Group construction and access authentication method for satellite network high-speed terminal group
By performing identity authentication and key negotiation in high-speed terminal groups, the challenges of high-speed terminal groups in terms of communication security and access authentication efficiency are solved, and stable, efficient and secure communication is achieved.
Patent Information
- Application Number
- CN202510203868.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-24
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2045-02-24
AI Technical Summary
High-speed terminal groups face challenges in communication security and access authentication efficiency, including the vulnerability of communication links, the complexity of key management, and the inefficiency of authentication caused by rapid movement.
By initializing in the ground control center, configuring the identity identity and shared keys, and mutual verification and grouping of shared keys are performed in the high-speed terminal group, secure communication between the high-speed terminal group, ground control center and access points is realized.
This method ensures the stability, efficiency and continuity of communication, effectively protects information content, resists illegal access and communication interference, reduces resource occupation, and improves system performance.
Smart Images

Figure CN120050610A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of satellite communication, and particularly relates to a method for constructing and accessing authentication of a high-speed terminal group in a satellite network. Background Art
[0002] In the current process of technological development, the High-Speed Terminal Group (HSTG) has gradually become a key application form in multiple fields. For example, in the field of intelligent transportation, the HSTG can be used for tasks such as traffic flow monitoring and intelligent navigation assistance; in environmental monitoring, it can achieve real-time environmental data collection and transmission over a large area. The information interaction among its members and communication cooperation with the outside are crucial for the smooth execution of tasks.
[0003] However, the HSTG faces a series of severe challenges. In terms of security, the security of its communication link is extremely vulnerable. Attackers can take advantage of the openness of the link and adopt various attack means. For example, through traffic analysis attacks, they attempt to obtain valuable information from the communication traffic patterns; use man-in-the-middle attacks to steal or tamper with data when the members of the HSTG communicate with the outside; and may also launch denial-of-service attacks to paralyze the communication of the HSTG. At the same time, during the dynamic operation of the HSTG, the joining and leaving of group members occur frequently, which poses extremely high requirements for group key management. Once the key management is not well done, it will not only affect the communication efficiency, but also greatly increase the risk of communication content leakage.
[0004] In terms of performance, the high-speed mobile characteristics of the HSTG pose great difficulties in the access authentication process. Traditional authentication methods often cannot adapt to its rapidly changing network environment, resulting in low authentication efficiency. Moreover, during the group construction and maintenance process, due to the lack of an efficient mechanism, problems such as communication delay and excessive signaling overhead are likely to occur. These problems seriously restrict the effectiveness of the HSTG in practical applications, and there is an urgent need for an innovative solution to ensure its safe and efficient operation.
[0005] X. Wang (X. Wang and S. Xu, “A secure access control scheme based on group for peer to peer network”, 2012 International Conference on Systems and Informatics (ICSAI 2012), pp. 1507 - 1511, 2012.) proposed a system that uses a group structure to manage a peer - to - peer network, which is divided into multiple groups. Each group contains a unique trusted group head GH responsible for group construction and organization. The group head can directly connect for communication and relay data. Members within a group can directly connect with the group head and other members, and members from different groups communicate through the group head. This structure facilitates management and security control, optimizes network communication and resource allocation, and enhances network scalability and security. However, this scheme cannot meet the needs of high - speed terminal groups to quickly switch and access access points during high - speed movement, resulting in a large overhead or even access failure during the access process. Summary of the Invention
[0006] In order to overcome the defects of the above - mentioned existing technologies, the purpose of the present invention is to provide a method for group construction and access authentication of high - speed terminal groups in a satellite network. This method first initializes the ground control center GCC and configures identity identifiers and shared keys for the high - speed terminal group HSTG and the access point AP respectively. j Then, mutual verification and group - shared keys are respectively carried out between the group leader L and group member i in the high - speed terminal group HSTG. Finally, the group leader L sends a verification request to the access point AP. j The access point AP j forwards the access verification request to the ground control center GCC. The ground control center GCC then sends a verification response to the access point AP. j The access point AP j forwards the verification response to the group leader L, and the group leader L verifies the response and broadcasts it to group member i, thereby realizing secure communication among the high - speed terminal group HSTG, the ground control center GCC, and the access point AP. j Through the group construction and access authentication mechanism, this method ensures the stability, efficiency, and continuity of communication. At the same time, it effectively protects the transmitted information content, resists the access and communication interference of illegal entities, effectively reduces resource occupancy, and improves the overall performance of the system.
[0007] To achieve the above - mentioned purpose, the technical solution adopted by the present invention is as follows:
[0008] A method for group construction and access authentication of high - speed terminal groups in a satellite network, comprising:
[0009] The Ground Control Center (GCC) initializes and configures identity identifiers and shared keys for the High-Speed Terminal Group (HSTG) and the Access Point (AP) respectively; the High-Speed Terminal Group (HSTG) includes multiple group members i and a group leader L; j Based on the identity identifiers and shared keys configured for the High-Speed Terminal Group (HSTG), the group leader L and the group members i perform mutual authentication and group shared key respectively to complete the construction of the High-Speed Terminal Group (HSTG);
[0010] Based on the identity identifiers and shared keys configured for the High-Speed Terminal Group (HSTG) and the construction of the High-Speed Terminal Group (HSTG), the group leader L sends a verification request to the Access Point (AP), and the Access Point (AP) forwards the access verification request to the Ground Control Center (GCC); the Ground Control Center (GCC) then sends a verification response to the Access Point (AP), and the Access Point (AP) forwards the verification response to the group leader L, and the group leader L verifies the response and broadcasts it to the group members i to achieve secure communication among the High-Speed Terminal Group (HSTG), the Ground Control Center (GCC), and the Access Point (AP).
[0011] Based on the identity identifiers and shared keys configured for the High-Speed Terminal Group (HSTG) and the Access Point (AP) and the construction of the High-Speed Terminal Group (HSTG), the group leader L sends a verification request to the Access Point (AP), and the Access Point (AP) forwards the access verification request to the Ground Control Center (GCC); the Ground Control Center (GCC) then sends a verification response to the Access Point (AP), and the Access Point (AP) forwards the verification response to the group leader L, and the group leader L verifies the response and broadcasts it to the group members i to achieve secure communication among the High-Speed Terminal Group (HSTG), the Ground Control Center (GCC), and the Access Point (AP). j Based on the identity identifiers and shared keys configured for the High-Speed Terminal Group (HSTG) and the Access Point (AP) and the construction of the High-Speed Terminal Group (HSTG), the group leader L sends a verification request to the Access Point (AP), and the Access Point (AP) forwards the access verification request to the Ground Control Center (GCC); the Ground Control Center (GCC) then sends a verification response to the Access Point (AP), and the Access Point (AP) forwards the verification response to the group leader L, and the group leader L verifies the response and broadcasts it to the group members i to achieve secure communication among the High-Speed Terminal Group (HSTG), the Ground Control Center (GCC), and the Access Point (AP). j Based on the identity identifiers and shared keys configured for the High-Speed Terminal Group (HSTG) and the Access Point (AP) and the construction of the High-Speed Terminal Group (HSTG), the group leader L sends a verification request to the Access Point (AP), and the Access Point (AP) forwards the access verification request to the Ground Control Center (GCC); the Ground Control Center (GCC) then sends a verification response to the Access Point (AP), and the Access Point (AP) forwards the verification response to the group leader L, and the group leader L verifies the response and broadcasts it to the group members i to achieve secure communication among the High-Speed Terminal Group (HSTG), the Ground Control Center (GCC), and the Access Point (AP). j Based on the identity identifiers and shared keys configured for the High-Speed Terminal Group (HSTG) and the Access Point (AP) and the construction of the High-Speed Terminal Group (HSTG), the group leader L sends a verification request to the Access Point (AP), and the Access Point (AP) forwards the access verification request to the Ground Control Center (GCC); the Ground Control Center (GCC) then sends a verification response to the Access Point (AP), and the Access Point (AP) forwards the verification response to the group leader L, and the group leader L verifies the response and broadcasts it to the group members i to achieve secure communication among the High-Speed Terminal Group (HSTG), the Ground Control Center (GCC), and the Access Point (AP). j Based on the identity identifiers and shared keys configured for the High-Speed Terminal Group (HSTG) and the Access Point (AP) and the construction of the High-Speed Terminal Group (HSTG), the group leader L sends a verification request to the Access Point (AP), and the Access Point (AP) forwards the access verification request to the Ground Control Center (GCC); the Ground Control Center (GCC) then sends a verification response to the Access Point (AP), and the Access Point (AP) forwards the verification response to the group leader L, and the group leader L verifies the response and broadcasts it to the group members i to achieve secure communication among the High-Speed Terminal Group (HSTG), the Ground Control Center (GCC), and the Access Point (AP). j Based on the identity identifiers and shared keys configured for the High-Speed Terminal Group (HSTG) and the Access Point (AP) and the construction of the High-Speed Terminal Group (HSTG), the group leader L sends a verification request to the Access Point (AP), and the Access Point (AP) forwards the access verification request to the Ground Control Center (GCC); the Ground Control Center (GCC) then sends a verification response to the Access Point (AP), and the Access Point (AP) forwards the verification response to the group leader L, and the group leader L verifies the response and broadcasts it to the group members i to achieve secure communication among the High-Speed Terminal Group (HSTG), the Ground Control Center (GCC), and the Access Point (AP). j Based on the identity identifiers and shared keys configured for the High-Speed Terminal Group (HSTG) and the Access Point (AP) and the construction of the High-Speed Terminal Group (HSTG), the group leader L sends a verification request to the Access Point (AP), and the Access Point (AP) forwards the access verification request to the Ground Control Center (GCC); the Ground Control Center (GCC) then sends a verification response to the Access Point (AP), and the Access Point (AP) forwards the verification response to the group leader L, and the group leader L verifies the response and broadcasts it to the group members i to achieve secure communication among the High-Speed Terminal Group (HSTG), the Ground Control Center (GCC), and the Access Point (AP).
