WO2023083346A1 - 卫星通信系统、方法、装置、接收方网元及存储介质 - Google Patents

卫星通信系统、方法、装置、接收方网元及存储介质 Download PDF

Info

Publication number
WO2023083346A1
WO2023083346A1 PCT/CN2022/131721 CN2022131721W WO2023083346A1 WO 2023083346 A1 WO2023083346 A1 WO 2023083346A1 CN 2022131721 W CN2022131721 W CN 2022131721W WO 2023083346 A1 WO2023083346 A1 WO 2023083346A1
Authority
WO
WIPO (PCT)
Prior art keywords
security
data packet
network element
satellite
processing
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2022/131721
Other languages
English (en)
French (fr)
Inventor
周巍
徐晖
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Datang Mobile Communications Equipment Co Ltd
Original Assignee
Datang Mobile Communications Equipment Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Datang Mobile Communications Equipment Co Ltd filed Critical Datang Mobile Communications Equipment Co Ltd
Publication of WO2023083346A1 publication Critical patent/WO2023083346A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/03Protecting confidentiality, e.g. by encryption
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/10Integrity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/10Integrity
    • H04W12/106Packet or message integrity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/30Security of mobile devices; Security of mobile applications
    • H04W12/37Managing security policies for mobile devices or for controlling mobile applications

