Satellite Short Message Communication Method Integrating Authentication and Encryption

By integrating authentication and encryption in satellite short message communication, the short message message sent at one time includes authentication value and encrypted data, and the terminal performs authentication and decryption processing, solving the problems of complex authentication and encryption methods and waste of resources in the existing technology, and achieving efficient satellite short message communication.

CN115334508BActive Publication Date: 2025-06-17CHIPSET SECURITY WE THINGS (SHANGHAI)MICROELECTRONICS TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210971254.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-21
Publication Date
2025-06-17
Estimated Expiration
2042-06-21

AI Technical Summary

Technical Problem

In existing satellite short message communication, the authentication and encryption methods have problems such as the number of information interactions, poor key preset flexibility, low security, high interaction complexity, and large signaling overhead. Especially in satellite communication scenarios with limited resources, it leads to waste of communication bandwidth and increased latency.

Method used

A satellite short message communication method is proposed that integrates authentication and encryption. By including authentication value and encrypted data in a short message message sent at one time, the terminal performs authentication and decryption processing. If the authentication fails, the message packet will be discarded. The specific steps include configuring the ID and key for the user, hash calculation and encryption processing based on the input data, forming message data containing authentication values ​​and encrypted data, and authenticating and data transmission through the core network.

Benefits of technology

It realizes a simple message process, saves satellite communication bandwidth resources, reduces system interaction delay, and simplifies processing processes without additional deployment requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115334508B_ABST
    Figure CN115334508B_ABST
Patent Text Reader

Abstract

The present application relates to a satellite short message communication method integrating authentication and encryption. By respectively configuring an ID and a key K for the calling user and the called user, the ID and the key K are respectively stored in the core network and the SIM card; based on the data input by the calling user, the ID and the key K of the calling user, a hash calculation is performed to obtain a hash value for authentication; the data input by the calling user is encrypted to obtain encrypted data, and the encrypted data and the authentication value are combined to form the message data of the calling user, and the message data is sent to the core network; the core network performs an authentication judgment on the message data, and if the authentication value passes the authentication, the message data is sent to the called user. The short message sent once contains an authentication value and encrypted data, the message is concise, there is no need to establish a long connection, bandwidth resources are saved, and the system interaction delay is reduced; the process is simplified and there is no additional deployment requirement.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of satellite communication technologies, and in particular, to a satellite short message communication method, apparatus, and satellite short message communication control system that integrate authentication and encryption. Background Art

[0002] Internet of Things (IoT) is known as the third wave of the development of the information industry following the computer and the Internet. As an extension and expansion of cellular IoT, the core application scenarios of satellite IoT include communication in remote areas, ocean operations and scientific research broadband, aviation broadband, and disaster emergency communication. The interconnection and interoperability of satellite networks and cellular networks are the development pattern of the future integrated sky-earth big data industry and also the major trend of the development of future 6G, or even 7G networks.

[0003] In recent years, the cost of satellite launches and the entry threshold for satellite development have been continuously decreasing. A large number of start-up companies have been booming, aiming to develop low-earth orbit IoT small satellite constellations to provide low-cost, wide-coverage, low-latency, and large-connection IoT services for global users. Traditional mobile and fixed satellite operators represented by Inmarsat, IrIDium, and Eutelsat have also carried out layouts in this field through various means to seek new business growth points. Currently, more than 20 companies around the world have proposed constellation plans, and many emerging operators have launched multiple test satellites and service satellites, presenting a pattern of multiple parties advancing simultaneously. Although there are many satellite companies, different satellites have their own characteristics and are currently mainly divided into the following categories: navigation satellites, whose main function is to provide navigation, such as GPS in the United States, Glonass in Russia, and Galileo in Europe; communication satellites, whose main function is telephone and data services, such as Tian Tong-1 in China, Iridium in the United States, Starlink in the United States, and Inmarsat in the United Kingdom; navigation plus short message satellites, whose main function is navigation and can also provide short message services, such as Beidou satellites in China; and pure short message satellites, whose main function is to provide pure short message services for IoT, such as Tianqi satellites in China.

[0004] Short message communication mainly targets IoT services, and its communication security is particularly important. Therefore, both parties to the communication must have relevant authentication, and the communication content must also be encrypted. Currently, the more representative authentication and encryption modes are the cellular network authentication and encryption mode and the Internet authentication and encryption mode.

