Navigation Signal Authentication Method, Network Device, Terminal Device, Chip, Computer Readable Storage Medium and Computer Program Product Based on Composite Code Shift Keying Signal

By generating encrypted composite code keyshift control signals and performing dual authentication, the security and measurement accuracy problems of the existing technology medium and low-orbit satellite signal authentication are solved, and the second-level authentication of low-orbit satellite MCSK signals is realized, which improves the anti-spoofing ability of navigation signals.

CN119788292BActive Publication Date: 2025-07-11CHINA SATELLITE NETWORK SYSTEM CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510248768.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-04
Publication Date
2025-07-11
Estimated Expiration
2045-03-04

AI Technical Summary

Technical Problem

When existing navigation signal authentication technology faces spoofing attacks, especially for composite code-shift keying signals of low-orbit satellites, it is difficult to achieve effective second-level signal authentication, and cannot guarantee measurement accuracy and security at the same time.

Method used

The navigation signal authentication method based on the composite code key shift control signal is adopted. By generating an encrypted code key shift control code, combining navigation message authentication and spread spectrum code authentication, the composite code key shift control signal is generated, and digital signature and spread spectrum code authentication is carried out to achieve dual authentication at the information level and signal level.

Benefits of technology

Without losing measurement accuracy, the second-level authentication of low-orbit satellite MCSK signals is achieved, improving the anti-spoofing ability and safety.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119788292B_ABST
    Figure CN119788292B_ABST
Patent Text Reader

Abstract

Provided are a navigation signal authentication method, a network device, a terminal device, a chip, a computer-readable storage medium, and a computer program product based on a composite code shift keying signal, relating to the technical field of navigation signal processing. The navigation signal authentication method based on a composite code shift keying signal includes: generating a code shift keying code based on spreading code parameters; using a ciphertext to replace target chips within a code shift keying code period in an authentication period to obtain an encrypted code shift keying code; generating a digital signature based on a target message within the authentication period; generating an authentication message, where the authentication message includes navigation message authentication information and spreading code authentication information, the navigation message authentication information is used for digital signature authentication, and the spreading code authentication information is used for spreading code authentication; modulating the authentication message and a high-speed message of the navigation message based on the encrypted code shift keying code, and modulating a low-speed message of the navigation message through binary phase shift keying to generate a composite code shift keying signal; and broadcasting the composite code shift keying signal.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of navigation signal processing, and particularly relates to a navigation signal authentication method, a network device, a terminal device, a chip, a computer-readable storage medium, and a computer program product based on a composite code shift keying signal. Background Art

[0002] Navigation signal authentication refers to using encryption features to counter spoofing and providing navigation signal authentication services. Among them, authentication refers to verifying the authenticity of the signal and the sending information entity (i.e., entity authentication and data source authentication). Authentication can play a role at the level of the satellite ephemeris broadcast in the navigation message or at the level of the spreading code used for ranging. Both the message and the spreading code are modulated into the Global Navigation Satellite System (GNSS) signal.

[0003] Current authentication technologies include Navigation message authentication (NMA) and Spreading code authentication (SCA). Navigation message authentication means protecting the navigation message bits (i.e., the entire data frame or part of the bits). Navigation message authentication can be achieved by digitally signing the navigation data. Therefore, the navigation message remains clean (i.e., unencrypted) and can be used by non-authenticated users. Spreading code authentication inserts unpredictable parts (i.e., encrypted chips) into the nominal (unencrypted) spreading code and then verifies through a cryptographic function.

[0004] Navigation message authentication is only authentication at the information level. In theory, a spoofing attacker can demodulate the message, modify the signal by regeneration, and implement spoofing. Therefore, the anti-spoofing ability is generally average. While spreading code authentication is authentication at the signal level, the information and the signal are bound and cannot be modified. Therefore, the security level is higher. Summary of the Invention

[0005] In view of this, a navigation signal authentication method, a network device, a terminal device, a chip, a computer-readable storage medium, and a computer program product based on a composite code shift keying signal are provided.

[0006] In a first aspect, a navigation signal authentication method based on a composite code shift keying signal is provided, including:

[0007] Generating a code shift keying code based on spreading code parameters;

[0008] Replacing target chips within the code shift keying code period in the authentication period with encrypted chips to obtain an encrypted code shift keying code;

[0009] Generating a digital signature based on the target message within the authentication period;

[0010] Generate an authentication message, where the authentication message includes navigation message authentication information and spread spectrum code authentication information. The navigation message authentication information is used for digital signature authentication, and the spread spectrum code authentication information is used for spread spectrum code authentication;

[0011] Modulate the authentication message and the high-speed message of the navigation message based on the encrypted code shift keying code, and generate a composite code shift keying signal by modulating the low-speed message of the navigation message through binary phase shift keying;

[0012] Broadcast the composite code shift keying signal.

