[0275] For example, if the third satellite transmits a downlink NAS message including the SQN, the terminal device can increment the SQN by 1 and use it as the first value of its locally stored downlink counter. In this case, the value of the downlink counter is the first value of the downlink counter stored locally on the terminal device. That is, since the first value of the downlink counter stored locally on the terminal device is obtained by adding 1 to the SQN, the value of the downlink counter does not need to be incremented by 1 when transmitting the downlink counter value information to the first satellite.

[0276] It is understandable that if the SQN of the first value of the downlink counter stored locally on the end device is the same as the SQN in the downlink NAS message sent by the third satellite, then when sending the downlink counter value information to the first satellite, the value of the downlink counter can be incremented by 1.

[0277] In other words, the downlink NAS SQN in the downlink counter value information can be obtained by adding 1 to the SQN in the downlink NAS message, or it can be obtained by directly using the SQN in the downlink NAS message as the downlink NAS SQN in the downlink counter value information.

[0278] In one implementation, when the uplink NAS SQN flips, the uplink NAS overflow value is incremented by 1.

[0279] For example, each time the terminal device sends an uplink NAS message, the value of the uplink NAS SQN maintained or stored locally on the terminal device is incremented by 1. When the uplink NAS SQN increases to its maximum value, if there are still uplink NAS messages, the uplink NAS SQN will increment from the maximum value. At this time, the value of the uplink NAS SQN will be flipped, and the value of uplink NAS OVERFLOW will be incremented by 1, for example, the value of uplink NAS OVERFLOW will be incremented to 1. When the uplink NAS SQN increases to its maximum value again and starts to increment from the maximum value, the value of uplink NAS OVERFLOW will be incremented by 1 again. That is, every time the value of uplink NAS SQN increases to its maximum value, and then there is another uplink NAS message sent, the uplink NAS SQN will start to increase from the maximum value, and the value of uplink NAS OVERFLOW will be incremented by 1. At this time, the value of uplink NAS OVERFLOW will be incremented by 1, and the value of uplink NAS SQN will be set to 0.

[0280] In one implementation, the uplink counter value information includes the uplink NAS SQN. If the uplink counter value undergoes an SQN flip, the uplink counter value information also includes the uplink NAS SQN. Alternatively, the uplink NAS message may also include information indicating that the uplink NAS SQN has flipped. Or, the uplink NAS message may also include information indicating that the uplink NAS overflow value is incremented.

[0281] If the uplink counter value does not undergo an SQN toggle, the uplink counter value includes the uplink NAS SQN. At this time, the uplink NAS overflow value does not increment; therefore, the uplink counter value does not include the uplink NAS overflow value.

[0282] For example, the value information of the uplink counter may include any of the following: the highest 8 bits of the uplink counter default value of 0, and / or the uplink NAS overflow value, and / or the uplink NAS SQN; the value information of the downlink counter may include any of the following: the highest 8 bits of the downlink counter default value of 0, and / or the downlink NAS overflow value, and / or the downlink NAS SQN.

[0283] In one implementation, the terminal device determines the first value of the uplink counter based on the local NAS SQN and the local uplink NAS OVERFLOW, and performs security protection on the uplink NAS messages based on the first value of the uplink counter and the NAS key.

[0284] As an example, when the uplink counter value information includes the uplink NAS SQN, the uplink NAS SQN is determined based on the NAS SQN of the terminal local storage.

[0285] As an example, when the uplink counter value information includes uplink NAS SQN and uplink NAS OVERFLOW, the uplink NAS SQN and uplink NAS OVERFLOW are determined based on the terminal local storage NAS SQN and local storage NAS OVERFLOW.

[0286] It should be noted that the first satellite can obtain the uplink NAS OVERFLOW and / or downlink NAS OVERFLOW from the ground network element, or the first satellite can use the uplink NAS OVERFLOW and / or downlink NAS OVERFLOW sent by the terminal device last time.

[0287] In one implementation, when the downlink NAS SQN flips, the downlink NAS overflow value is incremented by 1.

[0288] For example, for each downlink NAS message sent by the first satellite, the downlink NAS SQN value maintained or stored locally by the first satellite is incremented by 1. When the downlink NAS SQN increases to its maximum value, if there are still downlink NAS messages, the downlink NAS SQN increments from the maximum value. At this time, the downlink NAS SQN value flips, and the downlink NAS OVERFLOW value is incremented by 1, for example, the downlink NAS OVERFLOW value is incremented to 1. When the downlink NAS SQN increases to its maximum value again and starts incrementing from the maximum value, the downlink NAS OVERFLOW value is incremented by 1 again. That is, every time the downlink NAS SQN value increases to its maximum value, and another downlink NAS message is sent, the downlink NAS SQN starts increasing from the maximum value, and the downlink NAS OVERFLOW value is incremented by 1. At this time, the uplink NAS OVERFLOW value is incremented by 1, and the downlink NAS SQN value is set to 0.

[0289] In one implementation, the uplink counter value information includes the uplink NAS SQN. If the downlink counter value has flipped, the downlink counter value information also includes the downlink NAS SQN. Alternatively, the uplink NAS message may also include information indicating that the downlink NAS SQN has flipped, or the uplink NAS message may also include information indicating that the downlink NAS overflow value is incremented.

[0290] For example, if the downlink counter value does not undergo an SQN flip, the downlink counter value information includes the downlink NAS SQN, but does not include the downlink NAS overflow value.

[0291] In one implementation, the terminal sends a security protection NAS message to the first satellite, including: when the terminal device receives a paging message from the first satellite, sending the security protection NAS message to the first satellite. At this time, the terminal device determines that the first satellite has sent downlink messages to the terminal device, and then sends uplink counter value information and downlink counter value information to the first satellite.

[0292] In one implementation, the NAS key is the same as the NAS key used when the second satellite and the terminal device communicate securely.

[0293] For example, the NAS key used when the first satellite and the terminal device communicate securely is NAS key #1, and the NAS key used when the second satellite and the terminal device communicate securely is NAS key #2. When NAS key #1 and NAS key #2 are the same, the terminal device sends the value information of the uplink counter and the value information of the downlink counter to the first satellite. In this way, when the first satellite and the second satellite communicate securely with the terminal device, the input of the NAS security algorithm is different, and different key streams can be generated.

[0294] In one implementation, the terminal device sends a secure uplink NAS message to the first satellite, including: sending the secure NAS message to the first satellite if the NAS key is the same as the NAS key used when the second satellite and the terminal device conduct NAS secure communication.

[0295] In one implementation, the terminal device sends a security-protected uplink NAS message to the first satellite, including sending the security-protected uplink NAS message to the first satellite if the first satellite and the second satellite belong to the same satellite group or set.

[0296] For example, the first satellite and the second satellite belong to the same satellite group or set. This can be understood as the identifier of the first satellite and the identifier of the second satellite belonging to the same satellite group or set, wherein the satellites in the same satellite group or set are of the same type.

[0297] Optionally, before the terminal device sends a security protection uplink NAS message to the first satellite, the method 600 further includes step S611.

[0298] S611. The terminal device determines the value information of the uplink counter and the downlink counter.

[0299] The implementation method for the terminal device to determine the value information of the uplink counter and the downlink counter can be found in step S620 above, and will not be repeated here.

[0300] In one implementation, determining the value information of the uplink counter and the value information of the downlink counter includes: determining the value information of the uplink counter and the value information of the downlink counter based on the satellite group, set, or connected ground network element to which the first satellite belongs.

[0301] Among them, satellites in the same group, set, or connected to the same ground network element have the same NAS key.

[0302] For example, the terminal device determines the satellite group or set to which the first satellite belongs or the ground network element it is connected to. Then, based on the satellite group or set to which the first satellite belongs or the ground network element it is connected to, it determines which satellites are in the satellite group or set to which the first satellite belongs, or which other satellites the ground network element connected to the first satellite can also connect to. Then, based on the satellites in these satellite groups or sets or the satellites connected to the ground network element, it determines the uplink counter value information and downlink counter value information corresponding to these satellites, and then determines the uplink counter value information and downlink counter value information.

[0303] S630: The first satellite performs security protection on the uplink NAS messages between the terminal device and the first satellite based on the uplink counter value information and the NAS key.

[0304] For example, the first satellite uses the uplink counter value and the NAS key as input to the NAS decryption algorithm to generate a decryption keystream. The uplink NAS message is then decrypted based on this decryption keystream. The first satellite also uses the uplink counter value and the NAS key as input to the NAS integrity algorithm to generate a first uplink XMAC-I / XNAS-MAC. The integrity of the uplink NAS message is then verified based on this first uplink XMAC-I / XNAS-MAC.

[0305] For example, the first satellite determines the first value of the uplink counter based on the value information of the uplink counter, and performs de-security protection on the uplink NAS messages between the terminal device and the first satellite based on the first value of the uplink counter and the NAS key.

[0306] For example, the first satellite determines a first value of the uplink counter based on the uplink counter value information, including: when the uplink counter value information includes the uplink NAS SQN, the first satellite determines the first value of the uplink counter based on the local uplink NAS overflow value and the uplink NAS SQN; or when the NAS message also includes information for indicating the uplink NAS overflow value to increment, and the uplink counter value information includes the uplink NAS SQN, the first satellite determines the first value of the uplink counter based on the local uplink NAS overflow value plus 1 and the uplink NAS SQN; or when the uplink counter value information includes both the uplink NAS SQN and the uplink NAS overflow value, the first satellite determines the first value of the uplink counter based on both the uplink NAS overflow value and the uplink NAS SQN.

[0307] Optionally, method 600 further includes steps S640 and S650, as detailed below.

[0308] S640: The first satellite securely protects downlink NAS messages between the terminal device and the first satellite based on the downlink counter value information and the NAS key.

[0309] For example, the first satellite uses the downlink counter value and the NAS key as input to the NAS encryption algorithm to generate a first downlink encryption key stream. The downlink NAS message is then encrypted based on this first downlink encryption key stream. The first satellite also uses the downlink counter value and the NAS key as input to the NAS integrity algorithm to generate a first downlink MAC-I / NAS-MAC. The downlink NAS message is then protected for integrity based on this first downlink MAC-I / NAS-MAC.

[0310] For example, the first satellite determines a second value of the downlink counter based on the downlink counter value information, and performs security protection on the downlink NAS messages between the terminal device and the first satellite based on the second value of the downlink counter and the NAS key.

[0311] For example, the first satellite determines a second value of the downlink counter based on the downlink counter value information, including: when the downlink counter value information includes the downlink NAS SQN, the first satellite determines the second value of the downlink counter based on the local downlink NAS overflow value and the downlink NAS SQN; or when the NAS message also includes information indicating the increment of the downlink NAS overflow value, and the downlink counter value information includes the downlink NAS SQN, the first satellite determines the second value of the downlink counter based on the local downlink NAS overflow value plus 1 and the downlink NAS SQN; or when the downlink counter value information includes both the downlink NAS SQN and the downlink NAS overflow value, the first satellite determines the second value of the downlink counter based on both the downlink NAS overflow value and the downlink NAS SQN.

[0312] In one implementation, the first satellite determines a first value of the uplink counter based on the value information of the uplink counter, and performs de-security protection on the uplink NAS messages between the terminal device and the first satellite based on the first value of the uplink counter and the NAS key; the second value of the downlink counter is determined based on the value information of the downlink counter, and the second value of the downlink counter and the NAS key are used to perform security protection on the downlink NAS messages between the terminal device and the first satellite.

[0313] In one implementation, when the uplink counter value information includes the uplink NAS SQN, the first satellite determines a first value of the uplink counter based on the local uplink NAS overflow value and the uplink NAS SQN; when the downlink counter value information includes the downlink NAS SQN, the first satellite determines a second value of the downlink counter based on the local downlink NAS overflow value and the downlink NAS SQN.

[0314] In one implementation, when the uplink counter value information includes the uplink NAS SQN, the first satellite determines a first value of the uplink counter based on the local uplink NAS overflow value and the uplink NAS SQN; when the NAS message also includes information for indicating the increment of the downlink NAS overflow value, and the downlink counter value information includes the downlink NAS SQN, the first satellite determines a second value of the downlink counter based on the local downlink NAS overflow value plus 1 and the downlink NAS SQN.

[0315] In one implementation, when the uplink counter value information includes the uplink NAS SQN, the first satellite determines the first value of the uplink counter based on the local uplink NAS overflow value and the uplink NAS SQN; when the downlink counter value information includes the downlink NAS SQN and the downlink NAS overflow value, the first satellite determines the first value of the uplink counter based on the downlink NAS overflow value and the downlink NAS SQN.

[0316] In one implementation, when the NAS message also includes information indicating an increment of the uplink NAS overflow value, and the uplink counter value information includes the uplink NAS SQN, the first satellite determines a first value of the uplink counter based on the local uplink NAS overflow value plus 1 and the uplink NAS SQN; when the downlink counter value information includes the downlink NAS SQN, the first satellite determines a second value of the downlink counter based on the local downlink NAS overflow value and the downlink NAS SQN.

[0317] In one implementation, when the NAS message also includes information indicating an increment of the uplink NAS overflow value, and the uplink counter value information includes the uplink NAS SQN, the first satellite determines a first value of the uplink counter based on the local uplink NAS overflow value plus 1 and the uplink NAS SQN; when the NAS message also includes information indicating an increment of the downlink NAS overflow value, and the downlink counter value information includes the downlink NAS SQN, the first satellite determines a second value of the downlink counter based on the local downlink NAS overflow value plus 1 and the downlink NAS SQN.

