A method and system for encrypted transmission of a Loran signal
By pre-injecting a symmetric key into the Roland signal transmission system and using a key derivation function and a pseudo-random number generator to generate a time offset, the security and accuracy issues of the Roland signal transmission system are solved, enabling encrypted transmission and precise positioning correction, thus improving the system's security and positioning accuracy.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SHANGYU HEBEI ELECTRONICS SCI & TECH CO LTD
- Filing Date
- 2025-10-24
- Publication Date
- 2026-04-24
AI Technical Summary
The existing Roland signal transmission system uses plaintext broadcasting, which cannot perform identity verification and authorization management, posing a serious security risk. Unauthorized devices can receive and use the signal, resulting in insufficient security and positioning accuracy.
By pre-injecting a symmetric key offline, a pseudo-random time offset is generated using a first key derivation function and a pseudo-random number generator to achieve encrypted transmission of the Roland signal. The time offset is then corrected at the target receiving end to ensure the security of signal transmission and positioning accuracy.
It effectively resists signal spoofing, interception and replay attacks, ensuring the authorized security of Roland signal transmission, improving positioning accuracy, reducing deployment costs, and maintaining the real-time performance of signal transmission.
Smart Images

Figure CN121000388B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of signal transmission encryption technology, and in particular to an encrypted transmission method and system for authorized Roland signals. Background Technology
[0002] In today's complex communication environment, the Loland signal, as an important land-based long-range radio navigation signal, plays a crucial role in navigation, positioning, and other fields. With the rapid development of technology, higher demands are being placed on the security and reliability of Loland signal transmission. However, the core weakness of existing Loland systems lies in their completely plaintext broadcasting method. The navigation message is modulated onto the carrier wave in unencrypted form and broadcast, which means that any device with Loland receiving capabilities can receive and utilize its signal, making user authentication and authorization impossible. This poses a serious security risk in scenarios such as military applications.
[0003] There is an urgent need for an encrypted transmission method for authorized Roland signals to improve the security of Roland signals during transmission. Summary of the Invention
[0004] To address the aforementioned technical problems, this application provides a method and system for encrypted transmission of authorized Roland signals.
[0005] A first aspect of this application provides a method for encrypted transmission of authorized Roland signals, comprising:
[0006] Obtain the reference launch time;
[0007] Based on preset sensitive parameters and a built-in symmetric key, a first pseudo-random time offset within a preset range is generated through a first key derivation function and a first pseudo-random number generator; wherein, the sensitive parameters include the broadcast time timestamp, and the symmetric key is pre-injected into the transmitter and the target receiver offline;
[0008] The first pseudo-random time offset is superimposed on the base transmission time to generate an encrypted transmission time;
[0009] The encrypted transmission time control transmitter sends a Roland signal to the target receiver;
[0010] The target receiver is controlled to generate a second pseudo-random time offset based on the built-in symmetric key and local clock, and the observed signal transmission time reference value is corrected using the second pseudo-random time offset to complete the positioning calculation and obtain the positioning result.
[0011] A second aspect of this application provides an encrypted transmission system for authorized Roland signals, including a memory, a processor, and a computer program stored in the memory and running on the processor, wherein the processor executes the computer program to implement the steps of the encrypted transmission method for authorized Roland signals described above.
[0012] A third aspect of this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the above-described encrypted transmission method for authorized Roland signals.
[0013] The beneficial effects of the encrypted transmission method and system for authorized Loland signals provided in this application are as follows: Firstly, this application avoids the risk of key leakage during online transmission by pre-injecting a symmetric key offline. Secondly, it generates a time offset using a first key derivation function and a pseudo-random number generator, making the encrypted transmission time random and effectively resisting signal forgery, interception, and replay attacks, thus ensuring the authorized security of Loland signal transmission and preventing unauthorized receivers from obtaining valid positioning information. Thirdly, the target receiver generates a second pseudo-random time offset based on the same symmetric key, which can accurately correct the observed signal transmission time reference value, offsetting the impact of the time offset on time measurement, reducing time errors, improving positioning accuracy, and making the positioning results more reliable. Finally, the method of this application can achieve encryption and correction using a built-in key and a local clock, without requiring complex additional hardware, reducing deployment costs. Furthermore, the symmetric key and pseudo-random number related operations are efficient and do not increase the computational burden on the transmitter and receiver, ensuring the real-time performance of signal transmission and positioning. This method is suitable for Loland positioning scenarios with high security and accuracy requirements. Attached Figure Description
[0014] Figure 1 A flowchart illustrating an embodiment of the encrypted transmission method for authorized Roland signals provided in this application;
[0015] Figure 2 This is a schematic diagram of an encrypted transmission system for authorized Roland signals provided in an embodiment of this application. Detailed Implementation
[0016] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application may also be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods have been omitted so as not to obscure the description of this application with unnecessary detail.
[0017] To make the purpose, technical solution, and advantages of this application clearer, the following will be described in conjunction with the appendix. Figure 1-2 The following is an explanation using specific examples.
[0018] Please refer to Figure 1 , Figure 1 This is a flowchart illustrating an embodiment of the encrypted transmission method for authorized Loran signals provided in this application. This method establishes a symmetric key-based synchronous encryption mechanism between the transmitting and receiving ends, achieving full-process security protection for the Loran signal from transmission to reception and positioning. The entire technical framework mainly includes two core modules: encrypted signal generation and transmission at the transmitting end, and signal decryption and positioning calculation at the receiving end. It relies on a pre-configured symmetric key offline as a security foundation, ensuring consistency and uniqueness in encryption logic between the transmitting and receiving ends, thus fundamentally preventing unauthorized devices from cracking and exploiting the signal.
[0019] The authorized Roland signal encryption transmission method includes:
[0020] S101: Obtain the reference launch time.
[0021] In this embodiment, the reference transmission time is the time base for the Loland signal transmission, and its accuracy directly affects the accuracy of subsequent positioning results. The transmitter first acquires a standard time signal through a high-precision time synchronization module (BeiDou / GPS dual-mode time receiving module, atomic clock synchronization unit, etc.). After processing by an internal time calibration algorithm (Kalman filter calibration, bias compensation algorithm), a reference transmission time with nanosecond-level accuracy is obtained. This reference transmission time will serve as the basis for generating the encrypted transmission time, ensuring that the time base for the Loland signal transmission is consistent with global standard time, providing a reliable basis for the receiver's time synchronization and positioning calculations.
[0022] S102: Based on preset sensitive parameters and built-in symmetric key, a first pseudo-random time offset within a preset range is generated through a first key derivation function and a first pseudo-random number generator; wherein, the sensitive parameters include the broadcast time timestamp, and the symmetric key is pre-injected into the transmitter and the target receiver offline.
[0023] In this embodiment, the generation of the first pseudo-random time offset is the core step in transmitting signal encryption. It is generated based on preset sensitive parameters and a built-in symmetric key, ensuring the randomness, uniqueness, and confidentiality of the first pseudo-random time offset.
