A post-quantum key distribution method and system for satellite communications based on QUIC

By introducing a two-stage key exchange method TPKEM in satellite communication, the QUIC protocol exchange quantum keys are used to solve the problems of quantum computing attacks and computing resource consumption in satellite networks, and safe and efficient communication is achieved.

CN120281477BActive Publication Date: 2025-08-19ZHEJIANG LAB
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510752487.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-06
Publication Date
2025-08-19
Estimated Expiration
2045-06-06

AI Technical Summary

Technical Problem

The existing QUIC protocol faces the security threat of quantum computing attacks in satellite communications, and traditional post-quantum encryption algorithms are not suitable for computing resource-sensitive satellite networks in terms of computing resource consumption and connection establishment delay.

Method used

The two-stage key exchange method (TPKEM) is used to exchange post-quantum keys between satellite terminals and ground control terminals, and exchange public keys and application keys through the QUIC protocol, reducing the computing burden of satellite terminals, and introducing post-quantum encryption algorithms to resist quantum computing attacks.

Benefits of technology

It provides security protection against quantum computing attacks, reduces the computing consumption of satellite terminals, and does not require upper-layer applications to be modified, reduces system upgrade costs, and is suitable for a variety of systems with limited computing resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281477B_ABST
    Figure CN120281477B_ABST
Patent Text Reader

Abstract

The present invention discloses a QUIC-based satellite communication post-quantum key distribution method and system, which belongs to the field of information security. The present invention includes: designing a two-stage key distribution method, in which the ground control terminal sends the public key of the public-private key pair generated by the post-quantum key encapsulation algorithm to the satellite terminal that initiates the request, and retains the corresponding private key; wherein the public key is used to generate the application key and the key ciphertext, and the private key is used to decrypt the key ciphertext to obtain the corresponding application key; in the second stage, the ground control terminal and the satellite terminal complete the exchange of application keys; the two-stage key distribution method is integrated with the QUIC protocol, and the next generation post-quantum encryption algorithm is introduced into the QUIC protocol. The present invention has the ability to resist future quantum computing attacks, can reduce the computing consumption of satellite terminals, and not only has low transformation and migration costs, but is also suitable for multi-scenario adaptation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security, and in particular to a QUIC-based satellite communication post-quantum key distribution method and system. Background Art

[0002] In recent years, with the continued decline in satellite launch costs, satellite internet networks, represented by SpaceX's StarLink, have experienced rapid growth. Numerous countries and regions, including the United States, China, and the European Union, have launched or participated in satellite internet projects. Satellite internet technology is gaining increasing recognition and widespread adoption in fields such as military, scientific research, remote sensing, and even entertainment, playing an increasingly important role in our daily lives. However, satellite internet networks also face numerous challenges, with data transmission security and efficiency being crucial.

[0003] Unlike terrestrial environments, satellite networks operate in an electromagnetically open space environment, characterized by dynamic and time-varying network topology, long transmission delays, and high bit error rates. Traditional Transmission Control Protocol / Internet Protocol (TCP / IP) suffers from poor performance in satellite internet networks. To overcome these shortcomings, a new data transmission protocol, QUIC, is gaining adoption in satellite communications. QUIC (Quick UDP Internet Connection), proposed by Google based on the User Datagram Protocol (UDP), offers shorter handshake delays and introduces features such as multi-streaming and connection migration. The protocol has now been standardized and replaces TCP in the next-generation Hypertext Transfer Protocol (HTTP / 3), also known as HTTP / 3.

[0004] Currently, the security of the QUIC protocol is primarily based on the Transport Layer Security (TLS) protocol. The cipher suites that TLS relies on are based on proven algorithms, such as RSA, ECC, AES, and SHA, which are widely used in current network environments. However, with the rapid development of quantum computers, the TLS protocol faces significant security threats, making the integration of the latest post-quantum cryptographic algorithms into TLS imperative. Currently, in the experimental integration of post-quantum cryptographic algorithms in the latest TLS 1.3, a hybrid approach is commonly used with non-post-quantum cryptographic algorithms. Because post-quantum cryptographic algorithms require more computation than traditional algorithms, this hybrid approach consumes significant computing resources each time a connection is established, increasing connection latency and making it unsuitable for computationally intensive scenarios such as satellites. Summary of the Invention

[0005] In view of the shortcomings of the existing technology, the purpose of the present invention is to provide a post-quantum key distribution method and system for satellite communications based on QUIC.

[0006] The object of the present invention is achieved through the following technical solution: a QUIC-based satellite communication post-quantum key distribution method, comprising the following steps:

[0007] The satellite terminal sends a first initial data packet to the ground control terminal, where the first initial data packet includes a first-stage client Hello message, hereinafter referred to as HELO(client_p0);

[0008] After receiving and reading the first initial data packet, the ground control terminal generates a public-private key pair, retains the private key, and stores the public key in the first public key data packet. The ground control terminal then returns the second initial data packet and the first public key data packet in sequence. The second initial data packet contains the first-stage server Hello message, hereinafter referred to as HELO (server_p0).

