Apparatus, method and computer program

The method and apparatus for multi-satellite registration and authentication address the challenge of seamless service continuity and efficient authentication across different satellite orbits, ensuring optimal communication quality for diverse applications by using random number-based authentication vectors.

WO2026114804A1PCT designated stage Publication Date: 2026-06-04NOKIA TECHNOLOGIES OY

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
NOKIA TECHNOLOGIES OY
Filing Date
2025-11-24
Publication Date
2026-06-04

AI Technical Summary

Technical Problem

Existing communication systems, particularly in satellite networks, face challenges in ensuring seamless service continuity and efficient authentication across multiple orbits, such as low Earth orbit (LEO), medium Earth orbit (MEO), and geostationary orbit (GEO), especially for applications involving autonomous ships, vehicles, and weather forecasting, due to discontinuous coverage and varying latency requirements.

Method used

A method and apparatus for multi-satellite registration and authentication that involves receiving a registration request from a satellite, obtaining random numbers for multiple satellites, and providing an authentication vector to ensure secure communication across different orbits, with mechanisms for authentication and authorization tailored for user equipment supporting multi-orbit operations.

Benefits of technology

Enables seamless service continuity and efficient authentication across multiple satellite orbits, minimizing service interruptions and optimizing communication quality for diverse applications, including autonomous vehicles and weather forecasting, by leveraging multi-orbit satellite networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025083990_04062026_PF_FP_ABST
    Figure EP2025083990_04062026_PF_FP_ABST
Patent Text Reader

Abstract

There is provided an apparatus comprising means for receiving a registration request for a user equipment from a first satellite, the registration request including an identifier of the first satellite and an indication that the user equipment supports multi orbit satellites, obtaining a random number associated with the first satellite and a random number associated with at least one further satellite, providing an authentication request to an authentication entity, the authentication request comprising the identifier of the first satellite, and each of the random numbers associated with each of the first and at least one further satellites, in response, receiving an authentication vector from the authentication entity and providing the authentication vector to the first and at least one further satellite.
Need to check novelty before this filing date? Find Prior Art

Description

TITLEAPPARATUS, METHOD AND COMPUTER PROGRAMTECHNICAL FIELD

[0001] Various embodiments of this disclosure relate generally to methods, apparatus and computer programs, and in particular, but not exclusively, to UE multi-satellite registration and authentication.BACKGROUND

[0002] A communication system can be seen as a facility that enables communication sessions between two or more communication devices, or provides communication devices access to a network. A mobile or wireless communication network is one example of a communication network. A communication device may be provided with a service by an application server.

[0003] A mobile or wireless communication network may operate in accordance with standard^), such as those provided by 3GPP (Third Generation Partnership Project) or ETSI (European Telecommunications Standards Institute). Examples of mobile or wireless communication network that operate in accordance with 3GPP standards are generally referred to as 4G (4th Generation) networks, 5G (5th Generation) network, 5G-Advanced networks and 6G networks.SUMMARY

[0004] Some embodiments of this disclosure will be described with respect to certain aspects. These aspects are not intended to indicate key or essential features of the various example embodiments of this disclosure, nor are they intended to be used to limit the scope of thereof. Other features, aspects, and elements will be readily apparent to a person skilled in the art in view of this disclosure. For example, it should be appreciated that further aspects may be provided by the combination of any two or more of the various aspects described herein.

[0005] In a first aspect there is provided a method comprising receiving a registration request for a user equipment from a first satellite, the registration request including an identifier of the first satellite and an indication that the user equipment supports multi orbit satellites, obtaining a random number associated with the first satellite and a random number associated with at least one further satellite, providing an authentication request to an authentication entity, the authentication request comprising the identifier of the first satellite, and each of the random numbers associated with the first and at least one further satellites, in response, receiving an authentication vector from the authentication entity and providing the authentication vector to the first and at least one further satellite.

[0006] The first satellite may be in a first orbit. The at least one further satellite may be in a different orbit.

[0007] The first orbit may be a low Earth orbit. The different orbit may be a medium Earth orbit or a geostationary orbit.

[0008] Obtaining the random number associated with the first satellite and the random number associated with the at least one further satellite may comprise receiving the random number associated with each of the first satellite and at least one further satellite from the respective satellite.

[0009] Obtaining the random number associated with the first satellite and the random number associated with the at least one further satellite may comprise generating the random number associated with each of the first satellite and at least one further satellites.

[0010] The method may comprise obtaining an identifier of the at least one further satellite, wherein the authentication request further comprises the identifier of the at least one further satellite.

[0011] Obtaining the identifier of the at least one further satellite may comprise receiving the identifier of the at least one further satellite in a registration request from the respective satellite.

[0012] The method may comprise providing the indication that the user equipment supports multi orbit satellites to the authentication entity.

[0013] The method may be performed at an apparatus. The apparatus may be, comprise or be comprised in a network entity implemented for mobility management function.

[0014] In a second aspect there is provided a method comprising receiving an authentication request for a user equipment from a network entity, the request comprising an identifier of a first satellite and a random number associated with the first satellite and a random number associated with at least one further satellite, determining an authentication vector, based on the identifier of a first satellite and each of the random numbers associated with the first satellite and the at least one further satellite, respectively and providing an indication of the determined authentication vector to the network entity.

[0015] The authentication request may include an indication that the user equipment supports multi orbit satellites.

[0016] The method may comprise generating a random number associated with the network and concatenating the random number associated with the home network and each of the random numbers associated with the first satellite and the at least one further satellite, respectively.

[0017] The authentication request may further comprise an identifier of the at least one further satellite. The method may comprise determining the authentication vector further based on the identifier of the at least one further satellite.

[0018] In a third aspect there is provided a method comprising providing a registration request for a user equipment to a first satellite, wherein the registration request includes an indication that the user equipment supports multi orbit satellites and receiving an indication from thefirst satellite of an authentication vector, the authentication vector comprising a random number associated with the first satellite and at least one further satellite.

[0019] The method may comprise providing an authentication response to the first satellite, the authentication response comprising a response token for the first satellite and a response token for the at least one further satellite, wherein each respective response token is generated based on the received authentication vector.

[0020] In a fourth aspect there is provided an apparatus comprising means for performing the method according to the first, second or third aspect.

[0021] In a fifth aspect there is provided an apparatus comprising at least one processor, and at least one memory storing instructions which, when executed by the at least one processor, cause the apparatus at least to perform a method according to the first, second or third aspect.

[0022] In a sixth aspect there is provided a non-transitory computer readable medium comprising instructions wherein the instructions when executed by at least one processor of an apparatus cause the apparatus to perform the method according to the first, second or third aspect.

[0023] In a seventh aspect there is provided a computer program comprising instructions which, when executed by an apparatus, cause the apparatus to perform at least the method according to the first or second aspect.

[0024] Some embodiments of the invention are defined in the dependent claims.

