Password synchronization method and system based on Beidou time
By utilizing the one-way incremental characteristics of Beidou, the security and equipment life problems of wireless communication systems in the case of channel resources shortage are solved, and efficient password synchronization methods and system application security are achieved.
Patent Information
- Application Number
- CN202510323529.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-19
- Publication Date
- 2025-06-17
AI Technical Summary
In the case of shortage of channel resources, existing wireless communication systems are difficult to transmit resources through limited channel, which not only ensures system service security but does not reduce the service life of the equipment.
When Beidou is used as the construction factor for password synchronization data, the one-way incremental characteristics of Beidou are used to construct password synchronization data to reduce the use of system channel transmission resources, and the one-way uniqueness of password synchronization data is ensured through identification information and extended information.
It effectively reduces the occupation of system channel transmission resources, strictly ensures the one-way increment of password synchronization data, reduces the probability of password reuse, improves the security of system applications, and extends the service life of the equipment.
Smart Images

Figure CN120165852A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and particularly to a password synchronization method and system based on Beidou time. Background Art
[0002] In a wireless communication system, it is usually necessary to rely on the system channel to transmit password synchronization data to ensure the password synchronization of both communication parties, so as to realize the encryption protection of the system service data. In order to ensure the security of system service applications, the password synchronization data used each time should be different from each other.
[0003] The existing password synchronization technologies generally calculate whether the reuse probability of password synchronization data meets the security requirements of system applications by providing a variable amount of a certain bit length space. The lower the reuse probability, the more secure it is, but it also means that more channel transmission resources need to be occupied. In addition, password synchronization can also be achieved by designing a counting mechanism that can strictly ensure one-way non-repetition, which can also ensure the security of system applications. For this password synchronization counting mechanism, one is to achieve counting by applying a certain type of one-way information (such as time element, etc.) provided by the application system; the other is to be implemented by the device in a way of real-time recording and storing the count. The method of using the time element of the application system will lead to complex system construction, high maintenance costs, and it is difficult to effectively ensure the accuracy and non-repetition of the time element; while the method of the device's real-time recording and storing the count can ensure that the count is not lost and not repeated when the power is off, thus realizing the security of system applications, but it will frequently erase the non-volatile memory of the device, ultimately resulting in the failure of the non-volatile memory device (the number of erasable times is generally 100,000 times, and the actual usage times may be lower), reducing the service life of the device. To sum up, due to the relatively scarce channel resources of the wireless communication system, it may not be able to provide the channel transmission resources for the bit change length of the password synchronization data required for application security. In such extreme cases, how to transmit limited password synchronization data through the system channel, which can not only ensure the security of system services but also not reduce the service life of the device, is a technical problem that the password synchronization technology urgently needs to study and solve.
[0004] How to make full use of the accuracy and high reliability of Beidou time, introduce Beidou time as an input, give play to its one-way increasing characteristics, and use fewer channel resources to solve the following technical problems:
[0005] (1) When the application system cannot meet the channel resource occupancy requirements of the traditional password synchronization method, how to design a new password synchronization method to effectively respond and solve it;
[0006] (2) When there are multiple users in the application system communicating concurrently, how to effectively ensure the one-way uniqueness of password synchronization data to meet the security requirements of system applications;
[0007] (3) When communicating with a single user frequently, how to solve the problem of one-way uniqueness of password synchronization data to achieve system application security. Summary of the Invention
[0008] To overcome the deficiencies of the prior art, the present invention provides a password synchronization method and system based on Beidou time, which solves the problems such as occupying channel resources existing in the prior art.
[0009] The technical solution adopted by the present invention to solve the above problems is:
[0010] A password synchronization method based on Beidou time constructs password synchronization data based on Beidou time, and encrypts and / or decrypts service data using the password synchronization data when communicating between a communication sender and a communication receiver.
[0011] As a preferred technical solution, the service data frame transmitted by communication includes Beidou time, password synchronization data K, service data, and other fields.
[0012] As a preferred technical solution, it includes the following steps:
[0013] S1. The sending user sends the local Beidou time T1, password synchronization data, service data data to be encrypted, and other field information to the sending password unit according to the service data frame format.
