Lightweight satellite networking authentication and key agreement method and system based on SM2

By employing a lightweight satellite networking authentication and key negotiation method based on SM2, and utilizing the exchange of temporary public-private key pairs and challenge messages, the security authentication problem under resource constraints and dynamic topology in satellite networks is solved. This enables fast and secure inter-satellite connections and session key negotiation, thereby improving the security and efficiency of satellite communication systems.

CN121968084APending Publication Date: 2026-05-01XINGTANG TELECOMM TECH CO LTD +2
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
XINGTANG TELECOMM TECH CO LTD
Filing Date
2024-10-31
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

In existing technologies, satellite communication systems do not take into account satellite network access security authentication measures during the initial design phase. This results in satellite networks facing security challenges in complex network environments, such as resource constraints, dynamically changing topologies, frequent link switching, and open link communication, making it difficult to achieve secure and reliable inter-satellite networking.

Method used

A lightweight satellite networking authentication and key negotiation method based on SM2 is adopted. Temporary public-private key pairs are generated by the satellite, and encryption and signing are performed using the SM2 algorithm. Combined with random numbers and challenge messages, two-way identity authentication and session key negotiation with three interactions are realized, avoiding complex long-term certificates and frequent ground interactions, and a lightweight inter-satellite authentication protocol is designed.

Benefits of technology

It enables rapid and secure connections between satellites in resource-constrained inter-satellite environments, simplifies authentication protocols, reduces the complexity of long-term key management, improves the security and system efficiency of inter-satellite connections, prevents replay attacks and man-in-the-middle attacks, and ensures the confidentiality and integrity of messages.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121968084A_ABST
    Figure CN121968084A_ABST
Patent Text Reader

Abstract

The invention relates to a lightweight satellite networking authentication and key negotiation method and system based on SM2, belongs to the technical field of satellite communication, and solves the problems that inter-satellite networking authentication needs to frequently interact with a ground site and inter-satellite connection has potential safety hazards in the prior art. The method comprises the following specific steps: a satellite A and a satellite B respectively generate temporary public and private key pairs (PKA, SKA) and (PKB, SKB); the satellite A initiates an authentication request to the satellite B based on the own identification IDA and the temporary public key PKA; the satellite B responds to the authentication request, generates a ciphertext and a signature through encryption based on an SM2 algorithm, and sends a challenge message to the satellite A; the satellite A responds to the challenge message and carries out decryption and authentication in sequence; after success, generating a session key KA, and sending an encrypted response message; and the satellite B authenticates the received response message, generates a session key KB after successful authentication, and obtains a shared session key. And a lightweight and high-security authentication process and a key negotiation process are realized.
Need to check novelty before this filing date? Find Prior Art

Description

A lightweight satellite networking authentication and key negotiation method and system based on SM2 Technical Field

[0001] This invention relates to the field of satellite communication technology, and in particular to a lightweight satellite networking authentication and key negotiation method and system based on SM2. Background Technology

[0002] With the increase in the weight of payloads that satellites can carry, the deployment of low-level protocol processing units (distributed units, DUs) and satellite-based base stations, the onboard processing capabilities have been greatly enhanced. Satellites will no longer simply forward signaling and service data transparently. At the same time, with the planning and construction of satellite constellations such as "Hongyan" and "Satellite Internet," large and giant satellite communication networks are on the verge of emerging.

[0003] Satellite networking can expand the coverage of satellite signals, but satellite communication systems are not designed with satellite network access security authentication measures in mind. Unlike terrestrial wireless networks, satellite network authentication technology needs to address a series of security challenges in complex network environments, including resource-constrained on-board environments, dynamically changing network structures, and intermittent communication links.

[0004] (1) Satellite motion brings about dynamic changes in physical position, and satellite networks cannot maintain a stable topology. Satellites need to be re-authenticated. For example, when a satellite passes through the polar region, the positions of satellites on adjacent orbits will change. Satellites on adjacent orbits but in opposite directions will gradually move further away from each other and exceed the communication range over time. Satellites on the link also need to be re-authenticated.

[0005] (2) Frequent link switching increases the risk of satellite networks being compromised by malicious nodes.

[0006] (3) Inter-satellite communication uses open links, which are easily monitored, tampered with and forged, making it very likely that the networking process of satellite networks will not be completed due to malicious interference.

