Mobile user identity authentication method based on elliptic curve encryption algorithm in satellite network

By adopting a distributed identity authentication method based on elliptic curve encryption algorithm in satellite networks, the problem of direct identity authentication between mobile users and satellites is solved, an efficient and secure identity authentication process is achieved, and the security and reliability of the network are enhanced.

CN120018130APending Publication Date: 2025-05-16CHENZHI AUTOMOBILE TECHNOLOGY GROUP CO LTD CHONGQING INNOVATION RESEARCH BRANCH +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510141546.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-08
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

In satellite networks, it is difficult for the prior art to realize direct identity authentication between mobile users and satellites, and there are problems such as inefficiency, frequent interactions, large signal jitter, and failure to effectively resist distributed denial of service attacks.

Method used

The distributed identity authentication method based on the elliptic curve encryption algorithm is adopted, through the initialization of the distributed identity system and the publication of public parameters, the distributed identity registration and DID document release of entities, the proxy authorization of ground stations to satellites, and the direct authentication of mobile users and satellites obtained by the proxy authorization.

Benefits of technology

It realizes direct identity authentication between mobile users and satellites, improves identity authentication efficiency, and enhances information security attributes, including conditional anonymity, anti-replay attacks, non-forgery, anti-witch attacks, anti-man-in-the-middle attacks and anti-distributed denial of service attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120018130A_ABST
    Figure CN120018130A_ABST
Patent Text Reader

Abstract

The invention provides a user identity authentication method based on an elliptic curve encryption algorithm in a satellite network, and the method comprises the steps: carrying out the initialization of a distributed identity system, and issuing public parameters to all parties; the ground station, the satellite and the mobile user register distributed identities to the distributed identity system respectively and publish respective DID documents on the distributed identity network; the ground station authorizes the satellite through the distributed identity of the ground station, so that the satellite obtains proxy authorization; when the mobile user needs service, the mobile user is directly authenticated through the distributed identity of the mobile user and the satellite which obtains agent authorization; and after the identity authentication is passed, the mobile user negotiates a shared key with the satellite which obtains the agent authorization, and an authentication key and an encryption key which are required by the satellite to provide service for the mobile user are derived from the shared key through a key derivation function.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of identity authentication, and specifically to a method for mobile user identity authentication based on an elliptic curve encryption algorithm in a satellite network. Background Art

[0002] "He, D., Chen, C., Chan, S., Bu, J.: Analysis and improvement of a secure and efficient handover authentication for wireless networks. IEEE Communications Letters 16 (8), 1270-1273 (2012)" proposed a secure and efficient handover authentication scheme based on bilinear pairing functions, which is also suitable for the high mobility of cars. However, since the nodes of the LEO (low earth orbit satellite) network are distributed in an extremely wide open area, it is difficult to establish an online key management center as powerful as a centralized solution.

[0003] "Liu, Y., Zhang, A., Li, J., Wu, J.: An anonymous distributed key management system based on cl-pkc for space information network. In: 2016 IEEE international conference on communications (ICC). pp. 1-7. IEEE (2016)" proposed a distributed key management system model to provide a complete key exchange service based on a certificateless public key cryptography system, avoiding complex certificate management and key escrow issues. However, the efficiency of this solution in satellite Internet is low, and the number of interactions during the authentication process is too large, which is not conducive to the "vehicle-satellite" authentication with high signal jitter.

[0004] "Huang, Y., Al-Qahtani, FS, Duong, TQ, Wang, J.: Secure transmission in mimowire tap channels using general-order transmit antenna selection without dated csi. IEEE Transactions on Communications 63 (8), 2959-2971 (2015)" points out that the signal processing and beamforming methods of MIMO technology can be used to further improve the security of satellite systems, and proposes a secure routing protocol based on intrusion detection. The protocol uses an intrusion detection system to detect malicious attacks through a routing protocol, and then reduces the credit of the node through a credit system. However, this scheme does not take into account issues such as user identity and privacy anonymity, and does not resist distributed denial of service attacks.

