Satellite base station cross-layer lightweight authentication method based on identification

By using the SM9 identifier cryptography algorithm and radio frequency fingerprint authentication method, the problems of identity spoofing and key management difficulties in satellite communication are solved, achieving efficient identity authentication and secure access, and improving the security of satellite communication.

CN119788293BActive Publication Date: 2026-01-20NAT SPACE SCI CENT CAS
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510258831.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2026-01-20
Estimated Expiration
2045-03-06

AI Technical Summary

Technical Problem

Identity spoofing exists in satellite communication links, and existing encryption technologies suffer from difficulties in key management, complex authentication processes, and long processing times.

Method used

The SM9 identifier cryptographic algorithm is used for registration and initial authentication to avoid digital certificate management. Radio frequency fingerprints are used for re-authentication, and bispectral analysis and convolutional autoencoder are combined for radio frequency fingerprint feature extraction and recognition.

Benefits of technology

It reduces authentication latency, minimizes redundant calculations, and improves communication security and device identification efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119788293B_ABST
    Figure CN119788293B_ABST
Patent Text Reader

Abstract

This invention relates to the field of satellite communication technology, and in particular to a lightweight cross-layer authentication method for satellite base stations based on identifiers. The method includes: a satellite base station and a user terminal registering and obtaining authentication information; the user terminal initiating an initial authentication request; the satellite base station and the user terminal performing initial identity authentication on each other based on the authentication information; if authentication is successful, a session key is calculated, completing the initial two-way authentication and key negotiation; the user terminal initiating a second authentication request; the satellite base station and the user terminal performing second identity authentication by extracting and identifying radio frequency fingerprints, completing the second two-way authentication and key negotiation. This invention ensures the identification and secure access of satellite communication devices, guaranteeing the security of the satellite communication network environment.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of satellite communication, in particular to a satellite base station cross-layer lightweight authentication method based on identity. BACKGROUND

[0002] Satellite communication, as an important part of modern communication field, refers to using artificial satellites as relay stations to forward radio waves, so as to realize the communication between two or more earth stations. Satellite communication link is highly exposed in free space, and is easy to be attacked by illegal users, so it is very important to protect the security of satellite communication network. Satellite communication equipment identity authentication technology includes encryption algorithm-based authentication technology and physical layer-based authentication technology, and the encryption technology is divided into symmetric encryption technology and asymmetric encryption technology. The symmetric encryption technology has the problems of key management and distribution. In symmetric encryption, the same key is used for encryption and decryption, and the secure distribution and management of the key is very important to ensure the security and confidentiality of data. In actual use of symmetric encryption scheme, it is easy to suffer from denial of service attack and key analysis attack and other problems.

[0003] The asymmetric encryption technology can be divided into public key encryption infrastructure-based technology and identity-based cryptography technology. In the public key encryption infrastructure-based technology, in order to protect the security of the public key, the sender needs to apply for a certificate from the certificate authority and send his own certificate during authentication, and the receiver needs to query the certificate authority for the legality of the certificate after receiving the authentication message, which leads to a complex authentication process, and a large number of certificates also have the problems of difficult management and maintenance. The identity-based cryptography technology unifies the public key of the user with the real identity, avoids the participation of the third party in the authentication process, and overcomes the shortcomings of the public key encryption infrastructure-based technology in the identity authentication process. However, the identity-based cryptography technology needs multiple bilinear pair operations and multiple rounds of communication interaction in each authentication terminal during the authentication process, which will lead to a long time consumption in the identity authentication and key agreement process.

[0004] The device identity authentication method based on radio frequency fingerprint is to extract the radio frequency fingerprint of the device to be authenticated, and combine the radio frequency fingerprint of the legal device in the radio frequency fingerprint library to realize the identity authentication of the device. Each wireless communication device has a unique radio frequency fingerprint due to the interference of external factors such as process, material and environment. The features of the radio frequency fingerprint extraction mainly include instantaneous frequency, amplitude, phase, carrier frequency deviation, code rate deviation, box dimension, information dimension, bispectrum feature, high-order spectrum feature and the like. The commonly used radio frequency fingerprint feature extraction methods mainly include time-frequency analysis, wavelet transform and the like. The satellite communication signal is usually nonlinear and non-stationary, and the effect of the traditional time-frequency analysis method on the radio frequency fingerprint feature extraction and identification of the signal affected by the noise and other environmental factors is not ideal. Therefore, the application provides a satellite base station cross-layer lightweight authentication method based on identification. SUMMARY

[0005] The application aims at the identity spoofing problem in the existing satellite communication link, and provides a satellite base station cross-layer lightweight authentication method based on identification, so as to ensure the identity recognition and safe access of the satellite communication device and protect the safety of the satellite communication network environment.

