An access method and device, an electronic device, and a storage medium

By conducting mutual pairwise authentication and session key negotiation among the three parties in the integrated space-ground network, the insecurity of the access process caused by satellite control by attackers is resolved, and secure and reliable access and data transmission between user equipment and ground stations are realized.

CN118785165BActive Publication Date: 2025-12-16CHINA TELECOM CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411035650.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-30
Publication Date
2025-12-16
Estimated Expiration
2044-07-30

AI Technical Summary

Technical Problem

In an integrated space-ground network, if a satellite is controlled by an attacker, the service data accessed to the ground station can be stolen or tampered with, making the entire access process insecure.

Method used

By conducting mutual pairwise authentication among user equipment, satellite, and ground station, and utilizing publicly available parameters provided by NCC for legal verification and session key negotiation, the security and trustworthiness among user equipment, satellite, and ground station are ensured.

Benefits of technology

It improves the security and trustworthiness of the access process without increasing communication overhead, identifies unauthorized and illegal entities, and ensures the security and efficiency of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118785165B_ABST
    Figure CN118785165B_ABST
Patent Text Reader

Abstract

The application discloses an access method and device, electronic equipment and storage medium, and relates to the technical field of communication. The method comprises the following steps: receiving a first access request from a user equipment; performing legal verification on the user equipment according to first authentication information, first identity information and second identity information in the first access request; if the user equipment is verified to be legal, sending a second access request to a ground station; wherein the second access request is related to the first access request and second authentication information of a satellite; receiving a first access request response from the ground station; wherein the first access request response is related to third authentication information of the ground station; performing legal verification on the ground station according to the third authentication information, and sending a second access request response to the user equipment when the ground station is verified to be legal; wherein the second access request response is related to the third authentication information and fourth authentication information of the satellite.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to an access method, apparatus, electronic device and storage medium. Background Technology

[0002] A space-ground integrated network refers to the integration of space-based and ground-based networks to achieve extensive network coverage and data exchange, thus forming a crucial infrastructure for efficient global communication. For example, a space-ground integrated network combines satellite communication systems in space with ground-based network infrastructure to create a large-scale, highly integrated, globally seamless heterogeneous communication network. This provides users with broader communication coverage, enabling low-overhead services such as communication, navigation, and positioning, as well as high-overhead services such as cloud computing and big data from ground stations.

[0003] Currently, in integrated space-ground networks, when user equipment needs to access a ground station via satellite to obtain its services, the satellite is generally used as a fully trusted relay node. Access is completed and the corresponding services are obtained only after mutual authentication between the user equipment and the satellite, and between the satellite and the ground station. For example, after the satellite decrypts the ground station's service data using the session key negotiated between the user equipment and the ground station, it then encrypts the service data again using the same session key and sends it to the user equipment.

[0004] However, as various satellites are gradually added to the integrated space-ground network, satellites with weak security protection are easily controlled by attackers. Therefore, when it is necessary to access a ground station based on a satellite and obtain its services, if the satellite is controlled by an attacker, it can steal or tamper with the service data of the ground station, making the entire access process insecure. Summary of the Invention

[0005] This application provides an access method, apparatus, electronic device, and storage medium to improve the security of the entire access process for user equipment.

[0006] Firstly, an access method is provided for use with a satellite, the method comprising:

[0007] Receive a first access request from a user equipment; wherein the first access request includes first authentication information of the user equipment, first identity information of the satellite, and second identity information of the ground station;

[0008] The user equipment is verified for legitimacy based on the first authentication information, the first identity information, and the second identity information.

[0009] If the user equipment is verified to be legitimate, a second access request is sent to the ground station; wherein the second access request is related to the first access request and the second authentication information of the satellite;

[0010] Receive a first access request response from the ground station; wherein the first access request response is generated by the ground station after verifying that the user equipment and the satellite are both legitimate based on the second access request, and the first access request response is related to the third authentication information of the ground station;

[0011] The ground station is validated based on the third authentication information, and a second access request response is sent to the user equipment when the ground station is validated.

[0012] Optionally, the first authentication information is related to the user key information of the user equipment provided by the NCC and the public parameters of the NCC. The first authentication information includes a first timestamp, the temporary identity information of the user equipment, a first public key, a first temporary public key, and a first authentication factor; wherein, the first timestamp is used to characterize the timestamp when the user equipment generates the first access request.

[0013] The second authentication information is related to the satellite key information of the satellite provided by the NCC and the public parameters. The second authentication information includes a second timestamp, a second authentication factor of the satellite, a second public key, and a second temporary public key; wherein, the second timestamp is used to characterize the time when the satellite generates the second access request;

[0014] The third authentication information includes a third timestamp, a third authentication factor, a fourth authentication factor, and the third public key and a third temporary public key of the ground station; wherein, the third authentication factor is an authentication factor related to the user equipment calculated by the ground station, the fourth authentication factor is an authentication factor related to the satellite calculated by the ground station, and the third timestamp is used to characterize the timestamp at which the ground station generates the first access request response;

[0015] The fourth authentication information includes the second public key, the second temporary public key, the third public key, the third temporary public key, the third timestamp, the fourth timestamp, and the fifth authentication factor; wherein, the fourth timestamp is used to characterize the timestamp at which the satellite generates the second access request response, and the fifth authentication factor is an authentication factor related to the user equipment calculated by the satellite.

[0016] Optionally, the step of verifying the legitimacy of the user equipment based on the first authentication information, the first identity information, and the second identity information includes:

[0017] When the first timestamp is verified to be valid, the first authentication hash value of the user equipment is calculated based on the first public key, and the first authentication hash factor of the user equipment is calculated based on the temporary identity information, the first temporary public key, the first timestamp, the first identity information, and the second identity information.

[0018] The user equipment is validated based on the first authentication hash value and the first authentication hash factor.

[0019] Optionally, the first authentication hash value and the first authentication hash factor respectively satisfy the following expressions:

[0020] d′ i1 =h1(ID) ncc PK i )

[0021] d′1=h1(TID i ID j ID k PK ncc ,R i ,t1)

[0022] Wherein, the d′ i1 The first authentication hash value, the PK i The first public key, the ID ncc The third identity information of the NCC is h1, which is the first hash function in the public parameters. The first hash function is related to the private key range set by the NCC.

[0023] Wherein, d′1 is the first authentication hash factor, and TID i The ID is the temporary identity information of the user equipment. j For the first identity information, the ID k The second identity information, the PK ncc The public key of the NCC, the R i t1 is the first temporary public key, and t1 is the first timestamp.

[0024] Optionally, the user equipment is deemed valid if the following equation is satisfied:

[0025] a1·P=PK i +d′ i1 ·PK ncc +d′1·R i

[0026] Wherein, a1 is the first authentication factor, P is the base point of the security elliptic curve in the public parameters, and PK... i Let d′ be the first public key. i1 The first authentication hash value, the PK ncc The public key of the NCC, d′1 is the first authentication hash factor, and R i This is the first temporary public key.

[0027] Optionally, before receiving the first access request from the user equipment, the method further includes:

[0028] Send a satellite registration request carrying a satellite identifier to the NCC; wherein the satellite registration request is used to instruct the NCC to register the satellite based on the satellite identifier;

[0029] Receive a satellite registration request response from the NCC; wherein the satellite registration request response carries the satellite key information of the satellite, as well as public parameters related to the NCC.

[0030] Optionally, the second public key is the public key in the satellite key information, the second temporary public key is calculated by the satellite based on the public parameters, and the second authentication factor is calculated by the satellite based on the public parameters, the second temporary public key, the first access request, and the second timestamp.

[0031] Optionally, the step of verifying the legitimacy of the ground station based on the third authentication information includes:

[0032] Upon verifying the validity of the third timestamp, the first session key between the satellite and the ground station is calculated;

[0033] The second authentication hash value of the ground station is calculated based on the third public key, and the second authentication hash factor of the ground station is calculated based on the first session key, the third authentication factor, and the third timestamp;

[0034] The ground station is validated based on the second authentication hash value and the second authentication hash factor.

[0035] Optionally, the ground station is deemed valid if the following equation is satisfied:

[0036] a4·P=PK k +d′ k2 ·PK ncc +d′2·R k

[0037] Wherein, a4 is the fourth authentication factor, P is the base point in the security elliptic curve represented by the public parameters, and PK... k The third public key, d′ k2 The second authentication hash value, the PK ncc The public key of the NCC, d′2 is the second authentication hash factor, and R k This is the third temporary public key.

[0038] Optionally, the first session key satisfies the following expression:

[0039] Key j-k =h5(TID) i ID j ID k PK ncc ,R i ,R j ,R k ,r j ·R k ,t1,t2,t3)

[0040] Wherein, h5 is the fifth hash function in the public parameters, and the fifth hash function is related to the session key length, TID i The ID is the temporary identity information of the user equipment. j For the first identity information, the ID k The second identity information, the PK ncc The public key of the NCC, the R i For the first temporary public key, the R j The second temporary public key for the satellite, R k For the third temporary public key, r j The session key parameter selected by the satellite within the private key range set in the public parameters, wherein t1 is the first timestamp, t2 is the timestamp for generating the second authentication information, and t3 is the third timestamp.

[0041] Optionally, the second authentication hash value and the second authentication hash factor respectively satisfy the following expressions:

[0042] d′ k2 =h1(ID) k ID ncc PK k )

[0043] d′2=h1(TID i ID j ID k PKncc ,R i ,R j ,R k Key j-k ,a3,t3)

[0044] Wherein, the d′ k2 The second authentication hash value is h1, which is the first hash function in the public parameters. The first hash function is related to the private key range set by the NCC. The ID k The ID is the second identity information. ncc The third identity information of the NCC, the PK k The third public key;

[0045] Wherein, d′2 is the second authentication hash factor, and the Key j-k The first session key is a3, and the third authentication factor is a3.

[0046] Optionally, the method further includes:

[0047] During a set time period, N third access requests are received from the user equipment; wherein the N third access requests are for requesting access to the ground station via the satellite, and N is an integer greater than 1;

[0048] When all N third access requests are verified to be valid based on their respective timestamps, N authentication hash values ​​and N authentication hash factors related to the user equipment are calculated for each of the N third access requests.

[0049] The validity of the N third-party access requests is verified based on the N authentication hash values ​​and the N authentication hash factors.

[0050] If all N third access requests are verified to be valid, then a fourth access request is generated based on the N third access requests, and each fourth access request is sent to the ground station.

[0051] Optionally, the publicly disclosed parameters of the NCC include at least:

[0052] The safety elliptic curve set by the NCC;

[0053] The range of private keys set by the NCC;

[0054] The base point in the safety elliptic curve;

[0055] The NCC uses a probability generation function, a reconstruction function, and multiple hash functions determined by biometric fuzzy technology.

[0056] Optionally, the plurality of hash functions include a first hash function related to the private key range, a second hash function related to the identity information length, a third hash function related to the security elliptic curve, a fourth hash function related to the verification information length, and a fifth hash function related to the session key length.

[0057] Secondly, an access method is provided for use with a user equipment, the method comprising:

[0058] Send a first access request to the satellite; wherein the first access request includes the first authentication information of the user equipment, the first identity information of the satellite, and the second identity information of the ground station;

[0059] When the satellite verifies that the user equipment is legitimate based on the first access request, the ground station verifies that both the user equipment and the satellite are legitimate based on the second access request sent by the satellite, and the satellite verifies that the ground station is legitimate based on the first access request response sent by the ground station, the ground station receives the second access request response sent by the satellite; wherein, the second access request is related to the first access request and the second authentication information of the satellite, and the first access request response is related to the third authentication information of the ground station;

[0060] The satellite and the ground station are validated according to the second access request response. If the satellite and the ground station are both validated, the satellite accesses the ground station. The second access request response is related to the third authentication information and the fourth authentication information of the satellite.

