Authentication data processing method and device for satellite short message and electronic equipment
By deploying an authentication unit in the baseband chip of the terminal, and utilizing the chip identifier of the baseband chip and multi-round interactive verification, the cumbersome authentication and verification problem in satellite short message service is solved, achieving efficient and secure satellite communication authentication, and reducing data processing volume and security risks.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA SPACE-TIME INFORMATION GROUP CO LTD
- Filing Date
- 2025-12-09
- Publication Date
- 2026-05-01
AI Technical Summary
The authentication process for satellite short message service in the existing technology is cumbersome and involves a large amount of data processing, especially when a large number of users are authenticating at the same time.
By deploying an authentication unit in the baseband chip of the terminal, application data is generated using the chip identifier of the baseband chip, and the satellite service authentication parameters are obtained and verified through multiple rounds of interactive verification, including data interaction with the satellite gateway and the authentication management system.
It achieves efficient and secure authentication and verification with a relatively small amount of data processing, reduces the burden of key management and security risks, and protects the security of satellite communication data.
Smart Images

Figure CN121968097A_ABST
Abstract
Description
Satellite short message authentication data processing methods, devices and electronic equipment Technical Field
[0001] This specification relates to the field of satellite communication technology, and in particular to a method, apparatus and electronic device for processing authentication data for satellite short messages. Background Technology
[0002] When conducting satellite short message service (e.g., BeiDou satellite short message service), it is usually necessary to authenticate the user's terminal (e.g., the user's mobile phone terminal). However, based on existing methods, the authentication process is relatively cumbersome and complex, and involves a large amount of data processing. This problem becomes more pronounced when a large number of users need to undergo authentication for satellite communication services simultaneously.
[0003] There is currently no effective solution to the above problems. Summary of the Invention
[0004] To address the problems in the prior art, embodiments of this specification provide a method, apparatus, and electronic device for processing authentication data for satellite short messages, which can efficiently and securely achieve authentication and verification of satellite communication services with a relatively small amount of data processing.
[0005] This specification provides an embodiment of a satellite short message authentication data processing method applied to a terminal. The terminal includes at least a baseband chip associated with a satellite, and the baseband chip is equipped with an authentication unit. The method includes: sending application data regarding satellite service authentication parameters; wherein the application data is generated at least based on the chip identifier of the baseband chip; receiving application response data regarding satellite service authentication parameters; wherein the application response data is generated by an authentication management system based on the application data; when the application response data is verified, sending confirmation data regarding satellite service authentication parameters; receiving confirmation response data regarding satellite service authentication parameters; wherein the confirmation response data is received by the terminal after the authentication management system verifies the confirmation data; and obtaining satellite service authentication parameters based on the confirmation response data.
[0006] In one embodiment, sending the application data regarding satellite service authentication parameters includes: sending the application data regarding satellite service authentication parameters to a satellite gateway; wherein the satellite gateway forwards the application data to the authentication management system.
[0007] In one embodiment, the method further includes: invoking an authentication unit to generate the application data.
[0008] In one embodiment, the step of calling the authentication unit to generate the application data includes: when it is detected that there are no satellite service authentication parameters on the terminal's local machine, calling the authentication unit to generate the application data; or, when it is detected that the cumulative time of the satellite service authentication parameters on the terminal's local machine is greater than a preset first duration threshold, calling the authentication unit to generate the application data.
[0009] In one embodiment, the step of calling the authentication unit to generate the application data includes: calling the authentication unit to generate a first random number and an application sequence number; obtaining the user's identity identifier, date information, and the chip identifier of the baseband chip; calling the authentication unit to generate an application authentication code based on the application sequence number, the chip identifier of the baseband chip, the user's identity identifier, the first random number, and the date information; and generating the application data based on the application authentication code.
[0010] In one embodiment, the application response data includes at least: an application response authentication code and a registration response code.
[0011] In one embodiment, after receiving application response data regarding satellite service authentication parameters, the method further includes: performing a consistency check on the application sequence number in the application response data; when the application sequence number consistency check passes, verifying the response authentication code and registration response code in the application response data; and when the response authentication code and registration response code pass verification, generating confirmation data regarding the satellite service authentication parameters.
[0012] In one embodiment, generating confirmation data regarding satellite service authentication parameters includes: invoking an authentication unit to generate a confirmation response code; and generating the confirmation data based on the confirmation response code; wherein the confirmation data includes at least the confirmation response code.
[0013] In one embodiment, verifying the reply authentication code and registration response code in the application reply data includes: calling the authentication unit to generate a reference reply authentication code and a reference registration response code locally based on preset protocol rules; and verifying the reply authentication code and registration response code in the application reply data according to the reference reply authentication code and the reference registration response code.
[0014] In one embodiment, obtaining satellite service authentication parameters based on the confirmation response data includes: extracting authentication verification results from the confirmation response data; determining that the satellite service authentication parameters are valid when the authentication verification results indicate that the satellite communication service authentication verification is successful; responding to the confirmation response data when the satellite service authentication parameters are determined to be valid, generating satellite service authentication parameters according to preset protocol rules; and saving the satellite service authentication parameters locally.
[0015] In one embodiment, the method further includes: responding to a trigger operation, generating a satellite service authentication code using locally stored satellite service authentication parameters; adding the satellite service authentication code to a short message; and sending the short message to the satellite.
[0016] In some embodiments, the satellite includes a BeiDou satellite.
[0017] This specification also provides an authentication data processing method for satellite short messages, applied to an authentication management system. The method includes: receiving application data regarding satellite service authentication parameters; wherein the application data is generated at least based on the chip identifier of the baseband chip; sending application response data regarding satellite service authentication parameters based on the application data; receiving confirmation data regarding satellite service authentication parameters; and sending confirmation response data regarding satellite service authentication parameters when the confirmation data is verified.
[0018] In one embodiment, after receiving application data regarding satellite service authentication parameters, the method further includes: detecting whether the absolute value of the difference between the date information in the application data and the receiving date is less than a preset second duration threshold; when the absolute value of the difference between the date information in the application data and the receiving date is less than the preset second duration threshold, determining that the application data has been verified.
[0019] In one embodiment, when the application data is verified, the method further includes: generating a second random number; generating negotiation authentication parameters and a negotiation factor based on the application serial number and the chip identifier of the baseband chip in the application data; generating a registration response code based on the negotiation authentication parameters, the user's identity identifier, the first random number, and the second random number; generating a reply authentication code based on the application serial number, the verification result of the application data, the second random number, and the registration response code; and generating application reply data regarding satellite service authentication parameters based on the registration response code, the reply authentication code, the second random number, and the application serial number.
[0020] In one embodiment, after determining that the application data has been verified, the method further includes: generating satellite service authentication parameters based on the user's identity identifier, a first random number, a second random number, and a negotiation factor; and recording the satellite service authentication parameters, as well as the user's identity identifier, the baseband chip's chip identifier, and the application serial number corresponding to the satellite service authentication parameters.
[0021] In one embodiment, after receiving confirmation data regarding satellite service authentication parameters, the method further includes: performing a consistency check on the application number, user identity identifier, and baseband chip identifier in the confirmation data; when the consistency check of the application number, user identity identifier, and baseband chip identifier passes, calculating and verifying the confirmation response code in the confirmation data; and when the confirmation response code passes verification, generating confirmation reply data carrying encrypted data of satellite service authentication parameters.
[0022] In one embodiment, generating the confirmation response data carrying encrypted data of satellite service authentication parameters includes: encrypting the satellite service authentication parameters using a pre-defined code of the satellite gateway according to preset protocol rules to obtain encrypted data of the satellite service authentication parameters; and adding the encrypted data of the satellite service authentication parameters to the confirmation response data.
[0023] In one embodiment, after sending confirmation response data regarding satellite service authentication parameters, the method further includes: the satellite gateway determining whether the satellite communication service authentication verification is successful based on the confirmation response data; when it is determined that the satellite communication service authentication verification is successful, the satellite gateway decrypts the encrypted data of the satellite service authentication parameters using a pre-defined code of the satellite gateway according to preset protocol rules to obtain the satellite service authentication parameters; and forwards the confirmation response data to the terminal.
[0024] This specification also provides an embodiment of a satellite short message authentication data processing method applied to a satellite gateway, comprising: receiving confirmation reply data regarding satellite service authentication parameters sent by an authentication management system; wherein the confirmation reply data carries encrypted data of the satellite service authentication parameters; when the confirmation reply data indicates that the satellite communication service authentication verification of the terminal is successful, decrypting the encrypted data of the satellite service authentication parameters to obtain the corresponding satellite service authentication parameters; saving the satellite service authentication parameters; and forwarding the confirmation reply data to the terminal.
[0025] In one embodiment, decrypting the encrypted data of the satellite service authentication parameters to obtain the corresponding satellite service authentication parameters includes: using a pre-defined code associated with the satellite gateway to decrypt the encrypted data of the satellite service authentication parameters to obtain the corresponding satellite service authentication parameters.
[0026] This specification also provides an authentication data processing device for satellite short messages, applied to a terminal. The terminal includes at least a baseband chip associated with a satellite, and the baseband chip is equipped with an authentication unit. The device includes: a first sending module for sending application data regarding satellite service authentication parameters; wherein the application data is generated at least based on the chip identifier of the baseband chip; a first receiving module for receiving application response data regarding satellite service authentication parameters; wherein the application response data is generated by an authentication management system based on the application data; a second sending module for sending confirmation data regarding satellite service authentication parameters when the application response data is verified; a second receiving module for receiving confirmation response data regarding satellite service authentication parameters; wherein the confirmation response data is received by the terminal after the authentication management system verifies the confirmation data; and a processing module for obtaining satellite service authentication parameters based on the confirmation response data.
[0027] This specification also provides an authentication data processing device for satellite short messages, applied to an authentication management system. The device includes: a first receiving module for receiving application data regarding satellite service authentication parameters; wherein the application data is generated at least based on the chip identifier of a baseband chip; a first sending module for sending application response data regarding satellite service authentication parameters based on the application data; a second receiving module for receiving confirmation data regarding satellite service authentication parameters; and a second sending module for sending confirmation response data regarding satellite service authentication parameters when the confirmation data is verified.
[0028] This specification also provides an electronic device, including a processor and a memory for storing processor-executable instructions, wherein the processor executes the instructions to implement the steps of the authentication data processing method for satellite short messages.
[0029] This specification also provides a computer-readable storage medium storing a computer program that, when executed by a processor, performs the steps of the satellite short message authentication data processing method.
[0030] This specification also provides a computer program product, which includes a computer program that, when executed by a processor, implements the steps of the authentication data processing method for satellite short messages.
