Communication method and apparatus, communication device and storage medium
Patent Information
- Application Number
- PCT/CN2025/127339
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-14
- Filing Date
- 2025-10-13
- Publication Date
- 2026-09-17
Smart Images

Figure CN2025127339_17092026_PF_FP_ABST
Abstract
Description
Communication methods, devices, communication equipment and storage media
[0001] Related applications
[0002] This application claims priority to Chinese patent application filed on March 14, 2025, with application number 2025103063566, entitled "Communication Method, Apparatus, Communication Device and Storage Medium", the entire contents of which are incorporated herein by reference. Technical Field
[0003] This application relates to the field of mobile communication technology, and in particular to a communication method, apparatus, communication device, and storage medium. Background Technology
[0004] In its research on 5G non-terrestrial network communication, the 3GPP (3rd Generation Partnership Project) discovered that the connection between User Equipment (UE) and satellite and terrestrial networks may be intermittent. Therefore, it proposed that 5G networks can use satellite S&F (Store and Forward Satellite Operation), i.e., satellite store-and-forward operation.
[0005] However, when the feeder link between the satellite and the core network is unavailable, there may be security issues with using satellite-based S&F operations. For example, when the feeder link is unavailable, the terminal cannot establish a security context with the satellite (specifically, the satellite-side base station) / core network. If S&F operations are used, the satellite / core network cannot determine the authenticity of the user equipment's request message, making it vulnerable to DOS (Denial of Service) attacks. Summary of the Invention
[0006] Therefore, it is necessary to provide a communication method, apparatus, communication device, and storage medium that can improve communication security in response to the above-mentioned technical problems.
[0007] In a first aspect, this application provides a communication method applied to a satellite, comprising:
[0008] The system receives a first message sent by a user equipment; wherein the first message is generated by the user equipment based on a first encrypted message, a request message, and a first quantum key; the first encrypted message is obtained by encrypting the request message based on the first quantum key.
[0009] Based on the first message, determine the operational availability of the S&F operation;
[0010] If the operational availability condition is met, a second message is sent to the core network based on the first encrypted message in the first message.
[0011] In some embodiments, the first encrypted message is generated by the user equipment performing HMAC processing on the request message based on the first quantum key to obtain the first message authentication code, and generating a first key identifier based on the first encrypted message, the first message authentication code, and the first quantum key.
[0012] In some embodiments, determining the operational availability of the S&F operation based on the first message includes:
[0013] Based on the first message, obtain the first key identifier, the first encrypted message, and the first message authentication code;
[0014] The first quantum key is obtained based on the first key identifier;
[0015] Based on the first quantum key, the first encrypted message, and the first message authentication code, the operational availability of the S&F operation is determined.
[0016] In some embodiments, determining the operational availability of the S&F operation based on the first quantum key, the first encrypted message, and the first message authentication code includes:
[0017] The first encrypted message is decrypted using the first quantum key to obtain the first decrypted message;
[0018] The first decryption message is processed by HMAC based on the first quantum key to obtain the second message authentication code;
[0019] Based on the first message authentication code and the second message authentication code, determine the operational availability of the S&F operation.
[0020] In some embodiments, determining the operational availability of the Store & Forward (S&F) function based on the first message includes:
[0021] Determine the availability of the power supply lines between the satellite and the core network;
[0022] If the feeder line is unavailable, the availability of the S&F operation is determined based on the first message.
[0023] In some embodiments, a second message is sent to the core network based on a first encrypted message in a first message, including:
[0024] When the feeder line becomes available, a second message is sent to the core network based on the first encrypted message in the first message.
[0025] In some embodiments, the method further includes:
[0026] Receive an initial registration request sent by a user equipment; wherein the initial registration request carries a first key identifier of the first quantum key;
[0027] Based on the initial registration request, a terminal authentication request carrying a first key identifier is sent to the core network; wherein, the terminal authentication request is used to instruct the core network to obtain the first quantum key based on the first key identifier, and to send back a terminal authentication request response message carrying the first quantum key and the first key identifier to the satellite;
[0028] Store the first quantum key and the first key identifier, and encrypt the terminal authentication request response message based on the third quantum key to obtain the third encrypted message;
[0029] A third encrypted message is sent to the user equipment; wherein the third encrypted message carries a third key identifier of the third quantum key; the third encrypted message is used to instruct the user equipment to perform a terminal authentication operation based on the third encrypted message and the third key identifier.
[0030] In some embodiments, the third encrypted message is specifically used to instruct the user equipment to send a fourth encrypted message to the satellite; wherein, the fourth encrypted message is obtained by the user equipment encrypting the terminal authentication response message based on the fourth quantum key; the fourth encrypted message carries a third message authentication code and a fourth key identifier of the fourth quantum key; the third message authentication code is obtained by the user equipment performing HMAC processing on the terminal authentication response message based on the fourth quantum key; the terminal authentication response message is generated by the user equipment obtaining the third quantum key based on the third key identifier, decrypting the terminal authentication request response message based on the third quantum key, and generating the response message based on the decryption result.
[0031] In some embodiments, the method further includes:
[0032] Receive the fourth encrypted message and obtain the fourth quantum key based on the fourth key identifier carried in the fourth encrypted message;
[0033] The fourth encrypted message is decrypted using the fourth quantum key to obtain the second decrypted message;
[0034] The fourth message authentication code is obtained by performing HMAC processing on the second decryption message based on the fourth quantum key.
[0035] The true nature of the message is determined based on the fourth message authentication code and the third message authentication code carried in the fourth encrypted message;
[0036] If the information in the message is true, the second decrypted message is determined to be a terminal authentication response message, and a terminal authentication response message is sent to the core network.
[0037] Secondly, this application provides another communication method applied to user equipment, including:
[0038] When there is a need to send a request message to the core network, the request message is encrypted based on the first quantum key to obtain the first encrypted message;
[0039] A first message is generated based on the first encrypted message, the request message, and the first quantum key;
[0040] Send a first message to the satellite; wherein the first message is used to instruct the satellite to determine the operational availability of S&F operations, and if the operational availability is available, send a second message to the core network based on the first encrypted message in the first message.
[0041] In some embodiments, generating the first message based on the first encrypted message, the request message, and the first quantum key includes:
[0042] The request message is processed using HMAC based on the first quantum key pair to obtain the first message authentication code;
[0043] The first message is generated based on the first encrypted message, the first message authentication code, and the first key identifier of the first quantum key.
[0044] In some embodiments, the method further includes:
[0045] Receive the S&F operation service response message sent by the satellite; wherein, the S&F operation service response message is obtained by the satellite determining the service result based on the operation availability of S&F operation, and encrypting the service result based on the second quantum key; the S&F operation service response message also carries the second key identifier of the second quantum key;
[0046] Obtain the second quantum key based on the second key identifier;
[0047] Based on the second quantum key, the S&F operation service response message is decrypted to obtain the service result.
[0048] In some embodiments, before encrypting the request message based on the first quantum key in response to the request message sending request to obtain the first encrypted message, the method further includes:
[0049] An initial registration request carrying a first key identifier of a first quantum key is sent to the satellite, so that the satellite sends a terminal authentication request carrying at least the first key identifier to the core network based on the initial registration request; wherein, the terminal authentication request is used to instruct the core network to obtain the first quantum key based on the first key identifier, and to send back a terminal authentication request response message carrying the first quantum key and the first key identifier to the satellite; the terminal authentication request response message is used to instruct the satellite to store the first quantum key and the first key identifier, and to encrypt the terminal authentication request response message based on the third quantum key to obtain a third encrypted message;
[0050] Receive a third encrypted message sent by a satellite; wherein the third encrypted message carries at least a third key identifier of a third quantum key;
[0051] Terminal authentication is performed based on the third encrypted message and the third key identifier.