[0025] In the above, many different aspects have been described. As previously noted, it should be appreciated that further aspects may be provided by the combination of any two or more of the aspects described above (or otherwise in this disclosure).

[0026] Various other aspects are also described in the following detailed description and in the claims.BRIEF DESCRIPTION OF THE FIGURES

[0027] Some embodiments will be described, by way of non-limiting and illustrative example only, with reference to the figures, in which:

[0028] Fig. 1 shows an example of a communication network to which examples disclosed herein may be applied;

[0029] Fig. 2 shows a schematic diagram of service continuity through multi-orbit satellite access for an autonomous ship;

[0030] Fig. 3 shows a schematic diagram of multi orbit 5G satellite access for autonomous vehicle operation;

[0031] Fig. 4 shows a schematic diagram of multi-orbit satellite use for weather forecasting and natural disaster prediction;

[0032] Fig. 5 shows a flowchart of a method according to an example embodiment;

[0033] Fig. 6 shows a flowchart of a method according to an example embodiment;

[0034] Fig. 7 shows a flowchart of a method according to an example embodiment;

[0035] Fig. 8 shows a signalling flow of an example variant;

[0036] Fig. 9 shows a signalling flow of an example variant;

[0037] Fig. 10 shows a signalling flow of an example variant;

[0038] Fig. 1 1 shows a flowchart of a method according to an example embodiment;

[0039] Fig. 12 shows a flowchart of a method according to an example embodiment;

[0040] Fig. 13 shows a signalling flow of an example variant;

[0041] Fig. 14 shows an example of an apparatus.DETAILED DESCRIPTION

[0042] The following embodiments are provided by way of non-limiting and illustrative example. Although the specification may refer to “an”, “one”, or “some” embodiment(s) in several locations of the text, this does not necessarily mean that each reference is made to the same embodiment(s), or that a particular feature only applies to a single embodiment. Single features of different embodiments may also be combined to provide other embodiments. Further, when a particular feature, structure, or characteristic is described in connection of an embodiment, it intended such feature, structure, or characteristic may be applied in connection with other embodiments (whether or not explicitly described).

[0043] It shall be understood that although the terms “first,” “second” and the like may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another.

[0044] For the purposes of this disclosure, the phrases “at least one of A or B”, “at least one of A and B”, and “A and / or B” means (A), (B), or (A and B). For the purposes of this disclosure, the phrase “A, B, and / or C” means (A), (B), (C), (A and B), (A and C), (B and C), or (A, B, and C).

[0045] As used herein, the term “or” refers to a non-exclusive “or” unless otherwise indicated (e.g., use of “or else” or “or in the alternative”).

[0046] As used herein, unless stated explicitly, performing a respective feature, step, or functionality “in response to A” does not indicate that the respective feature, step, or functionality is performed immediately after “A” occurs as one or more intervening features, steps, or functionalities may be performed (at least in part) between an occurrence of the respective feature, step, or function and “A”. Analogously, performing a respective feature, step, or functionality “based on A” does not indicate that the respective feature, step, or functionality is performed solely based on “A” as the respective feature, step, or functionality may be further based on one or more other features, steps, or functionalities in addition to “A”.

[0047] Embodiments described herein may be implemented in a communication network, such as any of the following radio access technologies (RATs): Worldwide Interoperability for Micro-wave Access (WiMAX), Global System for Mobile communications (GSM, 2G), GSM EDGEradio access Network (GERAN), General Packet Radio Service (GRPS), Universal Mobile Telecommunication System (UMTS, 3G) based on basic wideband-code division multiple access (W- CDMA), high-speed packet access (HSPA), Long Term Evolution (LTE), LTE-Advanced, and enhanced LTE (eLTE), 5G (also called NR), or any future RAT such as 6G. Moreover, communication within the communication network may utilize any proper wireless communication technology, comprising but not limited to: Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access (TDMA), Frequency Division Duplex (FDD), Time Division Duplex (TDD), Multiple-Input Multiple-Output (MIMO), Orthogonal Frequency Division Multiple (OFDM), and / or Discrete Fourier Transform spread OFDM (DFT-s-OFDM).

[0048] As used herein, the term “network device” or “network node” refers to a node in a communication network via which user equipment may access the network and / or which is configured to control radio communication and managing radio resources within a cell. The network node or network device may be referred to as a base station (BS), an access point (AP) or an access node. The network device may be, depending on the applied technology, for example, a node B (NodeB or NB), an evolved NodeB (eNodeB or eNB), an NR NB (also referred to as a gNB), a Remote Radio Unit (RRU), a radio head (RH), a remote radio head (RRH), a relay, an Integrated Access and Backhaul (IAB) node, a low power node, a non-terrestrial network (NTN) or non-ground network device, such as a satellite network device, a low earth orbit (LEO) satellite and a geosynchronous earth orbit (GEO) satellite, or an aircraft network device.

[0049] Moreover, in connection of split radio access network (RAN), the network device may refer to a centralised unit (CU) of a base station and / or a distributed unit (DU) of a base station. An interface between CU and DU may be referred to as an F1 interface in NR. In the split RAN architecture, node operations may be carried out, at least partly, in the central / centralized unit, CU, (e.g. server, host or node) operationally coupled to the DU, (e.g. a radio head / node). One CU may control one or more DUs, acting at least as transmit / receive (Tx / Rx) nodes. In some embodiments, the DUs may comprise e.g. a radio link control (RLC), medium access control (MAC) layer and a physical (PHY) layer, whereas the CU may comprise the layers above RLC layer, such as a packet data convergence protocol (PDCP) layer, a radio resource control (RRC) and an internet protocol (IP) layers. Other functional splits are possible too. In practice, any processing task may be performed in either the CU or the DU and the boundary where the responsibility is shifted between the CU and the DU may depend on the applied implementation.

[0050] The term “terminal device” refers to any end device that may be configured to perform wireless communication. By way of example, a terminal device may be referred to as a communication device, user equipment (UE), a Subscriber Station (SS), or a Mobile Station (MS). The terminal device may include a mobile phone, a cellular phone, a smart phone, voice over IP (VoIP) phones, wireless local loop phones a tablet, a wearable terminal device, a personal digital assistant (PDA), portable computers, desktop computer, image capture terminal devices such asdigital cameras, gaming terminal devices, music storage and playback appliances, vehiclemounted wireless terminal devices, USB dongles, an Internet of Things (loT) device, a watch or other wearable, a head-mounted display (HMD), a vehicle, a drone, a medical device and applications (e.g., remote surgery), an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processing chain contexts), a consumer electronics device, a device operating on commercial and / or industrial wireless networks, and the like.

[0051] A term “resource”, as used herein, may refer to radio resources in time domain, in frequency domain, in space domain, and / or in code domain. Some examples of resources may include, e.g., a physical resource block (PRB), a radio frame, a subframe, a time slot, a subband, a frequency region, a sub-carrier, a beam, etc. The term “transmission” and / or “reception” may refer to wirelessly transmitting and / or receiving via a wireless propagation channel on radio resources.