[0024] The core sensitive parameter is the broadcast timestamp, and other parameters can be added according to actual security requirements, such as the unique identifier of the transmitting device (device ID), the channel parameters of the Loran signal, and the sequence number of the current signal transmission. The broadcast timestamp is accurate to the millisecond level and synchronized with the reference transmission time. Other supplementary parameters need to undergo format standardization processing (such as conversion to fixed-length binary data) to ensure that all sensitive parameters can be effectively identified and processed by the first key derivation function.
[0025] The symmetric key is pre-injected into the transmitter and target receiver offline. The injection process uses a physically isolated key writing device (dedicated key programmer) to prevent the symmetric key from being intercepted during transmission. Before generating the first pseudo-random time offset, the transmitter performs integrity verification on the built-in symmetric key. For example, it verifies whether the hash value of the key matches the preset value using a hash check algorithm. If the verification fails, the device alarm mechanism is immediately triggered, stopping the signal transmission process to prevent encryption failure due to key corruption or tampering.
[0026] In this embodiment, the processed sensitive parameters and the verified symmetric key are input to a first key derivation function (e.g., an HMAC-based key derivation function, the PBKDF2 key derivation algorithm, etc.). This first key derivation function generates a fixed-length intermediate key through multiple rounds of hash operations and data obfuscation. The length of the intermediate key is determined according to a preset range of a first pseudo-random time offset. For example, if the preset offset range is 0-100 microseconds, the intermediate key can be mapped to all integer microsecond values within that range.
[0027] The intermediate key generated by the first key derivation function is used as the seed for the first pseudo-random number generator, triggering the generator to generate a first pseudo-random time offset that conforms to a preset range. The first pseudo-random number generator employs a cryptographically secure pseudo-random number generation algorithm (AES-CTR pseudo-random number generation algorithm), ensuring that the generated first pseudo-random time offset exhibits good randomness and no predictable pattern, preventing malicious attackers from cracking the encryption logic by analyzing the offset distribution characteristics. Simultaneously, the generator performs range verification on the generated offset; if the offset exceeds the preset range, it will regenerate until a first pseudo-random time offset that meets the requirements is obtained.
[0028] S103: The first pseudo-random time offset is superimposed on the reference transmission time to generate an encrypted transmission time. At the encrypted transmission time, the transmitter is controlled to send the Roland signal to the target receiver.
[0029] In this embodiment, the encrypted transmission time is calculated by superimposing the reference transmission time and the first pseudo-random time offset. For example, if the reference transmission time is T0 and the first pseudo-random time offset is ΔT1, then the encrypted transmission time T1 = T0 + ΔT1. The time control module at the transmitting end precisely controls the transmitter to send the Loran signal at the encrypted transmission time T1. Before sending the Loran signal, the transmitter modulates the Loran signal (using amplitude modulation, phase modulation, etc.) to ensure that the Loran signal can be transmitted stably within the specified radio frequency band, while reducing the impact of external electromagnetic interference on the signal. During the transmission of the Loran signal, the transmitting end monitors parameters such as the signal's transmission power and frequency stability in real time; if any abnormal parameters occur, the transmitter's operating status is adjusted promptly to ensure that the Loran signal can be transmitted accurately and stably to the target receiving end.
[0030] S104: The target receiver generates a second pseudo-random time offset based on the built-in symmetric key and local clock, and corrects the observed signal transmission time reference value based on the second pseudo-random time offset to complete the positioning calculation and obtain the positioning result.
[0031] In this embodiment, the target receiver receives the Loland signal transmitted by the transmitter via a Loland signal receiving antenna. The signal is amplified to a processable amplitude by a preamplifier module, filtered to remove external electromagnetic interference signals by a filtering module, and demodulated to restore the original time information of the signal, thus obtaining the observed signal transmission time reference value. This reference value is the actual arrival time of the Loland signal observed by the receiver, and needs to be subsequently corrected by a second pseudo-random time offset to eliminate the deviation of the first pseudo-random time offset.
[0032] The process of generating the second pseudo-random time offset at the target receiver is completely consistent with the process of generating the first pseudo-random time offset at the transmitter, ensuring that the offsets generated at both ends are the same, thereby achieving accurate correction of the observation time reference value.
[0033] The receiver has a built-in high-precision local clock. Before receiving the Loland signal, it synchronizes with global standard time (BeiDou time, GPS time) through a time synchronization module, achieving nanosecond-level synchronization accuracy. Simultaneously, the receiver performs real-time calibration of the local clock based on the time characteristics of the received Loland signal, compensating for time drift caused by factors such as temperature changes and aging. This ensures that the local clock remains highly consistent with the transmitter's reference transmission time, providing an accurate time basis for the acquisition of sensitive parameters and the retrieval of symmetric keys.
[0034] The sensitive parameters collected by the receiver are exactly the same as those collected by the transmitter, including the broadcast timestamp (obtained by demodulating the Loran signal and synchronized with the broadcast timestamp of the transmitter), the unique identifier of the receiver device (which must be consistent with the target receiver device ID pre-agreed upon by the transmitter), the channel parameters of the Loran signal, and the sequence number of the signal transmission. The receiver performs the same format standardization processing on the collected sensitive parameters as the transmitter to ensure the consistency of the sensitive parameters.
[0035] The symmetric key built into the receiver is exactly the same as the symmetric key of the transmitter, and is also pre-injected offline. Before generating the second pseudo-random time offset, the receiver performs the same integrity verification on the symmetric key as the transmitter. If the verification fails, the receiver alarm mechanism will be triggered, stopping the positioning and solving process to prevent correction deviations due to key issues.
[0036] The receiving end inputs the processed sensitive parameters and the verified symmetric key into the second key derivation function (using the same algorithm as the first key derivation function at the transmitting end) to generate an intermediate key of the same length. This intermediate key is then used as the seed for the second pseudo-random number generator (using the same algorithm as the first pseudo-random number generator at the transmitting end) to generate a second pseudo-random time offset that is identical to the first pseudo-random time offset. Because the sensitive parameters, symmetric key, and algorithm are completely identical at both ends, the consistency between the second and first pseudo-random time offsets is ensured, providing an accurate basis for subsequent time correction.
[0037] The receiving end calculates the difference between the observed signal transmission time reference value and the second pseudo-random time offset to obtain the corrected signal transmission time, i.e., the corrected time T2 = observed time reference value - ΔT2, where ΔT2 is the second pseudo-random time offset. Since ΔT2 is equal to ΔT1, T2 is consistent with the transmitter's reference transmission time T0. This embodiment effectively eliminates the time offset caused by encryption during signal transmission through the above correction process, and also compensates for the influence of external interference on the observed time reference value to a certain extent, ensuring that the corrected time accurately reflects the actual transmission reference time of the Loran signal.
