Method, apparatus, device and medium for backhaul link security protection
By using the EDHOC mechanism to perform identity authentication and key negotiation between satellite base stations and gateway stations, the problem of limited computing resources and bandwidth in satellite base station backhaul links is solved, and secure and reliable data transmission is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA MOBILE COMM LTD RES INST
- Filing Date
- 2026-01-12
- Publication Date
- 2026-06-05
AI Technical Summary
In 3GPP NTN, due to limited computing resources and wireless bandwidth, the existing secure transmission mechanism of IPsec protocol cannot effectively guarantee data security in the backhaul link of satellite base stations, posing a risk of eavesdropping and tampering.
The EDHOC mechanism is used for mutual authentication and key negotiation. Lightweight security protection is achieved by generating and exchanging initial request information, parameter response messages, authentication completion messages and key ready messages.
In resource-constrained satellite environments, it enables mutual authentication and key negotiation, ensuring secure transmission of the backhaul link, making it suitable for scenarios with limited onboard resources.
Smart Images

Figure CN122160086A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a method, apparatus, device, and medium for backhaul link security protection. Background Technology
[0002] 3GPP NTN refers to the "Non-Terrestrial Network" standard defined by 3GPP (3rd Generation Partnership Project, the world's leading mobile communications standards organization). Simply put, it is the technical specification developed by 3GPP for non-terrestrial communication methods such as 5G / 6G convergence satellite and high-altitude platforms.
[0003] Base station deployment on satellite involves "moving" 5G base stations originally deployed on the ground to satellites, allowing the satellite to directly act as a 5G base station. It communicates with user terminals (UEs) via the satellite air interface (NR Uu), and then connects to ground-based NTN gateways (i.e., gateway stations), core networks, and other equipment to ultimately access the data network. The backhaul link refers to the transmission channel between the base station (such as gNB / eNB) and the core network, used to carry user plane data and control plane signaling. When the base station is on a satellite, the backhaul link between the base station and the ground core network can no longer be connected via fiber optic cable, but rather wirelessly. Compared to physical fiber optic cables, wireless transmission is more susceptible to interference, theft, and tampering; therefore, this backhaul link requires security mechanisms to ensure secure transmission.
[0004] Employing the NDS / IP mechanism in the 3GPP standard, the IPsec protocol ensures the security of the backhaul link. It typically uses tunneling mode to ensure data is not eavesdropped on, tampered with, or forged during transmission. IPsec encapsulates the original data packet with a new IP header, pointing to the address of the terrestrial IPsec gateway, which can be located between the gateway station and the core network. Therefore, using IPsec tunneling or (D)TLS for security protection presents two challenges: firstly, it requires satellite-side computing power to support IPsec establishment and encryption / decryption operations during secure transmission; secondly, it requires sufficient bandwidth in the wireless transmission channel. However, in reality, onboard computing resources and wireless bandwidth are limited, thus necessitating a lightweight backhaul security mechanism. Summary of the Invention
[0005] To address the problems existing in the prior art, the present invention provides a method, apparatus, device, and medium for backhaul link security protection.
[0006] This invention provides a method for backhaul link security protection, applied to satellite base stations, comprising: Obtain initial request information, which includes the Method type and the initiator's temporary public key; Send the initial request information to the gateway station; Receive a parameter response message sent by the gateway station, the parameter response message including the gateway station signature or gateway station message authentication code, the responder's temporary public key and the responder's credential reference identifier; Based on the parameter response message, after authenticating the identity of the gateway station, an authentication completion message is generated. The authentication completion message includes the initiator credential reference identifier and the base station signature or base station message authentication code.
[0007] The method for backhaul link security protection provided by the present invention further includes: Receive the key ready message sent by the gateway station.
[0008] According to the backhaul link security protection method provided by the present invention, the identity of the gateway station is authenticated based on the parameter response message, including: The responder's temporary public key is obtained from the response message based on the parameters described. The shared key is obtained based on the responder's temporary public key and the initiator's temporary public key; Decrypt the response message based on the parameters of the shared key to obtain the responder's credential reference identifier; Based on the responder's credential reference identifier, the gateway signature or gateway message authentication code is verified to complete the authentication of the gateway's identity.
[0009] The method for backhaul link security protection provided by the present invention generates an authentication completion message, including: Generate a base station signature or base station message authentication code based on the Method type; The initiator's credential reference identifier and the base station signature or base station message authentication code are encrypted to generate an authentication completion message.