[0052] Fig. 1 illustrates an example of a communication network to which examples disclosed herein may be applied. The communication network or a cellular communication network may comprise a network node 110 configured to provide one or more cells, such as cell 100, and a network node 1 12 configured to provide one or more other cells, such as cell 102. Each cell may, for example, be a macro cell, a micro cell, femto, or a pico cell. The cell may define a coverage area or a service area of the corresponding access node.

[0053] The network node (110, 1 12) may be configured to provide a user equipment (UE) 120 (one or more UEs) with wireless access to the communication network. The wireless access may comprise downlink (DL) communication from the network node (1 10, 112) to the UE 120 and uplink (UL) communication from the UE 120 to the network node (110, 112). Examples of uplink channels may comprise physical uplink control channel (PUCCH) for transmitting control information and physical uplink shared channel (PUSCH) for transmitting data towards the network. Examples of downlink channels may comprise physical downlink control channel (PDCCH) for transmitting control information and physical downlink shared channel (PDSCH) for transmitting data towards the user equipment.

[0054] There may be a plurality of UEs (120, 122) in the system. Each of the plurality of UEs may be served by the same or by different network nodes (110, 112). UE may be configured with dual connectivity (DC), wherein the UE, for example UE 120, may be connected to multiple network nodes (1 10, 112). The UEs (120, 122) may communicate with each other, in case device- to-device (D2D) communication interface is established between them via a so-called sidelink (SL). Such D2D communications may be referred to as machine-to-machine, peer-to-peer (P2P) communications, or vehicle-to-vehicle (V2V), for example.

[0055] In the case of multiple network nodes in the communication network, the network nodes may be connected to each other via an interface. LTE specifications, for example, refer tosuch an interface as an X2 interface. An interface between an LTE node and a 5G node, or between two 5G nodes may be called an Xn interface.

[0056] The network nodes 110 and 1 12 may be further connected via another interface to a core network 1 16 of the communication network. The LTE specifications specify the core network as an evolved packet core (EPC), and the core network may comprise a plurality of entities (e.g. a mobility management entity (MME) and a gateway node). The MME may handle mobility of terminal devices in a tracking area encompassing a plurality of cells and handle signalling connections between the terminal devices and the core network. The gateway node may handle data routing in the core network and to / from the terminal devices. The 5G specifications specify the core network as a 5G core (5GC). The 5GC may, for example, comprise an access and mobility management function (AMF) and a user plane function / gateway (UPF) and other functions. The AMF may handle termination of non-access stratum (NAS) signalling, NAS ciphering & integrity protection, registration management, connection management, mobility management, access authentication and authorization, security context management. The UPF node may, for example, support packet routing and forwarding, packet inspection and quality of service (QoS) handling.

[0057] The future of satellite communications is moving toward hybrid satellite networks that combine the services from low-Earth orbit (LEO) satellites and high-altitude satellites in me- dium-Earth orbits (MEO) and geostationary orbits (GEO or GSO). Satellite communication developments may be being driven by the commercial sectors including maritime and aviation, which are increasingly pursuing multi-orbit satellite solutions.

[0058] In the maritime sector, enhanced maritime communication technologies have been developed to support autonomous ships (e.g., Maritime Autonomous Surface Ship (MASS)), which are commercial vessels that operate independently of human interaction, using sensors, software, and communication systems to navigate, avoid collisions and perform the tasks and functions of the vessel. To support autonomous ships, the maritime communication systems enable an autonomous ship to exchange the information with a remote monitoring and control centre on the ground.

[0059] Considering the provision of global communication coverage and seamless network connectivity in a maritime environment, communication technology utilizing multi-orbit satellites may be employed in maritime communication systems. During the rollout of LEO satellite constellations, the limited number of satellites in orbit inevitably leads to discontinuities in coverage. Therefore, it should be considered how to ensure the continuity of communication services through multi-orbit satellite access.

[0060] An example operator may operate many autonomous ships globally as well as several centres on the ground to monitor and control the autonomous ships in remote area.

[0061] An example satellite operator may deploy multi-orbit (LEO, MEO and GSO)satellites and have an agreement with a Terrestrial Operator to provide communication services for UEs under satellite coverage.

[0062] The ship operator has an agreement with the satellite operator to use the satellites for communication services using satellite access. Thus, the devices on autonomous ships can communicate with a remote monitoring and control centre via satellite access.

[0063] For example, device A on an autonomous ship can communicate with a remote monitoring and control center continuously through multi-orbit satellites connectivity. Fig. 2 shows an example of service continuity through multi-orbit satellite access at time t1 , t2 and t3,

[0064] At time t1 , device A on an autonomous ship is under the coverage of LEO Satellite Sat-A and MEO / GSO Satellite Sat-B.

[0065] Taking into account communication latency and power consumption, Device A registers with the terrestrial 5G network via LEO Satellite Sat-A. After the registration, it can communicate with a remote monitoring and control center operated by the ship operator.

[0066] During the communication service, at time t2, due to the short service duration and discontinuous coverage of LEO satellites, Device A is under the coverage of only MEO / GSO Satellite Sat-B, the communication path can be switched to MEO / GSO Satellite Sat-B depending on the required quality of service. Then, Device A communicates with a remote monitoring and control center via MEO / GSO Satellite Sat-B.

[0067] At time t3, Device A is under the coverage of the following LEO Satellite Sat-C, the communication path can be switched to LEO Satellite Sat-C with the consideration of communication latency and power consumption. As a result, Device A communicates with a remote monitoring and control center via LEO Satellite Sat-C.

[0068] The charging information of the traffic data exchanged via multi-orbit satellites is collected and reported to the remote core network. Satellite access and satellite connectivity are supported in Rel-19. The 5G system is able to provide services using satellite access. For a 5G system with satellite access, subject to regulatory requirements and operator’s policy, a 5G system with satellite access shall be able to support service continuity (with minimum service interruption) of a UE-Satellite-UE communication when the UE communication path moves between serving satellites (due to the movement of the UE and / or the satellites). The 5G core network may support collection of charging information based on the access type (e.g., 3GPP, non-3GPP, satellite access). However, it is not sufficient in regards of supporting service continuity through multiorbit satellite access.

[0069] A further example use case is a scenario in an environment where an autonomous vehicle operates under remote control from a central station, facilitated by e.g., satellite-based access. The UE installed on the vehicle is served by two different orbit satellites (e.g., GEO and LEO) belonging to the same PLMN which is managed by a 5G satellite operator. The UE holds a subscription with a single PLMN.

[0070] Multi-orbits satellite access is applied to accommodate a high amount of data traffic for remote control operations. For better performance of the autonomous vehicle operations, the delay-sensitive applications (e.g., remote control operations, collision / accident prevention, emergency management, etc.) use LEO satellite link as it has smaller UE to ground propagation delay than GEO satellite connection. Other applications (i.e. delay tolerant, such as SMS, sensor data monitoring, video surveillance, etc.) may use GEO satellite link.

