A terminal access authentication method and system for realizing satellite-ground pre-authentication
By performing pre-authentication and same-domain authentication mechanisms for terminals and satellites in the satellite-ground fusion NTN network, the problem of paralysis of the entire network caused by DDOS storm attacks is solved, network security and authentication efficiency are improved, and the scope of the attack is limited.
Patent Information
- Application Number
- CN202211462918.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-22
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2042-11-22
AI Technical Summary
In the NTN network that is integrated with satellites, attackers can implement large-scale DDOS storm attacks from user links, resulting in the entire network being paralyzed, and the existing technology has no effective solution.
Identity pre-authentication is performed between the terminal and the satellite, and the same-orbit satellite is defined as the same domain. Communication tokens are obtained through satellite-ground pre-authentication, and the authentication results are shared in this domain. When the terminal initiates the primary authentication, it carries the token to make a legal judgment, which limits the attack to affect the access satellite.
Effectively prevent the security risks of DDOS storm attacks on subsequent routing node satellites, information security stations and ground core networks, and realize the security improvement of the satellite-ground NTN network, and improve the authentication efficiency without changing the ground network main authentication process.
Smart Images

Figure CN116232595B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of mobile communication security, and specifically to a terminal access authentication method and system for realizing satellite-ground pre-authentication. Background Art
[0002] The integration of space-air-ground network is one of the core development directions for building a global public mobile communication network in the future. Since the concept of NTN (non-terrestrial network) was first proposed by 3GPP in the 5G standard R15, efforts have been made to achieve the integration of 5G network and satellite network / high-altitude platform system (HAPS). Currently, research reports such as 3GPP TR38.811 and 3GPP TR 38.821 have been formed, and two networking modes, namely satellite-based transparent payload forwarding and regenerative payload forwarding, have been proposed in the NR solution supporting NTN. In the 6G plan, it is further proposed that the space-air-ground integrated network architecture will be based on the terrestrial cellular mobile network, combined with the characteristics of wide coverage and flexible deployment of satellite communication, and achieve ubiquitous coverage of the entire domain and all-weather in the three-dimensional space through deep integration of multiple heterogeneous networks, providing the ability of ubiquitous and on-demand access.
[0003] Although the global coverage ability of the satellite-ground integrated network improves the convenience of terminal access and the flexibility of networking, it also brings new problems in terms of security. For example, in the evolution of the access network architecture for the integration of 5G and satellite network, the deep integration mode is to deploy the gNB completely on the satellite to become the S-gNB and use the regenerative payload mode for networking. Deploying the gNB on the satellite improves the coverage ability of a single base station, but introduces new risks: attackers can take advantage of a vulnerability in 3GPP TS 33.501 (the user information in the <N1 messege> packet initiated for the first time when the UE starts authentication is SUCI, and the base station cannot verify the user's legitimacy and can only transparently forward it to the core network), and launch a DDOS storm attack on the 5G access network and the core network from the user link. This vulnerability has always existed in the current 5G network. However, since the current 5G networks are all deployed on the ground and their coverage areas are within the territory of our country, it is extremely difficult for attackers to launch a large-scale DDOS attack through the NR uu interface of the access network. For the globally covered satellite-ground deep integration NTN network, attackers can organize and forge a super-large number of terminals anywhere in the world at any time to launch a DDOS attack on the system through the user link, which may seriously lead to the paralysis of the entire network operation. The network elements / functional entities involved in the attack include the access satellite S-gNB, routing node satellite, gateway station, and AMF, AUSF, UDM, SIDF functional entities in the 5G core network, etc.
[0004] Regarding the problem of how to solve the DDOS storm attack on the access network and the core network from the user link in the space-ground integrated NTN network, there is no relevant research and solution at present, and further research and improvement are needed. Summary of the Invention
[0005] To overcome the deficiencies of the prior art, the present invention provides a terminal access authentication method and system for implementing space-ground pre-authentication, which solves the problem that the space-ground integrated NTN network is facing the DDOS storm attack on the network from the user link, resulting in the paralysis of the entire network, and limits the attack to the access satellite, eliminating the attack hidden danger to the subsequent routing node satellites, gateway stations and the ground core network.
[0006] The technical solution adopted by the present invention to solve the above problems is:
[0007] A terminal access authentication method for implementing space-ground pre-authentication. Before the terminal initiates the main authentication, first perform identity pre-authentication between the terminal and the satellite. The result of the pre-authentication is the basis for the satellite to authenticate whether the main authentication application received by the user link is legal. And, define the co-orbiting satellites as the same-domain satellites. The terminal completes the space-ground pre-authentication with any satellite in the domain, and all satellites in the domain recognize the legitimacy of the terminal to initiate the main authentication.
[0008] As a preferred technical solution, it includes the following steps:
[0009] S1, Divide the whole network of satellites into domains: Divide the whole network of satellites according to the orbital plane, and divide the co-orbiting satellites into the same domain. The domain fields in the satellite security virtual identifier SSVID of the same-domain satellites are the same, and the satellite broadcasts its own SSVID after being enabled.
[0010] S2, Mutual authentication between adjacent satellites in the same domain: Complete two-way mutual authentication between adjacent satellites in the same domain, and establish an inter-satellite secure transmission link within the domain. If the establishment is successful, enter step S3; if the establishment fails, re-execute step S2 until the establishment is successful.
[0011] S3, The satellite determines the type of authentication application: After the satellite receives the authentication application, it determines the authentication type based on the type word carried in the authentication application. If the authentication type is space-ground pre-authentication, enter step S5; if the authentication type is main authentication, enter step S8.
[0012] S4, The terminal prepares to access the network: The terminal prepares to initiate access authentication. After receiving the SSVID of the satellite to be accessed, it determines whether it needs to initiate space-ground pre-authentication. If it needs to, enter step S5; if not, enter step S7.
[0013] S5, Satellite-ground pre-authentication: The terminal initiates a satellite-ground pre-authentication application and conducts satellite-ground pre-authentication with the access satellite. If the authentication is successful, the terminal obtains and saves the communication token, and then proceeds to step S6. If the authentication fails, the satellite returns to step S3 and the terminal returns to step S4 until the pre-authentication is successful.
[0014] S6, Sharing pre-authentication results within the satellite domain: After encrypting the terminal pre-authentication results using the session key negotiated by satellite interconnection authentication, the access satellite pushes them via the inter-satellite link to all other satellites within the domain. Other satellites within the domain save the authentication results and return to step S3 to wait for receiving the terminal's authentication application and determine the type of authentication application.
[0015] S7, Terminal initiates the main authentication application: The terminal starts the main authentication process and initiates the main authentication application, carrying the communication token obtained after successful pre-authentication in the authentication application.
[0016] S8, Satellite determines the legality of the authentication application: After receiving the terminal's main authentication application, the access satellite determines whether the application is legal based on the communication token carried in the application. If it is legal, it proceeds to step S9. If it is not legal, it discards the authentication application and returns to step S3.
[0017] S9, Terminal main authentication: The access satellite transparently forwards the terminal main authentication application data to the ground core network, and subsequently completes the network access authentication of the terminal to the ground core network following the main authentication mechanism of the ground network. If the authentication fails, the terminal returns to step S7 to re-initiate the main authentication application until the network access authentication is successful, and at the same time the satellite returns to step S3 to wait for receiving the terminal's authentication application and determine the type of authentication application.
[0018] As a preferred technical solution, in step S2, assume that Satellite 1 and Satellite 2 are two adjacent satellites in the same domain. The two-way interconnection authentication between Satellite 1 and Satellite 2 includes the following steps:
[0019] S21, Satellite 1 determines whether it belongs to the same domain satellite according to the domain identifier in the satellite 2 identity identifier SSVID2. If so, it proceeds to step S22. If not, it proceeds to step S21.
[0020] S22, Satellite 1 determines whether it has completed interconnection authentication with Satellite 2 according to SSVID2. If so, it proceeds to step S21. If not, it proceeds to step S23.