[0031] Based on the satellite short message authentication data processing method, apparatus, and electronic device provided in the embodiments of this specification, a terminal can first send application data regarding satellite service authentication parameters to the authentication management system through a satellite gateway. The application data is generated at least based on the chip identifier of the baseband chip. After receiving application response data generated by the authorization management system based on the application data through the satellite gateway, the terminal can verify the application response data. When the application response data verification is successful, the terminal can send confirmation data regarding the satellite service authentication parameters to the authentication management system through the satellite gateway. After receiving confirmation response data sent by the authorization management system after verifying the confirmation data, the terminal can obtain valid satellite service authentication parameters based on the confirmation response data and store them locally. Then, it can use these satellite service authentication parameters to normally use satellite communication services based on satellites such as BeiDou. By introducing and using the chip identifier of the baseband chip and multiple rounds of interactive verification, authentication verification of satellite communication services with satellites such as BeiDou can be achieved efficiently and securely with a relatively small data processing volume. This effectively reduces security risks during the authentication verification process and better protects data security during satellite communication. Attached Figure Description
[0032] To more clearly illustrate the technical solutions in the embodiments or prior art of this specification, the drawings used in the description of the embodiments or prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0033] Figure 1 is a schematic diagram of the composition of a satellite short message authentication data processing system according to an embodiment of this specification; Figure 2 is a flowchart of a satellite short message authentication data processing method provided in an embodiment of this specification; Figure 3 is a schematic diagram of a scenario embodiment of the satellite short message authentication data processing method provided in an embodiment of this specification; Figure 4 is a schematic diagram of a scenario embodiment of the satellite short message authentication data processing method provided in an embodiment of this specification; Figure 5 is a schematic diagram of a scenario embodiment of the satellite short message authentication data processing method provided in an embodiment of this specification; Figure 6 is a schematic diagram of the composition of another satellite short message authentication data processing system according to an embodiment of this specification; Figure 7 is a schematic diagram of the composition of yet another satellite short message authentication data processing system according to an embodiment of this specification; Figure 8 is a schematic diagram of the structure of an electronic device according to an embodiment of this specification; Figure 9 is a schematic diagram of the structure of a satellite short message authentication data processing device according to an embodiment of this specification; Figure 10 is a schematic diagram of a scenario embodiment of the satellite short message authentication data processing method provided in an embodiment of this specification. Detailed Implementation
[0034] The technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this specification, and not all embodiments. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this specification.
[0035] It should be noted that the information and data related to users involved in the embodiments of this specification are all information and data authorized by the user or fully authorized by the relevant parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of the relevant data all comply with relevant laws, regulations, and standards, and necessary confidentiality measures have been taken. They do not violate public order and good morals, and corresponding operation entry points are provided for users or relevant parties to choose to authorize or refuse.
[0036] It should also be noted that in the embodiments of this specification, certain software, components, models and other existing solutions in the industry may be mentioned. These should be regarded as exemplary and are only intended to illustrate the feasibility of implementing the technical solution of this application. However, it does not mean that the applicant has used or necessarily used the solution.
[0037] The satellite short message authentication data processing method provided in this specification can be specifically applied to satellite communication scenarios. Specifically, referring to Figure 1, this scenario includes at least components such as a terminal, a satellite gateway, and an authentication management system. The terminal can specifically be a terminal that supports satellite communication. The satellite gateway can be connected to the authentication management system (or authentication management center) via wired or wireless means.
[0038] In practical implementation, referring to Figure 2, when a user wants to use their terminal (e.g., a mobile terminal) to enable the corresponding satellite communication service for specific business data processing (e.g., sending short messages to the target terminal), they can first obtain the chip identifier (e.g., the chip number of the baseband chip) of the baseband chip built into the terminal to support satellite communication; then, according to the preset protocol rules, using the chip identifier of the baseband chip and other information data, they can generate application data for satellite service authentication parameters that is highly reliable and rich in information; and send the application data to the satellite gateway (e.g., the BeiDou satellite short message gateway) through the terrestrial network to initiate the first round of interactive verification.
[0039] After receiving the request data, the satellite gateway can forward the request data to the backend authentication and management system (e.g., password and authorization management subsystem).
[0040] After receiving the application data, the authentication management system can first verify the application data based on time synchronization according to the preset protocol rules; if the application data verification is successful, the authentication management system can generate the corresponding application response data; and then send the application response data to the satellite gateway.
[0041] After receiving the response data for the request, the satellite gateway can forward the response data to the terminal to complete the first round of interactive verification.
[0042] After receiving the response data for the application, the terminal can first verify the response data according to the preset protocol rules; if the verification is successful, it generates confirmation data for the satellite service authentication parameters; and then sends the confirmation data to the satellite gateway to initiate the second round of interactive verification.
[0043] After receiving the confirmation data, the satellite gateway can forward it to the authentication management system.
[0044] After receiving the confirmation data, the authentication management system can verify the confirmation data according to the preset protocol rules; if the verification is successful, it generates the corresponding confirmation response data and sends the confirmation response data to the satellite gateway.
[0045] Upon receiving the confirmation response data, the satellite gateway can first determine whether the satellite communication service authentication has passed based on the response data. If authentication has passed, it can extract the corresponding satellite service authentication parameters based on the confirmation response data and then send the confirmation response data containing the satellite service authentication parameters to the terminal. Simultaneously, the satellite gateway can associate these satellite service authentication parameters with relevant identification information (e.g., the baseband chip's chip identifier and / or the user's identity identifier) and save them locally. Subsequently, the satellite gateway can also send the associated service authentication parameters to the corresponding information processing system for storage and use.
[0046] Based on the confirmation response data, the terminal obtains the satellite service authentication parameters associated with the satellite communication service and completes the second round of interactive verification.
[0047] Based on the above approach, by introducing and using the baseband chip's chip identifier and a multi-round interactive verification mechanism, on the one hand, since the entire authentication and verification process does not require separate storage and reliance on keys, the overall data processing volume is reduced. This alleviates the data burden on the authentication and verification management system when storing and maintaining massive amounts of keys, making it better suited to complex business scenarios where a large number of users simultaneously need to perform authentication and verification for satellite communication services. It also effectively avoids security risks caused by key leakage during the authentication and verification process, thus enabling more efficient and secure authentication and verification for satellite communication services. On the other hand, by sequentially performing two rounds of interactive verification, the security risks caused by data tampering during the authentication and verification process can be effectively reduced, thereby better protecting the data security of satellite communication.
[0048] Furthermore, the terminal can store the aforementioned satellite service authentication parameters locally. Then, when a user initiates operations related to satellite communication services, the terminal can use the local satellite service authentication parameters to interact with the satellite (e.g., BeiDou satellites) to complete specific service data processing based on satellite communication.
[0049] Specifically, taking satellite short message service (e.g., BeiDou satellite short message service) as an example, as shown in Figure 1, in an environment without a mobile network, users can operate on the terminal to trigger the short message service.
[0050] The terminal can respond to the user's trigger operation, generate a satellite service authentication code using the locally stored satellite service authentication parameters, add the satellite service authentication code to the user-edited short message to obtain the corresponding short message, and then send the short message directly to the satellite via the satellite link based on the relevant transmission protocol.
[0051] After receiving the short message, the satellite can transmit it to the ground station via downlink.
[0052] After receiving the short message through the ground station, the information processing system first checks whether the short message contains a satellite service authentication code. If the presence of the authentication code is confirmed, it extracts the code and verifies it using the associated satellite service authentication parameters obtained through the satellite gateway. If the authentication code verification is successful, the short message is deemed valid. The system then forwards the short message to the corresponding target terminal, completing the service data processing for sending the short message to the target terminal. This allows users to smoothly and conveniently complete specific satellite communication services through their terminals.
[0053] Based on the above approach, and referring to Figure 3, this embodiment of the specification provides a method for processing authentication data for satellite short messages. This method is specifically applied to a terminal, wherein the terminal includes at least a baseband chip associated with a satellite, and the baseband chip is equipped with an authentication unit. In specific implementation, the method may include the following: S301: Sending application data regarding satellite service authentication parameters; wherein the application data is generated at least based on the chip identifier of the baseband chip; S302: Receiving application response data regarding satellite service authentication parameters; wherein the application response data is generated by the authentication management system based on the application data; S303: When the application response data is verified, sending confirmation data regarding the satellite service authentication parameters; S304: Receiving confirmation response data regarding the satellite service authentication parameters; wherein the confirmation response data is received by the terminal after the authentication management system verifies the confirmation data; S305: Obtaining the satellite service authentication parameters based on the confirmation response data.
[0054] Specifically, the authentication data processing method for the aforementioned satellite short messages can be applied to the terminal side.
[0055] The aforementioned terminals can be understood as user terminals that support satellite communication services. Specifically, these terminals can be electronic devices owned by users that support satellite communication, such as mobile phones, tablets, navigators, and smartwatches. It should be noted that the terminals listed above are only illustrative. In actual implementation, depending on the specific application scenario and processing requirements, the aforementioned terminals may also include other types of electronic devices. This specification does not limit this.
[0056] Specifically, the aforementioned terminal includes at least a baseband chip associated with the satellite. This baseband chip can be understood as a processing chip that supports satellite communication.
[0057] The aforementioned baseband chip may specifically include a CPU processor, channel encoder, digital signal processor, modem, and interface module. Based on this baseband chip, the terminal can synthesize and transmit corresponding baseband signals to satellites, as well as receive and decode baseband signals from satellites.
[0058] Specifically, each baseband chip can have a one-to-one chip identifier, such as a unique chip number. In practice, this chip identifier can be used to identify the terminal containing that baseband chip.
[0059] The aforementioned satellites may specifically include BeiDou Navigation Satellites, etc. Of course, in specific implementations, depending on the circumstances, the aforementioned satellites may also be other suitable types of satellites besides BeiDou. This specification does not impose any limitations on this.
[0060] Furthermore, an authentication unit for satellite communication service authentication and verification can be embedded within the baseband chip, such as an authentication IP core. Accordingly, the terminal can securely complete data processing for satellite communication service authentication and verification by invoking the authentication unit deployed within the baseband chip.
[0061] The authentication unit mentioned above can be deployed with preset protocol rules. These preset protocol rules may specifically include data processing rules, interactive transmission rules, verification rules, and confidentiality rules related to satellite communication service authentication and verification. The authentication management system and the satellite gateway can each be deployed with corresponding preset protocol rules.
[0062] Specifically, the aforementioned satellite communication services may include satellite-based short message services, such as satellite short message service (or satellite SMS service). Of course, in specific implementations, depending on the application scenario and processing requirements, the aforementioned satellite communication services may also include other types of services such as satellite navigation services. This specification does not limit this.
[0063] The aforementioned satellite service authentication parameters can be understood as the data credentials obtained by the terminal after passing the authentication verification of the satellite communication service, which are used to perform the satellite communication service.
[0064] In practice, the terminal can automatically detect whether the preset triggering conditions are met. When the preset triggering conditions are met, it triggers the generation of application data for satellite service authentication parameters and sends the application data to initiate the first round of interactive verification.
[0065] Conversely, if the preset triggering conditions are not met, the above detection will continue.
[0066] In practice, after the terminal connects to the terrestrial mobile network, it automatically detects whether there are valid satellite service authentication parameters on the terminal's local machine. When it is detected that there are no satellite service authentication parameters on the terminal's local machine; or when satellite service authentication parameters exist but have expired (for example, the cumulative time of the satellite service authentication parameters is greater than a preset first duration threshold), it is determined that the preset triggering condition is met.
[0067] In practice, the terminal can obtain the chip identifier of the baseband chip and use the chip identifier of the baseband chip to generate application data for applying to obtain satellite service authentication parameters.