[0071] The autonomous vehicle supports multi-orbits satellite access (e.g., GEO and LEO) provided by same 5G satellite operator. The UE installed on the vehicle has a subscription for using GEO and LEO satellite services of a 5G satellite operator. Based on the service agreement between the vehicle managing company and the 5G satellite operator, the 5G satellite network has the following policies for the UE on the vehicle: the data traffic of delay-sensitive applications is routed via LEO satellite link whenever it is available and the data traffic of delay-tolerant applications is routed via GEO and / or LEO satellite links.

[0072] Fig. 3 shows a diagram of a vehicle at a location (e.g., a remote location) being remotely controlled by a central station. The vehicle has two types of active data traffic - one for remote control operation and the other for SMS.

[0073] As shown in the bottom of Fig. 3, LEO satellite 1 access becomes unavailable (e.g., due to loss of line of sight between the UE and a satellite 1 ). Therefore, the traffic that was routed via the LEO satellite 1 access is moved to LEO satellite 2 access or GEO satellite access, while the continuity of data sessions is maintained.

[0074] After a while, the LEO satellite 1 access becomes available again. Therefore, the traffic distribution across three satellite accesses is returned to the state as in the top of Fig. 3

[0075] Based on operator policy, the 5G system shall be able to dynamically offload part of the traffic (e.g., from 3GPP RAT to non-3GPP access technology), taking into account traffic load and traffic type. Based on operator policy, the 5G system shall be able to provide simultaneous data transmission via different access technologies (e.g., NR, E-UTRA, non-3GPP), to access one or more 3GPP services. When a UE is using two or more access technologies simultaneously, the 5G system shall be able to optimally distribute user traffic over select between access technologies in use, taking into account e.g., service, traffic characteristics, radio characteristics, and UE's moving speed. The 5G system shall support UEs with multiple radio and single radio capabilities. The 5G system shall be able to provide services using satellite access. A 5G system with satellite access shall support different configurations where the radio access network is either a satellite NG-RAN or a non-3GPP satellite access network, or both. Subject to regulatory requirements and operator’s policies, a 5G system with satellite access shall be able to support collection of information on usage statistics and location of the UEs that are connected to the satellite. Subject to regulatory requirements and operator’s policy, a 5G system with satellite access shall be able to support service continuity (with minimum service interruption) of a UE-Satellite-UE communication when the LIE communication path moves between serving satellites (due to the movement of the UE and / or the satellites). Subject to HPLMN policy and network control, the 5G system shall be able to support mechanisms to enable traffic steering and / or switching of a DualSteer device’s user data (for different services) across two 3GPP access networks belonging to the same PLMN (either HPLMN or VPLMN), assuming data anchoring in the HPLMN and non-simultaneous transmission over the two networks. Subject to HPLMN policy and network control, the 5G system may be able to support mechanisms to enable traffic steering and / or switching with simultaneous transmission of a DualSteer device’s user data (for different services) across two 3GPP access networks belonging to the same PLMN (either HPLMN or VPLMN), assuming data anchoring in the HPLMN. Subject to HPLMN policy and network control, the 5G system shall be able to support mechanisms to minimize service interruption when switching a DualSteer device’s user data, for one or multiple services, between two 3GPP access networks. Subject to HPLMN policy and network control, the 5G system shall be able to collect charging information related to traffic steering and / or switching of a DualSteer device’s user data across two 3GPP access networks.

[0076] In a further example use case, a control center of a Meteorological Bureau monitors Earth's atmosphere, clouds, oceans and other aspects of weather through the data and images returned by satellites for weather forecasting and nature disaster prediction. A Ministry of Natural Resources monitors earthquake, fire disaster, typhoon, hurricane, sandstorm, cold wave and other natural hazard through satellite for weather forecasting and nature disaster prediction.

[0077] Satellites for weather forecasting and nature disaster prediction take a set of high- resolution meteorological images at regular intervals, which show the distribution, thickness and shape of cloud cover, topography. These images are rapidly transmitted back to the ground, where experts from the Meteorological Bureau analyse them to accurately predict the trend of weather systems. Experts of Ministry of Natural Resources could analyse these pictures to predict and monitor a natural hazard accurately before it happens. In this example, there are a group of satellites for weather forecasting and nature disaster prediction at LEO. Usually, they transmit these pictures back to ground. An application server on the ground will proceed data processing and analysis based on requirements of experts. Since these images are high-resolution and are generated at about 1 .5G / s, which need very high bandwidth to transmit back to ground, it is more efficiency to process and analysis on the satellite and send the results to ground. However, as the load on satellite is limited as it equipped with a lot of high-resolution cameras, it’s not very practical for satellite to equip large amount of computing resource. Communication satellites are distributed in space on LEO, MEO, and GEO, they are more convenient to facilitate computing resource. And with the bandwidth at about 15-25Gb / s on ISL, satellites for weather forecasting and nature disaster prediction can send the data to communication satellites and 5G system is able to provide Service Hosting Environment on satellite for the data processing.

[0078] In an example, illustrated in Fig. 4, Operator A has multiple LEO satellites and also GEO satellites, servers of Ministry of Natural Resources are deployed in the edge application server on two LEO satellites of operator, and servers of Meteorological Bureau / Ministry are deployed in the edge application server on three GEO satellites. There are a group of LEO satellites for weather forecasting and nature disaster prediction to monitor same area which are also operated by Operator A.

[0079] Weather analysis service requires a large number of data for analysis such as high- resolution pictures which take very large bandwidth of satellite. It may difficult to transmit all the data at one time for LEO for weather forecasting and nature disaster prediction. Natural hazard service requires high reliability.

[0080] In the example shown in Fig. 4, LEO satellites for weather forecasting and nature disaster prediction take a set of pictures of earth’s atmosphere, clouds and topography with high definition.As the pictures are high-resolution, and satellites are LEO, the data cannot be transmitted to ground at one time. So satellites for weather forecasting and nature disaster prediction send the data to the edge application server which is deployed on operator’s LEO to do on-board processing, so that only the processing result will be send to the ground which takes lower bandwidth.

[0081] The 5G system select the closest EAS on the operator LEO satellites. High-resolution pictures will be send to the EAS of Meteorological Bureau on the operator LEO via intersatellite link. 5G system selects the closest EAS on the GEO. High-resolution pictures of all these satellites for weather forecasting and nature disaster prediction will be send to the EAS of Ministry of Natural Resources on the operator GEO via inter-satellite link.

[0082] EAS sends result to Meteorological Bureau / Ministry of Natural Resources on the ground so that each location receives analysis results and part of pictures. In this example, A 5G system with satellite access shall be able to select the communication link providing the UE with the connectivity that most closely fulfils the agreed QoS

[0083] There are several use cases, which requires multi orbit Satellite to serve a particular UE or loT device or assisting vehicle communication. For example, one orbit SAT becomes unavailable, and another orbit SAT serves. A use case may be a disaster scenario (e.g., link between the LEO satellite and the ground station is temporarily unavailable due to a disaster ), where LEO couldn’t serve due to unavailability.

