Beidou communication electronic seal information encryption method based on SM9
Through the SM9-based encryption method, the Beidou communication short messages are clustered and encrypted, which solves the problems of inefficient encryption and high resource consumption in the existing technology, and realizes efficient and secure short message encryption and responsibility traceability.
Patent Information
- Application Number
- CN202510034604.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-09
- Publication Date
- 2025-05-27
AI Technical Summary
When the existing Beidou Communication electronic seal information encryption technology handles large-scale or high-frequency short message communication, there are application scenario restrictions in the environment of low encryption efficiency, excessive computing resource consumption, insufficient identity authentication, and resource-constrained application scenarios.
Using an SM9-based encryption method, a distance matrix is obtained by calculating the Euclidean distance between samples, and based on this, the contour coefficient calculation and hierarchical division are performed to generate short message clustering data. Then, an SM9 password recognition system is established, an identity-bound encryption key is generated, and a packet encryption and identity authentication is performed on Beidou communication short messages, and integrity checks and identity verification is performed.
It effectively reduces repeated encryption operations, improves encryption efficiency, enhances information security, and reduces the system's demand for computing resources, so that this technology can operate efficiently on resource-constrained terminal devices, and establishes a complete responsibility traceability chain.
Smart Images

Figure CN120050651A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication encryption technology, and in particular to a Beidou communication electronic seal information encryption method based on SM9. Background Art
[0002] Beidou communication electronic seal information encryption technology is a key component of the Beidou satellite navigation system. It is mainly used in military, emergency rescue and transportation fields to ensure the security, integrity and tamper-proofness of information transmission. Currently, the widely used encryption schemes include symmetric encryption and asymmetric encryption. Symmetric encryption (such as AES) can quickly complete the encryption and decryption operations of large amounts of data with its efficient data processing capabilities, which is particularly suitable for frequent short message communication scenarios in the Beidou system. However, symmetric encryption has significant defects in key management and distribution. Once the key is leaked, the security of the entire communication system will be seriously threatened. Although asymmetric encryption (such as RSA) shows high security in identity authentication and key exchange, it consumes a lot of computing resources. Especially when processing large-scale short messages, the encryption and decryption efficiency is significantly reduced, and higher requirements are placed on the system storage space.
[0003] The existing Beidou communication electronic seal information encryption technology has problems such as low encryption efficiency and excessive consumption of computing resources when processing large-scale or high-frequency short message communications. Specifically, the traditional encryption scheme fails to fully consider the similarity characteristics of short message data, resulting in repeated redundant encryption operations for similar messages; secondly, the existing technology is insufficient in identity authentication and responsibility tracing, making it difficult to effectively confirm the responsible person during the short message forwarding process, and is vulnerable to forgery and tampering attacks; finally, the high requirements of the existing encryption technology on system resources limit its application scenarios in resource-constrained environments. Summary of the invention
[0004] In view of the above-mentioned problems, the present invention is proposed.
[0005] Therefore, the present invention provides a Beidou communication electronic seal information encryption method based on SM9, which can solve the problems mentioned in the background technology.
[0006] In order to solve the above technical problems, the present invention provides the following technical solutions: a Beidou communication electronic seal information encryption method based on SM9, comprising: calculating the Euclidean distance between samples of Beidou communication short message data to obtain a distance matrix, and performing contour coefficient calculation and hierarchical division based on the distance matrix to generate short message clustering data;
[0007] Establishing an SM9 password identification system according to the short message clustering data, wherein the SM9 password identification system includes a password identification management center, a control center and an interactive function module, and is used to generate an encryption key for identity binding;
[0008] The encryption key is used to encrypt and forward the Beidou communication short message, wherein the encryption processing includes group encryption and identity authentication of the short message, and the forwarding verification includes integrity verification and identity verification of the encrypted short message.
[0009] As a preferred solution of the Beidou communication electronic seal information encryption method based on SM9 described in the present invention, the generation process of the distance matrix includes:
[0010] Collect Beidou communication short message sample space S, the sample space S contains n short message samples, any two short message samples x in the sample space S i With x j The Euclidean distance between them is denoted as d(x i ,x j );
[0011] Calculate each short message sample x in the sample space S i The average distance d(x i ):
[0012]
[0013] Extract the short message sample x with the largest average distance in the sample space S max :
[0014]
[0015] Remove the short message sample x max And construct the short message dataset M:
[0016] M=Sx max .
