A satellite inter-satellite identity authentication method and system based on zero trust
By sending future status information to the satellite network from the ground end and using a summary algorithm for identity authentication, the security risks brought by implicit trust in the satellite network are resolved, and low-data-volume and reliable inter-satellite identity authentication is achieved.
Patent Information
- Application Number
- CN202411202458.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-29
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2044-08-29
AI Technical Summary
In existing technologies, the zero-trust identity authentication model of satellite networks cannot be fully applied to satellite networks, especially when communication resources are limited and intermittent visibility between satellites is intermittent, resulting in increased network security risks brought by implicit trust.
Future status information is sent to satellites in the satellite network through the ground end, and summary information is generated using a summary algorithm for identity authentication, ensuring the reliability and security of inter-satellite identity authentication and avoiding the hazards caused by implicit trust.
It achieves low-data-volume and reliable identity authentication in satellite networks, ensuring that the current satellite status is consistent with the previous plan and reducing network security risks.
Smart Images

Figure CN119172081B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of satellite network security, and in particular to a zero-trust-based satellite inter-satellite identity authentication method and system. Background Art
[0002] As users' demands for functional functions such as satellite data timeliness and inter-satellite coordination continue to increase, satellites are beginning to develop from single satellites to constellations and even across constellations. Intra-constellation coordination and inter-constellation coordination inevitably involve information exchange between satellites. Usually, the status of each satellite in orbit is known by the ground-based measurement and control station. This status knowledge makes each satellite in orbit have "implicit trust" from the control station. Implicit trust makes it difficult for satellites and ground-based control stations to detect malicious operations when the actual status of the satellite in orbit is inconsistent with the status known from the ground (for example, autonomously performing unconventional operations in non-measurement and control segments or reasonable operations that are not generated through planned mission execution sequences such as mission planning).
[0003] Zero Trust is a cybersecurity paradigm centered around resource protection. Its premise is that trust is never implicitly granted but rather must be continuously assessed. Therefore, for satellites, the inherent implicit trust inherent in satellite networks increases with their scale. This inherent trust creates an increasing probability of cybersecurity risks, necessitating the introduction of Zero Trust-based identity authentication to minimize these risks.
[0004] At present, the zero-trust identity authentication for satellites at home and abroad mainly applies the zero-trust authentication model of the ground network to the satellite network, but there are the following prominent problems: on the one hand, some information in the zero-trust authentication model of the ground network cannot be provided by satellite nodes and cannot be used for satellite identity authentication; on the other hand, since the authentication and authenticated objects in the ground network are visible for a long time, authentication requests can be initiated to the terminal in real time, while satellites will be affected by limited communication resources and intermittent visibility between satellites. Therefore, the "zero trust" solution adopted by the ground network cannot be fully applied to satellite networks. Summary of the Invention
[0005] The technical problem solved by the present invention is: to overcome the shortcomings of the existing technology and provide a zero-trust based satellite inter-satellite identity authentication method and system, by injecting the future status information of other satellites in the satellite network to the satellites in the satellite network from the ground, generating summary information for mutual authentication, avoiding the hazards brought by "implicit trust", and at the same time not being affected by the limited satellite communication resources and intermittent visibility between satellites.
[0006] The technical solution of the present invention is: a satellite inter-satellite identity authentication method based on zero trust, comprising:
[0007] The ground terminal sends the verification satellite's future state information to the requesting satellite, and sends the requesting satellite's future state information to the verification satellite;
[0008] The requesting satellite utilizes the future state information of the verification satellite to generate and store the verification satellite comparison verification information; the verification satellite utilizes the future state information of the requesting satellite to generate and store the requesting satellite comparison verification information;
[0009] The requesting satellite sends an authentication request message to the verification satellite according to current needs;
[0010] The verification satellite compares the authentication request information with the stored verification information of the requesting satellite; if the comparison is successful, the verification satellite returns the authentication verification information to the requesting satellite;
[0011] The requesting satellite compares the authentication verification information with the stored verification satellite verification information; if the comparison is successful, the requesting satellite establishes a link with the verification satellite.