[0021] S23, Satellite 1 generates the authentication vector V 12 , including the following steps:
[0022] S231, Generate a random number Rnd1;
[0023] S232, Obtain the timestamp TS1;
[0024] S233, the public key Pks2 of the satellite 2 derived based on the IBC algorithm and SSVID2;
[0025] S234, sign Rnd1||SSVID1 with the IBC algorithm and its own private key Sks1 to obtain IBC_S Sks1 (Rnd1||SSVID1); where || represents the data concatenation symbol, Rnd1||SSVID1 represents the data string obtained by concatenating the random number Rnd1 and the satellite 1 identity SSVID1, with Rnd1 placed on the left and SSVID1 placed on the right), IBC_S Sks1 (Rnd1||SSVID1) represents the signature data obtained by signing Rnd1||SSVID1 with the IBC algorithm and the private key Sks1;
[0026] S235, encrypt IBC_S Sks1 (Rnd1||SSVID1)||Rnd1||TS1 with the IBC algorithm and the public key Pks2 of the satellite 2 to obtain the authentication vector V 12 , denote V 12 =IBC_E Pks2 (IBC_S Sks1 (Rnd1||SSVID1)||Rnd1||TS1);
[0027] IBC_E Pks2 (IBC_S Sks1 (Rnd1||SSVID1)||Rnd1||TS1) represents the ciphertext authentication data obtained by encrypting the plaintext authentication data IBC_S Sks1 (Rnd1||SSVID1)||Rnd1||TS1 with the IBC algorithm and the public key Pks2 of the satellite 2;
[0028] S24, the satellite 1 sends the authentication vector V 12 to the satellite 2;
[0029] S25, the satellite 2 verifies the authentication vector V 12 , including the following steps:
[0030] S251, decrypt the authentication vector V 12 with the IBC algorithm and its own private key Sks2 to obtain IBC_S Sks1 (Rnd1||SSVID1), Rnd1 and TS1; if the decryption is successful, verify the message freshness; if the decryption fails, terminate the authentication process;
[0031] S252, verify the message freshness based on TS1; if the verification passes, verify the signature of the message; if the verification fails, terminate the authentication process;
[0032] S253. The satellite 2 derives the public key Pks1 of the satellite 1 based on the IBC algorithm and SSVID1, and then verifies the signature of IBC_S Sks1 (Rnd1||SSVID1); if it passes, go to step S26; if it fails, terminate the authentication process;
[0033] S26. The satellite 2 obtains the session key: generates a random number Rnd2, and obtains the session key SeK by performing a bitwise exclusive OR operation on Rnd1 and Rnd2;
[0034] S27. The satellite 2 generates an authentication vector V 21 , including the following steps:
[0035] S271. Obtain the timestamp TS2;
[0036] S272. Sign Rnd2||SSVID2 through the IBC algorithm and its own private key Sks2 to obtain the signature data IBC_S Sks2 (Rnd2||SSVID2);
[0037] S273. Encrypt the authentication data IBC_S Sks2 (Rnd2||SSVID2)||Rnd2||TS2 based on the IBC algorithm and the public key Pks1 of the satellite 1 to obtain the authentication vector V 21 , denote V 21 =IBC_E Pks1 (IBC_S Sks2 (Rnd2||SSVID2)||Rnd2||TS2);
[0038] where, IBC_E Pks1 (IBC_S Sks2 (Rnd2||SSVID2)||Rnd2||TS2) represents the encrypted authentication data obtained by encrypting the plaintext authentication data IBC_S Sks2 (Rnd2||SSVID2)||Rnd2||TS2 with the IBC algorithm and the public key Pks1 of the satellite 1;
[0039] S28. The satellite 2 sends the authentication vector V 21 to the satellite 1;
[0040] S29. The satellite 1 verifies the authentication vector V 21 , and obtains the session key, including the following steps:
[0041] S291. Decrypt the authentication vector V 21 using the IBC algorithm and its own private key Sks1 to obtain IBC_S Sks2(Rnd2||SSVID2), Rnd2, and TS2; if decryption is successful, verify the message freshness; if decryption fails, terminate the authentication process and return to step S21;
[0042] S292, verify the message freshness based on TS2; if the verification is successful, verify the signature of the message; if the verification fails, terminate the authentication process and return to step S21;
[0043] S293, use Pks2 to verify the signature of IBC_S Sks2 (Rnd2||SSVID2); if the signature verification is successful, go to step S210; if the signature verification fails, terminate the authentication process and return to step S21;
[0044] S210, Satellite 1 obtains the session key: perform a bitwise exclusive OR operation on Rnd1 and Rnd2 to obtain the session key SeK.
[0045] As a preferred technical solution, in step S4, the terminal determines whether satellite-ground pre-authentication is required, including the following steps:
[0046] S41, the terminal queries the tokens stored locally to check if there is a token for the domain of the satellite to be accessed; if there is, go to step S42; if not, go to step S5;
[0047] S42, the terminal checks if the token has expired; if it has, delete the token and go to step S5; if not, go to step S7.
[0048] As a preferred technical solution, in step S5, the steps of satellite-ground pre-authentication include the following steps:
[0049] S51, the terminal prepares the authentication vector V u1 , including the following steps:
[0050] S511, derive the public key Pks1 of Satellite 1 based on the IBC algorithm and SSVID1;
[0051] S512, obtain the timestamp TS3;
[0052] S513, sign its own terminal security virtual identifier TSVID u based on the IBC algorithm and its own private key Sk u to obtain the signature data IBC_S SKu (TSVID u );
[0053] S514, encrypt the authentication data TSVID u ||IBC_S SKu (TSVID u) || After TS3, the authentication vector V is obtained u1 : IBC_E Pks1 (TSVID u || IBC_S SKu (TSVID u ) || TS3);
[0054] S52, the terminal sends a satellite - ground pre - authentication application and sends the authentication vector V u1 to satellite 1;
[0055] S53, satellite 1 verifies the authentication vector V u1 , including the following steps:
[0056] S531, use the IBC algorithm and its own private key Sks1 to decrypt the authentication vector V u1 to obtain TSVID u , IBC_S SKu (TSVID u ) and TS3; if the decryption is successful, then verify the message freshness; if the decryption fails, then terminate the authentication process and return to step S3;
[0057] S532, verify the message freshness based on TS3; if the verification is successful, then verify the signature of the message; if the verification fails, then terminate the authentication process and return to step S3;
[0058] S533, derive the public key Pk of the terminal based on the IBC algorithm and TSVID u and verify the signature of IBC_S u (TSVID SKu ); if it passes, then enter step S54; if it fails, then terminate the authentication process and return to step S3; u
[0059] S54, satellite 1 prepares the authentication vector V 1u , including the following steps:
[0060] S541, obtain the time stamp TS4;
[0061] S542, generate the communication token TokenU corresponding to the terminal and sign it with the IBC algorithm and its own private key Sks1 to obtain IBC_S Sks1 (TokenU); where, IBC_S Sks1 (TokenU) represents the signature data obtained by signing the communication token TokenU with the IBC algorithm and the private key Sks1;
[0062] S543, encrypt TokenU || IBC_S u based on the IBC algorithm and the public key Pk of the terminal Sks1(TokenU) || TS4, obtain the authentication vector V 1u : IBC_E Pku (TokenU || IBC_S Sks1 (TokenU) || TS4);
[0063] S544, save the TSVID of this terminal u and the corresponding token TokenU;
[0064] S55, satellite 1 sends the authentication vector V 1u to the terminal;
[0065] S56, the terminal verifies the authentication vector V 1u , including the following steps:
[0066] S561, adopt the IBC algorithm and its own private key Sk u to decrypt the authentication vector V 1u to obtain the communication token TokenU, IBC_S Sks1 (TokenU) and TS4; if the decryption is successful, verify the message freshness; if the decryption fails, terminate the authentication process and return to step S51;
[0067] S562, verify the message freshness based on TS3; if the verification is successful, verify the signature of the message; if the verification fails, terminate the authentication process and return to step S51;
[0068] S563, verify the signature of IBC_S Sks1 (TokenU) based on the IBC algorithm and Pks1; if the signature verification passes, save the communication token TokenU and the authentication is completed; if the signature verification fails, terminate the authentication process and return to step S51.