[0005] The typical authentication and encryption process in a cellular network is that both the mobile device and the core network pre - reserve a pair of user identifiers / keys and a series of encryption algorithms in advance. In a typical LTE cellular network authentication and encryption process, the mobile device and the core network negotiate to use the same encryption algorithm, then calculate the authentication value and the encryption value respectively. Finally, both sides verify the values calculated by the other side for authentication. After successful authentication, both sides use the symmetric keys they calculated for data encryption and decryption.

[0006] The Internet authentication communication mode usually uses the PKI / CA system. Both sides hold their own certificates (issued by the CA center). When authentication is required, the certificate is sent to the other side, and the public key of the CA center is used to parse the signature in the certificate for authentication.

[0007] Looking at the existing communication methods, the authentication and encryption methods between communication parties either have a large number of information interactions like the cellular communication mode, where the keys need to be pre - configured, with poor flexibility and low security; or are complex and require additional deployment of dependent systems like the Internet communication mode, with high interaction complexity, large signaling overhead, and the need for an additional certificate management system. Of course, for long - connection communication parties, this is understandable, but for short - message services, especially in scenarios where satellite communication resources are limited, multiple interactions or complex authentication methods not only greatly waste communication bandwidth but also increase communication latency. Therefore, for short - message satellite communication, a new and efficient authentication, encryption, and data - sending mechanism is needed. Summary of the Invention

[0008] To solve the above problems, this application proposes a satellite short - message communication method, device, and satellite short - message communication control system that integrate authentication and encryption, that is, the short - message message sent once contains an authentication value and encrypted data. After the other end (core network or satellite terminal) receives and parses the short - message, it first performs authentication. If the authentication fails, the message packet is directly discarded.

[0009] On the one hand, this application proposes a satellite short - message communication method that integrates authentication and encryption, including the following steps:

[0010] S100: Configure IDs and keys K for the calling user and the called user respectively, and save the IDs and keys K to the core network and the SIM card respectively;

[0011] S200: Based on the data input by the calling user, the ID of the calling user, and the key K, perform a hash calculation to obtain a hash value for authentication;

[0012] S300: Encrypt the data input by the calling user to obtain encrypted data, combine the encrypted data and the authentication value to form the message data of the calling user, and send it to the core network;

[0013] S400. Authenticate and judge the packet data through the core network. If the authentication value passes the authentication, send the packet data to the called user.

[0014] As an optional implementation of this application, optionally, in step S100, configure IDs and keys K for the calling user and the called user respectively, and save the IDs and keys K to the core network and the SIM card respectively, including:

[0015] S101. Set the ID1 and key K1 of the calling user, and configure the ID1 and key K1 on the calling SIM card and save them to the core network;

[0016] S102. Set the ID2 and key K2 of the called user, and configure the ID2 and key K2 on the called SIM card and save them to the core network.

[0017] As an optional implementation of this application, optionally, in step S200, perform a hash calculation based on the data input by the calling user, the ID and key K of the calling user to obtain a hash value for authentication, including:

[0018] S201. Obtain the data Data input by the calling user;

[0019] S202. Through a preset first hash algorithm, perform a hash calculation on the data Data input by the calling user, the ID1 and key K1 of the calling user to obtain a first hash value:

[0020] HASH(ID1||K1||Data1) = AUTH1,

[0021] where || is a concatenation operation, and AUTH1 is the first authentication value;

[0022] S203. Perform preprocessing on the first hash value.

[0023] As an optional implementation of this application, optionally, in step S300, encrypt the data input by the calling user to obtain encrypted data, combine the encrypted data and the authentication value to form the packet data of the calling user, and send it to the core network, including:

[0024] S301. Through a preset first encryption algorithm, use the key K1 of the calling user to encrypt the data Data input by the calling user to obtain encrypted data K1(data);

[0025] S302. Construct the message data of the calling user according to the AUTH1, K1(data), and the ID1 of the calling user through a preset short message format: ID1+AUTH1+K1(data);

[0026] S303. Send the message data of the calling user to the calling satellite.

[0027] As an optional implementation of this application, optionally, in step S400, the core network performs an authentication judgment on the message data. If the authentication value passes the authentication, the message data is sent to the called user, including:

[0028] S401. The core network receives the message data;

[0029] S402. Parse the message data through a preset parsing algorithm to obtain the ID1 of the calling user;

[0030] S403. Check the legitimacy of the ID1 of the calling user according to the legitimacy check rule.