[0061] Optionally, the first authentication information is related to the user key information of the user equipment provided by the NCC and the public parameters of the NCC. The first authentication information includes a first timestamp, the temporary identity information of the user equipment, a first public key, a first temporary public key, and a first authentication factor; wherein, the first timestamp is used to characterize the timestamp when the user equipment generates the first access request.

[0062] The second authentication information is related to the satellite key information of the satellite provided by the NCC and the public parameters. The second authentication information includes a second timestamp, a second authentication factor of the satellite, a second public key, and a second temporary public key; wherein, the second timestamp is used to characterize the time when the satellite generates the second access request;

[0063] The third authentication information includes a third timestamp, a third authentication factor, a fourth authentication factor, and the third public key and a third temporary public key of the ground station; wherein, the third authentication factor is an authentication factor related to the user equipment calculated by the ground station, the fourth authentication factor is an authentication factor related to the satellite calculated by the ground station, and the third timestamp is used to characterize the timestamp at which the ground station generates the first access request response;

[0064] The fourth authentication information includes the second public key, the second temporary public key, the third public key, the third temporary public key, the third timestamp, the fourth timestamp, and the fifth authentication factor; wherein, the fourth timestamp is used to characterize the timestamp at which the satellite generates the second access request response, and the fifth authentication factor is an authentication factor related to the user equipment calculated by the satellite.

[0065] Optionally, before sending the first access request to the satellite, the method further includes:

[0066] Send a user registration request carrying a user identifier to the NCC; wherein the user registration request is used to instruct the NCC to register the user equipment based on the user identifier;

[0067] The system receives a user registration request response from the NCC; wherein the user registration request response carries user key information of the user equipment and public parameters related to the NCC, the user key information including the first public key and the first private key of the user equipment, and a fake user identifier assigned to the user equipment by the NCC.

[0068] Optionally, the publicly disclosed parameters of the NCC include at least:

[0069] The safety elliptic curve set by the NCC;

[0070] The range of private keys set by the NCC;

[0071] The base point in the safety elliptic curve;

[0072] The NCC uses a probability generation function, a reconstruction function, and multiple hash functions determined by biometric fuzzy technology.

[0073] Optionally, the plurality of hash functions include a first hash function related to the private key range, a second hash function related to the identity information length, a third hash function related to the security elliptic curve, a fourth hash function related to the verification information length, and a fifth hash function related to the session key length.

[0074] Optionally, the method further includes:

[0075] In response to a user operation of entering a first login password and a first biometric feature on the login / registration interface, login authentication information for the user device is generated based on the first login password, the first biometric feature, the user key information, and the public parameters.

[0076] The login authentication information includes at least the user device's private key derived value, public key derived value, fake derived value, login verification code, and biometric key public parameters.

[0077] Optionally, sending the first access request to the satellite includes:

[0078] In response to the input of a second login password and a second biometric feature on the login interface, login verification is performed based on the second login password, the second biometric feature, and the login authentication information;

[0079] When the user equipment successfully logs in, it sends the first access request to the satellite.

[0080] Optionally, the method further includes:

[0081] When the user equipment login verification is successful, in response to the user operation of entering a new login password and new biometric features on the login registration interface, the login authentication information of the user equipment is updated according to the new login password, the new biometric features, the user key information, and the public parameters;

[0082] Store the updated login authentication information.

[0083] Optionally, the second public key is the public key in the third key information, the second temporary public key is calculated by the satellite based on the public parameters, and the second authentication factor is calculated by the satellite based on the public parameters, the second temporary public key, the first access request, and the second timestamp.

[0084] Optionally, the step of performing a validity check on the satellite and the ground station based on the second access request response includes:

[0085] When both the third and fourth timestamps are verified to be valid, the second session key between the user equipment and the ground station, and the third session key between the user equipment and the satellite are calculated.

[0086] The third authentication hash value of the ground station is calculated based on the third public key, and the third authentication hash factor of the ground station is calculated based on the second session key and the third timestamp.

[0087] The fourth authentication hash value of the satellite is calculated based on the second public key, and the fourth authentication hash factor of the satellite is calculated based on the third session key and the fourth timestamp.

[0088] The satellite and the ground station are verified for legitimacy based on the third authentication hash value, the third authentication hash factor, the fourth authentication hash value, and the fourth authentication hash factor.

[0089] Optionally, if the following equation is satisfied, then both the satellite and the ground station are verified to be valid:

[0090] a5·P=PK k +PK j +(d′ k3 +d′ j4 )·PK ncc +d′3·R k +d′4·R j

[0091] Wherein, a5 is the fifth authentication factor, P is the base point in the security elliptic curve, and PK... k The third public key, the PK j The second public key, d′ k3 The third authentication hash value, d′ j4 The fourth authentication hash value, the PK ncc The public key of the NCC, d′3 is the third authentication hash factor, and R k The third temporary public key, d′4, is the fourth authentication hash factor, and R... j This is the second temporary public key.

[0092] Optionally, the second session key satisfies the following expression:

[0093] Key i-k =h5(TID) i ID j ID k PK ncc ,R i ,R j ,R k ,r k ·R i ,t1,t3)

[0094] Wherein, h5 is the fifth hash function in the public parameters, the fifth hash function is related to the session key length, and the TID i The ID is the temporary identity information of the user equipment. jFor the first identity information, the ID k The second identity information, the PK ncc The public key of the NCC, the R i For the first temporary public key, the R j The second temporary public key for the satellite, R k For the third temporary public key, r k The session key parameter selected by the ground station within the private key range set in the public parameters, wherein t1 is the first timestamp and t3 is the third timestamp.

[0095] Optionally, the third session key satisfies the following expression:

[0096] Key i-j =h5(TID) i ID j ID k PK ncc ,R i ,R j ,R k ,r i ·R j ,t1,t4)

[0097] Wherein, h5 is the fifth hash function in the public parameters, and the fifth hash function is related to the session key length, TID i The ID is the temporary identity information of the user equipment. j For the first identity information, the ID k The second identity information, the PK ncc The public key of the NCC, the R i For the first temporary public key, the r i The R is the session key parameter selected by the user equipment within the set private key range. j The second temporary public key for the satellite, R k The third temporary public key is t1, the first timestamp is t1, and the fourth timestamp is t4.

[0098] Thirdly, an access method is provided for use at a ground station, the method comprising:

[0099] Receive a second access request from a satellite; wherein the second access request is related to a first access request sent by the user equipment to the satellite and the second authentication information of the satellite, the first access request including the first authentication information of the user equipment, the first identity information of the satellite, and the second identity information of the ground station;

[0100] The satellite and the user equipment are verified for validity based on the second access request.

[0101] If both the satellite and the user equipment are verified to be legitimate, a first access request response is sent to the satellite; wherein the first access request response is related to the third authentication information of the ground station.

[0102] The first authentication information is related to the user key information of the user equipment provided by the NCC and the public parameters of the NCC. The first authentication information includes a first timestamp, the temporary identity information of the user equipment, a first public key, a first temporary public key, and a first authentication factor; wherein, the first timestamp is used to characterize the timestamp when the user equipment generates the first authentication information.

[0103] The second authentication information is related to the satellite key information of the satellite provided by the NCC and the public parameters. The second authentication information includes a second timestamp, a second authentication factor of the satellite, a second public key, and a second temporary public key; wherein, the second timestamp is used to characterize the time when the satellite generates the second authentication information.

[0104] The third authentication information includes a third timestamp, a third authentication factor, a fourth authentication factor, and the third public key and third temporary public key of the ground station; wherein, the third authentication factor is an authentication factor related to the user equipment calculated by the ground station, the fourth authentication factor is an authentication factor related to the satellite calculated by the ground station, and the third timestamp is used to characterize the timestamp at which the ground station generates the first access request response.

[0105] Optionally, before receiving the second access request from the satellite, the method further includes:

[0106] Send a ground station registration request carrying a ground station identifier to the NCC; wherein the ground station registration request is used to instruct the NCC to register the ground station based on the ground station identifier;

[0107] Receive a ground station registration request response from the NCC; wherein the ground station registration request response carries the ground station key information of the ground station, as well as public parameters related to the NCC.

[0108] Optionally, the publicly disclosed parameters of the NCC include at least:

[0109] The safety elliptic curve set by the NCC;

[0110] The range of private keys set by the NCC;

[0111] The base point in the safety elliptic curve;

[0112] The NCC uses a probability generation function, a reconstruction function, and multiple hash functions determined by biometric fuzzy technology.

[0113] Optionally, the plurality of hash functions include a first hash function related to the private key range, a second hash function related to the identity information length, a third hash function related to the security elliptic curve, a fourth hash function related to the verification information length, and a fifth hash function related to the session key length.

[0114] Optionally, the second public key is the public key in the satellite key information, the second temporary public key is calculated by the satellite based on the public parameters, and the second authentication factor is calculated by the satellite based on the public parameters, the second temporary public key, the first access request, and the second timestamp.

[0115] Optionally, the step of performing a validity check on the satellite and the user equipment based on the second access request includes:

[0116] When both the first timestamp and the second timestamp are verified to be valid, the fifth authentication hash value of the user equipment is calculated based on the first public key, and the fifth authentication hash factor of the user equipment is calculated based on the temporary identity information, the first temporary public key, the first timestamp, the first identity information, and the second identity information.

[0117] The sixth authentication hash value of the satellite is calculated based on the second public key, and the sixth authentication hash factor of the satellite is calculated based on the temporary identity information, the first temporary public key, the second temporary public key, the first identity information, the second identity information, the first timestamp, and the second timestamp.

[0118] The satellite and the user equipment are verified for legitimacy based on the fifth authentication hash value, the fifth authentication hash factor, the sixth authentication hash value, and the sixth authentication hash factor.

[0119] Optionally, if the following equation is satisfied, then both the satellite and the user equipment are verified to be valid:

[0120] a2·P=PK i +PK j +(d′ i5 +d′ j6 )·PK ncc +d′5·R i +d′6·r j

[0121] Wherein, a2 is the second authentication factor, P is the base point in the disclosed parameters representing the security elliptic curve, and PK... i The first public key, the PK j The second public key, d′ i5 The fifth authentication hash value, d′ j6 The sixth authentication hash value, the PK ncc The public key of the NCC, d′5 is the fifth authentication hash factor, d′6 is the sixth authentication hash factor, and R... i For the first temporary public key, the R j This is the second temporary public key.

[0122] Optionally, the method further includes:

[0123] During a set time period, M fourth access requests are received from the satellite; wherein the M fourth access requests are used to request access to the ground station through the satellite, and M is an integer greater than 1;

[0124] When all M fourth access requests are found to be valid based on their respective timestamps, M authentication hash values ​​and M authentication hash factors associated with the user equipment and satellite are calculated for each of the M fourth access requests.

[0125] The validity of the M fourth access requests is verified based on the M authentication hash values ​​and M authentication hash factors associated with the user equipment and the M authentication hash values ​​and M authentication hash factors associated with the satellite.

[0126] If all M fourth access requests are verified to be valid, then a second access request response is generated for each of the M fourth access requests, and each second access request response is sent to the satellite.

[0127] Fourthly, a satellite is provided, comprising:

[0128] The first receiving module is configured to receive a first access request from a user equipment; wherein the first access request includes first authentication information of the user equipment, first identity information of the satellite, and second identity information of the ground station.

[0129] The first verification module is used to perform a legality verification on the user equipment based on the first authentication information, the first identity information, and the second identity information.

[0130] The first sending module is configured to send a second access request to the ground station if the first verification module verifies that the user equipment is legitimate; wherein the second access request is related to the first access request and the second authentication information of the satellite;

[0131] The second receiving module is used to receive a first access request response from the ground station; wherein the first access request response is generated by the ground station after verifying that the user equipment and the satellite are both legitimate based on the second access request, and the first access request response is related to the third authentication information of the ground station;

[0132] The second verification module is used to perform a legality verification of the ground station based on the third authentication information;

[0133] The second sending module is used to send a second access request response to the user equipment when the second verification module verifies that the ground station is legitimate; wherein the second access request response is related to the third authentication information and the fourth authentication information of the satellite.

