Large-scale terminal access authentication system and method for satellite-ground fusion network
By employing a secret sharing mechanism of polynomial interpolation and lightweight Lagrange interpolation in the space-ground converged network, the problems of authentication latency, computational overhead, and privacy protection for large-scale terminal access in the space-ground converged network are solved, achieving efficient and secure terminal access authentication.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING UNIV OF POSTS & TELECOMM
- Filing Date
- 2026-03-04
- Publication Date
- 2026-05-12
AI Technical Summary
Existing technologies have issues with authentication latency and reliability, computational and energy consumption, and privacy and security risks when enabling large-scale terminal access in space-ground converged networks. In particular, they are difficult to guarantee access success rate and security in highly dynamic environments with high bit error rates and long latency links.
A secret sharing mechanism based on polynomial interpolation is adopted to achieve multiple batch authentications through a single secret sharing. Combined with lightweight Lagrange interpolation and temporary identity binding mechanism, an anonymous authentication system is constructed to reduce computational complexity and enhance privacy protection.
It significantly reduces access latency under long-latency links, reduces terminal computing complexity and energy consumption, improves security and privacy protection in large-scale access scenarios, and meets the real-time performance and security resilience of millions of concurrent terminals.
Smart Images

Figure CN122028043A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a large-scale terminal access authentication system and method for satellite-ground converged networks. Background Technology
[0002] As mobile communication technologies evolve towards 5G-Advanced and 6G, space-ground converged networks (also known as non-terrestrial networks, NTNs) have become an indispensable key enabling architecture for achieving ubiquitous global connectivity. This network integrates space segments such as low Earth orbit satellites, medium Earth orbit satellites, and geostationary orbit satellites with terrestrial cellular networks, aiming to provide continuous services to wide-area sea areas, remote regions, and high-speed mobile platforms, and supporting large-scale concurrent access by massive numbers of terminals in future IoT, industrial internet, and other application scenarios. A typical space-ground converged network architecture includes a space segment, a ground segment, and a user segment. Low Earth orbit satellites, with their lower propagation latency, become key nodes carrying user plane data and control plane signaling. In this application scenario, terminal devices need to access the network through onboard base stations or onboard regenerative payloads. However, the wireless link between satellites and ground terminals inherently has characteristics such as long propagation latency, highly time-varying link quality, and intermittent coverage.
[0003] In related technologies, authentication and key negotiation mechanisms based on 5G-AKA or its evolution are commonly used. To address the signaling storm problem caused by large-scale terminal access, existing technologies have further proposed group authentication schemes. Specifically, the network side divides terminals into several groups based on their geographical location or service attributes, and assigns a group identifier and group key to each group. During access authentication, a group representative node (or group head) interacts with the network side on behalf of the entire group for authentication signaling. After the network side verifies the legitimacy of the group's identity, the group representative node broadcasts the obtained authentication vector or session key material within the group, thereby avoiding the network side performing a complete authentication process with each terminal individually. This technical solution reduces the redundant processing overhead on the core network side to some extent through aggregated interaction. However, when the above-mentioned existing technologies are applied to the large-scale access scenarios of the aforementioned space-ground converged network, the following shortcomings still exist: First, there are issues with authentication latency and reliability. While existing group authentication schemes reduce the number of interactions, their fixed multi-round interaction process is significantly amplified on long-latency satellite-to-ground links, leading to excessively long terminal access latency. Simultaneously, on satellite links with high error rates, the loss or timeout of authentication messages easily triggers terminal retransmissions, initiating a chain reaction of "failure-retry-network congestion," severely reducing the access success rate and reliability of large-scale terminals in highly dynamic environments.
[0004] Secondly, there are issues with computational and energy consumption. Existing solutions for group authentication and key negotiation often rely on elliptic curve-based public-key cryptography or bilinear peer-to-peer computationally intensive operations. This places a heavy burden on computationally, storage-, and energy-constrained IoT terminals, and the accumulated energy consumption will shorten the terminal's battery life. More importantly, the on-board processing unit is limited by strict size, weight, and power consumption constraints, and its limited computing resources cannot handle such complex calculations in real time, becoming a performance bottleneck to support future connection densities of millions.
[0005] Finally, there are privacy and security risks. Satellite broadcast channels are inherently open, making signals easily intercepted. In existing group authentication schemes, group member identities are either transmitted in plaintext as long-term identifiers or appear as associatable pseudo-identifiers. This allows attackers to launch link attacks through traffic analysis, tracking the location and behavioral patterns of terminals over extended periods. This poses a serious threat to the deployment of high-security services such as emergency communications. Summary of the Invention
[0006] This application provides a large-scale terminal access authentication system for space-ground converged networks. To provide a basic understanding of some aspects of the disclosed embodiments, a brief summary is given below. This summary is not intended as a general description, nor is it intended to identify key / important components or describe the scope of protection of these embodiments. Its sole purpose is to present some concepts in a simple form as a prelude to the detailed description that follows.
