Security authentication system and method

By coordinating low-orbit satellite authentication through high-orbit satellites and using RPUF to generate dynamic authentication credentials, the problem of inter-satellite authentication delay in low-orbit satellite networks is solved, and an efficient and secure authentication process is achieved.

CN120602934APending Publication Date: 2025-09-05CHINA TELECOM CORP LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510724647.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-30
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

In low-orbit satellite networks, inter-satellite authentication requires the transmission of authentication information through multiple hops, which results in a long authentication time and cannot adapt to the requirements of high dynamics and real-time performance.

Method used

High-orbit satellites are used to coordinate the authentication process between low-orbit satellites. Dynamic authentication credentials are generated through the Reconfigurable Physical Unclonable Function (RPUF), and authentication is performed directly on the high-orbit satellite to avoid multi-hop transmission.

Benefits of technology

It improves the efficiency of inter-satellite authentication, reduces authentication delay, adapts to the high dynamics and real-time requirements of low-orbit satellite networks, and enhances security and the speed of authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602934A_ABST
    Figure CN120602934A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a security authentication system and method, which are used for solving the problem that in the prior art, a low earth orbit satellite usually needs to transmit related information of authentication to a ground station for authentication in a multi-hop mode, so that relatively long time is needed for inter-satellite authentication. In the security authentication process, the to-be-authenticated low-orbit satellites do not need to send related authentication information to a ground station in a multi-hop mode, the inter-satellite authentication request of each to-be-authenticated low-orbit satellite is directly sent to the high-orbit satellite, and the security authentication efficiency is improved through coordination authentication of the high-orbit satellites.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of satellite network security technology, and in particular to a security authentication system and method. Background Art

[0002] With the development of Low Earth Orbit Satellite (LEO) networks, inter-satellite communications play a vital role in satellite networks. In LEO satellite communications, authentication and security issues become increasingly complex due to the high-speed movement of satellites and the constant handoffs between ground stations and other satellites. Related technologies typically require LEO satellites to transmit authentication information to ground stations via multiple hops during inter-satellite authentication. This results in a lengthy inter-satellite authentication process and is unable to meet the high dynamics and real-time requirements of LEO satellites.

[0003] Therefore, how to improve the efficiency of intersatellite security authentication has become an urgent problem to be solved. Summary of the Invention

[0004] The embodiments of the present application provide a security authentication system and method to solve the problem in the prior art that low-orbit satellites usually need to transmit authentication-related information to ground stations for authentication through multiple hops, resulting in a long time for inter-satellite authentication.

[0005] In a first aspect, the present application provides a security authentication system, the system comprising: a high-orbit satellite and at least two low-orbit satellites to be authenticated;

[0006] Any low-orbit satellite to be authenticated is configured to, upon receiving a first inter-satellite authentication request sent by another low-orbit satellite to be authenticated, determine a second inter-satellite authentication request based on its own current operation information and historical operation information; send the first inter-satellite authentication request and the second inter-satellite authentication request to the high-orbit satellite; wherein the inter-satellite authentication request includes at least a system reference identity corresponding to the low-orbit satellite to be authenticated, and the inter-satellite authentication request includes the first inter-satellite authentication request and the second inter-satellite authentication request; and if an authentication credential is received, send the authentication credential to the other low-orbit satellite to be authenticated and establish a communication link;

[0007] The high-orbit satellite is used to, upon receiving an inter-satellite authentication request from a pair of low-orbit satellites to be authenticated, search for each matching standard information in the pre-stored registration information according to the system reference identity of each low-orbit satellite to be authenticated carried in the inter-satellite authentication request; and authenticate other information carried in the corresponding inter-satellite authentication request based on each standard information; and send an authentication credential to the low-orbit satellite to be authenticated that sent the inter-satellite authentication request if the authentication of the pair of low-orbit satellites to be authenticated is passed.

[0008] In a second aspect, the present application provides a security authentication method applied to a low-orbit satellite, the method comprising:

[0009] If a first inter-satellite authentication request is received from another low-orbit satellite to be authenticated, the second inter-satellite authentication request is determined based on the current operation information and historical operation information of the satellite;

[0010] Sending the first inter-satellite authentication request and the second inter-satellite authentication request to the high-orbit satellite; wherein the inter-satellite authentication request includes at least a system reference identity corresponding to the low-orbit satellite to be authenticated, and the inter-satellite authentication request includes the first inter-satellite authentication request and the second inter-satellite authentication request;

[0011] If the authentication credential is received, the authentication credential is sent to the other low-orbit satellite to be authenticated, and a communication link is established.

[0012] In a third aspect, the present application provides a security authentication method applied to a high-orbit satellite, the method comprising:

[0013] If an inter-satellite authentication request is received for a low-orbit satellite pair to be authenticated, searching for each matching standard information in the pre-stored registration information according to the system reference identity of each low-orbit satellite to be authenticated carried in the inter-satellite authentication request;

[0014] Authenticating other information carried in the corresponding intersatellite authentication request based on each standard information;

[0015] In a case where the authentication of the low-orbit satellite to be authenticated is passed, an authentication credential is sent to the low-orbit satellite to be authenticated that sent the inter-satellite authentication request.

[0016] In a fourth aspect, an embodiment of the present application further provides a security authentication device, comprising:

[0017] A determination module is configured to determine a second inter-satellite authentication request based on its own current operation information and historical operation information upon receiving a first inter-satellite authentication request sent by another low-orbit satellite to be authenticated;

[0018] A sending module is used to send the first inter-satellite authentication request and the second inter-satellite authentication request to the high-orbit satellite; wherein the inter-satellite authentication request includes at least the system reference identity of the low-orbit satellite to be authenticated, and the inter-satellite authentication request includes the first inter-satellite authentication request and the second inter-satellite authentication request; if an authentication credential is received, the authentication credential is sent to the other low-orbit satellites to be authenticated, and a communication link is established.

[0019] In a fifth aspect, an embodiment of the present application further provides a security authentication device, the device comprising:

[0020] a search module configured to, upon receiving an inter-satellite authentication request for a low-orbit satellite pair to be authenticated, search for each matching standard information in pre-stored registration information according to the system reference identity of each low-orbit satellite to be authenticated carried in the inter-satellite authentication request;

[0021] an authentication module, configured to authenticate other information carried in the corresponding intersatellite authentication request based on each standard information;

[0022] The sending module is used to send an authentication certificate to the low-orbit satellite to be authenticated that sent the inter-satellite authentication request when the authentication of the low-orbit satellite to be authenticated is passed.

[0023] In a sixth aspect, the present application provides an electronic device, which includes a processor, and the processor is used to implement the steps of any of the above-mentioned security authentication methods when executing a computer program stored in a memory.

[0024] In a seventh aspect, an embodiment of the present application further provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of any of the security authentication methods described above.

[0025] Because in the embodiment of the present application, when performing security authentication, if any low-orbit satellite to be authenticated in the low-orbit satellite pair to be authenticated receives the first inter-satellite authentication request sent by the other low-orbit satellite to be authenticated, it determines the second inter-satellite authentication request based on its own current operation information and historical operation information, and sends the first inter-satellite authentication request and the second inter-satellite authentication request to the high-orbit satellite; if the high-orbit satellite receives the inter-satellite authentication request of the low-orbit satellite pair to be authenticated, it searches for each matching standard information in the pre-saved registration information based on the system reference identity of each low-orbit satellite to be authenticated carried in the inter-satellite authentication request; and authenticates the other information carried in the corresponding inter-satellite authentication request based on each standard information. If the authentication of the low-orbit satellite pair to be authenticated is passed, the authentication certificate is sent to the low-orbit satellite to be authenticated that sent the inter-satellite authentication request. During the security authentication process, the low-orbit satellite to be authenticated does not need to send the authentication related information to the ground station through multiple hops. Instead, the inter-satellite authentication request of each low-orbit satellite to be authenticated is directly sent to the high-orbit satellite. The high-orbit satellite coordinates the authentication, thereby improving the efficiency of security authentication. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] In order to more clearly illustrate the technical solution of the present application, the following is a brief introduction to the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0027] Figure 1 A schematic diagram of a system architecture provided in an embodiment of the present application;

[0028] Figure 2 A schematic diagram of a security authentication system provided in an embodiment of the present application;

[0029] Figure 3 A schematic diagram of a flow chart of an inter-satellite authentication process provided in an embodiment of the present application;

[0030] Figure 4 A schematic diagram of a security authentication process provided in an embodiment of the present application;

[0031] Figure 5 A schematic diagram of a security authentication process provided in an embodiment of the present application;

[0032] Figure 6 A schematic diagram of the structure of a security authentication device provided in an embodiment of the present application;

[0033] Figure 7 A schematic diagram of the structure of a security authentication device provided in an embodiment of the present application;

[0034] Figure 8 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0035] In order to make the purpose, technical solutions and advantages of this application more clear, the technical solutions of the embodiments of this application will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field are within the scope of protection of this application.

[0036] To make the objectives, technical solutions, and advantages of this application more clear, this application will be further described in detail below with reference to the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making any creative efforts are within the scope of protection of this application.

[0037] It should be noted that the terms "including" and "having" and their variations involved in the documents of this application are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or are inherent to these processes, methods, products or devices.

[0038] The terms "first" and "second" are used for descriptive purposes only and should not be construed as explicitly or implicitly indicating relative importance or the number of the technical features indicated. Therefore, features specified as "first" or "second" may explicitly or implicitly include one or more of such features. In the description of the embodiments of this application, unless otherwise specified, "plurality" means two or more.

[0039] The word “exemplary” is used hereinafter to mean “serving as an example, example, or illustration.” Any embodiment described as “exemplary” is not necessarily to be construed as preferred or advantageous over other embodiments.

[0040] For ease of understanding, before introducing the technical solution of this application, some of the terms involved in this application are explained:

[0041] Reconfigurable Physical Unclonable Function (RPUF): A function based on the physical properties of hardware whose challenge-response pair (CRP) can be dynamically reconfigured using its logical state. After each authentication, the internal state is updated through hashing or key derivation, making subsequent CRPs unpredictable. This combines physical unclonability with dynamic modeling resistance.

[0042] Low Earth Orbit Satellite (LEO): A satellite operating at an altitude of 300 to 2000 kilometers. It features short orbits (circling the Earth in approximately 90 minutes), low latency (communication delay <50ms), and highly dynamic topology. Typical applications include Starlink and remote sensing constellations.

[0043] Inter-Satellite Authentication: In a low-orbit satellite network, two or more satellites verify the legitimacy of each other's identities by exchanging authentication information before establishing a communication link.

[0044] Challenge-Response Pair (CRP): The core security element of a PUF, consisting of an input challenge (Challenge) and a physically generated response (Response). In this solution, the challenge is dynamically obfuscated before being input into the RPUF, and the response is hashed before being output, preventing direct exposure of the original PUF behavior.

[0045] Related technologies often employ authentication mechanisms based on traditional public key infrastructure (PKI) or symmetric key protocols for inter-satellite security authentication. However, these technical approaches face a series of challenges in low-orbit satellite networks, primarily in the following areas:

[0046] Public Key Infrastructure Authentication: It is the basis of most current network authentication systems, including digital certificates, the exchange of private and public keys. PKI can provide strong identity authentication capabilities and is widely used. Traditional PKI authentication schemes verify the identity of satellites through trusted certificate authorities (CA). However, a major problem with PKI authentication is the need for a complex certificate management system, involving operations such as certificate generation, verification, and revocation, which is very complicated in low-orbit satellite networks. Especially when the network topology of the satellite changes frequently, the workload of certificate management increases, which may cause authentication delays and affect communication efficiency. In addition, the security of PKI also depends on the security of the CA. If the CA is attacked, the security of the entire authentication system will also be threatened.

