Safe and efficient satellite certificate revocation query method
By introducing a two-layer certificate revocation query architecture and encryption technology, combined with relay satellites and ground base stations, the high overhead problem of certificate revocation query in the satellite Internet is solved, and efficient and secure satellite certificate revocation query is achieved, protecting the privacy of initiating satellites and meeting a large number of concurrent query needs.
Patent Information
- Application Number
- CN202510369045.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2025-07-18
AI Technical Summary
In the prior art, the certificate revocation query method in the satellite Internet consumes a large amount of storage and computing resources for initiating satellites, and the traditional method is not suitable for satellite environments with limited power and computing capabilities.
The two-layer certificate revocation query architecture is adopted, including cuckoo filter and Othello structure, combined with encryption technology and relay satellites, querying through ground base stations and certificate authorization centers is carried out to reduce satellite computing and storage overhead and protect query privacy.
It realizes efficient and secure certificate revocation query in the satellite Internet, reduces the computing and storage overhead of satellites and certificate authorization centers, protects the privacy information of the initiating satellites, and is suitable for a large number of concurrent query needs.
Smart Images

Figure CN120343554A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of satellite certificate revocation query, and particularly relates to a secure and efficient satellite certificate revocation query method. Background Art
[0002] With the rapid progress of space technology, satellite Internet, as an important part of the global space economy, is rapidly promoting the development of the global space economy. Satellite Internet not only plays an important role in global communication and network access, enabling application scenarios limited by terrestrial networks, but also shows great potential in multiple space economy fields such as Earth observation, satellite navigation, and space situation awareness. Benefiting from the reduction in satellite costs, the number of satellites has increased rapidly, driving the continuous expansion of satellite Internet. According to the latest data from the Union of Concerned Scientists (UCS), as of May 1, 2023, the number of operational satellites globally has exceeded 7,500. On September 18, 2024, Novaspace released the 27th edition of "Satellites to be Built and Launched", predicting that an average of more than 3,700 satellites will be launched globally each year during the period from 2024 to 2033.
[0003] Establishing a trust relationship in satellite Internet is crucial. Public key infrastructure has been proposed as a trust framework for satellite Internet, where public key certificates and certificate revocation queries are basic tools for establishing trust relationships between entities. The most commonly used certificate revocation query method is to use Certificate Revocation Lists (CRLs). The satellite initiating the certificate revocation query operation can download the current certificate revocation list and retrieve the corresponding public key certificate in the list. However, using the certificate revocation list method requires consuming a large amount of storage and computing resources at the initiating satellite. Due to the many limitations of current communication satellites, such as strict power limitations, limitations on the computing and storage capabilities of radiation-resistant chips, and limitations on physical transmission, etc., the certificate revocation list method is not applicable to certificate revocation queries in satellite Internet scenarios. In addition, the popular Online Certificate Status Protocol (OCSP) requires direct communication with the Certificate Authority (CA), which is also not applicable to satellite Internet. Summary of the Invention
[0004] The purpose of the present invention is to overcome the deficiencies of the prior art and provide a secure and efficient satellite certificate revocation query method.
[0005] The purpose of the present invention is achieved through the following technical solutions:
[0006] The present invention discloses a secure and efficient method for querying satellite certificate revocation, including the following steps:
[0007] S1. In the system initialization stage, the system is initialized according to security parameters to determine the public parameters of the system; the Certificate Authority (CA), the initiating satellite, the satellite query object, and the ground base station respectively generate their corresponding public and private key pairs; the CA initializes a two-layer certificate revocation query data structure for certificate revocation query, including a Cuckoo filter and Othello, and sends the initialized Cuckoo filter to the ground base station;
[0008] S2. In the request stage, the initiating satellite calculates the session key for communicating with the ground base station; the initiating satellite generates an Internet revocation query request message, sets the common name of the initiating satellite, the common name of the ground base station, the serial number corresponding to the initiating satellite certificate, the public key of the initiating satellite, and the satellite Internet revocation query identifier as authenticated encryption associated messages, encrypts the Internet revocation query request message with the session key to obtain a request ciphertext, and synthesizes the request ciphertext and the associated messages into a query request; the initiating satellite sends the query request to the ground base station according to the current communication range: if the ground base station is within the communication range of the initiating satellite, the initiating satellite sends the query request to the ground base station; otherwise, the initiating satellite uses inter-satellite links to forward the query request to the ground base station through multiple relay satellites;
[0009] S3. In the response stage, after receiving the query request, the ground base station calculates the session key and decrypts the query ciphertext. If the integrity verification fails during the decryption process, the service is aborted; if the integrity verification passes, the certificate status of the initiating satellite query object is queried according to the two-layer satellite certificate revocation query architecture, a satellite Internet revocation query response message is generated, the common name of the ground base station, the common name of the initiating satellite, and the satellite Internet revocation response identifier are set as authenticated encryption associated messages, the satellite Internet revocation query response message is encrypted with the session key to obtain a response ciphertext, and the response ciphertext and the associated messages are synthesized into a query response; the ground base station dynamically adopts a sending method according to the current communication coverage range of the initiating satellite and sends the query response to the satellite;
[0010] S4. In the verification stage, after receiving the query response, the initiating satellite decrypts the response ciphertext to obtain the status of the query object certificate, and completes the revocation query of the satellite certificate.
