Store-and-Forward Satellite Authentication for Intermittent Connectivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing 5G authentication flow is not suitable for store and forward satellite operations due to the requirement of continuous connectivity, which is not guaranteed in intermittent satellite connectivity scenarios, necessitating an alternative authentication method for delay-tolerant/non-real-time IoT satellite services.

Innovation Solution

A method for mutual authentication between a UE and a serving satellite in a store and forward operation, involving the UE sending a registration request with a certificate, checking its validity, and performing a primary authentication procedure using a subscriber key, followed by secure data transmission and forwarding to the core network when connectivity is restored.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the existing 5G authentication flow is used, then continuous connectivity between UE and core network is required, but this is not guaranteed in store and forward satellite operations with intermittent connectivity

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidconnectivity adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by performing authentication and key establishment during periods when the satellite is connected to the ground network, storing the authenticated state and security context in advance. This allows the UE to be authenticated before intermittent connectivity occurs, and the stored authentication state enables subsequent data transmission without requiring continuous real-time authentication. The UDM/AUSF/ARPF or HSS/AuC stores the UE certificate and establishes security contexts beforehand, so when the satellite becomes available, data can be transmitted using the pre-established authentication state.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If store and forward operation is implemented for intermittent connectivity, then delay-tolerant communication is enabled, but real-time communication requirements are not met

Engineering Contradiction:
Improveconnectivity adaptabilityVSAvoidcommunication speed
Core Design Contradiction:
Adaptability or versatilityVSSpeed

Solution Approach 1:

The patent applies dynamics by making the communication system adaptable to varying connectivity conditions. The network dynamically switches between real-time communication mode (when satellite is continuously connected) and store-and-forward mode (during intermittent connectivity). The system dynamically manages data buffering, authentication state validity periods, and resource allocation based on current connectivity status. This dynamic behavior allows the same system to serve both real-time and delay-tolerant applications depending on satellite availability.

Inventive Principle:
Principle #15Dynamics

3Reliability

If certificate-based authentication is used in store and forward operation, then security is maintained during intermittent connectivity, but additional authentication management complexity is introduced

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidauthentication management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces the UDM/AUSF/ARPF or HSS/AuC as an intermediary that manages certificate-based authentication during store-and-forward operations. This intermediary entity stores UE certificates, validates them when needed, and manages the authentication state across intermittent connectivity periods. By centralizing authentication management in this intermediary network function, the complexity of certificate management is consolidated in the network rather than distributed across multiple UE and satellite units, simplifying overall system complexity while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4607852A1A store and forward satellite method for providing by a serving satellite a communication service to a ue
Publication Date: 2025.08.27 THALES DIS FRANCE SA
  • EP4607852A1 patent drawingFigure 1
  • EP4607852A1 patent drawingFigure 2
  • EP4607852A1 patent drawing

AI summary

The invention concerns a Store and Forward satellite 22 method for providing by a serving satellite 22 a communication service to a UE 10 which the serving satellite 22 is connected to the ground network intermittently and temporarily via a feeder link or ISL, the UE 10 comprising a secure element and provisioned by a home MNO 11 with PKI key pair and associated UE 10 certificate, the method comprising: a) sending from the UE 10 to the serving satellite 22 a registration request message comprising the UE 10 certificate, the serving satellite 22 comprising an UDM/AUSF/ARPF or a HSS/AuC 23 of a serving satcom MNO 22; b) checking at the UDM/AUSF/ARPF or the HSS/AuC 23 the validity of the UE 10 certificate and, if the UE 10 certificate is valid: c) - sending from the UDM/AUSF/ARPF or HSS/AuC 23 to the UE 10 in a protected way a subscriber identity, a subscriber key associated to the serving satcom MNO, and a certificate of the serving satellite 22; d) - performing a primary authentication procedure between the UE 10 and the UDM/AUSF/ARPF according to TS 33.501 or the HSS/AuC TS 33.401 with the primary authentication procedure being based on the subscriber key; e) - sending from the UE 10 to a Store and Forward entity 31 of the satellite 22 user plane data protected in confidentiality and/or integrity by session keys derived during the primary authentication procedure; f) and, when the serving satellite 22 is connected to the ground network via the feeder link or ISL: g) - sending from the Store and Forward entity 31 to the core network of the satcom MNO the user plane data; h) - sending from the core network of the satcom MNO to an application server 40 the user plane data.