Self-adaptive authentication method for space-air-ground cooperative NOMA communication system

By adopting an adaptive access authentication mechanism based on NTRU encryption algorithm in the space-to-earth collaborative NOMA communication system, the system's secure access authentication problem in the face of quantum attacks is solved, and efficient data security guarantee and system adaptability are achieved.

CN120166400APending Publication Date: 2025-06-17NORTHWESTERN POLYTECHNICAL UNIV
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510243826.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-03
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

The prior art has failed to effectively solve the problem of secure access authentication in the face of quantum attacks by the space-to-earth collaborative NOMA communication system, especially in an untrusted NOMA relay environment.

Method used

Adaptive access authentication mechanism based on NTRU encryption algorithm is adopted to design a dual security mechanism for trusted and untrusted NOMA relay. Ensure data security through authentication and key exchange in trusted mode, and prevent data tampering and theft through temporary session keys and message authentication codes in distrust mode.

Benefits of technology

It significantly enhances the security of the space-space and earth-integrated NOMA communication system, can effectively prevent threats brought by quantum computing, ensure the confidentiality and integrity of data transmission, and improve the adaptability and security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120166400A_ABST
    Figure CN120166400A_ABST
Patent Text Reader

Abstract

The invention discloses a self-adaptive authentication method for a space-air-ground cooperative NOMA communication system, which introduces a self-adaptive access authentication mechanism based on an NTRU encryption algorithm, designs a dual-security mechanism for trusted and untrusted NOMA relays, ensures data security through authentication and key exchange in a trusted mode, and improves the security of the communication system. And in an untrusted mode, data tampering and stealing are prevented through a temporary session key and a message authentication code, and flexible application guarantee is provided. Meanwhile, in combination with a certification authority (CA) and a digital certificate technology, it is ensured that the public key is not tampered in the transmission process, man-in-the-middle attack is avoided, and the reliability of communication node identity authentication is further improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of network security technology, and particularly relates to an adaptive authentication method for an air-ground-space cooperative NOMA communication system. Background Art

[0002] To meet the high-traffic and seamless connection requirements in the Internet of Everything (IoE) era, the 6G wireless communication system will integrate space, air, and ground networks to achieve global coverage. In addition, non-orthogonal multiple access (NOMA) technology will improve the coverage and spectral efficiency of the space-air-ground integrated network (SAGIN). To enhance NOMA communication, cooperative non-orthogonal multiple access (C-NOMA) technology, which combines cooperative communication and NOMA technology, has been developed and can achieve higher performance gains in network capacity compared to traditional NOMA. C-NOMA technology will be integrated into SAGIN to achieve large-scale connection and higher spectral efficiency, meeting the diverse requirements of IoE applications.

[0003] Despite the broad application prospects, security issues such as privacy information leakage and forgery attacks are inevitable due to the limited resources, untrusted NOMA relays, and open channels in SAGIN. In addition, the receivers in a typical NOMA group can decode the strongest signals of other users, and the formation of a NOMA group is usually based on channel quality rather than security considerations. Therefore, confidential or sensitive data may be transmitted through insecure relays in each C-NOMA group.

[0004] To solve this problem, advanced access authentication for orthogonal multiple access (OMA) communication systems is a feasible direction. For the space-air-ground integrated network, an authentication invention that utilizes the wireless security negotiation protection process has been developed. The research work on NOMA communication systems mainly focuses on physical layer authentication inventions, specifically, a group authentication mechanism suitable for large-scale machine-type communication systems is proposed by leveraging the advantages of NOMA and the irreversibility of hash operations. To address the risk of collusion between users and attackers, three physical layer authentication inventions for NOMA systems have been proposed, including shared authentication tags, superimposed independent authentication tags, and time-division multiplexing authentication tags. On this basis, a privacy protection authentication invention has been further developed to improve the system authentication performance.

[0005] The above-mentioned inventions do not fully consider secure access authentication under quantum attacks, especially in the space-air-ground integrated network (SAGIN). To address this problem, researchers have turned to post-quantum cryptography mechanisms, such as lattice-based NTRU anonymous access authentication and hash-chain-based NTRU mutual authentication mechanisms. These inventions mainly target OMA systems. Therefore, how to design an effective invention in the future SAGIN that combines the advantages of C-NOMA and post-quantum cryptography mechanisms remains an unsolved problem. Summary of the Invention

[0006] To overcome the deficiencies of the prior art, the present invention provides an adaptive authentication method for an air-space-ground cooperative NOMA communication system, introduces an adaptive access authentication mechanism based on the NTRU encryption algorithm, designs a dual security mechanism for trusted and untrusted NOMA relays, ensures data security through authentication and key exchange in the trusted mode, while in the untrusted mode, prevents data tampering and theft through a temporary session key and a message authentication code, and provides flexible application guarantee. At the same time, in combination with the certification authority (CA) and digital certificate technology, the present invention ensures that the public key is not tampered with during transmission, avoids man-in-the-middle attacks, and further improves the reliability of communication node identity authentication.