[0011] Further, step S1 includes: determining a system public parameter set according to security parameters where q represents a prime number, represents a group of order q on the elliptic curve, P is a generator of, H1: {0, 1} * → {0, 1} 256Represents a secure cryptographic hash function; uniformly and randomly select a private key And through the private key Calculate the first public key Obtain the first public-private key pair of the certificate authority center Similarly, the satellite Generate a second public-private key pair Satellite Query object Generate a third public-private key pair Ground base station Generate a fourth public-private key pair Certificate authority center Save the revoked certificate serial number set RCS and generate a Cuckoo filter CF, which specifically includes the following steps:
[0012] S111. Determine the parameters according to the size |RCS| of the revoked certificate serial number set RCS Where Is the number of buckets in the Cuckoo filter CF, b is the number of entries in each bucket of the Cuckoo filter CF, NMax is the maximum number of moves, f is the bit length of the fingerprint in the Cuckoo filter, h1: {0, 1} * →{0, 1} f And Are two non-cryptographic hash functions;
[0013] S112. For any certificate serial number cno1 in the revoked certificate serial number set RCS, it includes the following steps:
[0014] S1121. Calculate the first certificate fingerprint fp1: = h1(cno1), and calculate the first candidate bucket index value i 11 : = h2(fp1) and the second candidate bucket index value
[0015] S1122. If there is an empty entry in bucket[i 11 or bucket[i 21 , where bucket[i 11 and bucket[i 21 represent buckets, put the first certificate fingerprint fp1 into the empty entry to complete the generation operation of the Cuckoo filter CF;
[0016] S1123. If there is no empty entry in bucket[i 11 or bucket[i 21 , uniformly and randomly select the first random number
[0017] S1124. Randomly select an entry e from bucket[i], where bucket[i] represents a bucket, swap the values of entry e and the certificate fingerprint fp, and update the first random number. If there is an empty entry in bucket[i], place the fp1 with swapped values at the empty entry; if there is no empty entry in bucket[i], repeat this step.
[0018] S1125. If the number of swaps reaches the maximum number of moves NMax, the cuckoo filter CF is full. Repeat steps S1121 - S1125 to generate a new cuckoo filter.
[0019] S113. All buckets constitute the cuckoo filter CF.
[0020] Certificate Authority Save the set LCS of valid certificate serial numbers. For any certificate serial number cno2 in the set LCS of valid certificate serial numbers, the following steps are included:
[0021] S1141. Calculate the second certificate fingerprint fp2 := h1(cno2), and calculate the third candidate bucket index value i 12 := h2(fp2) and the fourth candidate bucket index value
[0022] S1142. If the second certificate fingerprint fp2 is in bucket[i 12 or bucket[i 22 , where bucket[i 12 and bucket[i 22 represent buckets, then any certificate serial number cno2 in the set LCS of valid certificate serial numbers is a false positive.
[0023] S1143. Combine all the false positive certificate serial numbers into a set; obtain the set FRS of false positive certificate serial numbers.
[0024] Certificate Authority Save the set RCS of revoked certificate serial numbers and the set FRS of false positive certificate serial numbers, and generate OthelloO, which specifically includes the following steps:
[0025] S121. Set the set S = RCS ∪ FRS, the size of the set S is n = |S|, and determine the parameters {m a , m b , h a , h b} based on the size n of the set S, where m a and m bare the lengths of hash table A and hash table B, h a : {0, 1} * → {0, 1, ..., m a - 1} and h b : {0, 1} * → {0, 1, ..., m b - 1} are two non - cryptographic hash functions;
[0026] S122. Construct graph G based on set S. Among them, for any certificate serial number cno in set S, the corresponding vertex v a α , v b β and edge (v a α , v b β ), where α and β represent the index values of the vertices, α = h a (cno), β = h b (cno);
[0027] S123. Use depth - first search to sort graph G, that is, sort all elements in set S to obtain a list L: = (cno1, cno2, ..., cno n ), where cno k ∈ S, 1 ≤ k ≤ n; For includes the following steps:
[0028] S1231. If cno k ∈ FRS, set the value of the corresponding edge v: = 0, otherwise, set the value of the corresponding edge v: = 1;
[0029] S1232. Calculate i k = h a (cno k ), j k = h b (cno k ), where i k and j k are two candidate bucket index values corresponding to cno k . If both A[i k and B[j k are not assigned values, set A[i k : = 0, B[j k : = v; If only A[i k is not assigned a value, set If only B[j k is not assigned a value, set
[0030] S124. Randomly assign 0 or 1 to the unassigned positions in hash table A and hash table B. After that, hash table A and hash table B form the othello O.