[0069] As a preferred technical solution, in step S6, the process of accessing the shared pre-authentication result within the domain of the satellite includes the following steps:
[0070] S61, satellite 1 combines the TSVID of the pre-authenticated terminal u and the corresponding TokenU to form the shared data TSVID u ||TokenU, and uses the symmetric encryption algorithm and SeK to encrypt it to obtain the shared data ciphertext: E SeK (TSVID u ||TokenU);
[0071] S62, satellite 1 sends E SeK (TSVID u ||TokenU) to the adjacent satellite 2 in the same domain through the inter-satellite link;
[0072] S63, Satellite 2 decrypts E SeK (TSVID u ||TokenU) to obtain TSVID u and the corresponding TokenU and store them.
[0073] As a preferred technical solution, in step S7, the terminal starts the main authentication standard process, including the following steps:
[0074] S71, the terminal queries whether TokenU has expired; if not, it proceeds to step S72; otherwise, it returns to step S5;
[0075] S72, the terminal obtains the timestamp TS5;
[0076] S73, the terminal encrypts TokenU||TS5 based on the IBC algorithm and the public key Pks1 of Satellite 1 to obtain IBC_E Pks1 (TokenU||TS5); where IBC_E Pks1 (TokenU||TS5) represents the legitimate access order for the main authentication application;
[0077] S74, the terminal adds IBC_E Pks1 (TokenU||TS5) to the main authentication application data frame and sends it to Satellite 1.
[0078] As a preferred technical solution, in step S8, the satellite determines whether the main authentication application sent by the terminal is legal, including the following steps:
[0079] S81, Satellite 1 queries whether there is a corresponding communication token stored locally based on the TSVID of the terminal u ; if so, it directly proceeds to step S82, otherwise, it requests the communication token of this terminal from the adjacent satellites within the domain, and then proceeds to step S82;
[0080] S82, decrypt the legitimate access order IBC_E Pks1 (TokenU||TS5) of the terminal's main authentication application based on the IBC algorithm and its own private key Sks1 to obtain TokenU and TS5;
[0081] S83, Satellite 1 verifies the message freshness based on TS5; if the verification passes, it proceeds to step S84; if the verification fails, it discards the main authentication application data and terminates the authentication process, returning to step S3;
[0082] S84, Satellite 1 compares whether this TokenU is consistent with the communication token stored locally; if the comparison passes, it proceeds to step S9; if the comparison fails, it discards the main authentication application data and terminates the authentication process, returning to step S3.
[0083] As a preferred technical solution, in steps S5 to S8, the composition of TokenU includes but is not limited to the following information: token header, terminal SSVID, access satellite SSVID, token data, expiration time.
[0084] A terminal network access authentication system for implementing satellite-ground pre-authentication is used to implement the described terminal network access authentication method for implementing satellite-ground pre-authentication, including a terminal, a satellite, a gateway station, and a ground core network that are sequentially communicatively connected;
[0085] Among them, the terminal includes a terminal security module and a terminal host. The terminal security module is used for the process handling of satellite-ground pre-authentication and main authentication, authentication algorithm operation, and storage and access of authentication data and results; the terminal host is used for implementing human-computer interaction processing and communication data transceiver processing functions with the satellite; the terminal includes but is not limited to satellite terminals, 5G / 6G mobile phones, ground gateways with satellite access capabilities, and mobile gateway stations;
[0086] The satellite includes an on-board integrated security payload, an on-board base station, an on-board service computer, and a communication payload; the on-board integrated security payload is used for implementing inter-satellite interconnection authentication in the same domain, satellite-ground pre-authentication, sharing of pre-authentication results within the domain, determination of the legality of authentication applications, authentication algorithm operation, and storage and access of authentication data and results; the on-board base station is used for invoking the on-board integrated security payload and processing the main authentication process; the on-board service computer is used for implementing satellite operation management and scheduling and control functions of on-board payloads; the communication payload is used for communication processing of inter-satellite links, user links, and feeder links;
[0087] The gateway station is used for forwarding and processing satellite-ground communication data;
[0088] The ground core network is used for processing the main authentication process of the terminal, authentication algorithm operation, and storage and access of authentication data and results.
[0089] Compared with the prior art, the present invention has the following beneficial effects:
[0090] (1) The present invention realizes the purpose of neither changing the main authentication process and authentication frame structure of the ground network nor effectively solving the problem that the NTN network of satellite-ground integration faces a DDOS storm attack on the network from the user link by an attacker, resulting in a complete network paralysis, and limits the scope of influence caused by the attack to the access satellite, eliminating the security risks brought by the attack to subsequent routing node satellites, gateway stations, and ground core networks;
[0091] (2) The present invention designs a mechanism and process for identity pre-authentication between the terminal and the satellite based on the IBC cryptosystem, and the result of the pre-authentication provides an effective basis for the satellite to identify whether the main authentication application received on the user link is legal;
[0092] (3) The present invention designs a mechanism and process for inter-satellite interconnection authentication and key negotiation based on the IBC cryptographic system, providing a secure transmission channel for the sharing of important data between satellites;
[0093] (4) To reduce the consumption of on-board computing power resources for pre-authentication and effectively improve the authentication efficiency, the method defines co-orbital satellites as co-domain satellites. By actively pushing the terminal TokenU within the domain, it realizes the satellite-ground pre-authentication between the terminal and any satellite in the domain. All satellites in this domain recognize the legitimacy of the terminal initiating the main authentication, avoiding the situation where the terminal needs to authenticate with all satellites. BRIEF DESCRIPTION OF THE DRAWINGS
[0094] Figure 1 It is a schematic diagram of the steps of a terminal network access authentication method for realizing satellite-ground pre-authentication according to the present invention;
[0095] Figure 2 It is a flowchart of inter-satellite interconnection authentication of a terminal network access authentication method for realizing satellite-ground pre-authentication according to the present invention;
[0096] Figure 3 It is a flowchart of satellite-ground authentication of a terminal network access authentication method for realizing satellite-ground pre-authentication according to the present invention;
[0097] Figure 4 It is a schematic diagram of the topology of a terminal network access authentication system for realizing satellite-ground pre-authentication according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0098] The present invention will be further described in detail below in conjunction with the embodiments and the accompanying drawings, but the embodiments of the present invention are not limited thereto.
[0099] Embodiment 1
[0100] As Figures 1 to 4 shown, the present invention discloses a terminal network access authentication method for realizing satellite-ground pre-authentication, and the method includes:
[0101] When building a satellite network, on-orbit satellites are divided into domains according to the orbital plane. First, two-way interconnection authentication is completed between adjacent satellites in the same domain to establish an inter-satellite secure transmission link within the domain. The satellite regularly broadcasts its own SSVID (Satellite Secure Virtual Identifier), waiting for the terminal to initiate an access request. When the terminal needs to access the network and is about to initiate an authentication request, it first determines whether satellite-ground pre-authentication is required before initiating the main access authentication based on the SSVID of the satellite to be accessed. If required, satellite-ground pre-authentication is initiated. After receiving the authentication request, the satellite determines the authentication type based on the type field carried in the authentication request and enters the corresponding processing flow. After the terminal and the access satellite pass the satellite-ground pre-authentication, the terminal obtains and saves the communication token, and the access satellite pushes the terminal pre-authentication result to all other satellites in the domain through a secure inter-satellite link for saving. When the terminal initiates the main authentication, the communication token is carried in the main authentication request. The access satellite determines whether the request is legal based on the communication token. If it is not legal, the authentication request is discarded and the authentication is terminated. If it is legal, the terminal main authentication request data is transparently forwarded to the ground core network, and then the main authentication from the terminal to the ground core network is completed following the original authentication process of the ground network. After success, the terminal completes the access authentication.