[0013] In a second aspect, a navigation signal authentication method based on a composite code shift keying signal is provided, including:

[0014] Receive a composite code shift keying signal;

[0015] Demodulate the composite code shift keying signal to obtain an authentication message;

[0016] Authenticate the digital signature based on the navigation message authentication information in the authentication message, and authenticate the spread spectrum code based on the spread spectrum code authentication information in the authentication message.

[0017] In a third aspect, a satellite network device is provided. The satellite network device includes: one or more processors; and one or more memories coupled to the one or more processors and storing instructions thereon. When the instructions are executed by the one or more processors alone or jointly, the satellite network device executes the method described in the first aspect.

[0018] In a fourth aspect, a terminal device is provided. The terminal device includes: one or more processors; and one or more memories coupled to the one or more processors and storing instructions thereon. When the instructions are executed by the one or more processors alone or jointly, the terminal device executes the method described in the second aspect.

[0019] In a fifth aspect, a chip is provided. The chip includes a circuit system configured to execute the method described in the first aspect or the second aspect.

[0020] In a sixth aspect, a non-transitory computer-readable storage medium storing machine-executable instructions is provided. When the machine-executable instructions are executed by one or more processors of the machine, the machine executes the method described in the first aspect or the second aspect.

[0021] In a seventh aspect, a computer program product including machine-executable instructions is provided. When the machine-executable instructions are executed by one or more processors of the machine, the machine executes the method described in the first aspect or the second aspect.

[0022] It should be understood that the Summary of the Invention section is not used to identify the key or essential features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Through the following description, other features of the present disclosure will become readily understandable. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] By a more detailed description of some embodiments of the present disclosure in the drawings, the above and other objects, features, and advantages of the present disclosure will become more apparent, wherein:

[0024] Figure 1 An exemplary communication network in which exemplary embodiments of the present disclosure can be implemented is shown;

[0025] Figure 2 A schematic structural diagram of a composite code shift keying signal according to some embodiments of the present disclosure is shown;

[0026] Figure 3 A flowchart of an exemplary method for authenticating a navigation signal based on a composite code shift keying signal according to some embodiments of the present disclosure is shown;

[0027] Figure 4 A flowchart of an exemplary method for generating a composite code shift keying signal according to some embodiments of the present disclosure is shown;

[0028] Figure 5 A schematic structural diagram of the navigation message authentication information of an authentication message according to some embodiments of the present disclosure is shown;

[0029] Figure 6 A schematic structural diagram of the spread spectrum code authentication information of an authentication message according to some embodiments of the present disclosure is shown;

[0030] Figure 7 A schematic structural diagram of a composite code shift keying signal according to some embodiments of the present disclosure is shown;

[0031] Figure 8 A flowchart of an exemplary method for authenticating a composite code shift keying signal according to some embodiments of the present disclosure is shown;

[0032] Figure 9 A simplified block diagram of a device suitable for implementing exemplary embodiments of the present disclosure is shown. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0033] The principles of the present disclosure will now be described with reference to some embodiments. It should be understood that the description of these embodiments is for illustrative purposes only and helps those skilled in the art to understand and implement the present disclosure, without imposing any limitation on the scope of the present disclosure. The disclosure described herein may be implemented in a different manner than described below.

[0034] In the following description and claims, unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure belongs.

[0035] References in this disclosure to "one embodiment", "an embodiment", "an exemplary embodiment", etc., indicate that the described embodiment may include a particular feature, structure, or characteristic, but not necessarily every embodiment includes the particular feature, structure, or characteristic. Moreover, such phrases do not necessarily refer to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an exemplary embodiment, whether or not explicitly described, those skilled in the art will recognize such feature, structure, or characteristic in connection with other embodiments.

[0036] It should be understood that although terms such as "first" and "second" may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, without departing from the scope of the exemplary embodiments, a first element may be termed a second element, and similarly, a second element may be termed a first element. The term "and / or" used herein includes any and all combinations of one or more of the listed terms.

[0037] The terms used herein are for the purpose of describing particular embodiments only and are not intended to be limiting of the exemplary embodiments. The singular forms "a", "an", and "the" used herein also include the plural forms unless the context clearly dictates otherwise. The term "a set of elements" or "a collection of elements" as used herein is intended to include one or more elements. It should also be understood that the terms "comprises", "comprising", "has", "having", "includes", and / or "including", when used herein, specify the presence of the stated features, elements, and / or components, etc., but do not preclude the presence or addition of one or more other features, elements, components, and / or combinations thereof.

[0038] As used herein, the term "circuit" may refer to one or more or all of the following:

[0039] (a) only hardware circuit implementations (e.g., only in analog and / or digital circuits);

[0040] (b) combinations of hardware circuits and software, e.g., as applicable:

[0041] (i) combinations of analog and / or digital hardware circuits and software / firmware; and

[0042] (ii) any portion of a hardware processor (including a digital signal processor) with software and memory, which work together to cause a device such as a mobile phone or a server to perform various functions; and

[0043] (c) A hardware circuit and / or a processor, such as a microprocessor or a part of a microprocessor, which requires software (e.g., firmware) to operate, but the software may be absent when it is not required to operate.