[0047] Symmetric key authentication schemes rely on pre-shared keys, requiring all communicating nodes to share the same key. While computationally efficient, symmetric key authentication in low-Earth orbit satellite networks faces a major challenge: key distribution and management. Due to the large number of satellites in a low-Earth orbit satellite network and their dynamic state, distributing and updating keys across different satellites presents a challenge. Furthermore, symmetric key authentication cannot effectively address key leakage and identity forgery.

[0048] In recent years, Physical Unclonable Functions (PUFs) have been introduced into security authentication as a hardware-level security authentication solution. PUFs leverage the characteristics of satellite hardware to generate unique authentication information, thereby achieving security authentication. The advantage of PUFs is that they do not rely on traditional keys and certificates, but instead rely on the unique physical characteristics of the device, making them more difficult for attackers to copy. However, existing PUF authentication solutions still face the following problems when facing the dynamic changes in low-orbit satellite networks:

[0049] Single-time authentication problem: Existing PUF authentication schemes typically use the same PUF response throughout the lifecycle of a device, which allows attackers to obtain the PUF's behavior pattern through long-term observation and modeling attacks, thereby forging an identity.

[0050] Static state problem: Many PUF authentication solutions fail to address the issue of how devices update keys and reconfigure their states in dynamic environments, which results in a lack of adaptability in the authentication process.

[0051] In summary, although existing authentication schemes can provide basic identity authentication and security protection for satellites, the following technical issues still exist, especially in the highly dynamic environment of low-orbit satellite networks:

[0052] Difficulty in dynamic authentication and key updates: Satellites in low-orbit satellite networks frequently change their orbits and communication links, making traditional authentication solutions (such as PKI-based solutions or symmetric key authentication) unable to meet the needs of real-time key updates and authentication. Authentication needs to be completed quickly while satellites are in motion, and traditional solutions often involve complex certificate management and key exchange processes, which can cause delays.

[0053] Insufficient resistance to modeling attacks: While existing PUF-based authentication schemes offer some resistance to counterfeiting, they still present the risk of modeling attacks in dynamic environments. Attackers can collect a large number of challenge-response pairs (CRPs) to build models and predict device responses. This is particularly true for low-Earth orbit satellites, where frequent inter-satellite communications allow attackers to forge identities by tracking satellite behavior patterns over time.

[0054] Key distribution and management difficulties: Symmetric key schemes face key distribution and management challenges, particularly in low-orbit satellite networks. Securely and efficiently distributing, updating, and managing keys between satellites is a key issue. In a dynamic satellite network, ensuring that each satellite can quickly and securely generate session keys when communicating with other satellites while preventing key leakage and replay attacks remains a challenge.

[0055] High re-authentication latency: The high-speed movement of low-orbit satellites and frequent communication link disconnections require frequent re-authentication between satellites. Existing authentication mechanisms are unable to effectively handle these frequently changing authentication requirements, which can lead to increased authentication latency, impacting communication quality and system stability.

[0056] Based on the above analysis, the embodiments of the present application provide a secure authentication system and method, which are suitable for lightweight, modeling attack-resistant satellite identity authentication and key agreement in a dynamic topology environment. The system includes a high-orbit satellite and at least two low-orbit satellites to be authenticated; any low-orbit satellite to be authenticated is used to determine a second inter-satellite authentication request based on its own current operation information and historical operation information if it receives a first inter-satellite authentication request sent by other low-orbit satellites to be authenticated; the first inter-satellite authentication request and the second inter-satellite authentication request are sent to the high-orbit satellite; wherein the inter-satellite authentication request at least includes a system reference identity of the corresponding low-orbit satellite to be authenticated, and the inter-satellite authentication request includes the first inter-satellite authentication request and the second inter-satellite authentication request; if an authentication credential is received, the authentication credential is sent to the other low-orbit satellite to be authenticated, and a communication link is established; the high-orbit satellite is used to search for each matching standard information in the pre-stored registration information based on the system reference identity of each low-orbit satellite to be authenticated carried in the inter-satellite authentication request if it receives an inter-satellite authentication request of the low-orbit satellite pair to be authenticated; and authenticate other information carried in the corresponding inter-satellite authentication request based on each standard information; if the authentication of the low-orbit satellite pair to be authenticated is passed, the authentication credential is sent to the low-orbit satellite to be authenticated that sent the inter-satellite authentication request.

[0057] The innovation of this application is to use RPUF (Reconfigurable Physical Unclonable Function) to ensure the security of authentication in low-orbit satellite networks. To facilitate the subsequent understanding of the solution, the formation process of RPUF is explained below.

[0058] ① Input Transformation (ITF) and Challenge Generation:

[0059] ■ During the satellite authentication process, the challenge C is input together with the satellite's state S. After being processed by the input transfer function (ITF), a perturbed intermediate value ITF(C,S) is generated. At this time, the challenge C is converted into a perturbed intermediate value. This process ensures the security and irreversibility of the challenge information.

[0060] ② Physical unclonable function (P):

[0061] The P-function, the core of the RPUF, generates a unique response based on the physical characteristics of satellite hardware (such as chip variations). This response is used in the subsequent authentication process to ensure the unique and unforgeable identity of each satellite. Thanks to the P-function, each satellite has its own unique challenge-response pair (CRP). These CRPs are generated based on the characteristics of the satellite's hardware. This prevents an attacker from forging or replicating the satellite's identity, even if they capture a portion of the CRP.

[0062] ③Output Transformation (OTF) and Response Generation:

[0063] ■After generating the perturbed intermediate value W, the satellite uses the output transfer function (OTF) to generate the PUF authentication response, ensuring that the response is irreversible during the authentication process and preventing forgery and modeling attacks.

[0064] ④Fuzzy Extractor and Error Correction:

[0065] ■ To ensure accurate response generation in noisy environments, Fuzzy Extractor is used to correct the generated challenge-response pairs. Fuzzy Extractor extracts accurate response information from noisy responses, ensuring authentication is successful even in unstable communication and hardware environments.

[0066] The security authentication system provided in the embodiments of the present application is intended to solve technical problems such as authentication delays, key management difficulties, and insufficient security caused by the rapid movement of satellites and dynamic changes in communication links in low-orbit satellite networks. The application of existing authentication schemes in low-orbit satellite (LEO) networks faces multiple technical challenges. In particular, when faced with highly dynamic communication links in low-orbit satellite networks, existing technologies find it difficult to provide efficient, secure, and reliable authentication solutions. Specifically, this application solves the following major technical problems:

[0067] High dynamics and the need for frequent authentication. Low-orbit satellites move rapidly in their orbits, resulting in frequent changes in communication links and network topologies between satellites. Existing authentication methods are mainly based on static identity authentication and cannot effectively cope with this rapidly changing environment. In traditional authentication schemes, satellites must frequently re-authenticate, which not only increases authentication delays but also leads to a decrease in network efficiency. This application adopts a reconfigurable physically unclonable function (RPUF) and generates unique authentication information at each authentication through a dynamic key and state update mechanism, thereby significantly reducing authentication delays and ensuring that the authentication process between satellites adapts to highly dynamic environments.

[0068] Key management and dynamic update issues. In low-orbit satellite networks, secure key management and timely updates are key to ensuring network communication security. However, existing authentication schemes are difficult to deal with the risks in the key distribution, management, and update process, especially when satellite communication links change frequently. The keys in existing schemes may be leaked or reused, posing a hidden danger to system security. This application introduces the dynamic key update mechanism of RPUF, which automatically generates new keys and status after each authentication, ensuring that different keys are used for each authentication session, preventing key leakage or replay attacks, and thus greatly improving the security of the system.

[0069] Anti-modeling attacks and identity forgery problems. In traditional physically unclonable function (PUF)-based schemes, attackers may build models by long-term monitoring and collecting challenge-response pairs (CRP), thereby predicting subsequent authentication responses and forging identities or bypassing authentication. This application uses the reconfigurable characteristics of RPUF to use unique challenges, responses, and keys for each authentication. Even if an attacker collects a large number of challenge-response pairs, they cannot predict subsequent authentication responses, thereby effectively preventing modeling attacks and identity forgery problems.

[0070] Efficient and fast authentication process. In low-orbit satellite networks, due to the dynamic and high-latency characteristics of the communication links between satellites, the authentication process is usually limited by bandwidth and latency, resulting in a slow authentication process and affecting system performance. Existing authentication schemes may take a long time to perform authentication and key exchange, and cannot adapt to the high dynamics and real-time requirements of low-orbit satellites. This application combines GEO satellites as an auxiliary role of the authentication server. When authenticating between LEO satellites, the authentication process is coordinated through GEO satellites, and the efficient computing characteristics of RPUF are used to ensure that the authentication process is fast and efficient, and can quickly complete authentication in a low-bandwidth and high-latency environment.

[0071] Specifically, the technical objectives of this application are:

[0072] 1. Efficient dynamic authentication: In low-orbit satellite networks, communication links between satellites frequently change, and existing authentication solutions are unable to meet the authentication needs in this highly dynamic environment. This invention uses an RPUF mechanism to dynamically generate challenges and responses for each authentication, ensuring an efficient and timely authentication process.

[0073] 2. Secure key management and updates: Due to the frequent changes in communication links in low-orbit satellite networks, secure key management and timely updates are critical technical issues. This invention leverages the reconfigurable nature of the RPUF to ensure that each authentication uses a unique key and state, eliminating the risks of key leakage, identity forgery, and replay attacks.

[0074] 3. Protection against modeling attacks and identity forgery: Traditional authentication schemes are vulnerable to modeling attacks, where attackers collect a large number of challenge-response pairs (CRPs) to construct models and forge identities. By using RPUF's dynamic key generation and state updates, this invention prevents attackers from predicting authentication responses through modeling attacks, thus ensuring the security of the authentication system.

[0075] 4. Efficient authentication in low-bandwidth and high-latency environments: Low-Earth Orbit satellite communications are often limited by bandwidth and latency. This invention utilizes the assistance of GEO satellites to make the authentication process between LEO satellites more efficient. GEO satellites act as authentication servers, assisting with inter-satellite authentication, ensuring a fast and secure authentication process that is adaptable to low-bandwidth and high-latency environments.

[0076] Through these technical means, the low-orbit satellite inter-satellite authentication method and system of this application solves key technical issues in low-orbit satellite networks, such as dynamic authentication requirements, key management, resistance to modeling attacks, and authentication delays, thereby improving the security, efficiency, and scalability of satellite networks. The authentication process of the security authentication system will be described in detail below, combined with various embodiments.

[0077] For ease of understanding, before introducing the security authentication process, the system architecture of the security authentication system is first explained. Figure 1 A schematic diagram of a system architecture provided in an embodiment of the present application is shown as follows: Figure 1 As shown in the figure, the security authentication system mainly includes: Geostationary Satellite (GEO), multiple Low Earth Orbit Satellite (LEO) and a Ground Authority Station. The functions of each role in the authentication process are as follows:

[0078] Authoritative ground station:

[0079] An authoritative ground station can be understood as a pre-defined gateway with administrative authority. It manages and controls the entire satellite network, including LEO satellite registration, key management, and oversight and coordination of the authentication process. It provides basic authentication data for GEO satellites and assists with satellite authentication when necessary.

[0080] The authoritative ground station is the core of the system. It is responsible for verifying the uniqueness of satellite identities and ensuring the safe entry of all satellites into the network.