[0012] Furthermore, the requesting satellite utilizes the verification satellite's future state information to generate verification satellite comparison verification information, specifically in the following manner:
[0013] Requesting the satellite to extract the timestamp in the future state information of the satellite for verification, generating summary information of the future state information of the satellite for verification through a summary algorithm, and storing the timestamp and summary information of the future state information of the satellite for verification as a key-value pair;
[0014] The verification satellite uses the future status information of the requesting satellite to generate the comparison verification information of the requesting satellite. The specific method is as follows:
[0015] The verification satellite extracts the timestamp in the future state information of the requested satellite, generates summary information of the future state information of the requested satellite through a summary algorithm, and stores the timestamp and summary information of the future state information of the requested satellite as a key-value pair.
[0016] Furthermore, the authentication request information includes a current timestamp and summary information of the current status information of the requesting satellite; after receiving the authentication request information, the verification satellite compares the current timestamp and the summary information of the current status information of the requesting satellite to see whether they exist in the stored requesting satellite comparison verification information. If they exist, the comparison is passed; if not, the comparison fails.
[0017] Furthermore, the authentication verification information includes a current timestamp and summary information of the current status information of the verification satellite; after receiving the authentication verification information, the requesting satellite compares the current timestamp and the summary information of the current status information of the verification satellite to see whether they exist in the stored verification satellite comparison verification information. If they exist, the comparison is passed; if not, the comparison fails.
[0018] Furthermore, the future status information and current status information of the satellite are requested or verified in the same format, including: timestamp, satellite ID, payload working status and orbital elements.
[0019] The present invention also provides a zero-trust-based satellite inter-satellite identity authentication system, which is deployed on the ground terminal, the requesting satellite and the verifying satellite;
[0020] Ground terminal, including:
[0021] A ground sending module is used to send the verification satellite's future state information to the requesting satellite and send the requesting satellite's future state information to the verification satellite;
[0022] Request satellites, including:
[0023] The first information receiving module is used to receive the future status information of the verification satellite sent by the ground terminal; receive the authentication verification information sent by the verification satellite;
[0024] A first verification information generating module is used to generate verification satellite comparison verification information using the verification satellite future state information;
[0025] A first verification information storage module is used to store verification satellite comparison verification information;
[0026] The first comparison and verification module is used to compare the authentication verification information with the stored verification satellite comparison and verification information to obtain a verification comparison result;
[0027] A first information sending module is used to send authentication request information to the verification satellite;
[0028] Validation satellites, including:
[0029] The second information receiving module is used to receive the future state information of the requesting satellite sent by the ground terminal; and receive the authentication request information sent by the requesting satellite;
[0030] A second verification information generating module is used to generate requested satellite comparison verification information using the requested satellite future state information;
[0031] A second verification information storage module is used to store the requested satellite comparison verification information;
[0032] The second comparison and verification module is used to compare the authentication request information with the stored requested satellite comparison and verification information to obtain a request comparison result;
[0033] The second information sending module is used to send authentication verification information to the verification satellite.
[0034] Furthermore, the first verification information generation module generates the verification satellite comparison verification information in a specific manner: extracting the timestamp in the verification satellite future state information, generating summary information of the verification satellite future state information through a summary algorithm, and sending the timestamp and summary information of the verification satellite future state information as a key-value pair to the first verification information storage module;
[0035] The second verification information generation module generates the requested satellite comparison verification information in the following specific manner: extracting the timestamp in the requested satellite future state information, generating summary information of the requested satellite future state information through a summary algorithm, and sending the timestamp and summary information of the requested satellite future state information as a key-value pair to the second verification information storage module.
[0036] Furthermore, the authentication request information includes a current timestamp and summary information of the current status information of the requested satellite; the second comparison and verification module obtains the request comparison result in the following specific manner: after receiving the authentication request information, compare whether the current timestamp and the summary information of the current status information of the requested satellite exist in the comparison and verification information of the requested satellite in the second verification information storage module; if so, the comparison passes; if not, the comparison fails.