[0010] According to the backhaul link security protection method provided by the present invention, the initial request information further includes a cryptographic suite, which is used by the gateway station to authenticate the legitimacy of the algorithm and identity of the satellite base station.
[0011] This invention also provides a method for backhaul link security protection, applied to a gateway station, comprising: Receive initial request information sent by the satellite base station, the initial request information including the method type and the initiator's temporary public key; A parameter response message is generated based on the initial request information. The parameter response message includes a gateway signature or gateway message authentication code, a responder's temporary public key, and a responder's credential reference identifier. Send the parameter response message to the satellite base station; The system receives an authentication completion message sent by the satellite base station. The authentication completion message includes an initiator credential reference identifier and a base station signature or base station message authentication code.
[0012] The method for backhaul link security protection provided by the present invention further includes: After authenticating the identity of the satellite base station based on the authentication completion message, a key ready message is generated; the key ready message is then sent to the satellite base station.
[0013] According to the method for backhaul link security protection provided by the present invention, the step of generating a parameter response message based on the initial request information includes: Generate a gateway signature or gateway message authentication code based on the Method type; The shared key is obtained based on the responder's temporary public key and the initiator's temporary public key; Based on the shared key, the gateway signature or gateway message authentication code and the responder credential reference identifier are encrypted to obtain encrypted data; The encrypted data and the responder's temporary public key are concatenated and encoded to obtain the parameter response message.
[0014] According to the method for backhaul link security protection provided by the present invention, the initial request information further includes a cryptographic suite, the cryptographic suite including an encryption algorithm type and an radio frequency fingerprint; correspondingly, the method further includes: The legitimacy of the satellite base station's algorithm is verified based on the encryption algorithm type. The identity and legitimacy of the satellite base station are authenticated based on the radio frequency fingerprint.
[0015] According to the method for backhaul link security protection provided by the present invention, the method type includes RPK mode.
[0016] This invention also provides a backhaul link security protection device, applied to a satellite base station, comprising: The first acquisition module is used to acquire initial request information, which includes the Method type and the initiator's temporary public key. The first sending module is used to send the initial request information to the gateway station; The first receiving module is used to receive the parameter response message sent by the gateway station. The parameter response message includes the gateway station signature or gateway station message authentication code, the responder's temporary public key, and the responder's credential reference identifier. The first authentication module is used to authenticate the identity of the gateway station according to the parameter response message and then generate an authentication completion message. The authentication completion message includes the initiator credential reference identifier and the base station signature or base station message authentication code.
[0017] This invention also provides a backhaul link security protection device, applied to a gateway station, comprising: The second receiving module is used to receive initial request information sent by the satellite base station, the initial request information including the method type and the initiator's temporary public key; The response module is used to generate a parameter response message based on the initial request information. The parameter response message includes a gateway signature or gateway message authentication code, a responder's temporary public key, and a responder's credential reference identifier. The second sending module is used to send the parameter response message to the satellite base station; The second authentication module is used to receive an authentication completion message sent by the satellite base station. The authentication completion message includes an initiator credential reference identifier and a base station signature or base station message authentication code.
[0018] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement any of the backhaul link security protection methods described above.
[0019] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements any of the backhaul link security protection methods described above.
[0020] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements any of the above-described methods for backhaul link security protection.
[0021] This invention provides a method, apparatus, device, and medium for backhaul link security protection. By sending initial request information to a gateway station and receiving a parameter response message generated by the gateway station based on the initial request information, and then authenticating the gateway station's identity based on the parameter response message, an authentication completion message is generated, thereby realizing identity authentication and key negotiation between the two parties. This is suitable for scenarios with limited on-board resources and ensures backhaul link security protection. Attached Figure Description
[0022] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0023] Figure 1 This is a schematic diagram of network communication in a 3GPP NTN scenario.
[0024] Figure 2 This is a schematic diagram of the backhaul link in a base station uplink scenario.
[0025] Figure 3 This is a flowchart illustrating the backhaul link security protection method provided by the present invention. Figure 1 .
[0026] Figure 4 This is a timing diagram of the secure connection between the satellite base station and the gateway station provided by the present invention.
[0027] Figure 5 This is a timing diagram of a secure connection between a satellite base station and a gateway station in a scenario where the base station and the gateway station each generate their own public-private key pairs, as provided by this invention.