[0044] The definition of the circuit applies to all uses of the term in this application, including in any claim. As another example, as used in this application, the term circuit also includes an implementation of only a hardware circuit or a processor (or processors) or a part of a hardware circuit or a processor and its (or their) accompanying software and / or firmware. The term circuit also includes, for example, if applicable to a particular claim element, a baseband integrated circuit or a processor integrated circuit for a mobile device, or a similar integrated circuit in a server, a cellular network device, or other computing network devices.

[0045] The term "communication network" refers to a network that follows any appropriate communication standard, such as Long Term Evolution (LTE), LTE-Advanced (LTE-A), Wideband Code Division Multiple Access (WCDMA), High Speed Packet Access (HSPA), Narrowband Internet of Things (NB-IoT), New Radio (NR), Non-Terrestrial Network (NTN), etc. Additionally, the communication between a terminal device and a network device in a communication network can be performed according to any appropriate generation of communication protocol, including but not limited to the first generation (1G), second generation (2G), 2.5G, 2.75G, third generation (3G), fourth generation (4G), 4.5G, fifth generation (5G), future sixth generation (6G) communication protocols, and / or any other protocol known currently or to be developed in the future. Embodiments of the present disclosure can be applied to satellite communication systems. Considering the rapid development in communication, of course, there will also be future types of communication technologies and systems, and the present disclosure can be implemented with these technologies and systems. The scope of the present disclosure should not be considered limited to the foregoing systems.

[0046] The term "satellite network device" refers to a node set on a satellite or a ground segment in a satellite communication network. A terminal device accesses the network through this node and receives services therefrom. Depending on the terms and technologies applied, the satellite network device may refer to a base station (BS) or an access point (AP) as a satellite payload, such as Node B (NodeB or NB), evolved Node B (eNodeB or eNB), NR NB (also referred to as gNB), Remote Radio Unit (RRU), Radio Header (RH), Remote Radio Header (RRH), relay node. An example of a relay node can be an Integrated Access and Backhaul (IAB) node. The Distributed Unit (DU) part of an IAB node can perform the function of a "satellite network device" and thus can operate as a network device. In the following description, the terms "satellite network device", "BS", and "node" can be used interchangeably.

[0047] The term "terminal device" refers to any terminal device capable of wireless communication. By way of example and not limitation, the terminal device may also be referred to as a communication device, user equipment (UE), user station (SS), portable user station, mobile station (MS), or access terminal (AT). The terminal device may include, but is not limited to, mobile phones, cellular phones, smart phones, IP voice (VoIP) phones, wireless local loop phones, tablet computers, wearable terminal devices, personal digital assistants (PDAs), portable computers, desktop computers, image capture terminal devices such as digital cameras, game terminal devices, music storage and playback devices, in-vehicle wireless terminal devices, wireless endpoints, mobile stations, laptop embedded devices (LEEs), laptop mounted devices (LMEs), USB dongles, smart devices, wireless customer premise equipment (CPE), Internet of Things (IoT) devices, watches or other wearable devices, head-mounted displays (HMDs), vehicles, drones, medical devices and applications (e.g., remote surgery), industrial devices and applications (e.g., robots and / or other wireless devices operating in the context of an industrial and / or automation processing chain), consumer electronic devices, relay nodes, devices operating on commercial and / or industrial wireless networks, etc. The mobile terminal (MT) part of an IAB node can perform the functions of a "terminal device" and thus can operate as a terminal device. In the following description, the terms "terminal device", "communication device", "terminal", "user equipment", and "UE" may be used interchangeably.

[0048] Although the functions described herein may be performed in fixed and / or wireless network nodes in various exemplary embodiments, in other exemplary embodiments, the functions may be implemented in a user equipment device such as a cellular phone, or a tablet computer, or a laptop computer, or a desktop computer, or a mobile IoT device, or a fixed IoT device. For example, the user equipment device may suitably have the corresponding capabilities associated with fixed and / or wireless network nodes. The user equipment device may be a user equipment and / or a control device, such as a chipset or a processor, configured to control the user equipment when the user equipment is installed therein. Examples of such functions include a bootstrapping server function and / or a home subscriber server, which may be implemented in the user equipment device by providing software configured to cause the user equipment device to perform from the perspective of these functions / nodes.

[0049] Figure 1FIG. 100 illustrates an exemplary communication network 100 in which embodiments of the present disclosure may be implemented. The communication network 100 includes a satellite network device 110 and terminal devices 120 served by the satellite network device 110. The satellite network device 110 may include satellite network devices 110A, 110B, and 110C, and the terminal devices 120 may include terminal devices 120A and 120B. The communication network 100 may provide a serving cell 130 to serve the terminal devices 120. The satellite communication network may include low Earth orbit satellites (LEO), medium Earth orbit satellites (MEO), and geostationary Earth orbit satellites (GEO).

[0050] It should be understood that the numbers of the satellite network device 110, the terminal devices 120, and the serving cell 130 are for illustrative purposes only and are not intended to impose any limitations. The communication network 100 may include any suitable numbers of satellite network devices, terminal devices, and serving cells adapted to implement the embodiments of the present disclosure. It should be noted that the terms "cell" and "serving cell" may be used interchangeably herein.