[0102] The purpose of the present invention is to overcome the deficiencies of the prior art and provide a terminal access authentication method for implementing satellite-ground pre-authentication. This method designs a mechanism and process for identity pre-authentication between the terminal and the satellite based on the IBC cryptosystem. The result of the pre-authentication provides an effective basis for the satellite to identify whether the main authentication request received on the user link is legal. This method designs a mechanism and process for inter-satellite interconnection authentication and key negotiation based on the IBC cryptosystem, providing a secure transmission channel for important data sharing between satellites. To reduce the consumption of on-board computing power resources by pre-authentication and effectively improve the authentication efficiency, this method defines co-orbital satellites as co-domain satellites. By actively pushing the terminal TokenU within the domain, it realizes the satellite-ground pre-authentication between the terminal and any satellite in the domain, and all satellites in this domain recognize the legitimacy of the terminal initiating the main authentication, avoiding the situation where the terminal needs to authenticate with all satellites. This solution uses the method that the terminal carries a communication token in the first frame of the main authentication request for the satellite to identify the legitimacy of the terminal main authentication request. If it is legal, the communication token field is deleted and the main authentication request is transparently forwarded. If it is not legal, the authentication request frame is discarded, achieving the purpose of neither changing the main authentication process and authentication frame structure of the ground network nor effectively solving the problem that in the NTN network of satellite-ground integration, an attacker launches a DDOS storm attack on the network from the user link, causing the entire network to collapse. The scope of influence caused by the attack is limited to the access satellite, eliminating the security risks brought by the attack to subsequent routing node satellites, gateway stations, and the ground core network.
[0103] The purpose of the present invention is achieved through the following technical solutions:
[0104] A terminal network access authentication method for implementing satellite-ground pre-authentication includes the following steps:
[0105] Step S1, dividing the entire network of satellites into domains: Divide the entire network of satellites into domains according to the orbital plane. Satellites in the same orbit belong to the same domain, and the domain fields in the SSVIDs of satellites in the same domain are the same. After being enabled, the satellites broadcast their own SSVIDs regularly.
[0106] Step S2, mutual authentication between adjacent satellites in the same domain: Complete two-way mutual authentication between adjacent satellites in the same domain and establish an inter-satellite secure transmission link within the domain. If successful, directly proceed to step S3; if failed, return to step S2.
[0107] Step S3, satellite determines the type of authentication application: The satellite waits to receive an authentication application initiated by the terminal; after receiving the authentication application, the satellite determines the authentication type based on the type word carried in the authentication application. If it is satellite-ground pre-authentication, directly proceed to step S5; if it is main authentication, directly proceed to step S8.
[0108] Step S4, terminal prepares for network access: The terminal prepares to initiate network access authentication. After receiving the SSVID of the satellite to be accessed, it determines whether it needs to initiate satellite-ground pre-authentication. If it does, proceed to step S5; if not, directly proceed to step S7.
[0109] Step S5, satellite-ground pre-authentication: The terminal initiates a satellite-ground pre-authentication application and conducts satellite-ground pre-authentication with the access satellite. If the authentication is successful, the terminal obtains and saves the communication token, the access satellite proceeds to step S6, and the terminal proceeds to step S7; if the authentication fails, the access satellite returns to step S3 and the terminal returns to step S4.
[0110] Step S6, sharing the pre-authentication result within the satellite domain: The access satellite encrypts the terminal pre-authentication result using the session key negotiated by satellite mutual authentication and pushes it to all other satellites within the domain through the inter-satellite link. Other satellites within the domain save the authentication result, and the satellite returns to step S3.
[0111] Step S7, terminal initiates a main authentication application: The terminal starts the main authentication process and initiates a main authentication application, which carries the communication token obtained after successful pre-authentication.
[0112] Step S8, satellite determines the legality of the authentication application: After receiving the terminal's main authentication application, the access satellite determines whether the application is legal based on the communication token carried in the application. If it is legal, proceed to step S9; if it is not legal, discard the authentication application and return to step S3.
[0113] Step S9, Terminal Main Authentication: The access satellite transparently forwards the terminal main authentication application data to the ground core network, and then follows the original authentication process of the ground network to complete the main authentication of the terminal to the ground core network. After successful authentication, the terminal completes the network access authentication and the process ends; if the authentication fails, the terminal returns to step S7 and the satellite returns to step S3.
[0114] Specifically, step S1 specifically includes: Before the construction of the satellite network, a unified plan is carried out, and the entire network of satellites is divided into domains according to the orbital plane. Satellites in the same orbit belong to the same domain, and whether they are in the same domain is reflected in the SSVID.
[0115] Furthermore, step S1 also includes: The SSVID is the unique security identity identifier of the satellite, which is a 32-bit binary number. The encoding rule is defined as follows: Country identifier (8 bits) + Operator identifier (3 bits) + Domain identifier (6 bits) + Satellite identifier (13 bits) + Reserved bit (2 bits);
[0116] Furthermore, step S1 also includes: After completing the domain division plan for the entire network of satellites, the SSVID is written into the satellite on the ground. After the satellite is launched and enabled, it will broadcast its own identity identifier SSVID regularly and enter step S2.
[0117] Specifically, step S2 specifically includes: Bidirectional interconnection authentication is completed between adjacent satellites in the same domain. In this embodiment, it is assumed that satellite 1 and satellite 2 are adjacent satellites in the same domain and need to initiate interconnection authentication. The IBC algorithm used for authentication is the SM9 algorithm. The steps of the interconnection authentication include:
[0118] S21, Satellite 1 determines whether it belongs to the same domain satellite according to the domain identifier in the SSVID2 of satellite 2. If so, it enters step S22; if not, it enters step S21;
[0119] S22, Satellite 1 determines whether it has completed interconnection authentication with satellite 2 according to SSVID2. If so, it enters step S21; if not, it enters step S23;
[0120] S23, Satellite 1 generates an authentication vector V 12 , including the following process: Generate a random number Rnd1; Obtain a timestamp TS1; Derive the public key Pks2 of satellite 2 based on the SM9 algorithm and SSVID2; Sign Rnd1||SSVID1 based on the SM9 algorithm and its own private key Sks1 to get SM9_S Sks1 (Rnd1||SSVID1); Encrypt SM9_S Sks1 (Rnd1||SSVID1)||Rnd1||TS1 based on the SM9 algorithm and Pks2 to obtain the authentication vector V 12 That is, SM9_E Pks2 (SM9_SSks1 (Rnd1||SSVID1)||Rnd1||TS1);
[0121] S24, Satellite 1 sends the authentication vector V 12 to Satellite 2;
[0122] S25, Satellite 2 verifies the authentication vector V 12 , including the following process: decrypt the authentication vector V using the SM9 algorithm and its own private key Sks2 12 to obtain SM9_S Sks1 (Rnd1||SSVID1), Rnd1 and TS1. If successful, verify the message freshness. If failed, terminate the authentication process; verify the message freshness based on TS1. If passed, verify the signature of the message. If failed, terminate the authentication process; Satellite 2 derives the public key Pks1 of Satellite 1 based on the SM9 algorithm and SSVID1, and then verifies the signature of SM9_S Sks1 (Rnd1||SSVID1). If passed, go to step S26. If failed, terminate the authentication process;
[0123] S26, Satellite 2 obtains the session key: generates a random number Rnd2, and performs a bitwise exclusive OR operation on Rnd1 and Rnd2 to obtain the session key SeK;
[0124] S27, Satellite 2 generates the authentication vector V 21 , including the following process: obtains the timestamp TS2; signs Rnd2||SSVID2 through the SM9 algorithm and its own private key Sks2 to obtain SM9_S Sks2 (Rnd2||SSVID2); encrypts SM9_S Sks2 (Rnd2||SSVID2)||Rnd2||TS2 through the SM9 algorithm and Pks1 to obtain the authentication vector V 21 i.e., SM9_E Pks1 (SM9_S Sks2 (Rnd2||SSVID2)||Rnd2||TS2);
[0125] S28, Satellite 2 sends the authentication vector V 21 to Satellite 1;
[0126] S29, Satellite 1 verifies the authentication vector V 21 , obtains the session key, including the following process: decrypts the authentication vector V using the SM9 algorithm and its own private key Sks1 21 to obtain SM9_S Sks2(Rnd2||SSVID2), Rnd2, and TS2. If successful, verify the message freshness. If failed, terminate the authentication process and return to step S21; verify the message freshness based on TS2. If successful, verify the signature of the message. If failed, terminate the authentication process and return to step S21; use Pks2 to verify the signature of SM9_S Sks2 (Rnd2||SSVID2). If successful, enter step S210. If failed, terminate the authentication process and return to step S21;
[0127] S210, Satellite 1 obtains the session key: Exclusive OR Rnd1 and Rnd2 bit by bit to obtain the session key SeK.