Definitions

  • the present disclosure relates to the field of communication technologies, and in particular to a satellite communication system, method, device, receiving network element and storage medium.
  • the user plane function User Plane Function
  • UPF User Plane Function
  • the core network performs confidentiality and integrity protection on all user data
  • no intervention or configuration of the core network is required. Therefore, the current session management function (SMF) to the base station does not include the security policy between the base station and the UPF, and the SMF does not issue any security policy to the UPF, and the UPF does not process any protocol data unit (Protocol Data Unit, PDU ) session security-related content.
  • the security policy issued by the Session Management Function (SMF) to the base station does not include the security policy between the base station and the UPF, and the SMF does not issue any security policy to the UPF, and the UPF does not process any protocol data unit (Protocol Data Unit, PDU ) session security-related content.
  • PDU Protocol Data Unit
  • the satellite communication system determines that the data communication in the bearer network must be divided into two segments: inter-satellite communication and satellite-ground communication. If the traditional security mechanism is directly applied, the encryption method of the destination satellite to the information is unknown, the information cannot be decrypted to obtain the routing information, and the address of the next hop cannot be determined; if the communication parties negotiate the encryption method of the information, the complex Communication resources are high during the key negotiation process, and satellite communication management is complex.
  • Embodiments of the present disclosure provide a satellite communication system, method, device, receiver network element, and storage medium to solve the defects of high communication resources and complex satellite communication management in the prior art, and reduce the cost of security-related negotiations. The complexity of satellite communication management is reduced.
  • an embodiment of the present disclosure provides a satellite communication system, including:
  • the first security module is configured to receive the first data packet sent by the sending network element and the security policy of the satellite bearer network, and perform the security policy on the first data packet based on the security policy of the satellite bearer network.
  • First security processing generating a second data packet, the data packet structure of the second data packet includes a security field, and sending the second data packet to the sending network element;
  • the second security module is configured to receive the second data packet sent by the receiver network element, obtain the security policy of the satellite bearer network, and perform security checks on the second packet based on the security policy of the satellite bearer network. performing second security processing on the data packet to obtain a third data packet, the third data packet including the data of the first data packet, and sending the third data packet to the receiving network element;
  • the sending network element is configured to generate the first data packet and receive the security policy of the satellite bearer network sent by the session management function SMF, and combine the first data packet and the security policy of the satellite bearer network sending to the first security module to obtain the second data packet, and sending the second data packet to the receiving network element through the satellite bearer network;
  • the receiver network element is configured to receive the second data packet sent by the sender network element through the satellite bearer network, obtain the security policy of the satellite bearer network, and transmit the second data packet and the security policy of the satellite bearer network are sent to the second security module to obtain the third data packet.
  • the first security processing includes at least one of the following: confidentiality protection processing and integrity protection processing
  • the second security processing includes at least one of the following: decryption processing and integrity protection verification processing.
  • the security policy of the satellite bearer network includes at least one of the following:
  • Data security policy information where the data security policy information is used to indicate the type of security protection processing included in the first security processing, where the type of security protection processing includes the confidentiality protection processing and/or the integrity protection processing ;
  • the algorithm information is used to indicate the algorithm for implementing the confidentiality protection process and/or the algorithm for implementing the integrity protection process;
  • Key information where the key information is used to indicate a key for implementing the confidentiality protection process and/or a key for implementing the integrity protection process.
  • the first security module is specifically configured to: receive the first data packet sent by the sending network element and the security policy of the satellite bearer network, and based on the The data security policy information in the security policy of the satellite bearer network, determine the security protection processing type, and based on the algorithm corresponding to the security protection processing type in the algorithm information, and the key information and The key corresponding to the security protection processing type implements the first security processing on the first data packet, generates the second data packet, and sends the second data packet to the sending network element.
  • the second security module is specifically configured to: receive the second data packet sent by the receiver network element, based on the security policy of the satellite bearer network In the data security policy information, determine the type of security protection processing, and based on the algorithm corresponding to the type of security protection processing in the algorithm information, and the corresponding type of security protection processing in the key information key, implement second security processing on the second data packet, obtain the third data packet, and send the third data packet to the receiving network element.
  • the sending network element is a satellite base station S-gNB
  • the receiving network element is a user plane function UPF
  • the first security module is an on-board security module.
  • a function module, the second safety module is a ground station safety function module; or
  • Both the sending network element and the receiving network element are satellite base stations S-gNB, and both the first security module and the second security module are satellite-borne security function modules; or
  • the sending network element is a user plane function UPF
  • the receiving network element is a satellite base station S-gNB
  • the first security module is a ground station security function module
  • the second security module is an onboard security function module .
  • the data packet structure of the first data packet includes a GTP-U part and a security field part
  • the GTP-U part includes a destination network element IP address part
  • the source Network element IP address part UDP port part
  • GTP-U Header part destination IP address part
  • source IP address part source IP address part and Payload part.
  • the protocol layer for processing the second data packet is the security layer in the data transmission protocol stack of the satellite bearer network, and the security layer is between the GTP-U layer and the PDU Layer. between layers.
  • the first security module is specifically used for at least one of the following:
  • security protection processing type includes the confidentiality protection processing, perform confidentiality on the destination IP address part, the source IP address part and the Payload part in the data packet structure of the first data packet Protection processing, obtaining ciphertext;
  • the security protection processing type includes the integrity protection processing, the IP address part of the destination network element, the IP address part of the source network element, the UDP The port part, the GTP-U Header part, the security field part, the destination IP address part, the source IP address part and the Payload part perform integrity protection processing;
  • the destination IP address part, the source IP address part and the The Payload part performs confidentiality protection processing to obtain ciphertext.
  • confidentiality protection processing for the destination network element IP address part in the data packet structure of the first data packet, the source network element IP address part, the UDP port part, the GTP-U Header part, the security field part, and the ciphertext are integrity protected.
  • the second security module is specifically used for at least one of the following:
  • the security protection processing type includes the confidentiality protection processing, then decrypt the ciphertext in the data packet structure of the second data packet to obtain the destination IP address part, the source IP address part and the Payload section;
  • security protection processing type includes the integrity protection processing, the destination network element IP address part, the source network element IP address part, the UDP port part, and all The GTP-U Header part, the security field part, the destination IP address part, the source IP address part and the Payload part carry out integrity protection verification processing;
  • the security protection processing type includes the confidentiality protection processing and the integrity protection processing
  • the destination network element IP address part, the source network element IP address part, and the source network element IP address part in the data packet structure of the second data packet The UDP port part, the GTP-U Header part, the security field part, and the ciphertext are subjected to integrity protection verification processing, and after the integrity protection verification processing, the ciphertext is decrypted to obtain The destination IP address part, the source IP address part and the Payload part.
  • the security field in the second data packet includes the security policy of the satellite bearer network, and the security policy of the satellite bearer network obtained by the receiving network element The policy is carried in the second data packet and sent by the sending network element to the receiving network element.
  • the SMF is configured to send the security policy of the satellite bearer network to the sending network element.
  • the security policy of the satellite bearer network obtained by the second security module is obtained from a security field in the second data packet.
  • the security policy of the satellite bearer network acquired by the receiving network element is sent by the SMF to the receiving network element.
  • the SMF is configured to send the security policy of the satellite bearer network to the sending network element and the receiving network element.
  • the security policy of the satellite bearer network acquired by the second security module is acquired from the receiver network element.
  • the receiving network element is further configured to: after acquiring the security policy of the satellite bearer network, send the satellite The security policy of the bearer network.
  • the security policy of the satellite bearer network is acquired by the SMF from a security management entity, and the security management entity includes a unified data management function UDM.
  • an embodiment of the present disclosure provides a secure transmission method, which is applied to a receiving network element, and the method includes:
  • the data packet structure of the second data packet includes a security field
  • the second data packet is a satellite provided by the first data packet based on the SMF
  • the security policy of the bearer network is obtained after the first security processing
  • the sending network element and the receiving network element communicate through the satellite bearer network.
  • the first security processing includes at least one of the following: confidentiality protection processing and integrity protection processing
  • the second security processing includes at least one of the following: decryption processing and integrity protection verification processing.
  • the security policy of the satellite bearer network includes at least one of the following:
  • Data security policy information where the data security policy information is used to indicate the type of security protection processing included in the first security processing, where the type of security protection processing includes the confidentiality protection processing and/or the integrity protection processing ;
  • the algorithm information is used to indicate the algorithm for implementing the confidentiality protection process and/or the algorithm for implementing the integrity protection process;
  • Key information where the key information is used to indicate a key for implementing the confidentiality protection process and/or a key for implementing the integrity protection process.
  • the sending network element is a satellite base station S-gNB
  • the receiving network element is a user plane function UPF
  • the first security module is an on-board security module.
  • a function module, the second safety module is a ground station safety function module; or
  • Both the sending network element and the receiving network element are satellite base stations S-gNB, and both the first security module and the second security module are satellite-borne security function modules; or
  • the sending network element is a user plane function UPF
  • the receiving network element is a satellite base station S-gNB
  • the first security module is a ground station security function module
  • the second security module is an onboard security function module .
  • the security field in the second data packet includes the security policy of the satellite bearer network.
  • the method further includes:
  • the method before acquiring the third data packet, the method further includes:
  • an embodiment of the present disclosure provides a receiver network element, including a memory, a transceiver, and a processor:
  • the memory is used to store computer programs; the transceiver is used to send and receive data under the control of the processor; the processor is used to read the computer programs in the memory and perform the following operations:
  • the data packet structure of the second data packet includes a security field
  • the second data packet is a satellite provided by the first data packet based on the SMF
  • the security policy of the bearer network is obtained after the first security processing
  • the sending network element and the receiving network element communicate through the satellite bearer network.
  • the first security processing includes at least one of the following: confidentiality protection processing and integrity protection processing
  • the second security processing includes at least one of the following: Decryption processing and integrity protection verification processing.
  • the security policy of the satellite bearer network includes at least one of the following:
  • Data security policy information where the data security policy information is used to indicate the type of security protection processing included in the first security processing, where the type of security protection processing includes the confidentiality protection processing and/or the integrity protection processing ;
  • the algorithm information is used to indicate the algorithm for implementing the confidentiality protection process and/or the algorithm for implementing the integrity protection process;
  • Key information where the key information is used to indicate a key for implementing the confidentiality protection process and/or a key for implementing the integrity protection process.
  • the sender network element is a satellite base station S-gNB
  • the receiver network element is a user plane function UPF
  • the first security module is an on-board A safety function module
  • the second safety module is a ground station safety function module
  • Both the sending network element and the receiving network element are satellite base stations S-gNB, and both the first security module and the second security module are satellite-borne security function modules; or
  • the sending network element is a user plane function UPF
  • the receiving network element is a satellite base station S-gNB
  • the first security module is a ground station security function module
  • the second security module is an onboard security function module .
  • the security field in the second data packet includes the security policy of the satellite bearer network.
  • the operations further include:
  • the operation before acquiring the third data packet, the operation further includes:
  • an embodiment of the present disclosure provides a secure transmission device, the device comprising:
  • the first receiving module is configured to receive the second data packet sent by the network element of the sending party through the satellite bearer network, wherein the data packet structure of the second data packet includes a security field, and the second data packet is generated by the first The data packet is obtained after the first security processing based on the security policy of the satellite bearer network provided by SMF;
  • the first sending module is configured to send the second data packet to the second security module to obtain a third data packet, wherein the third data packet includes the data of the first data packet, and the first data packet
  • the third data packet is obtained after the second data packet undergoes second security processing based on the security policy of the satellite bearer network;
  • the sending network element and the receiving network element communicate through the satellite bearer network.
  • an embodiment of the present disclosure provides a processor-readable storage medium, the processor-readable storage medium stores a computer program, and the computer program is used to enable the processor to execute the method described in the first aspect .
  • the first security module performs first Security processing, generating a second data packet containing a security field in the data packet structure, and sending it to the receiving network element by the sending network element, after receiving the second data packet, the receiving network element can pass the second security module , based on the obtained security policy of the satellite bearer network, the second security process is performed on the second data packet, and the third data packet containing the data of the first data packet is obtained, so that the network elements at both ends of the bearer network do not need to carry out key and security Policy negotiation can protect the data to be transmitted, reduce the overhead of security-related negotiations, and reduce the complexity of satellite communication management.
  • Fig. 1 is a satellite communication entity relationship diagram provided by an embodiment of the present disclosure
  • FIG. 2 is a schematic diagram of a PDU session user plane protocol stack provided by an embodiment of the present disclosure
  • FIG. 3 is a schematic diagram of an inter-satellite routing data packet structure provided by an embodiment of the present disclosure
  • FIG. 4 is a schematic structural diagram of a satellite communication system provided by an embodiment of the present disclosure.
  • FIG. 5 is a schematic flow diagram of a secure data transmission method provided by an embodiment of the present disclosure.
  • FIG. 6 is a schematic diagram of a security process from a satellite base station to a UPF provided by an embodiment of the present disclosure
  • FIG. 7 is a schematic diagram of a security process from a satellite base station to a satellite base station provided by an embodiment of the present disclosure
  • Fig. 8 is a schematic diagram of a UPF-to-satellite base station security process provided by an embodiment of the present disclosure
  • FIG. 9 is a schematic diagram of a satellite communication user plane data security architecture provided by an embodiment of the present disclosure.
  • FIG. 10 is a schematic diagram of a data packet structure provided by an embodiment of the present disclosure.
  • FIG. 11 is a schematic diagram of a data transmission protocol stack provided by an embodiment of the present disclosure.
  • FIG. 12 is a schematic flowchart of a secure transmission method provided by an embodiment of the present disclosure.
  • Fig. 13 is a schematic structural diagram of a secure transmission device provided by an embodiment of the present disclosure.
  • Fig. 14 is a schematic structural diagram of a receiving network element provided by an embodiment of the present disclosure.
  • the embodiment of the present disclosure provides a satellite communication system, which is used to reduce the overhead of security-related negotiation and reduce the complexity of satellite communication management.
  • the applicable system may be a global system of mobile communication (GSM) system, a code division multiple access (CDMA) system, a wideband code division multiple access (WCDMA) general packet Wireless business (general packet radio service, GPRS) system, long term evolution (long term evolution, LTE) system, LTE frequency division duplex (frequency division duplex, FDD) system, LTE time division duplex (time division duplex, TDD) system, Long term evolution advanced (LTE-A) system, universal mobile telecommunications system (UMTS), worldwide interoperability for microwave access (WiMAX) system, 5G new air interface (New Radio, NR) system, etc.
  • GSM global system of mobile communication
  • CDMA code division multiple access
  • WCDMA wideband code division multiple access
  • GPRS general packet Wireless business
  • long term evolution long term evolution
  • LTE long term evolution
  • LTE frequency division duplex frequency division duplex
  • FDD frequency division duplex
  • TDD time division duplex
  • LTE-A Long term evolution advanced
  • the terminal device involved in the embodiments of the present disclosure may be a device that provides voice and/or data connectivity to users, a handheld device with a wireless connection function, or other processing devices connected to a wireless modem.
  • the name of the terminal equipment may be different.
  • the terminal equipment may be called User Equipment (User Equipment, UE).
  • the wireless terminal equipment can communicate with one or more core networks (Core Network, CN) via the radio access network (Radio Access Network, RAN), and the wireless terminal equipment can be a mobile terminal equipment, such as a mobile phone (or called a "cellular "telephones) and computers with mobile terminal equipment, such as portable, pocket, hand-held, computer built-in or vehicle-mounted mobile devices, which exchange language and/or data with the radio access network.
  • a mobile terminal equipment such as a mobile phone (or called a "cellular "telephones) and computers with mobile terminal equipment, such as portable, pocket, hand-held, computer built-in or vehicle-mounted mobile devices, which exchange language and/or data with the radio access network.
  • PCS Personal Communication Service
  • SIP Session Initiated Protocol
  • WLL Wireless Local Loop
  • PDA Personal Digital Assistant
  • Wireless terminal equipment can also be called system, subscriber unit, subscriber station, mobile station, mobile station, remote station, access point , remote terminal (remote terminal), access terminal (access terminal), user terminal (user terminal), user agent (user agent), and user device (user device), which are not limited in the embodiments of the present disclosure.
  • the network device involved in the embodiments of the present disclosure may be a base station, and the base station may include multiple cells that provide services for terminals.
  • the base station can also be called an access point, or it can be a device in the access network that communicates with the wireless terminal device through one or more sectors on the air interface, or other names.
  • the network device can be used to interchange received over-the-air frames with Internet Protocol (IP) packets and act as a router between the wireless terminal device and the rest of the access network, which can include the Internet Protocol (IP) communication network.
  • IP Internet Protocol
  • Network devices may also coordinate attribute management for the air interface.
  • the network equipment involved in the embodiments of the present disclosure may be a network equipment (Base Transceiver Station, BTS) in Global System for Mobile communications (GSM) or Code Division Multiple Access (Code Division Multiple Access, CDMA) ), it can also be a network device (NodeB) in Wide-band Code Division Multiple Access (WCDMA), or it can be an evolved network device in a long-term evolution (long term evolution, LTE) system (evolutional Node B, eNB or e-NodeB), 5G base station (gNB) in the 5G network architecture (next generation system), can also be a home evolved base station (Home evolved Node B, HeNB), relay node (relay node) , a home base station (femto), a pico base station (pico), etc., are not limited in this embodiment of the present disclosure.
  • a network device may include a centralized unit (centralized unit, CU) node and a distributed unit (distributed unit, DU) node
  • Figure 1 is a satellite communication entity relationship diagram provided by an embodiment of the present disclosure. As shown in Figure 1, a satellite communication system based on 5G technology can have the following two communication modes: a)-b):
  • the UE data is forwarded to the destination through the core network, that is, the data outbound service.
  • UE data does not pass through the core network, and the data is directly forwarded to another UE by the satellite, that is, the terminal to terminal (T2T) service of the satellite.
  • Outbound service data security can be divided into three segments: UE (initiation)-satellite (initial), satellite (initial)-satellite (destination), and satellite (destination)-ground station/core network.
  • T2T service data security can be divided into three sections: UE (origin)-satellite (initial), satellite (initial)-satellite (destination), and satellite (destination)-UE (destination).
  • Fig. 2 is a schematic diagram of a PDU session user plane protocol stack provided by an embodiment of the present disclosure, as shown in Fig. 2 .
  • UPF is usually implemented using a General packet radio service Tunneling Protocol (GTP) tunnel.
  • GTPtunnel endpoint identifier) tunnel is bidirectional, consisting of source Internet Protocol (Internet Protocol, IP) address, destination IP address, User Datagram Protocol (User Datagram Protocol, UDP) port number, source GTP tunnel endpoint identifier (Tunnel Endpoint Identifier, TEID ), identified by the destination GTP TEID.
  • IP Internet Protocol
  • UDP User Datagram Protocol
  • TEID source GTP tunnel endpoint identifier
  • Fig. 3 is a schematic diagram of the structure of the inter-satellite routing data packet provided by the embodiment of the present disclosure. As shown in Fig. 3, the inter-satellite routing data packet includes:
  • Data packets processed by UE destination IP address, source IP address, payload (Payload);
  • Network elements Tellite base station S-gNB or S-UPF/UPF: destination network element IP address, source network element IP address, GTP-U Header, UE data packet;
  • Inter-satellite routing data packets L2 labels, data packets processed by satellite base station S-gNB or UPF.
  • the user plane data is divided into the following two sections:
  • the air interface security is based on the security policy provided by the network SMF to the gNB to decide whether to enable and which security functions to enable.
  • Security protection from base station gNB to core network element UPF This protection adopts the security mechanism of Internet Protocol Security (IPSec).
  • IPSec Internet Protocol Security
  • the network does not provide a security policy for a specific UE, that is, it provides security protection for all user data.
  • the S-gNB For the user data of the outbound service, the S-gNB establishes a GTP-U tunnel with the ground UPF, and the user plane data will be transmitted in the GTP-U tunnel.
  • the format of the user plane data packet is shown in FIG. 3 .
  • L2 labels are used for inter-satellite routing.
  • the NE IP address is mainly used for the routing of the GTP-U tunnel between NEs.
  • a typical data encryption method is a 3-stage encryption method: UE-satellite, satellite-satellite, satellite-land station. That is to say, encryption and decryption are performed three times respectively.
  • UE-satellite can be realized through the existing UE-base station (S-gNB) security mechanism; satellite-satellite can be realized through inter-satellite communication security mechanism, that is, encrypt GTP-U information, and use inter-satellite routing The mechanism routes the information to the destination satellite; the destination satellite decrypts the information and obtains the routing information in GTP-U, based on which the destination of the next hop is determined, and then the GTP-U data is encrypted again and sent to the land station.
  • S-gNB UE-base station
  • inter-satellite communication security mechanism that is, encrypt GTP-U information, and use inter-satellite routing
  • the mechanism routes the information to the destination satellite; the destination satellite decrypts the information and obtains the routing information in GTP
  • the PDU session is used as a unit to enable the secure communication capability between the satellite and the land station on demand, it means that the PDU session security policy needs to be provided to the satellite and the land station, and a security association should be established between the two.
  • the satellite communication system determines that the data communication in the bearer network must be divided into two segments: inter-satellite communication and satellite-ground communication. If the latter two of the three security mechanisms are simply merged, it means that after the data arrives at the destination satellite, the destination satellite cannot determine the address of the next hop due to the encryption of the routing information in GTP-U.
  • the 5G core network does not have an interface to the bearer network element land station (the land station is transparent to the core network), so the PDU session security policy cannot be provided to the satellite land station.
  • an embodiment of the present disclosure proposes a satellite communication system.
  • Fig. 4 is a schematic structural diagram of a satellite communication system provided by an embodiment of the present disclosure.
  • the system 400 includes: a sender network element 410, a first security module 420 corresponding to the sender network element, and a receiver network element.
  • the element 430 and the second security module 440 corresponding to the network element of the receiver, wherein the network element 410 of the sender and the network element 430 of the receiver communicate through a satellite bearer network; wherein:
  • the first security module 420 is configured to receive the first data packet sent by the sender network element and the security policy of the satellite bearer network, and perform the security policy on the first data packet based on the security policy of the satellite bearer network. First security processing, generating a second data packet, the data packet structure of the second data packet includes a security field, and sending the second data packet to the sending network element;
  • the second security module 440 is configured to receive the second data packet sent by the receiver network element, obtain the security policy of the satellite bearer network, and perform security checks on the second data packet based on the security policy of the satellite bearer network. performing second security processing on the data packet to obtain a third data packet, the third data packet including the data of the first data packet, and sending the third data packet to the receiving network element;
