A Blockchain-Based Dynamic Secure Sharing Method and System for Satellite Data

By deploying SGX trusted hardware and blockchain technology in satellite systems, establishing end-to-end secure channels, combining attribute encryption and attribute pooling mechanisms, the security and efficiency imbalance and dynamic management problems in satellite data sharing are solved, efficient and secure dynamic permission management and cross-domain collaboration are achieved, and the security and efficiency of satellite data sharing are improved.

CN120186604BActive Publication Date: 2025-07-22XI AN JIAOTONG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510641896.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-19
Publication Date
2025-07-22
Estimated Expiration
2045-05-19

AI Technical Summary

Technical Problem

The existing satellite data sharing technology has problems such as imbalance in security and efficiency, insufficient dynamic management capabilities and lack of cross-domain collaboration mechanisms. Especially in low-orbit satellite systems, traditional encryption solutions have led to surge in transmission delays, low dynamic permission management efficiency, and cross-domain collaboration mechanisms have not achieved full-link trusted environment coverage.

Method used

Adopting a blockchain-based satellite data dynamic security sharing method, by deploying SGX trusted hardware on ground base stations and satellite service nodes, establishing an end-to-end secure channel, combining remote authentication protocols with Diffie-Hellman key negotiation, the encryption and access control are implemented in a trusted environment, and introducing an attribute-based encryption algorithm and attribute pooling mechanism to support dynamic permission management and secure deletion.

Benefits of technology

It realizes efficient and secure satellite data transmission and download, supports dynamic adjustment of access rights on demand, reduces management complexity, improves dynamic deletion efficiency, and ensures that the entire data transmission is carried out in a trusted environment, and resists network attacks and illegal interception.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120186604B_ABST
    Figure CN120186604B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and system for dynamically and securely sharing satellite data based on blockchain, belonging to the technical field of secure sharing of satellite data. The method includes: the ground base station and the satellite service node based on the secure enclave respectively request to verify each other's information and complete key negotiation, obtaining an encrypted channel and a negotiated secret key between the ground base station and the satellite service node; the ground base station sends the uploaded satellite data encrypted by the base station in the secure enclave of the ground base station to the satellite service node through the encrypted channel, and the satellite service node decrypts the uploaded satellite data encrypted by the base station through the negotiated key to obtain the decrypted uploaded satellite data and the ground base station key; the satellite service node encrypts the decrypted uploaded satellite data with the ground base station key in the secure enclave of the satellite service node, publishes it on the blockchain and then uploads it after being verified by the consensus satellite node, and destroys the ground base station key to complete the upload of the satellite data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of satellite data secure sharing, and relates to a method and system for dynamically secure sharing of satellite data based on blockchain. Background Art

[0002] Satellite data, as an important resource in modern information society, is widely used in fields such as meteorological monitoring, environmental assessment, disaster warning, military reconnaissance, and global communication. With the rapid deployment of low-earth orbit satellite constellations (such as SpaceX Starlink, Beidou system) and the breakthrough of remote sensing technology, the global satellite data volume has shown exponential growth. According to statistics, the daily generated volume of global satellite data in 2023 has exceeded 100 PB, and it is expected to exceed 1 EB in 2030. However, the sharing and circulation of massive data face severe security challenges: on the one hand, due to the wide distribution of satellite system nodes and complex communication links, satellite systems are vulnerable to network attacks and data theft; on the other hand, traditional centralized storage and encryption schemes are difficult to meet the requirements of multi-user dynamic permission management, real-time secure deletion, etc. How to build a secure, reliable, efficient, and flexible satellite data sharing system has become the core topic in the cross-field of global aerospace and information technology. Currently, satellite data secure sharing technologies mainly focus on three directions: encrypted transmission, blockchain-based evidence storage, and access control. In the field of encrypted transmission, NASA (National Aeronautics and Space Administration) uses AES-256 combined with SSL / TLS protocol to achieve satellite-ground link protection, but it relies on a centralized key distribution mechanism and has a single point of failure risk. Blockchain technology provides new ideas for data traceability through distributed ledgers and smart contracts. For example, the EU Copernicus program stores remote sensing data on the blockchain, and the IBM Hyperledger Fabric framework supports multi-node consensus for encrypted data. However, the plaintext or weakly encrypted state of data on the chain may still be cracked by malicious nodes. In access control technology, the Attribute-Based Encryption (ABE) scheme realizes fine-grained permission management through policy binding, but it is vulnerable to side-channel attacks when the algorithm runs in an untrusted environment. In recent years, Trusted Execution Environment (TEE) technologies such as Intel SGX (Software Guard Extensions) have been introduced into the data security field, and the Microsoft Confidential Computing framework uses SGX Enclave to protect cloud privacy computing. However, existing research mainly focuses on optimizing single links and lacks a systematic design for the end-to-end security system in satellite scenarios.

[0003] The existing technology system has three core defects: First, there is an imbalance between security and efficiency. Although traditional encryption and blockchain solutions enhance the credibility of data storage, the resources of satellite nodes are limited (such as computing power and energy consumption), and complex encryption algorithms lead to a sharp increase in transmission latency. For example, the computational overhead of key sharding management in the Shamir threshold secret sharing scheme in a large-scale satellite constellation is as high as , which is difficult to meet the millisecond-level response requirements of low-earth orbit constellations. Second, the dynamic management ability is insufficient. Mainstream permission control relies on static policies (such as the ACL (Access Control List) of AWS (Amazon Web Services) S3), and the access control list cannot adjust access permissions in real time according to attributes; for secure deletion, key invalidation or file overwrite mechanisms are mostly used, and all associated data blocks need to be traversed, and the deletion efficiency decreases linearly with the increase in the amount of files. Third, the cross-domain collaboration mechanism is lacking. The satellite system involves multi-agent collaboration in the space segment, ground segment, and user segment. Existing solutions do not achieve full-link trusted environment coverage. For example, on-board computers lack lightweight TEE support, and the transmission from ground base stations to user terminals relies on traditional SSL (Secure Sockets Layer) while ignoring hardware-level protection. Summary of the Invention

[0004] The purpose of the present invention is to solve the technical problems of the imbalance between security and efficiency in dynamic sharing of satellite data, insufficient dynamic management ability, and lack of cross-domain collaboration mechanism in the existing technology, and provide a method and system for dynamically secure sharing of satellite data based on blockchain.

[0005] To achieve the above purpose, the present invention adopts the following technical solutions:

[0006] In the first aspect, the present invention discloses a method for dynamically secure sharing of satellite data based on blockchain, including:

[0007] The ground base station based on the secure enclave and the satellite service node based on the secure enclave respectively request to verify each other's information and complete key negotiation to obtain an encrypted channel and a negotiation key between the ground base station and the satellite service node;

[0008] The ground base station sends the uploaded satellite data encrypted by the base station in the secure enclave of the ground base station to the satellite service node through the encrypted channel, and the satellite service node decrypts the uploaded satellite data encrypted by the base station through the negotiation key to obtain the decrypted uploaded satellite data and the ground base station key;

[0009] The satellite service node encrypts the decrypted uploaded satellite data with the ground base station key in the secure enclave of the satellite service node, publishes it on the blockchain, and then verifies it through the consensus satellite node and uploads it to the chain. After completing the upload to the chain, the ground base station key is destroyed;

[0010] The ground base station sends the ground base station key to the satellite service node through the encrypted channel. The satellite service node reads the satellite data on the blockchain into the secure enclave of the satellite service node and decrypts it with the ground base station key to obtain the decrypted satellite data, which is then sent to the secure enclave of the ground base station. After the transmission is completed, the ground base station key is destroyed.

[0011] A further improvement lies in:

[0012] A ciphertext-based attribute encryption algorithm is introduced in both the ground base station based on the secure enclave and the satellite service node based on the secure enclave.

[0013] The satellite service node encrypts the decrypted and uploaded satellite data in the secure enclave of the satellite service node with the ground base station key, publishes it to the blockchain, and then uploads it after verification by the consensus satellite node. After the upload is completed, the ground base station key is destroyed. Specifically:

[0014] The ground base station provides the uploaded satellite data, the ground base station key, and the access policy corresponding to the uploaded satellite data, and sends them to the satellite service node through the satellite data transmission mechanism of the dual-end secure enclave;

[0015] The satellite service node receives and decrypts the uploaded satellite data inside the secure enclave , the key and the access policy in plaintext. Then, it executes CP-ABE initialization to generate the public key . The CP-ABE public key is saved in the secure area page cache of the secure enclave and does not need to be regenerated repeatedly during the operation of the satellite service node;

[0016] The satellite service node encrypts the user satellite data with the ground base station key to generate encrypted satellite data , and then generates an access policy construction tree inside the EPC according to the access policy , and performs CP-ABE attribute encryption on the user key according to the access tree to generate the encrypted key ; where is Encryption, representing the encryption algorithm; the superscript is Symmetric, representing the symmetric encryption algorithm; the superscript is Attribute-Based Encryption, representing the attribute-based encryption algorithm;

[0017] The ciphertext of the satellite data encrypted with the ground base station key and the ground base station key encrypted twice by CP-ABE Are sent as processing results outside the secure enclave through the ocall function and uploaded to the blockchain through the blockchain network for storage.

