Data security sharing method for commercial spaceflight measurement and control network

By using a password service platform to issue smart password keys and digital certificates in commercial aerospace measurement and control networks, and using digital envelope technology for encryption, the problem of identity forgery and information leakage in data access in commercial aerospace field is solved, and the secure access sharing of data and high-security transmission of keys is achieved.

CN120017371AActive Publication Date: 2025-05-16XIAN HUANYU SATELLITE TT & C & DATA APPL CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510169270.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-17
Publication Date
2025-05-16
Estimated Expiration
2045-02-17

Smart Images

  • Figure CN120017371A_ABST
    Figure CN120017371A_ABST
Patent Text Reader

Abstract

The invention discloses a data security sharing method for a commercial spaceflight measurement and control network, which is applied to a commercial spaceflight measurement and control network system comprising a password service platform, a business data service platform and a data access demand end, and the data access demand end is in communication connection with the password service platform and the business data service platform. The business data service platform is in communication connection with the password service platform, the business data service platform comprises a plurality of spaceflight business systems, each spaceflight business system comprises security middleware, and the method comprises the following steps: issuing a secret key certificate; identity authentication; performing data access and encrypted downloading; and decrypting the data. According to the data security sharing method for the commercial spaceflight measurement and control network, the intelligent password key is issued to the data access demand end through the password service platform, and the digital certificate is issued, so that identity authentication is carried out by using the digital certificate, and the authenticity and credibility of the identity of the data access demand end are ensured; and secure access sharing of data is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of aerospace communication technology, and in particular to a data security sharing method for a commercial aerospace measurement and control network. Background Art

[0002] With the vigorous development of China's commercial aerospace, related technologies such as mobile Internet, Internet of Things, cloud computing, big data, artificial intelligence, and information security have also profoundly affected industrial development and people's daily lives. Commercial aerospace services cover different fields such as land, surveying and mapping, agriculture, forestry, water conservancy, environmental protection, navigation, and meteorology. The business volume is expanding year by year, involving a large amount of data information, and this data information may be closely related to national security, economic development, and the people's livelihood. The necessity of establishing corresponding security protection mechanisms for business data from the generation, storage, forwarding, transmission, and application of business data is self-evident.

[0003] The commercial aerospace field involves business links such as satellite rocket manufacturing, launching, operation, and application. The data types involved in each business link are diverse and the data flows frequently. The access authentication mechanism of each business system still uses a low-level authentication method of account number and password, which is not suitable for secure access to business in scenarios such as the Internet and mobile Internet. There is a risk of user identity being impersonated and forged, which will affect the company's reputation and damage the interests of the company and users. Summary of the invention

[0004] The technical problem to be solved by the present invention is to provide a data security sharing method for a commercial aerospace measurement and control network to perform identity authentication and realize secure access and sharing of data.

[0005] To solve the above technical problems, the purpose of the present invention is achieved through the following technical solutions: to provide a data security sharing method for a commercial aerospace measurement and control network, which is applied to a commercial aerospace measurement and control network system. The commercial aerospace measurement and control network system includes a cryptographic service platform, a business data service platform and a data access demand side. The data access demand side is respectively communicated with the cryptographic service platform and the business data service platform, and the business data service platform is communicated with the cryptographic service platform. The business data service platform includes a number of aerospace business systems, and each of the aerospace business systems includes a security middleware. The data security sharing method for a commercial aerospace measurement and control network includes the following steps: secret key certificate issuance: the cryptographic service platform issues the corresponding smart cryptographic key to the data access demand side, and issues a digital certificate to the data access demand side; identity authentication: the data access demand side concatenates the demand side encryption certificate and the random number generated by the received cryptographic service platform to form original data, uses the demand side signature private key to digitally sign the original data, obtains the data signature package and sends it to the business data service side The business data service platform calls the cryptographic service platform to parse and verify the data signature package, and performs a blacklist and whitelist check; data access and encrypted download: the business data service platform encrypts the demand-side encryption certificate sent by the data access demand side and caches it, and uses the digital envelope technology to encrypt the data to be encrypted, generates a digital envelope ciphertext and stores it; the data access demand side calls the security middleware through the business data service platform to use the encryption private key of the business data service platform to decrypt the symmetric key ciphertext to obtain the symmetric key, uses the demand-side encryption certificate to encrypt the symmetric key to update the symmetric key ciphertext, and updates the digital envelope ciphertext according to the updated symmetric key ciphertext; data decryption: the data access demand side calls the security middleware through the business data service platform to unpack the obtained digital envelope ciphertext, obtain the corresponding symmetric key ciphertext and data ciphertext, and uses an asymmetric encryption algorithm combined with the demand-side encryption private key to decrypt it to obtain a symmetric key, and uses a symmetric encryption algorithm combined with the symmetric key obtained by decryption to perform a symmetric algorithm on the unpacked data ciphertext to obtain the data to be encrypted.