[0005] Deng, X., Shao, J., Chang, L., Liang, J.: A blockchain-based authentication protocol using cryptocurrency technology in satellite networks. Electronics 10 (24), 3151 (2021) proposes a blockchain-based authentication protocol using cryptocurrency technology to solve the frequent switching between satellites and ground users and vehicles. However, due to the long consensus time of the blockchain, the time for distributed nodes to obtain public keys is not uniform, and there is a problem that user access authentication causes a long suspension time of satellite services, which will lead to extremely low identity authentication efficiency (more than 3 minutes) in actual application.

[0006] "Sudarsono, A, WidyatraSudibyo, R, Winarno, I & Yuliana, M2024, 'Ephemeral Secret Leakage-Free ID-Role-Based Access Control Authentication and Key Exchange Protocol for Securing Electric Vehicle Data', IEEE Access, vol. 12, pp. 120961-120978." also introduced a mutual authentication protocol that simply uses hash and XOR functions to provide simple and effective authentication at a low computational cost. However, NCC is involved in each authentication process, which becomes a bottleneck that limits performance and may cause a single point of failure. Moreover, the scheme does not take into account the privacy of users and may therefore be vulnerable to impersonation attacks.

[0007] "Beheshti-Atashgah, M., Aref, MR, Bayat, M., Barari, M.: Id-based strong designed verifier signature scheme and its applications in internet of things. In: 2019 27th Iranian Conference on Electrical Engineering (ICEE). pp. 1486-1491. IEEE (2019)" proposed a new and efficient designated authenticator identity-based signature scheme, which has a high degree of unforgeability, and also obtained a new and efficient designated authenticator proxy identity-based signature scheme. However, the cryptographic security properties of this scheme are not complete, and the dynamic motion scenario of LEO is not considered, and a lightweight scheme suitable for direct authentication between satellites and users is not proposed. Summary of the invention

[0008] The present application provides a method for mobile user identity authentication in a satellite network based on an elliptic curve encryption algorithm, which is used to implement identity authentication between a mobile user and a satellite directly.

[0009] The technical solution of the present invention is:

[0010] A method for mobile user identity authentication based on elliptic curve encryption algorithm in a satellite network, comprising:

[0011] The distributed identity system is initialized and public parameters are released to all parties;

[0012] The ground station, satellite, and mobile user each register a distributed identity with the distributed identity system and publish their own DID documents on the distributed identity network;

[0013] The ground station authorizes the satellite through its distributed identity, so that the satellite obtains proxy authorization;

[0014] When a mobile user needs service, he or she directly authenticates with the satellite that has obtained proxy authorization through his or her distributed identity. After the identity authentication is passed, the mobile user negotiates a shared key with the satellite that has obtained proxy authorization, and then derives the authentication key and encryption key required for the satellite to provide services to the mobile user from the shared key through a key derivation function.

[0015] Preferably, the steps of initializing the distributed identity system and publishing public parameters to all parties include:

[0016] Choose a k-bit prime number p and determine the elliptic curve E / Fp over the finite field; the points on the elliptic curve E / Fp together with the infinite point O form a cyclic additive group G of order q;

[0017] Choose a secret value x∈z q * As the master private key of the distributed identity system, and calculate P pub =x·P as the master public key, where P is a generator of the cyclic additive group G, z q * is the integer group, with group elements ranging from 1 to q-1;

[0018] Choose a hash function: H: {0, 1} * →z q * , h: {0, 1} * →{0, 1} n , where n represents the string length; the public parameters for initializing the DID system are:

[0019] P ar = {G,P,P pub ,H,h}.

[0020] Preferably, the steps of the ground station and the satellite each registering a distributed identity with the distributed identity system and publishing their respective DID documents on the distributed identity network include:

[0021] As entities, ground stations and satellites register their distributed identities according to the following process:

[0022] Entity j enters registration information; the distributed identity system generates a DID identity for entity j based on the registration information of entity j. The distributed identity system uses the public parameters and the DID identity of entity j to generate a private key for entity j and generate a DID document for entity j.