[0052] In some embodiments, terminal authentication is performed based on a third encrypted message and a third key identifier, including:
[0053] Obtain the third quantum key based on the third key identifier;
[0054] Based on the third quantum key, the terminal authentication request response message is decrypted, and a terminal authentication response message is generated based on the decryption result;
[0055] The terminal authentication response message is encrypted using the fourth quantum key to obtain the fourth encrypted message;
[0056] Based on the fourth quantum key, the terminal authentication response message is processed by HMAC to obtain the third message authentication code;
[0057] A fourth encrypted message carrying a key identifier containing a third message authentication code and a fourth quantum key is sent to the satellite; wherein, the fourth encrypted message is used to instruct the satellite to determine the authenticity of the message based on the fourth encrypted message, and if the authenticity of the message is true, to send a terminal authentication response message to the core network.
[0058] Thirdly, this application provides a communication device configured in a satellite, the device comprising:
[0059] The first receiving module is used to receive a first message sent by the user equipment; wherein the first message is generated by the user equipment based on a first encrypted message, a request message and a first quantum key; the first encrypted message is obtained by encrypting the request message based on the first quantum key;
[0060] The first determining module is used to determine the operational availability of the S&F operation based on the first message;
[0061] The first sending module is used to send a second message to the core network based on the first encrypted message in the first message, provided that the operation is available.
[0062] Fourthly, this application provides a communication device configured in a user equipment, the device comprising:
[0063] The encryption module is used to encrypt the request message based on the first quantum key when there is a need to send a request message to the core network, so as to obtain the first encrypted message;
[0064] A generation module is used to generate a first message based on a first encrypted message, a request message, and a first quantum key;
[0065] The second sending module is used to send a first message to the satellite; wherein the first message is used to instruct the satellite to determine the operational availability of S&F operations, and if the operational availability is available, to send a second message to the core network based on the first encrypted message in the first message.
[0066] Fifthly, this application also provides a communication device, which includes a memory, a transceiver, and a processor. The memory stores a computer program, the transceiver is used to receive or send data under the control of the processor, and the processor executes the computer program to implement the following methods:
[0067] The system receives a first message sent by a user equipment; wherein the first message is generated by the user equipment based on a first encrypted message, a request message, and a first quantum key; the first encrypted message is obtained by encrypting the request message based on the first quantum key.
[0068] Based on the first message, determine the operational availability of the S&F operation;
[0069] If the operational availability condition is met, a second message is sent to the core network based on the first encrypted message in the first message.
[0070] Sixthly, this application also provides another communication device, which includes a memory, a transceiver, and a processor. The memory stores a computer program, the transceiver is used to receive or send data under the control of the processor, and the processor executes the computer program to implement the following methods:
[0071] When there is a need to send a request message to the core network, the request message is encrypted based on the first quantum key to obtain the first encrypted message;
[0072] A first message is generated based on the first encrypted message, the request message, and the first quantum key;
[0073] Send a first message to the satellite; wherein the first message is used to instruct the satellite to determine the operational availability of S&F operations, and if the operational availability is available, send a second message to the core network based on the first encrypted message in the first message.
[0074] In a seventh aspect, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the following method:
[0075] The system receives a first message sent by a user equipment; wherein the first message is generated by the user equipment based on a first encrypted message, a request message, and a first quantum key; the first encrypted message is obtained by encrypting the request message based on the first quantum key.
[0076] Based on the first message, determine the operational availability of the S&F operation;
[0077] If the operational availability condition is met, a second message is sent to the core network based on the first encrypted message in the first message.
[0078] Eighthly, this application also provides another computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the following method:
[0079] When there is a need to send a request message to the core network, the request message is encrypted based on the first quantum key to obtain the first encrypted message;
[0080] A first message is generated based on the first encrypted message, the request message, and the first quantum key;
[0081] Send a first message to the satellite; wherein the first message is used to instruct the satellite to determine the operational availability of S&F operations, and if the operational availability is available, send a second message to the core network based on the first encrypted message in the first message.
[0082] Ninthly, this application also provides a computer program product, comprising a computer program that, when executed by a processor, implements the following methods:
[0083] The system receives a first message sent by a user equipment; wherein the first message is generated by the user equipment based on a first encrypted message, a request message, and a first quantum key; the first encrypted message is obtained by encrypting the request message based on the first quantum key.
[0084] Based on the first message, determine the operational availability of the S&F operation;
[0085] If the operational availability condition is met, a second message is sent to the core network based on the first encrypted message in the first message.
[0086] In a tenth aspect, this application also provides another computer program product, comprising a computer program that, when executed by a processor, implements the following methods:
[0087] When there is a need to send a request message to the core network, the request message is encrypted based on the first quantum key to obtain the first encrypted message;
[0088] A first message is generated based on the first encrypted message, the request message, and the first quantum key;
[0089] Send a first message to the satellite; wherein the first message is used to instruct the satellite to determine the operational availability of S&F operations, and if the operational availability is available, send a second message to the core network based on the first encrypted message in the first message.
[0090] The aforementioned communication method, apparatus, communication device, and storage medium receive a first message sent by a user equipment. The first message is generated by the user equipment based on a first encrypted message, a request message, and a first quantum key. The first encrypted message is obtained by encrypting the request message using the first quantum key. Based on the first message, the operational availability of the S&F operation is determined. If the operational availability is deemed acceptable, a second message is sent to the core network based on the first encrypted message in the first message. This application encrypts the request message using the first quantum key, improving the security of the request message. Furthermore, after receiving the first message, the satellite can also determine the operational availability of the S&F operation based on the first message. Only if the first message meets the requirements is the operational availability deemed acceptable, and thus, based on the S&F operation and the first encrypted message in the first message, the second message is sent to the core network, further enhancing communication security. Attached Figure Description
[0091] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the embodiments will be briefly described below. Obviously, the drawings described below are merely some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without any creative effort.
[0092] Figure 1 is an application environment diagram of a communication method provided in some embodiments;
[0093] Figure 2 is a flowchart illustrating the communication method provided in some embodiments;
[0094] Figure 3 is a flowchart illustrating the process of determining the availability of S&F operations according to some embodiments;
[0095] Figure 4 is a schematic diagram of the process of sending a third encrypted message to a user equipment according to some embodiments;
[0096] Figure 5 is a flowchart illustrating another communication method provided in some embodiments;
[0097] Figure 6 is a schematic diagram of the process for obtaining service results provided in some embodiments;
[0098] Figure 7 is a schematic diagram of the terminal registration and authentication process provided in some embodiments;
[0099] Figure 8 is a signaling interaction diagram of terminal authentication and registration provided in some embodiments;
[0100] Figure 9 is a signaling interaction diagram of message transmission between a terminal, satellite, and core network according to some embodiments;
[0101] Figure 10 is a structural block diagram of a communication device provided in some embodiments;
[0102] Figure 11 is a structural block diagram of another communication device provided in some embodiments;
[0103] Figure 12 is an internal structure diagram of a communication device provided in some embodiments. Detailed Implementation
[0104] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0105] The communication method provided in this application embodiment can be applied to the application environment shown in Figure 1.
[0106] Specifically, when a user equipment (UE) needs to send a request message to the core network, the UE encrypts the request message using a first quantum key to obtain a first encrypted message; and generates a first message based on the first encrypted message, the request message, and the first quantum key. The satellite receives the first message sent by the UE. Then, based on the first message, the satellite determines the operational availability of the S&F operation; and if the operational availability is found to be available, it sends a second message to the core network based on the first encrypted message in the first message.
[0107] In this context, "satellite" refers to an artificial satellite, primarily including, but not limited to, those used for communication, navigation, meteorological observation, Earth observation, and scientific research. The satellite in this application mainly refers to an artificial satellite with communication capabilities, which can act as a relay communication between user equipment and the core network.
[0108] User equipment refers to terminal equipment on the user side, including but not limited to smart terminals such as mobile phones and computers, and can also be smart wearable devices such as smart bracelets and smartwatches.
[0109] The core network refers to the core part of a mobile communication network responsible for processing user data and signaling. It acts as a bridge connecting user equipment and external networks, providing various services such as voice calls, SMS, data transmission, and internet access. The core network is the heart of the mobile communication network, responsible for managing and controlling the entire network's communication process. The core network in this application can be a 5G core network (i.e., 5GC (5GCore)).