[0007] (4) Faced with a massive number of satellite nodes, the authentication scheme also needs to minimize its reliance on trusted third parties such as ground control centers while ensuring network security.

[0008] (5) Given the limited resources of the satellite environment, lightweight authentication schemes should be adopted as much as possible to meet the authentication requirements of inter-satellite networking. Summary of the Invention

[0009] Based on the above analysis, the embodiments of the present invention aim to provide a lightweight satellite networking authentication and key negotiation method and system based on SM2, in order to solve the problems of frequent interaction with ground stations and security risks in inter-satellite networking authentication and inter-satellite connections in the prior art.

[0010] The objective of this invention is mainly achieved through the following technical solutions:

[0011] On one hand, embodiments of the present invention provide a lightweight satellite networking authentication and key negotiation method based on SM2, comprising the following steps:

[0012] Satellite A and Satellite B each generate a temporary public-private key pair (PK). A SK A ) and (PK B SK B );

[0013] Satellite A is based on its own identifier ID A PK with temporary public key A Initiate an authentication request to satellite B;

[0014] Satellite B responds to the authentication request by encrypting the temporary public key PK using the SM2 algorithm. A and its own temporary private key SK B Generate ciphertext and signature, and send a challenge message to satellite A;

[0015] Satellite A responds to the challenge message by sequentially decrypting and authenticating the ciphertext and signature; if both decryption and authentication are successful, a session key K is generated. A and send an encrypted response message;

[0016] Satellite B is based on the aforementioned temporary public key PK. A Upon successful authentication, a session key K is generated from the received response message. B Based on the session key K A and the session key K B Obtain the shared session key.

[0017] Furthermore, the challenge message includes a random number R. B ciphertext, signature Sig B PK with temporary public key B ;in,

[0018] The random number R is generated by satellite B. B ;

[0019] Using the temporary public key PK of satellite A A and the random number R B The ciphertext is obtained by encrypting the data using the SM2 algorithm.

[0020] Using the temporary private key SK from satellite B B and random number R B The signature Sig is generated based on the SM2 algorithm. B .

[0021] Furthermore, satellite A sequentially decrypts and authenticates the ciphertext and signature, including:

[0022] Using satellite A's temporary private key SK A Decrypt the ciphertext to obtain the decrypted random number R. B '; When the random number R B 'Compare with the random number R in the received challenge message B If the results are identical, decryption succeeds; otherwise, decryption fails.

[0023] After successful decryption, use the temporary public key PK provided by satellite B. B and the random number R B Verify the signature to obtain signature V B When the signature V B The signature Sig in the received challenge message B If the results are identical, authentication is successful; otherwise, authentication fails.

[0024] Furthermore, satellite B carries its own identification ID. B Send the challenge message to satellite A.

[0025] Furthermore, the temporary public-private key pair (PK) is generated. A SK A ) and (PK A SK A )include:

[0026] Each random number is used as a temporary private key SK. A and the temporary private key SK B ;

[0027] Using the temporary private key SK respectively A and the temporary private key SK B The corresponding temporary public key PK is calculated based on the following formula. A and PK B :

[0028] PK i =SK i ·G,

[0029] Where G is the base point of the elliptic curve; SK i PK is the temporary private key for satellite i. i Let i be the temporary public key for satellite i, where i is either A or B.

[0030] Furthermore, the session key K A and session key K B Obtaining the shared session key includes:

[0031] Satellite A uses the temporary private key SK A PK with satellite B's temporary public key B The session key K is obtained based on the key exchange algorithm. A ;

[0032] Satellite B uses the temporary private key SK B And the temporary public key PK of satellite A A The session key K is obtained based on the key exchange algorithm. B ;

[0033] The session key K obtained through the key exchange algorithm A With session key K B They are the same, sharing a session key.

[0034] Furthermore, the calculation formula for the key exchange algorithm is as follows:

[0035] SK i ·PK j =SK i ·(SK j ·G)=(x,y), K i =KDF(x),

[0036] Among them, PK j SK is the temporary public key for satellite j negotiated with satellite i. j The temporary private key for satellite j to negotiate with satellite i; (x,y) represents the two-dimensional coordinates on the elliptic curve obtained after transformation; K i The session key is calculated for satellite i; KDF() is the key derivation function.

