An ADS-B Information Security Authentication and Encryption / Decryption Method
By encrypting and calculating the AA and ME fields of the ADS-B system, the problem that ADS-B system information is easily listened and interfered is solved, and high security and compatibility information transmission is realized, suitable for monitoring applications and extended data link communication in dedicated scenarios.
Patent Information
- Application Number
- CN202310838112.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-07-10
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2043-07-10
AI Technical Summary
The information transmission of ADS-B system is easily listened to and decoded, interfered and spoofed, and lacks security authentication and encryption measures, resulting in flight information leakage and false target display, limiting its use in special application scenarios.
The AA and ME fields of the ADS-B plaintext are encrypted using standard encryption algorithms, and authentication code calculation and security authentication are performed on the receiving end. ADS-B ciphertext in DF19 format is constructed, supporting customized information fields and high security transmission.
It realizes the high security and reliability of ADS-B information, is suitable for monitoring applications in dedicated scenarios, and expands the security and compatibility of data link communication.
Smart Images

Figure CN116668183B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of ADS-B information security, and particularly relates to an ADS-B information security authentication and encryption / decryption method. Background Art
[0002] ADS-B is a new surveillance technology developed in recent years. It uses the information generated by satellite-based navigation equipment and other on-board equipment as the data source, uses the 1090ES data link as the communication means, and realizes real-time ground surveillance of aircraft through the automatic external periodic broadcast of aircraft status information by the on-board terminal and the timely reception by the ground terminal; at the same time, the on-board terminal also receives the broadcast information of other aircraft to realize mutual perception between aircraft. Compared with traditional radar surveillance means, ADS-B technology has the advantages of high surveillance accuracy, fast data update, wide application range, low cost, etc., and will be used as the main means of future air surveillance.
[0003] The ADS-B system supports three data link formats: DF17, DF18, and DF19. Among them, the DF17 and DF18 formats are mainly used for civil aviation surveillance and have clear message formats; DF19 is reserved for special purposes, and some of its fields can be used for confidential surveillance and communication. The DF19 message format specification is shown in Table 1.
[0004] Table 1 DF19 Message Format
[0005]
[0006] The disadvantages of the prior art mainly lie in:
[0007] (1) ADS-B uses open technical specifications and information formats, and is extremely easy to be eavesdropped and decoded, resulting in the public exposure of flight information, which may be obtained and utilized by unauthorized parties.
[0008] (2) ADS-B uses an omnidirectional antenna to automatically broadcast externally in a public cycle, and is extremely easy to be jammed and deceived, showing false targets at the ground terminal, resulting in the ground control department obtaining a distorted traffic situation, and then issuing incorrect control command orders, causing flight disorder and even air traffic accidents.
[0009] (3) ADS-B lacks information security authentication and encryption measures, and the confidentiality of information transmission is poor, and it cannot be directly used for special purposes such as military training, which brings limitations to its role in important application scenarios. Summary of the Invention
[0010] The object of the present invention is to disclose an ADS-B information security authentication and encryption / decryption method in order to overcome the problems of the prior art. The method of the present invention enables the transmission of ADS-B surveillance information to have high security and reliability, meets the needs of aviation surveillance applications, and the method of the present invention allows for the customization of the valid information fields in the message, supporting secure communication or extended applications based on ADS-B.
[0011] The object of the present invention is achieved by the following technical solutions:
[0012] An ADS-B information security authentication and encryption / decryption method, the ADS-B information security authentication and encryption / decryption method includes message encryption processing at the transmitting end and message decryption processing at the receiving end.
[0013] Among them, the message encryption processing at the transmitting end includes the following steps:
[0014] S11: Construct an ADS-B plaintext, and assemble an ADS-B plaintext in DF19 format without a check field.
[0015] S12: Calculate the authentication code according to the key and the plaintext.
[0016] S13: Generate ciphertext, encrypt the AA and ME fields of the ADS-B plaintext using a standard encryption algorithm to obtain the ciphertext of the valid data segment.
[0017] S14: Calculate the check field PI.