[0038] In actual operation, the receiver receives encrypted Loran signals from multiple Loran transmitters. The aforementioned time correction is applied to each signal to obtain the corrected transmission time for each transmitter. Then, based on the Loran navigation principle, the location information of multiple transmitters (pre-stored in the receiver's Loran station database, including latitude, longitude, altitude, etc.) and the corrected transmission time are used to calculate the distance between the receiver and each transmitter (distance = speed of light × signal propagation time, signal propagation time = difference between the corrected transmission time and the receiver's local reception time). Finally, a multi-station positioning algorithm (such as trilateration or least squares positioning) is used to calculate the multiple distance values to obtain the receiver's precise location information (latitude, longitude, altitude), completing the positioning calculation. After the positioning calculation is completed, the receiver verifies the accuracy of the positioning result (by calculating the confidence interval of the positioning result and the deviation from the known reference position). If the accuracy meets the preset requirements, the positioning result is output; if the accuracy does not meet the requirements, the signal is received again and the positioning calculation is performed until a satisfactory positioning result is obtained.
[0039] As can be seen from the above, this application avoids the risk of key leakage during online transmission by pre-injecting a symmetric key offline. The time offset generated by the first key derivation function and a pseudo-random number generator ensures the randomness of the encrypted transmission time, effectively resisting signal spoofing, interception, and replay attacks, thus guaranteeing the authorized security of the Roland signal transmission and preventing unauthorized receivers from obtaining valid positioning information. Secondly, the target receiver generates a second pseudo-random time offset based on the same symmetric key, which accurately corrects the observed signal transmission time reference value, offsetting the impact of the time offset on time measurement, reducing time errors, improving positioning accuracy, and making the positioning results more reliable. Finally, the method of this application relies on a built-in key and a local clock for encryption and correction, eliminating the need for complex additional hardware, reducing deployment costs. Furthermore, the symmetric key and pseudo-random number related operations are efficient and do not increase the computational burden on the transmitter and receiver, ensuring the real-time performance of signal transmission and positioning. This method is suitable for Roland positioning scenarios with high security and accuracy requirements.
[0040] An example implementation of pseudo-random offsets is as follows:
[0041] The reference transmission time T0 is organized into a series of numbers according to a specific format: year, month, day, hour, minute, second, millisecond, microsecond, nanosecond (e.g., 20250202090503060320010 represents the reference transmission time: February 2, 2025, 9:05:03, 60 milliseconds, 320 microseconds, and 10 nanoseconds). The decimal sequence is directly converted into binary numbers bit by bit, that is, each decimal number is represented by 4 bits, for a total of 92 bits. Zeros are added at the end to make the length 128 bits, denoted as S0.
[0042] The AES encryption algorithm (or other encryption algorithms) is used to encrypt the digital sequence S0 with an agreed key to obtain the encrypted digital sequence, resulting in 128-bit encrypted data S1;
[0043] Then, the binary sequence S1 is divided into 13 groups (with the last 2 bits padded with zeros), each group being 10 bits, arranged as a data block of 13 rows and 10 columns. An XOR operation is performed on each column, and each column yields a binary operation result. After the 13 groups of operations are completed, a 10-bit calculation result S2 is obtained (there are 1024 possible cases), with a value range of 0 to 1023.
[0044] Based on the obtained 10-bit value S2, the pre-made timing offset table is queried to obtain the first pseudo-random time offset DT;
[0045] The first pseudo-random time offset is added to the reference transmission time to obtain the encrypted transmission time T1.
[0046] For example, under the original signal system, the target receiver obtains the time differences TD_X and TD_Y by observing the signal of a certain station chain, and then calculates the position using the hyperbolic positioning principle. After encryption, the time differences observed by the target receiver are TD_X+PX1 and TD_Y+PX2, where PX1 and PX2 are errors obtained by adding a first pseudo-random time offset to the reference transmission time. Furthermore, PX1 and PX2 are time-varying, causing unlicensed target receivers to be unable to calculate the correct position information. In addition, due to the unpredictability of the encrypted transmission time, unlicensed target receivers cannot accumulate signals over multiple periods, and the target receiver cannot capture and track the licensed signal.
[0047] Even if the receiving end is located very close to the broadcasting station and uses a method of acquiring the signal first and then processing it, thus achieving signal acquisition and demodulation, the actual reference transmission time cannot be obtained because the message is still encrypted. The target receiving end, however, is equipped with an authorization component that stores the private key corresponding to the transmitting end, enabling the decryption of the encrypted transmission time.
[0048] For example, the target receiver's workflow is as follows:
[0049] The target receiver obtains a rough current time through the local time synchronization circuit;
[0050] The target receiver searches for the signal within the time uncertainty range. Specifically, it first guesses the current time, then sends it to the authorization module to obtain the offset of the current reference transmission time. If the current signal can be captured, the capture is completed; otherwise, it searches for the next time within the time uncertainty range until the signal is captured.
[0051] After the target receiver completes signal acquisition, it predicts the next reference transmission time according to the existing broadcast specifications and sends it to the authorized component to calculate the corresponding random time offset. The target receiver corrects the time offset to obtain the true reference transmission time and achieves signal tracking.
[0052] The target receiver subtracts the second pseudo-random time offset (PX1 and PX2, obtained by the authorized component) from the observed time difference information (TD_X+PX1 and TD_Y+PX2) to obtain the true time difference information (TD_X and TD_Y), thus completing the positioning calculation. The target receiver then sends the demodulated information to the authorized component to complete the message decryption, realize time tracing, and complete the autonomous positioning function.
[0053] In one embodiment of this application, the observed signal transmission time reference value is corrected based on a second pseudo-random time offset to complete the positioning calculation and obtain the positioning result, including:
[0054] The local clock is calibrated based on a clock synchronization protocol to obtain the calibration time.
[0055] Based on the calibration time and the built-in symmetric key, a second pseudo-random time offset is generated through a second key derivation function and a second pseudo-random number generator.
[0056] The observed signal transmission time reference value is corrected using the second pseudo-random time offset;
[0057] The positioning calculation is completed based on the corrected signal transmission time reference value, and the positioning result is obtained.
[0058] In this embodiment, local clock calibration is a prerequisite for ensuring the accuracy of offset generation and the effectiveness of time correction. High-precision time alignment needs to be achieved through a standardized clock synchronization protocol. The specific process includes:
[0059] The receiver employs an industrial-grade high-precision clock synchronization protocol, prioritizing protocols that support nanosecond-level synchronization accuracy, such as the IEEE 1588PTP Precision Time Protocol and the IRIG-B Time Code Protocol. The IEEE 1588PTP protocol achieves time synchronization in a distributed system by calculating network latency and clock skew through bidirectional master-slave clock communication. The IRIG-B protocol, on the other hand, transmits time information via serial encoding and is suitable for short-distance, high-reliability clock synchronization scenarios. The receiver selects an appropriate synchronization protocol based on the actual application environment and deploys corresponding protocol parsing modules and hardware interfaces. The Ethernet interface is used for the IEEE 1588PTP Precision Time Protocol, and the RS485 interface is used for the IRIG-B Time Code Protocol.