[0037] Furthermore, satellite A encrypts the response message based on the SM2 algorithm, including:

[0038] Using satellite A's temporary private key SK A The response message is signed using the SM2 algorithm to obtain the signature Sig. A ;

[0039] The response message is combined with the signature Sig A Receive the encrypted response message.

[0040] Furthermore, Satellite B uses the aforementioned temporary public key PK. A The authentication response message includes:

[0041] Using the temporary public key PK of satellite A A The signature of the received response message is calculated based on the SM2 algorithm, resulting in the signature Sig. A ';

[0042] When the received signature Sig A With the signature Sig A If the signatures match, the signature verification passes and authentication succeeds; otherwise, authentication fails.

[0043] On the other hand, embodiments of the present invention provide a lightweight satellite networking authentication and key negotiation system based on SM2, comprising:

[0044] The data transceiver module is used to drive the interface to achieve high-speed data synchronization and data transmission and reception, including sending and receiving authentication requests, challenge messages, and response messages;

[0045] The data exchange and scheduling module is used to forward and schedule input data according to the load status of each encryption and decryption channel and the load balancing strategy, and to sort and output the data that has completed the password processing to the corresponding data transceiver module for output.

[0046] The operation management module includes a password management module and a system management module. It is used for operation management and control through the system management module; and for managing all pre-stored shared keys and updating keys through the password management module, including generating temporary key pairs.

[0047] The onboard authentication negotiation module is used to complete lightweight satellite networking authentication and key negotiation based on SM2.

[0048] Compared with the prior art, the present invention can achieve at least one of the following beneficial effects:

[0049] 1. The authentication process proposed in this invention utilizes the exchange and verification of temporary public-private key pairs and challenge messages, avoiding the use of complex long-term certificates and authentication chains that frequently interact with the ground, thereby simplifying the authentication protocol and achieving lightweight authentication; at the same time, it uses SM2 asymmetric cryptography technology for encryption and signing to ensure the confidentiality, integrity and non-repudiation of messages, thereby improving the security of inter-satellite connections.

[0050] 2. By using random numbers and temporary key pairs, replay attacks and man-in-the-middle attacks are prevented; a key exchange algorithm is adopted and a two-way authentication mechanism is designed to ensure the confidentiality and forward security of session key negotiation; multiple security mechanisms ensure the security of the authentication process and session key negotiation.

[0051] 3. Since temporary key pairs are discarded after the session ends, they do not need to be stored and managed for a long time, which can reduce the complexity of long-term key management and related computational overhead, and improve the efficiency of the system.

[0052] 4. The proposed system adopts an integrated hardware platform architecture design. Based on the satellite platform hardware architecture, it designs an inter-satellite networking authentication and key negotiation hardware architecture to provide lightweight and secure inter-satellite networking authentication for interconnection between satellites and the construction of satellite networks.

[0053] In this invention, the above-described technical solutions can be combined with each other to achieve more preferred combinations. Other features and advantages of this invention will be set forth in the following description, and some advantages may become apparent from the description or be learned by practicing the invention. The objects and other advantages of this invention can be realized and obtained from what is particularly pointed out in the description and drawings. Attached Figure Description

[0054] The accompanying drawings are for illustrative purposes only and are not intended to limit the invention. Throughout the drawings, the same reference numerals denote the same parts.

[0055] Figure 1 is a flowchart of satellite networking authentication and key negotiation according to an embodiment of the present invention;

[0056] Figure 2 is a schematic diagram of the inter-satellite networking authentication and key negotiation protocol according to an embodiment of the present invention;

[0057] Figure 3 is an on-board implementation architecture diagram of inter-satellite networking authentication and key negotiation according to an embodiment of the present invention;

[0058] Figure 4 shows the onboard authentication negotiation module according to an embodiment of the present invention;

[0059] Figure 5 is a schematic diagram of the spaceborne hardware platform architecture according to an embodiment of the present invention. Detailed Implementation

[0060] Preferred embodiments of the present invention will now be described in detail with reference to the accompanying drawings, which form part of this application and are used together with the embodiments of the present invention to illustrate the principles of the present invention, but are not intended to limit the scope of the present invention.