[0031] As an optional implementation of this application, optionally, in step S400, the core network performs an authentication judgment on the message data. If the authentication value passes the authentication, the message data is sent to the called user, and further includes:

[0032] S410. According to the ID1 of the calling user that passes the check, query and obtain the corresponding key K1 from the core network;

[0033] S420. Parse out the data Data from the message data according to the key K1;

[0034] S430. The core network performs a hash calculation on the data Data, ID1, and key K1 through a preset second hash algorithm to obtain a first authentication value;

[0035] S440. Compare the first authentication value with the first hash value to judge whether the first authentication value is consistent with the first hash value: if they are consistent, the authentication passes; otherwise, the authentication fails and the data is discarded.

[0036] As an optional implementation of this application, optionally, in step S400, the core network performs an authentication judgment on the message data. If the authentication value passes the authentication, the message data is sent to the called user, and further includes:

[0037] S411. The core network encrypts the data Data using the key K2 of the called user through a preset second encryption algorithm to obtain encrypted data K2(data); and performs a hash calculation on the ID2 of the called user, the key K2, and the data Data through a preset hash algorithm to obtain a second hash value AUTN2

[0038] S421. According to the AUTN2, K2(data), and the ID2 of the called user, construct the called data to be sent to the called user through a preset short message format: ID2 + AUTN2 + K2(data);

[0039] S431. Send the called data of the called user to the called satellite.

[0040] As an optional implementation of the present application, optionally, in step S400, the core network performs an authentication judgment on the message data. If the authentication value passes the authentication, the message data is sent to the called user, and further includes:

[0041] S412. Receive the called data sent in step S431 through the called terminal;

[0042] S422. Calculate the authentication value on the called side according to the called data based on the authentication methods in steps S401 - S403 and steps S410 - S440, and perform authentication;

[0043] S432. Analyze the called data to obtain Data.

[0044] On the other hand, the present application provides an apparatus for implementing the satellite short message communication method for integrated authentication and encryption according to any one of claims 1 - 8, including:

[0045] ID and key K configuration module, configured to configure ID and key K for the calling user and the called user respectively, and save the ID and key K to the core network and the SIM card respectively;

[0046] Hash calculation module, configured to perform a hash calculation based on the data input by the calling user, the ID and key K of the calling user to obtain a hash value for authentication;

[0047] Encryption module, configured to encrypt the data input by the calling user to obtain encrypted data, combine the encrypted data and the authentication value to form the message data of the calling user, and send it to the core network;

[0048] Authentication module, configured to perform an authentication judgment on the message data through the core network. If the authentication value passes the authentication, the message data is sent to the called user.

[0049] On the other hand, the present application also provides a satellite short message communication control system, including:

[0050] A processor;

[0051] A memory for storing executable instructions of the processor;

[0052] Wherein, when the processor is configured to execute the executable instructions, it implements the satellite short message communication method for fusion authentication and encryption described in any one of claims 1 to 8.

[0053] Technical effects of the present invention:

[0054] In the present application, an ID and a key K are respectively configured for the calling user and the called user, and the ID and the key K are respectively stored in the core network and the SIM card; based on the data input by the calling user, the ID and the key K of the calling user, a hash calculation is performed to obtain a hash value for authentication; the data input by the calling user is encrypted to obtain encrypted data, and the encrypted data and the authentication value are combined to form the message data of the calling user, and the message data is sent to the core network; the core network performs an authentication judgment on the message data, and if the authentication value passes the authentication, the message data is sent to the called user. It is realized that the short message contains an authentication value and encrypted data in one transmission. After the receiving end (core network or satellite terminal) receives and parses the received message, it first performs authentication. If the authentication fails, the message packet is directly discarded. The message flow is simple, saving bandwidth, without the need to establish a long connection. One data transmission contains authentication information and encrypted data, greatly saving the bandwidth resources of the satellite system and greatly reducing the system interaction delay; the processing flow is simplified and there are no additional deployment requirements.

[0055] According to the following detailed description of exemplary embodiments with reference to the accompanying drawings, other features and aspects of the present disclosure will become clear. BRIEF DESCRIPTION OF THE DRAWINGS

[0056] The drawings included in the specification and constituting a part of the specification, together with the specification, illustrate exemplary embodiments, features and aspects of the present disclosure and are used to explain the principles of the present disclosure.