[0017] As a preferred solution of the Beidou communication electronic seal information encryption method based on SM9 described in the present invention, the calculation of the contour coefficient includes:
[0018] For each sample x i , calculate its silhouette coefficient s(x i ):
[0019]
[0020] Where: a(x i ) represents the sample x i The average distance to other samples in the same class;
[0021] b(x i ) represents the sample x i Minimum average distance to samples of other classes:
[0022]
[0023] As a preferred solution of the Beidou communication electronic seal information encryption method based on SM9 described in the present invention, the hierarchical division process includes:
[0024] Compute the average silhouette coefficient for the clusters:
[0025]
[0026] If S avg If the value is greater than the preset silhouette coefficient threshold, the clustering is stopped; otherwise, the clustering is re-performed according to the Euclidean distance between samples.
[0027] As a preferred solution of the Beidou communication electronic seal information encryption method based on SM9 described in the present invention, the working process of the SM9 password recognition system includes: generating a system master key according to a user identity identifier; generating a user identification key according to the system master key; receiving an inbound short message; extracting sender identification information from the inbound short message; verifying the sender identification information based on the user identification key; when the sender identification information is verified, generating a session key bound to the sender identification information; when the sender identification information is not verified, generating a verification failure message and sending it to the sender.
[0028] As a preferred solution of the Beidou communication electronic seal information encryption method based on SM9 described in the present invention, the encryption processing and forwarding verification process includes: determining a preset group length value according to the Beidou communication protocol; dividing the inbound short message into multiple short message groups according to the preset group length value; using the session key to encrypt the short message group to obtain an encrypted short message group; calculating a message authentication code based on the encrypted short message group; combining the encrypted short message group and the message authentication code into an encrypted short message package; sending the encrypted short message package to the target terminal; the target terminal verifies the message authentication code; when the message authentication code verification passes, using the session key to decrypt the encrypted short message group; when the message authentication code verification fails, sending a resend request to the sender.
[0029] As a preferred solution of the Beidou communication electronic seal information encryption method based on SM9 described in the present invention, before performing the distance matrix calculation, it also includes a data preprocessing process: acquiring short message data; normalizing the short message data to obtain standardized short message data; performing outlier detection on the standardized short message data to obtain preprocessed short message data; establishing a communication protocol stack; and transmitting the preprocessed short message data through the communication protocol stack.
[0030] To further solve the above technical problems, the present invention provides the following technical solutions: A system for encrypting Beidou communication electronic seal information based on SM9, comprising: a data acquisition module for acquiring Beidou communication short message data;
[0031] A cluster processing module, used for calculating the Euclidean distance between samples to obtain a distance matrix, and performing silhouette coefficient calculation and hierarchical division based on the distance matrix to generate short message clustering data;
[0032] A key management module, used to establish an SM9 password identification system according to the short message clustering data, wherein the SM9 password identification system includes a password identification management center, a control center and an interactive function module, and is used to generate an encryption key bound to an identity;
[0033] The message encryption module is used to use the encryption key to encrypt and forward the Beidou communication short message, wherein the encryption processing includes group encryption and identity authentication of the short message, and the forwarding verification includes integrity verification and identity verification of the encrypted short message.
[0034] A computer device includes a memory and a processor, wherein the memory stores a computer program, and is characterized in that when the processor executes the computer program, the steps of the Beidou communication electronic seal information encryption method based on SM9 as described above are implemented.
[0035] A computer-readable storage medium having a computer program stored thereon, characterized in that when the computer program is executed by a processor, the steps of the Beidou communication electronic seal information encryption method based on SM9 as described above are implemented.
[0036] The beneficial effects of the present invention are as follows: the present invention pre-processes and classifies Beidou communication short message data through a segmentation hierarchical clustering algorithm, establishes a dynamic clustering mechanism based on the silhouette coefficient, realizes unified processing of similar short messages, effectively reduces repeated encryption operations, and solves the problem of waste of computing resources caused by repeated encryption of similar messages in traditional schemes; the forwarding verification model constructed through the SM9 recognition password algorithm binds password identification to user identity, and while ensuring the security of message encryption, a complete responsibility tracing chain is established, overcoming the technical defects of the separation of identity authentication and message security in the prior art; the group encryption mechanism based on the clustering results, combined with the communication application protocol and the receiving information protocol, significantly reduces the system's demand for computing resources while ensuring the security of data transmission, so that the technology can run efficiently on resource-constrained terminal devices; in addition, the hierarchical clustering architecture adopted by the present invention has adaptive characteristics, and can dynamically adjust the clustering parameters according to the communication load, while ensuring encryption efficiency and maintaining system stability, solving the performance bottleneck problem of traditional encryption schemes in large-scale short message processing. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative work.