[0007] The technical solution adopted by the present invention to solve its technical problems is as follows:

[0008] Step 1: Construct an air-space-ground integrated network downlink power domain non-orthogonal multiple access network system, including satellites, unmanned aerial vehicles, and ground users;

[0009] Step 1-1: Assume that the unmanned aerial vehicle and the ground user transmit data through non-orthogonal multiple access communication connected to the satellite. Each non-orthogonal multiple access group consists of two users, namely a near user and a far user; then the transmission power is divided into two parts, respectively for the near user and the far user in each non-orthogonal multiple access group; assume that the unmanned aerial vehicle in the air-space-ground integrated network can be used as a relay for each cooperative non-orthogonal multiple access group;

[0010] Step 1-2: For public key authentication, assume that the public keys of space, air, and ground communication devices rely on a trusted certification authority CA; CA provides digital certificates for each device, verifies the legality of its identity, and facilitates the exchange of public keys;

[0011] Step 1-3: Establish a threat model using the Dolev-Yao model;

[0012] Step 2: The system includes the definition of the NTRU algorithm, the encryption and decryption process, and the message recovery process;

[0013] Step 2-1: The NTRU algorithm is defined in the polynomial ring R q =(Z q [x]) / (x N –1), where N is a positive prime number, p and q are two integers, and q >> p, gcd(p,q)=1; x N represents the Nth power of x, Z q [x] represents the ring composed of all polynomials with coefficients in Z q , x represents the independent variable on the polynomial ring, and gcd(p,q) represents the greatest common divisor of p and q;

[0014] By selecting random polynomials f and g such that Let h = f -1 * g (mod p), then the associated NTRU lattice Λ h,q is represented as where C(h) is the convolution matrix generated by the polynomial h, and I n is the n×n identity matrix, and O n is the n×n zero matrix; represents the inverse of the polynomial f under the residue classes modulo q, represents the inverse of the polynomial f under the residue classes modulo p;

[0015] Step 2-2: During the encryption process, the message m is transformed into the polynomial form m(x) and represented as a coefficient vector, and the degree of m(x) is less than N - 1; a random polynomial r(x) ∈ R q is randomly selected, whose coefficients follow a Gaussian distribution, and the ciphertext c(x) is generated using the following formula:

[0016] c(x) = p·r(x) * h(x) + m(x) (mod q)

[0017] where * represents polynomial convolution. This formula ensures the mixing of the message m(x) and the random polynomial r(x), and h(x) represents the public key polynomial;

[0018] Step 2-3: During the decryption process, the private key polynomial f(x) is used to operate on the ciphertext c(x) as follows:

[0019] a(x) = f(x) * c(x) (mod q)

[0020]

[0021] Step 2-4: During the message recovery process, since c(x) contains the mixture of the message polynomial m(x) and the random polynomial r(x), the information of m(x) is extracted after subtracting the modulus p;

[0022] Step 3: In the system initialization phase, the infrastructure of the space-ground integrated network is established; satellites, drones, and ground users generate their own NTRU key pairs to ensure the security of the public and private keys of each communication node;

[0023] Step 3-1: Each node, namely satellites, drones, and ground users, generates its own NTRU key pair; the satellite generates the key pair (Pub S , Priv S ), the drone generates the key pair The ground user generates the key pair

[0024] Step 3-2: The user submits their public key, i.e., the (Pub S ) of the satellite and that of the drone of the user to the certification authority CA; after verifying the legality of these public keys, the certification authority generates a digital certificate for each user and returns it to the user; the digital certificate includes the public key, validity period, and CA signature;

[0025] Step 3-3: After receiving the verification from the certification authority, the user verifies the validity of the certificate using the public key of the certification authority to ensure the authenticity of the identity and public key of each node;

[0026] Step 4: In the key negotiation phase, the satellite, drone, and ground user establish a session key through a secure key exchange protocol and ensure the confidentiality and integrity of the data during the communication process; the key negotiation process among the ground user, drone, and satellite is as follows:

[0027] Step 4-1: For the key negotiation between the drone and the ground user, the user first verifies the certificate of the drone and obtains the public key Pub1 of the drone; then the user generates a random number r1 and encrypts it using Pub1; after generating the ciphertext C1, the user generates a validity period T1 and calculates the hash value H1 = H(Hello1||C1||H(r1)||T1) to ensure data integrity; finally, the ground user sends the message (Hello1, C1, Cert U2 , H1) to the drone; Hello1 is an identification message sent by the user indicating the start of the key negotiation with the drone.

[0028] Step 4-2: After receiving the message from the ground user, the drone first verifies the certificate of the ground user If the verification passes, it obtains Pub2; then, the drone decrypts the ciphertext C1 using its private key to obtain the random number and uses it to verify the hash value (H1)' and the drone checks the validity of T1. If the verification fails, it will send an error message to the ground user and terminate the negotiation process; if the verification passes, the drone will generate a random number r2 and encrypt it using Pub2 to generate the ciphertext C2; then, the drone generates a validity period T2, creates a session key and calculates the hash value H(r2) = H(Hello2||C2||H(r2)||T2) to ensure data integrity; finally, the drone sends the message (Hello2, C2, Cert U1 , H2) back to the ground user; Hello2 is an identification message sent by the drone in response to the ground user indicating the continuation of the negotiation process and conveying the drone's response.

[0029] Step 4-3: After the ground user receives the message from the drone, it decrypts C2 using its private key to obtain the random number Then, it verifies the validity of the hash value (H2)' and T2; if (H2)' and T2 are valid, the ground terminal will calculate the session key and generate an integrity hash value H(AllMessages1) for all messages; AllMessages1 represents all the messages for which the hash value will be generated;

[0030] Step 4-4: Subsequently, the drone receives and verifies the hash value H'(AllMessages1) from the ground user; if H'(AllMessages1) is valid, the drone will send the hash value H(AllMessages2) back to the ground user; finally, the ground user verifies the hash value H'(AllMessages2) from the drone; AllMessages2 represents all the messages for which the hash value will be generated;

[0031] This process is implemented in a similar way between the satellite and the ground user, and between the satellite and the drone;

[0032] Step 5: Non-orthogonal multiple access secure communication mechanism for trusted and untrusted relay scenarios;

