Data encryption and integrity protection method for aviation broadband communication system
By using SM4 algorithm encryption and SM3 algorithm verification methods in the aviation broadband communication system, the problems of data theft and tampering are solved, and data security protection with low overhead and high reliability are achieved, ensuring the confidentiality and integrity of data transmission.
Patent Information
- Application Number
- CN202510840317.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-23
- Publication Date
- 2025-08-22
AI Technical Summary
The existing aviation broadband communication systems lack effective data encryption and integrity protection mechanisms, and are vulnerable to network attacks caused by data theft and tampering, affecting the safe operation of aircraft.
The domestic SM4 algorithm is used for data encryption, and the SM3 algorithm is used for integrity verification. By generating secure message headers on the sending end and performing encryption operations, the receiving end performs integrity verification to ensure the confidentiality and integrity of the data during transmission.
In the aviation broadband communication system, low overhead and high reliability data security protection is realized, preventing data eavesdropping and tampering, and ensuring the security and integrity of data transmission.
Smart Images

Figure CN120528682A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of communication technology, and in particular relates to a data encryption and integrity protection method for an aviation broadband communication system. Background Art
[0002] As critical information infrastructure for aviation transportation safety, aviation broadband communication systems carry key functions such as flight control commands, real-time status monitoring, and meteorological data transmission. They are crucial for achieving safe and efficient airspace management, air traffic flow management, and air traffic control. Their network security is crucial for ensuring the safe operation of aircraft. Due to the open nature of their links and the dynamic heterogeneity of network nodes, the system faces diverse security threats and is vulnerable to malicious attacks from outsiders, leading to data theft and tampering, compromising the security of network data. Therefore, providing information protection mechanisms for the transmission of en-route communication, navigation, and surveillance service data is crucial to the ultimate deployment and success of aviation broadband communication systems.
[0003] Currently, research on aviation broadband security protection is still in the theoretical stage, and effective defense systems and mechanisms have yet to be developed. Therefore, it is necessary to draw on security protection technologies from established fields to improve secure transmission technologies for aviation broadband communication systems tailored to China's national conditions. For example, the Aircraft Communications Addressing and Reporting System (ACARS) is a widely used communication system in aviation. It uses VHF radio or satellite communications to communicate short messages and transmit data, such as text messages, flight data, and air traffic control messages, between aircraft and ground base stations. ACARS Message Security (AMS) provides security protection, with AES-256-based link-layer encryption gradually replacing traditional plaintext transmission. End-to-end encryption technology establishes a secure channel between aircraft and ground systems through a public key infrastructure, ensuring the confidentiality of sensitive information such as meteorological data and flight plans. Furthermore, AMS uses HMAC or ECDSA signatures, integrated into the ACARS message protocol, to verify data integrity and sender identity, preventing message tampering and spoofing attacks and significantly improving anti-interference and anti-eavesdropping capabilities. Summary of the Invention
[0004] In view of this, the present invention aims to overcome the shortcomings of the above-mentioned problems in the prior art and proposes a data encryption and integrity protection method for aviation broadband communication systems. It aims to conduct in-depth research on air-to-ground data encryption / decryption and data integrity protection schemes that can meet the requirements of low overhead and high reliability, and ensure the confidentiality and integrity of air-to-ground data link transmission, so as to effectively prevent network attacks such as data eavesdropping, tampering and replay.
[0005] To achieve the above object, the technical solution of the present invention is achieved as follows:
[0006] A first aspect of the present invention provides a data encryption and integrity protection method for an aviation broadband communication system, comprising the following steps:
[0007] At the sending end, the data sending entity initializes and prepares the payload, then builds a secure data structure according to the subnet layer protocol requirements. Based on the optional security services and policies, it generates the relevant security message header, encrypts the data, and generates the corresponding message authentication code. The sending entity finally encapsulates the securely protected data into an SNP_PDU and sends it to the receiving entity.