[0038] Figure 1 is a flow chart of the overall method in the present invention;
[0039] Figure 2 is a system flow chart of the present invention;
[0040] Figure 3 This is a flow chart of split hierarchical clustering in the present invention;
[0041] Figure 4 It is a schematic diagram of the short message forwarding verification model in the present invention;
[0042] Figure 5 This is a diagram of a computer device in the present invention. DETAILED DESCRIPTION
[0043] In order to make the above-mentioned purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the drawings of the specification. Obviously, the described embodiments are part of the embodiments of the present invention, but not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary persons in the art without creative work should fall within the scope of protection of the present invention.
[0044] In the following description, many specific details are set forth to facilitate a full understanding of the present invention, but the present invention may also be implemented in other ways different from those described herein, and those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.
[0045] Example 1, reference Figure 1 , Figure 3 and Figure 4 , as an embodiment of the present invention, provides a Beidou communication electronic seal information encryption method based on SM9.
[0046] Figure 1 The overall flow chart of a Beidou communication electronic seal information encryption method based on SM9 is shown, comprising: S1: calculating the Euclidean distance between samples of Beidou communication short message data to obtain a distance matrix, and performing contour coefficient calculation and hierarchical division based on the distance matrix to generate short message clustering data;
[0047] S2: Establishing an SM9 password identification system based on short message clustering data. The SM9 password identification system includes a password identification management center, a control center, and an interactive function module, and is used to generate an encryption key bound to an identity;
[0048] S3: Use the encryption key to encrypt and forward the Beidou communication short message, where the encryption processing includes group encryption and identity authentication of the short message, and the forwarding verification includes integrity verification and identity verification of the encrypted short message.
[0049] It should be noted that, first, the Euclidean distance between samples of Beidou communication short message data is calculated to obtain a distance matrix, and the contour coefficient is calculated and hierarchical division is performed based on the distance matrix to generate short message clustering data. This step innovatively introduces the hierarchical clustering algorithm into the field of Beidou short message encryption. By identifying and classifying similar short messages, it solves the problem of waste of computing resources caused by independent encryption of each short message in traditional encryption schemes. Especially in the application scenario where a large number of short messages in the Beidou system have similar content, this adaptive clustering method based on the contour coefficient can dynamically adjust the classification granularity, significantly improving the processing efficiency while ensuring encryption security.
[0050] Secondly, an SM9 password recognition system is established based on short message clustering data. The system includes a password recognition management center, a control center, and an interactive function module to generate identity-bound encryption keys. This step breaks through the technical limitations of the separation of identity authentication and message encryption in traditional encryption schemes. By combining the SM9 password recognition algorithm with the clustering results, a differentiated identity authentication mechanism based on data features is realized. This mechanism not only ensures the credibility of the identity of the message sender, but also dynamically adjusts the authentication strategy according to the clustering characteristics, thereby reducing the authentication overhead and improving the system security.
[0051] Finally, the encryption key is used to encrypt and forward the Beidou communication short message, where the encryption process includes group encryption and identity authentication of the short message, and the forwarding verification includes integrity check and identity verification of the encrypted short message. This step integrates encryption processing and forwarding verification to establish a complete message security transmission chain. Compared with the existing technology, this integrated processing method not only avoids the performance loss caused by multiple verifications, but also optimizes the group encryption strategy by reusing clustering information, so that the system can significantly reduce resource consumption while maintaining high security.
[0052] The organic combination of the above three steps constructs a complete technical solution from data preprocessing, identity authentication to secure transmission. This solution identifies short message features through cluster analysis and implements differentiated identity authentication and encryption strategies in combination with the SM9 algorithm, significantly improving system performance while ensuring security. Especially in the application scenario of frequent transmission of Beidou short messages, the solution can adaptively adjust the processing strategy according to data features, achieving the optimal balance between security, efficiency and resource consumption. This adaptive encryption solution based on data features is an important breakthrough in the existing Beidou communication encryption technology.