[0018] S15: Assemble the ADS-B transmission ciphertext and complete the transmission through the corresponding circuit.
[0019] Among them, the message decryption processing at the receiving end includes the following steps:
[0020] S21: Receive the ADS-B ciphertext.
[0021] S22: Perform PI field verification.
[0022] S23: Decrypt the ciphertext, and decrypt the ciphertext using a standard encryption algorithm according to the synchronized time and key to generate the plaintext of the AA and ME fields.
[0023] S24: AC code security authentication, perform AC code calculation and security authentication on the plaintext.
[0024] S25: Restore the ADS-B plaintext in DF19 format.
[0025] According to a preferred embodiment, the ADS-B plaintext constructed in step S11 includes:
[0026] DF field: Downlink data link format, using DF19 format, i.e., "10011", used as the transmission identifier for dedicated ADS-B messages;
[0027] AF field: Application type, select AF = 0, i.e., "000", for the message format of dedicated ADS-B;
[0028] AC field: Security authentication code, generated by dynamically encoding the message;
[0029] AA field: Published address, storing the address code uniquely assigned to each ADS-B transmitter;
[0030] ME field: Message field, carrying ADS-B messages, supporting bit customization or definition referring to DF17 format;
[0031] PI field: Parity check or consistency field, generated by the parity check calculation of the message based on the corresponding technical standards.
[0032] According to a preferred embodiment, the DF field has a total of 5 bits, the AF field has a total of 3 bits, the AC field has a total of 8 bits, the AA field has a total of 16 bits, the ME field has a total of 56 bits, and the PI field has a total of 24 bits.
[0033] According to a preferred embodiment, step S12: Calculating the authentication code includes:
[0034] Ⅰ: Construct the ADS-B message data segment participating in the authentication code calculation; Let represent the bit concatenation symbol, data represent the 128-bit ADS-B message data segment,
[0035] Define , where , , , ;
[0036] represents the first 48 bits of the 56-bit field, represents the last 8 bits of the 56-bit field;
[0037] Ⅱ: Let the 128-bit key of the incoming device be , and perform a bitwise exclusive OR operation on and the key to obtain the 128-bit ;
[0038] Ⅲ: Construct an 8-bit feedback shift register, construct a feedback polynomial, and the period of the feedback polynomial is not less than 8, and then send into the feedback shift register;
[0039] Ⅳ: After sending all 128 bits bit by bit into the feedback shift register, the register storage state is obtained as the authentication code AC. According to a preferred embodiment, the process of encrypting the AA and ME fields of the ADS-B plaintext in step S13 includes:
[0040] Ⅰ: Construct a 128-bit initialization vector, with the synchronization time being
[0041] , , , , , representing the numbers of the 4-digit year, 2-digit month, 2-digit day, and 2-digit hour in decimal;
[0042] Construct a 40-bit time-related code , where represents converting a decimal character into the 8421 code of 4 bits;
[0043] The initialization vector is composed of the random numbers , , and shared by the sender and receiver, that is ;
[0044] Let , ~ each character represents 8-bit binary data, and all characters are arranged in sequence;
[0045] Initialize ;
[0046] Ⅱ: Calculate , , where is the encryption function based on the AES standard encryption algorithm, is the 128-bit key;
[0047] Ⅲ: ;
[0048] Ⅳ: Calculate , , where represents the left shift bit operation;
[0049] Ⅴ: If , go to step Ⅲ; if , go to step Ⅵ;
[0050] Ⅵ: Output ciphertext , encryption ends.
[0051] According to a preferred embodiment, in the ciphertext decryption process of step S23, the input data is ciphertext C, and the decryption process includes:
[0052] Ⅰ: Construct a 128-bit initialization vector by using the initialization vector construction method in step S13 , the receiving end and the transmitting end synchronize time and share the same key , and initialize ;
[0053] Ⅱ: Calculate , , where is the decryption function based on the AES standard encryption algorithm, is the 128-bit key;
[0054] Ⅲ: ;
[0055] Ⅳ: Calculate , , where represents a left shift of bit operation;
[0056] Ⅴ: If , go to step Ⅲ; if , go to step Ⅵ;
[0057] Ⅵ: Output plaintext , decryption ends.