[0031] Certificate Authority Send the Cuckoo Filter CF to the ground base station Certificate Authority Respectively to the ground base station Satellite And its query object Issue the corresponding public key certificate And Satellite Stores the public key of the Certificate Authority Of the public key And the ground base station Of the public key Ground base station Stores the public key of the Certificate Authority Of the public key
[0032] Preferably, step S2 specifically includes the following steps:
[0033] S21. The satellite Calculates the first session key Where Represents the private key of the satellite Of the private key, Represents the public key of the ground base station Of the public key;
[0034] S22. The satellite Uniformly and consistently selects a second random number Calculates the coordinates of the first elliptic curve point Calculates the first intermediate parameter Generates the first signature Generates the first satellite Internet revocation query request message in ASN.1 format:
[0035]
[0036] Wherein, Is the common name of the satellite Of the common name, Is the common name of the Certificate Authority Of the common name, Is the query object Of the public key certificate In the serial number, nonce1 is the ninth random number;
[0037] S23. The satellite Generates the first association message Among them is the public key certificate of the satellite in the serial number, is the public key of the satellite SNR_Request represents the identification string, and the message SNRRequest is encrypted using the first session key to obtain the ciphertext Generate the first query request Q1: = (head1, c1); if the satellite communication can cover the ground base station send the first query request Q1 to the ground base station within the satellite communication range Otherwise, the satellite sends the first query request Q1 to the adjacent relay satellite, and through the forwarding of multiple relay satellites, sends the first query request Q1 to the ground base station within the relay satellite communication range
[0038] Preferably, step S3 specifically includes:
[0039] S31. After the ground base station receives the first query request Q1, calculate the second session key Among them represents the private key of the ground base station and decrypt the first ciphertext c1 using the second session key If the integrity verification cannot pass during the decryption process, abort the service; otherwise, obtain
[0040] S32. The ground base station queries whether the public key certificate of the query object is revoked. If it is revoked, the first status st2 of the public key certificate of the query object is set to "revoked". If it is not revoked, the first status st2 of the public key certificate of the query object is set to "good";
[0041] S33. The ground base station calculates the second update time t4: = t2, where t2 is the last update time of the first status st2, calculates the seventh random number nonce4: = nonce2, and uniformly and randomly selects the eighth random number Calculate the coordinates of the fourth elliptic curve point Calculate the fourth intermediate parameter Generate the fourth signature Generate the first satellite Internet revocation query response message in ASN.1 format:
[0042]
[0043] Where st3 is the status of the first satellite Internet revocation response message, t3 is the generation time of the first satellite Internet revocation response message, and st4 is the public key certificate of the query object of the query object of the second status;
[0044] S34. Ground base station Generate the second association message Use the second session key Encrypt the message SNRRequest to obtain the fourth ciphertext Generate the second query response R2 := (head2, c4) and send it to the satellite
[0045] S35. If the ground base station is within the communication range of the satellite the ground base station sends the query response R2 to the satellite Otherwise, the ground base station sends the query response R2 to the relay satellite that can currently cover the ground base station, and uses the forwarding of multiple relay satellites to send the query response R2 to the satellite
[0046] Preferably, the ground base station described in step S32 queries whether the public key certificate of the query object has been revoked, which specifically includes the following steps:
[0047] S321. The ground base station calculates the third certificate fingerprint fp3 := h1(no u ), calculates the fifth candidate bucket index value i 13 := h2(fp3) and the sixth candidate bucket index value
[0048] S322. The ground base station locates bucket[i 13 and bucket[i 23 in the cuckoo filter CF, where bucket[i 13 and bucket[i 23 represent buckets, and checks whether the third certificate fingerprint fp3 is in bucket[i 13 or bucket[i23 , if the third certificate fingerprint fp3 is not in the Cuckoo filter CF, query the object 's public key certificate has not been revoked, the ground base station completes the satellite certificate revocation query;
[0049] S323. If the third certificate fingerprint fp3 is in the Cuckoo filter CF, the ground base station calculates the third random number nonce2: = nonce1, and uniformly and consistently selects the fourth random number calculates the coordinates of the second elliptic curve point
[0050] calculates the second intermediate parameter generates the second signature generates the second satellite Internet revocation query request message in ASN.1 format:
[0051]
[0052] wherein, is the common name of the ground base station ;
[0053] S324. The ground base station generates the third association message calculates the third session key uses the third session key to encrypt the message SNRRequest to obtain the second ciphertext generates the second query request Q2: = (head3, c2) and sends it to the certificate authority
[0054] S325. After receiving the second query request Q2: = (head3, c2), the certificate authority calculates the fourth session key uses the fourth session key to decrypt the second ciphertext c2 If the integrity verification fails during the decryption process, abort the service; otherwise, obtain
[0055] S326. The certificate authority calculates j = h b (cno), If result = 0, the public key certificate of the query object has not been revoked; if result = 1, the public key certificate of the query object has not been revoked; if result = 1, the public key certificate of the query object 's public key certificate Revoked;
[0056] S327, Certificate Authorization Center Calculate the fifth random number nonce3 := nonce2, and uniformly and consistently select the sixth random number Calculate the coordinates of the third elliptic curve point Calculate the third intermediate parameter Generate the third signature Generate the second satellite Internet revocation query response message in ASN.1 format:
[0057]
[0058] Among them, st1 is the status of the second satellite Internet revocation response message, t1 is the generation time of the second satellite Internet revocation response message, and st2 is the public key certificate of the query object of the first status;
[0059] S328, Certificate Authorization Center Generate the fourth associated message Use the fourth session key Encrypt the message SNRResponse to obtain the third ciphertext Generate the first query response R1 := (head4, c3) and send it to the ground base station
[0060] S329, Ground Base Station After receiving the first query response R1 := (head4, c3), use the third session key Decrypt the third ciphertext c3 If the integrity verification fails during the decryption process, abort the query operation; otherwise, obtain Obtain the first status st2 and complete the query operation.
[0061] Preferably, step S4 specifically includes: Satellite After receiving R2 = (head2, c4), calculate If the integrity verification fails during the decryption process, then abort the query operation; otherwise, obtain Obtain the second status st4. If the second status st4 = "revoked", it means the certificate has been revoked, and the satellite Refuses to provide service to the query object If the second status st4 = "good", the satellite Carries out relevant business activities with the query object
[0062] The beneficial effects of the present invention are as follows:
[0063] 1) While realizing the revocation query of satellite certificates, it protects privacy information such as the content of the initiated satellite query, and ensures the reliability of the query result; the satellite certificate revocation query method reduces the computing overhead and storage overhead at the satellite and the certificate authority, and can meet the large number of concurrent query requirements under the satellite Internet, and is applicable to the actual scenario where the current satellite computing and storage capabilities are limited. Description of the Drawings
[0064] Figure 1 It is a schematic diagram of the steps of a secure and efficient satellite certificate revocation query method according to an embodiment of the present invention. Detailed Embodiments
[0065] Next, the technical solutions of the present invention will be clearly and completely described in conjunction with the embodiments. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present invention.
