A trustworthiness verification system for wireless communication
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-14
- Publication Date
- 2026-08-11
AI Technical Summary
在安全等级较高的应用场景中,单纯依赖数学密码的认证方法无法保证身份验证时的高可信性
[0051]本公开实施例中,接收方根据发送方发送的电子凭证携带的凭证发送时空戳,以及接收方接收到到电子凭证时接收方的时空信息,可以确定时空关联关系是否成立,进而确定电子凭证的可信性;其中,时空关联关系成立表征电子凭证的传播满足电磁传播特性。电磁传播特征难以物理伪造或假冒,本公开利用电磁波传播的物理难克隆属性,构建了可验证的时空关联关系,基于时空关联关系是否成立判断电子凭证的可信性,便捷高效地保证了身份验证时的高可信性。
Smart Images

Figure CN117715037B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of wireless communication technology, and in particular to a trustworthiness verification system for wireless communication. Background Technology
[0002] While providing various services to users, network information systems often employ mechanisms such as identity authentication, access control, and traffic engineering to identify and manage users in order to ensure their own security. This situation of "strong system-to-user authentication and weak user-to-system authentication" may prevent user impersonation and forgery to some extent, but when encountering system or service impersonation, users lack effective means to verify the true identity of the service provider, leading to problems such as fake base stations and GPS spoofing.
[0003] The root cause lies in the fact that the information receiver, as the passive party, has its security strategies and mechanisms dominated by the information sender. To address this issue, relevant security solutions typically employ two-way authentication methods, enabling users to verify their legitimate identity to the system, and vice versa. However, existing authentication or verification schemes often rely on cryptographic mathematical methods, which inherently involve the computational complexity of mathematical problems. Insecure authentication protocol designs can exploit vulnerabilities, allowing attackers to tamper with information to impersonate legitimate users or service providers. Furthermore, the complex interaction processes added to ensure the integrity and reliability of two-way authentication, such as the TCP / IP (Transmission Control Protocol / Internet Protocol) three-way handshake, consume significant resources. More seriously, in the event of key leakage or theft, attackers can impersonate any legitimate identity. In high-security applications, authentication methods relying solely on mathematical cryptography cannot guarantee high reliability during identity verification. Summary of the Invention
[0004] In view of the above problems, this disclosure provides a trustworthiness verification system for wireless communication to overcome or at least partially solve the above problems.
[0005] This disclosure provides a trustworthiness verification system for wireless communication, the system comprising: a sender, a receiver, and a third-party spatiotemporal attribute provider;
[0006] The sender is used to send an electronic certificate based on a time-space stamp; the electronic certificate includes: certificate payload data, certificate sending time-space stamp, and certificate signature;
[0007] The third-party spatiotemporal attribute provider is used to provide spatiotemporal information to the sender and the receiver;
[0008] The receiver is configured to determine whether a spatiotemporal correlation is established based on the time and space stamp of the electronic credential and the spatiotemporal information of the receiver when receiving the electronic credential, and to determine the credibility of the electronic credential; wherein, the establishment of the spatiotemporal correlation indicates that the propagation of the electronic credential satisfies the electromagnetic propagation characteristics.
[0009] Optionally, the electronic certificate includes: an electromagnetic map URL; the recipient is specifically used for:
[0010] If, based on the electromagnetic map, it is determined that the transmission of the electronic voucher is line-of-sight transmission, then, based on the voucher's transmission time stamp and the recipient's time-space information when the electronic voucher is received, it is determined whether the difference between the propagation speed of the electronic voucher and the speed of light is within the tolerance range of time-space accuracy.
[0011] When the difference between the propagation speed of the electronic voucher and the speed of light is within the tolerance range of the spatiotemporal accuracy, the spatiotemporal correlation is determined to be valid.
[0012] Optionally, the electronic certificate includes: an electromagnetic map URL; the recipient is specifically used for:
[0013] Based on the electromagnetic map, if it is determined that the transmission of the electronic certificate is non-line-of-sight transmission, the large-scale characteristics of electromagnetic propagation in a specific area stored in the electromagnetic map are obtained. The large-scale characteristics of electromagnetic propagation in the specific area include: the multipath delay and angle of arrival of electromagnetic propagation from the sender to the receiver.
[0014] Based on the time and space stamp of the electronic certificate and the spatiotemporal information of the receiver when the electronic certificate is received, it is determined whether the propagation of the electronic certificate satisfies the large-scale characteristics of electromagnetic propagation in the specific area.
[0015] When the propagation of the electronic credential satisfies the large-scale characteristics of electromagnetic propagation in the specific region, the spatiotemporal correlation is determined to be valid.
[0016] Optionally, if the receiver has angle resolution capability, the receiver is further configured to:
[0017] Obtain the true angle of arrival for receiving the electronic credential;
[0018] Based on the actual angle of arrival and the angle of arrival, determine whether the propagation of the electronic credential satisfies the large-scale characteristics of electromagnetic propagation in the specific area.
