Real-time Authentication Message Design of Satellite Navigation System and Terminal Authentication Method
By designing real-time authentication messages for satellite navigation systems, using slow authentication and fast authentication packet structures, combined with single-item functions and message digest technology, real-time authentication of satellite navigation signals is achieved, solving the problem of ciphertext verification lag caused by delayed key propagation in the existing technology, and improving the security and authentication efficiency of the signal.
Patent Information
- Application Number
- CN202510326890.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-19
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2045-03-19
AI Technical Summary
In the existing satellite navigation signal authentication technology, the delayed broadcast of keys caused by the TESLA protocol leads to lag in ciphertext verification, which cannot meet the needs of real-time authentication in some application scenarios.
A real-time authentication message for satellite navigation system was designed, and the real-time authentication packet structure was set up, including slow authentication packets and fast authentication packets. Slow authentication packets are used for first key authentication, and fast authentication packets are used for message authentication. Using the key chain generated by the single-term function to generate the root key, the validity of other keys is verified only once. The message digest is generated by the message information in the period where the delayed broadcast key is located, and the message authentication code is calculated by combining the key and message digest to realize real-time message authentication within the fast authentication cycle.
Real-time authentication of satellite navigation signals is realized, which meets the needs of real-time authentication, improves signal security and authentication efficiency, and reduces implementation overhead.
Smart Images

Figure CN119853909B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of satellite navigation signal authentication, and particularly to a real-time authentication message design for a satellite navigation system and a terminal authentication method. Background Art
[0002] Since the civil satellite navigation signal system is public, it is easy for deceivers to implement generative deception, which greatly threatens the security of civil navigation signals and thus affects the credibility of navigation and positioning results. To improve the signal security, experts and scholars have been committed to researching signal authentication technologies, broadcasting unpredictable authentication information on signal features, and the receiving end extracts the authentication information and judges the signal source based on the existence and validity of the authentication information. Since this technology is oriented to the system side, generates authentication information based on cryptographic algorithms and modifies the original signal system to a certain extent, its implementation cost is relatively high. And carrying the authentication information in the message is the authentication method with the lowest implementation cost and backward compatibility among all authentication methods. Therefore, this method was first applied to the E1 signal of the Galileo navigation system to provide Open Service Navigation Message Authentication (OSNMA). This scheme adopts the Timed Efficient Stream Loss-tolerant Authentication (TESLA) protocol. By first broadcasting the ciphertext and delaying the broadcast of the symmetric key, the symmetric encryption algorithm shows the effect of public key encryption, thus solving the problem of symmetric key distribution in the one-way broadcast scenario of satellite navigation and avoiding the use of public key encryption algorithms with relatively high computational complexity. However, this protocol also brings some problems. The delayed broadcast of the symmetric key results in the verification of the ciphertext can only be carried out later, and it cannot meet the user's demand for real-time authentication in some application scenarios, such as unmanned aerial vehicles, autonomous vehicles, financial transactions and other application scenarios.
[0003] At present, the academic community pays more attention to how to design an authentication signal model to improve the authentication efficiency and security of the authentication method while reducing the implementation cost, and pays less attention to the real-time nature of authentication. While in engineering, more attention is paid to the robustness and feasibility of the authentication method, and the attention to real-time authentication is insufficient. Therefore, this application provides a solution. Summary of the Invention
[0004] In view of the above technical problems and background, it is necessary to provide a real-time authentication message design for a satellite navigation system and a terminal authentication method that can achieve real-time authentication and solve the problem of authentication lag in navigation message authentication technology.