[0028] Figure 6 This is a flowchart illustrating the backhaul link security protection method provided by the present invention. Figure 2 .
[0029] Figure 7 This is a schematic diagram of the backhaul link security protection device provided by the present invention. Figure 1 .
[0030] Figure 8 This is a schematic diagram of the backhaul link security protection device provided by the present invention. Figure 2 .
[0031] Figure 9 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation
[0032] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0033] Figure 3 This diagram illustrates a flow chart of a method for backhaul link security protection provided by the present invention. (See attached diagram.) Figure 3 This method is applied to satellite base stations and includes the following steps: Step 31: Obtain the initial request information, which includes the Method type and the initiator's temporary public key.
[0034] Step 32: Send the initial request information to the gateway station.
[0035] Step 33: Receive the parameter response message sent by the gateway station. The parameter response message includes the gateway station signature or gateway station message authentication code, the responder's temporary public key, and the responder's credential reference identifier.
[0036] Step 34: After authenticating the identity of the gateway station based on the parameter response message, generate an authentication completion message. The authentication completion message includes the initiator's credential reference identifier and the base station signature or base station message authentication code.
[0037] Regarding steps 31 to 34, it should be noted that 3GPP NTN refers to the "Non-Terrestrial Network" standard defined by 3GPP (3rd Generation Partnership Project, the world's leading mobile communications standards organization). Simply put, it is the technical specification developed by 3GPP for non-terrestrial communication methods such as 5G / 6G convergence satellite and high-altitude platforms.
[0038] 3GPP NTN proposed a base station-on-satellite architecture, which belongs to the regenerative forwarding mode. The core of this architecture is to deploy some or all of the functions of the terrestrial base station (such as DU (Distributed Unit) or CU (Centralized Unit) + DU) on a satellite. Under this architecture, the satellite not only acts as a signal relay but also possesses protocol layer processing capabilities (such as modulation / demodulation, encoding / decoding, and routing). Starting with Release 19 (a key version of 5G - Advanced), 3GPP has been promoting the standardization of this regenerative mode, aiming to achieve seamless handover and spectrum sharing between satellite and terrestrial networks.
[0039] See Figure 1 This is a network communication diagram for a 3GPP NTN scenario. Figure 1This includes core network elements / modules and the interfaces / protocols between them. The core network elements / modules include the User Equipment (UE), Next-Generation Radio Access Network (NG-RAN), base station gNB (responsible for wireless communication with the UE), 5G Core Network (CN), Data Network, and non-terrestrial network gateway NTN Gateway (i.e., the gateway station). The interfaces / protocols include the satellite air interface NR Uu, the NG interface (the interface between NG-RAN (gNB) and 5G CN (the communication link between the base station and the core network)), NG over SRI (Satellite Radio Interface), and the N6 interface (the interface between 5G CN (core network) and Data Network). Base station deployment involves "moving" the 5G base station originally deployed on the ground to the satellite, allowing the satellite to directly act as a 5G base station. It communicates with the user equipment (UE) through the satellite air interface (NR Uu), and then connects to ground-based NTN gateways (i.e., gateway stations), core network equipment, and other devices via the satellite, ultimately accessing the data network. The backhaul link refers to the transmission channel between the base station (such as gNB / eNB) and the core network, used to carry user plane data and control plane signaling (see [link to core network]). Figure 2 This is a schematic diagram of the backhaul link in a base station satellite scenario. When the base station is on a satellite, the backhaul link between the base station and the ground core network can no longer be connected via optical fiber, but rather wirelessly. Compared with physical optical fiber, wireless transmission is more susceptible to interference, theft, and tampering. Therefore, this backhaul link needs to use security mechanisms to ensure secure transmission.
[0040] In the 3GPP standard, the security mechanisms for backhaul links are mainly specified by the following protocol documents: TS 33.210: This standard defines Network Domain Security (NDS / IP) and explicitly requires that the backhaul link use the IPSec (Internet Protocol Security) protocol to ensure the confidentiality and integrity of data transmission. IPSec protects the communication between the base station (such as gNB / eNB) and the core network through encryption and authentication mechanisms, and is the main security protocol for the backhaul link.
[0041] TS 33.501 (5G System Security Architecture and Procedures): As a core 5G security standard, this document further expands security requirements, including protection of the user plane (UP) and signaling data. For backhaul links, it requires the use of transport layer security protocols (such as TLS 1.3) or IPSec to ensure the security of interfaces (such as NG interfaces and Xn interfaces) and prevent man-in-the-middle attacks and data tampering.