[0037] Furthermore, the authentication verification information includes a current timestamp and summary information of the current status information of the verification satellite; the first comparison verification module obtains the verification comparison result in the following specific manner: after receiving the authentication verification information, compare the current timestamp and the summary information of the current status information of the verification satellite in the verification satellite comparison verification information of the first verification information storage module to see whether they exist; if so, the comparison passes; if not, the comparison fails.
[0038] Furthermore, the future status information and current status information of the satellite are requested or verified in the same format, including: timestamp, satellite ID, payload working status and orbital elements.
[0039] The advantages of the present invention compared with the prior art are:
[0040] (1) Compared with traditional one-time authentication such as username and password or direct connection instruction without authentication through ground connection, the present invention addresses the "implicit trust" in satellite authentication in satellite networks and proposes a satellite network inter-satellite identity authentication method based on "zero trust". It also optimizes the design based on the limited communication resources in satellite network links: the future status information of other related satellites in the satellite network is uploaded to the satellites in the satellite network from the ground, and the satellites that receive the information calculate the summary of the status information through a summary algorithm. When identity authentication is required between satellites, the timestamp information and the summary of the status information are provided to each other to ensure the trustworthiness of each other's identities and complete the authentication.
[0041] (2) The method proposed in the present invention ensures that the current satellite status is consistent with the previously planned satellite status and is credible by verifying the on-board telemetry information; by verifying the summary information rather than the original status information, the transmission data volume of the verification data is controlled to a certain value, thereby realizing low-data-volume and reliable identity authentication.
[0042] (2) The present invention includes a complete authentication process and has high security and practical application value. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] Figure 1 Schematic diagram of the authorization architecture of the authentication method of the present invention;
[0044] Figure 2 Flowchart of the authentication method according to an embodiment of the present invention;
[0045] Figure 3 Schematic diagram of state information composition in an embodiment of the present invention. DETAILED DESCRIPTION
[0046] In order to better understand the technical solutions of the present invention, embodiments of the present invention are described in detail below with reference to the accompanying drawings.
[0047] The authorization architecture diagram of the authentication method proposed by the present invention is as follows: Figure 1 As shown, the objects involve ground systems, requester satellites, and verifier satellites.
[0048] The ground system is responsible for sending the verifier satellite's status information for the next period of time to the requester satellite participating in the identity authentication process within the satellite network, and for sending the requester satellite's status information for the next period of time to the verifier satellite. The requester satellite is the satellite that initiates the identity authentication request; the verifier satellite is the satellite that verifies the identity authentication request initiated by the requester satellite.
[0049] The method steps given in this embodiment can be referred to Figure 2 ,include:
[0050] (1) The ground system sends the future status information of the verifier satellite and the future status information of the requester satellite to the two satellites based on their identity positioning.
[0051] (2) The requester satellite and the verification satellite extract the timestamp in the future state information, generate the summary information of the corresponding future state information through a pre-agreed summary algorithm, and store the timestamp and the summary information of the future state information as a key-value pair in the internal database of each satellite.
[0052] (3) The requester satellite sends an authentication request message to the verifier satellite based on current needs.
[0053] The authentication request message includes the current timestamp and a summary of the requester's satellite's current state information. The requester's satellite's current state information is obtained by reading its own telemetry. The summary of the current state information is generated using a pre-agreed summary algorithm.
[0054] (4) After receiving the authentication request information, the verifier satellite compares it with the timestamp and summary information of the requester satellite's future status information stored in its own database to determine whether the authentication request information exists.
[0055] If the authenticator satellite is present, it returns authentication verification information to the requester satellite. This information includes the current timestamp and a summary of the authenticator satellite's current state. The authenticator satellite obtains its current state information by reading its own telemetry. The summary of the current state information is generated using a digest algorithm. If the authenticator satellite is not present, it does not respond to the requester satellite.
[0056] (5) After receiving the authentication verification information, the requester satellite compares it with the timestamp and summary information of the future status of the verifier satellite stored in its own database to determine whether the authentication verification information exists.
[0057] If it exists, a connection is established with the validator satellite. If it does not exist, no action is taken.
[0058] In one possible implementation, whether the future state information or the current state information of the requester satellite or the verifier satellite is Figure 3 As shown, its format includes timestamp, satellite ID, payload working status, and orbit numbers.