[0110] In an optional embodiment, as shown in FIG2, a communication method is provided that can be applied to the satellite shown in FIG1. In this embodiment, the method includes the following steps:
[0111] S201, Receive the first message sent by the user equipment.
[0112] The first message is generated by the user equipment based on the first encrypted message, the request message, and the first quantum key; the first encrypted message is obtained by encrypting the request message using the first quantum key. User equipment refers to the user-side terminal device, including but not limited to smart terminals such as mobile phones and computers, and also smart wearable devices such as smart bracelets and smartwatches. The request message is the communication message that the user equipment needs to send to the core network.
[0113] Optionally, in this embodiment, the user equipment needs to obtain a first quantum key in advance. Specifically, the user equipment can obtain or pre-charge a quantum key in real time through a QKD (Quantum Key Distribution) network; which includes at least the first quantum key.
[0114] Optionally, in this embodiment, the user equipment generates the first message in the following ways: HMAC processing is performed on the request message based on the first quantum key to obtain a first message authentication code; the first message is generated based on the first encrypted message, the first message authentication code, and the first key identifier of the first quantum key. Here, HMAC processing refers to the process of processing the request message using the HMAC (Hash-based Message Authentication Code) algorithm to obtain the first message authentication code. In this embodiment, one optional method for generating the first message based on the first encrypted message, the first message authentication code, and the first key identifier of the first quantum key is to add the first message authentication code and the first key identifier of the first quantum key to the first encrypted message to obtain the first message. Another optional method for generating the first message based on the first encrypted message, the first message authentication code, and the first key identifier of the first quantum key is to add the first key identifier of the first quantum key to the first encrypted message to obtain the first message.
[0115] S202, based on the first message, determine the operational availability of the S&F operation.
[0116] S&F (Store and Forward Satellite Operation) refers to the operation of performing the satellite's storage and forwarding functions.
[0117] As an optional implementation of this application, based on the first message, the message truth status of the first message is determined; and based on the message truth status, the operational availability status of the S&F operation is determined. For example, if the message truth status is true, the operational availability status of the S&F operation is determined to be operational availability.
[0118] As another optional implementation of this application, based on the first message, the service subscription information of the user equipment is obtained. If the user equipment has subscribed to the relevant services for S&F operation, the operation availability status of S&F operation is determined to be available.
[0119] Another optional implementation of this application involves determining the availability of the feeder line between the satellite and the core network. If the feeder line is unavailable, the operational availability of the S&F operation is determined based on a first message. In other words, this application is primarily applicable when the feeder line between the satellite and the core network is unavailable. This is because when the feeder line is available, the core network can establish a security context with the user equipment. In this case, even if communication is conducted via satellite, DOS attacks can be effectively avoided. Therefore, this application is mainly applied when the feeder line is unavailable.
[0120] S203, if the operational availability condition is available, send the second message to the core network based on the first encrypted message in the first message.
[0121] As an optional implementation of this application, when the operational availability condition is met, the first encrypted message in the first message is used as the second message; the second message is sent to the core network. The second message also carries a first key identifier of the first quantum key, so that the core network can obtain the first quantum key based on the first key identifier, and then decrypt the first encrypted message to obtain the request message.
[0122] As another optional implementation of this application, when the operational availability condition is met, the first encrypted message in the first message is decrypted based on the first quantum key to obtain the request message, and the request message is sent to the core network as the second message. It should be noted that the satellite can also perform conventional processing on the request message (e.g., format conversion, signal amplification, etc.), and then send the processed request message as the second message to the core network.
[0123] Based on the above embodiments, another optional implementation of this application is to send a second message to the core network based on the first encrypted message in the first message when the feeder line becomes available. This is because satellite S&F operations are primarily performed when the feeder line is unavailable; the second message can only be sent to the core network when the feeder line becomes available.
[0124] The aforementioned communication method involves receiving a first message sent by a user equipment (UE). This first message is generated by the UE based on a first encrypted message, a request message, and a first quantum key. The first encrypted message is obtained by encrypting the request message using the first quantum key. Based on the first message, the operational availability of the S&F operation is determined. If the operational availability is deemed acceptable, a second message is sent to the core network based on the first encrypted message within the first message. This application encrypts the request message using the first quantum key, enhancing its security. Furthermore, after receiving the first message, the satellite can also determine the operational availability of the S&F operation based on it. Only if the first message meets the requirements is the operational availability deemed acceptable, thus enabling the second message to be sent to the core network based on the S&F operation and the first encrypted message within the first message, further enhancing communication security.
[0125] Based on the above embodiments, in order to further improve communication security and the accuracy of the determined S&F operation availability, as shown in Figure 3, an optional implementation of S202 includes:
[0126] S301, based on the first message, obtain the first key identifier, the first encrypted message, and the first message authentication code.
[0127] Optionally, in this embodiment, the first message is parsed to obtain a first key identifier, a first encrypted message, and a first message authentication code.
[0128] S302, based on the first key identifier, obtain the first quantum key.
[0129] Optionally, in this embodiment, the first quantum key is obtained from locally stored candidate quantum keys based on the first key identifier; each candidate quantum key has a corresponding key identifier. It should be noted that the candidate quantum keys are synchronized to the satellite by the core network.
[0130] S303, based on the first quantum key, the first encrypted message, and the first message authentication code, determines the operational availability of the S&F operation.
[0131] Optionally, in this embodiment, the first encrypted message is decrypted using the first quantum key to obtain a first decrypted message. The first decrypted message is then subjected to HMAC processing using the first quantum key to obtain a second message authentication code. Based on the first and second message authentication codes, the operational availability of the S&F operation is determined. One optional implementation of determining the operational availability of the S&F operation based on the first and second message authentication codes in this embodiment is to determine the true message information of the first message based on the first and second message authentication codes; and then determine the operational availability of the S&F operation based on the true message information of the first message. Another optional implementation of determining the true message information of the first message based on the first and second message authentication codes in this embodiment is to determine if the first and second message authentication codes are consistent. If they are consistent, the true message information of the first message is determined to be true, meaning the first message has not been maliciously tampered with. If they are inconsistent, the true message information of the first message is determined to be false, meaning the first message has been maliciously tampered with or attacked. In this embodiment, an optional implementation for determining the availability of the S&F operation based on the true nature of the first message is as follows: if the true nature of the message is true, the S&F operation is available; if the true nature of the message is false, the S&F operation is unavailable. It should be noted that if the S&F operation is unavailable, the first encrypted message can be discarded.
[0132] Optionally, in this embodiment, after determining the operational availability of the S&F operation based on the first quantum key, the first encrypted message, and the first message authentication code, one possible implementation of the communication method is as follows: Based on the operational availability of the S&F operation, determine the service result. Encrypt the service result based on the second quantum key to obtain an S&F operation service response message. Send the S&F operation service response message to the user equipment; wherein the S&F operation service response message carries a second key identifier of the second quantum key. This allows the user equipment to obtain the second quantum key based on the second key identifier. Decrypt the S&F operation service response message based on the second quantum key to obtain the service result. The service result refers to whether the S&F service is available or unavailable, used to inform the user equipment. It should be noted that the second quantum key can be the same quantum key as the first quantum key, or it can be a different quantum key.
[0133] In this embodiment, a first key identifier, a first encrypted message, and a first message authentication code are obtained based on a first message. A first quantum key is obtained based on the first key identifier. The first encrypted message is decrypted using the first quantum key to obtain a first decrypted message. HMAC processing is performed on the first decrypted message using the first quantum key to obtain a second message authentication code. The operational availability of the S&F operation is determined based on the first and second message authentication codes. This application can determine the true nature of the first message, i.e., whether the first message is a tampered attack message, based on the consistency between the first and second message authentication codes. Only when the first and second message authentication codes match, i.e., when the true nature of the message is true, is the operational availability of the S&F operation determined to be operational, further improving communication security and preventing satellite attacks.
[0134] In some embodiments, the user equipment needs to complete an authentication process before sending a request message to the satellite, as shown in Figure 4. An optional implementation of a communication method includes:
[0135] S401 receives the initial registration request sent by the user equipment.