[0023] The ground station publicly publishes the authentication public key in the DID document it publishes;

[0024] Satellites publish an authentication public key in the DID document they publish, along with a statement of permissions that allows proxy authorization.

[0025] Preferably, the step of the distributed identity system generating a private key of entity j for entity j using the public parameters comprises:

[0026] Distributed identity system selects random number r j ∈Z q * , calculate the public key K of entity j j and the private key σ j :K j =rj P and σ j = x·H(K j ,ID j )+r j ;

[0027] The distributed identity system uses a secure channel to send entity j’s key pair {K j ,σ j}Send to entity j;

[0028] Entity j receives the key pair {K j ,σ j}, verify the equation σ j P=H(K j ,ID j )·P pub +K j Is it true? If the equality holds, entity j will σ j Save it as its private key.

[0029] Preferably, the steps of registering a distributed identity and a verifiable credential with a distributed identity system and publishing its DID document on the distributed identity network include:

[0030] The mobile user, as user i, sends his real identity ID to the distributed identity system through a secure channel i ;

[0031] The distributed identity system receives the real identity ID of user i i After that, generate a temporary identity TID i , where TID i =h(K i ,x)+ID i ; Generate a proxy authorization w for user i i ;

[0032] The distributed identity system selects a random number r i ∈Z q * , and calculate the public key K of user i i and the private key σ i :K i =r i P,σ i = x·H(K i ,TID i ,w i )+r i ;

[0033] Distributed identity systems will i ,σ i ,TID i,w i}Send to user i and create a distributed identity and verifiable credentials for user i;

[0034] The DID document published by user i includes: user i’s public key K i and points to a storage location for verifiable credentials for user agent authorization.

[0035] Preferably, the ground station authorizes the satellite through its distributed identity, and the step of enabling the satellite to obtain proxy authorization includes:

[0036] Ground Station G s Select a proxy credential wG s L e , the proxy certificate wG s L e After signing, it is embedded into the proxy authorization;

[0037] Ground Station G s Choose two random numbers a s and rG s L e , calculate the temporary public key RG s , session key KGsL e and private key σG s L e ; Among them, RG s =a s ·P, KG s L e =rG s L e ·P,σG s L e =σG s ·H(KG s L e, IDLe, wG s L e, RG s )+rG s L e ; σG s For ground station G s The private key of

[0038] Ground Station G s The proxy authorization message MG is sent through the secure channel s L e Sent to satellite L e , proxy authorization message MG s L e Including ground station G s The public key KG s , session key KG s L e 、Private key σGs L e , proxy certificate wG s L e and the temporary public key RG s ;

[0039] Satellite L e Received proxy authorization message MG s L e Then, using the ground station G s The public key in the DID document is used to verify the proxy authorization and the proxy authorization message MG s L e ; After successful verification, satellite L e Save the proxy signing key pskG s L e =σG s L e and the agent authorized to {KG s L e ,σG s L e ,wG s L e}.

[0040] Preferably, the mobile user identity authentication method further comprises:

[0041] After identity authentication is passed, the mobile user and the ground station derive the authentication key and encryption key required for the ground station to provide services to the mobile user from the shared key through a key derivation function.

[0042] The beneficial effects of the present invention are:

[0043] Direct authentication between mobile users and satellite networks to obtain satellite services, without using satellites as message forwarders and allowing ground stations to provide services and service access policies. The access policy of mobile users is controlled by distributed identity DID. Since distributed identity DID ensures that mobile users can independently control their identities, has strong privacy attributes, and contains claims and verifiable credentials (VC) itself, it can greatly improve the single-point failure and identity control power distribution problems under the traditional hierarchical PKI system. The ECC (elliptic curve cryptography) algorithm is used to construct the private keys of mobile users, ground stations, and satellites. The ground station signs for the satellite proxy. After the satellite has the proxy signature, it can directly authenticate with the mobile user to achieve information interaction. The proxy authorization of mobile users stipulates and restricts the scope of services that users can access, the time of accessing the satellite network, etc. The proxy authorization of satellites allows satellites to directly authenticate with users and provide services, and also restricts the time of proxy authorization, whether reauthorization (to other satellites in the constellation) is allowed, the upper limit of reauthorization, the scope of services allowed to authenticate with users, etc. Through the above operations, the present application has the following information security attributes:

