A design method for onboard flexible reconfigurable access authentication protocol

By designing the satellite-based flexible reconfigurable access authentication protocol, using lightweight algorithms and flexible reconfigurable technology, the complexity and security problems of user equipment access authentication in the satellite network are solved, and an efficient and secure satellite-ground authentication process is achieved.

CN120150969BActive Publication Date: 2025-08-19XIDIAN UNIV +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510623845.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-15
Publication Date
2025-08-19
Estimated Expiration
2045-05-15

AI Technical Summary

Technical Problem

Traditional ground communication protocols are difficult to adapt to the dynamic network topology, resource limitations and large delay characteristics of satellite networks, resulting in complex user equipment access authentication and insufficient security.

Method used

The satellite-based flexible reconfigurable access authentication protocol is designed, and the lightweight algorithm and flexible reconfigurable technology are used to achieve safe authentication of satellite-based equipment and ground terminals through two-way authentication of satellite-ground, random number signatures and regular update of keys.

Benefits of technology

It reduces the computing resources consumption of satellite equipment, improves the security of the authentication process and data transmission efficiency, and enhances its resistance to potential security threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120150969B_ABST
    Figure CN120150969B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for designing a satellite-borne flexible reconfigurable access authentication protocol, which relates to the field of network security technology, including: designing a satellite-to-ground access authentication protocol based on the satellite measurement and control bandwidth; selecting a lightweight algorithm as the security algorithm of the access authentication protocol, and using flexible reconfigurable technology to implement encryption algorithm data updates; introducing random numbers in the authentication process to ensure the security of the authentication process; storing public keys, private keys, and data information in the authentication process in the satellite-borne device; storing the injection key and the negotiation key in the satellite-borne device, and regularly updating the injection key and the negotiation key; and implementing a reciprocating authentication process between the satellite-borne device and the ground terminal through authentication requests, authentication responses, and the establishment of a secure channel. The present invention reduces the computing resource consumption of the satellite-borne device by using a lightweight algorithm; introduces random numbers in the authentication process to improve the security of the authentication process; and utilizes flexible reconfigurable technology to enhance the authentication protocol's ability to resist potential security threats.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security, and in particular relates to a design method for a satellite-borne flexible reconfigurable access authentication protocol. Background Art

[0002] Satellite internet is a new heterogeneous network composed of space-based and terrestrial networks. Leveraging its vast satellite constellation and gateway nodes, it interconnects established terrestrial internet and mobile communication networks, enabling the interconnection, sharing, and efficient collaboration of information resources. Satellite internet is characterized by frequent network topology changes, limited network node resources, and significant satellite-to-ground transmission latency. Furthermore, because nodes in the network are highly exposed, the channels between them are open and highly vulnerable to attacks from attackers and adversaries. These characteristics present numerous challenges for traditional terrestrial communication protocols, such as 5G authentication and key agreement, in satellite networks. For example, the highly dynamic network topology complicates key management and distribution within the protocol, while limited network node resources make 5G protocols incapable of meeting the processing power and energy requirements of satellite networks. Furthermore, satellite-to-ground transmission latency can lead to sequence number synchronization issues, further impacting the protocol's real-time and reliability. Furthermore, channel loss and interference can cause packet loss, compromising the correctness of authentication signaling and message authentication code verification. Consequently, traditional terrestrial communication protocols, such as 5G, are difficult to directly apply to user device access scenarios in satellite networks.

[0003] To build a secure and efficient service network, the primary challenge is to resolve the issue of user device access authentication within the satellite network. Furthermore, terrestrial internet infrastructure is susceptible to natural disasters and other impacts, leading to communication service interruptions and significant economic losses. Therefore, it is necessary to design a user device re-authentication mechanism that operates under ground-based default conditions, eliminating the need for ground-based authentication, to ensure stable user access to satellite network communication services.