[0136] The initial registration request carries the first key identifier of the first quantum key. Initial registration refers to the registration request message sent to the satellite by the user equipment when it has communication needs. This message contains the authentication information required for user equipment registration and authentication; the initial registration request also needs to carry the user equipment's SUCI (Subscription Concealed Identifier). It should be noted that the initial registration request can be an encrypted or unencrypted message; if it is an encrypted message, the initial registration request must also carry the key identifier of the quantum key.
[0137] S402, based on the initial registration request, sends a terminal authentication request carrying the first key identifier to the core network.
[0138] The terminal authentication request instructs the core network to obtain the first quantum key based on the first key identifier and send a terminal authentication request response message carrying the first quantum key and the first key identifier back to the satellite. The terminal authentication request carries the user equipment's SUCI (Supply, Access, and Criteria).
[0139] It should be noted that the core network needs to obtain the first quantum key in advance. Specifically, the core network can obtain or pre-charge quantum keys in real time through the QKD network; these keys must include at least the first quantum key.
[0140] Optionally, in this embodiment, the satellite generates a terminal authentication request based on the initial registration request, and adds the first key identifier to the terminal authentication request.
[0141] Optionally, in this embodiment, the core network generates the terminal authentication request response message by generating an authentication vector based on the user equipment's SUCI, and then generating the terminal authentication request response message based on the authentication vector, adding the first quantum key and the first key identifier to the terminal authentication request response message. It should be noted that the specific process of generating the terminal authentication request response message based on the authentication vector is detailed in the 3GPP standard procedure and will not be repeated here.
[0142] S403, store the first quantum key and the first key identifier, and encrypt the terminal authentication request response message based on the third quantum key to obtain the third encrypted message.
[0143] The third quantum key refers to the quantum key stored in the satellite. The third quantum key can be the same as the first quantum key, or it can be a different quantum key. The third encrypted message refers to the message obtained by encrypting the terminal authentication request response message based on the third quantum key.
[0144] S404, sends a third encrypted message to the user equipment.
[0145] The third encrypted message carries the third key identifier of the third quantum key; the third encrypted message is used to instruct the user equipment to perform terminal authentication operations based on the third encrypted message and the third key identifier.
[0146] Optionally, in this embodiment, the user equipment performs terminal authentication based on the third encrypted message and the third key identifier in the following optional implementation: Based on the third key identifier, obtain the third quantum key; based on the third quantum key, decrypt the terminal authentication request response message and generate a terminal authentication response message based on the decryption result; encrypt the terminal authentication response message based on the fourth quantum key to obtain the fourth encrypted message; perform HMAC processing on the terminal authentication response message based on the fourth quantum key to obtain the third message authentication code; send the fourth encrypted message carrying the key identifier of the third message authentication code and the fourth quantum key to the satellite; wherein, the fourth encrypted message is used to instruct the satellite to determine the authenticity of the message based on the fourth encrypted message, and if the authenticity of the message is true, send the terminal authentication response message to the core network so that the core network completes the authentication process for the user equipment based on the terminal authentication response message. In this embodiment, an optional implementation of the satellite determining the authenticity of the message based on the fourth message authentication code and the third message authentication code carried in the fourth encrypted message is to determine the consistency between the third message authentication code and the fourth message authentication code. If they are consistent, the authenticity of the terminal authentication response message is determined to be true, that is, the terminal authentication response message has not been maliciously tampered with. If there is a discrepancy, it is determined that the actual message of the terminal authentication response message is not genuine. In other words, the terminal authentication response message has been maliciously tampered with or attacked. In the case that the actual message request is not genuine, the tampered terminal authentication response message will be discarded.
[0147] In this embodiment, a second encrypted message sent by a user equipment is received. This second encrypted message is obtained by encrypting an initial registration request based on a first quantum key. The second encrypted message carries a first key identifier of the first quantum key. A terminal authentication request carrying the first key identifier is sent to the core network based on the second encrypted message. This terminal authentication request instructs the core network to obtain the first quantum key based on the first key identifier and send a terminal authentication request response message carrying both the first quantum key and the first key identifier back to the satellite. The first quantum key and the first key identifier are stored, and the terminal authentication request response message is encrypted based on a third quantum key to obtain a third encrypted message. This third encrypted message is then sent to the user equipment. The third encrypted message carries a third key identifier of the third quantum key. The third encrypted message instructs the user equipment to perform a terminal authentication operation based on the third encrypted message and the third key identifier. This embodiment achieves both core network synchronization of the first quantum key to the satellite and ensures the security of user equipment authentication, thereby improving communication security.
[0148] In an optional embodiment, as shown in FIG5, a communication method is provided that can be applied to the user equipment shown in FIG1. In this embodiment, the method includes the following steps:
[0149] S501, when there is a need to send a request message to the core network, the request message is encrypted based on the first quantum key to obtain the first encrypted message.
[0150] Optionally, in this embodiment, when there is a need to send a request message to the core network, the request message is encrypted based on the first quantum key to obtain a first encrypted message.
[0151] Optionally, in this embodiment, when there is a need to send a request message to the core network, sensitive data in the request message is obtained, and the sensitive data in the request message is encrypted using a first quantum key to obtain a first encrypted message. Sensitive data refers to the data portion in the request message sent by the user equipment to the core network that requires a higher level of protection, such as user identification information, location information, and service request content. If this data is leaked, tampered with, or illegally obtained, it may harm user privacy, communication security, and service integrity; therefore, encryption is necessary.
[0152] S502, based on the first encrypted message, the request message and the first quantum key, generate the first message.
[0153] Optionally, in this embodiment, the request message is processed using HMAC based on the first quantum key to obtain a first message authentication code. A first message is generated based on the first encrypted message, the first message authentication code, and the first key identifier of the first quantum key.
[0154] Optionally, in this embodiment, one possible implementation of generating the first message based on the first encrypted message, the first message authentication code, and the first key identifier of the first quantum key is to add the first message authentication code and the first key identifier of the first quantum key to the first encrypted message to obtain the first message.
[0155] In this embodiment, another optional implementation for generating the first message based on the first encrypted message, the first message authentication code, and the first key identifier of the first quantum key is to add the first key identifier of the first quantum key to the first encrypted message to obtain the first message.
[0156] S503 sends the first message to the satellite.
[0157] The first message is used to instruct the satellite to determine the operational availability of S&F operations, and if the operational availability is available, to send a second message to the core network based on the first encrypted message in the first message.
[0158] Optionally, in this embodiment, one possible implementation of the satellite determining the operational availability of the S&F operation based on the first message is as follows: the first message specifically instructs the satellite to obtain a first quantum key based on a first key identifier, and to determine the operational availability of the S&F operation based on the first quantum key, the first encrypted message, and the first message authentication code. Specifically, the first message instructs the satellite to decrypt the first encrypted message using the first quantum key to obtain a first decrypted message, to perform HMAC processing on the first decrypted message using the first quantum key to obtain a second message authentication code, and to determine the operational availability of the S&F operation based on the first message verification code and the second message verification code. Another possible implementation of determining the operational availability of the S&F operation based on the first message verification code and the second message verification code is as follows: based on the first message authentication code and the second message authentication code, the true message status of the first message is determined; based on the true message status of the first message, the operational availability of the S&F operation is determined. Yet another possible implementation of determining the true message status of the first message based on the first message authentication code and the second message authentication code is as follows: the first message authentication code and the second message authentication code are determined to be consistent; if they are consistent, the true message status of the first message is determined to be genuine, meaning that the first message has not been maliciously tampered with. If there is a discrepancy, the message authenticity of the first message is determined to be false, meaning the first message has been maliciously altered or attacked. In this embodiment, the possible practical method for determining the availability of the S&F operation based on the message authenticity of the first message is as follows: if the message authenticity is true, the S&F operation is available; if the message authenticity is false, the S&F operation is unavailable. It should be noted that if the S&F operation is unavailable, the first encrypted message can be discarded.
[0159] Optionally, in this embodiment, another possible implementation for the satellite to determine the operational availability of the S&F operation based on the first message is to obtain the user equipment's service subscription information based on the first message. If the user equipment has subscribed to the relevant services for the S&F operation, the operational availability of the S&F operation is determined to be operational.