[0009] After receiving and reading the second initial data packet and the first public key data packet, the satellite terminal verifies the signature information of the first public key data packet; after the verification is passed, the information in the second initial data packet and the first public key data packet is integrated with the information in the first public key data packet and the information in the first public key data packet is persisted locally; and a second public key data packet is generated, wherein the second public key data packet includes a first-stage FINISH message;

[0010] After receiving the second public key data packet, the ground control terminal integrates the information generated through negotiation and the private key corresponding to the unique number field in the first-stage FINISH message and persists it locally.

[0011] The satellite terminal generates an application key and key ciphertext for the current session based on the persistence information, and generates a first handshake packet and a first application packet. The first handshake packet includes a second-phase client Hello message and key ciphertext, and the first application packet needs to transmit application data; the second-phase client Hello message is hereinafter referred to as HELO (client_p1).

[0012] After receiving and processing the first handshake data packet and the first application data packet, the ground control terminal generates a second handshake data packet and a second application data packet and returns them to the satellite terminal. The second handshake data packet includes a second-stage server Hello message, hereinafter referred to as HELO (server_p1).

[0013] After receiving and processing the second handshake data packet and the second application data packet, the satellite terminal generates a third handshake data packet, wherein the third handshake data packet includes a second-phase FINISH message;

[0014] After the ground control terminal receives the FINISH message in the third handshake data packet, the current key exchange is completed.

[0015] Furthermore, the HELO (client_p0) message includes the phase state P0, a supported key suite list, a unique number, a first random string, a recommended public key validity period, and a first current timestamp; the HELO (server_p0) message includes the phase state P0, a selected post-quantum encryption algorithm suite, a unique number, a second random string, an actual public key validity period, and a second current timestamp; the selected post-quantum encryption algorithm suite is selected according to the supported key suite list; and the public key validity period selects the minimum value between the recommended public key validity period and the actual public key validity period required by the ground control terminal configuration.

[0016] Furthermore, the satellite terminal generates an application key and a key ciphertext for the current session based on the persistent information using a public key in the information, and generates a first handshake data packet and a first application data packet, including: the satellite terminal obtains a symmetric key of the satellite terminal based on the application key and the HELO (client_p1) message, hereinafter referred to as key_client, and encrypts the first application data packet based on the key_client and a symmetric encryption algorithm in the encryption algorithm suite.

[0017] Furthermore, the HELO (client_p1) message includes the phase status P1, a unique number, a third random character string, and a third current timestamp.

[0018] Further, the ground control terminal receives and processes the first handshake data packet and the first application data packet, and then generates a second handshake data packet and a second application data packet and returns them to the satellite terminal, comprising:

[0019] The ground control terminal recovers the corresponding cryptographic algorithm suite, private key, and public key validity period based on the unique number of the HELO(client_p1) message in the first handshake data packet; if the public key is within the validity period, decrypts the key ciphertext using the private key to obtain the application key of the current session; and obtains the satellite terminal's symmetric key key_client based on the application key and the HELO(client_p1) message, which is used together with the symmetric encryption algorithm in the cryptographic suite to decrypt the first application data packet sent by the satellite terminal;

[0020] The HELO (server_p1) message includes the phase status P1, a unique number, a fourth random string, and a fourth current timestamp. A server-side symmetric key, hereinafter referred to as key_sever, is derived based on the application key and the HELO (server_p1) message and is used together with the symmetric encryption algorithm in the encryption suite to encrypt a second application data packet sent by the ground terminal.

[0021] Furthermore, the satellite terminal receives and processes the second handshake data packet and the second application data packet to generate a third handshake data packet, where the third handshake data packet includes a second-phase FINISH message.

[0022] The satellite terminal derives the ground control terminal's symmetric key key_server based on the HELO (server_p1) message in the second handshake data packet and the application key of the current session, which is used to decrypt the second application data packet together with the symmetric encryption algorithm in the encryption suite; and sends a third handshake data packet carrying a second-stage FINISH message to notify the ground control terminal to complete all key exchange processes.

[0023] The present invention also provides a QUIC-based satellite communication post-quantum key distribution system, comprising:

[0024] The two-phase key exchange module (TPKEM module) is used to implement the exchange of application keys between the client and the server, including the generation and persistence of negotiation information of the initial data packet and public key data packet in the first phase and the handshake data packet in the second phase; it replaces the native TLS1.3 protocol of QUIC;

[0025] The QUIC handshake module is responsible for coordinating key exchange with the QUIC encryption / decryption module and the TPKEM module;

[0026] Among them, after the satellite terminal initiates a connection request, the QUIC handshake module initiates a key exchange request to the two-stage key exchange module; after the TPKEM module receives the request, it decides to return the first initial data packet or the first handshake data packet to the QUIC handshake module for sending based on whether the one-stage exchange information is persisted locally.

[0027] Furthermore, the determining of returning the first initial data packet or the first handshake data packet to the QUIC handshake module based on whether the local persistent one-stage exchange information exists includes:

[0028] If the local data exchange does not persist, the first initial data packet is returned. After the ground control terminal receives and processes the first initial data packet, the QUIC handshake module hands it over to the TPKEM module. The TPKEM module generates a second initial data packet and the first public key data packet and hands them over to the QUIC handshake module before sending.