[0060] The clock synchronization module at the receiving end periodically communicates with external time references (BeiDou / GPS dual-mode time receiver, time calibration signal from the Roland station) to collect time synchronization data. First, it calculates the deviation ΔTsync between the local clock and the external reference clock (ΔT_sync = current local clock time - external reference clock time). Then, based on the magnitude and trend of the deviation, a dynamic calibration algorithm (proportional-integral-derivative (PID) calibration algorithm, sliding window averaging calibration algorithm) is used to adjust the local clock. For example, when ΔTsync is greater than 10 ns, the PID algorithm is used to fine-tune the crystal oscillator frequency of the local clock, gradually reducing the deviation; when ΔTsync is less than 10 ns, the sliding window averaging algorithm is used to smooth clock fluctuations and avoid clock instability caused by frequent adjustments.
[0061] After calibration, the receiving end verifies the validity of the obtained calibration time by comparing the deviation values of three consecutive calibration results (if all three deviation values are less than 5ns and the fluctuation range is less than 2ns), confirming the stability and reliability of the calibration time. Once verification is successful, the calibration time is used as the time reference for subsequent sensitive parameter acquisition and key derivation operations, stored in a local high-precision time register, and the generation time and synchronization protocol type are marked for easy troubleshooting and tracing.
[0062] The generation of the second pseudo-random time offset requires the calibration time as the core sensitive parameter, combined with a symmetric key to complete the encryption operation, ensuring complete consistency with the first pseudo-random time offset at the transmitting end. Specifically, the calibration timestamp is used as the core sensitive parameter to replace the broadcast time timestamp mentioned above, ensuring the uniformity of the time base.
[0063] In one embodiment of this application, calibrating a local clock based on a clock synchronization protocol includes:
[0064] Obtain time information from at least two time sources;
[0065] The standard deviation of clock errors for each time source is calculated based on a predefined clock error model.
[0066] Assign trust weights to each time source based on standard deviation;
[0067] The calibration time is obtained by weighting and fusing the time information from each time source based on trust weights.
[0068] The local clock is calibrated based on the calibration time.
[0069] In this embodiment, the time sources include the Loland system's own time reference, time signals provided by the Global Navigation Satellite System, and the time output of a high-precision atomic clock. Acquiring time information from multiple time sources can avoid the adverse effects on clock calibration caused by the failure or excessive error of a single time source, providing a data foundation for subsequent accurate calibration.
[0070] The predefined clock error model in this embodiment is established based on the characteristics of the time source, environmental factors, and historical data, and can accurately describe the error patterns existing in the time source. By analyzing and calculating the time information of each time source through the clock error model, the standard deviation of the clock error can quantify the time stability and error magnitude of each time source. The smaller the standard deviation, the more stable the time information of the time source and the smaller the error fluctuation.
[0071] In this embodiment, the assignment of trust weights follows the principle that the smaller the standard deviation, the greater the trust weight. This is because time sources with smaller standard deviations are more reliable and should be given greater weight in clock calibration. The specific weight calculation can be implemented using an algorithm, such as normalizing the reciprocal of the standard deviation of each time source to obtain the corresponding trust weight, ensuring that the sum of the trust weights of all time sources is 1.
[0072] The weighted fusion process in this embodiment involves multiplying the time information from each time source by its corresponding trust weight, and then summing all the products to obtain a comprehensive time value, i.e., the calibration time. This application fully utilizes the information from multiple time sources and combines the advantages of each time source, making the calibration time more accurate and reliable than that from a single time source.
[0073] This embodiment compares the local clock of the target receiver with the calibrated time, calculates the deviation between the two, and then adjusts the local clock according to the deviation to ensure that the local clock time is consistent with the calibrated time. The calibrated local clock in this embodiment provides an accurate time reference for subsequent signal reception, time calculation, and positioning calculation, ensuring the smooth operation of the entire Roland signal encryption transmission and positioning process.
[0074] In one embodiment of this application, based on preset sensitive parameters and a built-in symmetric key, a first pseudo-random time offset within a preset range is generated through a first key derivation function and a first pseudo-random number generator, including:
[0075] Based on the sensitive parameters and the built-in symmetric key, a seed key is generated through the first key derivation function;
[0076] Using the seed key as input to the first pseudo-random number generator, a predefined time offset table is queried to generate a first pseudo-random time offset within a preset range; wherein, the time offset table defines the mapping relationship between the index bit width and the time offset value, and the index bit width is configurable.
[0077] In this embodiment, a seed key is generated based on the sensitive parameters and the built-in symmetric key through a first key derivation function. The seed key is the key bridge connecting the sensitive parameters, the symmetric key, and the pseudo-random number generation. It needs to complete the encryption operation through the first key derivation function to ensure its unpredictability and uniqueness. The specific implementation process is as follows:
[0078] Sensitive parameters are preprocessed to ensure their length and format meet the input requirements of the first key derivation function. The symmetric key, built into the transmitter, is stored in a hardware security module that is resistant to physical tampering and side-channel attacks. Before generating the seed key, the transmitter's encryption control unit sends a key access request to the HSM (Hardware Smart Controller) and simultaneously uploads the hash values of the standardized sensitive parameters. After verifying the request's validity, the HSM transmits the symmetric key to the computation unit of the first key derivation function via its internal encryption bus. The transmission process is encrypted using a temporary session key (generated based on the ECC elliptic curve algorithm) to prevent key leakage.
[0079] The first key derivation function uses the PBKDF2-HMAC-SHA256 algorithm, with a standardized sensitivity parameter as the salt value and a symmetric key as the initial key. The iteration count is set to 20,000 (adjustable according to scenario requirements) to generate a fixed-length seed key. The specific computation steps are as follows:
[0080] The initial key and salt value are concatenated to obtain the first set of input data; HMAC-SHA256 hash operation is performed on the input data to obtain the first set of intermediate results; the first set of intermediate results is concatenated with the initial key and salt value as the input data for the next round, until 20,000 iterations are completed; all iteration results are XORed to obtain the seed key, the length of which matches the index bit width of the subsequent time offset table.
[0081] This embodiment uses a seed key as input to a first pseudo-random number generator, queries a predefined time offset table, and generates a first pseudo-random time offset within a preset range. By querying the time offset table to generate the offset, flexible configuration and precise control of the time offset can be achieved, avoiding the range overflow problem caused by direct pseudo-random number conversion. The specific implementation process is as follows:
[0082] The timing offset table adopts a two-dimensional table structure and is stored in the non-volatile memory of the transmitter, supporting online updates. The core of the table is defined as the mapping relationship between the index bit width and the time offset value, as detailed below:
[0083] The index bit width is dynamically adjusted according to the preset time offset range, and supports 8-bit, 16-bit, and 32-bit configurations.
[0084] The time offset value determines the range of index values based on the index bit width. A unique time offset value is assigned to each index, and the offset values are evenly distributed within a preset range to avoid predictability caused by concentrated distribution.
[0085] Before storing the time offset table, it is encrypted using AES-256, and the encryption key and the built-in symmetric key are managed independently. When reading the table, it must first be decrypted using HSM to prevent the table from being illegally tampered with.