[0007] In a first aspect, embodiments of this application provide a large-scale terminal access authentication system for satellite-ground converged networks, the system comprising: The system consists of a terrestrial core network, satellite-based base stations, and multiple terminal groups; each terminal group includes a group leader and at least one group member. The team leader is responsible for creating access authentication requests and sending them to the satellite base station. The spaceborne base station is used to create a second message by combining its own identifier and forward it to the ground core network; The ground core network is used to verify the legitimacy of the satellite base station and the validity of the second message. After successful verification, a secret sharing mechanism based on polynomial interpolation is used to construct an additional set of verification points and a session key for each group member. The device identifier, session key, set of verification points, and randomly generated group key of each group member are sent to the satellite base station as a third message. The satellite-borne base station is also used to store the session key of each group member and generate a temporary identity for each group member; based on the third message, it constructs a fourth message containing a set of verification points and sends it to the group leader; The group leader is also used to broadcast the fourth message to each group member; Each group member is responsible for calculating the current temporary identifier based on the set of verification points in the fourth message and broadcasting it to the group leader. The team leader is also responsible for collecting and verifying the current temporary identifiers of each team member, and aggregating the verified current temporary identifiers into a target message to be sent to the satellite base station. The satellite-borne base station is also used to verify target messages using pre-stored temporary identities. Once verified, it establishes a secure communication connection with all group members in the target message.
[0008] Optionally, create an access authentication request, including: Obtain the group identifier and current timestamp of the terminal group; Calculate the first hash value of the group identifier, the current timestamp, and the group leader's key; Encapsulate the group identifier, current timestamp, and first hash value as the first message; The first message is integrated into the access authentication request to obtain the access authentication request.
[0009] Optionally, a second message can be created by combining it with its own identifier, including: Obtain the satellite-borne base station's own identifier; The satellite base station's own identifier is added to the first message to obtain the second message.
[0010] Optionally, verifying the legitimacy of the satellite-borne base station and the validity of the second message includes: The legitimacy of the satellite-borne base station is verified by its own identifier; The group leader verifies the group identifier and the hash value of the current timestamp using the group leader's key to determine the validity of the second message.
[0011] Optionally, a secret sharing mechanism based on polynomial interpolation is employed to construct an additional set of verification points and a session key for each group member, including: Randomly generate group keys; Query the database to obtain the device identifier and secret point pre-assigned to each group member, where the secret point is a long-term key for each group member; Based on the group key, an nth-degree polynomial is constructed using a secret sharing mechanism based on polynomial interpolation to obtain the target polynomial. Based on each group member's secret point and objective polynomial, generate an additional set of verification points; Based on each group member's secret point and group key, a key distribution function is used to generate a session key for each group member, thus obtaining the session key for each group member.
[0012] Optionally, the expression for the objective polynomial is:
[0013] in, The constructed target A polynomial of degree 1, when the independent variable When x takes a specific value, the function value f(x) of the polynomial becomes a verification point. This is used to indicate that all operations are performed over a finite field, where p is a pre-selected, publicly known large prime number. It is the degree of the polynomial, used to represent the number of group members. It is the device identifier in each secret point. yes The corresponding function value, The independent variable of the polynomial will be used when reconstructing the secret. Substituting 0 into this polynomial, we can pass through the known points ( , Recover the group key. It is the first The public identifier value of each group member.
[0014] Optionally, generate a temporary identity for each group member, including: Calculate the device identifier and the second hash value of the group key for each group member; The second hash value is used to generate a temporary identity for each group member.
[0015] Optionally, based on the third message, a fourth message containing a set of verification points is constructed, including: Calculate the third hash value of the set of verification points contained in the third message; The set of verification points, the current timestamp, the third hash value, and the group key contained in the third message are encapsulated to obtain the fourth message containing the set of verification points.
[0016] Optionally, the current temporary identifier is calculated based on the set of verification points in the fourth message, including: Obtain your own pre-assigned initial secret point; Based on the initial secret point and the set of verification points contained in the fourth message, the target polynomial is reconstructed through Lagrange interpolation to recover the local group key; Verify the current timestamp and third hash value to determine if the local group key is correct; If so, calculate the session key and the current temporary identifier based on the local group key.