[0006] To achieve the above object, the application provides the following scheme.

[0007] A satellite base station cross-layer lightweight authentication method based on identification, comprising:

[0008] The satellite base station and the user terminal are registered and obtain authentication information respectively;

[0009] The user terminal initiates a first authentication request, and the satellite base station and the user terminal perform first identity authentication based on the authentication information, calculate a session key after the authentication is passed, and complete the first bidirectional authentication and key agreement;

[0010] The user terminal initiates a re-authentication request, and the satellite base station and the user terminal perform re-identity authentication through radio frequency fingerprint extraction and identification, and complete the re-bidirectional authentication and key agreement.

[0011] Optionally, the registration and obtaining of the authentication information by the satellite base station and the user terminal respectively comprises:

[0012] The satellite ground network system adopts an SM9 identification password algorithm, allocates an ID to the satellite base station and the user terminal respectively, generates an authentication key pair, and obtains the authentication information in combination with the authentication key pair and corresponding digest information, wherein the authentication key pair is calculated by using an SM3 password hash algorithm.

[0013] Optionally, the authentication key pair of the satellite base station is:

[0014] Pr S = ;

[0015] q S =Hash ;

[0016] The authentication key pair of the user terminal is:

[0017] Pr U = ;

[0018] q U = Hash ;

[0019] Wherein, (Pr S , q S ) is the authentication key pair of the satellite base station, (Pr U , q U ) is the authentication key pair of the user terminal, s is the encryption master private key of the satellite ground network system, P is the generator of the additive cyclic group, ID S is the ID assigned by the satellite ground network system to the satellite base station, and ID U is the ID assigned by the satellite ground network system to the user terminal.

[0020] Optionally, the authentication information of the satellite base station includes N, ê, G, G1, s, P, P0, ID S , Pr S , and the authentication information of the user terminal includes N, ê, G, G1, P, P0, ID S , ID U , Pr U , q S , wherein N is the prime order of the additive cyclic group and the multiplicative cyclic group, ê is a bilinear pair, G is the additive cyclic group, G1 is the multiplicative cyclic group, s is the encryption master private key of the satellite ground network system, P is the generator of the additive cyclic group, P0 is the encryption master public key of the satellite ground network system, ID S is the ID assigned by the satellite ground network system to the satellite base station, Pr S is the private key of the authentication key pair of the satellite base station, ID U is the ID assigned by the satellite ground network system to the user terminal, Pr U is the private key of the authentication key pair of the user terminal, and q S is the public key of the authentication key pair of the satellite base station.

[0021] Optionally, the user terminal initiates a first authentication request, and the satellite base station and the user terminal perform a first identity authentication based on the authentication information, and if the authentication is passed, a session key is calculated, and the first bidirectional authentication and key agreement includes:

[0022] When the user terminal initiates the first authentication request, the user terminal generates a prime random number n U , and calculates information (ψ U , σ U ) and sends the information to the satellite base station in combination with ID information, wherein ψ U is a user terminal random parameter value based on the prime random number n U and an additive cyclic group G, and σ U is a user terminal random key value based on the prime random number n U and a private key Pr U ;

[0023] After receiving the information, the satellite base station generates a prime random number n S , and calculates information (ψ S , σ S ) and sends the information to the user terminal, wherein ψ S is a satellite base station random parameter value based on the prime random number n S and the additive cyclic group G, and σ S is a satellite base station random key value based on the prime random number n S and the private key Pr S ;

[0024] The satellite base station verifies whether the bilinear pair meets the condition according to the information (ψ U , σ U ), and if the verification is passed, a session key SK S is calculated.

[0025] The user terminal verifies whether the bilinear pair meets the condition according to the information (ψ S , σ S ), and if the verification is passed, a session key SK U is calculated.

[0026] Optionally, the information (ψ U , σ U ) is calculated as follows:

[0027] ψ U = n U ·P;

[0028] σ U = n U ·Pr U ;

[0029] The satellite base station verifies whether the bilinear pair satisfies the condition according to information (ψ U , σ U ):

[0030] ê(σ U , P0+q U ·P) = ê(ψ U , P0);

[0031] Calculate the session key SK S :

[0032] SK S = Hash(ID S ‖ID U ‖ψ U ‖ψ S ‖X);

[0033] Wherein, P is the generator of the additive cyclic group, Pr U is the private key of the authentication key pair of the user terminal, ê is the bilinear pair, P0 is the encryption master public key of the satellite ground network system, q U is the public key of the authentication key pair of the user terminal, ID S is the ID assigned by the satellite ground network system to the satellite base station, ID U is the ID assigned by the satellite ground network system to the user terminal, X is a random parameter value obtained by combining prime random number n U and prime random number n S and the additive cyclic group G, and here X = n S ·ψ U .