[0053] Furthermore, the distance matrix generation process includes:
[0054] Collect Beidou communication short message sample space S, the sample space S contains n short message samples, any two short message samples x in the sample space S i With x j The Euclidean distance between them is denoted as d(x i ,x j );
[0055] Calculate each short message sample x in the sample space S i The average distance d(x i ):
[0056]
[0057] Extract the short message sample x with the largest average distance in the sample space S max :
[0058]
[0059] Remove short message sample x max And construct the short message dataset M:
[0060] M=Sx max .
[0061] Furthermore, the calculation of the silhouette coefficient includes:
[0062] For each sample x i , calculate its silhouette coefficient s(x i ):
[0063]
[0064] Where: a(x i ) represents the sample x i The average distance to other samples in the same class;
[0065] b(x i ) represents the sample x i Minimum average distance to samples of other classes:
[0066]
[0067] Furthermore, the hierarchical division process includes:
[0068] Compute the average silhouette coefficient for the clusters:
[0069]
[0070] If S avg If the value is greater than the preset silhouette coefficient threshold, the clustering is stopped; otherwise, the clustering is re-performed according to the Euclidean distance between samples.
[0071] It should be noted that the main purpose here is to solve the technical problems of low classification accuracy and low processing efficiency of short message data in Beidou communication.
[0072] Before performing the distance matrix calculation, data preprocessing needs to be completed. Specifically, a four-layer communication protocol stack is used to transmit data, which includes from bottom to top: the physical layer is responsible for bit stream transmission, the link layer performs error control, the network layer handles routing selection, and the application layer performs data preprocessing. The preprocessing uses the Z-score standardization method to normalize the data to a distribution with a mean of 0 and a standard deviation of 1, and at the same time uses an outlier detection method based on the 3σ principle to identify and process abnormal data. Although this preprocessing method is common, in the present invention, it is closely combined with the subsequent clustering process to significantly improve the accuracy of clustering.
[0073] The classification set division of the present invention adopts a method combining density and distance. First, based on the Euclidean distance d(x i ,x j ) Calculate the average distance d(x) of the samples i ), select the sample with the largest average distance as the classification starting point. By setting the local density threshold ρ 0 = 0.5 (empirical value), the sample space S is initially divided into k category sets. The key point of this method is to determine the number of categories k through adaptive density threshold, avoiding the limitation of the traditional K-means algorithm that the number of categories must be specified in advance.
[0074] The key to calculating the silhouette coefficient is to reasonably determine the threshold. Through a large number of experiments, it is verified that in the Beidou short message scenario, the average silhouette coefficient S avg The optimal threshold range of is [0.65, 0.75]. This is because this range can achieve a good balance between clustering accuracy and computational efficiency: when S avg When it is lower than 0.65, it indicates that the intra-class difference is too large; when it is higher than 0.75, although the clustering effect is better, the computational overhead increases significantly. The present invention selects 0.7 as the threshold value and achieves good results in practical applications.
[0075] Taking a Beidou communication scenario as an example, 1000 short messages containing location information are clustered and analyzed. These messages can be divided into three categories: static location information, low-speed mobile information, and high-speed mobile information. Using the method of this embodiment, the clustering process takes 1.2 seconds and the accuracy rate reaches 94.5%. Compared with the traditional method (taking 2.5 seconds and 86% accuracy), it not only improves the classification accuracy, but also reduces the computational overhead. This improvement stems from the density adaptive classification and contour coefficient dynamic evaluation mechanism proposed in the present invention. It not only solves the problem that the number of categories in the traditional method is difficult to determine, but also realizes the dynamic optimization of clustering quality through real-time feedback of the contour coefficient.
[0076] In summary, by organically combining preprocessing, density adaptive classification and silhouette coefficient evaluation, the processing efficiency is significantly improved while ensuring classification accuracy. Especially in the application scenario of Beidou short messages, where data features have high similarity and fast update frequency, the advantages of this solution are more obvious: first, the standardization and outlier processing in the preprocessing stage provide a reliable data basis for subsequent clustering; second, the density adaptive classification method avoids the errors that may be caused by manually specifying the number of categories; finally, the dynamic evaluation mechanism based on the silhouette coefficient ensures the reliability of the clustering results. In practical applications, this method is of great significance for improving the efficiency of subsequent encryption processing.