[0018] The ground base station sends the ground base station key to the satellite service node through the encrypted channel. The satellite service node reads the satellite data on the blockchain into the secure enclave of the satellite service node and decrypts it with the ground base station key to obtain the decrypted satellite data and send it to the secure enclave of the ground base station. After sending, the ground base station key is destroyed. Specifically:

[0019] The ground base station provides the requested satellite data name And the access attributes of the ground base station itself For attribute decryption to restore the key; The information interaction between the ground base station and the satellite service node is protected by the encrypted channel;

[0020] The satellite service node generates a CP-ABE private key according to the access attributes provided by the ground base station And obtains the encrypted satellite data and the secondary encryption key stored during the upload process from the chain according to the satellite data name And copies them into the secure enclave using the ocall function; And the secondary encryption key

[0021] The satellite service node constructs a tree using the access policy And the CP-ABE private key Attempts to decrypt the secondary encryption key. If the attributes provided by the user Meet the access policy requirements for decrypting the satellite data, the ground base station key is restored ; Is Decryption, representing the decryption algorithm; The superscript Is Attribute-Based Encryption, representing the attribute-based encryption algorithm;

[0022] The satellite service node decrypts the encrypted satellite data with the ground base station key Finally, the decrypted satellite data is obtained, and the decrypted satellite data is returned to the secure enclave of the ground base station through the encrypted channel.

[0023] Both the ground base station based on the secure enclave and the satellite service node based on the secure enclave introduce a trusted attribute deletion mechanism based on the attribute pool;

[0024] The construction of the attribute pool is specifically as follows:

[0025] ​​The attribute pool is a collection of attributes, for multiple different deletion strategies , denote the attribute set corresponding to each strategy as Then the attribute pool is expressed as:

[0026]

[0027] For each attribute , use the RSA algorithm to generate the corresponding public key and private key , that is, for each select large prime numbers , and calculate:

[0028]

[0029] Select a random integer satisfying being relatively prime to and , and calculate:

[0030]

[0031] Take ;

[0032] Among them, is the intermediate calculation result, is 's Euler's totient function, is 's inverse element with respect to the integer ; is the total number of strategies, determining the scope of the attribute pool; is the index variable, used to sequentially reference each strategy and its attribute set.

[0033] The trusted attribute deletion mechanism based on the attribute pool includes:

[0034] In the satellite data upload stage, the satellite service node receives the deletion strategy specified by the ground base station, decomposes the attribute set from the deletion strategy. For each attribute in the set, if the attribute does not exist in the attribute pool, it is added to the attribute pool. Each operation of adding a new attribute to the attribute pool will generate a public-private key pair of the RSA algorithm bound to the attribute. If the current attribute is already included in the attribute pool, it is skipped; after adding attributes to the attribute pool, the satellite service node generates a random deletion key inside its secure enclave and uses the deletion key to encrypt the ground base station key twice. Generate a large prime number inside the secure enclave and initialize the first node node, and then recursively construct a deletion tree starting from the root node according to the deletion strategy and perform secret sharing of the deletion key, specifically:

[0035] If the node is the root node, generate a polynomial: , according to the threshold number generate split messages: ; for each child node of the node, pass to , let ; where is the secret value, is the coefficient of the -th term of the polynomial, is the modulus;

[0036] If the node is a non-root node, generate a polynomial ; then perform the same message generation and passing process as in 1;

[0037] If the node is a leaf node, save the value passed from its parent node, then look up the RSA public key corresponding to the leaf property of the child node in the property pool , and encrypt the value with the public key: , save the value in the current leaf node; where and together form the public key ; is the encrypted secret value, saved in the leaf node; is the intermediate parameter passed from the parent node; is the property identifier corresponding to the leaf node; represents the modulo operation, which means finding the remainder after dividing two integers;

[0038] After the deletion tree construction in the satellite data upload stage is completed, serialize the deletion tree and copy it outside the secure enclave and save it on the blockchain; since each leaf node is encrypted with the RSA key corresponding to its property, the exposure of the deletion tree externally will not cause the leakage of the deletion key; after the value of each leaf node is saved in the encryption stage, delete the RSA public key corresponding to the property from the property pool; the property pool inside the secure enclave only maintains one RSA private key for each property.

[0039] The trusted property deletion mechanism based on the property pool further includes:

[0040] During the satellite data download phase, the satellite service node receives the access attributes from the ground base station and decrypts the doubly encrypted key using CP-ABE. If the decryption fails, the subsequent processes do not need to be executed; if the decryption is successful, the satellite service node requests the corresponding deletion tree ciphertext from outside the secure enclave and restores the deletion key; the restoration process is the message restoration process of traversing the deletion tree later and recursively executing the Shamir threshold algorithm for each node. Specifically:

[0041] If node is a leaf node, search in the attribute pool for the RSA private key corresponding to the current node's attribute ; if the search fails, it proves that the current node's attribute has been deleted by a certain ground base station, so the leaf node decryption fails and returns a null value; otherwise, obtain the saved value and decrypt it: ; after successful decryption, pass the value to the parent node;

[0042] For non-leaf nodes , denote each child node of the current node node as , and respectively let ; after completion, denote the set of ciphertext values restored from the child nodes of node as . If the number of non-empty elements in the set is less than , the decryption fails and returns a null value to its parent node; otherwise, take out no less than of the to restore the value of the current node: , where , is the number value of at its parent node, usually starting from 1 and increasing sequentially; ∑ is the symbol for summation; ∏ is the symbol for product; is the loop variable for the summation operation, traversing the index from 0 to ; is the loop variable for the product operation, traversing the index from 0 to ; is the polynomial degree or the total number of attributes, limiting the range of summation and product; is the value of the variable at ; is the value of the variable at ; is the secret value; is a large prime number generated in the secure enclave; is the target index for the current calculation, determining the specific form of ;​ is the value of the function at the point ; The modulo operation represents finding the remainder after dividing two integers; is a combined operation that represents performing integer division and taking the remainder simultaneously;

[0043] Treat the root node as a non - leaf node. If it returns empty, the decryption algorithm fails. Otherwise, calculate its value, which is the original text ; After the message restoration is successful, the deletion key for the secondary encryption of the ground base station key will be obtained. Use the deletion key to decrypt the secondary - encrypted ciphertext to restore the ground base station key. Note that the ground base station key is the original key used to encrypt satellite data. Therefore, decrypt the satellite data and return it to the ground base station; On the contrary, when the decryption fails, the ground base station key cannot be restored, and the satellite data stored on the blockchain will be regarded as deleted because it cannot be recovered.

[0044] The working process of the ground base station based on the secure enclave is specifically as follows:

[0045] The satellite service node first initializes the local secure enclave, and then works in the untrusted area to continuously listen for requests through the network port. After obtaining a request, it enters the secure enclave to work, executes the DH key negotiation algorithm to initialize and generate its own public key, and generates the information dh_msg1;

[0046] The local secure enclave generates a report, writes dh_msg1 into the custom data area of the report and requests local QE verification. After successful verification, it obtains the QUOTE from the key manager side and sends it to the user side. At the same time, it waits for and receives the QUOTE from the user side and forwards it to the Intel remote authentication server for verification;

[0047] After the verification is completed, read dh_msg2 from the custom data area of the QUOTE at the ground base station side, obtain the DH public key of the user side and calculate the negotiated key. Then, pack the connection information and authentication result into dh_msg3 and send it back to the user side;

[0048] The satellite service node reads the encrypted uploaded satellite data sent by the ground base station side into the secure enclave and decrypts it with the negotiated key to obtain the decrypted uploaded satellite data and the ground base station key;

[0049] The satellite service node encrypts the satellite data with the ground base station key in its secure enclave. The encrypted satellite data leaves the secure enclave and is published to the blockchain network. Then, after being consensus - verified by the consensus satellite nodes, it is uploaded to the chain, and the ground base station key is destroyed inside the secure enclave.