[0034] Optionally, calculate the information (ψ S , σ S ):

[0035] ψ S = n S ·P;

[0036] σ S = n S ·Pr S ;

[0037] The user terminal verifies whether the bilinear pair satisfies the condition according to information (ψ S , σ S ):

[0038] ê(σ S , P0+q S ·P) = ê(ψS , P0);

[0039] computing a session key SK U :

[0040] SK U = Hash(ID S ‖ID U ‖ψ U ‖ψ S ‖X);

[0041] wherein P is a generator of an additive cyclic group, Pr S is a private key of an authentication key pair of the satellite base station, ê is a bilinear pair, P0 is an encryption master public key of the satellite ground network system, q S is a public key of the authentication key pair of the satellite base station, ID S is an ID assigned by the satellite ground network system to the satellite base station, ID U is an ID assigned by the satellite ground network system to the user terminal, X is a random parameter value obtained by combining prime random number n U and prime random number n S and the additive cyclic group G, and here X = n U · ψ S .

[0042] Optionally, the user terminal initiates a re-authentication request, and the satellite base station and the user terminal perform re-identity authentication through extraction and identification of a radio frequency fingerprint, and the completion of the re-bilateral authentication and key agreement comprises:

[0043] When the user terminal initiates a re-authentication request, the user terminal sends information (ψ U , σ U ) combined with ID information to the satellite base station;

[0044] After receiving the information, the satellite base station checks a storage list, and if the first authentication has been completed, the satellite base station performs feature extraction and identification of a radio frequency fingerprint on the signal sent by the user terminal, and if the identification result is a legal device, the satellite base station completes identity authentication of the user terminal and uses a session key SK S , and simultaneously sends information (ψ S , σ S ) to the user terminal;

[0045] After receiving the information, the user terminal checks a storage list, and if the first authentication has been completed, the user terminal performs feature extraction and identification of a radio frequency fingerprint on the signal sent by the satellite base station, and if the identification result is a legal device, the user terminal completes identity authentication of the satellite base station and uses a session key SK U .

[0046] Optionally, the feature extraction and identification of the radio frequency fingerprint of the signal is completed by using bispectrum analysis combined with a convolutional autoencoder.

[0047] The present application has the following advantages:

[0048] The present application uses an SM9 identity password algorithm in the registration stage and the first authentication stage, avoids the use and management of digital certificates, does not require the participation of a third party in the first authentication stage, and reduces authentication delay; the device identity authentication method based on a radio frequency fingerprint is used in the re-authentication stage, which reduces repeated calculation and improves communication security. BRIEF DESCRIPTION OF DRAWINGS

[0049] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed in the embodiments. Obviously, the drawings described below are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0050] Figure 1 A flow chart of an identity-based satellite base station cross-layer lightweight authentication method. DETAILED DESCRIPTION

[0051] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0052] In order to make the above-mentioned purposes, features and advantages of the present application more obvious and easy to understand, the present application will be further described in detail below with reference to the drawings and specific embodiments.

[0053] The present embodiment provides an identity-based satellite base station cross-layer lightweight authentication method, as shown in Figure 1 , which comprises:

[0054] The satellite base station and the user terminal are registered and obtain authentication information respectively;

[0055] The user terminal initiates a first authentication request, and the satellite base station and the user terminal perform first identity authentication on each other based on the authentication information, and calculate a session key after the authentication is passed, to complete the first bidirectional authentication and key agreement;

[0056] The user terminal initiates a re-authentication request, and the satellite base station and the user terminal perform re-identity authentication through extraction and identification of a radio frequency fingerprint, complete re-bilateral authentication and key negotiation.

[0057] Specifically, in the registration phase and the first authentication phase, the SM9 identity cryptography algorithm is used to avoid the use and management of digital certificates, and no third party is needed in the first authentication phase, thereby reducing authentication delay; in the re-authentication phase, a device identity authentication method based on a radio frequency fingerprint is used to reduce repeated calculation and improve communication security.

[0058] Further, the registration and acquisition of authentication information by the satellite base station and the user terminal respectively include:

[0059] The satellite ground network system adopts the SM9 identity cryptography algorithm, allocates IDs to the satellite base station and the user terminal respectively, generates an authentication key pair, and acquires the authentication information in combination with the authentication key pair and corresponding digest information, wherein the authentication key pair is calculated by using the SM3 cryptography hash algorithm.

