A method for constructing a group of a satellite network high-speed terminal group and access authentication

By implementing ground control center initialization and group authentication mechanisms, the security and efficiency issues of high-speed terminal groups are resolved, achieving stable and efficient communication, supporting dynamic member management, resisting attacks, and reducing resource consumption.

CN120050610BActive Publication Date: 2026-05-08XIDIAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
XIDIAN UNIV
Filing Date
2025-02-24
Publication Date
2026-05-08

AI Technical Summary

Technical Problem

High-speed terminal groups face challenges in terms of security and efficiency, including fragile communication links, difficulties in key management due to dynamic member joining and leaving, the inability of traditional authentication methods to adapt to rapidly changing network environments, and high overhead in the access process.

Method used

The group owner and group members perform mutual authentication and generate a group shared key by initializing and configuring identity identifiers and shared keys through the ground control center. The group owner sends an authentication request to the access point, and the ground control center responds, ensuring secure communication between the high-speed terminal group, the ground control center, and the access point.

Benefits of technology

It enables secure and efficient communication for high-speed terminal groups, resists unauthorized access, reduces resource consumption, improves system performance, supports key updates when members dynamically join and leave, and reduces computational and communication overhead.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050610B_ABST
    Figure CN120050610B_ABST
Patent Text Reader

Abstract

A satellite network high-speed terminal group construction and access authentication method, the method first initializes the ground control center, and respectively configures identity and shared key for high-speed terminal group and access point; then, the group owner and group members in high-speed terminal group respectively perform mutual authentication and group shared key; finally, the group owner sends authentication request to the access point, and the access point forwards access authentication request to the ground control center; the ground control center subsequently sends authentication response to the access point, and the access point forwards authentication response to the group owner, and the group owner verifies the response and broadcasts to the group members, thereby realizing the secure communication among high-speed terminal group, ground control center and access point; the method ensures the stability, efficiency and continuity of communication through group construction and access authentication mechanism; meanwhile, the method effectively protects the transmission information content, resists the access and interference of illegal entities, effectively reduces the resource occupation, and improves the overall performance of the system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of satellite communication technology, and more specifically to a method for the construction and access authentication of high-speed terminal groups in satellite networks. Background Technology

[0002] In the current technological development process, high-speed terminal groups It is gradually becoming a key application form in many fields. For example, in the field of intelligent transportation, high-speed terminal groups... It can be used for tasks such as traffic flow monitoring and intelligent navigation assistance; in environmental monitoring, it can achieve real-time environmental data collection and transmission over large areas. Information exchange among its members and external communication collaboration are crucial for the successful execution of tasks.

[0003] However, high-speed terminal groups It faces a series of severe challenges. In terms of security, its communication links are extremely vulnerable. Attackers can exploit the openness of these links to employ various attack methods. For example, they can use traffic analysis attacks to attempt to extract valuable information from communication traffic patterns; or they can use man-in-the-middle attacks to target high-speed terminal groups. Members may steal or tamper with data when communicating with external parties; they may also launch denial-of-service attacks, affecting high-speed terminal groups. Communication was paralyzed. Meanwhile, high-speed terminal groups... During dynamic operation, frequent joining and leaving of group members places extremely high demands on group key management. Poor key management can not only affect communication efficiency but also significantly increase the risk of communication content leakage.

[0004] In terms of performance, high-speed terminal groups The high-speed mobility of high-speed terminals presents significant challenges to access authentication. Traditional authentication methods are often inadequate for adapting to the rapidly changing network environment, resulting in low authentication efficiency. Furthermore, the lack of efficient mechanisms during group construction and maintenance easily leads to communication delays and excessive signaling overhead. These problems severely restrict the development of high-speed terminal groups. To ensure its effectiveness in practical applications, an innovative solution is urgently needed to guarantee its safe and efficient operation.

[0005] X. Wang(X. Wang and S. Xu,"A secure access control scheme based on group for peer to peer network”, 2012 International Conference on Systems and Informatics (ICSAI2012), pp. 1507-1511, 2012.) A system is proposed that employs a group structure to manage peer-to-peer networks, dividing them into multiple groups. Each group contains a unique trusted group header. This system is responsible for creating and organizing groups. The group leader can directly connect to the communication and relay data. Members within the group can directly connect to the group leader and other members. Members in different groups can communicate through the group leader. This structure facilitates management and security control, optimizes network communication and resource allocation, and enhances network scalability and security. However, this solution cannot meet the needs of high-speed terminal groups to quickly switch and access the access point when moving at high speed, resulting in high overhead during the access process or even access failure. Summary of the Invention

[0006] To overcome the shortcomings of the existing technology, the present invention aims to provide a method for the formation and access authentication of high-speed terminal groups in satellite networks. This method first involves the ground control center. Perform initialization and assign them to high-speed terminal groups. and access point Configure identity and shared key; then high-speed terminal group The group owner and group members Each group performs mutual verification and shares a key with the others; finally, the group owner... To the access point Send verification request, access point Forward the access verification request to the ground control center The ground control center Then to the access point Send verification response, access point Forward the verification response to the group owner Group owner Verify the response and broadcast it to group members. This enables high-speed terminal groups. Ground control center Access point Secure communication between them; this method ensures the stability, efficiency, and continuity of communication through group construction and access authentication mechanisms; at the same time, it effectively protects the transmitted information content, resists access and communication interference from illegal entities, effectively reduces resource consumption, and improves the overall performance of the system.

[0007] To achieve the above objectives, the technical solution adopted by the present invention is as follows:

[0008] A method for grouping and access authentication of high-speed terminal groups in a satellite network, comprising:

[0009] Ground control center Perform initialization and assign them to high-speed terminal groups. and access point Configure identity identifiers and shared keys; the high-speed terminal group Including multiple group members and a group owner ;

[0010] Based on the high-speed terminal group Configured identity and shared key, group owner and group members Each terminal performs mutual authentication and group key sharing to complete the high-speed terminal group. The construction;

[0011] Based on the high-speed terminal group and access point Configured identity identifiers and shared keys, as well as the high-speed terminal group Construction , Group owner To the access point Send verification request, access point Forward the access verification request to the ground control center The ground control center Then to the access point Send verification response, access point Forward the verification response to the group owner Group owner Verify the response and broadcast it to group members. To achieve high-speed terminal groups Ground control center Access point Secure communication between them.

[0012] Furthermore, the ground control center Initialization specifically includes:

[0013] The ground control center Select Ground Control Center First identity , call The algorithm is initialized, then the system parameters are made public and the first private key is used. Confidential;

[0014] The ground control center The publicly disclosed system parameters include the cyclic group order Generator First public key First hash function Second hash function Third hash function Fourth hash function Fifth hash function .