[0012] Further, the initialization of the Ground Control Center (GCC) specifically includes:
[0013] The Ground Control Center (GCC) selects the first identity ID of the Ground Control Center (GCC), calls the Init() algorithm for initialization, and then discloses the system parameters and keeps the first private key x confidential; the system parameters disclosed by the Ground Control Center (GCC) include the cyclic group G, the order q, the generator p, the first public key X, the first hash function H, the second hash function H, the third hash function H, the fourth hash function H, the fifth hash function H. G The Ground Control Center (GCC) selects the first identity ID of the Ground Control Center (GCC), calls the Init() algorithm for initialization, and then discloses the system parameters and keeps the first private key x confidential; the system parameters disclosed by the Ground Control Center (GCC) include the cyclic group G, the order q, the generator p, the first public key X, the first hash function H, the second hash function H, the third hash function H, the fourth hash function H, the fifth hash function H. G The Ground Control Center (GCC) selects the first identity ID of the Ground Control Center (GCC), calls the Init() algorithm for initialization, and then discloses the system parameters and keeps the first private key x confidential; the system parameters disclosed by the Ground Control Center (GCC) include the cyclic group G, the order q, the generator p, the first public key X, the first hash function H, the second hash function H, the third hash function H, the fourth hash function H, the fifth hash function H. G The Ground Control Center (GCC) selects the first identity ID of the Ground Control Center (GCC), calls the Init() algorithm for initialization, and then discloses the system parameters and keeps the first private key x confidential; the system parameters disclosed by the Ground Control Center (GCC) include the cyclic group G, the order q, the generator p, the first public key X, the first hash function H, the second hash function H, the third hash function H, the fourth hash function H, the fifth hash function H. 1 The Ground Control Center (GCC) selects the first identity ID of the Ground Control Center (GCC), calls the Init() algorithm for initialization, and then discloses the system parameters and keeps the first private key x confidential; the system parameters disclosed by the Ground Control Center (GCC) include the cyclic group G, the order q, the generator p, the first public key X, the first hash function H, the second hash function H, the third hash function H, the fourth hash function H, the fifth hash function H. 2 The Ground Control Center (GCC) selects the first identity ID of the Ground Control Center (GCC), calls the Init() algorithm for initialization, and then discloses the system parameters and keeps the first private key x confidential; the system parameters disclosed by the Ground Control Center (GCC) include the cyclic group G, the order q, the generator p, the first public key X, the first hash function H, the second hash function H, the third hash function H, the fourth hash function H, the fifth hash function H. 3 The Ground Control Center (GCC) selects the first identity ID of the Ground Control Center (GCC), calls the Init() algorithm for initialization, and then discloses the system parameters and keeps the first private key x confidential; the system parameters disclosed by the Ground Control Center (GCC) include the cyclic group G, the order q, the generator p, the first public key X, the first hash function H, the second hash function H, the third hash function H, the fourth hash function H, the fifth hash function H. 4 The Ground Control Center (GCC) selects the first identity ID of the Ground Control Center (GCC), calls the Init() algorithm for initialization, and then discloses the system parameters and keeps the first private key x confidential; the system parameters disclosed by the Ground Control Center (GCC) include the cyclic group G, the order q, the generator p, the first public key X, the first hash function H, the second hash function H, the third hash function H, the fourth hash function H, the fifth hash function H. 5 The Ground Control Center (GCC) selects the first identity ID of the Ground Control Center (GCC), calls the Init() algorithm for initialization, and then discloses the system parameters and keeps the first private key x confidential; the system parameters disclosed by the Ground Control Center (GCC) include the cyclic group G, the order q, the generator p, the first public key X, the first hash function H, the second hash function H, the third hash function H, the fourth hash function H, the fifth hash function H.
[0014] Further, the Ground Control Center (GCC) discloses the system parameters and keeps the first private key x confidential specifically includes: G The Ground Control Center (GCC) selects the elliptic curve E, selects the cyclic group G of order q and the generator p;
[0015] The Ground Control Center (GCC) selects the first random number x
[0016] The Ground Control Center (GCC) selects the first random number x GAs the first private key; based on the first private key x G and the generator p, calculate the first public key X G ; the corresponding expression is:
[0017] X G = x G ·P
[0018] Based on the elliptic curve E and the cyclic group G, the ground control center GCC respectively selects the first hash function the second hash function the third hash function H 3 : G×G→{0,1} * ; the fourth hash function H 4 :{0,1} * →{0,1} * ; the fifth hash function H 5 : G→{0,1} * ; where, {0, 1} * represents a zero-one bit string of any length; represents the set of non-zero elements and the multiplicative group of order q.
[0019] Furthermore, the ground control center GCC respectively configures identity identifiers and shared keys for the high-speed terminal group HSTG and the access point AP j specifically including:
[0020] The ground control center GCC respectively selects the second identity ID j for the group member i, the access point AP i the third identity the fourth identity ID L ; where, i = 1,..., n, n is the number of group members; j = 1,..., m, m is the number of access points;
[0021] The group member i selects the second random number x i as the second private key; the access point AP j selects the third random number as the third private key; the group leader L selects the fourth random number x L as the fourth private key; the second random number the third random number the fourth random number where: represents the set of non-zero elements and the multiplicative group of order q;
[0022] Based on the second private key x i and the generator p of the ground control center GCC, calculate the second public key X of the group member i i; Based on the third private key The generator p of the Ground Control Center (GCC) calculates the third public key of the Access Point (AP) j Based on the fourth private key x L and the generator p of the Ground Control Center (GCC), calculates the fourth public key X of the group leader L L ; The corresponding calculation expressions are respectively
[0023] X i = x i ·P
[0024]
[0025] X L = x L ·P
[0026] After the group member i sends the second identity ID of the group member i i and the second public key X i to the Ground Control Center (GCC), the Ground Control Center (GCC) calls the algorithm Keygen(ID i , X i , X G ) to generate the fifth private key z i and the fifth public key Y i of the group member i; The Ground Control Center (GCC) calls the algorithm Keygen(ID i , X i , X G ) to generate the fifth private key z i and the fifth public key Y i of the group member i specifically includes:
[0027] The Ground Control Center (GCC) selects the fifth random number and calculates the fifth public key Y i = y i ·P; The Ground Control Center (GCC) calculates the fifth private key z i = y i + x G H 1 (ID i , Y i , X i , X G ); The Ground Control Center (GCC) returns the fifth public key Y i and the fifth private key z i ; where H 1 represents the first hash function; X G represents the first public key of the Ground Control Center (GCC);
[0028] The Access Point (AP)j The third identity of the access point AP j and the third public key are sent to the Ground Control Center (GCC). After receiving them, the GCC calls an algorithm to generate the sixth private key and the sixth public key j of the access point AP ; The GCC calls an algorithm to generate the sixth private key and the sixth public key j of the access point AP specifically including: The GCC selects a sixth random number
[0029] and calculates the sixth public key ; The GCC calculates the sixth private key The GCC returns the sixth public key and the sixth private key
[0030] The group owner L sends the fourth identity ID L and the fourth public key X L of the group owner L to the GCC. After receiving them, the GCC calls the algorithm Keygen(ID L ,X L ,X G ) to generate the seventh private key z L and the seventh public key Y L ; The GCC calls the algorithm Keygen(ID L ,X L ,X G ) to generate the seventh private key z L and the seventh public key Y L specifically including:
[0031] The GCC selects a seventh random number and calculates the seventh public key Y L =y L ·P; The GCC calculates the seventh private key z L =y L +x G H 1 L (ID L ,Y L ,X G ,X L ); The GCC returns the seventh public key Y L, the seventh private key z L ;
[0032] Based on the second public key X of group member i i , the fifth public key Y i Obtain the first complete public key pk of group member i i =(X i , Y i ); Based on the second private key x of group member i i , the fifth private key z i Obtain the first complete private key sk of group member i i =(x i , z i ); Based on the access point AP j 's third public key and the sixth public key Obtain the second complete public key of access point AP j Based on the third private key of access point AP j and the sixth private key Obtain the second complete private key of access point AP j Based on the fourth public key X of the group leader L L , the seventh public key Y L L Obtain the third complete public key pk of the group leader L L =(X L , Y L L ); Based on the fourth private key x of the group leader L L , the seventh private key z L Obtain the third complete private key sk of the group leader L L =(x L , z L ).