[0060] Further, the authentication key pair of the satellite base station is:

[0061] Pr S = ;

[0062] q S =Hash ;

[0063] The authentication key pair of the user terminal is:

[0064] Pr U = ;

[0065] q U = Hash ;

[0066] wherein (Pr S , q S ) is the authentication key pair of the satellite base station, (Pr U , q U ) is the authentication key pair of the user terminal, s is the encryption master private key of the satellite ground network system, P is the generator of the additive cyclic group, ID S is the ID allocated to the satellite base station by the satellite ground network system, and ID U is the ID allocated to the user terminal by the satellite ground network system.

[0067] Further, the authentication information of the satellite base station includes N, ê, G, G1, s, P, P0, ID S , Pr Sauthentication information of the user terminal includes N, ê, G, G1, P, P0, ID S , ID U , Pr U , q S , wherein N is a prime order of an additive cyclic group and a multiplicative cyclic group, ê is a bilinear pair, G is the additive cyclic group, G1 is the multiplicative cyclic group, s is an encryption master private key of a satellite-ground network system, P is a generator of the additive cyclic group, P0 is an encryption master public key of the satellite-ground network system, ID S is an ID assigned by the satellite-ground network system to a satellite base station, Pr S is a private key of an authentication key pair of the satellite base station, ID U is an ID assigned by the satellite-ground network system to a user terminal, Pr U is a private key of an authentication key pair of the user terminal, and q S is a public key of the authentication key pair of the satellite base station.

[0068] Further, the user terminal initiates a first authentication request, and the satellite base station and the user terminal perform a first identity authentication on each other based on the authentication information, and if the authentication is passed, a session key is calculated, and the first bidirectional authentication and key agreement are completed, including:

[0069] When the user terminal initiates the first authentication request, the user terminal generates a prime random number n U , and calculates information (ψ U , σ U ) and sends the information to the satellite base station in combination with ID information, wherein ψ U is a user terminal random parameter value obtained based on the prime random number n U and the additive cyclic group G, and σ U is a user terminal random key value obtained based on the prime random number n U and the private key Pr U ;

[0070] After receiving the information, the satellite base station generates a prime random number n S , and calculates information (ψ S , σ S ) and sends the information to the user terminal, wherein ψ S is a satellite base station random parameter value obtained based on the prime random number n S and the additive cyclic group G, and σ S is a satellite base station random key value obtained based on the prime random number n S and the private key Pr S ;

[0071] The satellite base station calculates information (ψ U , σ UVerify if the bilinear pair meets the conditions. If the verification is successful, calculate the session key SK. S ;

[0072] The user terminal, based on information (ψ) S , σ S Verify if the bilinear pair meets the conditions. If the verification is successful, calculate the session key SK. U .

[0073] Further, the information (ψ) is calculated. U , σ U ):

[0074] ψ U = n U ·P;

[0075] σ U = n U ·Pr U ;

[0076] The satellite base station is based on information (ψ) U , σ U Verify whether the bilinear pairing meets the conditions:

[0077] ê(σ U , P0+q U ·P) = ê(ψ U , P0);

[0078] Calculate session key SK S :

[0079] SK S = Hash(ID S ||ID U ||ψ U ||ψ S ||X);

[0080] Where P is the generator of the additive cyclic group, Pr U The user terminal's authentication key pair contains the private key ê (a bilinear pair), P0 (the encryption master public key of the satellite ground network system), and q. U For the user terminal's authentication key pair, the public key, ID S ID is the ID assigned to a satellite base station by the satellite terrestrial network system. U X is the ID assigned to the user terminal by the satellite terrestrial network system, and X is a random number n combining prime numbers. U And prime random number n S And the random parameter values ​​obtained from the additive cyclic group G, where X = n S ·ψ U .

[0081] Further, the information (ψ S , σ S ) is calculated:

[0082] ψ S = n S ·P;

[0083] σ S = n S ·Pr S ;

[0084] The user terminal verifies whether the bilinear pair meets the condition according to the information (ψ S , σ S ):

[0085] ê(σ S , P0+q S ·P) = ê(ψ S , P0);

[0086] The session key SK U is calculated:

[0087] SK U = Hash(ID S ‖ID U ‖ψ U ‖ψ S ‖X);

[0088] Wherein, P is a generator of an additive cyclic group, Pr S is a private key of an authentication key pair of a satellite base station, ê is a bilinear pair, P0 is an encryption master public key of a satellite ground network system, q S is a public key of an authentication key pair of a satellite base station, ID S is an ID assigned by a satellite ground network system to a satellite base station, ID U is an ID assigned by a satellite ground network system to a user terminal, and X is a random parameter value obtained by combining a prime number random number n U and a prime number random number n S and an additive cyclic group G, and here X = n U ·ψ S .