[0077] Further, the working process of the SM9 password identification system includes: generating a system master key according to a user identity identifier; generating a user identification key according to the system master key; receiving an inbound short message; extracting sender identification information from the inbound short message; verifying the sender identification information based on the user identification key;
[0078] When the sender identification information is verified, a session key bound to the sender identification information is generated; when the sender identification information is not verified, verification failure information is generated and sent to the sender.
[0079] It should be noted that the focus here is to solve the technical problems of separation of identity authentication and message encryption and inefficient key management in Beidou communications.
[0080] The SM9 password identification system adopts an identity-based password system. The password identification management center generates the system master key based on the user identity ID (including the user's unique identification code and validity period information). This process uses the SM9 algorithm standard specification issued by the National Cryptography Administration to generate keys and obtain the master private key and master public key. This identity-based key generation method avoids the complexity of certificate management in the traditional public key system.
[0081] In the stage of generating user identification key, the present invention focuses on binding the key to the user identity. By calculating the user identity ID and the master key, a private key sk bound to the user identity is generated. This method is different from the traditional key distribution scheme. It realizes the one-to-one correspondence between the key and the identity, significantly reducing the complexity of key management.
[0082] When the system receives an incoming short message, it first extracts the sender identification information from the message. Unlike traditional solutions, the present invention sets up an identity information cache mechanism in the control center. For users who communicate frequently, identity authentication can be completed quickly, effectively reducing the verification delay. When verifying the sender identification information based on the user identification key, a hierarchical verification strategy is adopted: first, a quick identity validity check is performed, and only messages that pass the preliminary verification are fully verified. This hierarchical verification mechanism significantly improves the system processing efficiency.
[0083] After the verification is passed, the system generates a session key bound to the sender's identification information. The present invention adopts a key negotiation mechanism based on the SM9 algorithm, and ensures the uniqueness and timeliness of the key by binding the session key to the identity and timestamp. When the verification fails, the system generates verification failure information containing the specific reason for failure, and returns it to the sender through the feedback channel, so that the sender can make targeted corrections.
[0084] In a certain actual application scenario, a system with 1,000 users was tested, and each user sent an average of 5 short messages per minute. Using the method of this embodiment, identity authentication takes an average of 20ms, and key generation takes an average of 15ms, which is more than 60% more efficient than the traditional solution (50ms for identity authentication and 40ms for key generation). Especially in high-frequency communication scenarios, the hierarchical verification mechanism can intercept 90% of illegal requests in the initial verification stage, significantly reducing the system load.
[0085] In summary, an efficient password recognition system is constructed by combining the SM9 algorithm with the identity binding mechanism. While ensuring security, the system significantly improves processing efficiency through hierarchical verification and caching mechanisms, which is particularly suitable for application scenarios where a large number of users frequently interact in Beidou communications. The system has good scalability. When the user scale expands, stable processing performance can be maintained by increasing cache capacity and optimizing verification strategies.
[0086] Furthermore, the encryption processing and forwarding verification process includes: determining a preset packet length value according to the Beidou communication protocol; dividing the inbound short message into a plurality of short message packets according to the preset packet length value; encrypting the short message packets using a session key to obtain encrypted short message packets; calculating a message authentication code based on the encrypted short message packets; composing an encrypted short message packet with the encrypted short message packets and the message authentication code; sending the encrypted short message packet to a target terminal; and the target terminal verifying the message authentication code;
[0087] When the message authentication code verification passes, the encrypted short message group is decrypted using the session key; when the message authentication code verification fails, a resend request is sent to the sender.
[0088] It should be noted that the encryption processing and forwarding verification process of Beidou communication short messages is mainly described here, focusing on solving the security risks caused by the single key in the existing technology and the integrity verification problem in the message forwarding process.
[0089] Based on the Beidou communication protocol standard, the present invention sets the preset length value of the short message grouping to 128 bytes. The selection of this length value comprehensively considers the typical length distribution (64-256 bytes) of Beidou short messages and encryption efficiency factors. The grouping process adopts a padding alignment mechanism. For short messages less than 128 bytes, the PKCS7 standard padding method is used to fill them to ensure that all group lengths are unified. This fixed-length grouping method is combined with the clustering results in the previous step, which can make full use of the encryption characteristics of similar messages and improve encryption efficiency.