[0004] Current satellite technologies typically use either centralized authentication or signature-based authentication for access authentication. Centralized authentication involves a security control center performing access authentication. In this approach, the terminal transmits an authentication request to the security control center via a satellite base station and satellite. When a terminal needs to access the satellite network, it generates an access authentication request and sends it to the satellite base station. If the base station verifies the authentication request, it returns an access authentication response to the terminal. After successful authentication, the terminal then transmits access authentication and authorization to the security control center via satellite transmission. Once authenticated, the terminal can access satellite application system resources. In signature-based authentication, the terminal transmits the authentication request to the security control center via a satellite base station and satellite. When a terminal needs to access the satellite network, it generates an access authentication request and sends it to the satellite base station. If the base station verifies the authentication request, it generates and adds an identity signature to the terminal, creating a tamper-resistant and verifiable piece of information. Then, when user traffic reaches the access security control center, the signature is verified. If successful, the access control system trusts the user's identity.

[0005] Centralized authentication relies heavily on satellite communication base stations to verify authentication request information. This approach utilizes minimal satellite computing resources, but utilizes abundant ground computing resources, enabling highly secure protocols. However, this approach complicates data transmission and can lead to significant authentication transmission delays. Signature-based authentication requires fewer interactions, allowing direct access to satellite application systems after verifying the identity signature and access rights. This approach offers simple data transmission, short latency, and a good user experience, but the protocol lacks high security. Summary of the Invention

[0006] In order to solve the above problems existing in the prior art, the present invention provides a method for designing a satellite-based flexible reconfigurable access authentication protocol. The technical problem to be solved by the present invention is achieved through the following technical solutions:

[0007] The present invention provides a method for designing a satellite-borne flexible reconfigurable access authentication protocol, comprising:

[0008] Step 1: Based on the satellite TT&C bandwidth, design a satellite-to-ground access authentication protocol to achieve bidirectional authentication between satellite-borne equipment and ground terminals.

[0009] Step 2: Selecting a lightweight algorithm as the security algorithm of the access authentication protocol, wherein flexible reconfigurable technology is used to implement encryption algorithm data update;

[0010] Step 3: Introducing a random number in the two-way authentication process to ensure the security of the authentication process. In the two-way authentication process, the onboard device and the ground terminal respectively sign the random number using an encryption algorithm to generate a signature value, and the legitimacy of the identity is verified through the reciprocal authentication of the signature value;

[0011] Step 4: Storing the public key, private key and data information in the two-way authentication process in the onboard device;

[0012] Step 5: Storing the uplink key and the negotiated key in the onboard device, and regularly updating the uplink key and the negotiated key;

[0013] Step 6: Implement the reciprocal authentication process between the onboard device and the ground terminal through authentication request, authentication response and secure channel establishment.

[0014] In one embodiment of the present invention, in step 1, an S-band tracking and control link is selected to implement the satellite-to-ground access authentication protocol, wherein the protocol data field transmitted between the satellite and the ground does not exceed 444 bytes.

[0015] In one embodiment of the present invention, the lightweight algorithm is an asymmetric key signature algorithm.

[0016] In one embodiment of the present invention, a flexible reconfigurable technology is used to implement encryption algorithm data update, including:

[0017] The encryption algorithm is divided into several calculation configurations. Each calculation configuration contains part of the functions of the encryption algorithm. When the encryption algorithm is called, the algorithm function is completed through several calculation configurations. When the encryption algorithm is switched, the data of the different calculation configurations between the two encryption algorithms is updated.

[0018] In one embodiment of the present invention, the encryption algorithm data update is implemented using flexible reconfigurable technology, further comprising:

[0019] When a new encryption algorithm is updated from the ground terminal to the satellite-borne device, data of the calculation configuration that does not exist on the satellite-borne device is uploaded from the ground terminal to the satellite-borne device according to the calculation configuration of the new encryption algorithm.

[0020] In one embodiment of the present invention, step 3 includes:

[0021] During the two-way authentication process, the ground terminal sends a ground-to-satellite authentication request to the satellite device, where the ground-to-satellite authentication request includes a random number R1 and a ground terminal certificate; the satellite device uses an encryption algorithm to sign the random number R1 to generate a signature value S1, and sends the signature value S1 and the satellite-to-ground authentication request to the ground terminal, where the satellite-to-ground authentication request includes a random number R2 and a satellite device certificate; the ground terminal uses the encryption algorithm to sign the random number R2 to generate a signature value S2, and sends the signature value S2 and a session key to the satellite device; the satellite device verifies the signature value S2 and uses its own private key to restore the session key.

[0022] In one embodiment of the present invention, the data information includes: a satellite-borne equipment ID, a satellite-borne equipment certificate, a ground terminal ID, and a ground terminal certificate.