[0068] The above-mentioned generation of application data regarding satellite service authentication parameters can, in specific implementation, include: First, the terminal uses the SDK (Software Development Kit) to call a random number generator to generate a first random number corresponding to the application data (for example, it can be denoted as...). The system generates an application serial number for the application data, and simultaneously queries and obtains the identity identifier of the terminal holder (e.g., user ID), the current date information (or time information), and the chip identifier of the baseband chip. Further, the terminal can invoke the authentication unit to generate an application authentication code for the application data (e.g., which can be denoted as [missing information]) based on preset protocol rules and relevant encryption algorithms, using the aforementioned application serial number, baseband chip identifier, user identity identifier, first random number, and date information. Then, based on the aforementioned application authentication code, the corresponding application data is generated and encapsulated. The aforementioned application data includes at least the application authentication code.
[0069] In a specific implementation, sending the application data as described above may include: the terminal sending the application data to the satellite gateway via a terrestrial network; wherein the satellite gateway forwards the application data to the authentication management system.
[0070] After receiving the application data, the authentication management system can first perform time-synchronization-based verification of the application data; if the application data verification is successful, it can then generate corresponding application response data; and forward the application response data to the terminal through the satellite gateway to complete the first round of interactive verification.
[0071] The aforementioned time-synchronization-based application data verification can be implemented as follows: The authentication management system can first calculate and detect whether the absolute value of the difference between the date information in the application data and the receipt date when the application data is received is less than a preset second duration threshold (e.g., one day). When the absolute value of the difference between the date information in the application data and the receipt date when the application data is received is less than the preset second duration threshold, the application data verification is determined to be successful, that is, the time synchronization of the application data meets the requirements and can be processed. Here, the receipt date refers to the date when the authorization management system receives the application data.
[0072] Conversely, if the absolute value of the difference between the date information in the application data and the date of receipt of the application data is greater than or equal to the preset second duration threshold, it is determined that the application data verification has failed, that is, the time synchronization of the application data does not meet the requirements and cannot be processed.
[0073] The above-mentioned generation of corresponding application response data may, in specific implementation, include: when the application data verification is successful, the authentication management system generates a second random number according to preset protocol rules (for example, it can be denoted as...). Simultaneously, based on the application data, the application sequence number, baseband chip identifier, user identity identifier, and first random number corresponding to the application data are obtained; then, according to preset protocol rules and in combination with relevant generation functions, negotiation authentication parameters and negotiation factors for the application data are generated using the application sequence number and baseband chip identifier; then, according to preset protocol rules and in combination with relevant encryption algorithms, a registration response code for the application data is generated using the negotiation authentication parameters, user identity identifier, first random number, and second random number (for example, it can be denoted as...). Then, based on the preset protocol rules and relevant encryption algorithms, using the application serial number, the verification result of the application data, the second random number, and the registration response code, a corresponding reply authentication code is generated (for example, it can be denoted as...). Finally, according to the preset protocol rules, the corresponding application response data is generated using the registration response code, reply authentication code, second random number, and application sequence number. This application response data includes at least the registration response code and the reply authentication code.
[0074] When the application data is verified, the authentication management system can also generate and record satellite service authentication parameters corresponding to the application data in advance according to preset protocol rules. Specifically, the authentication management system can generate satellite service authentication parameters for the application data based on preset protocol rules, combined with relevant generation functions, using the user's identity identifier, a first random number, a second random number, and a negotiation factor.
[0075] When the application data fails, the authentication management system can directly set the registration response code and reply authentication code to 0 according to the preset protocol rules; and then generate the corresponding application reply data based on the above registration response code and reply authentication code.
[0076] After receiving the application response data, the terminal can first extract the registration response code and response authentication code from the data. Based on these codes, it can then determine whether the previously sent application data has been successfully verified by the authentication management system. Specifically, if both the registration response code and the response authentication code are 0, the application data has failed verification; in this case, the terminal can regenerate and resend the application data. Conversely, if at least one of the registration response code or the response authentication code is not 0, the application data has passed verification, triggering a second round of interactive verification.
[0077] The verification of the application response data described above can be implemented as follows: First, the terminal obtains the application sequence number, response authentication code, and registration response code from the application response data; then, based on the application sequence number in the previously sent application data, it performs a consistency check on the application sequence number in the application response data; if the two application sequence numbers are the same, it is determined that the consistency check of the application sequence number in the application response data has passed, and it can be determined that the application response data corresponds to the previously sent application data. Then, the authentication unit can be called to verify the response authentication code and registration code in the application response data according to the preset protocol rules; when both the response authentication code and the registration response code have passed the verification, it is determined that the application response data has been verified successfully.
[0078] Conversely, if the two application sequence numbers are different, it indicates that the application sequence number consistency check in the application response data has failed, meaning that the application response data does not correspond to the previously sent application data. In this case, the terminal can continue waiting for the application response data until it receives the corresponding application response data within a preset waiting time. If the corresponding application response data is not received within the preset waiting time, the terminal can exit the waiting state and send a timeout notification to the user; and / or, regenerate and resend the application data.
[0079] When the application sequence number in the application response data passes the consistency check, but at least one of the response authentication code and registration response code fails the verification, the terminal can generate an error message; and forward the error message to the authentication management system through the satellite gateway so that the authentication management system can regenerate accurate application response data.
[0080] Once the application response data verification is successful, the terminal can generate corresponding confirmation data according to the preset protocol rules; and forward the confirmation data to the authentication management system through the satellite gateway.
[0081] The generation of the aforementioned confirmation data, in specific implementation, may include: the terminal obtaining negotiation authentication parameters, a second random number, and other data based on the application response data; then, calling the authentication unit to generate a corresponding confirmation response code (for example, it can be denoted as...) according to preset protocol rules, combined with relevant encryption algorithms, using the negotiation authentication parameters, the second random number, and the user's identity identifier. ); and generate corresponding confirmation data based on the confirmation response code; wherein the confirmation data includes at least the confirmation response code.
[0082] After generating confirmation data, the terminal can forward the confirmation data to the authentication management system via the satellite gateway.
[0083] After receiving the confirmation data, the authentication management system verifies the confirmation data. When the confirmation data passes the verification, it can encrypt the satellite service authentication parameters to obtain the encrypted data of the satellite service authentication parameters. At the same time, it generates the corresponding confirmation reply data and then sends the confirmation reply data carrying the encrypted data of the satellite service authentication parameters to the satellite gateway.
[0084] The verification of the confirmation data described above may include the following steps: First, obtaining the corresponding application number, user identity identifier, baseband chip identifier, and confirmation response code based on the confirmation data. Then, performing a consistency check on the application number, user identity identifier, and baseband chip identifier in the confirmation data against the previously obtained application data. If the consistency check passes, verifying the confirmation response code in the confirmation data according to preset protocol rules. If the confirmation response code verification passes, the confirmation data is deemed verified. Otherwise, the confirmation data is deemed to have failed verification. If the confirmation data fails verification, the authentication management system may choose not to respond.
[0085] When the verification of the confirmed data is successful, the authentication management system encrypts the satellite service authentication parameters using a pre-defined code according to the preset protocol rules, obtaining the encrypted data of the satellite service authentication parameters; at the same time, it generates the authentication verification result of the application data, and generates the corresponding confirmation response data based on the verification result; then it adds the encrypted data of the satellite service authentication parameters to the confirmation response data, obtaining confirmation response data carrying the encrypted data of the satellite service authentication parameters; and finally sends the confirmation response data to the satellite gateway.
[0086] Specifically, the pre-configured code can be data associated with the satellite gateway and held only by the satellite gateway and the authentication management system. Specifically, the pre-configured code can be a unique identifier provided by the manufacturer when the satellite gateway leaves the factory. Correspondingly, the authentication management system can use the pre-configured code instead of key data to encrypt satellite service authentication parameters. This eliminates the need to generate and manage additional keys and prevents the leakage of satellite service authentication parameters during transmission.
[0087] After receiving the acknowledgment reply data carrying the encrypted data of satellite service authentication parameters, the satellite gateway can first extract the authentication verification result from the acknowledgment reply data. Based on the authentication verification result, it can determine whether the satellite communication service authentication verification has passed. When the satellite communication service authentication verification is determined to be successful, the satellite gateway can use its pre-defined code to decrypt the encrypted data of the satellite service authentication parameters to obtain the satellite service authentication parameters in plaintext form; and store the service authentication parameters locally for subsequent storage and use by the information processing system. Then, the satellite gateway can forward the acknowledgment reply data without the encrypted data carrying the satellite service authentication parameters to the terminal.
[0088] After receiving the confirmation reply data, the terminal can extract the authentication verification result based on the confirmation reply data. When the authentication verification result indicates that the satellite communication service authentication verification is successful, the satellite service authentication parameters are determined to be valid. At this time, the terminal can respond to the confirmation reply data and generate the corresponding satellite service authentication parameters locally according to the preset protocol rules. The terminal can then save the satellite service authentication parameters locally to complete the second round of interactive verification.
[0089] In some cases, after receiving the satellite service authentication parameters in plaintext, the satellite gateway can replace the previously encrypted satellite service authentication code with these plaintext parameters and add them to the confirmation response data; then, it forwards this confirmation response data to the terminal. In this way, if the terminal determines that the satellite service authentication parameters are valid, it can directly obtain the satellite service authentication parameters from the confirmation response data.
[0090] After obtaining the satellite service authentication parameters, the terminal can receive and respond to the user's triggered operations, and use the locally stored satellite service authentication parameters to perform data processing based on satellite communication services. For example, it can use the satellite service authentication parameters to generate a corresponding short message; then, it can send the short message to the corresponding target terminal via satellite.
[0091] Based on the above embodiments, by introducing and using the chip identifier of the baseband chip and multiple rounds of interactive verification, authentication and verification of satellite communication services can be achieved efficiently and securely with a relatively small amount of data processing. This can effectively reduce the security risks caused by the tampering of relevant information during the authentication and verification process, and protect the data security during satellite communication. Furthermore, it can also better handle complex business scenarios where a large number of users concurrently apply for relevant satellite communication services.
[0092] In some embodiments, sending the application data regarding satellite service authentication parameters may specifically include: sending the application data regarding satellite service authentication parameters to a satellite gateway; wherein the satellite gateway forwards the application data to the authentication management system.
[0093] In practice, the application data may carry identification information indicating satellite communication services. The terminal can send the application data to the satellite gateway via a terrestrial network (e.g., a mobile network). Upon receiving the application data, the satellite gateway can determine the corresponding authentication management system based on the identification information carried in the application data and forward the application data to that authentication management system.
[0094] In some embodiments, the method may further include: invoking an authentication unit to generate the application data.
[0095] Specifically, the authentication unit can be deployed within the baseband chip. Specifically, the chip identifier of the baseband chip can be stored within the baseband chip and its use is restricted to the baseband chip.
[0096] Based on the above embodiments, the terminal generates the application data by calling the authentication unit deployed on the baseband chip, rather than directly calling the processing unit on the main system deployed on the terminal's main chip. On the one hand, it can efficiently obtain and use the chip identifier of the baseband chip; on the other hand, it can also effectively prevent third parties from leaking relevant information of the application data, especially the chip identifier of the baseband chip, by intruding into the terminal's main system, thereby better protecting the data information security during the authentication and verification process.