[0059] Load operating state: used to describe the specific operating state of the load, such as power on, power off, rotating, etc. The operating state of the load can be a single state or a combination of multiple states (such as rotating and transmitting signals).
[0060] Orbital Element Numbers: Used to describe the current orbital position of the satellite. The six orbital element numbers can be expressed in any format.
[0061] In a possible implementation, the digest algorithm uses the SHA256 algorithm.
[0062] The present invention also provides an authentication system, which is deployed on the ground terminal, the requesting satellite and the verifying satellite;
[0063] Ground terminal, including:
[0064] A ground sending module is used to send the verification satellite's future state information to the requesting satellite and send the requesting satellite's future state information to the verification satellite;
[0065] Request satellites, including:
[0066] The first information receiving module is used to receive the future status information of the verification satellite sent by the ground terminal; receive the authentication verification information sent by the verification satellite;
[0067] A first verification information generating module is used to generate verification satellite comparison verification information using the verification satellite future state information;
[0068] A first verification information storage module is used to store verification satellite comparison verification information;
[0069] The first comparison and verification module is used to compare the authentication verification information with the stored verification satellite comparison and verification information to obtain a verification comparison result;
[0070] A first information sending module is used to send authentication request information to the verification satellite;
[0071] Validation satellites, including:
[0072] The second information receiving module is used to receive the future state information of the requesting satellite sent by the ground terminal; and receive the authentication request information sent by the requesting satellite;
[0073] A second verification information generating module is used to generate requested satellite comparison verification information using the requested satellite future state information;
[0074] A second verification information storage module is used to store the requested satellite comparison verification information;
[0075] The second comparison and verification module is used to compare the authentication request information with the stored requested satellite comparison and verification information to obtain a request comparison result;
[0076] The second information sending module is used to send authentication verification information to the verification satellite.
[0077] The functions of each module are implemented according to the above method.
[0078] It will be understood that the present invention is described by way of example, and it will be appreciated by those skilled in the art that various changes or equivalent substitutions may be made to these features and embodiments without departing from the spirit and scope of the present invention. In addition, under the teachings of the present invention, these features and embodiments may be modified to adapt to specific circumstances without departing from the spirit and scope of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed herein, and any embodiment that falls within the scope of the claims of this application is intended to be within the scope of protection of the present invention.
[0079] The contents not described in detail in the specification of the present invention belong to the common knowledge of those skilled in the art.
Claims
1. A zero-trust based satellite inter-satellite identity authentication method, characterized in that: include: The ground terminal sends the verification satellite's future state information to the requesting satellite, and sends the requesting satellite's future state information to the verification satellite; The requesting satellite uses the future state information of the verification satellite to generate verification satellite comparison verification information and stores it; The verification satellite uses the future state information of the requesting satellite to generate and store comparison verification information of the requesting satellite; The requesting satellite sends an authentication request message to the verification satellite according to current needs; The verification satellite compares the authentication request information with the stored verification information of the requesting satellite; if the comparison is successful, the verification satellite returns the authentication verification information to the requesting satellite; The requesting satellite compares the authentication verification information with the stored verification satellite verification information; if the comparison is successful, the requesting satellite establishes a link with the verification satellite.
2. The zero-trust satellite inter-satellite identity authentication method according to claim 1, characterized in that: The requesting satellite uses the future status information of the verification satellite to generate verification information for comparison with the verification satellite. The specific method is as follows: Requesting the satellite to extract the timestamp in the future state information of the verification satellite, generating summary information of the future state information of the verification satellite through a summary algorithm, and storing the timestamp and summary information of the future state information of the verification satellite as a key-value pair; The verification satellite uses the future state information of the requesting satellite to generate the requesting satellite comparison verification information in the following ways: The verification satellite extracts the timestamp from the future state information of the requested satellite, generates summary information of the future state information of the requested satellite through a summary algorithm, and stores the timestamp and summary information of the future state information of the requested satellite as a key-value pair.
3. The zero-trust based satellite inter-satellite identity authentication method according to claim 2, characterized in that: The authentication request information includes a current timestamp and summary information of the requested satellite's current status information; After receiving the authentication request information, the verification satellite compares the current timestamp and the summary information of the requesting satellite's current status information with the stored requesting satellite comparison verification information. If it exists, the comparison passes; if not, the comparison fails.