[0015] Furthermore, the ground control center Publicly disclose system parameters and the first private key Confidentiality specifically includes:

[0016] The ground control center Select Elliptic Curve Choose the order as Cyclic group and generator ;

[0017] The ground control center Select the first random number As the first private key; based on the first private key Generator Calculate the first public key The corresponding expression is:

[0018]

[0019] Based on elliptic curves Cyclic groups The ground control center Choose the first hash function respectively Second hash function Third hash function Fourth hash function Fifth hash function ;in, Represents a zero- or one-bit string of arbitrary length; Describes the set of non-zero elements and is expressed as follows: A multiplication group of order 1.

[0020] Furthermore, the ground control center High-speed terminal groups and access point Configuring identity and shared keys specifically includes:

[0021] The ground control center Group members Access point Group owner Choose a second identity Third identity Fourth identity ;in, ; ;

[0022] The group members Select the second random number As a second private key; the access point Select a third random number As a third private key; the group owner Select the fourth random number As the fourth private key; the second random number Third random number Fourth random number ;in: Describes the set of non-zero elements and is expressed as follows: A multiplication group of order 1;

[0023] Based on the second private key Ground control center generator Computation group members Second public key Based on the third private key Ground control center generator Calculate access point The third public key Based on the fourth private key Ground control center generator Calculate the group owner The fourth public key The corresponding calculation expressions are as follows:

[0024]

[0025]

[0026]

[0027] The group members group members Second identity Second public key Send to ground control center Afterwards, the ground control center Calling Algorithm Generate group members The fifth private key and the fifth public key The ground control center Calling Algorithm Generate group members The fifth private key and the fifth public key Specifically, it includes:

[0028] The ground control center Select the fifth random number And calculate the fifth public key. The ground control center Calculate the fifth private key The ground control center Return the fifth public key Fifth private key ;in, Indicates the first hash function; Indicates ground control center The first public key;

[0029] The access point Access point The third identity Third public key Send to ground control center Afterwards, the ground control center Calling Algorithm Generate access point The sixth private key and the sixth public key The ground control center Calling Algorithm Generate access point The sixth private key and the sixth public key Specifically, it includes:

[0030] The ground control center Choose a sixth random number And calculate the sixth public key. The ground control center Calculate the sixth private key The ground control center Return the sixth public key Sixth private key ;

[0031] The group owner group owner The fourth identity Fourth public key Send to ground control center Afterwards, the ground control center Calling Algorithm Generate group owner The seventh private key and the seventh public key The ground control center Calling Algorithm Generate group owner The seventh private key and the seventh public key Specifically, it includes:

[0032] The ground control center Select the seventh random number And calculate the seventh public key. The ground control center Calculate the seventh private key The ground control center Return the seventh public key 7th Private Key ;

[0033] Based on group members Second public key Fifth public key Get group members First complete public key Based on group members Second private key Fifth private key Get group members First complete private key Based on access point The third public key The sixth public key Get access point Second complete public key Based on access point The third private key Sixth private key Get access point Second complete private key Based on the group owner The fourth public key The seventh public key Get the group owner The third complete public key Based on the group owner The fourth private key 7th Private Key Get the group owner The third complete private key .

[0034] Furthermore, the group owner and group members The mutual verification between them specifically includes:

[0035] The group owner Generate the eighth random number and call the algorithm Generate the first signature The group owner Calling Algorithm Generate the first signature Specifically, it includes:

[0036] Group owner calculate , Group owner calculate ;but ;

[0037] in, group members The first complete public key; group members Second identity ; Indicates ground control center The first public key; Indicates ground control center generator ; Each represents the first signature Partial signature in the document; Indicates intermediate quantity; Indicates intermediate quantity; Indicates the second hash function; This indicates the first piece of information, including the group owner. The fourth identity Third complete public key ; The group owner The fourth private key The group owner The seventh private key; Describes the set of non-zero elements and is expressed as follows: A multiplication group of order 1;

[0038] Group owner To group members First Signature on Broadcast and first information ;

[0039] The group members Received first signature and first information Then, call the algorithm. Verify group owner The identity of the group members; Calling Algorithm Verify group owner The specific identities include:

[0040] Group members calculate Group members Analyzing the first information Get the group owner The third complete public key and the fourth identity Group members calculate Group members examine The signature is verified by checking if they are equal; where: Indicates intermediate quantity; Indicates intermediate quantity;

[0041] If verification is successful, group members To the group owner Send an access verification request and call the algorithm. To the group owner Output the second signature And the first ciphertext The group members Calling Algorithm To the group owner Output the second signature And the first ciphertext Specifically, it includes:

[0042] Group members Select the ninth random number and calculate , Group members calculate , Group members Calculate separately ;but ;

[0043] in, This indicates the second piece of information, including group members. A pair of random numbers generated Group members Second identity and the first complete public key ; The x-coordinate of a randomly selected point; The ordinate of a randomly selected point; , These represent the second signature. Partial signature in the document; Indicates intermediate quantity; Indicates intermediate quantity; Indicates intermediate quantity; Indicates intermediate quantity; The group owner The fourth public key; The group owner The seventh public key; group members The second private key; group members The fifth private key;

[0044] If verification fails, group members Will report to the group owner Send a verification failure response message;

[0045] The group owner Received second signature And the first ciphertext Then, call the algorithm. For the first ciphertext Decryption is performed to obtain the second information. And verify the second signature Is this correct? The group owner mentioned... Calling Algorithm For the first ciphertext Decryption is performed to obtain the second information. And verify the second signature Whether it is correct specifically includes:

[0046] Group owner calculate Group owner Analysis of group members Second information Get group members First complete public key 、 Group members Second identity Group members A pair of random numbers generated Group owner calculate and through inspection Verify signatures by checking for equality;

[0047] in, The group owner The third complete private key; Indicates intermediate quantity; Indicates intermediate quantity; Indicates intermediate quantity; Indicates the XOR operation;

[0048] If the second signature Correct, group owner Will store group members A pair of random numbers generated If the second signature Error, group owner Will inform group members Send a verification failure response message;

[0049] Furthermore, the group owner and group members Sharing keys among groups specifically includes:

[0050] The group owner Select the tenth random number And construct a [order] of [number]. interpolation polynomial , in order to pass One point, that is and ;in, The x-coordinate of a randomly selected point; Represents the ordinate of a randomly selected point;

[0051] The group owner exist Another option Points Generate timestamp and group shared key identifier Calculate message verification code and group shared key identifier Message verification code Group owner The fourth identity , Points timestamp Broadcast to group members ;in, Indicates the x-coordinate of the selected point; Represents the ordinate of the selected point;

[0052] The group members Received group shared key identifier Message verification code Group owner The fourth identity , Points timestamp Then, use the random number stored within itself. recover Calculate the tenth random number And verify the message verification code. The validity of the message verification code; Valid, group members The tenth random number Save as group member The group shared key; if the message verification code Invalid, group owner Will inform group members Send a verification failure response message.