[0006] The beneficial technical effects of the present invention are as follows: the data security sharing method for commercial aerospace measurement and control networks of the present invention issues corresponding intelligent password keys to the data access demand side through a password service platform, and issues digital certificates to the data access demand side, so as to ensure the authenticity and credibility of the identity of the data access demand side by using digital certificates for identity authentication, prevent identity disguise and information leakage, and realize secure access and sharing of data; the key can be protected by encrypting with digital envelope technology, ensuring that the key will not be stolen or tampered with during transmission, and the encryption and decryption of the digital envelope technology can ensure that only the intended recipient can open and obtain the key. Key, which greatly enhances the security of keys in the process of data sharing and ensures data confidentiality. Moreover, digital envelope technology allows public keys to be securely transmitted in the public network, while private keys remain securely stored, avoiding key leakage problems, simplifying the complexity of key management, and improving key management and exchange efficiency. During the data encryption process, only the symmetric key ciphertext is updated to update the digital envelope ciphertext, without the need to re-encrypt and decrypt data, optimizing the encryption process, and improving the encryption and decryption speed during data sharing. It can ensure the security of data sharing while improving speed and efficiency, reducing computational complexity and resource consumption, and can be applied to different scenarios with strong practicality. BRIEF DESCRIPTION OF THE DRAWINGS

[0007] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying any creative work.

[0008] Figure 1 A schematic flow chart of a data security sharing method for a commercial aerospace measurement and control network provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0009] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0010] See also Figure 1 , Figure 1A flow chart of a data security sharing method for a commercial aerospace tracking and control network provided in an embodiment of the present invention, wherein the data security sharing method for a commercial aerospace tracking and control network is applied to a commercial aerospace tracking and control network system, wherein the commercial aerospace tracking and control network system includes a cryptographic service platform, a business data service platform, and a data access demand end, wherein the data access demand end is respectively connected to the cryptographic service platform and the business data service platform in communication, wherein the business data service platform is connected to the cryptographic service platform in communication, wherein the business data service platform includes several aerospace business systems, wherein each of the aerospace business systems includes a security middleware, and wherein the data security sharing method for a commercial aerospace tracking and control network includes the following steps:

[0011] Step S11, issuance of secret key certificates: The cryptographic service platform issues the corresponding intelligent cryptographic key to the data access demand side, and issues a digital certificate to the data access demand side. Among them, the intelligent cryptographic key includes a demand-side encryption key pair and a demand-side signature key pair, and the key pair includes a public key and a private key. The demand-side encryption key pair includes a demand-side encryption public key and a demand-side encryption private key, and the demand-side signature key pair includes a demand-side signature public key and a demand-side signature private key. The cryptographic service platform provides a certificate application and download interface for the data access demand side to issue a digital certificate to the data access demand side. The digital certificate uses advanced encryption technology to ensure the security and integrity of data during transmission and effectively prevent data from being tampered with or forged. The digital certificate includes a demand-side signature certificate and a demand-side encryption certificate. The cryptographic service platform issues a demand-side signature certificate and a demand-side encryption certificate to the data access demand side. The demand-side signature certificate is used to prove the identity of the data access demand side, and the demand-side encryption certificate is used to encrypt data to improve data security.

