Method for generating and receiving civil anti-counterfeiting navigation signals based on random processing of spread spectrum codes
Through the method of random processing of spread spectrum code, anti-counterfeiting navigation signals are generated and received, and the time resolution and receiver complexity of satellite navigation signal authentication are solved, and navigation signal authentication with high security and low overhead is achieved.
Patent Information
- Application Number
- CN202310371591.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-04-10
- Publication Date
- 2025-08-26
- Estimated Expiration
- 2043-04-10
AI Technical Summary
The existing satellite navigation signal authentication technology has problems such as low authentication time resolution, low detection probability and high receiver implementation complexity, making it difficult to effectively prevent short delay or regenerative spoofing signal attacks.
Using a random processing method based on spread spectrum code, an authentication root key pair is randomly generated, an authentication flag sequence is generated, and randomly flipped in the spread spectrum code, combining the digital signature and public key cryptography system to generate and receive anti-counterfeiting navigation signals.
It realizes navigation signal authentication with high authentication time resolution, high detection probability and low receiver implementation overhead, improving the safety and reliability of navigation signals and reducing the complexity of the receiver.
Smart Images

Figure CN116594040B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of satellite navigation technology, and in particular to an anti-counterfeiting and anti-spoofing signal system for civil satellite navigation. More specifically, it relates to a civil anti-counterfeiting navigation signal method, system and medium based on random processing of spread spectrum codes. Background Art
[0002] With the development of modern satellite navigation systems such as the BeiDou system, GPS, Galileo, and GLONASS, a growing number of critical civilian infrastructure and life-saving services, such as those in finance, electricity, drones, and autonomous driving, have come to rely on satellite navigation to provide accurate time and location information. However, numerous experiments and case studies have demonstrated that unauthenticated civilian navigation signals are vulnerable to spoofing attacks, allowing attackers to manipulate the time and location calculated by navigation receivers, thereby threatening the security of satellite navigation services. Clearly, to protect the reliability and security of critical civilian infrastructure and life-saving services using satellite navigation services, the authenticity of satellite navigation signals must be authenticated.
[0003] The core concept of satellite navigation signal authenticity authentication is to generate a piece of information that is easy to verify but difficult to forge and append it to the satellite navigation signal. The receiver verifies the authenticity of the satellite navigation signal by extracting and verifying this authentication information. Satellite navigation signals are direct sequence spread spectrum signals, consisting of a navigation message, a spreading code, and a radio frequency carrier. Most navigation signal authentication techniques reported in the literature primarily rely on authenticating the navigation message and the spreading code sequence. Navigation message authentication offers high detection probability and low receiver implementation complexity. However, since the symbol rate of most satellite navigation messages is approximately 100 bits per second, the time resolution or characteristic symbol width for authentication is the navigation message bit width (approximately 10 ms). This makes it difficult to effectively detect short-delay forwarding or regeneration spoofing signals, where the delay difference from the authentic signal is less than the navigation message bit width, and presents certain security vulnerabilities. On the other hand, spread spectrum code authentication benefits from the higher rate of spread spectrum codes and has the characteristic of high authentication time resolution. However, some of the currently known spread spectrum code sequence authentication methods require the assistance of a third-party communication link, which cannot achieve self-closed-loop authentication within the navigation system. Another part requires the receiver to cache a relatively long amount of original signal samples (usually several seconds), introducing a huge data storage overhead. Therefore, it encounters great difficulties in the complexity of receiver implementation, hindering its large-scale promotion.
[0004] In view of the current design difficulties of satellite navigation signal authenticity authentication signals, an anti-counterfeiting navigation signal system with high authentication time resolution, high detection probability and low receiver implementation overhead is urgently needed. Summary of the Invention
[0005] The present invention provides a civilian anti-counterfeiting navigation signal method, system and medium based on random processing of spread spectrum codes, so as to achieve anti-spoofing authentication of navigation signals with high authentication time resolution, high detection probability and low receiver implementation overhead. The method is used to solve the problems of low time resolution of navigation message authentication and the need for large amounts of data cache or communication system assistance for spread spectrum code authentication, and provides a receiving and authentication method for the signal system.
[0006] The first aspect of the present invention discloses a method for generating a civilian anti-counterfeiting navigation signal based on random processing of spread spectrum codes, the method comprising:
[0007] Step S1: randomly generate a pair of public key cryptography authentication root key pairs as the authentication basic key pairs;
[0008] Step S2: Using the authentication basic key pair from step S1, a digital signature is signed for the navigation message within the period. A basic authentication spread spectrum code is obtained from the navigation message of the next period, and the digital signature is modulated onto the basic authentication spread spectrum code to obtain an authentication flag sequence.