[0008] At the receiving end, the receiving entity parses the data packet after receiving the SNP_PDU message and performs an integrity check based on the security information contained in the security message header. If the check results are consistent, the receiving entity will accept the data packet and decrypt the payload based on the security policy and parameters provided by the security message header, restoring it to plaintext data.
[0009] Furthermore, each SNP_PDU includes an integer byte, a header part, a data part, and a trailer part.
[0010] Furthermore, data encryption is completed at the LME layer and the SNP layer. The SM4 algorithm is used to encrypt the transmitted data, generate a data header, and configure the COUNT value and ciphertext length to be sent to the data link layer. The SNP layer and the LME layer use the negotiated encryption key to decrypt the received ciphertext and transmit the obtained data to the application layer.
[0011] Furthermore, each entity uses a separate COUNT variable on both the uplink and downlink to prevent key reuse.
[0012] Furthermore, the SM3 algorithm is used to implement the integrity check of the communication data, with the message M and the key K as input, and the output tag MAC. The algorithm initializes the cipher block size to 64 bytes, defines opad as 0x5C, and ipad as 0x36. If the length of the key K is greater than the cipher block size, the key K will be hash-compressed to obtain a hash key key with a length of 64 bytes. If the length of the key K is less than the cipher block size, it will be padded on the right until the length is equal to 64 bytes to generate the hash key key. The algorithm processes the internal key key1, whose value is the XOR operation of key and ipad. Key1 is hashed with the message M to obtain inner_hash = SM3(key1+M). The external key key2 is processed by setting key2 to the XOR operation of key and opad, and using key2 to hash the inner_hash to obtain hmac = SM3(key2+inner_hash). Finally, the generated MAC value is compared with the original MAC to verify the integrity of the message.
[0013] Furthermore, during data transmission, the sender encapsulates the message authentication code of the user data according to the information in the security message header; after receiving the SNP data message, the receiver parses the data and uses the generated message authentication code MAC for integrity verification.
[0014] Furthermore, the system receiver performs integrity check after receiving the protected data, uses the integrity protection key after key negotiation to recalculate the message authentication code XMAC of the received data, and compares it with the MAC in the message to determine whether the data has been tampered with.
[0015] The second aspect of the present invention provides a data encryption and integrity protection device for aviation broadband communication system, comprising
[0016] The first data processing unit is configured to, at the sending end, perform initialization and preparation operations on the payload by the data sending entity, and then construct a secure data structure according to the subnet layer protocol requirements; at the same time, based on the optional security services and policies, generate a related security message header, encrypt the data, and generate a corresponding message authentication code. The sending entity finally encapsulates the securely protected data into an SNP_PDU and sends it to the receiving entity;
[0017] The second data processing unit is used to parse the data packet at the receiving end after the receiving entity receives the SNP_PDU message, and perform integrity verification based on the security information contained in the security message header. If the verification results are consistent, the receiving entity will accept the data packet and decrypt the payload based on the security policy and parameters provided by the security message header to restore it to plaintext data.
[0018] A third aspect of the present invention provides an electronic device, comprising a processor and a memory communicatively connected to the processor and used to store instructions executable by the processor, wherein the processor is used to execute the above-mentioned method for data encryption and integrity protection in an aviation broadband communication system.
[0019] A fourth aspect of the present invention provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the above-mentioned method for data encryption and integrity protection in an aviation broadband communication system.