[0012] Step S12, identity authentication: The data access demand side concatenates the demand side encryption certificate and the random number generated by the received cryptographic service platform to form the original data, uses the demand side signature private key to digitally sign the original data, obtains the data signature package and sends it to the business data service platform, the business data service platform calls the cryptographic service platform to parse and verify the data signature package, and performs a blacklist and whitelist check; wherein, the demand side encryption certificate is the demand side encryption certificate in the digital certificate issued by the cryptographic service platform to the data access demand side, and the demand side signature private key is the demand side signature private key in the demand side signature key pair issued by the cryptographic service platform to the data access demand side. By verifying the demand side encryption certificate of the data signature package and checking the blacklist and whitelist, identity authentication can be performed and the status of the corresponding demand side encryption certificate in the business data service platform can be confirmed.

[0013] Step S13, data access and encrypted download: the business data service platform encrypts the demand-side encryption certificate sent by the data access demand side and caches it, encrypts the data to be encrypted using digital envelope technology, generates digital envelope ciphertext and stores it; the data access demand side calls the security middleware through the business data service platform to use the encryption private key of the business data service platform to decrypt the symmetric key ciphertext to obtain the symmetric key, uses the demand-side encryption certificate to encrypt the symmetric key to update the symmetric key ciphertext, and updates the digital envelope ciphertext according to the updated symmetric key ciphertext; the data to be encrypted can be data information or files to be encrypted. The demand-side encryption certificate contains the demand-side encryption public key.

[0014] Step S14, data decryption: The data access demand side calls the security middleware through the business data service platform to unpack the obtained digital envelope ciphertext, obtain the corresponding symmetric key ciphertext and data ciphertext, and use an asymmetric encryption algorithm combined with the demand side encryption private key to decrypt and obtain a symmetric key. The symmetric encryption algorithm is used in combination with the symmetric key obtained by decryption to perform a symmetric algorithm decryption on the unpacked data ciphertext to obtain the data to be encrypted.

[0015] Among them, the data access demand side is the demand side that needs to access telemetry and other commercial aerospace measurement and control network system data. The data access demand side includes aerospace measurement and control personnel, aerospace measurement and control equipment and aerospace measurement and control organizations. The cryptographic service platform is used for certificate management and provides key management, middleware management and log auditing functions for security middleware. The data security sharing method for the commercial aerospace measurement and control network issues a corresponding intelligent password key to the data access demand side through a password service platform, and issues a digital certificate to the data access demand side, so that the authenticity and credibility of the identity of the data access demand side can be ensured by using the digital certificate for identity authentication, identity disguise and information leakage can be prevented, and secure access and sharing of data can be achieved; the key can be protected by encrypting with the digital envelope technology to ensure that the key will not be stolen or tampered with during the transmission process, and the encryption and decryption of the digital envelope technology can ensure that only the predetermined recipient can open and obtain the key, thereby greatly enhancing the security of the key in the data sharing process and ensuring the confidentiality of the data. Moreover, the digital envelope technology allows the public key to be securely transmitted in the public network, while the private key is kept securely stored, avoiding the problem of key leakage, simplifying the complexity of key management, and improving the efficiency of key management and exchange; in the data encryption process, only the symmetric key ciphertext is updated to update the digital envelope ciphertext, without the need to re-encrypt and decrypt the data, optimizing the encryption process, and improving the encryption and decryption speed during data sharing, which can ensure the security of data sharing while improving the speed and efficiency, reducing the computational complexity and resource consumption, and can be applied to different scenarios with strong practicality. The data security sharing method for the commercial aerospace tracking and control network of the security middleware can facilitate the recording of data access and sharing operations, including information such as operation time, operator and operation content, so as to facilitate subsequent audits and accountability, making the operations auditable.