[0019] Optionally, the sender is specifically used for:
[0020] Upon receiving a request to send an electronic certificate, obtain the current location and current time of the sender;
[0021] Predict the voucher's voucher sending time and space stamp, which represents the sending time and location of the electronic voucher; wherein the difference between the sending time and the current time is not less than the time required to generate the electronic voucher;
[0022] Complete the data encapsulation of the electronic voucher, and send the electronic voucher at the specified sending time and location.
[0023] Optionally, the sender includes: a security module, a protocol processing module, and a spatiotemporal module; the security module has a key secure transmission interface;
[0024] The security module is used to receive credential payload data, select whether to add an electromagnetic map URL, generate a credential signature, and generate an electronic credential.
[0025] The protocol processing module is used for uplink and downlink data parsing and data processing of the spatiotemporal stamp mathematical authentication protocol;
[0026] The spatiotemporal module is used to obtain spatiotemporal information through an external spatiotemporal reference module; the spatiotemporal information is used by the security module to fill in the credential sending spatiotemporal stamp when generating the electronic credential.
[0027] Optionally, the receiver includes: a security module, a protocol processing module, and a spatiotemporal module;
[0028] The security module is used to send a time stamp and credential signature based on the electromagnetic map verification credentials.
[0029] The protocol processing module is used for uplink and downlink data parsing and data processing of the spatiotemporal stamp mathematical authentication protocol;
[0030] The spatiotemporal module is used to receive the spatiotemporal information contained in the electronic certificate and to obtain the spatiotemporal information from the navigation module.
[0031] Optionally, the receiver is specifically used for:
[0032] In cases where the scenario cannot be determined, the difference between the propagation speed of the electronic voucher and the speed of light is determined based on the voucher's transmission time stamp and the recipient's time and space information when the electronic voucher is received.
[0033] If the difference between the propagation speed of the electronic voucher and the speed of light is within the tolerance range of the spatiotemporal precision, then the spatiotemporal correlation is determined to be valid.
[0034] If the difference between the propagation speed of the electronic voucher and the speed of light is not within the tolerance range of the spatiotemporal precision, the electronic voucher shall be retained until verification is completed.
[0035] Optionally, the sender is specifically used for:
[0036] The sender receives credential payload data and a requirement for secure transmission of the credential payload data; the sender possesses a public key, which is public and known to the receiver.
[0037] Obtain the spatiotemporal attributes of the sender from the third-party spatiotemporal attribute provider, and predict the credential sending spatiotemporal stamp based on the spatiotemporal attributes of the sender;
[0038] Determine whether to add an electromagnetic map URL based on whether the current location's electromagnetic map information is known;
[0039] Generate a credential signature using your own private key and assemble the electronic credential; process the credential through a protocol and transmit it via a wireless channel;
[0040] The receiver is specifically used for:
[0041] The electronic certificate sent via the wireless channel is received through protocol processing;
[0042] Obtain the spatiotemporal attributes of the recipient from the third-party spatiotemporal attribute provider, and parse the credential parameters;
[0043] Verify the signature of the credential using the sender's public key;
[0044] If the electronic certificate includes an electromagnetic map URL, verify the credibility of the electromagnetic map URL;
[0045] Verify whether the spatiotemporal correlation holds true.
[0046] Optionally, the receiver is specifically used for:
[0047] If the verification is successful, proceed according to the instructions in the voucher payload data;
[0048] If verification fails, discard the electronic certificate;
[0049] If verification is not possible, retain the electronic certificate until verification is completed.
[0050] The embodiments disclosed herein have the following advantages:
[0051] In this embodiment, the recipient can determine whether a spatiotemporal correlation exists based on the time-space stamp of the electronic credential sent by the sender and the recipient's spatiotemporal information when the recipient receives the electronic credential, thereby determining the credibility of the electronic credential. The existence of a spatiotemporal correlation indicates that the propagation of the electronic credential satisfies the electromagnetic propagation characteristics. Electromagnetic propagation characteristics are difficult to physically forge or counterfeit. This disclosure utilizes the physically difficult-to-clone property of electromagnetic wave propagation to construct a verifiable spatiotemporal correlation. The credibility of the electronic credential is determined based on whether the spatiotemporal correlation exists, conveniently and efficiently ensuring high credibility during identity verification. Attached Figure Description
[0052] To more clearly illustrate the technical solutions of the embodiments of this disclosure, the accompanying drawings used in the description of the embodiments of this disclosure will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0053] Figure 1 This is a schematic diagram of the architecture of a wireless communication trust verification system according to an embodiment of this disclosure;
[0054] Figure 2 This is a schematic diagram of an electronic certificate in an embodiment of this disclosure;
[0055] Figure 3 This is a schematic diagram of the spatiotemporal declaration attribute credibility verification method in this embodiment of the disclosure;
[0056] Figure 4 This is a schematic diagram of the high-precision spatiotemporal certificate generation and deterministic delay issuance method in the embodiments of this disclosure;
[0057] Figure 5 This is a schematic diagram of the sender's structure in an embodiment of this disclosure;
[0058] Figure 6 This is a schematic diagram of the receiver's structure in an embodiment of this disclosure;
[0059] Figure 7 This is a flowchart of the working protocol of the wireless communication trustworthiness verification system in this embodiment of the disclosure;
[0060] Figure 8 This is an example diagram of verifying the authenticity of the spatiotemporal declaration attributes in an embodiment of this disclosure. Detailed Implementation
[0061] To make the above-mentioned objectives, features and advantages of this disclosure more apparent and understandable, the disclosure will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0062] Reference Figure 1 As shown, a schematic diagram of the architecture of a wireless communication trust verification system according to an embodiment of this disclosure is illustrated. Figure 1 As shown, the wireless communication credibility verification system includes a sender, a receiver, and a third-party spatiotemporal attribute provider; the third-party spatiotemporal attribute provider is a BeiDou signal source. The sender is mainly responsible for issuing electronic credentials, the receiver is responsible for verifying the spatiotemporal attributes declared by the sender and the credibility of the credential content of the received electronic credentials, and the third-party spatiotemporal attribute provider provides highly accurate auxiliary spatiotemporal information.
