Real-time communication cryptographic equipment based on GNSS (Global Navigation Satellite System) and key generation method
Through a real-time communication cryptographic device based on GNSS, the GNSS module uses the GNSS module to obtain high-precision time information and the shared key input by the user, and automatically update the key, solving the problem of difficulty in key management in traditional wireless encryption algorithms and improving the security of communication.
Patent Information
- Application Number
- CN202510468604.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-15
- Publication Date
- 2025-07-11
AI Technical Summary
The key management of traditional wireless encryption algorithms is difficult, the risk of key leakage is high, and it is easy to be cracked in communication, especially when the user increases, the risk increases significantly.
The real-time communication cryptographic device based on GNSS is adopted, and the GNSS module is used to obtain high-precision time information, combine the shared key input by the user and the key change cycle, and automatically update the key, and realize the encryption and decryption functions through FPGA, and adopt the AES encryption method.
Automatic key update is realized, the security of encrypted communication is improved, the time cost of cracking is increased, and the security of communication is improved.
Smart Images

Figure CN120302282A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of wireless data communication encryption, and particularly relates to a real-time communication cipher device based on GNSS and a key generation method. Background Art
[0002] When transmitting sensitive information wirelessly, it is necessary to encrypt the information. Traditional encryption algorithms are divided into symmetric encryption and asymmetric encryption. Symmetric encryption has the advantages of fast encryption speed, high operation efficiency, easy implementation of the algorithm, and low consumption of computing resources, and is suitable for wireless data encrypted communication. Its main disadvantages are difficult key management. Once the key is leaked, the communication content is easily cracked, and as the number of communication users increases, the risk of key leakage will increase significantly. Summary of the Invention
[0003] The purpose of the present invention is to overcome the deficiencies of the prior art and provide a real-time communication cipher device based on GNSS and a key generation method, which can be updated automatically at regular intervals, making the key have higher timeliness and improving the security of encrypted communication.
[0004] The technical solution adopted by the present invention is as follows: A real-time communication cipher device based on GNSS is connected between a data transceiver terminal and a wireless data transmission station, and includes a GNSS module, a cipher module, and a human-computer interaction module; The GNSS module receives satellite navigation signals, obtains high-precision 1PPS second pulse signals and messages with time, and transmits them to the cipher module; The human-computer interaction module uses a touch liquid crystal screen to receive the shared key Ks and the key change period Tp information input by the user, and transmits them to the cipher module; The cipher module generates a key K with time information according to the shared key Ks and the key change period Tp, encrypts the data from the data terminal with the key K, and sends the encrypted ciphertext to the data transmission station to transmit the ciphertext through wireless signals; or decrypts the ciphertext data from the data transmission station with the key K, and sends the decrypted plaintext to the data terminal.
[0005] Specifically, the cipher module is implemented by an FPGA and includes a time calculation unit, a key generation unit, an encryption unit, and a decryption unit.
[0006] A key generation method for a real-time communication cipher device based on GNSS, the specific steps are as follows: S1: The GNSS module receives satellite navigation signals, obtains high-precision 1PPS second pulse signals and messages with time, and transmits them to the cipher module; S2: The time calculation unit of the password module receives the message statement sent by the GNSS module, calculates the year, month, day, hour, minute, and second information, corrects it through the 1PPS second pulse signal to obtain high-precision time, forms 56-bit time information T according to BCD coding, and sends it to the key generation unit; S3: The human-computer interaction module interacts with the user through the touch liquid crystal screen. The user inputs a 9-byte 72-bit shared key Ks through the human-computer interaction module, and selects the key change period Tp through the single-choice button of the human-computer interaction module. The shared key Ks and the key change period Tp input by the user are sent to the key generation unit, and Ks and Tp are agreed upon by both communication parties; S4: The key generation unit completes the encoding of the 128-bit key to obtain the final 128-bit key K. The 128-bit key K contains 72-bit shared key Ks and 56-bit time-varying key Kt; S5: According to the time interval Tlag from the start of encryption at the data sending terminal to the start of decryption at the data receiving terminal, in the first N seconds of each key change period Tp, where Tp > N > Tlag, set the 8-bit time flag TF = TBF, and set another 8-bit time flag TF = TEF at other times, where TEF is not equal to TBF; At any time, the key K and the time flag TF form a pair {K, TF}; The generated {K, TF} is sent to the encryption unit and the decryption unit; S6: The encryption unit receives {K, TF} provided by the key generation unit, receives the data to be sent sent by the data transceiver terminal, and divides it into groups of 120 bits per group Data, padding with 0 for less than 120 bits; Take the 8-bit time flag TF, and form 128-bit plaintext data from {TF, Data}; {TF, Data} is encrypted through the encryption key K using the AES encryption method, and the encrypted 128-bit ciphertext is sent to the data transmission radio for transmission; S7: The decryption unit decrypts the 128-bit ciphertext received from the data transmission radio once; The decryption unit stores the {K, TF} at the current moment, denoted as {K(n), TF(n)}, and the {K, TF} at the latter segment of the previous key period, denoted as {K(n - 1), TF(n - 1)}, where TF(n - 1) = TEF.