  • the sending network element 410 is configured to generate the first data packet and receive the security policy of the satellite bearer network sent by the session management function SMF, and transmit the first data packet and the security policy of the satellite bearer network sending to the first security module to obtain the second data packet, and sending the second data packet to the receiving network element through the satellite bearer network;
  • the receiver network element 430 is configured to receive the second data packet sent by the sender network element through the satellite bearer network, obtain the security policy of the satellite bearer network, and transmit the second data packet and the security policy of the satellite bearer network are sent to the second security module to obtain the third data packet.
  • the embodiments of the present disclosure extend the SMF function.
  • the sending network element of the bearer network connection provides the security policy of the satellite bearer network, which is applied to the data transmission of the satellite bearer network.
  • the sending network element may first generate a first data packet, which includes the data to be sent by the sending network element; after receiving the security policy of the satellite bearer network, the sending network element may send the first data to The security policy of the packet and the satellite bearer network is sent to the first security module;
  • the first security module acquires the first data packet and the security policy of the satellite bearer network, it can perform first security processing on the first data packet based on the security policy of the satellite bearer network to generate a second data packet,
  • the data packet structure of the second data packet includes a security field, and the security field may be empty or may include a security policy of the satellite bearer network;
  • the first security module may be a physical module communicatively connected with the sending network element, or a virtual module capable of realizing the above functions.
  • the first security module after the first security module generates the second data packet, it can send the second data packet to the sending network element; after the sending network element obtains the second data packet, it can send the second data packet Send to the receiving network element through the satellite bearer network;
  • the satellite bearer network does not participate in work related to data security protection.
  • the receiving network element may send the second data packet to the second security module
  • the second security module can obtain the second data packet, and can also obtain the security policy of the satellite bearer network, then based on the security policy of the satellite bearer network, the second security process can be performed on the second data packet, and the third data can be obtained.
  • the third data includes the data in the first data, that is, the second security processing can be understood as recovery processing of the data packet after the first security processing.
  • the embodiment of the present disclosure obtains the security policy of the satellite bearer network through the sender network element and the receiver network element, and the sender network element transmits to the satellite bearer network through the first security module based on the security policy of the satellite bearer network.
  • the first security processing is performed on the data packets
  • the receiver network element performs the second security processing on the data packets received from the bearer network through the second security module based on the security policy of the satellite bearer network, that is, the second security module is based on the satellite bearer network’s
  • the security policy can directly determine how to perform security processing on the received second data packet, so as to realize the capability of providing secure data transmission on demand.
  • the satellite communication system provided by the embodiments of the present disclosure can realize the secure data transmission mode of the above process, so that the network elements at both ends of the satellite bearer network do not need to negotiate keys and security policies, that is, they can perform confidentiality and security on the data to be transmitted. / or integrity protection.
  • the first security module performs the first security processing on the first data packet based on the security policy of the satellite bearer network owned by the sending network element, and generates a data packet structure containing a security field.
  • the second data packet is sent by the sending network element to the receiving network element.
  • the receiving network element can pass the second security module based on the obtained security policy of the satellite bearer network.
  • the second data packet is subjected to the second security processing, and the third data packet containing the data of the first data packet is obtained, so that the network elements at both ends of the bearer network can protect the data to be transmitted without negotiating keys and security policies, Reduce the overhead of security-related negotiations and reduce the complexity of satellite communication management.
  • the first security processing includes at least one of the following: confidentiality protection processing and integrity protection processing
  • the second security processing includes at least one of the following: decryption processing and integrity protection verification processing.
  • the first security processing may include confidentiality protection processing, and correspondingly, the second second security processing may include decryption processing;
  • the first security processing may include integrity protection processing
  • the second second security processing may include integrity protection verification processing
  • the first security processing may include confidentiality protection processing and integrity protection processing
  • the second security processing may include decryption processing and integrity protection verification processing.
  • the security policy of the satellite bearer network includes at least one of the following:
  • Data security policy information where the data security policy information is used to indicate the type of security protection processing included in the first security processing, where the type of security protection processing includes the confidentiality protection processing and/or the integrity protection processing ;
  • the algorithm information is used to indicate the algorithm for implementing the confidentiality protection process and/or the algorithm for implementing the integrity protection process;
  • Key information where the key information is used to indicate a key for implementing the confidentiality protection process and/or a key for implementing the integrity protection process.
  • the security policy of the satellite bearer network may include any one or more of the following:
  • Data security policy information used to indicate the security protection processing type included in the first security processing, where the security protection processing type includes at least one of the following: the confidentiality protection processing and the integrity protection processing, which is used to indicate whether It is necessary to perform confidentiality protection processing on the first data processing, and whether to perform integrity protection processing on the first data processing;
  • Algorithm information indicating an algorithm implementing said confidentiality protection process and an algorithm implementing said integrity protection process
  • Key information where the key information is used to indicate a key for implementing the confidentiality protection process and a key for implementing the integrity protection process.
  • the first security module is specifically configured to: receive the first data packet sent by the sending network element and the security policy of the satellite bearer network, based on the data security policy information, determining the type of security protection processing, and based on the algorithm corresponding to the type of security protection processing in the algorithm information and the key corresponding to the type of security protection processing in the key information, Implementing first security processing on the first data packet, generating the second data packet, and sending the second data packet to the sending network element.
  • the first security module when the first security module performs the first security processing on the first data packet based on the security policy of the satellite bearer network and obtains the second data packet, it may be based on the data security in the security policy of the satellite bearer network. Policy information, determining the type of security protection processing, and based on the algorithm corresponding to the type of security protection processing in the algorithm information and the key corresponding to the type of security protection processing in the key information, implement the The first security processing of the first data packet generates the second data packet.
  • the second security module is specifically configured to: receive the second data packet sent by the receiver network element, and determine the data security policy information in the security policy of the satellite bearer network based on the the type of security protection processing, and based on the algorithm corresponding to the type of security protection processing in the algorithm information and the key corresponding to the type of security protection processing in the key information, realize the encryption of the second data
  • the second security processing of the packet is to obtain the third data packet, and send the third data packet to the receiving network element.
  • the second security module when the second security module performs the second security processing on the second data packet based on the security policy of the satellite bearer network to obtain the third data packet, it may be based on the data security in the security policy of the satellite bearer network. Policy information, determining the type of security protection processing, and based on the algorithm corresponding to the type of security protection processing in the algorithm information and the key corresponding to the type of security protection processing in the key information, implement the The second security processing of the second data packet is to obtain the third data packet.
  • FIG. 5 is a schematic flow diagram of a secure data transmission method provided by an embodiment of the present disclosure. As shown in FIG. 5 , the process of secure data transmission includes the following steps (1)-(6):
  • the UE requests to establish a PDU session
  • the SMF obtains the security policy of the satellite bearer network applicable to the PDU session according to the subscription information of the UE.
  • the information described in the security policy of the satellite bearer network may include different algorithms and key information for the security protection of the bearer network;
  • SMF generates bearer network user plane uplink and downlink data security policies based on the obtained bearer network security policy applicable to the PDU session, and sends the security policies to the third-generation network connected to both ends of the bearer network in the PDU session tunnel.
  • 3GPP 3rd Generation Partnership Project
  • the sending network element sends the second data packet to the receiving network element
  • the receiver network element performs the operations shown in (d)-(e) below:
  • the sending network element is a satellite base station S-gNB
  • the receiving network element is a user plane function UPF
  • the first security module is an on-board security function module
  • the second security module is a ground station security function module
  • Both the sending network element and the receiving network element are satellite base stations S-gNB, and both the first security module and the second security module are satellite-borne security function modules; or
  • the sending network element is a user plane function UPF
  • the receiving network element is a satellite base station S-gNB
  • the first security module is a ground station security function module
  • the second security module is an onboard security function module .
  • At least one of the sending network element and the receiving network element at both ends of the satellite bearer network in the embodiment of the present disclosure may be a satellite base station;
  • the sending network element is a satellite base station S-gNB
  • the receiving network element is a user plane function UPF
  • the first security module is an on-board security function module
  • the second security module is a ground Station security function module
  • Fig. 6 is a schematic diagram of a security process from a satellite base station to a UPF provided by an embodiment of the present disclosure, as shown in Fig. 6 , in which steps 1 to 3 are performed by air interface user plane (User Plane, UP) security.
  • the satellite bearer network part provides data security transmission on demand, based on the security policy of the satellite bearer network provided by SMF, in steps 4-5, the user plane data (first data packet) is subjected to the first security processing to obtain the second data Then the second data packet is transmitted on the bearer network; at the UPF, through steps 11 to 12, the second security processing is performed on the second data packet to obtain data plaintext; then the existing protocol continues to perform related processing.
  • both the sending network element and the receiving network element are satellite base stations S-gNB, and both the first security module and the second security module are satellite-borne security function modules;
  • Fig. 7 is a schematic diagram of a satellite base station-to-satellite base station security process provided by an embodiment of the present disclosure. As shown in Fig. 7, the process is applicable to T2T (terminal-to-terminal) security in a satellite communication environment; where in step 1-step 3 is The air interface is UP for security.
  • T2T terminal-to-terminal
  • the satellite bearer network part provides data security transmission on demand, based on the security policy of the satellite bearer network provided by SMF, in steps 4-5, the user plane data (first data packet) is subjected to the first security processing to obtain the second data Then the second data packet is transmitted on the bearer network; at the receiver's satellite base station, through steps 11 to 12, the second security processing is performed on the second data packet to obtain the plain text of the data; then the existing protocol continues to perform correlation deal with.
  • the sending network element is a user plane function UPF
  • the receiving network element is a satellite base station S-gNB
  • the first security module is a ground station security function module
  • the second security module is a satellite Load the safety function module.
  • Fig. 8 is a schematic diagram of the UPF-to-satellite base station security process provided by the embodiment of the present disclosure, as shown in Fig. 8, wherein in step 1-step 2, the UPF performs the first security processing on the user plane data (first data packet), and obtains The second data packet is then transmitted on the bearer network; at the satellite base station S-gNB, through steps 8 to 9, the second data packet is subjected to second security processing to obtain data plaintext; then the existing protocol continues to perform related processing .
  • Fig. 9 is a schematic diagram of a satellite communication user plane data security architecture provided by an embodiment of the present disclosure. Taking the satellite communication user plane data security architecture in Fig. 9 as an example, as shown in Fig. 9, the satellite communication user plane used in a satellite communication system
  • the data security architecture can be composed of the following functional entities or modules:
  • Satellite base station (S-gNB): the functional entity that realizes the base station function on the satellite;
  • Satellite UPF The entity that realizes the UPF function on the satellite
  • Inter-satellite communication function the functional entity responsible for inter-satellite data communication
  • On-board security function module the functional entity or virtual module on the satellite that is responsible for the security-related operations of the satellite bearer network;
  • Feed communication function the functional entity responsible for data communication between the satellite and the ground station (gateway station) on the satellite;
  • Ground Station An entity on the ground responsible for communicating with a satellite.
  • the core network is connected to the satellite through the gateway station, and further connected to the UE;
  • Ground station security function module connected with UPF: The ground station is responsible for the functional entity or virtual module of satellite bearer network security-related operations;
  • SMF responsible for distributing user plane security policies of 3GPP network elements at both ends of the bearer network.
  • the data packet structure of the first data packet includes a GTP-U part and a security field part
  • the GTP-U part includes a destination network element IP address part, a source network element IP address part, a UDP port part, a GTP -U Header part, destination IP address part, source IP address part and Payload part.
  • the first security protection process is performed on the first data packet to obtain the second data packet.
  • the traditional GTP-U data packet structure is extended, and a new The packet structure.
  • FIG. 10 is a schematic diagram of a data packet structure provided by an embodiment of the present disclosure.
  • the data packet structure of the first data packet includes a GTP-U part and a security field part, and the GTP-U part includes a destination network element IP address part, source network element IP address part, UDP port part, GTP-U Header part, destination IP address part, source IP address part and Payload part.
  • the protocol layer for processing the second data packet is a security layer in the satellite bearer network data transmission protocol stack, and the security layer is between the GTP-U layer and the PDU Layer.
  • the embodiments of the present disclosure focus on the communication between network elements that transmit user plane (UP) data.
  • the data transmission protocol has been extended to add a security layer, so that the bearer network does not have to deal with matters related to data security.
  • FIG. 11 is a schematic diagram of the data transmission protocol stack provided by the embodiment of the present disclosure.
  • a security layer is added to the data transmission protocol stack, which is between the GTP-U layer and the PDU Layer layer.
  • the new protocol stack is shown in Figure 11, and this layer can be processed by the satellite base station S-gNB and/or UPF that generate and process the first data packet and/or the second data packet.
  • the first security module is specifically used for at least one of the following:
  • security protection processing type includes the confidentiality protection processing, perform confidentiality on the destination IP address part, the source IP address part and the Payload part in the data packet structure of the first data packet Protection processing, obtaining ciphertext;
  • the security protection processing type includes the integrity protection processing, the IP address part of the destination network element, the IP address part of the source network element, the UDP The port part, the GTP-U Header part, the security field part, the destination IP address part, the source IP address part and the Payload part perform integrity protection processing;
  • the security protection processing type includes the confidentiality protection processing and the integrity protection processing
  • the confidentiality protection processing for the destination network element IP address part in the data packet structure of the first data packet, the source network element IP address part, the UDP port part, the GTP-U Header part, the security field part, and the ciphertext are integrity protected.
  • the L2 label is used for inter-satellite routing; the IP address of the destination network element and the IP address of the source network element are used for routing between S-gNB and UPF or between two S-gNBs;
  • the address, source IP address and Payload are carried by the UE and can be protected by confidentiality, that is, encrypted; other data except the L2 label are protected by integrity.
  • the security protection processing type includes the confidentiality protection processing
  • Confidentiality protection processing may be performed on the destination IP address part, the source IP address part and the Payload part in the data packet structure of the first data packet, that is, encryption processing is performed to obtain ciphertext
  • the security protection processing type includes the integrity protection processing
  • the The destination network element IP address part, the source network element IP address part, the UDP port part, the GTP-U Header part, the security field part, the destination IP address part, the source IP address part and The Payload part is processed for integrity protection;
  • the confidentiality processing may be performed first Re-execute integrity protection processing, then firstly, perform confidentiality protection processing on the destination IP address part, the source IP address part and the Payload part in the data packet structure of the first data packet, to obtain the ciphertext ;
  • the destination network element IP address part, the source network element IP address part, the UDP port part, the GTP -U The header part, the security field part, and the ciphertext obtained during the confidentiality protection process are integrity protected.
  • the second security module is specifically used for at least one of the following:
  • the security protection processing type includes the confidentiality protection processing, then decrypt the ciphertext in the data packet structure of the second data packet to obtain the destination IP address part, the source IP address part and the Payload section;
  • security protection processing type includes the integrity protection processing, the destination network element IP address part, the source network element IP address part, the UDP port part, and all The GTP-U Header part, the security field part, the destination IP address part, the source IP address part and the Payload part carry out integrity protection verification processing;
  • the security protection processing type includes the confidentiality protection processing and the integrity protection processing
  • the destination network element IP address part, the source network element IP address part, and the source network element IP address part in the data packet structure of the second data packet The UDP port part, the GTP-U Header part, the security field part, and the ciphertext are subjected to integrity protection verification processing, and after the integrity protection verification processing, the ciphertext is decrypted to obtain the described The destination IP address part, the source IP address part and the Payload part.
  • the second security module when the second security module performs the second security processing on the second data packet, if the security protection processing type includes the confidentiality protection processing, then decrypt the ciphertext in the data packet structure of the second data packet Processing, obtaining the destination IP address part, the source IP address part and the Payload part;
  • the security protection processing type includes the integrity protection processing
  • the destination network in the data packet structure of the second data packet element IP address part, the source network element IP address part, the UDP port part, the GTP-U Header part, the security field part, the destination IP address part, the source IP address part and the The Payload part performs integrity protection verification processing
  • the second security module when the second security module performs the second security processing on the second data packet, if the security protection processing type includes the confidentiality protection processing and the integrity protection processing, the integrity protection verification processing is first performed , and then perform decryption processing; that is, at first, the destination network element IP address part, the source network element IP address part, the UDP port part, the GTP-U Header part, The security field part and the ciphertext are subjected to integrity protection verification processing, and after the integrity protection verification processing, the ciphertext is decrypted to obtain the destination IP address part, the source IP address part and The Payload section.
  • the security protection processing type includes the confidentiality protection processing and the integrity protection processing
  • the integrity protection verification processing is first performed , and then perform decryption processing; that is, at first, the destination network element IP address part, the source network element IP address part, the UDP port part, the GTP-U Header part, The security field part and the ciphertext are subjected to integrity protection verification processing, and after the integrity protection verification processing
  • the security field in the second data packet includes the security policy of the satellite bearer network, and the security policy of the satellite bearer network acquired by the receiver network element is carried in the second data packet sent by the sending network element to the receiving network element.
  • the security policy of the satellite bearer network may be transmitted to the receiving network element by directly carrying the security policy of the satellite bearer network in the security field in the second data packet.
  • the security field in the second data packet includes the security policy of the satellite bearer network. This method requires modification of the content in the security field.
  • the key and the security policy can be integrated into the transmitted second data packet through the security field.
  • the receiving network element can determine how to perform security processing on the received second data packet through the security field, thereby reducing the overhead of security-related negotiation and the complexity of satellite communication management.
  • the SMF is configured to send the security policy of the satellite bearer network to the sending network element.
  • the security field in the second data packet includes the security policy of the satellite bearer network. This method requires modification of the content in the security field.
  • SMF only needs to send the security policy to the sender of the data.
  • the receiving network element may determine how to process the security data in the second data packet according to the security field included in the second data packet.
  • the security policy of the satellite bearer network obtained by the second security module is obtained from a security field in the second data packet.
  • the second security module can directly obtain the The security field of the data packet obtains the security policy of the satellite bearer network.
  • the security policy of the satellite bearer network acquired by the receiving network element is sent by the SMF to the receiving network element.
  • the security field in the second data packet may be empty, that is, the second data packet does not carry the security policy of the satellite bearer network. Therefore, there is no need to modify the security field in the first data packet.
  • SMF needs to distribute security policies to the sender and receiver of data, so that both parties can correctly process related data.
  • the security field in the second data packet may not be empty, that is, the second data packet may also carry the security policy of the satellite bearer network.
  • SMF can also distribute security policies to the sender and receiver of data, so that both parties can correctly process related data.
  • the SMF is configured to send the security policy of the satellite bearer network to the sending network element and the receiving network element.
  • the security field in the second data packet may be empty, that is, the second data packet does not carry the security policy of the satellite bearer network. Therefore, there is no need to modify the security field in the first data packet.
  • the security policy needs to be distributed to the sending network element and the receiving network element, so that both parties can correctly process relevant data, and effectively avoid resource waste caused by security-related negotiations.
  • the security policy of the satellite bearer network obtained by the second security module is obtained from the receiving network element.
  • the receiving network element when the receiving network element sends the second data packet to the second security module, it may also send the second data packet to the second security module.
  • the security policy of the satellite bearer network obtained from SMF.
  • the receiving network element is further configured to: send the security policy of the satellite bearer network to the second security module after acquiring the security policy of the satellite bearer network.
  • the receiving network element may send the security policy of the satellite bearer network to the second security module, so that the second security module is based on the satellite bearer network security policy.
  • the security policy performs second security processing on the second data packet.
  • the SMF obtains the security policy of the satellite bearer network from a security management entity, and the security management entity includes a unified data management function UDM.
  • the security management entity includes UDM or other network elements that can generate security policies for the satellite bearer network;
  • the SMF can obtain the security policy of the satellite bearer network in advance from the unified data management function UDM or other network elements that can generate the security policy of the satellite bearer network.
  • the first security module performs the first security processing on the first data packet based on the security policy of the satellite bearer network owned by the sending network element, and generates a data packet structure containing a security field.
  • the second data packet is sent by the sending network element to the receiving network element.
  • the receiving network element can pass the second security module based on the obtained security policy of the satellite bearer network.
  • the second data packet is subjected to the second security processing, and the third data packet containing the data of the first data packet is obtained, so that the network elements at both ends of the bearer network can protect the data to be transmitted without negotiating keys and security policies, Reduce the overhead of security-related negotiations and reduce the complexity of satellite communication management.
  • FIG. 12 is a schematic flow diagram of a secure transmission method provided by an embodiment of the present disclosure. The method is applied to a receiving network element. As shown in FIG. 12 , the method includes the following flow:
  • Step 1200 receiving the second data packet sent by the network element of the sender through the satellite bearer network, wherein the data packet structure of the second data packet includes a security field, and the second data packet is based on the SMF of the first data packet
  • the security policy of the provided satellite bearer network is obtained after the first security processing