[0009] Step S3: Generate a random key as an authentication key for the current period. Using the authentication key as the key and the signal time in the current period as the seed, generate a flag indicating whether each signal chip in the public periodic spreading code in the current period has been processed, i.e., the position of all processed spreading chips in the public periodic spreading code.
[0010] The specific method for determining the processing position is:
[0011] In the spread spectrum code of the anti-counterfeiting navigation signal, the spread spectrum code is recorded at intervals of a fixed number of chips as Segmentation, within each segment, Chip or post In the periodic public spread spectrum code of the chip, it is recorded as The spreading code chip is in the processing state, and the flip spreading code is indicated by the processing instruction sequence OK, this process indicates the sequence It is a sequence of 0 and 1. The spreading code corresponding to the moment when the value is 1 is processed. Determine each spreading code is the previous Code chip or after The authentication mark sequence is a sequence with a value of ±1, and the moment with a value of +1 corresponds to the next The code chip contains the processed spread spectrum code, and the moment when the value is -1 corresponds to the previous The code chip contains the processed spread spectrum code and the spread spectrum code of the anti-counterfeiting navigation signal It can be expressed as follows: ,
[0012] in is the original public periodic spreading code, is the spreading code rate, Is the navigation certification mark sequence, is the processing instruction sequence, t represents the corresponding time in the cycle; processing instruction sequence Calculated by the following formula:
[0013] ,
[0014] in is a sequence of values 0 or 1, A transformation method is described in which k is a key, t is a plaintext, and t is a signal time. The transformation method includes:
[0015] Step S31: Accurately calculate the signal time to the chip of the spreading code, obtain the starting time of the spreading code chip, and convert the eight time parameters of year, month, day, hour, minute, second, millisecond, and intra-millisecond chip number into binary sequences of lengths not less than 16 bits, 5 bits, 6 bits, 6 bits, 7 bits, 7 bits, 10 bits, and 16 bits, respectively, and combine them into a binary sequence of length not less than 96 bits;
[0016] Step S32: Based on whether the spreading code period belongs to public authentication or user-directed authentication, a 32-bit binary string is used as a signature. If the current period belongs to public authentication, the binary string uses an all-0 signature; otherwise, the 32-bit signature corresponding to the user ID is used.
[0017] Step S33: Concatenate the 96-bit time sequence with the 32-bit signature to obtain 128-bit flip position generation information as block plaintext, then use the current authentication key as the key and use the block cipher algorithm to calculate 128-bit ciphertext;
[0018] Step S34: Treat the 128-bit ciphertext as a decimal number. If the number is greater than ,but ,otherwise ;in is the ratio of processed chips to all spread spectrum codes;
[0019] Step S35, repeating steps S31 to S34, to generate an indication of whether each spreading code within the required time range should be processed;
[0020] The processing is specifically configured in different ways according to whether the anti-counterfeiting navigation signal adopts spread spectrum BPSK, BOC or MSK modulation based on spread spectrum code modulation:
[0021] For BPSK modulation, the polarity of the spread spectrum code is directly flipped, that is, +1 code is changed to -1 code, and -1 code is changed to +1 code; for BOC modulation, the phase sequence of the subcarrier is adjusted by half a cycle, that is, the subcarriers in the 01 sequence are adjusted to 10, and the subcarriers in the 10 sequence are adjusted to 01; for MSK modulation, the frequency offset is cyclically shifted, that is, the original frequency shift Adjust to ,in is the flip adjustment amount, and are the lowest and highest frequencies allowed in the signal band, respectively;
[0022] Step S4: Based on the authentication flag sequence obtained in step S2, within a period of the public periodic spreading code, each element of the authentication flag sequence is set to correspond to a segment of the spreading code. In the first half or the second half of the public periodic spreading code of the navigation signal, where the first half or the second half is determined by the flag corresponding to the element of the authentication flag sequence, the signal chips of the public periodic spreading code are processed based on the processing position obtained in step S3 to obtain a processed hybrid spreading code.
[0023] Step S5: Use the processed hybrid spread spectrum code obtained in step S4 to combine with the navigation message and the carrier to generate a navigation signal.
[0024] According to the first aspect of the present invention, a method for generating a civilian anti-counterfeiting navigation signal based on random processing of spread spectrum codes, in step S1, the public key cryptography system SM2 or ECDSA is used.
[0025] According to the first aspect of the present invention, a method for generating a civilian anti-counterfeiting navigation signal based on random processing of spread spectrum codes, in step S2, the digital signature is modulated onto the basic authentication spread spectrum code in a CSK modulation mode to obtain an authentication mark sequence.