[0090] The encryption of each short message group is processed using a session key. The present invention focuses on selecting an appropriate encryption mode using the clustering characteristics of the message. For message groups that are determined to have high similarity by cluster analysis, the CBC (Cipher Block Chaining) mode is used for encryption; for message groups with low similarity, the ECB (Electronic Code Book) mode is used for encryption. This adaptive encryption mode selection based on message characteristics not only ensures security, but also avoids unnecessary computing overhead.
[0091] The generation of the message authentication code adopts a MAC scheme based on the SM9 algorithm, which takes the encrypted short message group and the sender's identification information as input to generate a 32-byte authentication code. This scheme organically combines message integrity verification with identity authentication, solving the problem of separation between integrity verification and identity authentication in traditional schemes. The verification of the message authentication code adopts a two-level judgment mechanism: first, the validity of the authentication code is verified, and then the sender's identity information is verified. Failure in any link will trigger a retransmission request. In addition, the present invention introduces an exponential backoff algorithm in the retransmission mechanism. The initial retransmission waiting time is 100ms. The waiting time doubles after each retransmission failure, and the maximum does not exceed 1600ms, which effectively avoids network congestion.
[0092] Taking a certain actual scenario as an example, 1,000 short messages are processed, and the message lengths are distributed between 80 and 200 bytes. Using the method of this embodiment, the average encryption time for each message is 5ms, the authentication code generation time is 2ms, and the integrity verification time is 3ms. In the case of network fluctuations causing message retransmissions, 93% of the messages are transmitted within two retransmissions, and the average transmission delay increases by no more than 150ms. In particular, for message groups with high similarity, thanks to the reuse of clustering features and the selection of adaptive encryption modes, the processing efficiency is improved by 45% compared with the traditional solution. Experimental results show that the solution of the present invention significantly improves processing efficiency and system stability while ensuring security.
[0093] Furthermore, before calculating the distance matrix, a data preprocessing process is also included: obtaining short message data; normalizing the short message data to obtain standardized short message data; performing outlier detection on the standardized short message data to obtain preprocessed short message data; establishing a communication protocol stack; and transmitting the preprocessed short message data through the communication protocol stack.
[0094] In summary, the present invention pre-processes short message data by introducing a segmentation hierarchical clustering algorithm, realizes unified processing of similar short messages, and significantly improves encryption efficiency; at the same time, the SM9 identification password algorithm is used to construct a short message forwarding verification model, which strengthens identity authentication and responsibility tracing capabilities. The beneficial effects of the present invention include: improving encryption efficiency, enhancing information security, reducing system implementation costs, and improving system scalability and stability.
[0095] Example 2, reference Figure 2 , as an embodiment of the present invention, provides a Beidou communication electronic seal information encryption system based on SM9, including:
[0096] Data acquisition module, used to obtain Beidou communication short message data;
[0097] The cluster processing module is used to calculate the Euclidean distance between samples to obtain a distance matrix, and to calculate the silhouette coefficient and perform hierarchical division based on the distance matrix to generate short message clustering data;
[0098] The key management module is used to establish an SM9 password identification system based on short message clustering data. The SM9 password identification system includes a password identification management center, a control center and an interactive function module, and is used to generate an encryption key bound to an identity;
[0099] The message encryption module is used to use the encryption key to encrypt and forward the Beidou communication short message. The encryption process includes group encryption and identity authentication of the short message, and the forwarding verification includes integrity verification and identity verification of the encrypted short message.
[0100] Example 3, reference Figure 5 , is an embodiment of the present invention, which is different from the previous embodiment in that: if the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods of each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc. Various media that can store program codes.
[0101] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by an instruction execution system, device or apparatus (such as a computer-based system, a system including a processor, or other system that can fetch instructions from an instruction execution system, device or apparatus and execute instructions), or in conjunction with such instruction execution systems, devices or apparatuses. For the purposes of this specification, "computer-readable medium" can be any device that can contain, store, communicate, propagate or transmit a program for use by an instruction execution system, device or apparatus, or in conjunction with such instruction execution systems, devices or apparatuses.
[0102] More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection with one or more wires (electronic device), a portable computer disk case (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium may even be a paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering, or processing in another suitable manner as necessary, and then stored in a computer memory.
[0103] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware or a combination thereof. In the above-mentioned embodiments, a plurality of steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or their combination: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.
[0104] It is important to note that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.