[0044] Conditional anonymity: Different from entities such as satellites and ground stations, mobile users do not directly use their real identities, but temporary identities;

[0045] Replay attack prevention: Only users and entities themselves know their private keys, and other attackers without private keys cannot be verified; The user proxy (admission) and satellite proxy authorization are time-limited and will check whether they have expired. That is, when the satellite receives a vehicle's request, it will verify its private key and check whether its proxy authorization has expired or is invalid;

[0046] Non-forgeability: Due to the characteristics of ECC and private keys, other attackers without private keys cannot forge the private keys of entities or users.

[0047] Sybil attack resistance: The DID distributed network can jointly trace the real identity with other nodes. Here, the number of other nodes must be greater than or equal to the Byzantine fault tolerance, which represents the traceability initiated by an authoritative institution, rather than malicious nodes.

[0048] Man-in-the-middle attack resistance: A large number of hash functions appear in the solution, which can ensure the integrity of data.

[0049] Distributed denial-of-service attack resistance: In the distributed network of the solution, the nodes of the blockchain allow fault tolerance. Under Byzantine fault tolerance, the number of failed nodes or malicious nodes is t, and N is the total number of nodes, satisfying t < N / 3. The normal registration, proxy, and authentication processes can still be maintained. Brief Description of the Drawings

[0050] Figure 1This is a flow chart of a vehicle identity authentication method based on an elliptic curve encryption algorithm in a satellite network in an embodiment of the present application. DETAILED DESCRIPTION

[0051] The present application provides a method for mobile user identity authentication based on elliptic curve encryption algorithm in a satellite network, wherein the mobile user can be a mobile device such as a vehicle or a mobile phone. In the embodiment of the present application, the mobile user is a vehicle for a specific description. Figure 1 ,The method of this scheme is divided into four stages, namely the ,system initial stage, registration stage, proxy stage, and authentication stage.

[0052] In the initial stage of the system: the distributed identity system is initialized and public parameters are released to all parties.

[0053] The steps of initializing the distributed identity system and publishing public parameters to all parties include:

[0054] Choose a k-bit prime number p and determine the elliptic curve E / Fp over the finite field; the points on the elliptic curve E / Fp together with the infinite point O form a cyclic additive group G of order q;

[0055] Choose a secret value x∈z q * As the master private key of the distributed identity system, and calculate P pub =x·P as the master public key, where P is a generator of the cyclic additive group G, z q * is the integer group, with group elements ranging from 1 to q-1;

[0056] Choose a hash function: H: {0, 1} * →z q * , h: {0, 1} * →{0, 1} n , where n represents the length of the string;

[0057] The public parameters for initializing the DID system are:

[0058] P ar = {G, P, P pub , H, h}.

[0059] Registration phase: The ground station, satellite, and vehicle each register their distributed identities with the distributed identity system and publish their respective DID documents on the distributed identity network.

[0060] Furthermore, the ground station and the satellite each register a distributed identity with the distributed identity system, and publish their respective DID documents on the distributed identity network, including:

[0061] As entities, ground stations and satellites register their distributed identities according to the following process:

[0062] Entity j enters registration information; the distributed identity system generates a DID identity of entity j based on the registration information of entity j. The distributed identity system uses the public parameters and the DID identity of entity j to generate a private key for entity j and generate a DID document for entity j.

[0063] The ground station publishes the authentication public key in the DID document it publishes, allowing any entity to verify its identity through the public key;

[0064] The satellite publishes a public authentication key and a permission statement that allows proxy authorization (e.g., temporary proxy authorization that allows ground stations to use it) in the DID document it publishes.