[0089] Specifically, the embodiment proposes an identity-based lightweight authentication method for a satellite base station, and the authentication parties use an SM9 identity cryptography algorithm, thereby avoiding the use and management of digital certificates, and the identity information and key are allocated in the registration stage of the authentication parties, and a third party is not required to participate in the access authentication stage, thereby reducing the authentication delay.

[0090] Further, the user terminal initiates a re-authentication request, and the satellite base station and the user terminal perform re-identity authentication through extraction and identification of the radio frequency fingerprint, and complete re-bilateral authentication and key agreement, including:

[0091] When the user terminal initiates a re-authentication request, the user terminal sends information (ψ U , σ U ) to the satellite base station in combination with ID information;

[0092] After receiving the information, the satellite base station checks the storage list, and if the first authentication has been completed, the satellite base station performs feature extraction and identification of the radio frequency fingerprint on the signal sent by the user terminal, and if the identification result is a legal device, the satellite base station completes identity authentication for the user terminal and uses the session key SK S , and sends information (ψ S , σ S ) to the user terminal;

[0093] After receiving the information, the user terminal checks the storage list, and if the first authentication has been completed, the user terminal performs feature extraction and identification of the radio frequency fingerprint on the signal sent by the satellite base station, and if the identification result is a legal device, the user terminal completes identity authentication for the satellite base station and uses the session key SK U .

[0094] Further, feature extraction and identification of the radio frequency fingerprint of the signal are completed by using bispectrum analysis in combination with a convolutional autoencoder.

[0095] Specifically, the present embodiment proposes a physical layer security authentication method, i.e., a device identity authentication method based on a radio frequency fingerprint, for the re-authentication stage, thereby improving security. At the same time, repeated calculations are reduced, and legal devices use parameters of the first authentication, thereby reducing computational complexity.

[0096] The three stages of the satellite base station cross-layer lightweight authentication method based on identification proposed in the present embodiment are described in detail below, i.e., a registration stage, a first authentication stage, and a re-authentication stage, as follows:

[0097] (1) Registration stage:

[0098] This stage involves a user terminal, a satellite base station, a satellite ground network system, and a private key generation center. The user terminal is a terminal with specific satellite communication functions, including an airplane, a vehicle, a ship, a portable handheld device, etc. The satellite base station has limited computing and storage capabilities, and is responsible for user access and data transmission. The satellite ground network system is responsible for identity registration verification of the user terminal and the satellite base station. The private key generation center is responsible for generating system parameters and issuing private keys for the user terminal and the satellite base station.

[0099] In this stage, the registration of the user terminal and the satellite base station is completed. The user terminal registers with the satellite ground network system in an offline manner, obtains the identity information provided by the satellite ground network system and the corresponding negotiated key, and stores the information in the authentication card to be handed over to the registered user terminal in a secure manner. The satellite ground network system also registers with the satellite ground network system in an offline manner, and the identity information and the negotiated key information are also stored in the satellite authentication card. At the same time, the satellite ground network system reserves the relevant information of the satellite.

[0100] Satellite base station registration process:

[0101] 1) The satellite ground network system uses the SM9 identification password algorithm, selects a 256-bit BN curve and a additive cyclic group G with a prime number N and a generator P, and a bilinear pair ê and a multiplicative cyclic group G1 with a prime number N, wherein ê: G × G → G1, a secure random number generator is used to generate the encryption master private key s ∈ Z * N and the encryption master public key P0, wherein P0 = s·P;

[0102] 2) The satellite ground network system allocates an ID S to the satellite base station, and generates an authentication key pair (Pr S , q S ) for the satellite base station, wherein the private key Pr S and the public key q S are calculated by the following formula, wherein Hash( ) selects the SM3 password hash algorithm:

[0103] Pr S = ;

[0104] q S = Hash .

[0105] 3) The satellite ground network system stores the authentication key pair and the corresponding digest information in the authentication card of the satellite base station, and the specific information includes N, ê, G, G1, s, P, P0, ID S , Pr S .

