Beidou navigation authentication receiving method and device

By combining identity encryption and broadcast encryption technologies, simplifying public key management, and introducing a revocable mechanism, the problem of unauthorized users stealing and tampering with navigation messages in the BeiDou navigation system has been solved, thereby improving the security and anti-interference capabilities of navigation messages.

CN121099321APending Publication Date: 2025-12-09Chinese People's Liberation Army Cyberspace Force Information Engineering University
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511325720.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-17
Publication Date
2025-12-09

AI Technical Summary

Technical Problem

When faced with a large number of users, the existing BeiDou Navigation Satellite System cannot promptly revoke the decryption privileges of unauthorized users, leading to unauthorized users stealing and tampering with navigation messages, thus affecting the normal operation of the satellite communication system.

Method used

The system employs identity-based encryption and broadcast encryption technologies, combines user identity information to generate public keys, simplifies public key management, and introduces a revocable mechanism. Upgrade keys are periodically distributed through a key generation center to revoke user decryption privileges. A fixed-sequence dynamic arrangement strategy for authentication messages is designed to optimize the transmission process of navigation messages.

Benefits of technology

It improves the encryption efficiency of navigation messages, prevents unauthorized users from stealing and tampering with them, enhances the anti-deception and interference capabilities of the BeiDou system, and ensures the integrity and security of navigation messages.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121099321A_ABST
    Figure CN121099321A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a Beidou navigation authentication receiving method and device. A specific embodiment of the method comprises the following steps: generating a system public parameter and a master key according to a security parameter and the maximum number of authorized users; inputting the obtained user identity number, the system public parameter and the master key into a key generation algorithm to obtain a user private key, and transmitting the user private key to the user through a secure channel; comparing the navigation message hash value with a preset hash value to obtain a comparison result; and in response to determining that the comparison result represents that comparison is consistent, determining the navigation message as a navigation message signal which is not tampered. According to the embodiment, the public key management process is simplified, and the encryption efficiency is improved. The decryption authority of the illegal user can be cancelled in time, and the illegal user is effectively prevented from stealing and tampering the Beidou navigation message.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present disclosure relate to the field of computer technology, in particular to a Beidou navigation authentication receiving method and device. BACKGROUND

[0002] Beidou civilian navigation signals (especially B2b signals) are vulnerable to spoofing attacks in an open environment. Attackers can falsify navigation messages, tamper with positioning and timing results, causing user receivers to output incorrect information, and threatening critical infrastructure such as transportation safety, financial synchronization, and communication systems. Beidou navigation authentication receiving is a technology for authenticating Beidou navigation. Currently, when authenticating Beidou navigation, the commonly used method is to achieve Beidou navigation authentication receiving through asymmetric digital signature.

[0003] However, the inventors have found that when the above method is used, the following technical problems often occur:

[0004] During the transmission of the navigation message, as the number of users increases, the decryption rights of illegal users cannot be revoked in time, resulting in the theft and tampering of Beidou navigation messages by illegal users. Communication interruption and positioning errors may occur during demodulation, seriously affecting the operation of the satellite communication system. SUMMARY

[0005] The summary part of the present disclosure is used to introduce the concepts in a brief form, which will be described in detail in the specific embodiments part. The summary part of the present disclosure is not intended to identify key or essential features of the claimed technical solutions, nor is it intended to limit the scope of the claimed technical solutions.

[0006] Some embodiments of the present disclosure propose a Beidou navigation authentication receiving method and device to solve the technical problems mentioned in the background part.