[0033] Step 5-1: The satellite establishes a secure communication link between drone U1 and user U2, where U1 acts as a relay in the non-orthogonal multiple access group; at the start of the communication, U2 can choose to use the trusted mode or the untrusted mode;

[0034] Step 5-2: Before the start of the communication, the satellite, U1, and U2 first generate a message authentication code MAC key MK i,j based on the session key SK obtained from the previous handshake exchange i,j ; The MAC key is calculated as: MK i,j = HKDF(SK i,j )

[0035] Step 5-3: In the trusted mode, the downlink of the specific information transmission process from the satellite to U2 is as follows:

[0036] Step 5-3-1: The process from the satellite to U1 is as follows:

[0037] First, U2 sends a trusted mode communication request to the satellite; after receiving the request, the satellite encrypts the plaintext message M using the session key to generate the ciphertext represents the session key between SAT and U1; then, the satellite generates the current valid timestamp T1 and calculates the MAC value Finally, the satellite packages the message msg1 = (MAC1||C1||T1) and sends it to U1;

[0038] Step 5-3-2: The process from U1 to U2 is as follows:

[0039] First, U1 uses to verify the MAC value and the validity of the timestamp T1. If the timestamp is valid and the MAC verification passes, the message will be accepted; otherwise, the message will be discarded; denotes the message authentication code key between U1 and SAT; Second, U1 uses the session key to decrypt the ciphertext C1 and obtain the original plaintext data Meanwhile, U1 generates the current valid timestamp T2; Third, U1 uses the session key to encrypt the data M and generate a new ciphertext Then, U1 uses the MAC key to generate the MAC value MAC2, where Finally, U1 packages the message msg2 = (MAC2||C2||T2) and sends it to U2;

[0040] Step 5-3-3: U2 verifies the legality of the message and decrypts it;

[0041] First, U2 uses to verify the MAC value and the validity of the timestamp T2; If the timestamp is valid and the MAC verification passes, the message will be accepted; otherwise, the message will be discarded; Then, U2 uses the session key to decrypt the ciphertext C2 and recover the original plaintext data At this time, the satellite has successfully transmitted the message to U2 through the downlink; The mechanism of the uplink is similar to Step 5-3;

[0042] Step 5-4: In the untrusted mode, the downlink of the specific information transmission process from the satellite to U2 is as follows:

[0043] Step 5-4-1: The process from the satellite to U1 is as follows:

[0044] First, the satellite periodically generates a new random number R = rand(), which is used as the seed for the hybrid temporary session key; The temporary session key is only used to encrypt the communication in this session; Then, the satellite uses the temporary session key to encrypt the plaintext message and generate a ciphertext Finally, the satellite generates the current valid timestamp T1 and uses Calculate the MAC value The satellite packs the message and sends it to U1;

[0045] Step 5-4-2: The process from U1 to U2 is as follows:

[0046] First, U1 uses the shared MAC key to verify the MAC value and the validity of the timestamp T1; if the timestamp is valid and the MAC verification passes, the message will be accepted; otherwise, the message will be discarded; Second, U1 uses the session key to decrypt the ciphertext 1 ′ C to obtain the ciphertext Again, U1 generates the currently valid timestamp T2; then, U1 uses the session key to encrypt the data to generate a new ciphertext and uses the MAC key to generate the MAC value Finally, U1 packs the message msg2=(MAC2||C2||R||T2) and sends it to U2;

[0047] Step 5-4-3: U2 verifies the legality of the message and decrypts it;

[0048] First, U2 uses the shared MAC key to verify the MAC value, if the timestamp is valid and the MAC verification passes, the message will be accepted; otherwise, the message will be discarded; Second, U2 uses the session key to decrypt the ciphertext C2 to obtain the ciphertext Then, U2 calculates the temporary session key Finally, U2 uses to decrypt the ciphertext C1 to recover the plaintext data At this time, the satellite has successfully transmitted the message to U2 through the downlink;

[0049] The mechanism of the uplink is similar to Step 5-4.

[0050] The beneficial effects of the present invention are as follows:

[0051] 1. The present invention adopts an adaptive access authentication mechanism based on the NTRU encryption algorithm, significantly enhancing the security of the space-air-ground integrated NOMA communication system in the face of quantum computing threats. The NTRU encryption algorithm has the ability to resist quantum attacks, which can effectively prevent potential threats brought by quantum computing and ensure the confidentiality and integrity of data transmission. Through this encryption method, the system can still maintain a high level of security in the future quantum computing era, ensuring that the information in the communication process will not be cracked or tampered with.

[0052] 2. The present invention designs two security mechanisms adapted to different trust environments to meet the security requirements of trusted and untrusted NOMA relays respectively. In the trusted mode, the system ensures the secure transmission of data through an authentication and key exchange protocol, preventing man-in-the-middle attacks and data leakage. In the untrusted mode, by introducing a temporary session key and message authentication code (MAC) technology, it ensures that data can be effectively protected even in an environment with a low level of trust. This mechanism significantly improves the adaptability and security of the system and can operate stably in the complex and changeable space-air-ground communication environment.

[0053] 3. The present invention combines the certification authority (CA) and digital certificate technology to authenticate communication nodes during the communication process, preventing spoofing attacks and identity tampering. Digital certificates can effectively confirm the identity of communication nodes, thus avoiding the risk of malicious attackers forging identities to conduct attacks. In this way, the present invention improves the anti-counterfeiting ability and authentication reliability of the entire communication system, ensuring secure and trustworthy interactions between communication nodes.