[0016] Specifically, the step S12 includes:

[0017] The data access demand side sends a login access request to the business data service platform, and the business data service platform sends a random number request to the password service platform based on the received login access request;

[0018] The cryptographic service platform generates a random number based on the received random number request and sends the generated random number to the data access demand end;

[0019] The data access demand side concatenates the demand side encryption certificate and the received random number to form the original data, uses the demand side signature private key to digitally sign the original data, obtains a data signature package, and sends the data signature package to the business data service platform; wherein, the digital signature is a PKCS#7 signature, and the obtained data signature package contains the signature certificate corresponding to the demand side signature private key, which is used to verify whether the identity of the data access demand side is legal.

[0020] The business data service platform calls the cryptographic service platform to parse the data signature package, verify the validity period, certificate chain, CRL (Certificate Revocation List) and OCSP (Online Certificate Status Protocol) of the signature certificate corresponding to the demand-side signature private key of the data access demand side, and perform whitelist service verification to confirm the status of the signature certificate corresponding to the demand-side signature private key of the data access demand side on the cryptographic service platform. Among them, the CRL and OCSP of the signature certificate corresponding to the demand-side signature private key of the data access demand side are verified to perform blacklist and whitelist checks respectively.

[0021] Preferably, the step S12 further includes:

[0022] When identity authentication fails, the business data service platform rejects the login access request of the data access demand side; when identity authentication succeeds, the data access demand side successfully logs in to the business data service platform, and the business data service platform obtains the demand side encryption certificate from the data access demand side.

[0023] Preferably, the step of using the signature private key of the demand side to digitally sign the original data in step S12 is specifically: the data access demand side uses the signature private key of the demand side to digitally sign the original data through a secure password device. The secure password device corresponds to the data access demand side one by one and is used to store the corresponding smart password key.

[0024] Preferably, the step S11 may further include: the security password device stores the smart password key corresponding to the data access demand end.

[0025] Specifically, the step S13 includes:

[0026] The business data service platform encrypts and caches the encryption certificate sent by the data access demand side.

[0027] The business data service platform calls the encryption interface of the security middleware to generate a symmetric encryption random key;

[0028] A symmetric encryption algorithm is used in combination with a symmetric encryption random key to symmetrically encrypt the data to be encrypted to obtain data ciphertext; wherein the symmetric encryption algorithm can be an SM4 algorithm.

[0029] An asymmetric encryption algorithm is used in combination with a symmetric encryption random key generated by a public key pair of an asymmetric key pair to encrypt and obtain a symmetric key ciphertext; wherein the asymmetric encryption algorithm may be an SM2 algorithm.

[0030] Integrate and encapsulate the data ciphertext and the symmetric key ciphertext to generate a digital envelope ciphertext and store it;

[0031] The data access demand side calls the security middleware through the business data service platform and uses the encrypted private key of the business data service platform to decrypt the symmetric key ciphertext to obtain the symmetric key;

[0032] The symmetric key is encrypted using the demand-side encryption certificate to update the symmetric key ciphertext, and the data ciphertext and the updated symmetric key ciphertext are integrated and packaged to update the digital envelope ciphertext.

[0033] Preferably, before step S13, the step further includes:

[0034] The business data service platform calls the security middleware to obtain the encryption key pair of the business data service platform stored in the cryptographic service platform, and caches the public key of the asymmetric key pair of the encryption key pair of the business data service platform.