[0086] The first pseudo-random number generator employs a seed key-based linear feedback shift register algorithm, using the seed key as the generator's initial state to trigger the generation of a pseudo-random number sequence. The specific steps are as follows:
[0087] The seed key is written into the register group of the linear feedback shift register algorithm. Based on a preset feedback polynomial, the register data is shifted and XORed to generate a 1-bit pseudo-random number. This process is repeated until a pseudo-random number with the same bit width as the index is generated; this pseudo-random number is the lookup index for the time-series offset table. After generating the index, its range is validated (it is determined whether the index is within the range of index values in the time-series offset table). If it exceeds the range, a new pseudo-random number is generated until a valid index is obtained.
[0088] In this embodiment, the storage control unit at the transmitter queries a predefined timing offset table based on the generated valid index to obtain the corresponding time offset value. After the query is completed, the obtained time offset value is used as the first pseudo-random time offset and stored in the encrypted buffer of the transmitter, waiting to be superimposed with the reference transmission time to generate the encrypted transmission time.
[0089] In one embodiment of this application, a method for encrypted transmission of authorized Roland signals is characterized by further comprising:
[0090] The encryption parameters are adjusted based on environmental threat indicators to obtain the target encryption parameters;
[0091] Update the range parameter of the first pseudo-random number generator or the round parameter of the symmetric encryption algorithm based on the target encryption parameter;
[0092] The environmental threat index is determined based on the security level established by a preset geographical location risk rule base. In this embodiment, the environmental threat index characterizes the current security status of the Roland signal transmission environment and can provide real-time feedback on potential security risks. The security level determined by the preset geographical location risk rule base assesses risk from a spatial dimension. This rule base pre-sets risk level classification standards for different geographical locations; for example, military restricted areas and border areas are classified as high-risk, while ordinary urban areas are classified as medium- to low-risk. This embodiment can query the rule base based on the current geographical location to determine the corresponding security level. When the environmental threat index indicates a high risk, the security of the encryption parameters needs to be improved, such as by increasing encryption complexity or expanding the pseudo-random number range. When the risk is low, the complexity of the encryption parameters can be reduced to improve transmission efficiency while ensuring security. This embodiment uses such dynamic adjustments to ensure that the encryption parameters always match the level of environmental threat, achieving a balance between security and efficiency, and ultimately obtaining target encryption parameters adapted to the current environment.
[0093] In this embodiment, the range parameter of the first pseudo-random number generator determines the range of values for the generated first pseudo-random time offset. When the target encryption parameters require increased security, the range parameter can be increased to make the time offset more random and its values more dispersed; conversely, when the risk decreases and the target encryption parameters tend to improve efficiency, the range parameter can be decreased to reduce computational load. The round parameter of the symmetric encryption algorithm is related to the complexity of the encryption. More rounds result in a more complex encryption process and greater difficulty in cracking, but also increase the consumption of computational resources. In high-threat environments, the round parameter is increased based on the target encryption parameters to enhance encryption strength; in low-threat environments, the round parameter is reduced to accelerate encryption speed. This embodiment, by updating one or both of these parameters, enables the entire encryption mechanism to flexibly adjust according to changes in environmental threats, always maintaining optimal security protection.
[0094] In one embodiment of this application, the encryption parameters are adjusted based on environmental threat indicators to obtain target encryption parameters, including:
[0095] The direction and magnitude of the encryption parameter adjustment are determined based on environmental threat indicators;
[0096] The target encryption strength and target encryption value are determined based on the adjustment direction of the encryption parameters;
[0097] The encryption step size of the target encrypted value is determined based on the adjustment range of the encryption parameters;
[0098] The encryption parameters are adjusted based on the target encryption strength, target encryption value, and encryption step size to obtain the target encryption parameters.
[0099] In this embodiment, the environmental threat index determines the adjustment direction of encryption parameters based on the geographical location security level. When the geographical location security level is high-risk, it indicates that the current environmental threat is increasing, and the adjustment direction is the first adjustment direction, that is, to enhance the security of encryption parameters; conversely, when the geographical location security level is low-risk, the adjustment direction is to reduce the complexity of encryption parameters while ensuring basic security, so as to improve efficiency.
[0100] The adjustment range is determined based on the severity of the environmental threat indicated by the environmental threat index. For example, if the location is in an extremely high-risk geographical location, the adjustment range will be larger to significantly improve the encryption strength; if the threat level only increases or decreases slightly, the adjustment range will be relatively smaller to avoid excessive adjustment causing unnecessary impact on system performance.
[0101] When the adjustment direction is the first direction, enhancing security, the target encryption strength is set to a higher level, and the corresponding target encryption value will also move towards a larger range or a more complex degree. For example, for the range parameter of the first pseudo-random number generator, the target encryption value will be set to a larger numerical range; for the round parameter of the symmetric encryption algorithm, the target encryption value will be set to more rounds. When the adjustment direction is the second direction, reducing complexity, the target encryption strength is set to a level that meets basic security requirements, and the target encryption value will decrease accordingly, such as narrowing the range of pseudo-random numbers or reducing the number of encryption rounds.
[0102] In this embodiment, the encryption step size is the increment or decrement used each time the encryption parameters are adjusted. When the adjustment range is large, the encryption step size is set to a larger value to quickly adjust the encryption parameters to the target encryption value; when the adjustment range is small, the encryption step size is set to a smaller value to make the adjustment of the encryption parameters more stable and avoid impacting the stability of the system due to large changes.
[0103] During the adjustment process, guided by the target encryption strength, the encryption parameters are gradually adjusted to the target encryption value according to a determined encryption step size. If the current encryption parameters differ significantly from the target encryption value, adjustments are made multiple times according to the encryption step size to ensure that each adjustment meets the requirements of the target encryption strength; if the difference is small, the adjustment can be completed in one step. This embodiment, through the above adjustment method, ensures that the final target encryption parameters accurately respond to changes in environmental threat indicators while guaranteeing the rationality of the adjustment process and the stability of the system, keeping the encryption mechanism in an optimal operating state at all times.
[0104] In one embodiment of this application, the adjustment direction includes: a first adjustment direction and a second adjustment direction;
[0105] The target encryption strength and target encryption value are determined based on the adjustment direction of the encryption parameters, including:
[0106] When the adjustment direction is the first adjustment direction, the target encryption strength is increased to the preset highest security level, and the target encryption value is set to the upper limit of the highest security level;
[0107] When the adjustment direction is the second adjustment direction, the target encryption strength is reduced to the preset basic security level, and the target encryption value is set to the recommended value of the basic security level.
[0108] In this embodiment, when the adjustment direction is the first adjustment direction, it means that the current environment faces a high security threat, requiring the encryption protection to be upgraded to the highest level. At this time, the target encryption strength is directly upgraded to the preset highest security level. The target encryption value is set to the upper limit of this highest security level. For example, for the range parameter of the first pseudo-random number generator, its upper limit is the maximum value range that can be supported, ensuring that the randomness of the time offset reaches the strongest; for the round parameter of the symmetric encryption algorithm, the upper limit is the number of rounds that can achieve the highest encryption strength under rigorous testing and can ensure operation. By setting the target encryption value to the upper limit, this embodiment enables the encryption parameters to play the maximum protective role under the first adjustment direction, providing the most solid security guarantee for the encrypted transmission of the Loran signal.