[0057] Figure 1 It is shown as a schematic diagram of the implementation process of the satellite short message communication method for fusion authentication and encryption of the present invention;

[0058] Figure 2 It is shown as a timing diagram of the authentication data flow of the satellite short message of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0059] Various exemplary embodiments, features, and aspects of the present disclosure will be described in detail below with reference to the accompanying drawings. The same reference numerals in the drawings denote elements having the same or similar functions. Although various aspects of the embodiments are shown in the drawings, the drawings are not necessarily drawn to scale unless otherwise specified.

[0060] As used herein, the term "exemplary" means "serving as an example, embodiment, or illustration." Any embodiment described herein as "exemplary" is not necessarily to be construed as superior to or better than other embodiments.

[0061] In addition, for a better description of the present disclosure, numerous specific details are given in the following detailed description. Those skilled in the art should understand that the present disclosure can be implemented without some of these specific details. In some instances, methods, means, elements, and circuits well-known to those skilled in the art are not described in detail so as to highlight the gist of the present disclosure.

[0062] Embodiment 1

[0063] This application uses a SIM card (or eSIM) to store user-related information (such as ID, K, etc.), and uses a modified 4G / 5G core network as the satellite core network. For the transmission of communication data between users, the calling satellite and the called satellite are respectively used for long-distance transmission and reception. Among them, the satellite can use the Beidou system, which is not limited and elaborated in this embodiment.

[0064] In this embodiment, a short message mechanism and a coding method are designed, and the following authentication and encryption communication method for satellite short messages is proposed, that is, the short message message sent at one time contains an authentication value and encrypted data. After the receiving end (core network or satellite terminal) receives and parses the received message, it first performs authentication. If the authentication fails, the message packet is directly discarded (or the result can be returned to the sending end as needed).

[0065] In this embodiment, both the calling end and the called end select a communication user as the implementation object. Under permitted circumstances, multi-person communication can also be realized. For multi-person communication, only an eSIM communication card containing multiple user IDs is required for receiving / transmitting satellite communication short messages (equipped with communication facilities), which is not elaborated in this embodiment.

[0066] In this application, first, IDs and keys K are configured for the calling and called users to facilitate encoding and hash authentication according to the user's ID and key K when sending messages. Secondly, the calling user inputs the message data, performs encryption processing and hash calculation to obtain encrypted data Data containing the hash value, and sends it to the core network through the calling satellite. After the core network parses and calculates the hash value for authentication, if the authentication passes, the called satellite sends the encrypted data Data containing the calling user ID information to the called user to achieve the transmission of the message data.

[0067] As Figure 1 shown, on the one hand, this application proposes a satellite short message communication method that integrates authentication and encryption, including the following steps:

[0068] S100. Configure IDs and keys K for the calling user and the called user respectively, and save the IDs and keys K to the core network and the SIM card respectively;

[0069] S200. Perform a hash calculation based on the data input by the calling user, the ID of the calling user, and the key K to obtain a hash value for authentication;

[0070] S300. Encrypt the data input by the calling user to obtain encrypted data, combine the encrypted data and the authentication value to form the message data of the calling user, and send it to the core network;

[0071] S400. The core network performs an authentication judgment on the message data. If the authentication value passes the authentication, the message data is sent to the called user.

[0072] In the overall message communication design method, the following are adopted:

[0073] 1). Each of the terminal and the core network maintains a user ID (similar to IMSI) and the same key K;

[0074] 2). The terminal (including the calling terminal and the called terminal) and the core network adopt a unified symmetric encryption algorithm and hash algorithm. If domestic algorithms are used, it is recommended to use SM4 for the encryption algorithm and SM3 for the hash algorithm;

[0075] 3). Perform a hash calculation on the ID, Data, and key K, that is, HASH1(D||K||Data), where || is the concatenation operation, to obtain the first hash value AUTN1 as the reference comparison value for the authentication value during core network authentication. For example, 0000||1111 = 00001111. Considering that the hash result is too long and will waste bandwidth (SM3 is 256 bits), it is recommended to intercept the first 24 bits, that is, hash preprocessing.