[0097] In some embodiments, the step of calling the authentication unit to generate the application data may specifically include: when it is detected that there are no satellite service authentication parameters on the terminal's local machine, calling the authentication unit to generate the application data; or, when it is detected that the cumulative time of the satellite service authentication parameters on the terminal's local machine is greater than a preset first duration threshold (e.g., one week), calling the authentication unit to generate the application data.
[0098] In practice, when the terminal detects that there are no valid satellite service authentication parameters locally, or that the cumulative time of the local satellite service authentication parameters exceeds a preset first duration threshold, it determines that the preset triggering conditions are met. When the preset triggering conditions are met, the terminal triggers the authentication unit to generate application data for satellite service authentication parameters, thereby initiating authentication verification based on satellite communication services and obtaining the satellite service authentication parameters.
[0099] The aforementioned preset first duration threshold can be determined based on relevant communication protocols and / or historical satellite communication service records.
[0100] The aforementioned cumulative time can be the cumulative time from the moment the satellite service authentication parameters are received until the current time.
[0101] Specifically, for example, according to preset protocol rules, when the terminal detects that the cumulative time of the locally stored satellite service authentication parameters is greater than a preset first duration threshold, it can determine that the satellite service authentication parameters have expired and mark the satellite service authentication parameters as expired; delete the satellite service authentication parameters marked as expired by the terminal, and trigger a re-application to obtain satellite service authentication parameters.
[0102] For example, according to preset protocol rules, if the terminal detects that the cumulative time of the locally stored satellite service authentication parameters exceeds a preset first duration threshold, the satellite service authentication parameters remain valid. However, to ensure satellite communication security, according to preset protocol rules, a new request for satellite service authentication parameters can be triggered to update the locally stored parameters. If this request fails and new satellite service authentication parameters cannot be obtained, the terminal can continue to use the previously stored locally stored parameters and perform relevant data processing based on satellite communication services normally.
[0103] In some embodiments, referring to Figure 4, the step of calling the authentication unit to generate the application data may include the following: S1: calling the authentication unit to generate a first random number and an application sequence number; S2: obtaining the user's identity identifier, date information, and the chip identifier of the baseband chip; S3: calling the authentication unit to generate an application authentication code based on the application sequence number, the chip identifier of the baseband chip, the user's identity identifier, the first random number, and the date information; S4: generating the application data based on the application authentication code.
[0104] Specifically, the date information mentioned above can be date information based on UTC (Coordinated Universal Time).
[0105] The aforementioned user identification can be understood as identification information that can be used to indicate the user holding the terminal. Specifically, the aforementioned user identification may include one or more combinations of the following: identification number (e.g., user ID), account name, registered mobile phone number, etc.
[0106] The aforementioned authentication unit generates an application authentication code based on the application number, the baseband chip's chip identifier, the user's identity identifier, the first random number, and the date information. In specific implementation, this may include: based on preset protocol rules, calling the authentication unit, combining multiple encryption algorithms, and using the application number, the baseband chip's chip identifier, the user's identity identifier, the first random number, and the date information to generate the application authentication code.
[0107] Specifically, based on preset protocol rules, the authentication unit can be invoked to sequentially concatenate the application sequence number, the baseband chip's chip identifier, the user's identity identifier, and the first random number (e.g., ...) according to specified concatenation rules. The first information sequence is obtained by first encrypting the first information sequence using the first encryption algorithm (e.g., SM3 encryption algorithm) combined with the initial parameters, and then the ciphertext data of the first information sequence is obtained by first encrypting the first information sequence using the second encryption algorithm (e.g., MSB encryption algorithm), and then the ciphertext data of the first information sequence is obtained by second encrypting the first information sequence using the second encryption algorithm (e.g., MSB encryption algorithm), and then the corresponding application authentication code (e.g., ...) is obtained by first encrypting the first information sequence using the second encryption algorithm (e.g., MSB encryption algorithm). ).
[0108] The aforementioned initial parameters can be encrypted parameters that are jointly held and stored by the terminal and the authentication management system based on preset protocol rules and are not disclosed to the public.
[0109] Specifically, for example, the authentication unit can be invoked to generate the corresponding application authentication code in the following manner:
[0110] In this context, "||" represents a concatenation operation.
[0111] In practice, application data can be generated based on the aforementioned application authentication code; wherein the application data includes at least the application authentication code. Correspondingly, after receiving the application data, the authentication management terminal can, according to preset protocol rules and based on the aforementioned application authentication code, calculate and obtain relevant data information such as the application sequence number, the baseband chip's chip identifier, the user's identity identifier, a first random number, and date information used to generate the application authentication code.
[0112] In some cases, the application data may include, in addition to the application authentication code, the application serial number, the baseband chip's chip identifier, the user's identity identifier, the first random number, date information, and other related data.
[0113] In some embodiments, after receiving the application response data regarding satellite service authentication parameters, referring to Figure 5, the method may further include the following: S1: performing a consistency check on the application sequence number in the application response data; S2: when the application sequence number consistency check passes, verifying the response authentication code and registration response code in the application response data; S3: when the response authentication code and registration response code pass verification, generating confirmation data regarding the satellite service authentication parameters.
[0114] The aforementioned application response data includes at least the registration response code (e.g., ) and response authentication code (e.g., ).
[0115] Accordingly, after receiving the aforementioned application response data, the terminal can first extract the registration response code and the response authentication code; then, based on the preset protocol rules and the aforementioned registration response code and response authentication code, it can calculate and obtain the negotiated authentication parameters and the second random number (e.g., ...) used to generate the aforementioned registration response code and / or response authentication code. (and other related data and information.)
[0116] Furthermore, in addition to the registration response code and response authentication code, the aforementioned application response data may also include negotiation authentication parameters, a second random number, and other related data. Accordingly, the terminal can directly obtain the negotiation authentication parameters, the second random number, and other related data by accessing this application response data.
[0117] In some embodiments, the verification of the reply authentication code and registration response code in the application reply data may include the following: S1: Invoking the authentication unit to generate a reference reply authentication code and a reference registration response code locally based on preset protocol rules; S2: Verifying the reply authentication code and registration response code in the application reply data according to the reference reply authentication code and the reference registration response code.
[0118] Specifically, the terminal can directly parse the application response data to obtain relevant data information such as negotiation authentication parameters and the second random number; then, it can call the authentication unit to calculate the reference response authentication code and the reference registration response code locally on the second terminal based on the preset protocol rules and using the aforementioned negotiation authentication parameters, the second random number, and other relevant data information.
[0119] Specifically, the terminal can invoke the authentication unit to determine the first constant (e.g., based on preset protocol rules) according to the authentication unit. Then, according to the preset protocol rules, the first constant, the first random number, the second random number, and the user's identity identifier are concatenated to obtain the third sequence information; then, the third information sequence is encrypted for the first time according to the first encryption algorithm (e.g., SM3 encryption algorithm) combined with the negotiated authentication parameters to obtain the ciphertext data of the third information sequence; then, the ciphertext data of the third information sequence is encrypted for the second time according to the second encryption algorithm (e.g., MSB encryption algorithm) to obtain the corresponding registration response code, which serves as the reference registration response code.
[0120] Specifically, the terminal can call the authentication unit to concatenate the application sequence number, the second random number, and the reference registration response code based on preset protocol rules to obtain the fourth information sequence; then, according to the first encryption algorithm (e.g., SM3 encryption algorithm) combined with the initial parameters, the fourth information sequence is encrypted for the first time to obtain the ciphertext data of the fourth information sequence; then, according to the second encryption algorithm (e.g., MSB encryption algorithm), the ciphertext data of the fourth information sequence is encrypted for the second time to obtain the corresponding reply authentication code, which serves as the reference reply authentication code.
[0121] Specifically, the terminal can compare the locally calculated reference registration response code and reference reply authentication code with the registration response code and reply authentication code directly parsed from the application reply data to obtain the corresponding comparison results. According to the comparison results, when the registration response code in the application reply data is the same as the locally calculated reference registration response code, and the reply authentication code in the application reply data is the same as the locally calculated reference reply authentication code, it can be determined that the reply authentication code and registration response code in the application reply data have been verified. Then, it can be determined that the application reply data has been verified and the corresponding confirmation data is triggered.
[0122] In some embodiments, the generation of confirmation data regarding satellite service authentication parameters may specifically include the following: S1: Invoking the authentication unit to generate a confirmation response code (for example, it can be denoted as...). S2: Generate the confirmation data based on the confirmation response code; wherein the confirmation data includes at least the confirmation response code.
[0123] The aforementioned confirmation data may include at least a confirmation response code. Accordingly, based on the preset protocol rules and this confirmation response code, a second random number used to generate the confirmation response code, the user's identity identifier, and other relevant data information can be calculated and obtained.
[0124] Furthermore, the aforementioned confirmation data may also include: application serial number, user identification, baseband chip chip identification, and other related data information.
[0125] Specifically, the terminal can invoke the authentication unit to determine the second constant (for example, it can be denoted as...) according to preset protocol rules. According to the preset protocol rules, the second constant, the second random number, and the user's identity identifier are concatenated to obtain the fifth information sequence; then, the fifth information sequence is encrypted for the first time using the first encryption algorithm (e.g., SM3 encryption algorithm) combined with the negotiated authentication parameters to obtain the ciphertext data of the fifth information sequence; then, the ciphertext data of the fifth information sequence is encrypted for the second time using the second encryption algorithm (e.g., MSB encryption algorithm) to obtain the confirmation response code (e.g., ...). ).
[0126] Specifically, for example, the authentication unit can be invoked to generate the corresponding confirmation response code in the following manner: .
[0127] In some embodiments, the confirmation response data may not carry satellite service authentication parameters; correspondingly, the step of obtaining satellite service authentication parameters based on the confirmation response data may specifically include the following: S1: Extracting the authentication verification result based on the confirmation response data; S2: When the authentication verification result indicates that the satellite communication service authentication verification is successful, determining that the satellite service authentication parameters are valid; S3: When the satellite service authentication parameters are determined to be valid, responding to the confirmation response data, generating satellite service authentication parameters according to preset protocol rules; and saving the satellite service authentication parameters locally.
[0128] The confirmation response data contains at least satellite service authentication parameters.
[0129] Specifically, based on the data generated and / or acquired during previous interactions, the user's identity identifier, first random number, second random number, negotiation factor, and other information can be extracted according to the preset protocol rules. Then, according to the preset protocol rules, satellite service authentication parameters can be generated locally using the user's identity identifier, first random number, second random number, and negotiation factor.
[0130] Specifically, the satellite service authentication parameters can be stored together with the baseband chip's chip identifier in the baseband chip.
[0131] Based on the above embodiments, when the authentication verification is successful, the terminal can successfully obtain the satellite service authentication parameters provided by the authentication management system and save the satellite service authentication parameters locally on the terminal for easy retrieval and use later.
[0132] In some embodiments, the method may further include the following: S1: In response to a trigger operation, generate a satellite service authentication code using locally stored satellite service authentication parameters; S2: Add the satellite service authentication code to a short message; S3: Send the short message to the satellite.
[0133] Specifically, the aforementioned triggering operation can be an operation initiated by the user on the terminal to instruct the use of short message services. The aforementioned short message (e.g., satellite SMS) can be understood as short message data that carries at least a satellite service authentication code.
