Bidirectional authentication method for Beidou global short message communication
By introducing a two-way authentication method into the BeiDou global short message communication system, user terminals and satellites can verify each other's identities, solving the problem that satellites and user terminals cannot identify each other's identities, achieving a secure and reliable communication process, and reducing protocol overhead and latency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-17
- Publication Date
- 2026-04-14
AI Technical Summary
In the current technology, satellites and user terminals in the BeiDou global short message communication system cannot effectively identify each other's true identities, which poses a risk of being deceived.
By introducing a two-way authentication method into the BeiDou global short message communication system, the user terminal authenticates the MEO satellite and performs information exchange authentication through spreading codes and hash algorithms. The satellite also authenticates the user terminal, ensuring the legitimacy of both parties in the communication.
It achieves two-way authentication between satellites and user terminals, ensuring the security and legitimacy of communication, and reducing the protocol overhead and increased latency caused by satellite visibility switching.
Smart Images

Figure CN121865267A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a two-way authentication method for BeiDou global short message communication, belonging to the field of navigation satellite technology. Background Technology
[0002] The BeiDou-3 satellite navigation system has expanded its short message communication service from regional to global coverage, primarily conducting trial services for users in spacecraft and search and rescue applications. The BeiDou-3 global short message service includes inter-satellite transmission networks for MEO and IGSO satellites. MEO satellites equipped with short message communication payloads serve as uplink access satellites for users, receiving L-band uplink inbound signals transmitted by terminals as the entry point for inbound information, meeting the requirements of dual coverage at low elevation angles and single coverage at high elevation angles. Outbound information is broadcast via B2b signals from MEO and IGSO satellites.
[0003] Because MEO satellites and ground control stations located within my country lack continuous observation capabilities, inter-satellite links are required for information relay. The inbound information flow is as follows: overseas user terminal to overseas MEO satellite to inter-satellite link to visible BeiDou satellites within China, and then to the central station. The outbound information flow is as follows: central station to visible BeiDou satellites within China to inter-satellite link to overseas MEO satellites, and then to overseas user terminal. Due to the mutual movement of satellites and users, the MEO satellites accessed by users differ at different times. Similarly, there is the issue of additive switching between users and satellites during a single communication session; that is, users may transmit inbound signals through different MEO satellites or receive outbound signals from different MEO satellites.
[0004] Currently, there is no authentication method for the interface between users and satellites, which poses a risk that satellites and user terminals may not be able to identify the true identities of user terminals and satellites, and may be deceived. Summary of the Invention
[0005] The technical problem to be solved by the present invention is to overcome the shortcomings of the prior art and provide a two-way authentication method for BeiDou global short message communication, which enables satellites and user terminals to authenticate each other and ensures the legitimacy of satellites and terminals participating in the communication.
[0006] The objective of this invention is achieved through the following technical solutions: In a first aspect, the present invention provides a two-way authentication method for BeiDou global short message communication, which, for initial access authentication, includes: (1) The user terminal receives the downlink signal of the MEO satellite of the Beidou system and authenticates the identity of the MEO satellite; (2) If authentication is successful, the user terminal selects the MEO satellite as the access satellite; (3) Calculate the spreading code sequence number based on the access satellite ID and time, select the corresponding spreading code from the sequence number pool, and arrange the uplink signal frames; (4) The user terminal uses the corresponding spreading code to send inbound information to two or more satellites; (5) The MEO satellite receives signals from user terminals, calculates the on-board spreading code using the time-varying spreading code method, and uses it to receive signals transmitted by user terminals; (6) After demodulating the signal, the MEO satellite obtains the content of the information frame and performs authentication; (7) Query the inbound sequence number corresponding to the user ID, and determine whether it is a duplicate frame. If it is, discard it; otherwise, receive the frame and set the inbound sequence number on the satellite to the inbound sequence number in the received frame. At this point, the MEO satellite completes the authentication and broadcasts the confirmation frame through the B2b signal. (8) When the user terminal receives more than one confirmation frame, it selects the MEO satellite that received the confirmation first as the access satellite and completes the subsequent data transmission.