[0029] After the satellite control terminal receives and processes the second initial data packet and the first public key data packet, the QUIC handshake module hands them over to the TPKEM module. The TPKEM module persists the negotiation information and generates a second public key data packet, which is then handed over to the QUIC handshake module for sending.

[0030] After the ground control terminal receives and processes the second public key data packet, the QUIC handshake module hands it over to the TPKEM module. The TPKEM module persists the negotiation information and notifies the QUIC handshake module to end the first-phase key exchange.

[0031] Furthermore, the step of returning the first initial data packet or the first handshake data packet to the QUIC handshake module based on whether the local persistent one-stage exchange information exists also includes:

[0032] If there is a phase of information exchange in local persistence, the first handshake data packet is returned. After the ground control terminal receives and processes the first handshake data packet, the QUIC handshake module hands it over to the TPKEM module. The TPKEM module decrypts the application key of the current session and generates a second handshake data packet, which is then handed over to the QUIC handshake module for sending.

[0033] After the satellite control terminal receives and processes the second handshake data packet, the QUIC handshake module hands it over to the TPKEM module. The TPKEM module generates a third handshake data packet and hands it over to the QUIC handshake module before sending it.

[0034] After the ground control terminal receives and processes the third handshake data packet, the QUIC handshake module hands it over to the TPKEM module, and the TPKEM module notifies the QUIC handshake module to end the key exchange process.

[0035] The present invention also provides a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, it implements the QUIC-based satellite communication post-quantum key distribution method.

[0036] The beneficial effects of the present invention are:

[0037] 1. Resistance to future quantum computing attacks: This paper proposes a novel TPKEM method to adapt to post-quantum key encapsulation and digital signature algorithms and incorporates it into the leading transport layer protocol, QUIC. This ensures that satellite communication systems built on this method can withstand future quantum computing attacks, providing long-term security.

[0038] 2. Reduced Computational Consumption on Satellite Terminals: Post-quantum cryptographic algorithms are inherently computationally complex. For example, key generation, ciphertext generation, and decryption in post-quantum key encapsulation algorithms require relatively high computational resources. To conserve precious satellite terminal computing resources, TPKEM offloads public and private key generation and ciphertext decryption to the ground control terminal, which has more abundant computing resources. The satellite terminal is solely responsible for key and key ciphertext generation. Furthermore, a two-phase exchange mechanism enables multiple reuse of public and private keys, reducing the computational overhead required for key generation.

[0039] 3. Low transformation and migration cost: This invention is an upgrade of the transport layer. Upper-layer applications that rely on the QUIC protocol do not need any transformation, thereby reducing the upgrade and transformation costs of the original business system and achieving a smooth transition of the system.

[0040] 4. Adaptation and promotion in other scenarios: Although the present invention is mainly designed for satellite communication systems, it can also be used in other systems with limited terminal computing resources, and can even be adapted for use in the Internet and Internet of Things communication systems. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0042] Figure 1 This is a diagram of the QUIC protocol and TPKEM system architecture of the present invention;

[0043] Figure 2 This is a key exchange flow chart of the TPKEM method of the present invention;

[0044] Figure 3This is a flowchart of the interaction between QUIC and TPKEM in the first phase of the present invention;

[0045] Figure 4 This is the interaction flow chart of QUIC and TPKEM in the second phase of the present invention. DETAILED DESCRIPTION

[0046] Exemplary embodiments will be described in detail herein, examples of which are illustrated in the accompanying drawings. In the following description, when referring to the drawings, like numbers in different figures represent like or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all possible embodiments consistent with the present invention. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present invention, as detailed in the appended claims.

[0047] The terms used in this invention are for the purpose of describing specific embodiments only and are not intended to limit the invention. The singular forms "a," "the," and "the" used in this invention and the appended claims are also intended to include plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" as used herein refers to and includes any or all possible combinations of one or more of the associated listed items.

[0048] It should be understood that although the terms "first," "second," "third," etc. may be used in the present invention to describe various information, such information should not be limited to these terms. These terms are merely used to distinguish information of the same type from one another. For example, first information may also be referred to as second information, and similarly, second information may also be referred to as first information, without departing from the scope of the present invention. Depending on the context, the term "if" as used herein may be interpreted as "when," "when," or "in response to determining."

[0049] The present invention will be described in detail below with reference to the accompanying drawings. Unless there is any conflict, the features of the following embodiments and implementations may be combined with each other.

[0050] This paper proposes a post-quantum key distribution method and system for satellite communications based on QUIC. This method is a two-phase key exchange method (TPKEM). The following details how satellite terminals and ground control terminals use TPKEM to complete the public-private key pair initialization, public key transmission, application key, and key ciphertext generation processes of the post-quantum key encapsulation algorithm. Furthermore, the TPKEM method replaces the existing TLS 1.3 protocol within the QUIC protocol, ultimately achieving a complete secure, efficient, and stable communication solution.

[0051] Example 1

[0052] like Figure 1 As shown in FIG, a satellite communication post-quantum key distribution system based on QUIC is provided in an embodiment of the present invention. The present invention fully utilizes the advantages of QUIC in multiplexing, flow control, multi-path transmission, etc., replaces the TLS1.3 protocol it relies on with the TPKEM method, and introduces the post-quantum encryption algorithm into the QUIC protocol. The system includes:

[0053] QUIC application: refers to the upper-layer application built on the QUIC transport layer protocol, such as HTTP / 3, Socket, etc.