[0053] Furthermore, in the group owner and group members Each terminal performs mutual authentication and group key sharing to complete the high-speed terminal group. The construction also includes dynamic updates of group members, specifically:

[0054] When a new member joins, the new member first acts as the group owner. and group members The mutual verification phase between them, and then the group owner executes. and group members The group-shared key phase between;

[0055] When a former member leaves, the former member should first inform the group owner. Send a departure notification, then execute the group owner's request. and group members The shared key phase between groups.

[0056] Furthermore, the group owner To the access point Sending a verification request specifically includes:

[0057] via access point Access to ground control center group owner Generate the eleventh random number and call the algorithm Generate a third signature The group owner Calling Algorithm Generate a third signature Specifically, it includes:

[0058] Group owner calculate , Group owner calculate ;but ;

[0059] in: Indicates ground control center The first public key; Indicates ground control center generator; Indicates access point A third identity; Indicates intermediate quantity; Indicates intermediate quantity; The group owner Access point The required third information; Indicates access point The third private key; Indicates access point The sixth private key; 、 These represent the third signature. Partial signature in the document;

[0060] Based on the fourth hash function The tenth random number Group shared key identifier Ground control center First identity Calculate the group owner With ground control center The first key between Based on the fifth hash function 11th random number Group owner With ground control center The first key between Calculate the second ciphertext The corresponding calculation expressions are as follows:

[0061]

[0062]

[0063] in, Indicates the XOR operation; The group owner The third complete private key; Indicates access point The second complete public key;

[0064] The group owner To the access point Send third signature Group owner Access point Required third information Second ciphertext .

[0065] Furthermore, the access point Forward the access verification request to the ground control center Specifically, it includes:

[0066] The access point Received third signature Group owner Access point Required third information Second ciphertext Then, call the algorithm. Verify third signature The access point Calling Algorithm Verify third signature Specifically, it includes:

[0067] Access point Receive third information as an access request message. And calculate Access point calculate Access point examine Verify signatures by checking for equality;

[0068] in: Indicates intermediate quantity; 、 Each represents a third signature Partial signature in the document; Indicates access point The third private key; Indicates the second hash function; Indicates access point A third identity; Indicates intermediate quantity; Indicates the first hash function; The group owner The fourth identity ; The group owner The fourth public key; The group owner The seventh public key; Indicates ground control center The first public key; Indicates ground control center generator ; Indicates access point The second complete private key;

[0069] If verification is successful, access point The second ciphertext and third signature Forwarded to ground control center If verification fails, the access point It will be sent to the ground control center Send a verification failure response message;

[0070] Furthermore, the ground control center Then to the access point Send verification response, access point Forward the verification response to the group owner Group owner Verify the response and broadcast it to group members. To achieve high-speed terminal groups Ground control center Access point Secure communication between them specifically includes:

[0071] The ground control center Received the second ciphertext and third signature Then, regarding the second ciphertext Decrypt and based on the second ciphertext. Fifth hash function 、 Third Signature Partial signatures in 、 First private key Calculate the group owner L With ground control center The first key between Based on the fourth hash function Group owner L With ground control center The first key between Group shared key identifier Access point The third identity Calculate the group owner L Access point The second key between The corresponding calculation expressions are as follows:

[0072]

[0073]

[0074] in, Indicates an XOR operation; the ground control center Based on the fourth hash function Group owner L With ground control center The first key between Ground control center First identity Third Signature Partial signatures in Calculate response value The corresponding calculation expression is as follows:

[0075]

[0076] The access point Response value Forward to the group owner Group owner Verify response value and response value Broadcast to group members Ground Control Center Through the group owner L With ground control center The first key between With high-speed terminal group For secure communication; access point Through the group owner L Access point The second key between With high-speed terminal group To conduct secure communication.

[0077] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0078] 1. Regarding group creation and access authentication mechanisms:

[0079] In the process of group building, this invention uses the group owner... and group members Mutual verification between them and the group owner and group members The system uses a shared key among groups to ensure secure communication within the group; it also supports dynamic updates of the group key when members join or leave, maintaining forward and backward confidentiality of the group key. For example, in emergency rescue scenarios, a collaborative group composed of multiple high-speed drones can efficiently coordinate and execute tasks, and the efficiency of group construction and key management ensures communication security and the continuity of task execution.

[0080] During the group's network access process, the group owner Can represent group members Securely access terrestrial networks via satellite and connect to terrestrial networks and access points along the trajectory route. Pre-negotiated keys effectively prevent high latency or even failures that may occur during subsequent authentication switching, ensuring the stability and efficiency of communication.

[0081] 2. Regarding security:

[0082] Regarding mutual verification: Group owner and group members Both the mutual verification phase and the group access network phase utilize mechanisms such as private key signing and public key verification to ensure the group owner's identity. With group members Group owner With group members Ground Control Center The mutual authentication between them effectively prevents unauthorized entities from accessing the network and interfering with communication.

[0083] Regarding key negotiation: whether it's the group shared key construction phase or the first key... Second key During the construction phase, secure key security is ensured through secure key generation and transmission methods, preventing attackers from obtaining key information.

[0084] Regarding non-linkability: During the process of group building and network access, the use of encrypted information and random numbers increases the uncertainty and diversity of information, effectively protecting the information content and preventing attackers from obtaining key data by analyzing different information.

[0085] Regarding forward / backward key separation: During group construction, the group owner updates the group shared key when a new member joins or an old member leaves, ensuring the dynamism and independence of the group shared key and enhancing the security of key management.

[0086] In terms of defending against attacks using multiple protocols: through message verification codes timestamp It employs multiple methods, including signature and signature encryption algorithms, to effectively defend against various known security threats such as replay attacks, impersonation attacks, man-in-the-middle attacks, and private key theft attacks.

[0087] 3. Regarding resource consumption:

[0088] In terms of computational overhead: compared with the background technology X. Wang Compared to other solutions, this invention has lower computational overhead during group construction when the number of members is relatively large. X. Wang The plan of others.

[0089] Regarding communication overhead: During group building, the communication overhead of this invention is significantly lower than that of other inventions. X. Wang The proposed solution, especially when building large-scale groups, has significant advantages and higher communication efficiency.

[0090] Regarding signaling overhead: The signaling overhead of this invention is low during both group creation and dynamic changes in group members. X. WangThe proposed solution, as proposed by others, exhibits good stability in signaling overhead when the frequency of dynamic changes in group members increases, and can effectively reduce network resource consumption.

