A method for precise binding and distribution of keys based on demand-driven strategy

The demand-driven strategy-based key binding and distribution method solves the problems of low key management efficiency, insufficient security, and lack of flexibility in satellite communication system ground station access networks. It achieves efficient and secure key distribution and management, and is suitable for satellite communication system ground station access network environments with multiple beams and multiple boards.

CN120825336BActive Publication Date: 2025-12-16THE 54TH RESEARCH INSTITUTE OF CHINA ELECTRONICS TECHNOLOGY GROUP CORPORATION
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511255067.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-04
Publication Date
2025-12-16
Estimated Expiration
2045-09-04

AI Technical Summary

Technical Problem

In the ground station access network of satellite communication system, the use of 3U boards based on the VPX standard makes it impossible to independently integrate a security module for each channel board, resulting in low key management efficiency, difficulty in ensuring security, and insufficient flexibility. Traditional key management methods are unable to meet diverse business needs.

Method used

A demand-driven key binding and allocation method is adopted. Through steps such as baseband board registration and authentication, key demand request, key generation and distribution, and key storage and update, a key-to-baseband board precise binding and allocation model is constructed to achieve efficient and secure key management.

Benefits of technology

It improves key management efficiency, enhances system security, meets diverse business needs, adapts to system configuration and business changes, and is easy to expand and maintain.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120825336B_ABST
    Figure CN120825336B_ABST
Patent Text Reader

Abstract

The application is a kind of key accurate binding distribution method based on demand-driven strategy, belonging to the security communication technical field of satellite communication system ground station access network. In view of the problems that the current satellite communication system ground access network generally adopts standard VPX board card and cannot independently integrate security module for each channel board card, and the group road cipher machine is inconvenient for key interaction with numerous baseband board cards, the application builds a key to baseband board card accurate binding and distribution model, adopts demand-driven strategy, and realizes efficient and safe distribution of keys. The method includes baseband board card registration and authentication, key demand request, key generation and distribution, key storage and update and other steps, effectively solves the problems of complex key management and inconvenient interaction in the prior art, improves the security and reliability of the system, and is suitable for multi-beam, multi-board card satellite communication system ground station access network environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of secure communication technology for ground station access networks of satellite communication systems, and specifically relates to a method for precise key binding and distribution based on a demand-driven strategy. Background Technology

[0002] With the continuous development of satellite communication technology, the scale and complexity of satellite communication system ground station access networks are increasing. In the original satellite communication system ground station access networks, each channel card of each channel device integrated a separate security module, which ensured communication security to a certain extent. However, in the new system, due to the use of 3U cards based on the VPX standard, the limitations of card size and design architecture make it impossible to independently integrate a security module for each channel card.

[0003] Meanwhile, the new system supports multiple beams, with each channel equipment chassis supporting one beam, and each chassis deploying various types of boards, such as baseband boards, main control boards, switching boards, and intermediate frequency boards. In this context, the system decided to use a group-channel cipher machine for key management. However, due to the large number of baseband boards, and the fact that the group-channel cipher machine primarily interacts with them for key data, key exchange becomes extremely inconvenient. Traditional key management methods are insufficient to meet the needs of the new system, exhibiting the following problems:

[0004] 1. Inefficient key management: A large number of baseband cards need to frequently interact with the group cryptographic machine for key exchange, resulting in low efficiency in key distribution and management, which affects the overall system efficiency.

[0005] 2. Security is difficult to guarantee: In complex multi-board environments, traditional key distribution methods may have security risks, such as keys being easily stolen or tampered with during transmission, and lacking effective protection mechanisms.

[0006] 3. Insufficient flexibility: Different baseband boards may have different service requirements. The traditional unified key distribution method cannot meet the diverse service needs and cannot flexibly adjust the use of keys according to the actual situation.

[0007] Therefore, there is an urgent need for a new key management and distribution method that can achieve efficient, secure, and accurate key binding and distribution under the new system architecture to meet the secure communication requirements of satellite communication system ground station access networks. Summary of the Invention

[0008] In view of this, the present invention provides a key precise binding and allocation method based on a demand-driven strategy. The present invention employs a demand-driven strategy to construct a precise key-to-baseband board binding and allocation model, achieving efficient and secure key allocation.