[0065] Furthermore, the steps of the distributed identity system using the public parameters to generate a private key of entity j for entity j include:

[0066] Distributed identity system selects random number r j ∈Z q * , calculate the public key K of entity j j and the private key σ j :K j =r j P and σ j = x·H(K j , ID j )+ r j;

[0067] The distributed identity system uses a secure channel to send entity j’s key pair {K j , σ j}Send to entity j;

[0068] Entity j receives the key pair {K j , σ j}, verify the equation σ j P=H(K j , ID j )·P pub +K j Is it true? If the equality holds, entity j will σ j as its private key; otherwise, reject the message.

[0069] Further, the steps of registering the distributed identity and verifiable credentials of the vehicle with the distributed identity system and publishing its DID document on the distributed identity network include:

[0070] The vehicle acts as user i and sends its real identity ID to the distributed identity system through a secure channeli ;

[0071] The distributed identity system receives the real identity ID of user i i After that, generate a temporary identity TID i , where TID i =h(K i ,x)+ID i ; Generate a proxy authorization w for user i i , the agent authorizes w i is the proxy information of user i, including the access rights of user i on the network, the effective deadline of the proxy, etc. This proxy authorizes w i The credential content that will serve as the verifiable credential VC;

[0072] The distributed identity system selects a random number r i ∈Z q * , and calculate the public key K of user i i and the private key σ i :K i =r i P,σ i = x·H(K i ,TID i ,w i )+r i ;

[0073] Distributed identity systems will i ,σ i ,TID i ,w i}Send to user i and create a distributed identity DID and verifiable credential VC for user i;

[0074] In a distributed identity system, the DID document published by user i includes: the public key K of user i for user identity authentication i and points to the location where the user agent's verifiable credentials for authorization are stored.

[0075] Proxy stage: The ground station authorizes the satellite through its distributed identity, so that the satellite obtains proxy authorization.

[0076] Furthermore, the ground station authorizes the satellite through its distributed identity, and the steps for the satellite to obtain proxy authorization include:

[0077] Authorization generation: The ground station selects a proxy credential wG s L e , the proxy credential wG s L eIncluding: validity period of permission, scope of permission (for example, allowing access to authentication information of a specific user), whether to allow the proxy to further forward authorization, and other security attributes; s L e After signing, it is embedded in the proxy authorization, so that the proxy authorization can be issued through a distributed identity network or transmitted peer-to-peer, and its authenticity and validity can be verified by any verifier;

[0078] Key negotiation: Ground station G s Choose two random numbers a s and rG s L e , calculate the temporary public key RG s , session key KGsL e and private key σG s L e ; Among them, RG s =a s ·P, KG s L e =rG s L e ·P,σG s L e =σG s ·H(KG s L e, IDLe, wG s L e, RG s )+rG s L e ; σG s The ground station Gs sends the proxy authorization message MG through a secure channel. s L e Sent to satellite L e , proxy authorization message MG s L e Contains the public key KG of the ground station Gs s , session key KG s L e 、Private key σG s L e , proxy certificate wG s L e and the temporary public key RG s ;

[0079] Authorization Verification: Satellite L e Received proxy authorization message MG s L e Then, using the ground station G s The public key in the DID document is used to verify the proxy authorization and the proxy authorization message MG s Le ; After successful verification, satellite L e Save the proxy signing key pskG s L e =σG s L e and the agent authorized to {KG s L e ,σG s L e ,wG s L e}.

[0080] Satellite L e Received proxy authorization message MG s L e Then, using the ground station G s The public key in the DID document is used to verify the proxy authorization and the proxy authorization message MG s L e Specifically include:

[0081] Satellite L e Verify that the proxy authorization is done by the ground station G s Issue and check the validity of the credential content (validity includes whether it is within the scope of authority and validity period, etc.); after completing the verification, further verify whether the following equation is true: σG s L e P = KG s L e +H(KG s L e ,IDL e ,wG s L e ,RG s )·(H(KG s ,IDG s )·P pub +KG s ).