[0160] Optionally, in this embodiment, another possible implementation of the satellite determining the operational availability of S&F operations based on the first message is to determine the availability of the feeder line between the satellite and the core network. If the feeder line is unavailable, the operational availability of S&F operations is determined based on the first message. In other words, this application is mainly applicable to situations where the feeder line between the satellite and the core network is unavailable. This is because when the feeder line is available, the core network can establish a security context with the user equipment. In this case, even if communication is via satellite, it can effectively avoid DoS attacks. Therefore, this application is mainly applied to situations where the feeder line is unavailable.
[0161] Optionally, in this embodiment, when the operational availability condition is available, one possible implementation for sending a second message to the core network based on the first encrypted message in the first message is to use the first encrypted message in the first message as the second message and send the second message to the core network. The second message also carries a first key identifier of the first quantum key, so that the core network can obtain the first quantum key based on the first key identifier, and then decrypt the first encrypted message to obtain the request message.
[0162] Optionally, in this embodiment, when the operational availability condition is available, another possible implementation for sending the second message to the core network based on the first encrypted message in the first message is as follows: when the operational availability condition is available, the first encrypted message in the first message is decrypted based on the first quantum key to obtain a request message, and this request message is sent to the core network as the second message. It should be noted that the satellite can also perform conventional processing on the request message (e.g., format conversion, signal amplification, etc.), and then send the processed request message as the second message to the core network.
[0163] Optionally, in this embodiment, another possible implementation of sending a second message to the core network based on the first encrypted message in the first message when the operation is available is that the second message is sent to the core network based on the first encrypted message in the first message when the power supply line becomes available. This is because satellite S&F operations are primarily performed when the power supply line is unavailable; the second message can only be sent to the core network when the power supply line becomes available.
[0164] In this embodiment, when there is a need to send a request message to the core network, the request message is encrypted using a first quantum key to obtain a first encrypted message. Based on the first encrypted message, the request message, and the first quantum key, a first message is generated. The first message is then sent to the satellite; wherein, the first message instructs the satellite to determine the operational availability of the S&F operation, and if the operational availability is confirmed, a second message is sent to the core network based on the first encrypted message in the first message. This application not only improves the security of the request message, but also allows the satellite, after receiving the first message, to determine the operational availability of the S&F operation based on the first message. Only if the first message meets the requirements is the operational availability confirmed, and thus, based on the S&F operation and the first encrypted message in the first message, the second message is sent to the core network, further enhancing communication security.
[0165] In some embodiments, to notify the user equipment of the service results of S&F operations, as shown in FIG6, an optional implementation of a communication method includes:
[0166] S601 receives S&F operation service response messages sent by the satellite.
[0167] The S&F operation service response message is generated by the satellite based on the availability of S&F operations, determining the service result, and encrypting the result using a second quantum key. The S&F operation service response message also carries a second key identifier for the second quantum key. It should be noted that the second quantum key can be the same as the first quantum key, or it can be a different quantum key. The service result indicates whether the S&F service is available or unavailable, and is used to inform the user equipment.
[0168] S602, based on the second key identifier, obtain the second quantum key.
[0169] Optionally, in this embodiment, the second quantum key is obtained by searching locally or through the QKD network based on the second key identifier.
[0170] S603, based on the second quantum key, decrypts the S&F operation service response message to obtain the service result.
[0171] In this embodiment, an S&F operation service response message sent by a satellite is received. This message is obtained by the satellite determining the service result based on the availability of S&F operations and encrypting the result using a second quantum key. The S&F operation service response message also carries a second key identifier for the second quantum key. Based on the second key identifier, the second quantum key is obtained. Based on the second quantum key, the S&F operation service response message is decrypted to obtain the service result. Based on this embodiment, the user equipment can be notified whether S&F operations are available.
[0172] In some embodiments, before encrypting the request message based on the first quantum key in response to the request message sending request to obtain the first encrypted message, as shown in FIG7, an optional implementation of a communication method includes:
[0173] S701, an initial registration request carrying a first key identifier of a first quantum key is sent to the satellite, so that the satellite sends a terminal authentication request carrying at least the first key identifier to the core network based on the initial registration request. The terminal authentication request instructs the core network to obtain the first quantum key based on the first key identifier and send a terminal authentication request response message carrying both the first quantum key and the first key identifier back to the satellite. The terminal authentication request response message instructs the satellite to store the first quantum key and the first key identifier and to encrypt the terminal authentication request response message based on a third quantum key to obtain a third encrypted message. The terminal authentication request carries the user equipment's SUCI.
[0174] Optionally, in this embodiment, the core network generates the terminal authentication request response message as follows: the core network generates an authentication vector based on the user equipment's SUCI, and then generates the terminal authentication request response message based on the authentication vector. The first quantum key and the first key identifier are added to the terminal authentication request response message. It should be noted that the specific process of the core network generating the authentication vector based on the user equipment's SUCI and generating the terminal authentication request response message based on the authentication vector is detailed in the 3GPP standard process and will not be repeated here.
[0175] S702 receives the third encrypted message sent by the satellite.
[0176] The third encrypted message contains at least a third key identifier for the third quantum key.
[0177] S703 performs terminal authentication based on a third encrypted message and a third key identifier.
[0178] Optionally, in this embodiment, a third quantum key is obtained based on a third key identifier. The terminal authentication request response message is decrypted based on the third quantum key, and a terminal authentication response message is generated based on the decryption result. The terminal authentication response message is encrypted based on a fourth quantum key to obtain a fourth encrypted message. The terminal authentication response message is then subjected to HMAC processing based on the fourth quantum key to obtain a third message authentication code. A fourth encrypted message carrying the third message authentication code and the fourth quantum key identifier is sent to the satellite; wherein, the fourth encrypted message is used to instruct the satellite to determine the authenticity of the message based on the fourth encrypted message, and if the authenticity of the message is true, to send a terminal authentication response message to the core network.
[0179] Optionally, in this embodiment, one possible implementation of the satellite determining the authenticity of the message based on the fourth encrypted message and sending a terminal authentication response message to the core network if the authenticity of the message is true is as follows: The satellite receives the fourth encrypted message and obtains the fourth quantum key based on the fourth key identifier carried in the fourth encrypted message. It then decrypts the fourth encrypted message using the fourth quantum key to obtain a second decrypted message. Next, it performs HMAC processing on the second decrypted message using the fourth quantum key to obtain a fourth message authentication code. Based on the fourth message authentication code and the third message authentication code carried in the fourth encrypted message, the authenticity of the message is determined. If the authenticity of the message is true, the second decrypted message is determined to be a terminal authentication response message, and the satellite sends the terminal authentication response message to the core network. Another possible implementation of the satellite determining the authenticity of the message based on the fourth message authentication code and the third message authentication code carried in the fourth encrypted message is as follows: The satellite determines that the third message authentication code and the fourth message authentication code are consistent. If they are consistent, the authenticity of the terminal authentication response message is determined to be true, meaning that the terminal authentication response message has not been maliciously tampered with. If there is a discrepancy, the authenticity of the terminal authentication response message is determined to be false. In other words, the terminal authentication response message has been maliciously altered or attacked. In cases where the actual request is false, the altered terminal authentication response message will be discarded. It should be noted that the fourth quantum key can be the same as the first quantum key, or it can be a different quantum key.
[0180] In this embodiment, an initial registration request carrying a first key identifier of a first quantum key is sent to the satellite. This causes the satellite to send a terminal authentication request carrying at least the first key identifier to the core network based on the initial registration request. The terminal authentication request instructs the core network to obtain a first quantum key based on the first key identifier and send a response message to the satellite carrying both the first quantum key and the first key identifier. The response message instructs the satellite to store the first quantum key and the first key identifier and to encrypt the response message based on a third quantum key to obtain a third encrypted message. The third encrypted message sent by the satellite is received; the third encrypted message carries at least the third key identifier of the third quantum key. Based on the third encrypted message and the third key identifier, a terminal authentication operation is performed. This not only improves the security of terminal registration and authentication but also achieves synchronization of the first quantum key from the core network to the satellite.