[0050] The working process of the satellite service node based on the secure enclave is specifically as follows:

[0051] The ground base station provides satellite data, the ground base station key, and the access policy corresponding to the satellite data, and sends these to the satellite service node end through the satellite data transmission mechanism of the dual - end secure enclave;

[0052] The satellite service node end receives and decrypts the satellite data inside the secure enclave , the key and the access policy in plaintext, and then executes CP - ABE initialization to generate the public key , where represents a bilinear group; is a generator of the group used to generate other group elements; is generated by the secret parameter in the master key. During the encryption process, combines with the attribute policy to participate in the ciphertext generation; is the multiplicative inverse of under the modulus of the group order; is used in the key generation phase and combines with the user attributes to generate the private key; is the result based on the bilinear pair, where is another secret parameter of the master key; The CP - ABE public key

[0053] is saved in the secure area page cache of the secure enclave and does not need to be regenerated repeatedly during the operation of the satellite service node end; , where is the symmetric encryption key, is the satellite data, is the symmetric encryption algorithm, is the satellite data ciphertext; Then, according to the access policy , an access policy construction tree is generated inside the EPC, and the user key is encrypted by CP - ABE attributes according to the access tree to generate the encrypted key , where is the ABE public key, is the symmetric encryption key, is the access policy, is the ABE encrypted key; is the symmetric encryption key ciphertext;

[0054] The satellite data ciphertext encrypted by the ground base station key and the ground base station key encrypted by CP - ABE secondary encryption As the processing result, it reaches outside the secure enclave through the ocall function and is uploaded to the blockchain through the blockchain network for storage;

[0055] During the entire satellite data upload process, the plaintext of the satellite data related to the ground base station information only exists inside the secure enclave of the satellite service node, and the key finally stored on the blockchain is the secondary encryption key.

[0056] In a second aspect, the present invention discloses a satellite data dynamic security sharing system based on a blockchain, including:

[0057] A verification and negotiation unit, configured to respectively request the ground base station based on the secure enclave and the satellite service node based on the secure enclave to verify each other's information and complete key negotiation, so as to obtain an encrypted channel and a negotiation key between the ground base station and the satellite service node;

[0058] A satellite service node upload decryption unit, configured to send the uploaded satellite data encrypted by the base station in the secure enclave of the ground base station to the satellite service node through the encrypted channel by the ground base station, and the satellite service node decrypts the uploaded satellite data encrypted by the base station through the negotiation key to obtain the decrypted uploaded satellite data and the ground base station key;

[0059] A satellite data upload unit, configured to encrypt the decrypted uploaded satellite data by the satellite service node in the secure enclave of the satellite service node through the ground base station key, and publish it to the blockchain and then verify it through the consensus satellite node and upload it to the chain. After the upload is completed, the ground base station key is destroyed;

[0060] A satellite data download unit, configured to send the ground base station key to the satellite service node through the encrypted channel by the ground base station, and the satellite service node reads the satellite data on the blockchain into the secure enclave of the satellite service node and decrypts it through the ground base station key to obtain the decrypted satellite data and send it to the secure enclave of the ground base station. After the sending is completed, the ground base station key is destroyed.

[0061] Compared with the prior art, the present invention has the following beneficial effects:

[0062] The present invention discloses a method for dynamically and securely sharing satellite data based on blockchain. An end-to-end secure channel is established through dual-end enclaves, which can be achieved by deploying SGX trusted hardware at both the ground base station and the satellite service node. Combining the remote authentication protocol with the Diffie-Hellman key negotiation ensures that the entire data transmission process is carried out in a trusted environment. Operations such as encryption, decryption, and access control are restricted within the Enclave, eliminating untrusted memory interactions. At the same time, it liberates the computing power of the ground base station and realizes an efficient and secure data upload and download process. Through dual-end enclaves and blockchain technology, end-to-end encrypted transmission and on-chain consensus verification are achieved, effectively resisting network attacks and illegal interceptions.

[0063] Furthermore, the CP-ABE algorithm is reconstructed inside the SGX Enclave. Using the Montgomery group operation library to support complex operations such as bilinear mapping enables access policy determination and key encryption / decryption to be fully executed in a trusted environment. Only the ground base station key is secondarily encrypted through attribute encryption, and the encrypted result is stored in combination with the blockchain, ensuring that the satellite data plaintext only exists in the trusted area, and even the system administrator cannot steal the original data. Based on attribute-based encryption (CP-ABE) and secret sharing technology, it supports on-demand dynamic adjustment of access rights and secure deletion, reducing management complexity.

[0064] Furthermore, an attribute pool is introduced to uniformly manage the RSA key pairs. Combining the threshold secret sharing technology, the deletion key shards are bound to attributes, and the irreversible invalidation of the multi-file associated key can be achieved by deleting the attribute private key. Implementing the attribute pool with a hash table supports constant-level attribute addition and deletion operations, avoiding the performance loss of traversing multiple files in the traditional scheme. At the same time, relying on SGX to ensure the security of key generation and deletion significantly improves the dynamic deletion efficiency and system scalability. The attribute pool combines the threshold algorithm to centrally manage the key shards, greatly reducing the impact of deletion operations on system performance and avoiding the multi-file traversal bottleneck. Description of the Drawings

[0065] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for use in the embodiments. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.

[0066] Figure 1 It is a flowchart of a method for dynamically and securely sharing satellite data based on blockchain in the present invention;

[0067] Figure 2 It is a system model diagram of the dynamic and secure sharing of satellite data in the present invention;

[0068] Figure 3 This is the workflow of the ground base station during the data upload process of the satellite data transmission mechanism based on dual - end enclaves in the present invention;

[0069] Figure 4 This is the workflow of the satellite service node during the data upload process of the satellite data transmission mechanism based on dual - end enclaves in the present invention;

[0070] Figure 5 This is the process of encrypting and uploading satellite data in the trusted access control mechanism based on SGX in the present invention;

[0071] Figure 6 This is the process of encrypting and downloading satellite data in the trusted access control mechanism based on SGX in the present invention;

[0072] Figure 7 This is the process of deleting attributes based on the attribute pool in the present invention;

[0073] Figure 8 This is the unit diagram of a satellite data dynamic security sharing system based on blockchain in the present invention.

[0074] Among them: 1 - blockchain; 2 - satellite consensus node; 3 - ground base station; 4 - satellite service node. Detailed implementation manners

[0075] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Usually, the components of the embodiments of the present invention described and illustrated in the accompanying drawings here can be arranged and designed in various different configurations.

[0076] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed present invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.

[0077] It should be noted that: similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.

[0078] Term explanation:

[0079] 1. Block - SatShare: A method for dynamically and securely sharing satellite data based on blockchain.

[0080] 2. enclave: A secure enclave, in the field of computing, refers to a security protection mechanism that can isolate specific tasks and data to prevent malicious attacks.

[0081] 3. SGX: Software Guard Extensions, a hardware-based trusted execution environment technology launched by Intel, aiming to provide a higher level of security for scenarios such as cloud computing, data security, and privacy protection.

[0082] 4. CP-ABE: Ciphertext-Policy Attribute-Based Encryption, a ciphertext-policy attribute-based encryption. It is an advanced encryption technology aiming to provide fine-grained access control for data.

[0083] 5. EPID: Enhanced Privacy ID, an enhanced privacy identifier, a hardware-based remote authentication technology launched by Intel, aiming to provide secure and privacy-protected authentication services for application scenarios such as cloud computing and the Internet of Things.

[0084] 6. QUOTE report: QE is responsible for generating a report containing device status and attestation information.

[0085] 7. DH key: Diffie-Hellman, the Diffie-Hellman key exchange algorithm is a protocol for securely exchanging keys over a public network.

[0086] 8. dh_msg1: In the Diffie-Hellman key exchange protocol, both parties (usually called Alice and Bob) need to exchange a series of public information to negotiate a shared key. dh_msg1 is the public information sent by Alice or Bob in the first step.

[0087] 9. Local QE: Usually refers to Quoting Enclave or Quoting Entity, a component in a trusted execution environment (such as Intel SGX).

[0088] 10. sgx_create_enclave(): A function in SGX used to create an Enclave, that is, to create a protected execution environment.

[0089] 11. session_request_ecall(): It is an ECALL (Enclave Call) function for an Enclave to call external services. ECALL is the interface for an application or host system to enter the Enclave.

[0090] 12. Attestation Verification Service: (Remote Attestation Verification Service) is a component of SGX remote attestation, used to verify whether the Quote (attestation data) generated by the Enclave is valid.

[0091] 13. EREPORT: It is an instruction inside SGX, used to generate the attestation data (Quote) required for remote attestation.