[0058] The main solution of the present invention and its various further alternative solutions can be freely combined to form multiple solutions, all of which are solutions that can be adopted and claimed by the present invention. Those skilled in the art can understand that there are various combinations according to the prior art and common general knowledge after understanding the solution of the present invention, and all of them are the technical solutions to be protected by the present invention, and will not be enumerated here.
[0059] Advantages of the present invention:
[0060] The ADS-B information security authentication and encryption / decryption method of the present invention is easy to implement and has a high encryption security level, and is particularly suitable for surveillance applications in special scenarios; the method of the present invention can be extended to support high-security data link communication applications.
[0061] Moreover, the method of the present invention can be combined with ordinary ADS-B applications to provide a hybrid application mode that adapts to the security requirements of different scenarios, constituting a multi-mode working system with stronger compatibility and a wider application range. Description of the Drawings
[0062] Figure 1 It is a schematic flow diagram of the ADS-B information security authentication and encryption / decryption method of the present invention.
[0063] Figure 2 It is a schematic diagram of the principle of the authentication code AC calculation method in the method of the present invention.
[0064] Figure 3 It is a schematic diagram of the principle of the data encryption method in the method of the present invention. Specific implementation manners
[0065] The following uses specific specific examples to illustrate the implementation manners of the present invention. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific implementation manners. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other.
[0066] It should be noted that: similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.
[0067] Embodiment 1:
[0068] Refer to Figure 1 As shown, a kind of ADS-B information security authentication and encryption / decryption method is shown in the figure. The ADS-B information security authentication and encryption / decryption method includes message encryption processing at the transmitting end and message decryption processing at the receiving end.
[0069] Preferably, the message encryption processing at the transmitting end includes the following steps.
[0070] Step S11: Construct an ADS-B plaintext and assemble an ADS-B plaintext in DF19 format without a check field.
[0071] Preferably, the definition of the extended format of the constructed ADS-B plaintext is shown in Table 2, and the description is as follows:
[0072] DF field: Downlink data link format, using DF19 format, that is, "10011", used as the transmission identifier for dedicated ADS-B messages;
[0073] AF field: Application type, select AF = 0, that is, "000", which is the message format for dedicated ADS-B;
[0074] AC field: Security authentication code, generated by dynamically encoding the message;
[0075] AA field: Published address, storing the address code uniquely assigned to each ADS-B transmitter;
[0076] ME field: Message field, carrying ADS-B messages, supporting custom bit definitions or definitions referring to the DF17 format;
[0077] PI field: Parity check or consistency field, generated by the parity check calculation of the message based on the corresponding technical standard.
[0078] Furthermore, the DF field is 5 bits in total, the AF field is 3 bits in total, the AC field is 8 bits in total, the AA field is 16 bits in total, the ME field is 56 bits in total, and the PI field is 24 bits in total.
[0079] Table 2 ADS-B Extended Format Definition Table
[0080]
[0081] Step S12: Calculate the authentication code according to the secret key and the plaintext.
[0082] Calculating the authentication code AC is to perform data processing on part of the data in the DF19 format ADS-B message with the current encryption key to obtain the authentication code AC. The purpose of calculating the authentication code AC is to be able to authenticate the sending entity at the receiving end.
[0083] The present invention uses the feedback shift register method to calculate the authentication code, and the basic principle is as Figure 2 shown, specifically including the following steps:
[0084] Ⅰ: Construct the ADS-B message data segment participating in the authentication code calculation; let represent the bit concatenation symbol, represent the 128-bit ADS-B message data segment,
[0085] Define , where , , , , represent the first 48 bits of the 56-bit field, represent the last 8 bits of the 56-bit field.
[0086] Ⅱ: Assume the 128-bit secret key of the incoming device is , and perform a bitwise exclusive OR operation on and the secret key to obtain the 128-bit .
[0087] Ⅲ: Construct an 8-bit feedback shift register, construct a feedback polynomial, and ensure that the period of the feedback polynomial is not less than 8. Then, is fed into the feedback shift register. For example, the feedback polynomial is .