[0017] Secondly, a large-scale terminal access authentication method for space-ground converged networks is provided, applied to a network architecture including a terrestrial core network, spaceborne base stations, and multiple terminal groups. Each terminal group includes a group leader and at least one group member. The method includes: The team leader creates an access authentication request and sends it to the satellite base station; The spaceborne base station combines its own identifier to create a second message and forward it to the ground core network; The ground core network verifies the legitimacy of the satellite base station and the validity of the second message. After successful verification, a secret sharing mechanism based on polynomial interpolation is used to construct an additional set of verification points and a session key for each group member. The device identifier, session key, set of verification points, and randomly generated group key of each group member are sent to the satellite base station as a third message. The satellite-borne base station stores the session key of each group member and generates a temporary identity for each group member; based on the third message, it constructs a fourth message containing a set of verification points and sends it to the group leader; The group leader will broadcast the fourth message to each group member; Each group member calculates the current temporary identifier based on the set of verification points in the fourth message and broadcasts it to the group leader; The team leader collects and verifies the current temporary identifiers of each team member, and aggregates the verified current temporary identifiers into a target message to be sent to the satellite base station; The satellite-borne base station verifies the target message using a pre-stored temporary identity identifier. Once the verification is successful, it establishes a secure communication connection with all members in the target message.
[0018] In this embodiment, regarding communication overhead, a secret sharing mechanism based on polynomial interpolation enables one-time secret sharing and multiple batch authentications, compressing traditional multi-round signaling interactions into single-round group broadcasts. Combined with the broadcast characteristics of satellite-to-ground links, this significantly reduces access latency under long-latency links, meeting the real-time requirements of millions of concurrent terminals. Regarding computational overhead, lightweight Lagrange interpolation based on secret sharing replaces public-key cryptography operations, reducing terminal-side computational complexity to the level of hash operations and polynomial evaluations. This allows low-power IoT terminals and resource-constrained onboard payloads to execute efficiently, achieving an exponential reduction in energy consumption and processing latency. Regarding dynamic adaptability, a one-time secret sharing and temporary identity dynamic binding mechanism is introduced. While ensuring forward / backward security, the credential update cycle is decoupled from the satellite beam dwell time, avoiding frequent credential reconfiguration triggered by switching and ensuring authentication continuity in high-mobility scenarios. In terms of privacy protection, an anonymous authentication system based on temporary group identity (TID) is constructed. Identity non-linkability is achieved through hash chain and group key isolation, which effectively resists traffic analysis and tracking attacks under open satellite-ground channels and improves the security resilience of large-scale access scenarios.
[0019] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description
[0020] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0021] Figure 1 This is a schematic diagram of the system architecture of a large-scale terminal access authentication system for a space-ground converged network provided in an embodiment of this application; Figure 2 This is a network schematic diagram of a satellite-ground fusion network provided in an embodiment of this application; Figure 3 This is a flowchart illustrating a large-scale terminal access authentication method for a space-ground converged network provided in an embodiment of this application. Detailed Implementation
[0022] The following description and accompanying drawings fully illustrate specific embodiments of this application to enable those skilled in the art to practice them.
[0023] It should be understood that the described embodiments are merely some, not all, of the embodiments in this application. All other embodiments obtained by those skilled in the art based on the embodiments in this application without inventive effort are within the scope of protection of this application.
[0024] In the following description, when referring to the accompanying drawings, the same numbers in different drawings denote the same or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of systems and methods consistent with some aspects of this application as detailed in the appended claims.
[0025] In the description of this application, it should be understood that the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance. Those skilled in the art can understand the specific meaning of the above terms in this application based on the specific circumstances. Furthermore, in the description of this application, unless otherwise stated, "multiple" refers to two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship.
[0026] In this embodiment, regarding communication overhead, a secret sharing mechanism based on polynomial interpolation enables one-time secret sharing and multiple batch authentications, compressing traditional multi-round signaling interactions into single-round group broadcasts. Combined with the broadcast characteristics of satellite-to-ground links, this significantly reduces access latency under long-latency links, meeting the real-time requirements of millions of concurrent terminals. Regarding computational overhead, lightweight Lagrange interpolation based on secret sharing replaces public-key cryptography operations, reducing terminal-side computational complexity to the level of hash operations and polynomial evaluations. This allows low-power IoT terminals and resource-constrained onboard payloads to execute efficiently, achieving an exponential reduction in energy consumption and processing latency. Regarding dynamic adaptability, a one-time secret sharing and temporary identity dynamic binding mechanism is introduced. While ensuring forward / backward security, the credential update cycle is decoupled from the satellite beam dwell time, avoiding frequent credential reconfiguration triggered by switching and ensuring authentication continuity in high-mobility scenarios. In terms of privacy protection, an anonymous authentication system based on temporary group identity (TID) is constructed. Identity non-linkability is achieved through hash chain and group key isolation, which effectively resists traffic analysis and tracking attacks under open satellite-ground channels and improves the security resilience of large-scale access scenarios. The following is a detailed description using exemplary embodiments.