[0007] Secondly, this invention provides a two-way authentication method for BeiDou global short message communication, which includes authentication after the satellite and user visibility relationship is switched, comprising: (1) The navigation downlink signal contains the orbital elements of the satellite. When the visibility relationship between the user terminal and the satellite is about to change, the user terminal sends a handover request to the current satellite. (2) The current satellite sends the user terminal information to the target satellite for handover. The information includes the user terminal ID, the on-board entry number and the key K1. (3) The current satellite will send the relevant information of the target satellite to the user terminal. The information includes key K1 and the PRN number of the target satellite to be switched. (4) The user terminal generates the initial phase of the spreading code based on the target switching satellite PRN number, BeiDou time week count and intra-week seconds calculation; (5) The user terminal constructs an information authentication code based on the key K1 and a hash algorithm; (6) The user terminal calculates the spreading code sequence number used for the uplink signal; (7) The satellite receives signals from the user terminal, calculates the on-board spreading code using the time-varying method of spreading code, and uses it to receive signals transmitted by the user terminal; (8) After the satellite demodulates the signal, it obtains the content of the information frame and performs authentication; (9) Query the inbound sequence number corresponding to this user ID and determine whether it is a duplicate frame. If it is, discard it; otherwise, receive the frame and set the satellite inbound sequence number to the inbound sequence number in the received frame. At this point, the satellite completes the authentication and broadcasts the confirmation frame through the B2b signal. (10) The user terminal receives the confirmation frame, realizes the satellite switching, and completes the subsequent data transmission.
[0008] Compared with the prior art, the present invention has the following advantages: The method of this invention enables satellites and user terminals to authenticate each other, ensuring the legitimacy of satellites and terminals participating in communication. The method of this invention is closely integrated with the BeiDou-3 global short message service process, which enhances security. It also takes into account the problem of visibility relationship switching caused by the mutual movement of satellites and users. Through inter-satellite cooperation, it avoids the problems of large protocol overhead and increased latency caused by visibility switching. Attached Figure Description
[0009] Figure 1 This is a diagram of the downlink frame structure.
[0010] Figure 2 This is the uplink signal frame format.
[0011] Figure 3 For participation in authentication data.
[0012] Figure 4 For users' first access authentication process.
[0013] Figure 5 The authentication process after the satellite's visibility relationship with the user is switched. Detailed Implementation
[0014] To make the objectives, technical solutions, and advantages of the present invention clearer, the embodiments of the present invention will be described in further detail below with reference to the accompanying drawings.
[0015] A two-way authentication method for BeiDou global short message communication includes: I. Initial Access Authentication Process (1) The user terminal receives downlink signals from the MEO satellite of the Beidou system and authenticates the identity of the MEO satellite.
[0016] Satellite downlink signals include message data, Message Authentication Code (MAC), and keys, with the following structure: Figure 1 As shown. Message data is generated based on key Kj. Information authentication code Kj in the next message data Then send it. Compared to existing messages, add an authentication code and a key.
[0017] The user terminal uses the key Kj and calculate ,if and If they are equal, the authentication is successful, and the user terminal believes that the received signal comes from a legitimate satellite.
[0018] (2) If authentication is successful, the user terminal selects a MEO satellite as the access satellite. If multiple MEO satellites are authenticated simultaneously, the user terminal selects two or more of them as the access satellite.
[0019] (3) Calculate the spreading code sequence number based on the access satellite ID and time, select the corresponding spreading code from the sequence number pool, and arrange the uplink signal frames.
[0020] Uplink signal frame such as Figure 2 As shown, the fields involved in authentication in the signal frame are as follows: Figure 3 As shown, the definition is as follows: 1) User address: This is the address used to identify the user. User addresses are uniformly registered, distributed, and managed by the central control system.
[0021] 2) Incoming Satellite Number: Indicates the user terminal's automatic identification of the user's uplink satellite, which is the PRN number of that satellite.
[0022] 3) Inbound sequence number: Used to cyclically mark the information number transmitted by the user uplink. For transmissions after a power outage and power-on, and for retransmissions after a timeout, the sequence number is still incremented from the previous one.
[0023] 4) Identity authentication: Used for satellite users to authenticate their uplink users.
[0024] 5) Bit length: Indicates the bit length of the data segment.
[0025] 6) Information Category: Indicates the type of service information or network management information in the user's uplink frame.
[0026] 7) User data: Data sent by users.
[0027] When using BeiDou, time information is obtained through downlink messages.
[0028] The core of the authentication algorithm is a hash algorithm, which is used to construct the authentication code. For a key K and a message M, the authentication algorithm Y=RZ(K,M) is calculated as follows:
[0029] RZ stands for hash algorithm. The method for constructing M is as follows:
[0030] || indicates data concatenation.
[0031] The input parameters for the synchronization header spreading code generator are the satellite pseudo-random noise (PRN) code number, the current BeiDou week count, and the number of seconds within the week. The initial phase for spreading code generation is the initial phase of the shift register that generates the m-sequence. This initial phase is obtained by concatenating the binary representations of the week count and the number of hours within the week. The week count is 13 bits, and the number of hours within the week is obtained by dividing the number of seconds within the week by 3600, rounding down, and then adding one. Through polynomial changes to the initial phase, the spreading code changes every hour. This time-varying mechanism reduces the risk of prolonged blocking.
[0032] (4) The user terminal uses the corresponding spreading code to send inbound information to two or more satellites.