[0033] Furthermore, the mutual verification between the group leader L and group member i specifically includes:
[0034] The group leader L generates an eighth random number r 1 , and calls the algorithm Sign(M L , sk L , pk i , ID i , X G , r 1 ) to generate the first signature S L ; The group leader L calls the algorithm Sign(M L , sk L , pk i , ID i , X G , r 1 ) to generate the first signature SL Specifically, it includes:
[0035] The group leader L calculates v 1 = r 1 ·X G ; The group leader L calculates Then
[0036] Among them, pk i represents the first complete public key of group member i; ID i represents the second identity ID of group member i i ; X G represents the first public key of the ground control center GCC; P represents the generator of the ground control center GCC; respectively represent partial signatures in the first signature S L ; v 1 represents an intermediate quantity; f 1 represents an intermediate quantity; H 2 represents the second hash function; M L represents the first message, including the fourth identity ID of the group leader L L 、the third complete public key pk L =(X L , Y L ); x L represents the fourth private key of the group leader L, z L represents the seventh private key of the group leader L; represents a multiplicative group of non-zero elements with order q;
[0037] The group leader L broadcasts the first signature S L and the first message M L ;
[0038] After the group member i receives the first signature S L and the first message M L , it calls the algorithm VerifySign(S L , sk i , M L , ID i , X G ) to verify the identity of the group leader L; The group member i calls the algorithm VerifySign(S L , sk i , M L , ID i , X G ) to verify the identity of the group leader L specifically includes:
[0039] The group member i calculates The group member i parses the first message ML to obtain the third complete public key pk of the group owner L L =(X L , Y L ) and the fourth identity ID L ; group member i calculates h s =H 1 (ID L , X L , Y L , X G ); group member i checks whether they are equal to verify the signature; where: v 2 represents an intermediate quantity; h s represents an intermediate quantity;
[0040] If the verification is successful, group member i sends an access verification request to the group owner L and calls the algorithm SignCryption(Msg i , sk i , pk L , ID L , X G ) to output the second signature S i and the first ciphertext ci to the group owner L; group member i calls the algorithm SignCryption(Msg i , sk i , pk L , ID L , X G ) to output the second signature S i and the first ciphertext c i Specifically, it includes:
[0041] Group member i selects the ninth random number and calculates v 3 =r 2 ·X L ; group member i calculates Group member i calculates h r =H 1 (ID L , X L , Y L , X G ), v 4 =r 2 ·(Y L +X G h r ), Then the second signature
[0042] where Msg iIndicates the second information, including a pair of random numbers (p i , q i ) generated by group member i, the second identity ID of group member i i and the first complete public key pk i = (X i , Y i ); p i represents the abscissa of a randomly selected point; q i represents the ordinate of a randomly selected point; respectively represent partial signatures in the second signature S i ; v 3 represents an intermediate quantity; v 4 represents an intermediate quantity; f 2 represents an intermediate quantity; h r represents an intermediate quantity; X L represents the fourth public key of group leader L; Y L represents the seventh public key of group leader L; x i represents the second private key of group member i; z i represents the fifth private key of group member i;
[0043] If the verification fails, group member i will send a verification failure response message to group leader L;
[0044] After receiving the second signature S i and the first ciphertext c i , the group leader L calls the algorithm VerifySignCryption(S i , sk L , c i , ID L , X G ) to decrypt the first ciphertext c i to obtain the second information Msg i and verify whether the second signature S i is correct; the group leader L calls the algorithm VerifySignCryption(S i , sk L , c i , ID L , X G ) to decrypt the first ciphertext c i to obtain the second information Msg i and verify whether the second signature S i is correct, which specifically includes:
[0045] The group leader L calculates The group leader L parses the second information Msg of group member i i , and obtains the first complete public key pk of group member ii =(X i , Y i ), the second identity ID of group member i i , a pair of random numbers (p i , q i ) generated by group member i; the group owner L calculates h s = H 1 (ID i , X i , Y i , X G ), and verifies the signature by checking for equality;
[0046] where sk L represents the third complete private key of group owner L; v 5 represents an intermediate quantity; v 6 represents an intermediate quantity; f 3 represents an intermediate quantity; represents the exclusive OR operation;
[0047] If the second signature S i is correct, the group owner L will store a pair of random numbers (p i , q i ) generated by group member i; if the second signature S i is incorrect, the group owner L will send a verification failure response message to group member i;
[0048] Further, the specific process of generating the group - shared key between the group owner L and group member i includes:
[0049] The group owner L selects the tenth random number GK and constructs an interpolation polynomial f(x) of degree n to pass through n + 1 points, namely (0, GK) and (p i , q i ) (i = 1,..., n); where p i represents the abscissa of the randomly selected point; q i represents the ordinate of the randomly selected point;
[0050] The group owner L selects another n points on f(x) Generates a timestamp TS 1 and a group - shared key identifier GID, calculates the message authentication code and broadcasts the group - shared key identifier GID, the message authentication code MAC, the fourth identity ID of the group owner L L , the n points the timestamp TS 1 to group member i; where, represents the abscissa of the selected point; Represents the ordinate of the selected point;
[0051] The group member i receives the group shared key identifier GID, the message authentication code MAC, and the fourth identity ID of the group leader L L , n points Timestamp TS 1 After that, using the random numbers (p i , q i ) stored by itself to recover f(x), calculate the tenth random number GK = f(0), and verify the validity of the message authentication code MAC; if the message authentication code MAC is valid, the group member i stores the tenth random number GK as the group shared key of the group member i; if the message authentication code MAC is invalid, the group leader L will send a verification failure response message to the group member i.
[0052] Furthermore, in the process of mutual authentication and group shared key between the group leader L and the group member i to complete the construction of the high-speed terminal group HSTG, it also includes group member dynamic update, specifically:
[0053] When a new member joins, the new member first executes the mutual authentication phase between the group leader L and the group member i, and then executes the group shared key phase between the group leader L and the group member i;
[0054] When an old member leaves, the old member first sends a leave notice to the group leader L, and then executes the group shared key phase between the group leader L and the group member i.
[0055] Furthermore, the group leader L sends a verification request to the access point AP j Specifically includes:
[0056] The group leader L who accesses the ground control center GCC through the access point AP j generates the eleventh random number r 3 , and calls the algorithm to generate the third signature The group leader L calls the algorithm to generate the third signature Specifically includes:
[0057] The group leader L calculates v 7 = r 3 ·X G ; The group leader L calculates Then
[0058] Among them: X G represents the first public key of the ground control center GCC; P represents the generator of the ground control center GCC; represents the access point APj The third identity; v 7 Represents an intermediate quantity; f 4 Represents an intermediate quantity; m access Represents that the group owner L accesses the access point AP j The required third information; Represents the access point AP j The third private key; Represents the access point AP j The sixth private key; Respectively represent the third signature S' L The partial signature in;
[0059] Based on the fourth hash function H 4 The tenth random number GK, the shared key identifier GID, the first identity ID of the ground control center GCC G Calculate the first key GK between the group owner L and the ground control center GCC g-G ; Based on the fifth hash function H 5 The eleventh random number r 3 The first key GK between the group owner L and the ground control center GCC g-G Calculate the second ciphertext C; the corresponding calculation expressions are respectively:
[0060] GK g-G =H 4 (GK, GID, ID G )
[0061]
[0062] Wherein, Represents the exclusive OR operation; sk L Represents the third complete private key of the group owner L; Represents the access point AP j The second complete public key;
[0063] The group owner L sends the third signature to the access point AP j The third information m required for the group owner L to access the access point AP The group owner L accesses the access point AP j The third information m required access The second ciphertext C.
[0064] Furthermore, the access point AP j Forwarding the access verification request to the ground control center GCC specifically includes:
[0065] The access point AP j Receives the third signature The third information m required for the group owner L to access the access point AP j The third information m required access, after the second ciphertext C, call the algorithm Verify the third signature S' L ; The access point AP j Call the algorithm Verify the third signature S' L Specifically include:
[0066] Access point AP j Receive the third information m as an access request message access And calculate Access point AP j Calculate h s = H 1 (ID L , X L , Y L , X G ); The access point AP j Check Whether they are equal to verify the signature;
[0067] Among them: v 8 Represents an intermediate quantity; Respectively represent the partial signatures in the third signature S' L ; Represents the third private key of the access point AP j ; H 2 Represents the second hash function; Represents the third identity of the access point AP j ; h s Represents an intermediate quantity; H 1 Represents the first hash function; ID L Represents the fourth identity ID of the group owner L L ; X L Represents the fourth public key of the group owner L; Y L Represents the seventh public key of the group owner L; X G Represents the first public key of the ground control center GCC; P represents the generator of the ground control center GCC; Represents the second complete private key of the access point AP j ;
[0068] If the verification is successful, the access point AP j Will forward the second ciphertext C and the third signature S' L To the ground control center GCC; If the verification fails, the access point AP j Will send a verification failure response message to the ground control center GCC;
[0069] Furthermore, the ground control center GCC then sends a verification response to the access point AP j Send a verification response, access point APj Forward the verification response to group leader L, and group leader L verifies the response and broadcasts it to group member i to achieve secure communication among the high-speed terminal group HSTG, the ground control center GCC, and the access point AP j Specifically, it includes:
[0070] The ground control center GCC receives the second ciphertext C and the third signature S' L After that, decrypt the second ciphertext C, and based on the second ciphertext C, the fifth hash function H 5 、the third signature S' L and some signatures in The first private key x G Calculate the first key GK between group leader L and the ground control center GCC g-G ; Based on the fourth hash function H 4 、the first key GKg between group leader L and the ground control center GCC -G 、the shared key identifier GID, and the third identity of the access point AP j Calculate the second key GK between group leader L and the access point AP ; The corresponding calculation expressions are as follows: j The second key GK between group leader L and the access point AP g-j ; The corresponding calculation expressions are as follows:
[0071]
[0072] Among them, represents the exclusive OR operation; The ground control center GCC is based on the fourth hash function H 4 、the first key GK between group leader L and the ground control center GCC g-G 、the first identity ID of the ground control center GCC G 、the third signature S' L and some signatures in Calculate the response value RES; The corresponding calculation expression is as follows:
[0073]
[0074] The access point AP j Forwards the response value RES to group leader L, and group leader L verifies the response value RES and broadcasts the response value RES to group member i; The ground control center GCC conducts secure communication with the high-speed terminal group GSTG through the first key GK between group leader L and the ground control center GCC g-G ; The access point AP j Conducts secure communication with the high-speed terminal group HSTG through the second key GK between group leader L and the access point AP j ; The second key GK between group leader L and the access point AP g-j Conducts secure communication with the high-speed terminal group HSTG
[0075] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0076] 1. In terms of group construction and access authentication mechanism:
[0077] During the group construction process of the present invention, mutual verification between the group leader L and group member i and the sharing of group keys between the group leader L and group member i ensure the security of in-group communication; and it supports dynamic update of the group key when a member joins or exits, maintaining the forward and backward secrecy of the group key. For example, in an emergency rescue scenario, a cooperation group composed of multiple high-speed drones can efficiently cooperate to execute tasks, and the efficiency of group construction and key management guarantees communication security and the continuity of task execution.