[0020] Compared with the existing technology, the data encryption and integrity protection method for aviation broadband communication system described in the present invention has the following advantages:
[0021] In the scenario of limited aviation broadband communication bandwidth, the present invention designs a low-overhead, high-reliability data security protection method based on domestic cryptographic technology. The confidentiality of the data is protected through the encryption scheme, and the integrity of the data is ensured through the message authentication code scheme. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] The accompanying drawings, which constitute part of the present invention, are provided to provide a further understanding of the present invention. The exemplary embodiments of the present invention and their descriptions are provided to explain the present invention and do not constitute an undue limitation of the present invention. In the accompanying drawings:
[0023] Figure 1 It is the overall flow chart of the present invention;
[0024] Figure 2 Schematic diagram of a user data-control data transmission framework in an embodiment of the present invention;
[0025] Figure 3 Schematic diagram of the data processing flow of the SNP layer and the LME layer in an embodiment of the present invention;
[0026] Figure 4 Schematic diagram of the SM3 algorithm flow in an embodiment of the present invention;
[0027] Figure 5 This is a schematic diagram of the integrity protection process in an embodiment of the present invention;
[0028] Figure 6 Schematic diagram of the user data integrity protection and verification process in an embodiment of the present invention;
[0029] Figure 7 A physical connection diagram of a test environment in an embodiment of the present invention;
[0030] Figure 8 This is a schematic diagram of Scyther analysis results in an embodiment of the present invention;
[0031] Figure 9 This is an example diagram of MAC captured by Wireshark in an embodiment of the present invention. DETAILED DESCRIPTION
[0032] It should be noted that, in the absence of conflict, the embodiments of the present invention and the features in the embodiments may be combined with each other.
[0033] In the description of the present invention, it should be understood that the terms "center", "longitudinal", "lateral", "up", "down", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inside", "outside" and the like indicate orientations or positional relationships based on the orientations or positional relationships shown in the accompanying drawings, and are only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as limiting the present invention. In addition, the terms "first", "second", etc. are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, features defined as "first", "second", etc. may explicitly or implicitly include one or more of the features. In the description of the present invention, unless otherwise specified, "multiple" means two or more.
[0034] In the description of the present invention, it should be noted that, unless otherwise expressly specified or limited, the terms "mounted," "connected," and "connected" should be understood in a broad sense. For example, they may refer to fixed connections, detachable connections, or integral connections; mechanical connections or electrical connections; direct connections or indirect connections through an intermediate medium; and internal communication between two components. Those skilled in the art will understand the specific meanings of the above terms in the present invention based on specific circumstances.
[0035] The present invention will be described in detail below with reference to the accompanying drawings and in conjunction with embodiments.
[0036] Example 1:
[0037] The system faces problems such as eavesdropping and tampering in data transmission, and needs to provide support for confidentiality and integrity protection technology. The present invention is to encrypt / decrypt and protect the integrity of data for the subnet layer protocol of the system. The overall process is as follows Figure 1 shown.
[0038] The data sending entity initializes and prepares the payload, then constructs a secure data structure according to the subnet layer protocol requirements. At the same time, based on the optional security services and policies, it generates the associated security message header (SEC_HEAD), encrypts the data, and generates the corresponding message authentication code. The sending entity ultimately encapsulates the securely protected data into an SNP_PDU and sends it to the receiving entity. After receiving the SNP_PDU message, the receiving entity parses the data packet and performs an integrity check based on the security information contained in the security message header. If the verification results are consistent, the receiving entity will accept the data packet and decrypt the payload based on the security policy and parameters provided by the SEC_HEAD, restoring it to plaintext data. Throughout the transmission process, both the sender and receiver strictly follow the order of security operations to securely protect and unseal the data to ensure the confidentiality and integrity of the data.
[0039] The system's security is provided by the Sub-Network Protocol (SNP). Data from higher layers can be encrypted directly within this layer, without relying on instructions from lower-layer protocols. This arrangement helps to better leverage the advantages of end-to-end secure transmission protocols.
[0040] In order to ensure the transmission security of the system, the security protocol needs to add confidentiality and integrity fields to the message structure. Table 1 shows the various fields contained in the SNP layer data message. Each SNP_PDU should contain an integer number of bytes and should include a header part, a data part, and a trailer part.
[0041] Table 1
[0042]
[0043] In a subnet layer data message, the message header contains the data type, security level, etc. CTRL is used to indicate the data type of different security services, as shown in Table 2.
[0044] Table 2
[0045]
[0046] SEC represents the integrity protection mode of MACs of different lengths, as shown in Table 3.
[0047]
[0048] The present invention is based on the domestic SM4 cryptographic algorithm and designs a data confidentiality protection method suitable for the system.