[0091] In summary, this invention outperforms existing technologies in terms of security, performance, and adaptability, and is more suitable for the needs of high-speed terminal group construction and access authentication in satellite network scenarios, providing a more reliable and efficient solution for high-speed terminal communication in integrated space-ground networks. Attached Figure Description

[0092] Figure 1 This is a flowchart of the satellite network high-speed terminal group assembly and access authentication method of the present invention.

[0093] Figure 2 This is a scenario diagram of the high-speed terminal group access architecture of the present invention.

[0094] Figure 3 This is an overview diagram of the high-speed terminal group access architecture of the present invention. Detailed Implementation

[0095] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments:

[0096] Due to high-speed terminal groups Access point The wireless links between groups are highly exposed, making them vulnerable to attacks that could eavesdrop on and obtain critical data. Furthermore, communication between group members via insecure air interfaces is susceptible to replay and impersonation attacks. Therefore, to ensure the communication security of group members, [measures must be taken at the access point]. With ground control center Based on the established secure channel, this invention proposes a method for the grouping and access authentication of high-speed terminal groups in satellite networks. (See [link to relevant documentation]). Figure 1 and Figure 2 This method includes a system initialization process, a group creation process, and a group access network process, as detailed below:

[0097] I. System Initialization Process: Ground Control Center Perform initialization and assign them to high-speed terminal groups. and access point Configure identity identifiers and shared keys; the high-speed terminal group Including multiple group members and a group owner High-speed terminal group This includes multiple terminals, one of which was selected as the group owner. Other terminals are group members. The efficiency of multiple terminals working together is much higher than that of a single terminal working alone.

[0098] The ground control center Initialization specifically includes:

[0099] The ground control center Select Ground Control Center First identity , call The algorithm is initialized, then the system parameters are made public and the first private key is used. Confidential;

[0100] The ground control center The publicly disclosed system parameters include the cyclic group order Generator First public key First hash function Second hash function Third hash function Fourth hash function Fifth hash function .

[0101] Furthermore, the ground control center Publicly disclose system parameters and the first private key Confidentiality specifically includes:

[0102] The ground control center Select Elliptic Curve Choose the order as Cyclic group and generator ;

[0103] The ground control center Select the first random number As the first private key; based on the first private key Generator Calculate the first public key The corresponding expression is:

[0104]

[0105] Based on elliptic curves Cyclic groups The ground control center Choose the first hash function respectively Second hash function Third hash function Fourth hash function Fifth hash function ;in, Represents a zero- or one-bit string of arbitrary length; Describes the set of non-zero elements and is expressed as follows: A multiplication group of order 1.

[0106] Furthermore, the ground control center High-speed terminal groups and access point Configuring identity and shared keys specifically includes:

[0107] The ground control center Group members Access point Group owner Choose a second identity Third identity Fourth identity ;in, ; ;

[0108] The group members Select the second random number As a second private key; the access point Select a third random number As a third private key; the group owner Select the fourth random number As the fourth private key; the second random number Third random number Fourth random number ;in: A set of non-zero elements and with A multiplication group of order 1;

[0109] In this embodiment, the second random number and the second private key are essentially the same; the third random number and the third private key are essentially the same; the fourth random number and the fourth private key are essentially the same; the use of random numbers increases the uncertainty and diversity of information, effectively protecting the information content and preventing attackers from obtaining key data by analyzing different information.

[0110] Based on the second private key Ground control center generator Computation group members Second public key Based on the third private key Ground control center generator Calculate access point The third public key Based on the fourth private key Ground control center generator Calculate the group owner The fourth public key The corresponding calculation expressions are as follows:

[0111]

[0112]

[0113]

[0114] The group members group members Second identity Second public key Send to ground control center Afterwards, the ground control center Calling Algorithm Generate group members The fifth private key and the fifth public key ; The algorithm is mainly used to generate public and private key pairs by inputting group members. Second identity Group members Second public key Ground control center First public key Then group members can be calculated. The fifth private key and the fifth public key The ground control center Calling Algorithm Generate group members The fifth private key and the fifth public key Specifically, it includes:

[0115] The ground control center Select the fifth random number And calculate the fifth public key. The ground control center Calculate the fifth private key The ground control center Return the fifth public key Fifth private key ;in, Indicates the first hash function; Indicates ground control center The first public key;

[0116] The access point Access point The third identity Third public key Send to ground control center Afterwards, the ground control center Calling Algorithm Generate access point The sixth private key and the sixth public key The ground control center Calling Algorithm Generate access point The sixth private key and the sixth public key Specifically, it includes:

[0117] The ground control center Choose a sixth random number And calculate the sixth public key. The ground control center Calculate the sixth private key The ground control center Return the sixth public key Sixth private key ;

[0118] The group owner group owner The fourth identity Fourth public key Send to ground control center Afterwards, the ground control center Calling Algorithm Generate group owner The seventh private key and the seventh public key The ground control center Calling Algorithm Generate group owner The seventh private key and the seventh public key Specifically, it includes:

[0119] The ground control center Select the seventh random number And calculate the seventh public key. The ground control center Calculate the seventh private key The ground control center Return the seventh public key 7th Private Key ;

[0120] In the above embodiments, The algorithm is used to generate public and private key pairs, via ground control center. Different random numbers are selected as private keys, and key exchange technology is used to ensure the security of the distributed keys.

[0121] Based on group members Second public key Fifth public key Get group members First complete public key Based on group members Second private key Fifth private key Get group members First complete private key Based on access point The third public key The sixth public key Get access point Second complete public key Based on access point The third private key Sixth private key Get access point Second complete private key Based on the group owner The fourth public key The seventh public key Get the group owner The third complete public key Based on the group owner The fourth private key 7th Private Key Get the group owner The third complete private key ;

[0122] This embodiment group members Access point Group owner A complete public key consists of two parts, even if an attacker can obtain it from the ground control center. The attacker obtained a portion of the device's private key, but was still unable to deduce the group members. or group owner The additional private key held by the user greatly enhances the security of communication.

[0123] II. Group Construction Process: Based on the aforementioned high-speed terminal group Configured identity and shared key, group owner and group members Each terminal performs mutual authentication and group key sharing to complete the high-speed terminal group. The construction;

[0124] See Figure 3 This embodiment proposes a group building protocol that enables group members to... With the group owner Mutual authentication between groups, and secure group key negotiation, are used to ensure secure communication within the group.