[0054] 4. By designing an adaptive access authentication mechanism, the present invention not only improves the security of the system but also realizes the reasonable allocation of resources, avoiding unnecessary calculations and energy consumption. Through intelligent authentication, the system can optimize the authentication process under different security requirements, reducing redundant operations and computational complexity in traditional methods, and thus reducing the overall energy consumption of the system. This innovation improves the energy efficiency and operating efficiency of the space-air-ground integrated communication system while ensuring communication security. Description of the Drawings

[0055] Figure 1 It is a diagram of the relay communication system;

[0056] Figure 2 It is a flowchart of the trusted relay;

[0057] Figure 3 It is a flowchart of the untrusted relay;

[0058] Figure 4 It is a comparison diagram of the communication overhead between the present invention and other similar inventions;

[0059] Figure 5It is a comparison diagram of the computational overhead between the present invention and other similar inventions. Detailed implementation manners

[0060] The present invention will be further described below in conjunction with the accompanying drawings and embodiments.

[0061] The purpose of the present invention is to provide an access authentication mechanism in an integrated space-air-ground NOMA communication system, aiming to enhance the security and adaptability of the system. By introducing an adaptive access authentication mechanism based on the NTRU encryption algorithm, the present invention can effectively protect against quantum attacks. In addition, a dual security mechanism for trusted and untrusted NOMA relays is designed. In the trusted mode, data security is ensured through authentication and key exchange, while in the untrusted mode, data tampering and theft are prevented through temporary session keys and message authentication codes (MACs), providing flexible application guarantees. At the same time, in combination with the certification authority (CA) and digital certificate technology, the present invention ensures that the public key is not tampered with during transmission, avoids man-in-the-middle attacks, and further improves the reliability of communication node identity authentication.

[0062] The present invention provides a trust-based adaptive access authentication invention for resisting quantum attacks and ensuring the performance of cooperative non-orthogonal multiple access communication in an integrated space-air-ground network. The specific implementation manners of the present invention are as follows:

[0063] S1. The present invention considers a typical downlink power-domain non-orthogonal multiple access network system in an integrated space-air-ground network, including satellites, unmanned aerial vehicles (UAVs), and ground users.

[0064] S11. To improve network capacity and spectral efficiency, it is assumed that UAVs and ground users tend to connect to satellites through non-orthogonal multiple access communication for data transmission. If the receivers in the same non-orthogonal multiple access group can be interconnected, then by establishing a direct wireless link between them, cooperative non-orthogonal multiple access communication can be constructed, thereby maximizing the data transmission capacity. For simplicity of analysis, it is assumed that each access group consists of two users, and the transmission power is divided into two parts, respectively for the near user and the far user. UAVs in the air usually have better channel quality (i.e., usually line-of-sight channels) and higher computing capabilities, while ground users (such as possible non-line-of-sight channels and Internet of Things devices) are worse. Therefore, UAVs may perform successive interference cancellation when using non-orthogonal multiple access technology. Therefore, it is assumed that UAVs in SAGIN can act as relays for each C-NOMA group.

[0065] S12. For public key authentication, it is assumed that the public keys of space, air, and ground communication devices rely on a trusted certification authority (CA). The CA provides digital certificates for each device, verifies the legitimacy of its identity, and facilitates the exchange of public keys.

[0066] S13. To establish a threat model, the present invention adopts the Dolev-Yao model, assuming that the attacker has full control over network communication and can intercept, modify, forge, and replay messages. Specifically, the capabilities of the attacker are defined as follows: The attacker can capture all data transmitted between the drone and the user through the wireless link; the attacker can send any data to any drone or satellite through the wireless link; the attacker can obtain the short-term keys used by certain users for secure communication; the attacker cannot break specific cryptographic primitives, such as symmetric encryption and hash functions. That is, the attacker cannot recover the plaintext from the ciphertext or forge a valid message authentication code without the key; the attacker cannot solve the shortest vector problem in lattice-based cryptography.

[0067] S2. The entire system includes the definition of the NTRU algorithm, the encryption and decryption processes, and the message recovery process.

[0068] Table 1

[0069]

[0070] S21. The NTRU algorithm is defined in the polynomial ring R q =(Z q [x]) / (x N –1), where N is a positive prime number, p and q are two integers, and q >> p, gcd(p, q)=1. By selecting appropriate random polynomials f and g, such that Let h = f -1 * g (mod p), then the related NTRU lattice Λ h,q can be expressed as where C(h) is the convolution matrix generated by the polynomial h, I n is the n×n identity matrix, and O n is the n×n zero matrix.

[0071] S22. During the encryption process, the message m is converted into polynomial form m(x) and represented as a coefficient vector, and the degree of m(x) is less than N - 1. A random polynomial r(x) ∈ R q is randomly selected, and its coefficients follow a Gaussian distribution. Then, the ciphertext c(x) is generated using the following formula:

[0072] c(x)=p·r(x)*h(x)+m(x)(mod q)

[0073] where * represents polynomial convolution. This formula ensures the mixing of the message m(x) and the random polynomial r(x).

[0074] S23. During the decryption process, the private key polynomial f(x) is used to operate on the ciphertext c(x) as follows:

[0075] a(x) = f(x) * c(x) (mod q)

[0076]

[0077] S24. During the message recovery process, since c(x) contains a mixture of the message polynomial m(x) and the random polynomial r(x), the information of m(x) can be extracted after subtracting the modulus p.

[0078] S3. In the system initialization phase, it is necessary to establish the infrastructure of the space-ground integrated network. At this time, satellites, drones, and ground users need to generate their own NTRU key pairs to ensure the security of the keys of each communication node.