[0023] In one embodiment of the present invention, step 4 includes:

[0024] The onboard device ID, the onboard device certificate, the ground terminal ID, the ground terminal certificate, the public key and the private key are stored in the NAND FLASH of the onboard device in a file format.

[0025] In one embodiment of the present invention, step 5 includes:

[0026] The bet key and the negotiated key are stored in the SPI-FLASH of the onboard device, and the bet key and the negotiated key are regularly updated by actively sending remote control commands or setting expiration time.

[0027] Compared with the prior art, the present invention has the following beneficial effects:

[0028] The present invention provides a design method for a satellite-borne flexible reconfigurable access authentication protocol. By adopting a lightweight algorithm, the computing resource consumption of onboard equipment is reduced, thereby improving data transmission efficiency. The introduction of random numbers in the two-way authentication process enhances the unpredictability of signature values and improves the security of the authentication process. Utilizing flexible reconfigurable technology, the rapid switching and updating of encryption algorithms is achieved, thereby enhancing the authentication protocol's ability to resist potential security threats.

[0029] The above description is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present invention more obvious and easy to understand, the following preferred embodiments are specifically cited and described in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] Figure 1 This is a flow chart of a method for designing a satellite-borne flexible reconfigurable access authentication protocol provided by an embodiment of the present invention;

[0031] Figure 2 This is a schematic diagram of an encryption algorithm data update provided by an embodiment of the present invention;

[0032] Figure 3 This is a schematic diagram of an authentication process of a satellite-borne flexible reconfigurable access authentication protocol provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0033] In order to further illustrate the technical means and effects adopted by the present invention to achieve the predetermined purpose of the invention, the following is a detailed description of a design method for a satellite-borne flexible reconfigurable access authentication protocol proposed in accordance with the present invention, in conjunction with the accompanying drawings and specific implementation methods.

[0034] The aforementioned and other technical contents, features, and effects of the present invention are clearly presented in the following detailed description of the specific embodiments in conjunction with the accompanying drawings. Through the description of the specific embodiments, a deeper and more specific understanding of the technical means and effects adopted by the present invention to achieve the intended purpose can be obtained. However, the accompanying drawings are provided for reference and illustration purposes only and are not intended to limit the technical solutions of the present invention.

[0035] The embodiment of the present invention provides a method for designing a satellite-borne flexible reconfigurable access authentication protocol. Figure 1 , Figure 1 This is a flow chart of a method for designing a satellite-borne flexible reconfigurable access authentication protocol provided by an embodiment of the present invention. Figure 1 As shown, the design method of the satellite-borne flexible reconfigurable access authentication protocol of this embodiment may include the following steps:

[0036] Step 1: Based on the satellite measurement and control bandwidth, design a satellite-to-ground access authentication protocol to achieve two-way authentication between satellite-borne equipment and ground terminals.

[0037] In this embodiment, the ground terminal may be a satellite ground system or a mobile terminal.

[0038] Satellites usually use different frequency bands of measurement and control frequencies such as L, S, Ka, Q / V, and the corresponding measurement and control bandwidth will increase accordingly. However, because the satellite measurement and control bandwidth is usually low and there may be problems such as high latency and intermittent connection, the designed protocol must be efficient and try to reduce the number of communications and data volume while ensuring security.

[0039] In this embodiment, the S-band TT&C link is used to implement the satellite-to-ground access authentication protocol. To maximize the adaptability of the access authentication protocol, the protocol data field transmitted between the satellite and the ground does not exceed 444 bytes. Due to the narrow bandwidth of the S-band TT&C link and the telemetry rate of approximately 16 kb / s, only random numbers are used to generate the signature value, eliminating the need for certificates, reducing data transmission by 80%.

[0040] Step 2: Select a lightweight algorithm as the security algorithm for the access authentication protocol, wherein flexible reconfigurable technology is used to implement encryption algorithm data updates.

[0041] In this embodiment, the lightweight algorithm is an asymmetric key signature algorithm, which has low requirements on computing performance and is convenient for the authentication protocol to call.

[0042] In this embodiment, flexible reconfigurable technology is used to implement encryption algorithm data updates. The characteristics of the encryption algorithm are used to compress the data size required during the encryption algorithm update process, and it also supports uploading new lightweight algorithms from the ground.