[0005] Real-time authentication message design for a satellite navigation system and a terminal authentication method, the method comprising:
[0006] Set the real-time authentication data packet structure; the real-time authentication data packet consists of a slow authentication data packet and a fast authentication data packet; wherein the slow authentication data packet performs the first key authentication, and the fast authentication data packet realizes message authentication; the fast authentication data packet is composed of a key, a message, a message digest of the message information of the key broadcast with delay in the corresponding period, a digital signature fragment, and a message authentication code; wherein the digital signature fragments in multiple fast authentication data packets are combined into a complete digital signature, which is used as full authentication data to verify the validity of the generated root key and establish a trust basis;
[0007] Use the generated root key to calculate a key chain including multiple keys through a one-way function. Since different keys follow the mathematical relationship of the one-way function, it is only necessary to verify the validity of the generated root key once, and the validity of other keys can be verified through the one-way function; use the message information of the period in which the key is broadcast with delay to generate a message digest through a one-way function, and broadcast it in advance together with the message information and the message authentication code to which the key is applied; use the key to calculate the message authentication code for the data composed of the message and the message digest; calculate the digital signature of the generated root key;
[0008] Use the radio frequency front end to obtain the received signal; after performing analog-to-digital conversion on the received signal, execute relevant steps and decode the obtained message symbols, and store the message data until the key information and digital signature of a slow authentication period are collected;
[0009] Use the public key to operate on the digital signature to obtain the message digest of the key information, generate the message digest of the received key information through a one-way function, and compare the two. If they are equal, the key is valid, and the verified key is saved; if the two are not equal, the key is invalid and the authentication fails;
[0010] When the digital signature verification passes or the receiver is in the hot start state and has saved the authenticated key information, the receiver continues to complete the fast authentication and verify the validity of the message; the information in the fast authentication cycle data packet is arranged in the order of key, message, message digest, and message authentication code. By using the one-to-one mapping relationship between the message digest and the information, two fast authentication cycle information can be verified simultaneously in one fast authentication to achieve real-time message authentication. For the real-time authentication message design and terminal authentication method of the above satellite navigation system, this application constructs a hierarchical real-time authentication data packet structure to enable the terminal to achieve the authentication function in stages. The slow authentication cycle data packet protects the validity of the generated root key through digital signature. As the first authentication of the receiver, slow authentication is used to establish the trust basis for terminal message authentication; multiple nested fast authentication cycle data packets arrange the order of information such as key, message, message digest, and message authentication code, and use the one-to-one mapping relationship between the message digest and the information to achieve the function of verifying two fast authentication cycle information simultaneously in one fast authentication, building an efficient architecture for real-time authentication. Among them, cryptographic algorithms are used to generate authentication information, and the security of the authentication information is guaranteed by the mathematical security of the cryptographic algorithms, indicating that the authentication information generation system is rigorous. The generated root key is used to generate a key chain through a one-way function, so that the receiver only needs to perform a slow cycle authentication once to verify the key validity. When verifying the key later, only the verified key needs to be calculated through the key chain, and the validity of the current key can be verified by comparing the calculated key with the verified key, shortening the key verification time; the message information of the authentication cycle in which the delayed key is broadcast is generated into a message digest through a one-way function, and the message authentication code is obtained by encrypting the combined data of the message and the message digest with the key, enabling the receiving terminal to verify the messages of two fast authentication cycles at one time. The one-way nature of the one-way function protects the message in the cycle where the delayed key is located from being leaked. The message in the cycle where the delayed key is broadcast can be compared with the verified message digest through the one-way function to verify the validity of the information, achieving real-time authentication at the cost of a small message overhead. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] Figure 1 It is the TESLA protocol data packet structure in an embodiment;
[0012] Figure 2 It is the real-time authentication data packet structure in an embodiment;
[0013] Figure 3 It is the schematic diagram of key chain generation and use in an embodiment;
[0014] Figure 4 It is the block diagram of the slow authentication terminal receiving method for satellite navigation real-time message authentication in another embodiment;
[0015] Figure 5Block diagram of the fast authentication terminal receiving method for implementing message authentication in a satellite navigation system in an embodiment;
[0016] Figure 6 B-CNAV2 frame structure diagram in an embodiment;
[0017] Figure 7 Arrangement format diagram of B-CNAV2 information type 50 in an embodiment;
[0018] Figure 8 Arrangement format diagram of B-CNAV2 information type 51 in an embodiment;
[0019] Figure 9 Diagram of B2a message authentication period and information broadcast sequence in an embodiment. Detailed implementation manners
[0020] In order to make the objectives, technical solutions and advantages of the present application clearer and more understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0021] In an embodiment, a real-time authentication message design and terminal authentication method for a satellite navigation system are provided, including the following steps:
[0022] Set the real-time authentication data packet structure; the real-time authentication data packet is composed of a slow authentication data packet and a fast authentication data packet; wherein the slow authentication data packet performs the first key authentication, and the fast authentication data packet realizes message authentication; the fast authentication data packet is composed of a key, a message, the message digest and digital signature fragment of the message information of the key delayed for broadcast, and a message authentication code; wherein the digital signature fragments in multiple fast authentication data packets are combined into a complete digital signature, which is used as full authentication data to verify the validity of the generated root key and establish a trust basis;
[0023] Use the generated root key to calculate a key chain including multiple keys through a one-way function. Since different keys obey the mathematical relationship of the one-way function, only the validity of the generated root key needs to be verified once, and the validity of other keys can be verified through the one-way function; use the message information of the period where the key is delayed for broadcast to generate a message digest through a one-way function, and broadcast it in advance together with the message information and message authentication code using this key; calculate the message authentication code for the data composed of the message and the message digest using the key; calculate the digital signature of the generated root key;
[0024] Use the radio frequency front end to obtain the received signal; perform analog-to-digital conversion on the received signal, then execute relevant steps, decode the obtained message symbols, and store the message data until the key information and digital signature of a slow authentication period are collected;
[0025] Use the public key to calculate the message digest of the key information for the digital signature, generate the message digest of the received key information using a one-way function, and compare the two. If they are equal, the key is valid, and the verified key is saved; if the two are not equal, the key is invalid, and the authentication fails.