[0134] Fifthly, a user equipment is provided, comprising:

[0135] The transmitting module is used to send a first access request to the satellite; wherein the first access request includes the first authentication information of the user equipment, the first identity information of the satellite, and the second identity information of the ground station;

[0136] The receiving module is configured to receive a second access request response sent by the satellite when the satellite verifies the user equipment as legitimate based on the first access request, the ground station verifies the user equipment and the satellite as legitimate based on the second access request sent by the satellite, and the satellite verifies the ground station as legitimate based on the first access request response sent by the ground station; wherein the second access request is related to the first access request and the second authentication information of the satellite, and the first access request response is related to the third authentication information of the ground station;

[0137] The verification module is used to perform legality verification on the satellite and the ground station according to the second access request response, and to access the ground station through the satellite when both the satellite and the ground station are verified to be legal; wherein the second access request response is related to the third authentication information and the fourth authentication information of the satellite.

[0138] Sixthly, a ground station is provided, comprising:

[0139] A receiving module is configured to receive a second access request from a satellite; wherein the second access request is related to a first access request sent by the user equipment to the satellite and the second authentication information of the satellite, and the first access request includes the first authentication information of the user equipment, the first identity information of the satellite, and the second identity information of the ground station;

[0140] The verification module is used to perform a validity verification on the satellite and the user equipment based on the second access request;

[0141] The sending module is configured to send a first access request response to the satellite if the verification module verifies that both the satellite and the user equipment are legitimate; wherein the first access request response is related to the third authentication information of the ground station.

[0142] Seventhly, an access system is provided, including a satellite, user equipment, and a ground station;

[0143] The satellite is used to perform the method as described in any one of the first aspects;

[0144] The user equipment is used to perform the method as described in any one of the second aspects;

[0145] The ground station is used to perform the method as described in any one of the third aspects.

[0146] Eighthly, an electronic device is provided, comprising:

[0147] A memory for storing computer programs; a processor for executing the computer programs stored in the memory to implement the method steps described in any one of the first aspects.

[0148] Ninth aspect, a computer-readable storage medium is provided, wherein a computer program is stored therein, and when executed by a processor, the computer program implements the method steps described in any one of the first aspects.

[0149] In this embodiment of the application, the beneficial effects during the entire process of user equipment accessing the ground station via satellite are as follows:

[0150] First, since the satellite can verify the legitimacy of the user equipment based on the parameters included in the first access request, and the ground station can verify the legitimacy of the user equipment and the satellite based on the parameters included in the second access request, and the satellite can also verify the legitimacy of the ground station based on the parameters included in the first access request response, and the user equipment can verify the legitimacy of the ground station and the satellite based on the parameters included in the second access request response, it is possible to achieve mutual pairwise authentication between the user equipment, the satellite, and the ground station without increasing additional communication overhead (such as without the involvement of the NCC), thereby improving authentication efficiency. In addition, it can not only identify unauthorized satellites and ground stations, but also reject unauthorized users, ensuring the credibility and security of users accessing the ground station service across satellites, and also improving the security of the entire access process for the user equipment.

[0151] Secondly, by adopting the above-mentioned three-party mutual pairwise authentication mechanism, untrusted satellites can be effectively identified. Compared with the traditional authentication mechanism, which only treats satellite nodes as transparent and completely trustworthy nodes, the trustworthiness of satellites can be further confirmed, and untrusted, unauthorized satellites in heterogeneous networks can be prevented from providing relay services to users and ground stations.

[0152] Furthermore, based on the publicly available parameters provided by the NCC, the entire access process can achieve joint negotiation of session keys between any two nodes among the user equipment, satellite, and ground station without the involvement of the NCC. After access authentication is completed, any two nodes among the user equipment, satellite, and ground station can use their own independent session keys for secure transmission. This also ensures that the temporary public key required for the session key cannot be tampered with or replaced by an unauthorized satellite, further ensuring the trustworthiness and security of users accessing the ground station via satellite, and improving the efficiency and security of data transmission.

[0153] For the various aspects from the second to the ninth aspect mentioned above, and the technical effects that each aspect may achieve, please refer to the above description of the technical effects that can be achieved for the first aspect or the various possible solutions in the first aspect, which will not be repeated here. Attached Figure Description

[0154] Figure 1 An exemplary diagram illustrates an application scenario applicable to the embodiments of this application;

[0155] Figure 2 An exemplary illustration shows a signaling interaction diagram of an NCC registering a user equipment, provided in an embodiment of this application.

[0156] Figure 3 An exemplary illustration shows a signaling interaction diagram of NCC during satellite registration, provided in an embodiment of this application.

[0157] Figure 4An exemplary illustration shows a signaling interaction diagram for ground station registration provided in an embodiment of this application;

[0158] Figure 5 An exemplary flowchart illustrates a satellite-side access method provided in an embodiment of this application;

[0159] Figure 6 An exemplary flowchart illustrates an access method on the user equipment side provided in an embodiment of this application;

[0160] Figure 7 An exemplary flowchart illustrates an access method at a ground station provided in an embodiment of this application;

[0161] Figure 8 An exemplary diagram illustrates the signaling interaction of an access method provided in an embodiment of this application;

[0162] Figure 9 An exemplary schematic diagram of a satellite structure provided in an embodiment of this application is shown;

[0163] Figure 10 An exemplary schematic diagram of a user equipment provided in an embodiment of this application is shown;

[0164] Figure 11 An exemplary schematic diagram of a ground station provided in an embodiment of this application is shown;

[0165] Figure 12 An exemplary schematic diagram of an electronic device provided in an embodiment of this application is shown. Detailed Implementation

[0166] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. The specific operational methods in the method embodiments can also be applied to the device embodiments or system embodiments. It should be noted that in the description of this application, "multiple" is understood as "at least two". "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. A connected to B can represent: A and B directly connected, and A and B connected through C. Furthermore, in the description of this application, terms such as "first" and "second" are used only for distinguishing the purpose of description and should not be construed as indicating or implying relative importance or order.

[0167] To better understand the embodiments of this application, the technical terms involved in the embodiments of this application will be explained below.

[0168] (1) Elliptic curve cryptography (ECC) is a public-key cryptosystem whose main advantage is that in some cases it uses a smaller key than other methods (such as asymmetric cryptography) to provide a comparable or higher level of security.

[0169] (2) User Equipment (UE) is a device that can provide voice and / or data connectivity to users, including: handheld terminal devices with wireless connectivity, vehicle-mounted terminal devices, etc. For example, terminals include, but are not limited to: mobile phones, tablets, laptops, PDAs, mobile internet devices (MIDs), wearable devices, virtual reality (VR) devices, augmented reality (AR) devices, wireless terminal devices in industrial control, wireless terminal devices in autonomous driving, wireless terminal devices in smart grids, wireless terminal devices in transportation safety, wireless terminal devices in smart cities, or wireless terminal devices in smart homes, etc.

[0170] The following is a brief introduction to the application scenarios to which the technical solutions of the embodiments of this application are applicable. It should be noted that the application scenarios described below are only for illustrating the embodiments of this application and are not intended to limit the scope. In specific implementation, the technical solutions provided by the embodiments of this application can be flexibly applied according to actual needs.

[0171] Figure 1 The illustration shows an application scenario applicable to the embodiments of this application. Figure 1 As shown, this scenario includes user equipment 101, satellite 102, and ground station (GS) 103, all connected to the network control center (NCC) 100. It should be noted that in real-world applications, the number of user equipment, satellites, and ground stations can be greater. Figure 1 The relevant description will be based solely on user equipment 101, satellite 102, and ground station 103.

[0172] As a trusted manager in the integrated space-ground network, NCC 100 is responsible for the operation, maintenance, control, and management of the network. For example, NCC 100 can generate the system's NCC key information and public parameters, and can register user equipment 101, satellite 102, and ground station 103 respectively, thereby assigning them corresponding key information and other parameters.

[0173] Optionally, during the initialization phase, the NCC 100 generates the system's NCC key information and public parameters, which may include the following procedures:

[0174] First, an elliptic cryptography algorithm is used to select the secure elliptic curve for the system. For example, E p (a,b):y 2 =x 3 +ax+bmod p; where a,b∈F p (F p (representing the range of private keys), and 4a 3 +27b 2 mod P≠0, where P is based on E p (a,b) is a chosen base point.

[0175] Secondly, biometric fuzzy technology is used to extract the system's probability generation function Gen(·), reconstruction function Rep(·), and multiple hash functions. Furthermore, among the multiple hash functions is a first hash function (h1:{0,1}) related to the private key range. * →F p The second hash function related to the length of the identity information. Where l1 is the identity length), and the third hash function related to the secure elliptic curve (h3:{0,1}) * →E p(a,b) The fourth hash function related to the length of the verification information. Where l2 is the verification code length, and the fifth hash function is related to the session key length. Where l3 is the session key length).

[0176] Then, within the private key range (F) p Randomly select a system's private key (s) within ) ncc ), and based on this s ncc Calculate the system's public key (e.g., PK). ncc =s ncc ·P).

[0177] Finally, the s ncc Store and publish the above public parameters (pparams = {E p (a,b),F p ,P,Gen(·),Rep(·),h1,h2,h3,h4,h5}) etc.

[0178] Optionally, during the registration phase, NCC100 can register user equipment 101, satellite 102, and ground station 103 separately, thereby facilitating the deployment of each node within the space-air integrated network. The following example illustrates this. Figure 2 , Figure 3 , Figure 4 Each will be explained separately.

[0179] Figure 2 An exemplary illustration is shown in the signaling interaction diagram of an NCC registering a user equipment, provided in an embodiment of this application.

[0180] 201: User equipment sends a message to the NCC carrying the user identifier (ID) i User registration request.

[0181] In this step, the user equipment can be Figure 1 The user equipment 101 and NCC shown can be Figure 1 As shown in NCC100, the user registration request is used to instruct the NCC to register the user equipment based on the user identifier.

[0182] 202: Upon receiving a user registration request, the NCC assigns a fake user identifier (PID) to the user equipment that is not related to the user equipment. i Within the scope of the private key, randomly select one as the private key parameter (s) for the user equipment. i ).

[0183] In other embodiments, the NCC may also search the database based on the user identifier to determine whether the user equipment has been registered before. If not, the 202 procedure is executed; if so, other operations may be performed based on the user equipment's historical registration records.

[0184] In this embodiment of the application, in order to improve the user identity privacy protection mechanism, by assigning fake user identifiers to user equipment and implementing mask XOR processing to prevent such errors, the user's real identity can be effectively protected from being leaked. Furthermore, in the subsequent access authentication process, even legitimate but semi-honest satellites cannot track the user, thus enhancing user privacy.

[0185] 203: NCC based on this s i Calculate the first public key and the first private key of the user equipment, and use the first public key, the first private key, and the fake user identifier as the user key information of the user equipment.

[0186] Optionally, the first public key and the first private key satisfy the following expressions respectively:

[0187] PK i =s i ·P…(1)

[0188] sk i =s i +d i ·s ncc di =h1(ID) ncc PK i (2)

[0189] Among them, PK i Let P be the first public key of the user equipment, and let sk be the base point in the security elliptic curve. i This is the first private key for the user equipment, the d i The authentication hash value of the user equipment calculated for the NCC, this ID ncc This refers to the NCC's identity information (i.e., the third-party identity information referred to below).

[0190] 204: The NCC sends a user registration request response to the user equipment, which carries the user's key information and public parameters.

[0191] In other embodiments, the NCC may also assign a user identifier (ID) associated with the user equipment. i ), fake user identifier (PID) i First public key (PK) i Store them for easy access and management later.