[0035] Specifically, the step S14 includes:

[0036] The data access demand side calls the security middleware through the business data service platform to unpack the obtained digital envelope ciphertext and obtain the corresponding symmetric key ciphertext and data ciphertext;

[0037] Call the decryption interface of the security middleware to use an asymmetric encryption algorithm combined with the demand-side encryption private key to decrypt the symmetric key ciphertext obtained by unpacking and obtain the symmetric key;

[0038] The symmetric encryption algorithm is used in combination with the symmetric key obtained by decryption to decrypt the data ciphertext obtained by unpacking, and the data to be encrypted is obtained.

[0039] In summary, the data security sharing method for the commercial aerospace measurement and control network of the present invention issues the corresponding intelligent password key to the data access demand end through the password service platform, and issues the digital certificate to the data access demand end, so as to ensure the authenticity and credibility of the identity of the data access demand end by using the digital certificate for identity authentication, prevent identity disguise and information leakage, and realize secure access and sharing of data; the key can be protected by encrypting with the digital envelope technology to ensure that the key will not be stolen or tampered with during the transmission process, and the encryption and decryption of the digital envelope technology can ensure that only the predetermined recipient can open and obtain the key, thereby greatly enhancing the security of the key in the data sharing process and ensuring the confidentiality of the data. Moreover, the digital envelope technology allows the public key to be safely transmitted in the public network, while the private key is kept securely stored, avoiding the problem of key leakage, simplifying the complexity of key management, and improving the efficiency of key management and exchange; in the data encryption process, only the symmetric key ciphertext is updated to update the digital envelope ciphertext, without the need to re-encrypt and decrypt the data, optimizing the encryption process, and improving the encryption and decryption speed during data sharing, which can ensure the security of data sharing while improving the speed and efficiency, reducing the computational complexity and resource consumption, and can be applied to different scenarios with strong practicality.

[0040] The above is only a specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any technician familiar with the technical field can easily think of various equivalent modifications or replacements within the technical scope disclosed by the present invention, and these modifications or replacements should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention shall be based on the protection scope of the claims.

Claims

1. A data security sharing method for a commercial aerospace measurement and control network, characterized in that: Applied to a commercial aerospace tracking and control network system, the commercial aerospace tracking and control network system includes a cryptographic service platform, a business data service platform and a data access demand end, the data access demand end is respectively connected to the cryptographic service platform and the business data service platform, the business data service platform is connected to the cryptographic service platform, the business data service platform includes several aerospace business systems, each of the aerospace business systems includes a security middleware, and the data security sharing method for the commercial aerospace tracking and control network includes the following steps: Issuance of secret key certificates: The cryptographic service platform issues the corresponding intelligent cryptographic key to the data access demand side, and issues a digital certificate to the data access demand side; Identity authentication: The data access demand side concatenates the demand side encryption certificate and the random number generated by the received password service platform to form the original data, uses the signature private key of the demand side to digitally sign the original data, obtains the data signature package and sends it to the business data service platform. The business data service platform calls the password service platform to parse and verify the data signature package, and performs blacklist and whitelist checks; Data access and encrypted download: The business data service platform encrypts and caches the demand-side encryption certificate sent by the data access demand side, encrypts the data to be encrypted using digital envelope technology, generates and stores digital envelope ciphertext; the data access demand side calls the security middleware through the business data service platform to use the business data service platform's encrypted private key to decrypt the symmetric key ciphertext to obtain the symmetric key, encrypts the symmetric key using the demand-side encryption certificate to update the symmetric key ciphertext, and updates the digital envelope ciphertext based on the updated symmetric key ciphertext; Data decryption: The data access demand side calls the security middleware through the business data service platform to unpack the obtained digital envelope ciphertext, obtain the corresponding symmetric key ciphertext and data ciphertext, and use an asymmetric encryption algorithm combined with the demand-side encryption private key to decrypt and obtain a symmetric key. The symmetric encryption algorithm is used in combination with the symmetric key obtained by decryption to perform a symmetric algorithm decryption on the unpacked data ciphertext to obtain the data to be encrypted.