[0181] In some embodiments, as shown in Figures 8 and 9, a communication method is provided, which includes the following steps:
[0182] The user equipment sends an initial registration request to the satellite, carrying a first key identifier containing the first quantum key.
[0183] The satellite sends a terminal authentication request, carrying at least the first key identifier, to the core network based on the initial registration request.
[0184] The core network obtains the first quantum key based on the first key identifier and sends a terminal authentication request response message carrying the first quantum key and the first key identifier back to the satellite.
[0185] The satellite stores the first quantum key and the first key identifier, and encrypts the terminal authentication request response message based on the third quantum key to obtain the third encrypted message.
[0186] The user equipment receives a third encrypted message transmitted by the satellite. This third encrypted message carries at least a third key identifier, which is a third quantum key.
[0187] User equipment obtains the third quantum key based on the third key identifier.
[0188] The user equipment decrypts the terminal authentication request response message based on the third quantum key, and generates a terminal authentication response message based on the decryption result.
[0189] The user equipment encrypts the terminal authentication response message based on the fourth quantum key to obtain the fourth encrypted message.
[0190] The user equipment uses the fourth quantum key to perform HMAC processing on the terminal authentication response message to obtain the third message authentication code.
[0191] The user equipment sends a fourth encrypted message to the satellite, which carries a key identifier containing a third message authentication code and a fourth quantum key.
[0192] The satellite receives the fourth encrypted message and obtains the fourth quantum key based on the fourth key identifier carried in the fourth encrypted message.
[0193] The satellite decrypts the fourth encrypted message using the fourth quantum key to obtain the second decrypted message.
[0194] The satellite performs HMAC processing on the second decryption message based on the fourth quantum key to obtain the fourth message authentication code.
[0195] The satellite determines the authenticity of the message based on the fourth message authentication code and the third message authentication code carried in the fourth encrypted message.
[0196] If the satellite confirms that the message is genuine, it will determine that the second decrypted message is a terminal authentication response message and send the terminal authentication response message to the core network.
[0197] When there is a need to send a request message to the core network, the user equipment encrypts the request message based on the first quantum key to obtain the first encrypted message.
[0198] The user equipment performs HMAC processing on the request message based on the first quantum key to obtain the first message authentication code.
[0199] The user equipment generates a first message based on a first encrypted message, a first message authentication code, and a first key identifier of a first quantum key.
[0200] The user equipment sends the first message to the satellite.
[0201] The satellite determines the availability of the power supply lines between the satellite and the core network.
[0202] When the power supply line is unavailable, the satellite obtains the first key identifier, the first encrypted message, and the first message authentication code based on the first message.
[0203] The satellite obtains the first quantum key based on the first key identifier.
[0204] The satellite decrypts the first encrypted message using the first quantum key to obtain the first decrypted message.
[0205] The satellite performs HMAC processing on the first decrypted message based on the first quantum key to obtain the second message authentication code.
[0206] The satellite determines the operational availability of S&F operations based on the first message authentication code and the second message authentication code.
[0207] When the satellite is operationally available and the power supply line is available, it sends a second message to the core network based on the first encrypted message in the first message.
[0208] This embodiment also includes a service result notification process between the user equipment and the satellite, as detailed below:
[0209] The satellite's operational availability based on S&F operations determines the service outcome.
[0210] The satellite encrypts the service results using the second quantum key to obtain the S&F operation service response message.
[0211] The user equipment receives the S&F operation service response message sent by the satellite. This S&F operation service response message also carries a second key identifier for the second quantum key.
[0212] User equipment obtains the second quantum key based on the second key identifier.
[0213] The user equipment uses the second quantum key to decrypt the S&F operation service response message and obtain the service result.
[0214] In this embodiment, a first message is received from a user equipment. This first message is generated by the user equipment based on a first encrypted message, a request message, and a first quantum key. The first encrypted message is obtained by encrypting the request message using the first quantum key. Based on the first message, the operational availability of the S&F operation is determined. If the operational availability is confirmed, a second message is sent to the core network based on the first encrypted message in the first message. This application encrypts the request message using the first quantum key, improving the security of the request message. Furthermore, after receiving the first message, the satellite can also determine the operational availability of the S&F operation based on the first message. Only if the first message meets the requirements is the operational availability confirmed. Therefore, based on the S&F operation and the first encrypted message in the first message, the second message is sent to the core network, further enhancing communication security.
[0215] It should be understood that although the steps in the flowcharts of the above embodiments are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0216] Based on the same inventive concept, this application also provides a communication device for implementing the communication method described above. The solution provided by this device is similar to the solution described in the above method; therefore, specific limitations in one or more communication device embodiments provided below can be found in the limitations of the communication method described above, and will not be repeated here.
[0217] In one embodiment, as shown in FIG9, a communication device 1 is provided, configured in a satellite, comprising:
[0218] The first receiving module 11 is used to receive a first message sent by the user equipment; wherein the first message is generated by the user equipment based on a first encrypted message, a request message and a first quantum key; the first encrypted message is obtained by encrypting the request message based on the first quantum key;
[0219] The first determining module 12 is used to determine the operational availability of the S&F operation based on the first message;
[0220] The first sending module 13 is used to send a second message to the core network based on the first encrypted message in the first message when the operation is available.
[0221] In some embodiments, the first encrypted message is generated by the user equipment performing HMAC processing on the request message based on the first quantum key to obtain the first message authentication code, and generating a first key identifier based on the first encrypted message, the first message authentication code, and the first quantum key.
[0222] In some embodiments, the first determining module 12 is further specifically used for:
[0223] Based on the first message, obtain the first key identifier, the first encrypted message, and the first message authentication code;
[0224] The first quantum key is obtained based on the first key identifier;
[0225] Based on the first quantum key, the first encrypted message, and the first message authentication code, the operational availability of the S&F operation is determined.
[0226] In some embodiments, the first determining module 12 is further specifically used for:
[0227] The first encrypted message is decrypted using the first quantum key to obtain the first decrypted message;
[0228] The first decryption message is processed by HMAC based on the first quantum key to obtain the second message authentication code;
[0229] Based on the first message authentication code and the second message authentication code, determine the operational availability of the S&F operation.
[0230] In some embodiments, the first determining module 12 is further specifically used for:
[0231] Determine the availability of the power supply lines between the satellite and the core network;
[0232] If the feeder line is unavailable, the availability of the S&F operation is determined based on the first message.
[0233] In some embodiments, the first sending module 13 is further specifically used for:
[0234] When the feeder line becomes available, a second message is sent to the core network based on the first encrypted message in the first message.
[0235] In some embodiments, the communication device 1 in FIG9 above further includes:
[0236] The second receiving module is used to receive the initial registration request sent by the user equipment; wherein the initial registration request carries the first key identifier of the first quantum key;
[0237] The third sending module is used to send a terminal authentication request carrying a first key identifier to the core network based on the initial registration request; wherein, the terminal authentication request is used to instruct the core network to obtain the first quantum key based on the first key identifier, and to send back a terminal authentication request response message carrying the first quantum key and the first key identifier to the satellite;
[0238] The storage module is used to store the first quantum key and the first key identifier, and to encrypt the terminal authentication request response message based on the third quantum key to obtain the third encrypted message;
[0239] The fourth sending module is used to send a third encrypted message to the user equipment; wherein the third encrypted message carries a third key identifier of the third quantum key; the third encrypted message is used to instruct the user equipment to perform terminal authentication operation based on the third encrypted message and the third key identifier.
[0240] In some embodiments, the third encrypted message is specifically used to instruct the user equipment to send a fourth encrypted message to the satellite; wherein, the fourth encrypted message is obtained by the user equipment encrypting the terminal authentication response message based on the fourth quantum key; the fourth encrypted message carries a third message authentication code and a fourth key identifier of the fourth quantum key; the third message authentication code is obtained by the user equipment performing HMAC processing on the terminal authentication response message based on the fourth quantum key; the terminal authentication response message is generated by the user equipment obtaining the third quantum key based on the third key identifier, decrypting the terminal authentication request response message based on the third quantum key, and generating the response message based on the decryption result.