[0079] S31. Each node (satellite, drone, ground user) generates its own NTRU key pair. Specifically, the satellite generates the key pair (Pub S , Priv S ), the drone generates the key pair The ground user generates the key pair

[0080] S32. All users submit their public keys (such as (Pub S ) of the satellite, of the drone, of the user) to the certification authority (CA). After the certification authority verifies the legitimacy of these public keys, it generates digital certificates and returns them to the users. The digital certificate includes the public key, the validity period, and the CA signature.

[0081] S33. After receiving the verification from the certification authority, the user uses the public key of the certification authority to verify the validity of the certificate, ensuring the authenticity of the identity and public key of each node.

[0082] Taking the public key exchange between the satellite and the drone as an example, the satellite sends its certificate Cert S to the drone. The drone uses the public key of the certification center to verify the legitimacy of Cert S , and then the drone returns its certificate to the satellite. The satellite uses the public key of the certification center to verify the validity of . If the verification is successful, the satellite and the drone can share their public keys Pub S and The public key exchange mechanism between the satellite and the user can also be implemented by the above method.

[0083] S4. In the key negotiation phase, the satellite, the drone, and the ground user establish a session key through a secure key exchange protocol, and ensure the confidentiality and integrity of the data during the communication process. The following part is the key negotiation process among the ground user, the drone, and the satellite.

[0084] S41. Taking the key negotiation between the drone and the ground user as an example, the ground user first verifies the certificate of the drone and obtains the public key Pub1 of the drone. Then the ground user generates a random number r1 and encrypts it using Pub1. After generating the ciphertext C1, the ground user generates a validity period T1 and calculates the hash value H1 = H(Hello1||C1||H(t1)||T1) to ensure data integrity. Finally, the ground user sends the message (Hello1, C1, Cert U2 , H1) to the drone.

[0085] S42. After receiving the message from the ground user, the drone first verifies the certificate of the ground user If the verification passes, it obtains Pub2. Then, the drone decrypts the ciphertext C1 using the private key to get the random number and uses it to verify the hash value (H1)'. The drone also checks the validity of T1. If the verification fails, it will send an error message to the ground user and terminate the negotiation process. If the verification passes, the drone will generate a random number r2 and encrypt it using Pub2 to generate the ciphertext C2. Then, the drone generates a validity period T2, creates a session key and calculates the hash value H(r2) = H(Hello2||C2||H(r2)||T2) to ensure data integrity. Finally, the drone sends the message back to the ground user.

[0086] S43. After receiving the message from the drone, the ground user decrypts C2 using its private key to obtain the random number Then it verifies the validity of the hash value (H2)' and T2. If (H2)' and T2 are valid, the ground terminal will calculate the session key and generate an integrity hash value H(AllMessages1) for all messages.

[0087] S44. Subsequently, the drone receives and verifies the hash value H'(AllMessages1) from the ground user. If H'(AllMessages1) is valid, the drone will send the hash value H(AllMessages2) back to the ground user. Finally, the ground user verifies the hash value H'(AllMessages2) from the drone. This process will be implemented between the satellite and the ground user, and between the satellite and the drone in a similar way.

[0088] S5. Design a non-orthogonal multiple access (NOMA) security communication mechanism for trusted and untrusted relay scenarios, such as Figure 1 .

[0089] S51. As Figure 1 shown, the satellite establishes a secure communication link between the unmanned aerial vehicle (UAV) U1 and the ground user U2, where U1 acts as a relay in the NOMA group. At the beginning of the communication, U2 can choose a trusted mode or an untrusted mode, depending on whether the relay is secure. Different modes determine whether the relay can obtain the plaintext data.

[0090] S52. Before the communication starts, the satellite, U1, and U2 first generate a message authentication code (MAC) key MK i,j based on the session key SK i,j obtained in the previous handshake exchange. The MAC key is calculated as: MK i,j = HKDF(SK i,j ).

[0091] S53. In the trusted mode, the process of specific information transmission back and forth is as Figure 2 shown. Taking the downlink as an example for illustration.

[0092] S531. The process from the satellite to U1 is as follows:

[0093] First, U2 sends a trusted mode communication request to the satellite. After receiving the request, the satellite encrypts the plaintext message M using the session key to generate the ciphertext Then, the satellite generates the current valid timestamp T1 and calculates the MAC value Finally, the satellite packs the message msg1 = (MAC1||C1||T1) and sends it to U1.

[0094] S532. The process from U1 to U2 is as follows:

[0095] First, U1 first uses to verify the MAC value and the validity of the timestamp T1. If the timestamp is valid and the MAC verification passes, the message will be accepted; otherwise, the message will be discarded. Second, U1 decrypts the ciphertext C1 using the session key to obtain the original plaintext data At the same time, U1 generates the current valid timestamp T2. Third, U1 encrypts the data M using the session key to generate a new ciphertext Then, U1 uses the MAC key to generate the MAC value MAC2, where Finally, U1 packs the message msg2 = (MAC2||C2||T2) and sends it to U2.

[0096] S533. U2 verifies the legality of the message and decrypts it.

[0097] First, U2 uses to verify the MAC value and the validity of the timestamp T2. If the timestamp is valid and the MAC verification passes, the message will be accepted; otherwise, the message will be discarded. Then, U2 uses the session key to decrypt the ciphertext C2 and recover the original plaintext data At this time, the satellite has successfully transmitted the message to U2 via the downlink. The mechanism of the uplink is similar to the above steps.

[0098] S54. In the untrusted mode, the specific information transmission process from the satellite to U2 is as Figure 3 shown. The following takes the downlink as an example for specific description.