[0026] According to the first aspect of the present invention, a method for generating a civilian anti-counterfeiting navigation signal based on random processing of spread spectrum codes adopts BPSK modulation. The mathematical expression of the anti-counterfeiting navigation signal is as follows:
[0027]
[0028] in, is the signal power, It's a navigation message. After authentication and modification of the spread spectrum code, is the carrier frequency, is the initial carrier phase, j is the imaginary unit, and t is the signal time. The anti-counterfeiting information is carried on the spread spectrum code of the navigation signal and broadcast to the user together with the navigation signal.
[0029] The second aspect of the present invention discloses a method for receiving a civilian anti-counterfeiting navigation signal based on random processing of spread spectrum codes, which is used to receive the signal generated by the method for generating a civilian anti-counterfeiting navigation signal based on random processing of spread spectrum codes described in one of the first aspects. The receiving method includes two receiving and processing modes: slow channel and fast channel.
[0030] According to a second aspect of the present invention, a method for receiving a civilian anti-counterfeiting navigation signal based on random spread spectrum code processing is disclosed, in a slow channel processing mode, comprising the following steps:
[0031] Step S61: The receiver captures and tracks the navigation signal, extracts the correlation value of the on-time branch and the navigation message from the tracking channel;
[0032] In step S62, before receiving the complete navigation message of an authentication cycle, the receiver first caches the adjacent differential results of the on-time branch correlation values as observations of the authentication signature sequence. After receiving the complete navigation message of an authentication cycle, the receiver calculates the authentication signature spreading code for the current authentication cycle from the navigation message using the authentication signature spreading code derivation algorithm.
[0033] Step S63: The receiver uses the authentication mark spreading code of the authentication period to perform correlation calculation with the cached authentication mark sequence observation, and obtains the digital signature carried therein through the CSK demodulation algorithm;
[0034] In step S64, the receiver uses the public key of the asymmetric cryptographic system to verify the consistency between the navigation message and the digital signature, and obtains the result of navigation signal authentication.
[0035] According to a second aspect of the present invention, a method for receiving a civilian anti-counterfeiting navigation signal based on random spread spectrum code processing is disclosed. In the fast channel processing mode, the steps are as follows:
[0036] Step S71: The receiver obtains the authentication key and generates a spread spectrum code processing position according to the signal time, or receives the spread spectrum code processing position in a time period near the current time;
[0037] Step S72: According to the indication of the processing position of the spreading code, the receiver extracts the corresponding signal sample observation and performs a correlation operation with the processed spreading code and the signal sample observation;
[0038] In step S73, the receiver uses the correlation operation result as the authentication detection quantity, performs the hypothesis verification process of the authentication detector, and obtains the result of signal credibility authentication.
[0039] In summary, the proposed solution has the following technical advantages: The method for generating and receiving civilian anti-counterfeiting navigation signals based on random spread spectrum code processing achieves highly reliable and secure navigation signal authentication with moderate computational effort and without requiring user terminals to cache signal samples. Furthermore, the proportion of spread spectrum codes used for navigation signal authentication is relatively small, minimizing the impact on unauthenticated terminals. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the specific embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0041] Figure 1 This is a schematic structural diagram of a spread spectrum code flipping system for a civilian anti-counterfeiting navigation signal system based on BPSK provided by the technology of the present invention;
[0042] Figure 2 This is a layered time domain structure diagram of a civilian anti-counterfeiting navigation signal system provided by the technology of the present invention;
[0043] Figure 3 This is a schematic diagram of the cryptographic relationship between the digital signature and navigation message of a civilian anti-counterfeiting navigation signal system provided by the technology of the present invention;
[0044] Figure 4 This is a typical authentication processing structure of a GNSS receiver for a civilian anti-counterfeiting navigation signal system provided by the technology of the present invention;
[0045] Figure 5 This is a schematic diagram of the principle flow of a method for generating a signal of a civilian anti-counterfeiting navigation signal system provided by the technology of the present invention;
[0046] Figure 6 This is a schematic diagram of the specific generation structure and parameter setting layer of the anti-counterfeiting navigation signal in an embodiment of a civilian anti-counterfeiting navigation signal system provided by the technology of the present invention;
[0047] Figure 7 This is a flowchart of a specific method for generating another anti-counterfeiting navigation signal provided by an embodiment of the present invention;
[0048] Figure 8 It is a schematic diagram of the position flipping method of the anti-counterfeiting information guidance signal spread spectrum code provided by the technology of the present invention. DETAILED DESCRIPTION
[0049] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0050] Figure 1 The present invention provides a schematic diagram of the structure of the spread spectrum code flipping of a BPSK-based civil anti-counterfeiting navigation signal system, which includes the representation of the authentication mark sequence, the signal spread spectrum code, and the flip indication sequence. For BPSK modulation, the polarity of the spread spectrum code chip is directly flipped, that is, the +1 code chip is changed to -1 code chip, and the -1 code chip is changed to +1 code chip; for BOC modulation, the phase sequence of the subcarrier is adjusted by half a cycle, that is, the subcarriers in the 01 sequence are adjusted to 10, and the subcarriers in the 10 sequence are adjusted to 01; for MSK modulation, the frequency offset is cyclically shifted, that is, the original frequency shift is Adjust to ,in is the flip adjustment amount, and These are the lowest and highest frequencies allowed in the signal band, respectively.