[0042] Employing the NDS / IP mechanism in the 3GPP standard, the IPsec protocol ensures the security of the backhaul link. It typically uses tunneling mode to ensure data is not eavesdropped on, tampered with, or forged during transmission. IPsec encapsulates the original data packet with a new IP header, pointing to the address of the terrestrial IPsec gateway, which can be located between the gateway station and the core network. Therefore, using IPsec tunneling or (D)TLS for security protection presents two challenges: firstly, it requires satellite-side computing power to support IPsec establishment and encryption / decryption operations during secure transmission; secondly, it requires sufficient bandwidth in the wireless transmission channel. However, in reality, onboard computing resources and wireless bandwidth are limited, thus necessitating a lightweight backhaul security mechanism.
[0043] In this invention, the method aims to employ a secure interaction mechanism to complete mutual authentication and key negotiation, thereby ensuring secure data transmission. For example, this invention can utilize the EDHOC mechanism to achieve mutual authentication and key negotiation, thus guaranteeing secure data transmission.
[0044] EDHOC (Ephemeral Diffie-Hellman Over COSE) is a lightweight authentication key exchange protocol (core standard RFC 9528 / 9529) defined by the IETF LAKE working group. It is designed for resource-constrained scenarios such as the Internet of Things. Its core is to achieve low-overhead and high-security key negotiation by using temporary Diffie-Hellman (DHE) and COSE / CBOR lightweight encapsulation.
[0045] This invention employs the EDHOC mechanism. The interactive information between the two parties mainly includes EDHOC initial request information, parameter response message, authentication completion message, and key ready message, which are respectively used as EDHOC initial request information, EDHOC parameter response message, EDHOC authentication completion message, and EDHOC key ready message. For the satellite base station, the initiator's temporary public key serves as the initiator's temporary DH public key; for the gateway station, the responder's temporary public key serves as the responder's temporary DH public key.
[0046] In this invention, the satellite base station constructs an EDHOC initial request information. This EDHOC initial request information is unencrypted and includes the Method type and the initiator's temporary DH public key. It may also include the initiator's session identifier C_I and the base station's additional authorization information EAD_1. During the authentication and key negotiation process between the base station and the gateway station, the Method type and the initiator's temporary DH public key play a crucial role in the secure transmission of authentication information. The initiator's session identifier is a unique session ID generated by the satellite base station. The base station's additional authorization information is used by the gateway station to authenticate the satellite base station and may include the satellite device ID (a unique identifier used for gateway station whitelist verification), satellite orbit parameters (to assist the gateway station in optimizing link retransmission strategies), and security policy version (to ensure compatibility of cipher suites between the two parties). This information can be sent after the authentication and key negotiation process is completed, during subsequent interactive authentication, or it can be sent together with the Method type and the initiator's temporary DH public key to reduce the number of interactions and improve the authentication negotiation rate.
[0047] The Method type is a core parameter used to define the authentication and key exchange mechanism between the communicating parties. It directly determines the authentication credential types and key exchange logic between the initiator (such as a satellite base station) and the responder (such as a gateway station). This Method type includes the following: 0x01: Initiator's signature + Responder's static DH; 0x02: Initiator's static DH + Responder's signature; 0x03: Static DH of both parties; 0x04: Signatures of both parties.
[0048] The initiator's temporary ECDH public key G_X is a temporary ECDH public key randomly generated by the satellite base station, which is used to generate a forward-secure shared key later.
[0049] In this invention, the initial request information may also include cryptographic suites. A cryptographic suite is a "secure algorithm combination" agreed upon by both communicating parties. Its core function is to unify the algorithm standards for key negotiation, encryption, and authentication, ensuring that both parties can complete secure communication based on the same cryptographic rules, while balancing security, computational overhead, and link adaptability. For example, the cryptographic suite may specify a key exchange curve and the AEAD algorithm simultaneously. Curve: X25519 (elliptic curve, fast computation, short key); AEAD: AES-CCM-16-64-128 (low overhead, adaptable to satellite links).
[0050] In this invention, the preferred embodiment is to send the above-mentioned multiple contents together to the gateway station. Therefore, the EDHOC initial request information formed based on the above-mentioned multiple contents can be in the data format of "Method, Suite, G_X, C_I, EAD_1".