[0078] During the process of the group accessing the network, the group leader L can represent group member i to securely access the ground network through a satellite and pre-negotiate keys with the ground network and access points AP on the trajectory route j effectively preventing the high latency or even failure problems that may occur in subsequent handover authentication and ensuring the stability and efficiency of communication.
[0079] 2. In terms of security guarantee:
[0080] In terms of mutual authentication: During the mutual verification stage between the group leader L and group member i and the stage of the group accessing the network, mechanisms such as private key signature and public key verification are used to ensure the mutual authentication between the group leader L and group member i, and between the group leader L and group member i / ground control center GCC, effectively resisting the access and communication interference of illegal entities.
[0081] In terms of key negotiation: Whether it is during the construction stage of the group shared key or the construction stage of the first key GK g-G and the second key GK g-j the security of the key is ensured through secure key generation and transmission methods, preventing attackers from obtaining key information.
[0082] In terms of unlinkability: During the group construction and network access process, the use of encrypted information and random numbers increases the uncertainty and diversity of information, effectively protecting the information content and preventing attackers from obtaining key data by analyzing different information.
[0083] In terms of forward / backward key separation: During the group construction process, when a new member joins or an old member exits, the group leader updates the group shared key, ensuring the dynamicity and independence of the group shared key and enhancing the security of key management.
[0084] In terms of resisting various protocol attacks: Through message authentication code MAC, timestamp TS 1, through various means such as signatures and signature encryption algorithms, effectively resists various known security threats such as replay attacks, impersonation attacks, man-in-the-middle attacks, and private key theft attacks.
[0085] 3. In terms of resource overhead:
[0086] In terms of computing overhead: Compared with the solution of X. Wang et al. in the background technology, in the process of group construction of the present invention, when the number of members is relatively large, the computing overhead is lower than that of X. Wang et al.'s solution.
[0087] In terms of communication overhead: In the process of group construction, the communication overhead of the present invention is significantly lower than that of X. Wang et al.'s solution, especially when constructing large-scale groups, with obvious advantages and higher communication efficiency.
[0088] In terms of signaling overhead: In the process of group construction and dynamic changes of group members, the signaling overhead of the present invention is lower than that of the solution proposed by X. Wang et al., and when the frequency of dynamic changes of group members increases, the signaling overhead has better stability and can effectively reduce network resource occupancy.
[0089] In summary, the present invention is superior to the prior art in terms of security, performance, adaptability, etc., and is more suitable for the requirements of group construction and access authentication of high-speed terminal groups in satellite network scenarios, providing a more reliable and efficient solution for high-speed terminal communication in the space-ground integrated network. Brief Description of the Drawings
[0090] Figure 1 It is a flowchart of the method for group construction and access authentication of high-speed terminal groups in the satellite network of the present invention.
[0091] Figure 2 It is a scenario diagram of the access architecture of the high-speed terminal group of the present invention.
[0092] Figure 3 It is an overview diagram of the access architecture of the high-speed terminal group of the present invention. Detailed Embodiments
[0093] The following further describes the present invention in detail with reference to the drawings and embodiments:
[0094] Since the wireless link between the high-speed terminal group HSTG and the access point AP j is highly exposed, an attacker may obtain key data by eavesdropping on the wireless link; in addition, communication between group members through an insecure air interface channel is vulnerable to attacks such as replay and impersonation. Therefore, in order to ensure the communication security of group members, based on the fact that a secure channel has been established between the access point AP j and the ground control center GCC, the present invention proposes a method for group construction and access authentication of high-speed terminal groups in a satellite network. See Figure 1 andFigure 2 , the method includes a system initialization process, a group construction process, and a group access network process, which are specifically as follows:
[0095] I. System initialization process: The ground control center GCC is initialized, and identity identifiers and shared keys are respectively configured for the high-speed terminal group HSTG and the access point AP j ; the high-speed terminal group HSTG includes multiple group members i and a group leader L; the high-speed terminal group HSTG includes multiple terminals, where one terminal is selected as the group leader L, and the other terminals are group members i; through the collaborative work of multiple terminals, the working efficiency is much higher than that when a single terminal works alone.
[0096] The specific initialization of the ground control center GCC includes:
[0097] The ground control center GCC selects the first identity ID of the ground control center GCC G , calls the Init() algorithm for initialization, and then publishes the system parameters and keeps the first private key x G secret; the system parameters published by the ground control center GCC include the cyclic group G, the order q, the generator p, the first public key X G , the first hash function H 1 , the second hash function H 2 , the third hash function H 3 , the fourth hash function H 4 , the fifth hash function H 5 .
[0098] Furthermore, the ground control center GCC publishes the system parameters and keeps the first private key x G secret, which specifically includes:
[0099] The ground control center GCC selects the elliptic curve E, selects the cyclic group G of order q and the generator p;
[0100] The ground control center GCC selects the first random number x G as the first private key; based on the first private key x G , the generator p calculates the first public key X G ; the corresponding expression is:
[0101] X G =x G ·P
[0102] Based on the elliptic curve E and the cyclic group G, the ground control center GCC respectively selects the first hash function the second hash function the third hash function H 3: G×G → {0, 1} * ; The fourth hash function H 4 : {0, 1} * → {0, 1} * ; The fifth hash function H 5 : G → {0, 1} * ; Wherein, {0, 1} * represents a binary string of arbitrary length; represents the set of non - zero elements and the multiplicative group of order q.
[0103] Further, the Ground Control Center GCC configures identity identifiers and shared keys for the High - Speed Terminal Group HSTG and the Access Point AP respectively, specifically including: j The Ground Control Center GCC selects second identity IDs, third identities, and fourth identity IDs for group member i, Access Point AP, and group leader L respectively;
[0104] The Ground Control Center GCC selects second identity IDs, third identities, and fourth identity IDs for group member i, Access Point AP, and group leader L respectively; j The Ground Control Center GCC selects second identity IDs, third identities, and fourth identity IDs for group member i, Access Point AP, and group leader L respectively; i Third identity Fourth identity ID L ; Where i = 1,..., n, n is the number of group members; j = 1,..., m, m is the number of access points;
[0105] Group member i selects a second random number x i as the second private key; The Access Point AP j selects a third random number as the third private key; The group leader L selects a fourth random number x L as the fourth private key; The second random number Third random number Fourth random number Where: is the set of non - zero elements and the multiplicative group of order q;
[0106] In this embodiment, the second random number and the second private key are essentially the same; the third random number and the third private key are essentially the same; the fourth random number and the fourth private key are essentially the same; the use of random numbers increases the uncertainty and diversity of information, effectively protecting the information content and preventing attackers from obtaining key data by analyzing different information;
[0107] Based on the second private key x i and the generator p of the Ground Control Center GCC, calculate the second public key X of group member i i ; Based on the third private key and the generator p of the Ground Control Center GCC, calculate the third public key of the Access Point AP j ; Based on the fourth private key x and the generator p of the Ground Control Center GCC, calculate the third public key of the Access Point AP L, the generator p of the Ground Control Center GCC calculates the fourth public key X of the group master L L ; The corresponding calculation expressions are respectively:
[0108] X i = x i ·P
[0109]
[0110] X L = x L ·P
[0111] After the group member i sends the second identity ID of the group member i i , the second public key X i to the Ground Control Center GCC, the Ground Control Center GCC calls the algorithm Keygen(ID i , X i , X G ) to generate the fifth private key z of the group member i i and the fifth public key Y i ; The Keygen algorithm is mainly used to generate public and private key pairs. By inputting the second identity ID of the group member i i , the second public key X of the group member i i , the first public key X of the Ground Control Center GCC G , the fifth private key z of the group member i can be calculated i and the fifth public key Y i ; The Ground Control Center GCC calls the algorithm Keygen(ID i , X i , X G ) to generate the fifth private key z of the group member i i and the fifth public key Y i Specifically includes:
[0112] The Ground Control Center GCC selects the fifth random number and calculates the fifth public key Y i = y i ·P; The Ground Control Center GCC calculates the fifth private key z i = y i + x G H 1 (ID i , Y i , X i , X G ); The Ground Control Center GCC returns the fifth public key Y i , the fifth private key z i ; Among them, H 1 represents the first hash function; X GRepresents the first public key of the Ground Control Center (GCC);
[0113] The access point AP j Sends the third identity of the access point AP j To the Ground Control Center (GCC). After receiving it, the Ground Control Center (GCC) calls an algorithm To generate the sixth private key And the sixth public key of the access point AP After sending the third public key of the access point AP to the Ground Control Center (GCC), the Ground Control Center (GCC) calls an algorithm j To generate the sixth private key And the sixth public key Specifically, the Ground Control Center (GCC) Calls an algorithm to generate the sixth private key j And the sixth public key of the access point AP And the sixth public key Specifically includes:
[0114] The Ground Control Center (GCC) selects a sixth random number And calculates the sixth public key The Ground Control Center (GCC) calculates the sixth private key The Ground Control Center (GCC) returns the sixth public key The sixth private key
[0115] After the group owner L sends the fourth identity ID of the group owner L L , the fourth public key X L To the Ground Control Center (GCC), the Ground Control Center (GCC) calls the algorithm Keygen(ID L ,X L ,X G ) to generate the seventh private key z L And the seventh public key Y L ; The Ground Control Center (GCC) calls the algorithm Keygen(ID L ,X L ,X G ) to generate the seventh private key z L And the seventh public key Y L Specifically includes:
[0116] The Ground Control Center (GCC) selects the seventh random number And calculates the seventh public key Y L =y L ·P; The Ground Control Center (GCC) calculates the seventh private key z L =y L +x G H 1 (ID L ,Y L ,X L,X G ); the ground control center GCC returns the seventh public key Y L , the seventh private key z L ;
[0117] In the above embodiment, the Keygen algorithm is used to generate a public key and a private key pair. Different random numbers selected by the ground control center GCC are used as the private key, and the security of the distributed key is well guaranteed by using the key exchange technology;
[0118] Based on the second public key X i , the fifth public key Y i of group member i, the first complete public key pk i of group member i is obtained as pk i = (X i ); based on the second private key x i , the fifth private key z i of group member i, the first complete private key sk i of group member i is obtained as sk i = (x i ); based on the third public key j of the access point AP and the sixth public key of the access point AP, the second complete public key j of the access point AP is obtained. Based on the third private key j of the access point AP and the sixth private key of the access point AP, the second complete private key j of the access point AP is obtained. Based on the fourth public key X L , the seventh public key Y L of the group leader L, the third complete public key pk L of the group leader L is obtained as pk L = (X L ); based on the fourth private key x L , the seventh private key z L of the group leader L, the third complete private key sk L of the group leader L is obtained as sk L = (x L );
[0119] In this embodiment, the complete public keys of group member i, the access point AP j , and the group leader L are all composed of two parts. Even if an attacker can obtain part of the private key of the device from the ground control center GCC, the attacker cannot infer the other part of the private key held by group member i or the group leader L itself, which greatly improves the security of communication.