[0092] 14. sgx_read_ocall(): It is an OCALL (Outside Call) function in SGX, used to enable the Enclave to call the functions of the external environment. OCALL is the interface for the Enclave to call the external environment internally, usually used for interaction with external systems.

[0093] 15. sgx_send_ocall(): It is another OCALL function, which is used to send data or requests from the Enclave to the external system.

[0094] 16. AES_CMAC_ENC(): It is an encryption function that implements the AES-CMAC (AES-Cipher-based Message Authentication Code) algorithm, which is a method for generating a message authentication code (MAC) based on the AES algorithm.

[0095] 17. AES CMAC DEC(): It is an encryption function that implements the AES-CMAC (AES-Cipher-based Message Authentication Code) algorithm, which is a method for generating a message authentication code (MAC) based on the AES algorithm.

[0096] 18. listen(): Linux listens on a port.

[0097] 19. Hash(): Hash algorithm.

[0098] 20. EPC: Enclave Page Cache, the enclave page cache.

[0099] 21. TEE: Trusted Execution Environment, a trusted execution environment.

[0100] 22. : Modulo Operation, a modulo operation, which represents finding the remainder after dividing two integers.

[0101] 23. RSA algorithm: The first widely used public-key encryption system, proposed by Ronald Rivest, Adi Shamir, and Leonard Adleman in 1977. Its name is taken from the initials of the surnames of the three inventors.

[0102] 24. Shamir threshold algorithm: Proposed by Adi Shamir in 1979, it is a secret sharing scheme based on Lagrange interpolation polynomials. Its core idea is to divide a secret (such as a key, data) into n parts and distribute them to different participants. The original secret can only be recovered when at least t parts are aggregated, and no information can be obtained with less than t parts.

[0103] 25. Intel: Intel, a leading enterprise in the global semiconductor industry, taken from the abbreviation of "Integrated Electronics".

[0104] 26. : Encryption, representing an encryption algorithm.

[0105] 27. : Symmetric, representing a symmetric encryption algorithm.

[0106] 28. : Attribute-Based Encryption, representing an attribute-based encryption algorithm.

[0107] 29. : Decryption, representing a decryption algorithm.

[0108] The following further describes the present invention in detail with reference to the accompanying drawings:

[0109] See Figure 1 , an embodiment of the present invention discloses a blockchain-based dynamic secure sharing method for satellite data, including:

[0110] S1. The ground base station based on the secure enclave and the satellite service node based on the secure enclave respectively request to verify each other's information and complete key negotiation to obtain an encrypted channel and a negotiated key between the ground base station and the satellite service node;

[0111] S2. The ground base station sends the satellite data uploaded after base station encryption in the secure enclave of the ground base station to the satellite service node through the encrypted channel. The satellite service node decrypts the satellite data uploaded after base station encryption through the negotiated key to obtain the decrypted uploaded satellite data and the ground base station key.

[0112] S3. The satellite service node performs satellite encryption on the decrypted uploaded satellite data through the ground base station key in the secure enclave of the satellite service node, publishes it on the blockchain, and after verification by the consensus satellite node, it is uploaded to the chain. After the upload is completed, the ground base station key is destroyed.

[0113] S4. The ground base station sends the ground base station key to the satellite service node through the encrypted channel. The satellite service node reads the satellite data on the blockchain into the secure enclave of the satellite service node and decrypts it through the ground base station key to obtain the decrypted satellite data and sends it to the secure enclave of the ground base station. After the sending is completed, the ground base station key is destroyed.

[0114] The present invention discloses a method for dynamically and securely sharing satellite data based on blockchain. An end-to-end secure channel is established through dual-end enclaves, which can be realized by simultaneously deploying SGX trusted hardware at the ground base station and the satellite service node. Combining the remote authentication protocol and the Diffie-Hellman key negotiation ensures that the entire data transmission process is carried out in a trusted environment. Operations such as encryption, decryption, and access control are restricted within the enclave, eliminating untrusted memory interactions. At the same time, the computing power of the ground base station is liberated to achieve an efficient and secure data upload and download process. Through dual-end enclaves and blockchain technology, end-to-end encrypted transmission and on-chain consensus verification are realized, effectively resisting network attacks and illegal interceptions.

[0115] The following details the content of the present invention in combination with specific embodiments:

[0116] See Figure 2 , the method for dynamically and securely sharing satellite data based on blockchain (Block-SatShare) in the present invention has three roles: satellite service nodes, satellite consensus nodes, and ground base stations. Their functions are as follows:

[0117] Satellite service nodes: Satellite service nodes undertake functions such as querying, uploading to the chain, and sharing of satellite data. They act as the main service providers in the platform, passing the requested satellite data to the target nodes to ensure the availability and response speed of satellite data.

[0118] Satellite consensus nodes: The task of satellite consensus nodes is to verify and synchronize data to ensure the consistency and security of satellite data. These nodes communicate with each other to ensure the reliability of satellite data and handle complex environmental situations.

[0119] Ground base stations: Ground base stations are responsible for data interaction with satellite nodes, including the collection, upload, and query of satellite data. In addition, ground base stations can also execute access control policies to manage the access rights of other users to satellite data, ensuring the privacy and security of the data.

[0120] The blockchain-based dynamic secure satellite data sharing scheme (Block-SatShare) in the present invention mainly includes three core mechanisms, namely, a satellite data transmission mechanism based on dual-end enclaves, a trusted access control mechanism based on SGX, and a trusted attribute deletion mechanism based on SGX.

[0121] I. Satellite data transmission mechanism based on dual-end enclaves: Block-SatShare deploys SGX trusted hardware at both the ground base station and the satellite service node. Combining the supporting remote authentication protocol and the dual-end enclave message transmission protocol, it ensures the end-to-end secure transmission of user requests and files between the two enclaves during the upload and download processes. At the same time, operations such as file encryption and decryption, access control, and secure deletion are deployed inside the enclave of the satellite service node, liberating the computing power of the ground base station while ensuring the security and trustworthiness of the computing process of the satellite service node.

[0122] This mechanism deploys Intel SGX trusted hardware at both the ground base station end and the satellite service node end, enabling each of the ground base station end and the satellite service node end to maintain an enclave. At the same time, by leveraging hardware security measures such as EPID provided by SGX and combining with the asymmetric encryption algorithm, an interactive protocol for remote authentication between the two enclaves is given. The protocol can establish a secure channel protected by a negotiated key between the two enclaves, enabling the requests of the ground base station and satellite data to be securely transmitted end-to-end from one enclave to another for processing without being intercepted by network attackers or illegally.

[0123] See Figure 3 , under this mechanism, the working process of the ground base station during the satellite data upload process is as follows:

[0124] Step 1: The ground base station initializes and creates a local enclave, and then sends a remote authentication request to the satellite service node. The request information includes identity information, network connection information, etc.

[0125] Step 2: The ground base station receives the QUOTE report provided by the satellite service node enclave and forwards it to the Intel remote authentication server to request remote authentication. After successful authentication, the dh_msg1 provided by the satellite service node for Diffie-Hellman (DH) key negotiation can be obtained from the custom data area of the QUOTE. The message includes the global public key of the DH algorithm and the DH public key of the satellite service node;

[0126] Step 3: The ground base station enclave generates a report, calculates the ground base station public key as dh_msg2 based on dh_msg1 and writes it into the custom data area of the report, and requests the local QE to generate a QUOTE report through the EREOPRT instruction and send it to the satellite service node;

[0127] Step 4: The ground base station calculates the negotiated key and receives dh_msg3 returned by the satellite service node. This message contains the satellite service node's authentication result of the ground base station's QUOTE report and the final processing result of the remote authentication request. The authentication phase is now completed, and the ground base station saves the negotiated key in the local enclave.

[0128] Step 5: When the ground base station applies for satellite data upload, the ground base station reads the satellite data and key to the enclave through the ocall function, and then encrypts the negotiated key and sends it to the satellite service node in the cloud through the network. At this point, the upload phase is completed.

[0129] See also Figure 4 ,Under this mechanism, the workflow of the satellite service node during satellite data upload is as follows:

[0130] Step 1: The satellite service node first initializes the local enclave, then works in the untrusted area and continuously listens for requests through the network port. After receiving the request, it enters the enclave to initialize the DH key negotiation algorithm and generate its own public key, generating the message dh_msg1;

[0131] Step 2: The local enclave generates a report, writes the information dh_msg1 into the custom data area of the report and requests local QE verification. After successful verification, it obtains the key manager-side QUOTE and sends it to the user side. At the same time, it waits for and receives the user-side QUOTE and forwards it to the Intel remote authentication server to request verification.