[0081] GEO Satellites:

[0082] GEO satellites act as authentication intermediaries in the satellite network, coordinating and facilitating mutual authentication between LEO satellites. Because GEO satellites are fixed and stable relative to Earth, they have a longer communication window and can provide continuous authentication support for LEO satellites. In this embodiment of the present application, GEO satellites are primarily used to receive identity information from LEO satellites and verify their legitimacy.

[0083] LEO satellites:

[0084] In the embodiment of the present application, the LEO satellite generates its authentication information through the RPUF and uses this information to authenticate with other LEO satellites. When establishing communication with other LEO satellites, the LEO satellite uses the GEO satellite to assist in authentication and jointly negotiates the session key with other LEO satellites.

[0085] Example 1:

[0086] Figure 2 A schematic diagram of a security authentication system provided in an embodiment of the present application, the system comprising: a high-orbit satellite 101 and at least two low-orbit satellites 102 to be authenticated;

[0087] Any low-orbit satellite 102 to be authenticated is configured to, upon receiving a first inter-satellite authentication request sent by another low-orbit satellite 101 to be authenticated, determine a second inter-satellite authentication request based on its own current operating information and historical operating information; send the first inter-satellite authentication request and the second inter-satellite authentication request to the high-orbit satellite 101; wherein the inter-satellite authentication request includes at least a system reference identity of the corresponding low-orbit satellite to be authenticated, and the inter-satellite authentication request includes the first inter-satellite authentication request and the second inter-satellite authentication request; if an authentication credential is received, send the authentication credential to the other low-orbit satellite 102 to be authenticated, and establish a communication link;

[0088] The high-orbit satellite 101 is used to, upon receiving an inter-satellite authentication request from a low-orbit satellite pair to be authenticated, search for each matching standard information in the pre-saved registration information according to the system reference identity of each low-orbit satellite to be authenticated carried in the inter-satellite authentication request; and authenticate other information carried in the corresponding inter-satellite authentication request based on each standard information; and send an authentication credential to the low-orbit satellite to be authenticated 102 that sent the inter-satellite authentication request if the authentication of the low-orbit satellite pair to be authenticated is passed.

[0089] In a low-orbit satellite network, the LEO satellite inter-satellite authentication mechanism is a key link in ensuring secure communication and identity authentication between satellites. Inter-satellite authentication prevents identity forgery, replay attacks, and data tampering by ensuring the authenticity of satellite identities and the security of the network. In order to improve the efficiency of inter-satellite security authentication, a high-orbit satellite 101 is introduced in the security authentication process of an embodiment of the present application. The high-orbit satellite 101 is used to verify the information of the low-orbit satellite to be verified carried in the received inter-satellite authentication request. If the authentication is successful, the authentication certificate is sent to the corresponding low-orbit satellite to be authenticated. Only when the inter-satellite authentication is successful can a communication link be established between the corresponding low-orbit satellites to be authenticated for communication. In an embodiment of the present application, the security authentication system includes a high-orbit satellite 101 and at least two low-orbit satellites 102 to be authenticated. In an embodiment of the present application, based on the master-slave relationship between satellites, a routing protocol is used to determine which satellite initiates the authentication request. In an embodiment of the present application, an example is given in which the security authentication system includes two low-orbit satellites 102 to be authenticated. For ease of understanding, in the following embodiments of the present application, a LEO satellite L i and LEO satellite L j The interaction in intersatellite authentication is described as an example, describing the j Toward Satellite L i The authentication request initiated by the master and slave satellites ensures efficient and secure communication through authentication interaction.

[0090] Any LEO satellite 102 to be authenticated can receive a first inter-satellite authentication request sent by another LEO satellite 102 to be authenticated. This first inter-satellite authentication request is generated based on the satellite's stored device state, challenge data, auxiliary information, and reference identity. When any LEO satellite 102 to be authenticated receives a first inter-satellite authentication request from another LEO satellite 102 to be authenticated, it can be assumed that the other LEO satellite 102 to be authenticated needs to communicate with it. To complete security authentication, it can determine a second inter-satellite authentication request based on its current and historical operating information. Since security authentication is intended to verify whether the LEO satellite to be authenticated has been hacked and whether it is secure, when determining the second inter-satellite authentication request, any LEO satellite 102 to be authenticated can obtain its current and historical operating information. To prevent malicious tampering with the historical operating information, this historical operating information can be stored in a trusted execution environment. After obtaining this current and historical operating information, it can be used as content carried in the second inter-satellite authentication request. In order to facilitate the subsequent high-orbit satellite 101 to accurately distinguish which low-orbit satellite to be authenticated corresponds to each inter-satellite authentication request, the second inter-satellite authentication request may also carry the system reference identity of the low-orbit satellite to be authenticated 102. The system reference identity can be used to uniquely identify the corresponding low-orbit satellite. It should be noted that the content carried in the first inter-satellite authentication request is the same as the content carried in the second inter-satellite authentication request, except that the first inter-satellite authentication request carries the relevant data of the other low-orbit satellite to be authenticated 102, while the second inter-satellite authentication request carries the relevant data of any low-orbit satellite to be authenticated 102.

[0091] After receiving the second inter-satellite authentication request, the first and second inter-satellite authentication requests can be sent to the high-orbit satellite 101, and the high-orbit satellite 101 performs the authentication. In other words, the inter-satellite authentication requests of the low-orbit satellites 102 to be authenticated that are participating in the authentication are aggregated to the same low-orbit satellite 102 to be authenticated, and the low-orbit satellite 102 to be authenticated sends all inter-satellite authentication requests to the high-orbit satellite 101. For ease of description, in this embodiment of the present application, the first and second inter-satellite authentication requests may be collectively referred to as inter-satellite authentication requests.

[0092] Since the inter-satellite authentication requests sent to the high-orbit satellite 101 are all sent by a certain low-orbit satellite to be authenticated after gathering all the inter-satellite authentication requests, for the sake of convenience of description, in this embodiment of the present application, the low-orbit satellite to be authenticated 102 participating in the security authentication is referred to as a low-orbit satellite pair to be authenticated. In this embodiment of the present application, after the high-orbit satellite 101 receives the inter-satellite authentication request of the low-orbit satellite pair to be authenticated, it can search for each matching standard information in the pre-saved registration information based on the system reference identity of each low-orbit satellite to be authenticated carried in the inter-satellite authentication request. In other words, the high-orbit satellite 101 stores the registration information of each low-orbit satellite. After searching for each matching standard information, the other information carried in the corresponding inter-satellite authentication request can be authenticated based on each standard information. If the authentication of the low-orbit satellite pair to be authenticated is passed, the authentication certificate is sent to the low-orbit satellite to be authenticated that sent the inter-satellite authentication request. For example, the high-orbit satellite 101 can determine whether the found standard information is consistent with other information carried in the inter-satellite authentication request. If they are consistent, it means that the relevant information of the corresponding low-orbit satellite to be authenticated has not been tampered with and is safe; if they are inconsistent, it means that the relevant information of the corresponding low-orbit satellite to be authenticated may have been tampered with and there is a security risk.

[0093] After receiving the authentication credential sent by the high-orbit satellite 101, any low-orbit satellite 102 to be authenticated may send the authentication credential to the other low-orbit satellite 102 to be authenticated, and establish a communication link between itself and the other low-orbit satellite 102 to be authenticated. It should be noted that how to establish a communication link between low-orbit satellites is a prior art, and this embodiment of the present application will not further describe this process.

[0094] Because in the embodiment of the present application, when performing security authentication, if any low-orbit satellite to be authenticated in the low-orbit satellite pair to be authenticated receives the first inter-satellite authentication request sent by the other low-orbit satellite to be authenticated, it determines the second inter-satellite authentication request based on its own current operation information and historical operation information, and sends the first inter-satellite authentication request and the second inter-satellite authentication request to the high-orbit satellite; if the high-orbit satellite receives the inter-satellite authentication request of the low-orbit satellite pair to be authenticated, it searches for each matching standard information in the pre-saved registration information based on the system reference identity of each low-orbit satellite to be authenticated carried in the inter-satellite authentication request; and authenticates the other information carried in the corresponding inter-satellite authentication request based on each standard information. If the authentication of the low-orbit satellite pair to be authenticated is passed, the authentication certificate is sent to the low-orbit satellite to be authenticated that sent the inter-satellite authentication request. During the security authentication process, the low-orbit satellite to be authenticated does not need to send the authentication related information to the ground station through multiple hops. Instead, the inter-satellite authentication request of each low-orbit satellite to be authenticated is directly sent to the high-orbit satellite. The high-orbit satellite coordinates the authentication process, thereby improving the efficiency of security authentication.

[0095] Example 2:

[0096] In order to improve the accuracy of security authentication, based on the above embodiment, in the embodiment of the present application, any low-orbit satellite 102 to be authenticated is specifically used to determine its own current authentication information based on the current operation information and a preset algorithm, where the current authentication information includes a current state key and a current final authentication response; encrypt the current final authentication response and the current state key based on the historical operation information to obtain an encrypted final authentication response and an encrypted state key; determine a first hash value based on the historical operation information, the current state key, a pre-stored system reference identity, the current final authentication response, and the first inter-satellite authentication request; and determine the second inter-satellite authentication request based on the first hash value, the system reference identity, the encrypted final authentication response, and the encrypted state key.

[0097] The high-orbit satellite 101 is specifically used to search for matching standard historical operation information in the pre-saved registration information according to each of the system reference identities; decrypt the encrypted final authentication response and the encrypted status key based on the standard historical operation information respectively to obtain the final authentication response to be verified and the status key to be verified; determine the second hash value based on the standard historical operation information, the status key to be verified, the system reference identity, the final authentication response to be verified and the received first inter-satellite authentication request; if the second hash value is consistent with the first hash value, it is determined that the authentication of the low-orbit satellite pair to be authenticated is passed.

[0098] In order to enhance the randomness and unpredictability of the authentication process, in an embodiment of the present application, any low-orbit satellite 102 to be authenticated, when determining the second inter-satellite authentication request based on its own current operating information and historical operating information, can determine its own current authentication information based on the acquired current operating information and a preset algorithm. The current authentication information includes the current status key and the current final authentication response.

[0099] Specifically, any low-orbit satellite 102 to be authenticated can generate a device status S according to the current operating status. i,new and random challenge C i,new , and through the input transfer function (ITF) to the new challenge C i,new Perform perturbation processing to generate a new mask challenge W i,new :W i,new =ITF(C i,new ,S i,new), this process enhances the randomness and unpredictability of the challenge, ensuring the uniqueness and non-repeatability of each authentication request. The generation of new states and new challenges prevents replay attacks and enhances the unpredictability of authentication. i,new Afterwards, the mask challenge W can be performed by the physical unclonable function (P) i,new Generate response R i,new The process uses the physical characteristics of satellite hardware (such as chip differences) to generate a unique response, ensuring the unforgeability of the identity: R i,new =P(W i,new ). Then, the probability generation function Gen(R i,new ), from the response R i,new Extract the stable current state key and auxiliary data: K i,new and ad i,new =Gen(R i,new ). The generated K i,new and ad i,new It will be used for the generation and verification of subsequent authentication responses. Finally, the output transfer function (OTF) is used to convert the current state key K i,new and auxiliary data ad i,new Perform disturbance and generate the current final authentication response FR i,new :FR i,new =OTF(S i,new ,(K i,new ,ad i,new )), by further disturbing the authentication data, the irreversibility of the authentication response is ensured to prevent forgery and data leakage.

[0100] After obtaining the current authentication information, the current final authentication response and the current state key can be encrypted based on the historical operation information to obtain an encrypted final authentication response and an encrypted state key. In the embodiment of the present application, when performing encryption, those skilled in the art can select an appropriate encryption algorithm for encryption as needed.