[0134] In practice, the user's identity identifier and the baseband chip's chip identifier can be obtained; then, the satellite service authentication parameters, the user's identity identifier, and the baseband chip's chip identifier can be combined to generate the aforementioned satellite service authentication code.
[0135] In practice, the terminal can transmit the short message to the satellite via its baseband chip. Upon receiving the short message, the satellite can transmit it to the ground station via downlink. The ground station then forwards the short message to the information processing system (or short message service processing center). The information processing system pre-obtains the corresponding satellite service authentication parameters through the satellite gateway. After receiving the short message from the ground station, the information processing system can use the corresponding satellite service authentication parameters to check whether the short message carries a valid satellite service authentication code. If it is determined that the short message carries a valid satellite service authentication code, the short message is deemed valid and then transmitted to the target terminal via the terrestrial network.
[0136] Based on the above embodiments, the terminal can efficiently send short messages by using the stored satellite service authentication parameters.
[0137] In some embodiments, in order to further improve the security of data information during the verification process, the terminal can call the authentication unit to complete the relevant data processing in the terminal's trusted execution environment.
[0138] Specifically, the aforementioned trusted execution environment can include a high-security-level environment area within the terminal (e.g., a security level that meets preset security requirements). More specifically, the trusted execution environment can be a hardware area separated from the terminal's hardware resources through hardware configuration or other means, isolated from commonly used, relatively open environment areas (e.g., Rich Execution Environment, REE, etc.).
[0139] In this embodiment, the Trust Execution Environment (TEE) described above can run a complete operating system, which can be understood as the Secure World within the terminal. Unlike the Normal World (e.g., the REE in the terminal), the memory space of the TEE is typically relatively small, for example, perhaps only 100MB. In the terminal, usually only a portion of data with high security requirements is processed in the TEE; most data is processed in the Normal World, such as the REE. Of course, the Trust Execution Environment listed above is only an illustrative example. In specific implementations, depending on the specific application scenario and the specific conditions of the terminal, other suitable areas with higher security levels within the terminal can be selected to replace the TEE.
[0140] Based on the satellite short message authentication data processing method provided in the embodiments of this specification, the terminal can first send application data for satellite service authentication parameters to the authentication management system through a satellite gateway; wherein, the application data is generated based at least on the chip identifier of the baseband chip; after receiving application response data sent by the authorization management system after verifying the application data, the terminal can verify the application response data; when the application response data is verified, the terminal can send confirmation data for satellite service authentication parameters to the authentication management system through the satellite gateway; after receiving confirmation response data sent by the authorization management system after verifying the confirmation data, the terminal can obtain valid satellite service authentication parameters based on the confirmation response data, and then use the satellite service authentication parameters to normally use the corresponding satellite communication services. By introducing and using the chip identifier of the baseband chip, and multiple rounds of interactive verification, authentication verification for satellite communication services can be achieved efficiently and securely with a relatively small amount of data processing, thereby effectively reducing security risks in the authentication verification process and better protecting the data information security during satellite communication.
[0141] Referring to Figure 6, this embodiment of the specification also provides another method for processing authentication data for satellite short messages, which can be applied to an authentication management system. The method, when specifically implemented, may include the following: S601: Receiving application data regarding satellite service authentication parameters; wherein the application data is generated at least based on the chip identifier of the baseband chip; S602: Based on the application data, sending application response data regarding satellite service authentication parameters; S603: Receiving confirmation data regarding satellite service authentication parameters; S604: When the confirmation data is verified, sending confirmation response data regarding satellite service authentication parameters.
[0142] In practice, the authentication management system can receive application data from the terminal through the satellite gateway; and send the application response data to the terminal through the satellite gateway to complete the first round of interactive verification.
[0143] Furthermore, the authentication management system can receive confirmation data from the terminal via a satellite gateway; and send confirmation response data to the terminal via the satellite gateway to complete the second round of interactive verification.
[0144] In some embodiments, after receiving application data regarding satellite service authentication parameters, the method may further include the following: S1: detecting whether the absolute value of the difference between the date information in the application data and the receiving date is less than a preset second duration threshold; S2: when the absolute value of the difference between the date information in the application data and the receiving date is less than the preset second duration threshold, determining that the application data has been verified.
[0145] In some embodiments, when the application data verification is successful, the method may further include the following: S1: Generating a second random number (e.g., S1: Generate negotiation authentication parameters and negotiation factors based on the application serial number and baseband chip identifier in the application data; S2: Generate a registration response code based on the negotiation authentication parameters, user identity identifier, first random number, and second random number; S3: Generate a reply authentication code based on the application serial number, verification result of application data, second random number, and registration response code; S4: Generate application reply data regarding satellite service authentication parameters based on the registration response code, reply authentication code, second random number, and application serial number.
[0146] The above-mentioned generation of negotiation authentication parameters and negotiation factors based on the application serial number and baseband chip identifier in the application data can, in specific implementation, include: generating corresponding negotiation authentication parameters and negotiation factors using the application serial number and baseband chip identifier according to preset protocol rules and in combination with relevant generation functions (e.g., KDF function). The KDF (Key Derivation function) can be specifically understood as a key derivation function.
[0147] In practice, the authentication management system can first obtain relevant data information such as application serial number, baseband chip chip identifier, first random number, and user identity identifier based on the application data according to the preset protocol rules; then, based on the preset protocol rules, it can concatenate the initial parameters, application serial number, and baseband chip chip identifier to obtain the second information sequence; then, it can use relevant generation functions to process the second information sequence to obtain the corresponding processing result; and according to the preset protocol rules, it can extract the negotiation authentication parameters and negotiation factor from the processing result.
[0148] Specifically, for example, negotiation authentication parameters and negotiation factors can be generated as follows: Negotiation authentication parameters || Negotiation factor = KDF(initial parameters || application number || baseband chip chip identifier).
[0149] The above-mentioned registration response code is generated based on the negotiated authentication parameters, the user's identity identifier, the first random number, and the second random number (e.g., In specific implementation, this may include: determining a first constant based on preset protocol rules (e.g., Then, according to the preset protocol rules, the first constant, the first random number, the second random number, and the user's identity identifier are concatenated to obtain the third sequence information; then, the third information sequence is encrypted for the first time according to the first encryption algorithm (e.g., SM3 encryption algorithm) combined with the negotiated authentication parameters to obtain the ciphertext data of the third information sequence; then, the ciphertext data of the third information sequence is encrypted for the second time according to the second encryption algorithm (e.g., MSB encryption algorithm) to obtain the corresponding registration response code.
[0150] Specifically, for example, a registration response code can be generated in the following way: .
[0151] The above-mentioned response authentication code is generated based on the application serial number, the verification result of the application data, the second random number, and the registration response code (e.g., In specific implementation, it may include: based on preset protocol rules, concatenating the application sequence number, the second random number, and the registration response code to obtain the fourth information sequence; then, according to the first encryption algorithm (e.g., SM3 encryption algorithm) combined with the initial parameters, performing the first encryption process on the fourth information sequence to obtain the ciphertext data of the fourth information sequence; then, according to the second encryption algorithm (e.g., MSB encryption algorithm), performing the second encryption process on the ciphertext data of the fourth information sequence to obtain the corresponding reply authentication code.
[0152] When constructing the fourth information sequence, the verification result (or application result) of the application data can be determined based on whether the application data has been verified. Then, based on the preset protocol rules, the verification result, application number, second random number, and registration response code of the application data are concatenated to obtain the fourth information sequence.
[0153] Specifically, for example, when the application data verification passes, the verification result of the application data can be set to 1; conversely, when the application data verification fails, the verification result of the application data can be set to 0 or empty.
[0154] Specifically, for example, a response authentication code can be generated in the following way: .
[0155] In some embodiments, after determining that the application data has been verified, the method may further include the following: S1: generating satellite service authentication parameters based on the user's identity identifier, a first random number, a second random number, and a negotiation factor; S2: recording the satellite service authentication parameters, as well as the user's identity identifier, the baseband chip's chip identifier, and the application serial number corresponding to the satellite service authentication parameters.
[0156] The above-mentioned satellite service authentication parameters are generated based on the user's identity identifier, the first random number, the second random number, and the negotiation factor. In specific implementation, this may include: concatenating the user's identity identifier, the negotiation factor, the first random number, and the second random number according to preset protocol rules to obtain a fifth information sequence; and then using a relevant generation function (e.g., the KDF function) to process the fifth information sequence to obtain the corresponding processing result, which is used as the satellite service authentication parameters.
[0157] Specifically, for example, satellite service authentication parameters can be generated in the following manner: .
[0158] In practice, after generating the satellite service authentication parameters, the authentication management system can record the satellite service authentication parameters, as well as the application number, baseband chip chip identifier, user identity identifier, and other relevant information corresponding to the satellite service authentication parameters.
[0159] In some embodiments, after receiving confirmation data regarding satellite service authentication parameters, the method may further include the following: S1: performing a consistency check on the application number, user identity identifier, and baseband chip identifier in the confirmation data; S2: when the consistency check of the application number, user identity identifier, and baseband chip identifier passes, calculating and verifying the confirmation response code in the confirmation data; S3: when the confirmation response code passes verification, generating confirmation reply data carrying encrypted data of satellite service authentication parameters.
[0160] In practice, the authentication management terminal can use relevant data information obtained based on the application data and confirmation data to calculate a reference confirmation response code locally. Then, it verifies the confirmation response code in the confirmation data by comparing it with the reference confirmation response code. When the two confirmation response codes are the same, the verification is successful. Conversely, when the two confirmation response codes are different, the verification fails.
[0161] In practice, when the confirmation response code verification passes, the authentication management system can further generate confirmation reply data carrying encrypted data containing satellite service authentication parameters. Conversely, when the confirmation response code verification fails, the robust management system will not respond to the confirmation data.
[0162] In some embodiments, the generation of ciphertext data carrying satellite service authentication parameters may specifically include: encrypting the satellite service authentication parameters using a pre-defined code of the satellite gateway (e.g., a pre-defined code from the gateway server vendor) according to preset protocol rules to obtain ciphertext data of the satellite service authentication parameters; and adding the ciphertext data of the satellite service authentication parameters to the acknowledgment response data.
[0163] In practice, the authentication management system can first use a first encryption algorithm (e.g., SM3) to encrypt the satellite service authentication parameters according to the preset protocol rules to obtain the first encryption result; then use a second encryption algorithm (e.g., MSB) to encrypt the first encryption result a second time to obtain the second encryption result; the second encryption result and the satellite service authentication parameters are concatenated to obtain concatenated data; then a third encryption algorithm (e.g., SM4) is used in conjunction with a pre-defined code to encrypt the concatenated data to obtain the ciphertext data of the corresponding satellite service authentication parameters.
[0164] Specifically, for example, the encrypted data of satellite service authentication parameters can be obtained in the following way: .
[0165] In some embodiments, the authentication management system can send the confirmation response data regarding the satellite service authentication parameters to the satellite gateway; wherein the confirmation response data carries encrypted data of the satellite service authentication parameters, and the satellite gateway holds the same pre-coded data.