[0063] The sender is used to send an electronic certificate based on a time-space stamp; the electronic certificate includes: certificate payload data, certificate sending time-space stamp, and certificate signature;
[0064] The third-party spatiotemporal attribute provider is used to provide spatiotemporal information to the sender and the receiver;
[0065] The receiver is configured to determine whether a spatiotemporal correlation is established based on the time and space stamp of the electronic credential and the spatiotemporal information of the receiver when receiving the electronic credential, and to determine the credibility of the electronic credential; wherein, the establishment of the spatiotemporal correlation indicates that the propagation of the electronic credential satisfies the electromagnetic propagation characteristics.
[0066] The sender in this disclosure can be a system provider or a user provider; the receiver in this disclosure can be a system provider or a user provider; the third-party spatiotemporal attribute provider in this disclosure can be a BeiDou signal source or other trusted spatiotemporal attribute provider.
[0067] Figure 2 This is a schematic diagram of an electronic certificate in an embodiment of this disclosure. The electronic certificate includes certificate payload data, a certificate sending time and space stamp, and a certificate signature. Optionally, the electronic certificate also includes an electromagnetic map URL (Uniform Resource Locator). The certificate payload data is the content object to be protected by the electronic certificate; the electromagnetic map URL provides electromagnetic map information and is optional for the electronic certificate; the certificate sending time and space stamp and the certificate signature are used to ensure certificate security. The security of the electronic certificate mainly comes from two parts: verification of the reliability of the electromagnetic map and time and space stamp, and verification of the time and space declaration attributes.
[0068] Electromagnetic maps are used to reflect the electromagnetic propagation characteristics of the area where the sender and receiver are located. They can be obtained through an electromagnetic map URL provided by the sender, or through public networks and other channels. The obtained electromagnetic map URL needs to have its issuing certificate verified through a trusted list provided by a certificate authority to ensure its credibility.
[0069] The time stamp of the voucher is a time and space attribute declared by the sender when the voucher is issued (hereinafter referred to as "time and space declaration attribute"). The sender must fill in the real time and real location of the electronic voucher when generating the electronic voucher. The relevant time and space attributes are provided by a trusted third-party time and space attribute provider.
[0070] The credential signature is a signature generated using the sender's private key for the payload data, electromagnetic map URL, and spatiotemporal stamp. Upon receiving the credential, the receiver first verifies the sender's signature using mathematical methods to ensure the credibility and integrity of the electromagnetic map URL and spatiotemporal attribute parameters. For specific methods of verifying the credential signature using mathematical techniques, please refer to relevant technical documentation.
[0071] The electronic voucher adopts a mathematical-physical integration approach. On the one hand, mathematical methods can be used to verify the voucher signature to ensure the credibility and integrity of the source of the electromagnetic map URL and spatiotemporal attribute parameters. On the other hand, the physical characteristics of electromagnetic wave propagation can be used to verify the spatiotemporal declaration attributes.
[0072] In wireless communication scenarios, the two parties transmit information via electromagnetic waves, which inherently possess the characteristic that their spatiotemporal attributes are difficult to clone. Through spatiotemporal declaration attribute verification, even if an imposter obtains the user's private key and fills in valid spatiotemporal stamp information in the electronic certificate, they will still be unable to complete the spatiotemporal declaration attribute verification, thus allowing the identification and removal of the impersonating message sender.
[0073] When an electronic voucher contains an electromagnetic map URL, the recipient can obtain the electromagnetic map based on the electromagnetic map URL. By combining the electromagnetic map with the electromagnetic map, the verification of the spatiotemporal declaration attributes can be completed. Figure 3 This is a schematic diagram of the spatiotemporal declaration attribute credibility verification method in this embodiment. Based on electromagnetic map characteristics, spatiotemporal declaration attribute verification can be divided into three scenarios: line-of-sight (LoS) transmission, non-line-of-sight (NLoS) transmission, and scenarios where no distinction can be made.