[0027] Please see Figure 1 , Figure 1 This is a schematic diagram of the system architecture of a large-scale terminal access authentication system for a space-ground converged network provided in an embodiment of this application. The system includes: a ground core network, a spaceborne base station, and multiple terminal groups; each terminal group includes a group leader and at least one group member.
[0028] As a core enabling technology for 5G-Advanced and 6G, the space-ground converged network integrates non-terrestrial networks with terrestrial cellular networks to achieve seamless global coverage and ubiquitous connectivity. Its architecture typically comprises three layers: the space segment (composed of geostationary orbit (GEO), medium Earth orbit (MEO), and low Earth orbit (LEO) satellites), the ground segment (gateway stations, core network, and terrestrial network), and the user segment (various terminal devices, UEs). LEO satellites, due to their low latency, are key carriers for large-scale terminal communication in the space-ground converged network. Typical systems include the transparent payload architecture and regenerative payload architecture defined by the 3GPP NTN standard. In transparent payload mode, the satellite only performs frequency conversion and amplification of radio frequency signals, while signaling processing is concentrated at the ground gateway station. The regenerative payload mode possesses the computing capabilities of onboard base stations or some core network elements, reducing transmission latency but limited by onboard computing resources. A network diagram of the space-ground converged network is shown below. Figure 2 As shown.
[0029] It should be noted that a unified standard architecture has not yet been formed for 6G networks and space-ground converged networks. Therefore, this application is designed based on the regenerative payload architecture defined by the 3GPP NTN standard. The network mainly consists of the following three components: Ground terminals: Large-scale terminals located on the ground, including ordinary user terminals and IoT devices, can directly access satellite-based base stations to obtain network services. Ground terminals can be divided into multiple groups and have two identity categories: group leader and group member. For the group leader role, a device with sufficient processing power, resources, and communication range is selected as the group leader and is responsible for authenticating group members. If the group leader stops operating, authentication cannot be performed. Group member devices have limited storage and computing power and are low-end devices with similar attributes and access requirements.
[0030] Spaceborne base stations serve two main purposes: firstly, they provide air interface support, offering physical layer connectivity to terminal devices, including wireless signal modulation and demodulation, spectrum resource allocation, multi-antenna beamforming, and access and handover management; secondly, they undertake some service network functions and core business processing capabilities, enabling routing and forwarding of user plane data and control plane signaling management, i.e., including UPF and AMF network elements, and completing user authentication through interaction with the terrestrial core network (home network).
[0031] Terrestrial core network: In this application, it mainly serves as the management center for user subscription data, storing key data including user identity identifiers, subscription service information, and security credentials, and is responsible for generating and distributing authentication keys between users and the network.
[0032] Communication between the ground terminal and the satellite-based base station is coordinated by the satellite node. The satellite-based base station interacts with the ground gateway station and the ground core network through a dedicated secure channel to ensure the security and reliability of information transmission. In this scenario, the ground terminal consists of multiple equipment groups, each with a group leader and multiple members.
[0033] The implementation of this application can be divided into the following three stages: group establishment, group member registration and update, and authentication and key negotiation.
[0034] Specifically, during the group establishment phase, HN organizes device groups based on the physical location of the devices, application requirements, and communication modes. Each group is identified by a unique group identifier, and a group leader is selected for each group. The responsibilities of the group leader include: 1. Initiating access requests to the core network on behalf of the group; 2. Broadcasting authentication vectors to group members; 3. Coordinating authentication and key distribution within the group. During this phase, HN organizes groups based on device associations, considering factors such as geographical proximity, application execution, and communication modes. Each group is assigned a group identity identifier, and HN maintains relevant information for each group. Each group elects a group leader capable of broadcasting messages and delegates multiple tasks to this leader, such as initiating access requests to the core network on behalf of the group and propagating authentication vectors to members. Furthermore, HN and the group leader share a secret group leader key. The selection of the group leader considers factors such as group size and device functionality; various election algorithms are available for this purpose, but these are not the focus of this application.
[0035] Specifically, during the group member registration and update phase, each device is embedded with a unique identifier during manufacturing. This identifier is used as a identifier when registering with the core network. This is denoted as MID. i This represents the identifier of the i-th device in the group. It's important to note that the group leader is also considered a group member. When a device requests to join the group, HN will assign its MID... i The information is recorded in a persistent table, and a secret point (xi, yi) is generated and stored for the device, which is considered a long-term key. This secret information is transmitted to the device via a secure channel and stored by the device. This information is maintained in HN's group information table, allowing for easy updating of group information by adding or deleting device entries.
[0036] Specifically, for ease of description, the relevant symbols in the authentication and key negotiation phases are explained in Table 1.
[0037] Table 1
[0038] In this embodiment of the application, the group leader is used to create an access authentication request and send it to the satellite base station.