[0101] In one possible implementation, when encrypting the previous final authentication response based on the historical operation information, the historical state key can be determined based on the historical mask challenge, historical auxiliary data and reconstruction function, and the historical state key can be used to encrypt the current final authentication response to obtain an encrypted final authentication response.

[0102] Specifically, the historical state key can be determined based on the following formula: K i =Rep(W i ,hd i ). Where Rep() represents the reconstruction function; W iIndicates historical mask challenge; hd i Represents historical auxiliary data. The key generation process combines the challenge information and auxiliary data to ensure that the generated key has a high degree of randomness and stability, and is only generated by satellite L i In the embodiment of the present application, the W i ,hd i It can be directly obtained from the saved data or determined based on the saved historical device status and challenges. Specifically, the low-orbit satellite to be certified can generate and store the initial state S using its hardware characteristics and external environmental conditions during the registration phase. i , the status represents the identity of the satellite and is guaranteed to be unique and tamper-proof during the authentication process. i It is generated by the low-orbit satellite itself when the authentication system is initialized and stored in the satellite memory. It is always bound to the satellite hardware. Similarly, the satellite generates and stores the current challenge C during the initialization phase. i , the challenge will be used as one of the inputs in the authentication process to ensure the unpredictability of the challenge information. i Its auxiliary data hd i and reference identity SRD i Used together for subsequent authentication calculations. Reference identity SRD i It is generated by the ground station through the unique identification of the satellite and remains unique in the system to ensure the authenticity of the satellite identity. When determining the historical mask challenge, the input transformation function (ITF) can be used to extract the challenge C i and device status S i Process and generate mask challenge W i :W i =ITF(C i ,S i The input transformation function (ITF) ensures the irreversibility of the challenge information during the authentication process, preventing the challenge data from being reversed or forged. Through the perturbation process, the satellite further enhances the security of the authentication data.

[0103] After obtaining the historical state key, the current final authentication response can be encrypted with the historical state key to obtain an encrypted final authentication response. For example, the current final authentication response can be XORed with the historical state key to obtain an encrypted final authentication response. That is, the current final authentication response is encrypted based on the following formula: in, Indicates the encrypted final authentication response; FR i,new Indicates the current final authentication response; K i Represents the history state key.

[0104] For example, when encrypting the current state key based on historical operation information, the current state key can be XORed with the historical state key to obtain the encrypted state key. Of course, to further ensure the security of the key, the historical operation information can also be combined with other information to encrypt the current state key. For example, the current state key can be encrypted based on the following formula to obtain the encrypted state key: in, Indicates the encryption state key; FR i,new Indicates the current final authentication response; K i Represents the historical state key; SRD i Indicates its own system reference identity; SAR j Indicates the first intersatellite authentication request received; K i,new Represents the current state key. Encryption ensures the security of the final authentication response and the current state key, preventing information leakage or tampering during the authentication process.

[0105] In order to facilitate the subsequent verification of the high-orbit satellite 101, in an embodiment of the present application, the first hash value can be determined based on historical operation information, the current state key, the pre-saved system reference identity, the current final authentication response, and the first inter-satellite authentication request. Subsequently, by comparing the hash values, it can be more intuitive to determine whether the relevant data has been tampered with. It should be noted that those skilled in the art can also add other parameters to determine the first hash value together as needed. For example, the following formula can be used to calculate the first hash value to ensure that all data in the authentication process has not been tampered with or forged: i =VF(K i ,K i,new ,SRD i ,R i ,FR i,new ,t i ,SAR j ). Among them, v i represents the first hash value; VF() represents the verification hash function, which is essentially to determine the hash value of the data in (); K i Represents the historical state key; K i,new Indicates the current state key; SRD i Indicates its own system reference identity; R i Indicates a random number, which is randomly selected by the satellite. This value will ensure the uniqueness and unpredictability of each authentication request; FR i,new Indicates the current final authentication response; t i Indicates the current time; SAR j Indicates the first intersatellite authentication request received.

[0106] After determining the first hash value, a second inter-satellite authentication request may be determined based on the first hash value, the system reference identity, the encrypted final authentication response, and the encrypted state key. For example, the second inter-satellite authentication request may be obtained by concatenating the first hash value, the system reference identity, the encrypted final authentication response, and the encrypted state key.

[0107] Exemplarily, the second inter-satellite authentication request may include the following contents: Among them, SAR i Indicates the second intersatellite authentication request; SRD i Indicates its own system reference identity; R i represents a random number, i.e., a random number used to determine the first hash value; Represents the encrypted final authentication response; Indicates the encryption state key; v i represents the first hash value; t i Indicates the current time, t i Carrying it in the second inter-satellite authentication request can ensure the timeliness of the authentication request and prevent replay attacks.

[0108] The high-orbit satellite 101 searches for each matching standard information in the pre-saved registration information according to the system reference identity of each low-orbit satellite to be authenticated carried in the inter-satellite authentication request; and in the process of authenticating other information carried in the corresponding inter-satellite authentication request based on each standard information, it can search for matching standard historical operation information in the pre-saved registration information according to each system reference identity.

[0109] In one possible implementation, since the historical state key is used to encrypt the previous final authentication response, the same key needs to be used to decrypt the encrypted final authentication response during the decryption process. In an embodiment of the present application, a matching standard state key can be searched in the pre-saved registration information based on the system reference identity. The process of determining the standard state key is different from the method of determining the historical state key, but the content of the standard state key determined based on the different method is consistent with the content of the historical state key. It can be simply understood that the process of determining the standard state key is a forward process, and the process of determining the historical state key is a reverse process. After obtaining the standard state key, the standard state key can be used to decrypt the encrypted final authentication response to obtain the final authentication response to be verified.

[0110] Specifically, the encrypted final authentication response can be decrypted based on the following formula to obtain the final authentication response to be verified: Among them, FR i,new Indicates the current final authentication response of the low-orbit satellite i to be authenticated; Represents the encrypted final authentication response of the low-orbit satellite i to be authenticated; K i Indicates the standard state key of the low-orbit satellite i to be authenticated.

[0111] When decrypting the encrypted state key, the state key to be verified can be determined based on the following formula: Among them, K i,new Indicates the key in the state to be verified; represents the encryption state key; h() represents the hash function; FR i,new Indicates the final authentication response to be verified; K i Indicates the standard state key; SRD i Indicates System Reference Identity; SAR j Indicates the first intersatellite authentication request received. In other words, the data used by the low-orbit satellite to be authenticated when encrypting the relevant data will be used for decryption.

[0112] In an embodiment of the present application, the high-orbit satellite can use the decrypted data and the standard information of the corresponding low-orbit satellite to be authenticated stored in itself to determine the second hash value, and determine whether the second hash value is consistent with the first hash value. If they are consistent, it means that the corresponding low-orbit satellite to be authenticated is safe and the information has not been tampered with; if they are inconsistent, it means that the information of the corresponding low-orbit satellite to be authenticated may have been tampered with, or the inter-satellite authentication request has been tampered with during the transmission process. In either case, it means that there are security risks and communication is not suitable. In an embodiment of the present application, the second hash value can be determined based on the standard historical operation information, the state key to be verified, the system reference identity, the final authentication response to be verified, and the first inter-satellite authentication request received. It should be noted that those skilled in the art can add other parameters to the above as needed to determine the first hash value together. However, it needs to be ensured that the parameters used in determining the first hash value also require corresponding parameters when determining the second hash value. For example, the second hash value can be determined based on the following formula: VF(K i ,K i,new ,SRD i ,R i ,FR i,new ,t i ,SAR j ). Among them, K i Represents the standard state key; K i,new Indicates the state key to be verified; SRD i R represents the system reference identity of the received low-orbit satellite i to be verified; i Indicates the random number carried in the second intersatellite authentication request received; FR i,new Indicates the final authentication response to be verified after decryption; t iIndicates the timestamp carried in the second intersatellite authentication request received; SAR j If the second hash value is consistent with the first hash value, it can be determined that the information carried in the second inter-satellite authentication request is correct, and further, it can be determined that the low-orbit satellite to be authenticated corresponding to the second inter-satellite authentication request is safe and a legitimate node.

[0113] Similarly, for the first inter-satellite authentication request received, the high-orbit satellite performs similar verification processing, and this embodiment of the present application will not go into details about this process.

[0114] It should be noted that the process of determining the first inter-satellite authentication request is consistent with the process of determining the second inter-satellite authentication request. The process of determining the first inter-satellite authentication request is described below with reference to a specific embodiment.

[0115] Assume that the other low-orbit satellite to be authenticated that sends the first inter-satellite authentication request is L j The process of determining the first intersatellite authentication request mainly includes the following steps:

[0116] 1. Preparation of initial authentication information.

[0117] At this stage, satellite L j Use the previously stored device state S j 、Challenge C j , auxiliary data hd j and the system reference identity SRD j To initialize the authentication request. The specific process is as follows:

[0118] Extract device status S j and Challenge C j Satellite L j Generate and store the initial state S using its hardware characteristics and external environmental conditions j This state ensures that the satellite's identity is unique and cannot be tampered with during the authentication process. j It is generated by the ground control center when the authentication system is initialized and stored in the satellite memory, and is always bound to the satellite hardware. j During the initialization phase, the current challenge C is generated and stored. j , this challenge will be used as one of the inputs in the authentication process.

[0119] Extract auxiliary data hd j and reference identity SRD j Satellite L j Its auxiliary data hd j and reference identity SRD j Used together for subsequent authentication calculations. Reference identity SRD jIt is generated by the ground station using the satellite’s unique identifier and remains unique in the system to ensure the authenticity of the satellite’s identity.

[0120] 2. Calculation and generation of mask challenges.

[0121] Input Transfer Function (ITF): Satellite L j Using Input Transformation Function (ITF) to extract the challenge C j and device status S j Process and generate mask challenge W j :W j =ITF(C j ,S j ). The input transformation function ITF ensures the irreversibility of the challenge information during the authentication process, preventing the challenge data from being reversely calculated or forged. Through the perturbation process, the satellite L j The security of authentication data is further enhanced.

[0122] 3. The generation of new states and new challenges.

[0123] To enhance the randomness and unpredictability of the authentication process, Satellite L j Select a new device state S j,new and random challenge C j,new , and perform perturbations on new challenges:

[0124] New state S j,new and new challenge C j,new Satellite L j Select the new device status S j,new and random challenge C j,new , and through the input transfer function (ITF) to the new challenge C j,new Perform perturbation processing to generate a new mask challenge W j,new :W j,new =ITF(C j,new ,S j,new This process enhances the randomness of the challenge, ensuring the uniqueness and security of each authentication request. The generation of new states and new challenges prevents replay attacks and enhances the unpredictability of authentication.

[0125] 4. Calculate K j Challenge Response R j,new .

[0126] Generate challenge response R j,new Satellite L j Mask challenge W through physical unclonable function (P) j,new Generate response R j,newThe process uses the physical characteristics of satellite hardware (such as chip differences) to generate a unique response, ensuring the unforgeability of the identity: R j,new =P(W j,new ).

[0127] Calculate the key K j Satellite L j Calculate the current state key K j :K j =Rep(W j ,hd j The key generation process combines challenge information and auxiliary data to ensure that the generated key is highly random and stable and is only generated by satellite L j To be generated.

[0128] 5. Generation of keys and auxiliary data.

[0129] The fuzzy extractor generates keys and auxiliary data. Satellite L j Using the probability generation function Gen(R) of the Fuzzy Extractor j,new ), from the response R j,new Extract stable key information and auxiliary data: K j,new and ad j,new =Gen(R j,new ).