[0009] The technical solution adopted in this invention is as follows:

[0010] A key binding and distribution method based on a demand-driven strategy is characterized by its application to a ground station access network of a satellite communication system. The ground station access network includes a channel equipment chassis, which houses baseband cards, a main control board, a switching board, and an intermediate frequency board. The ground station access network employs a group-channel cryptographic machine for key management. The method includes the following steps:

[0011] Step S1: Each baseband board sends a registration request to the main control board. The registration request carries the unique identification information of the baseband board. After receiving the registration request, the main control board verifies the unique identification information of the baseband board. After successful verification, the baseband board is added to the management list, and an initial status identifier is assigned to each baseband board.

[0012] Step S2: The baseband board sends a key request to the main control board according to its own business needs. The key request includes the unique identification information of the baseband board, the type of key required, and the business scenario information.

[0013] Step S3: After receiving the key request, the main control board sends the corresponding key generation instruction to the group cryptographic machine according to the type information of the required key. The group cryptographic machine generates the corresponding key according to the key generation instruction and sends it to the main control board. After receiving the key, the main control board binds the key to the corresponding baseband board according to the preset mapping relationship, and distributes the key to the corresponding baseband board through the exchange board.

[0014] Step S4: After receiving the key, the baseband board stores the key in a local secure storage area.

[0015] Furthermore, the unique identification information is the hardware serial number, MAC address, or pre-set device number of the baseband board.

[0016] Furthermore, the service scenario information is used to indicate the type of service that the baseband board is currently participating in, including data transmission service, control command service, and test service.

[0017] Furthermore, the preset mapping relationship is established based on the correspondence between the unique identification information of the baseband board and the key, and is stored in the memory of the main control board.

[0018] Furthermore, in step S3, before distributing the key to the baseband board, the main control board encrypts the key. The key used for encryption is a session key that is pre-shared between the baseband board and the main control board.

[0019] Furthermore, step S4 also includes: the main control board periodically or according to preset conditions, triggering a key update process to update the key for the baseband board; wherein, the time interval for periodically triggering the key update process is set according to the system security policy, and the preset conditions are that the number of times the key is used reaches a threshold, the system detects a security threat, or receives an external forced update instruction.

[0020] Furthermore, it also includes a key revocation step: when the baseband board malfunctions, is removed, or is no longer needed, the main control board receives a key revocation request from the baseband board or an external management system, stops distributing new keys to the baseband board, and notifies the group cryptographic machine to invalidate the key associated with the baseband board.

[0021] The beneficial results of this invention are as follows:

[0022] 1. Improved Key Management Efficiency: By adopting a demand-driven strategy, keys are only requested and allocated when the baseband board actually needs them, avoiding unnecessary key interactions and significantly improving key management efficiency. Simultaneously, the main control board acts as an intermediary coordinator, uniformly managing the key requests and allocations of the baseband boards, reducing the burden on the group cryptographic machine and improving the overall system efficiency.

[0023] 2. Enhanced Security: Multiple security measures are implemented during key generation, transmission, and storage. For example, keys are encrypted during transmission to prevent theft or tampering; secure storage areas are used to store keys to prevent unauthorized access; and keys are updated periodically or according to preset conditions to reduce security risks caused by prolonged use of the same key. Furthermore, a registration and authentication mechanism ensures that only legitimate baseband cards can participate in the key distribution process, further enhancing system security.

[0024] 3. Meeting Diverse Business Needs: Considering that different baseband boards may participate in different business scenarios, this invention introduces business scenario information. The main control board can perform differentiated key processing based on the business scenario information, providing appropriate keys for different types of services and meeting diverse business needs.

[0025] 4. High flexibility: This method can adapt to different system configurations and business changes. Whether the number of baseband cards increases or decreases, or business requirements change, flexible key management and allocation can be achieved by adjusting relevant parameters and strategies.

[0026] 5. Easy to expand and maintain: This method can be implemented using a modular design concept. When the system needs to expand or upgrade its functions, only the corresponding modules need to be modified and improved, which reduces the maintenance cost and difficulty of the system. Attached Figure Description

[0027] Figure 1 This is a system framework diagram of the method of the present invention;

[0028] Figure 2 This is a flowchart illustrating the method of the present invention. Detailed Implementation

[0029] The present invention will be further described in detail below with reference to specific embodiments.