[0066] The present invention uses a relay satellite and a ground base station to forward query messages to indirectly contact the certificate authority on the ground, greatly reducing the computing and storage overhead of the initiating satellite. However, the certificate revocation query operation of the initiating satellite is very sensitive, and external adversaries can obtain query content such as the objects of the services provided by the initiating satellite through eavesdropping and other means, destroying the privacy of the initiating satellite; in addition, external adversaries may forge the query results for various purposes. The present invention introduces encryption technology under the satellite Internet to exchange query messages to ensure that external adversaries and the certificate authority cannot obtain query content such as the objects of the services planned to be provided by the initiating satellite, protect the privacy information of the initiating satellite, and ensure the reliability of the query result; introduce a two-layer satellite certificate revocation query architecture. The first-layer satellite certificate revocation query is a probabilistic query, provided by the ground base station, and the second-layer satellite certificate revocation query is a deterministic query, provided by the certificate authority, reducing the storage and computing overhead of the certificate authority for processing certificate revocation queries and meeting the large number of concurrent query requirements under the satellite Internet.
[0067] The present invention provides a secure and efficient satellite certificate revocation query method, which uses a relay satellite and a ground base station to forward messages to indirectly contact the certificate authority on the ground; introduces encryption technology under the satellite Internet to exchange query messages; introduces a two-layer certificate revocation query architecture, and its schematic diagram of steps is as Figure 1 shown, and specifically includes the following steps:
[0068] S1. In the system initialization phase, the system is initialized according to security parameters to determine the public parameters of the system; the certificate authority center, the initiating satellite, the satellite query object, and the ground base station respectively generate their corresponding public and private key pairs; the certificate authority center initializes a two-layer certificate revocation query data structure for certificate revocation query, including a cuckoo filter and othello, and sends the initialized cuckoo filter to the ground base station;
[0069] S2. In the request phase, the initiating satellite calculates the session key for communication with the ground base station; the initiating satellite generates an Internet revocation query request message, sets the common name of the initiating satellite, the common name of the ground base station, the serial number corresponding to the initiating satellite certificate, the public key of the initiating satellite, and the satellite Internet revocation query identifier as authenticated and encrypted associated messages, encrypts the Internet revocation query request message with the session key to obtain the request ciphertext, and synthesizes the request ciphertext and the associated messages into a query request; the initiating satellite sends the query request to the ground base station according to the current communication range: if the ground base station is within the communication range of the initiating satellite, the initiating satellite sends the query request to the ground base station; otherwise, the initiating satellite uses the inter-satellite link to forward the query request to the ground base station through multiple relay satellites;
[0070] S3. In the response phase, after receiving the query request, the ground base station calculates the session key and decrypts the query ciphertext. If the integrity verification fails during the decryption process, the service is aborted; if the integrity verification passes, the certificate status of the initiating satellite query object is queried according to the two-layer satellite certificate revocation query architecture, generates a satellite Internet revocation query response message, sets the common name of the ground base station, the common name of the initiating satellite, and the satellite Internet revocation response identifier as authenticated and encrypted associated messages, encrypts the satellite Internet revocation query response message with the session key to obtain the response ciphertext, and synthesizes the response ciphertext and the associated messages into a query response; the ground base station dynamically adopts a sending method according to the current communication coverage range of the initiating satellite and sends the query response to the satellite;
[0071] S4. In the verification phase, after receiving the query response, the initiating satellite decrypts the response ciphertext to obtain the status of the query object certificate, and completes the revocation query of the satellite certificate.
[0072] Specifically, step S1 includes: determining the system public parameter set according to security parameters where q represents a prime number, represents the group of order q on the elliptic curve, P is the generator of, H1: {0,1} * → {0,1} 256 represents a secure cryptographic hash function; uniformly and randomly select the private key and calculate the first public key through the private key to obtain the certificate authority center the first public-private key pair Similarly, the satellite generates a second public-private key pair The satellite query object generates a third public-private key pair The ground base station generates a fourth public-private key pair The certificate authority Saves the revocation certificate serial number set RCS and generates a cuckoo filter CF, which specifically includes the following steps:
[0073] S111. Determine the parameters according to the size |RCS| of the revocation certificate serial number set RCS where is the number of buckets in the cuckoo filter CF, b is the number of entries contained in each bucket in the cuckoo filter CF, NMax is the maximum number of moves, f is the bit length of the fingerprint in the cuckoo filter, h1: {0, 1} * →{0, 1} f and are two non-cryptographic hash functions;
[0074] S112. For any certificate serial number cno1 in the revocation certificate serial number set RCS, it includes the following steps:
[0075] S1121. Calculate the first certificate fingerprint fp1 := h1(cno1), and calculate the first candidate bucket index value i 11 := h2(fp1) and the second candidate bucket index value
[0076] S1122. If there is an empty entry in bucket[i 11 or bucket[i 21 , where bucket[i 11 and bucket[i 21 represent buckets, put the first certificate fingerprint fp1 into the empty entry to complete the generation operation of the cuckoo filter CF;
[0077] S1123. If there is no empty entry in bucket[i 11 or bucket[i 21 , uniformly and randomly select the first random number
[0078] S1124. Randomly select an entry e from bucket[i], where bucket[i] represents a bucket, swap the values of the entry e and the certificate fingerprint fp, and update the first random number If there is an empty entry in bucket[i], put the fp1 with the exchanged value into the empty entry; if there is no empty entry in bucket[i], repeat this step;
[0079] S1125. If the number of exchanges reaches the maximum number of moves NMax, the cuckoo filter CF is full. Repeat steps S1121 - S1125 to generate a new cuckoo filter;
[0080] S113. All buckets constitute the cuckoo filter CF;