[0049] The block length of the SM4 algorithm is 128 bits, and the key length is also 128 bits. The encryption algorithm uses a 32-round nonlinear iterative structure and performs encryption operations in units of words. Each iterative operation is a round of transformation function F. Suppose the input plaintext is four words (X0, X1, X2, X3), a total of 128 bits. The input round key is rki, i = 0, 1, ..., 31, a total of 32 words. The output ciphertext is four words (Y0, Y1, Y2, Y3), 128 bits. The processing method of the SM4 encryption algorithm has the characteristics of ciphertext feedback connection and stream cipher. The result of the previous round of encryption is spliced with the encrypted data of the previous round for the next round of encryption processing. Four words are encrypted at a time to produce an intermediate ciphertext of one word. This intermediate ciphertext is spliced with the previous three words and then used for the next encryption process. A total of 32 rounds of iterative encryption processing will be performed to produce a ciphertext of four words.
[0050] In the present invention, data encryption occurs at the LME layer or the SNP layer, such as Figure 2 As shown in Figure 1, user data from the communicating entities is transmitted from the application layer to the SNP, where it is encrypted. In addition to encrypting user data between the aircraft and the ground, the LME also uses security protocols to protect control data, such as key update messages. This data is generated by the LME layer and encrypted / decrypted at the LME.
[0051] After the security authentication is completed, the aircraft station and the ground station confirm the data protection method and key derivation method, and derive the user data encryption key K according to the "Security Mode Command". U-enc and control data encryption key K C-enc After the SNP layer and LME layer receive the data, Figure 3 As shown, SM4 symmetric encryption is used as the encryption algorithm to encrypt the transmitted data, generate a data header, and configure the COUNT value and ciphertext length to be sent to the data link layer. The SNP and LME layers use the negotiated encryption key to decrypt the received ciphertext and transmit the resulting data to the application layer. To ensure that session-specific encryption keys are protected throughout their lifecycle, or to protect message content from disclosure in accordance with organizational security policies, the aircraft and ground stations can trigger key update commands to obtain new master keys and control data encryption keys. On both the uplink and downlink, each entity uses a separate COUNT variable to prevent key reuse. Within the same message, the same COUNT variable is used for encryption / decryption and integrity protection, ensuring data security and preventing keystream reuse.
[0052] In accordance with the system data integrity protection requirements, the present invention adopts the domestic hash cipher SM3 algorithm to implement the integrity check of communication data to prevent data from being tampered with, thereby posing a security threat to aviation operations. The SM3-HMAC algorithm used in the present invention takes the message M and the key K as input and outputs the label MAC. The algorithm initializes the cipher block size to 64 bytes, defines opad as 0x5C, and ipad as 0x36. If the length of the key K is greater than the cipher block size, the key K will be hash-compressed to obtain a hash key key with a length of 64 bytes. If the length of the key K is less than the cipher block size, it will be padded on the right until the length is equal to 64 bytes to generate the hash key key. The algorithm processes the internal key key1, whose value is the XOR operation of key and ipad. Key1 is hashed with the message M to obtain inner_hash = SM3(key1+M). Subsequently, the external key key2 is processed by setting key2 to the XOR operation of key and opad. The inner_hash is hashed using key2 to obtain hmac = SM3(key2+inner_hash). Finally, the generated MAC value is compared with the original MAC to verify the integrity of the message.
[0053] The above process is as follows Figure 4 As shown, the SM3 algorithm ensures that messages are not tampered with or forged during transmission, providing security and data integrity. It's important to note that the input to the SM3 hash algorithm must be a multiple of 512-bit binary data blocks. If the length of message M is less than a single data block, padding is required. Furthermore, to prevent the key K from being leaked, internal and external keys are used during the hash calculation process to enhance security.
[0054] The integrity protection function is placed in the subnet layer of the system. During data transmission, the sender encapsulates the message authentication code of the user data according to the information in the security message header SEC_HEAD; after receiving the SNP data message, the receiver will parse the data and use the generated message authentication code MAC for integrity verification. The process is as follows Figure 5 As shown in FIG, by using the message authentication code MAC, it can be ensured that the system can maintain its security and reliability during the communication process.