[0030] A demand-driven strategy-based method for precise key binding and distribution is proposed, which is applied to the ground station access network of a satellite communication system, such as... Figure 1 As shown, the ground station access network includes a channel equipment chassis, which houses baseband cards, main control cards, switching cards, and intermediate frequency cards. The ground station access network uses a group cryptographic machine for key management. The method includes the following steps:

[0031] Step S1: Each baseband board sends a registration request to the main control board. The registration request carries the unique identification information of the baseband board. After receiving the registration request, the main control board verifies the unique identification information of the baseband board. If the verification is successful, the baseband board is added to the management list, and an initial status identifier is assigned to each baseband board. The unique identification information is the hardware serial number, MAC address, or pre-set device number of the baseband board.

[0032] Step S2: The baseband board sends a key request to the main control board according to its own service needs. The key request includes the unique identification information of the baseband board, the type information of the required key, and the service scenario information. The service scenario information is used to indicate the type of service that the baseband board is currently participating in. The service types include data transmission service, control command service, and test service.

[0033] Step S3: After receiving the key request, the main control board sends a corresponding key generation instruction to the group cryptographic machine according to the type information of the required key. The group cryptographic machine generates the corresponding key according to the key generation instruction and sends it to the main control board. After receiving the key, the main control board binds the key to the corresponding baseband board according to the preset mapping relationship, and distributes the key to the corresponding baseband board through the exchange board. The preset mapping relationship is established based on the correspondence between the unique identification information of the baseband board and the key, and is stored in the memory of the main control board.

[0034] Step S4: After receiving the key, the baseband board stores the key in a local secure storage area.

[0035] In step S3, before distributing the key to the baseband board, the main control board encrypts the key. The key used for encryption is a session key that is pre-shared between the baseband board and the main control board.

[0036] Step S4 also includes: the main control board periodically or according to preset conditions, triggering a key update process to update the key for the baseband board; wherein, the time interval for periodically triggering the key update process is set according to the system security policy, and the preset conditions are that the number of times the key is used reaches a threshold, the system detects a security threat, or receives an external forced update command.

[0037] The method may also include a key revocation step:

[0038] When a baseband board malfunctions, is removed, or is no longer needed, the main control board receives a key revocation request from the baseband board or an external management system, stops distributing new keys to the baseband board, and notifies the group cryptographic machine to invalidate the key associated with the baseband board.

[0039] like Figure 2 As shown, the principle of this method is as follows:

[0040] 1. Baseband Card Registration and Authentication: Each baseband card sends a registration request to the main control board, carrying its unique identifier. Upon receiving the request, the main control board verifies the unique identifier. If verification is successful, the baseband card is added to the management list and assigned an initial status identifier. This step ensures that only legitimate baseband cards can participate in the subsequent key distribution process. The specific method is as follows:

[0041] Registration Request Sending: After system startup or insertion of the baseband board into the channel equipment chassis, each baseband board actively sends a registration request to the main control board. To uniquely identify each baseband board, the registration request carries its unique identifier. This unique identifier can be the baseband board's hardware serial number, MAC address, or a pre-defined device number, etc. This identifier is unique and can accurately distinguish between different baseband boards.

[0042] Verification and Management List Update: Upon receiving a registration request, the main control board verifies the unique identifier information. This verification process can be completed by querying a pre-stored database of valid identifier information or by interacting with other relevant systems. If verification is successful, the main control board adds the baseband board to the management list, meaning that the baseband board has been recognized by the system and can participate in subsequent operations such as key allocation. Simultaneously, the main control board assigns an initial status identifier to each successfully registered baseband board to record its current status, such as normal or faulty.

[0043] 2. Key Request Request: The baseband board sends a key request to the main control board based on its own service requirements. The request includes the baseband board's unique identifier, the required key type, and the service scenario information. In this way, the baseband board can explicitly express its key requirements, enabling the main control board to accurately provide the appropriate key. The specific method is as follows:

[0044] Requirement Information Encapsulation: The baseband board sends a key request to the main control board based on its own business needs. In addition to the baseband board's unique identifier, the request specifies the type of key required. Key types can be categorized based on factors such as encryption algorithms and key lengths to meet the encryption requirements of different business scenarios. Furthermore, it includes business scenario information, indicating the type of business the baseband board is currently participating in, such as data transmission, control command, or testing. By providing this business scenario information, the main control board can better understand the baseband board's needs, thereby enabling more appropriate key allocation and management.