[0051] Figure 5 This is a schematic diagram of the principle flow of a method for generating a civilian anti-counterfeiting navigation signal based on random flipping of spread spectrum codes provided by the first embodiment of the present invention. The method is described using a BPSK signal as an example. The method includes four steps:
[0052] Step S1: randomly generate a pair of authentication root key pairs of the public key cryptography system as the authentication basic key pair.
[0053] In step S1, the public key cryptography system SM2 or ECDSA is used; the security calculation in step S2 is a hash algorithm or a block cipher algorithm.
[0054] Step S2: Based on the authentication basic key pair from step S1, a digital signature is signed for the navigation message within the cycle. Then, a basic authentication spread spectrum code is obtained from the navigation message of the next cycle through secure computing technology. The digital signature is modulated onto the basic authentication spread spectrum code to obtain an authentication mark sequence.
[0055] In step S2, the digital signature is modulated onto the basic authentication spread spectrum code in a CSK modulation mode to obtain an authentication mark sequence.
[0056] Step S3: Generate a random key as an authentication key for the current period. Through a shuffling algorithm, with the authentication key as the key and the signal sequence number in the current period as the seed, generate a flag indicating whether each signal code piece in the public periodic spread spectrum code in the current period is flipped, that is, the position of all flipped spread spectrum code pieces in the public periodic spread spectrum code.
[0057] In step S3, the specific method for determining the flip position is to record the spread spectrum code at intervals of a fixed number of chips in the spread spectrum code of the anti-counterfeiting navigation signal as Segmentation, within each segment, Chip or post In the periodic public spread spectrum code of the chip, it is recorded as The spread spectrum code chip is in the flip state, and the flip spread spectrum code is indicated by the flip indication sequence OK, the flip indication sequence It is a sequence of 0 and 1. The corresponding spreading code is flipped when the value is 1. Determine each spreading code is the previous Code chip or after The authentication mark sequence is a sequence with a value of ±1, and the moment with a value of +1 corresponds to the next The code chip contains the processed spread spectrum code, and the moment when the value is -1 corresponds to the previous The code chip contains the processed spread spectrum code and the spread spectrum code of the anti-counterfeiting navigation signal It can be expressed as follows: ,
[0058] in is the original public periodic spreading code, is the spreading code rate, Is the navigation certification mark sequence, is the processing instruction sequence, t represents the corresponding time in the cycle; processing instruction sequence Calculated by the following formula:
[0059] ,
[0060] in is a sequence of values 0 or 1, A transformation method is described in which k is a key, t is a plaintext, and t is a signal time. The transformation method includes:
[0061] Step S31: Accurately calculate the signal time to the chip of the spreading code, obtain the starting time of the spreading code chip, and convert the eight time parameters of year, month, day, hour, minute, second, millisecond, and intra-millisecond chip number into binary sequences of lengths not less than 16 bits, 5 bits, 6 bits, 6 bits, 7 bits, 7 bits, 10 bits, and 16 bits, respectively, and combine them into a binary sequence of length not less than 96 bits;
[0062] Step S32: Based on whether the spreading code period belongs to public authentication or user-directed authentication, a 32-bit binary string is used as a signature. If the current period belongs to public authentication, the binary string uses an all-0 signature; otherwise, the 32-bit signature corresponding to the user ID is used.
[0063] Step S33: Concatenate the 96-bit time sequence with the 32-bit signature to obtain 128-bit flip position generation information as block plaintext, then use the current authentication key as the key and use the block cipher algorithm to calculate 128-bit ciphertext;
[0064] Step S34: Treat the 128-bit ciphertext as a decimal number. If the number is greater than ,but ,otherwise ;in is the ratio of processed chips to all spread spectrum codes;
[0065] Step S35: Repeat steps S31 to S34 to generate an indication of whether each spreading code within the required time range should be processed.