[0109] In this embodiment, when the adjustment direction is the second adjustment direction, it indicates that the current security threat is low. Under the premise of ensuring basic security, the encryption complexity can be appropriately reduced to improve system operating efficiency. At this time, the target encryption strength is reduced to a preset basic security level. This basic security level is the minimum security protection level necessary for the normal operation of the system and can resist common, low-intensity security threats. The target encryption value is set to a recommended value of the basic security level. The recommended value is the optimal value determined based on security requirements and the computing resources of the device. For example, the recommended value for the range parameter of the first pseudo-random number generator can ensure a certain degree of randomness to meet basic security requirements without increasing the computational burden due to an excessively large range; the recommended value for the round parameter of the symmetric encryption algorithm can reduce the amount of computation in the encryption process while ensuring encryption effectiveness and speeding up signal processing. This embodiment uses recommended values as the target encryption value, achieving the best balance between security and efficiency under the second adjustment direction, allowing the system to maintain reliable security protection capabilities while reducing resource consumption.
[0110] In one embodiment of this application, determining the encryption step size based on the adjustment range of encryption parameters includes:
[0111] Map the adjustment range to a preset adjustment level;
[0112] The base step size value is scaled proportionally according to the adjustment level to generate the encrypted step size;
[0113] Among them, the scaling factor corresponding to the base step size value of the adjustment level.
[0114] In this embodiment, the adjustment range is the degree of adjustment of encryption parameters determined based on environmental threat indicators. To process this more systematically, it is mapped to preset adjustment levels. These preset adjustment levels can be divided into multiple tiers, such as slight adjustment, moderate adjustment, and significant adjustment. Specific mapping rules can be set according to actual application scenarios. For example, when the adjustment range is 0-20%, it is mapped to a slight adjustment level; 20%-50%, it is mapped to a moderate adjustment level; and greater than 50%, it is mapped to a significant adjustment level. This embodiment uses this mapping to transform the abstract adjustment range into specific, operable adjustment levels, providing a clear basis for determining the subsequent encryption step size.
[0115] In this embodiment, the base step size is a pre-set baseline step size, and different adjustment levels have different scaling factors. For example, the scaling factor for a slight adjustment level is 0.5, meaning the encryption step size is 0.5 times the base step size; the scaling factor for a moderate adjustment level is 1, meaning the encryption step size is equal to the base step size; and the scaling factor for a large adjustment level is 2, meaning the encryption step size is twice the base step size. Once the adjustment level is determined, the corresponding encryption step size can be obtained by multiplying the base step size by the scaling factor corresponding to that level. This proportional scaling method allows the encryption step size to be adjusted reasonably according to the magnitude of the adjustment. When the adjustment magnitude is large, the encryption step size increases accordingly to quickly adjust the encryption parameters; when the adjustment magnitude is small, the encryption step size is small to ensure the smoothness of the adjustment process and avoid excessive fluctuations in encryption parameters due to excessively large step sizes, which could affect the stability of the system.
[0116] In one embodiment of this application, the encryption parameters are adjusted according to the target encryption strength, the target encryption value, and the encryption step size, including:
[0117] When the encryption parameter is a pseudo-random time offset range parameter, the boundary value of the pseudo-random time offset is gradually adjusted based on the encryption step size, so that the pseudo-random time offset range parameter transitions from the current value to the target encrypted value.
[0118] When the encryption parameter is the round parameter of the encryption algorithm, the number of encryption rounds of the symmetric encryption algorithm is adjusted based on the encryption step size. Specifically, when the encryption strength is increased, the number of encryption rounds is gradually increased based on the encryption step size until the target encryption value is reached; when the encryption strength is decreased, the number of encryption rounds is gradually decreased based on the encryption step size until the target encryption value is reached.
[0119] When adjusting the index bit width parameter of the timing offset table, the index bit width is gradually increased or decreased based on the encryption step size until the target encrypted value is reached.
[0120] In this embodiment, when the encryption parameter is a pseudo-random time offset range parameter, the adjustment process is divided into two parts. First, the boundary values of the pseudo-random time offset are gradually adjusted based on the encryption step size. The pseudo-random time offset range is defined by upper and lower boundary values, and there is a certain difference between the current boundary value and the boundary value corresponding to the target encrypted value. According to the encryption step size, the boundary value is increased or decreased each time. After multiple adjustments, the pseudo-random time offset range parameter smoothly transitions from its current value to the target encrypted value. For example, if the upper boundary value of the current pseudo-random time offset range is 100ms, the upper boundary value corresponding to the target encrypted value is 200ms, and the encryption step size is 20ms, then it will be adjusted 5 times, increasing by 20ms each time, until it reaches 200ms.
[0121] When the encryption parameter is the round parameter of the encryption algorithm, the number of encryption rounds of the symmetric encryption algorithm is adjusted based on the encryption step size. Increasing encryption strength means a higher encryption complexity is required, so the number of encryption rounds is gradually increased in units of the encryption step size. For example, if the current number of encryption rounds is 8, the target encryption value is 16 rounds, and the encryption step size is 2 rounds, the adjustment will be made in 4 steps, increasing by 2 rounds each time, until 16 rounds are reached. Conversely, when the encryption strength decreases, to improve efficiency while maintaining basic security, the number of encryption rounds is gradually reduced based on the encryption step size. Assuming the current number of encryption rounds is 16, the target encryption value is 8 rounds, and the encryption step size is 2 rounds, the adjustment will be made in 4 steps, decreasing by 2 rounds each time, until 8 rounds are reached.
[0122] When adjusting the index bit width parameter of the time-series offset table, the adjustment is also based on the encryption step size. If the target encryption value is greater than the current index bit width, it indicates that the encryption strength needs to be increased. The index bit width will be gradually increased according to the encryption step size until the target encryption value is reached. If the target encryption value is less than the current index bit width, that is, the encryption strength is reduced, the index bit width will be gradually decreased according to the encryption step size until the target encryption value is reached. For example, if the current index bit width is 8 bits, the target encryption value is 12 bits, and the encryption step size is 2 bits, it will be adjusted in two steps, increasing by 2 bits each time, until it reaches 12 bits. If the target encryption value is 4 bits and the encryption step size is 2 bits, it will be adjusted in two steps, decreasing by 2 bits each time, until it drops to 4 bits. Through this adjustment method, the index bit width of the time-series offset table is matched with the target encryption strength and the target encryption value, ensuring the rationality and effectiveness of the encryption parameters.
[0123] In one embodiment of this application, the encrypted transmission method for authorized Roland signals further includes: after the positioning calculation is completed, calculating the absolute difference between the broadcast time timestamp and the transmission time obtained by reverse calculation of the positioning result;
[0124] If the absolute difference is greater than the propagation delay threshold, an alarm will be triggered and the current location result will be discarded.
[0125] In this embodiment, the broadcast time timestamp is the actual broadcast time of the signal recorded in the sensitive parameters, possessing high accuracy and authority. The transmission time derived from the positioning result is calculated by reverse engineering the signal transmission time based on information such as signal propagation time and reception time obtained during the positioning process. By calculating the absolute difference between these two times, the consistency and accuracy of the time information during the positioning process can be intuitively reflected.
