WO2023011373A1 - 一种传输方法、系统及相关装置 - Google Patents
一种传输方法、系统及相关装置 Download PDFInfo
- Publication number
- WO2023011373A1 WO2023011373A1 PCT/CN2022/109226 CN2022109226W WO2023011373A1 WO 2023011373 A1 WO2023011373 A1 WO 2023011373A1 CN 2022109226 W CN2022109226 W CN 2022109226W WO 2023011373 A1 WO2023011373 A1 WO 2023011373A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- data packet
- information
- authentication code
- data
- receiving
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04B—TRANSMISSION
- H04B7/00—Radio transmission systems, i.e. using radiation field
- H04B7/14—Relay systems
- H04B7/15—Active relay systems
- H04B7/185—Space-based or airborne stations; Stations for satellite systems
- H04B7/1851—Systems using a satellite or space-based relay
- H04B7/18519—Operations control, administration or maintenance
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04B—TRANSMISSION
- H04B7/00—Radio transmission systems, i.e. using radiation field
- H04B7/14—Relay systems
- H04B7/15—Active relay systems
- H04B7/185—Space-based or airborne stations; Stations for satellite systems
- H04B7/1851—Systems using a satellite or space-based relay
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04B—TRANSMISSION
- H04B7/00—Radio transmission systems, i.e. using radiation field
- H04B7/14—Relay systems
- H04B7/15—Active relay systems
- H04B7/185—Space-based or airborne stations; Stations for satellite systems
- H04B7/18528—Satellite systems for providing two-way communications service to a network of fixed stations, i.e. fixed satellite service or very small aperture terminal [VSAT] system
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04B—TRANSMISSION
- H04B7/00—Radio transmission systems, i.e. using radiation field
- H04B7/14—Relay systems
- H04B7/15—Active relay systems
- H04B7/185—Space-based or airborne stations; Stations for satellite systems
- H04B7/1853—Satellite systems for providing telephony service to a mobile station, i.e. mobile satellite service
- H04B7/18545—Arrangements for managing station mobility, i.e. for station registration or localisation
- H04B7/18547—Arrangements for managing station mobility, i.e. for station registration or localisation for geolocalisation of a station
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04B—TRANSMISSION
- H04B7/00—Radio transmission systems, i.e. using radiation field
- H04B7/14—Relay systems
- H04B7/15—Active relay systems
- H04B7/185—Space-based or airborne stations; Stations for satellite systems
- H04B7/1853—Satellite systems for providing telephony service to a mobile station, i.e. mobile satellite service
- H04B7/18565—Arrangements for preventing unauthorised access or for providing user protection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04B—TRANSMISSION
- H04B7/00—Radio transmission systems, i.e. using radiation field
- H04B7/14—Relay systems
- H04B7/15—Active relay systems
- H04B7/185—Space-based or airborne stations; Stations for satellite systems
- H04B7/18578—Satellite systems for providing broadband data service to individual earth stations
- H04B7/18593—Arrangements for preventing unauthorised access or for providing user protection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/03—Protecting confidentiality, e.g. by encryption
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
- H04W12/041—Key generation or derivation
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
- H04W12/043—Key management, e.g. using generic bootstrapping architecture [GBA] using a trusted network node as an anchor
- H04W12/0431—Key distribution or pre-distribution; Key agreement
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/10—Integrity
- H04W12/106—Packet or message integrity
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/60—Context-dependent security
- H04W12/61—Time-dependent
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W84/00—Network topologies
- H04W84/02—Hierarchically pre-organised networks, e.g. paging networks, cellular networks, WLAN [Wireless Local Area Network] or WLL [Wireless Local Loop]
- H04W84/04—Large scale networks; Deep hierarchical networks
- H04W84/06—Airborne or Satellite Networks
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W84/00—Network topologies
- H04W84/02—Hierarchically pre-organised networks, e.g. paging networks, cellular networks, WLAN [Wireless Local Area Network] or WLL [Wireless Local Loop]
- H04W84/10—Small scale networks; Flat hierarchical networks
- H04W84/12—WLAN [Wireless Local Area Networks]
Definitions
- the present application relates to the field of satellite communication, in particular to a transmission method, system and related devices.
- Satellite communication services can be used for positioning and communication in areas such as oceans, deserts, grasslands, and uninhabited areas that are not covered by mobile communications, or cannot be covered, or where the communication system is destroyed.
- the Beibei satellite communication system does not provide a secure transmission mechanism for civilian terminals.
- the application discloses a transmission method, system and related devices.
- the sending device can generate the authentication code A based on the information A and the original data.
- the sending device may send the data packet including the authentication code A to the receiving device under the first transmission system.
- the receiving device can generate the authentication code B based on the information B and the data packet.
- the receiving device can determine the receiving status of the data packet based on the authentication code B.
- Information A is sending time information and information B is receiving time information, or information A is context information A and information B is context information B. It is realized that when the receiving device receives the repeatedly sent data packet, the receiving device cannot parse the data packet, and the problems of repeated processing and billing will not occur.
- the present application provides a transmission method, including:
- the first device generates a first authentication code based on the first information, the first key, and the first data; wherein, the first information is sending time information or first context information; the first device generates a first authentication code based on the first authentication code and the first The data generates a first data packet; the first device sends the first data packet to the second device under the first transmission system.
- the method before the first device generates the first authentication code based on the first information, the first key, and the first data, the method further includes: the first device obtains the first key, and the first key The key is obtained through negotiation between the first device and the second device under the second transmission system; wherein, the first transmission system is different from the second transmission system.
- the method before the first device generates the first authentication code based on the first information, the first key, and the first data, the method further includes: the first device establishes a communication connection with the fourth device; A device obtains the first key through the fourth device.
- the first key is a key preset by the first device.
- the second transmission system is a cellular transmission system or a wireless local area network (WLAN) transmission system
- the first transmission system is a satellite transmission system.
- the first device obtains the first key through negotiation with the second device under the second transmission system through a general bootstrap framework (GBA) procedure.
- GBA bootstrap framework
- the sending of the first data packet by the first device to the second device under the first transmission system specifically includes:
- the message data convergence layer MDCP layer of the first device and/or the satellite link control layer SLC layer of the first device process the first data packet into at least one second data packet, pass at least one second data packet through the third device to the second device.
- the sending time information is used to indicate the time when the first device sends the first data packet.
- the time when the first device sends the first data packet is the time when the application AP layer of the first device sends the first data packet to the message data convergence MDCP layer, or is the time estimated by the first device The time when the first packet was sent to the second device.
- the first device acquires the sending time information through positioning and timing.
- the first data includes packaged first data and a first authentication code.
- the format of the sending time of the data packet is UTC or GMT.
- the specified time granularity of the sending time of the data packet includes any one of year, month, day number, hour, minute, and second.
- the first device and the second device negotiate to update the specified time granularity in the second transmission system.
- the first device acquires the sending time information through the fourth device.
- the first device obtains the first information in a preset encoding manner based on the sending time information and the specified time granularity.
- the method further includes:
- the first device receives the first application layer receipt sent by the second device; wherein, the first application layer receipt is used to instruct the second device to receive the receiving status of the first data packet.
- the first information is first context information
- the first context information is used to indicate the number of first data packets successfully sent by the first device, or the number of application receipts successfully received by the first device information, or the count value or sequence number of the first data packet sent by the first device.
- the first data packet further includes first indication information, where the first indication information is used to indicate the first message ID of the first data packet, or the first indication information is used to indicate the first message ID of the first data packet.
- the AP layer of the first device associates the first message ID or the first count value or the first sequence number with the first data packet, and the first device associates the first message ID or the first count value or Increment the default value on the value of the first serial number.
- the first data packet further includes third indication information, where the third indication information is used to indicate that the first data packet is a newly transmitted data packet or a retransmitted data packet.
- the third indication information when the value of the third indication information is the first value, the third indication information indicates that the first data packet is a newly transmitted data packet; when the value of the third indication information is the second value, The third indication information indicates that the first data packet is a retransmission data packet.
- the method before the first device generates the first authentication code based on the first information, the first key, and the first data, the method further includes:
- the first device acquires the initial value of the first information in the second transmission system; or,
- the first device acquires the initial value of the first information through the fourth device.
- the method further includes:
- the first device receives the first application layer receipt sent by the second device; wherein, the first application layer receipt is used to instruct the second device to receive the receiving status of the first data packet.
- the method further includes:
- the first device adds a preset value to the value of the first information; the adjusted value of the first information is different from the value of the first information.
- the method further includes: when the first application receipt is used to indicate that the second device fails to receive the first data packet, The first device adjusts the value of the first information to an initial value.
- the method further includes: the first device sends third information to the second device, the value of the third information and the adjusted first The value of one message is the same.
- the method further includes: when the first application receipt indicates that the first data packet is sent successfully, the first device displays the success Prompt information, the success prompt information is used to prompt the user that the message corresponding to the first data packet is sent successfully.
- the method further includes: when the first application receipt indicates that the sending of the first data packet failed, the first device displays failure Prompt information, the failure prompt information is used to prompt the user that the message corresponding to the first data packet fails to be sent.
- the method further includes: when the first application receipt includes the second message ID information, the first device displays success prompt information
- the success prompt information is used to prompt the user that the data packet indicated by the second message ID information is sent successfully.
- the application layer of the first device generates the first data packet according to the first authentication code and the first data, which specifically includes: the application layer of the first device encrypts the first authentication code based on the first key code and first data to generate a first data packet; wherein, the first data packet includes the encrypted first authentication code and the encrypted first data.
- the application layer of the first device encrypts the first data based on the first key to generate a first data packet; where the first data packet includes the encrypted first data.
- the method further includes: the first device receives the second application receipt information in the second transmission system, and the first The second application receipt information is used to indicate the sending status of the first data packet by the first device in the first transmission system.
- the method further includes: the first device displays sending prompt information, and sending the prompt information is used to remind the user that the second A device has sent a first data packet to a second device.
- the present application provides a transmission method, including: the second device receives the first data packet sent by the first device under the first transmission system; the second device receives the first data packet according to the second information, the first key, the first The data packet generates a second authentication code; wherein, the second information is receiving time information or second context information; the second device determines the receiving state of the first data packet based on the second authentication code.
- the method before the second device generates the second authentication code according to the second information, the first key, and the first data packet, the method further includes: the second device obtains the first key, the first The key is obtained by the second device through negotiation with the first device under the second transmission system; wherein, the second transmission system is different from the first transmission system.
- the second transmission system is a cellular transmission system or a WLAN transmission system
- the first transmission system is a satellite transmission system.
- the second device obtains the first key through negotiation with the first device under the second transmission system through a GBA process.
- the first key is a key preset by the first device.
- the second device receiving the first data packet under the first transmission system specifically includes: the second device receiving the first data packet sent by the third device under the first transmission system.
- the second device determines the first authentication code according to the first data packet.
- the receiving time information is used to indicate the receiving time of the first data packet.
- the method before the second device generates the second authentication code according to the second information, the first key, and the first data packet, the method further includes: the second device receives the second authentication code sent by the third device. information.
- the method before the second device generates the second authentication code according to the second information, the first key, and the first data packet, the method further includes: the second device receives the third authentication code sent by the third device. information; the second device generates second information based on the third information.
- the second context information is used to indicate information about the number of first data packets successfully received by the second device, or a count value or a sequence value of the first data packets received by the second device.
- the first data packet includes first indication information, and the first indication information is used to indicate a first message ID/first sequence number/first count value of the first data packet.
- the first data packet includes third indication information, and the third indication information is used to indicate that the first data packet is a newly transmitted data packet/a retransmitted data packet.
- the method before the second device generates the second authentication code according to the second information, the first key, and the first data packet, the method further includes: the second device acquires the second authentication code in the second transmission system The initial value of the second message.
- the second device determines the receiving state of the first data packet based on the second authentication code, which specifically includes: the second device determines whether the second authentication code is the same as the second authentication code Receive status of a data packet.
- the second device compares the first authentication code with the second authentication code, specifically including: the first authentication code is the same as the second authentication code, The second device determines that the first data packet is successfully received; or,
- the first authentication code is different from the second authentication code, and the second device determines that the reception of the first data packet fails; or,
- the first authentication code is different from the second authentication code
- the second device updates the second information and generates an updated second authentication code according to the updated second information
- the second device compares the updated second authentication code With the first authentication code, the receiving status of the first data packet is determined.
- the second device determines that the reception is successful, and the second device adds the preset value to the value of the updated second information. set value.
- the second device when the updated second authentication code is the same as the first authentication code, the second device generates and sends to the first device the first application receipt including the second indication information, and the second indication The message is used to indicate the message ID of the last successfully received packet.
- the second device when the updated second authentication code is the same as the first authentication code, the second device generates and sends to the first device a first application receipt indicating that the sending is successful.
- the second device when the updated second authentication code is different from the first authentication code, the second device generates and sends to the first device a first application for indicating failure to receive the first data packet. receipt.
- the second device compares the first authentication code with the second authentication code, specifically including: the first authentication code is the same as the second authentication code, The second device determines that the first data packet is successfully received; or,
- the first authentication code is different from the second authentication code, and the second device determines that the reception of the first data packet fails; or,
- the first authentication code is different from the second authentication code
- the second device updates the second information and generates a temporary authentication code according to the updated second information
- the second device compares the temporary authentication code with the first authentication code, and determines Receive status of the first packet.
- the second device when the temporary authentication code is the same as the first authentication code, the second device generates and sends the first application receipt including the second indication information to the first device, and the second indication information is used to indicate the latest successfully received data packet message ID; when the temporary authentication code is different from the first authentication code, the second device generates and sends to the first device a first application receipt for indicating failure to receive the first data packet.
- the method further includes:
- the second device adds a preset value to the value of the second information; the adjusted value of the second information is different from the value of the second information.
- the second device compares the third authentication code with the first authentication code, specifically including: the third authentication code is the same as the first authentication code, and the second device determines that the first data packet If the reception is successful, generate a first application layer receipt indicating that the first data packet is received successfully; or, the third authentication code is different from the first authentication code, and the second device determines that the first data packet has failed to receive, and generates a receipt for A first application layer receipt indicating that the first data packet fails to be received.
- the second device compares the third authentication code with the first authentication code, specifically including: the third authentication code is the same as the first authentication code, and the second device determines that the first data packet If the reception fails, generate a first application layer receipt indicating that the first data packet has failed to receive; wherein, the first application layer receipt includes the message ID corresponding to the successfully received data packet; or, the third authentication code is the same as the first authentication code codes are different, the second device determines that the first data packet fails to be received, and generates a first application layer receipt for indicating that the first data packet fails to be received.
- the method further includes: when the second device determines based on the second authentication code that the first data packet is received When successful, the second device sends a first application receipt to the first device, where the first application receipt is used to indicate that the first data packet is received successfully.
- the method further includes: when the second device determines based on the second authentication code that the first data packet is received In case of failure, the second device sends a first application receipt to the first device, and the first application receipt further includes a second message ID, and the second message ID indicates the message ID corresponding to the latest successfully transmitted data packet.
- the method further includes: when the second device determines based on the second authentication code that the first data packet is received In case of failure, the second device sends a first application receipt to the first device, where the first application receipt is used to indicate that the reception of the first data packet fails.
- the method further includes: the second device adds a preset value to the value of the second information; the second The adjusted value of the information is different from the value of the second information.
- the method further includes: the second device adjusts a value of the second information to a preset value.
- the method further includes: the second device receives the third information sent by the first device; the second device The value of the second information is adjusted to the value of the third information.
- the method further includes: the second device sends a second application receipt to the first device in the second transmission system Information, the second application receipt information is used to indicate the receiving status of the first data packet by the second device in the first transmission system.
- the present application provides a transmission method, including:
- the third device receives at least one second data packet sent by the first device
- the third device generates a first data packet based on at least one second data packet
- the third device sends the first data packet to the second device.
- the third device sends the second information or the fourth information to the second device, where the second information or the fourth information is receiving time information.
- the reception time information is used to indicate the time when the third device receives the first data packet in the at least one second data packet.
- the present application provides a transmission method, including:
- the first device receives the third data packet under the first transmission system
- the first device generates a third authentication code based on fifth information and the third data packet; wherein, the fifth information is sending time information or fifth context information; the first device determines the third data packet based on the third authentication code Receive status of the package.
- the first device generates the third authentication code based on the fifth information and the third data package, and further includes: the first device generates the third authentication code based on the fifth information, the third data package and the first key The third authentication code.
- the first device before the first device generates the third authentication code based on the fifth information, the first key, and the third data packet, it further includes: the first device obtains the first key, the first key The key is obtained through negotiation between the first device and the second device under the second transmission system; wherein, the first transmission system is different from the second transmission system.
- the first device before the first device generates the first authentication code based on the first information, the first key and the first data, it further includes: establishing a communication connection between the first device and the fourth device; The device acquires the first key through the fourth device.
- the first key is a key preset by the first device.
- the first transmission system is a satellite transmission system
- the second transmission system is a non-satellite transmission system
- the second transmission system is a cellular transmission system or a wireless local area network (WLAN) transmission system.
- WLAN wireless local area network
- the first device obtains the first key through negotiation with the second device through a generic bootstrapping architecture (Generic Bootstrapping Architecture, GBA) process under the second transmission system.
- GBA Generic Bootstrapping Architecture
- the first device determines the fourth authentication code according to the third data packet.
- the first device receiving the third data packet under the first transmission system specifically includes: the first device receiving at least one fourth data packet sent by the third device; the satellite link of the first device The control layer SLC layer and/or the message data convergence layer MDCP layer of the first device process at least one fourth data packet into a third data packet.
- the sixth information is reception time information.
- the reception time information is used to indicate the time when the first device receives the third data packet.
- the time when the first device receives the third data packet is the time when the first device receives the first fourth data packet in the at least one fourth data packet.
- the first device acquires the fifth information through positioning and timing.
- the first device obtains the fifth information in a preset encoding manner based on the receiving time information and the specified time granularity.
- the fifth information is fifth context information
- the fifth context information is used to indicate the number information of the third data packets successfully received by the first device, or the number of third data packets received by the first device Count value or serial number.
- the third data packet includes sixth indication information, and the sixth indication information is used to indicate a fourth message ID/fourth sequence number/fourth count value of the third data packet.
- the third data packet includes fourth indication information, and the fourth indication information is used to indicate that the third data packet is a newly transmitted data packet or a retransmitted data packet.
- the method before the first device generates the third authentication code according to the fifth information, the first key, and the third data packet, the method further includes: the first device acquires the first authentication code in the second transmission system The initial value of five information.
- the first device determines the receiving state of the third data packet based on the third authentication code, which specifically includes: the first device determines whether the third authentication code is the same as the fourth authentication code, Receive status of three packets.
- the first device determines the receiving status of the third data packet based on whether the third authentication code is the same as the fourth authentication code, specifically including:
- the third authentication code is the same as the fourth authentication code, and the first device determines that the third data packet is successfully received; or,
- the third authentication code is different from the fourth authentication code, and the first device determines that the reception of the third data packet fails; or,
- the third authentication code is different from the fourth authentication code.
- the first device generates temporary information based on the fifth information, and generates a temporary authentication code according to the temporary information.
- the first device compares the third authentication code and the temporary authentication code to determine The receiving status of the third data packet.
- the first device when the fourth authentication code is the same as the temporary authentication code, the first device generates and sends the third application receipt including the fifth indication information to the second device; when the fourth authentication code and the temporary authentication code are different , the first device generates and sends a failure application receipt to the second device.
- the third authentication code is different from the fourth authentication code
- the first setting is to update the value of the fifth information, and generate an updated third authentication code according to the updated fifth information
- the first device compares the updated third authentication code with the fourth authentication code, and determines the receiving status of the third data packet.
- the first device when the updated third authentication code is the same as the fourth authentication code, the first device generates and sends the third application receipt including the fifth indication information to the second device; when the updated When the last third authentication code is different from the fourth authentication code, the first device generates and sends to the second device a third application receipt for indicating sending failure.
- the first device when the updated third authentication code is the same as the fourth authentication code, the first device generates and sends to the second device a third application receipt for indicating that the sending is successful.
- the first device when the updated third authentication code is the same as the fourth authentication code, the first device adds a preset value to the updated value of the fifth information.
- the indication application receipt includes fifth indication information, and the value of the fifth indication information is the same as the value of the sixth indication information of the latest successfully received data packet.
- the method further includes:
- a preset value is added to the value of the fifth information; the adjusted value of the fifth information is different from the value of the fifth information.
- the method further includes: the first device sends a third application receipt to the second device, and the third application The receipt is used to indicate the receiving status of the third data packet.
- the method further includes: when the first device determines that the receiving status of the third data packet is received correctly , the first device adds a preset value to the value of the fifth information; the adjusted value of the fifth information is different from the value of the fifth information.
- the method further includes: when the first device determines that the reception status of the third data packet is reception failure , the first device updates the value of the fifth information to a preset value.
- the preset value is an initial value.
- the method further includes: the first device receives seventh information sent by the second device; and the first device updates the fifth information to a value of the seventh information based on the seventh information.
- the method further includes: the first device displays the third data.
- the method further includes:
- the first device sends third application receipt information to the second device in the second transmission system, where the third application receipt information is used to indicate a receiving status of the third data packet by the second device in the first transmission system.
- the present application provides a transmission method, including: the second device generates a fourth authentication code based on the sixth information and the first data; wherein, the sixth information is sending time information or sixth context information; the second The application AP layer of the device generates a third data packet according to the fourth authentication code and the first data; the second device sends the third data packet to the first device under the first transmission system.
- the second device generates the fourth authentication code based on the sixth information and the first data, and further includes: the second device generates the fourth authentication code based on the sixth information, the first key and the first data. right code.
- the method before the second device generates the fourth authentication code based on the sixth information, the first key, and the first data, the method further includes:
- the second device obtains the first key, and the first key is obtained by the first device through negotiation with the second device under the second transmission system; wherein, the first transmission system is different from the second transmission system.
- the first key is a preset key.
- the second device and the first device obtain the first key through a generic bootstrapping architecture (Generic Bootstrapping Architecture, GBA) process under the second transmission system.
- GBA Generic Bootstrapping Architecture
- the second device sending the third data packet to the first device under the first transmission system specifically includes: the second device sending the third data packet to the first device through the third device.
- the sixth information is used to indicate sending time information.
- the sending time information is used to indicate the time when the fourth authentication code is generated, or the time when the second device sends the third data packet.
- the time when the second device sends the third data packet is the time when the second device sends the third data packet to the third device, or is the time when the second device sends the third data packet The time when the packet was sent to the first device.
- the second device adds the fourth authentication code to the third data packet after packaging the third data packet.
- the format of the generation time of the fourth authentication code is Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT).
- the minimum time granularity of the generation time of the fourth authentication code includes any one of year, month, day number, hour, minute, and second.
- the second device obtains the sixth information by specifying an encoding manner based on the sending time information and the specified time granularity.
- the method before the second device generates the fourth authentication code based on the sixth information, the first key, and the first data, the method further includes: the second device acquires the sixth information through the third device.
- the method before the second device generates the fourth authentication code based on the sixth information, the first key and the first data, the method further includes: the second device receives the eighth information sent by the third device ; The second device generates sixth information based on the eighth information.
- the second device receives sixth information sent by the third device.
- the sixth information is sixth context information
- the sixth context information is used to indicate the number information of the third data packet successfully sent by the second device, or the number information of the application receipt successfully received by the second device , or the count value or sequence value of the third data packet sent by the second device.
- the method further includes: the second device acquires an initial value of the sixth information in the second transmission system; or, the second device resets the sixth information to a preset value in the second transmission system .
- the third data packet further includes sixth indication information, where the sixth indication information is used to indicate the fourth message ID of the third data packet, or the sixth indication information is used to indicate the ID of the third data packet. Fourth count value or fourth sequence number.
- the method further includes: associating the fourth count value or the fourth sequence number with the application layer of the second device Four sequence numbers to the third data packet, the second device adds a preset value to the fourth count value or the value of the fourth sequence number.
- the third data packet further includes fourth indication information, where the fourth indication information is used to indicate new transmission and retransmission information of the third data packet.
- the application AP layer of the second device generates the third data packet according to the fourth authentication code and the first data, which specifically includes: the application layer of the second device encrypts the fourth authentication code based on the first key; The authorization code and the first data to generate a third data packet; wherein, the third data packet includes the encrypted fourth authentication code and the encrypted first data.
- the method further includes:
- the second device receives the third application layer receipt sent by the first device; wherein, the third application layer receipt is used to instruct the first device to receive a receiving status of the third data packet.
- the method further includes: the second device adds a preset value to the value of the sixth information; The latter value is different from the value of the sixth information.
- the second device receives fourth application receipt information in the second transmission system, where the fourth application receipt information is used to indicate the sending status of the third data packet by the second device in the first transmission system;
- the second device updates the sending status according to the second application receipt information.
- the second device deletes the successfully sent third data packet.
- the present application provides a transmission method, including:
- the third device receives the third data packet sent by the second device
- the third device generates at least one fourth data packet according to the third data packet
- the third device sends at least one fourth data packet to the first device.
- the method before the third device receives the third data packet sent by the second device, the method further includes: the third device sends the second information or the fourth information to the second device, and the second information or the first The fourth information is time information.
- the present application provides a transmission method, including:
- the first device generates a first authentication code based on the first information, the first key, and the first data; wherein, the first information is sending time information or first context information; the first device generates a first authentication code based on the first authentication code and the first The data generates a first data packet; the first device sends the first data packet to the second device under the first transmission system.
- the method before the first device generates the first authentication code based on the first information, the first key, and the first data, the method further includes: the first device obtains the first key, and the first key The key is obtained through negotiation between the first device and the second device under the second transmission system; wherein, the first transmission system is different from the second transmission system.
- the method before the first device generates the first authentication code based on the first information, the first key, and the first data, the method further includes: the first device establishes a communication connection with the fourth device; A device obtains the first key through the fourth device.
- the first key is a key preset by the first device.
- the second transmission system is a cellular transmission system or a wireless local area network (WLAN) transmission system
- the first transmission system is a satellite transmission system.
- the first device obtains the first key through negotiation with the second device under the second transmission system through a GBA process.
- the sending time information is used to indicate the time when the first authentication code is generated, or indicate the time when the first device sends the first data packet.
- the time when the first device sends the first data packet is the time when the application AP layer of the first device sends the first data packet to the message data convergence MDCP layer, or is the time estimated by the first device The time when the first packet was sent to the second device.
- the first device acquires the sending time information through positioning and timing.