[0128] Specifically, step S3 specifically includes: After all satellites in the network complete the timed broadcast of their own SSVIDs, they wait for the authentication request from the terminal. If an authentication request is received, after the satellite receives the authentication request, it determines the authentication type. If it is a satellite-ground pre-authentication request, it directly enters the satellite-ground authentication process in step S5; if it is a primary authentication, it directly enters step S8 to determine the legitimacy of the primary authentication request.
[0129] Specifically, step S4 specifically includes: The terminal determines whether satellite-ground pre-authentication is required. The specific steps for determination include:
[0130] S41, The terminal queries the tokens stored locally to check if there is a token for the domain where the satellite to be accessed is located. If there is, enter step S42; if not, directly enter step S5;
[0131] S42, The terminal checks if the token has expired. If it has, delete the token and enter step S5; if not, directly enter step S7.
[0132] Specifically, step S5 specifically includes: The terminal and the satellite perform satellite-ground pre-authentication. In this embodiment, it is assumed that a certain terminal initiates satellite-ground pre-authentication to Satellite 1. The IBC algorithm used for authentication is the SM9 algorithm. The specific steps for authentication include:
[0133] S51, The terminal prepares the authentication vector V u1 , including the following processes: Derive the public key Pks1 of Satellite 1 based on the SM9 algorithm and SSVID1; obtain the timestamp TS3; sign its own identity identifier TSVID u using its own private key Sk u to obtain SM9_S SKu (TSVID u ); Encrypt TSVID u ||SM9_S SKu (TSVID u )||TS3 based on the SM9 algorithm and Pks1, and then obtain the authentication vector V u1: SM9_E Pks1 (TSVID u ||SM9_S SKu (TSVID u )||TS3);
[0134] S52, The terminal sends a satellite - ground pre - authentication application and sends the authentication vector V u1 to satellite 1;
[0135] S53, Satellite 1 verifies the authentication vector V u1 , including the following process: Use the SM9 algorithm and its own private key Sks1 to decrypt the authentication vector V u1 to obtain TSVID u , SM9_S SKu (TSVID u ) and TS3. If successful, verify the message freshness. If failed, terminate the authentication process and return to step S3; Verify the message freshness based on TS3. If successful, verify the signature of the message. If failed, terminate the authentication process and return to step S3; Derive the public key Pk u of the terminal based on the SM9 algorithm and ID u and verify the signature of SM9_S SKu (TSVID u ). If passed, enter step S54. If failed, terminate the authentication process and return to step S3;
[0136] S54, Satellite 1 prepares the authentication vector V 1u , including the following process: Obtain the timestamp TS4; Generate the TokenU corresponding to the terminal and sign it with the SM9 algorithm and its own private key Sks1 to get SM9_S Sks1 (TokenU); Encrypt TokenU||SM9_S u (TokenU)||TS4 based on the SM9 algorithm and Pk Sks1 to obtain the authentication vector V 1u : SM9_E Pku (TokenU||SM9_S Sks1 (TokenU)||TS4); Save the TSVID u of this terminal and the corresponding token TokenU;
[0137] S55, Satellite 1 sends the authentication vector V 1u to the terminal.
[0138] S56, The terminal verifies the authentication vector V 1u , including the following process: Use the SM9 algorithm and Sk u to decrypt the authentication vector V 1u to obtain TokenU, SM9_SSks1 (TokenU) and TS4. If successful, verify the message freshness. If failed, terminate the authentication process and return to step S51; verify the message freshness based on TS3. If successful, verify the signature of the message. If failed, terminate the authentication process and return to step S51; verify the signature of SM9_S based on the SM9 algorithm and Pks1 Sks1 (TokenU). If passed, save TokenU and the authentication is completed. If failed, terminate the authentication process and return to step S51.
[0139] Specifically, step S6 specifically includes: accessing the shared pre-authentication result within the local domain of the satellite. In this embodiment, it is assumed that satellite 1 shares the satellite-ground pre-authentication result with satellite 2, and the symmetric encryption algorithm used for authentication is the SM4 algorithm. The specific sharing steps include:
[0140] S61, satellite 1 encrypts the TSVID of the satellite terminal u and the corresponding token TokenU using the SM4 algorithm and SeK to obtain SM4 SeK (TSVID u ||TokenU);
[0141] S62, satellite 1 sends SM4 SeK (TSVID u ||TokenU) to satellite 2 through the inter-satellite link;
[0142] S63, satellite 2 decrypts SM4 SeK (TSVID u ||TokenU) to obtain TSVID u ||TokenU and stores it.
[0143] Specifically, step S7 specifically includes: the terminal starts the main authentication standard process. In this embodiment, it is assumed that the terminal accesses the satellite network through satellite 1, and the IBC algorithm used is the SM9 algorithm. The specific steps include:
[0144] S71, the terminal queries whether TokenU is invalid. If not invalid, proceed to step S72; otherwise, return to step S5;
[0145] S72, the terminal obtains the timestamp TS5;
[0146] S73, the terminal encrypts TokenU||TS5 based on the SM9 algorithm and Pks1 to obtain SM9_E Pks1 (TokenU||TS5);
[0147] S74, the terminal adds SM9_E Pks1 (TokenU||TS5) to the main authentication application data frame and sends it to satellite 1.
[0148] Specifically, step S8 specifically includes: determining whether the primary authentication application sent by the satellite determination terminal is legal. In this embodiment, it is assumed that the access satellite is Satellite 1 and the IBC algorithm used is the SM9 algorithm. The specific steps include:
[0149] S81, Satellite 1 queries whether there is a corresponding token locally. If there is, it directly proceeds to step S82. Otherwise, it requests the token of this terminal from adjacent satellites within the domain and then proceeds to step S82; u Corresponding token, if any, then directly enter step S82, otherwise, request the token of this terminal from adjacent satellites within the domain, and then enter step S82;
[0150] S82, decrypt SM9_E Pks1 (TokenU||TS5) based on the SM9 algorithm and its own private key Sks1 to obtain TokenU||TS5;
[0151] S83, Satellite 1 verifies the message freshness based on TS5. If it passes, it proceeds to step S84. If it fails, it discards the authentication data and terminates the authentication process, returning to step S3;
[0152] S84, Satellite 1 compares TokenU with the token saved locally. If it passes, it proceeds to step S9. If it fails, it discards the authentication data and terminates the authentication process, returning to step S3.
[0153] As Figure 4 shown, a satellite terminal network access authentication system based on the IBC algorithm for implementing satellite - ground pre - authentication is used to implement the above - mentioned terminal network access authentication method for satellite - ground pre - authentication. The system includes a terminal, a satellite, a gateway station, and a ground core network.