[0045] When to send a key request: The baseband board can send a key request in the following situations: First, during the initialization phase, when the baseband board has completed registration and is ready to start services; second, during the service process, when the existing key expires, becomes invalid, or cannot meet the current service requirements; and third, under other specific conditions, such as receiving an external instruction to change the key.

[0046] 3. Key Generation and Distribution: After receiving a key request, the main control board sends a corresponding key generation command to the group cipher machine based on the key type information. The group cipher machine generates the corresponding key and sends it to the main control board. The main control board binds the key to the corresponding baseband board according to a preset mapping relationship and distributes the key to the corresponding baseband board through a swapping board. This step achieves precise key allocation, ensuring that each baseband board receives the key it needs. The specific method is as follows:

[0047] Key generation command transmission: After receiving the key request from the baseband board, the main control board first parses the key type information. Based on the parsing result, the main control board sends the corresponding key generation command to the cipher machine. The cipher machine is a device specifically designed for generating and managing keys, possessing powerful computing capabilities and a secure storage mechanism. Upon receiving the command from the main control board, the cipher machine generates the corresponding key according to the specified algorithm and parameters.

[0048] Key Binding and Distribution: After generating the key, the group cipher machine sends it back to the main control board. Upon receiving the key, the main control board binds it to the corresponding baseband board according to a preset mapping relationship. This mapping relationship is established based on the correspondence between the unique identifier information of the baseband board and the key, and is usually stored in the main control board's memory. After binding, the main control board distributes the key to the corresponding baseband board through a switching board. The switching board acts as an intermediary bridge, responsible for transmitting data and control signals between the main control board and the baseband board, ensuring that the key accurately reaches the target baseband board.

[0049] Encrypted Key Transmission: To ensure key security during transmission, the main control board can encrypt the key before distributing it to the baseband board. The encryption key is a pre-shared session key between the baseband board and the main control board. This way, even if the key is intercepted during transmission, attackers cannot directly obtain the plaintext key, thus improving the security of key transmission.

[0050] 4. Key Storage and Update: After receiving the key, the baseband board stores it in a local secure storage area. The main control board periodically or according to preset conditions triggers a key update process, repeating the above steps to update the key for the baseband board. This ensures the timeliness and security of the key, preventing security risks caused by the long-term use of the same key. The specific method is as follows:

[0051] Key storage: After receiving the key, the baseband board stores it in a local secure storage area. This secure storage area can be a dedicated encryption chip, non-volatile memory, etc., with certain security protection measures to prevent the key from being illegally read or tampered with.

[0052] Key update trigger conditions: The main control board triggers the key update process periodically or according to preset conditions. The time interval for periodic triggering can be set according to the system's security policy, such as automatically updating the key every certain period of time (e.g., daily, weekly). Preset conditions also include the key usage reaching a threshold, the system detecting a security threat (e.g., abnormal traffic detected by an intrusion detection system), or receiving an external forced update command. When these conditions are met, the main control board will repeat the above steps to update the key for the baseband board. This ensures the timeliness and security of the key and reduces the security risks caused by the long-term use of the same key.

[0053] 5. Key revocation (optional step), the specific method is as follows:

[0054] Revocation Request Reception: When the baseband board malfunctions, is removed, or is no longer needed, the main control board receives a key revocation request from the baseband board or an external management system.

[0055] Stopping Key Distribution and Deactivation: Upon receiving a revocation request, the main control board stops distributing new keys to the baseband board and notifies the group cryptographic machine to deactivate the key associated with that baseband board. This ensures that the revoked baseband board no longer uses the old key for communication, avoiding potential security risks.

[0056] The above method can be implemented through the following modules:

[0057] 1. Registration and Authentication Module: This module receives registration requests from each baseband board, verifies the unique identification information of the baseband board, and adds the baseband board to the management list after successful verification. It also assigns an initial status identifier to each baseband board. This module can also obtain the unique identification information of the baseband board during registration, such as the hardware serial number, MAC address, or a pre-defined device number.