- the first data includes packaged first data and a first authentication code.
- the format of the sending time of the data packet is UTC or GMT.
- the specified time granularity of the sending time of the data packet includes any one of year, month, day number, hour, minute, and second.
- the first device and the second device negotiate to update the specified time granularity in the second transmission system.
- the first device acquires the sending time information through the fourth device.
- the first device obtains the first information in a preset encoding manner based on the sending time information and the specified time granularity.
- the method further includes:
- the first device receives the first application layer receipt sent by the second device; wherein, the first application layer receipt is used to instruct the second device to receive the receiving status of the first data packet.
- the first information is first context information
- the first context information is used to indicate the number of first data packets successfully sent by the first device, or the number of application receipts successfully received by the first device information, or the count value or sequence number of the first data packet sent by the first device.
- the first data packet further includes first indication information, where the first indication information is used to indicate the first message ID of the first data packet, or the first indication information is used to indicate the first message ID of the first data packet.
- the AP layer of the first device associates the first message ID or the first count value or the first sequence number with the first data packet, and the first device associates the first message ID or the first count value or Increment the default value on the value of the first serial number.
- the first data packet further includes third indication information, where the third indication information is used to indicate that the first data packet is a newly transmitted data packet or a retransmitted data packet.
- the third indication information when the value of the third indication information is the first value, the third indication information indicates that the first data packet is a newly transmitted data packet; when the value of the third indication information is the second value, The third indication information indicates that the first data packet is a retransmission data packet.
- the method before the first device generates the first authentication code based on the first information, the first key, and the first data, the method further includes:
- the first device acquires the initial value of the first information in the second transmission system; or,
- the first device acquires the initial value of the first information through the fourth device.
- the method further includes:
- the first device receives the first application layer receipt sent by the second device; wherein, the first application layer receipt is used to instruct the second device to receive the receiving status of the first data packet.
- the method further includes:
- the first device adds a preset value to the value of the first information; the adjusted value of the first information is different from the value of the first information.
- the method further includes: when the first application receipt is used to indicate that the second device fails to receive the first data packet, The first device adjusts the value of the first information to an initial value.
- the method further includes: the first device sends third information to the second device, the value of the third information and the adjusted first The value of one message is the same.
- the method further includes: when the first application receipt indicates that the first data packet is sent successfully, the first device displays the success Prompt information, the success prompt information is used to prompt the user that the message corresponding to the first data packet is sent successfully.
- the method further includes: when the first application receipt indicates that the sending of the first data packet failed, the first device displays failure Prompt information, the failure prompt information is used to prompt the user that the message corresponding to the first data packet fails to be sent.
- the method further includes: when the first application receipt includes the second message ID information, the first device displays success prompt information
- the success prompt information is used to prompt the user that the data packet indicated by the second message ID information is sent successfully.
- the application layer of the first device generates the first data packet according to the first authentication code and the first data, which specifically includes: the application layer of the first device encrypts the first authentication code based on the first key code and first data to generate a first data packet; wherein, the first data packet includes the encrypted first authentication code and the encrypted first data.
- the application layer of the first device encrypts the first data based on the first key to generate a first data packet; where the first data packet includes the encrypted first data.
- the method further includes: the first device receives the second application receipt information in the second transmission system, and the first The second application receipt information is used to indicate the sending status of the first data packet by the first device in the first transmission system.
- the method further includes: the first device displays sending prompt information, and sending the prompt information is used to remind the user that the second A device has sent a first data packet to a second device.
- the present application provides a transmission method, including: the second device receives the first data packet sent by the first device under the first transmission system; the second device receives the first data packet according to the second information, the first key, the first The data packet generates a second authentication code; wherein, the second information is receiving time information or second context information; the second device determines the receiving state of the first data packet based on the second authentication code.
- the method before the second device generates the second authentication code according to the second information, the first key, and the first data packet, the method further includes: the second device obtains the first key, the first The key is obtained by the second device through negotiation with the first device under the second transmission system; wherein, the second transmission system is different from the first transmission system.
- the second transmission system is a cellular transmission system or a WLAN transmission system
- the first transmission system is a satellite transmission system.
- the second device obtains the first key through negotiation with the first device under the second transmission system through a general bootstrap framework (GBA) procedure.
- GBA bootstrap framework
- the first key is a key preset by the first device.
- the second device receiving the first data packet under the first transmission system specifically includes: receiving at least one second data packet sent by the first device at a satellite link control layer SLC layer of the second device ;
- the message data convergence layer MDCP layer of the second device and/or the satellite link control layer SLC layer of the first device obtains the first data packet based on at least one second data packet.
- the second device determines the first authentication code according to the first data packet.
- the receiving time information is used to indicate the receiving time of the first data packet.
- the method before the second device generates the second authentication code according to the second information, the first key, and the first data packet, the method further includes: the second device acquires the second authentication code at the MDCP layer/SLC layer A receiving time of a data packet; the second device generates second information based on the receiving time of the first data packet at the MDCP layer/SLC layer.
- the method before the second device generates the second authentication code according to the second information, the first key, and the first data packet, the method further includes: the second device acquires the second authentication code at the MDCP layer/SLC layer The receiving time of a data packet; the second device determines that the receiving time of the first data packet is the eighth information, and uploads the eighth information to the AP layer; the second device generates second information based on the eighth information at the AP layer.
- the second context information is used to indicate information about the number of first data packets successfully received by the second device, or a count value or a sequence value of the first data packets received by the second device.
- the first data packet includes first indication information, and the first indication information is used to indicate a first message ID/first sequence number/first count value of the first data packet.
- the first data packet includes third indication information, and the third indication information is used to indicate that the first data packet is a newly transmitted data packet/a retransmitted data packet.
- the method before the second device generates the second authentication code according to the second information, the first key, and the first data packet, the method further includes: the second device acquires the second authentication code in the second transmission system The initial value of the second message.
- the second device determines the receiving state of the first data packet based on the second authentication code, which specifically includes: the second device determines whether the second authentication code is the same as the second authentication code Receive status of a data packet.
- the second device compares the first authentication code with the second authentication code, specifically including: the first authentication code is the same as the second authentication code, The second device determines that the first data packet is successfully received; or,
- the first authentication code is different from the second authentication code, and the second device determines that the reception of the first data packet fails; or,
- the first authentication code is different from the second authentication code
- the second device updates the second information and generates a temporary authentication code according to the updated second information
- the second device compares the temporary authentication code with the first authentication code, and determines Receive status of the first packet.
- the second device when the temporary authentication code is the same as the first authentication code, the second device generates and sends the first application receipt including the second indication information to the first device, and the second indication information is used to indicate the latest successfully received data packet message ID; when the temporary authentication code is different from the first authentication code, the second device generates and sends to the first device a first application receipt for indicating failure to receive the first data packet.
- the method further includes:
- the second device adds a preset value to the value of the second information; the adjusted value of the second information is different from the value of the second information.
- the second device compares the third authentication code with the first authentication code, specifically including: the third authentication code is the same as the first authentication code, and the second device determines that the first data packet If the reception is successful, generate a first application layer receipt indicating that the first data packet is received successfully; or, the third authentication code is different from the first authentication code, and the second device determines that the first data packet has failed to receive, and generates a receipt for A first application layer receipt indicating that the first data packet fails to be received.
- the second device compares the third authentication code with the first authentication code, specifically including: the third authentication code is the same as the first authentication code, and the second device determines that the first data packet If the reception fails, generate a first application layer receipt indicating that the first data packet has failed to receive; wherein, the first application layer receipt includes the message ID corresponding to the successfully received data packet; or, the third authentication code is the same as the first authentication code codes are different, the second device determines that the first data packet fails to be received, and generates a first application layer receipt for indicating that the first data packet fails to be received.
- the method further includes: when the second device determines based on the second authentication code that the first data packet is received When successful, the second device sends a first application receipt to the first device, where the first application receipt is used to indicate that the first data packet is received successfully.
- the method further includes: when the second device determines based on the second authentication code that the first data packet is received In case of failure, the second device sends a first application receipt to the first device, and the first application receipt further includes a second message ID, and the second message ID indicates the message ID corresponding to the latest successfully transmitted data packet.
- the method further includes: when the second device determines based on the second authentication code that the first data packet is received In case of failure, the second device sends a first application receipt to the first device, where the first application receipt is used to indicate that the reception of the first data packet fails.
- the method further includes: the second device adds a preset value to the value of the second information; the second The adjusted value of the information is different from the value of the second information.
- the method further includes: the second device adjusts a value of the second information to a preset value.
- the method further includes: the second device receives the third information sent by the first device; the second device The value of the second information is adjusted to the value of the third information.
- the method further includes: the second device sends a second application receipt to the first device in the second transmission system Information, the second application receipt information is used to indicate the receiving status of the first data packet by the second device in the first transmission system.
- the present application provides a transmission method, including:
- the first device receives the third data packet under the first transmission system
- the first device generates a third authentication code based on fifth information and the third data packet; wherein, the fifth information is sending time information or fifth context information; the first device determines the third data packet based on the third authentication code Receive status of the package.
- the first device generates the third authentication code based on the fifth information and the third data package, and further includes: the first device generates the third authentication code based on the fifth information, the third data package and the first key The third authentication code.
- the first device before the first device generates the third authentication code based on the fifth information, the first key, and the third data packet, it further includes: the first device obtains the first key, the first key The key is obtained through negotiation between the first device and the second device under the second transmission system; wherein, the first transmission system is different from the second transmission system.
- the first device before the first device generates the first authentication code based on the first information, the first key and the first data, it further includes: establishing a communication connection between the first device and the fourth device; The device acquires the first key through the fourth device.
- the first key is a key preset by the first device.
- the first transmission system is a satellite transmission system
- the second transmission system is a non-satellite transmission system
- the second transmission system is a cellular transmission system or a wireless local area network (WLAN) transmission system.
- WLAN wireless local area network
- the first device obtains the first key through negotiation with the second device through a generic bootstrapping architecture (Generic Bootstrapping Architecture, GBA) process under the second transmission system.
- GBA Generic Bootstrapping Architecture
- the first device determines the fourth authentication code according to the third data packet.
- the first device receiving the third data packet under the first transmission system specifically includes: the first device receiving at least one fourth data packet sent by the second device; the satellite link of the first device The control layer SLC layer and/or the message data convergence layer MDCP layer of the first device process at least one fourth data packet into a third data packet.
- the sixth information is reception time information.
- the reception time information is used to indicate the time when the first device receives the third data packet.
- the time when the first device receives the third data packet is the time when the first device receives the first fourth data packet in the at least one fourth data packet.
- the first device acquires the fifth information through positioning and timing.
- the first device obtains the fifth information in a preset encoding manner based on the receiving time information and the specified time granularity.
- the fifth information is fifth context information
- the fifth context information is used to indicate the number information of the third data packets successfully received by the first device, or the number of third data packets received by the first device Count value or serial number.
- the third data packet includes sixth indication information, and the sixth indication information is used to indicate a fourth message ID/fourth sequence number/fourth count value of the third data packet.
- the third data packet includes fourth indication information, and the fourth indication information is used to indicate that the third data packet is a newly transmitted data packet or a retransmitted data packet.
- the method before the first device generates the third authentication code according to the fifth information, the first key, and the third data packet, the method further includes: the first device acquires the first authentication code in the second transmission system The initial value of five information.
- the first device determines the receiving state of the third data packet based on the third authentication code, which specifically includes: the first device determines whether the third authentication code is the same as the fourth authentication code, Receive status of three packets.
- the first device determines the receiving status of the third data packet based on whether the third authentication code is the same as the fourth authentication code, specifically including:
- the third authentication code is the same as the fourth authentication code, and the first device determines that the third data packet is successfully received; or,
- the third authentication code is different from the fourth authentication code, and the first device determines that the reception of the third data packet fails; or,
- the third authentication code is different from the fourth authentication code
- the first device generates temporary information based on the second information, and generates a temporary authentication code according to the temporary information
- the first device compares the third authentication code with the temporary authentication code, A reception status of the third data packet is determined.
- the first device when the fourth authentication code is the same as the temporary authentication code, the first device generates and sends an application receipt to the second device; when the fourth authentication code is different from the temporary authentication code, the first device generates and sends a receipt to the second device The second device sends a failure application receipt.
- the indication application receipt includes fifth indication information, and the value of the fifth indication information is the same as the value of the sixth indication information of the latest successfully received data packet.
- the method further includes:
- a preset value is added to the value of the fifth information; the adjusted value of the fifth information is different from the value of the fifth information.
- the method further includes: the first device sends a third application receipt to the second device, and the third application The receipt is used to indicate the receiving status of the third data packet.
- the method further includes: when the first device determines that the receiving status of the third data packet is received correctly , the first device adds a preset value to the value of the fifth information; the adjusted value of the fifth information is different from the value of the fifth information.
- the method further includes: when the first device determines that the reception status of the third data packet is reception failure , the first device updates the value of the fifth information to a preset value.
- the preset value is an initial value.
- the method further includes: the first device receives seventh information sent by the second device; and the first device updates the fifth information to a value of the seventh information based on the seventh information.
- the method further includes: the first device displays the third data.
- the method further includes:
- the first device sends third application receipt information to the second device in the second transmission system, where the third application receipt information is used to indicate a receiving status of the third data packet by the second device in the first transmission system.
- the present application provides a transmission method, including:
- the second device generates a fourth authentication code based on the sixth information and the first data; wherein, the sixth information is sending time information or sixth context information; the application AP layer of the second device generates the fourth authentication code based on the fourth authentication code and the first data A third data packet is generated; the second device sends the third data packet to the first device under the first transmission system.
- the second device generates the fourth authentication code based on the sixth information and the first data, and further includes: the second device generates the fourth authentication code based on the sixth information, the first key and the first data. right code.
- the method before the second device generates the fourth authentication code based on the sixth information, the first key, and the first data, the method further includes:
- the second device obtains the first key, and the first key is obtained by the first device through negotiation with the second device under the second transmission system; wherein, the first transmission system is different from the second transmission system.
- the first key is a preset key.
- the second device and the first device obtain the first key through a generic bootstrapping architecture (Generic Bootstrapping Architecture, GBA) process under the second transmission system.
- GBA Generic Bootstrapping Architecture
- the second device sending the third data packet to the first device under the first transmission system specifically includes: the second device sending the third data packet to the first device through the third device.
- the sixth information is used to indicate sending time information.
- the sending time information is used to indicate the time when the fourth authentication code is generated, or the time when the second device sends the third data packet.
- the time when the second device sends the third data packet is the time when the second device sends the third data packet to the third device, or is the time when the second device sends the third data packet The time when the packet was sent to the first device.
- the second device adds the fourth authentication code to the third data packet after packaging the third data packet.
- the format of the generation time of the fourth authentication code is Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT).
- the minimum time granularity of the generation time of the fourth authentication code includes any one of year, month, day number, hour, minute, and second.
- the second device obtains the sixth information by specifying an encoding manner based on the sending time information and the specified time granularity.
- the method before the second device generates the fourth authentication code based on the sixth information, the first key, and the first data, the method further includes: the second device acquires the sixth information through the third device.
- the method before the second device generates the fourth authentication code based on the sixth information, the first key and the first data, the method further includes: the MDCP layer/SLC layer of the second device obtains the eighth information; the second device generates sixth information based on the eighth information at the AP layer.
- the second device generates sixth information at the MDCP layer/SLC layer.
- the sixth information is sixth context information
- the sixth context information is used to indicate the number information of the third data packet successfully sent by the second device, or the number information of the application receipt successfully received by the second device , or the count value or sequence value of the third data packet sent by the second device.
- the method further includes: the second device acquires an initial value of the sixth information in the second transmission system; or, the second device resets the sixth information to a preset value in the second transmission system .
- the third data packet further includes sixth indication information, where the sixth indication information is used to indicate the fourth message ID of the third data packet, or the sixth indication information is used to indicate the ID of the third data packet. Fourth count value or fourth sequence number.
- the method further includes: associating the fourth count value or the fourth sequence number with the application layer of the second device Four sequence numbers to the third data packet, the second device adds a preset value to the fourth count value or the value of the fourth sequence number.
- the third data packet further includes fourth indication information, where the fourth indication information is used to indicate new transmission and retransmission information of the third data packet.
- the application AP layer of the second device generates the third data packet according to the fourth authentication code and the first data, which specifically includes: the application layer of the second device encrypts the fourth authentication code based on the first key; The authorization code and the first data to generate a third data packet; wherein, the third data packet includes the encrypted fourth authentication code and the encrypted first data.
- the method further includes:
- the second device receives the third application layer receipt sent by the first device; wherein, the third application layer receipt is used to instruct the first device to receive a receiving status of the third data packet.
- the method further includes: the second device adds a preset value to the value of the sixth information; The latter value is different from the value of the sixth information.
- the second device receives fourth application receipt information in the second transmission system, where the fourth application receipt information is used to indicate the sending status of the third data packet by the second device in the first transmission system;
- the second device updates the sending status according to the second application receipt information.
- the second device deletes the successfully sent third data packet.
- the present application provides a transmission method, including:
- the sending device generates an authentication code A based on the information A and original data; wherein, the information A is sending time information or context information A; the sending device obtains a data packet based on the authentication code A and the original data; the sending device is under the first transmission system Send the packet to the receiving device.
- the sending device generates the authentication code A based on the information A and original data, which specifically includes: the sending device generates the authentication code A based on the information A, the specified key and the original data.
- the sending device negotiates with the receiving device to obtain a specified key under the second transmission system.
- the first transmission system is different from the second transmission system.
- the designated key is a key preset by the sending device.
- the second transmission system is a cellular transmission system or a wireless local area network (WLAN) transmission system
- the first transmission system is a satellite transmission system.
- the sending device negotiates with the receiving device to obtain a specified key through a general bootstrap framework (GBA) procedure under the second transmission system.
- GSA bootstrap framework
- the information A is sending time information
- the information A is used to indicate the sending time of the data packet.
- the time when the sending device sends the data packet is the time when the application AP layer of the sending device sends the data packet to the message data convergence MDCP layer, or is the estimated time for the sending device to send the data packet to the receiving device time.
- the information A is the context information A, and the information A is used to indicate the quantity information of the sent data packets, or the sequence number or count value of the data packets.
- the data packet further includes a message ID field A, and the message ID field A is used to identify the data packet.
- the data packet further includes a sequence number field A, where the sequence number field A is used to identify the data packet and is also used to indicate information A.
- the sending device associates the sequence number A with the data packet, and generates the sequence number field A based on the sequence number A.
- the sending device associates the message ID with the data packet, and generates the message ID field A based on the message ID.
- the data packet further includes a retransmission indication field, and the retransmission indication field is used to indicate that the data packet is a retransmission data packet or a new transmission data packet.
- the sending device encrypts the original data and authentication code A with a specified key, and then adds header information before the encrypted original data and authentication code A to obtain a data packet; wherein, the header The information includes an encryption indication field, and the encryption indication field is used to indicate the encryption algorithm used by the sending device.
- the method further includes: the sending device adds a preset value to the sequence number A; the sending device No. A, adjust the value of context information A.
- the sending device adjusts the value of the context information A based on the adjusted sequence number A, which specifically includes: the sending device determines the value of the superframe number A based on the adjusted sequence number A, and based on the adjusted After the sequence number A and superframe number A, adjust the value of the context information A.
- the sending device is a terminal
- the receiving device is a satellite network device.
- the sending device is a satellite network device
- the receiving device is a terminal
- the method further includes: after the sending device receives the successful application receipt sent by the receiving device, in the context information A A preset value is added to the value; wherein, the successful application receipt is used to indicate that the receiving device receives the data packet successfully.
- the sending device when the sending device is a terminal; after the sending device sends the data packet to the receiving device under the first transmission system, the method further includes: the sending device receives the successful application receipt sent by the receiving device After that, the sending device displays a success prompt message, which is used to prompt the user that the data packet is sent successfully.
- the sending device when the sending device is a satellite network device; after the sending device sends the data packet to the receiving device under the first transmission system, the method further includes: After the receipt is applied, the sending device deletes the packet in memory.
- the method further includes: after the sending device receives the application failure receipt sent by the receiving device, in the context information A A preset value is added to the value; wherein, the failure application receipt is used to indicate that the receiving device fails to receive the data packet.
- the method further includes: the sending device adjusts the content of the context information A after receiving the application failure receipt sent by the receiving device.
- the value is the default value.
- the method further includes: the sending device sends the value of the context information A to the receiving device.
- the method further includes: after the sending device receives the application failure receipt sent by the receiving device, the sending device and the receiving device The value of the context information A is negotiated under the second transmission system.
- the sending device when the sending device is a terminal; after the sending device sends the data packet to the receiving device under the first transmission system, the method further includes: the sending device receives the application failure receipt sent by the receiving device After that, the sending device displays a failure prompt message, which is used to prompt the user that the data packet transmission fails.
- the method further includes: after the sending device receives the application receipt sent by the receiving device, the sending device sends the context information The value of A is increased by a preset value; wherein, the indication application receipt is used to indicate that the current data packet fails to be sent; wherein, the indication application receipt includes a message ID field B, and the message ID field B is used to indicate the latest successfully sent data packet.
- the sending device when the sending device is a terminal; after the sending device sends the data packet to the receiving device under the first transmission system, the method further includes: the sending device receives the instruction application receipt sent by the receiving device Finally, the sending device displays success prompt information and failure prompt information, the success prompt information is used to prompt the user that the data packet indicated by the message ID field B is successfully sent, and the failure prompt information is used to prompt the user that the current data packet transmission fails.
- the sending device when the sending device is a terminal; after the sending device sends the data packet to the receiving device under the first transmission system, the method further includes: the sending device displays sending prompt information, and the sending prompt information is used for Prompt the user that the sending device has sent a packet to the receiving device.
- the method further includes: after the sending device receives the collection application receipt sent by the receiving device under the second transmission system, The reception status of the data packets sent under the first transmission transmission system is determined based on the collective application receipt.
- the present application provides a transmission method, including: the receiving device receives the data packet sent by the sending device under the first transmission system; the receiving device generates an authentication code B based on the information B and the data packet; wherein, the information B is receiving time information or context information B; the receiving device determines the receiving status of the data packet based on the authentication code B.
- the receiving device generates the authentication code B based on the information B and the original data, which specifically includes: the receiving device generates the authentication code B based on the information B, the specified key and the original data.
- the receiving device negotiates with the sending device to obtain a specified key under the second transmission system.
- the first transmission system is different from the second transmission system.
- the designated key is a key preset by the receiving device.
- the second transmission system is a cellular transmission system or a wireless local area network (WLAN) transmission system
- the first transmission system is a satellite transmission system.
- the receiving device obtains the specified key through negotiation with the sending device under the second transmission system through a GBB process.
- the information B when the information B is receiving time information, the information B is used to indicate the receiving time of the data packet.
- the time when the receiving device receives the data packet is the time when the satellite link control SLC layer of the receiving device receives the first SLC PDU of the data packet.
- the information B is context information B, and the information B is used to indicate the quantity information of the received data packets, or the sequence number or count value of the data packets.
- the data packet further includes a sequence number field A, where the sequence number field A is used to identify the data packet and is also used to indicate context information B.
- the receiving device determines the value of the context information B based on the serial number field A and the stored serial number B.
- the receiving device determines the value of the context information B based on the serial number field A and the stored serial number B, which specifically includes: the receiving device determines the values of the serial number field A and the serial number B, The value of the superframe number B is determined; the receiving device obtains the context information B based on the sequence number field A and the superframe number B.
- the receiving device when the value of the sequence number field A is less than or equal to the value of the sequence number B, the receiving device adds a preset value to the value of the hyperframe number B.
- the receiving device concatenates the hyperframe number B and the sequence number field A to obtain the context information B.
- the value of the serial number B may be adjusted to the value of the serial number field A.
- the data packet further includes a message ID field A, and the message ID field A is used to identify the data packet.
- the receiving device is a satellite network device
- the sending device is a terminal
- the receiving device is a terminal
- the sending device is a satellite network device.
- the receiving device acquires the authentication code A based on the data packet.
- the receiving device determines the receiving state of the data packet based on the authentication code B, which specifically includes: the receiving device compares the authentication code A and the authentication code B to determine the receiving state of the data packet.
- the receiving device compares the authentication code A and the authentication code B to determine the receiving status of the data packet, which specifically includes: when the authentication code B and the authentication code A are the same, the receiving device determines that the data packet is successfully received .
- the method further includes: the receiving device generates a successful application receipt, and the successful application receipt is used to indicate that the receiving device successfully receives the data packet; Application receipt.
- the data packet includes a message ID field A; after the receiving device determines that the data packet is received successfully, the method further includes: the receiving device adjusts the value of the message ID field B to the value of the message ID field A.
- the method when the receiving device is a terminal; after the receiving device determines that the data packet is successfully received, the method further includes: the receiving device displays the original data.
- the method when the receiving device is a satellite network device; after the receiving device determines that the data packet is successfully received, the method further includes: the receiving device sends the original data to the electronic device under the second transmission system equipment.
- the receiving device compares the authentication code A and the authentication code B to determine the receiving status of the data packet, which specifically includes: when the authentication code B and the authentication code A are different, the receiving device determines that the data packet has failed to receive .
- the method further includes: the receiving device generates a failure application receipt, and the failure application receipt is used to indicate that the receiving device fails to receive the data packet; the receiving device sends the sending device Failed application receipt.
- the method further includes: the receiving device generates an application indication receipt based on the message ID field B, the application indication receipt is used to indicate that the receiving device fails to receive the data packet, and the message ID Field B is used to indicate that the receiving device has recently successfully received the data packet; the receiving device sends the indication application receipt to the sending device.
- the method further includes: the receiving device generates information C based on information B, and generates an authentication code based on information C. code C, the receiving device determines whether the sending device has not received the latest successful application receipt based on the authentication code C.
- the receiving device when the authentication code C is the same as the authentication code A, that is, the receiving device determines that the sending device has not received the latest successful application receipt, the receiving device sends the successful application receipt to the sending device.
- the receiving device when the authentication code C is different from the authentication code A, the receiving device sends a failure application receipt to the sending device.
- the data packet further includes a retransmission indication field, and the retransmission indication field is used to indicate that the data packet is a retransmission data packet or a new transmission data packet.
- the method further includes: the receiving device determines that the data packet includes a message indicating that the data packet is a newly transmitted data packet; In the retransmission indication field, the receiving device generates and sends a failure application receipt to the sending device.