[0051] In the communication network 100, the satellite network device 110 may transmit data and control information to the terminal devices 120, and the terminal devices 120 may also transmit data and control information to the satellite network device 110. The link from the satellite network device 110 to the terminal device 120 is referred to as the downlink (DL) or forward link, while the link from the terminal device 120 to the satellite network device 110 is referred to as the uplink (UL) or reverse link. The satellite network device 110 may broadcast navigation messages to the terminal devices 120, and the terminal devices 120 implement functions such as navigation and positioning based on the received navigation messages.

[0052] The communication in the communication network 100 may comply with any suitable standards, but is not limited to Long Term Evolution (LTE), LTE Evolution, LTE-Advanced (LTE-A), Wideband Code Division Multiple Access (WCDMA), Code Division Multiple Access (CDMA), and Global System for Mobile Communications (GSM), etc. In addition, the communication may be performed according to any generation of communication protocols known currently or developed in the future. Examples of communication protocols include, but are not limited to, the first generation (1G), the second generation (2G), 2.5G, 2.75G, the third generation (3G), the fourth generation (4G), 4.5G, the fifth generation (5G), and the sixth generation (6G) communication protocols.

[0053] The navigation message is a message broadcast by navigation satellites to users, describing the operating state parameters of the navigation satellites, including the time scale information, ephemeris parameters, clock error parameters, satellite status parameters, almanac parameters, ionospheric parameters, etc. of the navigation satellites themselves. In some embodiments, the navigation message includes a low-speed message and a high-speed message. The low-speed message includes basic navigation information for measurement with a slow update speed, such as the time scale information, ephemeris parameters, clock error parameters, satellite status parameters, almanac parameters, ionospheric parameters, etc. of the navigation satellites themselves. The high-speed message includes navigation enhancement information with a fast update speed, such as the orbits of all navigation satellite systems, carrier phase deviation, and code deviation, etc.

[0054] When generating the navigation signal, the low-speed message of the navigation message can be modulated by binary phase shift keying (BPSK) to form a BPSK code period, and the high-speed message of the navigation message can be modulated by code shift keying (CSK) to form a CSK code period. The BPSK code period and the CSK code period are alternately arranged to form a multiplexed code shift keying (MCSK) signal 200, as Figure 2 shown.

[0055] Existing navigation signal authentication is designed for GNSS signals and cannot be directly applied to the MCSK signals of low-earth orbit satellites. The embodiments of the present disclosure propose a navigation signal authentication method based on MCSK signals to implement the navigation signal authentication of MCSK signals, and combine navigation message authentication and spreading code authentication to achieve second-level signal authentication.

[0056] Figure 3 shows a schematic flow chart of a navigation signal authentication method based on a multiplexed code shift keying signal according to some embodiments of the present disclosure. As Figure 3 shown, the navigation signal authentication method 300 based on the multiplexed code shift keying signal includes the following steps:

[0057] Step S301, generation of the multiplexed code shift keying signal.

[0058] In the stage of generating the multiplexed code shift keying signal, it includes generating a CSK code, encrypting the spreading code, generating a digital signature, generating an authentication message, generating the multiplexed code shift keying signal, and broadcasting the multiplexed code shift keying signal.

[0059] Step S302, authentication of the multiplexed code shift keying signal.

[0060] In the stage of authenticating the multiplexed code shift keying signal, after the terminal device 120 (such as the receiver in the terminal device 120) tracks, demodulates, and synchronizes, digital signature authentication and spreading code authentication are performed.

[0061] The disclosed embodiment performs dual authentication at the information level and the signal level, and can achieve second-level authentication of MCSK signals without losing measurement accuracy.

[0062] Now refer to Figure 4 . Figure 4 4 is a flow chart showing an exemplary method 400 for generating a composite code shift keying signal according to some embodiments of the present disclosure. The method 400 may be implemented on a device, such as Figure 1 The satellite network device 110 is shown. For the purpose of discussion, reference will be made to Figure 1 Method 400 is described. Method 400 may involve Figure 1 Satellite network device 110 and terminal devices 120A and 120B are shown. It should be understood that method 400 may include additional steps not shown and / or may omit some of the steps shown, and the scope of the present disclosure is not limited in this regard.

[0063] In step S401, a code shift keying code is generated based on a spread spectrum code parameter.

[0064] In step S402, the encryption code is used to replace the target code chip in the code shift keying code period in the authentication period to obtain an encrypted code shift keying code.

[0065] In some embodiments, the target code chip is a code chip at a target position of a target code shift keying code period within a target time period in an authentication period, the target code shift keying code period is one or more code shift keying code periods, and the target position is one or more continuous code chip positions.