[0066] The anti-counterfeiting navigation signal adopts spread spectrum BPSK, BOC or MSK modulation based on spread spectrum code modulation.
[0067] Using BPSK modulation, the mathematical expression of the anti-counterfeiting navigation signal is as follows:
[0068]
[0069] in, is the signal power, It's a navigation message. After authentication and modification of the spread spectrum code, is the carrier frequency, is the initial carrier phase, j is the imaginary unit, and t is the signal time. The anti-counterfeiting information is carried on the spread spectrum code of the navigation signal and broadcast to the user together with the navigation signal.
[0070] Step S4: Based on the authentication flag sequence obtained in step S2, within one public periodic spreading code period, in a manner such that each element of the authentication flag sequence corresponds to a spreading code segment, in the first half or the second half of the original public periodic spreading code of the navigation signal, wherein the first half or the second half is determined by the polarity of the corresponding element of the authentication flag sequence, the signal chips of the public periodic spreading code are flipped at the flip position obtained in step S3 to obtain a flipped hybrid spreading code;
[0071] Step S5: Use the flipped spread spectrum code obtained in step S4 to combine with the navigation message and the carrier to generate a navigation signal.
[0072] The signal structure generated based on the above steps is shown in the attached Figure 6 As shown in the attached figure, the signal authentication information structure is as follows: Figure 8 shown.
[0073] Another embodiment of the present invention provides a specific implementation of a method for generating a civilian anti-counterfeiting navigation signal based on random processing of spread spectrum codes, such as Figure 7 As shown in the figure: randomly generate an authentication root public key and a key chain to generate a root key; continuously calculate the cryptographic hash function for the key chain to generate the root key to obtain the key chain and its authentication root key; extract the key at the corresponding position in the key chain according to the current signal time; calculate the starting position of the spread spectrum code authentication cluster and the starting position of the authentication spread spectrum code in each cycle within it according to the key; replace the spread spectrum code authentication cluster with the navigation signal spread spectrum code according to the calculated position; fill the authentication root information into the navigation message; use the replaced spread spectrum code and navigation message to modulate the navigation signal in the normal way and broadcast it to the user.
[0074] The following describes in detail the novel signal system for anti-counterfeiting authentication of civil navigation signals, namely, a civil anti-counterfeiting navigation signal system based on clustered spread spectrum code position authentication, by taking the anti-counterfeiting authentication modification of the Beidou system civil signal B1C as an example.
[0075] The technical solution of the present invention provides a new civilian anti-counterfeiting navigation signal based on random reversal of spread spectrum codes, including the following features:
[0076] The anti-counterfeiting navigation signal adopts spread spectrum BPSK, BOC or MSK modulation based on spread spectrum code modulation. Taking BPSK modulation as an example, the mathematical expression of the anti-counterfeiting navigation signal is as follows:
[0077]
[0078] in, is the signal power, It's a navigation message. After authentication and modification of the spread spectrum code, is the carrier frequency, is the initial carrier phase, j is the imaginary unit, and t is the signal time. The anti-counterfeiting information is carried on the spread spectrum code of the navigation signal and broadcast to the user together with the navigation signal.
[0079] In the spread spectrum code of the anti-counterfeiting navigation signal, the spread spectrum code is recorded at intervals of a fixed number of chips as Segmentation, within each segment, Chip or post In the periodic public spread spectrum code of the chip, it is recorded as The spreading code chip is in the processing state, and the flip spreading code is indicated by the processing instruction sequence OK, this process indicates the sequence It is a sequence of 0 and 1. The spreading code corresponding to the moment when the value is 1 is processed. Determine each spreading code is the previous Code chip or after The authentication mark sequence is a sequence with a value of ±1, and the moment with a value of +1 corresponds to the next The code chip contains the processed spread spectrum code, and the moment when the value is -1 corresponds to the previous The code chip contains the processed spread spectrum code and the spread spectrum code of the anti-counterfeiting navigation signal It can be expressed as follows: ,
[0080] in is the original public periodic spreading code, is the spreading code rate, Is the navigation certification mark sequence, is the flip indication sequence, and t represents the corresponding time in the cycle. The structure of the spread spectrum code flip is shown in the attached figure. Figure 1 shown.
[0081] Flip Indicator Sequence The authentication key and signal time are combined through a cryptographic algorithm, as shown in the following formula:
[0082]
[0083] in This is a cryptographic transformation algorithm using k as the key and t as the plaintext, with t being the signal time. The authentication mark sequence is a digital signature signal spread over a confidential spreading code. The digital signature is modulated on the spreading code using BPSK or CSK modulation methods. The digital signature signs the navigation message containing the current signal.