  • Step 1210 sending the second data packet to the second security module to obtain a third data packet, wherein the third data packet includes the data of the first data packet, and the third data packet is obtained by the second data packet after second security processing based on the security policy of the satellite bearer network;
  • the sending network element and the receiving network element communicate through the satellite bearer network.
  • the embodiments of the present disclosure extend the SMF function.
  • the sending network element of the bearer network connection provides the security policy of the satellite bearer network, which is applied to the data transmission of the satellite bearer network.
  • the receiver network element may receive the second data packet sent by the sender network element through the satellite bearer network, wherein the second data packet is the first data packet based on the security policy of the satellite bearer network provided by the SMF through the first security obtained after processing;
  • the manner in which the second data packet is obtained after the first security processing based on the security policy of the satellite bearer network provided by the first data packet based on the SMF can be as shown in (1)-(3):
  • the sending network element can first generate the first data packet, which includes the data to be sent by the sending network element; after receiving the security policy of the satellite bearer network, the sending network element can send the first data The security policy of the packet and the satellite bearer network is sent to the first security module;
  • the first security module can perform first security processing on the first data packet based on the security policy of the satellite bearer network to generate a second data packet,
  • the data packet structure of the second data packet includes a security field, and the security field may be empty or may include a security policy of the satellite bearer network;
  • the first security module may be a physical module communicatively connected with the sending network element, or a virtual module capable of realizing the above-mentioned functions.
  • the first security module After the first security module generates the second data packet, it can send the second data packet to the sending network element; after the sending network element obtains the second data packet, it can send the second data packet Send to the receiving network element through the satellite bearer network;
  • the satellite bearer network does not participate in work related to data security protection.
  • the receiving network element may send the second data packet to the second security module to obtain a third data packet, wherein the third data packet includes The data of the first data packet, the third data packet is obtained by the second data packet after second security processing based on the security policy of the satellite bearer network;
  • the manner in which the second data packet is obtained after the second security processing based on the security policy of the satellite bearer network to obtain the third data packet may be as follows:
  • the receiving network element can send the second data packet to the second security module, and the second security module can obtain the second data packet, and can also obtain the security policy of the satellite bearer network , then the second security process can be performed on the second data packet based on the security policy of the satellite bearer network, and the third data can be obtained, and the third data includes the data in the first data, that is, the second security process can be understood as the - Restoration processing of the securely processed data packets.
  • the second security module performs the second security processing on the second data packet based on the security strategy of the satellite bearer network, and the manner of obtaining the third data may be as follows:
  • the second security module When the second security module performs second security processing on the second data packet based on the security policy of the satellite bearer network to obtain the third data packet, based on the data security policy information in the security policy of the satellite bearer network, determining the type of security protection processing, and based on the algorithm corresponding to the type of security protection processing in the algorithm information and the key corresponding to the type of security protection processing in the key information, implement the The second security processing of the second data packet is to obtain the third data packet.
  • the embodiment of the present disclosure obtains the security policy of the satellite bearer network through the sender network element and the receiver network element, and the sender network element transmits to the satellite bearer network through the first security module based on the security policy of the satellite bearer network.
  • the first security processing is performed on the data packets
  • the receiver network element performs the second security processing on the data packets received from the bearer network through the second security module based on the security policy of the satellite bearer network, that is, the second security module is based on the satellite bearer network’s
  • the security policy can directly determine how to perform security processing on the received second data packet, so as to realize the capability of providing secure data transmission on demand.
  • the satellite communication system provided by the embodiments of the present disclosure can realize the secure data transmission mode of the above process, so that the network elements at both ends of the satellite bearer network do not need to negotiate keys and security policies, that is, they can perform confidentiality and security on the data to be transmitted. / or integrity protection.
  • the first security module performs first security processing on the first data packet based on the security policy of the satellite bearer network owned by the sending network element, and generates a data packet structure containing a security field.
  • the second data packet is sent by the sending network element to the receiving network element.
  • the receiving network element can pass the second security module based on the obtained security policy of the satellite bearer network.
  • the second data packet is subjected to the second security processing, and the third data packet containing the data of the first data packet is obtained, so that the network elements at both ends of the bearer network can protect the data to be transmitted without negotiating keys and security policies, Reduce the overhead of security-related negotiations and reduce the complexity of satellite communication management.
  • the first security processing includes at least one of the following: confidentiality protection processing and integrity protection processing
  • the second security processing includes at least one of the following: decryption processing and integrity protection verification processing.
  • the first security processing may include confidentiality protection processing, and correspondingly, the second second security processing may include decryption processing;
  • the first security processing may include integrity protection processing
  • the second second security processing may include integrity protection verification processing
  • the first security processing may include confidentiality protection processing and integrity protection processing
  • the second security processing may include decryption processing and integrity protection verification processing.
  • the security policy of the satellite bearer network includes at least one of the following:
  • Data security policy information where the data security policy information is used to indicate the type of security protection processing included in the first security processing, where the type of security protection processing includes the confidentiality protection processing and/or the integrity protection processing ;
  • the algorithm information is used to indicate the algorithm for implementing the confidentiality protection process and/or the algorithm for implementing the integrity protection process;
  • Key information where the key information is used to indicate a key for implementing the confidentiality protection process and/or a key for implementing the integrity protection process.
  • the security policy of the satellite bearer network may include any one or more of the following:
  • Data security policy information used to indicate the security protection processing type included in the first security processing, where the security protection processing type includes at least one of the following: the confidentiality protection processing and the integrity protection processing, which is used to indicate whether It is necessary to perform confidentiality protection processing on the first data processing, and whether to perform integrity protection processing on the first data processing;
  • Algorithm information indicating an algorithm implementing said confidentiality protection process and an algorithm implementing said integrity protection process
  • Key information where the key information is used to indicate a key for implementing the confidentiality protection process and a key for implementing the integrity protection process.
  • the sending network element is a satellite base station S-gNB
  • the receiving network element is a user plane function UPF
  • the first security module is an on-board security function module
  • the second security module is a ground station security function module
  • Both the sending network element and the receiving network element are satellite base stations S-gNB, and both the first security module and the second security module are satellite-borne security function modules; or
  • the sending network element is a user plane function UPF
  • the receiving network element is a satellite base station S-gNB
  • the first security module is a ground station security function module
  • the second security module is an onboard security function module .
  • At least one of the sender network element and the receiver network element at both ends of the satellite bearer network in the embodiment of the present disclosure may be a satellite base station;
  • the sending network element is a satellite base station S-gNB
  • the receiving network element is a user plane function UPF
  • the first security module is an on-board security function module
  • the second security module is a ground Station security function module
  • Step 1-Step 3 the security is up by the air interface.
  • the user plane data first data packet
  • the first security processing is subjected to the first security processing to obtain the second data
  • the second data packet is transmitted on the bearer network; at the UPF, through steps 11 to 12, the second security processing is performed on the second data packet to obtain data plaintext; then the existing protocol continues to perform related processing.
  • both the sending network element and the receiving network element are satellite base stations S-gNB, and both the first security module and the second security module are satellite-borne security function modules;
  • this process is applicable to T2T (terminal-to-terminal) security in a satellite communication environment; where in step 1-step 3 is the air interface UP security.
  • the satellite bearer network part provides data security transmission on demand, based on the security policy of the satellite bearer network provided by SMF, in steps 4-5, the user plane data (first data packet) is subjected to the first security processing to obtain the second data Then the second data packet is transmitted on the bearer network; at the receiver's satellite base station, through steps 11 to 12, the second security processing is performed on the second data packet to obtain the plain text of the data; then the existing protocol continues to perform correlation deal with.
  • the sending network element is a user plane function UPF
  • the receiving network element is a satellite base station S-gNB
  • the first security module is a ground station security function module
  • the second security module is a satellite Load the safety function module.
  • step 1-step 2 the UPF performs the first security processing on the user plane data (first data packet), obtains the second data packet, and then transmits it on the bearer network; at the satellite base station S-gNB place , after step 8 to step 9, the second security processing is performed on the second data packet to obtain the data plaintext; then the existing protocol continues to perform related processing.
  • the security field in the second data packet includes the security policy of the satellite bearer network.
  • the first security protection process is performed on the first data packet to obtain the second data packet.
  • the traditional GTP-U data packet structure is extended, and a new The packet structure.
  • the data packet structure of the first data packet includes a GTP-U part and a security field part
  • the GTP-U part includes a destination network element IP address part, a source network element IP address part, a UDP port part, a GTP -U Header part, destination IP address part, source IP address part and Payload part.
  • the protocol layer for processing the second data packet is a security layer in the satellite bearer network data transmission protocol stack, and the security layer is between the GTP-U layer and the PDU Layer.
  • the embodiments of the present disclosure focus on the communication between network elements that transmit user plane (UP) data.
  • the data transmission protocol has been extended to add a security layer, so that the bearer network does not have to deal with matters related to data security.
  • a security layer is added to the data transmission protocol stack, which is between the GTP-U layer and the PDU Layer.
  • the new protocol stack is shown in Figure 11, and this layer can be processed by the satellite base station S-gNB and/or UPF that generate and process the first data packet and/or the second data packet.
  • the method also includes:
  • the security field in the second data packet may be empty, that is, the second data packet does not carry the security policy of the satellite bearer network. Therefore, there is no need to modify the security field in the first data packet.
  • the receiver network element can receive the security policy of the satellite bearer network sent by the SMF, that is, the SMF needs to distribute the security policy to the data sender and receiver, so that both parties can correctly process related data.
  • the security field in the second data packet may not be empty, that is, the second data packet may also carry the security policy of the satellite bearer network.
  • the receiver network element can receive the security policy of the satellite bearer network sent by the SMF, that is, the SMF can also distribute the security policy to the data sender and receiver, so that both parties can correctly process related data.
  • the method before the acquiring the third data packet, the method further includes:
  • the receiving network element may send the security policy of the satellite bearer network to the second security module, so that the second security module is based on the satellite bearer network security policy.
  • the security policy performs second security processing on the second data packet.
  • the first security module performs first Security processing, generating a second data packet containing a security field in the data packet structure, and sending it to the receiving network element by the sending network element, after receiving the second data packet, the receiving network element can pass the second security module , based on the obtained security policy of the satellite bearer network, the second security process is performed on the second data packet, and the third data packet containing the data of the first data packet is obtained, so that the network elements at both ends of the bearer network do not need to carry out key and security Policy negotiation can protect the data to be transmitted, reduce the overhead of security-related negotiations, and reduce the complexity of satellite communication management.
  • Fig. 13 is a schematic structural diagram of a secure transmission device provided by an embodiment of the present disclosure. As shown in Fig. 13, the device includes:
  • the first receiving module 1310 is configured to receive the second data packet sent by the network element of the sending party through the satellite bearer network, wherein the data packet structure of the second data packet includes a security field, and the second data packet is generated by the second data packet A data packet is obtained after first security processing based on the security policy of the satellite bearer network provided by the SMF;
  • the first sending module 1320 is configured to send the second data packet to a second security module to obtain a third data packet, wherein the third data packet includes the data of the first data packet, and the The third data packet is obtained after the second data packet undergoes second security processing based on the security policy of the satellite bearer network;
  • the sending network element and the receiving network element communicate through the satellite bearer network.
  • the secure transmission device may receive, through the first receiving module 1310, the second data packet sent by the network element of the sender through the satellite bearer network, wherein the data packet structure of the second data packet includes a security field, and the second data The packet is obtained by the first data packet based on the security policy of the satellite bearer network provided by the SMF after the first security processing; then the second data packet can be sent to the second security module through the sending module 1320 to obtain the third A data packet, wherein the third data packet includes the data of the first data packet, and the third data packet is the second data packet that undergoes second security processing based on the security policy of the satellite bearer network acquired afterwards.
  • the first security processing includes at least one of the following: confidentiality protection processing and integrity protection processing
  • the second security processing includes at least one of the following: decryption processing and integrity protection verification processing.
  • the security policy of the satellite bearer network includes at least one of the following:
  • Data security policy information where the data security policy information is used to indicate the type of security protection processing included in the first security processing, where the type of security protection processing includes the confidentiality protection processing and/or the integrity protection processing ;
  • the algorithm information is used to indicate the algorithm for implementing the confidentiality protection process and/or the algorithm for implementing the integrity protection process;
  • Key information where the key information is used to indicate a key for implementing the confidentiality protection process and/or a key for implementing the integrity protection process.
  • the sending network element is a satellite base station S-gNB
  • the receiving network element is a user plane function UPF
  • the first security module is an on-board security function module
  • the second security module is a ground station security function module
  • Both the sending network element and the receiving network element are satellite base stations S-gNB, and both the first security module and the second security module are satellite-borne security function modules; or
  • the sending network element is a user plane function UPF
  • the receiving network element is a satellite base station S-gNB
  • the first security module is a ground station security function module
  • the second security module is an onboard security function module .
  • the security field in the second data packet includes the security policy of the satellite bearer network.
  • the device also includes:
  • the second receiving module is configured to receive the security policy of the satellite bearer network sent by the SMF.
  • the device also includes:
  • the second sending module is configured to send the security policy of the satellite bearer network to the second security module before the acquisition of the third data packet.
  • the first security module performs the first security processing on the first data packet based on the security policy of the satellite bearer network owned by the sending network element, and generates a data packet structure containing a security field.
  • the second data packet is sent by the sending network element to the receiving network element.
  • the receiving network element can pass the second security module based on the obtained security policy of the satellite bearer network.
  • the second data packet is subjected to the second security processing, and the third data packet containing the data of the first data packet is obtained, so that the network elements at both ends of the bearer network can protect the data to be transmitted without negotiating keys and security policies, Reduce the overhead of security-related negotiations and reduce the complexity of satellite communication management.
  • each functional unit in each embodiment of the present disclosure may be integrated into one processing unit, each unit may exist separately physically, or two or more units may be integrated into one unit.
  • the above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
  • the integrated unit is realized in the form of a software function unit and sold or used as an independent product, it can be stored in a processor-readable storage medium.
  • the technical solution of the present disclosure is essentially or part of the contribution to the prior art, or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium , including several instructions to make a computer device (which may be a personal computer, a server, or a network device, etc.) or a processor (processor) execute all or part of the steps of the methods described in various embodiments of the present disclosure.
  • the aforementioned storage media include: U disk, mobile hard disk, read-only memory (Read-Only Memory, ROM), random access memory (Random Access Memory, RAM), magnetic disk or optical disc and other media that can store program codes. .
  • FIG. 14 is a schematic structural diagram of a receiving network element provided by an embodiment of the present disclosure.
  • the receiving network element includes a memory 1420, a transceiver 1400, and a processor 1410, including a memory, a transceiver, and a processor :
  • the memory 1420 is used to store computer programs; the transceiver is used to send and receive data under the control of the processor 1410; the processor 1410 is used to read the computer programs in the memory 1420 and perform the following operations:
  • the data packet structure of the second data packet includes a security field
  • the second data packet is a satellite provided by the first data packet based on the SMF
  • the security policy of the bearer network is obtained after the first security processing
  • the sending network element and the receiving network element communicate through the satellite bearer network.
  • the receiver network element provided by the embodiment of the present disclosure performs the first security processing on the first data packet through the first security module based on the security policy of the satellite bearer network owned by the sender network element, and generates a data packet structure containing security fields
  • the second data packet is sent by the sending network element to the receiving network element.
  • the receiving network element can use the second security module based on the obtained security policy of the satellite bearer network
  • the second security processing is performed on the second data packet, and the third data packet containing the data of the first data packet is obtained, so that the network elements at both ends of the bearer network can protect the data to be transmitted without negotiating keys and security policies , reduce the overhead of security-related negotiations, and reduce the complexity of satellite communication management.
  • the first security processing includes at least one of the following: confidentiality protection processing and integrity protection processing
  • the second security processing includes at least one of the following: decryption processing and integrity protection verification processing.
  • the security policy of the satellite bearer network includes at least one of the following:
  • Data security policy information where the data security policy information is used to indicate the type of security protection processing included in the first security processing, where the type of security protection processing includes the confidentiality protection processing and/or the integrity protection processing ;
  • the algorithm information is used to indicate the algorithm for implementing the confidentiality protection process and/or the algorithm for implementing the integrity protection process;
  • Key information where the key information is used to indicate a key for implementing the confidentiality protection process and/or a key for implementing the integrity protection process.
  • the sending network element is a satellite base station S-gNB
  • the receiving network element is a user plane function UPF
  • the first security module is an on-board security function module
  • the second security module is a ground station security function module
  • Both the sending network element and the receiving network element are satellite base stations S-gNB, and both the first security module and the second security module are satellite-borne security function modules; or
  • the sending network element is a user plane function UPF
  • the receiving network element is a satellite base station S-gNB
  • the first security module is a ground station security function module
  • the second security module is an onboard security function module .
  • the security field in the second data packet includes the security policy of the satellite bearer network.
  • processor 1410 is also used for:
  • processor 1410 is also used for:
  • the receiver network element provided by the embodiment of the present disclosure performs the first security processing on the first data packet through the first security module based on the security policy of the satellite bearer network owned by the sender network element, and generates a data packet structure containing security fields
  • the second data packet is sent by the sending network element to the receiving network element.
  • the receiving network element can use the second security module based on the obtained security policy of the satellite bearer network
  • the second security processing is performed on the second data packet, and the third data packet containing the data of the first data packet is obtained, so that the network elements at both ends of the bearer network can protect the data to be transmitted without negotiating keys and security policies , reduce the overhead of security-related negotiations, and reduce the complexity of satellite communication management.
  • the transceiver 1400 is configured to receive and send data under the control of the processor 1410 .
  • the bus architecture may include any number of interconnected buses and bridges, specifically one or more processors represented by the processor 1410 and various circuits of the memory represented by the memory 1420 are linked together.
  • the bus architecture can also link together various other circuits such as peripherals, voltage regulators, and power management circuits, etc., which are well known in the art and therefore will not be further described herein.
  • the bus interface provides the interface.
  • Transceiver 1400 may be a plurality of elements, including a transmitter and a receiver, providing a unit for communicating with various other devices over transmission media, including wireless channels, wired channels, optical cables, and other transmission media.
  • the processor 1410 is responsible for managing the bus architecture and general processing, and the memory 1420 can store data used by the processor 1410 when performing operations.
  • the processor 1410 can be a central processing unit (Central Processing Unit, CPU), an application specific integrated circuit (Application Specific Integrated Circuit, ASIC), a field programmable gate array (Field-Programmable Gate Array, FPGA) or a complex programmable logic device (Complex Programmable Logic Device, CPLD), the processor can also adopt a multi-core architecture.
  • CPU Central Processing Unit
  • ASIC Application Specific Integrated Circuit
  • FPGA Field-Programmable Gate Array
  • CPLD Complex Programmable Logic Device
  • the receiver network element provided by the embodiments of the present disclosure can realize all the method steps implemented in the method embodiment in which the execution subject is the receiver network element, and can achieve the same technical effect.
  • Parts and beneficial effects in this embodiment that are the same as those in the method embodiment will not be described in detail again.
  • the embodiments of the present disclosure further provide a processor-readable storage medium, the processor-readable storage medium stores a computer program, and the computer program is used to enable the processor to execute the above-mentioned embodiments.
  • methods including:
  • the data packet structure of the second data packet includes a security field
  • the second data packet is a satellite provided by the first data packet based on the SMF
  • the security policy of the bearer network is obtained after the first security processing
  • the sending network element and the receiving network element communicate through the satellite bearer network.
  • the processor-readable storage medium can be any available medium or data storage device that can be accessed by a processor, including but not limited to magnetic storage (e.g., floppy disk, hard disk, magnetic tape, magneto-optical disk (MO), etc.), optical storage (e.g., CD, DVD, BD, HVD, etc.), and semiconductor memory (such as ROM, EPROM, EEPROM, non-volatile memory (NAND FLASH), solid-state drive (SSD)), etc.
  • magnetic storage e.g., floppy disk, hard disk, magnetic tape, magneto-optical disk (MO), etc.
  • optical storage e.g., CD, DVD, BD, HVD, etc.
  • semiconductor memory such as ROM, EPROM, EEPROM, non-volatile memory (NAND FLASH), solid-state drive (SSD)
  • the embodiments of the present disclosure may be provided as methods, systems, or computer program products. Accordingly, the present disclosure can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present disclosure may take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, optical storage, etc.) having computer-usable program code embodied therein.
  • processor-executable instructions may also be stored in a processor-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, such that the instructions stored in the processor-readable memory produce a manufacturing product, the instruction device realizes the functions specified in one or more procedures of the flow chart and/or one or more blocks of the block diagram.
  • processor-executable instructions can also be loaded onto a computer or other programmable data processing device, causing a series of operational steps to be performed on the computer or other programmable device to produce a computer-implemented
  • the executed instructions provide steps for implementing the functions specified in the procedure or procedures of the flowchart and/or the block or blocks of the block diagrams.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Radio Relay Systems (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本公开实施例提供一种卫星通信系统,包括:发送方网元,第一安全模块、接收方网元和第二安全模块;第一安全模块用于基于安全策略对第一数据包进行第一安全处理生成数据包结构包含安全字段的第二数据包发送给发送方网元;第二安全模块用于基于安全策略对第二数据包进行第二安全处理获得包括第一数据包的数据的第三数据包发送给接收方网元;发送方网元用于生成第一数据包和接收SMF发送的安全策略,并发送给第一安全模块以获得第二数据包,并将第二数据包发送给接收方网元;接收方网元用于接收第二数据包并获取安全策略,将第二数据包和安全策略发送至第二安全模块以获取第三数据包。本公开实施例减少安全相关协商开销,降低卫星通信管理复杂度。