[0126] If the absolute difference exceeds the propagation delay threshold, an alarm is triggered and the current positioning result is discarded. The propagation delay threshold is a pre-defined range based on the propagation characteristics of the Loland signal and environmental factors; it represents the maximum allowable deviation between two times under normal circumstances. When the absolute difference exceeds the propagation delay threshold, it indicates an anomaly in the positioning calculation process. For example, the signal may have experienced severe interference during transmission, the positioning algorithm may have errors, or the received signal may not be a legitimate Loland signal. In this case, to ensure the reliability of the positioning result and avoid adverse consequences from using incorrect positioning information, the system will immediately issue an alarm, prompting relevant personnel to investigate, and discard the current positioning result, preventing its use as valid positioning data. This verification step further improves the accuracy and security of the positioning result, providing a more reliable guarantee for the practical application of the Loland signal.
[0127] In one embodiment of this application, the encrypted transmission method for authorized Roland signals further includes: a dynamic parameter adjustment mechanism.
[0128] The transmitting end periodically pushes parameter update instructions to the authorized receiving end through an encrypted signaling channel;
[0129] Temporary adjustment of the pseudo-random number range when abnormal reception behavior is detected;
[0130] Every preset period, both parties synchronously update the iteration parameters of the first key derivation function to enhance anti-cracking capabilities.
[0131] The dynamic parameter adjustment mechanism in this embodiment significantly enhances the security and adaptability of the encrypted transmission system. From a long-term protection perspective, both parties periodically and synchronously update the iterative parameters of the first key derivation function, breaking the risk that fixed parameters can be analyzed and cracked over time. This ensures the key derivation logic is constantly changing dynamically, thus improving security. From an anomaly response perspective, when abnormal reception behavior is detected, the pseudo-random number range is temporarily adjusted, quickly altering the generation logic of the encrypted transmission time. This renders unauthorized parties' attack strategies based on historical patterns ineffective, promptly blocking abnormal attacks. Simultaneously, the transmitting end pushes parameter update instructions through the encrypted signaling channel, ensuring the security of parameter updates and achieving dynamic coordination between the authorized receiving end and the transmitting end. This avoids location failures caused by asynchronous parameters, enabling the system to operate stably even in complex environments, further consolidating the security and reliability of authorized transmission.
[0132] In one embodiment of this application, a method for encrypted transmission of an authorized Roland signal further includes controlling a target receiving end to capture the Roland signal within a preset time capture window, comprising:
[0133] Based on the calibration time and the built-in symmetric key, predict the second pseudo-random time offset corresponding to the current signal period;
[0134] Based on the broadcast timestamp obtained from historical decryption, the reference transmission time of the current signal cycle is predicted by linear extrapolation or cryptographic chain functions.
[0135] The predicted reference transmission time, the predicted second pseudo-random time offset, the signal propagation delay uncertainty, and the clock error of the target receiver are combined to generate an optimized acquisition time window that is much smaller than the preset time acquisition window.
[0136] Signal search and capture are performed within the optimized capture time window.
[0137] This embodiment solves the signal acquisition problem of authorized receivers caused by encryption time offset. Instead of blindly searching the entire window, it uses the unique key and historical information of the authorized receiver to dynamically and accurately predict the occurrence time of the next signal, thereby compressing the acquisition window from the "millisecond-second level" to the "microsecond level", which greatly improves the acquisition speed and receiver sensitivity. This is an original method for achieving efficient synchronization under encryption constraints.
[0138] In one embodiment of this application, the encrypted transmission method for authorized Roland signals further includes:
[0139] At the transmitting end, a pulse phase perturbation factor is generated based on the value of the first pseudo-random time offset through the third key derivation function;
[0140] When generating the Roland signal, a pulse phase perturbation factor is applied to the phase of one or more specified pulses in the Roland pulse group, so that the phase of the specified pulses produces a small deterministic perturbation that is cryptographically associated with the first pseudo-random time offset.
[0141] At the target receiving end, based on the second pseudo-random time offset obtained by decryption, the pulse phase perturbation factor is locally reproduced using the same third key derivation function;
[0142] Before the positioning calculation, the phase of a specified pulse in the received Rowland signal is reverse-corrected using the reproduced pulse phase perturbation factor to eliminate deterministic perturbations.
[0143] This embodiment enhances encryption depth while ensuring positioning accuracy and strengthening the system's anti-interference and anti-spoofing capabilities. From an encryption perspective, a pulse phase perturbation factor is generated based on a first pseudo-random time offset and applied to a specified pulse phase. This gives the Roland signal additional cryptographic association features. Even if an unauthorized party intercepts the signal, they cannot obtain the key to reproduce the perturbation factor, making it difficult to decipher the true information of the signal, further improving the confidentiality of signal transmission. From a positioning accuracy perspective, the target receiver reproduces the perturbation factor using the same key and a third key derivation function, performing reverse correction on the specified pulse phase of the received signal. This completely eliminates the phase deviation caused by deterministic perturbations, preventing perturbations from affecting time measurement and positioning calculations, ensuring that positioning accuracy remains unaffected. Furthermore, the unique phase perturbation feature can serve as a basis for identifying the authenticity of the signal, effectively resisting attacks that forge Roland signals, further enhancing system security and anti-interference capabilities.
[0144] See Figure 2 , Figure 2 This is a schematic diagram of an encrypted transmission system for authorized Roland signals provided in an embodiment of this application. Figure 2 The encrypted transmission system 300 for authorized Roland signals in this embodiment may include one or more processors 301, one or more input devices 302, one or more output devices 303, and one or more memories 304. The processors 301, input devices 302, output devices 303, and memories 304 communicate with each other via a communication bus 305. The memories 304 store computer programs, including program instructions. The processors 301 execute the program instructions stored in the memories 304. Specifically, the processors 301 are configured to invoke the program instructions to execute the encrypted transmission method for authorized Roland signals in the above embodiments.
[0145] It should be understood that, in the embodiments of this application, the processor 301 may be a central processing unit (CPU), or it may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor.
[0146] Input device 302 may include a touchpad, a fingerprint sensor (for collecting the user's fingerprint information and fingerprint orientation information), a microphone, etc., and output device 303 may include a display (LCD, etc.), a speaker, etc.
[0147] The memory 304 may include read-only memory and random access memory, and provides instructions and data to the processor 301. A portion of the memory 304 may also include non-volatile random access memory. For example, the memory 304 may also store device type information.
[0148] In specific implementations, the processor 301, input device 302, and output device 303 described in the embodiments of this application can execute the implementation methods described in any embodiment of the encrypted transmission method for authorized Roland signals provided in the embodiments of this application, or they can execute the implementation methods of the encrypted transmission system for authorized Roland signals described in the embodiments of this application, which will not be repeated here.