[0014] S2. The sending password unit constructs password synchronization data K based on Beidou time T1, and encrypts the service data data using the password synchronization data K and the working key to obtain the encrypted service data data_enc; then fills the password synchronization data K and the encrypted service data data_enc into the service data frame and returns it to the sending user.
[0015] S3. The sending user sends the password synchronization data K, the encrypted service data data_enc, and other fields in the service data to the receiving user.
[0016] S4. After receiving the service data sent by the sending user, the receiving user sends the service data to the receiving password unit according to the service data frame format.
[0017] S5. The receiving password unit parses the service data frame to obtain the password synchronization data K, and decrypts the service data data_enc using the password synchronization data K and the working key to obtain the plaintext data data, and returns it to the receiving user.
[0018] As a preferred technical solution, in step S3, the sending user sends the password synchronization data K, the encrypted service data data_enc, and other fields in the service data to the communication receiving user through a satellite channel or a wireless network.
[0019] As a preferred technical solution, the password synchronization data consists of three data segments: identification information, Beidou time information, and extended information. The Beidou time information represents time information.
[0020] As a preferred technical solution, the identification information is used to identify the situation where multiple users send service data at the same moment.
[0021] As a preferred technical solution, the extended information is used to identify the situation where a certain user sends multiple packets of service data at the same moment.
[0022] As a preferred technical solution, when constructing the password synchronization data, the Beidou time information is intercepted to the second level.
[0023] As a preferred technical solution, the local times of the communication sender and the communication receiver are both synchronized by the Beidou system.
[0024] A Beidou-time-based password synchronization system for implementing the Beidou-time-based password synchronization method described above, including a communication sender, a communication receiver, and a password distribution system. The communication sender includes a sending user and a sending password unit that are communicatively connected to each other. The communication receiver includes a receiving user and a receiving password unit that are communicatively connected to each other. The password distribution system is communicatively connected to the sending password unit and the receiving password unit respectively. Both the sending user and the receiving user can communicate with the Beidou system.
[0025] Compared with the prior art, the present invention has the following beneficial effects:
[0026] (1) Using Beidou time as a construction factor for password synchronization data, the password synchronization method is simple and efficient, and can effectively reduce the occupation of system channel transmission resources;
[0027] (2) The password synchronization data constructed based on Beidou time can strictly ensure one-way increment and non-repetition, effectively reducing the probability of password reuse and improving the security of system applications;
[0028] (3) By introducing Beidou time information, a global unified, accurate and reliable time reference is established, simplifying the construction of application systems and effectively meeting the time-frequency usage requirements of application systems themselves;
[0029] (4) Beidou time synchronization has the characteristics of global full-time, and this password synchronization method is particularly suitable for application systems with a large number of users and large scale;
[0030] (5) This password synchronization method and its design concept can effectively solve similar problems of achieving unique counting by frequently erasing and writing non-volatile memories to store synchronization data, reduce the device usage cost, and improve the device service life. Brief Description of the Drawings
[0031] Figure 1 It is a schematic diagram of a multi-user communication system based on Beidou time;
[0032] Figure 2 It is a schematic diagram of the password synchronization data format based on Beidou time information;
[0033] Figure 3 It is a schematic diagram of the service data frame format. Specific Embodiments
[0034] The present invention will be further described in detail below in conjunction with the embodiments and the drawings, but the embodiments of the present invention are not limited thereto.
[0035] Embodiment 1
[0036] As Figures 1 to 3 shown, the multi-user communication system of the present invention based on Beidou time, as Figure 1 shown, is composed of a communication sending user, a communication receiving user, password units supporting each user, a key distribution system, a communication channel, etc. The local time of each user in the communication system is timed by the Beidou system to ensure time accuracy.
[0037] The solution is as follows:
[0038] (1) The construction method of password synchronization data
[0039] The Beidou time system itself has a strict, precise and unified time reference, and the timing accuracy is at the nanosecond level, which can ensure that the Beidou time information in each packet of data is strictly increasing and highly reliable. Considering the actual situation that the time accuracy required by general application systems is mostly at the second level, the Beidou time information is intercepted to the second level, and the construction method of password synchronization data is designed as Figure 2 shown.