Description

卫星通信系统、方法、装置、接收方网元及存储介质
相关申请的交叉引用
本申请要求于2021年11月15日提交的申请号为202111347750.2,发明名称为“卫星通信系统、方法、装置、接收方网元及存储介质”的中国专利申请的优先权,其通过引用方式全部并入本文。
技术领域
本公开涉及通信技术领域,尤其涉及一种卫星通信系统、方法、装置、接收方网元及存储介质。
背景技术
在通信系统中,从基站至核心网用户面功能(User Plane Function,UPF)对所有用户数据进行机密性和完整性保护时,可以不需要核心网络的干预或配置,因此,当前会话管理功能(Session ManagementFunction,SMF)下发给基站的安全策略不包含有基站与UPF之间的安全策略,并且SMF不向UPF下发任何安全策略,UPF也不处理任何与协议数据单元(Protocol Data Unit,PDU)会话安全相关的内容。
而卫星的通信体制决定了承载网中的数据通信必须分为星间通信和星地通信2段。若直接应用传统的安全机制,目的卫星对信息的加密方式是未知的,无法对信息进行解密获得路由信息,进而无法确定下一跳的地址;若通信双方对信息的加密方式进行协商,复杂的密钥协商过程中通信资源高,卫星通信管理复杂。
发明内容
本公开实施例提供一种卫星通信系统、方法、装置、接收方网元及存储介质,用以解决现有技术中通信资源高,卫星通信管理复杂的缺陷,实现减少了安全相关协商的开销,降低了卫星通信管理的复杂度。
第一方面,本公开实施例提供一种卫星通信系统,包括:
发送方网元,所述发送方网元对应的第一安全模块、接收方网元、和所述接收方网元对应的第二安全模块,其中,所述发送方网元和所述接收方网元通过卫星承载网进行通信;
所述第一安全模块,用于接收所述发送方网元发送的第一数据包和所述卫星承载网的安全策略,并基于所述卫星承载网的安全策略对所述第一数据包进行第一安全处理,生成第二数据包,所述第二数据包的数据包结构中包含安全字段,并将所述第二数据包发送给所述发送方网元;
所述第二安全模块,用于接收所述接收方网元发送的所述第二数据包,获取所述卫星承载网的安全策略,并基于所述卫星承载网的安全策略对所述第二数据包进行第二安全处理,获得第三数据包,所述第三数据包中包括所述第一数据包的数据,并将所述第三数据包发送给所述接收方网元;
所述发送方网元,用于生成所述第一数据包和接收会话管理功能SMF发送的所述卫星承载网的安全策略,并将所述第一数据包和所述卫星承载网的安全策略发送给所述第一安全模块,以获得所述第二数据包,并将所述第二数据包通过所述卫星承载网发送给所述接收方网元;
所述接收方网元,用于接收所述发送方网元通过所述卫星承载网发送的所述第二数据包,并获取所述卫星承载网的安全策略,并将所 述第二数据包和所述卫星承载网的安全策略发送至所述第二安全模块,以获取所述第三数据包。
可选地,根据本公开一个实施例的卫星通信系统,所述第一安全处理包括以下至少一项:机密性保护处理和完整性保护处理,所述第二安全处理包括以下至少一项:解密处理和完整性保护验证处理。
可选地,根据本公开一个实施例的卫星通信系统,所述卫星承载网的安全策略包括以下至少一项:
数据安全策略信息,所述数据安全策略信息用于指示所述第一安全处理包括的安全保护处理类型,其中所述安全保护处理类型包括所述机密性保护处理和/或所述完整性保护处理;或
算法信息,所述算法信息用于指示实现所述机密性保护处理的算法和/或实现所述完整性保护处理的算法;或
密钥信息,所述密钥信息用于指示实现所述机密性保护处理的密钥和/或实现所述完整性保护处理的密钥。
可选地,根据本公开一个实施例的卫星通信系统,所述第一安全模块具体用于:接收所述发送方网元发送的第一数据包和所述卫星承载网的安全策略,基于所述卫星承载网的安全策略中的所述数据安全策略信息,确定所述安全保护处理类型,并基于所述算法信息中与所述安全保护处理类型对应的算法,以及所述密钥信息中与所述安全保护处理类型对应的密钥,实现对所述第一数据包的第一安全处理,生成所述第二数据包,并将所述第二数据包发送给所述发送方网元。
可选地,根据本公开一个实施例的卫星通信系统,所述第二安全模块具体用于:接收所述接收方网元发送的所述第二数据包,基于所述卫星承载网的安全策略中的所述数据安全策略信息,确定所述安全保护处理类型,并基于所述算法信息中与所述安全保护处理类型对应的算法,以及所述密钥信息中与所述安全保护处理类型对应的密钥,实现对所述第二数据包的第二安全处理,获得所述第三数据包,并将 所述第三数据包发送给所述接收方网元。
可选地,根据本公开一个实施例的卫星通信系统,所述发送方网元为卫星基站S-gNB,所述接收方网元为用户面功能UPF,所述第一安全模块为星载安全功能模块,所述第二安全模块为地面站安全功能模块;或
所述发送方网元和所述接收方网元均为卫星基站S-gNB,所述第一安全模块和所述第二安全模块均为星载安全功能模块;或
所述发送方网元为用户面功能UPF,所述接收方网元为卫星基站S-gNB,所述第一安全模块为地面站安全功能模块,所述第二安全模块为星载安全功能模块。
可选地,根据本公开一个实施例的卫星通信系统,所述第一数据包的数据包结构包括GTP-U部分和安全字段部分,所述GTP-U部分包括目的网元IP地址部分,源网元IP地址部分,UDP端口部分,GTP-U Header部分,目的IP地址部分、源IP地址部分和Payload部分。
可选地,根据本公开一个实施例的卫星通信系统,处理所述第二数据包的协议层为卫星承载网数据传输协议栈中的安全层,所述安全层在GTP-U层与PDU Layer层之间。
可选地,根据本公开一个实施例的卫星通信系统,所述第一安全模块,具体用于以下至少一项:
若所述安全保护处理类型包括所述机密性保护处理,则对所述第一数据包的数据包结构中的所述目的IP地址部分、所述源IP地址部分和所述Payload部分进行机密性保护处理,获得密文;
若所述安全保护处理类型包括所述完整性保护处理,则对所述第一数据包的数据包结构中的所述目的网元IP地址部分、所述源网元IP地址部分、所述UDP端口部分、所述GTP-U Header部分、所述安全字段部分、所述目的IP地址部分、所述源IP地址部分和所述 Payload部分进行完整性保护处理;
若所述安全保护处理类型包括所述机密性保护处理和所述完整性保护处理,则对所述第一数据包的数据包结构中的所述目的IP地址部分、所述源IP地址部分和所述Payload部分进行机密性保护处理,获得密文,在所述机密性保护处理后,对所述第一数据包的数据包结构中的目的网元IP地址部分,所述源网元IP地址部分,所述UDP端口部分,所述GTP-U Header部分,所述安全字段部分,以及所述密文进行完整性保护。
可选地,根据本公开一个实施例的卫星通信系统,所述第二安全模块,具体用于以下至少一项:
若所述安全保护处理类型包括所述机密性保护处理,则对第二数据包的数据包结构中的密文进行解密处理,获得所述目的IP地址部分、所述源IP地址部分和所述Payload部分;
若所述安全保护处理类型包括所述完整性保护处理,则对第二数据包的数据包结构中的目的网元IP地址部分、所述源网元IP地址部分、所述UDP端口部分、所述GTP-U Header部分、所述安全字段部分、所述目的IP地址部分,所述源IP地址部分以及所述Payload部分进行完整性保护验证处理;
若所述安全保护处理类型包括所述机密性保护处理和所述完整性保护处理,则对第二数据包的数据包结构中的目的网元IP地址部分、所述源网元IP地址部分、所述UDP端口部分、所述GTP-U Header部分、所述安全字段部分、以及密文进行完整性保护验证处理,在所述完整性保护验证处理后,对所述密文进行解密处理,获得所述目的IP地址部分、所述源IP地址部分和所述Payload部分。
可选地,根据本公开一个实施例的卫星通信系统,所述第二数据包中的安全字段包含所述卫星承载网的安全策略,所述接收方网元获取的所述卫星承载网的安全策略是被携带在所述第二数据包中由所 述发送方网元发送至所述接收方网元的。
可选地,根据本公开一个实施例的卫星通信系统,所述SMF用于向所述发送方网元发送所述卫星承载网的安全策略。
可选地,根据本公开一个实施例的卫星通信系统,所述第二安全模块获取的所述卫星承载网的安全策略,是从所述第二数据包中的安全字段获取的。
可选地,根据本公开一个实施例的卫星通信系统,所述接收方网元获取的所述卫星承载网的安全策略是所述SMF发送给所述接收方网元的。
可选地,根据本公开一个实施例的卫星通信系统,所述SMF用于向所述发送方网元和所述接收方网元发送所述卫星承载网的安全策略。
可选地,根据本公开一个实施例的卫星通信系统,所述第二安全模块获取的所述卫星承载网的安全策略,是从所述接收方网元获取的。
可选地,根据本公开一个实施例的卫星通信系统,所述接收方网元还用于:在所述获取所述卫星承载网的安全策略之后,向所述第二安全模块发送所述卫星承载网的安全策略。
可选地,根据本公开一个实施例的卫星通信系统,所述卫星承载网的安全策略是所述SMF从安全管理实体获取的,所述安全管理实体包括统一数据管理功能UDM。
第二方面,本公开实施例提供一种安全传输方法,应用于接收方网元,所述方法包括:
接收发送方网元通过卫星承载网发送的第二数据包,其中,所述第二数据包的数据包结构中包含安全字段,所述第二数据包是由第一数据包基于SMF提供的卫星承载网的安全策略经过第一安全处理后获得的;
将所述第二数据包发送至第二安全模块,以获取第三数据包,其 中,所述第三数据包中包括所述第一数据包的数据,所述第三数据包是由所述第二数据包基于所述卫星承载网的安全策略经过第二安全处理后获得的;
其中,所述发送方网元和所述接收方网元通过所述卫星承载网进行通信。
可选地,根据本公开一个实施例的安全传输方法,所述第一安全处理包括以下至少一项:机密性保护处理和完整性保护处理,所述第二安全处理包括以下至少一项:解密处理和完整性保护验证处理。
可选地,根据本公开一个实施例的安全传输方法,所述卫星承载网的安全策略包括以下至少一项:
数据安全策略信息,所述数据安全策略信息用于指示所述第一安全处理包括的安全保护处理类型,其中所述安全保护处理类型包括所述机密性保护处理和/或所述完整性保护处理;或
算法信息,所述算法信息用于指示实现所述机密性保护处理的算法和/或实现所述完整性保护处理的算法;或
密钥信息,所述密钥信息用于指示实现所述机密性保护处理的密钥和/或实现所述完整性保护处理的密钥。
可选地,根据本公开一个实施例的安全传输方法,所述发送方网元为卫星基站S-gNB,所述接收方网元为用户面功能UPF,所述第一安全模块为星载安全功能模块,所述第二安全模块为地面站安全功能模块;或
所述发送方网元和所述接收方网元均为卫星基站S-gNB,所述第一安全模块和所述第二安全模块均为星载安全功能模块;或
所述发送方网元为用户面功能UPF,所述接收方网元为卫星基站S-gNB,所述第一安全模块为地面站安全功能模块,所述第二安全模块为星载安全功能模块。
可选地,根据本公开一个实施例的安全传输方法,所述第二数据 包中的安全字段包含所述卫星承载网的安全策略。
可选地,根据本公开一个实施例的安全传输方法,所述方法还包括:
接收SMF发送的所述卫星承载网的安全策略。
可选地,根据本公开一个实施例的安全传输方法,所述获取第三数据包之前,所述方法还包括:
向所述第二安全模块发送所述卫星承载网的安全策略。
第三方面,本公开实施例提供一种接收方网元,包括存储器,收发机,处理器:
存储器,用于存储计算机程序;收发机,用于在所述处理器的控制下收发数据;处理器,用于读取所述存储器中的计算机程序并执行以下操作:
接收发送方网元通过卫星承载网发送的第二数据包,其中,所述第二数据包的数据包结构中包含安全字段,所述第二数据包是由第一数据包基于SMF提供的卫星承载网的安全策略经过第一安全处理后获得的;
将所述第二数据包发送至第二安全模块,以获取第三数据包,其中,所述第三数据包中包括所述第一数据包的数据,所述第三数据包是由所述第二数据包基于所述卫星承载网的安全策略经过第二安全处理后获得的;
其中,所述发送方网元和所述接收方网元通过所述卫星承载网进行通信。
可选地,根据本公开一个实施例的接收方网元,所述第一安全处理包括以下至少一项:机密性保护处理和完整性保护处理,所述第二安全处理包括以下至少一项:解密处理和完整性保护验证处理。
可选地,根据本公开一个实施例的接收方网元,所述卫星承载网的安全策略包括以下至少一项:
数据安全策略信息,所述数据安全策略信息用于指示所述第一安全处理包括的安全保护处理类型,其中所述安全保护处理类型包括所述机密性保护处理和/或所述完整性保护处理;或
算法信息,所述算法信息用于指示实现所述机密性保护处理的算法和/或实现所述完整性保护处理的算法;或
密钥信息,所述密钥信息用于指示实现所述机密性保护处理的密钥和/或实现所述完整性保护处理的密钥。
可选地,根据本公开一个实施例的接收方网元,所述发送方网元为卫星基站S-gNB,所述接收方网元为用户面功能UPF,所述第一安全模块为星载安全功能模块,所述第二安全模块为地面站安全功能模块;或
所述发送方网元和所述接收方网元均为卫星基站S-gNB,所述第一安全模块和所述第二安全模块均为星载安全功能模块;或
所述发送方网元为用户面功能UPF,所述接收方网元为卫星基站S-gNB,所述第一安全模块为地面站安全功能模块,所述第二安全模块为星载安全功能模块。
可选地,根据本公开一个实施例的接收方网元,所述第二数据包中的安全字段包含所述卫星承载网的安全策略。
可选地,根据本公开一个实施例的接收方网元,所述操作还包括:
接收SMF发送的所述卫星承载网的安全策略。
可选地,根据本公开一个实施例的接收方网元,所述获取第三数据包之前,所述操作还包括:
向所述第二安全模块发送所述卫星承载网的安全策略。
第四方面,本公开实施例提供一种安全传输装置,所述装置包括:
第一接收模块,用于接收发送方网元通过卫星承载网发送的第二数据包,其中,所述第二数据包的数据包结构中包含安全字段,所述第二数据包是由第一数据包基于SMF提供的卫星承载网的安全策略 经过第一安全处理后获得的;
第一发送模块,用于将所述第二数据包发送至第二安全模块,以获取第三数据包,其中,所述第三数据包中包括所述第一数据包的数据,所述第三数据包是由所述第二数据包基于所述卫星承载网的安全策略经过第二安全处理后获得的;
其中,所述发送方网元和所述接收方网元通过所述卫星承载网进行通信。
第五方面,本公开实施例提供一种处理器可读存储介质,所述处理器可读存储介质存储有计算机程序,所述计算机程序用于使所述处理器执行第一方面所述的方法。
本公开实施例提供的卫星通信系统、方法、装置、接收方网元及存储介质,通过第一安全模块基于发送方网元拥有的卫星承载网的安全策略对所述第一数据包进行第一安全处理,生成数据包结构中包含安全字段的第二数据包,并由发送方网元将其发送至接收方网元,接收方网元接收到第二数据包后,可以通过第二安全模块,基于获取到的卫星承载网的安全策略对第二数据包进行第二安全处理,获取包含第一数据包的数据的第三数据包,进而实现承载网两端的网元不必进行密钥和安全策略协商即可以对需要传输的数据进行保护,减少安全相关协商的开销,降低卫星通信管理的复杂度。
附图说明
为了更清楚地说明本公开实施例或现有技术中的技术方案,下面将对实施例或现有技术描述中所需要使用的附图作一简单地介绍,显而易见地,下面描述中的附图是本公开的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1是本公开实施例提供的卫星通信实体关系图;
图2是本公开实施例提供的PDU会话用户面协议栈的示意图;
图3是本公开实施例提供的星间路由数据包结构的示意图;
图4是本公开实施例提供的卫星通信系统的结构示意图;
图5是本公开实施例提供的数据安全传输方式的流程示意图;
图6是本公开实施例提供的卫星基站至UPF安全流程的示意图;
图7是本公开实施例提供的卫星基站至卫星基站安全流程的示意图;
图8是本公开实施例提供的UPF至卫星基站安全流程的示意图;
图9是本公开实施例提供的卫星通信用户面数据安全架构的示意图;
图10是本公开实施例提供的数据包结构示意图;
图11是本公开实施例提供的数据传输协议栈的示意图;
图12是本公开实施例提供的安全传输方法的流程示意图;
图13是本公开实施例提供的安全传输装置的结构示意图;
图14是本公开实施例提供的接收方网元的结构示意图。
具体实施方式
本公开实施例中术语“和/或”,描述关联对象的关联关系,表示可以存在三种关系,例如,A和/或B,可以表示:单独存在A,同时存在A和B,单独存在B这三种情况。字符“/”一般表示前后关联对象是一种“或”的关系。
本公开实施例中术语“多个”是指两个或两个以上,其它量词与之类似。
下面将结合本公开实施例中的附图,对本公开实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本公开一部分实施例,并不是全部的实施例。基于本公开中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例, 都属于本公开保护的范围。
本公开实施例提供了卫星通信系统,用以减少安全相关协商的开销,降低卫星通信管理的复杂度。
本公开实施例提供的技术方案可以适用于多种系统,尤其是5G系统。例如适用的系统可以是全球移动通讯(global system of mobile communication,GSM)系统、码分多址(code division multiple access,CDMA)系统、宽带码分多址(Wideband Code Division Multiple Access,WCDMA)通用分组无线业务(general packet radio service,GPRS)系统、长期演进(long term evolution,LTE)系统、LTE频分双工(frequency division duplex,FDD)系统、LTE时分双工(time division duplex,TDD)系统、高级长期演进(long term evolution advanced,LTE-A)系统、通用移动系统(universal mobile telecommunication system,UMTS)、全球互联微波接入(worldwide interoperability for microwave access,WiMAX)系统、5G新空口(New Radio,NR)系统等。这多种系统中均包括终端设备和网络设备。系统中还可以包括核心网部分,例如演进的分组系统(Evloved Packet System,EPS)、5G系统(5GS)等。
本公开实施例涉及的终端设备,可以是指向用户提供语音和/或数据连通性的设备,具有无线连接功能的手持式设备、或连接到无线调制解调器的其他处理设备等。在不同的系统中,终端设备的名称可能也不相同,例如在5G系统中,终端设备可以称为用户设备(User Equipment,UE)。无线终端设备可以经无线接入网(Radio Access Network,RAN)与一个或多个核心网(Core Network,CN)进行通信,无线终端设备可以是移动终端设备,如移动电话(或称为“蜂窝”电话)和具有移动终端设备的计算机,例如,可以是便携式、袖珍式、手持式、计算机内置的或者车载的移动装置,它们与无线接入网交换语言和/或数据。例如,个人通信业务(Personal Communication Service, PCS)电话、无绳电话、会话发起协议(Session Initiated Protocol,SIP)话机、无线本地环路(Wireless Local Loop,WLL)站、个人数字助理(Personal Digital Assistant,PDA)等设备。无线终端设备也可以称为系统、订户单元(subscriber unit)、订户站(subscriber station),移动站(mobile station)、移动台(mobile)、远程站(remote station)、接入点(access point)、远程终端设备(remote terminal)、接入终端设备(access terminal)、用户终端设备(user terminal)、用户代理(user agent)、用户装置(user device),本公开实施例中并不限定。
本公开实施例涉及的网络设备,可以是基站,该基站可以包括多个为终端提供服务的小区。根据具体应用场合不同,基站又可以称为接入点,或者可以是接入网中在空中接口上通过一个或多个扇区与无线终端设备通信的设备,或者其它名称。网络设备可用于将收到的空中帧与网际协议(Internet Protocol,IP)分组进行相互更换,作为无线终端设备与接入网的其余部分之间的路由器,其中接入网的其余部分可包括网际协议(IP)通信网络。网络设备还可协调对空中接口的属性管理。例如,本公开实施例涉及的网络设备可以是全球移动通信系统(Global System for Mobile communications,GSM)或码分多址接入(Code Division Multiple Access,CDMA)中的网络设备(Base Transceiver Station,BTS),也可以是带宽码分多址接入(Wide-band Code Division Multiple Access,WCDMA)中的网络设备(NodeB),还可以是长期演进(long term evolution,LTE)系统中的演进型网络设备(evolutional Node B,eNB或e-NodeB)、5G网络架构(next generation system)中的5G基站(gNB),也可以是家庭演进基站(Home evolved Node B,HeNB)、中继节点(relay node)、家庭基站(femto)、微微基站(pico)等,本公开实施例中并不限定。在一些网络结构中,网络设备可以包括集中单元(centralized unit,CU)节点和分布单元(distributed unit,DU)节点,集中单元和分布单元也可以地理上分 开布置。
首先对以下内容进行介绍:
(1)图1是本公开实施例提供的卫星通信实体关系图,如图1所示,基于5G技术的卫星通信系统,可以有以下a)-b)共2种通信模式:
a)UE数据通过核心网实现数据转发至目的地,也即数据出网业务。
b)UE数据不通过核心网,直接由卫星实现数据转发至另一个UE,也即卫星终端对终端(Terminal to Terminal,T2T)业务。
当实现数据安全传输时:
出网业务数据安全可分为:UE(起始)-卫星(起始),卫星(起始)-卫星(目的),和卫星(目的)-地面站/核心网等3段。
T2T业务数据安全可分为:UE(起始)-卫星(起始),卫星(起始)-卫星(目的),和卫星(目的)-UE(目的)等3段。
(2)通信网络中PDU会话用户面协议栈;
图2是本公开实施例提供的PDU会话用户面协议栈的示意图,如图2所示。在通信系统中,UPF通常使用通用无线分组业务隧道协议(General packet radio service Tunneling Protocol,GTP)隧道来实现。GTPtunnel endpoint identifier)隧道是双向的,由源互联网协议(Internet Protocol,IP)地址、目的IP地址、用户数据报协议(User Datagram Protocol,UDP)端口号、源GTP隧道端点标识(Tunnel Endpoint Identifier,TEID),目的GTP TEID来标识。
图3是本公开实施例提供的星间路由数据包结构的示意图,如图3所示,星间路由数据包包括:
UE处理的数据包:目的IP地址,源IP地址,有效载荷(Payload);
网元处理的数据包(卫星基站S-gNB或S-UPF/UPF):目的网元IP地址,源网元IP地址,GTP-U Header,UE数据包;
星间路由数据包:L2标签,卫星基站S-gNB或UPF处理的数据包。
(3)UE用户面数据加密保护;
其中,用户面数据分以下两段:
空口部分的用户面数据保护:即UE至基站gNB的机密性和完整性保护。该空口安全基于网络SMF提供给gNB的安全策略决定是否开启,以及开启哪些安全功能。