[0058] 2. Request Receiving Module: This module receives key request requests from baseband boards and parses the unique identifier of the baseband board, the type of key required, and the service scenario information. Parsing the service scenario information provides a basis for subsequent key processing.

[0059] 3. Key Generation Module: Based on the key type information received by the demand receiving module, this module sends the corresponding key generation command to the cipher machine. This module coordinates the communication between the main control board and the cipher machine, ensuring that the key is generated according to the correct type and parameters.

[0060] 4. Key Distribution Module: This module receives keys generated by the group cryptographic machine, binds the keys to corresponding baseband cards according to a preset mapping relationship, and distributes the keys to the corresponding baseband cards via a switching board. Before distribution, the keys can also be encrypted using a pre-shared session key between the baseband card and the main control card to ensure the security of key transmission.

[0061] 5. Storage Update Module: This module triggers the key update process, enabling the storage and updating of baseband board keys. It can trigger key updates periodically or under preset conditions to ensure the timeliness and security of the keys.

[0062] 6. Key Revocation Module (Optional): Used to receive key revocation requests from baseband boards or external management systems, stop distributing new keys to the corresponding baseband boards, and notify the group cryptographic machine to invalidate the keys associated with the baseband board.

[0063] Here is a more specific example:

[0064] Suppose that a channel equipment chassis in the ground station access network of a satellite communication system contains 5 baseband cards (baseband cards A, B, C, D, and E), 1 main control board, 1 switching board, and 1 intermediate frequency board. The system uses a group cryptographic machine for key management. The specific steps of the precise key binding and distribution method for this system are as follows:

[0065] 1. Baseband board registration and certification

[0066] After the system starts up, baseband boards A through E send registration requests to the main control board, each carrying its own hardware serial number as a unique identifier.

[0067] After receiving the registration request, the main control board verifies the hardware serial number of each baseband board in turn. Once the verification is successful, the five baseband boards are added to the management list and assigned initial status identifiers (all in normal state).

[0068] 2. Key Request

[0069] Suppose baseband board A is performing a data transmission service and sends a key request to the main control board. The request includes the hardware serial number of baseband board A, the type of key required (AES - 256-bit symmetric encryption key), and the service scenario information ("data transmission").

[0070] Meanwhile, baseband board B is performing control command services, and it also sends a key request to the main control board. The request includes the hardware serial number of baseband board B, the type of the required key (RSA - 2048-bit asymmetric encryption key), and the service scenario information ("control command").

[0071] 3. Key generation and distribution

[0072] After receiving key request requests from baseband boards A and B, the main control board sends corresponding key generation instructions to the group cryptographic machine. For the request from baseband board A, it sends an instruction to generate an AES - 256-bit symmetric encryption key; for the request from baseband board B, it sends an instruction to generate an RSA - 2048-bit asymmetric encryption key.

[0073] The group cipher machine generates the corresponding key according to the instructions and sends the generated key to the main control board.

[0074] After receiving the keys, the main control board binds the AES - 256-bit symmetric encryption key to baseband board A and the RSA - 2048-bit asymmetric encryption key to baseband board B according to a preset mapping relationship (based on the correspondence between hardware serial numbers and keys). Then, the exchange board distributes these two keys to baseband boards A and B respectively. Before distribution, the main control board encrypts the keys using a pre-shared session key between baseband boards A and B and the main control board.

[0075] 4. Key storage and update

[0076] After receiving the key, baseband boards A and B store the key in their local secure storage areas (such as in an encryption chip).

[0077] Assume the main control board is set to update at 2:00 AM daily. At 2:00 AM the following day, the main control board triggers a key update process. At this time, baseband boards A and B again send key request requests to the main control board (because they are still providing services). The main control board repeats the above steps to generate and distribute new keys for them.

[0078] 5. Key Revocation (Optional)

[0079] If baseband board C malfunctions, the main control board receives a key revocation request from the external management system. The main control board stops distributing new keys to baseband board C and notifies the group cryptographic machine to invalidate the key associated with baseband board C. Thus, even if someone attempts to communicate using baseband board C, they cannot complete encryption and decryption operations without a valid key, thereby ensuring system security.