[0066] In an exemplary embodiment, let the authentication period be T seconds, and encrypt part of the code chips in at least part of the CSK code period in the last 1 second of each authentication period T. Specifically, select N in the CSK code period in the last 1 second of the authentication period T. period code period, the N period The code period is the target code shift keying code period. Use the encryption code to replace this N period The last N code cycles chip chips, that is, there are N chip_total =N period ×N chip The chips are encrypted. period The position of each code period can be given through the authentication message, or it can be the default position of the network system. chip_total 、N period and N chip The choice can be determined according to the required encryption strength. The larger the value, the higher the encryption strength.

[0067] In the above embodiment, the last 1s of the authentication cycle T is the target time period, and the last N of the code cycle chipThe position of a chip is the target position. It can be understood that the target code shift keying code period can be selected during other time periods in the authentication period T, and the chips at other positions of the target code shift keying code period can also be replaced with encrypted codes. The target time period and the target position can both be default values of the network system or can be given through the authentication message.

[0068] In some embodiments, the generation method of the encrypted code includes: selecting the initial phase for generating the encrypted code from the message digest in the digital signature generation process; generating the encrypted code based on the encrypted code generation polynomial and the initial phase for generating the encrypted code.

[0069] In an exemplary embodiment, based on the encrypted code generation polynomial and the initial phase for generating the encrypted code, N chip_total encrypted codes for chips are generated and evenly divided into N period parts, each part having N chip chips, which are used to replace the last N period chips of the selected N chip CSK code periods. In the last 1 s of each authentication period T seconds, the CSK code periods are counted. If the current CSK code period belongs to the code period at the encrypted code position, the last N chip chips of the CSK code period are replaced with the encrypted codes of N chip chips.

[0070] The initial phase for generating the encrypted code can be selected from HASH-A, so that the spread spectrum code authentication is bound to the navigation message authentication. Among them, HASH-A is the message digest obtained by mapping the target message within the authentication period through the hash (HASH) algorithm. For example, HASH-A is the 256-bit message digest obtained by mapping the target message through the HASH algorithm. The initial phase for generating the encrypted code can select the first 32 bits of the 256 bits of HASH-A, with bits 1-16 as the initial phase of the first generation polynomial and bits 17-32 as the initial phase of the second generation polynomial. Since HASH-A is bound to the digital signature of the navigation message authentication, the values of the N chip_total encrypted codes are bound to the navigation message authentication. Therefore, the spread spectrum code authentication is bound to the navigation message authentication.

[0071] In step S403, generate a digital signature based on the target message within the authentication period.

[0072] In some embodiments, generating a digital signature based on a target message within an authentication period includes: mapping the target message within the authentication period to a message digest through a hashing (HASH) algorithm; encrypting the message digest using an asymmetric encryption algorithm to generate a digital signature. Among them, the target message may include time stamp information, ephemeris parameters, and clock offset parameters of low-speed messages, as well as some high-speed messages. Using an asymmetric encryption algorithm, such as the ECDSA encryption algorithm, to authenticate navigation messages for the time stamp information, ephemeris parameters, and clock offset parameters of low-speed messages, as well as some high-speed messages, with each T seconds as an authentication period, improves security and reduces computational complexity.

[0073] In an exemplary embodiment, the target message N within the authentication period (such as time stamp information, ephemeris parameters, and clock offset parameters of low-speed messages, as well as some high-speed messages) is mapped to a 256-bit message digest through the HASH algorithm, denoted as HASH-A. Combining the private key d and HASH-A, using the ECDSA encryption algorithm, a digital signature pair (r, s) is generated. The embodiments of the present disclosure use the ECDSA encryption algorithm. When the timing accuracy ( is the user's time estimation error), the ECDSA encryption algorithm can ensure authentication security.

[0074] In step S404, an authentication message is generated.

[0075] The authentication message is similar to the high-speed message, with the same channel coding scheme, and an authentication message is broadcast every T seconds in each authentication period. The authentication message includes navigation message authentication information and spread spectrum code authentication information. Among them, the navigation message authentication information is used for digital signature authentication, and the spread spectrum code authentication information is used for spread spectrum code authentication. In some embodiments, the spread spectrum code authentication information indicates the position of the encryption code, such as the position of the target code shift keying code period, etc. The structure of the authentication message is as Figures 5 - 6 shown, where Figure 5 shows a schematic structural diagram of the navigation message authentication information of the authentication message according to some embodiments of the present disclosure, Figure 6 shows a schematic structural diagram of the spread spectrum code authentication information of the authentication message according to some embodiments of the present disclosure.

[0076] In step S405, based on the encrypted code shift keying code modulated authentication message and the high-speed message of the navigation message, the low-speed message of the navigation message is modulated by binary phase shift keying to generate a composite code shift keying signal.

[0077] Using the encrypted CSK code for spreading spectrum, after channel coding the authentication message, an MCSK signal 600 is generated, as Figure 7As shown. The spread spectrum code authentication in the embodiments of the present disclosure is only performed during the CSK code period in the MCSK signal 600. The BPSK code period in the MCSK signal 600 is used for measurement and does not affect the measurement performance.