[0106] User terminal registration process:

[0107] 1) The satellite ground network system uses the same encryption algorithm and parameters as the satellite base station registration process;

[0108] 2) The satellite ground network system allocates an ID U to the user terminal, and generates an authentication key pair (Pr U, q U ), private key Pr U and public key q U are calculated by the following formula, wherein Hash() selects the SM3 cryptographic hash algorithm:

[0109] Pr U = ;

[0110] q U = Hash .

[0111] 3) The satellite ground network system stores the authentication key pair and the corresponding digest information in the authentication card of the user terminal, and the specific information includes N, ê, G, G1, P, P0, ID S , ID U , Pr U , q S .

[0112] (2) First authentication stage:

[0113] When the user terminal initiates access authentication to the satellite base station for the first time, the user terminal and the satellite base station complete mutual authentication and key negotiation through the following steps:

[0114] 1) The user terminal generates a prime random number n U ∈Z * N , ψ U and σ U are calculated by the following formula, and (ID U , ψ U , σ U ) are sent to the satellite base station:

[0115] ψ U = n U ·P;

[0116] σ U = n U ·Pr U .

[0117] 2) The satellite base station receives the information (ID U , ψ U , σ U ) sent by the user terminal, calculates the public key q U from ID U , generates a prime random number n S ∈Z * N , and calculates ψ S and σ S by the following formula, and sends (ψ S , σS ) send to user terminal:

[0118] ψ S = n S ·P;

[0119] σ S = n S ·Pr S .

[0120] 3) Satellite base station verifies whether the bilinear pair is qualified according to (ψ U , σ U ):

[0121] ê(σ U , P0+q U ·P) = ê(ψ U , P0);

[0122] If qualified, calculate session key SK S :

[0123] SK S = Hash(ID S ‖ID U ‖ψ U ‖ψ S ‖X);

[0124] where X = n S ·ψ U .

[0125] 4) User terminal receives information (ψ S , σ S ), verifies whether the bilinear pair is qualified:

[0126] ê(σ S , P0+q S ·P) = ê(ψ S , P0);

[0127] If qualified, calculate session key SK U :

[0128] SK U = Hash(ID S ‖ID U ‖ψ U ‖ψ S ‖X);

[0129] where X = n U ·ψ S .

[0130] SK S = SK U , i.e. the session key is equal, then the key agreement of the user terminal and the satellite base station is successful. Therefore, through the above steps, the user terminal and the satellite base station can complete the two-way authentication and key agreement of the first access.

[0131] (3) Re-authentication phase:

[0132] When the user terminal initiates a re-access authentication request to the satellite base station, the two-way authentication between the user terminal and the satellite base station is completed through the device identity authentication method based on the radio frequency fingerprint. The device recognition based on the radio frequency fingerprint feature can be divided into four steps of signal collection, preprocessing, feature extraction and fingerprint recognition:

[0133] 1) Signal collection: the transmitter sends a radio frequency signal, and the receiver obtains a baseband signal by down-conversion sampling;

[0134] 2) Preprocessing: preprocessing the signal, including normalization, noise reduction, target signal interception and other operations;

[0135] 3) Feature extraction: signal feature extraction is performed using bispectrum analysis. The bispectrum analysis method has many advantages over the time-frequency analysis method, mainly including: the bispectrum can reflect the amplitude information and phase information of the signal at the same time; and like high-order cumulants, the bispectrum can theoretically completely suppress the interference of additive Gaussian noise. These advantages can play a good effect in the identification of real legal signals and fraudulent interference signals.

[0136] 4) Fingerprint identification: a convolutional autoencoder is constructed to identify satellite radio frequency fingerprints. Autoencoders are widely used in anomaly detection, intrusion detection, text classification, fault analysis and other fields due to their flexible feature extraction capabilities. As a typical unsupervised learning model, an autoencoder network can more comprehensively represent the main and secondary features of a radio frequency signal by weighting and fusing features, rather than simply discarding secondary features. Convolutional neural networks can extract information in the hidden space of data, so an encoder and decoder network constructed using a convolutional neural network will be better than a traditional autoencoder, thus generating a convolutional autoencoder. During the encoding process, the convolutional autoencoder uses a convolutional layer to extract features of the input sample, and during the decoding process, the convolutional autoencoder uses an inverse convolutional layer to attempt to restore the hidden feature vector to the original input sample. During training, the input signal sample is first normalized, then the low-dimensional feature representation of the signal is obtained by feature extraction through the encoder, and then the low-dimensional feature representation is reconstructed by the decoder to obtain the reconstructed sample, and the network is trained by reducing the error between the reconstructed sample and the original sample. During detection, the reconstructed error of the sample to be detected is obtained by inputting the sample set to be detected into the trained convolutional autoencoder, and the sample is determined to be an abnormal sample according to the size of the reconstructed error.