[0088] Ⅳ: After all 128 bits of are fed bit by bit into the feedback shift register, the register storage state is obtained as the authentication code AC.
[0089] Step S13: Ciphertext generation. Encrypt the AA and ME fields of the ADS-B plaintext using a standard encryption algorithm to obtain the ciphertext of the valid data segment.
[0090] The data encryption process encrypts the AA and ME fields to obtain the ciphertext. The input data is the DF19 format AA and ME field messages that have been prepared. The core algorithm uses the Advanced Encryption Standard (AES) algorithm with a high security level. The data encryption processing scheme is as Figure 3 shown. Specifically, it includes:
[0091] Ⅰ: Construct a 128-bit initialization vector. Let the synchronization time be , , , , representing the 4-digit year, 2-digit month, 2-digit day, and 2-digit hour in decimal;
[0092] Construct a 40-bit time-related code , where represents converting a decimal character into a 4-bit 8421 code;
[0093] Initialization vector is composed of the random quantities , , , and shared by the sender and receiver, that is, ;
[0094] Let , ~ each character represents 8-bit binary data, and all characters are arranged in sequence;
[0095] Initialize .
[0096] Ⅱ: Calculate , , where is the encryption function based on the AES standard encryption algorithm (AES Encryption), is a 128-bit key;
[0097] Ⅲ: .
[0098] Ⅳ: Calculate , , where represents a left shift of bit operation.
[0099] Ⅴ: If , go to step Ⅲ; if , go to step Ⅵ.
[0100] Ⅵ: Output the ciphertext , and the encryption ends.
[0101] Step S14: Calculate the check field PI.
[0102] Step S15: Assemble the ADS-B transmitted ciphertext and complete the transmission through the corresponding circuit.
[0103] Preferably, the message decryption process at the receiving end includes the following steps.
[0104] Step S21: Receive the ADS-B ciphertext.
[0105] Step S22: Perform the PI field check.
[0106] Step S23: Decrypt the ciphertext. According to the synchronized time and key, use the standard encryption algorithm to decrypt the ciphertext and generate the plaintext of the AA and ME fields.
[0107] The ADS-B message decryption is the inverse process of encryption. At this time, the input data is the ciphertext C, and the core algorithm uses the Advanced Encryption Standard (AES) algorithm with a high security level. The decryption process includes:
[0108] Ⅰ: Construct a 128-bit initialization vector using the construction method of the initialization vector in step S13 , synchronize the time between the receiving end and the transmitting end, and share the same key , and initialize ;
[0109] Ⅱ: Calculate , , where is the decryption function based on the AES standard encryption algorithm (AES Decryption), is a 128-bit key;
[0110] Ⅲ: ;
[0111] Ⅳ: Calculate , , where represents a left shift bit operation;
[0112] Ⅴ: If , go to step Ⅲ; if , go to step Ⅵ;
[0113] Ⅵ: Output the plaintext , and the decryption ends..
[0114] Step S24: AC code security authentication, perform AC code calculation and security authentication on the plaintext.
[0115] Step S25: After passing the authentication, restore the ADS-B plaintext in DF19 format.
[0116] The ADS-B information security authentication, encryption and decryption method of the present invention is easy to implement and has a high encryption security level, and is particularly suitable for surveillance applications in special scenarios; the method of the present invention can be extended to support high-security data link communication applications.
[0117] Moreover, the method of the present invention can be combined with ordinary ADS-B applications to provide a hybrid application mode that adapts to the security requirements of different scenarios, forming a multi-mode working system with stronger compatibility and a wider application range.