[0039] Specifically, the process of creating an access authentication request includes: obtaining the group identifier and current timestamp of the terminal group; calculating the first hash value of the group identifier, current timestamp, and group leader's key; encapsulating the group identifier, current timestamp, and first hash value into a first message; and integrating the first message into a request for access authentication to obtain the access authentication request.
[0040] For example Figure 1As shown, the group leader initiates an access request, sending a first message containing a group identifier and a timestamp to the satellite-borne base station. This first message is...<GID, TS, H(GID, TS, GLK)> .
[0041] In this embodiment of the application, the satellite-borne base station is used to create a second message by combining its own identifier and forward it to the ground core network.
[0042] Specifically, the process of creating a second message by combining its own identifier includes: obtaining the satellite base station's own identifier; adding the satellite base station's own identifier to the first message to obtain the second message.
[0043] For example Figure 1 As shown, after receiving the group leader's message, the satellite-based base station adds its own identifiers (IDs) to the message, obtaining the second message, and then forwards the second message to the ground core network. The second message is... <GID, TS, H(GID, TS,GLK), ID S >
[0044] In this embodiment of the application, the ground core network is used to verify the legitimacy of the satellite base station and the validity of the second message. After the verification is successful, an additional set of verification points and a session key for each group member are constructed using a secret sharing mechanism based on polynomial interpolation. The device identifier, session key, set of verification points, and randomly generated group key of each group member are sent to the satellite base station as a third message.
[0045] Specifically, the process of verifying the legitimacy of the satellite-borne base station and the validity of the second message includes: verifying the legitimacy of the satellite-borne base station through its own identifier; and verifying the group identifier and the hash value of the current timestamp through the group leader's key to determine the validity of the second message.
[0046] For example Figure 1 As shown, the ground core network first verifies the legitimacy of the satellite base station using its own identifiers (IDs). Then, the core network verifies the group identifier (GID) and the hash value of the current timestamp (TS) using the group leader's key (GLK) to determine the validity of the message.
[0047] Specifically, the process of constructing an additional set of verification points and a session key for each group member using a secret sharing mechanism based on polynomial interpolation includes: randomly generating a group key; querying a database to obtain a device identifier and secret point pre-assigned to each group member, where the secret point is a long-term key for each group member; constructing an nth-degree polynomial based on the group key and the secret sharing mechanism based on polynomial interpolation to obtain a target polynomial; generating an additional set of verification points based on each group member's secret point and the target polynomial; and generating a session key for each group member using a key distribution function based on each group member's secret point and the group key to obtain a session key for each group member.
[0048] Specifically, the expression for the objective polynomial is:
[0049] in, The constructed target A polynomial of degree 1, when the independent variable When x takes a specific value, the function value f(x) of the polynomial becomes a verification point. This is used to indicate that all operations are performed over a finite field, where p is a pre-selected, publicly known large prime number. It is the degree of the polynomial, used to represent the number of group members. It is the device identifier in each secret point. yes The corresponding function value, The independent variable of the polynomial will be used when reconstructing the secret. Substituting 0 into this polynomial, we can pass through the known points ( , Recover the group key. It is the first The public identifier value of each group member.
[0050] For example Figure 1 As shown, k0 is randomly selected as the group key. The database is queried to obtain the identifiers (MIDs) of all members in the group. i and secret point (x) i , y i Construct an nth-degree polynomial f(x) using (0, k0) (denoted as (x0, y0)). Calculate n additional validation points P based on f(x). i = (x i * ,y i * The key distribution function KDF is used to generate a session key SK for each member. i = KDF(x i ⊕ y iAfter completing the above calculations, the core network will assign the device identifier (MID) of each group member to all groups. i Session key SK i n verification points P i The group key k0 is sent as a third message to the satellite base station. The third message is <{P i},{SK i},{MID i},k0>.
[0051] It should be noted that Threshold Signature Scheme (TSS) is a cryptographic digital signature protocol that allows some members of a group of signers to jointly sign a message. The SecretSharing mechanism in this application is a classic implementation of threshold signatures. It allows a secret data to be divided into multiple "shares" and distributed to multiple participants. Each participant can only obtain one share, and a single share cannot reconstruct the original secret. Only when a sufficient number of participants cooperate can the original data be reconstructed. This technology ensures data security while avoiding the risk of data leakage. Shamir's secret sharing scheme based on polynomial interpolation is one of the most classic and widely used schemes. In this scheme, the secret is represented as a constant term of a polynomial, and the "share" obtained by each participant is the value of this polynomial at different points. Through Lagrange interpolation, participants can recover the polynomial after obtaining a sufficient number of shares, thus reconstructing the secret. This method has high security and flexibility, and can set different thresholds according to needs to adapt to various security strategies. The Shamir cryptographic sharing scheme is a (t, n) threshold encryption scheme based on multinomial interpolation, used to divide a secret into multiple shares and recover the secret from a specific number of shares when needed. The main idea and implementation steps of the scheme are as follows: 1. Constructing the polynomial: Assuming the secret is s, define a random polynomial of degree t-1: f(x) = s + a1x + a2x 2 +...+a t-1 x t-1 (mod p) Where, a1, a 2, ..., a t-1 The coefficients are random, and p is a prime number greater than the secret s. Generate n shared secret pairs, which are (x... i , f(x i )), where x i It is a unique value that is publicly allocated.