[0081] Certificate Authority Save the set LCS of valid certificate serial numbers. For any certificate serial number cno2 in the set LCS of valid certificate serial numbers, it includes the following steps:
[0082] S1141. Calculate the second certificate fingerprint fp2: h1(cno2), and calculate the third candidate bucket index value i 12 := h2(fp2) and the fourth candidate bucket index value
[0083] S1142. If the second certificate fingerprint fp2 is in bucket[i 12 or bucket[i 22 , where bucket[i 12 and bucket[i 22 represent buckets, then any certificate serial number cno2 in the set LCS of valid certificate serial numbers is a false positive;
[0084] S1143. Form a set of all false positive certificate serial numbers; obtain the set FRS of false positive certificate serial numbers;
[0085] Certificate Authority Save the set RCS of revoked certificate serial numbers and the set FRS of false positive certificate serial numbers, and generate OthelloO, which specifically includes the following steps:
[0086] S121. Set the set S = RCS ∪ FRS. The size of the set S is n = |S|. Determine the parameters {m a , m b , h a , h b} based on the size n of the set S, where m a and m b are the lengths of the hash tables A and B respectively, and h a : {0, 1} * → {0, 1,..., m a - 1} and hb : {0, 1} * → {0, 1,..., m b - 1} are two non-cryptographic hash functions;
[0087] S122. Construct a graph G based on the set S. Among them, for any certificate serial number cno in the set S, the corresponding vertex v a α , v b β and the edge (v a α , v b β ), where α and β represent the index values of the vertices, α = h a (cno), β = h b (cno);
[0088] S123. Use depth-first search to sort the graph G, that is, sort all elements in the set S to obtain a list L := (con1, con2,..., con n ), where con k ∈ S, 1 ≤ k ≤ n; For It includes the following steps:
[0089] S1231. If con k ∈ FRS, set the value of the corresponding edge v := 0, otherwise, set the value of the corresponding edge v := 1;
[0090] S1232. Calculate i k = h a (cno k ), j k = h b (cono k ), where i k and j k are two candidate bucket index values corresponding to cno k . If both A[i k and B[j k are not assigned values, set A[i k : = 0, B[j k : = v; If only A[i k is not assigned a value, set If only B[j k is not assigned a value, set
[0091] S124. Randomly assign 0 or 1 to the unassigned positions in the hash tables A and B. After that, the hash tables A and B form the othello O;
[0092] Certificate Authorization Center Send the Cuckoo Filter CF to the ground base station Certificate Authorization Center Send to the ground base station respectively Satellite And its query object Issue the corresponding public key certificate And Satellite Stores the public key of the Certificate Authorization Center Of And the ground base station Of the public key Ground base station Stores the public key of the Certificate Authorization Center Of
[0093] Specifically, step S2 specifically includes the following steps:
[0094] S21. The satellite Calculates the first session key Where Represents the private key of the satellite Of Represents the public key of the ground base station Of
[0095] S22. The satellite Uniformly and consistently selects the second random number Calculates the first elliptic curve point coordinates Calculates the first intermediate parameter Generates the first signature Generates the first satellite Internet revocation query request message in ASN.1 format:
[0096]
[0097]
[0098] Where Is the common name of the satellite Of Is the common name of the Certificate Authorization Center Of Is the query object Of the public key certificate In the serial number, nonce1 is the ninth random number;
[0099] S23. The satellite Generates the first associated message Where Is the satellite public key certificate serial number in is a satellite public key, SNR_Request represents an identification string, and uses the first session key encrypts the message SNRRequest to obtain a ciphertext generates the first query request Q1: = (head1, c1); if the satellite communication can cover the ground base station sends the first query request Q1 to the ground base station within the satellite communication range otherwise, the satellite sends the first query request Q1 to the adjacent relay satellite, and through the forwarding of multiple relay satellites, sends the first query request Q1 to the ground base station within the relay satellite communication range
[0100] Specifically, step S3 specifically includes:
[0101] S31. After the ground base station receives the first query request Q1, calculates the second session key where represents the private key of the ground base station uses the second session key to decrypt the first ciphertext c1 If the integrity verification fails during the decryption process, the service is aborted; otherwise, obtain
[0102] S32. The ground base station queries the public key certificate of the query object whether it has been revoked. If it has been revoked, the public key certificate of the query object the first status st2 of the public key certificate of the query object = "revoked". If it has not been revoked, the public key certificate of the query object the first status st2 of the public key certificate of the query object = "good";
[0103] S33. The ground base station calculates the second update time t4: = t2, where t2 is the last update time of the first status st2, calculates the seventh random number nonce4: = nonce2, and uniformly and randomly selects the eighth random number calculates the coordinates of the fourth elliptic curve point calculates the fourth intermediate parameter generates the fourth signature Generate the first satellite Internet revocation query response message in ASN.1 format:
[0104]
[0105] where st3 is the status of the first satellite Internet revocation response message, t3 is the generation time of the first satellite Internet revocation response message, and st4 is the public key certificate of the query object of the second status;
[0106] S34. The ground base station generates the second association message uses the second session key to encrypt the message SNRRequest to obtain the fourth ciphertext generates the second query response R2 := (head2, c4) and sends it to the satellite
[0107] S35. If the ground base station is within the communication range of the satellite the ground base station sends the query response R2 to the satellite Otherwise, the ground base station sends the query response R2 to the relay satellite that can currently cover the ground base station, and uses the forwarding of multiple relay satellites to send the query response R2 to the satellite
[0108] Specifically, the ground base station described in step S32 queries whether the public key certificate of the query object has been revoked, which specifically includes the following steps:
[0109] S321. The ground base station calculates the third certificate fingerprint calculates the fifth candidate bucket index value i 13 := h2(fp3) and the sixth candidate bucket index value
[0110] S322. The ground base station locates bucket[i 13 and bucket[i 23 in the cuckoo filter CF, where bucket[i 13 and bucket[i 23 represent buckets, and checks whether the third certificate fingerprint fp3 is in bucket[i 13 or bucket[i 23If the third certificate fingerprint fp3 is not in the Cuckoo Filter CF, query the public key certificate of the query object is not revoked, and the ground base station completes the satellite certificate revocation query;
[0111] S323. If the third certificate fingerprint fp3 is in the Cuckoo Filter CF, the ground base station calculates the third random number nonce2 := nonce1, and uniformly and randomly selects the fourth random number calculates the coordinates of the second elliptic curve point
[0112] calculates the second intermediate parameter generates the second signature generates the second satellite Internet revocation query request message in ASN.1 format:
[0113]
[0114] where is the common name of the ground base station
[0115] S324. The ground base station generates the third association message calculates the third session key uses the third session key to encrypt the message SNRRequest to obtain the second ciphertext generates the second query request Q2 := (head3, c2) and sends it to the certificate authority
[0116] S325. After receiving the second query request Q2 := (head3, c2), the certificate authority calculates the fourth session key uses the fourth session key to decrypt the second ciphertext c2 If the integrity verification fails during the decryption process, abort the service; otherwise, obtain
[0117] S326. The certificate authority calculates j = h b (cno),(cno), If result = 0, the public key certificate of the query object is not revoked; if result = 1, the public key certificate of the query object is revoked; is revoked; is revoked;
[0118] S327, Certificate Authorization Center Calculate the fifth random number nonce3: = nonce2, and uniformly and consistently select the sixth random number Calculate the coordinates of the third elliptic curve point Calculate the third intermediate parameter Generate the third signature Generate the second satellite Internet revocation query response message in ASN.1 format:
[0119]
[0120] where st1 is the status of the second satellite Internet revocation response message, t1 is the generation time of the second satellite Internet revocation response message, and st2 is the public key certificate of the query object of the first status; of the first status;
[0121] S328, Certificate Authorization Center Generate the fourth associated message Use the fourth session key Encrypt the message SNRResponse to obtain the third ciphertext Generate the first query response R1: = (head4, c3) and send it to the ground base station
[0122] S329, Ground Base Station After receiving the first query response R1: = (head4, c3), use the third session key Decrypt the third ciphertext c3 If the integrity verification fails during the decryption process, abort the query operation; otherwise, obtain Obtain the first status st2 and complete the query operation.
[0123] Specifically, step S4 specifically includes: The satellite After receiving R2 = (head2, c4), calculate If the integrity verification fails during the decryption process, abort the query operation; otherwise, obtain Obtain the second status st4. If the second status st4 = "revoked", it means the certificate has been revoked, and the satellite Refuses to provide service to the query object If the second status st4 = "good", the satellite Carries out relevant business activities with the query object Carries out relevant business activities.
[0124] In the query process of the present invention, an encryption technology under satellite Internet is introduced to exchange query messages, which can prevent external adversaries from learning the content of satellite queries initiated and forging query results, protect the privacy of the initiating satellite, and ensure the reliability of queries; a two-layer satellite certificate revocation architecture is introduced, and the status query of satellite certificates is completed through the first-layer probabilistic query and the second-layer deterministic query. While realizing the satellite certificate revocation query, it protects the privacy information such as the content of satellite queries initiated, and ensures the reliability of query results; the satellite certificate revocation query method reduces the computational overhead and storage overhead at the satellite and the certificate authority, can meet the large number of concurrent query requirements under satellite Internet, and is applicable to the actual scenario where the current satellite computing and storage capabilities are limited.
[0125] The above are only the preferred embodiments of the present invention. It should be understood that the present invention is not limited to the form disclosed herein, should not be regarded as excluding other embodiments, but can be used in various other combinations, modifications, and environments, and can be changed within the scope of the concept described herein through the above teachings or the technology or knowledge in related fields. And any changes and modifications made by those skilled in the art without departing from the spirit and scope of the present invention shall fall within the protection scope of the appended claims of the present invention.
Claims
1. A secure and efficient method for querying satellite certificate revocation, characterized in that, It includes the following steps: S1. In the system initialization stage, the system is initialized according to security parameters to determine the public parameters of the system; the certificate authority center, the initiating satellite, the satellite query object, and the ground base station respectively generate the corresponding public and private key pairs; the certificate authority center initializes a two-layer certificate revocation query data structure for certificate revocation query, including a cuckoo filter and Othello, and sends the initialized cuckoo filter to the ground base station; S2. In the request stage, the initiating satellite calculates the session key for communicating with the ground base station; The initiating satellite generates an Internet revocation query request message, sets the common name of the initiating satellite, the common name of the ground base station, the serial number corresponding to the initiating satellite certificate, the public key of the initiating satellite, and the satellite Internet revocation query identifier as the associated message for authenticated encryption, encrypts the Internet revocation query request message with the session key to obtain the request ciphertext, and synthesizes the request ciphertext and the associated message into a query request; The initiating satellite sends the query request to the ground base station according to the current communication range: if the ground base station is within the communication range of the initiating satellite, the initiating satellite sends the query request to the ground base station; otherwise, the initiating satellite uses the inter-satellite link to forward the query request to the ground base station through multiple relay satellites; S3. In the response stage, after receiving the query request, the ground base station calculates the session key and decrypts the query ciphertext. If the integrity verification fails during the decryption process, the service is aborted; If the integrity verification is passed, query the certificate status of the initiating satellite query object according to the two-layer satellite certificate revocation query architecture, generate a satellite Internet revocation query response message, set the common name of the ground base station, the common name of the initiating satellite, and the satellite Internet revocation response identifier as the associated message for authenticated encryption, encrypt the satellite Internet revocation query response message with the session key to obtain the response ciphertext, and synthesize the response ciphertext and the associated message into a query response; the ground base station dynamically adopts a sending method according to the current communication coverage range of the initiating satellite and sends the query response to the satellite; S4. In the verification stage, after receiving the query response, the initiating satellite decrypts the response ciphertext to obtain the status of the query object certificate, and completes the revocation query of the satellite certificate.