[0318] In one implementation, when the NAS message also includes information indicating an increment of the uplink NAS overflow value, and the uplink counter value information includes the uplink NAS SQN, the first satellite determines a first value of the uplink counter based on the local uplink NAS overflow value plus 1 and the uplink NAS SQN; when the downlink counter value information includes the downlink NAS SQN and the downlink NAS overflow value, the first satellite determines a second value of the downlink counter based on the downlink NAS overflow value and the downlink NAS SQN.

[0319] In one implementation, when the uplink counter value includes the uplink NAS SQN and the uplink NAS overflow value, the first satellite determines a first value of the uplink counter based on the uplink NAS overflow value and the uplink NAS SQN; when the downlink counter value includes the downlink NAS SQN, the first satellite determines a second value of the downlink counter based on the local downlink NAS overflow value and the downlink NAS SQN.

[0320] In one implementation, when the uplink counter value information includes the uplink NAS SQN and the uplink NAS overflow value, the first satellite determines a first value of the uplink counter based on the uplink NAS overflow value and the uplink NAS SQN; when the NAS message also includes information for indicating the increment of the downlink NAS overflow value, and the downlink counter value information includes the downlink NAS SQN, the first satellite determines a second value of the downlink counter based on the local downlink NAS overflow value plus 1 and the downlink NAS SQN.

[0321] In one implementation, when the uplink counter value information includes the uplink NAS SQN and the uplink NAS overflow value, the first satellite determines the first value of the uplink counter based on the uplink NAS overflow value and the uplink NAS SQN; when the downlink counter value information includes the downlink NAS SQN and the downlink NAS overflow value, the first satellite determines the second value of the downlink counter based on the downlink NAS overflow value and the downlink NAS SQN.

[0322] The information used to indicate the increment of the NAS overflow value can also be used to indicate the NAS SQN flip.

[0323] S650, the first satellite sends a downlink NAS message for security protection to the terminal equipment.

[0324] Accordingly, the terminal device receives a downlink NAS message from the first satellite for security protection.

[0325] The downlink NAS message includes the third value of the downlink counter, which is either the value of the downlink counter or the value of the downlink counter + 1.

[0326] For example, after the first satellite secures the downlink NAS message based on the downlink counter value and the NAS key, the first satellite sends the downlink NAS message to the terminal device. At this time, the downlink NAS message will include a third value of the downlink counter.

[0327] In one implementation, the third value is the second value of the downlink counter. That is, after the terminal device and the first satellite complete NAS secure communication or the communication is disconnected, the third value of the downlink counter maintained or stored locally by the terminal device is the second value of the downlink counter mentioned above. Then, the terminal device synchronizes the value of the downlink counter to the next satellite to be accessed.

[0328] In one implementation, the third value is the second value of the downlink counter plus 1. That is, after the terminal device and the first satellite complete NAS secure communication or the communication is disconnected, the third value of the downlink counter maintained or stored locally by the terminal device is the value of the downlink counter plus 1. Then the terminal device synchronizes the third value of the downlink counter to the next satellite to be accessed.

[0329] In this embodiment of the application, when the terminal device communicates with different satellites, the terminal device transmits the uplink counter value information and downlink counter value information to different satellites through uplink NAS messages, so that different satellites can generate different key streams and / or MACs based on different uplink counter value information and downlink counter value information, thereby realizing NAS secure connection between the terminal device and different satellites and ensuring secure data transmission between the terminal device and each satellite.

[0330] Figure 7 is a schematic diagram of a communication method 700 provided in an embodiment of this application. As shown in Figure 7, the method is described using a UE, RAN#A, on-board MME#A, RAN#B, on-board MME#B, and a ground MME as examples. RAN#A and on-board MME#A are carried on satellite A, which is the second satellite in the above embodiment; RAN#B and on-board MME#B are carried on satellite #B, which is the first satellite in the above embodiment. It should be noted that method 700 is a more detailed description of the schemes in steps S501 to S503. Method 700 may include the following multiple steps.

[0331] If the service link #A between the UE and satellite #A is available, assuming the UE is initially registered to satellite #A, then steps S701 to S703 are executed.

[0332] S701, RAN#A sends broadcast message #1 to UE.

[0333] Accordingly, the UE receives broadcast message #1 from RAN#A.

[0334] The broadcast message #1 includes the identifier (ID) of satellite #A. The ID of satellite #A can uniquely identify satellite #A, so that when the UE receives the ID of satellite #A, it can determine that the satellite currently communicating with the UE is satellite #A.

[0335] This application uses a Service and Flow (S&F) scenario in an NTN network as an example. In the S&F scenario, the communication links between the UE and the satellite, and between the satellite and the ground MME, are not simultaneously available. In other words, the service link between the satellite and the UE, and the power supply link between the satellite and the ground MME, cannot be available simultaneously. For example, satellite #A cannot simultaneously communicate with both the UE and the ground MME. Specifically, when the service link between satellite #A and the UE is available, the power supply link between satellite #A and the ground MME is unavailable; in this case, the UE sends a message to satellite #A. When the power supply link between satellite #A and the ground MME is available, the service link between satellite #A and the UE is unavailable; in this case, satellite #A sends the message received from the UE to the ground MME. The interaction between satellite #A and satellite #B needs to be achieved through the ground MME. For example, satellite #A sends data to the ground MME, and then the ground MME forwards the data to satellite #B.

[0336] For example, the UE receives broadcast message #1 from RAN#A when the communication link with satellite #A is available. That is, the UE receives broadcast message #1 from RAN#A when the service link #A between the UE and satellite #A is available.

[0337] For example, the broadcast message #1 also includes S&F indication information for satellite #A, which indicates that satellite #A supports S&F operation.

[0338] S702, The UE sends request information #1 to the onboard MME#A.

[0339] Accordingly, the onboard MME#A receives request information #1 from the UE.

[0340] The request information #1 contains the identifier corresponding to the UE, the UE's store-and-forward capability, and the UE's security capabilities.

[0341] For example, the identifier corresponding to the UE can be the International Mobile Subscriber Identity (IMSI); the UE having store-and-forward capability can be understood as the UE supporting the S&F architecture or the UE supporting S&F operation.

[0342] For example, request information #1, also known as attach request or registration request information, is used to request attaching or registering to a satellite network.

[0343] Furthermore, after receiving the request information #1, the satellite MME#A determines whether it has a UE's security context. If there is no UE's security context on satellite #A, satellite #A sends a response information #1 to the UE for request information #1. That is, step S703 is executed.

[0344] S703, the onboard MME#A sends response information #1 to the UE.

[0345] Accordingly, the UE receives response information #1 from the onboard MME#A.

[0346] Response information #1 indicates that the connection establishment between the terminal device and the onboard MME #A failed. This response information #1 includes a waiting time, which is the waiting time for the UE to establish a connection with the next satellite.

[0347] Optionally, the response information #1 may also include a monitoring list, where the next satellite to be accessed is a candidate satellite from the monitoring list.

[0348] For a description of the monitoring list, please refer to step S511 above, which will not be repeated here.

[0349] The security context of a UE can include K ASME #A and / or eKSI#A, where eKSI#A is used to identify K ASME #A.

[0350] It should be noted that during the initial UE registration process described above, satellite #A does not have the UE's security context. Therefore, satellite #A can obtain the UE's security context and / or subscription information from the ground-based MME. If satellite #A has the UE's security context during steps S701 to S703, step S704 will not be executed.

[0351] Specifically, when the power supply link #A between the ground MME and satellite #A is available, or in other words, when the communication link between satellite #A and the ground MME is available, step S704 is executed.

[0352] S704, Onboard MME#A obtains the authentication vector (AV).

[0353] Specifically, the onboard MME #A sends request message #2 to the ground MME. Correspondingly, the ground MME receives request message #2 from the onboard MME #A.

[0354] In this context, request message #2 is a message from the satellite MME #A forwarding request message #1 to the ground MME.

[0355] Then, the ground MME sends an authentication data request to the HSS based on the request information #2. The HSS generates an AV based on the authentication data request and the IMSI in the request information #2, and sends it to the on-board MME #A. The on-board MME #A then stores and uses the AV.

[0356] AV is used for authentication and includes the following parameters: random number (RAND), authentication token (AUTN), expected response (XRES), and key #A (K). ASME #A). RAND is used to generate the parameters required for authentication; AUTN is used to verify the UE's identity; XRES is used to compare with the response calculated by the UE.

[0357] It should be noted that when storing AV, the onboard MME#A also stores the identifier K. ASME #A's eKSI#A and / or UE's contract information. Regarding K ASME The usage of #A and eKSI#A can be found in existing technologies, and will not be elaborated here.

[0358] In step S704, the onboard MME#A obtains the security context of the UE.

[0359] For example, after step S704, the ground MME also performs steps S705 to S707.

[0360] S705, Ground MME obtains satellite list.

[0361] This satellite list is also known as the monitoring list.

[0362] For a detailed description of the monitoring list and how ground network elements obtain the monitoring list, please refer to step S501 above, which will not be repeated here.

[0363] S706, Ground MME determines the corresponding relationship #1.

[0364] Among them, correspondence #1 is an example of the first correspondence mentioned above. For details on how the ground MME obtains correspondence #1, please refer to step S501 above, which will not be repeated here.

[0365] It should be noted that if the number of satellites requiring parameter allocation exceeds the 32 values ​​corresponding to 5 bits of the BEARER, the ground MME or the onboard MME#A can update the aforementioned NAS key#A. In this case, the NAS key input to the NAS security algorithm is updated, and the ground MME sends the updated NAS key to the onboard MME#A. The onboard MME#A then uses the new NAS key to generate a keystream.

[0366] It should also be noted that the ground-based MME is not limited to determining parameters for satellites in the monitoring list, but can also assign parameters to all satellites that may connect to the UE.

[0367] S707, the ground MME sends the corresponding relationship #1 to the satellite MME#A.

[0368] Correspondingly, the onboard MME#A receives the corresponding relationship #1 from the ground MME.

[0369] For a detailed description of step S707, please refer to step S502 above, which will not be repeated here.

[0370] After obtaining the correspondence #1 from the onboard MME#A, this correspondence #1 can be sent to the terminal device. This correspondence #1 can include information about satellite #A and its corresponding parameter #A (an example of the second parameter). For ease of description, the following description uses the example of correspondence #1 including satellite #A information and its corresponding parameter #A. However, it is understood that correspondence #1 may not include satellite #A information and its corresponding parameter #A; in this case, parameter #A is considered a default value.

[0371] For a detailed description of parameter #A, please refer to the descriptions in steps S501 to S503 above, which will not be repeated here.

[0372] Furthermore, when the service link #A between the onboard MME#A and the UE becomes available, the terminal device and the satellite #A conduct NAS secure communication.

[0373] S708, RAN#A sends broadcast message #2 to UE.

[0374] Accordingly, the UE receives broadcast message #2 from RAN#A.

[0375] For a detailed description of broadcast message #2, please refer to step S701 above, which will not be repeated here.

[0376] It should be noted that broadcast message #1 and broadcast message #2 can also come from different satellites. In other words, the satellite accessing the UE can be a satellite other than satellite #A.

[0377] At this point, the satellite #A that interacts with the UE in steps S701-S703 can be a different satellite or the same satellite as the satellite in steps S708-S722b. In other words, the satellite that initially receives the UE request message and the satellite that completes authentication and security establishment with the UE can be different satellites or the same satellite.

[0378] S709, UE sends request information #3 to MME#A on satellite.

[0379] Accordingly, the onboard MME#A receives request information #3 from the UE.

[0380] Regarding request information #3, please refer to the description of request information #1 in step S702 above, which will not be repeated here.

[0381] Furthermore, after receiving the request information #3, the on-board MME#A initiates an authentication request to the UE. NAS secure communication is then initiated between the UE and the on-board MME#A. Specifically, this is illustrated in steps S710 to S718.

[0382] S710, the onboard MME#A sends request information #4 to the UE.

[0383] Accordingly, the UE receives request information #4 from the onboard MME#A.

[0384] The request information #4 includes the authentication token AUTN, a random number, and eKSI#A. The request information #4 is used to request the UE to authenticate the on-board MME#A.

[0385] S711a, UE generation K ASME #A.

[0386] Among them, K is generated ASME The process of #A can be found in existing technology and will not be repeated here.

[0387] S711b, onboard MME#A based on K ASME #A Generate NAS Key#A.

[0388] Among them, NAS key #A includes K NAS_enc #A and K NAS_int #A.

[0389] S711c, onboard MME#A based on K NAS_int #A, parameter #A, and NAS integrity protection algorithm are used to protect the integrity of downlink NAS messages.

[0390] Specifically, K NAS_int#A and parameter #A are used as inputs to the NAS integrity protection algorithm to generate MAC-I / NAS-MAC#A (an example of the second MAC).

[0391] It should be noted that steps S711a to S711b described above can occur simultaneously, and this application does not limit this.

[0392] Furthermore, the onboard MME#A performs integrity protection on downlink NAS messages based on MAC-I / NAS-MAC#A and sends secure downlink NAS messages to the UE, such as NAS security mode command message #A.

[0393] S712, the onboard MME#A sends a NAS security mode command message#A to the UE.

[0394] Accordingly, the UE receives the NAS security mode command message #A from the onboard MME#A.

[0395] The NAS security mode command message #A includes the NAS security algorithm and parameter #A. The NAS security algorithm includes the NAS encryption / decryption algorithm and the NAS integrity protection algorithm.