[0125] In this implementation, all group members All must be with the group owner The mutual verification process is as follows:

[0126] Furthermore, the group owner and group members The mutual verification between them specifically includes:

[0127] The group owner Generate the eighth random number and call the algorithm Generate the first signature The group owner Calling Algorithm Generate the first signature Specifically, it includes:

[0128] Group owner calculate , Group owner calculate ;but ;

[0129] in, Indicates group members The first complete public key; Indicates group members Second identity ; Indicates ground control center The first public key; Indicates ground control center generator ; Each represents the first signature Partial signature in the document; Indicates intermediate quantity; Indicates intermediate quantity; Indicates the second hash function; This indicates the first piece of information, including the group owner. The fourth identity Third complete public key ; The group owner The fourth private key The group owner The seventh private key; Describes the set of non-zero elements and is expressed as follows: A multiplication group of order 1;

[0130] In this embodiment, call The algorithm generates two partial signatures respectively. The purpose is to sign the first part. Nested in the second half of the signature The following The algorithm also adopts this method, which greatly improves the security of the key;

[0131] Group owner To group members First Signature on Broadcast and first information ;

[0132] The group members Received first signature and first information Then, call the algorithm. Verify group owner The identity of the group members; Calling Algorithm Verify group owner The specific identities include:

[0133] Group members calculate Group members Analyzing the first information Get the group owner The third complete public key and the fourth identity Group members calculate Group members examine The signature is verified by checking if they are equal; where: Indicates intermediate quantity; Indicates intermediate quantity;

[0134] If verification is successful, group members To the group owner Send an access verification request and call the algorithm. To the group owner Output the second signature And the first ciphertext The group members Calling Algorithm To the group owner Output the second signature And the first ciphertext Specifically, it includes:

[0135] Group members Select the ninth random number and calculate , Group members calculate , Group members Calculate separately ;but ;

[0136] in, This indicates the second piece of information, including group members. A pair of random numbers generated Group members Second identity and the first complete public key ; The x-coordinate of a randomly selected point; Represents the ordinate of a randomly selected point; , These represent the second signature. Partial signature in the document; Indicates intermediate quantity; Indicates intermediate quantity; Indicates intermediate quantity; Indicates intermediate quantity; The group owner The fourth public key; The group owner The seventh public key; Indicates group members The second private key; Indicates group members The fifth private key;

[0137] If verification fails, group members Will report to the group owner Send a verification failure response message;

[0138] The group owner Received second signature And the first ciphertext Then, call the algorithm. For the first ciphertext Decryption is performed to obtain the second information. And verify the second signature Is this correct? The group owner mentioned... Calling Algorithm For the first ciphertext Decryption is performed to obtain the second information. And verify the second signature Whether it is correct specifically includes:

[0139] Group owner calculate Group owner Analysis of group members Second information , gain group members First complete public key 、 Group members Second identity Group members A pair of random numbers generated Group owner calculate And through inspection Verify signatures by checking for equality;

[0140] in, The group owner The third complete private key; Indicates intermediate quantity; Indicates intermediate quantity; Indicates intermediate quantity; Indicates the XOR operation;

[0141] If the second signature Correct, group owner Will store group members A pair of random numbers generated If the second signature Error, group owner Will inform group members Send a verification failure response message;

[0142] After completing the group owner and group members After mutual verification, the group owner Generate a group shared key and distribute it to all group members. Assuming the group owner... Currently owned The access verification information for each group member, and the corresponding random number pair is: This process can be divided into the following steps:

[0143] Furthermore, the group owner and group members Sharing keys among groups specifically includes:

[0144] The group owner Select the tenth random number And construct a [order] of [number]. interpolation polynomial , in order to pass One point, that is and ;in, The x-coordinate of a randomly selected point; Represents the ordinate of a randomly selected point;

[0145] The group owner exist Another option Points Generate timestamp and group shared key identifier Calculate message verification code and group shared key identifier Message verification code Group owner The fourth identity , Points timestamp Broadcast to group members ;in, Indicates the x-coordinate of the selected point; Represents the ordinate of the selected point;

[0146] The group members Received group shared key identifier Message verification code Group owner The fourth identity , Points timestamp Then, use the random number stored within itself. recover Calculate the tenth random number And verify the message verification code. The validity of the message verification code; Valid, group members The tenth random number Save as group member The group shared key; if the message verification code Invalid, group owner Will inform group members Send a verification failure response message.

[0147] During the group shared key phase, a message verification code is set. timestamp It employs multiple methods, including signature and signature encryption algorithms, to effectively defend against various known security threats such as replay attacks, impersonation attacks, man-in-the-middle attacks, and private key theft attacks.

[0148] Furthermore, in the group owner and group members Each terminal performs mutual authentication and group key sharing to complete the high-speed terminal group. The construction also includes dynamic updates of group members, specifically:

[0149] When a new member joins, the new member first acts as the group owner. and group members The mutual verification phase between them, and then the group owner executes. and group members The group-shared key phase between;

[0150] When a former member leaves, the former member should first inform the group owner. Send a departure notification, then execute the group owner's request. and group members The shared key phase between groups.

[0151] This embodiment supports dynamic updates of the group key when a new member joins or an old member leaves, thereby maintaining the forward / backward confidentiality of the group key.

[0152] III. Group access network process: Based on the aforementioned high-speed terminal group and access point Configured identity identifiers and shared keys, as well as the high-speed terminal group Construction , Group owner To the access point Send verification request, access point Forward the access verification request to the ground control center The ground control center Then to the access point Send verification response, access point Forward the verification response to the group owner Group owner Verify the response and broadcast it to group members. To achieve high-speed terminal groups Ground control center Access point Secure communication between them.

[0153] See Figure 3 In this embodiment, the group owner Representatives of the group access the terrestrial network and the access point Ground control center Complete mutual verification and communicate with [the relevant parties] in advance. All access points along the trajectory route The negotiation group shares the key; The broadcast will include relevant information, including identity identifiers. and public key .

[0154] Furthermore, the group owner To the access point Sending a verification request specifically includes:

[0155] via access point Access to ground control center group owner Generate the eleventh random number and call the algorithm Generate a third signature The group owner Calling Algorithm Generate a third signature Specifically, it includes:

[0156] Group owner calculate , Group owner calculate ;but ;

[0157] in: Indicates ground control center The first public key; Indicates ground control center generator; Indicates access point A third identity; Indicates intermediate quantity; Indicates intermediate quantity; The group owner Access point The required third information; Indicates access point The third private key; Indicates access point The sixth private key; 、 These represent the third signature. Partial signature in the document;

[0158] Based on the fourth hash function The tenth random number Group shared key identifier Ground control center First identity Calculate the group owner With ground control center The first key between Based on the fifth hash function 11th random number Group owner With ground control center The first key between Calculate the second ciphertext The corresponding calculation expressions are as follows:

[0159]

[0160]

[0161] in, Indicates the XOR operation; The group owner The third complete private key; Indicates access point The second complete public key;

[0162] The group owner To the access point Send third signature Group owner Access point Required third information Second ciphertext .