[0040] The password synchronization data consists of three data segments: identification information, Beidou time information, and extended information. The three data segments complement each other, are combined organically, and jointly constitute a unique set of data information, which can effectively ensure that the password synchronization data is different from each other. Among them, the identification information is an auxiliary data segment, and the sender identification, type identification, etc. can be introduced; the Beidou time information is the core data segment, representing time information. The maximum representation interval of "month, day, hour, minute, second" is one year, which is used to construct the password synchronization data, and it can change once per second and will not repeat within one year; the extended information is an auxiliary data segment, as a supplement to the Beidou time information, and a counter can be introduced to identify different data packets within the same time slice in seconds, ensuring uniqueness.
[0041] ① System channel resource occupancy
[0042] For this construction method, the length of the password synchronization data that needs to be transmitted through the system channel is (m + 26 + n) bit, where m and n can be customized according to the actual situation of the system, and 26 bit is the Beidou time information. The strictly unidirectional increasing method of using Beidou time to construct password synchronization data requires much less bit amount for obtaining unique security compared with the method of obtaining statistical security by the probability of bit change repetition, that is, less resources are occupied when transmitting through the system channel.
[0043] ② Unidirectional uniqueness
[0044] The 26-bit Beidou time information has a strictly unified time reference, will not have jumps, and has unidirectional incrementality, which can effectively ensure the uniqueness of the second-level time slice; if there are multiple users sending service data within the same second in the application system, the uniqueness of the password synchronization data can be ensured through the identification information; if there is a situation where a certain user sends multiple packets of service data within the same second in the application system, the packet numbers can be incremented through the extended information record to ensure the uniqueness of the password synchronization data and ensure the security of system applications.
[0045] ③ No need for real-time storage
[0046] For this construction method, only the last used password synchronization data needs to be recorded in the cache to ensure the update of the extended information during the processing of service data, and there is no need to store the last used password synchronization data in the non-volatile memory, reducing the service life of the non-volatile memory. This design also considers the non-repetitive increment of the password synchronization data after the user device is powered on and restarted compared with the password synchronization data before power-off. Generally, when the user device is powered on and restarted, the restart process takes more than 1 second, that is, the interval from the device power-on to the sending of the password synchronization data has exceeded 1 second, so the situation of destroying the uniqueness of the password synchronization data will not occur. Even if the restart time of some types of devices is very short, the uniqueness problem can be solved by increasing the accuracy of the Beidou time information (such as adding a "millisecond" field to the Beidou time information).
[0047] (2) Password Synchronization Workflow
[0048] ① The communication sender user A sends the local Beidou time T1, password synchronization data (filled with 0), business data to be encrypted data, and other field information to the password unit A according to the Figure 3 shown service data frame format.
[0049] ② The password unit A constructs the password synchronization data K according to the Beidou time T1, and uses the password synchronization data K and the working key to encrypt the business data data to obtain the encrypted business data data_enc. Then, the password synchronization data K and the encrypted business data data_enc are filled into the service data frame and returned to the communication sender user A.
[0050] ③ The communication sender user A sends the relevant information (password synchronization data K, encrypted business data data_enc, other fields, etc.) in the business data to the communication receiver user B through communication channels such as satellite channels / wireless networks.
[0051] ④ After receiving the business data sent by user A, the communication receiver user B sends the business data to the password unit B according to the Figure 3 shown service data frame format.
[0052] ⑤ The password unit B parses the service data frame to obtain the password synchronization data K, and uses the password synchronization data K and the working key to decrypt the business data data_enc to obtain the plaintext data data, and returns it to the communication receiver user B.
[0053] The present invention has the following advantages:
[0054] (1) Using Beidou time as the construction factor of password synchronization data, the password synchronization method is simple and efficient, and can effectively reduce the occupation of system channel transmission resources.
[0055] (2) The password synchronization data constructed based on Beidou time can strictly ensure one-way increment and non-repetition, effectively reducing the probability of password reuse and improving the security of system applications.