[0074] The recipient can obtain the electromagnetic map based on the electromagnetic map URL included in the electronic voucher, and determine whether it is a line-of-sight transmission scenario, a non-line-of-sight transmission scenario, or an undetermined scenario based on the electromagnetic map. If the electronic voucher does not contain an electromagnetic map URL, or the obtained electromagnetic map is incomplete, or some areas lack multipath information, it is considered an undetermined scenario.
[0075] In a line-of-sight transmission scenario, the receiver determines whether the difference between the propagation speed of the electronic voucher and the speed of light is within the tolerance range of spatiotemporal accuracy based on the voucher's transmission time and spacetime stamp carried by the electronic voucher and the receiver's spatiotemporal information when the electronic voucher is received; if the difference between the propagation speed of the electronic voucher and the speed of light is within the tolerance range of spatiotemporal accuracy, the spatiotemporal correlation is determined to be established.
[0076] In line-of-sight transmission scenarios, such as Figure 3 As shown, assume the sender is in<T1,L1> Electronic vouchers are sent at a specific time, where T1 is the sender's actual time of sending the electronic voucher, and L1 is the sender's actual location at time T1. Both T1 and L1 are embedded in the electronic voucher generation process and sent along with the electronic voucher; the recipient...<T2,L2> The electronic voucher is received at time T2, where T2 is the actual time the recipient receives the electronic voucher, and L2 is the actual location of the recipient at time T2. If the recipient determines, based on the electromagnetic map, that there is a Los path between the sender and receiver, meaning the information travels along a direct path from the sender to the receiver, and since electromagnetic waves propagate at the speed of light, then the above spatiotemporal attribute parameters satisfy the following spatiotemporal correlation verification formula:
[0077] |L2-L1|=c(T2-T1);
[0078] Where c is the speed of light.
[0079] Verifying this spatiotemporal correlation is quite easy for actual communication processes, as all spatiotemporal attribute parameters are actually generated. Considering the potential for error, a tolerance range for spatiotemporal precision can be set according to actual needs. If the difference between the propagation speed of the electronic voucher and the speed of light is within this tolerance range, it is considered a genuine communication process. The accuracy of the verification hinges on this spatiotemporal precision tolerance range.
[0080] For the impersonator, assuming that the actual time and space in which they send the forged electronic credentials is [missing information]<T3,L3> Where T3 is the actual time when the forged electronic certificate is sent, and L3 is the actual location of the forger at time T3. It is also assumed that the forger has stolen the private key of the legitimate sender, which can be used to generate a signature. Subsequently, the forger wishes to impersonate the legitimate spatiotemporal declaration attributes.<T1,L1> This is then embedded into a forged electronic certificate and sent to the recipient. When the recipient receives this counterfeit message...<T2',L2'> Where T2' is the actual time the recipient receives the forged electronic credential, and L2' is the recipient's actual location at time T2'. The recipient will then extract the valid spatiotemporal declaration attributes from the electronic credential.<T1,L1> And the following relationship was verified:
[0081] |L2'-L1|≠c(T2'-T1);
[0082] The equation fails because the imposter misuses legitimate spatiotemporal declaration attributes, which cannot pass spatiotemporal correlation verification. For the imposter, the valid equation is:
[0083] |L2'-L3|=c(T2'-T3).
[0084] The recipient is unaware of the imposter's actual time and space.<T3,L3> Therefore, it would be difficult to complete the above equation verification. Unless the imposter's spatiotemporal location happens to be very close to the distance between the real sender's spatiotemporal location and the receiver's spatiotemporal location, this situation is almost impossible if the imposter does not know the receiver's actual spatiotemporal location.
[0085] In non-line-of-sight transmission scenarios, the receiver obtains the large-scale electromagnetic propagation characteristics of a specific area stored in the electromagnetic map; based on the credential transmission time stamp carried by the electronic credential and the receiver's spatiotemporal information when the electronic credential is received, it determines whether the propagation of the electronic credential satisfies the large-scale electromagnetic propagation characteristics of the specific area; if the propagation of the electronic credential satisfies the large-scale electromagnetic propagation characteristics of the specific area, it determines that the spatiotemporal correlation is established.
[0086] The verification method for spatiotemporal correlations in non-line-of-sight transmission scenarios is basically similar to that in line-of-sight transmission scenarios. The difference lies in the fact that electromagnetic waves cannot directly travel from the sender to the receiver along the direct path; they need to undergo multipath propagation, including reflection. That is, propagation delay cannot be simply verified by dividing the distance between the sender and receiver by the speed of light. Therefore, electromagnetic maps are needed to verify spatiotemporal correlations. Electromagnetic maps can store large-scale characteristics of electromagnetic propagation in a specific area, including parameters such as multipath delay and angle of arrival from the sender to the receiver, denoted as:
[0087] ;
[0088] Where X1 and X2 are the sender's and receiver's locations, respectively, and P is the large-scale parameter of the multipath channel between the sender's and receiver's locations. These represent the time delay and angle of arrival for the p-th path, arranged in descending order of time delay. If the receiver determines, based on the electromagnetic map, that there is no Loss path between the transmitter and receiver, then it is an NLoS scenario. The formula for verifying the spatiotemporal correlation in this scenario is:
[0089] ;
[0090] That is, among them, This represents the first-path delay obtained from the electromagnetic map.