[0118] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. An ADS-B information security authentication and encryption / decryption method, characterized in that The ADS-B information security authentication and encryption / decryption method includes message encryption processing at the transmitting end and message decryption processing at the receiving end. Among them, the message encryption processing at the transmitting end includes the following steps: S11: Construct the ADS-B plaintext and assemble the ADS-B plaintext in DF19 format without a check field. The ADS-B plaintext constructed in step S11 includes: DF field: Downlink data link format, using DF19 format, i.e., "10011", used as the transmission identifier for dedicated ADS-B messages. AF field: Application type, select AF = 0, i.e., "000", which is the message format for dedicated ADS-B. AC field: Security authentication code, generated by dynamically encoding the message. AA field: Published address, storing the address code uniquely assigned to each ADS-B transmitting device. ME field: Message field, carrying the ADS-B message, supporting bit custom definition or definition referring to the DF17 format. PI field: Parity check or consistency field, generated by calculating the parity check of the message based on the corresponding technical standard. S12: Calculate the authentication code according to the key and the plaintext. Step S12: Calculating the authentication code includes: Ⅰ: Construct the ADS-B message data segment participating in the calculation of the authentication code; Let denote the bit concatenation symbol, denote the 128-bit ADS-B message data segment, Definition , where , , , ; Among them, represents the first 48 bits of a 56-bit field, represents the last 8 bits of a 56-bit field; Ⅱ: Let the 128-bit key of the incoming device be , and is XORed bit by bit with the key to obtain the 128-bit ; Ⅲ: Construct an 8-bit feedback shift register, construct a feedback polynomial with a period of at least 8, and then send to the feedback shift register; IV: 128 bits After all bits are sent to the feedback shift register bit by bit, the register storage state is obtained as the authentication code AC; S13: Generate the ciphertext, encrypt the AA and ME fields of the ADS-B plaintext using a standard encryption algorithm to obtain the ciphertext of the effective data segment. S14: Calculate the check field PI. S15: Assemble the ADS-B transmission ciphertext and complete the transmission through the corresponding circuit. Among them, the message decryption processing at the receiving end includes the following steps: S21: Receive the ADS-B ciphertext. S22: Perform PI field verification. S23: Decrypt the ciphertext. According to the synchronized time and key, use a standard encryption algorithm to decrypt the ciphertext and generate the plaintext of the AA and ME fields. S24: AC code security authentication, calculate the AC code and perform security authentication on the plaintext. S25: Restore the ADS-B plaintext in DF19 format.
2. The ADS-B information security authentication and encryption / decryption method according to claim 1, wherein The DF field is 5 bits in total, the AF field is 3 bits in total, the AC field is 8 bits in total, the AA field is 16 bits in total, the ME field is 56 bits in total, and the PI field is 24 bits in total.
3. The ADS-B information security authentication and encryption / decryption method according to claim 1, characterized in that The process of encrypting the AA and ME fields of the ADS-B plaintext in step S13 includes: Ⅰ: Construct a 128-bit initialization vector, and let the synchronization time be , , , , the numbers representing the 4-digit year, 2-digit month, 2-digit day, and 2-digit hour in decimal; Construct a 40-bit time-related code , where represents converting a decimal character into an 8421 code of 4 bits; Initialization vector Random quantity shared by the sender and the receiver 、 、 and constitute, that is ; Let , to Each character represents 8-bit binary data, and all characters are arranged in sequence Initialization ; Ⅱ: Calculation , , where is an encryption function based on the AES standard encryption algorithm, is a 128-bit key; Ⅲ: ; Ⅳ: Calculation , , where represents a left shift bit operation; Ⅴ: If , go to step III; if , go to step VI; Ⅵ: Output ciphertext , Encryption ends.
4. The ADS-B information security authentication and encryption / decryption method according to claim 3, wherein, In the ciphertext decryption process of step S23, the input data is the ciphertext C, and the decryption process includes: Ⅰ: Construct a 128-bit initialization vector using the initialization vector construction method in step S13 , synchronize the time at the receiving end and the transmitting end, and share the same key , initialize ; Ⅱ: Calculation , , where is a decryption function based on the AES standard encryption algorithm, is a 128-bit key; Ⅲ: ; Ⅳ: Calculation , , where represents a left shift bit operation; Ⅴ: If , go to step Ⅲ; if , go to step Ⅵ; Ⅵ: Output plaintext , decryption ends.
Citation Information
Patent Citations
Encrypted automatic dependent surveillance - broadcast ( ADS-b ) for IFF systems
IN201741044911A