[0078] Compared with the existing CSK code period of the MCSK signal that only uses code shift phase modulation messages. The embodiments of the present disclosure utilize the information broadcasting capability reserved in the MCSK signal and use the code period polarity modulation authentication message reserved in the CSK code period, which can effectively support additional broadcasting requirements such as digital signatures and keys that need to be broadcast for signal authentication.

[0079] In step S406, broadcast a composite code shift keying signal.

[0080] Users tracking the primary spread spectrum sequence have a small correlation loss demodulation loss in one of the N period CSK code periods (for example, when the CSK code length is 2046 chips and N chip = 200, the loss is less than 0.9 dB), which can be compensated by increasing the average transmit power. Since some chips are encrypted, for non-authenticated users, the original spread spectrum code series is still used, which is related to the authentication signal, and the correlation power will decrease. Therefore, in order to ensure that the correlation power of unauthorized users remains unchanged, the spread spectrum code authentication signal needs to increase the signal transmit power.

[0081] In an exemplary embodiment, let the authentication period be T = 10 s, the CSK code rate be 5.115 MHz, and the code length be 2046 Chip. In the spread spectrum code encryption stage, some chips in the CSK code period of the last 1 s in each authentication period of 10 s are encrypted. For example, for the last N period = 30 code periods out of the 2500 CSK code periods in the last 1 s, the last N chip = 200 chips are replaced with encrypted chips, that is, only N period ×N chip = 6000 chips are encrypted. The impact on the demodulation of N period CSK code periods is as follows: , which only results in a loss of less than 0.9 dB for N period CSK code periods.

[0082] Now refer to Figure 8 . Figure 8 FIG. shows a flowchart of an exemplary method 700 for composite code shift keying signal authentication according to some embodiments of the present disclosure. Method 700 can be implemented on a device, such as Figure 1 the terminal device 120 shown. For the purpose of discussion, method 700 will be described with reference to Figure 1 . Method 700 may involve Figure 1The satellite network device 110 and the terminal devices 120A and 120B shown. It should be understood that the method 700 may include additional steps not shown and / or some of the shown steps may be omitted, and the scope of the present disclosure is not limited to this point.

[0083] In step S701, receive a composite code shift keying signal.

[0084] In step S702, demodulate the composite code shift keying signal to obtain an authentication message.

[0085] The terminal device 120 receives the MCSK signal, and after tracking demodulation and bit synchronization, obtains an authentication message. The authentication message includes navigation message authentication information and spreading code authentication information. Among them, the navigation message authentication information is used for digital signature authentication, and the spreading code authentication information is used for spreading code authentication. In some embodiments, demodulating the composite code shift keying signal includes: demodulating the high-speed message data and the authentication message data in the composite code shift keying signal according to the code shift keying mode, and demodulating the low-speed message data in the composite code shift keying signal according to the binary phase shift keying mode.

[0086] In step S703, authenticate the digital signature based on the navigation message authentication information in the authentication message, and authenticate the spreading code based on the spreading code authentication information in the authentication message.

[0087] The process of digital signature authentication includes: decrypting using the public key, and if the signature verification is correct, it indicates successful authentication. The public key pair (x Q , y Q ) can be obtained through a trusted certification authority, set when the terminal leaves the factory, subsequently obtained through the network, or updated by receiving an authentication message frame.

[0088] In some embodiments, authenticating the spreading code based on the spreading code authentication information in the authentication message includes: obtaining the first chip correlation value corresponding to the target chip in the chip shift keying code period within one authentication period of the composite code shift keying signal; generating an encrypted chip based on the spreading code authentication information in the authentication message to obtain the corresponding second chip correlation value; correlating the first chip correlation value with the second chip correlation value to obtain a correlation result; in response to the correlation result being greater than the threshold value, the authentication is successful, otherwise the authentication fails. Among them, the target chip is the chip at the target position in the target chip shift keying code period within the target time period in one authentication period, the target chip shift keying code period is one or more chip shift keying code periods, and the target position is one or more consecutive chip positions. In some embodiments, the position of the target chip shift keying code period can also be obtained based on the spreading code authentication information in the authentication message.

[0089] In an exemplary embodiment, the last N in the target CSK code period in the last 1 s of each authentication period T chipThe chip - related value corresponding to each chip (i.e., the first chip - related value) is stored. According to the spread - spectrum code authentication information (such as encryption parameters) in the received authentication message, N chip_total encrypted chips are generated. According to 24 encrypted chip positions, the corresponding N chip_total chip - related values (i.e., the second chip - related values) are selected, correlated with the N chip_total first chip - related values to obtain a correlation result, which is compared with a threshold value TH. If it is greater than the threshold value, the authentication is successful; otherwise, it fails. Among them, TH can be obtained according to the false - alarm probability or set as needed. The related value mentioned here refers to the I and Q chip - related values obtained by stripping the authentication message.

[0090] Figure 9 FIG. is a simplified block diagram of a device 800 suitable for implementing an embodiment of the present disclosure. For example, the satellite network device 110 and / or the terminal device 120 can be implemented by the device 800. As shown in the figure, the device 800 includes one or more processors 810, one or more memories 820 coupled to the processor 810, and one or more communication modules 840 coupled to the processor 810.