[0130] 6. Generation and perturbation of the final authentication response.

[0131] Output Transfer Function (OTF): Satellite L j Use the output transfer function (OTF) to transform the new state key K j,new and auxiliary data ad j,new Perform perturbation and generate the final authentication response FR j,new :FR j,new =OTF(S j ,(K j ,ad j )), by further disturbing the authentication data, the irreversibility of the authentication response is ensured to prevent forgery and data leakage.

[0132] Authentication response disturbance. Satellite L j Final certification response FR j,new To encrypt: At the same time, satellite L j For the new key K j,new Perform encryption processing to obtain the encrypted key The security of authentication responses and keys is ensured to prevent information leakage or tampering during the authentication process.

[0133] 7. Identity Verification and Status Verification

[0134] Authentication value v j :Satellite L j Calculate the authentication value v using the verification hash function (VF) j , ensuring the consistency and correctness of identity information, keys, responses and states: v j =VF(K j ,K j,new ,SRD j ,R j ,FR j,new ,t j ), Satellite L j Ensure that all data during the authentication process has not been tampered with or forged.

[0135] 8. Generation of Intersatellite Authentication Request

[0136] The authentication request message is generated. Finally, the satellite L j Integrate all authentication information to generate intersatellite authentication request message SAR j , and sent to the main satellite L j The request message includes the following: Among them, t j It is the current timestamp, which ensures the timeliness of the authentication request and prevents replay attacks.

[0137] Example 3:

[0138] In order to further improve the accuracy of security authentication, based on the above embodiments, in the embodiment of the present application, the system further includes a ground station 103;

[0139] Any of the low-orbit satellites to be authenticated 102 is further configured to, during satellite registration, determine a masked challenge based on its own initial state, a generated random challenge, and an input conversion function; determine a response based on a physical unclonable function (PUF) and the masked challenge; process the response based on a fuzzy extractor to extract a first state key and first auxiliary data; determine a first final authentication response based on the first state key, the first auxiliary data, the initial state, and the output conversion function; and send its own identity, the first state key, and the first final authentication response to the ground station;

[0140] The ground station 103 is configured to search for the identity in a pre-stored registration list; if not, determine a third hash value based on the identity and the first final authentication response, determine the third hash value as the system reference identity of the any low-orbit satellite to be authenticated, and send the third hash value to the any low-orbit satellite to be authenticated; store the system reference identity, the first state key, and the first final authentication response corresponding to the identity, and send them to the high-orbit satellite;

[0141] The high-orbit satellite 101 is further configured to store the system reference identity, the first state key, and the first final authentication response as standard information.

[0142] In order to ensure the security of each satellite, each low-orbit satellite needs to be registered during the initialization process. LEO satellite registration is an important step to ensure the uniqueness and credibility of each satellite in the network. By registering the identity of each satellite, the system can achieve high-security inter-satellite authentication and secure communication. In order to adapt to the dynamic low-orbit satellite environment, a reconfigurable physical unclonable function (RPUF) is introduced in the embodiment of the present application. Through dynamic state reconstruction and authentication information update mechanism, the anti-modeling attack capability and key security of the registration process are enhanced. The following is an example of a LEO satellite L i Take this as an example to explain the registration process in detail.

[0143] When the LEO satellite to be certified registers, it can determine the mask challenge based on its own initial state, the generated random challenge and the input conversion function. i First, a random initial state S can be generated based on its current state i = Random(State). This initial state is used to ensure the uniqueness and non-repeatability of the hardware identity during the authentication process. Satellite L i Then generate a random challenge C i = Random(Challenge), the random challenge will be used as one of the input information in the authentication process, combined with the initial state S i Used to generate mask challenges later. Random Challenge C i Ensures the unpredictability and anti-forgery of data during the authentication process. i The generated random challenge C i and the initial state S i Input to the input transfer function (ITF) for processing. Input transfer function ITF (C i ,S i ) will challenge C i and state S i Perform perturbation processing to generate mask challenge W i =ITF(Ci ,S i This process is used to confuse the challenge and state information, ensuring the security and irreversibility of the challenge information and preventing data leakage or attackers from guessing the challenge content.

[0144] After obtaining the mask challenge, the physical unclonable function (P) can be used to challenge the perturbed mask W. i Generate unique response R i , that is: R i =P(W i ), which generates a unique response based on the hardware characteristics of the satellite (such as slight differences in satellite chips), ensuring that the identity of each satellite is unforgeable.

[0145] After the response is determined, the probability generation function Gen(R i ) for the response R i Process and generate the first state key K i and first auxiliary data ad i This process is done by i Extract high entropy information from the key to generate secure keys and auxiliary data, ensuring the randomness and anti-replay attack capability of the key, namely Gen(R i )=(K i ,ad i ). First state key K i Used for identity mutual trust operations in subsequent communications.

[0146] After determining the first state key and the first auxiliary data, the first state key K i and the first auxiliary data d i The input is perturbed into the output transfer function (OTF) to generate the final first final authentication response FR i =OTF(S i ,(K i ,ad i )), the output transformation function further ensures the irreversibility of the authentication response and prevents attackers from reversely calculating the satellite's key and identity information.

[0147] To complete the registration, after determining the first final authentication response, the satellite L i You can use its identity ID i , first state key K i and the first final authentication response FR i Composed of registration message set {ID i ,K i ,FR i}Sent to ground station 103.

[0148] After receiving the registration message, the ground station 103 can search for the identity in the pre-stored registration list. i Verify whether the satellite has been registered in the system. If not, it means that the satellite is not registered. The ground station 103 can use the satellite's ID i and the first final authentication response FR i To generate a system reference identity. In the embodiment of the present application, a third hash value can be determined based on the identity identifier and the first final authentication response, and the third hash value can be determined as the system reference identity of any low-orbit satellite to be authenticated to ensure the uniqueness of the satellite identity and prevent forgery. For example, the system reference identity can be expressed as SRD: SRD i =RIGF(ID i ,FR i ,msk G ). Among them, SRD i Indicates the system reference identity of satellite i; ID i Indicates the identity of satellite i; FR i Indicates the first final authentication response of satellite i; msk G represents a pre-generated private key; RIGF() represents the reference identity generation function, which essentially determines the hash value of the data in (). The reference identity generation function RIGF is used to generate the reference satellite identity SRD in the satellite network, which is used to uniquely identify each LEO satellite in the system.

[0149] After determining the system reference identity, in order to facilitate subsequent security authentication, the system reference identity can be sent to the corresponding low-orbit satellite to be authenticated. At the same time, the system reference identity, the first state key and the first final authentication response corresponding identity are saved. In other words, the ground station will generate the system reference identity SRD i , first state key K i and the first final certification response FR i Store and return it as a registration response to the satellite L i , the response message returned is: {SRD i After receiving the registration response, the low-orbit satellite to be authenticated can use the system reference identity SRD i , initial state S i , first auxiliary data ad i and random challenge C i Stored in non-volatile memory, the LEO satellite registration process is now completed.

[0150] After the LEO satellite completes the registration, the ground station can send the system reference identity, the first state key and the first final authentication response to the high-orbit satellite, so that the high-orbit satellite can perform security authentication based on the registration information. In order to further ensure the security of data transmission, in this embodiment of the application, a symmetric encryption mechanism (using the master private key msk G )Registration information, such as {SRD i ,K i ,FR i}) and send the encrypted registration information to the GEO satellite: Among them, msk G It is randomly generated by the high-orbit satellite 101 during the initialization phase and synchronized to the ground station 103. Specifically, during the high-orbit satellite initialization phase, the high-orbit satellite generates a key set F in advance. p Randomly select a key as the master private key msk G . This private key will be used to generate a reference identity for each LEO satellite in the subsequent authentication process. The master private key of the GEO satellite is only stored locally and in the authoritative ground station and is not disclosed to the outside world to ensure the confidentiality of the private key. In an embodiment of the present application, different key sets can be saved for different security levels. The higher the security level, the more keys are included in the corresponding key set, and the less likely it is to be deciphered. When determining the master private key, you can first obtain the security level pre-configured for the high-orbit satellite, and then select the corresponding target key set according to the security level, and select the master private key from the target key set.

[0151] After receiving the encrypted information, the GEO satellite decrypts and stores the registration information to provide support for subsequent authentication and key exchange between satellites.

[0152] The following describes the initialization phase of the security authentication system using a specific example. The initialization phase is a critical part of system startup, aiming to set basic system parameters, select security algorithms, and generate the required encryption keys. This phase is managed by the authoritative ground station, which sets public parameters and functions to ensure system security and the reliability of the authentication process. The specific steps are as follows:

[0153] Parameter setting and function selection. The authoritative ground station is responsible for setting the system's public parameters and security functions. These functions and parameters will play an important role in the subsequent certification process. Key functions include:

[0154] Input Transformation Function (ITF): Based on a secure one-way hash function, it is used to transform the input challenge C into an intermediate value W, ensuring the one-way nature and security of the challenge during the authentication process.

[0155] Output Transformation Function (OTF): Similar to ITF, OTF is based on a one-way hash function and converts the generated response into an output FR, ensuring that the response is not easily reversed during the authentication process, thereby improving the security of the authentication process.

[0156] Reference Identity Generation Function (RIGF): used to generate the reference satellite identity SRD in the satellite network, which is used to uniquely identify each LEO satellite in the system.

[0157] Physical Unclonable Function (P): This function generates challenge-response pairs based on the physical properties of satellite hardware, ensuring that each satellite's identity cannot be forged. The P function is the core of this invention and plays a key role in verifying satellite identity and preventing identity forgery.

[0158] Verification Hash Function (VF): Verification hash functions are used to ensure the integrity and verification of data passed during the authentication process. During the authentication process, the verification hash function verifies that the response data matches the stored expected data, preventing data tampering.

[0159] Key Generation Function (KGF): This function generates the key used during the authentication process. This function generates the session key SK based on the input authentication data (such as the satellite identity information and the authentication challenge response). This session key is used for encryption and decryption operations in subsequent communications.

[0160] Secure one-way hash function (h): used for hash calculations throughout the authentication process, ensuring the one-way and irreversibility of data processing.

[0161] Once initialization is complete, the authoritative ground station will publish the selected public parameters and the aforementioned functions to the entire system. These parameters include: secure one-way hash function and check hash function; specific configurations for the input transformation function (ITF), output transformation function (OTF), and reference identity generation function (RIGF); and other necessary public system parameters to ensure correct use by each satellite during authentication.

[0162] Example 4:

[0163] In order to further improve the accuracy of security authentication, based on the above embodiments, in the embodiment of the present application, any low-orbit satellite 102 to be authenticated is specifically used to obtain a first current time, and send the first current time, the first inter-satellite authentication request, and the second inter-satellite authentication request to the high-orbit satellite;

[0164] The high-orbit satellite 101 is also used to determine the time interval between the first current time and the current time; if the time interval meets the preset interval threshold requirement, the subsequent steps of searching for each matching standard information in the pre-saved registration information based on the system reference identity of each low-orbit satellite to be authenticated carried in the inter-satellite authentication request are continued.

[0165] In order to further improve the accuracy of security authentication and prevent replay attacks, in an embodiment of the present application, any low-orbit satellite 102 to be authenticated can also obtain the current first current time when sending the first inter-satellite authentication request and the second inter-satellite authentication request to the high-orbit satellite, and send the first current time, the first inter-satellite authentication request, and the second inter-satellite authentication request to the high-orbit satellite.