[0076] 5). The payload of each sent Burst = ID + AUTN1 + K(data) encrypted data;

[0077] 6) When the core network receives data, it first parses the ID, checks the legality of the ID, and simultaneously queries the key K corresponding to the ID. Then it parses out the data Data, calculates HASH(D||K||Data), and finally compares the HASH value calculated at the core network (AUTN1 authentication) with the received HASH1 value. If they are the same, the authentication passes; otherwise, the authentication fails and the data is discarded. Similarly, when the core network sends data to the called terminal through the called satellite, authentication will also be performed.

[0078] As Figure 2 shown, the implementation steps of the above steps S100 - S400 will be specifically described below.

[0079] As an optional implementation scheme of the present application, optionally, in step S100, the ID and the key K are respectively configured for the calling user and the called user, and the ID and the key K are respectively saved to the core network and the SIM card, including:

[0080] S101. Set the ID1 and the key K1 of the calling user, and configure the ID1 and the key K1 on the calling SIM card and save them to the core network shown;

[0081] S102. Set the ID2 and the key K2 of the called user, and configure the ID2 and the key K2 on the called SIM card and save them to the core network shown.

[0082] The calling user, that is, the calling end, and the called user, that is, the called end, are both configured with their respective ID and key K, which are used as the sending identifier and encryption key of the message data. In this embodiment, the specific manner of the ID and the key K is not limited in this embodiment, as long as each ID can be recognized and used for encryption. As Figure 2 shown, the users at the calling end and the called end are both configured with the ID and the key K, and are saved at the core network, which is convenient for the identification authentication and legality identification of the ID and the key K. The core network provides services such as data transfer, parsing, authentication, and data assembly for the user's message, which is specifically determined according to the designed / selected core network.

[0083] The calling end needs to perform hash calculation and encryption processing on the message data input by the calling user to form message data that meets the short message format. Similarly, the core network also needs to perform hash calculation and message sending processing on the received and authenticated message data. In this embodiment, the terminal and the core network adopt a unified symmetric encryption algorithm and hash algorithm. If a domestic algorithm is used, the encryption algorithm uses SM4 and the hash algorithm uses SM3.

[0084] As an optional implementation scheme of the present application, optionally, in step S200, based on the data input by the calling user, the ID and the key K of the calling user, perform hash calculation to obtain a hash value for authentication, including:

[0085] S201. Obtain the data Data input by the calling user;

[0086] S202. Perform a hashing calculation on the data Data input by the calling user, the ID1 of the calling user, and the key K1 through a preset first hashing algorithm to obtain a first hash value:

[0087] HASH(ID1||K1||Data1) = AUTH1,

[0088] where || is a concatenation operation, and AUTH1 is the first hash value;

[0089] S203. Preprocess the first hash value.

[0090] At the calling terminal, perform a hashing calculation on the ID, Data, and key K of the calling user, that is, HASH(ID1||K1||Data1), where || is a concatenation operation, to obtain the first hash value AUTN1. For example, 0000||1111 = 00001111. Considering that the hash result is too long and will waste bandwidth (SM3 is 256 bits), it is recommended to intercept the first 24 bits; that is, preprocess the hash value. In this embodiment, the content of HASH can also make a selection and judgment of the hashing operation according to the input information and other calling information.

[0091] As an optional implementation solution of the present application, optionally, in step S300, encrypt the data input by the calling user to obtain encrypted data, and combine the encrypted data and the authentication value to form the message data of the calling user and send it to the core network, including:

[0092] S301. Encrypt the data Data input by the calling user by using the key K1 of the calling user through a preset first encryption algorithm to obtain encrypted data K1(data);

[0093] S302. Construct the message data of the calling user according to the AUTH1, K1(data), and the ID1 of the calling user through a preset short message format (specified by the short message protocol stack): ID1+AUTH1+K1(data);

[0094] S303. Send the message data of the calling user to the calling satellite.

[0095] After obtaining the first hash value and the encrypted data, form short message data including the ID1 of the calling user, such as the incoming call number, with AUTH1, K1(data), and the ID1 of the calling user. The calling terminal sends it out and remotely sends it to the core network through the calling satellite.

[0096] Here, although the method of hashing first and then encrypting is selected for user information processing, in other implementation scenarios, if the set environment permits, the method of encrypting first and then hashing can also be adopted, and it can be specifically selected according to the set communication method.

[0097] As an alternative implementation of this application, optionally, in step S400, the core network performs an authentication judgment on the packet data. If the authentication value passes the authentication, the packet data is sent to the called user, including:

[0098] S401. The core network receives the packet data;

[0099] S402. Parse the packet data through a preset parsing algorithm to obtain the ID1 of the calling user;

[0100] S403. Perform a legality check on the ID1 of the calling user according to the legality check rules.