[0166] Accordingly, after sending the confirmation reply data regarding satellite service authentication parameters, the method may further include: the satellite gateway determining whether the satellite communication service authentication verification is successful based on the confirmation reply data; when the satellite communication service authentication verification is successful, the satellite gateway decrypts the encrypted data of the satellite service authentication parameters using its pre-defined code according to preset protocol rules to obtain the satellite service authentication parameters; saves the satellite service authentication parameters; and then forwards the confirmation reply data to the terminal. Specifically, the satellite gateway can forward confirmation reply data without carrying satellite service authentication parameters and without carrying encrypted data of satellite service authentication parameters to the terminal. In certain scenarios, according to the corresponding communication protocol, the satellite gateway can also forward confirmation reply data carrying satellite service authentication parameters to the terminal.
[0167] Referring to Figure 7, this embodiment of the specification also provides another method for processing authentication data of satellite short messages, which can be applied to satellite gateways. The method, in its specific implementation, may include the following: S701: Receiving confirmation reply data regarding satellite service authentication parameters sent by the authentication management system; wherein the confirmation reply data carries encrypted data of the satellite service authentication parameters; S702: When the confirmation reply data indicates that the terminal's satellite communication service authentication verification is successful, decrypting the encrypted data of the satellite service authentication parameters to obtain the corresponding satellite service authentication parameters; and saving the satellite service authentication parameters; S703: Forwarding the confirmation reply data to the terminal.
[0168] The aforementioned confirmation response data can be encrypted data that does not carry satellite service authentication parameters. This effectively prevents the satellite service authentication parameters carried in the confirmation response data from being intercepted and leaked during transmission.
[0169] In specific implementation, the method may further include: receiving application data sent by the terminal; and forwarding the application data to the authentication management system.
[0170] In specific implementation, the method may further include: receiving application response data sent by the authentication management system; and forwarding the application response data to the terminal.
[0171] In some embodiments, the step of decrypting the encrypted data of the satellite service authentication parameters to obtain the corresponding satellite service authentication parameters may specifically include: using a pre-defined code associated with the satellite gateway to decrypt the encrypted data of the satellite service authentication parameters to obtain the corresponding satellite service authentication parameters.
[0172] In practice, after obtaining the satellite service authentication parameters, the satellite gateway can store these parameters locally for later retrospective queries; it can also provide the relevant satellite service authentication parameters to the information processing system for storage and use. Furthermore, the satellite gateway can use the satellite service authentication parameters to replace the previously encrypted satellite service authentication parameters in the confirmation response data; then, it sends the confirmation response data carrying the satellite service authentication parameters to the terminal. Alternatively, the satellite gateway can also send confirmation response data to the terminal that does not carry satellite service authentication parameters and is also encrypted data without satellite service authentication parameters.
[0173] Referring to Figure 8, an embodiment of this specification provides an electronic device. Specifically, this electronic device can be deployed and applied to a ground-based central location.
[0174] Specifically, the electronic device includes a network communication port 801, a processor 802, and a memory 803. These structures are connected by internal cables so that each structure can perform specific data interaction.
[0175] Specifically, the network communication port 801 can be used to receive trigger commands.
[0176] The processor 802 can specifically be used to respond to a trigger command and send application data regarding satellite service authentication parameters; wherein the application data is generated based at least on the chip identifier of the baseband chip; receive application response data regarding satellite service authentication parameters; wherein the application response data is generated by the authentication management system based on the application data; when the application response data is verified, send confirmation data regarding satellite service authentication parameters; receive confirmation response data regarding satellite service authentication parameters; wherein the confirmation response data is received by the terminal after the authentication management system verifies the confirmation data; and obtain satellite service authentication parameters based on the confirmation response data.
[0177] The memory 803 can be used to store the corresponding instruction program and related intermediate data.
[0178] Based on the above method, the relevant structural performance of electronic devices can be effectively utilized to improve the data processing speed of electronic devices and efficiently realize the data processing for determining the signal arrival angle of satellite signals.
[0179] In this embodiment, the network communication port 801 can be a virtual port bound to different communication protocols, thereby enabling the sending or receiving of different data. For example, the network communication port can be a port responsible for web data communication, a port responsible for FTP data communication, or a port responsible for email data communication. Furthermore, the network communication port can also be a physical communication interface or communication chip. For example, it can be a wireless mobile network communication chip, such as GSM or CDMA; it can also be a Wi-Fi chip; or it can be a Bluetooth chip.
[0180] In this embodiment, the processor 802 can be implemented in any suitable manner. For example, the processor can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers, etc. This specification is not limiting.
[0181] In this embodiment, the memory 803 may include multiple layers. In a digital system, anything that can store binary data can be a memory. In an integrated circuit, a circuit with storage function but no physical form is also called a memory, such as RAM, FIFO, etc. In a system, a storage device with a physical form is also called a memory, such as a memory stick, TF card, etc.
[0182] This specification also provides a computer-readable storage medium for the authentication data processing method based on the above-described satellite short message service. The computer-readable storage medium stores computer program instructions that, when executed, implement the following: sending application data regarding satellite service authentication parameters; wherein the application data is generated at least based on the chip identifier of the baseband chip; receiving application response data regarding satellite service authentication parameters; wherein the application response data is generated by the authentication management system based on the application data; when the application response data is verified, sending confirmation data regarding satellite service authentication parameters; receiving confirmation response data regarding satellite service authentication parameters; wherein the confirmation response data is received by the terminal after the authentication management system verifies the confirmation data; and obtaining satellite service authentication parameters based on the confirmation response data.
[0183] This specification also provides a computer-readable storage medium for the authentication data processing method based on the above-described satellite short message. The computer-readable storage medium stores computer program instructions that, when executed, implement the following: receiving application data regarding satellite service authentication parameters; wherein the application data is generated at least based on the chip identifier of the baseband chip; sending application response data regarding satellite service authentication parameters based on the application data; receiving confirmation data regarding satellite service authentication parameters; and sending confirmation response data regarding satellite service authentication parameters when the confirmation data is verified.
[0184] This specification also provides a computer-readable storage medium for the authentication data processing method based on the above-described satellite short message. The computer-readable storage medium stores computer program instructions that, when executed, perform the following: receiving confirmation response data regarding satellite service authentication parameters sent by the authentication management system; wherein the confirmation response data carries encrypted data of the satellite service authentication parameters; when the confirmation response data indicates that the terminal's satellite communication service authentication verification is successful, decrypting the encrypted data of the satellite service authentication parameters to obtain the corresponding satellite service authentication parameters; and forwarding the confirmation response data to the terminal.
[0185] In this embodiment, the storage medium includes, but is not limited to, Random Access Memory (RAM), Read-Only Memory (ROM), Cache, Hard Disk Drive (HDD), or Memory Card. The memory can be used to store computer program instructions. The network communication unit can be an interface configured according to standards specified in the communication protocol for network connection communication.
[0186] In this embodiment, the specific functions and effects implemented by the program instructions stored in the computer-readable storage medium can be explained in comparison with other embodiments, and will not be repeated here.
[0187] This specification also provides a computer program product, comprising at least a computer program that, when executed by a processor, implements the following method steps: sending application data regarding satellite service authentication parameters; wherein the application data is generated at least based on the chip identifier of a baseband chip; receiving application response data regarding satellite service authentication parameters; wherein the application response data is generated by an authentication management system based on the application data; when the application response data is verified, sending confirmation data regarding satellite service authentication parameters; receiving confirmation response data regarding satellite service authentication parameters; wherein the confirmation response data is received by the terminal after the authentication management system verifies the confirmation data; and obtaining satellite service authentication parameters based on the confirmation response data.
[0188] This specification also provides another computer program product, which includes at least a computer program that, when executed by a processor, implements the following method steps: receiving application data regarding satellite service authentication parameters; wherein the application data is generated at least based on the chip identifier of the baseband chip; sending application response data regarding satellite service authentication parameters based on the application data; receiving confirmation data regarding satellite service authentication parameters; and sending confirmation response data regarding satellite service authentication parameters when the confirmation data is verified.
[0189] This specification also provides another computer program product, which includes at least a computer program that, when executed by a processor, implements the following method steps: receiving confirmation response data regarding satellite service authentication parameters sent by an authentication management system; wherein the confirmation response data carries encrypted data of the satellite service authentication parameters; when the confirmation response data indicates that the terminal's satellite communication service authentication verification is successful, decrypting the encrypted data of the satellite service authentication parameters to obtain the corresponding satellite service authentication parameters; and forwarding the confirmation response data to the terminal.
[0190] Referring to Figure 9, this embodiment of the specification also provides a satellite short message authentication data processing device, which specifically includes the following structural modules: a first sending module 901, specifically used to send application data regarding satellite service authentication parameters; wherein, the application data is generated at least based on the chip identifier of the baseband chip; a first receiving module 902, specifically used to receive application response data regarding satellite service authentication parameters; wherein, the application response data is generated by the authentication management system based on the application data; a second sending module 903, specifically used to send confirmation data regarding satellite service authentication parameters when the application response data is verified; a second receiving module 904, specifically used to receive confirmation response data regarding satellite service authentication parameters; wherein, the confirmation response data is received by the terminal after the authentication management system verifies the confirmation data; and a processing module 905, specifically used to obtain satellite service authentication parameters based on the confirmation response data.
[0191] In some embodiments, when the first sending module 901 is specifically implemented, it can send application data regarding satellite service authentication parameters in the following manner: sending application data regarding satellite service authentication parameters to the satellite gateway; wherein, the satellite gateway forwards the application data to the authentication management system.
[0192] In some embodiments, when the device is specifically implemented, the application data may be generated by calling the authentication unit.
[0193] In some embodiments, when the device is specifically implemented, the authentication unit can be invoked to generate the application data in the following manner: when it is detected that there are no satellite service authentication parameters on the local terminal, the authentication unit is invoked to generate the application data; or, when it is detected that the cumulative time of the satellite service authentication parameters on the local terminal is greater than a preset first duration threshold, the authentication unit is invoked to generate the application data.
[0194] In some embodiments, when the device is specifically implemented, the authentication unit can be invoked to generate the application data in the following manner: the authentication unit is invoked to generate a first random number and an application sequence number; the user's identity identifier, date information, and the chip identifier of the baseband chip are obtained; the authentication unit is invoked to generate an application authentication code based on the application sequence number, the chip identifier of the baseband chip, the user's identity identifier, the first random number, and the date information; and the application data is generated based on the application authentication code.
[0195] In some embodiments, the application response data may include at least: a second random number, an application response authentication code, an application serial number, and a registration response code.
[0196] In some embodiments, after receiving application response data regarding satellite service authentication parameters, the device may further be used to: perform a consistency check on the application sequence number in the application response data; when the application sequence number consistency check passes, verify the response authentication code and registration response code in the application response data; when the response authentication code and registration response code pass verification, generate confirmation data regarding the satellite service authentication parameters.
[0197] In some embodiments, when the device is specifically implemented, confirmation data regarding satellite service authentication parameters can be generated in the following manner: calling the authentication unit to generate a confirmation response code; generating the confirmation data based on the confirmation response code; wherein, the confirmation data includes at least the confirmation response code.
[0198] In some embodiments, when the device is specifically implemented, the response authentication code and registration response code in the application response data can be verified in the following manner: the authentication unit is invoked to generate a reference response authentication code and a reference registration response code locally based on preset protocol rules; the response authentication code and the reference registration response code are verified according to the reference response authentication code and the reference registration response code.