[0061] Example 1

[0062] A specific embodiment of the present invention discloses a lightweight satellite networking authentication and key negotiation method based on SM2, as shown in Figure 1, including the following steps:

[0063] Step S1: Satellite A and Satellite B generate temporary public-private key pairs (PK). A SK A ) and (PK B SKB );

[0064] Step S2: Satellite A, based on its own identifier ID... A PK with temporary public key A Send an authentication request message Auth_Req to target satellite B, represented as Auth_Req = {IDA, PKA};

[0065] Step S3: Satellite B responds to the authentication request based on the identifier ID. A PK with temporary public key A Satellite A is authenticated. After successful authentication, the temporary public key PK is encrypted using the SM2 algorithm. A and its own temporary private key SK B Generate ciphertext and signature, and send a challenge message to satellite A;

[0066] Step S4: Satellite A responds to the challenge message by decrypting and authenticating the ciphertext and signature sequentially; if both decryption and authentication are successful, a session key K is generated. A and send an encrypted response message;

[0067] Step S5: Satellite B uses the temporary public key PK. A Upon successful authentication, a session key K is generated from the received response message. B Based on session key K A and session key K B Obtain the shared session key between satellite A and satellite B.

[0068] By introducing a challenge mechanism and encrypting authentication parameters, and employing a two-way satellite identifier verification and an efficient key negotiation mechanism based on temporary key pairs, the key negotiation and authentication process is completed through three interactions. Ultimately, this achieves rapid connectivity between satellites without frequent interactions with ground stations, while maintaining a lightweight and secure architecture.

[0069] For example, in step S1, the satellite node to be authenticated in the network can generate a temporary key pair using a random number and an elliptic curve basis point. Taking satellite A as an example, a random number is selected as the temporary private key SK. A The temporary public key for node satellite A is calculated based on the elliptic curve base points using the following formula:

[0070] PK A =SK A ·G,

[0071] Where G is the base point of the elliptic curve.

[0072] Specifically, in step S2, as shown in Figure 2, as the first interaction for network authentication, the authentication request from the satellite initiator includes the satellite's identifier ID and temporary public key PK. Attackers cannot forge the identity of a legitimate satellite, which can effectively prevent identity forgery attacks during network authentication.

[0073] Specifically, in step S3, satellite B responds to the authentication request and initiates a second interaction through a random challenge; wherein, a challenge message is generated based on the following steps:

[0074] Step S31: Use the temporary public key to perform a PK. A and random number R B Encryption is performed based on the SM2 algorithm to obtain the ciphertext Enc(R). B ), represented as Enc(R B =SM2_Enc(PK) A ,R B );

[0075] Step S32: Use the temporary private key SK of satellite B B and random number R B Generate signature Sig based on SM2 algorithm B , represented as Sig B =SM2_Sign(SK B ,R B );

[0076] Step S33: Based on the random number R B Enc(R) B ), Signature Sig B With the temporary public key PKB, a challenge message is obtained, represented as Challenge_Msg = {R B ,Enc(RB),Sig B PK B}

[0077] Encryption and signing using the SM2 algorithm ensure the confidentiality, integrity, and non-repudiation of messages. Signature verification confirms the message's origin and that its content has not been tampered with. This method ensures authentication of both parties and data security and integrity. Furthermore, the use of ephemeral key pairs ensures that each authentication session has a different public-private key pair, further increasing the difficulty of man-in-the-middle attacks. On the other hand, during each authentication process, the target satellite generates a random number R as a challenge message. This random number ensures that each authentication session is unique; therefore, replaying old authentication messages is ineffective, effectively resisting replay attacks.

[0078] Furthermore, satellite B carries its own identification ID. BThe challenge message is sent to satellite A. Similar to including the initiating satellite's identifier ID in the authentication request, the security of network authentication is improved by adding a unique identifier for each satellite to the authentication request response information.

[0079] Specifically, in step S4, after successfully decrypting and authenticating the challenge message, satellite A sends a response message for a third interaction; wherein, satellite A sequentially decrypts and authenticates the ciphertext and signature, including:

[0080] Using satellite A's temporary private key SK A Decrypt the ciphertext to obtain the decrypted random number R. B ', represented as R B =SM2_Dec(SK A ,Enc(R B When the random number R B 'Compare with the random number R in the received challenge message B If the results are identical, decryption is successful; otherwise, decryption fails and the negotiation process terminates.