[0043] Specifically, flexible reconfigurable technology is used to implement encryption algorithm data updates, including: dividing the encryption algorithm into several computing configurations, each computing configuration contains part of the functions of the encryption algorithm. When calling the encryption algorithm, the algorithm function is completed through several computing configurations. When switching the encryption algorithm, the data of the different computing configurations between the two encryption algorithms is updated.

[0044] Furthermore, the use of flexible reconfigurable technology to implement encryption algorithm data updates also includes: when updating the new encryption algorithm from the ground terminal to the satellite-borne device, uploading the data of the calculation configuration that does not exist on the satellite-borne device from the ground terminal to the satellite-borne device according to the calculation configuration of the new encryption algorithm.

[0045] See Figure 2 , Figure 2 Schematic diagram of an encryption algorithm data update provided by an embodiment of the present invention. Figure 2 The embodiment of the present invention uses the flexible reconfigurable technology to implement encryption algorithm data update.

[0046] like Figure 2 As shown, two encryption algorithms, Algorithm A and Algorithm B, are available for onboard use. Flexible reconfiguration technology divides each algorithm into several "computation configurations," each encompassing a portion of the algorithm's functionality. Leveraging the similarities between encryption algorithms, different algorithms can abstract certain common "computation configurations." When an encryption algorithm is called, several "computation configurations" are combined to perform the algorithm's functions. These "computation configurations" are executed sequentially to complete the encryption algorithm calculation. For example, Algorithm A consists of "computation configuration 1," "computation configuration 2," "computation configuration 3," and "computation configuration 4," while Algorithm B consists of "computation configuration 1," "computation configuration 5," "computation configuration 6," and "computation configuration 4." When an onboard application needs to switch from Algorithm A to Algorithm B, only "computation configuration 2" and "computation configuration 3" need to be updated, shortening the update time.

[0047] Furthermore, when updating a new encryption algorithm from a ground terminal to a satellite-based device, the algorithm's "computing configuration" is first analyzed to determine whether it exists on the satellite. Existing "computing configurations" do not need to be transferred again, rather than uploading all "computing configuration" data from the ground terminal to the satellite. For example, if the algorithm M to be updated is analyzed to consist of "computing configuration 7," "computing configuration 5," "computing configuration 4," and "computing configuration 1," "computing configuration 1," "computing configuration 4," and "computing configuration 5" already exist on the satellite-based device, only "computing configuration 7" needs to be uploaded from the ground terminal to the satellite-based device, significantly reducing the amount of data transmitted.

[0048] It is understandable that when a lightweight algorithm is selected as the security algorithm for the access authentication protocol, pre-made keys can be shared by the ground terminal and the satellite device to solve the bottleneck of limited computing resources of the satellite device. The pre-made keys are keys agreed upon by the ground terminal and the satellite device, and need to be pre-made in the ground terminal and the satellite device respectively; the number of bits of the encryption algorithm can also be trimmed to compress the data capacity that needs to be transmitted during each algorithm switching and update process, thereby completing the rapid switching of existing algorithms on the satellite device.

[0049] Step 3: Introduce random numbers in the two-way authentication process to ensure the security of the authentication process. In the two-way authentication process, the onboard equipment and the ground terminal respectively sign the random numbers through encryption algorithms to generate signature values, and verify the legitimacy of the identity through reciprocal authentication of the signature values.

[0050] In this embodiment, the onboard device and the ground terminal respectively use their own private keys to sign the random number through an encryption algorithm to generate a signature value.

[0051] See Figure 3 , Figure 3 This is a schematic diagram of an authentication process of a satellite-borne flexible reconfigurable access authentication protocol provided by an embodiment of the present invention. Figure 3 Specifically, during the two-way authentication process, the ground terminal sends a ground-to-satellite authentication request to the onboard device. The ground-to-satellite authentication request includes a random number R1 and the ground terminal's certificate. The onboard device uses an encryption algorithm to sign the random number R1 to generate a signature value S1. It then sends the signature value S1 and the ground-to-satellite authentication request to the ground terminal. The satellite-to-ground authentication request includes a random number R2 and the onboard device's certificate. The ground terminal also uses an encryption algorithm to sign the random number R2 to generate a signature value S2. It then sends the signature value S2 and the session key to the onboard device. The onboard device verifies the signature value S2 and uses its own private key to recover the session key. The session key is typically a symmetric key, derived from the negotiated key, and generated by the ground terminal.