[0163] Furthermore, the access point Forward the access verification request to the ground control center Specifically, it includes:

[0164] The access point Received third signature Group owner Access point Required third information Second ciphertext Then, call the algorithm. Verify third signature The access point Calling Algorithm Verify third signature Specifically, it includes:

[0165] Access point Receive third information as an access request message. And calculate Access point calculate Access point examine Verify signatures by checking for equality;

[0166] in: Indicates intermediate quantity; 、 These represent the third signature. Partial signature in the document; Indicates access point The third private key; Indicates the second hash function; Indicates access point A third identity; Indicates intermediate quantity; Indicates the first hash function; The group owner The fourth identity ; The group owner The fourth public key; The group owner The seventh public key; Indicates ground control center The first public key; Indicates ground control center generator ; Indicates access point The second complete private key;

[0167] If verification is successful, access point The second ciphertext and third signature Forwarded to ground control center If verification fails, the access point It will be sent to the ground control center Send a verification failure response message; where, Indicates access point The second complete private key; Indicates access point A third identity; Indicates ground control center The first public key.

[0168] Furthermore, the ground control center Then to the access point Send verification response, access point Forward the verification response to the group owner Group owner Verify the response and broadcast it to group members. To achieve high-speed terminal groups Ground control center Access point Secure communication between them specifically includes:

[0169] The ground control center Received the second ciphertext and third signature Then, regarding the second ciphertext Decrypt and based on the second ciphertext. Fifth hash function 、 Third Signature Partial signatures in 、 First private key Calculate the group owner L With ground control center The first key between Based on the fourth hash function Group owner L With ground control center The first key between Group shared key identifier Access point The third identity Calculate the group owner L Access point The second key between The corresponding calculation expressions are as follows:

[0170]

[0171]

[0172] in, Indicates the XOR operation; Indicates the fourth signature;

[0173] The ground control center Based on the fourth hash function Group owner L With ground control center The first key between Ground control center First identity Third Signature Partial signatures in Calculate response value The corresponding calculation expression is as follows:

[0174]

[0175] The access point Response value Forward to the group owner Group owner Verify response value and response value Broadcast to group members Ground Control Center Through the group owner L With ground control center The first key between With high-speed terminal group For secure communication; access point Through the group owner L Access point The second key between With high-speed terminal group To conduct secure communication.

[0176] In this embodiment, the ground control center Completed with high-speed terminal group After secure access, the ground control center, based on the trajectory prediction mechanism, High-speed terminal groups can be pre-set. Access points along the trajectory route The second key such high-speed terminal groups Upon entering the target access point When the range is met, the second key can be used directly. Secure communication is established, thereby avoiding problems such as high overhead, high latency, and even handover failure.

[0177] The application effects of this invention will be described in further detail below in conjunction with a safety analysis.

[0178] I. Mutual Authentication

[0179] 1. Group Owner and group members The mutual verification phase between them: On the one hand, the group owner Use group owner The third complete private key Generate the first signature Due to the unforgeability of the private key, only the group owner can access it. The correct signature can be calculated, and the group members... You can use the group owner The third complete public key and ground control center First public key Verify the first signature Verify the correctness, and then verify the group owner. On the other hand, each group member To the group owner After successful authentication, group members will be used. First complete private key Generate a second signature and use the group owner The third complete public key Encrypt the second information This way, only legitimate group owners can participate. Only then can the first ciphertext be deciphered. , obtain the second information Therefore, only legitimate group owners... Only then can be group members Validated successfully.

[0180] 2. Group access network stage: Group owner Use group owner The third complete private key Generate a third signature And send to the access point Due to the unforgeability of the private key, only the group owner can access it. The correct third signature can be calculated. ,and You can use the group owner The third complete public key and ground control center First public key Verify third signature The correctness, and then to the group owner. Identity verification is required. In addition, the group owner... Using the ground control center The third complete public key And the eleventh random number Encrypted group owner L With ground control center The first key between Therefore, only the ground control center It can use its unforgeable first private key Decrypting the second ciphertext Get the group owner L With ground control center The first key between and generate response values. Group owner L You can check the response value To verify the access point Ground control center Therefore, the group owner's identity. L and access point Ground control center Mutual authentication can be established between them.

[0181] II. Key Negotiation

[0182] 1. Group Shared Key Construction Phase: The group shared key is constructed using a method that constructs interpolation polynomials. Random number pairs used to construct the group shared key are then used in the first ciphertext. Send to the group owner Because only the group owner Only then can the first ciphertext be deciphered. Obtain the second information Then obtain a pair of random numbers. This is used to construct a block shared key, so even if an attacker intercepts the first ciphertext... Furthermore, the group sharing key cannot be obtained.

[0183] 2. First Key Second Key The construction phase: Group owner Calculate the first key And encrypt it into a second ciphertext. Then the second ciphertext Send to access point Access point Verify group owner After identifying the second ciphertext Forwarded to ground control center Therefore, only high-speed terminal groups and ground control center The first key can be obtained Therefore, the group owner L Access point The second key between It is also safe.

[0184] III. Unlinkability

[0185] During group setup and network access, key negotiation and encryption of information are performed. Encrypted information can only be decrypted by the recipient possessing the correct key. Furthermore, random numbers (e.g., the sixth random number) are used during both processes. The introduction of random numbers increases the uncertainty and diversity of information, making it difficult for attackers to link different pieces of information by analyzing them, thereby protecting the information content and improving its unlinkability.

[0186] IV. Forward Key Separation / Backward key separation BKS

[0187] During the group creation process, whether new members join or old members leave, the group owner... The process of building a group shared key will be executed in all group members to update the group shared key. This ensures the dynamism and independence of the group shared key, while also protecting the group shared key from the pair of random numbers used in the group shared key construction phase. The privacy and randomness of the group shared key make it impractical to derive an old group shared key from a new one or vice versa. This achieves forward key separation (FKS) / backward key separation (BKS), enhancing security.

[0188] V. Defending against replay attacks

[0189] During the group key construction phase, a message verification code will be used. and timestamp When group members receive a message from the group owner When you receive information, you can check the message verification code. and timestamp To determine whether the message has been replayed. If the message verification code... Incorrect or timestamp If the time difference exceeds a threshold, the message is considered to have been subjected to a replay attack and is rejected. Group access to the network also involves message verification codes. and timestamp The use of this method ensures the freshness of information and prevents replay attacks.