[0091] If the receiving antenna has angle resolution capability, the spatiotemporal correlation can be further verified based on the angle information. Specifically, the receiver determines whether the actual angle of arrival of the received electronic certificate and the angle of arrival in the large-scale characteristics of electromagnetic propagation in a specific area are consistent. If they are consistent, the spatiotemporal correlation is established; if they are inconsistent, the spatiotemporal correlation is not established.
[0092] Similarly, if the imposter wants to impersonate a legitimate spacetime declaration property...<T1,L1> When the recipient receives the fake message, it is<T2',L2'> And the following relationship was verified:
[0093] ;
[0094] This equation is false. For the imposter, the equation that holds true is:
[0095] ;
[0096] Imposters, unaware of the recipient's location, cannot easily forge legitimate spatiotemporal attribute declarations.
[0097] If the electronic voucher does not contain an electromagnetic map URL, or the obtained electromagnetic map is incomplete, or multipath information is lacking in some areas, the scenario cannot be determined. In cases where the scenario cannot be determined, based on the voucher's transmission time stamp and the receiver's time-space information when the electronic voucher is received, it is determined whether the difference between the electronic voucher's propagation speed and the speed of light is within the tolerance range of spatiotemporal accuracy. If the difference is within the tolerance range, the spatiotemporal correlation is confirmed. If the difference is outside the tolerance range, the electronic voucher is retained until verification is complete.
[0098] If the scenario cannot be determined, first assume that the scenario is a Los scenario for verification. If the spatiotemporal correlation is established, the verification will pass, indicating that there is a Los path between the sender and receiver. If the verification fails, it is impossible to determine whether the sender is an imposter. In this case, you can continue to receive electronic credentials until the verification is completed.
[0099] Verifiable methods for spatiotemporal declaration attributes are highly sensitive to these attributes, especially time attributes. However, electronic vouchers comprise voucher payload data, voucher sending time and space stamps, electromagnetic map URLs, and voucher signatures. Each component originates from different modules or is the output of processing by different modules, and further processing requires baseband and radio frequency processing. Therefore, if... Figure 4As shown, this disclosure proposes a method for generating highly accurate spatiotemporal credentials and issuing deterministic delays to ensure the consistency between the spatiotemporal stamp in the actual sent credentials and the spatiotemporal information of the sender when sending the credentials.
[0100] When the sender receives a request to send an electronic voucher, it obtains its current location and current time; predicts the voucher's voucher sending time-space stamp, which represents the sending time and sending location of the electronic voucher; wherein the difference between the sending time and the current time is not less than the time required to generate the electronic voucher; completes the data encapsulation of the electronic voucher, and sends the electronic voucher at the sending time and sending location.
[0101] like Figure 4 As shown, in<t1,L1> In terms of time and space, the sender receives a request to send a trusted electronic credential, and the predicted time and space stamp for the electronic credential's transmission is...<t3,L3> The time interval (t3-t1) must be no less than the time required for the voucher generation process. Complete voucher data encapsulation is completed at time t2 between t1 and t3, and the system waits until the predicted time and location for voucher issuance is reached before accurately issuing the voucher.
[0102] To achieve the above operations, in addition to the necessary communication modules such as RF (radio frequency) front-end and baseband processing, the sender and receiver also need to add a time and space module, a security module, and a protocol processing module.
[0103] The sender is primarily responsible for generating and issuing electronic credentials based on time and space stamps. The sender also has a key security transmission interface, which can receive the sender's key input and realize the sender's key security storage and management, data encryption and signing, etc.
[0104] Figure 5 This is a schematic diagram of the sender's structure in an embodiment of this disclosure. For example... Figure 5 As shown, the transmitter includes a security module, a protocol processing module, a time-space module, a baseband processing module, and an RF front end.
[0105] The security module is primarily responsible for receiving credential payload data, generating credential signatures, packaging credential data packets, and adding electromagnetic map URLs based on conditions. Furthermore, the security module has a secure key transfer interface, allowing external keys to be input and used for signature generation, encryption, and other functions.
[0106] The protocol processing module is mainly responsible for the uplink and downlink data parsing and processing of the mathematical authentication protocol that integrates time and space stamps. The security module inputs the content of the electronic certificate to be sent, which is then processed by the protocol processing module and sent to the baseband processing module for subsequent actual issuance of the electronic certificate.
[0107] The spatiotemporal module can obtain more accurate spatiotemporal information through an external spatiotemporal reference module (such as the BeiDou information source), which is used for the spatiotemporal stamp field filled in when packaging electronic credentials for the security module;
[0108] The baseband processing module is a protocol processing module adapted for the generation and issuance of electronic vouchers, and is mainly responsible for caching and processing physical layer data;
[0109] The RF front-end is a radio frequency module that ensures wireless connectivity. To meet the functional and performance requirements of the transmitting device, the RF front-end must be a highly integrated front-end with higher performance and linearity.