[0026] When the digital signature verification passes or the receiver is in the hot start state and has saved the authenticated key information, the receiver continues to complete the fast authentication and verify the validity of the message. The information arrangement order in the fast authentication cycle data packet is the key, the message, the message digest, and the message authentication code. Using the one-to-one mapping relationship between the message digest and the information, two fast authentication cycle information can be verified simultaneously in one fast authentication, realizing real-time message authentication. In a specific embodiment, the present application modifies and rearranges on the basis of the original TESLA data packet (such as Figure 1 ) and divides it into a slow authentication data packet and a fast authentication data packet. The slow authentication cycle uses the digital signature to protect the validity of the key, performs the first key authentication, and at the same time realizes the time synchronization of the receiver. The fast authentication cycle uses the message authentication code (MAC) to prevent the message from being tampered with and realizes message authentication. The specific modifications are summarized as follows:
[0027] 1. The MAC of each authentication cycle protects the message information of the current cycle and the message information of the cycle where the delayed broadcast key is located at the same time;
[0028] 2. Multiple fast authentication cycles are included in the slow authentication cycle, and the digital signature is scattered and broadcast in each fast authentication cycle data packet;
[0029] 3. The present application advances the broadcast position of the key in each authentication cycle, so that before the complete broadcast of the message in each authentication cycle, the receiver can verify the message digest of it. Due to the consistency between the message digest and the message information, their validity is also consistent, and the one-way characteristic of the hash function protects the security of the message information.
[0030] The detailed data packet structure of the present application is as Figure 2 shown. The digital signature in the slow authentication cycle is generated for the key of the fast authentication cycle within this cycle. A slow authentication cycle contains M fast authentication cycle data packets, so the digital signature DS is divided into M ones; the data packet of the j th authentication cycle includes four parts, namely the key , the message , the message digest of the message information of the ( j + n )th authentication cycle , and the one obtained by using the key for and Message Authentication Code MAC calculated from the composed data j , where i indicates that this key is the i th in the key chain, n indicates that the MAC of the current authentication period is generated by the key n broadcast after K i-n authentication periods.
[0031] According to the principle of message digest validity, a message digest is generated by a one-way function using the message information of the authentication period, which is equivalent to creating a unique "digital fingerprint" for each message. Since the message digest has a fixed length and can accurately reflect the key features of the message, there is a one-to-one relationship between the message information and the message digest. When the message digest of a piece of information is verified as valid data, the corresponding message data is also valid.
[0032] At the same time, based on the TESLA protocol packet structure, it is optimized, and key elements such as message digest are incorporated to construct a real-time fast authentication period packet. After the receiving end receives the packet and verifies the validity of the key, using the currently broadcast key, the validity of the message data of the past fast authentication period and the validity of the message digest of the current period can be verified through one fast authentication, without waiting to generate the authentication code and key corresponding to the message of the current period, realizing real-time authentication of the message.