[0054] QUIC encryption / decryption module: The module specifically refers to the data packet encryption / decryption module built by QUIC natively based on the Authenticated Encryption with Associated Data (AEAD) mode. The QUIC encryption / decryption module is used to complete the encryption of sent data packets and the decryption of received data packets. The encryption / decryption keys used by this module will be generated using different strategies according to different handshake stages. The encryption / decryption keys are implemented based on the HKDF function (HMAC-based Extracted-and-Expand Key Derivation Function). In the key derivation process, the application key of the current session is used as the primary key, and the HELO message is input into the HKDF function as a random value after hashing.

[0055] QUIC handshake module: The QUIC handshake module is a transition module located between the QUIC encryption / decryption module and the TPKEM module, and cooperates with the TPKEM module to complete the entire handshake process.

[0056] TPKEM module: The TPKEM module is the core module of the present invention. Its function and positioning are similar to TLS1.3. It completes the exchange of public keys and application keys between the satellite terminal and the ground control terminal through multiple handshakes. Its detailed design will be described in detail later.

[0057] QUIC transmission control module: refers to the native data transmission control module of the QUIC protocol, which completes the specific work of sending data packets, including packet loss detection control, congestion control, multi-stream transmission control, etc.

[0058] UDP transmission: The UDP protocol is the underlying protocol used by QUIC for native data transmission, completing the sending and receiving of data streams.

[0059] Example 2

[0060] like Figure 2The TPKEM method provided in this embodiment of the present invention is shown in Figure 1. The two parties in the key exchange are: the satellite terminal acts as the client initiating the request, and the ground control terminal acts as the server receiving and processing the request. This method is divided into the key encapsulation algorithm public key exchange phase (referred to as phase one) and the application key exchange phase (referred to as phase two), including:

[0061] Phase 1: The goal of this phase is for the ground control terminal to send the public key of the public-private key pair generated by the post-quantum key encapsulation algorithm to the satellite terminal that initiated the request, while retaining the corresponding private key. The public key is used to generate the application key and key ciphertext, and the private key is used to decrypt the key ciphertext to obtain the corresponding application key. The application key is the symmetric key used in the symmetric encryption algorithm and is also called the shared key between the communicating parties. This phase includes:

[0062] 1.1. The satellite terminal sends a first initial data packet to the ground control terminal. The first initial data packet includes a HELO (client_p0) message. The HELO (client_p0) message includes information such as the phase status (P0), a list of supported key suites, a unique number, a random string, a public key validity period, and a current timestamp.

[0063] 1.2. After receiving the HELO (client_p0) message, the ground control terminal returns two data packets, the second initial data packet and the first public key data packet, in sequence.

[0064] Second Initial Data Packet: Similar to the first initial data packet sent by the satellite terminal, this second initial data packet contains a HELO(server_p0) message, which includes fields such as the phase status (P0), the selected post-quantum cryptographic algorithm suite, a unique number, a random string, the public key validity period, and the current timestamp. The selected cryptographic algorithm suite is selected based on the comparison between the support list in HELO(client_p0) and the local support list; the unique number is inherited from HELO(client_p0); and the public key validity period is the minimum value required by the satellite terminal and the ground control terminal.

[0065] The first public key data packet is the core exchange data for the first phase. The ground control terminal initializes a public-private key pair using the selected post-quantum key encapsulation algorithm. The private key is temporarily stored locally, and the public key is added to the public key data packet. The first public key data packet also includes the digital certificate and the digital signature information for the public key data packet.

[0066] 1.3. After receiving the second initial data packet and the first public key data packet from the ground terminal, the satellite terminal first reads the HELO (server_p0) message in the second initial data packet and then verifies the signature of the first public key data packet to ensure that the message is sent by the trusted ground terminal. It then consolidates the unique number, selected cryptographic algorithm suite, public key, and public key validity period, and stores them locally for persistence.

[0067] In addition, the satellite terminal generates a second public key data packet including a FINISH message. The FINISH message includes a unique number field inherited from the HELO (server_p0) message.

[0068] 1.4. After receiving the second public key data packet from the satellite terminal, the ground control terminal integrates the unique number in the HELO message with the negotiated encryption suite, private key, public key validity period and other information, and persists them locally, completing the first stage of the public key exchange process.

[0069] Phase 2: The goal of this phase is to complete the exchange of application keys for the current session between the ground control terminal and the satellite terminal. The application keys are only valid in the current session. The second phase includes:

[0070] 2.1. The satellite terminal generates the application key and key ciphertext for the current session based on the public key in the persistent information of the first phase. This handshake will generate two data packets: the first handshake packet and the first application packet.

[0071] The first handshake packet contains the HELO (client_p1) message and the key ciphertext. The HELO (client_p1) message includes information such as the phase status (P1), a unique number (recovered from persistent information), a random string, and the current timestamp. At this point, the satellite terminal derives the symmetric key (key_client) used to encrypt application data based on the current session's application key and the HELO (client_p1) message.