[0033] Because the target satellites have different PRN numbers, their corresponding spreading codes are also different. By sending inbound signals to multiple satellites, the risk of all inbound links being blocked is greatly reduced.
[0034] (5) The MEO satellite receives signals from user terminals, calculates on-board spreading codes using the time-varying spreading code method, and uses them to receive signals transmitted by user terminals.
[0035] (6) After the MEO satellite demodulates the signal, it obtains the content of the information frame, uses the key K and message M, and employs the authentication algorithm Y=RZ(K,M) to calculate as follows:
[0036] If the authentication code Y' calculated on-board matches the authentication code Y in the frame, proceed to the next step.
[0037] (7) Query the inbound sequence number corresponding to this user ID. If the satellite inbound sequence number is greater than the inbound sequence number in the frame, the frame is considered to be a duplicate and is discarded. Otherwise, the frame is received and the satellite inbound sequence number is set to the inbound sequence number in the received frame. At this point, the satellite completes authentication and broadcasts an acknowledgment frame via the B2b signal.
[0038] (8) When the user terminal receives more than one confirmation frame, it selects the satellite that received the confirmation first as the access satellite and completes the subsequent data transmission.
[0039] The process is as follows Figure 4 As shown.
[0040] II. Authentication Process After the MEO Satellite's Visibility Relationship with the User is Switched (1) The navigation downlink signal contains the orbital elements of the satellite. When the visibility relationship between the user terminal and the satellite is about to change, the user terminal sends a handover request to the current satellite.
[0041] (2) The current satellite sends the user terminal information to the target satellite for switching. The information includes the user terminal ID, the on-board entry number and the key K1.
[0042] (3) The current satellite will send the relevant information of the target satellite to the user terminal. The information includes the key K1 and the PRN number of the target satellite to be switched.
[0043] (4) The user terminal calculates and generates the initial phase of the spreading code based on the target satellite PRN number, the BeiDou week count, and the number of seconds within the week. The initial phase is obtained by concatenating the binary representations of the week count and the number of hours within the week. The week count is obtained by truncating the lowest 8 bits of the 13-bit week count WN, and the number of hours within the week is obtained by dividing the number of seconds within the week by 3600, rounding down, and then adding one.
[0044] (5) The user terminal constructs an authentication code based on the key K1 and a hash algorithm. For the key K1 and the message M, the authentication algorithm Y=RZ(K1,M) is calculated as follows:
[0045] RZ stands for hash algorithm. The method for constructing M is as follows:
[0046] || indicates data concatenation.
[0047] (6) The user terminal calculates the spreading code sequence number used for the uplink signal. The input parameters for the synchronization header spreading code generator are the satellite PRN number, the current BeiDou week count, and the number of seconds within the week. The initial phase for spreading code generation is the initial phase of the shift register that generates the m-sequence. This initial phase is obtained by concatenating the binary representations of the week count and the number of days within the week. Specifically, the week count is truncated to the lowest 8 bits of the 13-bit week count WN, and the number of hours within the week is obtained by dividing the number of seconds within the week by 3600, rounding down, and then adding one. Through polynomial changes to the initial phase, the spreading code changes every hour. This time-varying mechanism reduces the risk of prolonged blocking.
[0048] The user terminal arranges uplink signal frames and sends uplink signals.
[0049] (7) The MEO satellite receives signals from user terminals, calculates on-board spreading codes using the time-varying spreading code method, and uses them to receive signals transmitted by user terminals.
[0050] (8) After the satellite demodulates the signal, it obtains the content of the information frame. Using the authentication algorithm Y=RZ(K1,M) for key K1 and message M, the following calculation is performed:
[0051] If the authentication code Y' calculated on-board matches the authentication code Y in the frame, then proceed to the next step: (9) Query the inbound sequence number corresponding to this user ID. If the satellite inbound sequence number is greater than the inbound sequence number in the frame, the frame is considered a duplicate and is discarded. Otherwise, the frame is received and the satellite inbound sequence number is set to the inbound sequence number in the received frame. At this point, the satellite completes authentication and broadcasts an acknowledgment frame via the B2b signal.
[0052] (10) The user terminal receives the confirmation frame, realizes the satellite switching, and completes the subsequent data transmission.
[0053] The process is as follows Figure 5 As shown.
[0054] The contents not described in detail in this specification are common knowledge to those skilled in the art.
[0055] Although the present invention has been disclosed above with reference to preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make possible changes and modifications to the technical solutions of the present invention by utilizing the methods and techniques disclosed above without departing from the spirit and scope of the present invention. Therefore, any simple modifications, equivalent changes and alterations made to the above embodiments based on the technical essence of the present invention without departing from the content of the technical solutions of the present invention shall fall within the protection scope of the technical solutions of the present invention.