[0166] After receiving the inter-satellite authentication request of the low-orbit satellite to be authenticated, the high-orbit satellite 101 can also verify the timestamp before searching for each matching standard information in the pre-saved registration information based on the system reference identity of each low-orbit satellite to be authenticated carried in the inter-satellite authentication request to prevent replay attacks. In an embodiment of the present application, the high-orbit satellite 101 can determine the time interval between the received first current time and the current time, and determine whether the time interval meets the preset interval threshold requirement. That is, determine whether the difference between the first current time and the current time is within the allowed range. If so, the request can be considered valid, and the subsequent steps of searching for each matching standard information in the pre-saved registration information based on the system reference identity of each low-orbit satellite to be authenticated carried in the inter-satellite authentication request can be continued. If not, the request can be considered invalid and the request can be rejected.

[0167] It should be noted that since the time of generating the first inter-satellite authentication request and the time of generating the second inter-satellite authentication request are different, in order to further ensure the accuracy of security authentication, the timestamp can be carried in them when generating the first inter-satellite authentication request and the second inter-satellite authentication request, so that high-orbit satellites can perform timestamp verification before processing the inter-satellite authentication request.

[0168] Example 5:

[0169] To further improve the accuracy of security authentication, based on the above embodiments, in an embodiment of the present application, the high-orbit satellite 101 is further configured to determine, for each low-orbit satellite to be authenticated in the low-orbit satellite pair to be authenticated, a fourth hash value based on the system reference identity of the low-orbit satellite to be authenticated and other information carried in the corresponding inter-satellite authentication request; use the fourth hash value to update the system reference identity of the low-orbit satellite to be authenticated stored in itself; and carry the updated system reference identity of each low-orbit satellite to be authenticated in the low-orbit satellite pair to be authenticated in the authentication credential and send it to the low-orbit satellite to be authenticated that sent the inter-satellite authentication request;

[0170] Any of the low-orbit satellites to be authenticated 102 is further configured to update its stored system reference identity using the received system reference identity corresponding to itself, and send the updated system reference identity corresponding to the other low-orbit satellites to be authenticated to the other low-orbit satellites to be authenticated.

[0171] To prevent attackers from tracking satellites through their identities, the high-orbit satellite 101 can generate a new system reference identity for each low-orbit satellite in the low-orbit satellite pair to be authenticated after completing security authentication of the low-orbit satellite pair to be authenticated. Specifically, a fourth hash value can be determined for each low-orbit satellite in the low-orbit satellite pair to be authenticated based on the system reference identity of the low-orbit satellite to be authenticated and other information carried in the corresponding inter-satellite authentication request. The fourth hash value is then used to update the system reference identity of the low-orbit satellite to be authenticated stored in the high-orbit satellite 101. In other words, the fourth hash value is used as the new system reference identity of the low-orbit satellite to be authenticated.

[0172] For example, the new system reference identity of the low-orbit satellite i to be authenticated can be determined based on the following formula: SRD i,new =RIGF(SRD i ,FR i,new ,msk G ), where SRD i,new Indicates the fourth hash value; SRD i Indicates the current system reference identity of the low-orbit satellite i to be authenticated; FR i,new Indicates the final authentication response to be verified; msk G Represents the master private key; RIGF() represents the reference identity generation function, which essentially determines the hash value of the data in ().

[0173] Similarly, the new system reference identity of the low-orbit satellite j to be authenticated can be determined based on the following formula: SRD j,new =RIGF(SRD j ,FR j,new ,msk G ).

[0174] In order to facilitate subsequent authentication, the high-orbit satellite can store the generated new reference identity and corresponding authentication data: ({SRD i,new ,FR i,new ,K i,new}) and ({SRD j,new ,FR j,new ,K j,new}).

[0175] In order for the corresponding low-orbit satellite to be authenticated to update its own system reference identity in a timely manner, the high-orbit satellite 101 can also carry the updated system reference identity of each low-orbit satellite to be authenticated in the authentication certificate and send it to the low-orbit satellite to be authenticated that sends the inter-satellite authentication request.

[0176] After receiving the authentication certificate, any low-orbit satellite to be authenticated can use the received system reference identity corresponding to itself to update its own saved system reference identity, and send the updated system reference identities corresponding to other low-orbit satellites to be authenticated to other low-orbit satellites to be authenticated, so that other low-orbit satellites to be authenticated can be updated.

[0177] Example 6:

[0178] To further improve the accuracy of security authentication, based on the above embodiments, in an embodiment of the present application, the high-orbit satellite 101 is specifically configured to generate an authentication credential based on each system reference identity corresponding to the low-orbit satellite pair to be authenticated and other information carried in the first inter-satellite satellite authentication request;

[0179] The any one of the low-orbit satellites to be authenticated 102 is specifically configured to determine a fifth hash value based on the authentication credential and each system reference identity corresponding to the low-orbit satellite pair to be authenticated, and send the fifth hash value to the other low-orbit satellites to be authenticated;

[0180] The other low-orbit satellite to be authenticated 102 is configured to, upon receiving the fifth hash value, determine a candidate authentication credential based on each system reference identity corresponding to the low-orbit satellite pair to be authenticated and other information carried by the other satellite when determining the first inter-satellite satellite; determine a sixth hash value based on the authentication credential and each system reference identity corresponding to the low-orbit satellite pair to be authenticated; and if the sixth hash value is consistent with the fifth hash value, encrypt the authentication success identifier using the session key to obtain an encrypted authentication success identifier;

[0181] The any one of the low-orbit satellites 102 to be authenticated is specifically configured to, upon receiving an encrypted authentication success identifier, decrypt the encrypted authentication success identifier using the session key to obtain the authentication success identifier.

[0182] Since the authentication credentials fed back by the high-orbit satellite to the low-orbit satellite to be authenticated may still be tampered with, in this embodiment of the present application, the low-orbit satellite to be authenticated can also verify the received authentication credentials after receiving them. In this embodiment of the present application, when generating the authentication credentials, the high-orbit satellite can generate the authentication credentials based on each system reference identity corresponding to the low-orbit satellite to be authenticated and other information carried in the first inter-satellite satellite authentication request.

[0183] Specifically, when determining the authentication credentials that can enable the low-orbit satellites to be authenticated to authenticate each other, the high-orbit satellite can determine based on the following formula: AC i-j =VF(SRD i ,SRD j ,FR j,new ,K j,new ). Among them, SRD i Indicates the system reference identity of the received low-orbit satellite i to be authenticated; SRD j Indicates the system reference identity of the received low-orbit satellite j to be authenticated; FR j,new Indicates the final authentication response to be verified; K j,new Represents the state key to be verified; VF() represents the hash value of the data in the brackets. The subsequent low-orbit satellite to be authenticated can determine whether the authentication certificate has been tampered with based on the hash value. In order to further ensure the security of the authentication certificate, in the embodiment of the present application, the authentication certificate can also be disturbed, that is, the authentication certificate is encrypted to obtain a disturbed certificate. Among them, K i,new Indicates the verification status key of other low-orbit satellites to be authenticated in the low-orbit satellite pair to be authenticated; FR i,new Indicates the final authentication response to be verified for other low-orbit satellites to be authenticated in the authentication low-orbit satellite pair; t g Indicates the current timestamp. Since the new system reference identity of the low-orbit satellite to be authenticated also needs to be sent together, in this embodiment of the application, the high-orbit satellite can also perturb the generated reference identity to ensure the security of the identity during the authentication process and prevent attackers from tracking the identity to locate the satellite.

[0184]

[0185] Finally, the high-orbit satellite sends the authentication certificate AR to any low-orbit satellite to be authenticated. G This can include: in, It is the overall verification value of the authentication process, ensuring the integrity and security of the authentication process. G Represents the identity of the high-orbit satellite. Other parameters have been described in detail in the above content and will not be repeated in the embodiments of this application.

[0186] Assume that the low-orbit satellite to be certified is L i After receiving the authentication certificate, any low-orbit satellite to be authenticated can first check the validity of the timestamp and then verify the correctness of each authentication information to ensure that the data has not been tampered with. i By calculating the authentication credentials and generating the corresponding session keys,j Send intersatellite authentication response.

[0187] LEO satellite L i Receive authentication response AR G After that, first check the timestamp t in the response g The authentication request is considered invalid if the timestamp is expired or out of the allowed range. Otherwise, the subsequent verification process continues.

[0188] Since the authentication certificate sent by the high-orbit satellite is encrypted, the ciphertext can be decrypted first to obtain the plaintext of the authentication certificate. G Authentication credentials in LEO satellite L i The authentication credentials are calculated using the following formula: And calculate the updated system reference identity SRD i,new : Here, is the perturbation system reference identity received from the GEO satellite, SRD i Represents the forward system reference identity. Use the verification hash function (VF) to verify the consistency of identity and state:

[0189] If the validation value With the received v G Match, then satellite L i Confirm the legitimacy of GEO satellite G and that the authentication data has not been tampered with.

[0190] After confirming the legality of GEO satellites, LEO satellites i Continue to generate L for other low-orbit satellites to be certified j In the embodiment of the present application, the fifth hash value can be determined based on the authentication credentials and each system reference identity corresponding to the low-orbit satellite to be authenticated and sent to the other low-orbit satellites to be authenticated. j Specifically, the mutual authentication parameter can be determined based on the following formula, that is, the fifth hash value MA i-j : Among them, t j From satellite L j Received timestamp, t i,new It is Satellite L i The current timestamp of the authentication. This parameter is used for subsequent authentication verification to ensure the integrity of the authentication.

[0191] After the fifth hash value is determined, the fifth hash value and the authentication certificate are sent to the other low-orbit satellite to be authenticated. In the embodiment of the present application, it is assumed that the other low-orbit satellite to be authenticated is L j For example, LEO satellite L i Generate intersatellite authentication response ISAR and send it to satellite L j The authentication response message includes: in, is the updated reference identity of the perturbation system; MA i-j is the mutual authentication parameter, i.e. the fifth hash value; g ,t i,new It is a timestamp used to ensure the timeliness of authentication information.

[0192] When LEO satellite L j Received from LEO satellite L i After receiving the intersatellite authentication response message ISAR, the validity of the timestamp is verified first, and then the session key is generated based on the system reference identity, mutual authentication parameters and key generation function. Finally, an authentication success flag is generated and the authentication result is encrypted.

[0193] LEO satellite L j After receiving the authentication response message ISAR, first verify the timestamp t contained in it g ,t i,new The validity of the timestamp is determined. That is, whether the time interval between the timestamp and the current time meets the preset interval threshold. If the timestamp is valid, the subsequent authentication steps will be continued.

[0194] LEO satellite L j According to the LEO satellite i System reference identity in the received authentication response ISAR Calculate the new system reference identity SRD j,new : Among them, SRD j It is Satellite L j The locally stored system reference identity, K j,new is the newly calculated key, FR j,new It is from L i Received response data.

[0195] To obtain the authentication credential, the high-orbit satellite can determine a candidate authentication credential based on each system reference identity corresponding to the low-orbit satellite pair to be authenticated, as well as other information it carries when identifying the first inter-satellite satellite. A sixth hash value is then determined based on the authentication credential and each system reference identity corresponding to the low-orbit satellite pair to be authenticated. If the sixth hash value matches the fifth hash value, indicating that the authentication response has not been tampered with in the inter-satellite link, the session key can be used to encrypt the authentication success indicator to obtain an encrypted authentication success indicator.

[0196] Specifically, LEO satellite L j Based on the locally stored system reference identity SRD j and SRD i , and the updated system reference identity SRD j,new Calculate mutual authentication credentials AC i-j :AC i-j =VF(SRD i ,SRD j ,FR j,new ,K j,new ). This certificate is used in the subsequent verification process to ensure that the identities of the two satellites are mutually confirmed. j Use the verification hash function VF to verify whether the received mutual authentication parameter MA i-j This agrees with the calculated: If they match, then satellite L is confirmed i The authentication response ISAR is legitimate and has not been tampered with in the intersatellite link.