[0072] The first application packet contains the actual application data to be transmitted. The encryption of this application data is implemented by the QUIC encryption and decryption module using the symmetric encryption algorithm agreed upon in the first phase and key_client. However, the transmission of the application packet at this point does not hinder the subsequent handshake process.

[0073] 2.2. After receiving and processing the first handshake data packet and the first application data packet from the satellite terminal, the ground control terminal also generates a second handshake data packet and a second application data packet from the ground control terminal and returns them to the satellite terminal.

[0074] The ground control terminal then uses the unique ID in the HELO (client_p1) message contained in the satellite terminal's first handshake packet to recover the corresponding cryptographic algorithm suite, private key, and public key validity period. If the public key is within its validity period, the private key is used to decrypt the key ciphertext to obtain the application key for the current session. The ground control terminal then uses the same key derivation strategy as the satellite terminal to generate the satellite terminal's symmetric key (key_client), which is used to decrypt the application data packets sent by the satellite terminal.

[0075] The second handshake packet from the ground control terminal contains the HELO(server_p1) message, which includes information such as the phase status (P1), a unique number (recovered from persistent information), a random string, and the current timestamp. Based on the decrypted application key for the current session and the HELO(server_p1) message, the server symmetric key (key_sever) can be derived. This is used to encrypt application data sent by the ground terminal.

[0076] The encryption and decryption of application packets is primarily handled by the QUIC encryption / decryption module. Incoming application packets are decrypted using the key_client key, while outgoing application packets are encrypted using the key_server key. Similarly, whether or not a packet is sent at this point does not hinder the subsequent handshake.

[0077] 2.3. After receiving and processing the second handshake data packet from the ground control terminal, the satellite terminal generates a new third handshake data packet and returns it.

[0078] The ground control terminal derives the symmetric key (key_server) used by the ground control terminal based on the HELO (client_p1) message in the second handshake packet and the current session application key. This key is used to decrypt subsequent application packets sent by the ground control terminal. At this point, a third handshake packet carrying a FINISH message is sent to notify the ground control terminal that all key exchange processes have been completed.

[0079] In the current session, the subsequent satellite control terminal encrypts the sent application data packets based on key_client and decrypts the received application data packets based on key_server in the QUIC encryption / decryption module.

[0080] 2.4. After the ground control terminal receives the FINISH message in the third handshake packet, it indicates that the current key exchange process is complete. In the current session, all subsequent application data packets sent are encrypted based on key_server, and all received application data packets are decrypted based on key_client.

[0081] When the satellite terminal initiates a connection request, it first checks whether the persistent cipher suite and public key data are available and whether the data is valid. If not, it completes the public key exchange from the first phase, followed by the second phase of application key exchange. If yes, it recovers the public key from the persistent data and begins the second phase of exchange.

[0082] The TPKEM method adopted in the present invention has the following characteristics:

[0083] 1) The ground control terminal needs to complete two operations: key generation and key ciphertext decryption. The satellite terminal completes one key ciphertext generation operation. Relatively speaking, the satellite terminal saves more computing power.

[0084] 2) When the satellite terminal and the ground control terminal initiate data exchange, most connections will be initiated directly from the second phase, and the satellite terminal does not need to wait for the ground control terminal to return the handshake information before sending the application data, that is, realizing 0-RTT data transmission similar to QUIC.

[0085] 3) The key used for each transmission is different, so even if the previous key is stolen, it will not affect the security of subsequent data transmission.

[0086] 4) Regularly and automatically update the public and private key pairs of the key encapsulation algorithm to reduce the harm caused by the theft of the private key, and the update time can be adjusted as needed.

[0087] Example 3

[0088] The TPKEM method is mainly used in the QUIC protocol to complete the exchange of application keys and provide the application keys to the encryption / decryption module of QUIC. All data packets delivered for UDP transmission are encrypted by the encryption / decryption module of QUIC. In the interaction process between the client and service of the QUIC application, the two-stage interaction process between the QUIC protocol and TPKEM is as follows Figure 3 、 Figure 4 As shown, the upper layer application of the satellite terminal built based on QUIC is called QUIC application, the TPKEM method module is called TPKEN (client), and the QUIC protocol layer is called QUIC (client). The application of the ground control terminal built based on QUIC is called QUIC service, the TPKEM method module is called TPKEM (server), and the QUIC protocol layer is called QUIC (server).

[0089] An embodiment of the present invention provides a QUIC-based satellite communication post-quantum key distribution method, which integrates the QUIC protocol with the TPKEM method. The method includes the following steps:

[0090] Phase 1: Figure 3As shown, the exchange of information such as the encryption suite and the public and private keys of the key encapsulation algorithm is completed.

[0091] 1.1. The client's QUIC application initiates a connection request:

[0092] QUIC (client) first notifies TPKEM (client) to check whether there is a persistent key suite and a public key for the post-quantum key encapsulation algorithm locally. If not, QUIC (client) initiates a phase one handshake request.

[0093] After receiving the handshake request, TPKEM (client) initializes the HELO (client_p0) message and encapsulates it in the first initial data packet and delivers it to QUIC (client) for transmission.

[0094] The first initial data packet is encrypted by the encryption / decryption module in QUIC (client) and then delivered to the QUIC transport control module for transmission. The encryption algorithm and encryption key initialization of the first initial data packet are both performed using the default mode agreed upon in the QUIC protocol.