[0120] II. Group construction process: Based on the identity identifier and shared key configured for the High-Speed Terminal Group (HSTG), mutual authentication and group shared key are performed between the group owner L and group member i to complete the construction of the High-Speed Terminal Group (HSTG).
[0121] See Figure 3 , in this embodiment, a group construction protocol is proposed, which can achieve mutual authentication between group member i and group owner L, as well as secure group key negotiation to ensure communication security within the group.
[0122] In this implementation, all group members i need to complete mutual authentication with group owner L. The specific process is as follows:
[0123] Furthermore, the mutual authentication between the group owner L and group member i specifically includes:
[0124] The group owner L generates the eighth random number and calls the algorithm Sign(M L , sk L , pk i , ID i , X G , r 1 ) to generate the first signature S L ; The group owner L calls the algorithm Sign(M L , sk L , pk i , ID i , X G , r 1 ) to generate the first signature S L Specifically, it includes:
[0125] The group owner L calculates v 1 = r 1 · X G ; The group owner L calculates Then
[0126] where, pk i represents the first complete public key of group member i; ID i represents the second identity ID of group member i i ; X G represents the first public key of the Ground Control Center (GCC); P represents the generator of the Ground Control Center (GCC); respectively represent partial signatures in the first signature S L ; v 1 represents an intermediate quantity; f 1 represents an intermediate quantity; H 2 represents the second hash function; M LRepresents the first piece of information, including the fourth identity ID of the group owner L L , the third complete public key pk L =(X L ,Y L ); x L represents the fourth private key of the group owner L, z L represents the seventh private key of the group owner L; represents a multiplicative group of non-zero elements with order q;
[0127] In this embodiment, the Sign algorithm is called to generate two partial signatures respectively The purpose is to nest the first half of the signature into the second half of the signature The subsequent SignCryption algorithm also adopts this method, greatly improving the security of the key;
[0128] The group owner L broadcasts the first signature S L and the first piece of information M L ;
[0129] The group member i receives the first signature S L and the first piece of information M L After that, the algorithm VerofySign(S L ,sk i ,M L ,ID i ,X G ) is called to verify the identity of the group owner L; The group member i calls the algorithm VerifySign(S L ,sk i ,M L ,ID i ,X G ) to verify the identity of the group owner L specifically includes:
[0130] The group member i calculates The group member i parses the first piece of information M L to obtain the third complete public key pk of the group owner L L =(X L ,Y L ) and the fourth identity ID L ; The group member i calculates h s =H 1 (ID L ,X L ,Y L ,X G ); The group member i checks whether they are equal to verify the signature; where: v 2 represents an intermediate quantity; hs Represents an intermediate quantity;
[0131] If the verification is successful, group member i sends an access verification request to the group owner L and calls the algorithm SignCryption(Msg i , sk i , pk L , ID L , X G ) to output the second signature S i and the first ciphertext c i ; The group member i calls the algorithm SignCryption(Msg i , sk i , pk L , ID L , X G ) to output the second signature S i and the first ciphertext c i Specifically, it includes:
[0132] Group member i selects the ninth random number and calculates v 3 = r 2 · X L ; Group member i calculates Group member i calculates h r = H 1 (ID L , X L , Y L , X G ), v 4 = r 2 ·(Y L + X G h r ), Then the second signature
[0133] where Msg i represents the second piece of information, including a pair of random numbers (p i , q i ) generated by group member i, the second identity ID of group member i i and the first complete public key pk i = (X i , Y i ); p i represents the abscissa of the randomly selected point; q i represents the ordinate of the randomly selected point; respectively represent the partial signatures in the second signature S i ; v 3Represents an intermediate quantity; v 4 Represents an intermediate quantity; f 2 Represents an intermediate quantity; h r Represents an intermediate quantity; X L Represents the fourth public key of the group leader L; Y L Represents the seventh public key of the group leader L; x i Represents the second private key of group member i; z i Represents the fifth private key of group member i;
[0134] If the verification fails, group member i will send a verification failure response message to the group leader L;
[0135] The group leader L receives the second signature S i and the first ciphertext c i After that, call the algorithm VerifySignCryption(S i , sk L , c i , ID L , X G ) to decrypt the first ciphertext c i to obtain the second message Msg i and verify whether the second signature S i is correct; The group leader L calls the algorithm VerifySignCryption(S i , sk L , c i , ID L , X G ) to decrypt the first ciphertext c i to obtain the second message Msg i and verify whether the second signature S i is correct specifically including:
[0136] The group leader L calculates The group leader L parses the second message Msg of group member i i , and obtains the first complete public key pk of group member i i =(X i , Y i ), the second identity ID of group member i i , a pair of random numbers (p i , q i ) generated by group member i; The group leader L calculates h s =H 1 (ID i , X i , Y i , X G ), and verifies the signature by checking whether they are equal;
[0137] Among them, sk L represents the third complete private key of the group owner L; v 5 represents an intermediate quantity; v 6 represents an intermediate quantity; f 3 represents an intermediate quantity; represents the exclusive OR operation;
[0138] If the second signature S i is correct, the group owner L will store a pair of random numbers (p i , q i ) generated by the group member i; if the second signature S i is incorrect, the group owner L will send a verification failure response message to the group member i;
[0139] After the mutual verification between the group owner L and the group member i is completed, the group owner L generates a group shared key and distributes it to all group members i. Assume that the group owner L currently has access verification information of m group members, and the corresponding random number pairs are (p i , q i )(i = 1,..., n), then this process is divided into the following:
[0140] Furthermore, the specific process of the group shared key between the group owner L and the group member i includes:
[0141] The group owner L selects the tenth random number GK and constructs an interpolation polynomial f(x) of order n to pass through n + 1 points, namely (0, GK) and (p i , q i )(i = 1,..., n); where, p i represents the abscissa of the randomly selected point; q i represents the ordinate of the randomly selected point;
[0142] The group owner L selects another n points on f(x) generates a timestamp TS 1 and a group shared key identifier GID, calculates the message authentication code and broadcasts the group shared key identifier GID, the message authentication code MAC, the fourth identity ID of the group owner L L , n points the timestamp TS 1 to the group member i; where, represents the abscissa of the selected point; represents the ordinate of the selected point;
[0143] The group member i receives the group shared key identifier GID, the message authentication code MAC, the fourth identity ID of the group owner L L , n points Time Stamp TS 1 , after that, use the random numbers (p i , q i ) stored by itself to recover f(x), calculate the tenth random number GK = f(0), and verify the validity of the message authentication code MAC; if the message authentication code MAC is valid, group member i stores the tenth random number GK as the group shared key of group member i; if the message authentication code MAC is invalid, the group leader L will send a verification failure response message to group member i.
[0144] During the group shared key phase, by setting means such as the message authentication code MAC, time stamp TS 1 , signature, and signature encryption algorithm, etc., effectively resist various known security threats such as replay attacks, impersonation attacks, man-in-the-middle attacks, and private key theft attacks.
[0145] Furthermore, during the mutual verification and group shared key between the group leader L and group member i to complete the construction of the high-speed terminal group HSTG, it also includes group member dynamic update, specifically:
[0146] When a new member joins, the new member first executes the mutual verification phase between the group leader L and group member i, and then executes the group shared key phase between the group leader L and group member i;
[0147] When an old member leaves, the old member first sends a leave notice to the group leader L, and then executes the group shared key phase between the group leader L and group member i.