[0081] After successful decryption, use the temporary public key PK provided by satellite B. B and random number R B Verify the signature to obtain signature V B , represented as V B =SM2_Veri_Sign(PK) B ,R B Sig B ); when the signature V B The signature Sig in the received challenge message B If the results are identical, authentication is successful; otherwise, authentication fails.

[0082] If the challenge message includes the identifier ID of satellite B B Then satellite A can be based on the identifier ID. B The system authenticates the satellite that sends the challenge message and then sends the corresponding response message to satellite B, thereby effectively preventing the response message from being sent to the attacking satellite that has deciphered the challenge information.

[0083] After successful authentication, Satellite A will encrypt a response message based on the SM2 algorithm, including:

[0084] Generate a corresponding response message based on the negotiation protocol;

[0085] Using satellite A's temporary private key SK A The response message is signed using the SM2 algorithm to obtain the signature Sig. A ;

[0086] The response message is combined with the signature SigA Receive the encrypted response message.

[0087] Meanwhile, satellite A uses its own temporary private key SK A PK with satellite B's temporary public key B Generate session key K based on key exchange algorithm A The calculation formula is:

[0088] SK A ·PK B =SK A ·(SK B ·G)=(x,y), K A =KDF(x),

[0089] Where G is the base point of the elliptic curve; (x,y) represents the two-dimensional coordinates on the elliptic curve after transformation; and KDF() is the key derivation function.

[0090] Specifically, in step S5, satellite B uses the temporary public key PK. A The authentication response message includes:

[0091] Using the temporary public key PK of satellite A A The signature of the received response message is calculated based on the SM2 algorithm, resulting in the signature Sig. A ';

[0092] When the received signature Sig A With the signature Sig A If the signatures match, the signature verification passes and authentication succeeds; otherwise, authentication fails.

[0093] After successful authentication, Satellite B uses its temporary private key SK. B PK with satellite A's temporary public key A The session key K is obtained based on the same cryptographic exchange algorithm. B The calculation formula is:

[0094] SK B ·PK A =SK B ·(SK A ·G)=(x,y), K B =KDF(x).

[0095] Through the key exchange algorithm mechanism described above, the keys generated by each party are equal and can be used as a shared session key. This same key is then used as the symmetric key, ensuring that information exchanged between the two parties is encrypted. Furthermore, a new session key is generated with each session negotiation, preventing attackers from gaining access even if they intercept the public key (PK). A and PK BFurthermore, it is impossible to calculate the session key; on the other hand, since a different temporary key pair is used for each session, even if an attacker obtains the session key in a certain session, they cannot deduce the key for previous or subsequent sessions, thereby improving the confidentiality and forward security of the negotiation.

[0096] Compared to existing technologies, this embodiment provides a lightweight satellite networking authentication and key negotiation method based on SM2. By using random numbers and their signatures, it ensures the immutability of messages during the authentication process. The session key negotiation process relies on temporary key pairs between the two parties, preventing attackers from forging or tampering with the negotiation messages. All sensitive data during authentication and key negotiation is encrypted, preventing attackers from obtaining valid information through passive eavesdropping. Ultimately, this achieves rapid and secure connections between satellites in resource-constrained inter-satellite environments. On one hand, the method requires no third-party involvement during authentication, completing bidirectional authentication between network entities with only three interactions, reducing air-to-ground traffic and thus minimizing the occupation of limited air frequency resources. On the other hand, SM2 and key exchange negotiate a session key that can be used for subsequent sessions, providing confidentiality guarantees for subsequent data transmission.

[0097] Example 2

[0098] Another specific embodiment of the present invention discloses a lightweight satellite networking authentication and key negotiation system based on SM2, as shown in Figure 3, comprising:

[0099] The data transceiver module mainly includes an air interface data transceiver module, an inter-satellite data transceiver module, and a control data transceiver module. It is used to drive the interface to realize high-speed data synchronization and data transmission and reception, including sending and receiving authentication requests, challenge messages, and response messages.

[0100] The data exchange and scheduling module is a data communication bridge between the data transceiver module, the encryption / decryption channel, and the operation management module. It is used to forward and schedule input data according to the load balancing strategy based on the load status of each encryption / decryption channel, and to sort and output the data that has completed the password processing to the corresponding data transceiver module.