[0137] In the re-authentication phase, the user terminal and the satellite base station complete authentication through the following steps:

[0138] 1) The user terminal sends information (ID U , ψ U , σ U ) to the satellite base station;

[0139] 2) After receiving the message, the satellite base station checks the stored list. If the first authentication has been completed before, the signal sent by the user terminal is subjected to feature extraction and identification of the radio frequency fingerprint. If the identification result is a legal device, the identity of the user terminal is authenticated, and the session key SK S negotiated in the first authentication is used, and information (ψ S, σ S ) is sent to the user terminal;

[0140] 3) After receiving the message, the user terminal checks the stored list. If the first authentication has been completed before, the signal sent by the satellite base station is subjected to feature extraction and identification of the radio frequency fingerprint. If the identification result is a legal device, the identity of the satellite base station is authenticated, and the session key SK U negotiated in the first authentication is used.

[0141] Through the above steps, the user terminal and the satellite base station can complete the two-way authentication and key negotiation for re-access.

[0142] The above described embodiments are only to illustrate the preferred modes of the present application, and are not intended to limit the scope of the present application. Any modification and improvement made by those skilled in the art to the technical solutions of the present application without departing from the design spirit of the present application shall fall within the protection scope of the present application as defined by the claims.

Claims

1. A lightweight, cross-layer authentication method for satellite base stations based on identifiers, characterized in that, include: Both satellite base stations and user terminals register and obtain authentication information. The user terminal initiates an initial authentication request. The satellite base station and the user terminal perform initial identity authentication on each other based on the authentication information. If the authentication is successful, the session key is calculated to complete the initial two-way authentication and key negotiation. The user terminal initiates a re-authentication request, and the satellite base station and the user terminal perform re-identification by extracting and identifying radio frequency fingerprints, thus completing re-bidirectional authentication and key negotiation. The process involves the user terminal initiating an initial authentication request, the satellite base station and the user terminal performing initial identity authentication on each other based on the authentication information, and calculating a session key upon successful authentication to complete the initial two-way authentication and key negotiation. When the user terminal initiates its first authentication request, the user terminal generates a prime random number n. U And calculate information (ψ) U , σ U ), and send it to the satellite base station in combination with the ID information, wherein ψ U For prime-based random numbers n U The user terminal random parameter values ​​obtained by the additive cyclic group G, σ U For prime-based random numbers n U and private key Pr U The obtained random key value for the user terminal; After receiving the information, the satellite base station generates a prime random number n. S And calculate information (ψ) S , σ S ) is sent to the user terminal, wherein, ψ S For prime-based random numbers n S The random parameter values ​​of the satellite base station obtained by the additive cyclic group G, σ S For prime-based random numbers n S and private key Pr S The obtained random key value for the satellite base station; The satellite base station is based on information (ψ) U , σ U Verify if the bilinear pair meets the conditions. If the verification is successful, calculate the session key SK. S ; The user terminal, based on information (ψ) S , σ S Verify if the bilinear pair meets the conditions. If the verification is successful, calculate the session key SK. U ; The user terminal initiates a re-authentication request, and the satellite base station and the user terminal perform re-identification by extracting and identifying radio frequency fingerprints, completing the re-mutual authentication and key negotiation, including: When the user terminal initiates a re-authentication request, the user terminal will send information (ψ) U , σ U The ID information is then sent to the satellite base station. After receiving the information, the satellite base station checks the storage list. If the initial authentication has been completed, it performs radio frequency fingerprint feature extraction and identification on the signal sent by the user terminal. If the identification result is a legitimate device, it completes the identity authentication of the user terminal and uses the session key SK. S Simultaneously, information (ψ) is sent to the user terminal. S , σ S ); After receiving the information, the user terminal checks the storage list. If the initial authentication has been completed, it performs radio frequency fingerprint feature extraction and identification on the signal transmitted by the satellite base station. If the identification result is a legitimate device, it completes the identity authentication of the satellite base station and uses the session key SK. U ; Feature extraction and recognition of the radio frequency fingerprint of the signal are performed using bispectral analysis combined with a convolutional autoencoder, including: 1) Signal acquisition: The transmitter