基站gNB至核心网网元UPF的安全保护:该保护采用互联网安全协议(Internet Protocol Security,IPSec)安全机制。网络不提供针对特定UE的安全策略,也即对所有用户数据均提供安全保护。
针对出网业务的用户数据,S-gNB与地面UPF建立GTP-U隧道,用户面数据将在GTP-U隧道里进行传输。用户面数据包格式如图3所示。L2标签用于星间路由。网元IP地址主要用于网元之间的GTP-U隧道的路由。
典型的数据加密方式是采用3段加密方式:UE-卫星,卫星-卫星,卫星-陆地站。也就是说,分别进行3次加解密。其中,UE-卫星可通过已有的UE-基站(S-gNB)安全机制实现;卫星-卫星可通过星间通信安全机制实现,也即,对GTP-U信息进行加密,并利用星间路由机制将信息路由至目的卫星;目的卫星对信息解密后获得GTP-U中的路由信息,据此确定下一跳的目的,然后将GTP-U数据再次加密,并发送至陆地站。这种方式的缺点是增加了卫星资源的消耗。
若实现以PDU会话为单位,按需开启卫星至陆地站之间的安全通信能力,则意味需要将PDU会话安全策略提供给卫星和陆地站,并在两者之间建立安全关联。卫星的通信体制决定了承载网中的数据通信必须分为星间通信和星地通信2段。若直接将3段安全机制中的后2段进行简单合并,则意味着数据到达目的卫星后,因GTP-U中的路由信息加密,目的卫星不能确定下一跳的地址。另外,5G核心 网并没有至承载网网元陆地站的接口(陆地站对核心网是透明的),因此PDU会话安全策略不能提供给卫星陆地站。
为了克服上述缺陷,本公开实施例提出了一种卫星通信系统。
图4是本公开实施例提供的卫星通信系统的结构示意图,如图4所示,该系统400包括:发送方网元410、所述发送方网元对应的第一安全模块420、接收方网元430、和所述接收方网元对应的第二安全模块440,其中,所述发送方网元410和所述接收方网元430通过卫星承载网进行通信;其中:
所述第一安全模块420用于接收所述发送方网元发送的第一数据包和所述卫星承载网的安全策略,并基于所述卫星承载网的安全策略对所述第一数据包进行第一安全处理,生成第二数据包,所述第二数据包的数据包结构中包含安全字段,并将所述第二数据包发送给所述发送方网元;
所述第二安全模块440用于接收所述接收方网元发送的所述第二数据包,获取所述卫星承载网的安全策略,并基于所述卫星承载网的安全策略对所述第二数据包进行第二安全处理,获得第三数据包,所述第三数据包中包括所述第一数据包的数据,并将所述第三数据包发送给所述接收方网元;
所述发送方网元410用于生成所述第一数据包和接收会话管理功能SMF发送的所述卫星承载网的安全策略,并将所述第一数据包和所述卫星承载网的安全策略发送给所述第一安全模块,以获得所述第二数据包,并将所述第二数据包通过所述卫星承载网发送给所述接收方网元;
所述接收方网元430用于接收所述发送方网元通过所述卫星承载网发送的所述第二数据包,并获取所述卫星承载网的安全策略,并将所述第二数据包和所述卫星承载网的安全策略发送至所述第二安全模块,以获取所述第三数据包。
具体地,若实现按需开启卫星承载网的安全通信能力,比如卫星至陆地站之间的安全通信能力,则意味需要将安全策略提供给卫星和陆地站,并在两者之间建立安全关联。因此,为了实现承载网两端的网元不必进行密钥和安全策略协商即可以对需要传输的数据进行保护,本公开实施例对SMF功能进行了扩展,SMF在为UE建立PDU会话时可以向与承载网的连接的发送方网元,提供卫星承载网的安全策略,应用于卫星承载网数据传输。
具体地,发送方网元可以首先生成第一数据包,第一数据包中包括发送方网元需要发送的数据;在发送方网元接收到卫星承载网的安全策略后,可以将第一数据包和卫星承载网的安全策略发送第一安全模块;
具体地,该第一安全模块在获取到第一数据包和卫星承载网的安全策略后,可以基于该卫星承载网的安全策略对第一数据包进行第一安全处理,生成第二数据包,所述第二数据包的数据包结构中包含安全字段,该安全字段可以为空或可以包括卫星承载网的安全策略;
具体地,该第一安全模块可以是一个与发送方网元通信连接的实体模块,也可以是一个可以实现上述功能的虚拟模块。
具体地,在第一安全模块生成第二数据包后,可以将所述第二数据包发送给所述发送方网元;发送方网元获取到第二数据包后,可以将第二数据包通过卫星承载网发送给接收方网元;
具体地,本公开实施例中,卫星承载网不参与数据的安全保护相关工作。
具体地,在发送方网元将第二数据包发送给接收方网元后,接收方网元可以将第二数据包发送至第二安全模块;
具体地,第二安全模块可以获取第二数据包,还可以获取卫星承载网的安全策略,则可以基于卫星承载网的安全策略,对第二数据包进行第二安全处理,可以获取第三数据,该第三数据包括第一数据中 的数据,即第二安全处理可以理解为对第一安全处理后的数据包的恢复处理。
具体地,本公开实施例通过发送方网元和接收方网元获取到的卫星承载网的安全策略,发送方网元通过第一安全模块基于该卫星承载网的安全策略对向卫星承载网发送的数据包进行第一安全处理,接收方网元通过第二安全模块基于该卫星承载网的安全策略对从承载网接收的数据包进行第二安全处理,即第二安全模块基于卫星承载网的安全策略可以直接确定如何对接收到的第二数据包进行安全处理,从而实现按需提供数据安全传输的能力。
具体地,本公开实施例提供的卫星通信系统可以实现上述流程的数据安全传输方式,使卫星承载网两端的网元不必进行密钥和安全策略协商,即可以对需要传输的数据进行机密性和/或完整性保护。
本公开实施例提供的卫星通信系统,通过第一安全模块基于发送方网元拥有的卫星承载网的安全策略对所述第一数据包进行第一安全处理,生成数据包结构中包含安全字段的第二数据包,并由发送方网元将其发送至接收方网元,接收方网元接收到第二数据包后,可以通过第二安全模块,基于获取到的卫星承载网的安全策略对第二数据包进行第二安全处理,获取包含第一数据包的数据的第三数据包,进而实现承载网两端的网元不必进行密钥和安全策略协商即可以对需要传输的数据进行保护,减少安全相关协商的开销,降低卫星通信管理的复杂度。
可选地,所述第一安全处理包括以下至少一项:机密性保护处理和完整性保护处理,所述第二安全处理包括以下至少一项:解密处理和完整性保护验证处理。
具体地,在卫星系统中,由于卫星资源有限,需要按需对用户数据进行机密性和/或完整性保护。
可选地,第一安全处理可以包括机密性保护处理,相应的,第二 第二安全处理可以包括解密处理;
可选地,第一安全处理可以包括完整性保护处理,相应的,第二第二安全处理可以包括完整性保护验证处理;
可选地,第一安全处理可以包括机密性保护处理和完整性保护处理,相应的,第二安全处理可以包括解密处理和完整性保护验证处理。
可选地,所述卫星承载网的安全策略包括以下至少一项:
数据安全策略信息,所述数据安全策略信息用于指示所述第一安全处理包括的安全保护处理类型,其中所述安全保护处理类型包括所述机密性保护处理和/或所述完整性保护处理;或
算法信息,所述算法信息用于指示实现所述机密性保护处理的算法和/或实现所述完整性保护处理的算法;或
密钥信息,所述密钥信息用于指示实现所述机密性保护处理的密钥和/或实现所述完整性保护处理的密钥。
具体地,卫星承载网的安全策略可以包括以下任一项或任意多项:
数据安全策略信息,用于指示第一安全处理包括的安全保护处理类型,所述安全保护处理类型包括以下至少一项:所述机密性保护处理和所述完整性保护处理,即用于指示是否需要对第一数据处理进行机密性保护处理,以及是否对第一数据处理进行完整性保护处理;
或者,
算法信息,用于指示实现所述机密性保护处理的算法和实现所述完整性保护处理的算法;或
密钥信息,所述密钥信息用于指示实现所述机密性保护处理的密钥和实现所述完整性保护处理的密钥。
可选地,所述第一安全模块具体用于:接收所述发送方网元发送的第一数据包和所述卫星承载网的安全策略,基于所述卫星承载网的安全策略中的所述数据安全策略信息,确定所述安全保护处理类型,并基于所述算法信息中与所述安全保护处理类型对应的算法,以及所 述密钥信息中与所述安全保护处理类型对应的密钥,实现对所述第一数据包的第一安全处理,生成所述第二数据包,并将所述第二数据包发送给所述发送方网元。
具体地,在第一安全模块基于卫星承载网的安全策略,对第一数据包进行第一安全处理,获得第二数据包时,可以基于所述卫星承载网的安全策略中的所述数据安全策略信息,确定所述安全保护处理类型,并基于所述算法信息中与所述安全保护处理类型对应的算法,以及所述密钥信息中与所述安全保护处理类型对应的密钥,实现对所述第一数据包的第一安全处理,生成所述第二数据包。
可选地,所述第二安全模块具体用于:接收所述接收方网元发送的所述第二数据包,基于所述卫星承载网的安全策略中的所述数据安全策略信息,确定所述安全保护处理类型,并基于所述算法信息中与所述安全保护处理类型对应的算法,以及所述密钥信息中与所述安全保护处理类型对应的密钥,实现对所述第二数据包的第二安全处理,获得所述第三数据包,并将所述第三数据包发送给所述接收方网元。
具体地,在第二安全模块基于卫星承载网的安全策略,对第二数据包进行第二安全处理,获得第三数据包时,可以基于所述卫星承载网的安全策略中的所述数据安全策略信息,确定所述安全保护处理类型,并基于所述算法信息中与所述安全保护处理类型对应的算法,以及所述密钥信息中与所述安全保护处理类型对应的密钥,实现对所述第二数据包的第二安全处理,获得所述第三数据包。
具体地,图5是本公开实施例提供的数据安全传输方式的流程示意图,如图5所示,数据安全传输的流程包括如下步骤(1)-(6):
(1)UE请求建立PDU会话;
(2)SMF依据UE的签约信息获取适用于该PDU会话的卫星承载网的安全策略,该卫星承载网的安全策略描述的信息可以包括承载网安全保护使用不同的算法和密钥信息;
(3)SMF基于获取的适用于该PDU会话的承载网安全策略生成承载网用户面上行和下行数据安全策略,并将安全策略分别发送至PDU会话隧道中与承载网两端连接的第三代伙伴计划协议(3rd Generation Partnership Project,3GPP)网元,也即S-gNB和/或UPF;
(4)数据发送时,发送方网元执行如下(a)-(c)所示的操作:
(a)生成欲发送至接收方网元的第一数据包;
(b)基于所述卫星承载网的安全策略中的所述数据安全策略信息,确定所述安全保护处理类型;
(c)基于所述算法信息中与所述安全保护处理类型对应的算法,和所述密钥信息中与所述安全保护处理类型对应的密钥,实现对所述第一数据包的第一安全处理,生成第二数据包;
(5)发送方网元将第二数据包发送至接收方网元;
(6)接收方网元执行如下(d)-(e)所示的操作:
(d)基于所述卫星承载网的安全策略中的所述数据安全策略信息,确定所述安全保护处理类型;
(e)基于所述算法信息中与所述安全保护处理类型对应的算法,和所述密钥信息中与所述安全保护处理类型对应的密钥,实现对所述第二数据包的第二安全处理,获得第三数据包。
可选地,所述发送方网元为卫星基站S-gNB,所述接收方网元为用户面功能UPF,所述第一安全模块为星载安全功能模块,所述第二安全模块为地面站安全功能模块;或
所述发送方网元和所述接收方网元均为卫星基站S-gNB,所述第一安全模块和所述第二安全模块均为星载安全功能模块;或
所述发送方网元为用户面功能UPF,所述接收方网元为卫星基站S-gNB,所述第一安全模块为地面站安全功能模块,所述第二安全模块为星载安全功能模块。
具体地,本公开实施例中的卫星承载网两端的发送方网元和接收 方网元可以至少有一方网元为卫星基站;
可选地,所述发送方网元为卫星基站S-gNB,所述接收方网元为用户面功能UPF,所述第一安全模块为星载安全功能模块,所述第二安全模块为地面站安全功能模块;
图6是本公开实施例提供的卫星基站至UPF安全流程的示意图,如图6所示,其中在步骤1-步骤3为由空口用户面(User Plane,UP)安全。为实现卫星承载网部分按需提供数据安全传输,基于SMF提供的卫星承载网的安全策略,在步骤4-步骤5实现对用户面数据(第一数据包)进行第一安全处理获得第二数据包,然后第二数据包在承载网上传输;在UPF处,经步骤11至步骤12,对第二数据包进行第二安全处理,获得数据明文;随后由已有协议继续进行相关处理。
可选地,所述发送方网元和所述接收方网元均为卫星基站S-gNB,所述第一安全模块和所述第二安全模块均为星载安全功能模块;
图7是本公开实施例提供的卫星基站至卫星基站安全流程的示意图,如图7所示,该流程适用于卫星通信环境下的T2T(终端至终端)安全;其中在步骤1-步骤3为由空口UP安全。为实现卫星承载网部分按需提供数据安全传输,基于SMF提供的卫星承载网的安全策略,在步骤4-步骤5实现对用户面数据(第一数据包)进行第一安全处理获得第二数据包,然后第二数据包在承载网上传输;在接收方的卫星基站处,经步骤11至步骤12,对第二数据包进行第二安全处理,获得数据明文;随后由已有协议继续进行相关处理。
可选地,所述发送方网元为用户面功能UPF,所述接收方网元为卫星基站S-gNB,所述第一安全模块为地面站安全功能模块,所述第二安全模块为星载安全功能模块。
图8是本公开实施例提供的UPF至卫星基站安全流程的示意图,如图8所示,其中在步骤1-步骤2为UPF对用户面数据(第一数据包)进行第一安全处理,获得第二数据包,然后在承载网上传输;在 卫星基站S-gNB处,经步骤8至步骤9,对第二数据包进行第二安全处理,获得数据明文;随后由已有协议继续进行相关处理。
图9是本公开实施例提供的卫星通信用户面数据安全架构的示意图,以图9中的卫星通信用户面数据安全架构为例,如图9所示,卫星通信系统所应用的卫星通信用户面数据安全架构可以由如下功能实体或模块组成:
卫星基站(S-gNB):卫星上实现基站功能的功能实体;
卫星UPF(S-UPF):卫星上实现UPF功能的实体;
星间通信功能:负责卫星间数据通信的功能实体;
星载安全功能模块:卫星上负责卫星承载网安全相关操作的功能实体或虚拟模块;
馈电通信功能:卫星上负责卫星与地面站(信关站)间数据通信的功能实体;
地面站(信关站):地面上负责与卫星进行通信的实体。核心网通过信关站与卫星相连接,并进一步与UE相连接;
核心网或信关站中部署的UPF;
与UPF连接的地面站安全功能模块:地面站负责卫星承载网安全相关操作的功能实体或虚拟模块;
SMF:负责承载网两端3GPP网元用户面安全策略的分发。
可选地,所述第一数据包的数据包结构包括GTP-U部分和安全字段部分,所述GTP-U部分包括目的网元IP地址部分,源网元IP地址部分,UDP端口部分,GTP-U Header部分,目的IP地址部分、源IP地址部分和Payload部分。
具体地,本公开实施例中对第一数据包进行第一安全保护处理获得第二数据包,通过在数据包结构中加入安全字段,对传统的GTP-U数据包结构进行扩展,提出了新的数据包结构。
图10是本公开实施例提供的数据包结构示意图,如图10所示, 第一数据包的数据包结构包括GTP-U部分和安全字段部分,所述GTP-U部分包括目的网元IP地址部分,源网元IP地址部分,UDP端口部分,GTP-U Header部分,目的IP地址部分、源IP地址部分和Payload部分。
可选地,处理所述第二数据包的协议层为卫星承载网数据传输协议栈中的安全层,所述安全层在GTP-U层与PDU Layer层之间。
具体地,为实现按需提供卫星通信承载网数据安全传输的能力和减少卫星承载网分段处理数据安全的负担和开销,本公开实施例对传输用户面(UP)数据的网元之间的数据传输协议进行了扩展,可以增加一个安全层,从而使承载网不必处理数据安全相关的事项。
图11是本公开实施例提供的数据传输协议栈的示意图,为实现承载网数据安全传输,对数据传输协议栈增加了一个安全层,该层在GTP-U层与PDU Layer层之间。新的协议栈如图11所示,该层可以由生成和处理第一数据包和/或第二数据包的卫星基站S-gNB和/或UPF处理。
可选地,所述第一安全模块,具体用于以下至少一项:
若所述安全保护处理类型包括所述机密性保护处理,则对所述第一数据包的数据包结构中的所述目的IP地址部分、所述源IP地址部分和所述Payload部分进行机密性保护处理,获得密文;
若所述安全保护处理类型包括所述完整性保护处理,则对所述第一数据包的数据包结构中的所述目的网元IP地址部分、所述源网元IP地址部分、所述UDP端口部分、所述GTP-U Header部分、所述安全字段部分、所述目的IP地址部分、所述源IP地址部分和所述Payload部分进行完整性保护处理;
若所述安全保护处理类型包括所述机密性保护处理和所述完整性保护处理,则对所述第一数据包的数据包结构中的所述目的IP地址部分、所述源IP地址部分和所述Payload部分进行机密性保护处理, 获得密文,在所述机密性保护处理后,对所述第一数据包的数据包结构中的目的网元IP地址部分,所述源网元IP地址部分,所述UDP端口部分,所述GTP-U Header部分,所述安全字段部分,以及所述密文进行完整性保护。
具体地,如图7所示,L2标签用于星间路由;目的网元IP地址和源网元IP地址用于S-gNB和UPF之间路由或者两个S-gNB之间的路由;IP地址,源IP地址和Payload为UE承载,可被机密性保护即加密处理;除L2标签外的其他数据被完整性保护。
可选地,第一安全模块在对第一数据包进行第一安全处理时,若所述安全保护处理类型包括所述机密性保护处理,则在对第一数据包进行第一安全处理时,可以对所述第一数据包的数据包结构中的目的IP地址部分、所述源IP地址部分和所述Payload部分进行机密性保护处理,即进行加密处理,获得密文;
可选地,第一安全模块在对第一数据包进行第一安全处理时,若所述安全保护处理类型包括所述完整性保护处理,则对第一数据包的数据包结构中的所述目的网元IP地址部分、所述源网元IP地址部分、所述UDP端口部分、所述GTP-U Header部分、所述安全字段部分、所述目的IP地址部分、所述源IP地址部分和所述Payload部分进行完整性保护处理;
可选地,第一安全模块在对第一数据包进行第一安全处理时,若所述安全保护处理类型同时包括所述机密性保护处理和所述完整性保护处理,可以先执行机密性处理再执行完整性保护处理,则可以首先对所述第一数据包的数据包结构中的所述目的IP地址部分、所述源IP地址部分和所述Payload部分进行机密性保护处理,获得密文;在所述机密性保护处理后,可以再对所述第一数据包的数据包结构中的目的网元IP地址部分,所述源网元IP地址部分,所述UDP端口部分,所述GTP-U Header部分,所述安全字段部分,以及机密性保 护处理时获得的密文进行完整性保护。
可选地,所述第二安全模块,具体用于以下至少一项:
若所述安全保护处理类型包括所述机密性保护处理,则对第二数据包的数据包结构中的密文进行解密处理,获得所述目的IP地址部分、所述源IP地址部分和所述Payload部分;
若所述安全保护处理类型包括所述完整性保护处理,则对第二数据包的数据包结构中的目的网元IP地址部分、所述源网元IP地址部分、所述UDP端口部分、所述GTP-U Header部分、所述安全字段部分、所述目的IP地址部分,所述源IP地址部分以及所述Payload部分进行完整性保护验证处理;
若所述安全保护处理类型包括所述机密性保护处理和所述完整性保护处理,则对第二数据包的数据包结构中的目的网元IP地址部分、所述源网元IP地址部分、所述UDP端口部分、所述GTP-U Header部分、所述安全字段部分、以及密文进行完整性保护验证处理,在所述完整性保护验证处理后,对密文进行解密处理,获得所述目的IP地址部分、所述源IP地址部分和所述Payload部分。
可选地,第二安全模块在对第二数据包进行第二安全处理时,若安全保护处理类型包括所述机密性保护处理,则对第二数据包的数据包结构中的密文进行解密处理,获得所述目的IP地址部分、所述源IP地址部分和所述Payload部分;
可选地,第二安全模块在对第二数据包进行第二安全处理时,若所述安全保护处理类型包括所述完整性保护处理,则对第二数据包的数据包结构中的目的网元IP地址部分、所述源网元IP地址部分、所述UDP端口部分、所述GTP-U Header部分、所述安全字段部分、所述目的IP地址部分,所述源IP地址部分以及所述Payload部分进行完整性保护验证处理;
可选地,第二安全模块在对第二数据包进行第二安全处理时,若 所述安全保护处理类型包括所述机密性保护处理和所述完整性保护处理,首先进行完整性保护验证处理,再进行解密处理;即首先则对第二数据包的数据包结构中的目的网元IP地址部分、所述源网元IP地址部分、所述UDP端口部分、所述GTP-U Header部分、所述安全字段部分、以及密文进行完整性保护验证处理,在所述完整性保护验证处理后,对所述密文进行解密处理,获得所述目的IP地址部分、所述源IP地址部分和所述Payload部分。
可选地,所述第二数据包中的安全字段包含所述卫星承载网的安全策略,所述接收方网元获取的所述卫星承载网的安全策略是被携带在所述第二数据包中由所述发送方网元发送至所述接收方网元的。
可选地,可以通过第二数据包中的安全字段直接携带卫星承载网的安全策略的方式使卫星承载网的安全策略传输至接收方网元。
具体地,所述第二数据包中的安全字段包含所述卫星承载网的安全策略。这种方式需要对安全字段里的内容进行修改。
本公开实施例中,可以通过安全字段将密钥和安全策略(即卫星承载网的安全策略)集成至所传输的第二数据包中。接收方网元可以通过该安全字段确定如何对接收到的第二数据包进行安全处理,从而减少了安全相关协商的开销,降低了卫星通信管理的复杂度。
可选地,所述SMF用于向所述发送方网元发送所述卫星承载网的安全策略。
具体地,所述第二数据包中的安全字段包含所述卫星承载网的安全策略。这种方式需要对安全字段里的内容进行修改。相应的,SMF只需要将安全策略发送至数据的发送方即可。接收方网元可以依据第二数据包中包含的安全字段确定如何处理第二数据包中的安全数据。
可选地,所述第二安全模块获取的所述卫星承载网的安全策略,是从所述第二数据包中的安全字段获取的。
可选地,在第二数据包的安全字段中携带卫星承载网的安全策略 的情况下,接收方网元在向第二安全模块发送第二数据包后,第二安全模块可以直接从第二数据包的安全字段获取卫星承载网的安全策略。
可选地,所述接收方网元获取的所述卫星承载网的安全策略是所述SMF发送给所述接收方网元的。
具体地,第二数据包中的安全字段可以为空,即第二数据包中不携带卫星承载网的安全策略。因此不需要对第一数据包中的安全字段进行修改。相应的,SMF需要将安全策略分发至数据的发送方和接收方,以便双方能够正确处理相关数据。
具体地,第二数据包中的安全字段也可以不为空,即第二数据包中也可以携带卫星承载网的安全策略。相应地,SMF也可以将安全策略分发至数据的发送方和接收方,以便双方能够正确处理相关数据。
可选地,所述SMF用于向所述发送方网元和所述接收方网元发送所述卫星承载网的安全策略。
具体地,第二数据包中的安全字段可以为空,即第二数据包中不携带卫星承载网的安全策略。因此不需要对第一数据包中的安全字段进行修改。相应的,需要将安全策略分发至发送方网元和接收方网元,以便双方能够正确处理相关数据,且有效避免安全相关协商带来的资源浪费。
可选地,所述第二安全模块获取的所述卫星承载网的安全策略,是从所述接收方网元获取的。
可选地,在第二数据包的安全字段中不携带卫星承载网的安全策略的情况下,接收方网元在向第二安全模块发送第二数据包时,还可以向第二安全模块发送从SMF获取的卫星承载网的安全策略。
可选地,所述接收方网元还用于:在所述获取所述卫星承载网的安全策略之后,向所述第二安全模块发送所述卫星承载网的安全策略。
可选地,接收方网元在接收到从SMF发送的卫星承载网的安全 策略之后,可以向第二安全模块发送所述卫星承载网的安全策略,以使第二安全模块基于卫星承载网的安全策略对第二数据包进行第二安全处理。
可选地,所述卫星承载网的安全策略是所述SMF从安全管理实体获取的,所述安全管理实体包括统一数据管理功能UDM。
具体地,安全管理实体包括UDM或其他可以生成卫星承载网的安全策略的网元;
具体地,SMF可以预先从统一数据管理功能UDM或其他可以生成卫星承载网的安全策略的网元获取卫星承载网的安全策略。