[0056] (3) Introducing Beidou time information to establish a unified, accurate and reliable time reference for the whole domain simplifies the construction of application systems and can effectively meet the time and frequency usage requirements of application systems themselves.
[0057] (4) Beidou time service has the characteristics of full domain and all time, and this password synchronization method is especially suitable for application systems with a large number of users and large scale.
[0058] (5) The password synchronization method and its design concept can effectively solve similar problems of achieving unique counting by frequently erasing and writing non-volatile memory to store synchronization data, reduce the equipment usage cost, and improve the service life of the equipment.
[0059] As described above, the present invention can be preferably realized.
[0060] All features disclosed in all embodiments in this specification, or all steps in any method or process implicitly disclosed, except for mutually exclusive features and / or steps, can be combined and / or extended and / or replaced in any manner.
[0061] The above is only a preferred embodiment of the present invention, and does not impose any formal limitation on the present invention. According to the technical essence of the present invention, any simple modification, equivalent replacement, and improvement made to the above embodiments within the spirit and principle of the present invention still fall within the protection scope of the technical solution of the present invention.
Claims
1. A password synchronization method based on Beidou, characterized in that: Cryptographic synchronization data is constructed based on Beidou time, and the cryptographic synchronization data is used to encrypt and / or decrypt business data when a communication sender communicates with a communication receiver.
2. A Beidou-based password synchronization method according to claim 1, characterized in that: The business data frame of communication transmission includes Beidou time, cryptographic synchronization data K, business data, and other fields.
3. A Beidou-based password synchronization method according to claim 2, characterized in that: The following steps are involved: S1, the sending user sends the local Beidou time T1, password synchronization data, business data to be encrypted, and other field information to the sending cryptographic unit in the service data frame format; S2, the sender's cryptographic unit constructs cryptographic synchronization data K according to Beidou time T1, and uses the cryptographic synchronization data K and the working key to encrypt the service data data to obtain the encrypted service data data_enc; then fills the cryptographic synchronization data K and the encrypted service data data_enc into the service data frame and returns it to the sender user; S3, the sending user sends the password synchronization data K, the encrypted business data data_enc, and other fields in the business data to the receiving user; S4, after receiving the service data sent by the sending user, the receiving user sends the service data to the receiving cryptographic unit according to the service data frame format; S5, the receiving cryptographic unit parses the service data frame to obtain the cryptographic synchronization data K, and uses the cryptographic synchronization data K and the working key to decrypt the service data data_enc to obtain the plaintext data data, and returns it to the receiving user.
4. A Beidou-based password synchronization method according to claim 3, characterized in that: In step S3, the sending user sends the password synchronization data K, the encrypted business data data_enc, and other fields in the business data to the communication receiving user through a satellite channel or a wireless network.
5. The Beidou-based password synchronization method according to claim 1, characterized in that: The cryptographic synchronization data consists of three data segments: identification information, Beidou time information, and extended information. Beidou time information represents time information.
6. A Beidou-based password synchronization method according to claim 5, characterized in that: The identification information is used to identify the situation where multiple users send service data at the same time.
7. The Beidou-based password synchronization method according to claim 5, characterized in that: The extended information is used to identify the situation where a certain user sends multiple packets of service data at the same time.
8. The Beidou-based password synchronization method according to claim 1, characterized in that: When constructing password synchronization data, intercept Beidou time information to the second level.
9. A Beidou-based password synchronization method according to any one of claims 1 to 8, characterized in that: The local time of the communication sender and receiver is synchronized through the Beidou system.
10. A password synchronization system based on Beidou time, characterized in that: A Beidou-based password synchronization method for implementing any one of claims 1 to 9, comprising a communication sender, a communication receiver, and a password distribution system, wherein the communication sender comprises a sender user and a sender password unit that are communicatively connected to each other, the communication receiver comprises a receiver user and a receiver password unit that are communicatively connected to each other, the password distribution system is communicatively connected to the sender password unit and the receiver password unit, respectively, and both the sender user and the receiver user can communicate with the Beidou system.