[0084] All orbit satellites may serve at a given point in time. A use case could be that a satellite operator has deployed multi-orbit (LEO, MEO and GEO) satellites and has an agreement with Terrestrial Operator to provide communication or connectivity services for UEs under satellite coverage. Different latency requirements may be served by different orbit satellites.

[0085] Subject to regulatory requirements and operator’s policy, a 5G system with satellite access shall be able, if applicable, to support service continuity and provide suitable QoS controlwhen the LIE communication path moves between satellites in different orbits (due to the movement of the UE and / or the satellites).

[0086] Service continuity across different orbits might not always be possible / applicable depending on the service characteristics (e.g., service continuity for a low-latency service may not be applicable across LEO and GEO orbits).

[0087] A 5G network with satellite access shall be able to support charging mechanisms for communication services using satellite access in different orbits based on the type of satellites (e.g., LEO, MEO, GEO).

[0088] The 5G system with satellite access shall be able to support a mechanism to satisfy the QoS when user data traffic moves across satellites at different orbits.

[0089] The 5G network shall be able to collect charging information related to traffic of user data when user data traffic moves across satellites at different orbits.

[0090] Based on regulatory requirements and operators’ policy, the 5G system shall support Service Hosting Environment (e.g., edge application server) on multi-orbit satellites.

[0091] Based on regulatory requirements, operators’ policy and agreement with 3rd party, the 5G system shall support a mechanism to provide most suitable service hosting environment via multi-orbit satellites. One example is an operator can choose the most suitable service hosting environment on-board of satellites, based on the topology of satellites as they are moving on the orbits.

[0092] The 5G system using multi orbit satellite network for backhauling shall be able to take into account the respective capabilities (e.g., latency, data rate) and availability of the different satellite access (e.g., over GEO, MEO, LEO) to map the backhaul traffic with a given aggregated QoS.

[0093] The 5G system shall be able to collect and distinguish charging information related to backhaul traffic over different orbits of the satellite network.

[0094] All the above new requirements need the multi orbit Satellite to be authenticated to serve the UE at the same time.

[0095] Authentication procedures and authorization procedure of multi orbit Satellite.

[0096] Authentication at UDM needs to be differentiated for each UE for better service.

[0097] In the 5G System (5GS), when a User Equipment (UE) is in dual connectivity mode, the UE connects to two gNBs: a Master Node (MN) and a Secondary Node (SN). However, the UE maintains only a single Radio Resource Control (RRC) context with the MN, not separate RRC contexts for the MN and SN. The Master Node (MN), which is typically the primary gNB in the 5G network, manages the entire RRC connection with the UE. The MN is responsible for handling RRC signalling and controlling both its own resources and the resources allocated from the SN. While the Secondary Node (SN) (another gNB that assists in improving throughput or reliability) contributes additional radio resources to the UE, it does not establish a separate RRCcontext with the LIE. Instead, the SN communicates with the MN, which then controls the SN resources on behalf of the LIE. The MN coordinates with the SN for data transmission and reception, using interfaces like XN (the interface between the MN and SN) to ensure synchronized communication. This allows the LIE to use resources from both gNBs simultaneously for enhanced performance without maintaining two separate RRC connections. In summary, only one RRC context exists between the LIE and the MN in dual connectivity. The MN manages the RRC signalling and controls SN resources via coordination with the SN, thereby avoiding the complexity of maintaining dual RRC contexts at the UE level.

[0098] Fig. 5 shows a flowchart of a method according to an example embodiment. The method may be performed at an apparatus. The apparatus may be, comprise or be comprised in a network entity implemented for mobility management function. For example, the apparatus may be, comprise or be comprised in an AMF.

[0099] At 501 , the method comprises receiving a registration request for a user equipment from a first satellite, the registration request including an identifier of the first satellite and an indication that the user equipment supports multi orbit satellites.

[0100] At 502, the method comprises obtaining a random number associated with the first satellite and a random number associated with the at least one further satellite.

[0101] At 503, the method comprises providing an authentication request to an authentication entity, the authentication request comprising the identifier of the first satellite, and each of the random numbers associated with the first and at least one further satellites.

[0102] At 504, the method comprises, in response, receiving an authentication vector from the authentication entity.

[0103] At 505, the method comprises providing the authentication vector to the first and at least one further satellite.

[0104] Fig. 6 shows a flowchart of a method according to an example embodiment. The method may be performed at an apparatus. The apparatus may be, comprise or be comprised in a network entity implemented for authentication. For example, the apparatus may be, comprise or be comprised in an ALISF.

[0105] At 601 , the method comprises receiving an authentication request for a user equipment from a network entity, the request comprising an identifier of a first satellite and a random number associated with the first satellite and a random number associated with at least one further satellite.

[0106] At 602, the method comprises determining an authentication vector, based on the identifier of a first satellite and each of the random numbers associated with the first satellite and the at least one further satellite, respectively.

[0107] At 603, the method comprises providing an indication of the determined authentication vector to the network entity.

[0108] Fig. 7 shows a flowchart of a method according to an example embodiment. The method may be performed at an apparatus. The apparatus may be, comprise or be comprised in an apparatus.

[0109] At 701 , the method comprises providing a registration request for a user equipment to a first satellite, wherein the registration request includes an indication that the user equipment supports multi orbit satellites.

[0110] At 702, the method comprises receiving an indication from the first satellite of an authentication vector, the authentication vector comprising a random number associated with the first satellite and at least one further satellite.

[0111] The first satellite may be in a first orbit and the at least one further satellite may be in a different orbit. The first orbit may be a low Earth orbit (LEO). The different orbit may be a medium Earth orbit (MEO) or a geostationary orbit (GEO).

[0112] Obtaining the random number associated with the first satellite and the random number associated with the at least one further satellite may comprises receiving each of the random numbers associated with the first satellite and at least one further satellite from the respective satellite.

[0113] A method as described with reference to Fig. 5 may comprise obtaining an identifier of the at least one further satellite, wherein the authentication request further comprises the identifier of the at least one further satellite. Obtaining the identifier of the at least one further satellite may comprise receiving the identifier of the at least one further satellite in a registration request from the respective satellite.

[0114] For example, in variant A of a method as described with reference to Figs. 5 to 7, the UE sends a registration request indicating its support for multiple satellite orbits. Each satellite orbit (LEO, MEO, GEO) communicates with the core network, appending its SAT ID and RAND to the request. The 6G core network (AMF) concatenates the satellite IDs and sends an authentication request to the AUSF of home network (HN), which verifies the UE's authorization. The authentication vector is generated by combining random values (RAND) and satellite IDs, with each orbit handling its own security response calculation (RES**). Once the UE verifies the authentication vectors for each satellite, the response is shared across the relevant multi-orbit satellites and the core network for final verification. Upon successful validation by the satellites, core network, and home network, the multi-orbit satellite authentication is complete.