- the method further includes: the receiving device determines that the data packet includes a message indicating that the data packet is a retransmitted data packet In the retransmission indication field, the receiving device generates information C based on information B, and generates an authentication code C based on information C, and the receiving device determines whether the sending device has not received the latest successful application receipt based on the authentication code C.
- the receiving device when the authentication code C is the same as the authentication code A, that is, the receiving device determines that the sending device has not received the latest successful application receipt, the receiving device sends the successful application receipt to the sending device.
- the receiving device when the authentication code C is different from the authentication code A, the receiving device sends a failure application receipt to the sending device.
- the receiving device sends a collection application receipt to the sending device under the second transmission system, where the collection application receipt is used to indicate the receiving device's reception status of the data packet for the sending device under the first transmission system.
- the present application provides a satellite communication system, including: a sending device and a receiving device; wherein,
- the sending device is configured to generate an authentication code A based on the information A and original data; where the information A is sending time information or context information A;
- the sending device is also used to obtain the data packet based on the authentication code A and the original data;
- the sending device is further configured to send the data packet to the receiving device under the first transmission system.
- the receiving device is configured to receive the data packet sent by the sending device under the first transmission system
- the receiving device is also used to generate an authentication code B based on the information B and the data packet; wherein, the information B is receiving time information or context information B;
- the receiving device is further configured to determine the receiving status of the data packet based on the authentication code B.
- the present application provides a communication device, including one or more processors, one or more memories, and a transceiver; wherein, the transceiver, one or more memories and one or more The processors are coupled, and one or more memories are used to store computer program codes.
- the computer program codes include computer instructions.
- the communication device performs the eleventh aspect or the twelfth aspect. any of the methods.
- the communication device is a terminal or a satellite network device.
- the present application provides a computer-readable storage medium, where instructions are stored in the computer-readable storage medium, and when the instructions are run on a computer, the computer is made to perform the eleventh aspect or the tenth aspect. Either of the two methods.
- the present application provides a chip or a chip system, applied to a terminal, including a processing circuit and an interface circuit, the interface circuit is used to receive code instructions and transmit them to the processing circuit, and the processing circuit is used to run the code Instructions to perform the method according to any one of the eleventh aspect or the twelfth aspect.
- the present application provides a communication device, including one or more processors, one or more memories, and a transceiver.
- the transceiver, the one or more memories are coupled to the one or more processors, the one or more memories are used to store computer program codes, the computer program codes include computer instructions, and when the one or more processors execute the computer instructions, the The communication device executes the method in any possible implementation manner of the first aspect, the fourth aspect, the seventh aspect, or the ninth aspect.
- the communication device may be a terminal or other product form equipment.
- the present application provides a communication device, including one or more processors, one or more memories, and a transceiver.
- the transceiver, the one or more memories are coupled to the one or more processors, the one or more memories are used to store computer program codes, the computer program codes include computer instructions, and when the one or more processors execute the computer instructions, the The communication device executes the method in any possible implementation manner of the second aspect, the fifth aspect, the eighth aspect, or the tenth aspect above.
- the communication device may be satellite network equipment, or any network element or a combination of multiple network elements in the satellite network equipment.
- the present application provides a communication device, including one or more processors, one or more memories, and a transceiver.
- the transceiver, the one or more memories are coupled to the one or more processors, the one or more memories are used to store computer program codes, the computer program codes include computer instructions, and when the one or more processors execute the computer instructions, the The communication device executes the method in any possible implementation manner of the third aspect and the sixth aspect above.
- the communication device may be any network element or a combination of multiple network elements in the satellite network equipment.
- the present application provides a computer storage medium, including computer instructions.
- the computer instructions When the computer instructions are run on the computer, the computer is made to execute any one of the first aspect, the fourth aspect, the seventh aspect or the ninth aspect. method in a possible implementation.
- the present application provides a computer storage medium, including computer instructions.
- the computer instructions When the computer instructions are run on the computer, the computer executes any one of the above-mentioned second aspect, fifth aspect, eighth aspect or tenth aspect. method in a possible implementation.
- the present application provides a computer storage medium, including computer instructions.
- the computer instructions When the computer instructions are run on the computer, the computer executes the method in any possible implementation manner of the third aspect and the sixth aspect above.
- the present application provides a computer program product that, when the computer program product is run on a computer, enables the computer to execute any possible implementation of the above-mentioned first aspect, fourth aspect, seventh aspect or ninth aspect methods in methods.
- the present application provides a computer program product.
- the computer program product When the computer program product is run on a computer, it enables the computer to perform any one of the possible tasks of the second aspect, the fifth aspect, the eighth aspect, or the tenth aspect. method in the implementation.
- the present application provides a computer program product, which, when running on a computer, causes the computer to execute the method in any possible implementation manner of the above-mentioned third aspect and sixth aspect.
- the present application provides a chip or a chip system applied to a terminal, including a processing circuit and an interface circuit, the interface circuit is used to receive code instructions and transmit them to the processing circuit, and the processing circuit is used to run the The code instructions are used to execute the method in any one possible implementation manner of the first aspect, the fourth aspect, the seventh aspect, or the ninth aspect.
- FIG. 1A is a schematic diagram of a satellite communication system provided by an embodiment of the present application.
- FIG. 1B is a schematic diagram of another satellite communication system provided by the embodiment of the present application.
- FIG. 2A is a schematic diagram of a protocol encapsulation architecture of inbound data of a satellite communication system provided by an embodiment of the present application;
- FIG. 2B is a schematic diagram of a protocol analysis framework for inbound data of a satellite communication system provided by an embodiment of the present application;
- FIG. 3A is a schematic diagram of a protocol encapsulation framework for outbound data of a satellite communication system provided by an embodiment of the present application;
- FIG. 3B is a schematic diagram of a protocol analysis framework for outbound data of a satellite communication system provided by an embodiment of the present application
- FIG. 4 is a schematic flow diagram of authentication verification during inbound transmission in a satellite communication system provided by an embodiment of the present application
- FIG. 5 is a flow chart of a method for obtaining a specified key provided in an embodiment of the present application.
- FIG. 6 is a schematic diagram of a replay attack scenario provided by an embodiment of the present application.
- FIG. 7 is a schematic diagram of a processing flow of a transmission method provided in an embodiment of the present application.
- FIG. 8 is a schematic diagram of a processing flow of another transmission method provided in an embodiment of the present application.
- FIG. 9 is a schematic diagram of an inbound transmission process provided by an embodiment of the present application.
- FIG. 10 is a schematic diagram of an outbound transmission process provided by an embodiment of the present application.
- FIG. 11 is a schematic diagram of a processing flow of another transmission method provided in the embodiment of the present application.
- FIG. 12 is a schematic diagram of another inbound transmission process provided by the embodiment of the present application.
- FIG. 13 is a schematic diagram of another outbound transmission process provided by the embodiment of the present application.
- FIG. 14 is a schematic diagram of a transmission process provided by an embodiment of the present application.
- 15A-15H are a set of schematic diagrams of interfaces provided by the embodiment of the present application.
- FIG. 16A is a schematic diagram of another transmission process provided by the embodiment of the present application.
- FIG. 16B is a schematic diagram of another transmission process provided by the embodiment of the present application.
- FIG. 17A is a schematic diagram of another transmission process provided by the embodiment of the present application.
- FIG. 17B is a schematic diagram of another transmission process provided by the embodiment of the present application.
- FIG. 17C is a schematic diagram of another transmission process provided by the embodiment of the present application.
- FIGS 18A-18C are another set of schematic diagrams of interfaces provided by the embodiment of the present application.
- FIG. 19 is a schematic diagram of another transmission process provided by the embodiment of the present application.
- Figure 20 is a schematic interface diagram provided by the embodiment of the present application.
- FIG. 21 is a schematic diagram of the processing flow of another transmission method provided by the embodiment of the present application.
- FIG. 22 is a schematic diagram of another inbound transmission process provided by the embodiment of the present application.
- FIG. 23 is a schematic diagram of another outbound transmission process provided by the embodiment of the present application.
- FIG. 24 is a schematic diagram of another transmission process provided by the embodiment of the present application.
- 25A-25D are another set of schematic diagrams of interfaces provided by the embodiment of the present application.
- FIG. 26 is a schematic diagram of another transmission process provided by the embodiment of the present application.
- 27A-27B are another set of schematic diagrams of interfaces provided by the embodiment of the present application.
- FIG. 28 is a schematic diagram of another transmission process provided by the embodiment of the present application.
- Fig. 29 is a schematic interface diagram provided by the embodiment of the present application.
- FIG. 30 is a schematic diagram of another transmission process provided by the embodiment of the present application.
- 31A-31B are another set of schematic diagrams of interfaces provided by the embodiment of the present application.
- FIG. 32 is a schematic diagram of another inbound transmission process provided by the embodiment of the present application.
- FIG. 33 is a schematic diagram of another outbound transmission process provided by the embodiment of the present application.
- FIG. 34 is a schematic diagram of another transmission process provided by the embodiment of the present application.
- FIG. 35 is a schematic diagram of another transmission process provided by the embodiment of the present application.
- FIG. 36 is a schematic diagram of another inbound transmission process provided by the embodiment of the present application.
- FIG. 37 is a schematic diagram of another outbound transmission process provided by the embodiment of the present application.
- FIG. 38 is a schematic diagram of another transmission process provided by the embodiment of the present application.
- FIG. 39 is a schematic diagram of another transmission process provided by the embodiment of the present application.
- FIG. 40 is a schematic diagram of another transmission process provided by the embodiment of the present application.
- FIG. 41 is a schematic diagram of another transmission process provided by the embodiment of the present application.
- FIG. 42 is a schematic diagram of a hardware structure provided by an embodiment of the present application.
- 43A-43B are another set of schematic diagrams of interfaces provided by the embodiment of the present application.
- first and second are used for descriptive purposes only, and cannot be understood as implying or implying relative importance or implicitly specifying the quantity of indicated technical features. Therefore, the features defined as “first” and “second” may explicitly or implicitly include one or more of these features. In the description of the embodiments of the present application, unless otherwise specified, the “multiple” The meaning is two or more.
- a satellite communication system 10 provided in the embodiment of the present application is introduced below.
- the satellite communication system 10 may include but not limited to a terminal 100 , a satellite 21 , a satellite network device 200 , a cellular network device 400 , a terminal 300 and so on.
- the terminal 100 of the satellite network may send the satellite message to the terminal 300 of the cellular network.
- the terminal 100 may first send the satellite message to the satellite 21, and the satellite 21 only performs relay, and may directly forward the satellite message sent by the terminal 100 to the satellite network device 200 on the ground.
- the satellite network device 200 can analyze the satellite message forwarded by the satellite 21 according to the satellite communication protocol, and forward the message content parsed from the satellite message to the cellular network device 400 .
- the cellular network device 400 may forward the message content to the terminal 300 through a traditional cellular communication network.
- the terminal 300 of the cellular network can also send satellite messages to the terminal 100 of the satellite network.
- the terminal 300 can send the short message to the short message center 25 through the traditional cellular communication network.
- the short message center 25 can forward the short message of the terminal 300 to the satellite network device 200 .
- the satellite network device 200 can relay the short message of the terminal 300 to the terminal 100 through the satellite 21 .
- the satellite communication system 10 may also include an emergency rescue platform and an emergency rescue center.
- the satellite network device 200 may send the satellite message of the emergency rescue type sent by the terminal 100 to the emergency rescue center through the emergency rescue platform.
- the aforementioned satellite network device 200 may include but not limited to a ground transceiver station 22 , a central station 23 and a converged communication platform 24 .
- the ground transceiver station 22 may include one or more devices respectively having a sending function and one or more devices having a receiving function, or may include one or more devices having a sending function and a receiving function, which is not limited here.
- the ground transceiver station 22 can be used for the data processing function of the satellite network equipment 200 in the physical layer (physical layer protocol, PHY).
- the central station 23 can be used for the data processing function of the satellite network device 200 at the satellite link control layer (satellite link control protocol, SLC) layer and the message data convergence protocol (message data convergence protocol, MDCP).
- the converged communication platform 24 can be used to process data at the application layer (application layer protocol, AP). Wherein, the converged communication platform 24 may also be called a converged communication gateway 24 .
- the above-mentioned cellular network device 400 may include but not limited to short message center (short message service center, SMSC) 25, home location register (home location register, HLR) 28, telecommunication business operation support system (business&operation support system, BOSS) 29 , a bootstrapping server function (BSF) 41 and a home subscriber server (HSS) 42.
- SMSC short message service center
- HLR home location register
- BOSS business&operation support system
- BOSS business&operation support system
- BOSS business&operation support system
- HSS home subscriber server
- the guide server 41 and the home subscriber server 42 are not shown in FIG. 1A .
- the short message center 25 can be used to forward the data sent by the satellite network device 200 to the terminal under the cellular network, and can also be used to forward the data of the cellular network to the satellite network device 200 .
- the telecommunications service operation support system 29 can be used for terminal account opening.
- the telecommunications service operation support system 29 may assign a corresponding personal identification (identity, ID) number and the like to the terminal (such as the terminal 100 ) when opening an account.
- ID number may be a mobile phone number of the terminal.
- the guide server 41 may be used to receive service requests from the terminal 100 and the satellite network device 200 .
- the bootstrap server 41 can also be used to store authentication parameters obtained from the home subscriber server 42 .
- authentication parameters may include but not limited to random number (random, RAND), authentication token (authentication token, AUTN), expected response (expected response, XRES), encryption key (cipher key, CK) and integrity specification Key (integrity key, IK).
- the bootstrap server 41 may also generate a session specific key_network application function (session key_network application function, Ks_NAF) based on the authentication parameters.
- the guidance server 41 may also send Ks_NAF to the satellite network device 200 .
- the bootstrap server 41 may also send some authentication parameters (RAND and AUTN) to the terminal 100 .
- the home location register 28 and/or the home subscriber server 42 may be used to generate authentication parameters and send the authentication parameters to the guidance server 41 .
- RAND and AUTN can be used for terminal 100 to calculate CK, IK and response (response, RES).
- the XRES in the authentication parameters can be used by the satellite network device 200 to authenticate whether the terminal 100 is a legal terminal, and only when the satellite network device 200 confirms that the XRES and RES are the same, the satellite network device 200 confirms that the terminal 100 is a legal terminal (that is, the satellite network device 200 is successfully authenticated), the satellite network device 200 and the terminal 100 can encrypt and decrypt the communication data through Ks_NAF.
- CK and IK in the authentication parameters can be used to calculate Ks_NAF.
- Ks_NAF is a designated key (also referred to as the first key) in the following application embodiments.
- the specified key can be used to encrypt and decrypt data.
- the specified key can also be used to generate an authentication code.
- the ground transceiver station 22 and the central station 23 may be the same device.
- the device may be the ground central station 31 in the satellite communication system 20 shown in FIG. 1B .
- the ground central station 31 can be used for the data processing function of the satellite network equipment 200 at the physical layer, the satellite link control layer and the message data convergence layer.
- the sending device and the receiving device may obtain a specified key in the second transmission system.
- the sending device can obtain the authentication code A based on the specified key and the original data, and send the data packet including the authentication code A to the receiving device in the first transmission system.
- the receiving device can generate the authentication code B based on the specified key and the data packet.
- the receiving device can confirm the receiving status of the data packet based on the authentication code B.
- the sending device and the receiving device can use the sufficient air interface resources of the cellular network to update and obtain the specified key, saving the air interface resources of the satellite network required for negotiating the specified key.
- the sending device and the receiving device can also transmit the authentication code and the original data together, saving the interaction steps required for authentication and further saving the air interface resources of the satellite network.
- the first transmission system may be a satellite transmission system (also referred to as a satellite network, a satellite communication system), for example, the above-mentioned satellite communication system 10 .
- the first transmission system may be a Beidou network transmission system.
- the second transmission system is a transmission system other than the first transmission system.
- the second transmission system may be a cellular transmission system (also called a cellular network), or the second transmission system may also be a wireless local area network (wireless local area networks, WLAN) transmission system, and so on. This embodiment of the present application does not limit it.
- the transmission method will be described by taking satellite network and cellular network as examples.
- FIG. 2A shows a schematic diagram of a protocol encapsulation architecture of inbound data of a satellite communication system 10 provided in an embodiment of the present application.
- the transmission protocol layer on the terminal 100 can be divided into an application layer, a message data aggregation layer, a satellite link control layer and a physical layer.
- the workflow of the transmission protocol on the terminal 100 can be as follows:
- the terminal 100 At the AP layer, the terminal 100 generates a first data packet, wherein the first data packet includes original data and a first authentication code generated based on a specified key and the original data.
- the terminal 100 can generate the first authentication code based on the original data (also referred to as the first data) and the specified key, and splicing the first authentication code and the original data together, and after processing (such as adding a header), obtain first packet.
- the raw data may include but not limited to data input by the user, indication of the number of receiving users, ID of the receiving user, location information of the terminal 100 , voice, image, animation and so on.
- the terminal 100 may use a specified key to encrypt the concatenated first authentication code and original data to obtain encrypted data.
- the terminal 100 may add packet header information before the encrypted data to obtain the first data packet.
- the packet header information may include but not limited to an encryption indication field.
- the encryption indication field may be used to indicate the encryption algorithm used by the terminal 100 to encrypt data.
- the terminal 100 may first compress the concatenated first authentication code and original data.
- the packet header information may also include a compression indication field.
- the compression indication field may be used to indicate the compression algorithm used by the terminal 100 to compress data.
- the terminal 100 may only encrypt original data to obtain encrypted data.
- the terminal 100 may add packet header information before the encrypted data to obtain the first data packet.
- the packet header information may include, but is not limited to, an encryption indication field.
- the terminal 100 adds the first authentication code to the first data packet to obtain the first data packet including the first authentication code and encrypted data.
- the terminal 100 can obtain the first data packet sent by the AP layer through the interlayer interface, and use the first data packet as an MDCP SDU.
- the terminal 100 can add padding to a specified length at the end of the MDCP SDU, and add a redundant length indication field to the MDCP SDU.
- the redundant length indication field may be used to indicate the length of the padding data.
- the terminal 100 can split the padding data and the MDCP SDU after adding the redundant length indication field into one or more fixed-length MDCP segment data (M_segment), and add a follow-up indication to the header of each MDCP segment data field to get the MDCP PDU. That is, the MDCP PDU includes M_segment and successor indication fields.
- the successor indication field can be used to indicate the order of the current MDCP PDU in multiple MDCP PDUs in the same MDCP SDU, or whether there is another MDCP PDU behind the current MDCP PDU, or the current MDCP PDU is the only MDCP PDU in the MDCP SDU .
- the terminal 100 can obtain the MDCP PDU sent by the MDCP layer through the interlayer interface as the SLC SDU.
- the terminal 100 can segment the SLC SDU into one or more (for example, 4) fixed-length SLC segment data (S_segment), and add frame header information (also known as frame header) to each S_segment header. Format indication information) to get the SLC PDU.
- the frame header information may include but not limited to a user ID field, a frame total number field and a frame sequence number field.
- the user ID field can be used to indicate the terminal (for example, terminal 100) that generates the SLC PDU.
- the total number of frames field can be used to indicate the total number of SLC PDUs included in the SLC SDU to which the SLC PDU belongs.
- the frame sequence number field can be used to indicate the sequence number of the SLC PDU in the SLC SDU to which it belongs.
- the SLC PDU may be called the second data packet. That is to say, the terminal 100 may process the first data packet into at least one second data packet through the MDCP layer and the SLC layer.
- the MDCP segment may also be called a second data packet, and the terminal 100 may process the first data packet into at least one second data packet through the MDCP layer.
- the terminal 100 can obtain the SLC PDU delivered by the SLC layer through the interlayer interface.
- the terminal 100 may perform transmission processing (such as coding, modulation, spread spectrum, etc.) on it to obtain the inbound data.
- the terminal 100 can send the inbound data to the satellite 21 , and relay and forward it to the satellite network device 200 via the satellite 21 .
- FIG. 2B shows a schematic diagram of a protocol analysis framework for inbound data of a satellite communication system 10 provided in an embodiment of the present application.
- the transmission protocol layer on the satellite network device 200 can be divided into an application layer, a message data aggregation layer, a satellite link control layer and a physical layer.
- the satellite network device 200 may include but not limited to a ground transceiver station 22 , a central station 23 and a converged communication platform 24 .
- the ground transceiver station 22 can be used to be responsible for the protocol processing of the PHY layer.
- the central station 23 can be used to be responsible for the protocol processing of the SLC layer and the MDCP layer.
- the converged communication platform 24 can be used to be responsible for the protocol processing of the AP layer.
- the workflow of the Beidou message transmission protocol on the satellite network device 200 can be as follows:
- the satellite network device 200 can acquire inbound data sent by the terminal 100 . After the satellite network device 200 receives and processes the inbound data (such as despreading, demodulation, decoding, etc.), it can present it to the SLC layer through the interlayer interface as an SLC PDU of the SLC layer.
- the satellite network device 200 receives and processes the inbound data (such as despreading, demodulation, decoding, etc.), it can present it to the SLC layer through the interlayer interface as an SLC PDU of the SLC layer.
- the satellite network device 200 can splice the SLC PDUs of the same SLC SDU belonging to the same terminal into one SLC SDU based on the frame header information of the SLC PDU.
- the satellite network device 200 can present the SLC SDU to the MDCP layer through the interlayer interface as an MDCP PDU of the MDCP layer.
- the satellite network device 200 can splice together all MDCP PDUs belonging to the same MDCP SDU according to the receiving order, and remove the padding data and redundant length indication fields of the spliced MDCP PDUs to obtain the MDCP SDU.
- the satellite network device 200 may present the MDCP SDU to the AP layer through the interlayer interface as the first data packet received by the AP layer. So far, the SLC layer and the MDCP layer of the satellite network device 200 process at least one second data packet (i.e., SLC PDU) to obtain the first data packet, or the MDCP layer of the satellite network device 200 processes at least one second data packet (i.e., MDCP PDU) is processed to obtain the first data packet.
- the satellite network device 200 may generate a second authentication code based on the specified key and the first data packet, and judge the receiving status of the first data packet based on the second authentication code. Specifically, the satellite network device 200 may obtain the original data in the first data packet, and then generate the second authentication code based on the specified key and the original data. The satellite network device 200 may obtain the first authentication code in the first data packet, and determine the receiving status of the first data packet by comparing whether the first authentication code and the second authentication code are the same. When the first authentication code is the same as the second authentication code, the satellite network device 200 determines that the first data packet is successfully received.
- the satellite network device 200 determines that the original data in the first data packet is the data sent by the terminal 100, and the satellite network device 200 can perform corresponding operations on the original data (for example, forwarding the original data to the called user equipment under the cellular network ).
- the satellite network device 200 determines that the reception of the first data packet fails. That is, the satellite network device 200 determines that the original data in the first data packet is not the data sent by the terminal 100, and the satellite network device 200 may discard the first data packet.
- the first data packet includes encrypted data
- the encrypted data includes an encrypted first authentication code and encrypted original data.
- the satellite network device 200 may determine the encryption algorithm used by the terminal 100 based on the header of the first data packet.
- the satellite network device 100 may decrypt the first data packet based on the specified key and encryption algorithm to obtain the original data and the first authentication code.
- the satellite network device 200 may generate the second authentication code based on the specified key and the original data.
- the compressed data may be obtained after the satellite network device 200 decrypts the encrypted data. After the satellite network device 200 decompresses the compressed data, the first authentication code and original data are obtained.
- the first data packet includes encrypted data and a first authentication code.
- the satellite network device 200 may directly obtain the first authentication code in the first data packet.
- the satellite network device 200 may perform a decryption operation on the encrypted data based on the specified key and the encryption indication field in the packet header information to obtain the original data.
- FIG. 3A shows a schematic diagram of an outbound data protocol encapsulation framework of a satellite communication system 10 provided in an embodiment of the present application.
- the transmission protocol layer on the satellite network device 200 can be divided into an application layer, a message data convergence layer, a satellite link control layer and a physical layer.
- the workflow of the message transmission protocol on the satellite network device 200 can be as follows:
- the satellite network device 200 At the AP layer, the satellite network device 200 generates a third data packet, where the third data packet includes original data and a fourth authentication code.
- the satellite network device 200 may generate a fourth authentication code based on the original data (also referred to as the first data) and a specified key, and splicing the fourth authentication code and the original data together, after processing (such as adding a header) , to get the third packet.
- the original data may include but not limited to data, text, semaphore, voice, image, animation, etc. sent by a third-party server (eg, short message center 25 ).
- the satellite network device 200 may generate the fourth authentication code based only on the original data.
- the satellite network device 200 may encrypt the concatenated original data and the fourth authentication code based on a specified key and an encryption algorithm to obtain encrypted data.
- the satellite network device 200 may add a packet header before the encrypted data to obtain a third data packet.
- the packet header may include but not limited to an encryption indication field.
- the encryption indication field may be used to indicate the encryption algorithm used by the satellite network device 200 to encrypt data.
- the satellite network device 200 may first compress the spliced fourth authentication code and original data.
- the packet header may also include a compression indication field.
- the compression indication field may be used to indicate the compression algorithm used by the satellite network device 200 to compress data.
- the satellite network device 200 may compress the spliced fourth authentication code and original data to obtain compressed data.
- the satellite network device 200 may add the above-mentioned compression indication field before the compressed data, and then use a specified key to encrypt the compressed data with the compression indication field added to obtain encrypted data.
- the satellite network device 200 may only encrypt original data to obtain encrypted data.
- the satellite network device 200 may add packet header information before the encrypted data to obtain the third data packet.
- the packet header information may include, but is not limited to, an encryption indication field.
- the satellite network device 200 adds the fourth authentication code to the third data packet to obtain a third data packet including the first authentication code and encrypted data.
- the satellite network device 200 can obtain the third data packet delivered by the AP layer through the interlayer interface, and use the third data packet as an MDCP SDU.
- the satellite network device 200 can split the MDCP SDU into one or more MDCP segment data (M_segment), and add a follow-up indication field at the head of each MDCP segment data to obtain an MDCP PDU, that is, the MDCP PDU includes M_segment and follow-up Indicates the field.
- the successor indication field can be used to indicate the order of the current MDCP PDU in the same MDCP SDU, such as whether it is the only PDU, whether there are subsequent MDCP PDUs, and whether it is the first MDCP PDU.
- the data length of the subsequent indication field may occupy 2 bits.