[0051] In this invention, the satellite base station encodes the EDHOC initial request information using CBOR and then sends it to the gateway station. That is, the information fields use a compact CBOR type: Method uses an unsigned integer (0x00-0x03), G_X uses a byte string (0x40 + length), and EAD_1 uses a mapping (0xA0 + number of key-value pairs), reducing the number of bytes transmitted via the satellite link.
[0052] In this invention, upon receiving the EDHOC initial request information, the gateway station needs to generate an EDHOC parameter response message based on the EDHOC initial request information and send the EDHOC parameter response message back to the satellite base station. The EDHOC parameter response message includes the gateway station's signature or gateway station message authentication code, the responder's temporary DH public key, and the responder's credential reference identifier. Furthermore, it can also send the responder's session identifier and additional authorization information from the gateway station.
[0053] Since the EDHOC initial request information is encoded, the gateway station, upon receiving it, first decodes it. After decoding, the Method type is determined, and then the authentication method is identified based on the Method type. A gateway station signature or gateway station message authentication code is then generated according to the selected authentication method. If a static DH key is used for authentication, the MAC message authentication code is calculated from the temporary DH shared key; if a signature is used for authentication, the signature is performed using the gateway station's own private key.
[0054] Each gateway has its own initiator's ephemeral DH public key. Therefore, a shared key is obtained based on the responder's ephemeral DH public key and the initiator's ephemeral DH public key. Using the shared key, the responder's session identifier, gateway signature or gateway message authentication code, responder's credential reference identifier, and additional authorization information from the first gateway are encrypted to obtain encrypted data.
[0055] The responder session identifier is a unique session ID generated by the gateway.
[0056] The responder credential reference identifier is a pointer to the gateway station's authentication credentials (such as a signing public key / static DH public key). In this case, the gateway station does not need to transmit the complete authentication credentials in the EDHOC parameter response message, but only transmits ID_CRED_R (credential reference identifier). The satellite base station uses this credential reference identifier to query the locally pre-configured gateway station credentials, which greatly reduces the amount of satellite link transmission.
[0057] Similar to the base station's additional authorization information, the EDHOC parameter response message also includes gateway station additional authorization information. This information is used by the satellite base station to authenticate the gateway station.
[0058] Corresponding to the ephemeral DH public key sent by the gateway station, the responder's ephemeral DH public key is also available.
[0059] At this point, the encrypted data and the responder's temporary DH public key are concatenated and CBOR encoded to obtain the EDHOC parameter response message.
[0060] In this invention, after receiving the EDHOC parameter response message, the satellite base station authenticates the gateway station's identity based on the message. Since the EDHOC parameter response message involves information concatenation and encoding, it is first decoded. After decoding, the responder's temporary DH public key is obtained. Then, based on the responder's and initiator's temporary DH public keys, a shared key is derived. Finally, the EDHOC parameter response message is decrypted using the shared key to obtain the responder's credential reference identifier, the gateway station's signature or message authentication code, and the responder's session identifier.
[0061] Furthermore, the authentication credentials (such as (signature public key / static DH public key)) are obtained based on the responder's credential reference identifier. Then, the gateway signature or gateway message authentication code is authenticated based on the authentication credentials. The validity of the gateway's information is authenticated based on the responder's session identifier. After the authentication is completed, it is determined that the gateway's identity authentication has been passed.
[0062] Simultaneously, the satellite base station also needs to generate an EDHOC authentication completion message and send it back to the gateway station. The EDHOC authentication completion message includes the initiator's credential reference identifier and the base station signature or base station message authentication code. Furthermore, additional base station authorization information can also be sent along with it. This information informs the gateway station that authentication has been successful, and also provides authorization information such as the key derivation parameters. In response, the satellite base station generates a base station signature or base station message authentication code based on the Method type, encrypts the initiator's credential reference identifier, the base station signature or base station message authentication code, and the additional authorization information from the second base station, and generates the EDHOC authentication completion message.
[0063] In this invention, after receiving the EDHOC authentication completion message, the gateway station authenticates the identity of the satellite base station based on the EDHOC authentication completion message, and then generates an EDHOC key ready message. The EDHOC key ready message includes additional authorization information from the second gateway station, and is then sent to the satellite base station. This information represents the application layer key ready status fed back to the satellite base station after the key validity verification has passed.