[0101] After the core network receives the packet data sent by the calling satellite, it needs to parse and perform an authentication judgment to check whether the ID included in the packet data matches the pre-stored ID and K value. The core network can parse the packet data through a preset parsing algorithm or method to obtain the ID1 of the calling user, compare ID1 with the pre-stored ID1 of the calling user to judge whether the addresses are consistent, and perform a legality check. If the check is legal, then obtain the Data in the packet data.

[0102] As an alternative implementation of this application, optionally, in step S400, the core network performs an authentication judgment on the packet data. If the authentication value passes the authentication, the packet data is sent to the called user, and it further includes:

[0103] S410. According to the legal ID1 of the calling user, query and obtain the corresponding key K1 from the core network;

[0104] S420. Parse the data Data from the packet data according to the key K1;

[0105] S430. The core network performs a hashing calculation on the data Data, ID1, and key K1 through a preset second hashing algorithm to obtain a first authentication value;

[0106] S440. Compare the first authentication value with the first hash value to judge whether the first authentication value is consistent with the first hash value: if they are consistent, the authentication passes; otherwise, the authentication fails and the data is discarded.

[0107] After the address legal check, authentication is also required. According to the ID1 of the calling user that passes the check, the key K1 corresponding to the ID1 of the calling user is queried and obtained from the core network. According to the key K1, the data Data is parsed from the message data. The parsed data Data, ID1, and key K1 are hashed again to obtain the first authentication value. The first authentication value is compared with the first hash value to determine whether the first authentication value is the same as the first hash value: if they are the same, the authentication passes; otherwise, the authentication fails and the data is discarded. Through the hash calculation and comparison of the front and back message data, the protection of data encryption is achieved.

[0108] After the core network performs authentication and ID legality check on the message data, it is sent to the called terminal through the called satellite.

[0109] As an optional implementation of the present application, optionally, in step S400, when the core network performs an authentication judgment on the message data, if the authentication value passes the authentication, the message data is sent to the called user, and it further includes:

[0110] S411. The core network encrypts the data Data using the key K2 of the called user through a preset second encryption algorithm to obtain the encrypted data K2(data); and performs a hash calculation on the ID2, key K2, and data Data of the called user through a preset hash algorithm to obtain the second hash value AUTN2;

[0111] S421. According to the AUTN2, K2(data), and the ID2 of the called user, a called data to be sent to the called user is constructed through a preset short message format: ID2 + AUTN2 + K2(data);

[0112] S431. The called data of the called user is sent to the called satellite.

[0113] The called terminal also needs to perform authentication processing. First, through the core network, based on a preset hash algorithm and symmetric encryption algorithm, the data Data is forwarded, that is, the data Data is encrypted using the key K2 of the called user to obtain the encrypted data K2(data); and a hash calculation is performed on the ID2, key K2, and data Data of the called user through a preset hash algorithm to obtain the second hash value AUTN2. This step is the same as that of the calling terminal, only the user ID and the key K are different, so it will not be elaborated here. After the processing, a called data to be sent to the called user is constructed through a preset short message format: ID2 + AUTN2 + K2(data), that is, Figure 2 the prepared called data in

[0114] Called data: ID2 + AUTN2 + K2(data) is sent to the called terminal via the called satellite selected by the core network.

[0115] As an alternative implementation of the present application, optionally, in step S400, the core network performs authentication judgment on the message data. If the authentication value passes the authentication, the message data is sent to the called user, and further includes:

[0116] S412. Receive the called data sent in step S431 through the called terminal;

[0117] S422. Calculate the authentication value on the called side based on the called data and the authentication methods in steps S401 - S403 and steps S410 - S440, and perform authentication;

[0118] S432. Analyze the called data to obtain Data.

[0119] The called terminal receives the called data, and also calculates the authentication value on the called side and performs authentication according to the authentication methods in steps S401 - S403 and steps S410 - S440. If the authentication is successful, the called data is analyzed to obtain the data Data sent by the calling user. The configured hash algorithm can be the same as that of the above - mentioned calling side.

[0120] It should be noted that although the message communication method between the above - mentioned two users is introduced as an example, those skilled in the art can understand that the present disclosure should not be limited thereto. In fact, users can flexibly set user identifiers such as eSIM and message protocols according to actual application scenarios, as long as the technical functions of the present application can be realized according to the above - mentioned technical methods.