[0110] The protocol processing module, security module (including the key secure transmission interface), and spatiotemporal module are the core processing modules for the sender of electronic credentials in the spatiotemporal declaration attribute trusted verification method. It is necessary to ensure the stability of the output results of these modules and the deterministic latency of the processing process. The RF front end and baseband processing module are data transceiver modules, which need to ensure strong real-time performance of the data reception and processing process.
[0111] As the recipient of the communication verification protocol, the recipient is mainly responsible for receiving the electronic certificate and verifying the authenticity of the spatiotemporal attributes declared by the sender of the electronic certificate, as well as the credibility of the content of the electronic certificate itself.
[0112] Figure 6 This is a schematic diagram of the receiver's structure in an embodiment of this disclosure. For example... Figure 6 As shown, the receiver includes: a security module, a protocol processing module, a spatiotemporal module, a navigation module, a baseband processing module, and an RF front end.
[0113] The security module is mainly responsible for verifying the electronic voucher's time stamp, signature, and other information based on the electromagnetic map. It ensures that the electronic voucher can only be used to perform subsequent operations after completing the time stamp declaration attribute verification, voucher signature verification, and meeting the security policy conditions.
[0114] The protocol processing module is mainly responsible for the uplink and downlink data parsing and data processing of the mathematical authentication protocol that integrates time and space stamps. The protocol processing module receives and parses the data from the baseband processing module, inputs it into the security module for authentication and verification operations, and uses it for the subsequent actual use of electronic credentials.
[0115] The spatiotemporal module is used to receive spatiotemporal information and can obtain additional time and space information from the navigation module, thereby ensuring the freshness and credibility of the spatiotemporal stamp verification of electronic vouchers;
[0116] The navigation module is responsible for obtaining high-precision spatiotemporal information from external spatiotemporal reference modules (such as BeiDou information sources);
[0117] The baseband processing module is a protocol processing module adapted for electronic credential reception and verification, mainly responsible for caching and processing physical layer data;
[0118] The RF front-end is a radio frequency module that ensures wireless connectivity. To meet the functional and performance requirements of the user terminal, the RF front-end must be a highly integrated front-end with low loss rate and higher linearity.
[0119] Among them, the security module, protocol processing module, and spatiotemporal module are the core processing modules for the recipient of electronic credentials in the spatiotemporal declaration attribute trusted verification method, and the stability of the output results of these modules needs to be guaranteed; the RF front end, baseband processing module, and navigation module are data transceiver modules, and the consistency and integrity of data reception and processing need to be guaranteed.
[0120] Figure 7 This is a flowchart of the working protocol of the wireless communication trust verification system in this embodiment of the disclosure, specifically including:
[0121] Initially: The sender receives the credential payload data and a request to securely transmit the credential payload data; the sender has a pair of public keys, where the public key is public and the receiver knows the public key;
[0122] Generate and encapsulate credentials: The sender obtains high-precision real spatiotemporal attributes from a third-party spatiotemporal provider, predicts the credential sending spatiotemporal stamp, optionally adds an electromagnetic map URL depending on whether it knows the current location electromagnetic map information, generates a credential signature using its own private key, and assembles the credential.
[0123] Sending Credentials: The sender processes the credentials according to the protocol and sends them via a wireless channel;
[0124] Receipt credentials: The receiving party processes the credentials sent from the wireless channel through the protocol.
[0125] Parse and verify credentials: The receiver obtains high-precision real spatiotemporal attributes from a third-party spatiotemporal provider, parses the credential parameters, first verifies the credential signature using the sender's public key, then verifies the trustworthiness of the electromagnetic map URL, and finally verifies the spatiotemporal attributes of the credential.
[0126] Follow-up: If the receiver successfully verifies the data, proceed with the subsequent operations according to the instructions in the credential payload data; if the receiver fails to verify the data, discard the data packet; if verification is impossible, retain the data packet until verification is complete.
[0127] The technical solution of this disclosure utilizes the physical and spatiotemporal unclonability of electromagnetic wave propagation. Based on an electromagnetic map, it designs easily verifiable spatiotemporal relationships and designs and implements a spatiotemporal declaration attribute authenticity verification system based on spatiotemporal stamps. Its beneficial effect lies in employing a mathematical-physical fusion-based trusted verification method to assist in verifying the sender's identity credibility and strengthen the assurance of the credibility of the transmitted content (i.e., credential payload data). Simultaneously, this disclosure proposes a highly accurate spatiotemporal credential generation and deterministic delay delivery method to ensure efficient spatiotemporal trusted verification within a tolerable error range. Compared with related technologies, it can effectively reduce identity fraud problems caused by design flaws in authentication protocols and potential vulnerabilities in authentication algorithms, thereby improving wireless communication security.