[0154] In this system, the terminal consists of a terminal security module and a terminal host. The terminal security module implements the process handling of satellite - ground pre - authentication and primary authentication, authentication algorithm operation, and the functions of storing and retrieving authentication data and results; the terminal host implements human - machine interaction processing and the function of sending and receiving communication data with the satellite.
[0155] In this system, the satellite consists of an on - board integrated security payload, an on - board base station, an on - board computer, a communication payload, etc. The on - board integrated security payload implements inter - satellite interconnection authentication within the same domain, satellite - ground pre - authentication, sharing of pre - authentication results within the domain, determination of the legality of authentication applications, authentication algorithm operation, and the functions of storing and retrieving authentication data and results; the on - board base station implements the invocation of the on - board integrated security payload and the processing of the primary authentication process; the on - board computer implements satellite operation management and the scheduling and control function of on - board payloads; the communication payload implements communication processing for inter - satellite links, user links, and feeder links;
[0156] In this system, the gateway station realizes the satellite-ground data forwarding during the primary authentication of the terminal to the ground core network; the ground core network realizes the functions of processing the primary authentication process of the terminal, performing authentication algorithm operations, and storing and retrieving authentication data and results.
[0157] Figure 2 The steps shown by Arabic numerals 1 to 10 are as follows:
[0158] 1. Determine whether it belongs to the same domain satellite according to the domain identifier in SSVID2;
[0159] 2. Determine whether the interconnection authentication with Satellite 2 has been completed according to SSVID2;
[0160] 3. Prepare the authentication vector V 12 :
[0161] 3.1, Generate a random number Rnd1;
[0162] 3.2, Obtain the time stamp TS1;
[0163] 3.3, Derive the public key Pks2 of Satellite 2 based on the SM9 algorithm and SSVID2;
[0164] 3.4, Sign Rnd1ⅡTS1 based on the SM9 algorithm and its own private key Sks1 to obtain SM9_S Sks1 (Rnd1ⅡTS1);
[0165] 3.5, Encrypt SM9_S Sks1 (Rnd1||SSVID1)||Rnd1||TS1 based on the SM9 algorithm and Pks2 to obtain the authentication vector V 12 ;
[0166] 4. Satellite 1 sends the authentication vector V 12 :
[0167] SM9_E Pks2 (SM9_S Sks1 (Rnd1||SSVID1)||Rnd1||TS1);
[0168] 5. Verify the authentication vector V 12 ;
[0169] 5.1, Decrypt the authentication vector V using the SM9 algorithm and its own private key Sks2 12 to obtain SM9_S Sks1 (Rnd1||SSVID1), Rnd1 and TS1;
[0170] 5.2, Verify the message freshness based on TS1;
[0171] 5.3, Public key Pks1 of derived satellite 1, verify signature SM9_S Sks1 (Rnd1||SSVID1);
[0172] 6. Generate random number Rnd2, and obtain session key SeK by bitwise exclusive OR of Rnd1 and Rnd2;
[0173] 7. Generate authentication vector V 21 :
[0174] 7.1, Obtain timestamp TS2;
[0175] 7.2, Sign Rnd2||SSVID2 through SM9 algorithm and its own private key Sks2 to obtain SM9_S Sks2 (Rnd2||SSVID2);
[0176] 7.3, Encrypt SM9_S Sks2 (Rnd2||SSVID2)||Rnd2||TS2 based on SM9 algorithm and Pks1 to obtain authentication vector V 21 ;
[0177] 8. Satellite 1 sends authentication vector V 21 :
[0178] SM9_E Pks1 (SM9_S Sks2 (Rnd2||SSVID2)||Rnd2||TS2)
[0179] 9. Verify authentication vector V 21 :
[0180] 9.1, Decrypt authentication vector V using SM9 algorithm and its own private key Sks1 21 to obtain SM9_S Sks2 (Rnd2||SSVID2), Rnd2 and TS2;
[0181] 9.2, Verify message freshness based on TS2;
[0182] 9.3, Verify signature of SM9_S Sks2 (Rnd2||SSVID2) using Pks2;
[0183] 10. Obtain session key SeK by bitwise exclusive OR of Rnd1 and Rnd2.
[0184] Figure 3 The steps shown by Arabic numerals 1 to 10 are as follows:
[0185] 1. The terminal prepares authentication vector V u1 :
[0186] 1.1, The public key Pks1 of satellite 1 derived based on the SM9 algorithm and SSVID1;
[0187] 1.2, Obtain the timestamp TS3;
[0188] 1.3, Based on the SM9 algorithm and its own private key Sk u Sign its own identity identifier TSVID u to obtain SM9_S SKu (TSVID u );
[0189] 1.4, Encrypt TSVID u ||SM9_S SKu (TSVID u )||TS3 based on the SM9 algorithm and Pks1, and then obtain the authentication vector V u1 : SM9_E Pks1 (TSVID u ||SM9_S SKu (TSVID u ));
[0190] 2. The terminal sends a satellite-ground pre-authentication application and transmits the authentication vector V u1 to satellite 1;
[0191] 3. Satellite 1 verifies the authentication vector V u1 :
[0192] 3.1, Decrypt the authentication vector V u1 using the SM9 algorithm and its own private key Sks1 to obtain TSVID u , SM9_S SKu (TSVID u ) and TS3;
[0193] 3.2, Verify the message freshness based on TS3;
[0194] 3.3, Derive the public key Pk u of the terminal based on the SM9 algorithm and TSVID u and verify the signature of SM9_S SKu (TSVID u );
[0195] 4. Satellite 1 prepares the authentication vector V 1u :
[0196] 4.1, Obtain the timestamp TS4;
[0197] 4.2. Generate the TokenU corresponding to the terminal and sign it with the SM9 algorithm and its own private key Sks1 to obtain SM9_S Sks1 (TokenU);
[0198] 4.3. Based on the SM9 algorithm and Pk u Encrypt TokenU||SM9_S Sks1 (TokenU)||TS4 to obtain the authentication vector V 1u : SM9_E Pku (TokenU||SM9_S Sks1 (TokenU)||TS4);
[0199] 4.4. Save the ID of this terminal u and the corresponding token TokenU;
[0200] 5. Satellite 1 sends the authentication vector V 1u to the terminal;
[0201] 6. The terminal verifies the authentication vector V 1u , and obtains the communication token:
[0202] 6.1. Use the SM9 algorithm and Sk u to decrypt the authentication vector V 1u to obtain TokenU, SM9_S Sks1 (TokenU) and TS4;
[0203] 6.2. Verify the message freshness based on TS3;
[0204] 6.3. Verify the signature of SM9_S Sks1 (TokenU) based on the SM9 algorithm and Pks1. If it passes, save TokenU and the authentication is completed. If it fails, terminate the authentication process and initiate the authentication again.
[0205] In view of the security risk of the DDOS storm attack from the user link faced by the network due to the change of the access network architecture in the non-terrestrial network where the satellite network is deeply integrated with the terrestrial mobile communication network (such as 5G / 6G cellular network), the above security problem is solved by the present invention, and the attack is limited to the access satellite, eliminating the security threats to the subsequent routing satellite nodes, terrestrial gateway stations and core networks.
[0206] As described above, the present invention can be preferably implemented.
[0207] All the features disclosed in all the embodiments in this specification, or all the steps in the methods or processes implicitly disclosed, except for the mutually exclusive features and / or steps, can be combined and / or extended and replaced in any way.
[0208] The above are only the preferred embodiments of the present invention, and do not impose any formal restrictions on the present invention. Based on the technical essence of the present invention, any simple modifications, equivalent replacements, and improvements made to the above embodiments within the spirit and principles of the present invention still fall within the protection scope of the technical solution of the present invention.