[0149] In another embodiment of this application, a computer-readable storage medium is provided. This computer-readable storage medium stores a computer program, which includes program instructions. When executed by a processor, the program instructions implement all or part of the processes in the methods described above. Alternatively, the computer program can instruct related hardware to complete the process. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include any entity or device capable of carrying computer program code, a recording medium, a USB flash drive, a portable hard drive, a magnetic disk, an optical disk, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium, etc.
[0150] The computer-readable storage medium can be an internal storage unit of the encrypted transmission system of the licensed Loran signaling in any of the foregoing embodiments, such as a hard drive or memory of an electronic device. The computer-readable storage medium can also be an external storage device of the licensed Loran signaling encrypted transmission system, such as a plug-in hard drive, SmartMedia Card (SMC), Secure Digital (SD) card, or Flash Card equipped on an electronic device. Furthermore, the computer-readable storage medium can include both internal storage units and external storage devices of the electronic device. The computer-readable storage medium is used to store computer programs and other programs and data required by the electronic device. The computer-readable storage medium can also be used to temporarily store data that has been output or will be output.
[0151] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this application.
[0152] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process of the electronic devices and units described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0153] In the several embodiments provided in this application, it should be understood that the disclosed electronic devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces or units, or it may be an electrical, mechanical, or other form of connection.
[0154] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of the embodiments of this application, depending on actual needs.
[0155] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0156] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method for encrypted transmission of authorized Roland signals, characterized in that, include: The reference transmission time is obtained, and based on preset sensitive parameters and a built-in symmetric key, a first pseudo-random time offset within a preset range is generated through a first key derivation function and a first pseudo-random number generator; wherein, the sensitive parameters include the broadcast time timestamp, and the symmetric key is pre-injected into the transmitter and the target receiver offline; The first pseudo-random time offset is superimposed on the reference transmission time to generate an encrypted transmission time. The transmitter is controlled to send a Roland signal to the target receiver at the encrypted transmission time. The control of the target receiver to capture the Roland signal within a preset time acquisition window includes: predicting the second pseudo-random time offset corresponding to the current signal period based on the calibration time and the built-in symmetric key; predicting the reference transmission time of the current signal period based on the broadcast time timestamp obtained from historical decryption through linear extrapolation or a cryptographic chain function; synthesizing the predicted reference transmission time, the predicted second pseudo-random time offset, the signal propagation delay uncertainty, and the clock error of the target receiver to generate an optimized acquisition time window smaller than the preset time acquisition window; and performing signal search and acquisition within the optimized acquisition time window. The target receiver is controlled to generate a second pseudo-random time offset based on the built-in symmetric key and local clock, and the observed signal transmission time reference value is corrected based on the second pseudo-random time offset to complete the positioning calculation and obtain the positioning result. Before the encrypted transmission time control transmitter sends the Roland signal to the target receiver, the method further includes: Based on the value of the first pseudo-random time offset, a pulse phase perturbation factor is generated through the third key derivation function; when generating the Roland signal, the pulse phase perturbation factor is applied to the phase of one or more specified pulses of the Roland pulse group, so that the phase of the specified pulses produces a deterministic perturbation that is cryptographically associated with the first pseudo-random time offset. At the target receiver, based on the second pseudo-random time offset obtained from decryption, the pulse phase perturbation factor is locally reproduced using the same third key derivation function. Before the positioning calculation, the phase of the specified pulse of the received Rowland signal is reverse-corrected using the reproduced pulse phase perturbation factor to eliminate deterministic perturbations.
2. The encrypted transmission method for authorized Roland signals according to claim 1, characterized in that, The location calculation is completed by correcting the observed signal transmission time reference value based on the second pseudo-random time offset, and the location result is obtained, including: The local clock is calibrated based on a clock synchronization protocol to obtain the calibration time. Based on the calibration time and the built-in symmetric key, a second pseudo-random time offset is generated through a second key derivation function and a second pseudo-random number generator. The observed signal transmission time reference value is corrected using the second pseudo-random time offset. The positioning calculation is completed based on the corrected signal transmission time reference value, and the positioning result is obtained.
3. The encrypted transmission method for authorized Roland signals according to claim 2, characterized in that, The calibration of the local clock based on the clock synchronization protocol includes: Obtain time information from at least two time sources; The standard deviation of clock errors for each time source is calculated based on a predefined clock error model. Assign a trust weight to each time source based on the standard deviation; The time information from each time source is weighted and fused based on the trust weight to obtain the calibration time. The local clock is calibrated based on the calibration time.
4. The encrypted transmission method for authorized Roland signals according to claim 1, characterized in that, Based on preset sensitive parameters and a built-in symmetric key, a first pseudo-random time offset within a preset range is generated through a first key derivation function and a first pseudo-random number generator, including: Based on the aforementioned sensitive parameters and the built-in symmetric key, a seed key is generated through the first key derivation function; Using the seed key as input to the first pseudo-random number generator, a predefined time offset table is queried to generate a first pseudo-random time offset within a preset range; wherein, the time offset table defines a mapping relationship between the index bit width and the time offset value, and the index bit width is configurable.
5. The encrypted transmission method for authorized Roland signals according to claim 1, characterized in that, Also includes: The encryption parameters are adjusted based on environmental threat indicators to obtain the target encryption parameters; Update the range parameter of the first pseudo-random number generator or the round parameter of the symmetric encryption algorithm based on the target encryption parameter; The environmental threat index is determined based on the security level determined by a preset geographical location risk rule base.
6. The encrypted transmission method for authorized Roland signals according to claim 5, characterized in that, The process of adjusting the encryption parameters based on environmental threat indicators to obtain the target encryption parameters includes: The direction and magnitude of the adjustment of the encryption parameters are determined based on the environmental threat indicators. The target encryption strength and target encryption value of the encryption parameters are determined based on the adjustment direction of the encryption parameters; The encryption step size of the target encrypted value is determined based on the adjustment range of the encryption parameters; Based on the target encryption strength, target encryption value, and encryption step size, the encryption parameters are adjusted to obtain the target encryption parameters.
7. The encrypted transmission method for authorized Roland signals according to claim 6, characterized in that, The adjustment direction includes: a first adjustment direction and a second adjustment direction; The determination of the target encryption strength and target encryption value based on the adjustment direction of the encryption parameters includes: When the adjustment direction is the first adjustment direction, the target encryption strength is increased to the preset highest security level, and the target encryption value is set to the upper limit of the highest security level; When the adjustment direction is the second adjustment direction, the target encryption strength is reduced to a preset basic security level, and the target encryption value is set to the recommended value of the basic security level.
8. The encrypted transmission method for authorized Roland signals according to claim 6, characterized in that, The method of determining the encryption step size based on the adjustment range of encryption parameters includes: The adjustment range is mapped to a preset adjustment level; The encryption step size is generated by scaling the base step size value proportionally according to the adjustment level. The adjustment level corresponds to the scaling factor of the base step size value.
9. An encrypted transmission system for authorized Roland signals, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the method as described in any one of claims 1 to 8.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method as described in any one of claims 1 to 8.
Citation Information
Patent Citations
System And Methods For A Private eLoran Service
US20190377055A1