[0095] 1.2. After QUIC (server) receives the first initial data packet:

[0096] First, the first initial data packet is decrypted to obtain the HELO(client_p1) message. As with QUIC(client), the decryption algorithm and decryption key initialization are performed using the default mode agreed upon in the QUIC protocol.

[0097] QUIC (server) sends the decrypted HELO (client_p0) message to TPKEM (server). TPKEM (server) parses the HELO (client_p0) message and negotiates a mutually supported set of cipher suites and public key expiration times. It then generates a corresponding server-side HELO (server_p0) message, encapsulates it in a second initial data packet, and delivers it to QUIC (server). QUIC (server) encrypts the second initial data packet in the same manner as the first initial data packet in QUIC (client), using the default agreed-upon mode in the QUIC protocol.

[0098] TPKEM (server) initializes a public-private key pair using the negotiated post-quantum key encapsulation algorithm and adds the public key to the first public key data packet. Furthermore, TPKEM (server) adds the digital certificate to the first public key data packet and signs the public key and certificate data using the negotiated post-quantum digital signature algorithm, adding the signature result to the first public key data packet.

[0099] QUIC (server) encrypts the first public key data packet using a negotiated symmetric encryption algorithm, using a symmetric key derived from the HELO (server) message. After encryption is complete, the second initial data packet and the first public key data packet are sent sequentially.

[0100] 1.3. After QUIC (client) receives the second initial data packet and the first public key data packet:

[0101] First, QUIC (client) decrypts the second initial data packet sent by QUIC (server) based on the default agreed decryption mode, obtains the HELO (server_p0) message, and parses the selected encryption suite, public key expiration time and other information.

[0102] Then QUIC (client) derives the symmetric key for encrypting the public key data packet on the QUIC (server) side through the HELO (server_p0) message, and uses the encryption suite to perform decryption operation with the negotiated symmetric encryption algorithm to obtain the decrypted first public key data packet and send it to TPKEM (client).

[0103] After receiving the first public key packet, TPKEM (client) first verifies the digital certificate and digital signature of the first public key packet. After verification, it persists the negotiated cipher suite, public key, expiration time, and other information. It also generates a FINISH message and adds it to a new second public key packet.

[0104] After receiving the second public key packet, QUIC (client) encrypts and sends it. Its encryption algorithm is based on the symmetric encryption algorithm selected in the negotiation, and the encryption key is derived from the HELO (client_p0) message.

[0105] 1.4. After QUIC (server) receives the second public key data packet:

[0106] QUIC (server) first decrypts the received second public key packet using the negotiated symmetric encryption algorithm derived from the previously received HELO (client_p0). After decryption, the second public key packet is delivered to TPKEM (server).

[0107] After TPKEM (server) reads the FINISH message from the second public key data packet, it indicates that the first phase of the public key exchange process has ended, and persists the previously negotiated encryption suite, the private key in the public key pair, and the expiration time in the local storage.

[0108] Phase II: Figure 4 As shown, the exchange of application keys is completed and the subsequent secure transmission of application data is supported.

[0109] 2.1. After the client initiates a QUIC application connection request:

[0110] QUIC (client) notifies TPKEM (client) to check whether there is a persistent cipher suite and public key locally and that they are within the validity period. If the result is yes, the second phase handshake is directly initiated.

[0111] TPKEM(client) first generates a HELO(client_p1) message, then reads the persistent public key, generates the application key and key ciphertext for the current session, and finally packages the HELO(client_p1) and key ciphertext into the first handshake data packet.

[0112] After QUIC (client) receives the handshake data packet, it is encrypted and sent using the default mode as in the first initial data packet of the same stage.

[0113] At this point, the application key for the current session has been initialized by TPKEM(client) using the locally persisted public key, and the first application data packet can be sent. QUIC(client) encrypts application data using a one-stage persistent symmetric encryption algorithm, using a symmetric key (key_client) derived from the current session application key and HELO(client_p1). It's important to note that whether or not the first application data packet is sent does not hinder the subsequent handshake process.

[0114] 2.2. After QUIC (server) receives the first handshake packet and the first application packet:

[0115] QUIC (server) uses the same default method as the first initial data packet in the same phase to decrypt, obtaining the HELO (client_p1) and application key ciphertext. After decryption, QUIC (server) sends the first handshake data packet to TPKEM (server).

[0116] After receiving the handshake packet, TPKEM (server) recovers the persistent post-quantum key encapsulation private key from the HELO (client_p1) information in the first handshake packet, decrypts the key ciphertext with the private key, obtains the application key for the current session, and passes it to QUIC (server). At the same time, it generates the HELO (server_p1) signal and adds it to the second handshake packet.

[0117] After receiving the second handshake data packet, QUIC (server) encrypts it in the same default way as the first initial data packet and then sends it.

[0118] After obtaining the application key for the current session, QUIC (server) can decrypt the first application packet using the persistent symmetric encryption algorithm of phase 1. The decryption key (key_client) is derived from the decrypted application key for the current session and HELO (client_p1). After decrypting the application packet, QUIC (server) sends it to the QUIC server for processing.