4. The zero-trust based satellite inter-satellite identity authentication method according to claim 2, characterized in that: The authentication verification information includes a current timestamp and summary information of the current state information of the verification satellite; After receiving the authentication verification information, the requesting satellite compares the current timestamp and the summary information of the verification satellite's current status information with the stored verification satellite comparison verification information. If so, the comparison is successful; if not, the comparison fails.
5. The zero-trust-based satellite inter-satellite identity authentication method according to any one of claims 1 to 4, characterized in that: The future status information and current status information of a satellite are requested or verified in the same format, including: timestamp, satellite ID, payload working status and orbital elements.
6. A zero-trust satellite inter-satellite identity authentication system, characterized by: Deployed on the ground side, requesting satellites and verifying satellites; Ground terminal, including: A ground sending module is used to send the verification satellite's future state information to the requesting satellite and send the requesting satellite's future state information to the verification satellite; Request satellites, including: The first information receiving module is used to receive the future status information of the verification satellite sent by the ground terminal; receive the authentication verification information sent by the verification satellite; A first verification information generating module is used to generate verification satellite comparison verification information using future state information of the verification satellite; A first verification information storage module is used to store verification satellite comparison verification information; The first comparison and verification module is used to compare the authentication verification information with the stored verification satellite comparison and verification information to obtain a verification comparison result; A first information sending module is used to send authentication request information to the verification satellite; Validation satellites, including: The second information receiving module is used to receive the future state information of the requesting satellite sent by the ground terminal; and receive the authentication request information sent by the requesting satellite; A second verification information generating module is used to generate requested satellite comparison verification information using the future state information of the requested satellite; A second verification information storage module is used to store the requested satellite comparison verification information; The second comparison and verification module is used to compare the authentication request information with the stored requested satellite comparison and verification information to obtain a request comparison result; The second information sending module is used to send authentication verification information to the verification satellite.
7. The zero-trust satellite inter-satellite identity authentication system according to claim 6, characterized in that: The first verification information generation module generates the verification satellite comparison verification information in a specific manner: extracting the timestamp in the future state information of the verification satellite, generating summary information of the future state information of the verification satellite through a summary algorithm, and sending the timestamp and summary information of the future state information of the verification satellite as a key-value pair to the first verification information storage module; The second verification information generation module generates the requested satellite comparison verification information in the following specific manner: extracting the timestamp in the future state information of the requested satellite, generating summary information of the future state information of the requested satellite through a summary algorithm, and sending the timestamp and summary information of the future state information of the requested satellite as a key-value pair to the second verification information storage module.
8. The zero-trust-based satellite inter-satellite identity authentication system according to claim 6, characterized in that: The authentication request information includes a current timestamp and summary information of the requested satellite's current status information; The second comparison and verification module obtains the request comparison result in the following specific manner: after receiving the authentication request information, the second comparison and verification module compares whether the current timestamp and the summary information of the current status information of the requested satellite exist in the requested satellite comparison and verification information of the second verification information storage module. If so, the comparison passes; otherwise, the comparison fails.
9. The zero-trust-based satellite inter-satellite identity authentication system according to claim 6, characterized in that: The authentication verification information includes a current timestamp and summary information of the current state information of the verification satellite; The first comparison and verification module obtains the verification comparison result in the following specific manner: after receiving the authentication verification information, the current timestamp and the summary information of the verification satellite's current status information are compared to see whether they exist in the verification satellite comparison verification information of the first verification information storage module. If so, the comparison passes; otherwise, the comparison fails.
10. The zero-trust satellite inter-satellite identity authentication system according to any one of claims 6 to 9, characterized in that: The future status information and current status information of a satellite are requested or verified in the same format, including: timestamp, satellite ID, payload working status and orbital elements.
Citation Information
Patent Citations
Satellite-ground and inter-satellite networking authentication method and system fused with double-layer satellite network and application
CN112953726A
Enhanced inter-satellite networking authentication method based on location key
CN114828005A