[0007] In a first aspect, some embodiments of this disclosure provide a BeiDou navigation authentication receiving method, which includes: generating system public parameters and a master key based on security parameters and a maximum number of authorized users; inputting the obtained user identification number, the aforementioned system public parameters, and the aforementioned master key into a key generation algorithm to obtain a user private key, and transmitting the aforementioned user private key to a user through a secure channel; generating an encryption key and a header file based on the aforementioned maximum number of authorized users; encrypting a navigation message based on the aforementioned encryption key to generate an encrypted navigation message, wherein the aforementioned navigation message is a signal used to transmit navigation information; modulating the aforementioned encrypted navigation message with a carrier wave to generate a modulated navigation message signal; determining a navigation message hash value based on the aforementioned modulated navigation message signal; comparing the aforementioned navigation message hash value with a preset hash value to obtain a comparison result; and, in response to determining that the aforementioned comparison result indicates a consistent comparison, identifying the aforementioned navigation message as an untampered navigation message signal.

[0008] Secondly, some embodiments of this disclosure provide a BeiDou navigation authentication receiving device, comprising: a first generation unit configured to generate system public parameters and a master key based on security parameters and a maximum number of authorized users; an input unit configured to input an acquired user identification number, the aforementioned system public parameters, and the aforementioned master key into a key generation algorithm to obtain a user private key, and to transmit the aforementioned user private key to a user through a secure channel; a second generation unit configured to generate an encryption key and a header file based on the aforementioned maximum number of authorized users; and an encryption unit configured to perform encryption on the navigation based on the aforementioned encryption key. The message is encrypted to generate an encrypted navigation message, wherein the navigation message is a signal used to transmit navigation information; a modulation unit is configured to modulate the encrypted navigation message with a carrier wave to generate a modulated navigation message signal; a first determining unit is configured to determine a navigation message hash value based on the modulated navigation message signal; a comparison unit is configured to compare the navigation message hash value with a preset hash value to obtain a comparison result; a second determining unit is configured to determine the navigation message as an untampered navigation message signal in response to determining that the comparison result indicates a match.

[0009] Thirdly, some embodiments of this disclosure provide an electronic device, including: one or more processors; and a storage device having one or more programs stored thereon, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the method described in any implementation of the first aspect above.

[0010] Fourthly, some embodiments of this disclosure provide a computer-readable medium having a computer program stored thereon, wherein the program, when executed by a processor, implements the method described in any of the implementations of the first aspect above.

[0011] The various embodiments disclosed herein have the following beneficial effects: Specifically, the BeiDou navigation authentication and reception method of some embodiments of this disclosure combines identity-based encryption technology and broadcast encryption technology, using the user's identity information as the public key, simplifying the public key management process and improving encryption efficiency. Simultaneously, by introducing a revocable mechanism, the decryption privileges of unauthorized users can be revoked in a timely manner, effectively preventing unauthorized users from stealing and tampering with BeiDou navigation messages (B2b), providing strong technical support for the secure application of the BeiDou system. Based on the revocation mechanism of identity encryption and identity-based broadcast encryption, revocable identity-based broadcast encryption schemes for GNSS CNAV with low parameter extension are designed using elliptic curve bilinear mapping. A systematic study of the key indirect revocation mechanism in the system is conducted, namely, the key generation center periodically distributes upgrade keys, preventing revoked users from using the upgrade keys to calculate decryption keys, thereby revoking the user's decryption privileges and improving the anti-spoofing and interference capabilities of navigation messages. This study investigates the B1C authentication message arrangement strategy for BeiDou civilian satellite-based augmentation signals. A fixed-time dynamic arrangement strategy for adding authentication messages is designed. By reducing the broadcast frequency or length of fast-change correction numbers, the bandwidth constraints caused by the addition of authentication messages are alleviated. A fixed-time dynamic arrangement strategy based on the optimization of fast-change correction number messages for BeiDou civilian satellite-based augmentation signals B1C is proposed. The design scheme is evaluated through simulation based on the extrapolation accuracy level of measured fast-change correction numbers. Attached Figure Description

[0012] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and elements are not necessarily drawn to scale.