[0052] In this embodiment, by exchanging certificates (ground terminal certificate and onboard device certificate), both parties can verify the legitimacy of each other's identities, relying on a trusted certificate authority (CA) system to prevent identity forgery. The signature mechanism (signature values S1 and S2) ensures that only the party in possession of the corresponding private key can generate a valid signature, further verifying identity authenticity and effectively defending against man-in-the-middle attacks. Both parties use random numbers (R1 and R2) during the authentication process to ensure the uniqueness of each session. Attackers cannot replay authentication requests by intercepting historical data because random numbers are unpredictable and single-use. The signature values (S1 and S2) are generated based on the random number and private key, ensuring that data has not been tampered with. Any modification of the random number or signature will be detected by the signature verification process, ensuring communication integrity. The signing process provides legal non-repudiation, and neither party can deny initiating the authentication.

[0053] Furthermore, the computational complexity of the signature and verification steps based on asymmetric encryption is manageable, making it suitable for resource-constrained scenarios that may exist in satellite-to-ground communications. The certificate mechanism is easily scalable and supports identity management for multiple devices, meeting the requirements of large-scale satellite networks. This embodiment effectively ensures entity trustworthiness, data confidentiality, and integrity in satellite-to-ground communications through bidirectional authentication, dynamic random numbers, digital signatures, and certificate mechanisms, while also providing a reliable session key foundation for subsequent secure communications.

[0054] Step 4: Store the public key, private key, and data information in the two-way authentication process in the onboard device.

[0055] In this embodiment, the data information includes: onboard device ID, onboard device certificate, ground terminal ID and ground terminal certificate. The public key is publicly distributed and used to encrypt data or verify digital signatures, while the private key is strictly confidential and used to decrypt data or generate digital signatures.

[0056] Optionally, the onboard device ID, onboard device certificate, ground terminal ID, ground terminal certificate, public key and private key can be stored in the NAND FLASH (a type of FLASH memory that uses a nonlinear macro unit mode internally) of the onboard device in file format for management and update.

[0057] Among them, the public key and private key involve the keys required for the security algorithm. Through storage and management, the public key and private key pair can be updated regularly or at any time to increase the difficulty of the security algorithm being cracked by the enemy. In this embodiment, by regularly updating the key pair, even if the attacker starts to crack the current key, the validity period of his cracking results is limited to the key replacement cycle. For example, if the key is rotated once a month, the attacker must crack the key within 30 days to be valuable, which greatly increases the cost of his attack. The leakage of a single key pair only affects the communication data within its validity period, rather than all historical or future communications. Through key lifecycle management, the impact of the leakage can be limited to a controllable time window. Even if part of the key is leaked, the overall system can still minimize the impact through rapid replacement.

[0058] Step 5: Store the uploaded key and negotiated key in the onboard device and update them regularly.

[0059] Optionally, the uplink key and negotiated key can be stored in the SPI-FLASH (FLASH using SPI communication) of the onboard device. These keys can be updated periodically by actively sending remote control commands or setting expiration times. The uplink key is the key that is uploaded to the spacecraft, while the negotiated key is generated through a key exchange protocol and can be used as a session key or master key. Regularly updating the uplink key and negotiated key allows for re-authentication and the formation of a new secure channel.

[0060] In this embodiment, SPI-FLASH, as a non-volatile memory, can store keys for a long time without losing them during power outages. Hardware isolation (e.g., independent storage chips) or secure partitioning reduces the risk of keys being illegally read by other software modules. Combined with SPI-FLASH read and write permission control (e.g., hardware encryption modules or secure boot mechanisms), only authorized processes are allowed to access the key storage area, protecting against malware and unauthorized operations. Key expiration times (e.g., triggered by a timer or issued by a command) enforce regular key updates to prevent the risk of leakage caused by long-term key use. For example, automatic expiration every 24 hours meets the requirements of short-term sessions in high-security scenarios, or key resets are proactively triggered upon detecting abnormal behavior (e.g., multiple authentication failures). Even if the current key is leaked, its limited validity period and the proactive deprecation of the old key prevent attackers from using it to decrypt historical communication data or forge future sessions, further enhancing forward security. Actively deactivating the key by sending a remote control command (e.g., when a satellite is under attack) quickly eliminates potential threats and prevents continued key misuse. Forced re-authentication and generation of a new key after key expiration ensures the freshness of the communication channel, effectively countering persistent, latent attacks.