[0241] In some embodiments, the communication device 1 in FIG9 above further includes:
[0242] The third receiving module is used to receive the fourth encrypted message and obtain the fourth quantum key based on the fourth key identifier carried in the fourth encrypted message;
[0243] The second determining module is used to decrypt the fourth encrypted message based on the fourth quantum key to obtain the second decrypted message;
[0244] The third determining module is used to perform HMAC processing on the second decryption message based on the fourth quantum key to obtain the fourth message authentication code.
[0245] The fourth determination module is used to determine the true nature of the message based on the fourth message authentication code and the third message authentication code carried in the fourth encrypted message;
[0246] The fifth determination module is used to determine that the second decrypted message is a terminal authentication response message if the message is true, and then send the terminal authentication response message to the core network.
[0247] In one embodiment, as shown in FIG10, a communication device 2 is provided, configured in a user equipment, including:
[0248] Encryption module 21 is used to encrypt the request message based on the first quantum key when there is a need to send a request message to the core network, so as to obtain the first encrypted message;
[0249] Generation module 22 is used to generate a first message based on the first encrypted message, the request message, and the first quantum key;
[0250] The second sending module 23 is used to send a first message to the satellite; wherein the first message is used to instruct the satellite to determine the operational availability of S&F operations, and if the operational availability is available, to send a second message to the core network based on the first encrypted message in the first message.
[0251] In some embodiments, the generation module 22 is further specifically used for:
[0252] The request message is processed using HMAC based on the first quantum key pair to obtain the first message authentication code;
[0253] The first message is generated based on the first encrypted message, the first message authentication code, and the first key identifier of the first quantum key.
[0254] In some embodiments, the communication device 2 further includes:
[0255] The fourth receiving module is used to receive the S&F operation service response message sent by the satellite; wherein, the S&F operation service response message is obtained by the satellite determining the service result based on the availability of S&F operations, and encrypting the service result based on the second quantum key; the S&F operation service response message also carries the second key identifier of the second quantum key.
[0256] The first acquisition module is used to acquire the second quantum key based on the second key identifier;
[0257] The second acquisition module is used to decrypt the S&F operation service response message based on the second quantum key and obtain the service result.
[0258] In some embodiments, the communication device 2 further includes:
[0259] The fifth transmitting module is used to send an initial registration request carrying a first key identifier of a first quantum key to the satellite, so that the satellite sends a terminal authentication request carrying at least the first key identifier to the core network based on the initial registration request; wherein, the terminal authentication request is used to instruct the core network to obtain the first quantum key based on the first key identifier, and to send back a terminal authentication request response message carrying the first quantum key and the first key identifier to the satellite; the terminal authentication request response message is used to instruct the satellite to store the first quantum key and the first key identifier, and to encrypt the terminal authentication request response message based on the third quantum key to obtain a third encrypted message;
[0260] The fifth receiving module is used to receive the third encrypted message sent by the satellite; wherein the third encrypted message carries at least the third key identifier of the third quantum key;
[0261] The execution module is used to perform terminal authentication operations based on a third encrypted message and a third key identifier.
[0262] In some embodiments, the above-described execution module is further specifically used for:
[0263] Obtain the third quantum key based on the third key identifier;
[0264] Based on the third quantum key, the terminal authentication request response message is decrypted, and a terminal authentication response message is generated based on the decryption result;
[0265] The terminal authentication response message is encrypted using the fourth quantum key to obtain the fourth encrypted message;
[0266] Based on the fourth quantum key, the terminal authentication response message is processed by HMAC to obtain the third message authentication code;
[0267] A fourth encrypted message carrying a key identifier containing a third message authentication code and a fourth quantum key is sent to the satellite; wherein, the fourth encrypted message is used to instruct the satellite to determine the authenticity of the message based on the fourth encrypted message, and if the authenticity of the message is true, to send a terminal authentication response message to the core network.
[0268] Each module in the aforementioned communication device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of the communication device in hardware form or independent of it, or stored in the memory of the communication device in software form, so that the processor can call and execute the operations corresponding to each module.
[0269] In some embodiments, a communication device is provided, which may be a server, and its internal structure diagram may be as shown in Figure 11. The communication device includes a processor, a memory, a network interface, and a transceiver connected via a system bus. The processor of the communication device provides computing and control capabilities. The memory of the communication device includes a non-volatile storage medium and internal memory. The transceiver of the communication device performs operations of receiving or sending data under the control of the processor. The non-volatile storage medium stores an operating system, computer programs, and a database. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The database of the communication device stores information related to communication methods. The network interface of the communication device is used to communicate with external terminals via a network connection. When the computer program is executed by the processor, it implements a communication method.
[0270] Those skilled in the art will understand that the structure shown in Figure 11 is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the communication device to which the present application is applied. Specific communication devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0271] In some embodiments, a communication device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the processing logic in the computer program to perform the following steps:
[0272] The system receives a first message sent by a user equipment; wherein the first message is generated by the user equipment based on a first encrypted message, a request message, and a first quantum key; the first encrypted message is obtained by encrypting the request message based on the first quantum key.
[0273] Based on the first message, determine the operational availability of the S&F operation;
[0274] If the operational availability condition is met, a second message is sent to the core network based on the first encrypted message in the first message.
[0275] In some embodiments, another communication device is provided, including a memory and a processor, wherein the memory stores a computer program and the processor performs the following steps when executing the processing logic in the computer program:
[0276] When there is a need to send a request message to the core network, the request message is encrypted based on the first quantum key to obtain the first encrypted message;
[0277] A first message is generated based on the first encrypted message, the request message, and the first quantum key;
[0278] Send a first message to the satellite; wherein the first message is used to instruct the satellite to determine the operational availability of S&F operations, and if the operational availability is available, send a second message to the core network based on the first encrypted message in the first message.
[0279] In some embodiments, a computer-readable storage medium is provided having a computer program stored thereon, wherein the processing logic in the computer program, when executed by a processor, performs the following steps:
[0280] The system receives a first message sent by a user equipment; wherein the first message is generated by the user equipment based on a first encrypted message, a request message, and a first quantum key; the first encrypted message is obtained by encrypting the request message based on the first quantum key.
[0281] Based on the first message, determine the operational availability of the S&F operation;
[0282] If the operational availability condition is met, a second message is sent to the core network based on the first encrypted message in the first message.
[0283] In some embodiments, another computer-readable storage medium is provided having a computer program stored thereon, the processing logic in the computer program performing the following steps when executed by a processor:
[0284] When there is a need to send a request message to the core network, the request message is encrypted based on the first quantum key to obtain the first encrypted message;
[0285] A first message is generated based on the first encrypted message, the request message, and the first quantum key;
[0286] Send a first message to the satellite; wherein the first message is used to instruct the satellite to determine the operational availability of S&F operations, and if the operational availability is available, send a second message to the core network based on the first encrypted message in the first message.
[0287] In some embodiments, a computer program product is provided, on which a computer program is stored, wherein the processing logic in the computer program, when executed by a processor, performs the following steps:
[0288] The system receives a first message sent by a user equipment; wherein the first message is generated by the user equipment based on a first encrypted message, a request message, and a first quantum key; the first encrypted message is obtained by encrypting the request message based on the first quantum key.
[0289] Based on the first message, determine the operational availability of the S&F operation;
[0290] If the operational availability condition is met, a second message is sent to the core network based on the first encrypted message in the first message.
[0291] In some embodiments, another computer program product is provided, on which a computer program is stored, the processing logic in the computer program performing the following steps when executed by a processor:
[0292] When there is a need to send a request message to the core network, the request message is encrypted based on the first quantum key to obtain the first encrypted message;
[0293] A first message is generated based on the first encrypted message, the request message, and the first quantum key;
[0294] Send a first message to the satellite; wherein the first message is used to instruct the satellite to determine the operational availability of S&F operations, and if the operational availability is available, send a second message to the core network based on the first encrypted message in the first message.
[0295] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.