[0033] In one embodiment, such as Figure 4 and Figure 5 . When the receiver is in the cold start state, the receiver needs to first complete the initial authentication and verify the validity of the key. The steps are as follows:
[0034] S1. The radio frequency front end performs analog-to-digital conversion on the received signal. After that, the receiver performs steps such as acquisition, tracking, and message demodulation, and decodes the obtained message symbols;
[0035] S2. Store the message data until the key information and digital signature information of a slow authentication period are collected;
[0036] S3. Use the public key to perform an operation on the digital signature to obtain the message digest of the key information, generate the message digest of the received key information using a one-way function, and compare the two. If they are equal, the key is valid, and the verified key is saved; if the two are not equal, the key is invalid and the authentication fails.
[0037] In one of the embodiments, after the digital signature verification passes or the receiver is in the hot start state and the authenticated key information is saved, the receiver can continue to perform fast authentication. Taking the j th fast authentication period as an example, the fast authentication steps are as follows:
[0038] F1. In the hot start state, the receiver RF front end performs analog-to-digital conversion on the received signal, and then performs capture, tracking, telegram demodulation and other steps to decode the obtained telegram symbols. If the receiver completes the initial authentication and the signal is in the locked state, there is no need to recapture the signal, and it can continue to track and perform the telegram demodulation and decoding process;
[0039] F2. Store the telegram data. j During a fast authentication cycle, the receiver stores the message information ( D j , MAC j );
[0040] F3. Key validity verification. j + n ) fast authentication cycle, receive the key K i-n And verify the validity of the key by K i-n Perform multiple one-way operations and compare the calculated key value with the fast authentication key verified by the slow authentication cycle. If the two are equal, it means K i-n If the key is valid, the authentication fails. The number of single function operations depends on the valid key stored in the receiver and the serial number of the received key in the key chain;
[0041] F4.MAC verification. K i-n Effective, will D j and K i-n Substitute the MAC generation function for calculation and compare the calculation result with the stored MAC j Compare them. If the two are equal, the MAC verification is successful, indicating that D j If the message digest is valid, the message has not been tampered with. Otherwise, the MAC verification fails and the authentication fails.
[0042] F5.Hash verification. When MAC verification succeeds, the receiver continues to receive the first ( j + n ) authentication cycle message information M j+n , substitute this value into the one-way function to calculate its message digest, and then compare it with the value stored by the receiver D j Hash j Compare them. If they are equal, it means the message information M j+n Valid, authentication successful, otherwise M j+n Invalid, authentication failed, achieving the effect of verifying the message as it is received.
[0043] For the real-time authentication message design and terminal authentication method of the above satellite navigation system, the present application constructs a hierarchical real-time authentication data packet structure to enable the terminal to implement the authentication function in stages. The slow authentication cycle data packet protects the validity of the generated root key through digital signature. As the first authentication of the receiver, slow authentication is used to establish the trust basis for terminal message authentication. Among them, multiple fast authentication cycle data packets nested therein realize the function of verifying two fast authentication cycle information at the same time in one fast authentication by arranging the order of information such as the key, message, message digest, and message authentication code, and by using the one-to-one mapping relationship between the message digest and the information, thus building an efficient architecture for real-time authentication. Among them, cryptographic algorithms are used to generate authentication information, and the security of the authentication information is guaranteed by the security of the cryptographic algorithms in mathematical theory, so it can be seen that the authentication information generation system is rigorous. The generated root key is used to generate a key chain through a one-way function, so that the receiver only needs to perform a slow cycle authentication once to verify the key validity. When verifying the key subsequently, only the verified key needs to be calculated through the key chain, and the validity of the current key can be verified by comparing the calculated key with the verified key, thus shortening the key verification time. The message digest is generated by applying a one-way function to the message information of the authentication cycle in which the delayed key is broadcast, and the message authentication code is obtained by encrypting the combined data of the message and the message digest with the key, so that the receiving terminal can verify the messages of two fast authentication cycles at one time. The one-way nature of the one-way function protects the message in the cycle where the delayed key is located from being leaked. The message in the cycle where the delayed key is broadcast can be compared with the verified valid message digest through the one-way function to verify the validity of the information, and real-time authentication is achieved at the cost of a small message overhead.