[0132] Step 3: After the verification is completed, dh_msg2 is read from the custom data area of QUOTE on the ground base station, the user's DH public key is obtained and the negotiated key is calculated. Then the connection information and authentication result are packaged into dh_msg3 and sent back to the user.

[0133] Step 4: The satellite service node reads the encrypted satellite data sent by the ground base station into the enclave and decrypts it with the negotiated key to obtain the satellite data and the ground base station key;

[0134] Step 5: The satellite service node encrypts the satellite data with the ground base station key in its enclave. The encrypted satellite data leaves the enclave and is published to the blockchain network, and then is verified and chained through the consensus of the consensus satellite nodes. The ground base station key is destroyed inside the enclave.

[0135] Under this mechanism, the download process of satellite data is similar to the upload process. The enclaves of the ground base station and the satellite service node first request local QE verification and exchange their respective QUOTE reports, respectively verify the information of the other party through remote service requests, and at the same time exchange the DH public keys of both parties to complete the key negotiation. Then the ground base station sends the ground base station key to the satellite service node through the negotiated encrypted channel. The latter reads the encrypted file on the blockchain into the enclave and decrypts it with the ground base station key, sends the decrypted satellite data to the ground base station enclave and destroys the ground base station key.

[0136] II. Policy-based trusted access control mechanism: Block-SatShare designs an attribute encryption algorithm that can run completely inside the enclave of the satellite service node based on the ciphertext-policy attribute encryption algorithm (CP-ABE), so that the overall algorithm works in a protected memory area and does not need to have any data interaction with the untrusted memory area during operation, thus enabling the satellite service node to have the function of performing trusted access control.

[0137] This mechanism realizes the function of access control by introducing the ciphertext-policy attribute encryption algorithm (CP-ABE) inside the enclave of the satellite service node to encrypt the user key according to attributes. For this reason, this paper implements the CP-ABE algorithm based on SGX, so that the CP-ABE algorithm can run completely inside the enclave of SGX as a trusted runtime library without the support of any external untrusted libraries or system calls during operation. The present invention implements a small group operation trusted library based on the Montgomery multiplicative group inside the enclave to support group operations such as bilinear mapping widely used in the CP-ABE algorithm, so that each process of the algorithm can be carried out in the protected memory area.

[0138] When the ground base station requests to upload satellite data, the satellite data and the ground base station key are transmitted to the satellite service node enclave through an encrypted channel. The satellite service node performs CP-ABE attribute encryption on the ground base station key after encrypting the file within the enclave. When the ground base station requests to download satellite data, the ground base station provides access attributes or the CP-ABE private key, and the satellite service node attempts to decrypt the ground base station key. Among them, the encrypted satellite data is obtained by symmetrically encrypting the original file with the ground base station key, and the attribute encryption algorithm only performs secondary encryption and decryption on the ground base station key used to encrypt the original satellite data.

[0139] See Figure 5 , under this mechanism, the satellite data upload process is as follows:

[0140] Step 1: The ground base station provides satellite data, the ground base station key, and the access policy corresponding to the satellite data, and sends these through the satellite data transmission mechanism of the dual-end enclave to the satellite service node side;

[0141] Step 2: The satellite service node side receives and decrypts the uploaded satellite data , the key and the access policy plaintext within the enclave, and then performs CP-ABE initialization to generate the public key , represents a bilinear group (usually a multiplicative cyclic group of prime order), containing the common parameters of the group (such as order, generator, etc.); is a generator of the group used to generate other group elements; is generated by the secret parameter in the master key. During the encryption process, combines with the attribute policy to participate in the ciphertext generation; is the multiplicative inverse of under the modulus of the group order; is used in the key generation phase to combine with user attributes to generate the private key; is the result based on the bilinear pair, where is another secret parameter of the master key. The CP-ABE public key is used to bind the message with the access policy to ensure that only users who meet the policy can decrypt. The CP-ABE public key is saved in the secure area page cache (EPC) of the enclave and does not need to be regenerated repeatedly during the operation of the satellite service node side.

[0142] Step 3: The satellite service node encrypts the user satellite data with the ground base station key to generate the encrypted satellite data , where is a symmetric encryption key, is to upload satellite data, is a symmetric encryption algorithm, is the satellite data ciphertext; then according to the access policy generate an access policy construction tree inside the EPC and perform CP-ABE attribute encryption on the user key to generate an encryption key according to the access tree where is the ABE public key, is the symmetric encryption key, is the access policy, is the ABE encryption key; is the ciphertext of the symmetric encryption key; among them, is Encryption, representing the encryption algorithm; the superscript is Symmetric, representing the symmetric encryption algorithm; the superscript is Attribute-Based Encryption, representing the attribute-based encryption algorithm;

[0143] Step 4: The satellite data ciphertext obtained by encrypting with the ground base station key and the ground base station key double-encrypted by CP-ABE are used as processing results to reach outside the enclave through the ocall function and are uploaded to the blockchain through the blockchain network for storage.

[0144] Throughout the satellite data upload process, the plaintext of the satellite data related to the ground base station information only exists inside the enclave at the satellite service node end, and the key finally stored on the blockchain is the double-encrypted key. Therefore, even an untrusted satellite system administrator cannot obtain the plaintext of the satellite data.

[0145] See Figure 6 Under this mechanism, the satellite data download process is as follows:

[0146] Step 1: The ground base station needs to provide the requested satellite data name and the access attributes of the ground base station itself for attribute decryption to restore the key. Similarly, the information interaction between the ground base station end and the satellite service node end is protected by a secure channel;

[0147] Step 2: The satellite service node end generates a CP-ABE private key according to the access attributes provided by the ground base station , is the secret parameter in the master secret key (MSK); is a random number introduced during the generation of the user's private key and is used to protect the confidentiality of the master key ; is a set of user attributes ; is a hash function that maps an attribute to an element in a group ; is a random number generated by the system is a random number associated with an attribute ; binds an attribute to a random number to ensure that only users with the attribute can generate a valid decryption component. According to the satellite data name retrieve the encrypted satellite data stored during the upload process and the secondary encryption key from the chain, and use the ocall function to copy them into the enclave; ;

[0148] Step 3: The satellite service node uses the access policy to construct a tree and the CP-ABE private key to attempt to decrypt the secondary encryption key. If the attributes provided by the user meet the access policy requirements for decrypting the satellite data, the ground base station key can be restored; is Decryption, representing the decryption algorithm; the superscript is Attribute-Based Encryption, representing the attribute-based encryption algorithm;

[0149] Step 4: The satellite service node decrypts the encrypted satellite data with the ground base station key and finally obtains the decrypted satellite data and returns the decrypted satellite data to the enclave at the ground base station end through a secure data transmission channel.

[0150] Reconstruct the CP-ABE algorithm inside the SGX Enclave, use the Montgomery group operation library to support complex operations such as bilinear mapping, and make access policy determination and key encryption and decryption fully executed in a trusted environment. Only the ground base station key is encrypted twice through attribute encryption, and the encryption result is stored in combination with the blockchain to ensure that the satellite data plaintext only exists in the trusted area, and even the system administrator cannot steal the original data. Based on attribute encryption (CP-ABE) and secret sharing technology, it supports on-demand dynamic adjustment of access rights and secure deletion, reducing management complexity.

[0151] III. Trusted Attribute Deletion Mechanism Based on Attribute Pool: Block-SatShare performs secondary encryption on the file encryption key by maintaining an additional key pair inside the enclave of the satellite service node. When deleting, only this key needs to be deleted, and the key of the encrypted file cannot be recovered, making the encrypted file stored on the chain completely inaccessible, thus achieving the secure deletion function. Further, the threshold algorithm is used to split the secondary encryption key for message splitting to support attribute-based secure deletion.

[0152] This trusted attribute deletion mechanism based on the attribute pool assigns an independent RSA public and private key pair to each attribute, and splits the deletion key into multiple ciphertexts according to the secret sharing technology and stores them in the attribute pool. When a certain attribute needs to be deleted, only the private key corresponding to this attribute needs to be removed from the attribute pool, making the key shards dependent on this attribute unable to be decrypted. In the specific process, when encrypting data, the deletion key is split and bound to the attribute; decryption requires aggregating a sufficient number of attribute key shards. Once an attribute is deleted, the remaining shards cannot meet the threshold, resulting in the key being irrecoverable and the data becoming permanently invalid. This mechanism centrally manages keys through the attribute pool, combines trusted hardware (SGX) to ensure the security of shard generation and deletion, realizes efficient and secure dynamic deletion, and avoids the performance bottleneck of traversing multiple files.