[0128] Optionally, as an embodiment, the technical solutions of this disclosure can be applied to, for example, Figure 8 The system shown includes a mobile base station (sender), a user terminal (receiver), and a BeiDou signal source. An unforgeable electronic credential based on a time-space stamp serves as the interaction object and verifiable carrier for both communicating parties. The mobile base station (current time-space stamp)<t1,L1> Predict the timing of electronic voucher issuance.<t3,L3> The system generates and issues electronic certificates with deterministic delays within a high-precision spatiotemporal range. The user terminal is responsible for verifying the spatiotemporal attributes declared by the sender and the credibility of the electronic certificate content. The BeiDou signal source provides highly accurate auxiliary spatiotemporal information.
[0129] User terminal<t4,L4> Upon receiving the electronic voucher, obtain the electromagnetic map using the electromagnetic map URL or other publicly available resources, and determine the communication scenario based on the electromagnetic map.
[0130] If the scenario is determined to be a Loss of Time (LoS) scenario, then verify whether the following spatiotemporal relationships hold true:
[0131] |L4-L3|=c(t4-t3);
[0132] If true, then the electronic certificate is determined to have been sent by the actual sender.
[0133] If the scenario is determined to be NLoS, then verify whether the following spatiotemporal correlation holds true:
[0134] ;
[0135] If the electromagnetic map information for the current location is incomplete, the LoS spatiotemporal correlation is used for verification. If the verification is successful, the electronic credential can be determined to have been sent by the genuine sender; otherwise, the data packet is retained until the sender and receiver complete the verification at other locations.
[0136] Assuming there are imposters (the electronic credential was sent at a specific time and location),<t5,L5> ) Forging the same legitimate spacetime declaration attribute<t3,L3> When the user terminal receives this fake message, it is<t4',L4'> Then, if the user terminal extracts the spatiotemporal attribute declaration from the electronic voucher and verifies the spatiotemporal association, it will find that:
[0137] |L4'-L3|≠c(t4'-t3);
[0138] ;
[0139] If the spatiotemporal correlation verification fails, the system can quickly and efficiently identify forged credentials and imposters, thus improving system security.
[0140] The technical solution of this disclosure is based on the physical non-clonable properties such as time and space for authentication. The verification is only considered successful when the message sender is in a specific location and at a specific time; otherwise, it is considered impersonation or forgery. This physical authentication method can effectively reduce the problem of identity impersonation caused by design flaws in the authentication protocol and potential vulnerabilities in the authentication algorithm.
[0141] The technical solution proposed in this disclosure generates a voucher sending time and space stamp by predicting the sending time and location of the voucher to be issued, and then issues the voucher at the predicted time and space. This method ensures that the voucher is issued with a deterministic delay, avoids the impact of changes in the completion time of each step in voucher generation, and ensures the consistency between the time and space stamp in the actual sent voucher and the time and space information of the sender when sending the voucher.
[0142] It should be noted that those skilled in the art should understand that the embodiments of this disclosure are not limited to the described order of actions, because according to the embodiments of this disclosure, some steps may be performed in other orders or simultaneously. Secondly, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions involved are not necessarily essential to the embodiments of this disclosure.
[0143] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.
[0144] Those skilled in the art will understand that embodiments of this disclosure can be provided as methods, apparatus, or computer program products. Therefore, embodiments of this disclosure can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, embodiments of this disclosure can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0145] This disclosure describes embodiments of methods, apparatus, electronic devices, and computer program products according to embodiments of this disclosure with reference to flowchart illustrations and / or block diagrams. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing terminal device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing terminal device, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0146] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing terminal device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0147] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal equipment, causing a series of operational steps to be performed on the computer or other programmable terminal equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable terminal equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0148] While preferred embodiments of the present disclosure have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including both the preferred embodiments and all changes and modifications falling within the scope of the present disclosure.
[0149] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or terminal device. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or terminal device that includes the element.
[0150] The above provides a detailed description of a wireless communication trust verification system. Specific examples have been used to illustrate the principles and implementation methods of this disclosure. The descriptions of the above embodiments are only for the purpose of helping to understand the methods and core ideas of this disclosure. At the same time, those skilled in the art will recognize that there will be changes in the specific implementation methods and application scope based on the ideas of this disclosure. Therefore, the content of this specification should not be construed as a limitation of this disclosure.