- the meaning of the value of the subsequent indication field can be as follows:
- MDCP PDU 01 Indicates that the MDCP PDU is the starting MDCP PDU among multiple MDCP PDUs in this MDCP SDU;
- MDCP PDU is an intermediate MDCP PDU among multiple MDCP PDUs in this MDCP SDU, that is, refers to other MDCP PDUs in this MDCP SDU except the initial MDCP PDU and the last MDCP PDU;
- the satellite network device 200 can obtain the MDCP PDU sent by the MDCP layer through the interlayer interface as the SLC SDU.
- the satellite network device 200 can segment the SLC SDU into one or more (for example, 4) SLC segment data (S_segment), and add frame header information to the head of each S_segment to obtain the SLC PDU.
- the frame header information may include but not limited to a user ID field, a frame total number field, and a frame sequence number field.
- the user ID field may be used to identify the receiving device (such as the terminal 100), and the value of the user ID field is the ID number of the receiving device.
- the SLC PDU may be called the fourth data packet.
- the satellite device 200 may process the third data packet into at least one fourth data packet at the MDCP layer and the SLC layer. Or a segment of MDCP may be called a fourth data packet, and the satellite device 200 may process the third data packet into at least one fourth data packet at the MDCP layer.
- the satellite network device 200 can obtain the SLC PDU delivered by the SLC layer through the interlayer interface as a user frame.
- the satellite network device 200 can splice user frames (also referred to as data frames) of multiple users or one user together, and add a frame header (such as a version number) and a check digit to obtain a physical frame.
- the satellite network device 200 may perform a transmission process (for example, code modulation, spread spectrum, etc.) on the physical frame to obtain coded data of the message branch (S2C-d branch).
- the satellite network device 200 can combine the coded data of the S2C-d branch and the pilot data (also called secondary code) of the pilot branch (S2C-p branch) to form pilot coded data, that is, outbound data.
- the outbound data is sent to the satellite 21, and relayed to one or more terminals via the satellite 21.
- the pilot data of the S2C-p branch is related to the satellite beam.
- the pilot data of the S2C-p branch is also known without decoding.
- the coded data of the S2C-d branch needs to be decoded.
- FIG. 3B shows a schematic diagram of a protocol analysis architecture of outbound data of a satellite communication system 10 provided in an embodiment of the present application.
- the transmission protocol layer on the terminal 100 can be divided into an application layer, a message data aggregation layer, a satellite link control layer and a physical layer.
- the terminal 100 can capture the coded data of the S2C-d branch based on the secondary code of the S2C-p branch sent by the satellite network device 200 . After capturing the coded data of the S2C-d branch, the terminal 100 may perform receiving processing (such as despreading, demodulation, decoding, etc.) on the coded data of the S2C-d branch to obtain a physical frame. The terminal 100 may extract user frames belonging to the terminal 100 from the physical frames. The terminal 100 can present the user frame to the SLC layer through the interlayer interface as an SLC PDU of the SLC layer.
- receiving processing such as despreading, demodulation, decoding, etc.
- the terminal 100 can splice the SLC PDUs belonging to the same SLC SDU into one SLC SDU.
- the terminal 100 can present the SLC SDU to the MDCP layer through the interlayer interface as the MDCP PDU of the MDCP layer.
- the terminal 100 can retransmit data/send the next SLC SDU based on the value of the bitmap field.
- the terminal 100 can splice one or more MDCP PDUs into one MDCP SDU after removing the header.
- the terminal 100 may present the MDCP SDU to the AP layer through the interlayer interface as the third data packet received by the AP layer. So far, the SLC layer and the MDCP layer of the terminal 100 process at least one fourth data packet (ie, SLC PDU) to obtain the third data packet.
- SLC PDU fourth data packet
- the terminal 100 may generate a third authentication code based on the specified key and the third data packet, and judge a receiving status of the third data packet based on the third authentication code. Specifically, the terminal 100 may acquire the original data in the third data packet, and then generate the third authentication code based on the specified key and the original data. The terminal 100 may obtain the fourth authentication code in the third data packet, and determine the reception status of the third data packet by comparing whether the fourth authentication code is the same as the third authentication code. When the fourth authentication code is the same as the third authentication code, the terminal 100 determines that the third data packet is successfully received.
- the terminal 100 determines that the original data of the third data packet is the data sent by the satellite network device 200, and the terminal 100 can perform corresponding operations on the original data (for example, display the original data in the form of a short message on the display screen of the terminal 100).
- the terminal 100 determines that the third data packet fails to be received. That is, when the terminal 100 determines that the original data of the third data packet is not the data sent by the satellite network device 200, the terminal 100 may discard the third data packet.
- the terminal 100 may generate the third authentication code only based on the original data in the third data packet.
- the third data packet includes encrypted data
- the encrypted data includes an encrypted fourth authentication code and encrypted original data.
- the terminal 100 can confirm the encryption algorithm used by the satellite network device 200 based on the encryption indication field of the third data packet, and then decrypt the encrypted data based on the specified key and encryption algorithm to obtain the original data and the fourth authentication code.
- the terminal 100 may generate the third authentication code based on the specified key and the decrypted original data.
- the terminal 100 may obtain compressed data after decrypting the encrypted data. After the terminal 100 decompresses the compressed data, the fourth authentication code and original data are obtained.
- the third data packet includes encrypted data and a fourth authentication code.
- the terminal 100 may directly intercept the fourth authentication code in the third data packet.
- the terminal 100 can decrypt the encrypted data based on the specified key and the encryption indication field in the header information to obtain the original data.
- the terminal 100 then obtains the third authentication code based on the original data and the designated key.
- a transmission method in a satellite communication system provided in an embodiment of the present application is introduced below.
- Fig. 4 shows a schematic flowchart of authentication verification during inbound transmission in the satellite communication system provided in the embodiment of the present application.
- the terminal 100, the satellite network device 200 and the cellular network device 400 negotiate a designated key.
- the terminal 100 and the satellite network device 200 After the terminal 100 and the satellite network device 200 acquire the designated key through the cellular network device 400, they may store the designated key. The terminal 100 and the satellite network device 200 can use the specified key to encrypt and decrypt data.
- the specified key obtained by the terminal 100 and the satellite network device 200 under the cellular network can only be used within a preset time (for example, 15 days).
- the available time of the specified key can be called the specified key.
- key validity period When the validity period of the specified key is over, the terminal 100 and the satellite network device 200 will return to the cellular network to update the specified key and the specified key validity period.
- the terminal 100 acquires the original data.
- the original data may include but not limited to data input by the calling user (user of the terminal 100) (such as text data, image data, audio data, video data, etc.), the number indication of the called user, the ID of the called user, The location information of the terminal 100 and the like.
- the terminal 100 may acquire raw data and send the raw data to the satellite network device 200 in response to the first input.
- the input may include but not limited to: gesture, voice and so on.
- the gesture may include a gesture of directly touching the display screen of the terminal 100 (for example, click) and a hovering gesture of not directly touching the display screen.
- the terminal 100 generates a first authentication code based on the specified key and the original data.
- the terminal 100 may generate the first authentication code through a specified algorithm based on the specified key and the original data. For example, the terminal 100 may obtain the first authentication code through a national secret algorithm for the specified key and original data.
- the terminal 100 obtains the first data packet based on the first authentication code and the original data.
- the terminal 100 may concatenate the first authentication code and original data together, obtain and encrypt the concatenated first authentication code and original data using a specified key, and obtain encrypted data.
- the terminal 100 may add packet header information before the encrypted data to obtain the first data packet.
- the packet header information may include but not limited to an encryption indication field.
- the encryption indication field may be used to indicate the encryption algorithm used by the terminal 100 .
- the length of the encryption indication field may be 2 bits. For example, when the value of the encryption indication field is 00, it indicates that the sending device does not use an encryption algorithm. When the value of the encryption indication field is 01, it indicates that the sending device uses the cryptographic hash algorithm in the national secret algorithm.
- the terminal 100 may send the first data packet to the satellite network device 200.
- the specific flow description of the terminal 100 sending data to the satellite network device 200 may refer to the above-mentioned embodiment in FIG. 2A , which will not be repeated here.
- the first data packet includes a user identifier.
- the frame header information added by the terminal 100 at the SLC layer may include a user ID field.
- the user ID field may be used to identify the terminal 100 .
- the value of the user ID field is the ID number of the terminal 100 .
- the ID number of the terminal 100 may be used to indicate parameters such as a designated key corresponding to the terminal 100 .
- the satellite network device 200 may generate a second authentication code based on the specified key and the first data packet.
- the satellite network device 200 may use the specified key to decrypt the first data packet to obtain the first authentication code and original data.
- the satellite network device 200 can determine the encryption algorithm used by the terminal 100 based on the encryption indication field in the packet header.
- the satellite network device 200 may use the designated key to decrypt the encrypted data in the first data packet through a decryption algorithm corresponding to the encryption algorithm, to obtain the first authentication code and original data.
- the specific flow description of the satellite network device 200 receiving the data from the terminal 100 may refer to the above embodiment described in FIG. 2B , which will not be repeated here.
- the satellite network device 200 may generate the second authentication code through a specified algorithm (such as a block encryption algorithm) based on the specified key and the original data.
- a specified algorithm such as a block encryption algorithm
- the specified algorithm used by the satellite network device 200 to generate the second authentication code is the same as the specified algorithm used by the terminal 100 to generate the authentication code.
- the satellite network device 200 determines whether the first authentication code is the same as the second authentication code.
- the satellite network device 200 may determine the receiving state of the first data packet based on the second authentication code.
- the satellite network device 200 determines that the first authentication code is different from the second authentication code, the satellite network device 200 determines that receiving the first data packet fails, and may discard the first data packet. Optionally, the satellite network device 200 may execute step S408.
- the satellite network device 200 determines that the first authentication code is the same as the second authentication code, the satellite network device 200 determines that the first data packet is received successfully, and optionally, the satellite network device 200 may execute step S409.
- the satellite network device 200 sends a failure application receipt to the terminal 100.
- the satellite network device 200 may also generate a failure application receipt, which is used to indicate that the satellite network device 200 fails to receive the first data packet.
- the satellite network device 200 may send the failed application receipt to the terminal 100 .
- the satellite network device 200 may send the original data to the cellular network device 400.
- Satellite network device 200 may send raw data to cellular network device 400 (eg, short message center 25).
- the cellular network device 400 may forward the original data to the called user (such as the terminal 300) in a specified format (such as a short message).
- the satellite network device 200 may also perform step S410.
- the satellite network device sends a successful application receipt to the terminal 100.
- the satellite network device 200 may also generate a successful application receipt, which is used to indicate that the satellite network device 200 receives the first data packet successfully.
- the satellite network device 200 may send a successful application receipt to the terminal 100 .
- the terminal 100 and the satellite network device 200 may obtain a specified key through negotiation under the cellular network.
- the terminal 100 can also use the specified key to encrypt and decrypt data under the satellite network, without negotiating with the satellite network equipment on the specified key, saving air interface resources of the satellite network equipment and ensuring data security.
- the terminal 100 and the satellite network device 200 can obtain the designated key through a generic bootstrapping architecture (GBA) process.
- GSA bootstrapping architecture
- the specific steps for the terminal 100 and the satellite network device 200 to obtain a designated key are as follows:
- the terminal 100 sends a service request 1 to the satellite network device 200.
- the terminal 100 may send a service request 1 to the satellite network device 200 under the cellular network.
- the service request 1 may include an identifier of the terminal 100 , which is used to identify the identity of the terminal 100 .
- service request 1 may be a hypertext transfer protocol get request (hypertext transfer protocol GET, HTTP GET).
- the satellite network device 200 sends a service response 1 to the satellite network device 200 .
- the satellite network device 200 may determine, based on the identification of the terminal 100, that the designated key of the terminal 100 is not stored in the satellite network device 200 or that the designated key of the terminal 100 has expired, and then send the service request 1 to the terminal 100.
- Business Response1 may be used to instruct the terminal 100 to obtain a specified key through the cellular network device 400 .
- the terminal 100 sends the service request 2 to the guidance server 41 .
- the terminal 100 may send the service request 2 to the guidance server 41 .
- the service request 2 may include the identification of the terminal 100, and the service request 2 may be used to instruct the cellular network device 400 to send to the terminal 100 parameters required for generating a specified key, for example, a random number RAND and an authentication token AUTN.
- service request 2 may be an HTTP authentication and specified key agreement (authentication and key agreement, AKA) request.
- the guidance server 41 sends an authentication request to the home user server 42.
- the guidance server 41 may send an authentication request to the home user server 42.
- the authentication request includes the identification of the terminal 100 .
- the authentication request may be used to instruct the home subscriber server 42 to feed back the authentication parameters of the terminal 100 .
- the authentication request may be a media authentication request (multimedia authentication request, MAR).
- the home user server 42 sends authentication parameters (including RAND, AUTN, XRES, CK, and IK) to the bootstrap server 41 .
- authentication parameters including RAND, AUTN, XRES, CK, and IK
- the home subscriber server 42 may acquire authentication parameters of the terminal 100 based on the identifier of the terminal 100 .
- the home subscriber server 42 pre-stores the identifier of the terminal 100 and the CK and IK corresponding to the identifier.
- the home subscriber server 42 can also obtain the random number RAND through the random number generator.
- Home Subscriber Server 42 may generate AUTN and XRES based on RAND, IK and CK.
- the home subscriber server 42 may send the generated authentication parameters to the bootstrap server 41 .
- the identifier of the terminal 100 may include but not limited to the mobile phone number of the terminal 100, an IP multimedia private identity (IP multimedia private identity, IMPI), a temporary IP multimedia private identity (Temporary IP Multimedia Private Identity, TMPI), etc.
- IP multimedia private identity IP multimedia private identity
- IMPI IP multimedia private identity
- TMPI Temporal IP Multimedia Private Identity
- the guidance server 41 sends the service response 2 to the terminal 100.
- the guidance server 41 may send a service response 2 to the terminal 100 .
- the service response 2 may include RAND and AUTN.
- the terminal 100 generates CK, IK and RES based on RAND and AUTN.
- the terminal 100 After receiving the RAND and AUTN, the terminal 100 can calculate CK, IK and RES based on the RAND and AUTN through the SIM card.
- the algorithm used by the terminal 100 to generate the RES is the same as the algorithm used by the cellular network device 400 to generate the XRES.
- the terminal 100 sends the service request 3 (including RES) to the guidance server 41 .
- service request 3 After generating the RES, the terminal 100 may send a service request 3 to the cellular network device 400 .
- service request 3 includes RES.
- service request 3 may be an HTTP GET including RES in the header field.
- the guide server 41 may compare whether the XRES and the RES are the same.
- the guidance server 41 can verify the identity of the terminal 100 by comparing whether the RES and XRES are the same. If the guidance server 41 determines that the RES and the XRES are the same, the guidance server 41 may execute steps S510 and S511.
- the bootstrapping server 41 may generate Ks_NAF based on CK and IK, the specified key validity period of Ks_NAF and the bootstrapping transaction identifier (bootstrapping transaction identifier, B-TID) of Ks_NAF.
- the bootstrap server 41 can calculate Ks_NAF based on CK and IK through an algorithm for generating a specified key. At the same time, the bootstrap server 41 may generate the B-TID corresponding to Ks_NAF and specify the valid period of the key.
- Ks_NAF is a specified key of the terminal 100 , which can be used for encryption and decryption of data during data transmission with the satellite network device 100 .
- the B-TID can be used by the satellite network device 200 to obtain the Ks_NAF of the terminal 100 from the guidance server 41 .
- the specified key validity period can be used to indicate the valid time of the specified key (i.e., Ks_NAF).
- the guidance server 41 may send a service response 3 to the terminal 100 .
- the service response 3 may include the specified key validity period and B-TID.
- the service response 3 may be used to instruct the terminal 100 to use the parameters in the service response 2 to generate a specified key.
- the terminal 100 may generate Ks_NAF based on the authentication parameter.
- the terminal 100 can calculate Ks_NAF based on CK and IK by using an algorithm for generating a specified key.
- the algorithm used by the terminal 100 to generate the specified key is the same as the algorithm used by the cellular network device 400 .
- the terminal 100 can obtain Ks_NAF (that is, the specified key) through the above-mentioned authentication parameters to perform data encryption and decryption operations during data transmission.
- the terminal 100 sends the service request 4 (including the B-TID) to the satellite network device 200 .
- the terminal 100 may send a service request 4 to the satellite network device 200 .
- service request 4 may include B-TID.
- the service request 4 may be used to instruct the satellite network device 200 to obtain the designated key of the terminal 100 .
- the satellite network device 200 sends a parameter request to the guidance server 41.
- the satellite network device 200 may send a parameter request to the guidance server 41.
- the parameter request may include B-TID.
- the parameter request may be a bootstrapping-info-request (BIR).
- the guidance server 41 sends a parameter response to the satellite network device 200.
- the guidance server 41 may send a parameter response to the satellite network device 200 based on the B-TID of the terminal 100 .
- the parameter response may include the Ks_NAF of the terminal 100 and the specified key validity period.
- the guidance server 41 may only generate the B-TID and the specified key validity period in step S515, and then generate the specified key Ks_NAF after receiving the parameter request from the satellite network device 200.
- the satellite network device 200 sends a service response 4 to the terminal 100.
- the satellite network device 200 may send a service response 4 to the terminal 100 after receiving the specified key returned by the guidance server 41 .
- the service response 4 may be used to indicate that within the validity period of the specified key, the terminal 100 and the satellite network device 200 can use the Ks_NAF stored respectively to perform data encryption and decryption operations.
- Ks_NAF is a specified key obtained by the terminal 100 and the satellite network device 200 through the cellular network device 400 .
- the designated key is updated under the cellular network, and the validity period is preset for the designated key.
- the terminal 100 and the satellite network device 200 can use the specified key within the validity period to perform data encryption and decryption operations. It not only saves the air interface resources of the satellite communication system needed to negotiate the designated key, but also reduces the steps of generating the designated key.
- the sending device and the receiving device since the sending device and the receiving device only generate authentication codes based on the original data, when the receiving device repeatedly receives a certain message from the sending device, it will repeatedly parse and process the repeated message, and charge for the repeated message multiple times. situation. As shown in Figure 6, when the sending device is the terminal 100 and the receiving device is the satellite network 200, if the inbound message of the terminal 100 is intercepted by the attacking terminal and the inbound message is repeatedly sent to the satellite network device 200, not only will the The computing resources of the satellite network device 200 may also repeatedly calculate the message fee of the terminal 100 .
- the embodiment of the present application provides a transmission method.
- the sending device can generate the authentication code A based on the information A and the original data.
- the sending device can obtain the data packet based on the authentication code A and the original data.
- the sending device can send the data packet to the receiving device under the first transmission system.
- the receiving device may generate the authentication code B based on the data packet and the information B after receiving the data packet.
- the receiving device may determine the receiving status of the first data packet based on the authentication code B.
- information A and information B are the information updated by the sending device and the receiving device according to the transmission, for example, it can be time information and updated with time, or the number information of received data packets, and the sending device can send data packets based on the number of update, the receiving device can update based on the number of packets received.
- the authentication code A in the repeatedly sent data packet is generated based on the information A before the update.
- the authentication code B generated by the receiving device based on the updated information B is different from the authentication code B in the repeated data packet, indicating that the data packet may be forwarded by an illegal terminal. There will be no problems of repeated processing and billing.
- the information A of the sending device is sending time information
- the information B of the receiving device is receiving time information.
- the information A is different from the information B, that is, the authentication code A is different from the authentication code B, and the receiving device cannot parse the information sent.
- the data packets sent by the device will not have the problem of repeated processing and billing.
- the sending device may generate the authentication code A based on the information A and the original data.
- the sending device may send the data packet including the authentication code A to the receiving device under the first transmission system.
- Information A is sending time information.
- the receiving device can generate the authentication code B based on the information B and the data packet.
- the receiving device can determine the receiving status of the data packet based on the authentication code B.
- Information B is reception time information. In this way, when the interval between the time when the sending device generates the authentication code and the time when the receiving device receives the data packet exceeds the minimum time granularity, the receiving device cannot parse the data packet, and the problems of repeated processing and billing will not occur.
- FIG. 7 shows a schematic diagram of a processing flow of a transmission method provided by an embodiment of the present application.
- the sending device generates an authentication code A based on the original data and information A.
- the information A is sending time information, and the information A may be used to indicate the sending time of the data packet.
- the sending device obtains the sending time of the data packet.
- the sending time of the data packet can be any time during the whole period from the sending device (terminal 100) obtaining the original data to generating the authentication code A plus the offset time (abbreviated as offset).
- the time when the terminal 100 obtains the original data may be the time when the terminal 100 receives an input of sending a satellite message from the calling user, and at this time, the original data includes the data input by the calling user.
- the time when the terminal 100 generates the authentication code A may be the current time obtained by the terminal 100 running a program statement to obtain the sending time of the first data packet (for example, by obtaining the current time function getCurrentTime()).
- the terminal 100 may determine the sending time of the data packet based on the positioning timing of the satellite.
- the sending time of the first data packet may be represented as the time when the sending device (terminal 100 ) delivers the first data packet to the MDCP layer at the AP layer.
- the sending time of the first data packet may be expressed as the time estimated by the sending device (terminal 100 ) that the sending device (terminal 100 ) sends the first data packet to the receiving device (satellite network device 200 ).
- the sending time of the data packet may be any time between the sending device (satellite network device 200 ) obtaining the original data and generating the authentication code A plus an offset.
- the time when the satellite network device 200 obtains the original data may be the time when the satellite network device 200 receives the service request sent by the terminal 100, or the time when the satellite network device 200 obtains the original data may be the time when the satellite network device 200 receives the service request sent to the terminal 100.
- the time of the message, or the time when the satellite network device 200 sends data to the terminal 100, or the time when the satellite network device 200 generates the authentication code A plus an offset is used to estimate the SLC layer or MDCP layer or the physical The time at which the layer sends data.
- the time when the satellite network device 200 generates the authentication code A may be the program statement that the satellite network device 200 runs to obtain the sending time of the first data packet (for example, the converged communication platform 24 in the satellite network device 200 obtains the current time function getCurrentTime ()) to get the current time.
- the ground transceiver station 22 or the central station 23 in the satellite network device 200 can determine the sending time of the data packet based on the satellite 21 .
- the satellite network device 200 can obtain the scheduling time of the data packet based on the amount of outbound data and the outbound air interface resources, and the satellite network device 200 can estimate the outbound of the data packet based on the scheduling time of the data packet time. That is to say, the sending time of the data packet of the satellite network device 200 may be the estimated outbound time of the data packet.
- the converged communication platform 24 in the satellite network device 200 receives the schedulable time indicated by the ground transceiver station 22 or the central station 23.
- the sending time of the data packet may be represented as the time when the sending device sends the data packet to the MDCP layer at the AP layer.
- the sending device generates information A based on the sending time of the data packet.
- the sending device can encode the time according to the preset or configured minimum time granularity to obtain information A.
- the time value before the preset minimum time granularity in the sending time of the data packet can be intercepted, and the time value can be encoded (for example, binary-decimal encoding, decimal to binary, etc.) to obtain information A.
- the sending device that is, the terminal 100, can encode the time according to the minimum time granularity preset or configured by the network of the terminal 100 under the cellular or WLAN, or configured under the satellite network, to obtain information A.
- the sending device that is, the satellite network device 200 generates information A, for example, the integrated communication platform 24 in the satellite network device 200, according to the time provided by the ground transceiver station 22 or the central station 23, and the minimum time granularity prefabricated or configured Encoding is performed to generate information A; for another example, the ground transceiver station or central station in the satellite network device 200 encodes information A according to time and the minimum prefabricated or configured time scale, and then informs the converged communication platform 24 of information A.
- information A for example, the integrated communication platform 24 in the satellite network device 200, according to the time provided by the ground transceiver station 22 or the central station 23, and the minimum time granularity prefabricated or configured Encoding is performed to generate information A; for another example, the ground transceiver station or central station in the satellite network device 200 encodes information A according to time and the minimum prefabricated or configured time scale, and then informs the converged communication platform 24 of information A.
- the preset or configured minimum time granularity may be minute, half minute, half hour, etc., which is not limited in this application.
- the sending time of the data packet is 17:23:51 on August 25, 2021.
- the sending device may intercept and obtain a time value of 202108251723 based on the preset minimum time granularity.
- the sending device may intercept the obtained time value based on the minimum time granularity. For example, the sending device may record the time not exceeding 30s as 0.0 minute, and record the time exceeding 30s as 0.5 minute. Then, the time value obtained based on the sending time of the above data packet is 202108251723.5. For another example, the sending device may record the time not exceeding 30s as 00 seconds, and record the time exceeding 30s as 30 seconds. Then, the time value obtained based on the sending time of the above data packet is 20210825172330.
- the sending device can directly add 1-bit data at the end of the obtained binary data after encoding the time value before the minute to obtain the binary data, which is used to indicate the first half minute or the last half minute (for example, 0 represents 1s- 30s, 1 represents 31s-60s).
- the sending device may divide the sending time value of the data packet by the minimum granularity to obtain an integer value, and the integer value is the time value obtained by the sending device. Then, the time value obtained by the sending device based on the above sending time is 404216503446. It can be understood that the actual sending time of the data packet is the product of the time value and the value of the minimum time granularity, so that the time information can be identified by an integer number of the minimum granularity.
- the sending device can obtain the value of information A as 0010 0000 0010 0001 0000 1000 0010 0101 0001 0111 0010 0011 based on the time value 202108251723 through 8421 encoding.
- the sending device can convert based on the time value 202108251723 to obtain the value of information A as 10111100001110100101110010111001001011.
- the value of the preset minimum time granularity and the selection of the encoding mode above are just examples, which are not specifically limited in this application.
- the sending device may also obtain one or more time values of a specific time granularity in the sending time of the data packet, and then perform encoding to obtain the information A. For example, when the sending time of the data packet is 17:23:51 on August 25, 2021, and the specific time granularity includes month, minute and hour, then the time value obtained by the sending device is 082317. (3) The sending device obtains the authentication code A based on the information A and the original data.
- the sending device can calculate the authentication code A based on the information A and the original data through a specified algorithm (for example, SM3 cryptographic hash algorithm).
- a specified algorithm for example, SM3 cryptographic hash algorithm
- the sending device can calculate the authentication code A based on the information A, the original data and the key, and through a specified algorithm.
- the sending device obtains the data packet based on the original data and the authentication code A.
- the sending device can splice the authentication code A and the original data together to obtain a data packet.
- the sending device may add packet header information before the concatenated authentication code A and original data to obtain a data packet.
- the packet header information may include service type indication and the like.