[0013] Figure 1 This is a flowchart of some embodiments of the BeiDou navigation authentication and reception method according to this disclosure;

[0014] Figure 2 This is a schematic diagram of the structure of some embodiments of the Beidou navigation authentication receiver according to this disclosure;

[0015] Figure 3 This is a schematic diagram of the structure of an electronic device suitable for implementing some embodiments of the present disclosure;

[0016] Figure 4 This is a flowchart of an implementation of a BeiDou navigation authentication and reception method according to some embodiments of this disclosure. Detailed Implementation

[0017] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0018] It should also be noted that, for ease of description, only the parts relevant to the invention are shown in the accompanying drawings. Unless otherwise specified, the embodiments and features described in this disclosure can be combined with each other.

[0019] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.

[0020] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".

[0021] The names of messages or information exchanged between multiple devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of such messages or information.

[0022] This disclosure will now be described in detail with reference to the accompanying drawings and embodiments.

[0023] Figure 1 A flowchart 100 of some embodiments of the BeiDou navigation authentication receiving method according to this disclosure is shown. The BeiDou navigation authentication receiving method includes the following steps:

[0024] Step 101: Generate system public parameters and master key based on security parameters and the maximum number of authorized users.

[0025] In some embodiments, the executing entity of the BeiDou navigation authentication receiving method (e.g., a computing device) can generate system public parameters and a master key based on security parameters and the maximum number of authorized users.

[0026] Here, the key distribution authority (KGC) is responsible for executing the system establishment algorithm. First, input the security parameter λ and the maximum number of authorized users in a single encryption operation. This refers to the maximum number of authorized users. Given the total number of members N and the maximum number of authorized users m, a hash function H is defined to map each user's identity ID. Random elements are selected from the relevant set to calculate system parameters, and finally, the master key MSK and the system public parameter PP are output.

[0027] Optionally, the aforementioned executing entity can generate system public parameters and master key based on security parameters and the maximum number of authorized users through the following steps:

[0028] The first step is to generate a bilinear group from the safety parameters to obtain the bilinear group.

[0029] Here, given the maximum number of authorized users, m, KGC invokes the bilinear group algorithm. Generate Type-3 bilinear group: ,in There are three cyclic groups. For the target group, They are The generator, e, is a bilinear mapping: It satisfies bilinearity, nondegeneracy, and computability. If N is a bilinear group of order N, and N has only one prime factor p (i.e., N = p), then it is called a bilinear group of order N-prime. .

[0030] The second step involves selecting two preset dimension vectors and random elements to determine the system parameters, based on the maximum number of authorized users and the total number of users.

[0031] Here, given the maximum value m of the authorization set, two m+1 dimensional vectors are randomly selected. and Select random elements and determine system parameters.

[0032] The third step is to generate the system public parameters and master key based on the system parameters.

[0033] Here, the system master key is set according to the system parameters. The system publicly released the parameter PP. Here, the master key is output. and The master key is secretly kept by the KGC and used to calculate private keys for users. The PP is publicly available within the system for users to use for encryption and decryption. For example, the aforementioned security parameters could refer to the public key length or the order of the bilinear group prime number.

[0034] Step 102: Input the obtained user identification number, the above-mentioned system public parameters, and the above-mentioned master key into the key generation algorithm to obtain the user private key, and transmit the above-mentioned user private key to the user through a secure channel.

[0035] In some embodiments, the executing entity may input the obtained user identification number, the system public parameters, and the master key into the key generation algorithm to obtain the user private key, and transmit the user private key to the user through a secure channel.

[0036] Here, the above key generation algorithm is: Given a user's identity number, i.e., ID, KGC selects a random number. and m random tags: Calculate the user's private key Among them, the above This is the private key. The complete subtree algorithm is then called to store the user's identity information in the leaf nodes, and the corresponding information for that node is found in the state information ST. KGC updates ST and returns the user's private key to the user via a secure channel.