[0055] This scheme uses a symmetric integrity protection key to generate a MAC, which is then sent to the receiving end along with the encrypted ciphertext. When a secure session is initiated, a specific message authentication key is created and associated with the session. This key must be protected from disclosure during the session to ensure the security and integrity of the communicated data. Upon receiving the protected data, the receiving end performs an integrity check, recalculating the message authentication code (XMAC) of the received data using the negotiated integrity protection key. This code is then compared with the MAC included in the message to determine if the data has been tampered with.
[0056] According to the system data integrity protection requirements, the present invention adopts the domestic hash cipher SM3 algorithm to implement the integrity check of communication data to prevent data from being tampered with, thereby posing a security threat to aviation operations. According to the characteristics of user data transmission, the present invention combines the previously proposed data security message format to design a data integrity protection and verification process, such as Figure 6 shown.
[0057] The process of integrity protection and verification of the user data message format is to encapsulate and transmit the user data security message header, MAC and user data PDU. The entity sending end configures the corresponding integrity algorithm according to the security policy of the security message header to generate MAC.
[0058] The ground station entity has determined the value of the Ctrl field during the encryption process and, following the principle of encryption first and integrity protection later, calls the integrity interface. This means that integrity protection and integrity MAC value verification are performed on the given data message. To obtain the field value of the complete algorithm suite, assuming that the HMAC-SM3-256 algorithm is used to generate the MAC value, the calculation is as follows, where K u_int is the integrity key.
[0059]
[0060] The encrypted ciphertext and MAC are then sent to the aircraft. Upon receiving the data packet, the aircraft calculates the XMAC and compares it with the MAC to see if they match. If they match, it proves that the message has not been tampered with during transmission.
[0061] The effectiveness of this scheme is verified through experiments below.
[0062] The present invention uses an industrial computer and two servers and other hardware. The servers simulate GS and AS respectively. The industrial computer is a security gateway. According to the design of the above software security module, this test platform is loaded onto the server to establish a communication connection. The physical connection of the test equipment is specifically deployed as follows: Figure 7 shown.
[0063] In view of the security requirements raised by the communication system, it is necessary to fully evaluate the security of the solution. Formal verification is performed on it. Figure 8 To verify the results of Scyther, the model defines two roles: GS and AS, representing the parties participating in the aviation broadband communication protocol. Each message sent and received by the GS and AS uses a key for message encryption and decryption and integrity protection, and a Secret declaration is made for the corresponding shared key. During the data transmission process, attack scenarios are simulated, which can ensure the integrity of the transmitted data.
[0064] In order to test whether the designed solution can complete encryption, decryption and integrity protection, the protocol needs to be tested for compliance. Using the protocol stack simulation test platform, Wireshark is used to capture packets after the AS and GS instances are started. The marked part is the 256-bit MAC obtained by integrity protection of the DCH message, such as Figure 9 shown.
[0065] Example 2:
[0066] A data encryption and integrity protection device for aviation broadband communication system, comprising
[0067] The first data processing unit is configured to, at the sending end, perform initialization and preparation operations on the payload by the data sending entity, and then construct a secure data structure according to the subnet layer protocol requirements; at the same time, based on the optional security services and policies, generate a related security message header, encrypt the data, and generate a corresponding message authentication code. The sending entity finally encapsulates the securely protected data into an SNP_PDU and sends it to the receiving entity;
[0068] The second data processing unit is used to parse the data packet at the receiving end after the receiving entity receives the SNP_PDU message, and perform integrity verification based on the security information contained in the security message header. If the verification results are consistent, the receiving entity will accept the data packet and decrypt the payload based on the security policy and parameters provided by the security message header to restore it to plaintext data.
[0069] Example 3:
[0070] An electronic device includes a processor and a memory communicatively connected to the processor and used to store instructions executable by the processor, wherein the processor is used to execute the above-mentioned method for data encryption and integrity protection in an aviation broadband communication system.