[0190] VI. Defend against impersonation attacks

[0191] Throughout the scheme, signatures and signature encryption algorithms are used to ensure the integrity and immutability of information, making it suitable for high-speed terminal groups. Interactions between members also apply to group owners. and access point The interaction between them. It is difficult for an attacker to forge a signature without the correct private key, making it difficult to impersonate a legitimate entity to communicate.

[0192] VII. Resisting Intermediaries attack

[0193] During group setup and network access, signature algorithms are used to ensure information is not tampered with or forged, while encryption is used to protect the confidentiality of important information. This ensures that information cannot be accessed, tampered with, or forged by a man-in-the-middle, thus resisting attacks. attack.

[0194] 8. Defend against private key theft attacks

[0195] During system initialization, even if an attacker can access the ground control center... Obtain partial private keys of the device (such as group members) Second private key Group owner The fourth private key ), due to the elliptic curve discrete logarithm problem The existence of the group prevents attackers from deduce its members. or group owner Another part of the private key held by the individual (such as group members) The fifth private key Group owner The seventh private key Therefore, it can successfully defend against private key theft attacks.

[0196] The above embodiments are merely detailed descriptions of the present invention, but the present invention is not limited to the above embodiments. Any modifications, substitutions, and changes made to the present invention within the spirit and scope of the claims are within the scope of protection of the present invention.

Claims

1. A method for constructing and authenticating access to a high-speed terminal group in a satellite network, characterized in that: include: Ground control center Perform initialization and assign them to high-speed terminal groups. and access point Configure identity identifiers and shared keys; the high-speed terminal group Including multiple group members and a group owner ; Based on the high-speed terminal group Configured identity and shared key, group owner and group members Each terminal performs mutual authentication and group key sharing to complete the high-speed terminal group. The construction; Based on the high-speed terminal group and access point Configured identity identifiers and shared keys, as well as the high-speed terminal group Construction , Group owner To the access point Send verification request, access point Forward the access verification request to the ground control center The ground control center Then to the access point Send verification response, access point Forward the verification response to the group owner Group owner Verify the response and broadcast it to group members. To achieve high-speed terminal groups Ground control center Access point Secure communication between them.

2. The method for constructing and authenticating access to a high-speed terminal group in a satellite network according to claim 1, characterized in that: The ground control center Initialization specifically includes: The ground control center Select Ground Control Center First identity , call The algorithm is initialized, then the system parameters are made public and the first private key is used. Confidential; The ground control center The publicly disclosed system parameters include the cyclic group order Generator First public key First hash function Second hash function Third hash function Fourth hash function Fifth hash function .

3. The method for constructing and authenticating access to a high-speed terminal group in a satellite network according to claim 2, characterized in that: The ground control center Publicly disclose system parameters and the first private key Confidentiality specifically includes: The ground control center Select Elliptic Curve Choose the order as Cyclic group and generator ; The ground control center Select the first random number As the first private key; based on the first private key Generator Calculate the first public key The corresponding expression is: Based on elliptic curves Cyclic groups The ground control center Choose the first hash function respectively Second hash function Third hash function Fourth hash function Fifth hash function ;in, Represents a zero- or one-bit string of arbitrary length; Describes the set of non-zero elements and is expressed as follows: A multiplication group of order 1.

4. The method for constructing and authenticating access to a high-speed terminal group in a satellite network according to claim 1 or 3, characterized in that: The ground control center High-speed terminal groups and access point Configuring identity and shared keys specifically includes: The ground control center Group members Access point Group owner Choose a second identity Third identity Fourth identity ;in, ; ; The group members Select the second random number As a second private key; the access point Select a third random number As a third private key; the group owner Select the fourth random number As the fourth private key; the second random number Third random number Fourth random number ;in: Describes the set of non-zero elements and is expressed as follows: A multiplication group of order 1; Based on the second private key Ground control center generator Computation group members Second public key Based on the third private key Ground control center generator Calculate access point The third public key Based on the fourth private key Ground control center generator Calculate the group owner The fourth public key The corresponding calculation expressions are as follows: The group members group members Second identity Second public key Send to ground control center Afterwards, the ground control center Calling Algorithm Generate group members The fifth private key and the fifth public key The ground control center Calling Algorithm Generate group members The fifth private key and the fifth public key Specifically, it includes: The ground control center Select the fifth random number And calculate the fifth public key. The ground control center Calculate the fifth private key The ground control center Return the fifth public key Fifth private key ;in, Indicates the first hash function; Indicates ground control center The first public key; The access point Access point The third identity Third public key Send to ground control center Afterwards, the ground control center Calling Algorithm Generate access point The sixth private key and the sixth public key The ground control center Calling Algorithm Generate access point The sixth private key and the sixth public key Specifically, it includes: The ground control center Choose a sixth random number And calculate the sixth public key. The ground control center Calculate the sixth private key The ground control center Return the sixth public key Sixth private key ; The group owner group owner The fourth identity Fourth public key Send to ground control center Afterwards, the ground control center Calling Algorithm Generate group owner The seventh private key and the seventh public key The ground control center Calling Algorithm Generate group owner The seventh private key and the seventh public key Specifically, it includes: The ground control center Select the seventh random number And calculate the seventh public key. The ground control center Calculate the seventh private key The ground control center Return the seventh public key 7th Private Key ; Based on group members Second public key Fifth public key Get group members First complete public key Based on group members Second private key Fifth private key Get group members First complete private key Based on access point The third public key The sixth public key Get access point Second complete public key Based on access point The third private key Sixth private key Get access point Second complete private key Based on the group owner The fourth public key The seventh public key Get the group owner The third complete public key Based on the group owner The fourth private key 7th Private Key Get the group owner The third complete private key .