[0119] At this point, QUIC (server) can also send a second application data packet. The data encryption algorithm it uses is also the symmetric encryption algorithm that persists in phase one. The symmetric key (key_server) is derived from the current session application key obtained through decryption and HELO (server_p1). After the application data packet is encrypted, it is sent to QUIC (client). Similarly, whether the application data packet is sent at this step does not hinder the subsequent handshake process. At this point, QUIC (server) has both key_client and key_server, and is fully capable of encrypting and sending application data and decrypting and receiving application data.

[0120] 2.3. After QUIC (client) receives the second handshake packet and the second application packet:

[0121] QUIC (client) receives the second handshake packet, decrypts it using the same default method as the first initial packet, and hands it over to TPKEM (client).

[0122] After TPKEM (client) parses the HELO (server_p1) message, the handshake ends. Finally, a FINISH message is generated and added to the third handshake packet.

[0123] The third handshake data packet with the FINISH message sent by QUIC (client) at this time is encrypted and sent in the same way as the first initial data packet in the same stage.

[0124] At this point, QUIC (client) can derive the server-side symmetric key (key_server) for encrypting data packets based on the received HELO (server_p1) and the previously initialized current session application key. Decryption of the received data packets is then performed based on the negotiated symmetric encryption algorithm. At this point, QUIC (client) now possesses both key_client and key_server, enabling it to encrypt outgoing application data and decrypt incoming application data.

[0125] 2.4. After QUIC (server) receives the final third handshake packet:

[0126] After receiving the final handshake data, QUIC (server) decrypts it in the same way as the first initial data packet in the same stage, and transmits the decrypted third handshake data packet to TPKEM (server).

[0127] After TPKEM (server) parses the FINISH message in the third handshake packet, it indicates that the two-phase handshake process is complete.

[0128] 2.5. Both QUIC (server) and QUIC (client) can fully decrypt received packets and encrypt sent packets. After that, all data sent and received is data generated by the QUIC application and the QUIC service.

[0129] An embodiment of the present invention also provides a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, it implements the QUIC-based satellite communication post-quantum key distribution method described in any of the above embodiments.

[0130] The computer-readable storage medium may be an internal storage unit of any device with data processing capabilities described in any of the aforementioned embodiments, such as a hard disk or memory. The computer-readable storage medium may also be any device with data processing capabilities, such as a plug-in hard disk, a smart media card (SMC), an SD card, a flash card, etc. equipped on the device. Furthermore, the computer-readable storage medium may also include both an internal storage unit of any device with data processing capabilities and an external storage device. The computer-readable storage medium is used to store the computer program and other programs and data required by any device with data processing capabilities, and may also be used to temporarily store data that has been output or is to be output.

[0131] The above embodiments are intended only to illustrate the design concepts and features of the present invention. Their purpose is to enable those skilled in the art to understand the contents of the present invention and implement them accordingly. The scope of protection of the present invention is not limited to the above embodiments. Therefore, any equivalent changes or modifications made based on the principles and design concepts disclosed in the present invention are within the scope of protection of the present invention.

Claims

1. A QUIC-based satellite communication post-quantum key distribution method, characterized in that: The steps include: The satellite terminal sends a first initial data packet to the ground control terminal, where the first initial data packet includes a first-stage client Hello message; After receiving and reading the first initial data packet, the ground control terminal generates a public-private key pair, retains the private key, stores the public key in the first public key data packet, and returns the second initial data packet and the first public key data packet in sequence. The second initial data packet contains the first-stage server Hello message. After receiving and reading the second initial data packet and the first public key data packet, the satellite terminal verifies the signature information of the first public key data packet; after the verification is passed, the information in the second initial data packet and the first public key data packet is integrated and persisted locally; Generate a second public key data packet, where the second public key data packet includes a phase FINISH message; After receiving the second public key data packet, the ground control terminal integrates the information generated through negotiation and the private key corresponding to the unique number field in the first-stage FINISH message and persists it locally. The satellite terminal generates an application key and key ciphertext for the current session based on the persistence information, and generates a first handshake data packet and a first application data packet, wherein the first handshake data packet includes a second-phase client Hello message and key ciphertext, and the first application data packet includes application data to be transmitted; After receiving and processing the first handshake data packet and the first application data packet, the ground control terminal generates a second handshake data packet and a second application data packet and returns them to the satellite terminal, wherein the second handshake data packet includes a second-stage server Hello message; After receiving and processing the second handshake data packet and the second application data packet, the satellite terminal generates a third handshake data packet, wherein the third handshake data packet includes a second-phase FINISH message; After the ground control terminal receives the second-phase FINISH message in the third handshake data packet, the current key exchange is completed.

2. A QUIC-based satellite communication post-quantum key distribution method according to claim 1, characterized in that: The first-stage client Hello message includes a first-stage status, a supported key suite list, a unique number, a first random string, a recommended public key validity period, and a first current timestamp; the first-stage server message includes a first-stage status, a selected post-quantum encryption algorithm suite, a unique number, a second random string, an actual public key validity period, and a second current timestamp; the selected post-quantum encryption algorithm suite is selected based on the supported key suite list; the public key validity period selects the minimum value between the recommended public key validity period and the actual public key validity period required by the ground control terminal configuration.