[0192] In other embodiments, after receiving a user registration response from the NCC, the user equipment may also respond by entering a first login password (PW) on the login / registration interface. i ), first biological characteristic (BIO) i The system processes user operations and generates login authentication information for the user device based on the first login password, the first biometric feature, the user key information, and public parameters; wherein the login authentication information includes at least the user device's private key derivation value (DSK). i ), Public key derived value (DPK) i ), spurious derived value (DPID) i ), login verification code (ver) i ), Biometric key public parameters (v i ).

[0193] Optional, Gen(BIO i )=(σ i ,v i Gen(BIO) i )=(σ i ,v i ),ver i =h4(DSK) i ,DPID i DPK i ,v i ,sk i,PID i PK i ), where σ i For biometric keys, RPW i This is a biometric verification factor for passwords.

[0194] Figure 3 An exemplary diagram illustrating the signaling interaction during NCC satellite registration provided in this application is shown.

[0195] 301: The satellite sends a satellite identifier (ID) to the NCC. j ( ) satellite registration request.

[0196] In this step, the satellite can be Figure 1 As shown in 102, NCC can be Figure 1 The NCC100 shown is a satellite registration request used to instruct the NCC to register the satellite based on the satellite identifier.

[0197] 302: Upon receiving the satellite registration request, the NCC will randomly select a private key parameter (s) for the satellite within the specified range. j ).

[0198] In other embodiments, the NCC may also search the database based on the satellite identifier to determine whether the satellite has been registered before. If not, the 302 procedure is executed; if so, other operations may be performed based on the satellite's historical registration records.

[0199] 303: NCC based on this s j Calculate the second public key and the second private key of the satellite, and use the second public key and the second private key as the satellite key information of the satellite.

[0200] PK j =s j ·P…(3)

[0201] sk j =s j +d j ·s ncc d j =h1(ID) j ID ncc PK j (4)

[0202] Among them, PK j This is the second public key for the satellite, where P is the base point in the secure elliptic curve, and sk... j This is the second private key for the satellite, d j The authentication hash value of the satellite calculated for the NCC, this ID nccThis refers to the NCC's identity information (i.e., the third-party identity information referred to below).

[0203] 304: The NCC sends a satellite registration request response to the satellite, which carries the satellite key information and the aforementioned publicly available parameters.

[0204] In other implementations, the NCC may also assign a satellite identifier (ID) to the satellite. j Second public key (PK) j Store them for easy access and management later.

[0205] Figure 4 An exemplary diagram illustrates a signaling interaction diagram of an NCC registering a ground station, as provided in this application.

[0206] 401: The ground station sends a message to the NCC carrying the ground station identifier (ID). k ) ground station registration request.

[0207] In this step, the ground station can be Figure 1 The 103 shown, NCC can be Figure 1 The NCC100 shown is a ground station registration request used to instruct the NCC to register the ground station based on the ground station identifier.

[0208] 402: After receiving the ground station registration request, the NCC randomly selects a private key parameter (s) for the ground station within the range of private keys. k ).

[0209] In other embodiments, the NCC may also search the database based on the ground station identifier to determine whether the ground station has been registered before. If not, the 402 error is executed; if so, other operations can be performed based on the ground station's historical registration records.

[0210] 403: NCC based on this s k Calculate the third public key and third private key of the ground station, and use the third public key and third private key as the ground station key information of the ground station.

[0211] PK k =s k ·P…(5)

[0212] sk k =s k +d k ·s ncc d k =h1(ID) k ID ncc PK k )…(6)

[0213] Among them, PK k This is the third public key for the ground station, where p is the base point in the secure elliptic curve, and sk is... k This is the third private key for the ground station, d k The authentication hash value of the ground station calculated for the NCC, this ID ncc This refers to the NCC's identity information (i.e., the third-party identity information referred to below).

[0214] 404: The NCC sends a ground station registration request response to the ground station, which carries the ground station's key information and the aforementioned public parameters.

[0215] During the registration phase described above, when the NCC registers user equipment, satellites, and ground stations separately, the registration interaction can be conducted through a secure channel, thereby avoiding malicious attacks.

[0216] User equipment 101 has the ability to communicate with satellite 102, and can request access to ground station 103 through satellite 102 and obtain corresponding services.

[0217] Satellite 102 can establish connections between users and ground stations via a space segment access point that operates according to a predetermined satellite orbit.

[0218] Ground station 103, as a node providing terrestrial network services to users, can provide broadband, communication, augmented reality (AR) and other services to users through the satellite-to-ground link.

[0219] In this embodiment of the application, based on the above scenario, when a user requests access to a ground station via satellite and obtains corresponding services, the user equipment, satellite, and ground station must perform mutual authentication between each other (i.e., three-way mutual authentication) to avoid being impersonated by unauthorized satellites and unauthorized ground stations when the user accesses the ground station, and also to prevent fake users from obtaining services from legitimate satellites and ground stations.

[0220] To further illustrate the technical solutions provided in the embodiments of this application, a detailed description is provided below in conjunction with the accompanying drawings and specific implementation methods. Although the embodiments of this application provide method operation steps as shown in the following embodiments or drawings, the method may include more or fewer operation steps based on conventional or non-inventive methods. In steps where there is no logically necessary causal relationship, the execution order of these steps is not limited to the execution order provided in the embodiments of this application. In actual processing or when the device executes the method, it may be executed in the order shown in the embodiments or drawings, or in combination.

[0221] Figure 5 A flowchart illustrating an embodiment of the satellite-side access method provided in this application is shown as an example. This process can be... Figure 1 The satellite 102 shown is designed to enhance the security of the entire user equipment access process. For example... Figure 5 As shown, the process includes the following steps:

[0222] 501: Received the first access request from the user equipment.

[0223] The user equipment can be Figure 1 The user equipment 101 shown here includes the user equipment's first authentication information and the satellite's first identity information (such as ID). j ), and the ground station's secondary identity information (such as ID). k ).

[0224] Optionally, the first authentication information is related to the user key information of the user equipment provided by the NCC and the public parameters of the NCC. The first authentication information may include a first timestamp (t1) and the temporary identity information (TID) of the user equipment. i First public key (PK) i ), first temporary public key (R) i ), and the first authentication factor (a1); wherein, the first timestamp is used to characterize the timestamp when the user equipment generates the first access request.

[0225] In other embodiments, before receiving the first access request from the user equipment, the satellite may first register with the NCC to enable subsequent access authentication with the user equipment and ground station without the NCC's involvement. The specific registration process can be referred to the above. Figure 3 The relevant descriptions will not be repeated here.

[0226] 502: The user device is legally verified based on the first authentication information, the first identity information, and the second identity information mentioned above.

[0227] Optionally, the validity verification of the user equipment can be performed as follows: upon verification that the first timestamp is valid, the first authentication hash value (d′) of the user equipment is calculated based on the first public key. i1 The system calculates the first authentication hash factor (d′1) of the user equipment based on the temporary identity information, the first temporary public key, the first timestamp, the first identity information, and the second identity information; then, it performs a valid verification of the user equipment based on the first authentication hash value and the first authentication hash factor.

[0228] Optionally, the first authentication hash value satisfies the following expression:

[0229] d′ i1 =h1(ID) ncc PK i )…(7)

[0230] Where, d′ i1 The first authentication hash value for the user equipment calculated for this satellite; the meanings of other characters can be found in the formula (2) above.

[0231] Optionally, the first authentication hash factor satisfies the following expression:

[0232] d′1=h1(TID i ID j ID k PK ncc ,P i ,t1)……(8)

[0233] Where d′1 is the first authentication hash factor of the user equipment calculated by the satellite, ITD i For temporary identity information calculated by user equipment based on a fake user identifier, ID j As the primary identity information, ID k For secondary identity information, PK ncc R is the public key of the NCC. i The first temporary public key is calculated for the user equipment, and t1 is the first timestamp.

[0234] In other embodiments, determining whether the first timestamp is valid can be done by: if the difference between the first timestamp and the current timestamp is less than or equal to an acceptable time difference range, then the first timestamp is considered active and valid; otherwise, the first timestamp is considered invalid and subsequent access authentication is terminated.

[0235] 503: If the user equipment is found to be legitimate, a second access request is sent to the ground station.

[0236] Optionally, the user equipment is deemed valid if the following equation is satisfied:

[0237] a1·P=PK i +d′ i1 ·PK ncc +d′1·R i …(9)

[0238] Where a1 is the first authentication factor calculated by the user equipment, P is the base point of the security elliptic curve in the public parameters, and PK i d′ is the first public key. i1 PK is the first authentication hash value. ncc d is the NCC's public key, d′1 is the first authentication hash factor, and R is the public key of the NCC. i This is the first temporary public key.

[0239] Optionally, if the above equation is not satisfied, it indicates that the user equipment is illegitimate, the satellite will refuse access to the user equipment, and terminate subsequent authentication.

[0240] Optionally, the second access request is related to the first access request and the satellite's second authentication information. The second authentication information may include a second timestamp, the satellite's second authentication factor, a second public key, and a second temporary public key. The second timestamp is used to characterize the time when the satellite generated the second access request, and the second authentication information is related to the satellite key information and the aforementioned public parameters.

[0241] Furthermore, the second public key is the public key in the satellite key information, the second temporary public key is calculated by the satellite based on the public parameters, and the second authentication factor is calculated by the satellite based on the public parameters, the second temporary public key, the first access request, and the second timestamp.

[0242] For example, after verifying the legitimacy of the user equipment, the satellite accesses it from the private key range (F... p Randomly select one parameter from the parameters (r) as the satellite's session key parameter. j According to r j Calculate the satellite's second temporary public key (e.g., R). j =r j ·P); Then, the satellite calculates the satellite's second authentication factor based on the public parameters, the second temporary public key, the first access request, and the second timestamp.

[0243] Optionally, the second authentication factor satisfies the following expression:

[0244] a2=a1+s j +d2·r j d2 = h1(TID) i ID j ID k PK ncc ,R i ,R j ,t1,t2)…(10)

[0245] Here, d2 is the satellite's self-authentication hash factor, and the meanings of the other characters can be found in the explanation of the previous expression, which will not be repeated here.

[0246] 504: Received the first access request response from the ground station.

[0247] In this step, the first access request response is generated by the ground station after verifying that both the user equipment and the satellite are legitimate based on the second access request. This first access request response is related to the third authentication information of the ground station.

[0248] Optionally, the third authentication information includes a third timestamp, a third authentication factor, a fourth authentication factor, and a third public key and a third temporary public key of the ground station; wherein, the third authentication factor is an authentication factor related to the user equipment calculated by the ground station, the fourth authentication factor is an authentication factor related to the satellite calculated by the ground station, and the third timestamp is used to characterize the timestamp at which the ground station generates the first access request response.

[0249] 505: Verify the legitimacy of the ground station based on the aforementioned third authentication information, and send a second access request response to the user equipment when the ground station is verified to be legitimate.

[0250] In this step, the second access request response is related to the third authentication information and the fourth authentication information of the satellite, which facilitates the user equipment to perform legal verification on the ground station and the satellite based on the second access request response, so as to ensure the security and integrity of the entire access process.

[0251] Optionally, the ground station may perform a validity verification by: first, calculating the first session key between the satellite and the ground station when the third timestamp is verified to be valid; then, calculating the second authentication hash value of the ground station based on the third public key, and calculating the second authentication hash factor of the ground station based on the first session key, the third authentication factor, and the third timestamp; and performing a validity verification of the ground station based on the second authentication hash value and the second authentication hash factor.

[0252] Optionally, verifying the validity of the third timestamp can be done in a similar way to verifying the validity of the first timestamp, and will not be described again here.