- the service type indication may be used to indicate the service type of the data packet (for example, a data packet for sending a message to the user equipment in the cellular network, or a data packet for requesting data from the satellite network device 200, etc.).
- the data packet may further include identification information for identifying the data packet, and the identification information may include but not limited to a message ID field, a count value field, or a sequence number field of the data packet.
- the identification can be used by the receiving device to identify the sent data packet, for example, the identification information can be added to the application receipt to indicate the reception status of the data packet.
- the sending device may use the identification information of the application receipt to confirm the receiving status of the data packet corresponding to the identification information.
- the receiving device obtains the authentication code A and the original data based on the data packet.
- the receiving device After the receiving device receives the data packet sent by the sending device, the receiving device can obtain the authentication code A and the original data from the data packet.
- the sending device may process the data packet into at least one subpacket at the MDCP layer and the SLC layer, or the sending device may comb the data packet into at least one subpacket at the MDCP layer.
- the data packet can be regarded as the first data packet in Figure 2A and Figure 2B above, and the sub-data packet can be regarded as the second data packet in Figure 2A and Figure 2B above.
- the data packet can be regarded as the third data packet in Figure 3A and Figure 3B above, and the sub-data packet can be regarded as the fourth data packet in Figure 3A and Figure 3B above.
- the receiving device acquires information B.
- the information B is receiving time information, and the information B may be used to indicate the receiving time of the data packet.
- the receiving device obtains the receiving time of the data packet.
- the receiving time of the data packet can be the time when the receiving device obtains the first sub-packet of the data packet, or the time when the receiving device obtains the first sub-packet of the data packet minus the offset value, or the time when the receiving device obtains the first sub-packet of the data packet Any time between the time of a subpacket minus the offset value and the generation of authentication code B.
- the offset value can be configured, or set according to transmission delay (for example, 540ms) or processing delay.
- the receiving time can be recorded through the SLC layer and passed to the AP layer through the MDCP layer.
- the receiving device can record the time of receiving each SLC PDU (that is, sub-packet) at the SLC layer, and the receiving device can record at least one SLC PDU in the SLC layer when splicing at least one SLC PDU based on the frame header information to obtain the SLC SDU.
- the earliest receiving time is the receiving time of the SLC SDU, and the SLC SDU and its corresponding receiving time are uploaded to the MDCP layer.
- the receiving device After the receiving device receives the SLC SDU uploaded by the SLC layer and the receiving time corresponding to the SLC SDU at the MDCP layer, it can use the SLC SDU as the MDCP PDU of the MDCP layer.
- the receiving device can determine whether the current MDCP PDU is the first MDCP PDU in at least one MDCP PDU based on the successor indication field, for example, the successor indication field is 00 or 01.
- the receiving device reserves the receiving time of the corresponding MDCP PDU, Use this reception time as the reception time of the MDCP SDU.
- the receiving device can upload the MDCP SDU and the receiving time of the MDCP SDU to the AP layer at the MDCP layer.
- the receiving device can receive MDCP SDUs as packets at the AP layer.
- the receiving time corresponding to the MDCP SDU is the time when the receiving device obtains the first sub-packet of the data packet.
- the receiving time can be recorded through the SLC layer and passed to the AP layer through the MDCP layer.
- the acquisition method is the same as the previous case, and will not be described again.
- the offset value can be configured or set according to the transmission delay (for example, 540ms).
- the receiving time can be recorded by the MDCP layer and passed to the AP layer.
- the receiving device records the time of the first MDCP PDU received at the MDCP layer.
- the MDCP layer can perform time recording based on the subsequent indication, for example, the subsequent indication field is 00 or 01.
- the receiving device reserves the receiving time of the corresponding MDCP PDU,
- the receiving device takes the receiving time as the receiving time of the MDCP SDU.
- the receiving device submits the receiving time to the AP layer.
- the receiving device can receive MDCP SDUs as packets at the AP layer.
- the receiving time corresponding to the MDCP SDU is the time when the receiving device obtains the first sub-packet of the data packet.
- the receiving time can be recorded by the MDCP layer and passed to the AP layer.
- the acquisition method is the same as the previous case, and will not be described again. It is based on subtracting an offset value from the time uploaded by MDCP, where the offset The value can be set through configuration, or according to the transmission delay (for example, 540ms), or according to the processing delay.
- the receiving time may be the time when the AP layer receives the MDCP SDU or the time when the MDCP SDU package submitted by the MDCP is completed.
- the receiving time can be the time when the AP layer receives the MDCP SDU or the time when the MDCP SDU package submitted by the MDCP is completed, and an offset value is subtracted.
- the offset value can be set through configuration, or according to transmission delay (for example, 540 ms), or according to processing delay.
- the receiving time may be the current time obtained by running a program statement to obtain the sending time of the data packet (for example, by obtaining the current time function getCurrentTime()) when the receiving device calculates the authentication code B.
- the receiving time can be the current time obtained by running the program statement to obtain the sending time of the data packet (for example, by obtaining the current time function getCurrentTime()) when the receiving device calculates the authentication code B, and subtract a bias value.
- the offset value can be set through configuration, or according to transmission delay (for example, 540 ms), or according to processing delay.
- the receiving device is a satellite network device 200, wherein the converged communication platform 24 in the satellite network device 200 carries the processing of the AP layer, and the processing of the SLC layer and the processing of the MDCP layer are carried by the ground transceiver station 22 or the central station 23 , the converged communication platform 24 can request the time information from the ground transceiver station 22 or the central station 23 .
- the receiving device is the terminal device 100 .
- the receiving device generates information B based on the receiving time of the packet.
- the receiving device can encode the time according to the preset or configured minimum time granularity to obtain information B.
- the time value before the preset minimum time granularity in the receiving time of the data packet can be intercepted, and the time value can be encoded (for example, binary-decimal encoding, decimal to binary, etc.) to obtain information B.
- the receiving device that is, the terminal 100, can encode the time according to the minimum time granularity preset or configured by the network of the terminal 100 under the cellular network, or configured under the satellite network, to obtain information B.
- the receiving device that is, the satellite network device 200 generates information B, for example, the integrated communication platform 24 in the satellite network device 200, according to the receiving time information of the data packet provided by the ground transceiver station 22 or the central station 23, and the prefabricated or The configured minimum time granularity is encoded to generate information B; for another example, the ground transceiver station or central station in the satellite network device 200 encodes information B according to the recorded time and the prefabricated or configured minimum time scale, and then the information B is transmitted to the converged communication platform 24 .
- information B for example, the integrated communication platform 24 in the satellite network device 200, according to the receiving time information of the data packet provided by the ground transceiver station 22 or the central station 23, and the prefabricated or The configured minimum time granularity is encoded to generate information B; for another example, the ground transceiver station or central station in the satellite network device 200 encodes information B according to the recorded time and the prefabricated or configured minimum time scale, and then the information B is transmitted to the converged communication platform 24 .
- the preset minimum time granularity may be minute, half minute, half hour, etc., which is not limited in the present application.
- the minimum time granularity and encoding method used by the receiving device to generate information B based on the receiving time of the data packet are the same as those used by the sending device to generate information A. That is, for the description of the information B generated by the receiving device, reference may be made to the description of the information A generated by the sending device above, and details are not repeated here.
- the receiving device may also intercept one or more time values of a specific time granularity in the receiving time of the data packet, and then perform encoding to obtain the information B.
- the receiving device after the receiving device obtains the receiving time of the MDCP SDU at the MDCP layer, it can be used as the receiving time of the data packet, and the information B is generated based on the receiving time of the data packet at the MDCP layer, and the information B is generated at the MDCP layer
- the layer uploads the MDCP SDU and information B to the AP layer.
- the receiving device can obtain the receiving time of the SLC SDU at the SLC layer, and use it as the receiving time of the data packet, and generate information B based on the receiving time of the data packet and the minimum granularity information at the SLC layer Upload to the MDCP layer, and upload the MDCP SDU and information B to the AP layer at the MDCP layer.
- the receiving device generates an authentication code B based on the information B and the data packet.
- the receiving device can calculate the authentication code B based on the information B and the original data in the data packet through a specified algorithm (for example, SM3 cryptographic hash algorithm).
- a specified algorithm for example, SM3 cryptographic hash algorithm.
- the designation algorithm of the receiving device is the same as that of the sending device.
- the sending device can add a designated algorithm indication in the header of the data packet, the designated algorithm indication can be used to indicate the designated algorithm used by the sending device, and the receiving device can determine the designated algorithm used by the sending device based on the designated algorithm indication in the received data packet.
- Algorithm instructions For another example, the sending device and the receiving device may negotiate a specified algorithm to be used under the cellular network.
- the receiving device determines the receiving status of the data packet based on the authentication code B.
- the receiving device can determine the receiving status of the data packet by comparing whether the authentication code A and the authentication code B are the same.
- the receiving device determines that the data packet is successfully received.
- the receiving device can perform corresponding processing operations on the original data. For example, when the receiving device is the terminal 100, the receiving device can display the original data.
- the receiving device is the satellite network device 200, the receiving device may forward the original data to the user equipment (such as the terminal 300) under the cellular network.
- the receiving device may also generate a successful application receipt and send the successful application receipt to the sending device, and the successful application receipt may be used to indicate that the receiving device receives the data packet successfully.
- the receiving device can obtain the information C based on the information B.
- the receiving device may obtain information C by reducing a preset value (for example, 1) from information B.
- the receiving device can obtain the authentication code C through a specified authentication algorithm based on the information C and the original data. For example, the time corresponding to information B is 18:00 on September 23, 2021, and the time corresponding to information C obtained by reducing the preset value is 17:59 on September 23, 2021.
- the authentication code C will be generated based on the time information corresponding to the information C.
- the receiving device can compare whether the authentication code C and the authentication code A are the same.
- the receiving device can determine that the data packet is received successfully.
- the receiving device may also generate and send a successful application receipt to the sending device, and the successful application receipt may be used to indicate that the receiving device receives the data packet successfully.
- the receiving device may determine that the receiving of the data packet fails.
- the receiving device may also generate and send a failure application receipt to the sending device, and the failure application receipt may be used to indicate that the receiving device fails to receive the data packet.
- the authentication code A and the authentication code B may be compared first, and then the information C is generated to compare the authentication code A and the authentication code C under different circumstances. It is also possible to first generate information B and information C, then generate authentication code B and authentication code C, and then compare them with authentication code A. If any one is the same as authentication code A, it means that the reception is successful.
- a successful application receipt can be fed back. If they are all different, the application receipt for sending failure will be fed back.
- the receiving device may obtain the receiving time set based on the receiving time of the data packet.
- the receiving device can obtain the first time value in the receiving time set based on the receiving time of the data packet and the minimum preset time granularity, and then reduce the receiving time by 1 for the first time value to obtain the second time value, and for the second time The value is reduced by 1 to obtain the third time value, and so on, the receiving device can obtain a receiving time set including n time values.
- n is a positive integer.
- the receiving device may perform encoding based on each time value in the receiving time set to obtain the information B set.
- the receiving device can calculate through a specified authentication algorithm for each numerical value and original data in the information B set to obtain an authentication code set.
- the receiving device can determine the reception status of the data packet by comparing the value in the authentication code with the authentication code A. Wherein, as long as there is a value in the authentication code set that is the same as the authentication code A, the receiving device determines that the data packet is successfully received. When any value in the authentication code set is different from the authentication code A, the receiving device determines that receiving the data packet fails.
- the sending device may use a specified key to encrypt the authentication code A and the original data.
- the sending device may also add packet header information including an encryption indication field in the data packet.
- the receiving device After receiving the data packet sent by the sending device, the receiving device can decrypt the data packet based on the encrypted indication field and the specified key to obtain the authentication code A and the original data. In this way, the sending device and the receiving device can ensure the security of the data by encrypting the data.
- the format of the sending time of the data packet and the receiving time of the data packet is Universal Time Coordinated (UTC), or Greenwich Mean Time (GMT), or Beijing Time, or Eastern Pacific Time, or Western Pacific Time Time, etc., are not limited in this embodiment.
- the difference between the sending time of the data packet of the sending device and the receiving time of the data packet of the receiving device will not exceed the preset minimum time granularity, that is, the receiving device can successfully receive the sent Packets sent by the device.
- the information A of the sending device is sending time information
- the information B of the receiving device is receiving time information.
- the sending device can generate an authentication code A based on the information A, the specified key, and the original data, and then generate a data packet based on the authentication code A and the original data.
- the receiving device can generate the authentication code B based on the information B, the specified key and the data packet. In this way, not only will there be no problems of repeated processing and billing. Since both the sending device and the receiving device generate authentication codes based on their respective stored specified keys, the receiving device can also verify whether the specified keys of both parties are the same through the authentication codes, thereby verifying the legitimacy of the sending device.
- the terminal 100 and the satellite network device 200 can obtain a designated key through negotiation through a cellular network, as shown in FIG. 5 .
- the terminal 100 and the satellite network device 200 may be preset with the same designated key.
- the terminal 100 may obtain the specified key through an intermediate device.
- the intermediate device and the satellite network device 200 can first negotiate to obtain the specified key through the cellular network (for example, the process of the intermediate device and the satellite network device 200 negotiating to obtain the specified key can refer to the terminal 100 and the satellite network device shown in FIG. 5 200 to negotiate the process of obtaining the specified key), the intermediate device can establish a communication connection with the terminal 100 (for example, Bluetooth connection, wi-fi connection or edge (sidelink) connection, etc.), the intermediate device can send the specified key through the communication connection Give terminal 100.
- a communication connection for example, Bluetooth connection, wi-fi connection or edge (sidelink) connection, etc.
- the sending device can splice the authentication code A and the original data to obtain spliced data.
- the sending device uses the specified key to encrypt the spliced data through the specified encryption algorithm to obtain the encrypted data.
- the sending device can add header information before the encrypted data, and the header information includes an encryption indication field.
- the encryption indication field may be used to indicate a specified encryption algorithm (eg SM3 cryptographic hash algorithm) used by the sending device.
- the receiving device can decrypt the encrypted data in the data packet based on the encrypted indication field and the specified key to obtain the authentication code A and the original data.
- the receiving device then generates an authentication code B based on the original data, information B and the specified key, as shown in FIG. 8 . In this way, since the sending device encrypts the data before sending it to the receiving device, the security of the data can be further ensured.
- the terminal 100 may generate the first authentication code based on the first information, the specified key and the first data (also referred to as original data). Wherein, the first information is sending time information. The terminal 100 may obtain the first data packet based on the first authentication code, the specified key, and the first data. The terminal 100 may send the first data packet to the satellite network device 200 . After receiving the first data packet, the satellite network device 200 may generate a second authentication code based on the second information, the designated key, and the first data packet. Wherein, the second information is receiving time information. The satellite network device 200 may determine the receiving state of the first data packet based on the second authentication code.
- the satellite network device 200 receives the first data packet sent repeatedly, since the second information has been updated with time, the generated authentication code is different from the first authentication code in the first data packet, and the satellite If the network device 200 determines that the first data packet fails to be received, there will be no problem of repeatedly receiving the same data packet.
- FIG. 9 shows a schematic diagram of an inbound transmission process provided by an embodiment of the present application.
- the terminal 100, the satellite network device 200 and the cellular network device 400 negotiate a key.
- the terminal 100 and the satellite network device 200 both store a specified key after negotiating the key.
- the terminal 100 acquires the original data.
- the terminal 100 can generate the original data based on the content of the satellite message input by the user.
- the terminal 100 may generate raw data based on the user's request after receiving an instruction from the user, for example, when the user wishes to inquire about a mailbox or obtain other information from the network.
- the original data may include but not limited to the quantity indication of the receiving user, the ID number of the receiving user, data input by the user (eg, text data, picture data, audio data, etc.), location information of the terminal 100, and the like.
- the terminal 100 generates a first authentication code based on the specified key, the original data, and the first information.
- the terminal 100 may acquire the sending time of the first data packet.
- the sending time of the first data packet may be any time between the terminal 100 obtaining the original data and generating the first authentication code.
- the time when the terminal 100 obtains the original data may be the time when the terminal 100 receives an input of sending a satellite message from the calling user, and at this time, the original data includes the data input by the calling user.
- the time when the terminal 100 generates the first authentication code may be the current time obtained by the terminal 100 running a program statement to obtain the sending time of the first data packet (for example, by obtaining the current time function getCurrentTime()).
- the terminal 100 may determine the sending time of the data packet based on the positioning timing of the satellite.
- the sending time of the first data packet may be represented as the time when the terminal 100 sends the first data packet to the MDCP layer at the AP layer.
- the sending time of the first data packet may be expressed as the time estimated by the terminal 100 that the terminal 100 sends the first data packet to the satellite network device 200 .
- the terminal 100 may refer to the above-mentioned embodiment shown in FIG. 7 for obtaining the sending time of the first data packet, and details are not repeated here.
- the terminal 100 After obtaining the sending time of the first data packet, the terminal 100 can intercept the time value before the preset minimum time granularity in the sending time of the first data packet, and encode the time value (for example, binary-decimal coding, decimal converted to binary, etc.) to obtain the first information.
- the preset minimum time granularity may be minute, half minute, half hour, etc., which is not limited in this application.
- the terminal 100 for a description of generating the first information by the terminal 100, reference may be made to the embodiment shown in FIG. 7 above, and details are not repeated here.
- the terminal 100 generates a first authentication code based on the designated key, original data and first information.
- the terminal 100 may calculate the first authentication code through a specified algorithm (for example, SM3 cryptographic hash algorithm) based on the first information, the specified key, and the original data.
- a specified algorithm for example, SM3 cryptographic hash algorithm
- HMAC hash-based message authentication code
- SM3 is a cryptographic hash algorithm.
- k+ can be obtained based on the specified key.
- the length of k+ may be 64 bytes.
- the high-order 16 bytes are the specified key, and the following 48 bytes are all 0.
- opad is 0x5C with 64 bytes repeated, and ipad is 0x36 with 64 bytes repeated.
- text is the original data, and context is the first information. in, is an XOR symbol, and
- the output length of the SM3 algorithm is 32 bytes.
- F is the function of intercepting the first 16bit data from the high order to the low order of the input.
- the output of F ie, HMAC) is the first authentication code.
- the length of the first authentication code is 16 bits.
- the terminal 100 may obtain the first data packet based on the first authentication code and the original data.
- the terminal 100 may splice the first authentication code and the original data together to obtain the first data packet.
- the terminal 100 may also add packet header information before the concatenated first authentication code and original data to obtain the first data packet.
- the packet header information may include but not limited to service type indication and the like.
- the service type indication may be used to indicate the service type of the first data packet (for example, a data packet for sending a message to a user equipment in a cellular network, or a data packet for requesting data from a satellite network device 200, etc.).
- the terminal 100 may also use a specified key to encrypt the concatenated first authentication code and original data to obtain the first data packet.
- a specified key may be used to encrypt the concatenated first authentication code and original data to obtain the first data packet.
- the terminal 100 sends the first data packet to the satellite network device 200.
- sending prompt information such as displaying "sent”
- the sending prompt information may be used to remind the user that the terminal 100 has sent the satellite network device 200 sends out the first data packet.
- Sending prompt information can also include a marker icon, which can be used to trigger (for example, click trigger) to display information explanations, such as "sent!, which can be triggered by clicking to display operation suggestions (for example, this message has been sent to the receiving device , delivery undetermined).
- the form of sending the prompt information is not limited, and may be text, picture, animation and so on.
- the terminal 100 can process the first data packet into at least one second data packet (that is, SLC PDU or MDCP PDU) at the MDCP layer and the SLC layer or the MDCP layer, and then send the at least one second data packet to the satellite Network device 200.
- at least one second data packet that is, SLC PDU or MDCP PDU
- the specific description of the terminal 100 obtaining at least one second data packet and sending it to the satellite network device 200 may refer to the above embodiments shown in FIG. 2A and FIG. 7 , which will not be repeated here.
- the satellite network device 200 acquires the receiving time of the first data packet, and generates second information based on the receiving time.
- the satellite network device 200 may acquire the receiving time of the first data packet.
- the satellite network device 200 may record the receiving time of each second data packet in the at least one second data packet when the SLC layer receives the at least one second data packet.
- the satellite network device 200 can splice the second data packets belonging to one SLC SDU to obtain the SLC SDU based on the frame header information of the second data packet at the SLC layer.
- the satellite network device 200 may compare the sequence of receiving times of the second data packets included in the SLC SDU, and use the earliest receiving time as the receiving time of the SLC SDU.
- the satellite network device 200 may upload the SLC SDU and the receiving time of the SLC SDU to the MDCP layer at the SLC layer.
- the satellite network device 200 can use the SLC SDU as an MDCP PDU at the MDCP layer, and obtain the MDCP SDU based on the MDCP PDU.
- the satellite network device 200 can determine the first MDCP PDU of the MDCP SDU through the successor indication field of the MDCP PDU, and use the receiving time of the SLC SDU corresponding to the first MDCP PDU as the receiving time of the MDCP SDU.
- the satellite network device 200 may upload the MDCP SDU and the receiving time of the MDCP SDU to the AP layer at the MDCP layer.
- the satellite network device 100 may use the MDCP SDU as the first data packet at the AP layer, and use the receiving time of the MDCP SDU as the receiving time of the first data packet.
- the satellite network device 200 obtains the receiving time of the first data packet, reference may also be made to the above-mentioned embodiment shown in the inbound process in FIG. 7 , which will not be repeated here.
- the satellite network device 200 After the satellite network device 200 acquires the receiving time of the first data packet (also referred to as the fourth information) at the AP layer, it may generate the second information based on the fourth information and a preset or configured minimum time granularity. For a specific description of generating the second information by the satellite network device 200, reference may be made to the embodiment of the information B generated by the receiving device shown in FIG. 7 above, and details are not repeated here.
- the satellite network device 200 may generate a second authentication code based on the specified key, the original data, and the second information.
- the satellite network device 200 may calculate the second authentication code based on the second information and the original data in the first data packet through a specified algorithm (for example, SM3 cryptographic hash algorithm).
- a specified algorithm for example, SM3 cryptographic hash algorithm.
- the designated authentication algorithm of the satellite network device 200 is the same as the designated authentication algorithm of the terminal 100 .
- the specified authentication algorithm used by the terminal 100 can be a hash-based message authentication code (hash-based message authentication code, HMAC) algorithm based on the SM3 cryptographic hash algorithm
- HMAC hash-based message authentication code
- SM3 is a cryptographic hash algorithm.
- k+ can be obtained based on the specified key.
- the length of k+ may be 64 bytes.
- the high-order 16 bytes are the specified key, and the following 48 bytes are all 0.
- opad is 0x5C with 64 bytes repeated, and ipad is 0x36 with 64 bytes repeated.
- text is the original data, and context is the second information. in, is an XOR symbol, and
- the output length of the SM3 algorithm is 32 bytes.
- F is the function of intercepting the first 16bit data from the high order to the low order of the input.
- the output of F ie, HMAC
- the length of the second authentication code is 16 bits.
- the satellite network device 200 determines whether the first authentication code is the same as the second authentication code.
- the satellite network device 200 can determine the receiving state of the first data packet by comparing whether the first authentication code is the same as the second authentication code. Wherein, when the first authentication code and the second authentication code are the same, the satellite network device 200 may execute step S909, and may also execute step S910.
- the satellite network device 200 may execute step S909, and may also execute step S910.
- the satellite network device 200 may execute step S911.
- the satellite network device 200 sends the original data to the cellular network device 400.
- the satellite network device 200 determines that the first authentication code is the same as the second authentication code, and determines that the first data packet is successfully received.
- the satellite network device 200 may perform corresponding processing operations on the raw data. For example, the satellite network device 200 may forward the original data to the user equipment (such as the terminal 300 ) under the cellular network.
- the satellite network device 200 may also record the time information of the successful reception of the first data packet.
- the time information of the successful reception of the first data packet may be the second information corresponding to the second authentication code, and the satellite network device 100 may The second information is recorded and forwarded to a network element (such as a short message center) in the cellular network.
- the network element in the cellular network can record the time of successful transmission of the inbound message based on the time information of the first data packet received, so that the terminal 100 can be updated by sending the time information of successful transmission to the terminal 100 in the cellular network The sending status of the message that the application receipt was not successfully received under the satellite network.
- the satellite network device 200 sends an application receipt to the terminal 100, indicating that the sending is successful.
- the satellite network device 200 may also generate a successful application receipt (that is, an application receipt indicating that the sending is successful), and the successful application receipt may be used to indicate that the satellite network device 200 receives the data packet successfully.
- the satellite network device 200 may send a successful application receipt to the terminal 100 .
- the satellite network device 200 sends an application receipt to the terminal 100, indicating that the sending fails.
- the satellite network device 200 determines that the first authentication code is different from the second authentication code, and determines that the first data packet fails to be received. Satellite network device 200 may delete the first data packet. The satellite network device 200 may also generate a failed application receipt (that is, an application receipt indicating failure to send), and the failed application receipt may be used to indicate that the satellite network device 200 fails to receive the data packet. The satellite network device 200 may send the failed application receipt to the terminal 100 .
- a failed application receipt that is, an application receipt indicating failure to send
- the satellite network device 200 may reduce the value of the second information by a preset value (for example, 1), A new second authentication code is then generated based on the adjusted second information, the specified key and the original data.
- a preset value for example, 1
- the satellite network device 200 may compare whether the first authentication code is the same as the new second authentication code, and if the first authentication code is the same as the new second authentication code, the satellite network device 200 may determine that the data packet is received successfully.
- the receiving device of the satellite network device 200 may also perform step S909 and step S910.
- the satellite network device 200 may determine that receiving the data packet fails.
- the satellite network device 200 may also generate and send a failure application receipt to the terminal 100, and the failure application receipt may be used to indicate that the satellite network device 200 fails to receive the data packet.
- the terminal 100 may regenerate and send the first data packet to the satellite network device 200 .
- the successful application receipt and the failed application receipt may be collectively referred to as the first application receipt, and the first application receipt may include indication information for indicating whether the user receives the application successfully.
- the terminal 100 may display result prompt information (including the success prompt information and the failure prompt information) on the display screen. In this way, the user can confirm the sending status of the first data packet through the result prompt information, avoiding repeated sending of successfully sent satellite messages.
- the terminal 100 may display the success prompt information.
- the success prompt information may be used to prompt the user that the first data packet is sent successfully.
- the terminal 100 may display failure prompt information after receiving the failure application receipt (that is, the application receipt indicating that the sending of the first data packet failed).
- the failure prompt information may be used to prompt the user that the sending of the first data packet fails.