5. The method for constructing and authenticating access to a high-speed terminal group in a satellite network according to claim 4, characterized in that: The group owner and group members The mutual verification between them specifically includes: The group owner Generate the eighth random number and call the algorithm Generate the first signature The group owner Calling Algorithm Generate the first signature Specifically, it includes: Group owner calculate , Group owner calculate ;but ; in, group members The first complete public key; group members Second identity ; Indicates ground control center The first public key; Indicates ground control center generator ; Each represents the first signature Partial signature in the document; Indicates intermediate quantity; Indicates intermediate quantity; Indicates the second hash function; This indicates the first piece of information, including the group owner. The fourth identity Third complete public key ; The group owner The fourth private key The group owner The seventh private key; Describes the set of non-zero elements and is expressed as follows: A multiplication group of order 1; Group owner To group members First Signature on Broadcast and first information ; The group members Received first signature and first information Then, call the algorithm. Verify group owner The identity of the group members; Calling Algorithm Verify group owner The specific identities include: Group members calculate Group members Analyzing the first information Get the group owner The third complete public key and the fourth identity Group members calculate Group members examine The signature is verified by checking if they are equal; where: Indicates intermediate quantity; Indicates intermediate quantity; If verification is successful, group members To the group owner Send an access verification request and call the algorithm. To the group owner Output the second signature And the first ciphertext The group members Calling Algorithm To the group owner Output the second signature And the first ciphertext Specifically, it includes: Group members Select the ninth random number and calculate , Group members calculate , Group members Calculate separately ;but ; in, This indicates the second piece of information, including group members. A pair of random numbers generated Group members Second identity and the first complete public key ; The x-coordinate of a randomly selected point; Represents the ordinate of a randomly selected point; , These represent the second signature. Partial signature in the document; Indicates intermediate quantity; Indicates intermediate quantity; Indicates intermediate quantity; Indicates intermediate quantity; The group owner The fourth public key; The group owner The seventh public key; group members The second private key; group members The fifth private key; If verification fails, group members Will report to the group owner Send a verification failure response message; The group owner Received second signature And the first ciphertext Then, call the algorithm. For the first ciphertext Decryption is performed to obtain the second information. And verify the second signature Is this correct? The group owner mentioned... Calling Algorithm For the first ciphertext Decryption is performed to obtain the second information. And verify the second signature Whether it is correct specifically includes: Group owner calculate Group owner Analysis of group members Second information Get group members First complete public key 、 Group members Second identity Group members A pair of random numbers generated Group owner calculate and through inspection Verify signatures by checking for equality; in, The group owner The third complete private key; Indicates intermediate quantity; Indicates intermediate quantity; Indicates the XOR operation; If the second signature Correct, group owner Will store group members A pair of random numbers generated If the second signature Error, group owner Will inform group members Send a verification failure response message.

6. The method for constructing and authenticating access to a high-speed terminal group in a satellite network according to claim 5, characterized in that: The group owner and group members Sharing keys among groups specifically includes: The group owner Select the tenth random number And construct a [order] of [number]. interpolation polynomial , in order to pass One point, that is and ;in, The x-coordinate of a randomly selected point; The ordinate of a randomly selected point; The group owner exist Another option Points Generate timestamp and group shared key identifier Calculate message verification code and group shared key identifier Message verification code Group owner The fourth identity , Points timestamp Broadcast to group members ;in, Indicates the x-coordinate of the selected point; Represents the ordinate of the selected point; The group members Received group shared key identifier Message verification code Group owner The fourth identity , Points timestamp Then, use the random number stored within itself. recover Calculate the tenth random number And verify the message verification code. The validity of the message verification code; Valid, group members The tenth random number Save as group member The group shared key; if the message verification code Invalid, group owner Will inform group members Send a verification failure response message.

7. The method for constructing and authenticating access to a high-speed terminal group in a satellite network according to claim 1, characterized in that: In the group owner and group members Each terminal performs mutual authentication and group key sharing to complete the high-speed terminal group. The construction also includes dynamic updates of group members, specifically: When a new member joins, the new member first acts as the group owner. and group members The mutual verification phase between them, and then the group owner executes. and group members The group-shared key phase between; When a former member leaves, the former member should first inform the group owner. Send a departure notification, then execute the group owner's request. and group members The shared key phase between groups.

8. A method for constructing and authenticating access to a high-speed terminal group in a satellite network according to claim 1 or 6, characterized in that: The group owner To the access point Sending a verification request specifically includes: via access point Access to ground control center group owner Generate the eleventh random number and call the algorithm Generate a third signature The group owner Calling Algorithm Generate a third signature Specifically, it includes: Group owner calculate , Group owner calculate ;but ; in: Indicates ground control center The first public key; Indicates ground control center generator; Indicates access point A third identity; Indicates intermediate quantity; Indicates intermediate quantity; The group owner Access point The required third information; Indicates access point The third private key; Indicates access point The sixth private key; 、 These represent the third signature. Partial signature in the document; Based on the fourth hash function The tenth random number Group shared key identifier Ground control center First identity Calculate the group owner With ground control center The first key between Based on the fifth hash function Eleventh random number Group owner With ground control center The first key between Calculate the second ciphertext The corresponding calculation expressions are as follows: in, Indicates the XOR operation; The group owner The third complete private key; Indicates access point The second complete public key; The group owner To the access point Send third signature Group owner Access point Required third information Second ciphertext .

9. The method for constructing and authenticating access to a high-speed terminal group in a satellite network according to claim 8, characterized in that: The access point Forward the access verification request to the ground control center Specifically, it includes: The access point Received third signature Group owner Access point Required third information Second ciphertext Then, call the algorithm. Verify third signature The access point Calling Algorithm Verify third signature Specifically, it includes: Access point Receive third information as an access request message. And calculate Access point calculate Access point examine Verify signatures by checking for equality; in: Indicates intermediate quantity; 、 These represent the third signature. Partial signature in the document; Indicates access point The third private key; Indicates the second hash function; Indicates access point A third identity; Indicates intermediate quantity; Indicates the first hash function; The group owner The fourth identity ; The group owner The fourth public key; The group owner The seventh public key; Indicates ground control center The first public key; Indicates ground control center generator ; Indicates access point The second complete private key; If verification is successful, access point The second ciphertext and third signature Forwarded to ground control center If verification fails, the access point It will be sent to the ground control center Send a verification failure response message.

10. The method for constructing and authenticating access to a high-speed terminal group in a satellite network according to claim 9, characterized in that: The ground control center Then to the access point Send verification response, access point Forward the verification response to the group owner Group owner Verify the response and broadcast it to group members. To achieve high-speed terminal groups Ground control center Access point Secure communication between them specifically includes: The ground control center Received the second ciphertext and third signature Then, regarding the second ciphertext Decrypt and based on the second ciphertext. Fifth hash function 、 Third Signature Partial signatures in 、 First private key Calculate the group owner L With ground control center The first key between Based on the fourth hash function Group owner L With ground control center The first key between Group shared key identifier Access point The third identity Calculate the group owner L Access point The second key between The corresponding calculation expressions are as follows: in, Indicates the XOR operation; The ground control center Based on the fourth hash function Group owner L With ground control center The first key between Ground control center First identity Third Signature Partial signatures in Calculate response value The corresponding calculation expression is as follows: The access point Response value Forward to the group owner Group owner Verify response value and response value Broadcast to group members Ground Control Center Through the group owner L With ground control center The first key between With high-speed terminal group For secure communication; access point Through the group owner L Access point The second key between With high-speed terminal group To conduct secure communication.

Citation Information

Patent Citations

  • Method, device and system for quickly and safely switching authentication of high-speed mobile terminal

    CN115396887A

  • Ultra-high-speed terminal security access and intra-group security communication method in satellite network scene

    CN119233252A