[0253] Optionally, if the following equation holds true, the ground station is considered valid:

[0254] a4·P=PK k +d′ k2 ·PK ncc +d′2·R k ……(11)

[0255] Where a4 is the fourth certification factor, P is the base point in the publicly disclosed parameters representing the security elliptic curve, and PK k For the third public key, d′ k2 PK is the second authentication hash value. ncc d is the NCC's public key, d′2 is the second authentication hash factor, and R is the public key of the NCC. k This is the third temporary public key.

[0256] Optional, the first session key satisfies the following expression:

[0257] Key j-k =h5(TID) i IDj ID k PK ncc ,R i ,R j ,R k ,r j ·R k ,t1,t2,t3)………(12)

[0258] Among them, Key j-k t3 is the first session key, t3 is the third timestamp, and the meanings of the other characters can be found in the explanation of the previous expressions, which will not be repeated here.

[0259] Optionally, the second authentication hash value and the second authentication hash factor shall satisfy the following expressions respectively:

[0260] d′ k2 =h1(ID) k ID ncc PK k )…(13)

[0261] d′4=h1(TID i ID j ID k PK ncc ,R i ,R j ,R k Key j-k ,a3,t3)…(14)

[0262] Where, d′ k2 d′2 is the second authentication hash value, a3 is the second authentication hash factor, and the meaning of other characters can be found in the explanation of the previous expression, which will not be repeated here.

[0263] In this embodiment, the satellite verifies the legitimacy of the ground station using the above formula (11). If the equation is true, the satellite confirms the legitimacy of the ground station, the correctness of the first session key negotiated with the ground station, and the integrity of the first access request response. If the equation is false, it indicates that the ground station is an illegitimate ground station of the system, or that the first access request response has been tampered with or forged during transmission of the satellite-ground link between the satellite and the ground station. The satellite then refuses the ground station access and terminates subsequent authentication.

[0264] Optionally, the fourth authentication information may include a second public key, a second temporary public key, a third public key, a third temporary public key, a third timestamp, a fourth timestamp, and a fifth authentication factor; wherein the fourth timestamp is used to characterize the timestamp at which the satellite generates the second access request response, and the fifth authentication factor is an authentication factor related to the user equipment calculated by the satellite.

[0265] Optional, the fifth authentication factor, satisfies the following expression:

[0266] a5 = a3 + s j +d5·r j …(15)

[0267] d5 = h1(TID) i ID j ID k PK ncc ,R i ,R j ,R k Key j-i ,t4)……(16)

[0268] Key j-i =h5(TID) i ID j ID k PK ncc ,R i ,R j ,R k ,r j ·R i ,t1,t4)…(17)

[0269] Among them, the Key j-i This is the session key related to the user equipment calculated by the satellite. The meanings of other characters can be found in the explanation of the expressions above, and will not be repeated here.

[0270] In other embodiments, when the satellite receives N third-party access requests from user equipment within a set time period, it can also implement a multi-level efficient batch verification mechanism, enabling the satellite to efficiently process a large number of access requests from user equipment and reducing the satellite resources required to verify a large number of access requests. The specific process is as follows:

[0271] First, within a set time period, N third access requests are received from the user equipment; wherein, the N third access requests are used to request access to the ground station through the satellite, and N is an integer greater than 1.

[0272] Secondly, after verifying that all N third access requests are valid based on their respective timestamps, the system calculates N authentication hash values ​​and N authentication hash factors related to the user equipment for each of the N third access requests.

[0273] Furthermore, the validity of N third-party access requests is verified based on N authentication hash values ​​and N authentication hash factors.

[0274] Finally, if all N third access requests are found to be valid, then a fourth access request is generated based on the N third access requests, and each fourth access request is sent to the ground station.

[0275] For example, suppose there are N third-party access requests, AARs = {AAR1, AAR2, ..., AAR...} N}, where AAR i ={TID i ID j ID k PK i ,R i ,a i,1 ,t i,1 First, for each third-party access request, check the timestamp t. i,1 Validity; then, for each third access request, calculate its respective authentication hash value d′. in =h1(ID) ncc PK i ), authentication hash factor d′ in,1 =h1(TID i ID j ID k PK ncc ,R i ,t i,1 If satisfied; The satellite then confirms that all AARs are legitimate access requests, and that none of the N third access requests have been tampered with in the satellite-to-ground link.

[0276] In this embodiment of the application, the beneficial effects during the entire process of user equipment accessing the ground station via satellite are as follows:

[0277] First, since the satellite can verify the legitimacy of the user equipment based on the parameters included in the first access request, and the ground station can verify the legitimacy of the user equipment and the satellite based on the parameters included in the second access request, and the satellite can also verify the legitimacy of the ground station based on the parameters included in the first access request response, and the user equipment can verify the legitimacy of the ground station and the satellite based on the parameters included in the second access request response, it is possible to achieve mutual pairwise authentication between the user equipment, the satellite, and the ground station without increasing additional communication overhead (such as without the involvement of the NCC), thereby improving authentication efficiency. In addition, it can not only identify unauthorized satellites and ground stations, but also reject unauthorized users, ensuring the credibility and security of users accessing the ground station service across satellites, and also improving the security of the entire access process for the user equipment.

[0278] Secondly, by adopting the above-mentioned three-party mutual pairwise authentication mechanism, untrusted satellites can be effectively identified. Compared with the traditional authentication mechanism, which only treats satellite nodes as transparent and completely trustworthy nodes, the trustworthiness of satellites can be further confirmed, and untrusted, unauthorized satellites in heterogeneous networks can be prevented from providing relay services to users and ground stations.

[0279] Furthermore, based on the publicly available parameters provided by the NCC, the entire access process can achieve joint negotiation of session keys between any two nodes among the user equipment, satellite, and ground station without the involvement of the NCC. After access authentication is completed, any two nodes among the user equipment, satellite, and ground station can use their own independent session keys for secure transmission. This also ensures that the temporary public key required for the session key cannot be tampered with or replaced by an unauthorized satellite, further ensuring the trustworthiness and security of users accessing the ground station via satellite, and improving the efficiency and security of data transmission.

[0280] Figure 6 A flowchart illustrating an access method on the user equipment side according to an embodiment of this application is provided. This process can be... Figure 1 The user equipment 101 shown performs this action to improve the security of the entire user equipment access process. For example... Figure 6 As shown, the process includes the following steps:

[0281] 601: Send the first access request to the satellite.

[0282] In this step, the satellite can be Figure 1 As shown in the satellite 102, the first access request includes the user equipment's first authentication information, the satellite's first identity information, and the ground station's second identity information.

[0283] In other embodiments, before sending the first access request to the satellite, the user equipment may first register with the NCC to enable subsequent access authentication with the satellite and ground station without the NCC's involvement. The specific process can be referred to the above. Figure 3 The relevant descriptions will not be repeated here.

[0284] In other embodiments, login verification can also be performed when sending the first access request to the satellite, specifically: in response to entering a second login password (PW′) on the login interface. i ), second biological characteristics (BIO′) i The system verifies login based on the second login password, the second biometric feature, and login authentication information. When the user device successfully logs in, it sends the first access request to the satellite to ensure that the user is a legitimate user holding the user device and that the device's authentication parameters are complete, unaltered, and valid.

[0285] Furthermore, login verification based on the second login password, the second biometric feature, and login authentication information can be performed by: extracting a reconstruction function (e.g., Rep(BIO′)) based on biometric fuzzy technology. i ,v i )=σ′ i ), current password biometric verification factor (RPW′) i =h1(PW′) i ,σ′ i Extract the private key from the private key derived value requested during login / registration (e.g., Extract fake user identifiers from fake derived values ​​(e.g., Extract the public key from the public key derivation value (e.g., And calculate the corresponding current login verification code (e.g., ver'). i =h4(DSK) i ,DPID i DPK i ,v i ,sk′ i ,PID′ i ,PK′ i Then, verify the current login verification code (ver'). i If the value is equal to (ver) in the login authentication information above, then the user's device is confirmed to be legitimate, and the authentication parameters in the device are valid and have not been tampered with; if not, then the user device is determined to be illegitimate, and the first access request is refused to be sent to the satellite.

[0286] In other embodiments, when the user device login verification is successful, the user can also change their login password and biometrics on the login and registration interface. Specifically, in response to the user operation of entering a new login password and new biometrics on the login and registration interface, the user device login authentication information is updated according to the new login password, new biometrics, user key information, and public parameters, and then the updated login authentication information is stored.

[0287] Furthermore, updating the user device's login authentication information based on the new login password, new biometrics, user key information, and publicly available parameters can be achieved by:

[0288] After obtaining the new login password (PW) i new ) and new biological characteristics Then, first calculate the new reconstruction function. New password biometric verification factor New private key derived value New False Derivative Value New public key derived value New login verification code Then update the above login authentication information to This allows users to use the new login password and biometrics for login verification on the login interface in the future.

[0289] Optionally, the first authentication information is related to the user key information of the user equipment provided by the NCC and the public parameters of the NCC. The first authentication information may include a first timestamp (t1) and the temporary identity information (TID) of the user equipment. i First public key (PK) i ), first temporary public key (R) i ), and the first authentication factor (a1); wherein, the first timestamp is used to characterize the timestamp when the user equipment generates the first access request.

[0290] Optionally, the first authentication factor satisfies the following expression:

[0291] a1=sk i +d1·r i ……(18)

[0292] d1 = h1(TID) i ID j ID k PK ncc ,R i ,t1)……(19)

[0293] R i =r i ·P…(20)

[0294]

[0295] Where d1 is the authentication hash value of the user equipment, and the meanings of the other characters can be found in the previous expression, and will not be repeated here.

[0296] 602: When the satellite verifies that the user equipment is legitimate based on the first access request, the ground station verifies that both the user equipment and the satellite are legitimate based on the second access request sent by the satellite, and the satellite verifies that the ground station is legitimate based on the first access request response sent by the ground station, the second access request response sent by the satellite is received.

[0297] The second access request is related to the first access request and the satellite's second authentication information, while the response to the first access request is related to the ground station's third authentication information.

[0298] Optionally, the second access request is related to the first access request and the satellite's second authentication information. The second authentication information may include a second timestamp, the satellite's second authentication factor, a second public key, and a second temporary public key. The second timestamp is used to characterize the time when the satellite generated the second access request, and the second authentication information is related to the satellite key information and the aforementioned public parameters.

[0299] Furthermore, the second public key is the public key in the satellite key information, the second temporary public key is calculated by the satellite based on the public parameters, and the second authentication factor is calculated by the satellite based on the public parameters, the second temporary public key, the first access request, and the second timestamp.

[0300] It should be noted that the specific calculation process for each parameter included in the above-mentioned second certification information can be found in the relevant description of 503 above, and will not be repeated here.

[0301] Optionally, the third authentication information includes a third timestamp, a third authentication factor, a fourth authentication factor, and a third public key and a third temporary public key of the ground station; wherein, the third authentication factor is an authentication factor related to the user equipment calculated by the ground station, the fourth authentication factor is an authentication factor related to the satellite calculated by the ground station, and the third timestamp is used to characterize the timestamp at which the ground station generates the first access request response.

[0302] 603: Perform a validity check on the satellite and ground station based on the second access request response, and access the ground station via the satellite if both the satellite and ground station are found to be valid.

[0303] The second access request response is related to the aforementioned third authentication information and the fourth authentication information related to the satellite.

[0304] Optionally, the fourth authentication information may include a second public key, a second temporary public key, a third public key, a third temporary public key, a third timestamp, a fourth timestamp, and a fifth authentication factor; wherein the fourth timestamp is used to characterize the timestamp at which the satellite generates the second access request response, and the fifth authentication factor is an authentication factor related to the user equipment calculated by the satellite.

[0305] It should be noted that the specific calculation process for each parameter included in the fourth authentication information mentioned above can be found in the above description. Figure 5 The description of the 505 error will not be repeated here.

[0306] Optionally, the satellite and ground station may be validated based on the second access request response, which may include the following process:

[0307] First, after verifying that both the third and fourth timestamps are valid, calculate the second session key between the user equipment and the ground station, and the third session key between the user equipment and the satellite.