- the satellite network device 200 may generate the fourth authentication code based on the sixth information and the original data (also referred to as the first data). Wherein, the sixth information is sending time information. The satellite network device 200 may obtain the third data packet based on the fourth authentication code and the original data. The satellite network device 200 may send the third data packet to the terminal 100 . After receiving the third data packet, the terminal 100 may generate a third authentication code based on the fifth information and the third data packet. Wherein, the fifth information is receiving time information. The terminal 100 may determine the receiving state of the third data packet based on the third authentication code. In this way, when terminal 100 receives the third data packet sent repeatedly, since the fifth information has been updated with time, the authentication code generated based on the fifth information is different from the fourth authentication code in the third data packet. , the terminal 100 determines that the third data packet fails to be received, and there will be no problem of receiving duplicate data packets.
- FIG. 10 shows a schematic diagram of an outbound transmission process provided by an embodiment of the present application.
- the satellite network device 200 receives original data sent by the cellular network device 400 .
- the satellite network device 200 receives the original data sent by the short message center 25 of the cellular network device 400 .
- the original data is data (including but not limited to text data input by the calling user, image data, etc.).
- the cellular network device 400 forwards the data sent by the terminal 300 to the terminal 100 to the satellite network device 200, it may also simultaneously forward the identity of the called user (for example, the ID number or phone number of the terminal 100) to the satellite network device 200. Satellite network equipment 200 .
- the raw data acquired by the satellite network device 200 may be data stored in a memory of the satellite network device 200 .
- the raw data may be map data stored by the satellite network device 200 .
- the original data received by the satellite network device 200 may be data sent to the satellite network device 200 by a third-party server (for example, text data, image data, audio data, video data, etc.).
- a third-party server for example, text data, image data, audio data, video data, etc.
- the satellite network device 200 receives the service request sent by the terminal 100.
- the service request may be a request for downloading original data
- the receiving device of the original data is the terminal 100 .
- the satellite network device 200 may execute step S1003-step 1005.
- the satellite network device 200 generates a fourth authentication code based on the original data and the sixth information.
- the satellite network device 200 may obtain the sending time of the third data packet.
- the sending time of the third data packet may be any time in the whole period from the satellite network device 200 obtaining the original data to generating the fourth authentication code plus the offset.
- the time when the satellite network device 200 obtains the original data may be the time when the satellite network device 200 receives the service request sent by the terminal 100, or the time when the satellite network device 200 receives the original data sent by the cellular network device 400, or the time when the satellite network device 200 receives the original data sent by the cellular network device 400, or The time when the device 200 sends data to the terminal 100, or the time when the satellite network device 200 generates the fourth authentication code minus the offset is used to estimate the time when the satellite network device 200 sends data at the SLC layer, MDCP layer or physical layer.
- the time when the satellite network device 200 generates the fourth authentication code may be the current time obtained by the satellite network device 200 running a program statement for obtaining the sending time of the third data packet (for example, by
- the satellite network device 200 may determine the sending time of the third data packet (also referred to as the eighth information) at the MDCP layer/SLC layer (ie, based on the central station 23 or the ground central station 31 ). The satellite network device 200 then generates sixth information at the AP layer based on the eighth information and the minimum time granularity.
- the satellite network device 200 may determine the sending time of the third data packet at the MDCP layer/SLC layer, and generate sixth information based on the sending time of the third data packet and the preset minimum time granularity, and then upload the sixth information to the AP layer.
- the sending time of the third data packet may be expressed as the time when the satellite network device 200 sends the third data packet to the MDCP layer at the AP layer, that is, the converged communication platform 24 sends the third data packet to The time of the central station 23 or the ground central station 31.
- the satellite network device 200 generates sixth information based on the sending time of the third data packet.
- the satellite network device 200 can encode the time according to the preset or configured minimum time granularity to obtain the sixth information, for example, it can intercept the sending time of the third data packet
- the time value before the minimum time granularity is preset or configured, and the time value is encoded (for example, binary-decimal encoding, decimal to binary, etc.) to obtain the sixth information.
- the preset or configured minimum time granularity may be seconds, minutes, half minutes, half an hour, etc., which is not limited in this application.
- the preset or configured minimum time granularity may be seconds, minutes, half minutes, half an hour, etc., which is not limited in this application.
- the satellite network device 200 generates a fourth authentication code based on the original data and the sixth information. Specifically, the satellite network device 200 may calculate the fourth authentication code through a specified algorithm (for example, SM3 cryptographic hash algorithm) based on the sixth information and the original data.
- a specified algorithm for example, SM3 cryptographic hash algorithm
- the satellite network device 200 obtains the third data packet based on the original data and the fourth authentication code.
- the satellite network device 200 may splice the fourth authentication code and the original data together to obtain the third data packet.
- the satellite network device 200 may also add packet header information before the spliced fourth authentication code and original data to obtain the third data packet.
- the packet header information may include but not limited to service type indication and the like.
- the service type indication may be used to indicate the service type of the third data packet (for example, a data packet for sending a satellite message to the terminal 100, or how many data packets for sending a satellite message to the terminal 100, etc.).
- the terminal 100 may obtain the fourth authentication code based on the specified key, the sixth information, and the original data.
- the terminal 100 may also use a specified key to encrypt the spliced fourth authentication code and original data to obtain the third data package.
- a specified key may be used to encrypt the spliced fourth authentication code and original data to obtain the third data package.
- the satellite network device 200 sends the third data packet to the terminal 100.
- the satellite network device 200 may process the third data packet into at least one fourth data packet (that is, SLC PDU) at the MDCP layer and the SLC layer, or the satellite network device 200 may process the third data packet at the MDCP layer At least one fourth data packet (ie, MDCP PDU), and then send the at least one fourth data packet to the terminal 100.
- the specific description of the satellite network device 200 obtaining at least one fourth data packet and sending it to the terminal 100 may refer to the above-mentioned embodiment shown in FIG. 3A , which will not be repeated here.
- the terminal 100 acquires the receiving time of the third data packet, and generates fifth information based on the receiving time.
- the terminal 100 may acquire the receiving time of the third data packet.
- the terminal 100 may record the receiving time of each fourth data packet in the at least one fourth data packet when the SLC layer receives the at least one fourth data packet.
- the terminal 100 can splice the fourth data packet belonging to one SLC SDU to obtain the SLC SDU based on the frame header information of the fourth data packet at the SLC layer.
- the terminal 100 may compare the sequence of receiving times of the fourth data packets included in the SLC SDU, and use the earliest receiving time as the receiving time of the SLC SDU.
- the terminal 100 can upload the SLC SDU and the receiving time of the SLC SDU to the MDCP layer at the SLC layer.
- the terminal 100 can use the SLC SDU as an MDCP PDU at the MDCP layer, and obtain the MDCP SDU based on the MDCP PDU.
- the terminal 100 can determine the first MDCP PDU of the MDCP SDU through the successor indication field of the MDCP PDU, and use the receiving time of the corresponding SLC SDU of the first MDCP PDU as the receiving time of the MDCP SDU.
- the terminal 100 can upload the MDCP SDU and the receiving time of the MDCP SDU to the AP layer at the MDCP layer.
- the satellite network device 100 may use the MDCP SDU as the third data packet at the AP layer, and use the receiving time of the MDCP SDU as the receiving time of the third data packet. For other detailed descriptions of obtaining the receiving time of the third data packet by the terminal 100, reference may be made to the description of obtaining the receiving time of the data packet by the receiving device in the embodiment in FIG. 7 , and details are not repeated here.
- the terminal 100 may generate fifth information based on the receiving time of the third data packet and a preset or configured minimum time granularity. For a specific description of generating the fifth information by the terminal 100, reference may be made to the embodiment shown in FIG. 7 above, and details are not repeated here.
- the terminal 100 obtains a third authentication code based on the third data packet and the fifth information.
- the terminal 100 may calculate the third authentication code through a specified authentication algorithm (for example, SM3 cryptographic hash algorithm) based on the fifth information and the original data in the third data packet.
- a specified authentication algorithm for example, SM3 cryptographic hash algorithm
- the designated authentication algorithm of the satellite network device 200 is the same as the designated authentication algorithm of the terminal 100 .
- the terminal 100 determines whether the third authentication code is the same as the fourth authentication code.
- the terminal 100 may determine the receiving state of the third data packet by comparing whether the third authentication code is the same as the fourth authentication code. Wherein, when the third authentication code and the fourth authentication code are the same, the terminal 100 executes step S1009, and optionally, also executes step S1010.
- the terminal 100 may also record time information when the third data packet is successfully received, for example, generate fifth information corresponding to the third authentication code.
- the time information of the successful reception of the third data packet can be used to send the time information of successful transmission to the satellite device 200 or the network element of the second transmission system when the subsequent terminal 100 accesses the second transmission system (such as a cellular or WLAN network), and update the satellite The sending status of the information that the application receipt has not been successfully received under the network. to avoid billing issues.
- the terminal 100 may execute step S1011.
- the terminal 100 displays the receiving prompt information.
- the terminal 100 determines that the third authentication code is the same as the fourth authentication code, and determines that the third data packet is received successfully.
- the terminal 100 may perform corresponding processing operations on the raw data.
- the terminal 100 may display receiving prompt information.
- the receiving prompt information may be used to prompt the user to receive a satellite message sent from the user equipment (such as the terminal 300 ) under the cellular network.
- Receiving prompt information may include but not limited to voice prompt information, text prompt information, vibration prompt information, and the like.
- the receiving prompt information is text prompt information
- the receiving prompt information may be "received a piece of satellite information from "terminal 300"".
- the terminal 100 may also display the original data in the third data packet on the display screen.
- the terminal 100 sends an application receipt to the satellite network device 200, indicating that the reception is successful.
- the terminal 100 may also generate a successful application receipt (that is, an application receipt indicating that the sending is successful), and the successful application receipt may be used to indicate that the terminal 100 receives the data packet successfully.
- the terminal 100 may send the successful application receipt to the satellite network device 200 .
- the satellite network device 200 may delete the original data of the third data packet.
- the terminal 100 sends an application receipt to the satellite network device 200, indicating that the reception fails.
- the terminal 100 determines that the third authentication code is different from the fourth authentication code, and determines that the third data packet fails to be received.
- the terminal 100 may delete the third data packet.
- the terminal 100 may also generate a failed application receipt (that is, an application receipt indicating failure to send), and the failed application receipt may be used to indicate that the terminal 100 fails to receive the data packet.
- the terminal 100 may send the failed application receipt to the satellite network device 200 .
- the terminal 100 can reduce the value of the fifth information by a preset value (for example, 1), and then based on the adjusted The fifth information and the original data generate a new third authentication code.
- a preset value for example, 1
- the receiving device may compare whether the fourth authentication code is the same as the new third authentication code, and when the fourth authentication code is the same as the new third authentication code, the terminal 100 may determine that the data packet is received successfully.
- the terminal 100 may also execute step S1010.
- the terminal 100 may determine that receiving the data packet fails.
- the terminal 100 may also generate and send a failed application receipt to the satellite network device 200, and the failed application receipt may be used to indicate that the terminal 100 fails to receive the data packet.
- the satellite network device 200 may regenerate and send the third data packet to the terminal 100 .
- the successful application receipt and the failed application receipt may be collectively referred to as a third application receipt
- the third application receipt may include indication information for indicating whether the user receives the application successfully.
- the information A of the sending device is context information (context) A
- the context information A can be used to indicate the number of data packets sent
- the number of data packets sent is the data packets successfully sent by the sending device quantity information.
- the information B of the receiving device is context information B
- the context information B may be used to indicate the quantity information of the received data packets.
- the number information of received data packets is the number information of data packets successfully received by the receiving device (that is, the number information of generated successful application receipts).
- the initial values of information A and information B are the same. In this way, when the receiving device successfully parses the data packet generated by the sending device based on information A based on information B, the value of information B can be updated.
- the value of the information A is different, that is, the authentication code A and the authentication code B are different, the receiving device cannot parse the data packet sent by the sending device, and there will be no problems of repeated processing and billing.
- the sending device and the receiving device can acquire context information.
- the context information of the sending device may be referred to as context information A, that is, information A.
- the context information of the receiving device may be referred to as context information B, that is, information B.
- the number of data packets successfully sent by the sending device may be the number of successful application receipts received by the sending device.
- the terminal 100 and the satellite network device 200 can obtain context information when negotiating to obtain a specified key through the cellular network.
- the terminal 100, the satellite network device 200 and the cellular network device 400 may execute steps S501 to S515 as shown in FIG. 5 .
- the satellite network device 200 can set the context information of the satellite network device 200 .
- the initial value of the context information of the satellite network device 200 may be X.
- the satellite network device 200 may send a service response 4 to the terminal 100 .
- the service response 4 may be used to indicate that within the validity period of the specified key, the terminal 100 and the satellite network device 200 can use the specified key stored respectively to perform data encryption and decryption operations.
- the service response 4 may also include context information of the satellite network device 200 .
- the terminal 100 may set the initial value of the context information of the terminal 100 to X based on the service response 4 . It should be noted that as long as the value of the context information of the satellite network device 200 is the same as the value of the context information of the terminal 100, any initial value of the context information will not affect the receiving results of the sending device and the receiving device.
- the terminal 100 can obtain the specified key and the initial value of the context information through the intermediate device.
- the intermediate device and the satellite network device 200 can first negotiate and obtain the specified key, the context information of the satellite network device 200 and the context information of the terminal 100 through the above operations in the cellular network, and the intermediate device can establish a communication connection with the terminal 100 (for example, Bluetooth connection, etc.), the intermediate device may send the specified key and the context information of the terminal 100 to the terminal 100 through the communication connection.
- the initial values of the information A of the terminal 100 and the information B of the satellite network device 200 are preset specified values.
- the initial value of the information A of the terminal 100 is the data value allocated to the terminal 100 by the satellite network device 200 .
- FIG. 11 shows a schematic diagram of a processing flow of a transmission method provided by an embodiment of the present application.
- the sending device generates an authentication code A based on the original data and information A.
- the information A is the context information A, and the information A may be used to indicate the quantity information of the sent data packets.
- the information on the number of data packets sent is information on the number of data packets successfully sent by the sending device.
- the number information of the successful application receipts received by the sending device may be used to indicate the number information of the data packets successfully sent by the sending device. That is to say, after receiving the successful application receipt, the sending device can add a preset value to the value of information A. It should be noted that the increment of information A is related to the number of data packets successfully sent by the sending device.
- the sending device can obtain the authentication code A based on the information A and the original data.
- the sending device obtains the authentication code A, reference may be made to the above-mentioned embodiment shown in FIG. 7 , which will not be repeated here.
- the sending device may generate an authentication code A based on the information A, a specified key, and original data, and then generate a data packet based on the authentication code A and the original data.
- the receiving device can generate the authentication code B based on the information B, the specified key and the data packet. In this way, the legitimacy of the sending device can be verified by specifying the key to ensure the security of the transmission.
- the sending device obtains the data packet based on the original data and the authentication code A.
- the sending device can splice the authentication code A and the original data together to obtain a data packet.
- the sending device may add packet header information before the concatenated authentication code A and original data to obtain a data packet.
- the packet header information may include service type indication and the like.
- the traffic type indication can be used to indicate the traffic type of the data packet.
- the sending device can splice the authentication code A and the original data together to obtain spliced data.
- the sending device uses the specified key to encrypt the spliced data through the specified algorithm to obtain the encrypted data.
- the sending device can add header information before the encrypted data, and the header information includes an encryption indication field.
- the encryption indication field may be used to indicate a specified algorithm (such as the SM3 cryptographic hash algorithm) used by the sending device. In this way, since the sending device encrypts the data before sending it to the receiving device, the security of the data can be further ensured.
- the sending device can send the data packet to the receiving device.
- the description of sending the data packet from the sending device to the receiving device during inbound can refer to the embodiment shown in FIG. 2A above, and the description of sending the data packet from the sending device to the receiving device during outbound can be Refer to the embodiment shown in FIG. 3A above, and details are not repeated here.
- the sending device when the sending device is the terminal 100, after the sending device sends the data packet to the receiving device, the sending device may display sending prompt information.
- the sending prompt information may be used to prompt the user that the sending device has sent a satellite message to the receiving device.
- the receiving device obtains the authentication code A and the original data based on the data packet.
- the receiving device After the receiving device receives the data packet sent by the sending device, the receiving device can obtain the authentication code A and the original data from the data packet.
- the description of receiving the data packet by the receiving device during inbound may refer to the embodiment shown in FIG. 2B above, and the description of receiving the data packet by the receiving device during outbound may refer to the embodiment shown in FIG. 3B above, which will not be repeated here.
- the data packet includes an encryption indication field and encrypted data.
- the receiving device can decrypt the encrypted data in the data packet based on the encrypted indication field and the specified key to obtain the authentication code A and the original data.
- the receiving device generates an authentication code B based on the information B and the data packet.
- the receiving device can calculate the authentication code B based on the information B and the original data in the data packet through a specified algorithm (for example, SM3 cryptographic hash algorithm).
- a specified algorithm for example, SM3 cryptographic hash algorithm.
- the designation algorithm of the receiving device is the same as that of the sending device.
- the sending device can add a designated algorithm indication in the header of the data packet, the designated algorithm indication can be used to indicate the designated algorithm used by the sending device, and the receiving device can determine the designated algorithm used by the sending device based on the designated algorithm indication in the received data packet.
- Algorithm instructions For another example, the sending device and the receiving device may negotiate a specified algorithm to be used under the cellular network.
- the sending device when the sending device generates the authentication code A based on the original data, the information A and the specified key, the receiving device may generate the authentication code B based on the original data, the information B and the specified key.
- the sending device and the receiving device can preset the parameters needed to generate the authentication code.
- the receiving device determines the receiving status of the data packet based on the authentication code B.
- the receiving device can determine the receiving status of the data packet by comparing whether the authentication code A and the authentication code B are the same.
- the receiving device determines that the data packet is successfully received.
- the receiving device can perform corresponding processing operations on the original data. For specific description, refer to the embodiment shown in FIG. 7 .
- the receiving device can update the value of information B. Specifically, the receiving device may add a preset value to the value of the information B.
- the receiving device may also generate a successful application receipt and send the successful application receipt to the sending device, and the successful application receipt may be used to indicate that the receiving device receives the data packet successfully.
- the receiving device can determine that the receiving of the data packet fails.
- the receiving device may also generate and send a failure application receipt to the sending device, and the failure application receipt may be used to indicate that the receiving device fails to receive the data packet.
- the sending device determines the sending status of the data packet based on the application receipt.
- the sending device can determine the sending status of the data packet based on the application receipt.
- the sending device can confirm that the data packet is sent successfully.
- the sending device may add a preset value to the value of message A. Wherein, the preset value added in the sending device and the receiving device is the same.
- the sending device when the sending device is the terminal 100, the sending device may display success prompt information after receiving the successful application receipt, and the success prompt information may be used to prompt the user that the data packet is sent successfully. It should be noted that the sending device can confirm that the data packet is sent successfully only after receiving the successful application receipt.
- the sending device can confirm that the sending of the data packet failed.
- the sending device may retransmit the failed data packet.
- the sending device when the sending device is the terminal 100, the sending device may display failure prompt information after receiving the failure application receipt, and the failure prompt information may be used to prompt the user that the data packet transmission fails.
- the terminal 100 may generate the first authentication code based on the first information, the specified key and the first data (also referred to as original data).
- the first information is first context information
- the first context information is used to indicate the quantity information of the sent data packets.
- the terminal 100 may obtain the first data packet based on the first authentication code, the designated key, and the original data.
- the terminal 100 may send the first data packet to the satellite network device 200 .
- the satellite network device 200 may generate a second authentication code based on the second information, the designated key, and the first data packet.
- the second information is second context information
- the second context information is used to indicate the quantity information of the received data packets.
- the satellite network device 200 may determine the receiving state of the first data packet based on the second authentication code. In this way, when the satellite network device 200 successfully receives the first data packet sent by the terminal 100, it can update the value of the second information. When the satellite network device 200 repeatedly receives the first data packet, since the updated second information is different from the pre-updated second information, the authentication code generated by the satellite network device 200 based on the updated second information is different from the first The first authentication codes in the data packets are different, and if the satellite network device 200 determines that the reception of the first data packet fails, the problem of repeatedly receiving the same data packet will not occur.
- FIG. 12 shows a schematic diagram of an inbound transmission process provided by an embodiment of the present application.
- the terminal 100, the satellite network device 200, and the cellular network device 400 negotiate a key, first information, and second information.
- the terminal 100, the satellite network device 200 and the cellular network device 400 may refer to the above-mentioned embodiment shown in FIG. 11 for the description of the negotiation key, the first information and the second information, and details are not repeated here.
- the terminal 100 and the satellite network device 200 both store a specified key after negotiating the key.
- the terminal 100 stores the first information.
- the satellite network device 200 stores the second information. The initial values of the first information and the second information are the same.
- the terminal 100 acquires the original data.
- the terminal 100 generates a first authentication code based on the specified key, the original data, and the first information.
- the terminal 100 may calculate the first authentication code through a specified authentication algorithm (for example, SM3 cryptographic hash algorithm) based on the stored first information, the specified key, and the original data.
- a specified authentication algorithm for example, SM3 cryptographic hash algorithm
- the terminal 100 may obtain the first data packet based on the first authentication code and the original data.
- the terminal 100 may also use a specified key to encrypt the concatenated first authentication code and original data to obtain the first data packet.
- the terminal 100 sends the first data packet to the satellite network device 200.
- sending prompt information such as displaying "sent”
- the sending prompt information may be used to remind the user that the terminal 100 has sent the satellite network device 200 sends the first data packet.
- Sending prompt information can also include a marker icon, which can be used to trigger (for example, click trigger) to display information explanations, such as "sent!, which can be triggered by clicking to display operation suggestions (for example, this message has been sent to the receiving device , delivery undetermined).
- the form of sending the prompt information is not limited, and may be text, picture, animation and so on.
- the satellite network device 200 may generate a second authentication code based on the specified key, the original data, and the second information.
- the satellite network device 200 determines whether the first authentication code is the same as the second authentication code.
- the satellite network device 200 can determine the receiving state of the first data packet by comparing whether the first authentication code is the same as the second authentication code. Wherein, when the first authentication code and the second authentication code are the same, the satellite network device 200 may perform step S1208-step S1210.
- the satellite network device 200 may execute step S1213.
- the satellite network device 200 updates the value of the second information.
- the satellite network device 200 may add a preset value to the value of the second information. For example, when the value of the second information is 0 and the preset value is 1, the updated value of the second information is 1.
- the satellite network device 200 sends the original data to the cellular network device 400.
- the satellite network device 200 sends a successful application receipt to the terminal 100.
- the terminal 100 updates the value of the first information.
- the terminal 100 may add a preset value to the value of the first information.
- the preset value added to the first information is the same as the preset value added to the second information, that is, the updated value of the first information is the same as the updated value of the second information.
- the terminal 100 may also execute step S1212.
- the terminal 100 displays a success prompt message.
- the terminal 100 displays a success prompt message.
- the success prompt information is used to prompt the user that the first data packet is sent successfully.
- the satellite network device 200 sends a failure application receipt to the terminal 100.
- the terminal 100 may also perform step S1214 after receiving the receipt of the failed application.
- the terminal 100 displays failure prompt information.
- the terminal 100 displays failure prompt information.
- the failure prompt information is used to prompt the user that the sending of the first data packet fails.
- step S1202-step S1206, step S1209, step S1210 and step S1212 can refer to the embodiment shown in FIG. 9 above, and will not be repeated here.
- the satellite network device 200 may generate a fourth authentication code based on the sixth information and the first data (also referred to as original data).
- the sixth information is sixth context information, and the sixth context information is used to indicate the quantity information of the sent data packets.
- the satellite network device 200 may obtain the third data packet based on the fourth authentication code and the original data.
- the satellite network device 200 may send the third data packet to the terminal 100 .
- the terminal 100 may generate a third authentication code based on the fifth information and the third data packet.
- the fifth information is fifth context information, and the fifth context information is used to indicate the quantity information of the received data packets.
- the terminal 100 may determine the receiving state of the third data packet based on the third authentication code.
- the terminal 100 when the terminal 100 successfully receives the third data packet sent by the satellite network device 200, it can update the value of the fifth information.
- the terminal 100 When the terminal 100 repeatedly receives the third data packet, since the updated fifth information is different from the pre-updated fifth information, the authentication code generated by the terminal 100 based on the updated fifth information and the third data packet The fourth authentication code is different, and the terminal 100 determines that the reception of the third data packet fails, so the problem of repeatedly receiving the same data packet will not occur.
- FIG. 13 shows a schematic diagram of an outbound transmission process provided by an embodiment of the present application.
- the terminal 100, the satellite network device 200, and the cellular network device 400 negotiate fifth information and sixth information.
- the terminal 100 and the satellite network device 200 can obtain their respective context information when negotiating to obtain a key through the cellular network device 400 under the cellular network. For a specific description, refer to the above-mentioned embodiment shown in FIG. 11 , which will not be repeated here.
- the terminal 100 and the satellite network device 200 may establish a communication connection under the cellular network, and negotiate to obtain respective context information.
- the terminal 100 stores fifth information.
- the satellite network device 200 stores sixth information. The initial values of the fifth information and the sixth information are the same.
- the satellite network device 200 receives the original data sent by the cellular network device 400 .
- the satellite network device 200 receives the service request sent by the terminal 100.
- the satellite network device 200 generates a fourth authentication code based on the original data and the sixth information.
- the satellite network device 200 may generate a fourth authentication code based on the stored sixth information and original data.
- the satellite network device 200 obtains the third data packet based on the original data and the fourth authentication code.
- the satellite network device 200 sends the third data packet to the terminal 100.
- the terminal 100 obtains a third authentication code based on the third data packet and the fifth information.
- the terminal 100 determines whether the third authentication code is the same as the fourth authentication code.
- the terminal 100 may determine the receiving state of the third data packet by comparing whether the third authentication code is the same as the fourth authentication code. Wherein, when the third authentication code and the fourth authentication code are the same, the terminal 100 may perform step S1309 to step S1311.
- the terminal 100 may execute step S1313.
- the terminal 100 displays the receiving prompt information.
- the terminal 100 updates the value of the fifth information.
- the terminal 100 may add a preset value to the value of the fifth information. For example, when the value of the fifth information is 0 and the preset value is 1, the updated value of the fifth information is 1.
- the terminal 100 sends a successful application receipt to the satellite network device 200 .
- the satellite network device 200 updates the value of the sixth information.