[0396] It should be noted that if the ground MME does not specify parameter #A for satellite #A, the NAS security mode command message #A will not contain parameter #A, and in this case, parameter #A will use the default value.

[0397] S713, UE based on K NAS_int The #A parameter and the NAS integrity verification algorithm perform integrity verification on the NAS security mode command message #A.

[0398] Specifically, UE will K NAS_int #A and parameter #A are used as inputs to the NAS integrity verification algorithm to generate XMAC-I#A / XNAS-MAC#A (an example of the second MAC).

[0399] If the NAS security mode command message #A passes the integrity check, the UE executes step S714.

[0400] S714. The UE performs security protection on the uplink NAS message #A based on the NAS key #A, parameter #A, and NAS security algorithm.

[0401] For example, the NAS security algorithm is a NAS encryption / decryption algorithm, and the NAS key #A is K. NAS_enc #A, then K NAS_enc#A and parameter #A are used as inputs to the NAS encryption / decryption algorithm to generate an encryption key stream #A (an example of a second encryption key stream). Uplink NAS messages are then encrypted using this key stream #A. The NAS security algorithm is the NAS integrity protection algorithm, and the NAS key #A is K. NAS_int #A, then K NAS_int #A and parameter #A are used as inputs to the NAS integrity protection algorithm to generate MCA-I / NAS-MAC#A. Integrity protection is performed on uplink NAS messages based on MCA-I / NAS-MAC#A. In addition, the inputs to the NAS integrity protection algorithm also include COUNT, DIRECTION, and uplink NAS messages.

[0402] Furthermore, the UE sends a security-protected uplink NAS message, such as NAS security mode completion message #A, to the on-board MME#A. Specifically, step S715 is executed.

[0403] S715, UE sends NAS security mode completion message #A to onboard MME#A.

[0404] Accordingly, the onboard MME#A receives the NAS security mode completion message #A from the UE.

[0405] The NAS security mode completion message #A is a message encrypted with the key stream #A generated by the UE, and a message with integrity protection provided by the MCA-I / NAS-MAC #A generated by the UE. The NAS security mode completion message indicates that the NAS security negotiation between the UE and the on-board MME #A is complete.

[0406] S716, Onboard MME#A decrypts and verifies the integrity of NAS security mode completion message #A.

[0407] Specifically, the onboard MME#A decrypts and verifies the integrity of the NAS security mode completion message #A based on parameter #A, NAS key #A, and NAS integrity verification algorithm.

[0408] For example, the NAS security algorithm is the NAS decryption algorithm, and the NAS key #A is K. NAS_enc #A, then K NAS_enc #A and parameter #A are used as inputs to the NAS decryption algorithm to generate a decryption keystream #A (an example of a second decryption keystream). The NAS security mode completion message #A is then decrypted based on the decryption keystream #A. The NAS security algorithm is the NAS integrity protection algorithm, and the NAS key #A is K. NAS_int #A, then K NAS_int#A and parameter #A serve as inputs to the NAS integrity protection algorithm, generating XMCA-I / XNAS-MAC#A. Integrity verification is performed on the NAS security mode completion message #A based on XMCA-I / XNAS-MAC#A. In addition, the inputs to the NAS integrity protection algorithm also include COUNT, DIRECTION, and the NAS security mode completion message #A.

[0409] S717, the onboard MME#A sends response information #3 to the UE.

[0410] Accordingly, the UE receives response information #3 from the onboard MME#A.

[0411] Among them, response information #3 includes the above-mentioned correspondence #1.

[0412] As an example, the corresponding relationship #1 can also be carried in other downlink messages, such as NAS security mode command messages, downlink NAS messages, etc.

[0413] For example, response information #3 also includes the aforementioned monitoring list. Response information #3 is also known as attach acceptance information, meaning that when the UE receives response information #3, it signifies that the UE has successfully attached to the current satellite network.

[0414] Step S717 corresponds to step S503 above, and will not be repeated here.

[0415] S718, Terminal Device Storage Correspondence #1.

[0416] In other words, the UE obtains the corresponding relationship #1 through the aforementioned response information #3 and saves it. When the UE needs to access another satellite later, it can use this corresponding relationship #1 to determine the parameters of the satellite to be accessed. Then, based on the parameters of the satellite to be accessed, the NAS key, and the NAS security algorithm, it can conduct NAS secure communication with the satellite. Since different satellites have different parameters, the keystreams / MACs generated by the MMEs on different satellites are different, thus protecting the NAS secure communication between the terminal device and different satellites.

[0417] Optionally, when data transmission is required between the UE and the on-board MME#A, the UE sends an uplink NAS message to the on-board MME#A; or the on-board MME#A sends a downlink NAS message #A to the UE. For example, if the UE has data to transmit to the on-board MME#A, then step S719 is executed. That is to say, step S719 is only executed when there is data to be transmitted between the UE and the on-board MME#A.

[0418] S719, UE sends uplink NAS message #A to onboard MME#A.

[0419] Accordingly, the onboard MME#A receives the uplink NAS message #A from the UE.

[0420] It is understandable that when the on-board MME#A transmits data to the UE, step S719 can also be that the on-board MME#A sends a downlink NAS message #A to the UE. Accordingly, the UE receives the downlink NAS message #A from the on-board MME#A.

[0421] Furthermore, the UE and the onboard MME#A store each other's uplink counter value and downlink counter value, respectively.

[0422] S720a, UE stores the value of the downlink counter corresponding to satellite #A.

[0423] Optionally, the UE also stores the parameter #A corresponding to satellite #A. This allows the UE to determine that the parameters of the subsequently accessed satellite are different from those of satellite #A when accessing another satellite.

[0424] Optionally, the UE also stores the values ​​of the NAS uplink counters corresponding to some satellites #A.

[0425] The S720b satellite MME#A stores the NAS uplink counter value corresponding to the UE.

[0426] Optionally, the onboard MME#A also stores the values ​​of some NAS downlink counters corresponding to the UEs.

[0427] Furthermore, when the power supply link #B between the ground MME and satellite #B is available, or in other words, when the communication link between the ground MME and satellite #B is available, the MME #B carried on satellite #B obtains the IMSI, the UE's subscription information, key #A and eKSI #A, and the parameters #B corresponding to satellite #B. Specifically, the UE will conduct NAS secure communication with satellite #B, including the following step S721.

[0428] Before introducing step S721, it is necessary to explain the key #A and eKSI #A obtained by MME #B carried on satellite #B. Specifically, in the embodiments of this application, satellite #A and satellite #B use the same key when communicating with the UE. ASME #A means that all keys use the key #A.

[0429] S721, Ground MME sends message #1 to satellite MME #B.

[0430] Accordingly, the onboard MME #B receives information #1 from the ground-based MME.

[0431] Information #1 includes parameter #B, which is used to indicate satellite #B and / or the MME carried on satellite #B.

[0432] Optionally, information #1 may also include IMSI, key #A, and eKSI #A. If key #A is not included in information #1, then NAS key #A may be included.

[0433] In one possible implementation, when the service link #B between the UE and satellite #B is available, or in other words, when the communication link between the UE and satellite #B is available, the RAN #B carried on satellite #B sends a broadcast message #3 to the UE. This includes the following steps S722 to S725b.

[0434] Step S721 corresponds to step S503 above.

[0435] S722, RAN#B sends broadcast message #3 to UE.

[0436] Accordingly, the UE receives broadcast message #3 from RAN#B.

[0437] Broadcast message #3 includes the ID of satellite #B. The ID of satellite #B can uniquely identify satellite #B, so that when the UE receives the ID of satellite #B, it can determine that the satellite currently communicating with the UE is satellite #B.

[0438] For example, the broadcast message #3 also includes S&F indication information for satellite #B, which indicates that satellite #B supports S&F operation.

[0439] Step S722 corresponds to step S510 above. That is, broadcast message #3 refers to the broadcast message in step S510 above.

[0440] S723, UE determines parameter #B based on satellite #B's ID.

[0441] Specifically, the UE determines the parameter #B corresponding to the ID of satellite #B based on the ID of satellite #B and the corresponding relationship #1.

[0442] Among them, parameter #B is an example of the first parameter mentioned above. For a detailed description of parameter #B, please refer to step S520 above. For the UE to determine parameter #B, please refer to step S503 above. It will not be repeated here.

[0443] S724. Based on parameter #B, NAS key #A, and NAS security algorithm, perform NAS secure communication with the on-board MME #B.

[0444] For a detailed description of step S724, please refer to step S520 above, which will not be repeated here.

[0445] S725a, UE stores the value of the downlink counter corresponding to satellite #B.

[0446] Optionally, the UE also stores the satellite #B corresponding to parameter #B. This ensures that when the UE accesses another satellite after satellite #B, it can determine that the parameters corresponding to the subsequently accessed satellite are different from those corresponding to satellite #B.

[0447] Optionally, the UE also stores the values ​​of the uplink counters corresponding to some satellites #B.

[0448] The S725b and onboard MME#B store the value of the uplink counter corresponding to the UE.

[0449] Optionally, the onboard MME#B also stores the values ​​of some downlink counters corresponding to UEs.

[0450] It should also be noted that the uplink NAS message #A and downlink NAS message #A in the above steps can both be NAS messages for security protection between the second satellite and the terminal device in the above embodiments, and the uplink NAS message #B and downlink NAS message #B can both be NAS messages for security protection between the first satellite and the terminal device in the above embodiments.

[0451] In this embodiment of the application, parameters are assigned to different satellites through a ground-based MME so that each satellite corresponds to different parameters.

[0452] Figure 8 is a schematic diagram of a communication method 800 provided in an embodiment of this application. As shown in Figure 8, the method is described using a UE, RAN#A, on-board MME#A, RAN#B, on-board MME#B, and a ground MME as examples. RAN#A and on-board MME#A are carried on satellite A, which is the second satellite in the above embodiment; RAN#B and on-board MME#B are carried on satellite #B, which is the first satellite in the above embodiment. It should be noted that method 800 is a more detailed description of the scheme in steps S501b to S503b above. Method 800 may include the following multiple steps.

[0453] If the service link #A between the UE and satellite #A is available, assuming the UE is initially registered to satellite #A, then steps S801 to S803 are executed.

[0454] S801, RAN#A sends broadcast message #1 to UE.

[0455] Accordingly, the UE receives broadcast message #1 from RAN#A.

[0456] S802, the UE sends request information #1 to the onboard MME#A.

[0457] Accordingly, the onboard MME#A receives request information #1 from the UE.

[0458] S803, the onboard MME#A sends response information #1 to the UE.

[0459] Accordingly, the UE receives response information #1 from the onboard MME#A.

[0460] For a description of steps S801 to S803 above, please refer to steps S701 to S703 above, which will not be repeated here.

[0461] It should be noted that during the initial UE registration process described above, satellite #A does not have the UE's security context. Therefore, satellite #A can obtain the UE's security context and / or the UE's subscription information from the ground MME.

[0462] Specifically, when the power supply link #A between the ground MME and satellite #A is available, or in other words, when the communication link between satellite #A and the ground MME is available, step S804 is executed.

[0463] S804, Star-mounted MME#A obtains AV.

[0464] For a detailed description of how the onboard MME#A acquires AV, please refer to step S704 above, which will not be repeated here.

[0465] Furthermore, the satellite allocation parameters currently connected to the ground-based MME.

[0466] S805, Ground MME determines the parameters #A for satellite #A.

[0467] Among them, correspondence #1 is an example of the first correspondence mentioned above, and parameter #A is an example of the second parameter.

[0468] For a detailed description of how the ground-based MME determines parameter #A for satellite #A, please refer to step S501b above, which will not be repeated here.

[0469] S806, the ground MME sends parameter #A to the satellite MME#1.

[0470] Accordingly, the onboard MME #1 receives parameter #A from the ground MME.

[0471] For a description of parameter #A, please refer to step S502b above, and it will not be repeated here.

[0472] Furthermore, when the service link #A between the onboard MME#A and the UE becomes available, the terminal device and the satellite #A conduct NAS secure communication.

[0473] S807, RAN#A sends broadcast message #2 to UE.

[0474] Accordingly, the UE receives broadcast message #2 from RAN#A.

[0475] S808, UE sends request message #3 to MME#A on satellite.

[0476] Accordingly, the onboard MME#A receives request information #3 from the UE.

[0477] Furthermore, after receiving the request information #3, the on-board MME#A initiates an authentication request to the UE. NAS secure communication is then initiated between the UE and the on-board MME#A. Specifically, see steps S809 to S.

[0478] S809, the onboard MME#A sends request information #4 to the UE.

[0479] Accordingly, the UE receives request information #4 from the onboard MME#A.

[0480] For a detailed description of steps S807 to S809, please refer to steps S708 to S809 above, and they will not be repeated here.

[0481] S810a, UE generates K ASME #A.

[0482] Among them, K is generated ASME The process of #A can be found in existing technology and will not be repeated here.

[0483] After the authentication between the UE and the onboard MME#A is completed, the onboard MME#A will execute steps S811b to S811c.

[0484] S810b, onboard MME#A based on K ASME #A Generate NAS Key#A.

[0485] S810c, on-board MME#A based on K NAS_int #A, parameter #A, and NAS integrity protection algorithm are used to protect the integrity of downlink NAS messages.

[0486] For a detailed description of S810a and S810c, please refer to steps S711a and S711c above, which will not be repeated here.

[0487] Furthermore, the onboard MME#A performs integrity protection on downlink NAS messages based on MAC-I / NAS-MAC#A and sends secure downlink NAS messages to the UE, such as NAS security mode command message #A.