[0037] Optionally, the aforementioned executing entity may, through the following steps, input the obtained user identification number, the aforementioned system public parameters, and the aforementioned master key into the key generation algorithm to obtain the user's private key, and then transmit the aforementioned user's private key to the user through a secure channel:

[0038] The first step is to use the user's identification number, the publicly available system parameters, and the master key to generate a random number, which is then selected by the user.

[0039] As an example, when a user requests a private key, the aforementioned execution entity can have KGC select a random number r and m random tags based on the user's identity ID.

[0040] The second step is to select random numbers for the above users to verify them and obtain the verification results, where the verification results represent whether the verification is successful or failed.

[0041] The third step is to determine the user's private key in response to the above verification result indicating that the verification is successful, and to transmit the above user's private key to the user through a secure channel.

[0042] As an example, the aforementioned execution entity calculates the user's private key based on the system master key MSK and the public parameter PP. In revocable systems, the private key generation algorithm is SKGen. This process is also handled by KGC. Given a user's identity ID, KGC first randomly generates m key tags. Next, the assignment algorithm for the complete subtree is called to randomly select an unassigned leaf node. And store the identity information ID in that leaf node. Then, for each node... Find the random group element corresponding to node θ from the state information ST. If not defined, it will be randomly selected. And store. Here, θ represents the node searched in ST, and 1 and 2 are random group elements. The two parameter numbers in the text.

[0043] Finally, select randomly. And calculate the parameters: Here, g2 is a generator of the bilinear pair G. KGC updates the state information ST and returns the private key to the user via a secure channel. .

[0044] Step 103: Generate encryption keys and header files based on the maximum number of authorized users mentioned above.

[0045] In some embodiments, the aforementioned executing entity may generate encryption keys and header files based on the maximum number of authorized users.

[0046] As an example, the aforementioned execution entity can use encryption algorithms. It employs a key encapsulation mechanism (KEM) and inputs a set of authorized users. ,in The algorithm output is ( , ),in The key is used to encrypt the message. The broadcast content is encrypted using symmetric encryption, thus obtaining the ciphertext. This is called a header file and is responsible for recovering the message encryption key. .

[0047] Step 104: Encrypt the navigation message according to the above encryption key to generate an encrypted navigation message, wherein the above navigation message is a signal used to transmit navigation information.

[0048] In some embodiments, the execution entity may encrypt the navigation message according to the encryption key to generate an encrypted navigation message, wherein the navigation message is a signal used to transmit navigation information.

[0049] As an example, the aforementioned executing entity can use broadcast encryption (BE) to encrypt the navigation message using the aforementioned encryption key, thereby generating an encrypted navigation message. Broadcast encryption (BE) is a cryptographic technique that broadcasts encrypted data to multiple users over an insecure channel. Its core principle is to use a specific encryption algorithm to enable the broadcaster to encrypt information and send it to multiple users. Only authorized users can decrypt and obtain the plaintext; unauthorized users, even if they obtain the ciphertext, cannot decrypt its content. The decapsulation algorithm is Decap(T,S,Hdr, The algorithm is a deterministic algorithm performed by the decryptor, and the input is the decryption key for a user ID that has not been revoked within a time period T. And the corresponding ciphertext header file Hdr of the authorized set S. If the user's identity ID∈S, that is, the user is an authorized user, the algorithm outputs the message encryption key K; otherwise, the algorithm outputs ┴ to indicate decryption failure.

[0050] Step 105: Modulate the encrypted navigation message with the carrier wave to generate a modulated navigation message signal.

[0051] In some embodiments, the aforementioned execution entity may perform signal modulation on the encrypted navigation message and the carrier wave to generate a modulated navigation message signal.

[0052] As an example, the aforementioned executing entity can... The encrypted navigation message is modulated with a carrier wave to generate a modulated navigation message signal. Here, t represents the signal transmission time, and j represents the j-th satellite. Indicates the signal amplitude. Indicates the ranging code signal. This represents the data code signal modulated onto the ranging code. Indicates the carrier frequency of signal B1. Indicates the initial phase.