[0197] If it is determined that the sixth hash value is consistent with the fifth hash value, the authentication success identifier is encrypted using the session key to obtain an encrypted authentication success identifier. In an embodiment of the present application, the other low-orbit satellite to be authenticated and any low-orbit satellite to be authenticated store the same session key. In an embodiment of the present application, the other low-orbit satellite to be authenticated and any low-orbit satellite to be authenticated can use a key generation function (KGF) to calculate the session key SK: SK=KGF(SRD i ,SRD j ,AC i-j ,t j ,t g ,t i,new ), the generated session key SK will be used for subsequent encrypted communications to ensure the confidentiality and security of information.

[0198] Specifically, LEO satellite L j The reference identity SRD stored locally can be used i ,SRD j Generate an authentication success mark SM and transmit the success mark to the satellite L i:SM=VF(SRD i ,SRD j ,AC i-j ,succ,t j,new ,t g ,t i,new ), where succ is a constant indicating successful authentication, t j,new is the current timestamp, t g is the GEO satellite timestamp, t i,new It is Satellite L i After obtaining the authentication success identifier, the session key SK can be used to authenticate the authentication success identifier SM and the current timestamp t j,new Encrypt and generate encryption authentication success mark: [SM,t j,new ] SK , the encryption authentication success mark ensures the confidentiality of data when transmitted in the intersatellite link. j The encrypted authentication success identifier and timestamp [SM,t j,new ] SK Send to L i , ensuring the integrity and timeliness of authentication information.

[0199] If any low-orbit satellite to be authenticated receives the encrypted authentication success identifier, it can use the session key to decrypt the encrypted authentication success identifier to obtain the authentication success identifier.

[0200] Specifically, when the LEO satellite L i Received from LEO satellite L j After the encrypted authentication success mark is obtained, the session key SK is first used to decrypt the encrypted authentication success mark to obtain the authentication success mark SM and the current timestamp t j,new , then calculates and verifies the consistency between the authentication success flag and the expected value. If they are consistent, the two satellites confirm mutual authentication and verify the correctness of the session key.

[0201] When the decryption and encryption authentication are successful, the LEO satellite L i Use the previously generated session key SK to encrypt the received authentication success identification message [SM,t j,new ] SK Decrypt and get the authentication success mark SM and timestamp t j,new The session key is the satellite L i Using the key generation function (KGF), based on the reference identity SRD i ,SRD j , Authentication Certificate AC i-j and timestamp to generate the session key SK: SK = KGF (SRD i ,SRD j,AC i-j ,t j ,t g ,t i,new ).

[0202] At the same time, LEO satellite L i Using the same parameters, determine the authentication success flag, the formula is as follows: VF(SRD i ,SRD j ,succ,t j,new ,t g ,t i,new ), where succ indicates a successful authentication, t j,new It is Satellite L j The current timestamp, t g is the timestamp of the GEO satellite, t i,new It is Satellite L i The current timestamp of the authentication request. This function ensures that the authentication identifier is consistent with the content in the authentication request to prevent data tampering. i Compare the authentication success flag SM obtained from decryption with the calculated authentication flag to see if they are consistent. If they are consistent, it means that the two satellites have successfully authenticated each other, and the generation process of the session key is also correct, and the authentication process has not been tampered with.

[0203] If the previous step is successful, L i Confirm with L j Mutual authentication between the two satellites has been completed and the session key SK has been correctly generated. At this point, the two satellites can securely establish an encrypted communication channel for subsequent data transmission.

[0204] The embodiments of this application provide an inter-satellite authentication mechanism for low-orbit satellite networks based on a reconfigurable physically unclonable function (RPUF). This mechanism enables secure and reliable identity verification and authentication between low-orbit satellites (LEO satellites) and between satellites and ground stations (GEO satellites). The entire authentication process is completed in six steps, involving the generation of an authentication request, identity verification, session key generation, and calculation of an authentication success indicator. This ensures the uniqueness of the satellite identity, the integrity of the authentication data, and the confidentiality and tamper resistance of communications.

[0205] Example 7:

[0206] The following describes the security authentication process of the security authentication system with a specific embodiment. In this embodiment, by introducing GEO satellites as authentication auxiliary roles, efficient and secure authentication is achieved between low-orbit satellites. The system includes three main mechanisms: initialization phase, LEO satellite registration, and LEO satellite inter-satellite authentication. Figure 3 The process of LEO satellite intersatellite certification is described in detail. Figure 3 A flowchart of an intersatellite authentication process provided in an embodiment of the present application is shown as follows: Figure 3 As shown, the intersatellite authentication process involves LEO satellite L i 、LEO satellite L j and GEO satellite G. The certification process mainly includes the following steps:

[0207] LEO satellite L i Generates masked challenge and response based on stored state, challenge, assistance data and system reference, and sends intersatellite authentication request message SAR j To L j ,The intersatellite authentication request message contains various types of ,information required for authentication, such as challenge response, identity, verification value and ,timestamp.

[0208] LEO Weiliang L j SAR received j After that, verify the timestamp and identity information, calculate and verify the correctness of the challenge response, and generate the intersatellite authentication request message SAR i SAR j and SAR i Sent to GEO satellite G.

[0209] GEO Satellite G Verification SAR i and SAR j The timestamp and identity information in L i and L j The legitimacy of the system generates a new system reference identity and returns an authentication response message AR G , and to L i and L j Send this AR G .

[0210] LEO satellite L i Verify AR G The authentication information in the and generate mutual authentication parameters MA (i-j) , and then returns the authentication response ISAR to ensure mutual authentication between the two satellites.

[0211] LEO satellite L j After receiving ISAR, verify the authentication information, calculate the session key and generate the authentication success mark SM, then encrypt the message with the session key and send it back to L i , complete the authentication process.

[0212] LEO satellite L i Decrypt and verify the authentication mark SM, confirm L j The legitimacy of the satellite and the correctness of the session key are verified to complete the inter-satellite authentication process and ensure communication security.

[0213] The embodiments of the present application combine RPUF, physical unclonable function (P), fuzzy extractor, verification hash function (VF) and session key generation function (KGF), etc., to ensure the high security, efficiency and reliability of satellite authentication and communication encryption.

[0214] In an embodiment of the present application, RPUF is used to perform satellite identity authentication. RPUF uses tiny physical differences in satellite hardware to generate a unique challenge-response pair (CRP), ensuring that the identity of each satellite during the authentication process is unique and cannot be forged. Specifically, traditional authentication methods rely on key management, while RPUF generates authentication data through physical hardware characteristics, and attackers cannot forge satellite identities by imitating hardware. This solution effectively prevents forgery and replay attacks by generating a unique identity response based on hardware characteristics, providing higher security. Moreover, unlike traditional key-based authentication mechanisms, the challenge response generated by RPUF is unclonable. Even if an attacker captures part of the response, he cannot reproduce the complete authentication response, which greatly enhances the system's anti-attack capabilities.

[0215] In an embodiment of the present application, identity authentication is tightly integrated with the session key generation process. Each satellite generates an authentication response and calculates the session key using an output transformation function (OTF) using an input transformation function (ITF), a physically unclonable function (P), and the key and auxiliary data generated by the fuzzy extractor. Specifically, by combining the unique response generated by the RPUF with the randomness of the fuzzy extractor, the risks of replay attacks and eavesdropping present in traditional key generation mechanisms are effectively avoided when generating session keys. Furthermore, during the authentication process, key generation is combined with identity authentication, reducing the complexity of separate key storage and management, thereby improving the overall security and operational efficiency of the system.

[0216] In the embodiments of the present application, a multi-stage authentication mechanism is employed, which includes multiple steps, including satellite registration, inter-satellite authentication request, inter-satellite authentication response, session key generation, and authentication success indicator generation. Each stage utilizes different encryption and verification technologies to ensure the security of the authentication data. This multi-stage authentication mechanism enables verification of satellite identity and communication integrity at different levels. Each stage of authentication has clear verification steps, ensuring the reliability and traceability of the authentication process. Furthermore, the staged authentication design effectively reduces the risk of man-in-the-middle attacks, as each step independently verifies identity and data, ensuring that data is verified at every stage from source to destination.

[0217] In the embodiment of the present application, an authentication success marker (SM) and session key encryption mechanism are used during the inter-satellite authentication process. A session key is generated using a session key generation function (KGF), and the authentication marker and timestamp are encrypted to ensure the confidentiality and integrity of the authentication information during transmission. Specifically, by encrypting the authentication information using the session key, the authentication information is effectively prevented from being tampered with or leaked in the inter-satellite link, ensuring the confidentiality and integrity of the communication. Furthermore, the encrypted authentication information effectively protects the security of the authentication data and key information, preventing the information from being leaked even when transmitted in an untrusted network environment.

[0218] During the authentication process, based on satellite state changes and network dynamics, embodiments of the present application provide a dynamic authentication mechanism. Each satellite generates new challenges and responses based on actual conditions, ensuring that the authentication process remains secure and reliable even with frequent state updates in the satellite network. The satellite's state and challenges are dynamically updated based on the current environment and network conditions, ensuring that the authentication mechanism can continue to operate effectively in diverse network environments. This dynamic nature enhances the system's flexibility and scalability. Furthermore, because each authentication stage involves randomized challenges and responses, attackers cannot impersonate legitimate satellites by replaying captured authentication data, improving the system's resistance to replay attacks.

[0219] This embodiment of the present application integrates satellite identity authentication with communication encryption, achieving a more efficient authentication process. Satellites generate session keys through a single authentication process and verify the correctness of mutual authentication using an authentication success indicator. This integration of authentication and encryption reduces the need for multiple key exchanges and authentications, making inter-satellite authentication more efficient. By verifying the correctness of the authentication success indicator and session key, the reliability of subsequent communications is ensured, preventing tampering with authentication data and misuse of session keys.

[0220] Example 8:

[0221] Based on the same inventive concept, the present application provides a security authentication method for low-orbit satellites. Figure 4 A flowchart of a security authentication process provided in an embodiment of the present application is shown as follows: Figure 4 As shown, the process includes the following steps:

[0222] S401: If a first inter-satellite authentication request is received from another low-orbit satellite to be authenticated, a second inter-satellite authentication request is determined based on the current operation information and historical operation information of the satellite.

[0223] S402: Send the first inter-satellite authentication request and the second inter-satellite authentication request to the high-orbit satellite; wherein the inter-satellite authentication request includes at least the system reference identity of the low-orbit satellite to be authenticated, and the inter-satellite authentication request includes the first inter-satellite authentication request and the second inter-satellite authentication request.

[0224] S403: If the authentication certificate is received, the authentication certificate is sent to the other low-orbit satellites to be authenticated and a communication link is established.

[0225] Since the principle of solving the problem by the above electronic device is similar to the principle of any low-orbit satellite to be authenticated in the security authentication system, the implementation of the above security authentication method can refer to the embodiment of the method, and the repeated parts will not be repeated.

[0226] Based on the same inventive concept, the present application provides a security authentication method applied to high-orbit satellites. Figure 5 A flowchart of a security authentication process provided in an embodiment of the present application is shown as follows: Figure 5 As shown, the process includes the following steps:

[0227] S501: If an inter-satellite authentication request for a low-orbit satellite pair to be authenticated is received, each matching standard information is searched in pre-stored registration information according to the system reference identity of each low-orbit satellite to be authenticated carried in the inter-satellite authentication request.