[0044] In one embodiment, the key for calculating the MAC in each authentication cycle comes from the key chain, such as Figure 3 , and the entire key chain is generated by performing multiple one-way function calculations on a generated root key, and the end points of these calculations serve as the authentication root key. For a key chain of length , the generated root key of the key chain is denoted as , the authentication root key is denoted as , then the key numbered on the chain can be calculated by the following method, including:
[0045] ;
[0046] wherein, is the low-order truncation function, represents the one-way function, is the key numbered on the chain, is the key length. Such as Figure 3As shown, the key chain generation order is opposite to the key application order. During the application process, the satellite sequentially discloses keys starting from the authentication root key until , the root key is generated and not disclosed.
[0047] In one embodiment, a message digest is generated by using the message information of the period in which the delayed broadcast key is located through a one-way function, including:
[0048] Using the message information of the ( i + n )th authentication period, the message digest of the j th authentication period generated through a one-way function is
[0049] ;
[0050] wherein, represents the length of the Hash.
[0051] In one embodiment, a message authentication code is calculated by using the key for the data composed of the message and the message digest, including:
[0052] Using the key to calculate the message authentication code of the j th authentication period for the data composed of the message and the message digest is
[0053] ;
[0054] wherein, represents the length of the MAC, is the key broadcast after delaying n authentication periods, , and the symbol || represents an information concatenation operator.
[0055] In one embodiment, calculating the digital signature of the root key generated includes:
[0056] Calculating the digital signature for the key to the key , and its calculation expression is as follows:
[0057] ;
[0058] wherein, represents the digital signature algorithm, represents the digital signature length, represents the satellite private key.
[0059] In one embodiment, the process of verifying the validity of the key includes:
[0060] Verifying the key K i-nPerform multiple one-way operations, compare the calculated key value with the fast authentication key verified by the slow authentication period. If the two are equal, it indicates that K i-n it is valid; otherwise, the key is invalid and the authentication fails. The number of one-way function operations depends on the valid key saved by the receiver and the sequence number of the received key in the key chain.
[0061] In a specific embodiment, take the B2a message structure of the Beidou civilian navigation signal as an example. This signal adopts the B-CNAV2 navigation message structure, and its frame structure is as Figure 6 shown. Each information type consists of 6 bits PRN, 6 bits MesType, 18 bits SOW, 234 bits message data, and 24 bits CRC. Among them, 234 bits of message data are used to carry message information of different information types, and up to 63 page types can be defined. Currently, 8 valid information types are defined, namely 10, 11, 30, 31, 32, 33, 34, 40. To implement real-time message authentication in the B2a signal, 2 additional information types 50 and 51 are added, and a message authentication model combining fast authentication and slow authentication is designed according to the data format of the present invention. Slow authentication refers to the initial authentication of the receiver, and the validity of the key is judged by verifying the legality of the digital signature, and its period is 150 s; fast authentication refers to after completing one slow authentication, the receiver judges whether the message has been tampered with by verifying the legality of the MAC, and its period is 30 s. The arrangement formats of the two data types are as Figure 7 and Figure 8 , and this solution uses commercial cryptographic algorithms to generate message digests and MACs. Therefore , 128 bits are filled in each frame, and the digital signature length is , 52 bits are filled in each frame. To achieve the same security level as the Galileo open service message authentication, set , CI represents the necessary information for message authentication. The CI data for one slow authentication period is a total of 65 bits, and the reserved bit Rev length is 6 bits. The relationship between the fast authentication period and the slow authentication period is as Figure 9 shown. The broadcast order of the newly defined two page types and the existing page types is 5X, 10, 11, 3X, 40. After verification, after the initial authentication and the receiver verifies the validity of the key, the fast authentication period can achieve real-time message authentication.
[0062] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.
[0063] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.