[0007] Specifically, in the above-mentioned S4, the working process of the key generation unit is as follows: a. Determine the shared key Ks according to the user input; b. Determine the key change period Tp according to the user input; c. Obtain the current time T from the time calculation unit; d. Generate the time-varying key Kt from the current time T and the key change period Tp; The generation method is: In the time T encoded in BCD, set the corresponding positions at the end of T to 0 according to the period Tp; e. Mix the 72-bit shared key Ks and the 56-bit time-varying key Kt in a bitwise mixed arrangement and recombine them to obtain the final 128-bit key K. The combination method is as follows: Set Y combination methods, where Y is preferably an integer in the range of 10 - 100. According to the 4-bit integer X composed of the "date" and "hour" of the current time T, the remainder Z obtained by dividing X by Y is used as the basis for determining the combination method. Each combination method ensures that each bit of the shared key Ks and the time-varying key Kt corresponds to one bit in the key K, and the arrangement method is as disordered as possible.
[0008] Specifically, the decryption process in S7 is as follows: f. Obtain {K(n), TF(n)} at the current moment and {K(n - 1), TF(n - 1)} in the previous key period. g. Decrypt with K(n) to obtain {TF’(n), Data’(n)}; decrypt with K(n - 1) to obtain {TF’(n - 1), Data’(n - 1)}. The two decryption processes are processed in parallel in the FPGA. h. Determine whether TF’(n - 1) is equal to TF(n - 1). If so, it means that the encryption start time is the previous key period, and the corresponding data Data’(n - 1) is the plaintext Data, and output Data’(n - 1). i. Otherwise, it means that the encryption start time is the current key period, and the corresponding data Data’(n) is the plaintext Data, and output the data Data’(n).
[0009] Due to the above-mentioned technical solution, the present invention has the following advantages: The password module of the present invention realizes the encryption and decryption functions of wireless communication. The password module is built-in with a GNSS module, which can obtain high-precision time information and implement a key generation algorithm based on GNSS time, and has an automatic key update function. The key generation method automatically updates the time information in the key every once in a while, greatly shortening the timeliness of the key. The keys used for the ciphertext received in different time periods may be different, which greatly increases the time cost of brute-force cracking and has higher security than traditional encryption methods. Description of the Drawings
[0010] Figure 1 is the overall flow schematic diagram of the present invention.
[0011] Figure 2 is the schematic diagram of the change situation of {K, TF} when the key change period Tp = 20s, the time N = 5s, TBF = 0xBB, and TEF = 0x04 in the embodiment S5 of the present invention.
[0012] Figure 3It is the flowchart of the decryption process in S6 of the present invention. Specific embodiments
[0013] The present invention will be further explained and illustrated below in conjunction with the accompanying drawings and embodiments. The protection scope of the present invention cannot be limited hereby. The purpose of disclosing the present invention is to protect all technical improvements within the scope of the present invention.
[0014] Combined with the attached Figures 1-3 A GNSS-based real-time communication cipher device is connected between a data transceiver terminal and a wireless data transmission radio. It includes a GNSS module, a cipher module, and a human-computer interaction module.
[0015] The GNSS module receives satellite navigation signals, obtains high-precision 1PPS second pulse signals and messages with time, and transmits them to the cipher module; the human-computer interaction module uses a touch liquid crystal screen to receive the shared key Ks and the key change period Tp information input by the user, and transmits them to the cipher module; the cipher module is implemented by an FPGA and includes a time calculation unit, a key generation unit, an encryption unit, and a decryption unit; the cipher module generates a key K with time information according to the shared key Ks and the key change period Tp, encrypts the data from the data terminal with the key K, and sends the encrypted ciphertext to the data transmission radio, and transmits the ciphertext through wireless signals; or decrypts the ciphertext data from the data transmission radio with the key K, and sends the decrypted plaintext to the data terminal.
[0016] A method for generating keys of a GNSS-based real-time communication cipher device, the specific steps are as follows: S1: The GNSS module receives satellite navigation signals, obtains high-precision 1PPS second pulse signals and messages with time, and transmits them to the cipher module.
[0017] S2: The time calculation unit of the cipher module receives the message statement sent by the GNSS module, calculates the year, month, day, hour, minute, and second information, corrects it through the 1PPS second pulse signal to obtain high-precision time, and forms 56-bit time information T according to BCD coding, and sends it to the key generation unit.