sends radio frequency signals, and the receiver obtains the baseband signals through down-conversion sampling; 2) Preprocessing: The signal is preprocessed, including normalization, noise reduction, and target signal extraction; 3) Feature extraction: Signal feature extraction is performed using bispectral analysis; 4) Fingerprint Recognition: A convolutional autoencoder is constructed to recognize satellite RF fingerprints. During the encoding process, the convolutional autoencoder uses convolutional layers to extract features from the input samples. During the decoding process, the convolutional autoencoder uses deconvolutional layers to attempt to restore the hidden feature vectors to the original input samples. During training, the input signal samples are first normalized, and then the encoder extracts features to obtain a low-dimensional feature representation of the signal. The decoder then reconstructs the low-dimensional feature representation to obtain reconstructed samples. The network is trained by reducing the error between the reconstructed samples and the original samples. During detection, the set of samples to be detected is input into the trained convolutional autoencoder to obtain the reconstruction error of the samples to be detected. The magnitude of the reconstruction error is used to determine whether the samples to be detected are abnormal samples. The registration and authentication information acquisition process for the satellite base station and user terminal includes: The satellite ground network system uses the SM9 identifier cryptographic algorithm to assign IDs to the satellite base station and user terminal, generate authentication key pairs, and obtain the authentication information by combining the authentication key pairs and corresponding digest information. The authentication key pairs are calculated using the SM3 cryptographic hash algorithm. The authentication key pair for the satellite base station is: Pr S = ; q S =Hash ; The authentication key pair of the user terminal is: Pr U = ; q U = Hash ; Among them, (Pr S q S ) is the authentication key pair for the satellite base station, (Pr U q U ) represents the authentication key pair for the user terminal, s represents the encryption master private key of the satellite ground network system, P represents the generator of the additive cyclic group, and ID represents the key pair. S ID is the ID assigned to a satellite base station by the satellite terrestrial network system. U The ID assigned to user terminals by the satellite terrestrial network system; The authentication information of the satellite base station includes N, ê, G, G1, s, P, P0, ID. S ,Pr S The authentication information of the user terminal includes N, ê, G, G1, P, P0, ID. S ID U ,Pr U q S Where N is the prime order of the additive cyclic group and the multiplicative cyclic group, ê is the bilinear pair, G is the additive cyclic group, G1 is the multiplicative cyclic group, s is the encrypted master private key of the satellite ground network system, P is the generator of the additive cyclic group, P0 is the encrypted master public key of the satellite ground network system, and ID S Pr is the ID assigned to a satellite base station by the satellite terrestrial network system. S The private key for the authentication key pair of the satellite base station, ID U Pr is the ID assigned to user terminals by the satellite terrestrial network system. U The private key of the authentication key pair for the user terminal, q S The public key of the authentication key pair for the satellite base station; Calculate the information (ψ) U , σ U ): ψ U = n U ·P; σ U = n U ·Pr U ; The satellite base station is based on information (ψ) U , σ U Verify whether the bilinear pairing meets the conditions: ê(s U ,P0+q U ·P) = ê(ψ U ,P0); Calculate session key SK S : SK S = Hash(ID S ‖ID U ‖ψ U ‖ψ S ‖X); Where P is the generator of the additive cyclic group, Pr U The user terminal's authentication key pair contains the private key ê (a bilinear pair), P0 (the encryption master public key of the satellite ground network system), and q. U For the user terminal's authentication key pair, the public key, ID S ID is the ID assigned to a satellite base station by the satellite terrestrial network system. U X is the ID assigned to the user terminal by the satellite terrestrial network system, and X is a random number n combining prime numbers. U And prime random number n S And the random parameter values ​​obtained from the additive cyclic group G, where X = n S ·ψ U ; Calculate the information (ψ) S , σ S ): ψ S = n S ·P; σ S = n S ·Pr S ; The user terminal, based on information (ψ) S , σ S Verify whether the bilinear pairing meets the conditions: ê(s S ,P0+q S ·P) = ê(ψ S , P0); Calculate session key SK U : SK U = Hash(ID S ‖ID U ‖ψ U ‖ψ S ‖X); Where P is the generator of the additive cyclic group, Pr S Here, ê is the private key of the authentication key pair for the satellite base station, P0 is the bilinear pair, and q is the encryption master public key for the satellite terrestrial network system. S For the authentication key pair of the satellite base station, the public key, ID S ID is the ID assigned to a satellite base station by the satellite terrestrial network system. U X is the ID assigned to the user terminal by the satellite terrestrial network system, and X is a random number n combining prime numbers. U And prime random number n S And the random parameter values ​​obtained from the additive cyclic group G, where X = n U ·ψ S .

Citation Information

Patent Citations

  • Two-stage security access authentication method fusing time-space characteristics in satellite-ground communication

    CN114172669A

  • Legitimacy verification method and device, related equipment and storage medium

    CN118828489A