Claims
1. A terminal access authentication method for implementing satellite-ground pre-authentication, characterized in that Before the terminal initiates the primary authentication, identity pre - authentication is first performed between the terminal and the satellite. The result of the pre - authentication serves as the basis for the satellite to determine whether the primary authentication application received on the user link is legal. Moreover, co - orbital satellites are defined as co - domain satellites. After the terminal completes the space - to - ground pre - authentication with any satellite in the domain, all satellites in this domain recognize the legitimacy of the terminal to initiate the primary authentication. The terminal network access authentication method includes the following steps: S1, Divide the whole - network satellites into domains: Divide the whole - network satellites into domains according to the orbital plane. Satellites in the same orbit are divided into the same domain. The domain field in the Satellite Security Virtual Identifier (SSVID) of co - domain satellites is the same. After being enabled, the satellite broadcasts its own SSVID. S2, Mutual authentication between adjacent co - domain satellites: Complete two - way mutual authentication between adjacent satellites in the same domain to establish an inter - satellite secure transmission link within the domain. If the establishment is successful, proceed to step S3; if the establishment fails, re - execute step S2 until the establishment is successful. S3, The satellite determines the type of authentication application: After receiving the authentication application, the satellite determines the authentication type based on the type word carried in the authentication application. If the authentication type is space - to - ground pre - authentication, proceed to step S5; if the authentication type is primary authentication, proceed to step S8. S4, The terminal prepares for network access: The terminal prepares to initiate network access authentication. After receiving the SSVID of the satellite to be accessed, it determines whether it needs to initiate space - to - ground pre - authentication. If it is necessary, proceed to step S5; if not, proceed to step S7. S5, Space - to - ground pre - authentication: The terminal initiates a space - to - ground pre - authentication application and conducts space - to - ground pre - authentication with the access satellite. If the authentication is successful, the terminal obtains and saves the communication token, and then proceeds to step S6; if the authentication fails, the satellite returns to step S3 and the terminal returns to step S4 until the pre - authentication is successful. S6, Share the pre - authentication result within the satellite domain: The access satellite encrypts the terminal pre - authentication result using the session key negotiated by satellite - to - satellite authentication and pushes it to all other satellites in the domain through the inter - satellite link. Other satellites in the domain save this authentication result and return to step S3 to enable the satellite to wait for receiving the terminal's authentication application and determine the authentication application type. S7, The terminal initiates a primary authentication application: The terminal starts the primary authentication process and initiates a primary authentication application. The communication token obtained after successful pre - authentication is carried in the authentication application. S8, The satellite determines the legality of the authentication application: After receiving the terminal's primary authentication application, the access satellite determines whether the application is legal based on the communication token carried in the application. If it is legal, proceed to step S9; if it is not legal, discard the authentication application and return to step S3. S9, Terminal primary authentication: The access satellite transparently forwards the terminal primary authentication application data to the ground core network, and subsequently follows the primary authentication mechanism of the ground network to complete the network access authentication of the terminal to the ground core network. If the authentication fails, the terminal returns to step S7 to re - initiate the primary authentication application until the network access authentication is successful. At the same time, the satellite returns to step S3 to wait for receiving the terminal's authentication application and determine the authentication application type.
2. The terminal access authentication method for realizing satellite-ground pre-authentication according to claim 1, characterized in that In step S2, let satellite 1 and satellite 2 be two adjacent satellites in the same domain. The two - way mutual authentication between satellite 1 and satellite 2 includes the following steps: S21, Satellite 1 determines whether it belongs to the same domain satellite according to the domain identifier in the satellite 2 identity identifier SSVID2; if so, it proceeds to step S22; if not, it returns to step S21; S22, Satellite 1 determines whether it has completed the interconnection authentication with satellite 2 according to SSVID2; if so, it returns to step S21; if not, it proceeds to step S23; S23, Satellite 1 generates authentication vector V 12 , including the following steps: S231, Generate a random number Rnd1; S232, Obtain the timestamp TS1; S233, Derive the public key Pks2 of satellite 2 based on the IBC algorithm and SSVID2; S234, sign Rnd1||SSVID1 with the IBC algorithm and its own private key Sks1 to obtain IBC_S Sks1 (Rnd1||SSVID1); where || represents the data concatenation symbol, and Rnd1||SSVID1 represents the data string obtained by concatenating the random number Rnd1 and the satellite 1 identity SSVID1. Rnd1 is placed on the left and SSVID1 is placed on the right. IBC_S Sks1 (Rnd1||SSVID1) represents the signature data obtained by signing Rnd1||SSVID1 with the IBC algorithm and the private key Sks1; S235, encrypt IBC_S with the public key Pks2 of satellite 2 based on the IBC algorithm Sks1 (Rnd1||SSVID1)||Rnd1||TS1 to obtain the authentication vector V 12 , denote V 12 =IBC_E Pks2 (IBC_S Sks1 (Rnd1||SSVID1)||Rnd1||TS1)); IBC_E Pks2 (IBC_S Sks1 (Rnd1||SSVID1)||Rnd1||TS1) represents the encrypted plaintext authentication data IBC_S using the IBC algorithm and the public key Pks2 of satellite 2 Sks1 (Rnd1||SSVID1)||Rnd1||TS1 is the ciphertext authentication data obtained after S24, Satellite 1 sends authentication vector V 12 to Satellite 2; S25, Satellite 2 verifies the authentication vector V 12 , including the following steps: S251, Decrypt the authentication vector V using the IBC algorithm and its own private key Sks2 12 Obtain IBC_S Sks1 (Rnd1||SSVID1), Rnd1, and TS1; if the decryption is successful, verify the message freshness; if the decryption fails, terminate the authentication process; S252, Verify the message freshness based on TS1; if the verification passes, verify the signature of the message; if the verification fails, terminate the authentication process; S253, Satellite 2 derives the public key Pks1 of Satellite 1 based on the IBC algorithm and SSVID1, and then verifies the signature of IBC_S Sks1 (Rnd1||SSVID1); if it passes, go to step S26, if it fails, terminate the authentication process; S26, Satellite 2 obtains the session key: generate a random number Rnd2, and perform a bitwise exclusive OR operation on Rnd1 and Rnd2 to obtain the session key SeK; S27, satellite 2 generates authentication vector V 21 , including the following steps: S271, Obtain the timestamp TS2; S272, sign Rnd2||SSVID2 with the IBC algorithm and its own private key Sks2 to obtain the signature data IBC_S Sks2 (Rnd2||SSVID2); S273, encrypt and authenticate the data IBC_S based on the IBC algorithm and the public key Pks1 of satellite 1 Sks2 (Rnd2||SSVID2)||Rnd2||TS2 to obtain the authentication vector V 21 , denote V 21 =IBC_E Pks1 (IBC_S Sks2 (Rnd2||SSVID2)||Rnd2||TS2)); Among them, IBC_E Pks1 (IBC_S Sks2 (Rnd2||SSVID2)||Rnd2||TS2) indicates the ciphertext authentication data obtained by encrypting the plaintext authentication data IBC_S Sks2 with the IBC algorithm and the public key Pks1 of satellite 1; S28, Satellite 2 sends authentication vector V 21 to Satellite 1; S29, Satellite 1 verifies the authentication vector V 21 , and obtains the session key, including the following steps: S291, decrypt the authentication vector V using the IBC algorithm and its own private key Sks1 21 Obtain IBC_S Sks2 (Rnd2||SSVID2), Rnd2, and TS2; if the decryption is successful, verify the message freshness; if the decryption fails, terminate the authentication process and return to step S21; S292, Verify the message freshness based on TS2; if the verification is successful, verify the signature of the message; if the verification fails, terminate the authentication process and return to step S21; S293, use Pks2 to verify the signature of IBC_S Sks2 (Rnd2||SSVID2); if the signature verification is successful, go to step S210; if the signature verification fails, terminate the authentication process and return to step S21; S210, Satellite 1 obtains the session key: perform a bitwise exclusive OR operation on Rnd1 and Rnd2 to obtain the session key SeK.