[0101] The operation management module includes a cryptography management module and a system management module. The system management module is used to manage and control the operation of the onboard cryptography module, and realize functions such as on-orbit management, on-orbit reconstruction, time synchronization, and operation status acquisition and reporting. The cryptography management module manages all pre-stored shared keys and update keys of the onboard cryptography module, including pre-stored and updated temporary key pairs generated by the onboard authentication negotiation module.

[0102] The onboard authentication negotiation module, including the inter-satellite networking authentication and inter-satellite key negotiation modules, is used to complete the lightweight satellite networking authentication and key negotiation based on SM2; as shown in Figure 4, it includes various encryption, signature and other algorithm sub-modules;

[0103] Noise source module: Provides compliant digital noise data for high-speed data encryption, network authentication, and key negotiation.

[0104] As shown in Figure 5, the onboard authentication and negotiation module runs on the onboard main processing module. Based on the satellite platform hardware architecture, it completes inter-satellite network authentication and key negotiation. It interconnects with the onboard router via a high-speed serial bus. The interconnection unit between the onboard authentication and negotiation module and the onboard router is an FPGA, which performs data communication and protocol parsing functions. The CPU of the inter-satellite network authentication module is the execution unit for the authentication and key negotiation protocol.

[0105] The inter-satellite networking authentication and key negotiation processes are performed on two adjacent satellites' inter-satellite networking authentication modules, which communicate via a transmission network established by the onboard router and the carrier network. The message format of the protocol data conforms to the space carrier network data format.

[0106] The satellite node key security negotiation process is initiated when both satellite nodes use confirmation feedback to ensure link alignment and synchronization. This process follows the inter-satellite link synchronization process and is initiated after both parties perform feedback confirmation. It confirms the master-slave relationship between nodes during the session establishment. To ensure the reliability of the session key negotiation, the satellite node that receives the confirmation message is selected as the master node, and the negotiation handshake process is initiated.

[0107] Compared to symmetric cryptography algorithms, public-key-based network authentication key management is simpler. Ground stations (e.g., Certificate Authorities) are responsible for generating and distributing keys and system parameters. After registering with the ground station, the satellite obtains and stores the public key and system parameters distributed by the ground station, and performs corresponding encryption, signing, and key negotiation operations during the authentication process. The key negotiation operation is based on temporary key pairs, not the public key issued by the CA, thus eliminating the need for frequent ground intervention.

[0108] Furthermore, the system can perform network authentication and key negotiation according to the SM2-based lightweight satellite networking authentication and key negotiation method described in any of the schemes in Embodiment 1. Related aspects can be referenced from each other, and are not repeated in this embodiment.

[0109] Compared with existing technologies, this embodiment provides a lightweight satellite networking authentication and key negotiation system based on SM2. By utilizing SM2 and key exchange technology, it ensures that the authentication and session key negotiation process between satellites is both secure and efficient. No third party is required during the authentication process, which can ensure the autonomy and independence of satellite networking. Each satellite agrees on a secret key known only to the other by using its own private key and the other's public key. It uses limited on-board resources to authenticate the identity of satellites entering the network, ensuring the secure networking of the satellite communication system and guaranteeing the secure transmission of inter-satellite data.

[0110] Those skilled in the art will understand that all or part of the processes of the methods described in the above embodiments can be implemented by a computer program instructing related hardware, and the program can be stored in a computer-readable storage medium. The computer-readable storage medium may be a disk, optical disk, read-only memory, or random access memory, etc.

[0111] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in the present invention should be included within the scope of protection of the present invention.

Claims

1. A lightweight satellite networking authentication and key negotiation method based on SM2, characterized in that, The steps include: Satellite A and Satellite B each generate a temporary public-private key pair (PK). A SK A ) and (PK B SK B Satellite A is based on its own identifier ID. A PK with temporary public key A An authentication request is initiated to satellite B; satellite B responds to the authentication request by encrypting the temporary public key PK based on the SM2 algorithm. A and its own temporary private key SK B Generate ciphertext and signature, and send a challenge message to satellite A; Satellite A responds to the challenge message by sequentially decrypting and authenticating the ciphertext and signature; if both decryption and authentication are successful, a session key K is generated. A And send an encrypted response message; Satellite B based on the temporary public key PK A Upon successful authentication, a session key K is generated from the received response message. B Based on the session key K A and the session key K B Obtain the shared session key.