[0082] If the equation holds true, satellite L e Save its proxy signing key pskG s L e =σG s L e And save the proxy authorization pair {KG s L e ,σG s L e ,wG s L e}.

[0083] Authentication phase: When the vehicle needs service, it sends a signal to the LEO satellite e Send the private key Si and proxy authorization i After completing the verification of the access request, the LEO satellite checks the proxy authorization w of vehicle i. i Is it expired or invalid? If invalid or expired, the access request is rejected; if approved, the LEO satellite L e Complete direct identity authentication of vehicle i, vehicle i and LEO satellite L e The algorithm is executed separately to establish a secure channel, generate a shared key sk, and the vehicle i and the LEO satellite L e The LEO satellite L is derived from the shared key sk e The authentication key and encryption key required to provide services to vehicle i. And, in the proxy authorization w of vehicle i i If not expired and valid, LEO satellite L e To ground station G s and vehicle i sends a response to reduce transmission delay; vehicle i and ground station G s Receive LEO satellite L e After the response of vehicle i and ground station G s The algorithm is executed separately to establish a secure channel and generate a shared key sk, vehicle i and ground station G s The authentication key AK required by the ground station to provide services to mobile users is derived from the shared key sk i and encryption key EK i ; Ground station G s The authentication key AK i Sent to LEO satellite G s . Authentication key AK in subsequent communications i and encryption key EK i Used for data authentication and encryption respectively.

[0084] Furthermore, after the identity authentication is passed, vehicle i and ground station G s The authentication key and encryption key required for the ground station to provide services to mobile users are derived from the shared key through a key derivation function (KDF).

[0085] It should be noted that the various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.

[0086] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present invention.

[0087] It should also be noted that, in this article, the orientation or position relationship indicated by the terms "center", "up", "down", "left", "right", "vertical", "horizontal", "inside", "outside", etc. is based on the orientation or position relationship shown in the drawings, which is for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation of the present invention. In addition, relational terms such as "first" and "second" are used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply that there is any such actual relationship or order between these entities or operations, nor can they be understood as indicating or implying relative importance. Moreover, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or terminal device including a series of elements does not include those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such a process, method, article or terminal device. In the absence of further restrictions, the elements defined by the sentence "including one..." do not exclude the existence of other identical elements in the process, method, article or terminal device including the elements.

[0088] The technical solution provided by the present invention is described in detail above. The principle and implementation mode of the present invention are described in this article using specific examples. The description of the above embodiments is only used to help understand the present invention, and the content of this specification should not be understood as limiting the present invention. At the same time, for those skilled in the art, according to the present invention, there will be different forms of changes in the specific implementation mode and application scope. It is not necessary and impossible to list all the implementation modes here, and the obvious changes or modifications derived therefrom are still within the protection scope of the present invention.

Claims

1. A method for mobile user identity authentication based on elliptic curve encryption algorithm in a satellite network, characterized in that: include: The distributed identity system is initialized and public parameters are released to all parties; The ground station, satellite, and mobile user each register a distributed identity with the distributed identity system and publish their own DID documents on the distributed identity network; The ground station authorizes the satellite through its distributed identity, so that the satellite obtains proxy authorization; When a mobile user needs service, he or she directly authenticates with the satellite that has obtained proxy authorization through his or her distributed identity. After the identity authentication is passed, the mobile user negotiates a shared key with the satellite that has obtained proxy authorization, and then derives the authentication key and encryption key required for the satellite to provide services to the mobile user from the shared key through a key derivation function.