[0071] Example 4:
[0072] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the above-mentioned data encryption and integrity protection method for an aviation broadband communication system.
[0073] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A method for data encryption and integrity protection in aviation broadband communication systems, characterized by: The steps include: At the sending end, the data sending entity initializes and prepares the payload, then builds a secure data structure according to the subnet layer protocol requirements. Based on the optional security services and policies, it generates the relevant security message header, encrypts the data, and generates the corresponding message authentication code. The sending entity finally encapsulates the securely protected data into an SNP_PDU and sends it to the receiving entity. At the receiving end, the receiving entity parses the data packet after receiving the SNP_PDU message and performs an integrity check based on the security information contained in the security message header. If the check results are consistent, the receiving entity will accept the data packet and decrypt the payload based on the security policy and parameters provided by the security message header, restoring it to plaintext data.
2. The method for data encryption and integrity protection in aviation broadband communication systems according to claim 1, characterized in that: Each SNP_PDU contains an integer number of bytes, a header part, a data part and a trailer part.
3. The method for data encryption and integrity protection in aviation broadband communication system according to claim 1, characterized in that: Data encryption is completed at the LME layer and SNP layer. The SM4 algorithm is used to encrypt the sent data, generate a data header, and configure the COUNT value and ciphertext length to be sent to the data link layer. The SNP layer and LME layer use the negotiated encryption key to decrypt the received ciphertext and transmit the obtained data to the application layer.
4. The method for data encryption and integrity protection in aviation broadband communication systems according to claim 3, characterized in that: On both uplink and downlink, each entity uses a separate COUNT variable to prevent key reuse.
5. The method for data encryption and integrity protection in aviation broadband communication system according to claim 1, characterized in that: The SM3 algorithm is used to implement the integrity check of communication data. It takes message M and key K as input and outputs label MAC. The algorithm initializes the cipher block size to 64 bytes, defines opad as 0x5C, and ipad as 0x36. If the length of key K is greater than the cipher block size, key K will be hash-compressed to obtain a 64-byte hash key key. If the length of key K is less than the cipher block size, it will be padded on the right until the length is equal to 64 bytes to generate the hash key key. The algorithm processes the internal key key1, whose value is the XOR operation of key and ipad. Key1 is hashed with message M to obtain inner_hash = SM3(key1+M). The external key key2 is processed by setting key2 to key and opad XOR operation, and using key2 to hash inner_hash to obtain hmac = SM3(key2+inner_hash). Finally, the generated MAC value is compared with the original MAC to verify the integrity of the message.
6. The method for data encryption and integrity protection in aviation broadband communication system according to claim 5, characterized in that: During data transmission, the sender encapsulates the message authentication code of the user data based on the information in the security message header; After receiving the SNP data message, the receiving end parses the data and uses the generated message authentication code MAC to perform integrity verification.
7. The method for data encryption and integrity protection in aviation broadband communication system according to claim 5, characterized in that: After receiving the protected data, the system receiver performs an integrity check, uses the integrity protection key after key negotiation to recalculate the message authentication code XMAC of the received data, and compares it with the MAC in the message to determine whether the data has been tampered with.
8. A data encryption and integrity protection device for aviation broadband communication systems, characterized by: include The first data processing unit is configured to, at the sending end, perform initialization and preparation operations on the payload by the data sending entity, and then construct a secure data structure according to the subnet layer protocol requirements; at the same time, based on the optional security services and policies, generate a related security message header, encrypt the data, and generate a corresponding message authentication code. The sending entity finally encapsulates the securely protected data into an SNP_PDU and sends it to the receiving entity; The second data processing unit is used to parse the data packet at the receiving end after the receiving entity receives the SNP_PDU message, and perform integrity verification based on the security information contained in the security message header. If the verification results are consistent, the receiving entity will accept the data packet and decrypt the payload based on the security policy and parameters provided by the security message header to restore it to plaintext data.
9. An electronic device comprising a processor and a memory in communication with the processor and configured to store instructions executable by the processor, wherein: The processor is configured to execute the method according to any one of claims 1 to 7.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.