Claims
1. A trustworthiness verification system for wireless communication, characterized in that, The system includes: a sender, a receiver, and a third-party spatiotemporal attribute provider; The sender is used to send an electronic certificate based on a time-space stamp; the electronic certificate includes: certificate payload data, certificate sending time-space stamp and certificate signature, and an electromagnetic map URL; The third-party spatiotemporal attribute provider is used to provide spatiotemporal information to the sender and the receiver; The receiver is configured to determine whether a spatiotemporal correlation is established based on the time and space stamp of the electronic credential and the spatiotemporal information of the receiver when receiving the electronic credential, and to determine the credibility of the electronic credential; wherein, the establishment of the spatiotemporal correlation indicates that the propagation of the electronic credential satisfies the electromagnetic propagation characteristics. The receiver is also used for: If, based on the electromagnetic map, it is determined that the transmission of the electronic voucher is line-of-sight transmission, then, based on the voucher's transmission time stamp and the receiver's time-space information when the electronic voucher is received, it is determined whether the difference between the electronic voucher's propagation speed and the speed of light is within the tolerance range of time-space accuracy; if the difference between the electronic voucher's propagation speed and the speed of light is within the tolerance range of time-space accuracy, then the time-space correlation is determined to be valid. The receiver is also used for: If, based on the electromagnetic map, it is determined that the transmission of the electronic credential is non-line-of-sight transmission, the large-scale characteristics of electromagnetic propagation in a specific area stored in the electromagnetic map are obtained. These large-scale characteristics include the multipath delay and angle of arrival of electromagnetic propagation from the sender to the receiver. Based on the credential transmission time stamp carried by the electronic credential and the spatiotemporal information of the receiver when the electronic credential is received, it is determined whether the propagation of the electronic credential satisfies the large-scale characteristics of electromagnetic propagation in the specific area. If the propagation of the electronic credential satisfies the large-scale characteristics of electromagnetic propagation in the specific area, the spatiotemporal correlation is determined to be established.
2. The system according to claim 1, characterized in that, If the receiver has angle resolution capability, the receiver is further configured to: Obtain the true angle of arrival for receiving the electronic credential; Based on the actual angle of arrival and the angle of arrival, determine whether the propagation of the electronic credential satisfies the large-scale characteristics of electromagnetic propagation in the specific area.
3. The system according to claim 1, characterized in that, The sender is specifically used for: Upon receiving a request to send an electronic certificate, obtain the current location and current time of the sender; Predict the voucher's voucher sending time and space stamp, which represents the sending time and location of the electronic voucher; wherein the difference between the sending time and the current time is not less than the time required to generate the electronic voucher; Complete the data encapsulation of the electronic voucher, and send the electronic voucher at the specified sending time and location.
4. The system according to claim 1, characterized in that, The sender includes: a security module, a protocol processing module, and a spatiotemporal module; the security module has a key secure transmission interface. The security module is used to receive credential payload data, select whether to add an electromagnetic map URL, generate a credential signature, and generate an electronic credential. The protocol processing module is used for uplink and downlink data parsing and data processing of the spatiotemporal stamp mathematical authentication protocol; The spatiotemporal module is used to obtain spatiotemporal information through an external spatiotemporal reference module; the spatiotemporal information is used by the security module to fill in the credential sending spatiotemporal stamp when generating the electronic credential.
5. The system according to claim 1, characterized in that, The receiver includes: a security module, a protocol processing module, and a spatiotemporal module; The security module is used to send a time stamp and credential signature based on the electromagnetic map verification credentials. The protocol processing module is used for uplink and downlink data parsing and data processing of the spatiotemporal stamp mathematical authentication protocol; The spatiotemporal module is used to receive the spatiotemporal information contained in the electronic certificate and to obtain the spatiotemporal information from the navigation module.
6. The system according to claim 1, characterized in that, The receiver is specifically used for: In cases where the scenario cannot be determined, the difference between the propagation speed of the electronic voucher and the speed of light is determined based on the voucher's transmission time stamp and the recipient's time and space information when the electronic voucher is received. If the difference between the propagation speed of the electronic voucher and the speed of light is within the tolerance range of the spatiotemporal precision, then the spatiotemporal correlation is determined to be valid. If the difference between the propagation speed of the electronic voucher and the speed of light is not within the tolerance range of the spatiotemporal precision, the electronic voucher shall be retained until verification is completed.
7. The system according to claim 1, characterized in that, The sender is specifically used for: The sender receives credential payload data and a requirement for secure transmission of the credential payload data; the sender possesses a public key, which is public and known to the receiver. Obtain the spatiotemporal attributes of the sender from the third-party spatiotemporal attribute provider, and predict the credential sending spatiotemporal stamp based on the spatiotemporal attributes of the sender; Determine whether to add an electromagnetic map URL based on whether the current location's electromagnetic map information is known; Use your own private key to generate a certificate signature and assemble the electronic certificate; The electronic credential is transmitted via a wireless channel through protocol processing; the protocol processing involves uplink and downlink data parsing and processing using a mathematical authentication protocol that integrates time and space stamps. The receiver is specifically used for: The electronic credential sent from the wireless channel is received through protocol processing; the protocol processing involves uplink and downlink data parsing and data processing using a mathematical authentication protocol that integrates time and space stamps. Obtain the spatiotemporal attributes of the recipient from the third-party spatiotemporal attribute provider, and parse the credential parameters; Verify the signature of the credential using the sender's public key; If the electronic certificate includes an electromagnetic map URL, verify the credibility of the electromagnetic map URL; Verify whether the spatiotemporal correlation holds true.
8. The system according to claim 6, characterized in that, The receiver is specifically used for: If the verification is successful, proceed according to the instructions in the voucher payload data; If verification fails, discard the electronic certificate; If verification is not possible, retain the electronic certificate until verification is completed.
Citation Information
Patent Citations
Trusted voucher generation method, equipment, storage medium and device
CN115130084A
Equipment authentication method and terminal equipment
CN117135631A