[0099] S541. The process from the satellite to U1 is as follows.

[0100] First, as Figure 3 shown, the satellite periodically generates a new random number R = rand(), which is used as the seed for the hybrid temporary session key. The temporary session key is only used to encrypt the communication in this session. Then, the satellite uses the temporary session key to encrypt the plaintext message and generate the ciphertext Subsequently, use the session key to encrypt the ciphertext message C1 and generate the ciphertext The satellite generates the currently valid timestamp T1 and uses to calculate the MAC value Finally, the satellite packs the message and sends it to U1.

[0101] S542. The process from U1 to U2 is as follows:

[0102] First, U1 first uses the shared MAC key to verify the MAC value and the validity of the timestamp T1. If the timestamp is valid and the MAC verification passes, the message will be accepted; otherwise, the message will be discarded. Secondly, U1 uses the session key to decrypt the ciphertext 1 ′ C , and obtains the ciphertext Again, U1 generates the currently valid timestamp T2. Then, U1 uses the session key to encrypt the data and generate a new ciphertext and uses the MAC key to generate the MAC value Finally, U1 packs the message msg2 = (MAC2||C2||R||T2) and sends it to U2.

[0103] S543. U2 verifies the legality of the message and decrypts it.

[0104] First, U2 uses the shared MAC key to verify the MAC value. If the timestamp is valid and the MAC verification passes, the message will be accepted; otherwise, the message will be discarded. Second, U2 uses the session key to decrypt the ciphertext C2 to obtain the ciphertext Then, U2 calculates the temporary session key Finally, U2 uses to decrypt the ciphertext C1 and recover the plaintext data

[0105] At this time, the satellite has successfully transmitted the message to U2. The mechanism of the uplink is similar to the above steps.

[0106] This embodiment analyzes the effectiveness and security of the present invention and demonstrates the performance advantages of the present invention from two perspectives of communication overhead and computational overhead. All experiments were conducted on a personal computer equipped with an Intel Core i5-13400F CPU and running the Windows 11 operating system.

[0107] Communication overhead:

[0108] For the complete end-to-end transmission, the present invention uses the metric satellite-to-ground transmission delay (STGD) (the satellite-to-ground transmission delay, about 4.833 ms for each STGD) to measure the size of the communication overhead. Table 2 compares the communication overhead of the present invention with other inventions. Compared with these inventions, the present invention only requires 2 STGDs, which is basically less than other inventions. (As Figure 4 shown)

[0109] Among them, the inventions proposed in four other documents are used for comparison, which are respectively:

[0110] The invention of lattice-based lightweight and certificateless anonymous access authentication for satellite-ground integrated networks proposed by Shanshan Wang et al. in 2022 (abbreviated as S. Wang), the invention of a secure and efficient authentication key protocol for space-ground integrated railway networks based on SDN proposed by Yu Wang et al. in 2023 (abbreviated as Y. Wang), the communication invention using identity-based encryption technology proposed by Zhong Yantao et al. in 2010 (abbreviated as Z. Yantao), and the NTRU-based authentication invention with provable security and conditional privacy protection proposed by Zhou Yousheng et al. in 2020 (abbreviated as Y. Zhou). All the following comparisons use the abbreviations.

[0111] Table 2

[0112]

[0113] Computation overhead:

[0114] The computation overhead comparison of this invention defines the total time of various operations in the entire authentication invention as the computation cost. As shown in Table 3, the time cost of each operation is explained as follows: the time cost of the Hash operation is Th (0.186 ms), the time cost of random generation is Tr (0.51 ms), the time cost of modular exponentiation is Te (5.8 ms), the time cost of NTRU encryption is TNE (0.15 ms), the time cost of NTRU decryption is TND (0.16 ms), the time cost of NTRU modular multiplication is TNM (0.026 ms), and the time cost of random sampling operation is Tg (73 ns). (As Figure 5 shown)

[0115] Table 3

[0116]

[0117] It can be seen from Table 3 that this invention has better performance than the other four inventions.

[0118] Security analysis:

[0119] This project uses relevant research to analyze the security of the invention proposed in this invention, as shown in Table 4. Specifically, Z. Yantao proved that his protocol is ECK secure in the random oracle model, based on the computational Diffie-Hellman (CDH) assumption model. Y. Wang and Y. Zhou used qualitative security analysis and BAN logic to evaluate the security performance of the proposed invention. S. Wang used mathematical formalization methods to verify the correctness of the protocol he designed, ensuring that the protocol meets various security requirements under the expected security model and assumptions. This invention compares the security and functional characteristics of four other inventions. To defend against replay attacks, this invention uses timestamps, nonces, and MACs (message authentication codes) to ensure the uniqueness of each session key, so that replayed messages cannot pass the verification. Also, to resist DoS attacks, this invention uses MACs and timestamps to authenticate legitimate requests and discard expired or forged requests to mitigate the impact of DoS attacks. To defend against man-in-the-middle attacks, this invention uses public keys issued by the CA for two-way authentication to ensure the authenticity of communication. To resist quantum attacks, this invention adopts the NTRU encryption algorithm, which is based on lattice-based design and cannot be efficiently cracked by quantum algorithms. In addition, the invention also independently generates session keys through the HKDF function. Even if the current session key is leaked, previous or future session keys will not be affected. This ensures forward and backward security. Finally, this invention realizes the message accessibility of users with weak channels.