[0148] This embodiment supports corresponding dynamic update of the group key when a new member joins or an old member exits, so as to maintain the forward / backward secrecy of the group key.
[0149] III. Group access network process: Based on the identity identifier and shared key configured by the high-speed terminal group HSTG and access point AP j and the construction of the high-speed terminal group HSTG, the group leader L sends a verification request to the access point AP j , and the access point AP j forwards the access verification request to the ground control center GCC; the ground control center GCC then sends a verification response to the access point AP j , and the access point AP j forwards the verification response to the group leader L, and the group leader L verifies the response and broadcasts it to group member i to achieve secure communication between the high-speed terminal group HSTG, ground control center GCC, and access point AP j .
[0150] See Figure 3 , in this embodiment, the group leader L represents the group members to access the ground network and communicates with the access point APj / The Ground Control Center GCC completes mutual verification and shares the secret key with all access points AP on the HSTG trajectory route in advance j ; The AP j will broadcast relevant information, including the identity identifier and the public key
[0151] Furthermore, the group leader L sends a verification request to the access point AP j specifically including:
[0152] The group leader L that accesses the Ground Control Center GCC through the access point AP j generates the eleventh random number r 3 , and calls the algorithm to generate the third signature The group leader L calls the algorithm to generate the third signature specifically including:
[0153] The group leader L calculates v 7 = r 3 ·X G ; The group leader L calculates Then
[0154] where: X G represents the first public key of the Ground Control Center GCC; P represents the generator of the Ground Control Center GCC; represents the third identity of the access point AP j ; v 7 represents an intermediate quantity; f 4 represents an intermediate quantity; m access represents the third information required for the group leader L to access the access point AP j ; represents the third private key of the access point AP j ; represents the sixth private key of the access point AP j ; respectively represent the partial signatures in the third signature S' L ;
[0155] Based on the fourth hash function H 4 , the tenth random number GK, the shared key identifier GID, and the first identity ID of the Ground Control Center GCC G calculate the first key GK between the group leader L and the Ground Control Center GCC g-G ; Based on the fifth hash function H 5 , the eleventh random number r3 The first secret key GK between the group owner L and the ground control center GCC g-G Calculate the second ciphertext C; the corresponding calculation expressions are respectively:
[0156] GK g-G = H 4 (GK, GID, ID G )
[0157]
[0158] Among them, represents the exclusive OR operation; sk L represents the third complete private key of the group owner L; represents the access point AP j 's second complete public key;
[0159] The group owner L sends the third signature j to the access point AP The third information m required for the group owner L to access the access point AP j and the second ciphertext C. access 、Second ciphertext C.
[0160] Furthermore, the access point AP j forwarding the access verification request to the ground control center GCC specifically includes:
[0161] The access point AP j receives the third signature The third information m required for the group owner L to access the access point AP j and the second ciphertext C, and then invokes the algorithm access to verify the third signature S'; the access point AP invokes the algorithm L to verify the third signature S' j invokes the algorithm to verify the third signature S' L specifically includes:
[0162] The access point AP j receives the third information m as the access request message access and calculates The access point AP j calculates h s = H 1 (ID L , X L , Y L , Y L ); the access point AP j checks whether they are equal to verify the signature;
[0163] Where: v 8 represents an intermediate quantity; respectively represent partial signatures in the third signature S'; L represents the third private key of the access point AP; H j 2 represents the second hash function; represents the third identity of the access point AP; h j s represents an intermediate quantity; H 1 represents the first hash function; ID L represents the fourth identity ID of the group leader L; L ; X L represents the fourth public key of the group leader L; Y L represents the seventh public key of the group leader L; X G represents the first public key of the ground control center GCC; P represents the generator of the ground control center GCC; represents the second complete private key of the access point AP; j
[0164] If the verification is successful, the access point AP j will forward the second ciphertext C and the third signature S' L to the ground control center GCC; if the verification fails, the access point AP j will send a verification failure response message to the ground control center GCC; where, represents the second complete private key of the access point AP; j represents the third identity of the access point AP; X j G represents the first public key of the ground control center GCC.
[0165] Furthermore, the ground control center GCC then sends a verification response to the access point AP j The access point AP j forwards the verification response to the group leader L, and the group leader L verifies the response and broadcasts it to the group member i to achieve secure communication among the high-speed terminal group HSTG, the ground control center GCC, and the access point AP j Specifically, it includes:
[0166] After the ground control center GCC receives the second ciphertext C and the third signature S' L it decrypts the second ciphertext C and calculates the first key GK between the group leader L and the ground control center GCC based on the second ciphertext C, the fifth hash function H 5 the third signature S' L partial signatures in the first private key x G g-G ; based on the fourth hash function H 4 , the first key GK between the group leader L and the ground control center GCC g-G , the shared key identifier GID, the access point AP j 's third identity Calculate the second key GK between the group leader L and the access point AP j ; The corresponding calculation expressions are as follows: g-j ; The corresponding calculation expressions are as follows:
[0167]
[0168] Wherein, represents the exclusive OR operation; represents the fourth signature;
[0169] The ground control center GCC is based on the fourth hash function H 4 , the first key GK between the group leader L and the ground control center GCC g-G , the first identity ID of the ground control center GCC G , the third signature S' L in the partial signature Calculate the response value RES; the corresponding calculation expression is as follows:
[0170]
[0171] The access point AP j forwards the response value RES to the group leader L, and the group leader L verifies the response value RES and broadcasts the response value RES to the group member i; the ground control center GCC communicates securely with the high-speed terminal group HSTG through the first key GK between the group leader L and the ground control center GCC g-G ; the access point AP j communicates securely with the high-speed terminal group HSTG through the second key GK between the group leader L and the access point AP j ; g-j communicates securely with the high-speed terminal group HSTG through the second key GK
[0172] In this embodiment, after the ground control center GCC completes the secure access to the high-speed terminal group HSTG, based on the trajectory prediction mechanism, the ground control center GCC can preset in advance the second key GK j of each access point AP g-j on the trajectory route of the high-speed terminal group HSTG, so that when the high-speed terminal group HSTG enters the range of the target access point AP j , it can directly use the second key GK g-j to communicate securely with it, thus avoiding problems such as high overhead, high latency, and even handover failure.
[0173] The application effect of the present invention will be further described in detail below in combination with security analysis.
[0174] I. Mutual authentication
[0175] 1. Mutual verification stage between group owner L and group member i: On the one hand, the group owner L uses the third complete private key sk of the group owner L L to generate the first signature S L . Due to the non-forgeability of the private key, only the group owner L can calculate the correct signature, and the group member i can use the third complete public key pk of the group owner L L and the first public key X of the ground control center GCC G to verify the correctness of the first signature S L , and then authenticate the group owner L. On the other hand, after each group member i successfully authenticates the group owner L, the group member i will use the first complete private key sk of the group member i i to generate the second signature S i , and use the third complete public key pk of the group owner L L to encrypt the second message Msg i , so that only the legitimate group owner L can decrypt the first ciphertext c i to obtain the second message Msg i . Therefore, only the legitimate group owner L can be successfully verified by the group member i.
[0176] 2. Group access network stage: The group owner L uses the third complete private key sk of the group owner L L to generate the third signature S' L and send it to the access point AP j . Due to the non-forgeability of the private key, only the group owner L can calculate the correct third signature S' L , and the access point AP j can use the third complete public key pk of the group owner L L and the first public key X of the ground control center GCC G to verify the correctness of the third signature S' L , and then authenticate the identity of the group owner L. In addition, the group owner L uses the third complete public key pk of the ground control center GCC L and the eleventh random number r 3 to encrypt the first key GK between the group owner L and the ground control center GCC g-G , so that only the ground control center GCC can use its non-forgeable first private key x G to decrypt the second ciphertext C to obtain the first key GK between the group owner L and the ground control center GCC g-G , and generate the response value RES. The group owner L can verify the access point AP by checking the response value RES j / The identity of the Ground Control Center GCC. Therefore, the group leader L and the access point AP j / can establish mutual authentication between the Ground Control Center GCC.
[0177] II. Key negotiation
[0178] 1. Group shared key construction phase: The method of constructing an interpolation polynomial is used to construct a packet shared key. The random number pair used to construct the packet shared key is sent to the group leader L in the first ciphertext c i because only the group leader L can decrypt the first ciphertext c i to obtain the second message Msg i , and then obtain a pair of random numbers (p i , q i ) in it to construct the packet shared key. Therefore, even if the attacker intercepts the first ciphertext c i , the packet shared key cannot be obtained.
[0179] 2. Construction phase of the first key GK g-G and the second key GK g-j : The group leader L calculates the first key GK g-G , encrypts it as the second ciphertext C, and then sends the second ciphertext C to the access point AP j . After verifying the identity of the group leader L, the access point AP j forwards the second ciphertext C to the Ground Control Center GCC. Therefore, only the High-Speed Terminal Group HSTG and the Ground Control Center GCC can obtain the first key GK g-G . Therefore, the second key GK j between the group leader L and the access point AP g-j is also secure.
[0180] III. Unlinkability
[0181] During the group construction process and the group access network process, key negotiation is carried out and information is encrypted. The encrypted information can only be decrypted by the recipient with the correct key. In addition, random numbers (such as the sixth random number r 2 ) are used during the group construction process and the group access network process. The introduction of random numbers increases the uncertainty and diversity of information, making it difficult for attackers to link different information through analysis, thereby protecting the information content and improving unlinkability.