Claims
1. A two-way authentication method for BeiDou global short message communication, characterized in that, For initial access authentication, the following are included: (1) The user terminal receives the downlink signal of the MEO satellite of the Beidou system and authenticates the identity of the MEO satellite; (2) If authentication is successful, the user terminal selects the MEO satellite as the access satellite; (3) Calculate the spreading code sequence number based on the access satellite ID and time, select the corresponding spreading code from the sequence number pool, and arrange the uplink signal frames; (4) The user terminal uses the corresponding spreading code to send inbound information to two or more satellites; (5) The MEO satellite receives signals from user terminals, calculates the on-board spreading code using the time-varying spreading code method, and uses it to receive signals transmitted by user terminals; (6) After demodulating the signal, the MEO satellite obtains the content of the information frame and performs authentication; (7) Query the inbound sequence number corresponding to the user ID, and determine whether it is a duplicate frame. If it is, discard it; otherwise, receive the frame and set the inbound sequence number on the satellite to the inbound sequence number in the received frame. At this point, the MEO satellite completes the authentication and broadcasts the confirmation frame through the B2b signal. (8) When the user terminal receives more than one confirmation frame, it selects the MEO satellite that received the confirmation first as the access satellite and completes the subsequent data transmission.
2. The BeiDou global short message communication two-way authentication method according to claim 1, characterized in that, In step (1), the satellite downlink signal includes message data, information authentication code, and key. Message data is generated based on key Kj. Information authentication code Kj in the next message data Then send it.
3. The BeiDou global short message communication two-way authentication method according to claim 2, characterized in that, In step (1), the user terminal uses the key Kj and calculate ,if and If they are equal, the authentication is successful, and the user terminal believes that the received signal comes from a legitimate satellite.
4. The BeiDou global short message communication two-way authentication method according to claim 1, characterized in that, In step (2), if multiple MEO satellites are certified at the same time, the user terminal selects two or more of them as access satellites.
5. The BeiDou global short message communication two-way authentication method according to claim 1, characterized in that, In step (3), the user address, inbound satellite number, inbound sequence number, identity authentication, bit length, information category, and user data fields in the uplink signal frame participate in authentication, and an information authentication code is constructed based on the hash algorithm.
6. The BeiDou global short message communication two-way authentication method according to claim 5, characterized in that, In step (3), for the key K and message M, the authentication algorithm Y=RZ(K,M) is as follows: RZ represents the hash algorithm; where M is constructed as follows: || indicates data concatenation.
7. The BeiDou global short message communication two-way authentication method according to claim 6, characterized in that, In step (6), the authentication algorithm Y=RZ(K,M) is used, and the calculation is as follows: If the authentication code Y' obtained by onboard calculation is consistent with the authentication code Y in the frame.
8. The BeiDou global short message communication two-way authentication method according to claim 1, characterized in that, In step (3), the spread spectrum code sequence number is calculated using the synchronization head spread spectrum code generator. The input parameters of the synchronization head spread spectrum code generator are the satellite pseudo-random noise code number, the current BeiDou week count, and the number of seconds within the week. The initial phase of the spread spectrum code generation is the initial phase of the shift register that generates the m-sequence. The initial phase is obtained by connecting the binary representation of the week count and the number of hours within the week. The spread spectrum code changes once every hour through the change of the polynomial initial phase.
9. A two-way authentication method for BeiDou global short message communication, characterized in that, Authentication after the switch in satellite and user visibility relationships includes: (1) The navigation downlink signal contains the orbital elements of the satellite. When the visibility relationship between the user terminal and the satellite is about to change, the user terminal sends a handover request to the current satellite. (2) The current satellite sends the user terminal information to the target satellite for handover. The information includes the user terminal ID, the on-board entry number and the key K1. (3) The current satellite will send the relevant information of the target satellite to the user terminal. The information includes key K1 and the PRN number of the target satellite to be switched. (4) The user terminal generates the initial phase of the spreading code based on the target switching satellite PRN number, BeiDou time week count and intra-week seconds calculation; (5) The user terminal constructs an information authentication code based on the key K1 and a hash algorithm; (6) The user terminal calculates the spreading code sequence number used for the uplink signal; (7) The satellite receives signals from the user terminal, calculates the on-board spreading code using the time-varying method of spreading code, and uses it to receive signals transmitted by the user terminal; (8) After the satellite demodulates the signal, it obtains the content of the information frame and performs authentication; (9) Query the inbound sequence number corresponding to this user ID and determine whether it is a duplicate frame. If it is, discard it; otherwise, receive the frame and set the satellite inbound sequence number to the inbound sequence number in the received frame. At this point, the satellite completes the authentication and broadcasts the confirmation frame through the B2b signal. (10) The user terminal receives the confirmation frame, realizes the satellite switching, and completes the subsequent data transmission.