[0018] S3: The human-computer interaction module interacts with the user through the touch liquid crystal screen. The user inputs a 9-byte 72-bit shared key Ks through the human-computer interaction module, and selects "20 seconds" from "20 seconds", "1 minute", "10 minutes", and "1 hour" as the key change period Tp through the single-selection button of the human-computer interaction module. The shared key Ks and the key change period Tp input by the user are sent to the key generation unit, and Ks and Tp are agreed upon by both communication parties.
[0019] S4: The key generation unit completes the encoding of the 128-bit key to obtain the final 128-bit key K. The 128-bit key K contains a 72-bit shared key Ks and a 56-bit time-varying key Kt. The specific process is as follows: a. Determine the shared key Ks according to the user input; b. Determine the key change period Tp according to the user input; c. Obtain the current time T from the time calculation unit; d. Generate the time-varying key Kt from the current time T and the key change period Tp. The generation method is: in the BCD-encoded time T, set the corresponding positions at the end of T to 0 according to the period Tp; In this embodiment S3, select Tp = "20 seconds", and set the last 5 positions of the time T to 0; if Tp = "1 minute" is selected in S3, set the last 8 positions of the time T to 0; if Tp = "10 minutes" is selected in S3, set the last 12 positions of the time T to 0; if Tp = "1 hour" is selected in S3, set the last 16 positions of the time T to 0; e. Arrange the 72-bit shared key Ks and the 56-bit time-varying key Kt in a bitwise mixed manner and recombine them to obtain the final 128-bit key K. The combination method is as follows: Set Y combination methods, select Y = 32, and according to the 4-bit integer X composed of the "date" and "hour" of the current time T, such as the 4-bit integer 1209 composed of the 12th day and 09:00, the remainder of 1209 divided by 32 is 25, that is, select the 25th combination method; Each combination method ensures that each bit of the shared key Ks and the time-varying key Kt corresponds to a bit in the key K, and the arrangement method is as disordered as possible.
[0020] S5: According to the time interval Tlag from the start of encryption by the data sending terminal to the start of decryption by the data receiving terminal, in the first 5 seconds of each 20-second key change period, set the 8-bit time flag TF = TBF, where TBF takes 0xBB, and set another 8-bit time flag TF = TEF at other times, where TEF takes 0x04; At any moment, the key K and the time flag TF form a pair {K, TF}; Send the generated {K, TF} to the encryption unit and the decryption unit.
[0021] S6: The encryption unit receives {K, TF} provided by the key generation unit, receives the data to be sent sent by the data transceiver terminal, and divides it into groups of 120 bits each as Data. Pad with 0s if it is less than 120 bits; Take the 8-bit time flag TF and form 128-bit plaintext data with {TF, Data}; {TF, Data} is encrypted by the encryption key K using the AES encryption method, and the encrypted 128-bit ciphertext is sent out by the data radio station.
[0022] S7: The decryption unit performs decryption processing once for every 128-bit ciphertext received from the data radio; the decryption unit stores {K, TF} at the current moment, denoted as {K(n), TF(n)}, and {K, TF} in the latter segment of the previous key period, denoted as {K(n - 1), TF(n - 1)}, where TF(n - 1) = TEF). The decryption process is as follows: f. Obtain {K(n), TF(n)} at the current moment and {K(n - 1), TF(n - 1)} of the previous key period. g. Decrypt using K(n) to obtain {TF’(n), Data’(n)}; decrypt using K(n - 1) to obtain {TF’(n - 1), Data’(n - 1)}; the two decryption processes are processed in parallel in the FPGA. h. Determine whether TF’(n - 1) is equal to TF(n - 1). If so, it means that the encryption start time is the previous key period, and the corresponding data Data’(n - 1) is the plaintext Data, and output Data’(n - 1). i. Otherwise, it means that the encryption start time is the current key period, and the corresponding data Data’(n) is the plaintext Data, and output the data Data’(n).
[0023] The parts not detailed in the present invention are prior art.
[0024] The embodiments selected herein for disclosing the object of the present invention are considered to be suitable at present. However, it should be understood that the present invention is intended to cover all variations and improvements of all embodiments that fall within the scope of this concept and invention.
Claims
1. A GNSS-based real-time communication cipher device is connected between a data transceiver terminal and a wireless data radio. It is characterized in that: It includes a GNSS module, a cryptographic module, and a human-machine interaction module; The GNSS module receives satellite navigation signals, obtains high-precision 1PPS second pulse signals and messages with time, and transmits them to the cryptographic module; The human-machine interaction module uses a touch liquid crystal screen to receive the shared key Ks and the key change period Tp information input by the user, and transmits them to the cryptographic module; The cryptographic module generates a key K with time information according to the shared key Ks and the key change period Tp, encrypts the data from the data terminal with the key K, and sends the encrypted ciphertext to the data transmission radio station, and transmits the ciphertext through wireless signals; or decrypts the ciphertext data from the data transmission radio station with the key K, and sends the decrypted plaintext to the data terminal.