[0153] (1)Construction of Attribute Pool

[0154] The attribute pool is a collection of attributes. For multiple different deletion policies Denote the set of attributes corresponding to each policy as Then the attribute pool can be expressed as:

[0155]

[0156] For each attribute , use the RSA algorithm to generate its corresponding public key and private key , that is, for each Select large prime numbers Pr , and calculate:

[0157]

[0158] Select a random integer satisfying being relatively prime to and , and calculate:

[0159]

[0160] Take .

[0161] (2)See Figure 7, The workflow of the attribute deletion algorithm based on the attribute pool

[0162] The attribute pool maintains a separate RSA public-private key pair for each attribute in each deletion policy, and at the same time deduplicates the duplicate attributes in the policy. In actual use, the attribute pool is very suitable to be implemented as a hash table data structure, with the attribute string as the key index and the RSA key pair as the value corresponding to the key. After the attribute pool is constructed, the encryption process of the secure deletion algorithm based on the attribute pool is as Figure 7 shown.

[0163] In the satellite data upload stage, the satellite service node receives the deletion policy specified by the ground base station, and then decomposes the attribute set from the deletion policy. For each attribute in the set, if the attribute does not exist in the attribute pool, it is added to the attribute pool, and each operation of adding a new attribute to the pool will generate a public-private key pair of the RSA algorithm bound to the attribute. If the current attribute is already included in the attribute pool, it is skipped. After adding attributes to the attribute pool, the satellite service node generates a random deletion key inside its enclave and uses the deletion key to encrypt the ground base station key twice, generates a large prime number inside the enclave and initializes the first node node, and then recursively constructs a deletion tree from the root node according to the deletion policy and secretly splits the deletion key:

[0164] Step 1: If node is the root node, generate a polynomial:

[0165] .

[0166] Generate according to the threshold number split messages: .

[0167] For each child node of node, pass to , and let ; where is the secret value, is the coefficient of the th term of the polynomial, is the modulus.

[0168] Step 2: If node is a non-root node, generate a polynomial:

[0169] ; then execute the same message generation and transmission process as in 1;

[0170] Step 3: If node is a leaf node, save the value passed by its parent node, and then look up in the attribute pool for the leaf attribute corresponding to the child node​ The corresponding RSA public key , encrypt the value with the public key: , and save the and together form the public key ; is the encrypted secret value, which is saved in the leaf node; is the intermediate parameter passed by the parent node; is the attribute identifier corresponding to the leaf node; is the modulo operation, which represents the remainder obtained by dividing two integers.

[0171] After the deletion tree construction in the upload stage is completed, the deletion tree can be serialized and copied outside the enclave and saved on the blockchain. Since each leaf node is encrypted by the RSA key corresponding to its attribute, the exposure of the deletion tree externally will not cause the leakage of the deletion key. After the value of each leaf node is saved in the encryption stage, the RSA public key corresponding to the attribute can be deleted from the attribute pool. The attribute pool inside the enclave only maintains one RSA private key for each attribute.

[0172] In the satellite data download stage, the satellite service node receives the access attribute from the ground base station and decrypts the twice-encrypted key with CP-ABE. If the decryption fails, it proves that the ground base station has no access permission and there is no need to execute the subsequent process. If the decryption is successful, the satellite service node requests the corresponding deletion tree ciphertext outside the enclave and tries to restore the deletion key. The restoration process is the subsequent process of traversing the deletion tree and recursively executing the message restoration process of the Shamir threshold algorithm for each node:

[0173] Step 1: If node is a leaf node, look up the RSA private key corresponding to the current node attribute in the attribute pool. If the lookup fails, it proves that the attribute has been deleted by a ground base station, so the decryption of this leaf node fails and a null value is returned. Otherwise, obtain the saved value and decrypt it: . After successful decryption, pass the value to the parent node.

[0174] Step 2: For a non-leaf node , denote each child node of the current node node as , and respectively let . After completion, denote the set of ciphertext values restored from the child nodes of node as , if the number of non-empty elements in the set is less than , decryption fails and an empty value is returned to its parent node; otherwise, no less than of the copies are used to restore the value of the current node: , where , is the number value at its parent node, usually incremented sequentially starting from 1; ∑ is the symbol for summation; ∏ is the symbol for product; is the loop variable for the summation operation, traversing the index from 0 to ; is the loop variable for the product operation, traversing the index from 0 to ; is the degree of the polynomial or the total number of attributes, limiting the range of summation and product; is the variable at ; is the variable at ; is the secret value; is a large prime number generated in the secure enclave; is the target index of the current calculation, determining the specific form; is the value of the function at the point ; represents the modulo operation to find the remainder after dividing two integers; is a combined operation, representing performing integer division and taking the remainder simultaneously;

[0175] Step 3: Treat the root node as a non-leaf node. If an empty value is returned, the decryption algorithm fails, proving that a large number of attributes in the permissions related to this satellite data have been deleted, and the remaining attributes are insufficient to grant access permissions to the file, and the satellite data has been securely deleted. Otherwise, calculate its value, which is the original text . After the message restoration is successful, the deletion key for the secondary encryption of the ground base station key will be obtained. Decrypt the secondary encrypted ciphertext with the deletion key to restore the ground base station key. Note that the ground base station key is the original key used to encrypt the satellite data. Therefore, the satellite data can be decrypted and returned to the ground base station. On the contrary, when decryption fails, the ground base station key cannot be restored, and the satellite data stored on the blockchain will be considered in a deleted state because it cannot be recovered.

[0176] During the attribute deletion phase, the satellite service node receives the set of attributes that the ground base station wishes to delete. In attribute deletion based on the Shamir secret sharing algorithm, it is necessary to traverse the deletion tree for each attribute in the set and delete the corresponding leaf nodes in the tree. When multiple related satellite data exist, all satellite data needs to be traversed. The introduction of the attribute pool significantly optimizes the deletion operation. It only needs to search for the corresponding attribute in the attribute pool and delete its RSA private key. As a result, the leaf nodes in the deletion tree corresponding to the attribute cannot be decrypted during the download phase. Deleting an attribute in the attribute pool will take effect on all deletion trees containing this attribute.

[0177] In practical applications, since the attribute pool needs to frequently perform operations of inserting and deleting attributes, the data structure it adopts will directly affect the performance of the system and is related to the number of requests that the key manager can handle per unit time. In the code implementation phase of this paper, a common hash table is selected to construct the attribute pool to obtain the performance of constant-time insertion, deletion, and key-value lookup. The hash table uses the attribute string as the key and the corresponding RSA public-private key pair as the value. The attribute pool will always exist inside the enclave of the key manager during its operation.

[0178] The introduction of the attribute pool significantly optimizes the deletion performance at the cost of sacrificing some performance in the upload and download phases. For each individual attribute in the upload and download phases, the additional overhead is equivalent to performing one RSA key generation plus RSA encryption and one RSA decryption respectively. Since the upload and download operations only affect the satellite data that needs to be uploaded and downloaded currently, and the number of specific satellite data affected by attribute deletion is related to the actual attributes to be deleted, the introduction of the attribute pool will bring a huge efficiency improvement when deleting attributes that exist in the deletion strategies of a large number of satellite data. At the same time, the existence of the attribute pool enables the deletion trees constructed for each satellite data and the deletion keys encoded according to these deletion trees to be safely stored outside the enclave, which can effectively reduce the memory overhead of the trusted area when the number of satellite data is large.

[0179] Introduce an attribute pool to uniformly manage the RSA key pairs, combine the threshold secret sharing technology, bind the deletion key shards to the attributes, and irreversible invalidation of the multi-file associated key can be achieved by deleting the attribute private key. Implement the attribute pool with a hash table, support constant-level attribute addition and deletion operations, avoid the performance loss of traversing multiple files in the traditional scheme, and rely on SGX to ensure the security of key generation and deletion, significantly improving the dynamic deletion efficiency and system scalability. The attribute pool combines the threshold algorithm to centrally manage the key shards, greatly reducing the impact of deletion operations on the system performance and avoiding the bottleneck of multi-file traversal.

[0180] See Figure 8 , the present invention discloses a blockchain-based satellite data dynamic security sharing system, including:

[0181] A target ECI position coordinate module, configured to obtain the position information of a target and convert the position information into a target ECI position coordinate;

[0182] A satellite ECI position coordinate module, configured to obtain the satellite orbit elements at time 0 and calculate the satellite ECI position coordinate based on the satellite orbit elements at time 0;

[0183] A satellite observation coordinate system module, configured to obtain the installation matrix and rotation matrix of the observation payload on the satellite; based on the installation matrix and rotation matrix, convert the target ECI position coordinate and the satellite ECI position coordinate into the observation coordinate system on the satellite, and respectively obtain a target coordinate and a satellite coordinate;

[0184] A turntable ground guidance angle module, configured to calculate an observation vector based on the target coordinate and the satellite coordinate; further calculate the azimuth angle and elevation angle of the observation vector, and use the azimuth angle and elevation angle of the observation vector as the on-orbit autonomous ground guidance angle of the turntable.