[0488] S811, the onboard MME#A sends a NAS security mode command message#A to the UE.

[0489] S812, UE based on K NAS_int The #A parameter and the NAS integrity verification algorithm perform integrity verification on the NAS security mode command message #A.

[0490] If the NAS security mode command message #A passes the integrity check, the UE executes step S813.

[0491] S813. The UE performs security protection on the uplink NAS message #A based on the NAS key #A, parameter #A, and NAS security algorithm. Detailed descriptions of steps S811 to S813 can be found in steps S712 to S714 above, and will not be repeated here.

[0492] Furthermore, the UE sends a secure uplink NAS message, such as a NAS security mode completion message #A, to the on-board MME #A based on the key stream #A. Specifically, step S814 is executed.

[0493] S814, UE sends NAS security mode completion message #A to onboard MME#A.

[0494] Accordingly, the onboard MME#A receives the NAS security mode completion message #A from the UE.

[0495] S815, the onboard MME#A decrypts and verifies the integrity of the NAS security mode completion message #A.

[0496] For a detailed description of steps S814 to S815, please refer to steps S715 to S716 above, and they will not be repeated here.

[0497] S816, the onboard MME#A sends response information #3 to the UE.

[0498] Accordingly, the UE receives response information #3 from the onboard MME#A.

[0499] The response information #3 includes the aforementioned parameter #A.

[0500] For example, response information #3 also includes a monitoring list. A description of the monitoring list can be found in step S511 above, and will not be repeated here.

[0501] However, it should be noted that in method 800, the monitoring list is determined by the onboard MME#A. In other words, the monitoring list is generated by the onboard MME#A.

[0502] Optionally, response message #3 is used to indicate that the NAS secure connection between the UE and satellite #A has been established.

[0503] Step S816 corresponds to step S503b above, and will not be repeated here.

[0504] S817, UE sends uplink NAS message #A to onboard MME#A.

[0505] Accordingly, the onboard MME#A receives the uplink NAS message #A from the UE.

[0506] It is understandable that when the on-board MME#A transmits data to the UE, step S817 can also involve the on-board MME#A sending a downlink NAS message #A to the UE. Accordingly, the UE receives the downlink NAS message #A from the on-board MME#A.

[0507] At this point, communication between the UE and the on-board MME#A is secure. The uplink NAS message #A sent by the UE can only be received, decrypted, and its integrity verified by the on-board MME#A. Alternatively, the downlink NAS message #A sent by the on-board MME#A can only be received, decrypted, and its integrity verified by the UE.

[0508] Furthermore, the UE and the onboard MME#A store each other's uplink counter value and downlink counter value, respectively.

[0509] S818a, UE stores the value of the downlink counter corresponding to satellite #A.

[0510] Optionally, the UE also stores the parameter #A corresponding to satellite #A. This allows the UE to determine that the parameters of the subsequently accessed satellite are different from those of satellite #A when accessing another satellite.

[0511] Optionally, the UE also stores the values ​​of the uplink counters corresponding to some satellites #A.

[0512] The S818b and onboard MME#A store the uplink and downlink counters corresponding to the UE.

[0513] Optionally, the onboard MME#A also stores the values ​​of some downlink counters corresponding to UEs.

[0514] Furthermore, the ground-based MME determines parameter #B for the onboard MME#B.

[0515] Before introducing step S819, it is necessary to explain the key #A and eKSI #A obtained by MME #B carried on satellite #B. Specifically, in the embodiments of this application, satellite #A and satellite #B use the same key when communicating with the UE. ASME#A means that all keys use the key #A.

[0516] S819, the ground-based MME determines the parameters #B for the on-board MME#B.

[0517] The implementation method of the ground MME determining parameter #B for the satellite MME#B is the same as the implementation method of the ground MME determining parameter #A for the satellite MME#A. Please refer to step S501b above, and it will not be repeated here.

[0518] In one possible implementation, when the service link #B between the ground MME and satellite #B is available, or in other words, when the communication link between the ground MME and satellite #B is available, the MME #B carried on satellite #B obtains the IMSI, the UE's subscription information, key #A and eKSI #A, and the parameter #B corresponding to satellite #B. This includes the following steps S820 to S823b.

[0519] S820, the ground MME sends information #1 to the satellite MME #B.

[0520] Accordingly, the onboard MME #B receives information #1 from the ground-based MME.

[0521] Information #1 includes parameter #B, which indicates satellite #B and / or the MME carried on satellite #B. At this time, the ground MME sends information #1 to the satellite MME #B, which can also be understood as the ground MME sending parameter #B to the satellite MME #B.

[0522] Optionally, information #1 may also include IMSI, key #A, and eKSI #A. If key #A is not included in information #1, then NAS key #A may be included.

[0523] In one possible implementation, when the service link #B between the UE and satellite #B is available, or in other words, when the communication link between the UE and satellite #B is available, the RAN #B carried on satellite #B sends a broadcast message #3 to the UE.

[0524] S821, RAN#B sends broadcast message #3 to UE.

[0525] Accordingly, the UE receives broadcast message #3 from RAN#B.

[0526] In one implementation, broadcast message #3 includes parameter #B.

[0527] In another implementation, method 800 further includes: satellite #B sending downlink message #B to the terminal device. Accordingly, the terminal device receives the downlink message #B from satellite #B. The downlink message #B includes parameter #B. The downlink message #B can be a broadcast message or other downlink messages, which can be RRC messages, NAS messages, or other messages. The sending of downlink message #B by satellite #B to the terminal device can be performed before or after step S821.

[0528] For a detailed description of broadcast message #3, please refer to step S722 above, which will not be repeated here.

[0529] S822, based on parameter #B, NAS key #A and NAS security algorithm, performs NAS secure communication with on-board MME #B.

[0530] For a detailed description of step S822, please refer to step S520 above, which will not be repeated here.

[0531] S823a, UE stores the value of the downlink counter corresponding to satellite #B.

[0532] Optionally, the UE also stores the values ​​of the uplink counters corresponding to some satellites #B.

[0533] Optionally, the UE also stores either satellite #B corresponding to parameter #B or parameter #B corresponding to satellite #B. This allows the UE to determine, when accessing another satellite, that the parameters corresponding to the subsequently accessed satellite are different from the parameters corresponding to satellite #B.

[0534] The S823b and onboard MME#B store the uplink and downlink counters corresponding to the UE.

[0535] Optionally, the onboard MME#B also stores the values ​​of some downlink counters corresponding to UEs.

[0536] It should also be noted that the uplink NAS message #A and downlink NAS message #A in the above steps can both be NAS messages for security protection between the second satellite and the terminal device in the above embodiments, and the uplink NAS message #B and downlink NAS message #B can both be NAS messages for security protection between the first satellite and the terminal device in the above embodiments.

[0537] In the embodiments of this application, when the communication link between the ground MME and different satellites is available, parameters are assigned to different satellites so that each satellite corresponds to different parameters.

[0538] Figure 9 is a schematic diagram of a communication method 900 provided in an embodiment of this application. As shown in Figure 9, the method is described using a UE, RAN#A, on-board MME#A, RAN#B, on-board MME#B, and ground MME as examples. RAN#A and on-board MME#A are carried by satellite A, which is the second satellite in the above embodiment; RAN#B and on-board MME#B are carried by satellite #B, which is the first satellite in the above embodiment. It should be noted that method 900 is a more detailed description of the scheme in steps S511a to S512a. Method 900 may include the following multiple steps.

[0539] If the service link #A between the UE and satellite #A is available, assuming the UE is initially registered to satellite #A, then steps S901 to S903 are executed.

[0540] S901, RAN#A sends broadcast message #1 to UE.

[0541] Accordingly, the UE receives broadcast message #1 from RAN#A.

[0542] For a detailed description of broadcast message #1, please refer to step S701 above, which will not be repeated here.

[0543] S902, the UE sends request information #1 to the onboard MME#A.

[0544] Accordingly, the onboard MME#A receives request information #1 from the UE.

[0545] In one implementation, the request information #1 includes parameter #A corresponding to satellite #A. In this case, the UE assigns parameter #A to satellite #A.

[0546] In one implementation, when the satellite is the satellite to which the UE initially accesses or attaches, the UE does not assign parameter #A to satellite #A. In this case, parameter #A can be considered as a default value, such as 0.

[0547] In another implementation, the UE determines that parameter #A corresponding to satellite #A is a default value. That is, when satellite #A is the initial satellite accessing the UE, the input parameters of the NAS security algorithm are all default values ​​when secure communication occurs between satellite #A and the UE. In this case, the UE does not need to send parameter #A to satellite #A; satellite #A uses the default value by default. It should be noted that when the UE determines that parameter #A corresponding to satellite #A is a default value, the parameters corresponding to the next accessing satellite are assigned by the UE. For example, if the next accessing satellite is satellite #B, the UE assigns parameter #B to satellite #B. This parameter #B is not a default value; that is, parameter #B is different from parameter #A.

[0548] Specifically, before the UE sends request information #1 to the on-board MME#A, method 900 also includes: the UE determining parameters #A for satellite #A.

[0549] Meanwhile, the onboard MME#A will save the parameter #A corresponding to satellite #A so that satellite #A can continue to use parameter #A the next time it accesses the UE.

[0550] For a detailed description of step S902 and the UE determining parameter #A for satellite #A, please refer to step S512a above, which will not be repeated here.

[0551] S903, the onboard MME#A sends response information #1 to the UE.

[0552] Accordingly, the UE receives response information #1 from the onboard MME#A.

[0553] For a detailed description of response information #1, please refer to step S703 above, which will not be repeated here.

[0554] It should be noted that during the initial UE registration process described above, satellite #A does not have the UE's security context. Therefore, satellite #A can obtain the UE's security context and / or subscription information from the ground-based MME. If satellite #A has the UE's security context during steps S901 to S903, step S904 will not be executed.

[0555] Specifically, when the power supply link #A between the ground MME and satellite #A is available, or in other words, when the communication link between satellite #A and the ground MME is available, step S904 is executed.

[0556] S904, Star-mounted MME#A obtains AV.

[0557] For a detailed description of how the onboard MME#A acquires AV, please refer to step S704 above, which will not be repeated here.

[0558] Furthermore, when the service link #A between the onboard MME#A and the UE becomes available, the terminal device and the satellite #A conduct NAS secure communication.

[0559] S905, RAN#A sends broadcast message #2 to UE.

[0560] Accordingly, the UE receives broadcast message #2 from RAN#A.

[0561] For a detailed description of broadcast message #2, please refer to step S709 above, which will not be repeated here.

[0562] S906, UE sends request information #3 to MME#A on satellite.

[0563] Accordingly, the onboard MME#A receives request information #3 from the UE.

[0564] For a detailed description of steps S905 and S906, please refer to steps S708 and S709 above, which will not be repeated here.

[0565] Furthermore, after receiving the request information #3, the on-board MME#A initiates an authentication request to the UE. NAS secure communication is then initiated between the UE and the on-board MME#A, as detailed in steps S907 to S908.

[0566] S907, the onboard MME#A sends request information #4 to the UE.

[0567] Accordingly, the UE receives request information #4 from the onboard MME#A.

[0568] For a detailed description of request information #4, please refer to step S710 above, which will not be repeated here.

[0569] S908a, UE generation K ASME #A.

[0570] After the authentication between the UE and the onboard MME#A is completed, the onboard MME#A will execute steps S909b to S909c.

[0571] S908b, onboard MME#A based on K ASME #A Generate NAS Key#A.

[0572] S908c, onboard MME#A based on K NAS_int #A, parameter #A, and NAS integrity protection algorithm are used to protect the integrity of downlink NAS messages.

[0573] For a detailed description of steps S908a and S908c, please refer to steps S711a and S712c above, and they will not be repeated here.

[0574] Furthermore, integrity protection is performed on downlink NAS messages based on MAC-I / NAS-MAC#A, and a secure downlink NAS message, such as NAS security mode command message #A, is sent to the UE. S909 and the onboard MME#A send the NAS security mode command message #A to the UE.

[0575] S910, UE based on K NAS_int The #A parameter and the NAS integrity verification algorithm perform integrity verification on the NAS security mode command message #A.

[0576] If the NAS security mode command message #A passes the integrity check, the UE executes step S911.

[0577] S911, the UE provides security protection for the uplink NAS message #A based on the NAS key #A, parameter #A, and NAS security algorithm.

[0578] Furthermore, the UE sends a security-protected uplink NAS message, such as a NAS security mode completion message #A, to the onboard MME#A. Specifically, step S912 is executed.

[0579] S912, UE sends NAS security mode completion message #A to onboard MME#A.

[0580] Accordingly, the onboard MME#A receives the NAS security mode completion message #A from the UE.

[0581] S913, the onboard MME#A decrypts and verifies the integrity of the NAS security mode completion message #A.

[0582] For a detailed description of steps S910 and S913, please refer to steps S712 and S716 above, and they will not be repeated here.

[0583] S914, the onboard MME#A sends response information #3 to the UE.

[0584] Accordingly, the UE receives response information #3 from the onboard MME#A.

[0585] For example, response message #3 includes a monitoring list.

[0586] For a description of the monitoring list, please refer to step S705 above, which will not be repeated here.

[0587] However, it should be noted that in method 900, the monitoring list is determined by the onboard MME#A. In other words, the monitoring list is generated by the onboard MME#A.

[0588] Optionally, response message #3 is used to indicate that the NAS secure connection between the UE and satellite #A has been established.