[0199] In some embodiments, when the processing module 905 is specifically implemented, it can obtain satellite service authentication parameters based on the confirmation response data in the following manner: extract the authentication verification result according to the confirmation response data; when the authentication verification result indicates that the satellite communication service authentication verification is passed, determine that the satellite service authentication parameters are valid; when the satellite service authentication parameters are determined to be valid, respond to the confirmation response data, generate satellite service authentication parameters according to preset protocol rules, and save the satellite service authentication parameters locally.
[0200] In some embodiments, the device may also be used to: respond to a trigger operation, generate a satellite service authentication code using locally stored satellite service authentication parameters; add the satellite service authentication code to a short message; and send the short message to the satellite.
[0201] In some embodiments, the satellite may specifically include a BeiDou satellite.
[0202] This specification also provides another satellite short message authentication data processing device, applied to an authentication management system. The device includes: a first receiving module, specifically configured to receive application data regarding satellite service authentication parameters; wherein the application data is generated at least based on the chip identifier of the baseband chip; a first sending module, specifically configured to send application response data regarding satellite service authentication parameters based on the application data; a second receiving module, specifically configured to receive confirmation data regarding satellite service authentication parameters; and a second sending module, specifically configured to send confirmation response data regarding satellite service authentication parameters when the confirmation data is verified.
[0203] In some embodiments, after receiving application data regarding satellite service authentication parameters, the device may further be used to: detect whether the absolute value of the difference between the date information in the application data and the receiving date is less than a preset second duration threshold; and determine that the application data has been verified when the absolute value of the difference between the date information in the application data and the receiving date is less than the preset second duration threshold.
[0204] In some embodiments, when the application data is verified, the device may further be used to: generate a second random number; generate negotiation authentication parameters and negotiation factors based on the application serial number and the chip identifier of the baseband chip in the application data; generate a registration response code based on the negotiation authentication parameters, the user's identity identifier, the first random number, and the second random number; generate a reply authentication code based on the application serial number, the verification result of the application data, the second random number, and the registration response code; and generate application reply data regarding satellite service authentication parameters based on the registration response code, the reply authentication code, the second random number, and the application serial number.
[0205] In some embodiments, after determining that the application data has been verified, the device may further be used to: generate satellite service authentication parameters based on the user's identity identifier, a first random number, a second random number, and a negotiation factor; record the satellite service authentication parameters, as well as the user's identity identifier, the baseband chip's chip identifier, and the application serial number corresponding to the satellite service authentication parameters.
[0206] In some embodiments, after receiving confirmation data regarding satellite service authentication parameters, the device may further be used to: perform consistency verification on the application number, user identity identifier, and baseband chip identifier in the confirmation data; when the consistency verification of the application number, user identity identifier, and baseband chip identifier passes, calculate and verify the confirmation response code in the confirmation data; when the confirmation response code passes verification, generate confirmation reply data carrying encrypted data of satellite service authentication parameters.
[0207] In some embodiments, when the device is specifically implemented, confirmation response data carrying encrypted data of satellite service authentication parameters can be generated in the following manner: according to preset protocol rules, the satellite service authentication parameters are encrypted using the pre-defined code of the satellite gateway to obtain encrypted data of the satellite service authentication parameters; and the encrypted data of the satellite service authentication parameters is added to the confirmation response data.
[0208] In some embodiments, after sending confirmation response data regarding satellite service authentication parameters, the satellite gateway determines whether the satellite communication service authentication has passed based on the confirmation response data. When it is determined that the satellite communication service authentication has passed, the satellite gateway decrypts the encrypted data of the satellite service authentication parameters using its pre-defined code according to preset protocol rules to obtain the satellite service authentication parameters, and forwards the confirmation response data to the terminal.
[0209] This specification also provides another satellite short message authentication data processing device applied to a satellite gateway, which may specifically include the following structural modules: a receiving module, specifically used to receive confirmation reply data regarding satellite service authentication parameters sent by the authentication management system; wherein the confirmation reply data carries encrypted data of the satellite service authentication parameters; a decryption module, specifically used to decrypt the encrypted data of the satellite service authentication parameters to obtain the corresponding satellite service authentication parameters when the confirmation reply data indicates that the terminal's satellite communication service authentication verification is successful; and to save the satellite service authentication parameters; and a forwarding module, specifically used to forward the confirmation reply data to the terminal.
[0210] In some embodiments, when the above-mentioned decryption module is specifically implemented, the encrypted data of the satellite service authentication parameters can be decrypted in the following way to obtain the corresponding satellite service authentication parameters: the encrypted data of the satellite service authentication parameters can be decrypted using the pre-made code related to the satellite gateway to obtain the corresponding satellite service authentication parameters.
[0211] It should be noted that the units, devices, or modules described in the above embodiments can be implemented by computer chips or physical entities, or by products with certain functions. For ease of description, the above devices are described by dividing them into various modules according to their functions. Of course, in implementing this specification, the functions of each module can be implemented in one or more software and / or hardware, or the module that implements the same function can be implemented by a combination of multiple sub-modules or sub-units, etc. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection between the devices or units shown or discussed can be through some interfaces, and the indirect coupling or communication connection between devices or units can be electrical, mechanical, or other forms.
[0212] As can be seen from the above, the satellite short message authentication data processing device provided in the embodiments of this specification, by introducing and using the chip identifier of the baseband chip and multiple rounds of interactive verification, can efficiently and securely realize the authentication verification of satellite communication services with a relatively small amount of data processing. This can effectively reduce the security risks caused by the tampering of relevant information during the authentication verification process and better protect the data information security during satellite communication.
[0213] In a specific scenario example, the authentication data processing method for satellite short messages provided in this specification can be applied to achieve the distribution of mobile phone service authentication parameters suitable for BeiDou short messages under narrow communication bandwidth conditions. The specific implementation process, as shown in Figure 10, may include the following:
[0214] 1) The mobile terminal (a type of terminal) SDK calls the authentication IP core (e.g., authentication unit) to generate a random request sequence number and a random number. (For example, the first random number).
[0215] 2) The mobile terminal SDK encapsulates the BeiDou service authentication parameter application data (e.g., application data) and calls the authentication IP core to calculate the application authentication code. The BeiDou service authentication parameter application data includes the application serial number, baseband chip number (e.g., the chip identifier of the baseband chip), and user ID (e.g., the user's identity identifier). The information includes the date (or date information) and the application authentication code. Among these, the aforementioned BeiDou services, such as the BeiDou satellite short message service, can be specifically understood as a type of satellite communication service.
[0216] 3) In the BeiDou service authentication parameter application data, the date is the date information in the current UTC time; the application authentication code is calculated by the authentication IP core, and can be the other five authentication words, that is, it can be generated according to the following formula: .
[0217] 4) The mobile terminal sends the BeiDou service authentication parameter application to the BeiDou short message gateway (e.g., satellite gateway) through the mobile network.
[0218] 5) The Beidou short message gateway forwards the Beidou service authentication parameter application to the password and authorization management subsystem (e.g., authentication management system).
[0219] 6) The password and authorization management subsystem verifies the date information in the BeiDou service authentication parameter application. If the difference between the date in the BeiDou service authentication parameter application and the date in the password and authorization management subsystem is within one day, the verification passes, and proceeds to step 7). If the verification fails, the application response authentication code is calculated directly.
[0220] 7) The password and authorization management subsystem generates random numbers. (For example, the second random number).
[0221] 8) The cryptography and authorization management subsystem uses KDF functions to generate negotiation authentication parameters, negotiation factors, and service authentication parameters (e.g., satellite service authentication parameters). Specifically, the following formulas can be used to calculate them: Negotiation Authentication Parameter || Negotiation Factor = KDF(Initial Parameter || Application Serial Number || Baseband Chip Number), Service Authentication Parameter = KDF(User ID || Negotiation Factor || || ).
[0222] 9) Password and Authorization Management Subsystem calculates registration response code Specifically, it can be calculated using the following formula: .
[0223] 10) The password and authorization management subsystem records the application serial number, baseband chip number, user ID, and service authentication parameters of successful applications.
[0224] 11) The password and authorization management subsystem calculates the application response authentication code (e.g., response authentication code). The application response authentication code is a verification value calculated based on the BeiDou service authentication parameters in the application response message. If the verification of the requested data fails, then and Set all values to 0.
[0225] 12) The password and authorization management subsystem sends a reply to the Beidou service authentication parameter application to the Beidou short message gateway.
[0226] 13) The BeiDou short message gateway forwards the BeiDou service authentication parameter request reply message to the mobile terminal via the mobile network. The mobile terminal verifies the consistency of the request sequence number. If they do not match, it continues to wait for a reply from the BeiDou short message gateway until it times out.
[0227] 14) After the mobile terminal verification application number matches, the mobile terminal SDK calls the authentication IP core to calculate and verify the application response authentication code. .
[0228] 15) The mobile terminal SDK calls the authentication IP core to calculate and verify the registration response code. .
[0229] 16) The mobile terminal SDK calls the authentication IP core and uses the KDF function to generate negotiation authentication parameters, negotiation factors, and service authentication parameters. Negotiation authentication parameters || Negotiation factor = KDF(initial parameters || Request serial number || Baseband chip number). Service authentication parameters = KDF(User ID || Negotiation factor || || ).
[0230] 17) The mobile terminal SDK calls the authentication IP core to calculate and generate an acknowledgment response code. : .
[0231] 18) The mobile terminal sends a BeiDou service authentication parameter confirmation message to the BeiDou short message gateway via the mobile network. The BeiDou service authentication parameter confirmation message includes the application sequence number, user ID, baseband chip number, and confirmation response code. .
[0232] 19) The Beidou short message gateway forwards the Beidou service authentication parameter confirmation message to the password and authorization management subsystem.
[0233] 20) The password and authorization management subsystem verifies the consistency of the application sequence number, user ID, and baseband chip number in the BeiDou service authentication parameter confirmation message. If they are inconsistent, it continues to wait for the mobile terminal to send a valid BeiDou service authentication parameter confirmation message until the timeout occurs and the process exits.
[0234] 21) After confirming the consistency of the application serial number, user ID, and baseband chip number, the password and authorization management subsystem calculates and verifies the confirmation response code. .
[0235] 22) The password and authorization management subsystem sends a confirmation reply and encrypted service authentication parameters to the BeiDou short message gateway. The encryption and encapsulation calculation rule for the service authentication parameters is: SM4_OFB gateway server vendor pre-defined code (IV, service authentication parameter || (SM3_HASH(Business Authentication Parameters))).
[0236] 23) Beidou short message gateway stores service authentication parameters.
[0237] 24) The BeiDou short message gateway forwards the confirmation reply of BeiDou service authentication parameters to the mobile terminal.
[0238] 25) The mobile terminal extracts the verification result from the confirmation reply of the BeiDou service authentication parameters. If the verification result is successful, the service authentication parameters officially take effect, and the process ends. If the verification result fails, the service authentication parameters are cleared.
[0239] 26) Business authentication parameters take effect.