[0185] A third object of the present invention is to provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, where when the processor executes the computer program, the blockchain-based dynamic and secure sharing method of satellite data is implemented.

[0186] The blockchain-based dynamic and secure sharing method of satellite data includes the following steps:

[0187] The ground base station and the satellite service node based on enclave respectively request to verify each other's information and complete key negotiation to obtain an encrypted channel and a negotiation key between the ground base station and the satellite service node;

[0188] The ground base station sends the uploaded satellite data encrypted by the base station in the ground base station enclave to the satellite service node through the encrypted channel, and the satellite service node decrypts the uploaded satellite data encrypted by the base station through the negotiation key to obtain the decrypted uploaded satellite data and the ground base station key;

[0189] The satellite service node encrypts the decrypted uploaded satellite data through the ground base station key in the satellite service node enclave, publishes it on the blockchain, and then uploads it to the chain after verification by the consensus satellite node, and destroys the ground base station key to complete the upload of satellite data;

[0190] The ground base station sends the ground base station key to the satellite service node through the encrypted channel. The satellite service node reads the satellite data on the blockchain into the satellite service node enclave and decrypts it with the ground base station key to obtain the decrypted satellite data, which is then sent to the ground base station enclave. The ground base station key is destroyed to complete the download of the satellite data and achieve the dynamic and secure sharing of satellite data.

[0191] The fourth object of the present invention is to provide a computer-readable storage medium storing a computer program, which when executed by a processor implements the method for dynamically and securely sharing satellite data based on blockchain.

[0192] The method for dynamically and securely sharing satellite data based on blockchain includes the following steps:

[0193] The ground base station and the satellite service node based on enclave respectively request to verify each other's information and complete key negotiation to obtain the encrypted channel and negotiation key between the ground base station and the satellite service node.

[0194] The ground base station sends the uploaded satellite data encrypted at the base station in the ground base station enclave to the satellite service node through the encrypted channel. The satellite service node decrypts the uploaded satellite data encrypted at the base station with the negotiation key to obtain the decrypted uploaded satellite data and the ground base station key.

[0195] The satellite service node encrypts the decrypted uploaded satellite data with the ground base station key in the satellite service node enclave, publishes it to the blockchain, and after verification by the consensus satellite node, it is uploaded to the chain. The ground base station key is destroyed to complete the upload of the satellite data.

[0196] The ground base station sends the ground base station key to the satellite service node through the encrypted channel. The satellite service node reads the satellite data on the blockchain into the satellite service node enclave and decrypts it with the ground base station key to obtain the decrypted satellite data, which is then sent to the ground base station enclave. The ground base station key is destroyed to complete the download of the satellite data and achieve the dynamic and secure sharing of satellite data.

[0197] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM (Compact Disc Read-Only Memory), optical memory, etc.) that contain computer-usable program code.

[0198] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for realizing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0199] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing devices to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device realizes the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0200] These computer program instructions can also be loaded onto a computer or other programmable data processing devices, so that a series of operation steps are executed on the computer or other programmable devices to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable devices provide steps for realizing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0201] The above are only the preferred embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A method for dynamically and securely sharing satellite data based on blockchain, characterized in that Including: The ground base station based on the secure enclave and the satellite service node based on the secure enclave respectively request to verify each other's information and complete key negotiation to obtain an encrypted channel and a negotiation key between the ground base station and the satellite service node; Both the ground base station based on the secure enclave and the satellite service node based on the secure enclave introduce a ciphertext-based attribute encryption algorithm; The ground base station sends the uploaded satellite data encrypted in the secure enclave of the ground base station to the satellite service node through the encrypted channel. The satellite service node decrypts the uploaded satellite data encrypted by the base station through the negotiation key to obtain the decrypted uploaded satellite data and the ground base station key; The satellite service node performs satellite encryption on the decrypted uploaded satellite data in the secure enclave of the satellite service node through the ground base station key, publishes it to the blockchain, and then uploads it after verification by the consensus satellite node. After the upload is completed, the ground base station key is destroyed; The satellite service node performs satellite encryption on the decrypted uploaded satellite data in the secure enclave of the satellite service node through the ground base station key, publishes it to the blockchain, and then uploads it after verification by the consensus satellite node. After the upload is completed, the ground base station key is destroyed. Specifically: The ground base station provides the uploaded satellite data, the ground base station key, and the access policy corresponding to the uploaded satellite data, and sends them to the satellite service node through the satellite data transmission mechanism of the dual-end secure enclave; The satellite service node receives and decrypts the uploaded satellite data within the secure enclave , the secret key and the access policy in plaintext. After that, it executes CP-ABE initialization to generate the public key . The CP-ABE public key is saved in the secure area page cache of the secure enclave and does not need to be regenerated repeatedly during the operation of the satellite service node; The ground base station key of the satellite service node encrypts the user satellite data to generate encrypted satellite data , and then according to the access policy generate an access policy construction tree inside the EPC , and for the user key perform CP-ABE attribute encryption on the access tree to generate an encrypted key ; among them, represents the encryption algorithm; the superscript represents the symmetric encryption algorithm; the superscript represents the attribute-based encryption algorithm; The ciphertext of satellite data encrypted by the ground base station key and the ground base station key double-encrypted by CP-ABE are used as processing results to reach the outside of the secure enclave through the ocall function and are uploaded to the blockchain through the blockchain network for storage; The ground base station sends the ground base station key to the satellite service node through the encrypted channel. The satellite service node reads the satellite data on the blockchain into the secure enclave of the satellite service node and decrypts it through the ground base station key to obtain the decrypted satellite data and sends it to the secure enclave of the ground base station. After the sending is completed, the ground base station key is destroyed.

2. The method for dynamically and securely sharing satellite data based on blockchain according to claim 1, wherein The ground base station sends the ground base station key to the satellite service node through the encrypted channel. The satellite service node reads the satellite data on the blockchain into the secure enclave of the satellite service node and decrypts it through the ground base station key to obtain the decrypted satellite data and sends it to the secure enclave of the ground base station. After the sending is completed, the ground base station key is destroyed. Specifically: The ground base station provides the requested satellite data name and the access attributes of the ground base station itself for decrypting the attributes to restore the key; the information interaction between the ground base station and the satellite service node is protected by an encrypted channel; The satellite service node generates a CP-ABE private key according to the access attributes provided by the ground base station and obtains the encrypted satellite data stored during the upload process and the secondary encryption key from the chain according to the satellite data name and copies them to the inside of the secure enclave using the ocall function;​​​ The satellite service node constructs a tree using the access policy and the CP-ABE private key Attempts to decrypt the secondary encryption key. If the attributes provided by the user meet the access policy requirements corresponding to decrypting the satellite data, the ground base station key is restored ; Indicates the decryption algorithm; the superscript Indicates the attribute-based encryption algorithm; The satellite service node decrypts the encrypted satellite data with the ground base station key Finally, the decrypted satellite data is obtained, and the decrypted satellite data is returned to the secure enclave of the ground base station through an encrypted channel.

3. The method for dynamically and securely sharing satellite data based on blockchain according to claim 1, characterized in that Both the ground base station based on the secure enclave and the satellite service node based on the secure enclave introduce a trusted attribute deletion mechanism based on the attribute pool; The construction of the attribute pool is specifically as follows: The attribute pool is a collection of attributes for multiple different deletion strategies , and denote the set of attributes corresponding to each strategy as Then the attribute pool is represented as: For each attribute , generate its corresponding public key using the RSA algorithm and private key , that is, for each select large prime numbers Pr , and calculate: Select a random integer Satisfy with Coprime and , and calculate: Take ; Among them, is the intermediate calculation result, is the Euler's totient function of is the multiplicative inverse of with respect to the integer is the total number of strategies, which determines the range of the attribute pool; is the index variable used to sequentially reference each strategy and its set of attributes.