[0061] Understandably, the expiration period can be dynamically adjusted based on business needs (e.g., shortened during mission-critical phases and extended during idle phases), balancing security and performance overhead. Ground terminals can remotely update key policies via commands, adapting to the fact that satellites cannot be physically maintained while in orbit.

[0062] This embodiment significantly enhances the key system's attack resistance and lifecycle security through dynamic key management and active failure control. It is particularly suitable for long-term on-orbit operations of remote unmanned equipment such as satellites. Combined with a two-way authentication mechanism, it forms a full-link security closed loop of "authentication-key agreement-key rotation," providing continuous and resilient security for satellite-to-ground communications.

[0063] Step 6: Implement the back-and-forth authentication process between the onboard equipment and the ground terminal through authentication request, authentication response and secure channel establishment.

[0064] In this embodiment, if Figure 3 As shown in the figure, during the ground-to-satellite authentication request, the return of the authentication response, the sending of the authentication response, and the establishment of the secure channel, the onboard device and the ground terminal each generate and sign a random number, completing the round-trip authentication process. After the two-way authentication is complete, the onboard device and the ground terminal each calculate and generate a new session key and establish a secure channel for the confidentiality and integrity protection of subsequent business data.

[0065] The design method of a satellite-borne flexible reconfigurable access authentication protocol in an embodiment of the present invention implements functions such as bidirectional identity authentication, confidentiality of management information, and integrity protection between satellite-borne equipment and ground terminals. The ground-to-ground access authentication process includes authentication request, authentication response, and secure channel establishment, which provides security protection for authentication messages between devices. The authentication process requires the use of random numbers, certificates, and other means to generate signature values, and message integrity protection is achieved through the signature value. Direct identity authentication at the ground terminal and the use of flexible reconfigurable technology reduce the data capacity required for each encryption algorithm function update, making it possible to quickly switch on-board algorithms and update ground control algorithms. This solves the problems of limited on-board computing resources and low strength of lightweight encryption and decryption algorithms, while improving system-level security.

[0066] In addition, through the integration of space and ground, the risks of illegal exploitation by malicious users, the implantation of viruses, Trojans and other malicious codes or programs can be resisted, ensuring the security of the data transmission channel between satellite-borne equipment and ground terminals and the legitimacy of their identities.

[0067] It is understood that the network entity "onboard equipment" involved in this embodiment can be replaced by access points such as "5G base stations" and "ground gateways." That is, the location-key-based networking authentication process between the onboard equipment and the ground terminal in this embodiment can also be applied to the identity authentication and key agreement between Satellite A / Satellite B and the ground station. Specifically, the ground station verifies the satellite's true identity based on the satellite's location key, and the satellite verifies the legitimacy of the ground station's identity based on information such as the ground station's geographic location, thereby completing satellite-to-ground authentication and key agreement.

[0068] It should be noted that, in this document, relational terms such as first and second are used solely to distinguish one entity or operation from another, and do not necessarily require or imply any actual relationship or order between these entities or operations. Furthermore, the terms "comprise," "include," or any other variations thereof are intended to encompass non-exclusive inclusion, such that an article or device comprising a list of elements includes not only those elements but also other elements not explicitly listed. Without further limitation, an element defined by the phrase "comprising a..." does not preclude the presence of additional identical elements in the article or device comprising the element. Terms such as "connected" or "connected" are not limited to physical or mechanical connections but may include electrical connections, whether direct or indirect. References to orientations or positional relationships, such as "upper," "lower," "left," and "right," are based on the orientations or positional relationships shown in the accompanying drawings and are intended solely to facilitate description and simplify the description of the present invention. They do not indicate or imply that the device or element referred to must have, be constructed, or operate in a specific orientation, and are therefore not to be construed as limiting the present invention.

[0069] In the description of this specification, the reference terms "one embodiment," "some embodiments," "example," "specific example," or "some examples" mean that the specific features or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features or characteristics described can be combined in any suitable manner in one or more embodiments or examples. In addition, those skilled in the art can combine and combine different embodiments or examples described in this specification.