[0589] S915, UE sends uplink NAS message #A to onboard MME#A.

[0590] Accordingly, the onboard MME#A receives the uplink NAS message #A from the UE.

[0591] For a detailed description of step S915, please refer to step S719 above, and it will not be repeated here.

[0592] S916a, UE stores the value of the downlink counter corresponding to satellite #A.

[0593] Optionally, the UE also stores the values ​​of the uplink counters corresponding to some satellites #A.

[0594] Optionally, the UE also stores the parameter #A corresponding to satellite #A. This allows the UE to determine that the parameters of the subsequently accessed satellite are different from those of satellite #A when accessing another satellite.

[0595] The S916b satellite MME#A stores the value of the uplink counter corresponding to the UE.

[0596] Optionally, the onboard MME#A also stores the values ​​of some downlink counters corresponding to UEs.

[0597] Furthermore, when the power supply link #B between the ground MME and satellite #B is available, or in other words, when the communication link between the ground MME and satellite #B is available, the MME #B carried on satellite #B obtains the IMSI, the UE's subscription information, key #A, and eKSI #A. Specifically, the UE will conduct NAS secure communication with satellite #B, including the following step S917.

[0598] Before introducing step S917, it is necessary to explain the key #A and eKSI #A obtained by MME #B carried on satellite #B. Specifically, in the embodiments of this application, satellite #A and satellite #B use the same key when communicating with the UE. ASME #A means that all keys use the key #A.

[0599] S917, Ground MME sends message #1 to satellite MME #B.

[0600] Accordingly, the onboard MME #B receives information #1 from the ground-based MME.

[0601] Information #1 includes IMSI, key #A, and eKSI #A. If key #A is not included in information #1, then NAS key #A will be included.

[0602] In one possible implementation, when the service link #B between the UE and satellite #B is available, or in other words, when the communication link between the UE and satellite #B is available, the RAN #B carried on satellite #B sends a broadcast message #3 to the UE. This includes the following steps S918 to S923b.

[0603] S918, RAN#B sends broadcast message #3 to UE.

[0604] Accordingly, the UE receives broadcast message #3 from RAN#B.

[0605] For a detailed description of broadcast message #3, please refer to step S722 above, which will not be repeated here.

[0606] S919, UE determines the parameters for satellite #B.

[0607] Specifically, the UE receives the satellite #B ID from broadcast message #3, and determines parameter #B based on the satellite #B ID from broadcast message #3.

[0608] It should be noted that when determining parameter #B for UE satellite #B, this parameter #B is different from the parameter #A mentioned above, to ensure that different satellites correspond to different parameters.

[0609] Step S919 corresponds to step S511a above, and will not be repeated here.

[0610] S920 provides security protection for uplink NAS message #B based on parameter #B, NAS key #A, and NAS security algorithm.

[0611] For example, the NAS security algorithm is a NAS encryption / decryption algorithm, and the NAS key #A is K. NAS_enc #A, then K NAS_enc #A and parameter #B are used as inputs to the NAS encryption / decryption algorithm to generate an encryption key stream B (an example of the first encryption key stream). The uplink NAS message #B is then encrypted using this key stream. The NAS security algorithm is the NAS integrity protection algorithm, and the NAS key #A is K. NAS_int #A, then K NAS_int #A and parameter #B are used as inputs to the NAS integrity protection algorithm to generate MCA-I / NAS-MAC#B (an example of the first MAC). Integrity protection is performed on the uplink NAS message #B based on MCA-I / NAS-MAC#B. In addition, the inputs to the NAS integrity protection algorithm also include COUNT, DIRECTION, and uplink NAS message #B.

[0612] S921, UE sends uplink NAS message #B to onboard MME#B.

[0613] Accordingly, the onboard MME#B receives the uplink NAS message#B from the UE.

[0614] Among them, the uplink NAS message #B is a message encrypted by the key stream #B generated by the UE, and the message protected for integrity by the MCA-I / NAS-MAC#B generated by the UE.

[0615] It is understandable that when the on-board MME#B transmits data to the UE, step S921 can also involve the on-board MME#B sending a downlink NAS message#B to the UE. Accordingly, the UE receives the downlink NAS message#B from the on-board MME#B.

[0616] In one implementation, the uplink NAS message #B includes the parameter #B. That is, the UE sends the parameter #B to the on-board MME #B via the uplink message #B. In another implementation, method 900 further includes: the terminal device sending the uplink message #B to the satellite #B. Correspondingly, the satellite #B receives the uplink message #B from the terminal device. The uplink message #B includes the parameter #B. The uplink message #B can be any other uplink message, which can be an RRC message, a NAS message, or any other message. The terminal device sending the uplink message #B to the satellite #B can be performed before or after step S921.

[0617] Step S921 corresponds to step S512a above.

[0618] S922, the onboard MME#B decrypts and verifies the integrity of the uplink NAS message #B.

[0619] Specifically, the onboard MME#B decrypts and verifies the integrity of the uplink NAS message #B based on parameter #B, NAS key #A, and NAS integrity verification algorithm.

[0620] In one implementation, the uplink NAS and downlink NAS messages #B include parameter #B, and the on-board MME #B obtains parameter #B from the uplink message sent by the UE.

[0621] In another implementation, the onboard MME#B determines parameter #B based on the satellite #B's ID, and the determination method can be found in step S919 above. However, it is understood that the onboard MME#B uses the same method to determine parameter #B as the UE does for satellite #B.

[0622] For example, the NAS security algorithm is the NAS decryption algorithm, and the NAS key #A is K. NAS_enc #A, then K NAS_enc #A and parameter #B are used as inputs to the NAS decryption algorithm to generate a decryption keystream #B (an example of the first decryption keystream). The NAS uplink message #B is then decrypted based on this decryption keystream #B. The NAS security algorithm is a NAS integrity verification algorithm, and the NAS key #A is K. NAS_int #A, then K NAS_int#A and parameter #B are used as inputs to the NAS integrity verification algorithm to generate XMCA-I / XNAS-MAC#B. The integrity of the uplink NAS message #B is verified based on XMCA-I / XNAS-MAC#B. In addition, the inputs to the NAS integrity protection algorithm also include COUNT, DIRECTION, and uplink NAS message #B.

[0623] S923a, UE stores the value of the downlink counter corresponding to satellite #B.

[0624] Optionally, the UE also stores the values ​​of the uplink counters corresponding to some satellites #B.

[0625] Optionally, the UE also stores the satellite #B corresponding to parameter #B. This ensures that when the UE accesses another satellite after satellite #B, it can determine that the parameters corresponding to the subsequently accessed satellite are different from those corresponding to satellite #B.

[0626] The S923b and onboard MME#B store the value of the uplink counter corresponding to the UE.

[0627] Optionally, the onboard MME#B also stores the values ​​of some downlink counters corresponding to UEs.

[0628] It should also be noted that the uplink NAS message #A and downlink NAS message #A in the above steps can both be NAS messages for security protection between the second satellite and the terminal device in the above embodiments, and the uplink NAS message #B and downlink NAS message #B can both be NAS messages for security protection between the first satellite and the terminal device in the above embodiments.

[0629] In this embodiment, when the communication link between the UE and different satellites is available, the UE assigns parameters to different satellites so that each satellite corresponds to different parameters. These parameters are used as input to the NAS security algorithm, thereby generating different key streams when the terminal device communicates with each satellite. This enables NAS secure connection between the terminal device and the MME on different satellites, ensuring secure data transmission between the terminal device and each satellite.

[0630] Figure 10 is a schematic diagram of a communication method 1000 provided in an embodiment of this application. As shown in Figure 10, the method is described using a UE, RAN#A, on-board MME#A, RAN#B, on-board MME#B, and ground MME as examples. RAN#A and on-board MME#A are carried on satellite A, which is the second satellite in the above embodiment; RAN#B and on-board MME#B are carried on satellite #B, which is the first satellite in the above embodiment. It should be noted that method 1000 is a more detailed description of the scheme in step S511 above. Method 1000 may include the following multiple steps.

[0631] S1001, UE determines the correspondence #1.

[0632] Among them, correspondence #1 is an example of the first correspondence.

[0633] For a description of the correspondence #1 and for determining the correspondence #1, please refer to step S511 above.

[0634] In this step, the UE also obtains a monitoring list, which can be obtained by the UE itself. Specifically, it can be generated by satellite #A and sent to the UE; or it can be obtained by the ground MME and sent to the UE via satellite #A. This application does not limit the method by which the UE obtains the monitoring list.

[0635] When the service link #A between satellite #A and UE is available, steps S1002 to S1004 are performed between UE and satellite #A.

[0636] S1002, RAN#A sends broadcast message #1 to UE.

[0637] Accordingly, the UE receives broadcast message #1 from RAN#A.

[0638] S1003, UE sends request information #1 to MME#A on satellite.

[0639] Accordingly, the onboard MME#A receives request information #1 from the UE.

[0640] S1004, the onboard MME#A sends response information #1 to the UE.

[0641] Accordingly, the UE receives response information #1 from the onboard MME#A.

[0642] For a detailed description of steps S1002 to S1004, please refer to steps S701 to S703 above, and they will not be repeated here.

[0643] Furthermore, when the power supply link #A between the ground MME and satellite #A is available, or in other words, when the communication link between satellite #A and the ground MME is available, step S1005 is executed.

[0644] S1005, Star-mounted MME#A obtains AV.

[0645] For a detailed description of how the onboard MME#A acquires AV, please refer to step S704 above, which will not be repeated here.

[0646] Furthermore, when the service link #A between the onboard MME#A and the UE becomes available, the terminal device and the satellite #A conduct NAS secure communication.

[0647] S1006, RAN#A sends broadcast message #2 to UE.

[0648] Accordingly, the UE receives broadcast message #2 from RAN#A.

[0649] For a detailed description of broadcast message #2, please refer to step S708 above, which will not be repeated here.

[0650] S1007, The UE sends request information #3 to the onboard MME#A.

[0651] Accordingly, the onboard MME#A receives request information #3 from the UE.

[0652] For a detailed description of request information #3, please refer to step S709 above, which will not be repeated here.

[0653] Furthermore, after receiving the request information #3, the on-board MME#A initiates an authentication request to the UE. NAS secure communication is then initiated between the UE and the on-board MME#A. Specifically, this is illustrated in steps S1008 to S1017b.

[0654] S1008, Onboard MME#A sends request information #4 to UE.

[0655] Accordingly, the UE receives request information #4 from the onboard MME#A.

[0656] For a detailed description of request information #4, please refer to step S710 above, which will not be repeated here.

[0657] S1009a, UE generation K ASME #A.

[0658] S1009b, Onboard MME#A based on K ASME #A Generate NAS Key#A.

[0659] S1009c, Onboard MME#A based on K NAS_int #A, parameter #A, and NAS integrity protection algorithm are used to protect the integrity of downlink NAS messages.

[0660] For a detailed description of S1009a and S1009c, please refer to steps S711a and S711c above, which will not be repeated here.

[0661] Furthermore, the onboard MME#A performs integrity protection on downlink NAS messages based on MAC-I / NAS-MAC#A and sends secure downlink NAS messages to the UE, such as NAS security mode command message #A.

[0662] S1010, the onboard MME#A sends a NAS security mode command message#A to the UE.

[0663] Accordingly, the UE receives the NAS security mode command message #A from the onboard MME#A.

[0664] S1011, UE based on K NAS_int The #A parameter and the NAS integrity verification algorithm perform integrity verification on the NAS security mode command message #A.

[0665] S1012. The UE performs security protection on the uplink NAS message #A based on the NAS key #A, parameter #A and NAS security algorithm.

[0666] Furthermore, the UE sends a security-protected uplink NAS message, such as a NAS security mode completion message #A, to the onboard MME#A. Specifically, step S1013 is executed.

[0667] S1013, UE sends NAS security mode completion message #A to onboard MME#A.

[0668] Accordingly, the onboard MME#A receives the NAS security mode completion message #A from the UE.

[0669] S1014, Onboard MME#A decrypts and verifies the integrity of NAS security mode completion message #A.

[0670] For a detailed description of steps S1010 to S1014, please refer to steps S712 to S716 above, and they will not be repeated here.

[0671] S1015, Onboard MME#A sends response information #3 to UE.

[0672] Accordingly, the UE receives response information #3 from the onboard MME#A.

[0673] S1016, UE sends uplink message #A to MME#A on satellite.

[0674] Accordingly, the onboard MME#A receives the uplink NAS message #A from the UE.

[0675] The value of the NAS downlink counter corresponding to S1017a and UE storage satellite #A.

[0676] Optionally, the UE also stores the values ​​of the NAS uplink counters corresponding to some satellites #A.

[0677] Optionally, the UE also stores the parameter #A corresponding to satellite #A. This allows the UE to determine that the parameters of the subsequently accessed satellite are different from those of satellite #A when accessing another satellite.

[0678] S1017b, the onboard MME#A stores the value of the NAS uplink counter corresponding to the UE.

[0679] Optionally, the onboard MME#A also stores the values ​​of some NAS downlink counters corresponding to the UEs.

[0680] For a detailed description of steps S1015 to S1017b, please refer to steps S717, S719 to S720b above, and they will not be repeated here.

[0681] Furthermore, when the power supply link #B between the ground MME and satellite #B is available, or in other words, when the communication link between the ground MME and satellite #B is available, the MME #B carried on satellite #B obtains the IMSI, the UE's subscription information, key #A, and eKSI #A. Specifically, the UE will conduct NAS secure communication with satellite #B, including the following step S1018.