[0084] As attached Figure 2The figure shows the overall structure of an anti-counterfeiting authentication signal using CSK as an example. Authentication of anti-counterfeiting navigation signals is divided into cycles, with each authentication cycle containing a complete digital signature. Each digital signature is further divided into N segments based on parameter settings. Each segment determines the cyclic shift size, or initial code phase, of an authentication mark sequence cycle. Each spread spectrum code chip in the authentication mark sequence corresponds to two segments in the civilian spread spectrum code. According to the definition of the flip operator, a +1 chip in the authentication mark sequence indicates that the second of the two civilian spread spectrum code segments contains the flipped chip, while a -1 chip in the authentication mark sequence indicates that the first of the two civilian spread spectrum code segments contains the flipped chip. The position of the flipped chip is controlled by the flip mark sequence.
[0085] The basic authentication mark spreading code is used to modulate the basic periodic repeating sequence carrying the digital signature. It remains confidential to the user during the current authentication cycle in which the authentication signal is broadcast. Using the navigation message from the next authentication cycle, the user can deduce the sequence of the basic authentication mark spreading code for the current authentication cycle. The derivation relationship between the navigation message and the basic authentication mark spreading code can be achieved using a one-way function. The output of this function exhibits statistical pseudo-random properties, meeting the requirements for use as a spreading code. For example, the cryptographic hash algorithm family is an excellent one-way function with a fixed output length. This function is easy to calculate in the forward direction and produces a pseudo-random output, but the reverse calculation complexity is extremely high. The method of modulating the digital signature onto the basic authentication mark spreading code is relatively flexible, and options such as BPSK or CSK can be selected.
[0086] Attachment Figure 3The figure shows the cryptographic relationship between the digital signature and the navigation message. Digital signatures establish a trustworthy foundation for anti-counterfeiting authentication signals. Signal security and trustworthiness are protected by the verifiable nature of digital signatures. Receivers can verify that the digital signature matches the data it signs (typically the navigation message) using the public key of asymmetric cryptography. Furthermore, the characteristics of asymmetric cryptography make it virtually impossible for an attacker without access to the private key to forge data with a valid digital signature. The digital signature used in the anti-counterfeiting authentication signal is generated within the navigation satellite using a private key. The navigation message is a suitable form of digital signature. When the public key for this signature is publicly available in the ICD, the receiver can verify the authenticity of the received digital signature by checking whether it matches the navigation message, thereby ensuring the verifiability of the navigation message in the broadcast signal. Furthermore, this digital signature is carried by the corresponding spreading code of the signal, modified with an authentication flag sequence. This allows for a timing binding between the navigation message and the spreading code. Based on digital signature verification and this timing binding, joint authentication of the navigation signal message and the spreading code can be achieved. Digital signatures, serving as the trust foundation for authentication, define the authentication cycle for navigation signal authentication: the signal time range authenticated by a single digital signature. Within each authentication cycle, navigation signal authentication information is independent of each other. To ensure the security of this authentication method against generative spoofing attacks, the private key of the digital signature is stored confidentially by the satellite or GNSS operation and control segment, while the corresponding public key and verification algorithm are distributed to all users. This allows the digital signature of each authentication cycle to be trusted and verified based on the consistency of the signature with the navigation message within the authentication cycle, using the signature verification algorithm and public key. In practice, the length of the navigation message segment is typically set to an integer multiple of the frame length to enable simple synchronization of signal authentication and message demodulation.
[0087] As attached Figure 4 Figure 2 shows the typical processing architecture of a GNSS receiver with signal authentication capabilities. The fast and slow channels of an authentication receiver have different processing modes. The slow channel processing mode verifies the digital signature demodulated from fluctuations in the correlation results within the tracking loop. The fast channel processing mode verifies signal authenticity by detecting the presence of flipped chips at the expected spreading code flip locations.
[0088] In the slow channel processing mode, the receiver first captures and tracks the navigation signal, and extracts the correlation value of the punctual branch and the navigation message from the tracking channel. Before the complete navigation message of an authentication cycle is received, the receiver first caches the adjacent differential results of the punctual branch correlation value as the observation value of the authentication mark sequence. When the navigation message of an authentication cycle is completely received, the receiver calculates the authentication mark spread spectrum code of the current authentication cycle from the navigation message through the derivation algorithm of the authentication mark spread spectrum code. Subsequently, the receiver uses the authentication mark spread spectrum code of the authentication cycle and the cached authentication mark sequence observation value to perform correlation calculations, and obtains the digital signature carried therein through the CSK demodulation algorithm. Finally, the receiver uses the public key of the public asymmetric cryptographic system to verify the consistency of the navigation message and the digital signature to obtain the result of navigation signal authentication.