Claims
1. A Beidou communication electronic seal information encryption method based on SM9, characterized in that: include: Calculating the Euclidean distance between samples of Beidou communication short message data to obtain a distance matrix, and performing contour coefficient calculation and hierarchical division based on the distance matrix to generate short message clustering data; Establishing an SM9 password identification system according to the short message clustering data, wherein the SM9 password identification system includes a password identification management center, a control center and an interactive function module, and is used to generate an encryption key for identity binding; The encryption key is used to encrypt and forward the Beidou communication short message, wherein the encryption processing includes group encryption and identity authentication of the short message, and the forwarding verification includes integrity verification and identity verification of the encrypted short message.
2. The Beidou communication electronic seal information encryption method based on SM9 as claimed in claim 1, characterized in that: The generation process of the distance matrix includes: Collect Beidou communication short message sample space S, the sample space S contains n short message samples, any two short message samples x in the sample space S i With x j The Euclidean distance between them is denoted as d(x i ,x j ); Calculate each short message sample x in the sample space S i The average distance d(x i ): Extract the short message sample x with the largest average distance in the sample space S max : x max =argmax xi∈S d(x i ); Remove the short message sample x max And construct the short message dataset M: M=S-x max 。 3. The Beidou communication electronic seal information encryption method based on SM9 as claimed in claim 2, characterized in that: The calculation of the silhouette coefficient includes: For each sample x i , calculate its silhouette coefficient s(x i ): Where: a(x i ) represents the sample x i The average distance to other samples in the same class; b(x i ) represents the sample x i Minimum average distance to samples of other classes:
4. The Beidou communication electronic seal information encryption method based on SM9 as claimed in claim 3, characterized in that: The hierarchical division process includes: Compute the average silhouette coefficient for the clusters: If S avg If the value is greater than the preset silhouette coefficient threshold, the clustering is stopped; otherwise, the clustering is re-performed according to the Euclidean distance between samples.
5. The Beidou communication electronic seal information encryption method based on SM9 as claimed in claim 4, characterized in that: The working process of the SM9 password identification system includes: generating a system master key according to a user identity; generating a user identification key according to the system master key; receiving an inbound short message; extracting sender identification information from the inbound short message; and verifying the sender identification information based on the user identification key; When the sender identification information is verified, a session key bound to the sender identification information is generated; when the sender identification information is not verified, verification failure information is generated and sent to the sender.
6. The Beidou communication electronic seal information encryption method based on SM9 as claimed in claim 5, characterized in that: The encryption processing and forwarding verification process includes: determining a preset packet length value according to the Beidou communication protocol; dividing the inbound short message into a plurality of short message packets according to the preset packet length value; encrypting the short message packets using the session key to obtain encrypted short message packets; calculating a message authentication code based on the encrypted short message packets; composing an encrypted short message packet with the encrypted short message packets and the message authentication code; sending the encrypted short message packet to a target terminal; and the target terminal verifying the message authentication code; When the message authentication code verification passes, the encrypted short message group is decrypted using the session key; when the message authentication code verification fails, a resend request is sent to the sender.
7. The Beidou communication electronic seal information encryption method based on SM9 as claimed in claim 6, characterized in that: Before performing the distance matrix calculation, the method also includes a data preprocessing process: acquiring short message data; normalizing the short message data to obtain standardized short message data; performing outlier detection on the standardized short message data to obtain preprocessed short message data; establishing a communication protocol stack; and transmitting the preprocessed short message data through the communication protocol stack.
8. A system using the Beidou communication electronic seal information encryption method based on SM9 as described in any one of claims 1 to 7, characterized in that: include: Data acquisition module, used to obtain Beidou communication short message data; A cluster processing module, used for calculating the Euclidean distance between samples to obtain a distance matrix, and performing silhouette coefficient calculation and hierarchical division based on the distance matrix to generate short message clustering data; A key management module, used to establish an SM9 password identification system according to the short message clustering data, wherein the SM9 password identification system includes a password identification management center, a control center and an interactive function module, and is used to generate an encryption key bound to an identity; The message encryption module is used to use the encryption key to encrypt and forward the Beidou communication short message, wherein the encryption processing includes group encryption and identity authentication of the short message, and the forwarding verification includes integrity verification and identity verification of the encrypted short message.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the Beidou communication electronic seal information encryption method based on SM9 as described in any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, the steps of the Beidou communication electronic seal information encryption method based on SM9 described in any one of claims 1 to 7 are implemented.