[0121] Adopting the above - mentioned technology, there is no need to establish a long - connection. One - time data sending includes authentication information and encrypted data, which greatly saves the satellite system bandwidth resources and greatly reduces the system interaction delay. The processing flow is simplified, and there is no additional deployment requirement (such as no need to deploy PKI / CA).

[0122] Embodiment 2

[0123] Based on the implementation principle of Embodiment 1, on the other hand, the present application provides a device for implementing the satellite short - message communication method for integrated authentication and encryption described in Embodiment 1, including:

[0124] ID and key K configuration module, used to configure ID and key K for the calling user and the called user respectively, and save ID and key K to the core network and the SIM card respectively;

[0125] A hash calculation module, configured to perform hash calculation based on the data input by the calling user, the ID of the calling user, and the key K to obtain a hash value for authentication;

[0126] An encryption module, configured to perform encryption processing on the data input by the calling user to obtain encrypted data, combine the encrypted data and the authentication value to form the message data of the calling user, and send the message data to the core network;

[0127] An authentication module, configured to perform authentication judgment on the message data through the core network, and if the authentication value passes the authentication, send the message data to the called user.

[0128] For the functional principles of the above-mentioned respective modules, please refer to Embodiment 1 specifically, and details are not described herein again.

[0129] Obviously, those skilled in the art should understand that to implement all or part of the processes in the above-mentioned embodiment methods, it can be completed by instructing relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the above-mentioned embodiments of each control method. The above-mentioned modules or steps of the present invention can be implemented by a general-purpose computing device. They can be concentrated on a single computing device or distributed on a network composed of multiple computing devices. Optionally, they can be implemented by program codes executable by the computing device. Thus, they can be stored in a storage device and executed by the computing device, or they can be separately fabricated into individual integrated circuit modules, or multiple modules or steps among them can be fabricated into a single integrated circuit module to implement. In this way, the present invention is not limited to any specific combination of hardware and software.

[0130] Those skilled in the art can understand that to implement all or part of the processes in the above-mentioned embodiment methods, it can be completed by instructing relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the above-mentioned embodiments of each control method. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM), a random access memory (RAM), a flash memory, a hard disk drive (HDD), or a solid-state drive (SSD), etc.; the storage medium can also include a combination of the above-mentioned types of memories.

[0131] Embodiment 3

[0132] Furthermore, on the other hand, the present application also provides a satellite short message communication control system, including:

[0133] a processor;

[0134] a memory for storing processor-executable instructions;

[0135] wherein, when the processor is configured to execute the executable instructions, it implements the satellite short message communication method for integrated authentication and encryption described in Embodiment 1.

[0136] The satellite short message communication control system according to an embodiment of the present disclosure includes a processor and a memory for storing processor-executable instructions. Among them, when the processor is configured to execute the executable instructions, it implements a satellite short message communication method for integrated authentication and encryption described in any one of the foregoing.

[0137] Here, it should be noted that the number of processors can be one or more. At the same time, in the satellite short message communication control system according to the embodiment of the present disclosure, an input device and an output device may also be included. Among them, the processor, the memory, the input device and the output device can be connected through a bus or in other ways, which is not specifically limited here.

[0138] The memory, as a computer-readable storage medium, can be used to store software programs, computer-executable programs and various modules, such as: the programs or modules corresponding to a satellite short message communication method for integrated authentication and encryption according to an embodiment of the present disclosure. The processor executes various functional applications and data processing of the traceability system by running the software programs or modules stored in the memory.

[0139] The input device can be used to receive input numbers or signals. Among them, the signal can be a key signal related to the user settings and function control of the device / terminal / server. The output device can include a display device such as a display screen.

[0140] The various embodiments of the present disclosure have been described above. The above description is exemplary, not exhaustive, and is not limited to the disclosed embodiments. Many modifications and variations are obvious to those of ordinary skill in the art in the technical field without departing from the scope and spirit of the described embodiments. The choice of terms used herein is intended to best explain the principles of the embodiments, practical applications, or improvements to the technology in the market, or to enable other ordinary skill in the art in the technical field to understand the disclosed embodiments.