[0115] Fig. 8 shows a flowchart for an example method, where an identifier and RAND is received from each orbit satellite at AUSF.

[0116] At step 0, pre-configuration for the multi orbit satellites is handled by the Home network.

[0117] At step 1 , a UE sends the registration request with SUCI and multi orbit SAT registration indication, which means that UE supports multi orbit satellites. This is an example ofproviding a registration request for a user equipment to a first satellite, wherein the registration request includes an indication that the user equipment supports multi orbit satellites.

[0118] At step 2, based on pre-configuration, UE’s registration request is sent from the LEO via the Inter-satellite Link (ISL) to MEO and GEO. If each orbit SAT has bandwidth currently to support this UE, then SAT will relay the registration request towards CN. Each orbit SAT will add their SAT ID and RAND when sent to CN. This is an example of receiving the identifier of the first satellite (e.g., LEO SAT ID), the identifier of the at least one further satellite (e.g., GEO SAT ID; MEO SAT ID), the random number associated with the first satellite (RANDLEO) and the random number associated with at least one further satellite (RANDGEO, RANDMEO) in a registration request from the respective satellite.

[0119] At step 3, the AMF, based on different registration request messages from the satellites at different orbits will concatenate the LEO SAT ID, GEO SAT ID and MEO SAT ID along with SNN (SNN could be “6G_SAT:SN ID” or “6G:MULTI_ORBIT:SN ID”).

[0120] At step 4, the authentication request is sent with SUCI , multi orbit SAT registration indication with SAT ID concatenated with SNN and RAND of GEO, RAND of LEO and RAND of MEO. This is an example of providing the indication that the user equipment supports multi orbit satellites to the authentication entity.

[0121] At step 5, the AUSF verifies if this UE is authorized for the multi orbit SAT services. LEO SAT ID, GEO SAT ID and MEO SAT IDs are sent along with AV to UE, so UE could also verify AV and also use these SAT IDs for later AS specific keys for each orbit.

[0122] AT step 6, AUSF will generate RANDHN and concatenate with RAND of all orbit SAT, including each orbit SAT ID and SN ID and concatenated RAND in the Authentication vector generation. This is an example of determining the authentication vector further based on the identifier of the at least one further satellite. This step is also an example of generating a random number associated with the network and concatenating the random number associated with the home network and each of the random numbers associated with the first satellite and the at least one further satellite, respectively.

[0123] At step 7, HN(AUSF) stores HN HXRES* when XRES* is sent from UDM.

[0124] At step 8, an Authentication response with SUPI and 6G SE Authentication vector is sent to 6G AMF. 6G AMF will send Authentication response with XRES** to each orbit SAT. Each orbit SAT will use its RAND to calculate their respective Hash value HXRES**. LEO SAT is the one which is connected to the UE, so the Authentication request is sent with 6G AV with RANDHN and RAND of all SATs.

[0125] At step 9 SON is verified, and AV is verified. Response is calculated for home network and also for all Satellites at each orbit.

[0126] At step 10, the UE will send to the LEO satellite the Authentication response with HN RES* and all orbit SAT RES**. This is an example of providing an authentication response to the first satellite, the authentication response comprising a response token for the first satellite and aresponse token for the at least one further satellite, wherein each respective response token is generated based on the received authentication vector.

[0127] At step 1 1 , the LEO satellite will provide the MEO RES** , GEO RES** to respective satellites and the response is verified. LEO will verify its LEO RES** with expected response. Also, the HN RES* is sent to CN, which is then verified at the AMF and also at HN.

[0128] At step 12, after the verification of responses at all orbit SATs, CN and HN, the authentication of the multi orbit is considered successful.

[0129] Obtaining the random number associated with the first satellite and the random number associated with the at least one further satellite in the method described with reference to Fig. 5 may comprise generating the random number associated with each of the first satellite and at least one further satellites. In an example variant of a method as described with reference to Figs. 5 to 7, variant B, the UE sends a registration request, including a multi-orbit SAT registration indication, showing that it supports communication across multiple satellite orbits. MEO and GEO satellites relay the registration request if they have the bandwidth, appending their satellite IDs. A Core Network (AMF) then concatenates the satellite IDs and SNN and generates a random value (RAND) for each satellite orbit. The authentication request is sent with the satellite IDs, SNN, and RANDs for each orbit. The 6G Home network verifies if the UE is authorized for multiorbit satellite services. Additionally, the AMF groups the satellites (LEO, MEO, and GEO) under its control, streamlining the management of the authentication process.

[0130] Fig. 9 shows a signaling flow according to an example. At step 0, pre-configuration for the multi orbit satellites is handled by the Home network.

[0131] At step 1 , the UE sends the registration request with SUCI and multi orbit SAT registration indication, which means that UE supports multi orbit satellites.

[0132] At step 2, based on pre-configuration, the UE’s registration request is sent to MEO and GEO is communicated with UE’s registration request. If each orbit SAT has bandwidth currently to support this UE, then SAT will relay the registration request towards the CN. Each orbit SAT will add their SAT ID when sent to CN.

[0133] At step 3, the Core network (e.g., AMF) will concatenate the LEO SAT ID, GEO SAT ID and MEO SAT ID along with SNN (SNN could be “6G_SAT:SN ID” or “6G:MULTI_ORBIT:SN ID”). The AMF will generate RAND for all orbit SATs. This is an example of generating the random number associated with each of the first satellite and at least one further satellites.

[0134] At step 4, an authentication request is sent with SUCI , multi orbit SAT registration indication with SAT ID concatenated with SNN and RAND of GEO, RAND of LEO and RAND of MEO.

[0135] At step 5, the HN verifies if this UE is authorized for the multi orbit SAT services.

[0136] A step 6, the LEO, MEO and GEO satellites will be formed as a group by AMF and controlled by CN / AMF.

[0137] The remainder of the steps follow those as described with reference to Fig. 8.

[0138] In an example variant of a method as described with reference to Figs. 5 to 7, variantC , the LEO satellite takes a central role without relaying the UE's registration request to other satellite orbits. When the UE sends a registration request with multi-orbit SAT registration indication, the LEO satellite informs the other orbit satellites (such as MEO and GEO) about the potential registration but does not relay the actual request. Instead, only the LEO satellite sends the registration request, including its SAT ID, to the 6G AMF. The rest of the process, including authentication and authorization, proceeds based solely on the LEO'S communication, while the MEO and GEO satellites are kept informed but not directly involved in the registration phase. This simplifies the registration handling while maintaining multi-orbit satellite awareness.

[0139] Fig. 10 shows a flowchart of an example method. With this variant, the LEO satellite will send the registration request with LEO SAT ID to AMF in step 2. The AMF undertakes to determine the satellites at the other orbits that can be in involved in multi-orbit registration and generates the random number associated with the LEO and satellites at other orbits (MEO and GEO). This is an example of generating the random number associated with each of the first satellite and at least one further satellites.