[0052] 2. Reconstructing the secret: Any t shared secret pairs can be used to reconstruct the polynomial f(x) using the Lagrange interpolation formula, thereby recovering the secret s=f(0).
[0053]
[0054] 3. Irrecoverability: The polynomial cannot be reconstructed with fewer than t shares, and therefore the secret cannot be derived.
[0055] The Shamir cryptographic sharing scheme is perfectly secure in an information theory sense, meaning that the probability of deriving a secret from fewer than t shared secret pairs is zero.
[0056] In this embodiment of the application, the satellite-borne base station is also used to store the session key of each group member and generate a temporary identity for each group member; according to the third message, a fourth message containing a set of verification points is constructed and sent to the group leader.
[0057] Specifically, the process of generating a temporary identity for each group member includes: calculating the device identifier and the second hash value of the group key for each group member; and using the second hash value as the temporary identity for each group member.
[0058] Specifically, the process of constructing a fourth message containing a set of verification points based on the third message includes: calculating the third hash value of the set of verification points contained in the third message; and encapsulating the set of verification points contained in the third message, the current timestamp, the third hash value, and the group key contained in the third message to obtain a fourth message containing a set of verification points.
[0059] For example Figure 1 As shown, calculate the third hash value of the set of verification points contained in the third message, denoted as H({P i} Calculate the device identifier and the second hash value of the group key for each group member, denoted as TID. i =H(MID i , k0). The fourth message is <{P i},TS,H({P i},TS,k0)>.
[0060] In this embodiment of the application, the group leader is also used to broadcast the fourth message to each group member; For example Figure 1 As shown, <{P i},TS,H({P i Broadcast to each group member.
[0061] In this embodiment of the application, each group member is used to calculate the current temporary identifier based on the set of verification points in the fourth message and broadcast it to the group leader; the group leader is also used to collect and verify the current temporary identifier of each group member, and aggregate the verified current temporary identifiers into a target message and send it to the satellite base station; the satellite base station is also used to verify the target message through pre-stored temporary identity identifiers, and after verification, establish a secure communication connection with all group members in the target message.
[0062] Specifically, the process of calculating the current temporary identifier based on the set of verification points in the fourth message includes: obtaining the initial secret point pre-allocated by itself; reconstructing the target polynomial through Lagrange interpolation based on the initial secret point and the set of verification points contained in the fourth message to recover the local group key; verifying the current timestamp and the third hash value to determine whether the local group key is correct; if so, calculating the session key and the current temporary identifier based on the local group key.
[0063] For example Figure 1 As shown, after each device receives a message from the group leader (including the group leader itself), it performs the following operations: (a) Using its own existing secret points and the {P} in the received group leader message i Reconstruct the polynomial f(x) and calculate k0. * = f(0).
[0064] (b) Verify the hash value and timestamp to check k0 * The accuracy and timeliness of the information.
[0065] (c) Calculate the session key SK i = KDF(x i ⊕ y i , k0 * ).
[0066] (d) Calculate the temporary identifier TID i = H(MID i , k0 * ).
[0067] Re-encapsulate the message as <TID i , H(TID i , k0 * )>, broadcast to the group leader.
[0068] For example Figure 1 As shown, the group leader receives all broadcast messages and verifies the TID. i Then, the team leader processed all the verified TIDs. iThe hash values are merged into a single target message and sent to the satellite-based base station. The satellite-based base station verifies the hash value; if the verification passes, the base station establishes a connection with all group members in the message, and subsequent messages are encrypted using the session key.
[0069] In this embodiment, regarding communication overhead, a secret sharing mechanism based on polynomial interpolation enables one-time secret sharing and multiple batch authentications, compressing traditional multi-round signaling interactions into single-round group broadcasts. Combined with the broadcast characteristics of satellite-to-ground links, this significantly reduces access latency under long-latency links, meeting the real-time requirements of millions of concurrent terminals. Regarding computational overhead, lightweight Lagrange interpolation based on secret sharing replaces public-key cryptography operations, reducing terminal-side computational complexity to the level of hash operations and polynomial evaluations. This allows low-power IoT terminals and resource-constrained onboard payloads to execute efficiently, achieving an exponential reduction in energy consumption and processing latency. Regarding dynamic adaptability, a one-time secret sharing and temporary identity dynamic binding mechanism is introduced. While ensuring forward / backward security, the credential update cycle is decoupled from the satellite beam dwell time, avoiding frequent credential reconfiguration triggered by switching and ensuring authentication continuity in high-mobility scenarios. In terms of privacy protection, an anonymous authentication system based on temporary group identity (TID) is constructed. Identity non-linkability is achieved through hash chain and group key isolation, which effectively resists traffic analysis and tracking attacks under open satellite-ground channels and improves the security resilience of large-scale access scenarios.