[0064] It should be further noted that the cryptographic suite includes the encryption algorithm type and the radio frequency fingerprint; correspondingly, the method also includes: The legitimacy of the encryption algorithm of the satellite base station is verified based on the type of encryption algorithm. Specifically, it is determined whether the ECDH curve (such as X25519) and AEAD encryption algorithm (such as AES-CCM) supported by the satellite base station are in the support list of the gateway station.
[0065] The identity and legitimacy of the satellite base station are authenticated based on the radio frequency fingerprint. Specifically, this involves determining whether the radio frequency fingerprint is on the gateway station's supported list.
[0066] Furthermore, if the Method type is configured as RPK, the base station and the gateway hold each other's list of legitimate identities and pre-store each other's radio frequency fingerprint information. Both parties have radio frequency fingerprint extraction capabilities and use radio frequency fingerprints to verify identity legitimacy. The radio frequency fingerprint information stored by both parties is bound to the public key.
[0067] See Figure 4 This is a timing diagram of the secure connection between the satellite base station and the gateway station. See also... Figure 4 This can describe the specific processing steps: 41) The base station sends an unencrypted message to the gateway station, indicating the Method type (used to specify the authentication method, currently supporting authentication using signature or static DH key), SUITES cipher suite, base station temporary DH public key G_X, connection identifier C_I and additional authorization information EAD_1, and uses CBOR to encode the initial request information; 42) Upon receiving the message, the gateway station first decodes the initial request message, generates a signature or MAC based on the Method type (if a static DH key is used for authentication, the MAC is calculated from the temporary DH shared key; if a signature is used for authentication, the signature is generated using its own private key), and performs key derivation based on the key schedule and method. The gateway station session identifier C_R, the gateway station credential reference identifier ID_CRED_R, the generated signature or MAC value, and the additional authorization information EAD_2 are then encrypted. The encrypted data is concatenated with the gateway station's temporary public key G_Y, and the message is then CBOR encoded and sent to the base station. 43) After receiving the message, the base station first decodes it, then decrypts it. After decryption, it provides EAD_2 and ID_CRED_R to the application layer. Specifically, it first obtains G_Y, generates a key based on the Method, then decrypts the message. After decryption, it verifies the Signature or MAC using the temporary public key. Successful verification indicates successful authentication, thus realizing the base station's authentication of the gateway station. Similarly, the base station generates a Signature or MAC, and encrypts its own credential reference identifier ID_CRED_I and additional authorization data EAD_3 using the AEAD algorithm before sending it to the gateway station. 44) After receiving the message, the gateway station decrypts it and verifies the signature. If the verification is successful, it means that the gateway station has completed the verification of the base station's identity and sends back additional authorization information EAD_4.
[0068] See Figure 5 Yes, this is a sequence diagram of the secure connection between the satellite base station and the gateway station in a scenario where the base station and the gateway station each generate their own public-private key pairs.
[0069] 51) The base station sends an EDHOC initial request message to the gateway station; 52) When the gateway station receives the encryption kit, it extracts the radio frequency fingerprint of the other party, determines whether it is in the pre-stored list of legitimate entities, and then signs it with its private key after confirmation. The EDHOC parameter response message carries the gateway station's proof of identity, indicating that the core network gateway supports TEE (or carries the gateway station's operational security proof), and sends it to the satellite base station. 53) After receiving the message, the satellite base station decrypts and verifies the signature to complete the identity verification of the gateway station. After verification, the satellite base station signs the message using its own private key. The EDHOC authentication completion message carries evidence of TEE support (or evidence of the satellite base station's operational security) and is sent to the gateway station. 54) The gateway station decrypts and verifies the signature to achieve the gateway station's authentication of the satellite base station's identity; after both parties have completed authentication, secure transmission can be carried out.
[0070] The backhaul link security protection method provided by this invention sends initial request information to the gateway station, receives parameter response messages generated by the gateway station based on the initial request information, and then authenticates the identity of the gateway station based on the parameter response messages to generate an authentication completion message, thereby realizing identity authentication and key negotiation between the two parties. It is suitable for scenarios with limited on-board resources and ensures the security protection of the backhaul link.
[0071] The method for backhaul link security protection provided by the present invention will be described below. The method for backhaul link security protection described below is applied to gateway stations and can be referred to in correspondence with the method for backhaul link security protection described above.
[0072] Figure 6 This diagram illustrates a flow chart of a method for backhaul link security protection provided by the present invention. (See attached diagram.) Figure 6 The method includes the following steps: Step 61: Receive the initial request information sent by the satellite base station. The initial request information includes the Method type and the initiator's temporary public key.