[0053] Step 106: Determine the navigation message hash value based on the modulated navigation message signal described above.

[0054] In some embodiments, the aforementioned execution entity may determine the navigation message hash value based on the aforementioned modulated navigation message signal.

[0055] Optionally, the aforementioned executing entity may determine the navigation message hash value based on the modulated navigation message signal using the following steps:

[0056] The first step is to demodulate the modulated navigation message signal in response to the confirmation that it has been received, so as to obtain the satellite number and navigation message data.

[0057] As an example, the aforementioned implementing entity can demodulate the modulated navigation message signal using a modem to obtain the satellite number and navigation message data.

[0058] The second step is to generate a verification key based on the aforementioned satellite number, navigation message data, and publicly available system parameters.

[0059] As an example, the aforementioned implementing entity can use the satellite number as input, combine it with publicly available system parameters and the aforementioned navigation message data, and use an identity-based encryption algorithm to generate a verification key.

[0060] The third step is to match and verify the above verification key with the user's private key to obtain the matching verification result, where the above matching verification result represents the normal matching verification result and the abnormal matching verification result.

[0061] As an example, the aforementioned executing entity can compare the verification key with the user's private key to obtain a matching verification result.

[0062] Fourth step: In response to determining that the above matching verification result represents a normal matching verification result, determine the hash value of the above navigation message to obtain the navigation message hash value.

[0063] As an example, the aforementioned executing entity uses a hash algorithm to determine the hash value of the navigation message, thus obtaining the navigation message hash value.

[0064] Step 107: Compare the above navigation message hash value with the preset hash value to obtain the comparison result.

[0065] In some embodiments, the execution entity may compare the navigation message hash value with a preset hash value to obtain a comparison result.

[0066] Here, the aforementioned preset hash value is a hash value that is pre-set or obtained through other secure channels. The preset hash value can be calculated by the sender using the same hash algorithm before the navigation message is sent, and then sent to the receiver in a secure manner such as digital signature or secure channel transmission.

[0067] As an example, the aforementioned executing entity can encrypt and transmit the hash value along with the navigation message, and the receiving end can decrypt it to obtain the hash value and the navigation message. The hash value of the decrypted navigation message is then determined. , and the hash value obtained from decryption Compare them.

[0068] Step 108: In response to determining that the above comparison results indicate a consistent comparison, the above navigation message is identified as an untampered navigation message signal.

[0069] In some embodiments, the execution entity may determine the navigation message as an untampered navigation message signal in response to determining that the comparison result indicates a consistent comparison.

[0070] Here, if the above With the above Complete consistency indicates that the navigation message has not been tampered with during transmission and its integrity is guaranteed.

[0071] Optionally, after step 108 above, the method further includes:

[0072] In response to the determination that the above comparison results indicate an inconsistency, the above navigation message is identified as a tampered navigation message signal.

[0073] Here, if the above With the above Inconsistency indicates that the navigation message has been tampered with or the data has been corrupted, thus compromising the integrity of the navigation message.

[0074] Further reference Figure 2 As an implementation of the methods shown in the above figures, this disclosure provides some embodiments of a BeiDou navigation authentication receiving device, which are similar to... Figure 2 Corresponding to the method embodiments shown, the BeiDou navigation authentication receiver can be specifically applied to various electronic devices.