[0182] IV. Forward Key Separation FKS / Backward Key Separation BKS
[0183] During the group construction process, whether new members join or old members leave, the group owner L will execute the process of constructing the group shared key to update the group shared keys of all group members. This ensures the dynamics and independence of the group shared key. At the same time, due to the privacy and randomness of the pair of random numbers (p i , q i ) used in the group shared key construction phase, it is impractical to derive the old group shared key from the new group shared key and vice versa, thus achieving forward key separation FKS / backward key separation BKS and enhancing security.
[0184] V. Defense against replay attacks
[0185] During the group key construction phase, a message authentication code MAC and a timestamp TS 1 are applied. When a group member receives information from the group owner L, they can determine whether the information has been replayed by checking the message authentication code MAC and the timestamp TS 1 . If the message authentication code MAC is incorrect or the difference between the timestamp TS 1 and the current time exceeds the threshold, it can be considered that the information has suffered a replay attack and is rejected. The process of the group accessing the network also involves the use of the message authentication code MAC and the timestamp TS 1 . This can ensure the freshness of the information and prevent replay attacks.
[0186] VI. Defense against impersonation attacks
[0187] In the entire solution, signature and signature encryption algorithms are used to ensure the integrity and immutability of information, which are applicable to the interactions between members of the high-speed terminal group HSTG and also applicable to the interactions between the group owner L and the access point AP j . It is difficult for an attacker to forge a signature without the correct private key, so it is difficult to impersonate a legitimate entity for communication.
[0188] VII. Defense against man-in-the-middle MitM attacks
[0189] During the group construction process and the process of the group accessing the network, signature algorithms are used to ensure that the information has not been tampered with or forged, and at the same time encryption is used to protect the confidentiality of important information. This realizes the feature that a man-in-the-middle cannot access, tamper with, or forge information, thus defending against MitM attacks.
[0190] VIII. Defense against private key theft attacks
[0191] During the system initialization process, even if an attacker can obtain part of the private key of the device from the ground control center GCC (such as the second private key x of group member i i , the fourth private key x of the group owner L L), due to the existence of the Elliptic Curve Discrete Logarithm Problem (ECDLP), an attacker cannot infer the other part of the private key held by group member i or the group owner L itself (such as the fifth private key z of group member i i , the seventh private key z of the group owner L L ). Therefore, it can successfully resist private key theft attacks.
[0192] The above embodiments are only a detailed elaboration of the present invention, but the present invention is not limited to the above embodiments. Any modifications, substitutions, and changes made within the spirit and scope of the claims of the present invention are within the protection scope of the present invention.
Claims
1. A method for group construction and access authentication of a satellite network high-speed terminal group, characterized in that: include: The ground control center GCC is initialized and the high-speed terminal group HSTG and access point AP are j Configure an identity and a shared key; the high-speed terminal group HSTG includes multiple group members i and a group owner L; Based on the identity and shared key configured by the high-speed terminal group HSTG, the group owner L and the group member i respectively perform mutual authentication and group shared key to complete the construction of the high-speed terminal group HSTG; Based on the high-speed terminal group HSTG and access point AP j The configured identity and shared key and the construction of the high-speed terminal group HSTG, the group owner L to the access point AP j Send authentication request to access point AP j Forward the access authentication request to the ground control center GCC; the ground control center GCC then sends the access point AP j Send authentication response, access point AP j The verification response is forwarded to the group owner L, who verifies the response and broadcasts it to group member i to achieve high-speed terminal group HSTG, ground control center GCC, access point AP j Secure communication between.
2. The method for group building and access authentication of a satellite network high-speed terminal group according to claim 1, characterized in that: The ground control center GCC performs initialization specifically including: The ground control center GCC selects the first identity ID of the ground control center GCC G , call the Init() algorithm to initialize, then disclose the system parameters and the first private key x G Confidentiality; the system parameters disclosed by the ground control center GCC include cyclic group G, order q, generator p, first public key X G , a first hash function H1, a second hash function H2, a third hash function H3, a fourth hash function H4, and a fifth hash function H5.
3. The method for group building and access authentication of a satellite network high-speed terminal group according to claim 2, characterized in that: The ground control center GCC discloses system parameters and uses the first private key x G Confidentiality specifically includes: The ground control center GCC selects an elliptic curve E, a cyclic group G of order q and a generator p; The ground control center GCC selects a first random number x G As the first private key; based on the first private key x G , generator p calculates the first public key X G ; The corresponding expression is: X G =x G ·P Based on the elliptic curve E and the cyclic group G, the ground control center GCC selects the first hash function Second hash function The third hash function H3:G×G→{0,1} * ; Fourth hash function H4: {0,1} * →{0,1} * ; Fifth hash function H5: H→{0,1} * ; where {0, 1} * Represents a string of zeros and one bits of any length; represents the multiplicative group of order q that is the set of nonzero elements.
4. A method for group building and access authentication of a satellite network high-speed terminal group according to claim 1 or 3, characterized in that: The ground control center GCC is composed of high-speed terminal groups HSTG and access points AP j Configuring the identity and shared key includes: The ground control center GCC is composed of group member i, access point AP j , Group owner L selects the second identity ID i , Third identity Fourth identity ID L ; Where i = 1, ..., n, n is the number of group members; j = 1, ..., m, m is the number of access points; The group member i selects a second random number x i As the second private key; the access point AP j Select the third random number As the third private key; the group owner L selects a fourth random number x L As the fourth private key; the second random number The third random number The fourth random number in: represents the multiplicative group of order q that represents the set of non-zero elements; Based on the second private key x i , the generator p of the ground control center GCC calculates the second public key X of group member i i ; Based on the third private key The generator p of the ground control center GCC calculates the access point AP j The third public key Based on the fourth private key x L , the generator p of the ground control center GCC calculates the fourth public key X of the group leader L L ; The corresponding calculation expressions are: X i =x i ·P X L =x L ·P The group member i sends the second identity ID of the group member i i , the second public key X i After being sent to the ground control center GCC, the ground control center GCC calls the algorithm Keygen (ID i ,X i ,X G ) Generate the fifth private key z of group member i i and the fifth public key Y i ; The ground control center GCC calls the algorithm Keygen (ID i ,X i ,X G ) Generate the fifth private key z of group member i i and the fifth public key Y i Specifically include: The ground control center GCC selects a fifth random number And calculate the fifth public key Y i =y i ·P; the ground control center GCC calculates the fifth private key z i =y i +x G H1(ID i ,Y i ,X i ,X G ); The ground control center GCC returns the fifth public key Y i 、Fifth private key z i ; Wherein, H1 represents the first hash function; X G Represents the first public key of the ground control center GCC; The access point AP j Access point AP j The third identity The third public key After sending it to the ground control center GCC, the ground control center GCC calls the algorithm Generate access point AP j The sixth private key and the sixth public key The ground control center GCC calls the algorithm Generate access point AP j The sixth private key and the sixth public key Specifically include: The ground control center GCC selects a sixth random number And calculate the sixth public key The ground control center GCC calculates the sixth private key The ground control center GCC returns the sixth public key Sixth private key The group owner L sends the fourth identity ID of the group owner L L 、The fourth public key X L After being sent to the ground control center GCC, the ground control center GCC calls the algorithm Keygen (ID L ,X L ,X G ) Generate the seventh private key z of group owner L L and the seventh public key Y L ; The ground control center GCC calls the algorithm Keygen (ID L ,X L ,X G ) Generate the seventh private key z of group owner L L and the seventh public key Y L Specifically include: The ground control center GCC selects the seventh random number And calculate the seventh public key Y L =y L ·P; the ground control center GCC calculates the seventh private key z L =y L +x G H1(ID L ,Y L ,X L ,X G ); The ground control center GCC returns the seventh public key Y L 、Seventh private key z L ; Based on the second public key X of group member i i 、Fifth public key Y i Get the first complete public key pk of group member i i =(X i ,Y i ); Based on the second private key x of group member i i 、Fifth private key z i Get the first complete private key sk of group member i i =(x i ,z i );Based on access point AP j The third public key Sixth public key Get access point AP j The second complete public key Based on access point AP j The third private key Sixth private key Get access point AP j The second complete private key Based on the fourth public key X of the group owner L L 、Seventh public key Y L Get the third complete public key pk of group owner L L =(X L ,Y L ); Based on the fourth private key x of the group owner L L 、Seventh private key z L Get the third complete private key sk of group owner L L =(x L ,z L ).