[0070] Please see Figure 3 This application provides a flowchart illustrating a large-scale terminal access authentication method for a space-ground converged network, applicable to a network architecture comprising a terrestrial core network, spaceborne base stations, and multiple terminal groups. Each terminal group includes a group leader and at least one group member. Figure 3 As shown, the detection method in this application embodiment may include the following steps: S101, The team leader creates an access authentication request and sends it to the satellite base station; S102, the satellite-borne base station combines its own identifier to create a second message and forward it to the ground core network; S103, the ground core network verifies the legitimacy of the satellite base station and the validity of the second message; after the verification is successful, a secret sharing mechanism based on polynomial interpolation is used to construct an additional set of verification points and a session key for each group member; the device identifier, session key, set of verification points, and randomly generated group key of each group member are sent to the satellite base station as a third message; S104, the satellite base station stores the session key of each group member and generates a temporary identity for each group member; based on the third message, it constructs a fourth message containing a set of verification points and sends it to the group leader; S105, the group leader broadcasts the fourth message to each group member; S106, Each group member calculates the current temporary identifier based on the set of verification points in the fourth message and broadcasts it to the group leader; S107, the team leader collects and verifies the current temporary identifier of each team member, and aggregates the verified current temporary identifiers into a target message and sends it to the satellite base station; S108, the satellite-borne base station verifies the target message using a pre-stored temporary identity identifier. Once the verification is successful, it establishes a secure communication connection with all members in the target message.
[0071] In this embodiment, regarding communication overhead, a secret sharing mechanism based on polynomial interpolation enables one-time secret sharing and multiple batch authentications, compressing traditional multi-round signaling interactions into single-round group broadcasts. Combined with the broadcast characteristics of satellite-to-ground links, this significantly reduces access latency under long-latency links, meeting the real-time requirements of millions of concurrent terminals. Regarding computational overhead, lightweight Lagrange interpolation based on secret sharing replaces public-key cryptography operations, reducing terminal-side computational complexity to the level of hash operations and polynomial evaluations. This allows low-power IoT terminals and resource-constrained onboard payloads to execute efficiently, achieving an exponential reduction in energy consumption and processing latency. Regarding dynamic adaptability, a one-time secret sharing and temporary identity dynamic binding mechanism is introduced. While ensuring forward / backward security, the credential update cycle is decoupled from the satellite beam dwell time, avoiding frequent credential reconfiguration triggered by switching and ensuring authentication continuity in high-mobility scenarios. In terms of privacy protection, an anonymous authentication system based on temporary group identity (TID) is constructed. Identity non-linkability is achieved through hash chain and group key isolation, which effectively resists traffic analysis and tracking attacks under open satellite-ground channels and improves the security resilience of large-scale access scenarios.
[0072] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The program for large-scale terminal access authentication for space-ground converged networks can be stored in a computer-readable storage medium. When executed, the program can include the processes of the embodiments of the above methods. The storage medium for large-scale terminal access authentication for space-ground converged networks can be a magnetic disk, optical disk, read-only memory, or random access memory, etc.
[0073] The above-disclosed embodiments are merely preferred embodiments of this application and should not be construed as limiting the scope of this application. Therefore, any equivalent variations made in accordance with the claims of this application shall still fall within the scope of this application.
Claims
1. A large-scale terminal access authentication system for satellite-ground converged networks, characterized in that, The system includes: The system consists of a terrestrial core network, satellite-based base stations, and multiple terminal groups; each terminal group includes a group leader and at least one group member. The group leader is used to create an access authentication request and send it to the satellite base station. The satellite-borne base station is used to create a second message by combining its own identifier and forward it to the ground core network; The ground core network is used to verify the legitimacy of the satellite base station and the validity of the second message. After successful verification, an additional set of verification points and a session key for each group member are constructed using a secret sharing mechanism based on polynomial interpolation. The device identifier of each group member, the session key, the set of verification points, and the randomly generated group key are sent to the satellite base station as a third message. The satellite-borne base station is also used to store the session key of each group member and generate a temporary identity for each group member; according to the third message, it constructs a fourth message containing the set of verification points and sends it to the group leader; The group leader is also used to broadcast the fourth message to each group member; Each group member is used to calculate the current temporary identifier based on the set of verification points in the fourth message and broadcast it to the group leader; The group leader is also used to collect and verify the current temporary identifier of each group member, and aggregate the verified current temporary identifiers into a target message and send it to the satellite base station. The satellite-borne base station is also used to verify the target message using a pre-stored temporary identity identifier, and after successful verification, to establish a secure communication connection with all group members in the target message.