[0075] like Figure 2 As shown, some embodiments of the BeiDou navigation authentication receiving device 200 include: a first generation unit 201, an input unit 202, a second generation unit 203, an encryption unit 204, a modulation unit 205, a first determination unit 206, a comparison unit 207, and a second determination unit 208. The first generation unit 201 is configured to generate system public parameters and a master key based on security parameters and the maximum number of authorized users; the input unit 202 is configured to input the acquired user identification number, the aforementioned system public parameters, and the aforementioned master key into a key generation algorithm to obtain a user private key, and to transmit the aforementioned user private key to the user through a secure channel; the second generation unit 203 is configured to generate an encryption key and a header file based on the aforementioned maximum number of authorized users; the encryption unit 204 is configured to encrypt the navigation message according to the aforementioned encryption key to generate an encrypted navigation message. The navigation message is a signal used to transmit navigation information; the modulation unit 205 is configured to modulate the encrypted navigation message with a carrier wave to generate a modulated navigation message signal; the first determining unit 206 is configured to determine the navigation message hash value based on the modulated navigation message signal; the comparison unit 207 is configured to compare the navigation message hash value with a preset hash value to obtain a comparison result; the second determining unit 208 is configured to determine the navigation message as an untampered navigation message signal in response to determining that the comparison result indicates a consistent comparison.

[0076] It is understandable that the various units recorded in the Beidou navigation authentication receiver 200 are related to the reference... Figure 1 The steps in the described method correspond to each other. Therefore, the operations, features, and beneficial effects described above for the method also apply to the Beidou navigation authentication receiver 200 and the units contained therein, and will not be repeated here.

[0077] The following is for reference. Figure 3It illustrates a schematic diagram of the structure of an electronic device (e.g., a computing device) suitable for implementing some embodiments of the present disclosure. Figure 3 The electronic device shown is merely an example and should not be construed as limiting the functionality or scope of the embodiments of this disclosure. Figure 3 As shown, the computer device includes a processor, memory, and a network interface connected via a system bus. The memory may include a non-volatile storage medium and internal memory. The non-volatile storage medium may store an operating system and a computer program. The computer program includes program instructions that, when executed, cause the processor to perform any of the methods described above. The processor provides computational and control capabilities to support the operation of the entire computer device. The internal memory provides an environment for the execution of the computer program in the non-volatile storage medium; when executed by the processor, the computer program causes the processor to perform any of the methods described above. The network interface is used for network communication, such as sending assigned tasks. Those skilled in the art will understand that... Figure 3 The structure shown is merely a block diagram of a portion of the structure related to the present disclosure and does not constitute a limitation on the computer device to which the present disclosure is applied. A specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0078] It should be understood that the processor can be a Central Processing Unit (CPU), but it can also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Among these, a general-purpose processor can be a microprocessor or any conventional processor.

[0079] In one embodiment, the processor is configured to run a computer program stored in a memory to perform the following steps: generating system public parameters and a master key based on security parameters and the maximum number of authorized users; inputting the acquired user identification number, the system public parameters, and the master key into a key generation algorithm to obtain a user private key, and transmitting the user private key to the user through a secure channel; generating an encryption key and a header file based on the maximum number of authorized users; encrypting the navigation message based on the encryption key to generate an encrypted navigation message, wherein the navigation message is a signal used to transmit navigation information; modulating the encrypted navigation message with a carrier wave to generate a modulated navigation message signal; determining a navigation message hash value based on the modulated navigation message signal; comparing the navigation message hash value with a preset hash value to obtain a comparison result; and, in response to determining that the comparison result indicates a match, identifying the navigation message as an untampered navigation message signal.

[0080] This disclosure also provides a computer-readable storage medium storing a computer program, which includes program instructions. When the program instructions are executed, the method implemented can be referred to the various embodiments of the BeiDou navigation authentication receiving method disclosed above.

[0081] The aforementioned computer-readable storage medium may be an internal storage unit of the computer device described in the foregoing embodiments, such as the hard disk or memory of the computer device. Alternatively, the aforementioned computer-readable storage medium may be an external storage device of the computer device, such as a plug-in hard disk, SmartMedia Card (SMC), Secure Digital (SD) card, or Flash Card equipped on the computer device.

[0082] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or system that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or system. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or system that includes that element.

[0083] The above description is merely a selection of preferred embodiments of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of the invention involved in the embodiments of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described inventive concept. For example, technical solutions formed by substituting the above-described features with (but not limited to) technical features with similar functions disclosed in the embodiments of this disclosure.