- the satellite network device 200 may add a preset value to the value of the sixth information.
- the preset value added to the sixth information is the same as the preset value added to the fifth information, that is, the updated value of the sixth information is the same as the updated value of the fifth information.
- the terminal 100 sends a failure application receipt to the satellite network device 200 .
- step S1302-step S1306, step S1308, step S1309, step S1311 and step S1313 can refer to the above-mentioned embodiment shown in FIG. 10 , which will not be repeated here.
- FIG. 14 shows a schematic diagram of a transmission process provided by an embodiment of the present application.
- the sending device After generating the authentication code A based on the information A, the sending device obtains a data packet based on the authentication code A and original data. At this time, the value of the information A is X.
- the sending device generates the authentication code A, and the detailed description of the obtained data packet can refer to the above-mentioned embodiment shown in FIG. 11 , which will not be repeated here.
- the sending device sends the data packet to the receiving device.
- the receiving device generates an authentication code B based on the information B and the data packet. At this time, the value of the information B is X.
- the receiving device determines that the authentication code A is the same as the authentication code B, and the value of the update information B is X+i.
- the receiving device determines that the authentication code A is the same as the authentication code B, and determines that the data packet is successfully received.
- the receiving device may add i to the value of information B, that is, update the value of information B to X+i.
- the receiving device sends a successful application receipt to the sending device.
- the receiving device can generate a successful application receipt after determining that the data packet is received successfully, and send the successful application receipt to the sending device.
- the successful application receipt can be used to indicate that the receiving device has successfully received the data packet.
- the value of the sending device update information A is X+i.
- the sending device can determine that the data packet is sent successfully.
- the sending device may add i to the value of information A, that is, update the value of information A to X+i.
- the value of i updated by the sending device and the receiving device is the same.
- the sending device After generating the authentication code A based on the information A, the sending device can obtain the data packet based on the authentication code A and the original data. At this time, the value of the information A is X+i.
- the sending device sends the data packet to the receiving device.
- the receiving device generates an authentication code B based on the information B and the data packet. At this time, the value of the information B is X+i.
- the receiving device determines that the authentication code A is the same as the authentication code B, and the value of the update information B is X+2i.
- the receiving device determines that the authentication code A is the same as the authentication code B, and determines that the data packet is successfully received.
- the receiving device may add i to the value of information B, that is, update the value of information B to X+2i.
- the receiving device sends a successful application receipt to the sending device.
- the receiving device may generate a successful application receipt and send the successful application receipt to the sending device.
- the successful application receipt can be used to indicate that the receiving device has successfully received the data packet.
- the value of the sending device update information A is X+2i.
- the sending device can determine that the data packet is sent successfully.
- the sending device may add i to the value of information A, that is, update the value of information A to X+2i.
- the value of i updated by the sending device and the receiving device is the same.
- the sending device and the receiving device can update and maintain their respective context information synchronously, the sending device and the receiving device can transmit data packets, and avoid the receiving device from repeatedly processing repeatedly sent data packets.
- a transmission method provided by the present application is specifically introduced below in combination with application scenarios.
- the terminal 100 may send a satellite message (that is, a data packet) to the satellite network device 200 and display sending prompt information.
- the sending prompt information may be used to remind the user terminal 100 that the satellite message has been sent to the satellite network device 200 .
- the terminal 100 may display result prompt information after receiving the application receipt, and the result prompt information may be used to prompt the user whether the satellite message has been sent successfully or failed. In this way, the user of the terminal 100 can confirm the sending status of the satellite message, and resend the satellite message when the sending of the satellite message fails.
- the terminal 100 may display a desktop 1500 .
- the desktop 1500 may include multiple application icons (for example, a clock application icon, an information application icon 1501, etc.).
- the information application icon 1501 may be used to trigger the display of an information application interface (for example, the information application interface 1510 shown in FIG. 15B ).
- the top of the desktop 1500 may also display a status bar including icons such as a time mark icon and a signal mark icon.
- the information identification icon may be used to prompt the user terminal 100 to be in a no-network scenario, that is, a scenario where a communication connection with the second transmission system cannot be established.
- tray icons for example, a dialer application icon, a contact application icon, and a camera application icon
- the tray icons remain displayed when the pages are switched.
- the information application icon 1501 may also be a tray icon displayed under multiple application icons.
- the terminal 100 may also display an information application interface 1510 as shown in FIG. 15B .
- the information application interface 1510 may include an information overview display area and a title bar.
- the information overview display area may be used to display information sent and received by the terminal 100 .
- the title bar may include but not limited to a return control, a new information control 1511 and so on.
- the return control can be used to trigger the terminal 100 to display the desktop 1500 .
- the new message control 1511 can be used to trigger the terminal 100 to create a new satellite message.
- the above status bar may also be displayed on the top of the information application interface 1510 .
- the terminal 100 may also display the contact interface 1520 as shown in FIG. 15C.
- the contact interface 1520 may include at least one contact icon (the contact icon may include but not limited to the contact's name, mobile phone number, etc.).
- At least one contact icon may include a contact icon 1521 .
- the contact icon 1521 may be used to trigger the terminal 100 to confirm the recipient's ID number.
- the terminal 100 may display an information detail interface 1530 as shown in FIG. 15D .
- the information detail interface 1530 may include, but not limited to, an information editing field 1533 , a sending control 1532 and a keyboard area 1531 .
- the information editing column 1533 can be used to display the data input by the user through the keyboard area 1531 .
- the keyboard area 1531 may be used to receive a user's input to trigger the terminal 100 to display corresponding data.
- the sending control 1532 can be used to trigger the terminal 100 to send the data in the information editing column 1533 to the recipient after receiving the user's input.
- the information editing column 1533 may display text information "X" input by the user. It should be noted that the content displayed in the information editing column 1533 is the content input by the user.
- the embodiment of the present application writes the content input by the user as "X" just to better describe the embodiment. This description does not describe the content input by the user. Not limiting.
- the terminal 100 since the terminal 100 is in the first transmission system, the terminal 100 needs to send the satellite message to the called user (such as the terminal 300 ) through the satellite network device 200 .
- the satellite network device 200 As long as the satellite network device 200 successfully receives the data packet sent by the terminal 100, the default information is successfully sent to the called user.
- the terminal 100 receives the user's input for the send control 1532 shown in FIG. 15D , and in response to the input, the terminal 100 can send the original data including the user's input (that is, the data displayed in the information editing column 1533 ) to the satellite network device 200 data packets.
- the detailed description of the terminal 100 sending the data packet to the satellite network device 200 may refer to step S1401 and step S1402 in FIG. 14 above.
- the satellite network device 200 receiving and processing the data packet refer to step S1403 to step S1404 in FIG. 14 .
- the terminal 100 may also display the information details interface 1530 shown in FIG. 15E .
- the information detail interface 1530 may include but not limited to an information editing column 1533 , an information box 1542 and a sending prompt 1543 .
- the information box 1542 may be used to display the content of the satellite message that the terminal 100 has sent to the satellite network device 200 .
- the information box 1542 is displayed with an "X”.
- the sending prompt 1543 can be used to prompt the user terminal 100 to send the content displayed in the information box 1542 to the satellite network device 200.
- the sending prompt 1543 can include but not limited to text prompt information.
- the sending prompt 1543 can be the character string "sent".
- the specific description of the information details interface 1530 can refer to the embodiment shown in FIG. 15D , which will not be repeated here.
- the terminal 100 may display the success prompt information 1551 as shown in FIG. 15F .
- the success prompt message 1551 may be used to prompt the user terminal 100 to send the content in the message box 1542 to the recipient successfully.
- the success prompt information 1551 may include but not limited to text prompt information, for example, the success prompt information 1551 may be text prompt information "Send successfully".
- the description of the satellite network device 200 sending the successful application receipt to the terminal 100 may refer to the step S1405 described above in FIG. 14 .
- the terminal 100 may further update the value of the first information to X+i. For a specific description of updating the first information by the terminal 100, reference may be made to step S1406 in FIG. 14 .
- the terminal 100 may receive the user's input to the sending control 1532 shown in FIG. , the data displayed in the information editing column 1533) data packet.
- the information editing column 1533 may display the text information "X+i" input by the user.
- the detailed description of the terminal 100 sending the data packet to the satellite network device 200 may refer to step S1407 and step S1408 in FIG. 14 above.
- the terminal 100 may also display an information box 1561 and a sending prompt 1562 as shown in FIG. 15G .
- the information box 1561 may be used to display the content of the satellite message that the terminal 100 has sent to the satellite network device 200 .
- the message box 1561 displays "X+i".
- the sending prompt 1562 may be used to prompt the user terminal 100 to send the content displayed in the information box 1561 to the satellite network device 200 .
- the information detail interface 1530 reference may be made to the embodiment shown in FIG. 15D , which will not be repeated here.
- the terminal 100 may display the success prompt information 1571 as shown in FIG. 15H .
- the success prompt message 1571 may be used to prompt the user terminal 100 to send the content in the message box 1561 to the recipient successfully.
- the sending device After generating the authentication code A based on the information A, the sending device obtains a data packet based on the authentication code A and original data. At this time, the value of the information A is X.
- the sending device fails to send the data packet to the receiving device.
- the data packet is lost during transmission, and the receiving device fails to receive the data packet.
- the sending device After generating the authentication code A based on the information A, the sending device can obtain the data packet based on the authentication code A and the original data. At this time, the value of the information A is X.
- the receiving device since the receiving device failed to receive the last data packet sent by the sending device, the information B of the receiving device is not updated. And the receiving device does not send a successful application receipt to the sending device, so the value of information A of the sending device is still X.
- the sending device sends the data packet to the receiving device.
- the receiving device generates an authentication code B based on the information B and the data packet. At this time, the value of the information B is X.
- the receiving device determines that the authentication code A is the same as the authentication code B, and the value of the update information B is X+i.
- the receiving device determines that the authentication code A is the same as the authentication code B, and determines that the data packet is successfully received.
- the receiving device may add i to the value of information B, that is, update the value of information B to X+i.
- the sending device sends a data packet to the receiving device
- the data packet is lost during the sending process, and the receiving device fails to receive the data packet.
- the context information of the sending device and the receiving device are not updated, the transmission of subsequent data packets will not be affected.
- the sending device sends the data packet to the receiving device
- the receiving device successfully receives the data packet and updates the value of information B.
- the successful application receipt sent by the receiving device to the sending device was lost during the sending process, and the sending device failed to receive the successful application receipt, and the value of information A was not updated.
- the context information of the sending device and the receiving device are inconsistent, which affects the transmission of subsequent data packets.
- the sending device After generating the authentication code A based on the information A, the sending device obtains the data packet based on the authentication code A and the original data. At this time, the value of the information A is X.
- the sending device sends the data packet to the receiving device.
- the receiving device generates an authentication code B based on the information B and the data packet. At this time, the value of the information B is X.
- the receiving device determines that the authentication code A is the same as the authentication code B, and the value of the update information B is X+i.
- the receiving device determines that the authentication code A is the same as the authentication code B, and determines that the data packet is successfully received.
- the receiving device may add i to the value of information B, that is, update the value of information B to X+i.
- the receiving device fails to send the successful application receipt to the sending device.
- the successful application receipt is lost during sending, and the sending device fails to receive the successful application receipt.
- the sending device After generating the authentication code A based on the information A, the sending device obtains the data packet based on the authentication code A and the original data. At this time, the value of the information A is X.
- the sending device fails to receive the successful application receipt sent by the receiving device, it cannot confirm the sending status of the previous data packet, and cannot update the information A. So the value of information A is still X.
- the sending device sends the data packet to the receiving device.
- the receiving device generates an authentication code B based on the information B and the data packet. At this time, the value of the information B is X+i.
- the receiving device determines that the authentication code A is different from the authentication code B.
- the receiving device determines that the authentication code A is different from the authentication code B, and determines that the data packet fails to be received.
- the sending device when the sending device sends a data packet to the receiving device, the receiving device successfully receives the data packet, updates the value of information B, and sends a successful application receipt to the sending device. However, because the sending device fails to receive the successful application receipt, the information A of the sending device is not updated, so the information A is different from the information B, which affects the transmission of subsequent data packets.
- the sending device and the receiving device can also transmit subsequent data packets.
- the sending device and the receiving device can reset the value of their respective context information. This way, the sending device and the receiving device can continue to transmit packets.
- the information B may be reset to a preset initial value.
- the sending device may also reset the information A to a preset initial value after receiving the receipt of the failed application.
- the values of information A and information B can be adjusted to the same value, and the sending device and receiving device can continue to transmit data packets.
- the sending device After generating the authentication code A based on the information A, the sending device obtains a data packet based on the authentication code A and original data. At this time, the value of the information A is X.
- the sending device sends the data packet to the receiving device.
- the receiving device generates an authentication code B based on the information B and the data packet. At this time, the value of the information B is Y.
- X and Y are different.
- the receiving device determines that the authentication code A is different from the authentication code B, and the value of the update information B is Z.
- the receiving device can determine whether the data packet is received by comparing whether the authentication code A and the authentication code B are the same. The receiving device determines that the authentication code A is different from the authentication code B, and determines that the data packet fails to be received.
- the receiving device may adjust the value of the information B to a preset initial value Z.
- the receiving device sends a failure application receipt to the sending device.
- the receiving device may generate an application receipt (ie, a failure application receipt) for indicating failure to receive the data packet.
- the receiving device may send the failed application receipt to the sending device.
- the sending device After receiving the failure application receipt, the sending device confirms that the data packet has failed to be sent, and the value of the update information A is Z. The context information of the sending device and the receiving device are adjusted to the same value.
- the sending device may only send a failure application receipt to the sending device, without changing the value of the information B.
- the sending device may reset the information A to a preset initial value after receiving the failure application receipt.
- the sending device can also send the preset initial value to the receiving device, and the receiving device can adjust the value of information B to the preset initial value after receiving the preset initial value. Exemplary, as shown in Figure 17B:
- the sending device After generating the authentication code A based on the information A, the sending device obtains a data packet based on the authentication code A and the original data. At this time, the value of the information A is X.
- the sending device sends the data packet to the receiving device.
- the receiving device generates an authentication code B based on the information B and the data packet. At this time, the value of the information B is Y.
- X and Y are different.
- the receiving device determines that the authentication code A is different from the authentication code B.
- the receiving device can determine whether the data packet is received by comparing whether the authentication code A and the authentication code B are the same. The receiving device determines that the authentication code A is different from the authentication code B, and determines that the data packet fails to be received.
- the receiving device sends a failure application receipt to the sending device.
- the receiving device may generate an application receipt (ie, a failure application receipt) for indicating failure to receive the data packet.
- the receiving device may send the failed application receipt to the sending device.
- the sending device After receiving the failure application receipt, the sending device confirms that the data packet has failed to be sent, and the value of the update information A is Z.
- the sending device sends the value of information A to the receiving device.
- the sending device may encapsulate the value of information A into a data packet, and then send the data packet including the value of information A to the receiving device.
- the terminal 100 may send the third information to the satellite network device 200 after adjusting the value of the first information to a preset value, wherein the value of the third information and the adjusted first The value of one message is the same.
- the satellite network device 200 may send the seventh information to the terminal 100 after adjusting the value of the sixth information to a preset value, wherein the value of the seventh information and the adjusted value of the sixth information same.
- the preset value is an initial value.
- the value of the receiving device updating information B is Z.
- the receiving device may adjust the value of information B to be the same as that of information A, that is, adjust the value of information B to the preset initial value Z.
- the attacking terminal intercepts the preset initial value and repeatedly sends the preset initial value to the receiving device
- the receiving device will always reset the value of the information B of the receiving device, causing the sending device and the receiving device to fail to communicate normally.
- the value of information B is greater than the value of information A by a preset value.
- the receiving device does not adjust the value of information B after failing to receive the data packet
- the sending device may add a preset value to the value of information A after receiving the failure application receipt. In this way, the sending device can adjust the value of information A by itself after receiving the application receipt, so that information A and information B are the same.
- the number of data packets successfully sent by the sending device may be the sum of the number of successful application receipts received by the sending device and the number of unreceived successful application receipts determined by the sending device based on the failed application receipts .
- the sending device After generating the authentication code A based on the information A, the sending device obtains the data packet based on the authentication code A and the original data. At this time, the value of the information A is X.
- the sending device sends the data packet to the receiving device.
- the sending device is the terminal 100
- the receiving device is the satellite network device 200
- the terminal 100 may display an information detail interface 1800 as shown in FIG. 18A .
- the information detail interface 1800 may include an information box 1801 and a sending prompt 1802 .
- the information box 1801 may be used to display the content of the satellite message that the terminal 100 has sent to the satellite network device 200 .
- information box 1801 displays information content, for example, "X”.
- the sending prompt 1802 may be used to prompt the user terminal 100 to send the content displayed in the information box 1801 to the satellite network device 200 .
- the information detail interface 1800 refer to the embodiment shown in FIG.
- the content displayed in any information box described in the embodiment of this application is the content input by the user in the satellite message.
- the embodiment of this application writes the content as "X" for better description For example, this description does not limit the content input by the user.
- the receiving device generates an authentication code B based on the information B and the data packet. At this time, the value of the information B is X.
- the receiving device determines that the authentication code A is the same as the authentication code B, and the value of the update information B is X+i.
- the receiving device determines that the authentication code A is the same as the authentication code B, and determines that the data packet is successfully received.
- the receiving device may add i to the value of information B, that is, update the value of information B to X+i.
- the receiving device fails to send the successful application receipt to the sending device.
- the successful application receipt is lost during sending, and the sending device fails to receive the successful application receipt.
- the sending device After generating the authentication code A based on the information A, the sending device obtains the data packet based on the authentication code A and the original data. At this time, the value of the information A is X.
- the sending device fails to receive the successful application receipt sent by the receiving device, it cannot confirm the sending status of the previous data packet, and cannot update the information A. So the value of information A is still X.
- the sending device sends the data packet to the receiving device.
- the sending device is the terminal 100
- the receiving device is the satellite network device 200
- the terminal 100 may display an information box 1811 and a sending prompt 1812 as shown in FIG. 18B .
- the information box 1811 may be used to display the content of the satellite message that the terminal 100 has sent to the satellite network device 200 .
- the message box 1811 is displayed with "X”.
- the sending prompt 1812 may be used to prompt the user terminal 100 to send the content displayed in the information box 1811 to the satellite network device 200 .
- FIG. 15D For a specific description of the information detail interface 1800, reference may be made to the embodiment shown in FIG. 15D , which will not be repeated here.
- the receiving device generates an authentication code B based on the information B and the data packet. At this time, the value of the information B is X+i.
- the receiving device determines that the authentication code A is different from the authentication code B.
- the receiving device determines that the authentication code A is different from the authentication code B, and determines that the data packet fails to be received.
- the receiving device sends a failure application receipt to the sending device.
- the value of the sending device update information A is X+i.
- the sending device can confirm that the current data packet fails to be received after receiving the failure application receipt. Moreover, since the sending device has only sent two data packets, the sending device can determine that the value of information B has been updated, that is, the sending device can determine that the receiving device has successfully received the previous data packet of the sending device. The sending device can determine that the previous data packet was successfully sent but the current data packet failed to be sent, and the sending device can add a preset value to the value of information A, that is, adjust the value of information A to X+i.
- the sending device is the terminal 100
- the receiving device is the satellite network device 200
- the terminal 100 may display the success prompt information 1821 and the failure prompt information 1822 as shown in FIG. 18C .
- the success prompt information 1821 may be used to prompt the user terminal 100 to send the content in the information box 1801 to the recipient successfully.
- the failure prompt information 1822 may be used to prompt the user terminal 100 to fail to send the content in the information box 1811 to the recipient.
- the failure prompt information 1822 may include but not limited to text prompt information, for example, the failure prompt information 1822 may include text prompt information "failed to send".
- the terminal 100 will display the result prompt information only after receiving the application receipt.
- the transmission of the next data packet between the sending device and the receiving device is not affected.
- the sending device can also determine that the previous data packet failed to be received according to the successful application receipt of the next data packet sent.
- the sending device After generating the authentication code A based on the information A, the sending device obtains a data packet based on the authentication code A and original data. At this time, the value of the information A is X.
- the sending device fails to send the data packet to the receiving device.
- the data packet is lost during transmission, and the receiving device fails to receive the data packet.
- the sending device is the terminal 100
- the receiving device is the satellite network device 200
- the terminal 100 may display an information detail interface 1800 as shown in FIG. 18A .
- the information detail interface 1800 reference may be made to the embodiment shown in FIG. 17C , which will not be repeated here.
- the sending device After generating the authentication code A based on the information A, the sending device can obtain the data packet based on the authentication code A and the original data. At this time, the value of the information A is X.
- the receiving device since the receiving device failed to receive the last data packet sent by the sending device, the information B of the receiving device is not updated. And the receiving device does not send a successful application receipt to the sending device, so the value of information A of the sending device is still X.
- the sending device sends the data packet to the receiving device.
- the sending device is the terminal 100
- the receiving device is the satellite network device 200
- the terminal 100 may display an information box 1811 and a sending prompt 1812 as shown in FIG. 18B .
- the detailed description of the information box 1811 and the sending prompt 1812 can refer to the embodiment shown in FIG. 17C , which will not be repeated here.
- the receiving device generates an authentication code B based on the information B and the data packet. At this time, the value of the information B is X.
- the receiving device determines that the authentication code A is the same as the authentication code B, and the value of the update information B is X+i.
- the receiving device determines that the authentication code A is the same as the authentication code B, and determines that the data packet is successfully received.
- the receiving device may add i to the value of information B, that is, update the value of information B to X+i.
- the receiving device sends a successful application receipt to the sending device.
- the value of the sending device update information A is X+i.
- the sending device After receiving the successful application receipt, the sending device confirms that the second data packet is sent successfully. Since the sending device did not update the value of information A when sending the second data packet, the sending device can confirm that the receiving device did not update the value of information B, that is, the receiving device did not receive the first data packet. The sending device confirms that the first data packet fails to be sent.
- the sending device is the terminal 100
- the receiving device is the satellite network device 200
- the terminal 100 may display failure prompt information 2101 and success prompt information 2102 as shown in FIG. 20 .
- the failure prompt information 2101 may be used to prompt the user terminal 100 to fail to send the content in the information box 1801 to the recipient.
- the success prompt message 2102 may be used to prompt the user terminal 100 to send the content in the message box 1811 to the recipient successfully.
- the sending device if the sending device has sent at least two data packets before receiving the failure application receipt (during sending the at least two data packets, the sending device has not received the application receipt), when the sending device receives the failure application receipt After the receipt is applied, it cannot be determined which of the at least two packets was successfully sent.
- the information A of the sending device is context information (context) A
- the information B of the receiving device is context information B.
- the context information A may be used to indicate the quantity information of the sent data packets.
- the information B of the receiving device is context information B, and the context information B may be used to indicate the quantity information of the received data packets.
- the sending device may add a message ID field A in the data packet.
- Message ID field A can be used to identify the data packet.
- the receiving device can determine the value of the message ID field B based on the message ID field A of the successfully received data packet.
- the receiving device may add a message ID field B to the application receipt, and the message ID field B may be used to identify the latest successfully received data packet.
- the application receipt added with the message ID field B of the successfully received data packet may be referred to as the instruction application receipt.
- the sending device can determine the successfully sent data packet by indicating the message ID field B in the application receipt.
- the terminal 100 and the satellite network device 200 may obtain the context information through the cellular network, or the terminal 100 may obtain the context information through an intermediate device, or the terminal 100 and the satellite network device 200 may preset the context information.
- the terminal 100 and the satellite network device 200 may obtain the context information through the cellular network, or the terminal 100 may obtain the context information through an intermediate device, or the terminal 100 and the satellite network device 200 may preset the context information.
- the successful application receipt, the failed application receipt and the instruction application receipt may be collectively referred to as the first application receipt.
- the successful application receipt, the failure application receipt and the instruction application receipt may be collectively referred to as a third application receipt.
- the satellite network device 200 only generates a successful application receipt and a failed application receipt, so the successful application receipt and the failed application receipt may be collectively referred to as the first application receipt.
- the terminal 100 only generates a successful application receipt and a failed application receipt, so the successful application receipt and the failed application receipt may be collectively referred to as the third application receipt.
- FIG. 21 shows a schematic diagram of a processing flow of a transmission method provided by an embodiment of the present application.
- the sending device generates an authentication code A based on the original data and context information A.
- the context information A is the context information A
- the context information A may be used to indicate the quantity information of the sent data packets.
- the information on the number of data packets sent is information on the number of data packets successfully sent by the sending device.
- the number information of successfully sent data packets may be the sum of a preset offset value, the number of successful application receipts received by the sending device, and the number of application indication receipts received by the sending device.
- the preset offset value is greater than or equal to zero. That is to say, after receiving the successful application receipt/indication application receipt, the sending device may add a preset value to the value of the context information A. It should be noted that the increment of the context information A is related to the number of data packets successfully sent by the sending device.
- the sending device can obtain the authentication code A based on the context information A and the original data.
- the sending device obtains the authentication code A, reference may be made to the above-mentioned embodiment shown in FIG. 7 , which will not be repeated here.
- the sending device may generate an authentication code A based on the context information A, a specified key, and original data, and then generate a data packet based on the authentication code A and the original data.
- the receiving device can generate the authentication code B based on the context information B, the specified key and the data packet. In this way, the legitimacy of the sending device can be verified by specifying the key to ensure the security of the transmission.
- the sending device obtains the data packet based on message ID field A, original data and authentication code A.
- the sending device can stitch together the message ID field A, the authentication code A and the original data to obtain a data packet.
- the sending device may store the message ID, and the value of the message ID may be updated along with the data packet generated by the sending device when the value of the context information A does not change. That is, the sending device may update the value of the message ID after generating the data packet based on the message ID field A corresponding to the message ID. Wherein, when the value of the context information A changes, the sending device may reset the value of the message ID. In this way, when the value of the context information A does not change, since the message ID can identify different data packets, the sending device and the receiving device can distinguish the data packets through the message ID field of the data packet.
- the sending device when the sending device sends multiple data packets and does not receive a successful application receipt, the receiving device can send the message ID of the latest successfully received data packet to the sending device, and the sending device can confirm based on the value of the message ID The sending of multiple packets.
- the message ID when the length of the message ID is 2 bits, the message ID may be "00", “01", “10", and "11".
- the sending device can send the data packet 1 to the receiving device after generating the data packet 1 including the message ID field A as "00" based on the message ID "00", and update the value of the message ID to "01".