[0682] Before introducing step S1018, it is necessary to explain the key #A and eKSI #A obtained by MME #B carried on satellite #B. Specifically, in the embodiments of this application, satellite #A and satellite #B use the same key when communicating with the UE. ASME #A means that all keys use the key #A.

[0683] S1018, The ground MME sends information #1 to the satellite MME #B.

[0684] Accordingly, the onboard MME #B receives information #1 from the ground-based MME.

[0685] In one possible implementation, when the service link #B between the UE and satellite #B is available, or in other words, when the communication link between the UE and satellite #B is available, the RAN #B carried on satellite #B sends a broadcast message #3 to the UE. This includes the following steps S1019 to S1022b.

[0686] S1019, RAN#B sends broadcast message #3 to UE.

[0687] Accordingly, the UE receives broadcast message #3 from RAN#B.

[0688] S1020, UE determines the parameter #B for satellite #B.

[0689] Specifically, the UE determines the parameter #B corresponding to the ID of satellite #B based on the ID of satellite #B and the corresponding relationship #1. However, it should be understood that the corresponding relationship is determined by the UE at this time, that is, the UE assigns the corresponding parameter to each satellite.

[0690] S1021. Perform NAS secure communication with the onboard MME #B based on parameter #B, NAS key #A, and NAS security algorithm.

[0691] For details regarding steps S1019 to S1021, please refer to steps S722 to S724 above, which will not be repeated here.

[0692] S1022a, UE stores the value of the downlink counter corresponding to satellite #B.

[0693] Optionally, the UE also stores the values ​​of the uplink counters corresponding to some satellites #B.

[0694] Optionally, the UE also stores the satellite #B corresponding to parameter #B. This ensures that when the UE accesses another satellite after satellite #B, it can determine that the parameters corresponding to the subsequently accessed satellite are different from those corresponding to satellite #B.

[0695] S1022b, the on-board MME#B stores the NAS uplink counter corresponding to the UE.

[0696] Optionally, the onboard MME#B also stores the values ​​of some downlink counters corresponding to UEs.

[0697] It should also be noted that the uplink NAS message #A and downlink NAS message #A in the above steps can both be NAS messages for security protection between the second satellite and the terminal device in the above embodiments, and the uplink NAS message #B and downlink NAS message #B can both be NAS messages for security protection between the first satellite and the terminal device in the above embodiments.

[0698] In this embodiment of the application, the UE simultaneously assigns parameters to each candidate satellite in the satellite set, so that each satellite corresponds to different parameters.

[0699] Figure 11 is a schematic diagram of a communication method 1100 provided in an embodiment of this application. As shown in Figure 11, the method is described using a UE, RAN#A, on-board MME#A, RAN#B, on-board MME#B, and a ground MME as examples. RAN#A and on-board MME#A are carried by satellite A, which is an example of the second satellite in method 600; RAN#B and on-board MME#B are carried by satellite #B, which is an example of the first satellite in method 600. It should be noted that method 1100 is a more detailed description of the scheme in method 600 described above. Method 1100 may include the following multiple steps.

[0700] If the service link #A between the UE and satellite #A is available, assuming the UE is initially registered to satellite #A, then steps S101 to S1103 are executed.

[0701] S1101, RAN#A sends broadcast message #1 to UE.

[0702] Accordingly, the UE receives broadcast message #1 from RAN#A.

[0703] For a detailed description of broadcast message #1, please refer to step S701 above, which will not be repeated here.

[0704] S1102, The UE sends request information #1 to the onboard MME#A.

[0705] Accordingly, the onboard MME#A receives request information #1 from the UE.

[0706] For a detailed description of request information #1, please refer to step S702 above, which will not be repeated here.

[0707] Furthermore, after receiving the request information #1, the satellite MME#A, depending on whether it has a UE's security context, sends a response information #1 to the UE if it does not have a UE's security context. That is, step S1103 is executed.

[0708] S1103, the onboard MME#A sends response information #1 to the UE.

[0709] Accordingly, the UE receives response information #1 from the onboard MME#A.

[0710] For a detailed description of response information #1, please refer to step S703 above, which will not be repeated here.

[0711] It should be noted that during the initial UE registration process described above, satellite #A does not have the UE's security context. Therefore, satellite #A can obtain the UE's security context and / or subscription information from the ground-based MME. If satellite #A has the UE's security context during steps S701 to S703, step S704 will not be executed.

[0712] Specifically, when the power supply link #A between the ground MME and satellite #A is available, or when the communication link between satellite #A and the ground MME is available, step S1104 is executed.

[0713] S1104, Star-mounted MME#A obtains AV.

[0714] For a detailed description of AV and the acquisition of AV by the onboard MME#A, please refer to step S704 above, which will not be repeated here.

[0715] Furthermore, when the service link #A between the onboard MME#A and the UE becomes available, the terminal device and the satellite #A conduct NAS secure communication.

[0716] S1105, RAN#A sends broadcast message #2 to UE.

[0717] Accordingly, the UE receives broadcast message #2 from RAN#A.

[0718] For a detailed description of broadcast message #2, please refer to step S708 above, which will not be repeated here.

[0719] S1106, The UE sends request information #3 to the onboard MME#A.

[0720] Accordingly, the onboard MME#A receives request information #3 from the UE.

[0721] For a detailed description of step S1106, please refer to step S709 above, which will not be repeated here.

[0722] Furthermore, after receiving the request information #3, the on-board MME#A initiates an authentication request to the UE. NAS secure communication is then initiated between the UE and the on-board MME#A. Specifically, this is illustrated in steps S1107 to S1118.

[0723] S1107, Onboard MME#A sends request information #4 to UE.

[0724] Accordingly, the UE receives request information #4 from the onboard MME#A.

[0725] For a detailed description of request information #4, please refer to step S710 above, which will not be repeated here.

[0726] S1108a, UE generation K ASME .

[0727] Among them, K is generated ASME The process can be found in existing technologies and will not be elaborated here.

[0728] S1108b, Onboard MME#A based on K ASME Generate NAS key.

[0729] For a detailed description of step S1108b, please refer to step S712b above, which will not be repeated here.

[0730] The S1108c and onboard MME#A perform integrity protection on downlink NAS messages based on the NAS integrity key, the downlink counter value information #A, and the NAS integrity protection algorithm.

[0731] It should be noted that when the downlink NAS message protected by the on-board MME#A based on the NAS integrity key, the downlink counter value #A, and the NAS integrity algorithm is the first NAS message between the on-board MME#A and the UE, the downlink counter value is the default value. That is, when satellite #A is the satellite to which the UE initially accesses or attaches, or the satellite to which a NAS secure connection is initially established, the initial value of the downlink counter is the default value of 0. In this case, the initial counter value of the first secure downlink NAS message is 0 by default. The value of the downlink counter will increase as the number of downlink NAS messages sent from satellite #A to the UE increases.

[0732] In one implementation, if satellite #A sends 4 downlink NAS messages to the UE, then the first downlink NAS message is sent, in which the downlink NAS SQN is 0 and the value of the downlink counter maintained or stored locally is 1; and so on, the fourth downlink NAS message is sent, in which the downlink NAS SQN is 3. At this time, the value of the downlink counter maintained or stored locally by the onboard MME#A is 4.

[0733] For example, the onboard MME#A uses the value information #A of the locally maintained or stored downlink counter as input to the integrity protection algorithm to generate MAC-I / NAS-MAC#A for integrity protection. The input to the integrity protection algorithm also includes the NAS integrity key KEY, COUNT, BEARER, DIRECTION, and the downlink NAS message #A. Then, the downlink NAS message #A for integrity protection is sent to the UE.

[0734] Furthermore, the onboard MME#A sends a downlink NAS message for security protection to the UE based on the generated MAC-I / NAS-MAC#A, such as a NAS security mode command message #A. The specific execution step is S1109.

[0735] S1109, The onboard MME#A sends a NAS security mode command message#A to the UE.

[0736] Accordingly, the UE receives the NAS security mode command message #A from the onboard MME#A.

[0737] In one implementation, after the onboard MME#A sends the NAS security mode command message #A to the UE, the value of the downlink counter is incremented by 1. For example, if the downlink counter value is 4 before sending the NAS security mode command message #A, then the downlink counter value is 5 at this time.

[0738] In another implementation, after the onboard MME#A sends an integrity-protected NAS message, the downlink NAS SQN value in the downlink counter value information #A maintained or stored locally by the onboard MME#A is incremented by 1. That is, for each integrity-protected downlink NAS message sent by the onboard MME#A, the downlink NAS SQN value is incremented by 1. When the downlink NAS SQN reaches its maximum value, if there are more downlink NAS messages, the downlink NAS SQN increments from the maximum value. At this time, the downlink NAS SQN value will flip, and the downlink NAS OVERFLOW value will increment by 1, for example, the downlink NAS OVERFLOW value will increment to 1. When the downlink NAS SQN reaches its maximum value again and starts incrementing from the maximum value, the downlink NAS OVERFLOW value will increment by 1 again. In other words, every time the downlink NAS SQN value reaches its maximum value, and another downlink NAS message is sent, the downlink NAS SQN starts incrementing from the maximum value, the downlink NAS OVERFLOW value will increment by 1, and the downlink NAS SQN value will be set to 0.

[0739] The NAS security mode command message #A includes the downlink counter value information #A, which includes the downlink NAS SQN.

[0740] For example, when the MME#A on the satellite finishes sending the last downlink NAS message to the UE, the UE locally stores or records the downlink counter value information #B. At this time, the downlink counter value information #B includes the downlink NAS overflow value and the downlink NAS SQN. The UE locally stores or records the downlink counter value #A (an example of the first value of the downlink counter).

[0741] It should be noted that when the NAS security mode command message #A is the last downlink NAS message, the downlink counter value #B is the same as the downlink counter value #A; when the NAS security mode command message #A is not the last downlink NAS message, the downlink counter value #B is the downlink counter value stored by the UE after the last downlink NAS message following the NAS security mode command message #A has been sent.

[0742] S1110, UE based on K ASME Generate NAS key.

[0743] Among them, UE is based on K ASME The process of generating NAS keys can be found in existing technologies and will not be elaborated here.

[0744] S1111, UE performs integrity verification on NAS security mode command message #A.

[0745] The NAS security mode command message #A includes a downlink NAS SQN. Based on this downlink NAS SQN and an estimated value of the downlink NAS OVERFLOW stored locally by the UE, the UE determines the value of a downlink counter, #A'. This downlink counter value #A' is used as input to an integrity verification algorithm to generate downlink XMAC-I#A / XNAS-MAC#A. Integrity verification is then performed on the NAS security mode command message #A based on this downlink XMAC-I#A / XNAS-MAC#A. The method for obtaining the estimated value of NAS OVERFLOW can be found in existing technologies and will not be elaborated here.

[0746] S1112. The UE performs security protection on the uplink NAS message #A between the UE and the on-board MME #A based on the NAS key, the uplink counter value information #A, and the NAS security algorithm.

[0747] For example, the UE uses the value information #A of the uplink counter, which is maintained or stored locally, as input to the encryption / decryption algorithm and / or the integrity protection algorithm to generate the uplink key stream #A and / or uplink MAC-I#A / NAS-MAC#A. The input to the integrity protection algorithm also includes the NAS integrity key KEY (e.g., K). NAS_int ), COUNT, BEARER, DIRECTION, and uplink NAS messages; the input to the encryption algorithm also includes the NAS encryption key KEY (e.g., K NAS_enc ), COUNT, BEARER, DIRECTION, LEHGTH. Then, the UE sends an encrypted and / or integrity-protected uplink NAS message #A to the onboard MME#A.

[0748] S1113, UE sends NAS security mode completion message #A to onboard MME#A.

[0749] Accordingly, the onboard MME#A receives the NAS security mode completion message #A from the UE.

[0750] In this context, the NAS security mode completion message #A is an example of the uplink NAS message #A.

[0751] It should be noted that when NAS security mode completion message #A is the first uplink NAS message, the uplink counter value is the default value. That is, when satellite #A is the satellite to which the UE initially accesses or attaches, or the satellite to which a NAS security connection is initially established, the initial value of the uplink counter is the default value of 0. In this case, the initial counter value of the first secure uplink NAS message is 0 by default. The value of the uplink counter will increase as the number of uplink NAS messages sent by the UE to satellite #A increases.

[0752] In one implementation, if the UE sends four uplink NAS messages to satellite #A, the first uplink NAS message contains an uplink NAS SQN of 0 and a locally maintained or stored downlink counter of 1. This continues until the fourth uplink NAS message, in which case the uplink NAS SQN is 3. At this point, the UE's locally maintained or stored uplink counter is 4.

[0753] In one implementation, after the UE sends an encrypted and integrity-protected uplink NAS message to the onboard MME#A, the value of the uplink NAS counter is incremented by 1.

[0754] In another implementation, after the UE sends an encrypted and / or integrity-protected uplink NAS message to the onboard MME#A, the NAS SQN value in the uplink counter is incremented by 1. That is, for each encrypted and / or integrity-protected uplink NAS message sent by the UE, the uplink NAS SQN value increases by 1. When the uplink NAS SQN reaches its maximum value, if there are still uplink NAS messages, the uplink NAS SQN continues to increment from the maximum value. At this point, the uplink NAS SQN flips, and therefore, the uplink NAS OVERFLOW value is incremented by 1. When the uplink NAS SQN reaches its maximum value again, if there are still uplink NAS messages, the uplink NAS SQN starts to increment from the maximum value. At this point, the uplink NAS SQN flips again, and the uplink NAS OVERFLOW value is incremented by 1 again. In other words, when the uplink NAS SQN flips, the uplink NAS OVERFLOW value is incremented by 1. At this point, the uplink NAS SQN value is set to 0.