[0308] Optional, a second session key, satisfying the following expression:

[0309] Key i-k =h5(TID) i ID j ID k PK ncc ,R i ,R j ,R k ,r k ·R i ,t1,t3)…(22)

[0310] Among them, Key i-k r is the second session key. k This is the session key parameter selected by the ground station within the set private key range. The meanings of other characters can be found in the previous expressions and will not be repeated here.

[0311] Optional, a third session key, satisfying the following expression:

[0312] Key i-j =h5(TID) i ID j ID k PK ncc ,R i ,R j ,R k ,r i ·R j ,t1,t4)……(23)

[0313] Among them, Key i-j For the third session key, r i This is the session key parameter selected by the user equipment within the set private key range. The meanings of other characters can be found in the previous expressions and will not be repeated here.

[0314] Secondly, the third authentication hash value of the ground station is calculated based on the third public key, and the third authentication hash factor (d′3) of the ground station is calculated based on the second session key and the third timestamp.

[0315] Optionally, the third authentication hash value and the third authentication hash factor shall satisfy the following expressions respectively:

[0316] d′ k3 =h1(ID) k ID ncc PK k )……(twenty four)

[0317] d′3=h1(TID iID j ID k PK ncc ,R i ,R j ,R k Key i-k ,t3)…(25)

[0318] Where, d′ k3 d′3 is the third authentication hash value, and d′3 is the third authentication hash factor. The meanings of the other characters can be found in the previous expression and will not be repeated here.

[0319] Furthermore, the fourth authentication hash value of the satellite is calculated based on the second public key, and the fourth authentication hash factor of the satellite is calculated based on the third session key and the fourth timestamp.

[0320] Optionally, the fourth authentication hash value and the fourth authentication hash factor shall satisfy the following expressions respectively:

[0321] d′ j4 =h1(ID) k ID ncc PK j )……(26)

[0322] d′4=h1(TID i ID j ,I*D k PK ncc ,R i ,R j ,R k Key i-j ,t4)……(27)

[0323] Where, d′ j4 d′4 is the fourth authentication hash value, and d′4 is the fourth authentication hash factor. The meanings of the other characters can be found in the previous expression and will not be repeated here.

[0324] Finally, the satellite and ground station are verified for legitimacy based on the third authentication hash value, the third authentication hash factor, the fourth authentication hash value, and the fourth authentication hash factor.

[0325] Optionally, if the following equation holds true, then both the satellite and the ground station are considered valid:

[0326] a5·P=PK k +PK j +(d′ k3 +d′ j4 )·PK ncc +d′3·R k +d′4·R j …(28)

[0327] Among them, a5 is the fifth authentication factor, and the meanings of the other characters can be referred to the previous expression, which will not be described again here.

[0328] In this embodiment of the application, if the above expression (28) is true, it can be confirmed that the legality of the satellite and the ground station, the session key parameters selected by each node have not been tampered with in multiple satellite-to-ground link transmissions, the session keys negotiated with the satellite and the ground station are all correct, and the second access request response has not been tampered with. If the above expression (28) is not true, it indicates that the satellite or the ground station is an unauthorized node of the system, or the session key parameters have been tampered with, or the second access request response has been tampered with in the satellite-to-ground link transmission process. In this case, the current access process can be terminated, and other measures can be taken to obtain the services of other ground stations.

[0329] In this embodiment of the application, the beneficial effects during the entire process of user equipment accessing the ground station via satellite are as follows:

[0330] First, since the satellite can verify the legitimacy of the user equipment based on the parameters included in the first access request, and the ground station can verify the legitimacy of the user equipment and the satellite based on the parameters included in the second access request, and the satellite can also verify the legitimacy of the ground station based on the parameters included in the first access request response, and the user equipment can verify the legitimacy of the ground station and the satellite based on the parameters included in the second access request response, it is possible to achieve mutual pairwise authentication between the user equipment, the satellite, and the ground station without increasing additional communication overhead (such as without the involvement of the NCC), thereby improving authentication efficiency. In addition, it can not only identify unauthorized satellites and ground stations, but also reject unauthorized users, ensuring the credibility and security of users accessing the ground station service across satellites, and also improving the security of the entire access process for the user equipment.

[0331] Secondly, by adopting the above-mentioned three-party mutual pairwise authentication mechanism, untrusted satellites can be effectively identified. Compared with the traditional authentication mechanism, which only treats satellite nodes as transparent and completely trustworthy nodes, the trustworthiness of satellites can be further confirmed, and untrusted, unauthorized satellites in heterogeneous networks can be prevented from providing relay services to users and ground stations.

[0332] Furthermore, based on the publicly available parameters provided by the NCC, the entire access process can achieve joint negotiation of session keys between any two nodes among the user equipment, satellite, and ground station without the involvement of the NCC. After access authentication is completed, any two nodes among the user equipment, satellite, and ground station can use their own independent session keys for secure transmission. This also ensures that the temporary public key required for the session key cannot be tampered with or replaced by an unauthorized satellite, further ensuring the trustworthiness and security of users accessing the ground station via satellite, and improving the efficiency and security of data transmission.

[0333] Figure 7 A flowchart illustrating an access method at a ground station side according to an embodiment of this application is provided. This process can be... Figure 1 The ground station 103 shown is used to improve the security of the entire access process for user equipment. For example... Figure 7 As shown, the process includes the following steps:

[0334] 701: Received a second access request from a satellite.

[0335] In this step, the second access request is related to the first access request sent by the user equipment to the satellite and the second authentication information of the satellite. The first access request includes the first authentication information of the user equipment, the first identity information of the satellite, and the second identity information of the ground station.

[0336] Optionally, in other embodiments, before receiving the second access request from the satellite, the ground station may first register with the NCC to enable subsequent access authentication with user equipment and the satellite without the NCC's involvement. The specific registration process can be referred to the above. Figure 4 The relevant descriptions will not be repeated here.

[0337] It should be noted that the specific calculation process for the parameters included in this first authentication information can be found in [reference needed]. Figure 6 For details regarding the 601 related description, the parameters included in the second authentication information, and the specific calculation process, please refer to [link / reference]. Figure 5 The description of 503 will not be repeated here.

[0338] 702: Perform a valid verification of the satellite and user equipment based on the second access request.

[0339] Optionally, the validity verification of the satellite and user equipment based on the second access request may include the following procedures:

[0340] First, when it is verified that both the first timestamp and the second timestamp in the second access request are valid, the fifth authentication hash value of the user equipment is calculated based on the first public key, and the fifth authentication hash factor of the user equipment is calculated based on the temporary identity information, the first temporary public key, the first timestamp, the first identity information, and the second identity information.

[0341] Optionally, the fifth authentication hash value and the fifth authentication hash factor shall satisfy the following expressions respectively:

[0342] d′ i5 =h1(ID) ncc PK i (29)

[0343] d′5=h1(TID i ID j ID k PK ncc ,R i ,t1)…(30)

[0344] Where, d′ i5 d′5 is the fifth authentication hash value, and d′5 is the fifth authentication hash factor. The meanings of the other characters can be found in the previous expression and will not be repeated here.

[0345] Secondly, the sixth authentication hash value of the satellite is calculated based on the second public key, and the sixth authentication hash factor of the satellite is calculated based on the temporary identity information, the first temporary public key, the second temporary public key, the first identity information, the second identity information, the first timestamp, and the second timestamp.

[0346] Optionally, the sixth authentication hash value and the sixth authentication hash factor shall satisfy the following expressions respectively:

[0347] d′ j6 =h1(ID) j ID ncc PK j )…(31)

[0348] d′6=h1(TID i ID j ID k PK ncc ,R i ,R j ,t1,t2)…(32)

[0349] Where, d′ j6 d′6 is the hash value for the sixth authentication, and d′6 is the hash factor for the sixth authentication. The meanings of the other characters can be found in the previous expression and will not be repeated here.

[0350] Then, the satellite and user equipment are verified for legitimacy based on the fifth authentication hash value, the fifth authentication hash factor, the sixth authentication hash value, and the sixth authentication hash factor.

[0351] 703: If both the satellite and the user equipment are verified to be legitimate, a first access request response is sent to the satellite.

[0352] Optionally, the satellite and user equipment are deemed valid if the following equation is satisfied:

[0353] a2·P=PK i +PK j +(d′ i5 +d′ j6 )·PK ncc +d′5·Ri +d′6·R j ……(33)

[0354] Here, a2 is the second authentication factor in the second access request, and the meanings of the other characters can be found in the previous expression, which will not be repeated here.

[0355] In this embodiment of the application, if the above expression (33) is true, the ground station can confirm the legitimacy of the satellite and user equipment, the integrity and trustworthiness of the first temporary public key and the second temporary public key, and the freshness, integrity and validity of each parameter in the second access request; if the above expression (33) is not true, it indicates that the user equipment or satellite is an unauthorized node of the system, or the second access request is tampered with during the transmission of the satellite-ground link, and the current access process can be terminated.

[0356] Optionally, the first access request response is related to the third authentication information of the ground station.

[0357] Optionally, the third authentication information includes a third timestamp, a third authentication factor, a fourth authentication factor, and a third public key and a third temporary public key of the ground station; wherein, the third authentication factor is an authentication factor related to the user equipment calculated by the ground station, the fourth authentication factor is an authentication factor related to the satellite calculated by the ground station, and the third timestamp is used to characterize the timestamp at which the ground station generates the first access request response.

[0358] Optionally, the ground station calculates the aforementioned third and fourth authentication factors, which may specifically include the following process:

[0359] First, the ground station randomly selects a parameter within the private key range as the ground station's session key parameter (r). k ).

[0360] Secondly, according to r k Calculate the third temporary public key (R) of the ground station k ), and session keys associated with the user equipment (e.g., Key) k-i =h5(TID) i ID j ID k PK ncc ,R i ,R j ,R k ,r k ·R i ,t1,t3), and satellite-related session keys (e.g., Key k-j =h5(TID) i ID j ID k PK ncc ,Ri ,R j ,R k ,r k ·R j ,t1,t2,t3)).

[0361] Then, based on the key k-i Calculate the authentication hash factor associated with the user equipment (e.g., d7 = h1(TID)). i ID j ID k PK ncc ,R i ,R j ,R k Key k-i ,t3)), and according to Key k-j Calculate the authentication hash factor associated with the satellite (e.g., d8 = h1(TID)). i ID j ID k PK ncc ,R i ,R j ,R k Key k-j ,a3,t3R i ,R j ,R k Key k-j ,a3,t3)); Calculate the third authentication factor based on d7 (e.g., a3 = s k +d7·r k ), and calculate the fourth authentication factor based on d8 (e.g., a4 = s k +d8·r k It should be noted that the meanings of other characters can be found in the expressions above, and will not be repeated here.

[0362] In other embodiments, when multiple access requests sent by a satellite are received within a set time period, a large number of access requests can be efficiently aggregated and batch verified. Specifically:

[0363] First, within a set time period, M fourth access requests are received from the satellite; where M are requests to access the ground station via the satellite, and M is an integer greater than 1.

[0364] Secondly, after verifying that all M fourth access requests are valid based on their respective timestamps, the system calculates M authentication hash values ​​and M authentication hash factors related to the user equipment and satellite for each of the M fourth access requests.

[0365] Furthermore, based on the M authentication hash values ​​and M authentication hash factors associated with the user equipment, and the M authentication hash values ​​and M authentication hash factors associated with the satellite, the M fourth access requests are validated for validity.

[0366] Finally, if all M fourth access requests are found to be valid, then a second access request response is generated based on each of the M fourth access requests, and each second access request response is sent to the satellite.