Claims

1. A BeiDou navigation authentication receiving method, characterized in that, include: Generate system public parameters and master key based on security parameters and the maximum number of authorized users; The obtained user identification number, the system public parameters, and the master key are input into the key generation algorithm to obtain the user private key, and the user private key is transmitted to the user through a secure channel; Generate encryption keys and header files based on the maximum number of authorized users; The navigation message is encrypted according to the encryption key to generate an encrypted navigation message, wherein the navigation message is a signal used to transmit navigation information; The encrypted navigation message is modulated with a carrier wave to generate a modulated navigation message signal; The navigation message hash value is determined based on the modulated navigation message signal; The hash value of the navigation message is compared with a preset hash value to obtain the comparison result; In response to determining that the comparison result indicates a consistent comparison, the navigation message is identified as an untampered navigation message signal.

2. The method according to claim 1, characterized in that, The process of generating system public parameters and master key based on security parameters and the maximum number of authorized users includes: Bilinear group generation is performed on the safety parameters to obtain the bilinear group; To determine the system parameters, two preset dimension vectors and random elements are selected, considering the maximum number of authorized users and the total number of users. Based on the system parameters, generate the system public parameters and master key.

3. The method according to claim 1, characterized in that, The step of inputting the obtained user identification number, the system public parameters, and the master key into the key generation algorithm to obtain the user private key, and transmitting the user private key to the user through a secure channel, includes: The user's identification number is used to generate a random number by combining the system's public parameters and the master key; A random number is selected for the user for verification, and a verification result is obtained, wherein the verification result represents whether the verification is successful or failed; In response to determining that the verification result indicates that the verification is successful, the user selects a random number as the user's private key, and transmits the user's private key to the user through a secure channel.

4. The method according to claim 1, characterized in that, The method further includes: In response to determining that the comparison result indicates a mismatch, the navigation message is identified as a tampered navigation message signal.

5. The method according to claim 1, characterized in that, Determining the navigation message hash value based on the modulated navigation message signal includes: In response to determining that the modulated navigation message signal has been received, the modulated navigation message signal is demodulated to obtain the satellite number and navigation message data; A verification key is generated based on the satellite number, the navigation message data, and the publicly available system parameters; The verification key is matched and verified with the user's private key to obtain a matching verification result, wherein the matching verification result represents a normal matching verification result and an abnormal matching verification result; In response to determining that the matching verification result represents a normal matching verification result, the hash value of the navigation message is determined, and the navigation message hash value is obtained.

6. A Beidou navigation authentication receiver, characterized in that, include: The first generation unit is configured to generate system public parameters and master key based on security parameters and the maximum number of authorized users; The input unit is configured to input the acquired user identification number, the system public parameters, and the master key into the key generation algorithm to obtain the user private key, and to transmit the user private key to the user through a secure channel; The second generation unit is configured to generate encryption keys and header files based on the maximum number of authorized users; An encryption unit is configured to encrypt a navigation message according to the encryption key to generate an encrypted navigation message, wherein the navigation message is a signal used to transmit navigation information; A modulation unit is configured to modulate the encrypted navigation message with a carrier wave to generate a modulated navigation message signal. The first determining unit is configured to determine the navigation message hash value based on the modulated navigation message signal; The comparison unit is configured to compare the navigation message hash value with a preset hash value to obtain a comparison result; The second determining unit is configured to determine the navigation message as an untampered navigation message signal in response to determining that the comparison result indicates a match.

7. An electronic device, characterized in that, include: One or more processors; A storage device on which one or more programs are stored; When the one or more programs are executed by the one or more processors, the one or more processors implement the method as described in any one of claims 1 to 5.

8. A computer-readable medium, characterized in that, It stores a computer program thereon, wherein the computer program, when executed by a processor, implements the method as described in any one of claims 1 to 5.