[0755] For example, when the last uplink NAS message is sent between the onboard MME#A and the UE, the UE locally maintains or stores the uplink counter value information #B, which includes the uplink NAS overflow value and the uplink NAS SQN. The UE locally stores or records the uplink counter value #A.

[0756] It should be noted that when NAS security mode completion message #A is the last uplink NAS message, the uplink counter value #B is the same as the uplink counter value #A; when NAS security mode completion message #A is not the last uplink NAS message, the uplink counter value #B is the uplink counter value stored by the UE after the last uplink NAS message following NAS security mode completion message #A has been sent.

[0757] S1114. Onboard MME#A decrypts and verifies the integrity of NAS security mode completion message #A.

[0758] The NAS security mode completion message #A includes an uplink NAS SQN. Based on this uplink NAS SQN and an estimated value of the uplink NAS OVERFLOW stored locally by the onboard MME #A, the uplink counter value #A' is determined. This uplink counter value #A' is used as input to the decryption and / or integrity verification algorithm to generate an uplink keystream #A and / or uplink XMAC-I#A / XNAS-MAC#A. The NAS security mode completion message #A is then decrypted and / or its integrity is verified based on this uplink keystream #A and / or uplink XMAC-I#A / XNAS-MAC#A. The method for obtaining the estimated value of the uplink NAS OVERFLOW can be found in existing technologies and will not be elaborated here.

[0759] S1115, Onboard MME#A sends response information #3 to UE.

[0760] Accordingly, the UE receives response information #3 from the onboard MME#A.

[0761] For example, when data transmission is required between the UE and the on-board MME#A, the UE continues to send uplink NAS messages to the on-board MME#A; or the on-board MME#A continues to send downlink NAS messages to the UE. Optionally, if the UE has data to transmit to the on-board MME#A, then method 1100 further includes:

[0762] The UE sends uplink data #A to the onboard MME#A.

[0763] Accordingly, the onboard MME#A receives uplink data#A from the UE.

[0764] Alternatively, method 1100 may further include: the on-board MME#A sending downlink data#A to the UE. Accordingly, the UE receives downlink data#A from the on-board MME#A.

[0765] It should be noted that both the uplink data #A and the downlink data #A are encrypted and / or protected for integrity.

[0766] Furthermore, the UE stores the uplink counter value information #B and the downlink counter value information #B.

[0767] S1116. The UE stores the uplink counter value information #B and the downlink counter value information #B.

[0768] In one implementation, the value of the uplink counter is the value #A of the uplink counter maintained or stored locally by the UE; the value of the downlink counter is the value #A of the downlink counter stored or recorded locally by the UE.

[0769] In another implementation, the value of the uplink counter is the value of the uplink counter #A maintained or stored locally by the UE; the value of the downlink counter is the value of the downlink counter #A stored or recorded locally by the UE plus 1.

[0770] As an example, the downlink NAS SQN of the downlink counter value information #B is the SQN in the downlink NAS message sent by the onboard MME #A. Alternatively, the downlink NAS SQN of the downlink counter value information #B is obtained by adding 1 to the SQN in the downlink NAS message sent by the onboard MME #A.

[0771] It should be noted that the satellite sending the downlink NAS message is not necessarily satellite #A; it can also be other satellites that have accessed the UE and have sent downlink NAS messages.

[0772] Furthermore, when the power supply link #B between the ground MME and satellite #B is available, or in other words, when the communication link between the ground MME and satellite #B is available, the MME #B carried on satellite #B obtains the IMSI, the UE's subscription information, key, and eKSI1. Specifically, the UE will conduct NAS secure communication with satellite #B, including the following step S1117.

[0773] S1117, Ground MME sends message #1 to satellite MME #B.

[0774] Specifically, when the power supply link #B between the ground MME and satellite #B is available, and the ground MME has relevant information about the UE, it can send information #1 to the satellite MME #B. In other words, communication between the ground MME and the satellite MME #B can occur before communication between the satellite MME #A and the UE.

[0775] Accordingly, the onboard MME #B receives information #1 from the ground-based MME.

[0776] Information #1 includes UE information, such as IMSI, K ASME and eKSI. Where information #1 does not include K ASME This will include the NAS key. The eKSI is used to uniquely identify K. ASME K ASME This is the key used for secure communication between the UE and satellite #B.

[0777] Furthermore, when the service link #B between the UE and satellite #B is available, the UE will synchronize the acquired uplink counter value information #B and downlink counter value information #B to satellite #B as needed, so that satellite #B can use the uplink counter value information and downlink counter value information as input to the NAS security algorithm. The steps for the UE to synchronize the uplink counter value information #B and downlink counter value information #B to satellite #B include steps S1118 to S1123.

[0778] S1118, RAN#B sends broadcast message #3 to UE.

[0779] Accordingly, the UE receives broadcast message #3 from RAN#B.

[0780] The description of broadcast message #3 can be found in step S722 above, and will not be repeated here.

[0781] S1119. The UE performs security protection on the uplink NAS message #B based on the uplink counter value information #B and the NAS key.

[0782] For a detailed description of step S1119, please refer to step S1112 above, and it will not be repeated here. However, it should be noted that the uplink counter value information #A is replaced with the uplink counter value information #B, and the uplink NAS message #A is replaced with the uplink message #B.

[0783] Among them, the key stream #B is used to securely protect the NAS messages between the UE and the satellite #B, and further, to send the securely protected uplink NAS message #B to the onboard MME #B.

[0784] S1120, the UE sends a security-protected uplink NAS message #B to the onboard MME#B.

[0785] Accordingly, the onboard MME#B receives the uplink NAS message #B from the UE for security protection.

[0786] The uplink NAS message #B for this security protection includes the uplink counter value information #B and the downlink counter value information #B.

[0787] As an example, when the value of the uplink counter is the value #A of the uplink counter maintained or stored locally by the UE, and the value of the downlink counter is the value #A of the downlink counter maintained locally by the UE, the on-board MME #B receives a NAS message for secure uplink protection and can increment the value #A of the downlink counter by 1.

[0788] As an example, the uplink counter value is the value #A of the uplink counter maintained or stored locally by the UE; the downlink counter value is the value #A of the downlink counter stored or recorded locally by the UE plus 1. At this time, the on-board MME #B receives a downlink counter value that is the current downlink counter value #A maintained or stored by the UE plus 1.

[0789] Optionally, the uplink counter value information #B and the downlink counter value information #B can also be carried in an uplink message. The uplink message can be a message sent by the UE when it randomly accesses the RAN#B. Then, the RAN#B forwards the uplink message to the on-board MME#B, so that the on-board MME#B can obtain the second parameter.

[0790] As an example, when the UE receives a paging message from the on-board MME#B, it determines that the on-board MME#B is currently sending downlink messages to the UE. At this time, the UE sends a security-protected uplink NAS message to the on-board MME#B, and the uplink NAS message at this time includes the uplink counter value information #B and the downlink counter value information #B.

[0791] As another example, the UE sends an uplink NAS message to the onboard MME#B. For example, in a CIoT scenario, the UE sends a radio resource control (RRC) uplink (UL) message or an RRC NAS message to the onboard MME#B. In this case, there may be no downlink NAS message. In this case, the NAS message includes the uplink counter value information #B, but does not include the downlink counter value information #B.

[0792] The information regarding the uplink counter value #B (an example of the uplink counter value information in the above method embodiment 600), the information regarding the downlink counter value #B (an example of the downlink counter value information in the above method embodiment 600), and the incomplete description of the uplink NAS message can be found in step S620 above, and will not be repeated here.

[0793] S1121, The onboard MME#B performs de-security protection and / or security protection on NAS messages based on the uplink counter value information#B and / or downlink counter value information#B.

[0794] In one implementation, the onboard MME#B performs desecurity protection on the uplink NAS message#B based on the uplink counter value information#B and the NAS key.

[0795] In one implementation, the onboard MME#B securely protects the downlink NAS message#B based on the downlink counter value information#B and the NAS key.

[0796] The detailed description of de-security protection of uplink NAS message #B based on the uplink counter value information #B (an example of the uplink counter value information in the above method embodiment 600), and the detailed description of security protection of downlink NAS message #B based on the downlink counter value information #B (an example of the downlink counter value information in the above method embodiment 600) can be found in step S630 above, and will not be repeated here.

[0797] For example, the onboard MME#B receives a securely protected uplink NAS message #B. The onboard MME#B obtains the uplink NAS SQN from this uplink NAS message #B. The onboard MME#B uses the obtained uplink NAS SQN, the estimated value of the uplink NAS OVERFLOW, and determines the value of the uplink counter #B. It then uses the value of the uplink counter #B as input to a decryption and / or integrity protection algorithm to generate an uplink key stream #B (an example of the first uplink key stream in method embodiment 600 above) and / or XMAC-I#B / XNAS-MAC#B (an example of the first uplink XMAC-I / XNAS-MAC in method embodiment 600 above). Based on the uplink key stream #B and / or XMAC-I#B / XNAS-MAC#B, the uplink NAS message is desecured. In other words, the uplink NAS message #B is decrypted and / or its integrity is protected.

[0798] For example, the onboard MME#B receives a secure uplink NAS message #B. The onboard MME#B obtains the downlink NAS SQN from this uplink NAS message #B. The onboard MME#B uses the obtained downlink NAS SQN, the estimated value of the downlink NAS OVERFLOW, and determines the value of the downlink counter #B. It then uses the value of the downlink counter #B as input to an encryption and / or integrity protection algorithm to generate a downlink keystream #B and / or downlink MAC-I#B / first downlink NAS-MAC#B (an example of the first downlink MAC-I / NAS-MAC in method embodiment 600 above). Based on the downlink keystream #B and / or the first downlink MAC-I#B / first downlink NAS-MAC#B, it performs security protection on the downlink NAS message, that is, it performs encryption and / or integrity protection on the downlink NAS message #B.

[0799] Furthermore, the satellite MME#B sends a security-protected downlink NAS message #B to the UE.

[0800] In this context, the downlink NAS message #B is the downlink NAS message in the above method embodiment 600.

[0801] For a detailed description of the downlink NAS message #B for security protection sent by the satellite MME#B to the UE, please refer to step S650 above, which will not be repeated here.

[0802] In this embodiment, the uplink counter value and downlink counter value obtained by the UE when communicating with the previously accessed satellite are synchronized to the next accessed satellite, so that each satellite accessing the UE uses the synchronized uplink counter value or downlink counter value to perform NAS security protection on the communication between the satellite and the UE when conducting NAS secure communication with the UE.

[0803] The methods provided by the embodiments of this application have been described in detail above with reference to Figures 5 to 11. The apparatus provided by the embodiments of this application will be described in detail below with reference to Figures 12 to 14. It should be understood that the descriptions of the apparatus embodiments correspond to the descriptions of the method embodiments; therefore, any content not described in detail can be referred to the method embodiments above, and for the sake of brevity, will not be repeated here.

[0804] Figure 12 is a schematic diagram of a communication device 2000 provided in an embodiment of this application. The communication device 2000 includes a transceiver unit 2010 and a processing unit 2020. The transceiver unit 2010 can be used to implement corresponding communication functions. The transceiver unit 2010 can also be referred to as a communication interface or a communication unit. The processing unit 2020 can be used to perform processing, such as determining information bits.

[0805] Optionally, the device 2000 may further include a storage unit, which can be used to store instructions and / or data, and the processing unit 2020 can read the instructions and / or data in the storage unit to enable the device to implement the aforementioned method embodiments.

[0806] In a first possible design, the device 2000 can be the terminal device in the foregoing embodiments, which can implement the steps or processes corresponding to those executed by the terminal device in the above method embodiments. Specifically, the transceiver unit 2010 can be used to perform transceiver-related operations (such as sending and / or receiving data or messages) of the terminal device in the above method embodiments, and the processing unit 2020 can be used to perform processing-related operations of the terminal device in the above method embodiments, or operations other than transceiver (such as operations other than sending and / or receiving data or messages).

[0807] One possible implementation is that the transceiver unit 2010 is used to receive a broadcast message from the first satellite, which includes the identifier of the first satellite, when the communication link between the terminal device and the first satellite is available; and the processing unit 2020 is used to perform NAS secure communication with the first satellite based on a first parameter indicating the first satellite and / or the network element carried on the first satellite, a non-access stratum NAS key, and a NAS security algorithm.

[0808] Another possible implementation is that the processing unit 2020 provides security protection for the uplink NAS message based on the uplink counter value information and the NAS key. The NAS message includes the uplink counter value information and the downlink counter value information. The transceiver unit 2010 is used to send the secure uplink NAS message to the first satellite.

[0809] In a second possible design, the device 2000 can be the first satellite in the aforementioned embodiments. The device 2000 can implement the steps or processes performed by the first satellite corresponding to those described in the method embodiments above. Specifically, the transceiver unit 2010 can be used to perform transceiver-related operations of the first satellite in the method embodiments above (such as sending and / or receiving data or messages), and the processing unit 2020 can be used to perform processing-related operations of the first satellite in the method embodiments above, or operations other than transceiver (such as operations other than sending and / or receiving data or messages).

[0810] In one possible implementation, the transceiver unit 2010 is used to acquire a first parameter, which indicates the first satellite and / or the network elements carried on the first satellite. The processing unit 2020 is used to perform NAS secure communication with the terminal device based on the first parameter, the non-access stratum NAS key, and the NAS security algorithm.