[0089] In fast-channel processing mode, the receiver obtains an authentication key from a data communication service and generates the spreading code flip position based on the signal time, or receives the spreading code flip position for a period of time near the current time through a data communication service. Based on these flip positions, the receiver extracts the corresponding signal sample observations from the signal samples stripped of their dynamic state via the tracking channel. The receiver then performs a correlation operation with the flipped spreading code and the extracted signal sample observations. Finally, the receiver uses the correlation result as the authentication measurement and performs the hypothesis testing process of the authentication detector to obtain a signal authenticity authentication result.
[0090] In summary, the technical solution proposed in the present invention has the following technical effects: the present invention provides a method for generating and receiving civil anti-counterfeiting navigation signals based on random flipping of spread spectrum codes, which can achieve high-reliability and high-security navigation signal authentication with moderate computational complexity and without the need for user terminal cache signal sampling. Moreover, the proportion of navigation signal authentication spread spectrum codes is small, and the impact on unauthenticated terminals is small, which plays an important guiding role in practical applications.
[0091] Please note that the technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification. The above embodiments only express several implementation methods of the present application. The description is relatively specific and detailed, but it cannot be understood as a limitation on the scope of the invention patent. It should be pointed out that for ordinary technicians in this field, without departing from the concept of this application, several variations and improvements can be made, which all fall within the scope of protection of this application. Therefore, the scope of protection of the patent in this application shall be based on the attached claims.
Claims
1. A method for generating a civilian anti-counterfeiting navigation signal based on random processing of spread spectrum codes, characterized in that: The method comprises: Step S1: randomly generate a pair of public key cryptography authentication root key pairs as the authentication basic key pairs; Step S2: Using the authentication basic key pair from step S1, a digital signature is signed for the navigation message within the period. A basic authentication spread spectrum code is obtained from the navigation message of the next period, and the digital signature is modulated onto the basic authentication spread spectrum code to obtain an authentication flag sequence. Step S3: Generate a random key as an authentication key for the current period. Using the authentication key as the key and the signal time in the current period as the seed, generate a flag indicating whether each signal chip in the public periodic spreading code in the current period has been processed, i.e., the position of all processed spreading chips in the public periodic spreading code. The specific method for determining the processing position is: In the spread spectrum code of the anti-counterfeiting navigation signal, the spread spectrum code is recorded at intervals of a fixed number of chips as Segmentation, within each segment, Chip or post In the periodic public spread spectrum code of the chip, it is recorded as The spreading code chip is in the processing state, and the flip spreading code is indicated by the processing instruction sequence OK, this process indicates the sequence It is a sequence of 0 and 1. The spreading code corresponding to the moment when the value is 1 is processed. Determine each spreading code is the previous Code chip or after The authentication mark sequence is a sequence with a value of ±1, and the moment with a value of +1 corresponds to the next The code chip contains the processed spread spectrum code, and the moment when the value is -1 corresponds to the previous The code chip contains the processed spread spectrum code and the spread spectrum code of the anti-counterfeiting navigation signal It can be expressed as follows: , in is the original public periodic spreading code, is the spreading code rate, Is the navigation certification mark sequence, is the processing instruction sequence, t represents the corresponding time in the cycle; processing instruction sequence Calculated by the following formula: , in is a sequence of values 0 or 1, A transformation method is described in which k is a key, t is a plaintext, and t is a signal time. The transformation method includes: Step S31: Accurately calculate the signal time to the chip of the spreading code, obtain the starting time of the spreading code chip, and convert the eight time parameters of year, month, day, hour, minute, second, millisecond, and intra-millisecond chip number into binary sequences of lengths not less than 16 bits, 5 bits, 6 bits, 6 bits, 7 bits, 7 bits, 10 bits, and 16 bits, respectively, and combine them into a binary sequence of length not less than 96 bits; Step S32: Based on whether the spreading code period belongs to public authentication or user-directed authentication, a 32-bit binary string is used as a signature. If the current period belongs to public authentication, the binary string uses an all-0 signature; otherwise, the 32-bit signature corresponding to the user ID is used. Step S33: Concatenate the 96-bit time sequence with the 32-bit signature to obtain 128-bit flip position generation information as block plaintext, then use the current authentication key as the key and use the block cipher algorithm to calculate 128-bit ciphertext; Step S34: Treat the 128-bit ciphertext as a decimal number. If the number is greater than ,but ,otherwise ;in is the ratio of processed chips to all spread spectrum codes; Step