[0080] As can be seen from the above specific implementation methods, the present invention can effectively solve the problem of key management and distribution in the new system, realize accurate binding and distribution of keys, and improve the security and operating efficiency of the system.

[0081] To address the problems of current satellite communication system ground access networks commonly using standard VPX boards, which cannot independently integrate a security module for each channel board, and the inconvenience of key interaction between the group cryptographic machine and numerous baseband boards, this invention constructs a precise key-to-baseband board binding and allocation model, employing a demand-driven strategy to achieve efficient and secure key distribution. This method includes steps such as baseband board registration and authentication, key request, key generation and distribution, and key storage and updating. It effectively solves the problems of complex key management and inconvenient interaction in existing technologies, improving system security and reliability, and is suitable for multi-beam, multi-board satellite communication system ground station access network environments.

[0082] In summary, the method of this invention, tailored to the characteristics and requirements of the new system, employs a demand-driven strategy to construct a comprehensive key management and distribution mechanism. This method offers advantages such as improved management efficiency, enhanced security, meeting diverse business needs, high flexibility, and ease of expansion and maintenance. It can be well applied in the environment of satellite communication system ground station access networks, ensuring secure communication for the system.

Claims

1. A key binding and allocation method based on a demand-driven strategy, characterized in that, This method is applied to a ground station access network for a satellite communication system. The ground station access network includes a channel equipment chassis, which houses baseband cards, main control cards, switching cards, and intermediate frequency cards. The ground station access network uses a group cryptographic machine for key management. The method includes the following steps: Step S1: Each baseband board sends a registration request to the main control board. The registration request carries the unique identification information of the baseband board. After receiving the registration request, the main control board verifies the unique identification information of the baseband board. After successful verification, the baseband board is added to the management list, and an initial status identifier is assigned to each baseband board. Step S2: The baseband board sends a key request to the main control board according to its own business needs. The key request includes the unique identification information of the baseband board, the type of key required, and the business scenario information. Step S3: After receiving the key request, the main control board sends the corresponding key generation instruction to the group cryptographic machine according to the type information of the required key. The group cryptographic machine generates the corresponding key according to the key generation instruction and sends it to the main control board. After receiving the key, the main control board binds the key to the corresponding baseband board according to the preset mapping relationship, and distributes the key to the corresponding baseband board through the exchange board. Step S4: After receiving the key, the baseband board stores the key in a local secure storage area.

2. The key precise binding and allocation method based on a demand-driven strategy according to claim 1, characterized in that, The unique identification information is the baseband board's hardware serial number, MAC address, or a pre-set device number.

3. The key precise binding and allocation method based on a demand-driven strategy according to claim 1, characterized in that, The service scenario information is used to indicate the type of service that the baseband board is currently participating in. The service types include data transmission service, control command service, and test service.

4. The key precise binding and allocation method based on a demand-driven strategy according to claim 1, characterized in that, The preset mapping relationship is established based on the correspondence between the unique identification information of the baseband board and the key, and is stored in the memory of the main control board.

5. The key precise binding and allocation method based on a demand-driven strategy according to claim 1, characterized in that, In step S3, before distributing the key to the baseband board, the main control board encrypts the key. The key used for encryption is a session key that is pre-shared between the baseband board and the main control board.

6. The key precise binding and allocation method based on a demand-driven strategy according to claim 1, characterized in that, Step S4 also includes: the main control board periodically or according to preset conditions, triggering a key update process to update the key for the baseband board; wherein, the time interval for periodically triggering the key update process is set according to the system security policy, and the preset conditions are that the number of times the key is used reaches a threshold, the system detects a security threat, or receives an external forced update command.

7. A key precise binding and allocation method based on a demand-driven strategy according to any one of claims 1 to 6, characterized in that, It also includes a key revocation step: when the baseband board malfunctions, is removed, or is no longer needed, the main control board receives a key revocation request from the baseband board or an external management system, stops distributing new keys to the baseband board, and notifies the group cryptographic machine to invalidate the key associated with the baseband board.

Citation Information

Patent Citations

  • Address allocation method and device for multi-board topology cascade structure and storage medium

    CN118138569A

  • Burned data transmission method, electronic equipment and storage medium

    CN119892426A