[0228] S502: Authenticate other information carried in the corresponding inter-satellite authentication request based on each standard information.

[0229] S503: When the authentication of the low-orbit satellite pair to be authenticated is passed, an authentication credential is sent to the low-orbit satellite to be authenticated that sent the inter-satellite authentication request.

[0230] Since the principle of solving the problem by the above electronic device is similar to the principle of high-orbit satellites in the security authentication system, the implementation of the above security authentication method can refer to the embodiment of the method, and the repeated parts will not be repeated.

[0231] Example 9:

[0232] Based on the same inventive concept, the present invention provides a device for cross-border data transmission. Figure 6 For a schematic diagram of a security authentication device provided in this application embodiment, please refer to Figure 6 , the device comprises:

[0233] The determination module 601 is configured to determine a second inter-satellite authentication request based on its own current operation information and historical operation information upon receiving a first inter-satellite authentication request sent by another low-orbit satellite to be authenticated;

[0234] The sending module 602 is used to send the first inter-satellite authentication request and the second inter-satellite authentication request to the high-orbit satellite; wherein the inter-satellite authentication request includes at least the system reference identity of the low-orbit satellite to be authenticated, and the inter-satellite authentication request includes the first inter-satellite authentication request and the second inter-satellite authentication request; if the authentication credential is received, the authentication credential is sent to the other low-orbit satellite to be authenticated, and a communication link is established.

[0235] Based on the same inventive concept, the present invention provides a device for cross-border data transmission. Figure 7 For a schematic diagram of a security authentication device provided in this application embodiment, please refer to Figure 7 , the device comprises:

[0236] A search module 701 is configured to, upon receiving an inter-satellite authentication request for a low-orbit satellite pair to be authenticated, search for each matching standard information in pre-stored registration information based on the system reference identity of each low-orbit satellite to be authenticated carried in the inter-satellite authentication request;

[0237] An authentication module 702 is configured to authenticate other information carried in a corresponding intersatellite authentication request based on each standard information;

[0238] The sending module 703 is configured to send an authentication credential to the low-orbit satellite to be authenticated that sent the inter-satellite authentication request if the authentication of the low-orbit satellite to be authenticated is successful.

[0239] Example 10:

[0240] Based on the same inventive concept, an embodiment of the present application provides an electronic device, Figure 8 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application is shown in FIG. Figure 8 As shown, it includes: a processor 801, a communication interface 802, a memory 803 and a communication bus 804, wherein the processor 801, the communication interface 802, and the memory 803 communicate with each other through the communication bus 804; a computer program is stored in the memory 803, and when the program is executed by the processor 801, the processor 801 executes the security authentication method described in the above embodiments.

[0241] Since the principle of solving the problem by the above electronic device is similar to that of the security authentication method, the implementation of the above electronic device can refer to the embodiment of the method, and the repeated parts will not be repeated.

[0242] The communication bus mentioned in the above-mentioned electronic device can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The communication bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one thick line is used in the figure, but it does not mean that there is only one bus or one type of bus. The communication interface 802 is used for communication between the above-mentioned electronic device and other devices. The memory can include a random access memory (RAM) and can also include a non-volatile memory (NVM), such as at least one disk storage. Optionally, the memory can also be at least one storage device located away from the aforementioned processor.

[0243] The above-mentioned processor can be a general-purpose processor, including a central processing unit, a network processor (NP), etc.; it can also be a digital signal processing processor (DSP), an application-specific integrated circuit, a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, etc.

[0244] Example 11:

[0245] Based on the same inventive concept, embodiments of the present application provide a computer-readable storage medium storing a computer program executable by a processor. When the program is executed on the processor, the processor executes any of the security authentication methods discussed above. Because the principles for solving the problems solved by the computer-readable storage medium are similar to those of the security authentication method, the implementation of the computer-readable storage medium can be referred to as the implementation of the method, and any repetitions will not be repeated here.

[0246] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0247] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0248] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0249] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps for the function specified in one or more boxes.

[0250] Obviously, those skilled in the art may make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.

Claims

1. A security authentication system, characterized in that: The system includes: a high-orbit satellite and at least two low-orbit satellites to be certified; Any low-orbit satellite to be authenticated is configured to, upon receiving a first inter-satellite authentication request sent by another low-orbit satellite to be authenticated, determine a second inter-satellite authentication request based on its own current operation information and historical operation information; send the first inter-satellite authentication request and the second inter-satellite authentication request to the high-orbit satellite; wherein the inter-satellite authentication request includes at least a system reference identity corresponding to the low-orbit satellite to be authenticated, and the inter-satellite authentication request includes the first inter-satellite authentication request and the second inter-satellite authentication request; and if an authentication credential is received, send the authentication credential to the other low-orbit satellite to be authenticated and establish a communication link; The high-orbit satellite is used to, upon receiving an inter-satellite authentication request from a pair of low-orbit satellites to be authenticated, search for each matching standard information in the pre-stored registration information according to the system reference identity of each low-orbit satellite to be authenticated carried in the inter-satellite authentication request; and authenticate other information carried in the corresponding inter-satellite authentication request based on each standard information; and send an authentication credential to the low-orbit satellite to be authenticated that sent the inter-satellite authentication request if the authentication of the pair of low-orbit satellites to be authenticated is passed.

2. The system according to claim 1, wherein: Any low-orbit satellite to be authenticated is specifically configured to determine its own current authentication information based on the current operation information and a preset algorithm, where the current authentication information includes a current state key and a current final authentication response; Encrypting the current final authentication response and the current state key based on the historical operation information to obtain an encrypted final authentication response and an encrypted state key; determining a first hash value based on the historical operation information, the current state key, a pre-stored system reference identity, the current final authentication response, and the first inter-satellite authentication request; determining the second intersatellite authentication request based on the first hash value, the system reference identity, the encrypted final authentication response, and the encryption state key; The high-orbit satellite is specifically configured to search for matching standard historical operation information in pre-stored registration information according to each of the system reference identities; decrypt the encrypted final authentication response and the encrypted state key based on the standard historical operation information to obtain the final authentication response to be verified and the state key to be verified; determining a second hash value based on the standard historical operation information, the state key to be verified, the system reference identity, the final authentication response to be verified, and the received first inter-satellite authentication request; If the second hash value is consistent with the first hash value, it is determined that the authentication of the low-orbit satellite pair to be authenticated is successful.

3. The system according to claim 2, characterized in that Any low-orbit satellite to be authenticated is specifically used to determine a historical state key based on a historical mask challenge, historical auxiliary data, and a reconstruction function; and use the historical state key to encrypt the current final authentication response to obtain an encrypted final authentication response.

4. The system according to claim 3, characterized in that The high-orbit satellite is specifically configured to search for a matching standard state key in pre-stored registration information according to the system reference identity, wherein the standard state key is determined differently from the historical state key; The encrypted final authentication response is decrypted using the standard state key to obtain a final authentication response to be verified.

5. The system according to any one of claims 1 to 4, characterized in that: The system further includes a ground station; Any low-orbit satellite to be authenticated is further configured to, during satellite registration, determine a masked challenge based on its own initial state, a generated random challenge, and an input conversion function; determine a response based on a physical unclonable function (PUF) and the masked challenge; process the response based on a fuzzy extractor to extract a first state key and first auxiliary data; determine a first final authentication response based on the first state key, the first auxiliary data, the initial state, and the output conversion function; and send its own identity, the first state key, and the first final authentication response to the ground station; The ground station is configured to search a pre-stored registration list for the identity identifier; if not, determine a third hash value based on the identity identifier and the first final authentication response; determine the third hash value as the system reference identity of any one of the low-orbit satellites to be authenticated; and send the third hash value to the any one of the low-orbit satellites to be authenticated; store the system reference identity, the first state key, and the first final authentication response corresponding to the identity identifier, and send them to the high-orbit satellite; The high-orbit satellite is further used to store the system reference identity, the first state key and the first final authentication response as standard information.

6. The system according to claim 1, wherein: The any one of the low-orbit satellites to be authenticated is specifically used to obtain a first current time, and send the first current time, the first inter-satellite authentication request, and the second inter-satellite authentication request to the high-orbit satellite; The high-orbit satellite is also used to determine the time interval between the first current time and the current time; if the time interval meets the preset interval threshold requirement, then continue to execute the subsequent steps of searching for each matching standard information in the pre-saved registration information based on the system reference identity of each low-orbit satellite to be authenticated carried in the inter-satellite authentication request.

7. The system according to claim 1, wherein: The high-orbit satellite is further configured to determine, for each low-orbit satellite to be authenticated in the low-orbit satellite pair to be authenticated, a fourth hash value based on the system reference identity of the low-orbit satellite to be authenticated and other information carried in the corresponding inter-satellite authentication request; Using the fourth hash value, the system reference identity of the low-orbit satellite to be authenticated stored in the system is updated; and the updated system reference identity of each low-orbit satellite to be authenticated of the low-orbit satellite pair to be authenticated is carried in the authentication credential and sent to the low-orbit satellite to be authenticated that sent the inter-satellite authentication request; Any of the low-orbit satellites to be authenticated is further configured to update its stored system reference identity using the received system reference identity corresponding to itself, and to send the updated system reference identity corresponding to the other low-orbit satellites to be authenticated to the other low-orbit satellites to be authenticated.

8. The system according to claim 1, wherein: The high-orbit satellite is specifically configured to generate an authentication credential based on each system reference identity corresponding to the low-orbit satellite pair to be authenticated and other information carried in the first inter-satellite satellite authentication request; The any one of the low-orbit satellites to be authenticated is specifically configured to determine a fifth hash value based on the authentication credential and each system reference identity corresponding to the low-orbit satellite to be authenticated, and send the fifth hash value to the other low-orbit satellites to be authenticated; The other low-orbit satellite to be authenticated is configured to, upon receiving the fifth hash value, determine a candidate authentication credential based on each system reference identity corresponding to the low-orbit satellite to be authenticated and other information carried by the satellite when determining the first inter-satellite satellite; Determining a sixth hash value based on the authentication credential and each system reference identity corresponding to the low-orbit satellite pair to be authenticated; If the sixth Hash value is consistent with the fifth Hash value, encrypting the authentication success identifier using the session key to obtain an encrypted authentication success identifier; The any one of the low-orbit satellites to be authenticated is specifically configured to, upon receiving an encrypted authentication success identifier, use the session key to decrypt the encrypted authentication success identifier to obtain the authentication success identifier.

9. A security authentication method, characterized in that: Applied to a low-orbit satellite, the method includes: If a first inter-satellite authentication request is received from another low-orbit satellite to be authenticated, the second inter-satellite authentication request is determined based on the current operation information and historical operation information of the satellite; Sending the first inter-satellite authentication request and the second inter-satellite authentication request to the high-orbit satellite; wherein the inter-satellite authentication request includes at least a system reference identity corresponding to the low-orbit satellite to be authenticated, and the inter-satellite authentication request includes the first inter-satellite authentication request and the second inter-satellite authentication request; If the authentication credential is received, the authentication credential is sent to the other low-orbit satellite to be authenticated, and a communication link is established.

10. A security authentication method, characterized in that: Applied to a high-orbit satellite, the method includes: If an inter-satellite authentication request is received for a low-orbit satellite pair to be authenticated, searching for each matching standard information in the pre-stored registration information according to the system reference identity of each low-orbit satellite to be authenticated carried in the inter-satellite authentication request; Authenticating other information carried in the corresponding intersatellite authentication request based on each standard information; In the case that the authentication of the low-orbit satellite to be authenticated is passed, an authentication credential is sent to the low-orbit satellite to be authenticated that sent the inter-satellite authentication request.