3. The terminal access authentication method for implementing satellite-ground pre-authentication according to claim 2, wherein, In step S4, the terminal determines whether satellite-ground pre-authentication is required, including the following steps: S41, The terminal queries the tokens stored locally to check if there is a token for the domain where the satellite to be accessed is located; if there is, it proceeds to step S42; if not, it proceeds to step S5; S42, The terminal checks if the token has expired; if it has, delete the token and proceed to step S5; if not, it proceeds to step S7.
4. The terminal access authentication method for realizing satellite-ground pre-authentication according to claim 3, wherein In step S5, the steps of satellite-ground pre-authentication include the following steps: S51, the terminal prepares the authentication vector V u1 , including the following steps: S511, Derive the public key Pks1 of satellite 1 based on the IBC algorithm and SSVID1; S512, Obtain the timestamp TS3; S513, based on the IBC algorithm and its own private key Sk u signs its own terminal security virtual identifier TSVID u to obtain the signature data IBC_S SKu (TSVID u ); S514, encrypt and authenticate the data TSVID based on the IBC algorithm and the public key Pks1 of satellite 1 u ||IBC_S SKu (TSVID u )||TS3, to obtain the authentication vector V u1 : IBC_E Pks1 (TSVID u ||IBC_S SKu (TSVID u )||TS3); S52, the terminal sends a satellite-ground pre-authentication application and sends the authentication vector V u1 to Satellite 1; S53, Satellite 1 verifies the authentication vector V u1 , including the following steps: S531, decrypt the authentication vector V using the IBC algorithm and its own private key Sks1 u1 to obtain TSVID u and IBC_S SKu (TSVID u ) and TS3; if the decryption is successful, verify the message freshness; if the decryption fails, terminate the authentication process and return to step S3; S532, Verify the message freshness based on TS3; if the verification is successful, verify the signature of the message; if the verification fails, terminate the authentication process and return to step S3; S533, Based on the IBC algorithm and TSVID u The public key Pk of the derived terminal u And verify the signature of IBC_S SKu (TSVID u ); If it passes, go to step S54; if it fails, terminate the authentication process and return to step S3; S54, Satellite 1 prepares authentication vector V 1u , including the following steps: S541, Obtain the timestamp TS4; Generate a communication token TokenU corresponding to the terminal and sign it with the IBC algorithm and its own private key Sks1 to obtain IBC_S Sks1 (TokenU); where, IBC_S Sks1 (TokenU) represents the signature data obtained by signing the communication token TokenU with the IBC algorithm and the private key Sks1; S543, based on the IBC algorithm and the public key Pk of the terminal u Encrypt TokenU||IBC_S Sks1 (TokenU)||TS4 to obtain the authentication vector V 1u : IBC_E Pku (TokenU||IBC_S Sks1 (TokenU)||TS4); S544, save the TSVID of this terminal u and the corresponding token TokenU; S55, the satellite 1 sends the authentication vector V 1u to the terminal; S56, the terminal verifies the authentication vector V 1u , including the following steps: S561, adopt the IBC algorithm and its own private key Sk u Decrypt the authentication vector V 1u Obtain the communication token TokenU, IBC_S Sks1 (TokenU) and TS4; if the decryption is successful, verify the message freshness; if the decryption fails, terminate the authentication process and return to step S51; S562, Verify the message freshness based on TS3; if the verification is successful, verify the signature of the message; if the verification fails, terminate the authentication process and return to step S51; S563, Verify IBC_S based on the IBC algorithm and Pks1 Sks1 (TokenU); if the verification is successful, save the communication token TokenU and the authentication is completed; if the verification fails, terminate the authentication process and return to step S51.
5. The terminal access authentication method for realizing satellite-ground pre-authentication according to claim 4, characterized in that, In step S6, the process of sharing the pre-authentication result within the domain of the access satellite includes the following steps: S61, Satellite 1 will pass the TSVID of the pre-authenticated terminal u and the corresponding TokenU to form the shared data TSVID u ||TokenU, and use the symmetric encryption algorithm and SeK to encrypt to obtain the shared data ciphertext: E SeK (TSVID u ||TokenU); S62, satellite 1 sends E SeK (TSVID u ||TokenU) to the co-located adjacent satellite 2 via the inter-satellite link; S63, Satellite 2 decrypts E SeK (TSVID u || TokenU) to obtain TSVID u and the corresponding TokenU and store them.
6. The terminal access authentication method for implementing satellite-ground pre-authentication according to claim 5, wherein In step S7, the terminal starts the main authentication standard process, including the following steps: S71, The terminal checks if TokenU is invalid; if it is not invalid, it proceeds to step S72; otherwise, it returns to step S5; S72, The terminal obtains the timestamp TS5; S73, the terminal encrypts TokenU||TS5 based on the IBC algorithm and the public key Pks1 of satellite 1 to obtain IBC_E Pks1 (TokenU||TS5); where IBC_E Pks1 (TokenU||TS5) represents the main authentication application for a legitimate access order; S74, the terminal adds IBC_E Pks1 (TokenU || TS5) to the main authentication application data frame and sends it to Satellite 1.
7. The terminal access authentication method for implementing satellite-ground pre-authentication according to claim 6, wherein In step S8, the satellite determines whether the main authentication application sent by the terminal is legal, including the following steps: S81, Satellite 1 is based on the TSVID of the terminal u Query whether the corresponding communication token is stored locally; if so, directly proceed to step S82, otherwise, request the communication token of this terminal from adjacent satellites within the domain, and then proceed to step S82; S82, decrypt the legitimate access order IBC_E of the terminal's main authentication application based on the IBC algorithm and its own private key Sks1 Pks1 (TokenU || TS5) to obtain TokenU and TS5; S83, Satellite 1 verifies the message freshness based on TS5; if the verification passes, it proceeds to step S84; if the verification fails, discard the main authentication application data and terminate the authentication process, returning to step S3; S84, Satellite 1 compares this TokenU with the communication token saved locally; if the comparison passes, it proceeds to step S9; if the comparison fails, discard the main authentication application data and terminate the authentication process, returning to step S3.
8. A terminal access authentication method for implementing satellite-ground pre-authentication according to any one of claims 4 to 7, characterized in that, In steps S5 to S8, the composition of TokenU includes but is not limited to the following information: token header, terminal SSVID, access satellite SSVID, token data, expiration time.
9. A terminal access authentication system for realizing satellite-ground pre-authentication, characterized in that, A terminal network access authentication method for implementing satellite-ground pre-authentication according to any one of claims 1 to 8, including a terminal, a satellite, a gateway station, and a ground core network that are sequentially communicatively connected; Wherein, the terminal includes a terminal security module and a terminal host. The terminal security module is used for processing the satellite-ground pre-authentication and main authentication processes, performing authentication algorithm operations, and storing and accessing authentication data and results; the terminal host is used for implementing human-computer interaction processing and communication data transceiver processing functions with the satellite; the terminal includes but is not limited to satellite terminals, 5G / 6G mobile phones, ground gateways with satellite access capabilities, and mobile gateway stations; The satellite includes an on-board integrated security payload, an on-board base station, an on-board computer, and a communication payload; The on-board integrated security payload is used for implementing inter-satellite interconnection authentication for adjacent satellites in the same domain, satellite-ground pre-authentication, sharing of pre-authentication results within the domain, determining the legality of authentication applications, performing authentication algorithm operations, and storing and accessing authentication data and results; the on-board base station is used for invoking the on-board integrated security payload and processing the main authentication process; the on-board computer is used for implementing satellite operation management and scheduling and control functions of on-board payloads; The communication payload is used for communication processing of inter-satellite links, user links, and feeder links; The gateway station is used for forwarding processing of satellite-ground communication data; The ground core network is used for processing the main authentication process of the terminal, performing authentication algorithm operations, and storing and accessing authentication data and results.
Citation Information
Patent Citations
Method for achieving token roaming and server
CN109150862A
Method for accessing service party equipment, access party equipment and service party equipment
CN114268506A