[0070] The above is a further detailed description of the present invention in conjunction with specific preferred embodiments, and the specific implementation of the present invention should not be considered to be limited to these descriptions. For those skilled in the art of the present invention, without departing from the concept of the present invention, several simple deductions or substitutions can be made, which should be considered to fall within the scope of protection of the present invention.

Claims

1. A design method for a satellite-borne flexible reconfigurable access authentication protocol, characterized in that: include: Step 1: Based on the satellite TT&C bandwidth, design a satellite-to-ground access authentication protocol to achieve bidirectional authentication between satellite-borne equipment and ground terminals. Step 2: Selecting a lightweight algorithm as the security algorithm of the access authentication protocol, wherein flexible reconfigurable technology is used to implement encryption algorithm data update; The flexible reconfigurable technology is used to implement encryption algorithm data update, including: The encryption algorithm is divided into several calculation configurations. Each calculation configuration contains part of the encryption algorithm's functions. When the encryption algorithm is called, the algorithm function is completed through several calculation configurations. When the encryption algorithm is switched, the data of the different calculation configurations between the two encryption algorithms is updated. When updating a new encryption algorithm from the ground terminal to the onboard device, uploading data of the calculation configuration that does not exist on the onboard device from the ground terminal to the onboard device according to the calculation configuration of the new encryption algorithm; Step 3: Introducing a random number in the two-way authentication process to ensure the security of the authentication process. In the two-way authentication process, the onboard device and the ground terminal respectively sign the random number using an encryption algorithm to generate a signature value, and the legitimacy of the identity is verified through the reciprocal authentication of the signature value; Step 4: Storing the public key, private key and data information in the two-way authentication process in the onboard device; Step 5: Storing the uplink key and the negotiated key in the onboard device, and regularly updating the uplink key and the negotiated key; Step 6: Implement the reciprocal authentication process between the onboard device and the ground terminal through authentication request, authentication response and secure channel establishment.

2. The method for designing a satellite-borne flexible reconfigurable access authentication protocol according to claim 1, characterized in that: In step 1, the S-band tracking and control link is selected to implement the satellite-to-ground access authentication protocol, wherein the protocol data field transmitted between the satellite and the ground does not exceed 444 bytes.

3. The method for designing a satellite-borne flexible reconfigurable access authentication protocol according to claim 1, wherein: The lightweight algorithm is an asymmetric key signature algorithm.

4. The method for designing a satellite-borne flexible reconfigurable access authentication protocol according to claim 1, wherein: The step 3 comprises: During the two-way authentication process, the ground terminal sends a ground-to-satellite authentication request to the satellite device, where the ground-to-satellite authentication request includes a random number R1 and a ground terminal certificate; the satellite device uses an encryption algorithm to sign the random number R1 to generate a signature value S1, and sends the signature value S1 and the satellite-to-ground authentication request to the ground terminal, where the satellite-to-ground authentication request includes a random number R2 and a satellite device certificate; the ground terminal uses the encryption algorithm to sign the random number R2 to generate a signature value S2, and sends the signature value S2 and a session key to the satellite device; the satellite device verifies the signature value S2 and uses its own private key to restore the session key.

5. The method for designing a satellite-borne flexible reconfigurable access authentication protocol according to claim 1, wherein: The data information includes: onboard equipment ID, onboard equipment certificate, ground terminal ID and ground terminal certificate.

6. The method for designing a satellite-borne flexible reconfigurable access authentication protocol according to claim 5, characterized in that: The step 4 comprises: The onboard device ID, the onboard device certificate, the ground terminal ID, the ground terminal certificate, the public key and the private key are stored in the NAND FLASH of the onboard device in a file format.

7. The method for designing a satellite-borne flexible reconfigurable access authentication protocol according to claim 1, wherein: The step 5 comprises: The bet key and the negotiated key are stored in the SPI-FLASH of the onboard device, and the bet key and the negotiated key are regularly updated by actively sending remote control commands or setting expiration time.

Citation Information

Patent Citations

  • Inter-satellite networking authentication system and method suitable for double-layer satellite network

    CN108566240A

  • Space-ground integrated network anonymous access authentication method based on identity encryption system

    CN111314056A