本公开实施例提供的卫星通信系统,通过第一安全模块基于发送方网元拥有的卫星承载网的安全策略对所述第一数据包进行第一安全处理,生成数据包结构中包含安全字段的第二数据包,并由发送方网元将其发送至接收方网元,接收方网元接收到第二数据包后,可以通过第二安全模块,基于获取到的卫星承载网的安全策略对第二数据包进行第二安全处理,获取包含第一数据包的数据的第三数据包,进而实现承载网两端的网元不必进行密钥和安全策略协商即可以对需要传输的数据进行保护,减少安全相关协商的开销,降低卫星通信管理的复杂度。
图12是本公开实施例提供的安全传输方法的流程示意图,该方法应用于接收方网元,如图12所示,该方法包括如下流程:
步骤1200,接收发送方网元通过卫星承载网发送的第二数据包,其中,所述第二数据包的数据包结构中包含安全字段,所述第二数据包是由第一数据包基于SMF提供的卫星承载网的安全策略经过第一安全处理后获得的;
步骤1210,将所述第二数据包发送至第二安全模块,以获取第三数据包,其中,所述第三数据包中包括所述第一数据包的数据,所述第三数据包是由所述第二数据包基于所述卫星承载网的安全策略 经过第二安全处理后获得的;
其中,所述发送方网元和所述接收方网元通过所述卫星承载网进行通信。
具体地,若实现按需开启卫星承载网的安全通信能力,比如卫星至陆地站之间的安全通信能力,则意味需要将安全策略提供给卫星和陆地站,并在两者之间建立安全关联。因此,为了实现承载网两端的网元不必进行密钥和安全策略协商即可以对需要传输的数据进行保护,本公开实施例对SMF功能进行了扩展,SMF在为UE建立PDU会话时可以向与承载网的连接的发送方网元,提供卫星承载网的安全策略,应用于卫星承载网数据传输。
具体地,接收方网元可以接收发送方网元通过卫星承载网发送的第二数据包,其中,第二数据包是由第一数据包基于SMF提供的卫星承载网的安全策略经过第一安全处理后获得的;
具体地,由第一数据包基于SMF提供的卫星承载网的安全策略经过第一安全处理后获得第二数据包的方式可以如下(1)-(3)所示:
(1)发送方网元可以首先生成第一数据包,第一数据包中包括发送方网元需要发送的数据;在发送方网元接收到卫星承载网的安全策略后,可以将第一数据包和卫星承载网的安全策略发送第一安全模块;
(2)该第一安全模块在获取到第一数据包和卫星承载网的安全策略后,可以基于该卫星承载网的安全策略对第一数据包进行第一安全处理,生成第二数据包,所述第二数据包的数据包结构中包含安全字段,该安全字段可以为空或可以包括卫星承载网的安全策略;
该第一安全模块可以是一个与发送方网元通信连接的实体模块,也可以是一个可以实现上述功能的虚拟模块。
(3)在第一安全模块生成第二数据包后,可以将所述第二数据 包发送给所述发送方网元;发送方网元获取到第二数据包后,可以将第二数据包通过卫星承载网发送给接收方网元;
具体地,本公开实施例中,卫星承载网不参与数据的安全保护相关工作。
具体地,在接收方网元接收到第二数据包后,接收方网元可以将第二数据包发送至第二安全模块,以获取第三数据包,其中,所述第三数据包中包括所述第一数据包的数据,所述第三数据包是由所述第二数据包基于所述卫星承载网的安全策略经过第二安全处理后获得的;
具体地,由所述第二数据包基于所述卫星承载网的安全策略经过第二安全处理后获得第三数据包的方式可以如下所示:
在接收方网元接收到第二数据包后,接收方网元可以将第二数据包发送至第二安全模块,第二安全模块可以获取第二数据包,还可以获取卫星承载网的安全策略,则可以基于卫星承载网的安全策略,对第二数据包进行第二安全处理,可以获取第三数据,该第三数据包括第一数据中的数据,即第二安全处理可以理解为对第一安全处理后的数据包的恢复处理。
其中,第二安全模块基于卫星承载网的安全策略,对第二数据包进行第二安全处理,获取第三数据的方式可以如下所示:
在第二安全模块基于卫星承载网的安全策略,对第二数据包进行第二安全处理,获得第三数据包时,可以基于所述卫星承载网的安全策略中的所述数据安全策略信息,确定所述安全保护处理类型,并基于所述算法信息中与所述安全保护处理类型对应的算法,以及所述密钥信息中与所述安全保护处理类型对应的密钥,实现对所述第二数据包的第二安全处理,获得所述第三数据包。
具体地,本公开实施例通过发送方网元和接收方网元获取到的卫星承载网的安全策略,发送方网元通过第一安全模块基于该卫星承载 网的安全策略对向卫星承载网发送的数据包进行第一安全处理,接收方网元通过第二安全模块基于该卫星承载网的安全策略对从承载网接收的数据包进行第二安全处理,即第二安全模块基于卫星承载网的安全策略可以直接确定如何对接收到的第二数据包进行安全处理,从而实现按需提供数据安全传输的能力。
具体地,本公开实施例提供的卫星通信系统可以实现上述流程的数据安全传输方式,使卫星承载网两端的网元不必进行密钥和安全策略协商,即可以对需要传输的数据进行机密性和/或完整性保护。
本公开实施例提供的卫星通信方法,通过第一安全模块基于发送方网元拥有的卫星承载网的安全策略对所述第一数据包进行第一安全处理,生成数据包结构中包含安全字段的第二数据包,并由发送方网元将其发送至接收方网元,接收方网元接收到第二数据包后,可以通过第二安全模块,基于获取到的卫星承载网的安全策略对第二数据包进行第二安全处理,获取包含第一数据包的数据的第三数据包,进而实现承载网两端的网元不必进行密钥和安全策略协商即可以对需要传输的数据进行保护,减少安全相关协商的开销,降低卫星通信管理的复杂度。
可选地,所述第一安全处理包括以下至少一项:机密性保护处理和完整性保护处理,所述第二安全处理包括以下至少一项:解密处理和完整性保护验证处理。
具体地,在卫星系统中,由于卫星资源有限,需要按需对用户数据进行机密性和/或完整性保护。
可选地,第一安全处理可以包括机密性保护处理,相应的,第二第二安全处理可以包括解密处理;
可选地,第一安全处理可以包括完整性保护处理,相应的,第二第二安全处理可以包括完整性保护验证处理;
可选地,第一安全处理可以包括机密性保护处理和完整性保护处 理,相应的,第二安全处理可以包括解密处理和完整性保护验证处理。
可选地,所述卫星承载网的安全策略包括以下至少一项:
数据安全策略信息,所述数据安全策略信息用于指示所述第一安全处理包括的安全保护处理类型,其中所述安全保护处理类型包括所述机密性保护处理和/或所述完整性保护处理;或
算法信息,所述算法信息用于指示实现所述机密性保护处理的算法和/或实现所述完整性保护处理的算法;或
密钥信息,所述密钥信息用于指示实现所述机密性保护处理的密钥和/或实现所述完整性保护处理的密钥。
具体地,卫星承载网的安全策略可以包括以下任一项或任意多项:
数据安全策略信息,用于指示第一安全处理包括的安全保护处理类型,所述安全保护处理类型包括以下至少一项:所述机密性保护处理和所述完整性保护处理,即用于指示是否需要对第一数据处理进行机密性保护处理,以及是否对第一数据处理进行完整性保护处理;
或者,
算法信息,用于指示实现所述机密性保护处理的算法和实现所述完整性保护处理的算法;或
密钥信息,所述密钥信息用于指示实现所述机密性保护处理的密钥和实现所述完整性保护处理的密钥。
可选地,所述发送方网元为卫星基站S-gNB,所述接收方网元为用户面功能UPF,所述第一安全模块为星载安全功能模块,所述第二安全模块为地面站安全功能模块;或
所述发送方网元和所述接收方网元均为卫星基站S-gNB,所述第一安全模块和所述第二安全模块均为星载安全功能模块;或
所述发送方网元为用户面功能UPF,所述接收方网元为卫星基站S-gNB,所述第一安全模块为地面站安全功能模块,所述第二安全模块为星载安全功能模块。
具体地,本公开实施例中的卫星承载网两端的发送方网元和接收方网元可以至少有一方网元为卫星基站;
可选地,所述发送方网元为卫星基站S-gNB,所述接收方网元为用户面功能UPF,所述第一安全模块为星载安全功能模块,所述第二安全模块为地面站安全功能模块;
如图6所示,其中在步骤1-步骤3为由空口UP安全。为实现卫星承载网部分按需提供数据安全传输,基于SMF提供的卫星承载网的安全策略,在步骤4-步骤5实现对用户面数据(第一数据包)进行第一安全处理获得第二数据包,然后第二数据包在承载网上传输;在UPF处,经步骤11至步骤12,对第二数据包进行第二安全处理,获得数据明文;随后由已有协议继续进行相关处理。
可选地,所述发送方网元和所述接收方网元均为卫星基站S-gNB,所述第一安全模块和所述第二安全模块均为星载安全功能模块;
如图7所示,该流程适用于卫星通信环境下的T2T(终端至终端)安全;其中在步骤1-步骤3为由空口UP安全。为实现卫星承载网部分按需提供数据安全传输,基于SMF提供的卫星承载网的安全策略,在步骤4-步骤5实现对用户面数据(第一数据包)进行第一安全处理获得第二数据包,然后第二数据包在承载网上传输;在接收方的卫星基站处,经步骤11至步骤12,对第二数据包进行第二安全处理,获得数据明文;随后由已有协议继续进行相关处理。
可选地,所述发送方网元为用户面功能UPF,所述接收方网元为卫星基站S-gNB,所述第一安全模块为地面站安全功能模块,所述第二安全模块为星载安全功能模块。
如图8所示,其中在步骤1-步骤2为UPF对用户面数据(第一数据包)进行第一安全处理,获得第二数据包,然后在承载网上传输;在卫星基站S-gNB处,经步骤8至步骤9,对第二数据包进行第二安全处理,获得数据明文;随后由已有协议继续进行相关处理。
可选地,所述第二数据包中的安全字段包含所述卫星承载网的安全策略。
具体地,本公开实施例中对第一数据包进行第一安全保护处理获得第二数据包,通过在数据包结构中加入安全字段,对传统的GTP-U数据包结构进行扩展,提出了新的数据包结构。
如图10所示,第一数据包的数据包结构包括GTP-U部分和安全字段部分,所述GTP-U部分包括目的网元IP地址部分,源网元IP地址部分,UDP端口部分,GTP-U Header部分,目的IP地址部分、源IP地址部分和Payload部分。
可选地,处理所述第二数据包的协议层为卫星承载网数据传输协议栈中的安全层,所述安全层在GTP-U层与PDU Layer层之间。
具体地,为实现按需提供卫星通信承载网数据安全传输的能力和减少卫星承载网分段处理数据安全的负担和开销,本公开实施例对传输用户面(UP)数据的网元之间的数据传输协议进行了扩展,可以增加一个安全层,从而使承载网不必处理数据安全相关的事项。
为实现承载网数据安全传输,对数据传输协议栈增加了一个安全层,该层在GTP-U层与PDU Layer层之间。新的协议栈如图11所示,该层可以由生成和处理第一数据包和/或第二数据包的卫星基站S-gNB和/或UPF处理。
可选地,所述方法还包括:
接收SMF发送的所述卫星承载网的安全策略。
具体地,第二数据包中的安全字段可以为空,即第二数据包中不携带卫星承载网的安全策略。因此不需要对第一数据包中的安全字段进行修改。相应的,接收方网元可以接收SMF发送的所述卫星承载网的安全策略,即SMF需要将安全策略分发至数据的发送方和接收方,以便双方能够正确处理相关数据。
具体地,第二数据包中的安全字段也可以不为空,即第二数据包 中也可以携带卫星承载网的安全策略。相应的,接收方网元可以接收SMF发送的所述卫星承载网的安全策略,即SMF也可以将安全策略分发至数据的发送方和接收方,以便双方能够正确处理相关数据。
可选地,所述获取第三数据包之前,所述方法还包括:
向所述第二安全模块发送所述卫星承载网的安全策略。
可选地,接收方网元在接收到从SMF发送的卫星承载网的安全策略之后,可以向第二安全模块发送所述卫星承载网的安全策略,以使第二安全模块基于卫星承载网的安全策略对第二数据包进行第二安全处理。
本公开实施例提供的卫星通信系统、方法、装置、接收方网元及存储介质,通过第一安全模块基于发送方网元拥有的卫星承载网的安全策略对所述第一数据包进行第一安全处理,生成数据包结构中包含安全字段的第二数据包,并由发送方网元将其发送至接收方网元,接收方网元接收到第二数据包后,可以通过第二安全模块,基于获取到的卫星承载网的安全策略对第二数据包进行第二安全处理,获取包含第一数据包的数据的第三数据包,进而实现承载网两端的网元不必进行密钥和安全策略协商即可以对需要传输的数据进行保护,减少安全相关协商的开销,降低卫星通信管理的复杂度。
图13是本公开实施例提供的安全传输装置的结构示意图,如图13所示,该装置包括:
第一接收模块1310,用于接收发送方网元通过卫星承载网发送的第二数据包,其中,所述第二数据包的数据包结构中包含安全字段,所述第二数据包是由第一数据包基于SMF提供的卫星承载网的安全策略经过第一安全处理后获得的;
第一发送模块1320,用于将所述第二数据包发送至第二安全模块,以获取第三数据包,其中,所述第三数据包中包括所述第一数据包的数据,所述第三数据包是由所述第二数据包基于所述卫星承载网 的安全策略经过第二安全处理后获得的;
其中,所述发送方网元和所述接收方网元通过所述卫星承载网进行通信。
其中,安全传输装置可以通过第一接收模块1310接收发送方网元通过卫星承载网发送的第二数据包,其中,所述第二数据包的数据包结构中包含安全字段,所述第二数据包是由第一数据包基于SMF提供的卫星承载网的安全策略经过第一安全处理后获得的;然后可以通过发送模块1320将所述第二数据包发送至第二安全模块,以获取第三数据包,其中,所述第三数据包中包括所述第一数据包的数据,所述第三数据包是由所述第二数据包基于所述卫星承载网的安全策略经过第二安全处理后获得的。
可选地,所述第一安全处理包括以下至少一项:机密性保护处理和完整性保护处理,所述第二安全处理包括以下至少一项:解密处理和完整性保护验证处理。
可选地,所述卫星承载网的安全策略包括以下至少一项:
数据安全策略信息,所述数据安全策略信息用于指示所述第一安全处理包括的安全保护处理类型,其中所述安全保护处理类型包括所述机密性保护处理和/或所述完整性保护处理;或
算法信息,所述算法信息用于指示实现所述机密性保护处理的算法和/或实现所述完整性保护处理的算法;或
密钥信息,所述密钥信息用于指示实现所述机密性保护处理的密钥和/或实现所述完整性保护处理的密钥。
可选地,所述发送方网元为卫星基站S-gNB,所述接收方网元为用户面功能UPF,所述第一安全模块为星载安全功能模块,所述第二安全模块为地面站安全功能模块;或
所述发送方网元和所述接收方网元均为卫星基站S-gNB,所述第一安全模块和所述第二安全模块均为星载安全功能模块;或
所述发送方网元为用户面功能UPF,所述接收方网元为卫星基站S-gNB,所述第一安全模块为地面站安全功能模块,所述第二安全模块为星载安全功能模块。
可选地,所述第二数据包中的安全字段包含所述卫星承载网的安全策略。
可选地,所述装置还包括:
第二接收模块,用于接收SMF发送的所述卫星承载网的安全策略。
可选地,所述装置还包括:
第二发送模块,用于在所述获取第三数据包之前,向所述第二安全模块发送所述卫星承载网的安全策略。
本公开实施例提供的卫星通信装置,通过第一安全模块基于发送方网元拥有的卫星承载网的安全策略对所述第一数据包进行第一安全处理,生成数据包结构中包含安全字段的第二数据包,并由发送方网元将其发送至接收方网元,接收方网元接收到第二数据包后,可以通过第二安全模块,基于获取到的卫星承载网的安全策略对第二数据包进行第二安全处理,获取包含第一数据包的数据的第三数据包,进而实现承载网两端的网元不必进行密钥和安全策略协商即可以对需要传输的数据进行保护,减少安全相关协商的开销,降低卫星通信管理的复杂度。
需要说明的是,本公开实施例中对单元的划分是示意性的,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式。另外,在本公开各个实施例中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用软件功能单元的形式实现。
所述集成的单元如果以软件功能单元的形式实现并作为独立的 产品销售或使用时,可以存储在一个处理器可读取存储介质中。基于这样的理解,本公开的技术方案本质上或者说对现有技术做出贡献的部分或者该技术方案的全部或部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)或处理器(processor)执行本公开各个实施例所述方法的全部或部分步骤。而前述的存储介质包括:U盘、移动硬盘、只读存储器(Read-Only Memory,ROM)、随机存取存储器(Random Access Memory,RAM)、磁碟或者光盘等各种可以存储程序代码的介质。
在此需要说明的是,本发明实施例提供的上述装置,能够实现上述方法实施例所实现的所有方法步骤,且能够达到相同的技术效果,在此不再对本实施例中与方法实施例相同的部分及有益效果进行具体赘述。
图14是本公开实施例提供的接收方网元的结构示意图,如图14所示,所述接收方网元包括存储器1420,收发机1400,处理器1410,其中包括存储器,收发机,处理器:
存储器1420,用于存储计算机程序;收发机,用于在所述处理器1410的控制下收发数据;处理器1410,用于读取所述存储器中1420的计算机程序并执行以下操作:
接收发送方网元通过卫星承载网发送的第二数据包,其中,所述第二数据包的数据包结构中包含安全字段,所述第二数据包是由第一数据包基于SMF提供的卫星承载网的安全策略经过第一安全处理后获得的;
将所述第二数据包发送至第二安全模块,以获取第三数据包,其中,所述第三数据包中包括所述第一数据包的数据,所述第三数据包是由所述第二数据包基于所述卫星承载网的安全策略经过第二安全处理后获得的;
其中,所述发送方网元和所述接收方网元通过所述卫星承载网进行通信。
本公开实施例提供的接收方网元,通过第一安全模块基于发送方网元拥有的卫星承载网的安全策略对所述第一数据包进行第一安全处理,生成数据包结构中包含安全字段的第二数据包,并由发送方网元将其发送至接收方网元,接收方网元接收到第二数据包后,可以通过第二安全模块,基于获取到的卫星承载网的安全策略对第二数据包进行第二安全处理,获取包含第一数据包的数据的第三数据包,进而实现承载网两端的网元不必进行密钥和安全策略协商即可以对需要传输的数据进行保护,减少安全相关协商的开销,降低卫星通信管理的复杂度。
可选地,所述第一安全处理包括以下至少一项:机密性保护处理和完整性保护处理,所述第二安全处理包括以下至少一项:解密处理和完整性保护验证处理。
可选地,所述卫星承载网的安全策略包括以下至少一项:
数据安全策略信息,所述数据安全策略信息用于指示所述第一安全处理包括的安全保护处理类型,其中所述安全保护处理类型包括所述机密性保护处理和/或所述完整性保护处理;或
算法信息,所述算法信息用于指示实现所述机密性保护处理的算法和/或实现所述完整性保护处理的算法;或
密钥信息,所述密钥信息用于指示实现所述机密性保护处理的密钥和/或实现所述完整性保护处理的密钥。
可选地,所述发送方网元为卫星基站S-gNB,所述接收方网元为用户面功能UPF,所述第一安全模块为星载安全功能模块,所述第二安全模块为地面站安全功能模块;或
所述发送方网元和所述接收方网元均为卫星基站S-gNB,所述第一安全模块和所述第二安全模块均为星载安全功能模块;或
所述发送方网元为用户面功能UPF,所述接收方网元为卫星基站S-gNB,所述第一安全模块为地面站安全功能模块,所述第二安全模块为星载安全功能模块。
可选地,所述第二数据包中的安全字段包含所述卫星承载网的安全策略。
可选地,处理器1410还用于:
接收SMF发送的所述卫星承载网的安全策略。
可选地,处理器1410还用于:
在所述获取第三数据包之前,向所述第二安全模块发送所述卫星承载网的安全策略。
本公开实施例提供的接收方网元,通过第一安全模块基于发送方网元拥有的卫星承载网的安全策略对所述第一数据包进行第一安全处理,生成数据包结构中包含安全字段的第二数据包,并由发送方网元将其发送至接收方网元,接收方网元接收到第二数据包后,可以通过第二安全模块,基于获取到的卫星承载网的安全策略对第二数据包进行第二安全处理,获取包含第一数据包的数据的第三数据包,进而实现承载网两端的网元不必进行密钥和安全策略协商即可以对需要传输的数据进行保护,减少安全相关协商的开销,降低卫星通信管理的复杂度。
具体地,收发机1400,用于在处理器1410的控制下接收和发送数据。
其中,在图14中,总线架构可以包括任意数量的互联的总线和桥,具体由处理器1410代表的一个或多个处理器和存储器1420代表的存储器的各种电路链接在一起。总线架构还可以将诸如外围设备、稳压器和功率管理电路等之类的各种其他电路链接在一起,这些都是本领域所公知的,因此,本文不再对其进行进一步描述。总线接口提供接口。收发机1400可以是多个元件,即包括发送机和接收机,提 供用于在传输介质上与各种其他装置通信的单元,这些传输介质包括无线信道、有线信道、光缆等传输介质。处理器1410负责管理总线架构和通常的处理,存储器1420可以存储处理器1410在执行操作时所使用的数据。
处理器1410可以是中央处理器(Central Processing Unit,CPU)、专用集成电路(Application Specific Integrated Circuit,ASIC)、现场可编程门阵列(Field-Programmable Gate Array,FPGA)或复杂可编程逻辑器件(Complex Programmable Logic Device,CPLD),处理器也可以采用多核架构。
在此需要说明的是,本公开实施例提供的上述接收方网元,能够实现上述执行主体为接收方网元的方法实施例所实现的所有方法步骤,且能够达到相同的技术效果,在此不再对本实施例中与方法实施例相同的部分及有益效果进行具体赘述。
另一方面,本公开实施例还提供一种处理器可读存储介质,所述处理器可读存储介质存储有计算机程序,所述计算机程序用于使所述处理器执行上述各实施例提供的方法,包括:
接收发送方网元通过卫星承载网发送的第二数据包,其中,所述第二数据包的数据包结构中包含安全字段,所述第二数据包是由第一数据包基于SMF提供的卫星承载网的安全策略经过第一安全处理后获得的;
将所述第二数据包发送至第二安全模块,以获取第三数据包,其中,所述第三数据包中包括所述第一数据包的数据,所述第三数据包是由所述第二数据包基于所述卫星承载网的安全策略经过第二安全处理后获得的;
其中,所述发送方网元和所述接收方网元通过所述卫星承载网进行通信。
所述处理器可读存储介质可以是处理器能够存取的任何可用介 质或数据存储设备,包括但不限于磁性存储器(例如软盘、硬盘、磁带、磁光盘(MO)等)、光学存储器(例如CD、DVD、BD、HVD等)、以及半导体存储器(例如ROM、EPROM、EEPROM、非易失性存储器(NAND FLASH)、固态硬盘(SSD))等。
本领域内的技术人员应明白,本公开的实施例可提供为方法、系统、或计算机程序产品。因此,本公开可采用完全硬件实施例、完全软件实施例、或结合软件和硬件方面的实施例的形式。而且,本公开可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器和光学存储器等)上实施的计算机程序产品的形式。
本公开是参照根据本公开实施例的方法、设备(系统)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机可执行指令实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机可执行指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。
这些处理器可执行指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的处理器可读存储器中,使得存储在该处理器可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。
这些处理器可执行指令也可装载到计算机或其他可编程数据处理设备上,使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方 框或多个方框中指定的功能的步骤。
显然,本领域的技术人员可以对本公开进行各种改动和变型而不脱离本公开的精神和范围。这样,倘若本公开的这些修改和变型属于本公开权利要求及其等同技术的范围之内,则本公开也意图包含这些改动和变型在内。