2. The method for querying revocation of satellite certificates according to claim 1, characterized in that The step S1 includes: determining a system public parameter set according to security parameters where q represents a prime number, represents a group of order q on an elliptic curve, P is a generator of, H1: {0, 1} * → {0, 1} 256 represents a secure cryptographic hash function; uniformly and randomly select a private key and calculate the first public key through the private key to obtain the first public-private key pair of the certificate authority Similarly, the satellite generates a second public-private key pair The satellite generates a third public-private key pair The satellite query object generates a third public-private key pair The ground base station generates a fourth public-private key pair The certificate authority saves the revoked certificate serial number set RCS and generates a cuckoo filter CF, which specifically includes the following steps: S111. Determine parameters according to the size |RCS| of the revocation certificate serial number set RCS where is the number of buckets in the cuckoo filter CF, b is the number of entries in each bucket of the cuckoo filter CF, NMax is the maximum number of moves, f is the bit length of the fingerprints in the cuckoo filter, h1: {0, 1} * → {0, 1} f and are two non-cryptographic hash functions; S112. For any certificate serial number cno1 in the revoked certificate serial number set RCS, it includes the following steps: S1121. Calculate the first certificate fingerprint fp1 := h1(cno1), and calculate the first candidate bucket index value i 11 := h2(fp1) and the second candidate bucket index value S1122. If there is an empty entry in bucket[i 11 or bucket[i 21 , where bucket[i 11 and bucket[i 21 represent buckets, put the first certificate fingerprint fp1 into the empty entry to complete the generation operation of the cuckoo filter CF; S1123. If there is no empty entry in bucket[i 11 or bucket[i 21 , uniformly and consistently select the first random number S1124. Randomly select an entry e from bucket[i], where bucket[i] represents a bucket, swap the values of entry e and the certificate fingerprint fp, and update the first random number. If there is an empty entry in bucket[i], put the fp1 with swapped values into the empty entry; if there is no empty entry in bucket[i], repeat this step. S1125. If the number of exchanges reaches the maximum number of moves NMax, the cuckoo filter CF is full, and repeat steps S1121 - step 1125 to generate a new cuckoo filter; S113. All buckets constitute the cuckoo filter CF; Certificate Authorization Center Save the set LCS of valid certificate serial numbers. For any certificate serial number cno2 in the set LCS of valid certificate serial numbers, the following steps are included: S1141. Calculate the second certificate fingerprint fp2 := h1(cno2), and calculate the third candidate bucket index value i 12 := h2(fp2) and the fourth candidate bucket index value S1142. If the second certificate fingerprint fp2 is in bucket[i 12 or bucket[i 22 , where bucket[i 12 and bucket[i 22 represent buckets, then any certificate serial number cno2 in the set of valid certificate serial numbers LCS is a false positive; S1143. Combine all the false positive certificate serial numbers into a set; obtain the false positive certificate serial number set FRS; Certificate Authorization Center Save the revoked certificate serial number set RCS and the false positive certificate serial number set FES, and generate OthelloO, which specifically includes the following steps: S121. Set the set S = RCS ∪ FRS. The size of the set S is n = |S|. Determine the parameters {m a , m b , h a , h b} based on the size n of the set S, where m a and m b are the lengths of the hash tables A and B respectively, and h a : {0, 1} * → {0, 1,..., m a - 1} and h b : {0, 1} * → {0, 1,..., m b - 1} are two non - cryptographic hash functions; S122. Construct graph G based on set S. For any certificate serial number cno in set S, the corresponding vertex v a α , v b β and edge (v a α , v b β ), where α and β represent the index values of the vertices, α = h a (cno), β = h b (cno); S123. Sort graph G using depth - first search, that is, sort all elements in set S to obtain a list L := (cno1, cno2,..., cno n ), where cno k ∈S, 1 ≤ k ≤ n; For It includes the following steps: S1231. If con k ∈ FRS, set the value v of the corresponding edge := 0; otherwise, set the value v of the corresponding edge := 1; S1232, calculate i k = h a (cno k ), j k = h b (cono k ), where i k and j k are two candidate bucket index values corresponding to cno k . If neither A[i k nor B[j k has been assigned a value, set A[i k : = 0, B[j k : = v; if only A[i k has not been assigned a value, set If only B[j k has not been assigned a value, set S124. Randomly assign 0 or 1 to the unassigned positions in hash table A and hash table B, and then hash table A and hash table B form the othello O; Certificate Authority Center Send the Cuckoo Filter CF to the ground base station Certificate Authority Center Send to the ground base station respectively Satellite And its query object Issue the corresponding public key certificate And Satellite Stores the public key of the Certificate Authority Center And The public key of the ground base station And Ground base station Stores the public key of the Certificate Authority Center And 3. The method for querying revocation of satellite certificates according to claim 2, characterized in that The step S2 specifically includes the following steps: S21, Satellite Calculate the first session key where represents the private key of the satellite , and represents the public key of the ground base station . S22, satellite Uniformly and consistently select the second random number Calculate the coordinates of the first elliptic curve point Calculate the first intermediate parameter Generate the first signature Generate the first satellite Internet revocation query request message in ASN.1 format: Among them, is the common name of the satellite and is the common name of the certificate authorization center ; is the public key certificate of the query object ; serial number in nonce1 is the ninth random number; S23, satellite Generate the first associated message where is the satellite 's public key certificate and the serial number in is the satellite 's public key. SNR_Request represents the identification string, and the message SNRRequest is encrypted using the first session key to obtain the ciphertext Generate the first query request Q1: = (head1, c1); if