[0811] Another possible implementation is that the transceiver unit 2010 is used to receive a NAS message for security protection from the terminal device when the communication link between the terminal device and the first satellite is available. The NAS message includes uplink counter value information and downlink counter value information. The processing unit 2020 is used to de-security protect the uplink NAS message between the terminal device and the first satellite based on the uplink counter value information and the NAS key.

[0812] In a third possible design, the device 2000 can be a terrestrial network element as described in the preceding embodiments. This device 2000 can implement the steps or processes corresponding to those performed by the terrestrial network element in the above method embodiments. Specifically, the transceiver unit 2010 can be used to perform transceiver-related operations of the terrestrial network element in the above method embodiments (such as sending and / or receiving data or messages), and the processing unit 2020 can be used to perform processing-related operations of the terrestrial network element in the above method embodiments, or operations other than transceiver operations (such as operations other than sending and / or receiving data or messages).

[0813] One possible implementation is that the processing unit 2020 is used to obtain a first correspondence, which includes a correspondence between at least one parameter and information of at least one satellite; the transceiver unit 2010 is used to send the first correspondence to the first satellite when the communication link between the first satellite and the ground network element is available, wherein the at least one parameter includes a first parameter for indicating the first satellite and / or the network element carried on the first satellite, and the first parameter is used for NAS secure communication between the first satellite and the terminal device.

[0814] It should be understood that the specific process of each unit performing the above-mentioned corresponding steps has been described in detail in the above method embodiments, and will not be repeated here for the sake of brevity.

[0815] It should also be understood that the device 2000 here is embodied in the form of a functional unit. The term "unit" here can refer to an application-specific integrated circuit (ASIC), electronic circuitry, a processor (e.g., a shared processor, a proprietary processor, or a group processor, etc.) and memory for executing one or more software or firmware programs, integrated logic circuitry, and / or other suitable components supporting the described functions. In an alternative example, those skilled in the art will understand that the device 2000 can be specifically the communication device in the above embodiments, and can be used to execute the various processes and / or steps corresponding to the communication device in the above method embodiments; to avoid repetition, these will not be described again here.

[0816] The apparatus 2000 of each of the above schemes has the function of implementing the corresponding steps performed by the communication device (such as a terminal device, a first satellite, or a ground network element) in the above methods. The function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions; for example, the transceiver unit can be replaced by a transceiver (e.g., the transmitting unit in the transceiver unit can be replaced by a transmitter, and the receiving unit in the transceiver unit can be replaced by a receiver), and other units, such as processing units, can be replaced by processors, respectively executing the transceiver operations and related processing operations in each method embodiment.

[0817] In addition, the transceiver unit 2010 may also be a transceiver circuit (for example, it may include a receiving circuit and a transmitting circuit), and the processing unit may be a processing circuit.

[0818] It should be noted that the device in Figure 12 can be the communication equipment in the aforementioned embodiments (such as a terminal device, a first satellite, or a ground network element), or it can be a chip or a chip system, such as a system on a chip (SoC). The transceiver unit can be an input / output circuit or a communication interface; the processing unit is a processor, microprocessor, or integrated circuit integrated on the chip. No limitations are imposed here.

[0819] Figure 13 is a schematic diagram of another communication device 3000 provided in an embodiment of this application. The device 3000 includes a processor 3010, which is coupled to a memory 3020. The memory 3020 is used to store computer programs or instructions and / or data. The processor 3010 is used to execute the computer programs or instructions stored in the memory 3020, or to read the data stored in the memory 3020, so as to execute the methods in the above method embodiments.

[0820] Optionally, there may be one or more processors 3010.

[0821] Optionally, the memory 3020 may be one or more.

[0822] Alternatively, the memory 3020 can be integrated with the processor 3010, or it can be set separately.

[0823] Optionally, as shown in FIG13, the device 3000 further includes a transceiver 3030 for receiving and / or transmitting signals. For example, the processor 3010 is used to control the transceiver 3030 to receive and / or transmit signals.

[0824] As an example, processor 3010 may have the functions of processing unit 3020 shown in FIG13, memory 3020 may have the functions of storage unit, and transceiver 3030 may have the functions of transceiver unit 3010 shown in FIG13.

[0825] As one approach, the device 3000 is used to implement the operations performed by the communication device (such as a terminal device, a first satellite, or a ground network element) in the various method embodiments described above.

[0826] For example, processor 3010 is used to execute computer programs or instructions stored in memory 3020 to implement the relevant operations of the communication device in the various method embodiments described above.

[0827] It should be understood that the processor mentioned in the embodiments of this application can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor.

[0828] It should also be understood that the memory mentioned in the embodiments of this application can be volatile memory and / or non-volatile memory. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM). For example, RAM can be used as an external cache. By way of example and not limitation, RAM includes the following forms: static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).

[0829] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA, or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, the memory (storage module) can be integrated into the processor.

[0830] It should also be noted that the memory described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0831] Figure 14 is a schematic diagram of a chip system 4000 provided in an embodiment of this application. The chip system 4000 (or may also be called a processing system) includes logic circuitry 4010 and input / output interface 4020.

[0832] The logic circuit 4010 can be a processing circuit in the chip system 4000. The logic circuit 4010 can be coupled to a memory unit, calling instructions from the memory unit, enabling the chip system 4000 to implement the methods and functions of the embodiments of this application. The input / output interface 4020 can be an input / output circuit in the chip system 4000, outputting processed information from the chip system 4000, or inputting data or signaling information to be processed into the chip system 4000 for processing.

[0833] As one approach, the chip system 4000 is used to implement the operations performed by the communication device (such as a terminal device, a first satellite, or a ground network element) in the various method embodiments described above.

[0834] For example, logic circuit 4010 is used to implement processing-related operations performed by communication devices (such as terminal devices, first satellites, or ground network elements) in the above method embodiments; input / output interface 4020 is used to implement sending and / or receiving-related operations performed by communication devices (such as terminal devices, first satellites, or ground network elements) in the above method embodiments.

[0835] This application also provides a computer-readable storage medium storing a computer program or instructions for implementing the methods executed by a communication device (such as a terminal device, a first satellite, or a ground network element) in the above-described method embodiments. For example, when the computer program or instructions are run on the communication device, they cause the communication device (such as a terminal device, a first satellite, or a ground network element) to execute the above-described methods (such as method 500 or method 600).

[0836] This application also provides a computer program product comprising instructions that, when executed by a computer, implement the methods described above, which are performed by a communication device (such as a terminal device, a first satellite, or a ground network element). For example, when the computer program or instructions are run on the communication device, the communication device (such as a terminal device, a first satellite, or a ground network element) performs the methods described above (such as method 500 or method 600).

[0837] This application also provides a communication system that includes the terminals and / or network devices described in the embodiments above. For example, the system includes the terminal device, a first satellite, and ground network elements as described in the embodiments of FIG5 or FIG6.

[0838] The explanations and beneficial effects of the relevant contents in any of the devices provided above can be referred to the corresponding method embodiments provided above, and will not be repeated here.

[0839] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces, and the indirect coupling or communication connection of apparatus or units may be electrical, mechanical, or other forms.

[0840] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. For example, the computer can be a personal computer, a server, or a network device, etc. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state disks, SSDs). For example, the aforementioned available media include, but are not limited to, USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks, and other media capable of storing program code.

[0841] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

A communication method, applied to a terminal device or a chip in a terminal device, characterized in that, include: When the communication link between the terminal device and the first satellite is available, a broadcast message from the first satellite is received, the broadcast message including the identifier of the first satellite; Based on the first parameters indicating the first satellite and / or the network elements carried on the first satellite, the non-access stratum NAS key, and the NAS security algorithm, NAS secure communication is performed with the first satellite. The method according to claim 1, characterized in that, Before performing NAS secure communication with the first satellite based on the first parameter indicating the network element carried on the first satellite, the non-access stratum NAS key, and the NAS security algorithm, the method further includes: Obtain the correspondence between the first parameter and the information of the first satellite, wherein the information of the first satellite includes the identifier of the first satellite and / or the identifier of the network element carried on the first satellite; Based on the aforementioned correspondence, the first parameter is determined. The method according to claim 2, characterized in that, The step of obtaining the correspondence between the first parameter and the information of the first satellite includes: The terminal device receives the correspondence from a second satellite, which is a satellite that the terminal device accessed before accessing the first satellite. The method according to claim 3, characterized in that, Receiving the correspondence from the second satellite includes: Receive a first correspondence from the second satellite, the first correspondence including a correspondence between at least one parameter and information of at least one satellite, the at least one satellite including the first satellite, the at least one parameter including the first parameter, and the information of the at least one satellite including information of the first satellite. The method according to claim 1 or 2, characterized in that, The method further includes: Determine the first parameter for the first satellite; Send the first parameter to the first satellite. The method according to claim 1, characterized in that, The method further includes: Receive the first parameter from the first satellite. The method according to any one of claims 1-6, characterized in that, Based on a first parameter instructing the first satellite and / or the network elements carried on the first satellite, a NAS key, and a NAS security algorithm, secure NAS communication is performed between the first satellite and the first satellite, including: The first parameter and the NAS key are used as inputs to the NAS security algorithm to generate a first key stream and / or a first message authentication code (MAC). NAS secure communication is performed between the first key stream or the first MAC and the first satellite, wherein the first parameter is included in the bearer and / or counter used as input to the NAS security algorithm. The method according to any one of claims 1-6, characterized in that, The first parameter is contained in a first field, which is different from the bearer, counter, transmission direction, length, or message used as input to the NAS security algorithm. The method according to any one of claims 3-8, characterized in that, The method further includes: NAS secure communication is conducted between the second satellite and the second satellite based on the second parameter, the NAS key, and the NAS security algorithm, wherein the second parameter is different from the first parameter. The method according to claim 9, characterized in that, The second parameter is used to indicate the second satellite and / or the network elements carried on the second satellite; or The second parameter is the default value. The method according to claim 9 or 10, characterized in that, The second parameter is included in the bearer and / or counter used as input to the NAS security algorithm; or The second parameter is contained in the first field, which is different from the bearer, counter, transmission direction, length, or message used as input to the NAS security algorithm. A communication method, applied to a first satellite or a chip in a first satellite, characterized in that, include: Obtain a first parameter, which is used to indicate the first satellite and / or the network element carried on the first satellite; Based on the first parameter, the non-access stratum NAS key, and the NAS security algorithm, secure NAS communication is established with the terminal device. The method according to claim 12, characterized in that, The process of obtaining the first parameter includes: If the communication link between the first satellite and the terminal device is available, the first parameter is received from the terminal device. The method according to claim 12, characterized in that, The process of obtaining the first parameter includes: If the communication link between the first satellite and the ground network element is available, the first parameter is received from the ground network element. The method according to any one of claims 12-14 is characterized in that, The method further includes: The first parameter is sent to the terminal device. The method according to claim 15, characterized in that, The first parameter is determined by the first satellite; The method further includes: The first parameter is sent to the terminal device. The method according to any one of claims 12-16 is characterized in that, NAS secure communication between the terminal device and the first parameter, NAS key, and NAS security algorithm includes: The first parameter and the NAS key are used as inputs to the NAS security algorithm to generate a first key stream and / or a first message authentication code (MAC). NAS secure communication is performed between the terminal device based on the first key stream and / or the first MAC. The first parameter is included in the bearer and / or counter used as inputs to the NAS security algorithm. The method according to any one of claims 12-16 is characterized in that, The first parameter is contained in a first field, which is different from the bearer, counter, transmission direction, length, or message used as input to the NAS security algorithm. A communication method applied to terrestrial network elements, characterized in that, include: Obtain a first correspondence, which includes a correspondence between at least one parameter and information of at least one satellite; When the communication link between the first satellite and the ground network element is available, the first correspondence is sent to the first satellite. The at least one parameter includes a first parameter for indicating the first satellite and / or the network element carried on the first satellite. The first parameter is used for NAS secure communication between the first satellite and the terminal device. The method according to claim 19, characterized in that, The method further includes: The first correspondence is sent to the second satellite, which is the satellite that the terminal device accessed before accessing the first satellite. The method according to claim 20, characterized in that, The first correspondence includes the correspondence between the second parameter and the information of the second satellite. The second parameter is used to indicate the second satellite and / or the network elements carried on the second satellite. The second parameter is used for NAS secure communication between the second satellite and the terminal device. The method according to any one of claims 19-21 is characterized in that, The first parameter is included in the bearer and / or counter used as input to the NAS security algorithm; or The first parameter is contained in the first field, which is different from the bearer, counter, transmission direction, length or message used as input to the NAS security algorithm. A communication device, characterized in that, It includes at least one module for performing the method as described in any one of claims 1 to 22. A communication device, characterized in that, include: Processor, the processor being coupled to memory; The processor is configured to execute a computer program stored in the memory, so that the apparatus performs the method according to any one of claims 1 to 22. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer program code or instructions that, when executed on a computer, cause the method of any one of claims 1 to 22 to be performed. A computer program product, characterized in that, The computer program product includes: computer program code, which, when executed, implements the method as described in any one of claims 1 to 11, or the method as described in any one of claims 12 to 18, or the method as described in any one of claims 19 to 22.

Citation Information

Patent Citations

  • Safety protection method and device

    CN109361655A

  • Communication method and device

    CN116941263A

  • Communication method and communication device

    CN117812574A

  • Communication method and related apparatus

    WO2024164135A1