S35, repeating steps S31 to S34 to generate an indication of whether each spreading code within the required time range should be processed; The processing is specifically configured in different ways according to whether the anti-counterfeiting navigation signal adopts spread spectrum BPSK, BOC or MSK modulation based on spread spectrum code modulation: For BPSK modulation, the polarity of the spread spectrum code is directly flipped, that is, +1 code is changed to -1 code, and -1 code is changed to +1 code; for BOC modulation, the phase sequence of the subcarrier is adjusted by half a cycle, that is, the subcarriers in the 01 sequence are adjusted to 10, and the subcarriers in the 10 sequence are adjusted to 01; for MSK modulation, the frequency offset is cyclically shifted, that is, the original frequency shift Adjust to ,in is the flip adjustment amount, and are the lowest and highest frequencies allowed in the signal band, respectively; Step S4: Based on the authentication flag sequence obtained in step S2, within a period of the public periodic spreading code, each element of the authentication flag sequence is set to correspond to a segment of the spreading code. In the first half or the second half of the public periodic spreading code of the navigation signal, where the first half or the second half is determined by the flag corresponding to the element of the authentication flag sequence, the signal chips of the public periodic spreading code are processed based on the processing position obtained in step S3 to obtain a processed hybrid spreading code. Step S5: Use the processed hybrid spread spectrum code obtained in step S4 to combine with the navigation message and the carrier to generate a navigation signal.
2. The method for generating a civilian anti-counterfeiting navigation signal based on random processing of spread spectrum codes according to claim 1, characterized in that: In step S1, the public key cryptography system SM2 or ECDSA is used.
3. The method for generating a civilian anti-counterfeiting navigation signal based on random processing of spread spectrum codes according to claim 1, characterized in that: In step S2, the digital signature is modulated onto the basic authentication spread spectrum code in a CSK modulation mode to obtain an authentication mark sequence.
4. The method for generating a civilian anti-counterfeiting navigation signal based on random processing of spread spectrum codes according to claim 3, characterized in that: Using BPSK modulation, the mathematical expression of the anti-counterfeiting navigation signal is as follows: , in, is the signal power, It's a navigation message. After authentication and modification of the spread spectrum code, is the carrier frequency, is the initial carrier phase, j is the imaginary unit, and t is the signal time. The anti-counterfeiting information is carried on the spread spectrum code of the navigation signal and broadcast to the user together with the navigation signal.
5. A method for receiving a civilian anti-counterfeiting navigation signal based on random spread spectrum code processing, the method being used to receive a signal generated by the method for generating a civilian anti-counterfeiting navigation signal based on random spread spectrum code processing according to any one of claims 1 to 4, characterized in that: The receiving method includes two receiving processing modes: slow channel and fast channel.
6. The method for receiving civilian anti-counterfeiting navigation signals based on random spread spectrum code processing according to claim 5, characterized in that: In slow channel processing mode, the following steps are included: Step S61: The receiver captures and tracks the navigation signal, extracts the correlation value of the on-time branch and the navigation message from the tracking channel; In step S62, before receiving the complete navigation message of an authentication cycle, the receiver first caches the adjacent differential results of the on-time branch correlation values as observations of the authentication signature sequence. After receiving the complete navigation message of an authentication cycle, the receiver calculates the authentication signature spreading code for the current authentication cycle from the navigation message using the authentication signature spreading code derivation algorithm. Step S63: The receiver uses the authentication mark spreading code of the authentication period to perform correlation calculation with the cached authentication mark sequence observation, and obtains the digital signature carried therein through the CSK demodulation algorithm; In step S64, the receiver uses the public key of the asymmetric cryptographic system to verify the consistency between the navigation message and the digital signature, and obtains the result of navigation signal authentication.
7. The method for receiving civilian anti-counterfeiting navigation signals based on random spread spectrum code processing according to claim 5, characterized in that: In fast channel processing mode, the steps are as follows: Step S71: The receiver obtains the authentication key and generates a spread spectrum code processing position according to the signal time, or receives the spread spectrum code processing position in a time period near the current time; Step S72: According to the indication of the processing position of the spreading code, the receiver extracts the corresponding signal sample observation and performs a correlation operation with the processed spreading code and the signal sample observation; In step S73, the receiver uses the correlation operation result as the authentication detection quantity, performs the hypothesis testing process of the authentication detector, and obtains the result of signal credibility authentication.
Citation Information
Patent Citations
Navigation signal encryption authentication method
CN110167023A
Broadband Spread Code Authentication Using Time-Dependent Frequency Variations for GNSS
DE102020119348A1