2. The mobile user identity authentication method according to claim 1, characterized in that: The steps for initializing the distributed identity system and publishing public parameters to all parties include: Choose a k-bit prime number p and determine the elliptic curve E / Fp over the finite field; the points on the elliptic curve E / Fp together with the infinite point O form a cyclic additive group G of order q; Choose a secret value x∈z q * As the master private key of the distributed identity system, and calculate P pub =x·P as the master public key, where P is a generator of the cyclic additive group G, z q * is the integer group, with group elements ranging from 1 to q-1; Choose a hash function: H: {0, 1} * →z q * , h: {0, 1} * →{0, 1} n , where n represents the length of the string; The public parameters for initializing the DID system are: P ar ={G,P,P pub ,H,h}。 3. The mobile user identity authentication method according to claim 2, characterized in that: The steps for the ground station and the satellite to register their respective distributed identities with the distributed identity system and publish their respective DID documents on the distributed identity network include: As entities, ground stations and satellites register their distributed identities according to the following process: Entity j enters registration information; the distributed identity system generates a DID identity for entity j based on the registration information of entity j. The distributed identity system uses the public parameters and the DID identity of entity j to generate a private key for entity j and generate a DID document for entity j. The ground station publicly publishes the authentication public key in the DID document it publishes; Satellites publish an authentication public key in the DID document they publish, along with a statement of permissions that allows proxy authorization.

4. The mobile user identity authentication method according to claim 3, characterized in that: The steps of the distributed identity system using the public parameters to generate the private key of entity j for entity j include: Distributed identity system selects random number r j ∈Z q * , calculate the public key K of entity j j and the private key σ j :K j =r j P and σ j = x·H(K j ,ID j )+r j ; The distributed identity system uses a secure channel to send entity j’s key pair {K j ,σ j }Send to entity j; Entity j receives the key pair {K j ,σ j }, verify the equation σ j P=H(K j ,ID j )·P pub +K j Is it true? If the equality holds, entity j will σ j Save it as its private key.

5. The mobile user identity authentication method according to claim 4, characterized in that: The steps for a mobile user to register a distributed identity and verifiable credentials with the distributed identity system and publish its DID document on the distributed identity network include: The mobile user, as user i, sends his real identity ID to the distributed identity system through a secure channel i ; The distributed identity system receives the real identity ID of user i i After that, generate a temporary identity TID i , where TID i =h(K i ,x)+ID i ; Generate a proxy authorization w for user i i ; The distributed identity system selects a random number r i ∈Z q * , and calculate the public key K of user i i and the private key σ i :K i =r i P,σ i = x·H(K i ,TID i ,w i )+r i ; Distributed identity systems will i ,σ i ,TID i ,w i }Send to user i and create a distributed identity and verifiable credentials for user i; The DID document published by user i includes: user i’s public key K i and points to a storage location for verifiable credentials for user agent authorization.

6. The method for mobile user identity authentication according to claim 5, characterized in that: The ground station authorizes the satellite through its distributed identity. The steps for the satellite to obtain proxy authorization include: Ground Station G s Select a proxy credential wG s L e , the proxy certificate wG s L e After signing, it is embedded into the proxy authorization; Ground Station G s Choose two random numbers a s and rG s L e , calculate the temporary public key RG s , session key KGsL e and private key σG s L e ; Among them, RG s =a s ·P, KG s L e =rG s L e ·P,σG s L e =σG s ·H(KG s L e, IDLe, wG s L e, RG s )+rG s L e ; σG s For ground station G s The private key of Ground Station G s The proxy authorization message MG is sent through the secure channel s L e Sent to satellite L e , proxy authorization message MG s L e Including ground station G s The public key KG s , session key KG s L e 、Private key σG s L e , proxy certificate wG s L e and the temporary public key RG s ; Satellite L e Received proxy authorization message MG s L e Then, using the ground station G s The public key in the DID document is used to verify the proxy authorization and the proxy authorization message MG s L e After successful verification, the satellite L e Save the proxy signing key pskG s L e =σG s L e and the agent authorized to {KG s L e ,σG s L e ,wG s L e }.

7. The method for mobile user identity authentication according to claim 6, characterized in that: The removable user identity authentication method also includes: After identity authentication is passed, the mobile user and the ground station derive the authentication key and encryption key required for the ground station to provide services to the mobile user from the shared key through a key derivation function.