2. The lightweight satellite networking authentication and key negotiation method based on SM2 according to claim 1, characterized in that, The challenge message includes a random number R. B ciphertext, signature Sig B PK with temporary public key B ; The random number R is generated by satellite B. B Using the temporary public key PK of satellite A A and the random number R B The ciphertext is obtained by encryption based on the SM2 algorithm; the temporary private key SK of satellite B is then used. B and random number R B The signature Sig is generated based on the SM2 algorithm. B .

3. The lightweight satellite networking authentication and key negotiation method based on SM2 according to claim 2, characterized in that, Satellite A sequentially decrypts and authenticates the ciphertext and signature, including using Satellite A's temporary private key SK. A Decrypt the ciphertext to obtain the decrypted random number R. B '; When the random number R B 'Compare with the random number R in the received challenge message B If the keys match, decryption succeeds; otherwise, decryption fails. After successful decryption, use the temporary public key PK provided by satellite B. B and the random number R B Verify the signature to obtain signature V B When the signature V B The signature Sig in the received challenge message B If the results are identical, authentication is successful; otherwise, authentication fails.

4. The lightweight satellite networking authentication and key negotiation method based on SM2 according to claim 2, characterized in that, Satellite B carries its own identification ID. B Send the challenge message to satellite A.

5. A lightweight satellite networking authentication and key negotiation method based on SM2 according to claim 1, characterized in that, Generate the temporary public-private key pair (PK) A SK A ) and (PK A SK A This includes: generating random numbers as temporary private keys SK. A and the temporary private key SK B ; respectively using the temporary private key SK A and the temporary private key SK B The corresponding temporary public key PK is calculated based on the following formula. A and PK B PK i =SK i ·G, where G is the base point of the elliptic curve; SK i PK is the temporary private key for satellite i. i Let i be the temporary public key for satellite i, where i is either A or B.

6. A lightweight satellite networking authentication and key negotiation method based on SM2 according to claim 5, characterized in that, The session key K A and session key K B Obtaining the shared session key includes: Satellite A using the temporary private key SK A PK with satellite B's temporary public key B The session key K is obtained based on the key exchange algorithm. A Satellite B uses the temporary private key SK B And the temporary public key PK of satellite A A The session key K is obtained based on the key exchange algorithm. B The session key K obtained through the key exchange algorithm. A With session key K B They are the same, sharing a session key.

7. A lightweight satellite networking authentication and key negotiation method based on SM2 according to claim 6, characterized in that, The calculation formula for the key exchange algorithm is: SK i ·PK j =SK i ·(SK j ·G)=(x,y), K i =KDF(x), where PK j SK is the temporary public key for satellite j negotiated with satellite i. j The temporary private key for satellite j to negotiate with satellite i; (x,y) represents the two-dimensional coordinates on the elliptic curve obtained after transformation; K i The session key is calculated for satellite i; KDF() is the key derivation function.

8. A lightweight satellite networking authentication and key negotiation method based on SM2 according to any one of claims 1-7, characterized in that, Satellite A encrypts the response message using the SM2 algorithm, including using Satellite A's temporary private key SK. A The response message is signed using the SM2 algorithm to obtain the signature Sig. A The response message is combined with the signature Sig A Receive the encrypted response message.

9. A lightweight satellite networking authentication and key negotiation method based on SM2 according to claim 8, characterized in that, Satellite B is based on the aforementioned temporary public key PK. A The authentication response message includes: using the temporary public key PK from satellite A. A The signature of the received response message is calculated based on the SM2 algorithm, resulting in the signature Sig. A ';When the received signature Sig A With the signature Sig A If the signatures match, the signature verification passes and authentication succeeds; otherwise, authentication fails.

10. A lightweight satellite networking authentication and key negotiation system based on SM2, characterized in that, include: The data transceiver module is used to drive the interface to achieve high-speed data synchronization and data transmission and reception, including sending and receiving authentication requests, challenge messages, and response messages; The data exchange and scheduling module is used to forward and schedule input data according to the load balancing strategy based on the load status of each encryption / decryption channel, and to sort and output the data that has completed password processing to the corresponding data transceiver module; the operation management module includes a password management module and a system management module, which is used for operation management and control through the system management module; The password management module manages all pre-stored shared keys and update keys, including pre-stored and updated temporary key pairs generated by the onboard authentication negotiation module. The onboard authentication negotiation module is used to complete lightweight satellite networking authentication and key negotiation based on SM2.