2. The data security sharing method for commercial aerospace measurement and control network according to claim 1 is characterized in that: The steps of identity authentication include: The data access demand side sends a login access request to the business data service platform, and the business data service platform sends a random number request to the password service platform based on the received login access request; The cryptographic service platform generates a random number based on the received random number request and sends the generated random number to the data access demand end; The data access demand side concatenates the demand side encryption certificate and the received random number to form the original data, uses the demand side signature private key to digitally sign the original data, obtains the data signature package, and sends the data signature package to the business data service platform; The business data service platform calls the cryptographic service platform to parse the data signature package, verify the validity period, certificate chain, CRL and OCSP of the signature certificate corresponding to the demand-side signature private key of the data access demand side, and perform whitelist service verification.

3. The data security sharing method for commercial aerospace measurement and control network according to claim 1 is characterized in that: The identity authentication step also includes: When identity authentication fails, the business data service platform rejects the login access request of the data access demand side; when identity authentication succeeds, the data access demand side successfully logs in to the business data service platform, and the business data service platform obtains the demand side encryption certificate from the data access demand side.

4. The data security sharing method for commercial aerospace measurement and control network according to claim 1 is characterized in that: The step of using the signature private key of the demand side to digitally sign the original data in the identity authentication step is: the data access demand side uses the signature private key of the demand side to digitally sign the original data through a secure cryptographic device.

5. The data security sharing method for commercial aerospace measurement and control network according to claim 4 is characterized in that: The step of issuing the secret key certificate also includes: The secure password device stores the smart password key corresponding to the data access demand side.

6. The data security sharing method for commercial aerospace measurement and control network according to claim 1 is characterized in that: The steps of data access and encrypted downloading include: The business data service platform encrypts and caches the encryption certificate sent by the data access demand side. The business data service platform calls the encryption interface of the security middleware to generate a symmetric encryption random key; Use a symmetric encryption algorithm combined with a symmetric encryption random key to symmetrically encrypt the data to be encrypted to obtain the data ciphertext; An asymmetric encryption algorithm is used to encrypt a symmetric encryption random key generated by a public key pair of an asymmetric key pair to obtain a symmetric key ciphertext; Integrate and encapsulate the data ciphertext and the symmetric key ciphertext to generate a digital envelope ciphertext and store it; The data access demand side calls the security middleware through the business data service platform and uses the encrypted private key of the business data service platform to decrypt the symmetric key ciphertext to obtain the symmetric key; The symmetric key is encrypted using the demand-side encryption certificate to update the symmetric key ciphertext, and the data ciphertext and the updated symmetric key ciphertext are integrated and packaged to update the digital envelope ciphertext.

7. The data security sharing method for commercial aerospace measurement and control network according to claim 6 is characterized in that: The steps of data decryption include: The data access demand side calls the security middleware through the business data service platform to unpack the obtained digital envelope ciphertext and obtain the corresponding symmetric key ciphertext and data ciphertext; Call the decryption interface of the security middleware to use an asymmetric encryption algorithm combined with the demand-side encryption private key to decrypt the symmetric key ciphertext obtained by unpacking and obtain the symmetric key; The symmetric encryption algorithm is used in combination with the symmetric key obtained by decryption to decrypt the data ciphertext obtained by unpacking, and the data to be encrypted is obtained.

8. The data security sharing method for commercial aerospace measurement and control network according to claim 1 is characterized in that: The smart cryptographic key includes an encryption key pair and a signature key pair.

Citation Information

Patent Citations

  • Network data secure transmission method

    CN106506470A

  • Electronic contract encryption and decryption method and system based on bidirectional authentication

    CN116388972A

  • Data processing method and device based on block chain and readable storage medium

    CN117560190A

  • High-speed secure data transmission method for commercial spaceflight measurement and control network

    CN120017370A

  • Method, apparatus, and storage medium for updating vehicle software

    EP4318217A1