[0120] Table 4

[0121] Security function Z.Yantao Y.Wang Y.Zhou S.Wang The present invention Mutual authentication √ √ √ √ √ Key negotiation √ √ √ √ √ Forward security √ √ √ √ √ Backward security √ √ √ √ √ Man-in-the-middle attack √ √ √ √ √ Replay attack √ √ √ √ √ Formal proof of security × × √ √ √ Resistance to quantum attacks × × × × √

[0122] In summary, considering the communication cost and the rationality of various computational overheads, in addition to mutual authentication, key establishment, and resistance to common attacks, this invention can also achieve some more powerful security attributes, including forward / backward security, generality, traceability, and resistance to quantum attacks. Theoretical and experimental analyses show that compared with existing inventions, the proposed invention has advantages in terms of computational cost, communication overhead, and performance under unknown attacks, while ensuring higher security.

Claims

1. An adaptive authentication method for an air-ground-space collaborative NOMA communication system, characterized in that: The steps include: Step 1: Build a non-orthogonal multiple access network system in the downlink power domain of the air-ground integrated network, including satellites, drones and ground users; Step 2: The system includes the definition of the NTRU algorithm, the encryption and decryption process, and the message recovery process; Step 3: During the system initialization phase, the infrastructure of the integrated space-ground network is established; satellites, drones, and ground users generate their own NTRU key pairs to ensure the security of the public and private keys of each communication node; Step 4: In the key negotiation phase, the satellite, drone, and ground user establish session keys through a secure key exchange protocol and ensure the confidentiality and integrity of data during communication; Key negotiation between ground users, drones, and satellites; Step 5: Non-orthogonal multiple access secure communication mechanism for trusted and untrusted relay scenarios.

2. According to claim 1, an adaptive authentication method for an air-ground-space collaborative NOMA communication system is characterized in that: The step 1 is specifically as follows: Step 1-1: Assume that the UAV and the ground user are connected to the satellite through non-orthogonal multiple access communication to transmit data. Each non-orthogonal multiple access group consists of two users, namely the near user and the far user. Then the transmission power is divided into two parts, which are used for the near user and the far user in each non-orthogonal multiple access group respectively. Assume that the UAV in the air-ground integrated network can serve as the relay of each cooperative non-orthogonal multiple access group. Step 1-2: For public key authentication, it is assumed that the public keys of space, air, and ground communication devices rely on a trusted certification authority (CA); the CA provides a digital certificate for each device, verifies the legitimacy of its identity, and facilitates the exchange of public keys; Step 1-3: Use the Dolev-Yao model to build a threat model.

3. According to claim 2, an adaptive authentication method for an air-ground-space collaborative NOMA communication system is characterized in that: The step 2 is specifically as follows: Step 2-1: The NTRU algorithm is defined on the polynomial ring R q =(Z q [x]) / (x N –1), where N is a positive prime number, p and q are two integers, and q>>p, gcd(p,q)=1; x N represents x to the power of N, Z q [x] represents the coefficients in Z q The ring formed by the polynomials in , x represents the independent variable on the polynomial ring, and gcd(p,q) represents the greatest common divisor of p and q; By choosing random polynomials f and g such that Let h = f -1 *g(mod p), then the relevant NTRU lattice Λ h,q Expressed as Among them, C(h) is the convolution matrix generated by the polynomial f, I n is the n×n identity matrix, O n is a b×n zero matrix; represents the inverse of the polynomial f under the residue class modulo q, represents the inverse of the polynomial f under the residue class modulo p; Step 2-2: During the encryption process, the message m is converted into a polynomial form m(x) and represented as a coefficient vector, and the degree of m(x) is less than N-1; a polynomial r(x)∈R is randomly selected. q , whose coefficients follow a Gaussian distribution, and the ciphertext c(x) is generated using the following formula: c(x)=p·r(x)*h(x)+m(x)(modq) Where * represents polynomial convolution; this formula ensures the mixing of the message m(x) with the random polynomial r(x), and h(x) represents the public key polynomial; Step 2-3: During the decryption process, the private key polynomial f(x) is used to perform the following operations on the ciphertext c(x): a(x)=f(x)*c(x)(modq) Step 2-4: During the message recovery process, since c(x) contains a mixture of the message polynomial m(x) and the random polynomial r(x), the information of m(x) is extracted by subtracting the modulus p.

4. According to claim 3, an adaptive authentication method for an air-ground-space collaborative NOMA communication system is characterized in that: The step 3 is as follows: Step 3-1: Each node, i.e. satellite, drone, and ground user, generates its own NTRU key pair; the satellite generates a key pair (Pub S ,Priv S ), the drone generates a key pair Ground user generates key pair Step 3-2: The user enters his public key, the satellite’s (Pub S ), UAV User's Submit it to the certification authority CA; after verifying the legitimacy of these public keys, the certification authority generates a digital certificate Cert for each user S , And return it to the user; the digital certificate includes the public key, validity period and CA signature; Step 3-3: After receiving the verification from the certification authority, the user uses the certification authority's public key to verify the validity of the certificate to ensure the authenticity of the identity and public key of each node.