2. The GNSS-based real-time communication cipher device according to claim 1, wherein: The cryptographic module is implemented by an FPGA and includes a time calculation unit, a key generation unit, an encryption unit, and a decryption unit.
3. A key generation method for a GNSS-based real-time communication cipher device according to any one of claims 1-2, characterized in that: The specific steps are as follows: S1: The GNSS module receives satellite navigation signals, obtains high-precision 1PPS second pulse signals and messages with time, and transmits them to the cryptographic module; S2: The time calculation unit of the cryptographic module receives the message statement sent by the GNSS module, calculates the year, month, day, hour, minute, and second information, corrects it through the 1PPS second pulse signal to obtain high-precision time, forms 56-bit time information T according to BCD coding, and sends it to the key generation unit; S3: The human-machine interaction module interacts with the user through the touch liquid crystal screen. The user inputs a 9-byte 72-bit shared key Ks through the human-machine interaction module, selects the key change period Tp through the single-selection button of the human-machine interaction module. The shared key Ks and the key change period Tp input by the user are sent to the key generation unit, and Ks and Tp are agreed upon by both communication parties; S4: The key generation unit completes the encoding of the 128-bit key to obtain the final 128-bit key K. The 128-bit key K contains 72-bit shared key Ks and 56-bit time-varying key Kt; S5: According to the time interval Tlag from the start of encryption at the data sending terminal to the start of decryption at the data receiving terminal, in the first N seconds of each key change period Tp, where Tp > N > Tlag, set an 8-bit time flag TF = TBF, and set another 8-bit time flag TF = TEF at other times. TEF is not equal to TBF; At any time, the key K and the time flag TF form a pair {K, TF}; the generated {K, TF} is sent to the encryption unit and the decryption unit; S6: The encryption unit receives {K, TF} provided by the key generation unit, receives the data to be sent from the data transceiver terminal, and takes 120 bits as a group Data for each group. If it is less than 120 bits, it is padded with 0s; take the 8-bit time flag TF, and form 128-bit plaintext data with {TF, Data}; {TF, Data} is encrypted by the encryption key K using the AES encryption method, and the encrypted 128-bit ciphertext is sent to the data transmission radio station for transmission; S7: The decryption unit performs a decryption process every time it receives 128-bit ciphertext from the data transmission radio station; The decryption unit stores {K, TF} at the current moment, denoted as {K(n), TF(n)}, and {K, TF} in the latter segment of the previous key cycle, denoted as {K(n - 1), TF(n - 1)}, where TF(n - 1) = TEF).
4. The key generation method of the GNSS-based real-time communication cipher device according to claim 3, characterized in that: In S4 described above, the working process of the key generation unit is as follows: a. Determine the shared key Ks according to the user input; b. Determine the key change period Tp according to the user input; c. Obtain the current time T from the time calculation unit; d. Generate the time-varying key Kt from the current time T and the key change period Tp; the generation method is: in the BCD-encoded time T, set the corresponding positions at the tail of T to 0 according to the period Tp; e. Arrange the 72-bit shared key Ks and the 56-bit time-varying key Kt in a bitwise mixed manner and recombine them to obtain the final 128-bit key K; the combination method is as follows: set Y combination methods, where Y is preferably an integer in the range of 10 - 100, and use the remainder Z obtained by dividing the 4-bit integer X composed of the "date" and "hour" of the current time T by Y as the basis for determining the combination method; each combination method ensures that each bit of the shared key Ks and the time-varying key Kt corresponds to a bit in the key K, and the arrangement method is as disordered as possible.
5. The key generation method of the GNSS-based real-time communication cipher device according to claim 3, wherein: The decryption process in S7 described above is as follows: f. Obtain {K(n), TF(n)} at the current moment and {K(n - 1), TF(n - 1)} in the previous key cycle; g. Decrypt with K(n) to obtain {TF’(n), Data’(n)}; decrypt with K(n - 1) to obtain {TF’(n - 1), Data’(n - 1)}; the two decryption processes are processed in parallel in the FPGA; h. Judge whether TF’(n - 1) is equal to TF(n - 1). If so, it means that the encryption start time is the previous key cycle, and the corresponding data Data’(n - 1) is the plaintext Data, and output Data’(n - 1); i. Otherwise, it means that the encryption start time is the current key cycle, and the corresponding data Data’(n) is the plaintext Data, and output the data Data’(n).