5. The method for group building and access authentication of a satellite network high-speed terminal group according to claim 1, characterized in that: The mutual verification between the group owner L and the group member i specifically includes: The group leader L generates an eighth random number And call the algorithm Sign(M L ,sk L ,pk i ,ID i ,X G ,r1) Generate the first signature S L ; The group owner L calls the algorithm Sign(M L ,sk L ,pk i ,ID i ,X G ,r1) Generate the first signature S L Specifically include: Group owner L calculation v1=r1·X G ; Group owner L calculation but Among them, pk i Represents the first complete public key of group member i; ID i Represents the second identity ID of group member i i ;X G represents the first public key of the ground control center GCC; P represents the generator of the ground control center GCC; Represent the first signature S L The partial signature in; v1 represents the intermediate quantity; f1 represents the intermediate quantity; H2 represents the second hash function; M L Indicates the first information, including the fourth identity ID of the group owner L L 、The third complete public key pk L =(X L ,Y L ); x L Indicates the fourth private key of group owner L, z L Represents the seventh private key of group owner L; represents the multiplicative group of order q that represents the set of non-zero elements; Group owner L broadcasts the first signature S to group member i L and the first information M L ; The group member i receives the first signature S L and the first information M L Then, call the algorithm VerifySign(S L ,sk i ,M L ,ID i ,X G ) verifies the identity of the group owner L; the group member i calls the algorithm VerifySign(S L ,sk i ,M L ,ID i ,X G ) Verifying the identity of group owner L specifically includes: Group member i calculation Group member i analyzes the first information M L To obtain the third complete public key pk of group owner L L =(X L ,Y L ) and the fourth identity ID L ; Group member i calculates h s =H1(ID L ,X L ,Y L ,X G ); Group member i check The signature is verified by checking whether they are equal; where: v2 represents the intermediate value; h s Indicates an intermediate quantity; If the verification is successful, group member i sends an access verification request to group owner L and calls the algorithm SignCryption (Msg i ,sk i ,pk L ,ID L ,X G ) Output the second signature S to the group owner L i and the first ciphertext c i ; The group member i calls the algorithm SignCryption(Msg i ,sk i ,pk L ,ID L ,X G ) Output the second signature S to the group owner L i and the first ciphertext c i Specifically include: Group member i selects the ninth random number And calculate v3=r2·X L ; Group member i calculates Group member i calculates h r =H1(ID L ,X L ,Y L ,X G ),v4=r2·(Y L +X G h r ), The second signature Among them, Msg i represents the second information, including a pair of random numbers (p i ,q i ), the second identity ID of group member i i and the first complete public key pk i =(X i ,Y i );p i represents the horizontal coordinate of a randomly selected point; q i represents the ordinate of a randomly selected point; Respectively represent the second signature S i Partial signature in; v3 represents the intermediate quantity; v4 represents the intermediate quantity; f2 represents the intermediate quantity; h r Indicates the intermediate quantity; X L represents the fourth public key of group owner L; Y L represents the seventh public key of the group owner L; x i represents the second private key of group member i; z i represents the fifth private key of group member i; If the verification fails, group member i will send a verification failure response message to group owner L; The group owner L receives the second signature S i and the first ciphertext c i Then, call the algorithm VerifySignCryption(S i ,sk L ,c i ,ID L ,X G ) for the first ciphertext c i Decrypt and get the second message Msg i And verify the second signature S i Is it correct? The group owner L calls the algorithm VerifySignCryption (S i ,sk L ,c i ,ID L ,X G ) for the first ciphertext c i Decrypt and get the second message Msg i And verify the second signature S i Whether it is correct specifically includes: Group owner L calculation The group owner L analyzes the second message Msg of group member i i , obtain the first complete public key pk of group member i i =(X i ,Y i ), the second identity ID of group member i i , a pair of random numbers generated by group member i (p i ,q i );Group leader L calculates h s =H1(ID i ,X i ,Y i ,X G ), and by checking Verify the signature by checking whether they are equal; Among them, sk L represents the third complete private key of the group owner L; v6 represents the intermediate amount; f3 represents the intermediate amount; Represents the exclusive OR operation; If the second signature S i Correct, the group owner L will store a pair of random numbers (p i ,q i ); if the second signature S i If the error occurs, the group owner L will send a verification failure response message to group member i.
6. The method for group building and access authentication of a satellite network high-speed terminal group according to claim 1, characterized in that: The group sharing key between the group owner L and the group member i specifically includes: The group leader L selects the tenth random number GK and constructs an interpolation polynomial f(x) of order n to pass through n+1 points, namely (0, GK) and (p i ,q i )(i=1,...,n); where p i represents the horizontal coordinate of a randomly selected point; q i represents the ordinate of a randomly selected point; The group leader L selects n other points on f(x) Generate timestamp TS1 and group shared key identifier GID, calculate message authentication code And the group shared key identifier GID, the message authentication code MAC, the fourth identity ID of the group owner L L , n points Timestamp TS1 is broadcast to group member i; where, Indicates the horizontal coordinate of the selected point; Indicates the ordinate of the selected point; The group member i receives the group shared key identifier GID, the message authentication code MAC, and the fourth identity ID of the group owner L L , n points After the timestamp TS1, use the random number stored in itself (p i ,q i ) recover f(x), calculate the tenth random number GK=f(0), and verify the validity of the message authentication code MAC; if the message authentication code MAC is valid, group member i stores the tenth random number GK as the group shared key of group member i; if the message authentication code MAC is invalid, group owner L will send a verification failure response message to group member i.
7. The method for group building and access authentication of a satellite network high-speed terminal group according to claim 1, characterized in that: The group owner L and the group member i respectively perform mutual authentication and group shared key to complete the construction of the high-speed terminal group HSTG, which also includes dynamic update of group members, specifically: When a new member joins, the new member first performs the mutual authentication phase between the group owner L and group member i, and then performs the group shared key phase between the group owner L and group member i; When an old member leaves, the old member first sends a leaving notification to the group owner L, and then executes the group sharing key phase between the group owner L and group member i.
8. The method for group building and access authentication of a satellite network high-speed terminal group according to claim 1, characterized in that: The group owner L to the access point AP j Sending a verification request specifically includes: Through access point AP j The group leader L who accesses the ground control center GCC generates the eleventh random number And call the algorithm Generate a third signature The group leader L calls the algorithm Generate a third signature Specifically include: Group owner L calculation v7=r3·X G ; Group owner L calculation but Where: X G represents the first public key of the ground control center GCC; P represents the generator of the ground control center GCC; Indicates access point AP j The third identity; v7 represents the intermediate quantity; f4 represents the intermediate quantity; m access Indicates that the group owner L accesses the access point AP j Required third party information; Indicates access point AP j The third private key of Indicates access point AP j The sixth private key of Respectively represent the third signature S' L Partial signature in ; Based on the fourth hash function H4, the tenth random number GK, the shared key identifier GID, and the first identity ID of the ground control center GCC G Calculate the first key GK between the group owner L and the ground control center GCC g-G Based on the fifth hash function H5, the eleventh random number r3, the first key GK between the group owner L and the ground control center GCC g-G Calculate the second ciphertext C; the corresponding calculation expressions are: GK g-G =H4(GK,GID,ID G ) in, Indicates XOR operation; sk L Represents the third complete private key of group owner L; Indicates access point AP j The second complete public key of The group owner L to the access point AP j Send third signature Group owner L access access point AP j Required third information m access , the second ciphertext C.
9. The method for group building and access authentication of a satellite network high-speed terminal group according to claim 1, characterized in that: The access point AP j Forwarding the access verification request to the ground control center GCC specifically includes: The access point AP j Receive the third signature Group owner L access access point AP j Required third information m access , after the second ciphertext C, call the algorithm Verify the third signature S' L ; The access point AP j Calling Algorithm Verify the third signature S' L Specifically include: Access Point j Receiving the third information m as an access request message access And calculate Access Point j Calculate h s =H1(ID L ,X L ,Y L ,X G ); Access point AP j examine Verify the signature by checking whether they are equal; Among them: v8 represents the intermediate quantity; Respectively represent the third signature S' L Partial signature in ; Indicates access point AP j The third private key of; H2 represents the second hash function; Indicates access point AP j The third identity of h s represents the intermediate quantity; H1 represents the first hash function; ID L Indicates the fourth identity ID of group owner L L ;X L represents the fourth public key of group owner L; Y L represents the seventh public key of group owner L; X G represents the first public key of the ground control center GCC; P represents the generator of the ground control center GCC; Indicates access point AP j The second complete private key of If the authentication is successful, the access point AP j The second ciphertext C and the third signature S' L Forwarded to the ground control center GCC; if the verification fails, the access point AP j A verification failure response message will be sent to the ground control center GCC.
10. The method for group building and access authentication of a satellite network high-speed terminal group according to claim 1, characterized in that: The ground control center GCC then sends the access point AP j Send authentication response, access point AP j The verification response is forwarded to the group owner l, and the group owner l verifies the response and broadcasts it to the group member i to achieve the high-speed terminal group HSTG, the ground control center GCC, and the access point AP j The secure communication between them specifically includes: The ground control center GCC receives the second ciphertext C and the third signature S' L After that, the second ciphertext C is decrypted, and based on the second ciphertext C, the fifth hash function H5, and the third signature S' L Partial signature in First private key x G Calculate the first key GK between the group owner L and the ground control center GCC g-G Based on the fourth hash function H4, the first key GK between the group owner L and the ground control center GCC g-G , shared key identifier GID, access point AP j The third identity Calculate the group owner L and access point AP j The second key GK g-j ; The corresponding calculation expressions are as follows: in, Represents the exclusive OR operation; The ground control center GCC is based on the fourth hash function H4, the first key GK between the group owner L and the ground control center GCC g-G 、The first identity ID of the ground control center GCC G , the third signature S' L Partial signature in Calculate the response value RES; the corresponding calculation expression is as follows: The access point AP j The response value RES is forwarded to the group owner L, the group owner L verifies the response value RES and broadcasts the response value RES to the group member i; the ground control center GCC uses the first key GK between the group owner L and the ground control center GCC g-G Secure communication with high-speed terminal group HSTG; access point AP j Through the group owner L and access point AP j The second key GK g-j Secure communication with High Speed Terminal Group (HSTG).
Citation Information
Patent Citations
Method, device and system for quickly and safely switching authentication of high-speed mobile terminal
CN115396887A
Ultra-high-speed terminal security access and intra-group security communication method in satellite network scene
CN119233252A
Ultra-high-speed terminal access and cooperative authentication method and program product in satellite network
CN119325087A
A Group Key based Authentication Protocol Providing Fast Handoff in IEEE 802.11
KR1020100040777A
Wireless network access method, device, equipment and system
WO2020143414A1