[0073] Step 62: Generate a parameter response message based on the initial request information. The parameter response message includes the gateway signature or gateway message authentication code, the responder's temporary public key, and the responder's credential reference identifier.
[0074] Step 63: Send the parameter response message to the satellite base station.
[0075] Step 64: Receive the authentication completion message sent by the satellite base station. The authentication completion message includes the initiator's credential reference identifier and the base station signature or base station message authentication code.
[0076] In a further method of the above method, the method further includes: After authenticating the identity of the satellite base station based on the authentication completion message, a key ready message is generated; Send a key-ready message to the satellite base station.
[0077] In a further step of the above method, generating a parameter response message based on the initial request information includes: Generate a gateway signature or gateway message authentication code based on the Method type; The shared key is obtained based on the responder's temporary public key and the initiator's temporary public key; Based on the shared key, the gateway signature or gateway message authentication code and the responder credential reference identifier are encrypted to obtain encrypted data; The encrypted data and the responder's temporary public key are concatenated and encoded to obtain the parameter response message.
[0078] In a further step of the above method, the initial request information further includes a cryptographic suite, which includes an encryption algorithm type and an RFID fingerprint. Accordingly, the method also includes: The legitimacy of the encryption algorithm used to authenticate satellite base stations is determined based on the type of encryption algorithm. The identity and legitimacy of satellite base stations are verified based on radio frequency fingerprints.
[0079] In a further method described above, the Method type includes the RPK method.
[0080] Since the method in this embodiment of the invention is based on the same principle as the method in the above embodiments, more detailed explanations will not be repeated here.
[0081] The backhaul link security protection device provided by the present invention will be described below. The backhaul link security protection device described below and the backhaul link security protection method described above can be referred to in correspondence.
[0082] Figure 7 This diagram illustrates the structure of a backhaul link security protection device provided by the present invention. (See attached diagram.) Figure 7 The device is used in satellite base stations and includes a first acquisition module 71, a first transmission module 72, a first receiving module 73, and a first authentication module 74, wherein: The first acquisition module is used to acquire initial request information, which includes the Method type and the initiator's temporary public key. The first sending module is used to send the initial request information to the gateway station; The first receiving module is used to receive parameter response messages sent by the gateway station. The parameter response messages include the gateway station signature or gateway station message authentication code, the responder's temporary public key, and the responder's credential reference identifier. The first authentication module is used to authenticate the identity of the gateway station based on the parameter response message and then generate an authentication completion message. The authentication completion message includes the initiator's credential reference identifier and the base station signature or base station message authentication code.
[0083] Figure 8 This diagram illustrates the structure of a backhaul link security protection device provided by the present invention. (See attached diagram.) Figure 8 This device is used in a gateway station and includes a second receiving module 81, a response module 82, a second transmitting module 83, and a second authentication module 84, wherein: The second receiving module is used to receive the initial request information sent by the satellite base station. The initial request information includes the Method type and the initiator's temporary public key. The response module is used to generate a parameter response message based on the initial request information. The parameter response message includes the gateway signature or gateway message authentication code, the responder's temporary public key, and the responder's credential reference identifier. The second sending module is used to send parameter response messages to the satellite base station; The second authentication module is used to receive authentication completion messages sent by satellite base stations. The authentication completion message includes the initiator's credential reference identifier and the base station signature or base station message authentication code.
[0084] Since the apparatus of this embodiment is based on the same principle as the method of the above embodiment, more detailed explanations will not be repeated here.
[0085] It should be noted that, in the embodiments of the present invention, the relevant functional modules can be implemented by a hardware processor.
[0086] The backhaul link security protection device provided by the present invention sends initial request information to the gateway station, receives parameter response messages generated by the gateway station based on the initial request information, and then authenticates the identity of the gateway station based on the parameter response messages to generate an authentication completion message, thereby realizing identity authentication and key negotiation between the two parties. It is suitable for scenarios with limited on-board resources and ensures backhaul link security protection.
[0087] Figure 9 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 9As shown, the electronic device may include: a processor 91, a communication interface 92, a memory 93, and a communication bus 94, wherein the processor 91, the communication interface 92, and the memory 93 communicate with each other via the communication bus 94. The processor 91 can call logical instructions in the memory 93 to execute a method for backhaul link security protection, the method including: Obtain the initial request information, which includes the Method type and the initiator's temporary public key; Send the initial request information to the gateway station; Receive parameter response messages sent by the gateway station. The parameter response messages include the gateway station signature or gateway station message authentication code, the responder's temporary public key, and the responder's credential reference identifier. Based on the parameter response message, after authenticating the identity of the gateway station, an authentication completion message is generated. The authentication completion message includes the initiator's credential reference identifier and the base station signature or base station message authentication code.