Claims (40)

  1. 一种卫星通信系统,其特征在于,包括:发送方网元,所述发送方网元对应的第一安全模块、接收方网元、和所述接收方网元对应的第二安全模块,其中,所述发送方网元和所述接收方网元通过卫星承载网进行通信;
    所述第一安全模块,用于接收所述发送方网元发送的第一数据包和所述卫星承载网的安全策略,并基于所述卫星承载网的安全策略对所述第一数据包进行第一安全处理,生成第二数据包,所述第二数据包的数据包结构中包含安全字段,并将所述第二数据包发送给所述发送方网元;
    所述第二安全模块,用于接收所述接收方网元发送的所述第二数据包,获取所述卫星承载网的安全策略,并基于所述卫星承载网的安全策略对所述第二数据包进行第二安全处理,获得第三数据包,所述第三数据包中包括所述第一数据包的数据,并将所述第三数据包发送给所述接收方网元;
    所述发送方网元,用于生成所述第一数据包和接收会话管理功能SMF发送的所述卫星承载网的安全策略,并将所述第一数据包和所述卫星承载网的安全策略发送给所述第一安全模块,以获得所述第二数据包,并将所述第二数据包通过所述卫星承载网发送给所述接收方网元;
    所述接收方网元,用于接收所述发送方网元通过所述卫星承载网发送的所述第二数据包,并将所述第二数据包发送至所述第二安全模块,以获取所述第三数据包。
  2. 根据权利要求1所述的卫星通信系统,其特征在于,所述第一安全处理包括以下至少一项:机密性保护处理和完整性保护处理,所述第二安全处理包括以下至少一项:解密处理和完整性保护验证处理。
  3. 根据权利要求2所述的卫星通信系统,其特征在于,所述卫星承载网的安全策略包括以下至少一项:
    数据安全策略信息,所述数据安全策略信息用于指示所述第一安全处理包括的安全保护处理类型,其中所述安全保护处理类型包括所述机密性保护处理和/或所述完整性保护处理;或
    算法信息,所述算法信息用于指示实现所述机密性保护处理的算法和/或实现所述完整性保护处理的算法;或
    密钥信息,所述密钥信息用于指示实现所述机密性保护处理的密钥和/或实现所述完整性保护处理的密钥。
  4. 根据权利要求3所述的卫星通信系统,其特征在于,所述第一安全模块具体用于:接收所述发送方网元发送的第一数据包和所述卫星承载网的安全策略,基于所述卫星承载网的安全策略中的所述数据安全策略信息,确定所述安全保护处理类型,并基于所述算法信息中与所述安全保护处理类型对应的算法,以及所述密钥信息中与所述安全保护处理类型对应的密钥,实现对所述第一数据包的第一安全处理,生成所述第二数据包,并将所述第二数据包发送给所述发送方网元。
  5. 根据权利要求3所述的卫星通信系统,其特征在于,所述第二安全模块具体用于:接收所述接收方网元发送的所述第二数据包,基于所述卫星承载网的安全策略中的所述数据安全策略信息,确定所述安全保护处理类型,并基于所述算法信息中与所述安全保护处理类型对应的算法,以及所述密钥信息中与所述安全保护处理类型对应的密钥,实现对所述第二数据包的第二安全处理,获得所述第三数据包,并将所述第三数据包发送给所述接收方网元。
  6. 根据权利要求1-5任一项所述的卫星通信系统,其特征在于,所述发送方网元为卫星基站S-gNB,所述接收方网元为用户面功能UPF,所述第一安全模块为星载安全功能模块,所述第二安全模块为 地面站安全功能模块;或
    所述发送方网元和所述接收方网元均为卫星基站S-gNB,所述第一安全模块和所述第二安全模块均为星载安全功能模块;或
    所述发送方网元为用户面功能UPF,所述接收方网元为卫星基站S-gNB,所述第一安全模块为地面站安全功能模块,所述第二安全模块为星载安全功能模块。
  7. 根据权利要求3-5任一项所述的卫星通信系统,其特征在于,所述第一数据包的数据包结构包括GTP-U部分和安全字段部分,所述GTP-U部分包括目的网元IP地址部分,源网元IP地址部分,UDP端口部分,GTP-U Header部分,目的IP地址部分、源IP地址部分和Payload部分。
  8. 根据权利要求7所述的卫星通信系统,其特征在于,处理所述第二数据包的协议层为卫星承载网数据传输协议栈中的安全层,所述安全层在GTP-U层与PDU Layer层之间。
  9. 根据权利要求7所述的卫星通信系统,其特征在于,所述第一安全模块,具体用于以下至少一项:
    若所述安全保护处理类型包括所述机密性保护处理,则对所述第一数据包的数据包结构中的所述目的IP地址部分、所述源IP地址部分和所述Payload部分进行机密性保护处理,获得密文;
    若所述安全保护处理类型包括所述完整性保护处理,则对所述第一数据包的数据包结构中的所述目的网元IP地址部分、所述源网元IP地址部分、所述UDP端口部分、所述GTP-U Header部分、所述安全字段部分、所述目的IP地址部分、所述源IP地址部分和所述Payload部分进行完整性保护处理;
    若所述安全保护处理类型包括所述机密性保护处理和所述完整性保护处理,则对所述第一数据包的数据包结构中的所述目的IP地址部分、所述源IP地址部分和所述Payload部分进行机密性保护处理, 获得密文,在所述机密性保护处理后,对所述第一数据包的数据包结构中的目的网元IP地址部分,所述源网元IP地址部分,所述UDP端口部分,所述GTP-U Header部分,所述安全字段部分,以及所述密文进行完整性保护。
  10. 根据权利要求7所述的卫星通信系统,其特征在于,所述第二安全模块,具体用于以下至少一项:
    若所述安全保护处理类型包括所述机密性保护处理,则对第二数据包的数据包结构中的密文进行解密处理,获得所述目的IP地址部分、所述源IP地址部分和所述Payload部分;
    若所述安全保护处理类型包括所述完整性保护处理,则对第二数据包的数据包结构中的目的网元IP地址部分、所述源网元IP地址部分、所述UDP端口部分、所述GTP-U Header部分、所述安全字段部分、所述目的IP地址部分,所述源IP地址部分以及所述Payload部分进行完整性保护验证处理;
    若所述安全保护处理类型包括所述机密性保护处理和所述完整性保护处理,则对第二数据包的数据包结构中的目的网元IP地址部分、所述源网元IP地址部分、所述UDP端口部分、所述GTP-U Header部分、所述安全字段部分、以及密文进行完整性保护验证处理,在所述完整性保护验证处理后,对所述密文进行解密处理,获得所述目的IP地址部分、所述源IP地址部分和所述Payload部分。
  11. 根据权利要求1-5任一项或8-10任一项所述的卫星通信系统,其特征在于,所述第二数据包中的安全字段包含所述卫星承载网的安全策略。
  12. 根据权利要求11所述的卫星通信系统,其特征在于,所述SMF用于向所述发送方网元发送所述卫星承载网的安全策略。
  13. 根据权利要求11所述的卫星通信系统,其特征在于,所述第二安全模块获取的所述卫星承载网的安全策略,是从所述第二数据 包中的安全字段获取的。
  14. 根据权利要求1-5任一项或8-10任一项所述的卫星通信系统,其特征在于,所述接收方网元还用于接收所述SMF发送的所述卫星承载网的安全策略。
  15. 根据权利要求14所述的卫星通信系统,其特征在于,所述SMF用于向所述发送方网元和所述接收方网元发送所述卫星承载网的安全策略。
  16. 根据权利要求14所述的卫星通信系统,其特征在于,所述第二安全模块获取的所述卫星承载网的安全策略,是从所述接收方网元获取的。
  17. 根据权利要求16所述的卫星通信系统,其特征在于,所述接收方网元还用于:在所述获取所述卫星承载网的安全策略之后,向所述第二安全模块发送所述卫星承载网的安全策略。
  18. 根据权利要求12或15所述的卫星通信系统,其特征在于,所述卫星承载网的安全策略是所述SMF从安全管理实体获取的,所述安全管理实体包括统一数据管理功能UDM。
  19. 一种安全传输方法,其特征在于,应用于接收方网元,所述方法包括:
    接收发送方网元通过卫星承载网发送的第二数据包,其中,所述第二数据包的数据包结构中包含安全字段,所述第二数据包是由第一数据包基于SMF提供的卫星承载网的安全策略经过第一安全处理后获得的;
    将所述第二数据包发送至第二安全模块,以获取第三数据包,其中,所述第三数据包中包括所述第一数据包的数据,所述第三数据包是由所述第二数据包基于所述卫星承载网的安全策略经过第二安全处理后获得的;
    其中,所述发送方网元和所述接收方网元通过所述卫星承载网进 行通信。
  20. 根据权利要求19所述的安全传输方法,其特征在于,所述第一安全处理包括以下至少一项:机密性保护处理和完整性保护处理,所述第二安全处理包括以下至少一项:解密处理和完整性保护验证处理。
  21. 根据权利要求20所述的安全传输方法,其特征在于,所述卫星承载网的安全策略包括以下至少一项:
    数据安全策略信息,所述数据安全策略信息用于指示所述第一安全处理包括的安全保护处理类型,其中所述安全保护处理类型包括所述机密性保护处理和/或所述完整性保护处理;或
    算法信息,所述算法信息用于指示实现所述机密性保护处理的算法和/或实现所述完整性保护处理的算法;或
    密钥信息,所述密钥信息用于指示实现所述机密性保护处理的密钥和/或实现所述完整性保护处理的密钥。
  22. 根据权利要求19-21任一项所述的安全传输方法,其特征在于,所述发送方网元为卫星基站S-gNB,所述接收方网元为用户面功能UPF,所述第一安全模块为星载安全功能模块,所述第二安全模块为地面站安全功能模块;或
    所述发送方网元和所述接收方网元均为卫星基站S-gNB,所述第一安全模块和所述第二安全模块均为星载安全功能模块;或
    所述发送方网元为用户面功能UPF,所述接收方网元为卫星基站S-gNB,所述第一安全模块为地面站安全功能模块,所述第二安全模块为星载安全功能模块。
  23. 根据权利要求19-21任一项所述的安全传输方法,其特征在于,所述第二数据包中的安全字段包含所述卫星承载网的安全策略。
  24. 根据权利要求19-21任一项所述的安全传输方法,其特征在于,所述方法还包括:
    接收SMF发送的所述卫星承载网的安全策略。
  25. 根据权利要求24所述的安全传输方法,其特征在于,所述获取第三数据包之前,所述方法还包括:
    向所述第二安全模块发送所述卫星承载网的安全策略。
  26. 一种接收方网元,包括存储器,收发机,处理器:
    存储器,用于存储计算机程序;收发机,用于在所述处理器的控制下收发数据;处理器,用于读取所述存储器中的计算机程序并执行以下操作:
    接收发送方网元通过卫星承载网发送的第二数据包,其中,所述第二数据包的数据包结构中包含安全字段,所述第二数据包是由第一数据包基于SMF提供的卫星承载网的安全策略经过第一安全处理后获得的;
    将所述第二数据包发送至第二安全模块,以获取第三数据包,其中,所述第三数据包中包括所述第一数据包的数据,所述第三数据包是由所述第二数据包基于所述卫星承载网的安全策略经过第二安全处理后获得的;
    其中,所述发送方网元和所述接收方网元通过所述卫星承载网进行通信。
  27. 根据权利要求26所述的接收方网元,其特征在于,所述第一安全处理包括以下至少一项:机密性保护处理和完整性保护处理,所述第二安全处理包括以下至少一项:解密处理和完整性保护验证处理。
  28. 根据权利要求27所述的接收方网元,其特征在于,所述卫星承载网的安全策略包括以下至少一项:
    数据安全策略信息,所述数据安全策略信息用于指示所述第一安全处理包括的安全保护处理类型,其中所述安全保护处理类型包括所述机密性保护处理和/或所述完整性保护处理;或
    算法信息,所述算法信息用于指示实现所述机密性保护处理的算法和/或实现所述完整性保护处理的算法;或
    密钥信息,所述密钥信息用于指示实现所述机密性保护处理的密钥和/或实现所述完整性保护处理的密钥。
  29. 根据权利要求26-28任一项所述的接收方网元,其特征在于,所述发送方网元为卫星基站S-gNB,所述接收方网元为用户面功能UPF,所述第一安全模块为星载安全功能模块,所述第二安全模块为地面站安全功能模块;或
    所述发送方网元和所述接收方网元均为卫星基站S-gNB,所述第一安全模块和所述第二安全模块均为星载安全功能模块;或
    所述发送方网元为用户面功能UPF,所述接收方网元为卫星基站S-gNB,所述第一安全模块为地面站安全功能模块,所述第二安全模块为星载安全功能模块。
  30. 根据权利要求26-28任一项所述的接收方网元,其特征在于,所述第二数据包中的安全字段包含所述卫星承载网的安全策略。
  31. 根据权利要求26-28任一项所述的接收方网元,其特征在于,所述操作还包括:
    接收SMF发送的所述卫星承载网的安全策略。
  32. 根据权利要求31所述的接收方网元,其特征在于,所述获取第三数据包之前,所述操作还包括:
    向所述第二安全模块发送所述卫星承载网的安全策略。
  33. 一种安全传输装置,其特征在于,所述装置包括:
    第一接收模块,用于接收发送方网元通过卫星承载网发送的第二数据包,其中,所述第二数据包的数据包结构中包含安全字段,所述第二数据包是由第一数据包基于SMF提供的卫星承载网的安全策略经过第一安全处理后获得的;
    第一发送模块,用于将所述第二数据包发送至第二安全模块,以 获取第三数据包,其中,所述第三数据包中包括所述第一数据包的数据,所述第三数据包是由所述第二数据包基于所述卫星承载网的安全策略经过第二安全处理后获得的;
    其中,所述发送方网元和所述接收方网元通过所述卫星承载网进行通信。
  34. 根据权利要求33所述的安全传输装置,其特征在于,所述第一安全处理包括以下至少一项:机密性保护处理和完整性保护处理,所述第二安全处理包括以下至少一项:解密处理和完整性保护验证处理。
  35. 根据权利要求34所述的安全传输装置,其特征在于,所述卫星承载网的安全策略包括以下至少一项:
    数据安全策略信息,所述数据安全策略信息用于指示所述第一安全处理包括的安全保护处理类型,其中所述安全保护处理类型包括所述机密性保护处理和/或所述完整性保护处理;或
    算法信息,所述算法信息用于指示实现所述机密性保护处理的算法和/或实现所述完整性保护处理的算法;或
    密钥信息,所述密钥信息用于指示实现所述机密性保护处理的密钥和/或实现所述完整性保护处理的密钥。
  36. 根据权利要求33-35任一项所述的安全传输装置,其特征在于,所述发送方网元为卫星基站S-gNB,所述接收方网元为用户面功能UPF,所述第一安全模块为星载安全功能模块,所述第二安全模块为地面站安全功能模块;或
    所述发送方网元和所述接收方网元均为卫星基站S-gNB,所述第一安全模块和所述第二安全模块均为星载安全功能模块;或
    所述发送方网元为用户面功能UPF,所述接收方网元为卫星基站S-gNB,所述第一安全模块为地面站安全功能模块,所述第二安全模块为星载安全功能模块。
  37. 根据权利要求33-35任一项所述的安全传输装置,其特征在于,所述第二数据包中的安全字段包含所述卫星承载网的安全策略。
  38. 根据权利要求33-35任一项所述的安全传输装置,其特征在于,所述装置还包括:
    第二接收模块,用于接收SMF发送的所述卫星承载网的安全策略。
  39. 根据权利要求38所述的安全传输装置,其特征在于,所述获取第三数据包之前,所述装置还包括:
    第二发送模块,用于向所述第二安全模块发送所述卫星承载网的安全策略。
  40. 一种处理器可读存储介质,其特征在于,所述处理器可读存储介质存储有计算机程序,所述计算机程序用于使所述处理器执行权利要求19至25任一项所述的方法。
PCT/CN2022/131721 2021-11-15 2022-11-14 卫星通信系统、方法、装置、接收方网元及存储介质 Ceased WO2023083346A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202111347750.2 2021-11-15
CN202111347750.2A CN116132990A (zh) 2021-11-15 2021-11-15 卫星通信系统、方法、装置、接收方网元及存储介质

Publications (1)

Publication Number Publication Date
WO2023083346A1 true WO2023083346A1 (zh) 2023-05-19

Family

ID=86293747

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2022/131721 Ceased WO2023083346A1 (zh) 2021-11-15 2022-11-14 卫星通信系统、方法、装置、接收方网元及存储介质

Country Status (2)

Country Link
CN (1) CN116132990A (zh)
WO (1) WO2023083346A1 (zh)

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102917333A (zh) * 2012-10-15 2013-02-06 航天恒星科技有限公司 大规模卫星终端的卫星通信系统及卫星终端的接入方法
CN110912854A (zh) * 2018-09-15 2020-03-24 华为技术有限公司 一种安全保护方法、设备及系统
US20210051005A1 (en) * 2019-08-16 2021-02-18 Lenovo (Singapore) Pte. Ltd. Security capabilities in an encryption key request
CN112689287A (zh) * 2019-10-02 2021-04-20 苹果公司 用户平面完整性保护处理过程
CN113328783A (zh) * 2021-05-25 2021-08-31 广州爱浦路网络技术有限公司 天地一体化信息网络中的数据传输方法、装置和存储介质
CN113519147A (zh) * 2019-03-08 2021-10-19 联想(新加坡)私人有限公司 安全模式完整性验证

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102917333A (zh) * 2012-10-15 2013-02-06 航天恒星科技有限公司 大规模卫星终端的卫星通信系统及卫星终端的接入方法
CN110912854A (zh) * 2018-09-15 2020-03-24 华为技术有限公司 一种安全保护方法、设备及系统
CN113519147A (zh) * 2019-03-08 2021-10-19 联想(新加坡)私人有限公司 安全模式完整性验证
US20210051005A1 (en) * 2019-08-16 2021-02-18 Lenovo (Singapore) Pte. Ltd. Security capabilities in an encryption key request
CN112689287A (zh) * 2019-10-02 2021-04-20 苹果公司 用户平面完整性保护处理过程
CN113328783A (zh) * 2021-05-25 2021-08-31 广州爱浦路网络技术有限公司 天地一体化信息网络中的数据传输方法、装置和存储介质

Also Published As

Publication number Publication date
CN116132990A (zh) 2023-05-16

Similar Documents

Publication Publication Date Title
CN110830991B (zh) 安全会话方法和装置
US12581290B2 (en) Security negotiation method and apparatus
CN108347410B (zh) 安全实现方法、设备以及系统
CN110830993B (zh) 一种数据处理的方法、装置和计算机可读存储介质
CN114827920B (zh) 一种通信方法、装置、设备和可读存储介质
CN1946233A (zh) 避免移动网络中昂贵的双重加密的机制
CN109246696B (zh) 密钥处理方法以及相关装置
US9801052B2 (en) Method and system for securing control packets and data packets in a mobile broadband network environment
CN110891269A (zh) 一种数据保护方法、设备及系统
CN114930890B (zh) 完整性保护方法和通信设备
WO2017133021A1 (zh) 一种安全处理方法及相关设备
CN116601985B (zh) 一种安全上下文生成方法、装置及计算机可读存储介质
WO2022027476A1 (zh) 密钥管理方法及通信装置
WO2023131044A1 (zh) 认证与安全方法、装置及存储介质
CN114205814B (zh) 一种数据传输方法、装置、系统、电子设备及存储介质
WO2017219365A1 (zh) 数据传输的方法和装置
WO2024032207A1 (zh) 通信方法、装置和系统
CA3115390C (en) Wireless communication method and device
WO2022151917A1 (zh) 消息处理方法、装置、终端及网络侧设备
US20100303233A1 (en) Packet transmitting and receiving apparatus and packet transmitting and receiving method
WO2023083346A1 (zh) 卫星通信系统、方法、装置、接收方网元及存储介质
WO2017210811A1 (zh) 安全策略的执行方法和设备
WO2020258292A1 (zh) 无线通信的方法、终端设备、接入网设备和核心网设备
CN121442322A (zh) 一种数据传输方法和通信装置以及存储介质
WO2025066649A1 (zh) Nas消息的安全保护方法、装置及存储介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 22892139

Country of ref document: EP

Kind code of ref document: A1

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 19/09/2024)

122 Ep: pct application non-entry in european phase

Ref document number: 22892139

Country of ref document: EP

Kind code of ref document: A1