[0140] At step 5 of Fig. 10, the HN verifies if this UE is authorized for the multi orbit SAT services and the remainder of the steps are as described with reference to Fig. 8.

[0141] Fig. 11 shows a flowchart of a method according to an example embodiment. The method is performed for a user equipment authenticated for operation with a first satellite and at least one further satellite. The method may be performed at an apparatus. The apparatus may be, comprise or be comprised in a network entity implemented for mobility management function, e.g., AMF.

[0142] At 1 101 , the method comprises generating keys for the first satellite and the at least one further satellite based on an identifier of the first satellite and an identifier of the at least one further satellite; and

[0143] At 1102, the method comprises initiating context setup with the first satellite and at least one further satellite.

[0144] Fig. 12 shows a flowchart of a method according to an example embodiment. The method is performed at an apparatus authenticated for operation with a first satellite and at least one further satellite and which has an active context set up with the first satellite and an inactive context setup with the at least one further satellite. The apparatus may be a UE.

[0145] At 1201 , the method comprises activating the inactive context with the at least one further satellite.

[0146] Fig. 13 shows a signaling flow according to any example embodiment, Once the multi orbit authentication is completed, the NAS Security Mode command is completed. NAS keys will be generated independently in UE and AMF. AMF can then derive three different gNB keys, each for orbit SATs. The AMF will initiate the UE context setup message with GEO, LEO and MEO.LEO is the one which has active connection with LIE , so AS SMC will be executed and RRC keys, UP keys will be generated in UE and LEO SAT. UE context in LEO and UE is active.

[0147] Activating the inactive context may comprise performing an access stratum security mode command. The MEO and GEO and also UE will have two different other UE context which is inactive at the moment with MEO gNB key and GEO gNB Key. When required, depending upon latency requirements, other UE inactive context could be activated and AS SMC is run for those orbit SATs also.

[0148] Fig. 14 shows, by way of example, a block diagram of an apparatus 10. The apparatus 10 comprises, for example, at least one processor 12 and at least one memory 14 storing instructions 15 that, when executed by the at least one processor, cause the apparatus 10 at least to perform the method or methods (or portion(s) thereof) as disclosed herein, and any of the embodiments (or respective portion(s) thereof). In an example, the at least one memory and the instructions (e.g. a computer program code, software), are configured, with the at least one processor, to cause the apparatus 10 to perform the method or methods (or portion(s) thereof) as disclosed herein, and any of the embodiments (or respective portion(s) thereof).

[0149] A processor 12 may comprise circuitry, or be constituted as circuitry or circuitries, the circuitry or circuitries being configured to perform phases of methods in accordance with embodiments described herein.

[0150] As used herein, the term “circuitry” may refer to one or more or all of the following: (a) hardware-only circuit implementations, such as implementations in only analog and / or digital circuitry, and (b) combinations of hardware circuits and software, such as, as applicable: (i) a combination of analog and / or digital hardware circuit(s) with software / firmware and (ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a user equipment, to perform various functions) and (c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation. This definition of circuitry applies to all uses of this term herein, including in any claims. As a further example, as used herein, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.

[0151] The memory 14 may be implemented using any suitable data storage technology. The memory may comprise a database for storing data. The memory 14 may, for example, be at least in part external to apparatus 10 but accessible to apparatus 10.

[0152] The instructions 15 may be comprised in a computer readable medium or a non- transitory computer readable medium. A term non-transitory, as used herein, is a limitation of the medium itself (i.e. tangible, not a signal) as opposed to a limitation on data storage persistency (e.g. random access memory, RAM, vs. read only memory, ROM).

[0153] For example, the apparatus 10 is a terminal device, such as a UE. As another example, the apparatus is comprised in such a terminal device, e.g. as a chipset configured to control the terminal device. The apparatus 10 may be caused or configured or comprise means to perform at least the method of Figs. 7 or 12 and / or any one or more of the embodiments described herein.

[0154] As another example, the apparatus 10 is a network entity. In another embodiment, the apparatus is comprised in such a network entity, e.g. as a chipset configured to control the network entity. The apparatus 10 may be caused or configured or comprise means to perform at least the method of Figs. 5, 6 or 11 and / or any one or more of the embodiments described herein.

[0155] The apparatus may comprise one or more entities of any of protocol layers, such as a MAC entity, an RRC entity, an RLC entity, a PDCP entity or a PHY entity. In some embodiments, the entity is configured to perform at least the method of Figs. 4, 9 and 11 , and / or any one or more of the embodiments described.

[0156] The apparatus 10 comprises a radio interface 16. The radio interface 16 may provide the apparatus 10 with communication capabilities. The radio interface 16 may comprise a receiver configured to receive information in accordance with at least one cellular or non-cellular standard. The radio interface 16 may comprise a transmitter configured to transmit information in accordance with at least one cellular or non-cellular standard. The receiver may comprise more than one receiver. The transmitter may comprise more than one transmitter. The radio interface 16 may comprise a transceiver configured to receive and transmit information in accordance with at least one cellular or non-cellular standard. The transceiver may comprise more than one transceiver.

[0157] The apparatus 10 may comprise a user interface 18 comprising, for example, at least one of a keypad, a microphone, a touch display, a display, a speaker, etc. The user interface 18 may be used to control the apparatus by the user. The user interface 18 may be external to the apparatus 10. For example, the apparatus 10 may be connected to another device, such as a computer, either via wireless or wired connection, and the apparatus 10 is controlled by the user via the computer.

[0158] In an embodiment, at least some of the processes described herein may be carried out by an apparatus comprising means for carrying out at least some of the described processes. Means for performing method steps as disclosed herein may include software and / or hardware components of the apparatus 10. For example, the at least one processor 12, the memory 14,and the computer program code form means for carrying out the method or methods (or portion(s) thereof) as disclosed herein, and any of the embodiments (or respective portion(s) thereof). As used herein the term “means” is to be construed in singular form, i.e. referring to a single element, or in plural form, i.e. referring to a combination of single elements. Therefore, terminology “means for [performing A, B, C]”, is to be interpreted to cover an apparatus in which there is only one means for performing A, B and C, or where there are separate means for performing A, B and C, or partially or fully overlapping means for performing A, B, C. Further, terminology “means for performing A, means for performing B, means for performing C” is to be interpreted to cover an apparatus in which there is only one means for performing A, B and C, or where there are sepa- rate means for performing A, B and C, or partially or fully overlapping means for performing A, B, C.

[0159] Even though this disclosure has been described above with reference to non-limiting and illustrative examples according to the accompanying figures, it is clear that the scope of this disclosure is not restricted thereto - but can be modified in many different ways. As technology advances, it will become apparent to a person skilled in art as to how the disclosure can be further implemented and / or modified in various ways. Further, it is clear to a person skilled in the art that the embodiments described herein may, but are not required to, be combined in various ways with other embodiments described herein.