[0240] The above scenario examples verify the authentication data processing method for satellite short messages provided in this specification. By adopting a lightweight cryptographic authentication protocol suitable for short messages, identity authentication and information encryption are satisfied. In addition, by utilizing the mobile network to construct a key negotiation handshake authentication mechanism, the problem of distributing keys to a large number of users under limited link bandwidth is solved, supporting concurrent authentication of a large number of users, which is conducive to improving the scalability and reliability of the system.
[0241] While this specification provides the steps of operation for the methods described in the embodiments or flowcharts, more or fewer steps may be included based on conventional or non-inventive means. The order of steps listed in the embodiments is merely one possible order of execution among many steps and does not represent the only possible order. In actual device or client product execution, the methods shown in the embodiments or drawings may be executed sequentially or in parallel (e.g., in a parallel processor or multi-threaded processing environment, or even a distributed data processing environment). The terms "comprising," "including," or any other variations thereof are intended to cover a non-exclusive inclusion, such that a process, method, product, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, product, or apparatus. Without further limitations, the presence of other identical or equivalent elements in a process, method, product, or apparatus that includes said elements is not excluded. The terms "first," "second," etc., are used to denote names and do not indicate any particular order.
[0242] Those skilled in the art will also know that, besides implementing the controller using purely computer-readable program code, the same functions can be achieved by logically programming the method steps, making the controller function as logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers (PLCs), and embedded microcontrollers. Therefore, such a controller can be considered a hardware component, and the devices within it used to implement various functions can also be considered structures within that hardware component. Alternatively, the devices used to implement various functions can be considered as both software modules implementing the method and structures within a hardware component.
[0243] This specification can be described in the general context of computer-executable instructions that are executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, classes, etc., that perform a specific task or implement a specific abstract data type. This specification can also be practiced in distributed computing environments, where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer-readable storage media, including storage devices.
[0244] As can be seen from the above description of the embodiments, those skilled in the art can clearly understand that this specification can be implemented by means of software plus necessary general-purpose hardware platforms. Based on this understanding, the technical solutions of this specification can essentially be embodied in the form of a software product. This computer software product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, mobile terminal, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments of this specification.
[0245] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on its differences from other embodiments. This specification can be used in numerous general-purpose or special-purpose computer system environments or configurations. Examples include: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable electronic devices, network PCs, minicomputers, mainframe computers, and distributed computing environments including any of the above systems or devices, etc.
[0246] Although this specification has been described by way of examples, those skilled in the art will recognize that many variations and modifications are possible without departing from the spirit of this specification, and it is intended that the appended claims cover such variations and modifications without departing from the spirit of this specification.
Claims
1. A method for processing authentication data for satellite short messages, characterized in that, An application is made to a terminal, the terminal including at least a baseband chip associated with a satellite, the baseband chip being deployed with an authentication unit. The method includes: sending application data regarding satellite service authentication parameters; wherein the application data is generated at least based on the chip identifier of the baseband chip; receiving application response data regarding the satellite service authentication parameters; wherein the application response data is generated by an authentication management system based on the application data; when the application response data is verified, sending confirmation data regarding the satellite service authentication parameters; receiving confirmation response data regarding the satellite service authentication parameters; wherein the confirmation response data is received by the terminal after the authentication management system verifies the confirmation data; and obtaining the satellite service authentication parameters based on the confirmation response data.
2. The method according to claim 1, characterized in that, Sending the request data regarding satellite service authentication parameters includes: sending the request data regarding satellite service authentication parameters to the satellite gateway; wherein the satellite gateway forwards the request data to the authentication management system.
3. The method according to claim 1, characterized in that, The method further includes: invoking the authentication unit to generate the application data.
4. The method according to claim 3, characterized in that, The step of calling the authentication unit to generate the application data includes: when it is detected that there are no satellite service authentication parameters on the terminal's local machine, calling the authentication unit to generate the application data; or, when it is detected that the cumulative time of the satellite service authentication parameters on the terminal's local machine is greater than a preset first duration threshold, calling the authentication unit to generate the application data.
5. The method according to claim 3, characterized in that, The step of calling the authentication unit to generate the application data includes: calling the authentication unit to generate a first random number and an application sequence number; obtaining the user's identity identifier, date information, and the chip identifier of the baseband chip; calling the authentication unit to generate an application authentication code based on the application sequence number, the chip identifier of the baseband chip, the user's identity identifier, the first random number, and the date information; and generating the application data based on the application authentication code.
6. The method according to claim 1, characterized in that, The application response data includes at least: application response authentication code and registration response code.
7. The method according to claim 6, characterized in that, After receiving the application response data regarding satellite service authentication parameters, the method further includes: performing a consistency check on the application sequence number in the application response data; when the application sequence number consistency check passes, verifying the response authentication code and registration response code in the application response data; and when the response authentication code and registration response code pass verification, generating confirmation data regarding the satellite service authentication parameters.
8. The method according to claim 7, characterized in that, The generation of confirmation data regarding satellite service authentication parameters includes: invoking the authentication unit to generate a confirmation response code; and generating the confirmation data based on the confirmation response code; wherein the confirmation data includes at least the confirmation response code.
9. The method according to claim 7, characterized in that, The verification of the reply authentication code and registration response code in the application reply data includes: calling the authentication unit to generate a reference reply authentication code and a reference registration response code locally based on preset protocol rules; and verifying the reply authentication code and registration response code in the application reply data according to the reference reply authentication code and the reference registration response code.
10. The method according to claim 1, characterized in that, The step of obtaining satellite service authentication parameters based on the confirmation response data includes: extracting the authentication verification result according to the confirmation response data; determining that the satellite communication service authentication parameter is valid when the authentication verification result indicates that the satellite communication service authentication verification is successful; responding to the confirmation response data when the satellite service authentication parameter is determined to be valid, generating the satellite service authentication parameter according to the preset protocol rules; and saving the satellite service authentication parameter locally.
11. The method according to claim 10, characterized in that, The method further includes: responding to a trigger operation, generating a satellite service authentication code using locally stored satellite service authentication parameters; adding the satellite service authentication code to a short message; and sending the short message to the satellite.
12. The method according to claim 1, characterized in that, The satellites mentioned include BeiDou satellites.
13. A method for processing authentication data for satellite short messages, characterized in that, An authentication management system is used as follows: the method includes: receiving application data for satellite service authentication parameters; wherein the application data is generated based at least on the chip identifier of the baseband chip; sending application response data for satellite service authentication parameters based on the application data; receiving confirmation data for satellite service authentication parameters; and sending confirmation response data for satellite service authentication parameters when the confirmation data is verified.
14. The method according to claim 13, characterized in that, After receiving the application data regarding satellite service authentication parameters, the method further includes: detecting whether the absolute value of the difference between the date information in the application data and the receiving date is less than a preset second duration threshold; when the absolute value of the difference between the date information in the application data and the receiving date is less than the preset second duration threshold, determining that the application data has been verified.
15. The method according to claim 14, characterized in that, When the application data is verified, the method further includes: generating a second random number; generating negotiation authentication parameters and negotiation factors based on the application serial number and the chip identifier of the baseband chip in the application data; generating a registration response code based on the negotiation authentication parameters, the user's identity identifier, the first random number, and the second random number; generating a reply authentication code based on the application serial number, the verification result of the application data, the second random number, and the registration response code; and generating application reply data regarding satellite service authentication parameters based on the registration response code, the reply authentication code, the second random number, and the application serial number.
16. The method according to claim 14, characterized in that, After confirming that the application data has been verified, the method further includes: generating satellite service authentication parameters based on the user's identity identifier, a first random number, a second random number, and a negotiation factor; recording the satellite service authentication parameters, as well as the user's identity identifier, the baseband chip's chip identifier, and the application serial number corresponding to the satellite service authentication parameters.
17. The method according to claim 13, characterized in that, After receiving confirmation data regarding satellite service authentication parameters, the method further includes: performing a consistency check on the application number, user identity identifier, and baseband chip identifier in the confirmation data; when the consistency check of the application number, user identity identifier, and baseband chip identifier passes, calculating and verifying the confirmation response code in the confirmation data; and when the confirmation response code passes verification, generating confirmation reply data carrying encrypted data of satellite service authentication parameters.
18. The method according to claim 17, characterized in that, The process of generating the confirmation response data carrying encrypted data of satellite service authentication parameters includes: encrypting the satellite service authentication parameters using a pre-defined code of the satellite gateway according to preset protocol rules to obtain encrypted data of the satellite service authentication parameters; and adding the encrypted data of the satellite service authentication parameters to the confirmation response data.
19. The method according to claim 18, characterized in that, After sending confirmation response data regarding satellite service authentication parameters, the method further includes: the satellite gateway determining whether the satellite communication service authentication verification is successful based on the confirmation response data; when it is determined that the satellite communication service authentication verification is successful, the satellite gateway decrypts the encrypted data of the satellite service authentication parameters using a pre-defined code according to preset protocol rules to obtain the satellite service authentication parameters; and forwards the confirmation response data to the terminal.
20. A method for processing authentication data for satellite short messages, characterized in that, Applied to a satellite gateway, the method includes: receiving confirmation response data regarding satellite service authentication parameters sent by an authentication management system; wherein the confirmation response data carries encrypted data of the satellite service authentication parameters; when the confirmation response data indicates that the terminal's satellite communication service authentication verification is successful, decrypting the encrypted data of the satellite service authentication parameters to obtain the corresponding satellite service authentication parameters; saving the satellite service authentication parameters; and forwarding the confirmation response data to the terminal.
21. The method according to claim 20, characterized in that, The step of decrypting the encrypted data of the satellite service authentication parameters to obtain the corresponding satellite service authentication parameters includes: using the pre-coded data related to the satellite gateway to decrypt the encrypted data of the satellite service authentication parameters to obtain the corresponding satellite service authentication parameters.
22. A satellite short message authentication data processing device, characterized in that, An application to a terminal, the terminal including at least a baseband chip associated with a satellite, the baseband chip being equipped with an authentication unit, the device comprising: a first transmitting module for transmitting application data regarding satellite service authentication parameters; wherein the application data is generated at least based on the chip identifier of the baseband chip; a first receiving module for receiving application response data regarding satellite service authentication parameters; wherein the application response data is generated by an authentication management system based on the application data; a second transmitting module for transmitting confirmation data regarding satellite service authentication parameters when the application response data is verified successfully; a second receiving module for receiving confirmation response data regarding satellite service authentication parameters; wherein the confirmation response data is received by the terminal after the authentication management system verifies the confirmation data successfully; and a processing module for obtaining satellite service authentication parameters based on the confirmation response data.
23. A satellite short message authentication data processing device, characterized in that, An authentication management system is provided, comprising: a first receiving module for receiving application data regarding satellite service authentication parameters; wherein the application data is generated at least based on the chip identifier of a baseband chip; a first sending module for sending application response data regarding satellite service authentication parameters based on the application data; a second receiving module for receiving confirmation data regarding satellite service authentication parameters; and a second sending module for sending confirmation response data regarding satellite service authentication parameters when the confirmation data is verified.
24. An electronic device, characterized in that, It includes a processor and a memory for storing processor-executable instructions, wherein the processor, when executing the instructions, implements the steps of the method according to any one of claims 1 to 21.
25. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, performs the steps of the method according to any one of claims 1 to 21.
26. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the steps of the method according to any one of claims 1 to 21.