[0367] For example, suppose the ground station receives M fourth access requests RAARs = {RAAR1, RAAR2, ..., RAAR} sent by the satellite. M}, where RAAR i ={TID i ID j ID k PK i PK j ,R i ,R j ,a i,2 ,t i,1 ,t i,2}; For each fourth access request, the timestamp (t) i,1 ,t i,2 If each fourth access request is found to be valid, then based on the parameters contained in each fourth access request, calculate M authentication hash values ​​(e.g., d′) associated with the user equipment. im =h1(ID) ncc PK i M authentication hash factors (e.g., d′) im,1 =h1(TID i ID j ID k PK ncc ,R i ,t i,1 ), and each of the M authentication hashes associated with the satellite (e.g., d′ jm =h1(ID) j ID ncc PK j M authentication hash factors (e.g., d′) im,2 =h1(TID i ID j ID k PK ncc ,R i ,R j ,t i,1 ,t i,2 If satisfied The ground station then confirms that all RAARs are legitimate access requests and that none of the third access requests have been tampered with in the satellite-to-ground link.

[0368] In this embodiment of the application, the beneficial effects during the entire process of user equipment accessing the ground station via satellite are as follows:

[0369] First, since the satellite can verify the legitimacy of the user equipment based on the parameters included in the first access request, and the ground station can verify the legitimacy of the user equipment and the satellite based on the parameters included in the second access request, and the satellite can also verify the legitimacy of the ground station based on the parameters included in the first access request response, and the user equipment can verify the legitimacy of the ground station and the satellite based on the parameters included in the second access request response, it is possible to achieve mutual pairwise authentication between the user equipment, the satellite, and the ground station without increasing additional communication overhead (such as without the involvement of the NCC), thereby improving authentication efficiency. In addition, it can not only identify unauthorized satellites and ground stations, but also reject unauthorized users, ensuring the credibility and security of users accessing the ground station service across satellites, and also improving the security of the entire access process for the user equipment.

[0370] Secondly, by adopting the above-mentioned three-party mutual pairwise authentication mechanism, untrusted satellites can be effectively identified. Compared with the traditional authentication mechanism, which only treats satellite nodes as transparent and completely trustworthy nodes, the trustworthiness of satellites can be further confirmed, and untrusted, unauthorized satellites in heterogeneous networks can be prevented from providing relay services to users and ground stations.

[0371] Furthermore, based on the publicly available parameters provided by the NCC, the entire access process can achieve joint negotiation of session keys between any two nodes among the user equipment, satellite, and ground station without the involvement of the NCC. After access authentication is completed, any two nodes among the user equipment, satellite, and ground station can use their own independent session keys for secure transmission. This also ensures that the temporary public key required for the session key cannot be tampered with or replaced by an unauthorized satellite, further ensuring the trustworthiness and security of users accessing the ground station via satellite, and improving the efficiency and security of data transmission.

[0372] Based on the above Figure 5 , Figure 6 , Figure 7 , Figure 8 An exemplary diagram illustrating the signaling interaction of an access method provided in an embodiment of this application is shown. Figure 8 As shown, it includes the following steps:

[0373] 801: User equipment is based on r selected within the private key range i Calculate its own TID i R i、a1.

[0374] 802: User equipment sends a message containing {TID} to the satellite. i ID j ID k PK i ,R i The first access request of ,a1,t1}.

[0375] In this step, the user equipment can be Figure 1 The user equipment 101 shown can be a satellite. Figure 1 Satellite 102 is shown.

[0376] 803: After receiving the first access request, the satellite performs a valid verification of the user equipment based on the first access request.

[0377] 804: When the satellite verifies that the user equipment is legitimate, it sends a request containing {TID} to the ground station based on the first access request. i ID j ID k PK i PK j ,R i ,R j The second access request of ,a2,t1,t2}.

[0378] 805: After receiving the second access request, the ground station performs a valid verification of the user equipment and the satellite based on the second access request.

[0379] 806: When the ground station verifies that both the user equipment and the satellite are legitimate, it sends a request containing {PK} to the satellite based on this second access request. k ,R k The first access request response for},a3,a4,t3}.

[0380] 807: After receiving the first access request response, the satellite performs a validity check on the ground station based on the first access request response.

[0381] 808: After the satellite verifies the legitimacy of the ground station, it sends a message containing {PK} to the user equipment based on the first access request response. k PK j ,R k ,R j The second access request response for}, a5, t3, t4}.

[0382] 809: After receiving the second access request response, the user equipment shall perform a valid verification of the satellite and the user equipment based on the second access request response.

[0383] In this step, once the user equipment verifies that both the satellite and the user equipment are legitimate, the satellite successfully connects to the ground station and obtains the corresponding services.

[0384] It should be noted that the specific explanations of the above parameters can be found in the previous text, and will not be repeated here.

[0385] In this embodiment, based on the access interaction process of the three parties mentioned above, the user equipment, satellite, and ground station successfully establish mutual authentication between each other, and each party jointly negotiates a session key. i-j =Key j-i Key i-k =Key k-i Key j-k =Key k-j This not only ensures the reliability and confidentiality of user equipment when accessing ground stations across satellites and obtaining ground station services, but also meets the mutual trust and secure transmission requirements between any three nodes.

[0386] Based on the same technical concept, this application also provides a satellite that can implement the above-described access method on the satellite side in this application.

[0387] Figure 9 An exemplary schematic diagram of a satellite structure provided in an embodiment of this application is shown. Figure 9 As shown, the satellite includes a first receiving module 901, a first verification module 902, a first transmitting module 903, a second receiving module 904, a second verification module 905, and a second transmitting module 906.

[0388] The first receiving module 901 is configured to receive a first access request from a user equipment; wherein the first access request includes first authentication information of the user equipment, first identity information of the satellite, and second identity information of the ground station.

[0389] The first verification module 902 is used to perform a legality verification on the user equipment based on the first authentication information, the first identity information, and the second identity information.

[0390] The first sending module 903 is configured to send a second access request to the ground station if the first verification module 902 verifies that the user equipment is legitimate; wherein the second access request is related to the first access request and the second authentication information of the satellite;

[0391] The second receiving module 904 is used to receive a first access request response from the ground station; wherein the first access request response is generated by the ground station after verifying that the user equipment and the satellite are both legitimate based on the second access request, and the first access request response is related to the third authentication information of the ground station;

[0392] The second verification module 905 is used to perform a legality verification on the ground station based on the third authentication information;

[0393] The second sending module 906 is used to send a second access request response to the user equipment when the second verification module 905 verifies that the ground station is legitimate; wherein the second access request response is related to the third authentication information and the fourth authentication information of the satellite.

[0394] Based on the same technical concept, this application embodiment also provides a user equipment that can implement the method flow of the access method on the user equipment side described in this application embodiment.

[0395] Figure 10 An exemplary schematic diagram of a user equipment provided in an embodiment of this application is shown. Figure 10 As shown, the user equipment includes a transmitting module 1001, a receiving module 1002, and a verification module 1003.

[0396] The sending module 1001 is used to send a first access request to the satellite; wherein the first access request includes the first authentication information of the user equipment, the first identity information of the satellite, and the second identity information of the ground station;

[0397] The receiving module 1002 is configured to receive a second access request response sent by the satellite when the satellite verifies that the user equipment is legitimate based on the first access request, the ground station verifies that both the user equipment and the satellite are legitimate based on the second access request sent by the satellite, and the satellite verifies that the ground station is legitimate based on the first access request response sent by the ground station; wherein the second access request is related to the first access request and the second authentication information of the satellite, and the first access request response is related to the third authentication information of the ground station;

[0398] The verification module 1003 is used to perform legal verification on the satellite and the ground station according to the second access request response, and to access the ground station through the satellite when both the satellite and the ground station are verified to be legal; wherein the second access request response is related to the third authentication information and the fourth authentication information of the satellite.

[0399] Based on the same technical concept, this application embodiment also provides a ground station, which can implement the method flow of the access method on the ground station side described above in this application embodiment.

[0400] Figure 11 An exemplary schematic diagram of a ground station provided in an embodiment of this application is shown. Figure 11 As shown, the ground station includes a receiving module 1101, a verification module 1102, and a transmitting module 1103.

[0401] The receiving module 1101 is used to receive a second access request from a satellite; wherein the second access request is related to a first access request sent by the user equipment to the satellite and the second authentication information of the satellite, and the first access request includes the first authentication information of the user equipment, the first identity information of the satellite, and the second identity information of the ground station;

[0402] Verification module 1102 is used to perform a validity verification on the satellite and the user equipment according to the second access request;

[0403] The sending module 1103 is configured to send a first access request response to the satellite if the verification module 1102 verifies that both the satellite and the user equipment are legitimate; wherein the first access request response is related to the third authentication information of the ground station.

[0404] It should be noted that the apparatus provided in this application embodiment can implement all the method steps in the above method embodiment and achieve the same technical effect. Therefore, the parts and beneficial effects that are the same as those in the method embodiment will not be described in detail here.

[0405] Based on the same technical concept, this application also provides an electronic device that can implement the function of the aforementioned access method.

[0406] Figure 12 An exemplary schematic diagram of the structure of an electronic device provided in an embodiment of this application is shown.

[0407] At least one processor 1201 and a memory 1202 connected to at least one processor 1201. In this embodiment, the specific connection medium between the processor 1201 and the memory 1202 is not limited. Figure 12 The example shown is the connection between processor 1201 and memory 1202 via bus 1200. Bus 1200 is... Figure 12 The connections between other components are shown in thick lines only and are not intended to be limiting. The Bus 1200 can be divided into address bus, data bus, control bus, etc., for ease of representation. Figure 12The term is represented by a single thick line, but this does not imply that there is only one bus or one type of bus. Alternatively, the processor 1201 can also be called a controller; there is no restriction on the name.

[0408] In this embodiment, the memory 1202 stores instructions executable by at least one processor 1201. By executing the instructions stored in the memory 1202, the at least one processor 1201 can perform a data processing method described above. The processor 1201 can implement... Figure 9 , Figure 10 , Figure 11 The functions of each module in the device shown.

[0409] The processor 1201 is the control center of the device. It can connect to various parts of the control device through various interfaces and lines. By running or executing instructions stored in memory 1202 and calling data stored in memory 1202, the processor can perform various functions and process data, thereby monitoring the device as a whole.

[0410] In this embodiment, processor 1201 may include one or more processing units. Processor 1201 may integrate an application processor and a modem processor. The application processor mainly handles the operating system, user interface, and applications, while the modem processor mainly handles wireless communication. It is understood that the modem processor may not be integrated into processor 1201. In some embodiments, processor 1201 and memory 1202 may be implemented on the same chip; in other embodiments, they may be implemented on separate chips.

[0411] The processor 1201 can be a general-purpose processor, such as a central processing unit (CPU), digital signal processor, application-specific integrated circuit, field-programmable gate array or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, capable of implementing or executing the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of an access method disclosed in the embodiments of this application can be directly manifested as execution by a hardware processor, or execution by a combination of hardware and software modules within the processor.

[0412] Memory 1202, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. Memory 1202 may include at least one type of storage medium, such as flash memory, hard disk, multimedia card, card-type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic memory, magnetic disk, optical disk, etc. Memory 1202 can be any other medium capable of carrying or storing desired program code in the form of instructions or data structures that can be accessed by a computer, but is not limited thereto. In the embodiments of this application, memory 1202 can also be a circuit or any other device capable of implementing storage functions for storing program instructions and / or data.

[0413] By designing and programming the processor 1201, the code corresponding to one of the access methods described in the foregoing embodiments can be embedded into the chip, thereby enabling the chip to execute the code during operation. Figure 5 , Figure 6 , Figure 7 The illustrated embodiment presents an access method. How to design and program the processor 1201 is a technique well-known to those skilled in the art and will not be described further here.

[0414] It should be noted that the electronic device provided in this application embodiment can implement all the method steps implemented in the above method embodiment and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.