the satellite 's communication can cover the ground base station send the first query request Q1 to the ground base station within the range of the initiating satellite communication otherwise, the satellite sends the first query request Q1 to the neighboring relay satellite, and through the forwarding of multiple relay satellites, sends the first query request Q1 to the ground base station within the range of the relay satellite communication 4. A secure and efficient method for querying satellite certificate revocation according to claim 3, characterized in that, The step S3 specifically includes: S31, Ground base station After receiving the first query request Q1, calculate the second session key Wherein Represents the private key of the ground base station Use the second session key Decrypt the first ciphertext c1 If the integrity verification cannot be passed during the decryption process, abort the service; otherwise, obtain S32, Ground Base Station Query the query object for its public key certificate to check if it has been revoked. If it has been revoked, the query object has a first status st2 of its public key certificate set to "revoked". If it has not been revoked, the query object has a first status st2 of its public key certificate set to "good"; S33, Ground Base Station Calculate the second update time t4 := t2, where t2 is the last update time of the first state st2, calculate the seventh random number nonce4 := nonce2, and uniformly and randomly select the eighth random number Calculate the coordinates of the fourth elliptic curve point Calculate the fourth intermediate parameter Generate the fourth signature Generate the first satellite Internet revocation query response message in ASN.1 format: Among them, st3 is the status of the first satellite Internet revocation response message, t3 is the generation time of the first satellite Internet revocation response message, and st4 is the public key certificate of the query object The second status of; S34, Ground Base Station Generate the second association message Use the second session key Encrypt the message SNRRequest to obtain the fourth ciphertext Generate the second query response R2 := (head2, c4) and send it to the satellite S35. If the terrestrial base station is within the communication range of the satellite , the terrestrial base station sends the query response R2 to the satellite Otherwise, the terrestrial base station sends the query response R2 to the relay satellite that can currently cover the terrestrial base station in communication, and uses the forwarding of multiple relay satellites to send the query response R2 to the satellite Specifically, the ground base station described in step S32 Query the query object 's public key certificate Whether it has been revoked specifically includes the following steps: S321, Ground Base Station Calculate the third certificate fingerprint Calculate the fifth candidate bucket index value i 13 := h2(fp3) and the sixth candidate bucket index value S322, Ground Base Station Locate bucket[i in cuckoo filter CF 13 ] and bucket[i 23 ], where bucket[i 13 ] and bucket[i 23 ] indicates a bucket, and checks whether the third certificate fingerprint fp3 is in bucket[i 13 ] or bucket[i 23 ], if the third certificate fingerprint fp3 is not in the cuckoo filter CF, query the object Public key certificate Not revoked, ground base station Complete satellite certificate revocation query; S323. If the third certificate fingerprint fp3 is in the Cuckoo Filter CF, the ground base station Calculate the third random number nonce2 := nonce1, and uniformly and consistently select the fourth random number Calculate the coordinates of the second elliptic curve point Calculate the second intermediate parameter Generate the second signature Generate the second satellite Internet revocation query request message in ASN.1 format: Among them, is the common name of the ground base station ; S324, Ground Base Station Generate the third association message Calculate the third session key Use the third session key Encrypt the message SNRRequest to obtain the second ciphertext Generate the second query request Q2: = (head3, c2) and send it to the Certificate Authority S325, Certificate Authorization Center After receiving the second query request Q2:=(head3, c2), calculate the fourth session key Use the fourth session key Decrypt the second ciphertext c2 If the integrity verification fails during the decryption process, abort the service; otherwise, obtain S326, Certificate Authorization Center Calculate j = h b (cno), If result = 0, the public key certificate of the query object is not revoked; if result = 1, the public key certificate of the query object is revoked; the public key certificate is revoked; S327, Certificate Authorization Center Calculate the fifth random number nonce3 := nonce2, and uniformly and consistently select the sixth random number Calculate the coordinates of the third elliptic curve point Calculate the third intermediate parameter Generate the third signature Generate the second satellite Internet revocation query response message in ASN.1 format: Among them, st1 is the status of the second satellite Internet revocation response message, t1 is the generation time of the second satellite Internet revocation response message, and st2 is the first status of the query object 's public key certificate 's first status; S328, Certificate Authorization Center Generate the fourth associated message Use the fourth session key Encrypt the message SNRResponse to obtain the third ciphertext Generate the first query response R1 := (head4, c3) and send it to the ground base station S329, Ground Base Station After receiving the first query response R1: = (head4, c3), use the third session key Decrypt the third ciphertext c3 If the integrity verification fails during the decryption process, abort the query operation; otherwise, obtain Obtain the first status st2 and complete the query operation.
5. A secure and efficient method for querying satellite certificate revocation according to claim 4, characterized in that, The specific steps of S4 include: The satellite After receiving R2 = (head2, c4), calculate If the integrity verification fails during the decryption process, abort the query operation; otherwise, obtain Obtain the second status st4. If the second status st4 = "revoked", it indicates that the certificate has been revoked, and the satellite Refuses to provide business services to the query object If the second status st4 = "good", the satellite Carries out relevant business activities with the query object