Claims

1. A satellite short message communication method integrating authentication and encryption, characterized in that, It includes the following steps: S100. Configure IDs and keys K for the calling user and the called user respectively, and save the IDs and keys K to the core network and the SIM card respectively, including: S101. Set the ID1 and key K1 of the calling user, and configure the ID1 and key K1 on the calling SIM card and save them to the core network shown; S102. Set the ID2 and key K2 of the called user, and configure the ID2 and key K2 on the called SIM card and save them to the core network shown. S200. Based on the data input by the calling user, the ID and key K of the calling user, perform a hash calculation to obtain a hash value for authentication, including: S201. Obtain the data Data input by the calling user; S202. Through a preset first hash algorithm, perform a hash calculation on the data Data input by the calling user, the ID1 and key K1 of the calling user, to obtain a first hash value: HASH(ID1||K1||Data1)=AUTH1, where || is a concatenation operation and AUTH1 is the first hash value; S203. Perform preprocessing on the first hash value. S300. Encrypt the data input by the calling user to obtain encrypted data, combine the encrypted data and the authentication value to form the message data of the calling user, and send it to the core network, including: S301. Through a preset first encryption algorithm, use the key K1 of the calling user to encrypt the data Data input by the calling user to obtain encrypted data K1(data); S302. According to the AUTH1, K1(data) and the ID1 of the calling user, construct the message data of the calling user through a preset short message format: ID1+AUTH1+K1(data); S303. Send the message data of the calling user to the calling satellite. S400. The core network performs an authentication judgment on the message data. If the authentication value passes the authentication, the message data is sent to the called user, including: S401. The core network receives the message data; S402. Parse the message data through a preset parsing algorithm to obtain the ID1 of the calling user; S403. According to the legality check rule, perform a legality check on the ID1 of the calling user; It also includes: S410. According to the ID1 of the calling user that passes the check, query and obtain the key K1 corresponding to the ID1 of the calling user from the core network; S420. According to the key K1, parse the data Data from the message data; S430. The core network performs a hash calculation on the data Data, ID1 and key K1 through a preset second hash algorithm to obtain a first authentication value; S440. Compare the first authentication value with the first hash value to judge whether the first authentication value is consistent with the first hash value: If they are consistent, the authentication passes; otherwise, the authentication fails and the data is discarded.

2. The satellite short message communication method integrating authentication and encryption according to claim 1, characterized in that, In step S400, the core network performs authentication judgment on the packet data. If the authentication value passes the authentication, the packet data is sent to the called user, and it further includes: S411. The core network uses a preset second encryption algorithm to encrypt the data Data with the key K2 of the called user to obtain encrypted data K2(data); and performs a hash calculation on the ID2, key K2, and data Data of the called user through a preset hash algorithm to obtain a second hash value AUTN2. S421. According to the AUTN2, K2(data), and the ID2 of the called user, construct the called data to be sent to the called user through a preset short message format: ID2 + AUTN2 + K2(data); S431. Send the called data of the called user to the called satellite.

3. The satellite short message communication method integrating authentication and encryption according to claim 2, characterized in that, In step S400, the core network performs authentication judgment on the packet data. If the authentication value passes the authentication, the packet data is sent to the called user, and it further includes: S412. Receive the called data sent in step S431 through the called terminal; S422. Calculate the authentication value on the called side based on the authentication methods of steps S401 - S403 and steps S410 - S440 according to the called data, and perform authentication; S432. Analyze the called data to obtain Data.

4. An apparatus for implementing the satellite short message communication method integrating authentication and encryption according to any one of claims 1-3, characterized in that, It includes: An ID and key K configuration module for configuring an ID and a key K for the calling user and the called user respectively, and saving the ID and the key K to the core network and the SIM card respectively; A hash calculation module for performing a hash calculation based on the data input by the calling user, the ID and key K of the calling user to obtain a hash value for authentication; An encryption module for encrypting the data input by the calling user to obtain encrypted data, combining the encrypted data and the authentication value to form the packet data of the calling user, and sending it to the core network; An authentication module for performing authentication judgment on the packet data through the core network. If the authentication value passes the authentication, the packet data is sent to the called user.

5. A satellite short message communication control system, characterized in that, It includes: A processor; A memory for storing instructions executable by the processor; Wherein, when the processor is configured to execute the executable instructions, it implements the integrated authentication and encryption satellite short message communication method according to any one of claims 1 to 3.

Citation Information

Patent Citations

  • Communication authentication processing method and device

    CN114599033A