[0415] Based on the same technical concept, embodiments of this application provide a computer storage medium, which includes computer program code. When the computer program code is executed on a computer, it causes the computer to perform any of the access methods described above. Since the principle by which the computer storage medium solves the problem is similar to that of an access method, the implementation of the computer storage medium can be referred to the implementation of the method, and repeated details will not be elaborated further.

[0416] In specific implementation, computer storage media can include: Universal Serial Bus Flash Drive (USB), portable hard drive, Read-Only Memory (ROM), Random Access Memory (RAM), magnetic disk or optical disk, and other storage media that can store program code.

[0417] Based on the same technical concept, this application also provides a computer program product, which includes computer program code. When the computer program code is run on a computer, it causes the computer to execute any of the access methods described above. Since the principle by which the above computer program product solves the problem is similar to that of an access method, the implementation of the above computer program product can refer to the implementation of the method, and repeated details will not be described again.

[0418] Computer program products may employ any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples (a non-exhaustive list) of readable storage media include: electrical connections having one or more wires, portable disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0419] The methods in this application can be implemented, in whole or in part, by software, hardware, firmware, or any combination thereof. When implemented in software, they can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in this application are performed, in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, network equipment, user equipment, core network equipment, OAM, or other programmable devices.

[0420] The computer program or instructions may be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program or instructions may be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium may be any available medium that a computer can access, or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; or an optical medium, such as a digital video optical disc; or a semiconductor medium, such as a solid-state drive. The computer-readable storage medium may be a volatile or non-volatile storage medium, or may include both volatile and non-volatile types of storage media.

[0421] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.

[0422] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that specifies the functions in one or more boxes. These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including the instruction device, which is implemented in a process. Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0423] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0424] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if these modifications and variations of the present invention fall within the scope of the claims of this application and their equivalents, this application also intends to include these modifications and variations.

Claims

1. An access method, characterized in that, Applied to satellites, the method includes: Receive a first access request from a user equipment; wherein the first access request includes first authentication information of the user equipment, first identity information of the satellite, and second identity information of the ground station; The user equipment is verified for legitimacy based on the first authentication information, the first identity information, and the second identity information. If the user equipment is verified to be legitimate, a second access request is sent to the ground station; wherein the second access request is related to the first access request and the second authentication information of the satellite; Receive a first access request response from the ground station; wherein the first access request response is generated by the ground station after verifying that the user equipment and the satellite are both legitimate based on the second access request, and the first access request response is related to the third authentication information of the ground station; The ground station is validated based on the third authentication information, and a second access request response is sent to the user equipment when the ground station is validated. The second access request response is related to the third authentication information and the fourth authentication information of the satellite. The first authentication information is related to the user key information of the user equipment provided by the Network Control Center (NCC) and the public parameters of the NCC. The first authentication information includes a first timestamp, the temporary identity information of the user equipment, a first public key, a first temporary public key, and a first authentication factor. The first timestamp is used to characterize the timestamp when the user equipment generates the first access request. The second authentication information is related to the satellite key information of the satellite provided by the NCC and the public parameters. The second authentication information includes a second timestamp, a second authentication factor of the satellite, a second public key, and a second temporary public key; wherein, the second timestamp is used to characterize the time when the satellite generates the second access request; The third authentication information includes a third timestamp, a third authentication factor, a fourth authentication factor, and the third public key and a third temporary public key of the ground station; wherein, the third authentication factor is an authentication factor related to the user equipment calculated by the ground station, the fourth authentication factor is an authentication factor related to the satellite calculated by the ground station, and the third timestamp is used to characterize the timestamp at which the ground station generates the first access request response; The fourth authentication information includes the second public key, the second temporary public key, the third public key, the third temporary public key, the third timestamp, the fourth timestamp, and the fifth authentication factor; wherein, the fourth timestamp is used to characterize the timestamp at which the satellite generates the second access request response, and the fifth authentication factor is an authentication factor related to the user equipment calculated by the satellite.

2. The method as described in claim 1, characterized in that, The step of verifying the legitimacy of the user equipment based on the first authentication information, the first identity information, and the second identity information includes: When the first timestamp is verified to be valid, the first authentication hash value of the user equipment is calculated based on the first public key, and the first authentication hash factor of the user equipment is calculated based on the temporary identity information, the first temporary public key, the first timestamp, the first identity information, and the second identity information. The user equipment is validated based on the first authentication hash value and the first authentication hash factor.

3. The method as described in claim 1, characterized in that, The step of verifying the legitimacy of the ground station based on the third authentication information includes: Upon verifying the validity of the third timestamp, the first session key between the satellite and the ground station is calculated; The second authentication hash value of the ground station is calculated based on the third public key, and the second authentication hash factor of the ground station is calculated based on the first session key, the third authentication factor, and the third timestamp; The ground station is validated based on the second authentication hash value and the second authentication hash factor.

4. The method as described in claim 1, characterized in that, The method further includes: During a set time period, N third access requests are received from the user equipment; wherein the N third access requests are for requesting access to the ground station via the satellite, and N is an integer greater than 1; When all N third access requests are verified to be valid based on their respective timestamps, N authentication hash values ​​and N authentication hash factors related to the user equipment are calculated for each of the N third access requests. The validity of the N third-party access requests is verified based on the N authentication hash values ​​and the N authentication hash factors. If all N third access requests are verified to be valid, then a fourth access request is generated based on the N third access requests, and each fourth access request is sent to the ground station.

5. An access method, characterized in that, Applied to user equipment, the method includes: Send a first access request to the satellite; wherein the first access request includes the first authentication information of the user equipment, the first identity information of the satellite, and the second identity information of the ground station; When the satellite verifies that the user equipment is legitimate based on the first access request, the ground station verifies that both the user equipment and the satellite are legitimate based on the second access request sent by the satellite, and the satellite verifies that the ground station is legitimate based on the first access request response sent by the ground station, the ground station receives the second access request response sent by the satellite; wherein, the second access request is related to the first access request and the second authentication information of the satellite, and the first access request response is related to the third authentication information of the ground station; The satellite and the ground station are validated according to the second access request response. If both the satellite and the ground station are validated, access to the ground station is granted through the satellite. The second access request response is related to the third authentication information and the fourth authentication information of the satellite. The first authentication information is related to the user key information of the user equipment provided by the Network Control Center (NCC) and the public parameters of the NCC. The first authentication information includes a first timestamp, the temporary identity information of the user equipment, a first public key, a first temporary public key, and a first authentication factor. The first timestamp is used to characterize the timestamp when the user equipment generates the first access request. The second authentication information is related to the satellite key information of the satellite provided by the NCC and the public parameters. The second authentication information includes a second timestamp, a second authentication factor of the satellite, a second public key, and a second temporary public key; wherein, the second timestamp is used to characterize the time when the satellite generates the second access request; The third authentication information includes a third timestamp, a third authentication factor, a fourth authentication factor, and the third public key and a third temporary public key of the ground station; wherein, the third authentication factor is an authentication factor related to the user equipment calculated by the ground station, the fourth authentication factor is an authentication factor related to the satellite calculated by the ground station, and the third timestamp is used to characterize the timestamp at which the ground station generates the first access request response; The fourth authentication information includes the second public key, the second temporary public key, the third public key, the third temporary public key, the third timestamp, the fourth timestamp, and the fifth authentication factor; wherein, the fourth timestamp is used to characterize the timestamp at which the satellite generates the second access request response, and the fifth authentication factor is an authentication factor related to the user equipment calculated by the satellite.

6. The method as described in claim 5, characterized in that, The step of verifying the legitimacy of the satellite and the ground station based on the second access request response includes: When both the third and fourth timestamps are verified to be valid, the second session key between the user equipment and the ground station, and the third session key between the user equipment and the satellite are calculated. The third authentication hash value of the ground station is calculated based on the third public key, and the third authentication hash factor of the ground station is calculated based on the second session key and the third timestamp. The fourth authentication hash value of the satellite is calculated based on the second public key, and the fourth authentication hash factor of the satellite is calculated based on the third session key and the fourth timestamp. The satellite and the ground station are verified for legitimacy based on the third authentication hash value, the third authentication hash factor, the fourth authentication hash value, and the fourth authentication hash factor.

7. The method as described in claim 5 or 6, characterized in that, The method further includes: In response to a user operation of entering a first login password and a first biometric feature on the login / registration interface, login authentication information for the user device is generated based on the first login password, the first biometric feature, the user key information, and the public parameters. The login authentication information includes at least the user device's private key derived value, public key derived value, fake derived value, login verification code, and biometric key public parameters.

8. An access method, characterized in that, Applied to ground stations, the method includes: Receive a second access request from a satellite; wherein the second access request is related to a first access request sent by the user equipment to the satellite and the second authentication information of the satellite, the first access request including the first authentication information of the user equipment, the first identity information of the satellite, and the second identity information of the ground station; The satellite and the user equipment are verified for validity based on the second access request. If both the satellite and the user equipment are verified to be legitimate, a first access request response is sent to the satellite; wherein the first access request response is related to the third authentication information of the ground station; The first authentication information is related to the user key information of the user equipment provided by the Network Control Center (NCC) and the public parameters of the NCC. The first authentication information includes a first timestamp, the temporary identity information of the user equipment, a first public key, a first temporary public key, and a first authentication factor. The first timestamp is used to characterize the time when the user equipment generates the first authentication information. The second authentication information is related to the satellite key information of the satellite provided by the NCC and the public parameters. The second authentication information includes a second timestamp, a second authentication factor of the satellite, a second public key, and a second temporary public key; wherein, the second timestamp is used to characterize the time when the satellite generates the second authentication information. The third authentication information includes a third timestamp, a third authentication factor, a fourth authentication factor, and the third public key and third temporary public key of the ground station; wherein, the third authentication factor is an authentication factor related to the user equipment calculated by the ground station, the fourth authentication factor is an authentication factor related to the satellite calculated by the ground station, and the third timestamp is used to characterize the timestamp at which the ground station generates the first access request response.

9. The method as described in claim 8, characterized in that, The step of verifying the legitimacy of the satellite and the user equipment based on the second access request includes: When both the first timestamp and the second timestamp are verified to be valid, the fifth authentication hash value of the user equipment is calculated based on the first public key, and the fifth authentication hash factor of the user equipment is calculated based on the temporary identity information, the first temporary public key, the first timestamp, the first identity information, and the second identity information. The sixth authentication hash value of the satellite is calculated based on the second public key, and the sixth authentication hash factor of the satellite is calculated based on the temporary identity information, the first temporary public key, the second temporary public key, the first identity information, the second identity information, the first timestamp, and the second timestamp. The satellite and the user equipment are verified for legitimacy based on the fifth authentication hash value, the fifth authentication hash factor, the sixth authentication hash value, and the sixth authentication hash factor.

10. The method as described in claim 8 or 9, characterized in that, The method further includes: During a set time period, M fourth access requests are received from the satellite; wherein the M fourth access requests are used to request access to the ground station through the satellite, and M is an integer greater than 1; When all M fourth access requests are found to be valid based on their respective timestamps, M authentication hash values ​​and M authentication hash factors associated with the user equipment and satellite are calculated for each of the M fourth access requests. The validity of the M fourth access requests is verified based on the M authentication hash values ​​and M authentication hash factors associated with the user equipment and the M authentication hash values ​​and M authentication hash factors associated with the satellite. If all M fourth access requests are verified to be valid, then a second access request response is generated for each of the M fourth access requests, and each second access request response is sent to the satellite.

11. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor, when executing a computer program stored in the memory, implements the method of any one of claims 1-4, or performs the method of any one of claims 5-7, or performs the method of any one of claims 8-10.

12. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the method of any one of claims 1-4, or performs the method of any one of claims 5-7, or performs the method of any one of claims 8-10.

Citation Information

Patent Citations

  • Space-ground integrated spatial information network anonymous access authentication method and system

    CN110971415A

  • NTRU-based space-ground integrated network anonymous access authentication method

    CN114339735A