3. A QUIC-based satellite communication post-quantum key distribution method according to claim 1, characterized in that: The satellite terminal generates an application key and key ciphertext for the current session based on the persistence information, and generates a first handshake data packet and a first application data packet, including: the satellite terminal obtains a symmetric key of the satellite terminal based on the application key and a second-stage client Hello message, and encrypts the first application data packet based on the symmetric key of the satellite terminal and a symmetric encryption algorithm in a selected post-quantum encryption algorithm suite.

4. A QUIC-based satellite communication post-quantum key distribution method according to claim 1, characterized in that: The second-stage client Hello message includes the second-stage status, a unique number, a third random string, and a third current timestamp.

5. A QUIC-based satellite communication post-quantum key distribution method according to claim 4, characterized in that: After the ground control terminal receives and processes the first handshake data packet and the first application data packet, generating a second handshake data packet and a second application data packet and returning them to the satellite terminal includes: The ground control terminal recovers the corresponding cryptographic algorithm suite, private key, and public key validity period based on the unique number of the second-phase Client Hello message in the first handshake data packet; if the public key is within the validity period, decrypts the key ciphertext using the private key to obtain the application key of the current session; and derives the satellite terminal's symmetric key based on the application key and the second-phase Client Hello message, and uses the symmetric key of the satellite terminal to decrypt the first application data packet sent by the satellite terminal together with the symmetric encryption algorithm in the cryptographic suite; The second-stage server Hello message includes the second-stage status, a unique number, a fourth random string, and a fourth current timestamp; the server's symmetric key is derived based on the application key and the second-stage server Hello message, and is used together with the symmetric encryption algorithm in the encryption suite to encrypt the second application data packet sent by the ground terminal.

6. A QUIC-based satellite communication post-quantum key distribution method according to claim 1, characterized in that: After receiving and processing the second handshake data packet and the second application data packet, the satellite terminal generates a third handshake data packet, wherein the third handshake data packet includes a second-stage FINISH message including: The satellite terminal derives the symmetric key of the ground control terminal based on the second-stage server Hello message in the second handshake data packet and the application key of the current session, and uses it to decrypt the second application data packet together with the symmetric encryption algorithm in the encryption suite; and sends a third handshake data packet carrying a second-stage FINISH message to notify the ground control terminal to complete all key exchange processes.

7. A QUIC-based satellite communication post-quantum key distribution system for implementing the method according to any one of claims 1 to 6, characterized in that: include: The two-phase key exchange module is used to implement the exchange of application keys between the client and the server, including the generation and persistence of negotiation information of the initial data packet and public key data packet in the first phase and the handshake data packet in the second phase; The QUIC handshake module is responsible for coordinating key exchange with the QUIC encryption / decryption module and the two-phase key exchange module; Among them, after the satellite terminal initiates a connection request, the QUIC handshake module initiates a key exchange request to the two-phase key exchange module; after the two-phase key exchange module receives the request, it decides to return the first initial data packet or the first handshake data packet to the QUIC handshake module and then send it according to whether the one-phase exchange information is persisted locally.

8. A satellite communication post-quantum key distribution system based on QUIC according to claim 7, characterized in that: The determining of returning the first initial data packet or the first handshake data packet to the QUIC handshake module according to whether the local persistent one-stage exchange information is present includes: If the one-phase exchange information is not persisted locally, the first initial data packet is returned. After the ground control terminal receives and processes the first initial data packet, the QUIC handshake module hands it over to the two-phase key exchange module. The two-phase key exchange module generates a second initial data packet and the first public key data packet and hands them over to the QUIC handshake module before sending. After the satellite control terminal receives and processes the second initial data packet and the first public key data packet, the QUIC handshake module hands them over to the two-phase key exchange module. The two-phase key exchange module persists the negotiation information and generates a second public key data packet, which is then handed over to the QUIC handshake module for sending. After the ground control terminal receives and processes the second public key data packet, the QUIC handshake module hands it over to the two-stage key exchange module. The two-stage key exchange module persists the negotiation information and notifies the QUIC handshake module to end the one-stage key exchange.

9. A satellite communication post-quantum key distribution system based on QUIC according to claim 7, characterized in that: The determining of returning the first initial data packet or the first handshake data packet to the QUIC handshake module based on whether the local persistent one-stage exchange information is present also includes: If there is a one-phase exchange of information in local persistence, the first handshake packet is returned. After the ground control terminal receives and processes the first handshake packet, the QUIC handshake module hands it over to the two-phase key exchange module. The two-phase key exchange module decrypts the application key of the current session and generates a second handshake packet, which is then handed over to the QUIC handshake module for sending. After the satellite control terminal receives and processes the second handshake data packet, the QUIC handshake module hands it over to the two-phase key exchange module. The two-phase key exchange module generates a third handshake data packet and hands it over to the QUIC handshake module before sending it. After the ground control terminal receives and processes the third handshake data packet, the QUIC handshake module hands it over to the two-stage key exchange module, and the two-stage key exchange module notifies the QUIC handshake module to end the key exchange process.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the QUIC-based satellite communication post-quantum key distribution method is implemented as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Data processing methods and data processing devices

    CN108574575A

  • Data encryption transmission method, device, equipment and medium

    CN112637177A