2. The system according to claim 1, characterized in that, The creation of the access authentication request includes: Obtain the group identifier and current timestamp of the terminal group; Calculate the first hash value of the group identifier, the current timestamp, and the group leader's key; Encapsulate the group identifier, the current timestamp, and the first hash value into the first message; The first message is integrated into a request for access authentication to obtain an access authentication request.
3. The system according to claim 2, characterized in that, The creation of a second message by combining its own identifier includes: Obtain the self-identifier of the satellite-borne base station; The satellite base station's own identifier is added to the first message to obtain the second message.
4. The system according to claim 3, characterized in that, The verification of the legitimacy of the satellite-borne base station and the validity of the second message includes: The legitimacy of the satellite-borne base station is verified by its own identifier; The validity of the second message is determined by verifying the group identifier and the hash value of the current timestamp using the group leader's key.
5. The system according to claim 1, characterized in that, The secret sharing mechanism based on polynomial interpolation is used to construct an additional set of verification points and a session key for each group member, including: Randomly generate group keys; The database is queried to obtain a device identifier and secret point pre-assigned to each group member, the secret point being a long-term key for each group member; Based on the group key, an nth-degree polynomial is constructed using a secret sharing mechanism based on polynomial interpolation to obtain the target polynomial. Based on the secret point and the target polynomial of each group member, generate an additional set of verification points; Based on the secret point and the group key of each group member, a session key is generated for each group member using a key distribution function, thus obtaining the session key for each group member.
6. The system according to claim 5, characterized in that, The expression for the objective polynomial is: in, The constructed target A polynomial of degree 1, when the independent variable When x takes a specific value, the function value f(x) of the polynomial becomes a verification point. This is used to indicate that all operations are performed over a finite field, where p is a pre-selected, publicly known large prime number. It is the degree of the polynomial, used to represent the number of group members. It is the device identifier in each secret point. yes The corresponding function value, The independent variable of the polynomial will be used when reconstructing the secret. Substituting 0 into this polynomial, we can pass through the known points ( , Recover the group key. It is the first The public identifier value of each group member.
7. The system according to claim 1, characterized in that, The process of generating a temporary identity for each group member includes: Calculate the device identifier for each group member and the second hash value of the group key; The second hash value is used as a temporary identity identifier for each group member.
8. The system according to claim 1, characterized in that, The step of constructing a fourth message containing the set of verification points based on the third message includes: Calculate the third hash value of the set of verification points contained in the third message; The verification point set, current timestamp, third hash value, and group key contained in the third message are encapsulated to obtain a fourth message containing the verification point set.
9. The system according to claim 8, characterized in that, The step of calculating the current temporary identifier based on the set of verification points in the fourth message includes: Obtain your own pre-assigned initial secret point; Based on the initial secret point and the set of verification points contained in the fourth message, the target polynomial is reconstructed through Lagrange interpolation to recover the local group key; Verify the current timestamp and the third hash value to determine if the local group key is correct; If so, calculate the session key and the current temporary identifier based on the local group key.
10. A large-scale terminal access authentication method for a space-ground converged network implemented using the system described in any one of claims 1-9, characterized in that, Applied to a network architecture comprising a terrestrial core network, spaceborne base stations, and multiple terminal groups, wherein each terminal group includes a group leader and at least one group member, the method includes: The group leader creates an access authentication request and sends it to the satellite base station; The satellite-borne base station combines its own identifier to create a second message and forward it to the ground core network; The ground core network verifies the legitimacy of the satellite base station and the validity of the second message; after successful verification, it uses a secret sharing mechanism based on polynomial interpolation to construct an additional set of verification points and a session key for each group member; and sends the device identifier of each group member, the session key, the set of verification points, and the randomly generated group key as a third message to the satellite base station. The satellite-borne base station stores the session key of each group member and generates a temporary identity for each group member; based on the third message, it constructs a fourth message containing the set of verification points and sends it to the group leader; The group leader broadcasts the fourth message to each group member; Each group member calculates the current temporary identifier based on the set of verification points in the fourth message and broadcasts it to the group leader; The group leader collects and verifies the current temporary identifier of each group member, and aggregates the verified current temporary identifiers into a target message and sends it to the satellite base station; The satellite-borne base station verifies the target message using a pre-stored temporary identity identifier. Once the verification is successful, it establishes a secure communication connection with all group members in the target message.