4. The method for dynamically and securely sharing satellite data based on blockchain according to claim 3, wherein, The trusted attribute deletion mechanism based on the attribute pool includes: In the satellite data upload phase, the satellite service node receives the deletion policy specified by the ground base station, decomposes the attribute set from the deletion policy. For each attribute in the set, if the attribute does not exist in the attribute pool, it is added to the attribute pool. Each operation of adding a new attribute to the attribute pool generates a public-private key pair of the RSA algorithm bound to the attribute. If the current attribute is already included in the attribute pool, it is skipped; after adding attributes to the attribute pool, the satellite service node generates a random deletion key inside its secure enclave and uses the deletion key to encrypt the ground base station key twice, and generates large prime numbers inside the secure enclave And initialize the first node node, and then recursively construct a deletion tree from the root node according to the deletion policy and perform secret sharing of the deletion key. Specifically: If node is the root node, generate a polynomial: , according to the threshold number generate split messages: ; For each child node of node, pass to , let ; Where is the secret value, is the coefficient of the -th term of the polynomial, is the modulus; If the node is a non-root node, generate a polynomial ; then perform the same message generation and transmission process as in 1; If the node is a leaf node, save the value passed from its parent node, then look up the RSA public key corresponding to the leaf attribute of the child node in the attribute pool , and encrypt the value with the public key : , and save the value within the current leaf node; where and together form the public key ; ; is the encrypted secret value, saved in the leaf node; is the intermediate parameter passed by the parent node; is the attribute identifier corresponding to the leaf node; is the modulo operation, representing the remainder obtained by dividing two integers; After the deletion tree construction in the satellite data upload phase is completed, serialize the deletion tree and copy it outside the secure enclave for storage on the blockchain; since each leaf node is encrypted with the RSA key corresponding to its attributes, the exposure of the deletion tree externally will not lead to the leakage of the deletion key; after the value of each leaf node is saved in the encryption phase, delete the corresponding RSA public key from the attribute pool; the attribute pool inside the secure enclave only maintains one RSA private key for each attribute.

5. The method for dynamically and securely sharing satellite data based on blockchain according to claim 4, wherein The trusted attribute deletion mechanism based on the attribute pool also includes: In the satellite data download stage, the satellite service node receives the access attributes of the ground base station and decrypts the doubly encrypted key using CP-ABE. If the decryption fails, the subsequent process does not need to be executed; if the decryption is successful, the satellite service node requests the corresponding deletion tree ciphertext outside the secure enclave and restores the deletion key; the restoration process is the subsequent process of traversing the deletion tree and recursively executing the message restoration process of the Shamir threshold algorithm for each node. Specifically: If the node is a leaf node, search for the RSA private key corresponding to the current node's attributes in the attribute pool. If the search fails, it proves that the current node's attributes have been deleted by a certain ground base station. Then the decryption of the leaf node fails and a null value is returned; otherwise, obtain the saved value and decrypt it: After successful decryption, pass the value to the parent node; ​ For non - leaf nodes , denote each child node of the current node node as , and respectively let ; After completion, the set of ciphertext values restored from the child nodes of node is . If the number of non - empty elements in the set is less than , the decryption fails, and an empty value is returned to its parent node. Otherwise, take out no less than of copies to restore the value of the current node: , where , is the number value of at its parent node, increasing sequentially from 1; ∑ is the symbol for summation operation; ∏ is the symbol for product operation; is the loop variable for the summation operation, traversing the index from 0 to ; is the loop variable for the product operation, traversing the index from 0 to ; is the polynomial degree or the total number of attributes, limiting the range of summation and product; is the value of the variable at ; is the value of the variable at ; is the secret value; is a large prime number generated in the secure enclave; is the target index of the current calculation, determining the specific form of ; is the value of the function at the point ; represents the modulo operation to find the remainder after dividing two integers; is a combined operation, representing performing integer division and taking the remainder simultaneously; Treat the root node as a non-leaf node. If it returns null, the decryption algorithm fails; otherwise, calculate its value, which is the original text. After the message restoration is successful, the deletion key for the secondary encryption of the ground base station key will be obtained. Use the deletion key to decrypt the secondary encrypted ciphertext to restore the ground base station key. Note that the ground base station key is the original key used to encrypt the satellite data. Therefore, decrypt the satellite data and return it to the ground base station. On the contrary, when the decryption fails, the ground base station key cannot be restored, and the satellite data stored on the blockchain will be regarded as deleted because it cannot be recovered.

6. The method for dynamically and securely sharing satellite data based on blockchain according to claim 1, wherein The working process of the ground base station based on the secure enclave is specifically as follows: The satellite service node first initializes the local secure enclave, and then works in the untrusted area to continuously listen for requests through the network port. After obtaining a request, it enters the secure enclave to work, executes the DH key negotiation algorithm to initialize and generate its own public key, and generates the information dh_msg1. The local secure enclave generates a report, writes dh_msg1 into the custom data area of the report and requests local QE verification. After successful verification, it obtains the QUOTE of the key manager side and sends it to the user side. At the same time, it waits for and receives the QUOTE of the user side and forwards it to the Intel remote authentication server for verification. After the verification is completed, it reads dh_msg2 from the custom data area of the QUOTE of the ground base station side, obtains the DH public key of the user side and calculates the negotiated key. Then, it packs the connection information and authentication result into dh_msg3 and sends it back to the user side. The satellite service node reads the encrypted satellite data uploaded by the ground base station into the secure enclave and decrypts it with the negotiated key to obtain the decrypted uploaded satellite data and the ground base station key. The satellite service node encrypts the satellite data with the ground base station key in its secure enclave. The encrypted satellite data leaves the secure enclave and is published to the blockchain network. Then, after being verified by the consensus satellite node, it is uploaded to the chain, and the ground base station key is destroyed inside the secure enclave.

7. The method for dynamically and securely sharing satellite data based on blockchain according to claim 1, wherein The working process of the satellite service node based on the secure enclave is specifically as follows: The ground base station provides the satellite data to be uploaded, the ground base station key, and the access policy corresponding to the satellite data, and sends these through the satellite data transmission mechanism of the dual-end secure enclave to the satellite service node side. The satellite service node receives and decrypts satellite data within the secure enclave. , key and access policies The plaintext, then execute CP-ABE to initialize and generate the public key ,in represents a bilinear group; It's a group A generator of , used to generate other group elements; By the secret parameter in the master key Generate, during the encryption process, Participate in ciphertext generation in combination with attribute strategies; yes Multiplicative inverses in modular group order; Used in the key generation phase, combined with user attributes to generate private keys; is the result based on bilinear pairings, where Another secret parameter of the master key; CP-ABE public key It is stored in the secure enclave's secure zone page cache and does not need to be regenerated during operation on the satellite service node side; The satellite service node encrypts the user's satellite data with the ground base station key to generate encrypted satellite data , where is the symmetric encryption key, is the satellite data, is the symmetric encryption algorithm, is the ciphertext of the satellite data; then, according to the access policy an access policy construction tree is generated inside the EPC , and the user key is encrypted with CP-ABE attributes according to the access tree to generate the encrypted key , where is the ABE public key, is the symmetric encryption key, is the access policy, is the encrypted key for ABE encryption; is the ciphertext of the symmetric encryption key; The satellite data ciphertext encrypted by the ground base station key and the ground base station key double-encrypted via CP-ABE are used as processing results, reach the outside of the secure enclave through the ocall function, and are uploaded to the blockchain via the blockchain network for storage; During the entire satellite data upload process, the plaintext of the satellite data related to the ground base station information only exists inside the secure enclave of the satellite service node side, and the key finally stored in the blockchain is the secondary encryption key.

8. A satellite data dynamic security sharing system based on blockchain, which is used to implement the satellite data dynamic security sharing method based on blockchain as described in any one of claims 1-7, characterized in that, Including: A verification negotiation unit, which is used to respectively request the ground base station based on the secure enclave and the satellite service node based on the secure enclave to verify each other's information and complete key negotiation, so as to obtain the encrypted channel and the negotiated key between the ground base station and the satellite service node. The satellite service node upload decryption unit, which is used for the ground base station to send the uploaded satellite data encrypted by the base station in the secure enclave of the ground base station to the satellite service node through the encrypted channel. The satellite service node decrypts the uploaded satellite data encrypted by the base station with the negotiated key to obtain the decrypted uploaded satellite data and the ground base station key. The satellite data upload unit, which is used for the satellite service node to encrypt the decrypted uploaded satellite data with the ground base station key in the secure enclave of the satellite service node, and publish it to the blockchain and then upload it to the chain after being verified by the consensus satellite node. After the upload to the chain is completed, the ground base station key is destroyed. The satellite data download unit, which is used for the ground base station to send the ground base station key to the satellite service node through the encrypted channel. The satellite service node reads the satellite data on the blockchain into the secure enclave of the satellite service node and decrypts it with the ground base station key to obtain the decrypted satellite data and sends it to the secure enclave of the ground base station. After the sending is completed, the ground base station key is destroyed.

Citation Information

Patent Citations

  • Internet of Things system

    CN116368355A

  • Satellite-based encryption communication method and device, terminal and storage medium

    CN118118074A