- the sending device may update the value of the context information A, and reset the value of the message ID to "00".
- the sending device may generate and send to the receiving device a data packet 2 including a message ID field A of "00".
- the sending device may, after generating the data packet 1 including the message ID field A of "00" based on the message ID "00", send the data packet 1 to the receiving device, and update the value of the message ID to "01".
- the sending device does not receive the application receipt of the data packet 1 whose message ID field A is "00”, it can generate and send the data packet 2 including the message ID field A of "01” to the receiving device, and the sending device can also update The value of the message ID is "10".
- the sending device does not receive the application receipt of the data packet 2 whose message ID field A is "01”
- it can generate and send the data packet 3 including the message ID field A of "10” to the receiving device, and the sending device can also update The value of the message ID is "11".
- the sending device When the sending device receives the application receipt that includes the message ID field B as "01", the sending device can determine that the data packets with the message ID field A as "00" and "10" have failed to be sent, and the message ID field A is "01". 01" packet sent successfully. The sending device may update the value of the context information A and adjust the value of the message ID to "00".
- the sending device may add packet header information before the concatenated authentication code A and original data to obtain a data packet.
- the packet header information may include message ID field A and so on.
- the sending device may concatenate the authentication code A and the original data to obtain concatenated data.
- the sending device uses the specified key to encrypt the spliced data through the specified algorithm to obtain the encrypted data.
- the sending device may add header information before the encrypted data, and the header information includes an encryption indication field and a message ID field A.
- the encryption indication field may be used to indicate a specified algorithm (such as the SM3 cryptographic hash algorithm) used by the sending device.
- the sending device can concatenate the message ID field A, the authentication code A and the original data together, and then use a specified key for encryption.
- the sending device can send the data packet to the receiving device.
- the description of sending the data packet from the sending device to the receiving device during inbound can refer to the embodiment shown in FIG. 2A above, and the description of sending the data packet from the sending device to the receiving device during outbound can be Refer to the embodiment shown in FIG. 3A above, and details are not repeated here.
- the sending device when the sending device is the terminal 100, after the sending device sends the data packet to the receiving device, the sending device may display sending prompt information.
- the sending prompt information may be used to prompt the user that the sending device has sent a satellite message to the receiving device.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Physics & Mathematics (AREA)
- Astronomy & Astrophysics (AREA)
- Aviation & Aerospace Engineering (AREA)
- General Physics & Mathematics (AREA)
- Mobile Radio Communication Systems (AREA)
- Communication Control (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims (54)
- 一种传输方法,其特征在于,包括:第一设备基于第一信息、第一密钥和第一数据生成第一鉴权码;其中,所述第一信息为发送时间信息或第一上下文信息;所述第一设备基于所述第一鉴权码与所述第一数据生成第一数据包;所述第一设备在第一传输系统下向第二设备发送所述第一数据包。
- 根据权利要求1所述的方法,其特征在于,在所述第一设备基于第一信息、第一密钥和第一数据生成第一鉴权码之前,所述方法还包括:所述第一设备获取所述第一密钥,所述第一密钥为所述第一设备在第二传输系统下与所述第二设备协商获取的;其中,所述第一传输系统与所述第二传输系统不同。
- 根据权利要求1所述的方法,其特征在于,在所述第一设备基于第一信息、第一密钥和第一数据生成第一鉴权码之前,所述方法还包括:所述第一设备和第四设备建立通信连接;所述第一设备通过所述第四设备获取所述第一密钥。
- 根据权利要求1所述的方法,其特征在于,所述第一密钥为所述第一设备预先设置的密钥。
- 根据权利要求2所述的方法,其特征在于,所述第二传输系统为蜂窝传输系统或无线局域网WLAN传输系统,所述第一传输系统为卫星传输系统。
- 根据权利要求2或5所述的方法,其特征在于,所述第一设备在所述第二传输系统下与所述第二设备通过通用引导框架GBA流程协商获取所述第一密钥。
- 根据权利要求1-5中任一项所述的方法,其特征在于,所述第一设备在第一传输系统下向第二设备发送所述第一数据包,具体包括:所述第一设备的消息数据汇聚层MDCP层和/或所述第一设备的卫星链路控制层SLC层将所述第一数据包处理为至少一个第二数据包后,将所述至少一个第二数据包经过第三设备发送给所述第二设备。
- 根据权利要求1-7中任一项所述的方法,所述发送时间信息用于指示所述第一数据包的发送时间。
- 根据权利要求8所述的方法,其特征在于,所述第一设备发送所述第一数据包的时间为所述第一设备的应用AP层向消息数据汇聚MDCP层发送所述第一数据包的时间,或者,为所述第一设备预估的将所述第一数据包发送给所述第二设备的时间。
- 根据权利要求1-9中任一项所述的方法,所述第一设备通过定位授时获取所述发送时间信息。
- 根据权利要求1-10中任一项所述的方法,其特征在于,所述第一设备基于所述发送时间信息和指定时间粒度,通过预设编码方式,得到所述第一信息。
- 根据权利要求1-11中任一项所述的方法,其特征在于,在所述第一设备发送所述第一数据包之后,所述方法还包括:所述第一设备接收到所述第二设备发送的第一应用层回执;其中,所述第一应用层回执用于指示所述第二设备接收所述第一数据包的接收状态。
- 根据权利要求1-7中任一项所述的方法,其特征在于,所述第一信息为第一上下文信 息,所述第一上下文信息用于指示所述第一设备发送成功的第一数据包的数量信息,或所述第一设备成功接收到应用回执的数量信息,或所述第一设备发送的第一数据包的计数值或序列号。
- 根据权利要求1-7、13中任一项所述的方法,其特征在于,所述第一数据包还包括第一指示信息,所述第一指示信息用于指示所述第一数据包的第一消息ID,或者所述第一指示信息用于指示所述第一数据包的第一计数值或第一序列号。
- 根据权利要求1-7、13、14中任一项所述的方法,其特征在于,所述方法还包括:所述第一设备的AP层关联第一消息ID或第一计数值或第一序列号到所述第一数据包,所述第一设备在所述第一消息ID或所述第一计数值或第一序列号的值上增加预设值。
- 根据权利要求1-4、13-15中任一项所述的方法,其特征在于,所述第一数据包还包括第三指示信息,所述第三指示信息用于指示所述第一数据包为新传数据包或重传数据包。
- 根据权利要求13-16中任一项所述的方法,其特征在于,在所述第一设备基于第一信息、第一密钥和第一数据生成第一鉴权码之前,所述方法还包括:所述第一设备在第二传输系统中获取所述第一信息的初始值;或者,所述第一设备通过第四设备获取所述第一信息的初始值。
- 根据权利要求13-17中任一项所述的方法,其特征在于,在所述第一设备发送所述第一数据包之后,所述方法还包括:所述第一设备接收到所述第二设备发送的第一应用层回执;其中,所述第一应用层回执用于指示所述第二设备接收所述第一数据包的接收状态。
- 根据权利要求18所述的方法,其特征在于,在所述第一设备接收到所述第二设备发送的第一应用层回执之后,所述方法还包括:所述第一设备在所述第一信息的值上增加预设值;所述第一信息调整后的值和所述第一信息的值不同。
- 根据权利要求19所述的方法,其特征在于,在所述第一设备接收到所述第二设备发送的第一应用层回执之后,所述方法还包括:当所述第一应用回执用于指示所述第二设备接收所述第一数据包失败时,所述第一设备调整所述第一信息的值为初始值。
- 根据权利要求20所述的方法,其特征在于,在所述第一设备调整所述第一信息的值为初始值之后,所述方法还包括:所述第一设备向所述第二设备发送第三信息,所述第三信息的值和调整后的所述第一信息的值相同。
- 根据权利要求12、18-21中任一项所述的方法,其特征在于,在所述第一设备接收到所述第二设备发送的第一应用层回执之后,所述方法还包括:当所述第一应用回执指示所述第一数据包发送成功时,所述第一设备显示成功提示信息,所述成功提示信息用于提示用户所述第一数据包对应的消息发送成功。
- 根据权利要求12、18-21中任一项所述的方法,其特征在于,在所述第一设备接收到所述第二设备发送的第一应用层回执之后,所述方法还包括:当所述第一应用回执指示所述第一数据包发送失败时,所述第一设备显示失败提示信息,所述失败提示信息用于提示用户所述第一数据包对应的消息发送失败。
- 根据权利要求12、18-21中任一项所述的方法,其特征在于,所述第一设备接收到所述第二设备发送的第一应用层回执之后,所述方法还包括:当所述第一应用回执包括第二消息ID信息时,所述第一设备显示成功提示信息,所述成功提示信息用于提示用户所述第二消息ID信息指示的数据包发送成功。
- 根据权利要求1-24中任一项所述的方法,其特征在于,所述第一设备的应用层根据所述第一鉴权码与所述第一数据生成第一数据包,具体包括:所述第一设备的应用层基于所述第一密钥加密所述第一鉴权码和所述第一数据,生成所述第一数据包;其中,所述第一数据包包括加密后的所述第一鉴权码和加密后的所述第一数据。
- 根据权利要求1-25中任一项所述的方法,其特征在于,在所述第一设备在第一传输系统下向第二设备发送所述第一数据包之后,所述方法还包括:所述第一设备在所述第二传输系统接收第二应用回执信息,所述第二应用回执信息用于指示所述第一设备在所述第一传输系统中所述第一数据包的发送状态。
- 根据权利要求1-26中任一项所述的方法,其特征在于,在所述第一设备在第一传输系统下向第二设备发送第一数据包之后,所述方法还包括:所述第一设备显示发送提示信息,所述发送提示信息用于提示用户所述第一设备已向所述第二设备发送所述第一数据包。
- 一种安全传输的方法,其特征在于,包括:第二设备在第一传输系统下接收第一设备发送的第一数据包;所述第二设备根据第二信息、第一密钥、所述第一数据包生成第二鉴权码;其中,所述第二信息为接收时间信息或第二上下文信息;所述第二设备基于所述第二鉴权码确定所述第一数据包的接收状态。
- 根据权利要求28所述的方法,其特征在于,在所述第二设备根据第二信息、第一密钥、所述第一数据包生成第二鉴权码之前,所述方法还包括:所述第二设备获取所述第一密钥,所述第一密钥为所述第二设备在第二传输系统下与所述第一设备协商获取的;其中,所述第二传输系统与所述第一传输系统不同。
- 根据权利要求29所述的方法,其特征在于,所述第二传输系统为蜂窝传输系统或WLAN传输系统,所述第一传输系统为卫星传输系统。
- 根据权利要求29或30所述的方法,其特征在于,所述第二设备在所述第二传输系统下与所述第一设备通过通用引导框架GBA流程协商获取所述第一密钥。
- 根据权利要求28所述的方法,其特征在于,第一密钥为所述第一设备预先设置的密钥。
- 根据权利要求28-32中任一项所述的方法,其特征在于,所述第二设备在第一传输系统下接收第一数据包,具体包括:所述第二设备在第一传输系统下接收第三设备发送的所述第一数据包。
- 根据权利要求28-33中任一项所述的方法,其特征在于,所述第二设备根据所述第一数据包确定第一鉴权码。
- 根据权利要求28-34中任一项所述的方法,其特征在于,所述接收时间信息用于指示所述第一数据包的接收时间。
- 根据权利要求28-35中任一项所述的方法,其特征在于,在所述第二设备根据第二信息、第一密钥、所述第一数据包生成第二鉴权码之前,所述方法还包括:所述第二设备接收所述第三设备发送的第二信息。
- 根据权利要求28-35中任一项所述的方法,其特征在于,在所述第二设备根据第二信 息、第一密钥、所述第一数据包生成第二鉴权码之前,所述方法还包括:所述第二设备接收所述第三设备发送的第三信息;所述第二设备基于所述第三信息生成所述第二信息。
- 根据权利要求28-34中任一项所述的方法,其特征在于,所述第二上下文信息用于指示所述第二设备成功接收第一数据包的数量信息,或所述第二设备接收的所述第一数据包的计数值或序列值。
- 根据权利要求28-34、38中任一项所述的方法,其特征在于,所述第一数据包包括第一指示信息,所述第一指示信息用于指示所述第一数据包的第一消息ID/第一序列号/第一计数值。
- 根据权利要求28-34、38、39中任一项所述的方法,其特征在于,所述第一数据包包括第三指示信息,所述第三指示信息用于指示所述第一数据包为新传数据包/重传数据包。
- 根据权利要求28-34、38-40中任一项所述的方法,其特征在于,在所述第二设备根据第二信息、第一密钥、所述第一数据包生成第二鉴权码之前,所述方法还包括:所述第二设备在第二传输系统中获取所述第二信息的初始值。
- 根据权利要求28-41中任一项所述的方法,其特征在于,所述第二设备基于所述第二鉴权码确定所述第一数据包的接收状态,具体包括:所述第二设备基于所述第一鉴权码与所述第二鉴权码是否相同,确定所述第一数据包的接收状态。
- 根据权利要求42所述的方法,其特征在于,当所述第二设备基于第二鉴权码确定出所述第一数据包接收成功时,所述方法还包括:所述第二设备向所述第一设备发送第一应用回执,所述第一应用回执用于指示所述第一数据包的接收成功。
- 根据权利要求42所述的方法,其特征在于,当所述第二设备基于第二鉴权码确定出所述第一数据包接收失败时,所述方法还包括:所述第二设备向所述第一设备发送第一应用回执,所述第一应用回执还包括第二消息ID字段,所述第二消息ID字段用于指示最近传输成功的数据包对应的消息ID。
- 根据权利要求42所述的方法,其特征在于,当所述第二设备基于第二鉴权码确定出所述第一数据包接收失败时,所述方法还包括:所述第二设备向所述第一设备发送第一应用回执,所述第一应用回执用于指示所述第一数据包的接收失败。
- 根据权利要求42所述的方法,其特征在于,当所述第二设备基于第二鉴权码确定出所述第一数据包接收成功时,所述方法还包括:所述第二设备在所述第二信息的值上增加预设值;所述第二信息调整后的值和所述第二信息的值不同。
- 根据权利要求42所述的方法,其特征在于,当所述第二设备基于第二鉴权码确定出所述第一数据包接收失败时,所述方法还包括:所述第二设备调整所述第二信息的值为预设值。
- 根据权利要求42所述的方法,其特征在于,当所述第二设备基于第二鉴权码确定出所述第一数据包接收失败时,所述方法还包括:所述第二设备接收到所述第一设备发送的第三信息;所述第二设备调整所述第二信息的值为所述第三信息的值。
- 根据权利要求28-48中任一项所述的方法,其特征在于,在所述第二设备基于所述第二鉴权码确定所述第一数据包的接收状态之后,所述方法还包括:所述第二设备在所述第二传输系统向所述第一设备发送第二应用回执信息,所述第二应用回执信息用于指示所述第二设备在所述第一传输系统中所述第一数据包的接收状态。
- 一种传输方法,其特征在于,包括:第三设备接收第一设备发送的至少一个第二数据包;所述第三设备基于所述至少一个第二数据包,生成第一数据包;所述第三设备向第二设备发送所述第一数据包。
- 根据权利要求50所述的方法,其特征在于,所述方法还包括:所述第三设备向所述第二设备发送第二信息或第四信息,所述第二信息或所述第四信息为接收时间信息。
- 根据权利要求51所述的方法,其特征在于,所述接收时间信息用于指示所述第三设备接收到至少一个第二数据包中的第1个数据包对应的时间。
- 一种通信装置,其特征在于,包括一个或多个处理器和一个或多个存储器;其中,所述一个或多个存储器用于存储计算机程序代码,所述计算机程序代码包括计算机指令,当一个或多个处理器在执行所述计算机指令时,使得所述通信装置执行如权利要求1-52中任一项所述的方法。
- 一种计算机可读存储介质,所述计算机可读存储介质中存储有指令,当所述指令在计算机上运行时,使得所述计算机执行如权利要求1-52中任一项所述的方法。
Priority Applications (4)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP22852086.2A EP4369631A4 (en) | 2021-07-31 | 2022-07-29 | TRANSMISSION METHOD AND SYSTEM, AND ASSOCIATED DEVICE |
| JP2024506446A JP7751069B2 (ja) | 2021-07-31 | 2022-07-29 | 伝送方法、システム、および関連装置 |
| US18/428,505 US20240276210A1 (en) | 2021-07-31 | 2024-01-31 | Transmission method, system, and related apparatus |
| JP2025159521A JP2026016389A (ja) | 2021-07-31 | 2025-09-25 | 伝送方法、システム、および関連装置 |
Applications Claiming Priority (4)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202110878362 | 2021-07-31 | ||
| CN202110878362.0 | 2021-07-31 | ||
| CN202111166937.2 | 2021-09-30 | ||
| CN202111166937.2A CN115694599B (zh) | 2021-07-31 | 2021-09-30 | 一种传输方法、系统及相关装置 |
Related Child Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US18/428,505 Continuation US20240276210A1 (en) | 2021-07-31 | 2024-01-31 | Transmission method, system, and related apparatus |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2023011373A1 true WO2023011373A1 (zh) | 2023-02-09 |
Family
ID=85059638
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2022/109226 Ceased WO2023011373A1 (zh) | 2021-07-31 | 2022-07-29 | 一种传输方法、系统及相关装置 |
Country Status (5)
| Country | Link |
|---|---|
| US (1) | US20240276210A1 (zh) |
| EP (1) | EP4369631A4 (zh) |
| JP (2) | JP7751069B2 (zh) |
| CN (2) | CN115694599B (zh) |
| WO (1) | WO2023011373A1 (zh) |
Families Citing this family (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN121511567A (zh) * | 2023-07-07 | 2026-02-10 | Oppo广东移动通信有限公司 | 一种无线通信方法、通信设备及存储介质 |
| CN119629167B (zh) * | 2024-12-05 | 2026-04-17 | 国家电投集团郑州燃气发电有限公司 | 一种基于物联网的现场数据传输方法及系统 |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN102594555A (zh) * | 2011-01-17 | 2012-07-18 | 华为技术有限公司 | 数据的安全保护方法、网络侧实体和通信终端 |
| US20150052360A1 (en) * | 2013-04-29 | 2015-02-19 | Hughes Network Systems, Llc | Method and system for providing enhanced data encryption protocols in a mobile satellite communications system |
| CN106304046A (zh) * | 2015-06-01 | 2017-01-04 | 陈晓华 | 对iBeacon广播消息加密、鉴权的方法 |
| US20180372878A1 (en) * | 2017-06-27 | 2018-12-27 | Here Global B.V. | Authentication of satellite navigation system receiver |
| CN112243235A (zh) * | 2020-09-15 | 2021-01-19 | 西安电子科技大学 | 适用于天地一体化的群组接入认证和切换认证方法及应用 |
Family Cites Families (18)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN1870808A (zh) * | 2005-05-28 | 2006-11-29 | 华为技术有限公司 | 一种密钥更新方法 |
| DE102005026982A1 (de) * | 2005-06-10 | 2006-12-14 | Siemens Ag | Verfahren zur Vereinbarung eines Sicherheitsschlüssels zwischen mindestens einem ersten und einem zweiten Kommunikationsteilnehmer zur Sicherung einer Kommunikationsverbindung |
| CN103155478A (zh) * | 2010-07-23 | 2013-06-12 | Emue控股集团公司 | 加密装置及加密方法 |
| WO2013146451A1 (ja) * | 2012-03-28 | 2013-10-03 | 日本電気株式会社 | 通信システム、送信装置、受信装置、及び通信方法 |
| KR101667970B1 (ko) * | 2012-11-15 | 2016-10-20 | 닛본 덴끼 가부시끼가이샤 | 서버 장치, 단말, 씬 클라이언트 시스템, 화면 송신 방법 및 프로그램 |
| US9866591B1 (en) * | 2013-06-25 | 2018-01-09 | Wickr Inc. | Enterprise messaging platform |
| CN104427584B (zh) * | 2013-08-19 | 2019-08-16 | 南京中兴软件有限责任公司 | 安全上下文处理方法及装置 |
| WO2017000272A1 (zh) * | 2015-07-01 | 2017-01-05 | 海能达通信股份有限公司 | 一种无线系统接入控制方法及装置 |
| CN108293223B (zh) * | 2015-11-30 | 2020-11-17 | 华为技术有限公司 | 一种数据传输方法、用户设备和网络侧设备 |
| CN108370601A (zh) * | 2015-12-22 | 2018-08-03 | 华为技术有限公司 | 数据传输处理方法、用户设备和基站 |
| EP3582531B1 (en) * | 2017-03-18 | 2021-02-17 | Huawei Technologies Co., Ltd. | Network access authentication method based on non-3gpp network, and related device and system |
| CN108810889B (zh) * | 2017-05-05 | 2020-12-04 | 华为技术有限公司 | 通信方法、装置及系统 |
| JP7164218B2 (ja) * | 2017-08-28 | 2022-11-01 | マイリオタ ピーティーワイ エルティーディー | 通信システムにおける端末識別情報保護方法 |
| CN112073184B (zh) * | 2017-10-23 | 2022-01-14 | 华为技术有限公司 | 一种生成密钥的方法、装置及系统 |
| US10667264B2 (en) * | 2018-04-18 | 2020-05-26 | Hughes Network Systems, Llc | Maintaining and distributing state due to temporary failures in a shared bandwidth network |
| US10868667B2 (en) * | 2018-11-06 | 2020-12-15 | GM Global Technology Operations LLC | Blockchain enhanced V2X communication system and method |
| CN112399476B (zh) * | 2019-08-15 | 2023-04-18 | 华为技术有限公司 | 一种数据包传输方法、终端设备及网络设备 |
| US11843943B2 (en) * | 2021-06-04 | 2023-12-12 | Winkk, Inc. | Dynamic key exchange for moving target |
-
2021
- 2021-09-30 CN CN202111166937.2A patent/CN115694599B/zh active Active
- 2021-09-30 CN CN202410946539.XA patent/CN118713729A/zh active Pending
-
2022
- 2022-07-29 EP EP22852086.2A patent/EP4369631A4/en active Pending
- 2022-07-29 WO PCT/CN2022/109226 patent/WO2023011373A1/zh not_active Ceased
- 2022-07-29 JP JP2024506446A patent/JP7751069B2/ja active Active
-
2024
- 2024-01-31 US US18/428,505 patent/US20240276210A1/en active Pending
-
2025
- 2025-09-25 JP JP2025159521A patent/JP2026016389A/ja active Pending
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN102594555A (zh) * | 2011-01-17 | 2012-07-18 | 华为技术有限公司 | 数据的安全保护方法、网络侧实体和通信终端 |
| US20150052360A1 (en) * | 2013-04-29 | 2015-02-19 | Hughes Network Systems, Llc | Method and system for providing enhanced data encryption protocols in a mobile satellite communications system |
| CN106304046A (zh) * | 2015-06-01 | 2017-01-04 | 陈晓华 | 对iBeacon广播消息加密、鉴权的方法 |
| US20180372878A1 (en) * | 2017-06-27 | 2018-12-27 | Here Global B.V. | Authentication of satellite navigation system receiver |
| CN112243235A (zh) * | 2020-09-15 | 2021-01-19 | 西安电子科技大学 | 适用于天地一体化的群组接入认证和切换认证方法及应用 |
Non-Patent Citations (1)
| Title |
|---|
| See also references of EP4369631A4 |
Also Published As
| Publication number | Publication date |
|---|---|
| JP2026016389A (ja) | 2026-02-03 |
| JP7751069B2 (ja) | 2025-10-07 |
| CN118713729A (zh) | 2024-09-27 |
| JP2024530458A (ja) | 2024-08-21 |
| EP4369631A4 (en) | 2024-10-23 |
| CN115694599B (zh) | 2024-06-18 |
| EP4369631A1 (en) | 2024-05-15 |
| CN115694599A (zh) | 2023-02-03 |
| US20240276210A1 (en) | 2024-08-15 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN111683367B (zh) | 安全通信模组、安全通信系统、方法及可读存储介质 | |
| JP2026016389A (ja) | 伝送方法、システム、および関連装置 | |
| US20060059265A1 (en) | Terminal connectivity system | |
| EP3703401A1 (en) | Apparatus and method for profile installation in communication system | |
| CN113098863B (zh) | 一种基于tls+mqtt协议的物联网双认证方法和系统 | |
| US20070249375A1 (en) | Method and system for phone-number discovery and phone-number authentication for mobile communications devices | |
| CN115378659B (zh) | 基于用户身份的高可靠文件加密和细粒度访问控制方法 | |
| CN111372056A (zh) | 一种视频数据加密、解密处理方法及装置 | |
| CN116830525A (zh) | 数据传输方法、装置、系统、电子设备及可读介质 | |
| CN120498743A (zh) | 一种基于铁路专用网络的铁路设备接入和数据安全传输方法及其系统 | |
| CN112436936B (zh) | 一种具备量子加密功能的云存储方法及系统 | |
| WO2020063170A1 (zh) | 数据处理方法、终端、服务器和存储介质 | |
| CN111770494A (zh) | 一种基于手机号的北斗rdss用户身份认证和火线注册方法及装置 | |
| CN109660568B (zh) | 基于srtp实现网络对讲安全机制的方法、设备及系统 | |
| CN114301967A (zh) | 窄带物联网控制方法、装置及设备 | |
| CN116781390B (zh) | 数据传输方法、装置、设备及存储介质 | |
| CN115701016B (zh) | 一种卫星通信系统中鉴权校验方法、系统及相关装置 | |
| CN117955944A (zh) | 使协同编辑系统与即时通信系统互通的方法及系统 | |
| WO2024139751A1 (zh) | 一种数据收发系统和方法 | |
| CN115857817A (zh) | Nas加密存储系统与方法 | |
| CN117640671A (zh) | 摩托车数据管理方法、系统及摩托车 | |
| CN220545151U (zh) | 一种物流数据加密装置、系统及传输装置 | |
| CN116528217B (zh) | 对eUICC进行远程管理的方法及相关设备 | |
| CN119996007B (zh) | 一种面向异构物联网的安全通信方法 | |
| CN219181539U (zh) | 一种量子安全工业互联网网关及平台 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 22852086 Country of ref document: EP Kind code of ref document: A1 |
|
| ENP | Entry into the national phase |
Ref document number: 2024506446 Country of ref document: JP Kind code of ref document: A |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2022852086 Country of ref document: EP |
|
| ENP | Entry into the national phase |
Ref document number: 2022852086 Country of ref document: EP Effective date: 20240207 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 202417014187 Country of ref document: IN |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 11202400733T Country of ref document: SG |