[0091] The communication module 840 is used for two - way communication. The communication module 840 has at least one antenna to facilitate communication. The communication interface can represent any interface necessary for communicating with other network elements.

[0092] The processor 810 can be of any type suitable for the local technical network and, by way of non - limiting example, can include one or more of the following: general - purpose computer, special - purpose computer, microprocessor, digital signal processor (DSP), and a processor based on a multi - core processor architecture. The device 800 can have multiple processors, such as an application - specific integrated circuit chip, which is clocked to synchronize with the main processor in a timely manner.

[0093] The memory 820 can include one or more non - volatile memories and one or more volatile memories. Examples of non - volatile memories include, but are not limited to, read - only memory (ROM) 824, electrically programmable read - only memory (EPROM), flash memory, hard disk, optical disc (CD), digital video disc (DVD), and other magnetic and / or optical memories. Examples of volatile memories include, but are not limited to, random - access memory (RAM) 822 and other volatile memories that do not persist during a power - off duration.

[0094] The computer program 830 includes computer - executable instructions executed by the relevant processor 810. The program 830 can be stored in the ROM 824. The processor 810 can execute any appropriate actions and processes by loading the program 830 into the RAM 822.

[0095] Embodiments of the present disclosure may be implemented by a program 830 such that the device 800 can perform references Figure 3 and Figure 4 and Figure 8 any of the disclosed processes discussed. Embodiments of the present disclosure may also be implemented by hardware or by a combination of software and hardware.

[0096] In some embodiments, the program 830 may be tangibly embodied in a computer-readable medium, which may be included in the device 800 (e.g., the memory 820) or other storage devices accessible to the device 800. The device 800 may load the program 830 from the computer-readable medium into the RAM 822 for execution. The computer-readable medium may include any type of tangible non-volatile memory, such as ROM, EPROM, flash memory, hard disk, CD, DVD, etc. The program 830 is stored on the computer-readable medium.

[0097] Generally, the various embodiments of the present disclosure may be implemented in hardware or a special-purpose circuit, software, logic, or any combination thereof. Certain aspects may be implemented in hardware, while other aspects may be implemented in firmware or software, which may be executed by a controller, a microprocessor, or other computing devices. Although the various aspects of the embodiments of the present disclosure are shown and described as block diagrams, flowcharts, or using some other graphical representation, it should be understood that, by way of non-limiting example, the blocks, devices, systems, techniques, or methods described herein may be implemented in hardware, software, firmware, special-purpose circuits or logic, general-purpose hardware or controllers or other computing devices, or some combination thereof.

[0098] The present disclosure also provides at least one computer program product tangibly stored on a non-transitory computer-readable storage medium. The computer program product includes computer-executable instructions, such as instructions included in program modules, which are executed in a device on a target real or virtual processor to perform the above references Figure 3 described method 300, and / or the above reference Figure 4 described method 400, and / or the above reference Figure 8 described method 700. Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, etc. that perform specific tasks or implement specific abstract data types. In various embodiments, the functions of program modules may be combined or separated as needed among program modules. The machine-executable instructions for program modules may be executed within a local or distributed device. In a distributed device, program modules may be located in local and remote storage media.

[0099] The program code for performing the methods of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to the processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the program code is executed by the processor or controller, the functions / operations specified in the flowchart and / or block diagram are implemented. The program code can be executed entirely on the machine as an independent software package, partially on the machine, partially on the machine, partially on a remote machine, partially on a remote machine, or entirely on a remote machine or server.

[0100] In the context of the present disclosure, the computer program code or related data can be carried by any suitable carrier to enable a device, apparatus, or processor to perform the various processes and operations described above. Examples of carriers include signals, computer-readable media, and the like.

[0101] The computer-readable media can be a computer-readable signal medium or a computer-readable storage medium. The computer-readable media can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or apparatuses, or any suitable combination of the foregoing. More specific examples of the computer-readable storage medium include an electrical connection having one or more wires, a portable computer floppy disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0102] Furthermore, although the operations are described in a specific order, this should not be construed as requiring that the operations be performed in the specific order or sequence shown, or that all of the shown operations be performed, to obtain the desired result. In some cases, multitasking and parallel processing may be advantageous. Similarly, although several specific implementation details are included in the above discussion, these details should not be construed as limiting the scope of the present disclosure, but rather can be construed as descriptions of specific features particular to a specific embodiment. Certain features described in the context of separate embodiments can also be implemented in combination in a single embodiment. Conversely, the various features described in the context of a single embodiment can also be implemented separately or in any suitable sub-combination in multiple embodiments.

[0103] Although the present disclosure has been described in a language specific to structural features and / or methodological acts, it should be understood that the present disclosure as defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.