Claims
1. A real-time authentication message design and terminal authentication method for a satellite navigation system, characterized in that: The method comprises: Setting a real-time authentication data packet structure; the real-time authentication data packet is composed of a slow authentication data packet and a fast authentication data packet; wherein the slow authentication data packet performs the first key authentication, and the fast authentication data packet implements the telegram authentication; A fast authentication data packet is formed according to the key, the message, the message digest of the message information of the delayed key broadcast period, the digital signature fragment, and the message authentication code; wherein the digital signature fragments in multiple fast authentication data packets are combined into a complete digital signature; A key chain including multiple keys is obtained by using a generated root key and calculating through a one-way function. A message digest is generated through a one-way function using the telegram information of the period in which the delayed broadcast key is located, and is broadcast in advance together with the telegram information and message authentication code of the delayed broadcast key application; a message authentication code is calculated using the key pair data consisting of the telegram and the message digest; a digital signature of the generated root key is calculated; a received signal is obtained using a radio frequency front end; the received signal is converted into digital form and then the related steps are executed and the obtained telegram symbols are decoded, and the telegram data is stored until the key information and digital signature of a slow authentication period are collected; The public key is used to operate the digital signature to obtain the message digest of the key information, and the received key information is used to generate the message digest using a one-way function. The two are compared. If they are equal, the key is valid and the verified key is saved; if they are not equal, the key is invalid and the authentication fails. When the digital signature verification is passed or the receiver is in hot start state, the authenticated key information is saved, and the receiver continues to complete the fast authentication to verify the validity of the message; the information in the fast authentication cycle data packet is arranged in the order of key, message, message digest and message authentication code. By using the one-to-one mapping relationship between the message digest and the information, one fast authentication verifies the information of two fast authentication cycles at the same time, realizing real-time message authentication.
2. The method according to claim 1, characterized in that The fast authentication process includes: F1: In the hot start state, the receiver RF front end performs analog-to-digital conversion on the received signal, and then executes the relevant steps to decode the obtained telegram symbols. If the receiver completes the initial authentication and the signal is in the locked state, there is no need to recapture the signal, and it only needs to continue tracking and executing the telegram demodulation and decoding process; F2: j During a fast authentication cycle, the receiver stores the message information ( D j , MAC j ),in, , the symbol || represents the information connector, Indicates j The message information of the authentication cycle, Hash j Indicates j The message digest of a fast authentication cycle, MAC j Indicates j A message authentication code with a fast authentication cycle; F3: In the ( j+n ) fast authentication cycle, receive the key K i-n And verify the validity of the key; F4: When K i-n Effective, will D j and K i-n Substitute the MAC generation function for calculation and compare the calculation result with the stored MAC j Compare them. If the two are equal, the MAC verification is successful, indicating that D j If the message digest is valid, the message has not been tampered with. Otherwise, the MAC verification fails and the authentication fails. F5: When MAC verification succeeds, the receiver continues to receive the first j+n ) authentication cycle message information M j+n , substitute this value into the one-way function to calculate its message digest, and then compare it with the value stored by the receiver D j Hash j Compare them. If they are equal, it means the message information M j+n Valid, authentication successful, otherwise M j+n Invalid, authentication failed.
3. The method according to claim 1, characterized in that The key chain including multiple keys is obtained by using the generated root key and calculating through a one-way function, including: in, is the low-order truncation function. represents a monotonic function, The chain number is The key of is the key length.
4. The method according to claim 1, characterized in that: The message digest is generated by using the telegram information of the period in which the delayed key is broadcast through a one-way function, including: Use delayed broadcast key location ( i + n ) authentication cycle’s message information is generated through a one-way function j The message digest of the authentication cycle is in, Indicates the length of the Hash.
5. The method according to any one of claims 1 to 4, characterized in that: The message authentication code is calculated using the key pair data consisting of the message and the message digest, including: The key is used to calculate the data consisting of the message and the message digest to obtain the j The message authentication code for the authentication cycle is in, Indicates the length of the MAC. For delay n The key broadcasted in the authentication cycle, , the symbol || represents the information connector.
6. The method according to claim 1, characterized in that Calculate and generate the digital signature of the root key, including: Key Calculate the digital signature, the calculation expression is as follows: in, Represents the digital signature algorithm, Indicates the length of the digital signature. Represents the satellite private key.
7. The method according to claim 1, characterized in that The process of verifying the validity of a key includes: Key K i-n Perform multiple one-way operations and compare the calculated key value with the fast authentication key verified by the slow authentication cycle. If the two are equal, it means K i-n If the key is valid, the authentication fails. The number of single function operations depends on the valid key stored in the receiver and the serial number of the received key in the key chain.
Citation Information
Patent Citations
Real name authentication method, server and display device
CN113975813A
Spreading code and message combined satellite navigation signal authentication structure and receiving method
CN116879925A