Claims

1. CLAIMS1 . An apparatus comprising means for: receiving a registration request for a user equipment from a first satellite, the registration request including an identifier of the first satellite and an indication that the user equipment supports multi orbit satellites; obtaining a random number associated with the first satellite and a random number associated with at least one further satellite; providing an authentication request to an authentication entity, the authentication request comprising the identifier of the first satellite, and each of the random numbers associated with the first and at least one further satellites; in response, receiving an authentication vector from the authentication entity; and providing the authentication vector to the first and at least one further satellite.

2. The apparatus according to claim 1 , wherein the first satellite is in a first orbit and the at least one further satellite is in a different orbit.

3. The apparatus according to claim 2, wherein the first orbit is a low Earth orbit and the different orbit is a medium Earth orbit or a geostationary orbit.

4. The apparatus according to any of claims 1 to 3, wherein obtaining the random number associated with the first satellite and the random number associated with the at least one further satellite comprises receiving the random number associated with each of the first satellite and at least one further satellite from the respective satellite.

5. The apparatus according to any of claims 1 to 3, wherein obtaining the random number associated with the first satellite and the random number associated with the at least one further satellite comprises generating the random number associated with each of the first satellite and at least one further satellites.

6. The apparatus according to any of claims 1 to 5, comprising means for: obtaining an identifier of the at least one further satellite, wherein the authentication request further comprises the identifier of the at least one further satellite.

7. The apparatus according to claim 6, wherein obtaining the identifier of the at least one further satellite comprises receiving the identifier of the at least one further satellite in a registration request from the respective satellite.

8. The apparatus according to any of claims 1 to 7, comprising means for: providing the indication that the user equipment supports multi orbit satellites to the authentication entity.

9. The apparatus according to any of claims 1 to 8, wherein the apparatus is, comprises or is comprised in a network entity implemented for mobility management function.

10. An apparatus comprising means for: receiving an authentication request for a user equipment from a network entity, the request comprising an identifier of a first satellite and a random number associated with the first satellite and a random number associated with at least one further satellite; determining an authentication vector, based on the identifier of a first satellite and each of the random numbers associated with the first satellite and the at least one further satellite, respectively; and providing an indication of the determined authentication vector to the network entity.11 . The apparatus according to claim 10, wherein the authentication request includes an indication that the user equipment supports multi orbit satellites.

12. The apparatus according to claim 10 or claim 1 1 , comprising means for generating a random number associated with the network and concatenating the random number associated with the home network and each of the random numbers associated with the first satellite and the at least one further satellite, respectively.

13. The apparatus according to any of claims 10 to 12, wherein the authentication request further comprises an identifier of the at least one further satellite and comprising means for determining the authentication vector further based on the identifier of the at least one further satellite.

14. An apparatus comprising means for:providing a registration request for a user equipment to a first satellite, wherein the registration request includes an indication that the user equipment supports multi orbit satellites; and receiving an indication from the first satellite of an authentication vector, the authentication vector comprising a random number associated with the first satellite and at least one further satellite.

15. The apparatus according to claim 14, comprising means for providing an authentication response to the first satellite, the authentication response comprising a response token for the first satellite and a response token for the at least one further satellite, wherein each respective response token is generated based on the received authentication vector.

16. A method comprising: receiving a registration request for a user equipment from a first satellite, the registration request including an identifier of the first satellite and an indication that the user equipment supports multi orbit satellites; obtaining a random number associated with the first satellite and a random number associated with at least one further satellite; providing an authentication request to an authentication entity, the authentication request comprising the identifier of the first satellite, and each of the random numbers associated with the first and at least one further satellites; in response, receiving an authentication vector from the authentication entity; and providing the authentication vector to the first and at least one further satellite.

17. A method comprising: receiving an authentication request for a user equipment from a network entity, the request comprising an identifier of a first satellite and a random number associated with the first satellite and a random number associated with at least one further satellite; determining an authentication vector, based on the identifier of a first satellite and each of the random numbers associated with the first satellite and the at least one further satellite, respectively; and providing an indication of the determined authentication vector to the network entity.

18. A method comprising: providing a registration request for a user equipment to a first satellite, wherein the registration request includes an indication that the user equipment supports multi orbit satellites; and receiving an indication from the first satellite of an authentication vector, the authentication vector comprising a random number associated with the first satellite and at least one further satellite.

19. An apparatus comprising at least one processor, and at least one memory storing instructions which, when executed by the at least one processor, cause the apparatus at least to perform: receiving a registration request for a user equipment from a first satellite, the registration request including an identifier of the first satellite and an indication that the user equipment supports multi orbit satellites; obtaining a random number associated with the first satellite and a random number associated with at least one further satellite; providing an authentication request to an authentication entity, the authentication request comprising the identifier of the first satellite, and each of the random numbers associated with the first and at least one further satellites; in response, receiving an authentication vector from the authentication entity; and providing the authentication vector to the first and at least one further satellite.

20. An apparatus comprising at least one processor, and at least one memory storing instructions which, when executed by the at least one processor, cause the apparatus at least to perform: receiving an authentication request for a user equipment from a network entity, the request comprising an identifier of a first satellite and a random number associated with the first satellite and a random number associated with at least one further satellite; determining an authentication vector, based on the identifier of a first satellite and each of the random numbers associated with the first satellite and the at least one further satellite, respectively; and providing an indication of the determined authentication vector to the network entity.21 . An apparatus comprising at least one processor, and at least one memory storing instructions which, when executed by the at least one processor, cause the apparatus at least to perform: providing a registration request for a user equipment to a first satellite, wherein the registration request includes an indication that the user equipment supports multi orbit satellites; and receiving an indication from the first satellite of an authentication vector, the authentication vector comprising a random number associated with the first satellite and at least one further satellite.

22. A computer program comprising instructions which, when executed by an apparatus, cause the apparatus to perform: receiving a registration request for a user equipment from a first satellite, the registration request including an identifier of the first satellite and an indication that the user equipment supports multi orbit satellites; obtaining a random number associated with the first satellite and a random number associated with at least one further satellite; providing an authentication request to an authentication entity, the authentication request comprising the identifier of the first satellite, and each of the random numbers associated with the first and at least one further satellites; in response, receiving an authentication vector from the authentication entity; and providing the authentication vector to the first and at least one further satellite.

23. A computer program comprising instructions which, when executed by an apparatus, cause the apparatus to perform: receiving an authentication request for a user equipment from a network entity, the request comprising an identifier of a first satellite and a random number associated with the first satellite and a random number associated with at least one further satellite; determining an authentication vector, based on the identifier of a first satellite and each of the random numbers associated with the first satellite and the at least one further satellite, respectively; and providing an indication of the determined authentication vector to the network entity.

24. A computer program comprising instructions which, when executed by an apparatus, cause the apparatus to perform:providing a registration request for a user equipment to a first satellite, wherein the registration request includes an indication that the user equipment supports multi orbit satellites; and receiving an indication from the first satellite of an authentication vector, the authentication vector comprising a random number associated with the first satellite and at least one further satellite.