5. The adaptive authentication method for the air-ground-space collaborative NOMA communication system according to claim 4, characterized in that: The step 4 is specifically as follows: Step 4-1: For key negotiation between the drone and the ground user, the user first verifies the drone's certificate and obtains the drone's public key Pub1; then the user generates a random number r1 and encrypts it using Pub1; after generating the ciphertext C1, the user generates a validity period T1 and calculates the hash value H1 = H(Hello1||C1||H(r1)||T1) to ensure data integrity; Finally, the ground user sends a message to the drone (Hello1, C1, Cert U2 ,H1); Hello1 is an identification message sent by the user, indicating the start of key negotiation with the drone; Step 4-2: After receiving the message from the ground user, the drone first verifies the ground user's certificate If the verification is successful, Pub2 is obtained; then, the drone uses the private key to decrypt the ciphertext C1 and obtains the random number The UAV verifies the hash value (H1)′ and checks the validity of T1. If the verification fails, an error message will be sent to the ground user and the negotiation process will be terminated. If the verification is successful, the drone will generate a random number r2 and encrypt it using Pub2 to generate the ciphertext C2; then, the drone generates a validity period T2 and creates a session key And calculate the hash value H(r2) = H(Hello2||C2||H(r2)∥T2) to ensure data integrity; finally, the drone sends the message (Hello2, C2, Cert U1 ,H2) sent back to ground users; Hello2 is the identification message sent by the drone to the ground user, indicating the continuation of the negotiation process and conveying the drone's response; Step 4-3: After receiving the message from the drone, the ground user uses his private key to decrypt C2 to obtain the random number 2 ′ r , and then verify the validity of the hash value (H2)′ and T2; if (H2)′ and T2 are valid, the ground terminal will calculate the session key And generate integrity hash values ​​H(AllMessages1) for all messages; AllMessages1 represents all messages for which hash values ​​will be generated; Step 4-4: Subsequently, the drone receives and verifies the hash value H′(AllMessages1) from the ground user; if H′(AllMessages1) is valid, the drone sends the hash value H(AllMessages2) back to the ground user; finally, the ground user verifies the hash value H′(AllMessages2) from the drone; AllMessages2 represents all messages for which hash values ​​will be generated; This process is achieved through similar methods between satellites and ground users, and between satellites and drones.

6. The adaptive authentication method for the air-ground-space collaborative NOMA communication system according to claim 5, characterized in that: The step 5 is specifically as follows: Step 5-1: The satellite establishes a secure communication link between UAV U1 and user U2, where U1 acts as a relay in a non-orthogonal multiple access group; when the communication starts, U2 can choose to use the trusted mode or the untrusted mode; Step 5-2: Before communication begins, the satellite, U1, and U2 first exchange the session key SK based on the session key SK obtained in the previous handshake exchange. i,j Generate message authentication code MAC key MK i,j ; The calculation method of MAC key is: MK i,j =HKDF(SK i,j ); Step 5-3: In Trust Mode, the downlink of the specific information transmission process from the satellite to the U2 is as follows: Step 5-3-1: The process from satellite to U1 is as follows: First, U2 sends a trusted mode communication request to the satellite; after receiving the request, the satellite uses the session key Encrypt the plaintext message M to generate ciphertext Represents the session key between SAT and U1; then, the satellite generates the current valid timestamp T1 and calculates the MAC value Finally, the satellite packages the message msg1 = (MAC1||C1||T1) and sends it to U1; Step 5-3-2: The process from U1 to U2 is as follows: First, U1 uses Verify the MAC value and the validity of the timestamp T1. If the timestamp is valid and the MAC verification passes, the message will be accepted; otherwise, the message will be discarded. represents the message authentication code key between U1 and SAT; secondly, U1 uses the session key Decrypt the ciphertext C1 to obtain the original plaintext data At the same time, U1 generates the current valid timestamp T2; again, U1 uses the session key Encrypt data M to generate new ciphertext U1 then uses the MAC key Generate a MAC value MAC2, where Finally, U1 packages the message msg2 = (MAC2||C2||T2) and sends it to U2; Step 5-3-3: U2 verifies the legitimacy of the message and decrypts it; First, U2 uses Verify the MAC value and verify the validity of the timestamp T2; if the timestamp is valid and the MAC verification is passed, the message will be accepted; otherwise, the message will be discarded; then, U2 uses the session key Decrypt the ciphertext C2 and restore the original plaintext data At this point, the satellite has successfully transmitted the message to U2 via the downlink; the uplink mechanism is similar to step 5-3; Step 5-4: In untrusted mode, the downlink of the specific information transmission process from the satellite to U2 is as follows: Step 5-4-1: The process from satellite to U1 is as follows: First, the satellite periodically generates a new random number R = rand(), which is used as the seed for the mixed temporary session key; the temporary session key Used only to encrypt communications during this session; the satellite then uses the temporary session key Encrypt plaintext message and generate ciphertext Then use the session key Encrypt the ciphertext message C1 to generate the ciphertext Finally, the satellite generates the currently valid timestamp T1 and uses Calculating MAC value Satellite will send message Pack and send to U1; Step 5-4-2: The process from U1 to U2 is as follows: First, U1 uses the shared MAC key Verify the MAC value and verify the validity of the timestamp T1; if the timestamp is valid and the MAC verification is passed, the message will be accepted; otherwise, the message will be discarded; secondly, U1 uses the session key Decrypted ciphertext 1 ′ C , get the ciphertext Again, U1 generates a currently valid timestamp T2; then, U1 uses the session key Encrypt the data and generate new ciphertext And use MAC key Generate MAC value Finally, U1 packages the message msg2 = (MAC2||C2||R||T2) and sends it to U2; Step 5-4-3: U2 verifies the legitimacy of the message and decrypts it; First, U2 uses the shared MAC key Verify the MAC value. If the timestamp is valid and the MAC verification passes, the message will be accepted; otherwise, the message will be discarded. Second, U2 uses the session key Decrypt the ciphertext C2 and get the ciphertext Then, U2 calculates the temporary session key Finally, U2 uses Decrypt ciphertext C1 and restore plaintext data At this point, the satellite has successfully transmitted the message to U2 via the downlink; The mechanism for the uplink is similar to step 5-4.

Citation Information

Cited By

  • Trusted time source device and implementation method and application thereof

    CN120639508A