[0104] It should be fully understood that the use of personally identifiable information should follow privacy policies and practices that are generally considered to meet or exceed industry or government requirements for maintaining user privacy. In particular, personally identifiable information data should be managed and processed to minimize the risk of inadvertent or unauthorized access or use, and the nature of the authorized use should be clearly indicated to the user.

Claims

1. A navigation signal authentication method based on a composite code shift keying signal, characterized in that Comprising: Generating a code shift keying code based on spread spectrum code parameters; Replacing target chips within the code shift keying code period in the authentication period with encryption codes to obtain an encrypted code shift keying code, where the target chips are the chips at the target positions within the target code shift keying code period in the target time period in the authentication period, the target code shift keying code period is one or more code shift keying code periods, and the target positions are one or more consecutive chip positions; Generating a digital signature based on the target message within the authentication period; Generating an authentication message, where the authentication message includes navigation message authentication information and spread spectrum code authentication information, the navigation message authentication information is used for digital signature authentication, and the spread spectrum code authentication information is used for spread spectrum code authentication; Modulating the authentication message and the high-speed message of the navigation message based on the encrypted code shift keying code, and modulating the low-speed message of the navigation message through binary phase shift keying to generate a composite code shift keying signal, where the authentication message is modulated through the polarity of the code shift keying code period, and the high-speed message is modulated through the code phase of the code shift keying code period; Broadcasting the composite code shift keying signal; Wherein, the generating a digital signature based on the target message within the authentication period includes: Mapping the target message within the authentication period to a message digest through a hashing algorithm; Encrypting the message digest using an asymmetric encryption algorithm to generate a digital signature; And the method further includes: Selecting an encryption code from the message digest to generate an initial phase; Generating the encryption code based on the encryption code generation polynomial and the encryption code generation initial phase; 2. The method according to claim 1, wherein The target message includes time scale information, ephemeris parameters, and clock error parameters of the low-speed message, as well as part of the high-speed message; 3. A navigation signal authentication method based on a composite code shift keying signal, characterized in that, Comprising: Receiving a composite code shift keying signal; Demodulating the composite code shift keying signal to obtain an authentication message; Authenticating the digital signature based on the navigation message authentication information in the authentication message, and authenticating the spread spectrum code based on the spread spectrum code authentication information in the authentication message, where the digital signature is generated by encrypting a message digest using an asymmetric encryption algorithm, and the message digest is obtained by mapping the target message within the authentication period through a hashing algorithm; Wherein, the demodulating the composite code shift keying signal includes: Demodulating the high-speed message data and the authentication message data in the composite code shift keying signal in the code shift keying mode, and demodulating the low-speed message data in the composite code shift keying signal in the binary phase shift keying mode, where the authentication message is modulated through the polarity of the code shift keying code period, and the high-speed message is modulated through the code phase of the code shift keying code period; And the authenticating the spread spectrum code based on the spread spectrum code authentication information in the authentication message includes: Obtaining a first chip correlation value corresponding to the target chips within the code shift keying code period in one authentication period of the composite code shift keying signal, where the target chips are the chips at the target positions within the target code shift keying code period in the target time period in the authentication period, the target code shift keying code period is one or more code shift keying code periods, and the target positions are one or more consecutive chip positions; Generate an encrypted chip based on the spread spectrum code authentication information in the authentication message, and obtain a corresponding second chip-related value; Correlate the first chip-related value with the second chip-related value to obtain a correlation result; In response to the correlation result being greater than a threshold value, the authentication is successful; otherwise, the authentication fails; Wherein, the generating of the encrypted chip based on the spread spectrum code authentication information in the authentication message includes: Generate an encrypted code based on an encrypted code generation polynomial and an encrypted code generation initial phase, wherein the encrypted code generation initial phase is selected from the message digest.

4. The method according to claim 3, wherein Further include: Obtain the position of the target code shift keying code period based on the spread spectrum code authentication information in the authentication message.

5. A satellite network device, characterized in that, Include: One or more processors; And One or more memories coupled to the one or more processors and storing instructions thereon, which when executed by the one or more processors alone or jointly, cause the satellite network device to execute the method according to any one of claims 1-2.

6. A terminal device, characterized in that, Include: One or more processors; And One or more memories coupled to the one or more processors and storing instructions thereon, which when executed by the one or more processors alone or jointly, cause the terminal device to execute the method according to any one of claims 3-4.

7. A chip, characterized in that, Include a circuit system configured to execute the method according to any one of claims 1-4.

8. A non-transitory computer-readable storage medium storing machine-executable instructions, characterized in that, When the machine-executable instructions are executed by one or more processors of the machine, the machine is caused to execute the method according to any one of claims 1-4.

9. A computer program product comprising machine-executable instructions, characterized in that, When the machine-executable instructions are executed by one or more processors of the machine, the machine is caused to execute the method according to any one of claims 1-4.

Citation Information

Patent Citations

  • Navigation signal encryption authentication method

    CN110167023A

  • Rapid message synchronization and decoding method for low-orbit constellation navigation enhancement signal

    CN115685267A

  • Spreading code and message combined satellite navigation signal authentication structure and receiving method

    CN116879925A