[0296] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0297] The above embodiments are merely illustrative of several implementation methods of this application, and their descriptions are relatively specific and detailed. However, they should not be construed as limiting the scope of this application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A communication method applied to a satellite, comprising: The user equipment receives a first message sent by a user equipment; wherein the first message is generated by the user equipment based on a first encrypted message, a request message, and a first quantum key; the first encrypted message is obtained by encrypting the request message based on the first quantum key. Based on the first message, determine the operational availability of the Store & Forward (S&F) function; and If the operation is available, a second message is sent to the core network based on the first encrypted message in the first message.
2. The method according to claim 1, wherein, The first encrypted message is generated by the user equipment performing HMAC-based message authentication code processing on the request message based on the first quantum key to obtain a first message authentication code, and generating a first key identifier based on the first encrypted message, the first message authentication code, and the first quantum key.
3. The method according to claim 2, wherein, The step of determining the operational availability of the Store & Forward (S&F) function based on the first message includes: Based on the first message, obtain the first key identifier, the first encrypted message, and the first message authentication code; Based on the first key identifier, obtain the first quantum key; and Based on the first quantum key, the first encrypted message, and the first message authentication code, the operational availability of the S&F operation is determined.
4. The method according to claim 3, wherein, The determination of the operational availability of the S&F operation based on the first quantum key, the first encrypted message, and the first message authentication code includes: The first encrypted message is decrypted based on the first quantum key to obtain the first decrypted message; Based on the first quantum key, the first decrypted message is processed using HMAC to obtain the second message authentication code; and Based on the first message authentication code and the second message authentication code, the operational availability of the S&F operation is determined.
5. The method according to claim 1, wherein, The step of determining the operational availability of the Store & Forward (S&F) function based on the first message includes: Determine the availability of the feeder lines between the satellite and the core network; and If the power supply line is unavailable, the availability of S&F operations is determined based on the first message.
6. The method according to claim 5, wherein, The step of sending a second message to the core network based on the first encrypted message in the first message includes: When the power supply line becomes available, a second message is sent to the core network based on the first encrypted message in the first message.
7. The method according to claim 1, wherein, The method further includes: Receive an initial registration request sent by the user equipment; wherein the initial registration request carries a first key identifier of the first quantum key; Based on the initial registration request, a terminal authentication request carrying the first key identifier is sent to the core network; wherein, the terminal authentication request is used to instruct the core network to obtain the first quantum key based on the first key identifier, and to send back a terminal authentication request response message carrying the first quantum key and the first key identifier to the satellite; The first quantum key and the first key identifier are stored, and the terminal authentication request response message is encrypted based on the third quantum key to obtain a third encrypted message; and The third encrypted message is sent to the user equipment; wherein the third encrypted message carries a third key identifier of the third quantum key; the third encrypted message is used to instruct the user equipment to perform a terminal authentication operation based on the third encrypted message and the third key identifier.
8. The method according to claim 7, wherein, The third encrypted message is specifically used to instruct the user equipment to send a fourth encrypted message to the satellite; wherein, the fourth encrypted message is obtained by the user equipment encrypting the terminal authentication response message based on the fourth quantum key; the fourth encrypted message carries a third message authentication code and a fourth key identifier of the fourth quantum key; the third message authentication code is obtained by the user equipment performing HMAC processing on the terminal authentication response message based on the fourth quantum key; the terminal authentication response message is generated by the user equipment obtaining the third quantum key based on the third key identifier, decrypting the terminal authentication request response message based on the third quantum key, and generating the response message based on the decryption result.
9. The method according to claim 8, wherein, The method further includes: Receive the fourth encrypted message, and obtain the fourth quantum key based on the fourth key identifier carried in the fourth encrypted message; The fourth encrypted message is decrypted based on the fourth quantum key to obtain the second decrypted message; Based on the fourth quantum key, the second decrypted message is processed by HMAC to obtain the fourth message authentication code; Based on the fourth message authentication code and the third message authentication code carried in the fourth encrypted message, the true nature of the message is determined; and If the message is genuine, the second decrypted message is determined to be a terminal authentication response message, and the terminal authentication response message is sent to the core network.
10. A communication method applied to a user equipment, comprising: When there is a need to send a request message to the core network, the request message is encrypted based on the first quantum key to obtain the first encrypted message; A first message is generated based on the first encrypted message, the request message, and the first quantum key; as well as The first message is sent to the satellite; wherein the first message is used to instruct the satellite to determine the operational availability of S&F operations, and if the operational availability is available, the second message is sent to the core network based on the first encrypted message in the first message.
11. The method according to claim 10, wherein, The step of generating the first message based on the first encrypted message, the request message, and the first quantum key includes: Based on the first quantum key, the request message is processed using HMAC to obtain the first message authentication code; and The first message is generated based on the first encrypted message, the first message authentication code, and the first key identifier of the first quantum key.
12. The method according to claim 10, wherein, The method further includes: The system receives an S&F operation service response message sent by the satellite; wherein the S&F operation service response message is obtained by the satellite determining the service result based on the availability of the S&F operation and encrypting the service result based on the second quantum key; the S&F operation service response message also carries a second key identifier of the second quantum key. Based on the second key identifier, obtain the second quantum key; and Based on the second quantum key, the S&F operation service response message is decrypted to obtain the service result.
13. The method according to claim 10, wherein, Before encrypting the request message based on the first quantum key in response to the request message sending request to obtain the first encrypted message, the method further includes: The initial registration request, carrying a first key identifier of the first quantum key, is sent to the satellite, so that the satellite sends a terminal authentication request, carrying at least the first key identifier, to the core network based on the initial registration request; wherein, the terminal authentication request is used to instruct the core network to obtain the first quantum key based on the first key identifier, and to send back a terminal authentication request response message carrying the first quantum key and the first key identifier to the satellite; the terminal authentication request response message is used to instruct the satellite to store the first quantum key and the first key identifier, and to encrypt the terminal authentication request response message based on a third quantum key to obtain a third encrypted message; Receive a third encrypted message sent by the satellite; wherein the third encrypted message carries at least a third key identifier of the third quantum key; and Based on the third encrypted message and the third key identifier, perform terminal authentication.
14. The method according to claim 13, wherein, The terminal authentication operation based on the third encrypted message and the third key identifier includes: Based on the aforementioned third key identifier, obtain the third quantum key; Based on the third quantum key, the terminal authentication request response message is decrypted, and a terminal authentication response message is generated based on the decryption result; The terminal authentication response message is encrypted using the fourth quantum key to obtain the fourth encrypted message; Based on the fourth quantum key, the terminal authentication response message is processed using HMAC to obtain the third message authentication code; and A fourth encrypted message carrying a key identifier containing the third message authentication code and the fourth quantum key is sent to the satellite; wherein, the fourth encrypted message is used to instruct the satellite to determine the authenticity of the message based on the fourth encrypted message, and if the authenticity of the message is true, to send the terminal authentication response message to the core network.
15. A communication device, configured in a satellite, comprising: A first receiving module is configured to receive a first message sent by a user equipment; wherein the first message is generated by the user equipment based on a first encrypted message, a request message, and a first quantum key; the first encrypted message is obtained by encrypting the request message based on the first quantum key; The first determining module is configured to determine the operational availability of the Store & Forward (S&F) function based on the first message; and The first sending module is configured to send a second message to the core network based on the first encrypted message in the first message, provided that the operation is available.
16. A communication device, configured in a user equipment, comprising: An encryption module is used to encrypt a request message based on a first quantum key to obtain a first encrypted message when there is a need to send a request message to the core network. A generation module is configured to generate a first message based on the first encrypted message, the request message, and the first quantum key; as well as The second sending module is used to send the first message to the satellite; wherein the first message is used to instruct the satellite to determine the operational availability of S&F operations, and if the operational availability is available, to send a second message to the core network based on the first encrypted message in the first message.
17. A communication device, comprising a memory, a transceiver, and a processor, wherein the memory stores a computer program, wherein... The transceiver is used to receive or send data under the control of the processor, and the processor, when executing the computer program, implements the steps of the method according to any one of claims 1-14.
18. A computer-readable storage medium having a computer program stored thereon, wherein, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1-14.
19. A computer program product comprising a computer program, wherein, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1-14.