[0088] Or, Receive initial request information sent by the satellite base station. The initial request information includes the Method type and the initiator's temporary public key. A parameter response message is generated based on the initial request information. The parameter response message includes the gateway signature or gateway message authentication code, the responder's temporary public key, and the responder's credential reference identifier. Send the parameter response message to the satellite base station; Receive the authentication completion message sent by the satellite base station. The authentication completion message includes the initiator's credential reference identifier and the base station signature or base station message authentication code.
[0089] Furthermore, the logical instructions in the aforementioned memory 93 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0090] On the other hand, the present invention also provides a computer program product, the computer program product comprising a computer program that can be stored on a non-transitory computer-readable storage medium, wherein when the computer program is executed by a processor, the computer is capable of performing the aforementioned method for backhaul link security protection, the method comprising: Obtain the initial request information, which includes the Method type and the initiator's temporary public key; Send the initial request information to the gateway station; Receive parameter response messages sent by the gateway station. The parameter response messages include the gateway station signature or gateway station message authentication code, the responder's temporary public key, and the responder's credential reference identifier. Based on the parameter response message, after authenticating the identity of the gateway station, an authentication completion message is generated. The authentication completion message includes the initiator's credential reference identifier and the base station signature or base station message authentication code.
[0091] Or, Receive initial request information sent by the satellite base station. The initial request information includes the Method type and the initiator's temporary public key. A parameter response message is generated based on the initial request information. The parameter response message includes the gateway signature or gateway message authentication code, the responder's temporary public key, and the responder's credential reference identifier. Send the parameter response message to the satellite base station; Receive the authentication completion message sent by the satellite base station. The authentication completion message includes the initiator's credential reference identifier and the base station signature or base station message authentication code.
[0092] In another aspect, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to perform the aforementioned method for backhaul link security protection, the method comprising: Obtain the initial request information, which includes the Method type and the initiator's temporary public key; Send the initial request information to the gateway station; Receive parameter response messages sent by the gateway station. The parameter response messages include the gateway station signature or gateway station message authentication code, the responder's temporary public key, and the responder's credential reference identifier. Based on the parameter response message, after authenticating the identity of the gateway station, an authentication completion message is generated. The authentication completion message includes the initiator's credential reference identifier and the base station signature or base station message authentication code.
[0093] Or, Receive initial request information sent by the satellite base station. The initial request information includes the Method type and the initiator's temporary public key. A parameter response message is generated based on the initial request information. The parameter response message includes the gateway signature or gateway message authentication code, the responder's temporary public key, and the responder's credential reference identifier. Send the parameter response message to the satellite base station; Receive the authentication completion message sent by the satellite base station. The authentication completion message includes the initiator's credential reference identifier and the base station signature or base station message authentication code.
[0094] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0095] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0096] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for security protection of a backhaul link, characterized in that, Applications in satellite base stations include: Obtain initial request information, which includes the Method type and the initiator's temporary public key; Send the initial request information to the gateway station; Receive a parameter response message sent by the gateway station, the parameter response message including the gateway station signature or gateway station message authentication code, the responder's temporary public key and the responder's credential reference identifier; Based on the parameter response message, after authenticating the identity of the gateway station, an authentication completion message is generated. The authentication completion message includes the initiator credential reference identifier and the base station signature or base station message authentication code.
2. The method for backhaul link security protection according to claim 1, characterized in that, The method further includes: Receive the key ready message sent by the gateway station.
3. The method for backhaul link security protection according to claim 1, characterized in that, Based on the parameter response message, the identity of the gateway station is authenticated, including: The responder's temporary public key is obtained from the response message based on the parameters described. The shared key is obtained based on the responder's temporary public key and the initiator's temporary public key; Decrypt the response message based on the parameters of the shared key to obtain the responder's credential reference identifier; Based on the responder's credential reference identifier, the gateway signature or gateway message authentication code is verified to complete the authentication of the gateway's identity.
4. The method for backhaul link security protection according to claim 1, characterized in that, Generate an authentication completion message, including: Generate a base station signature or base station message authentication code based on the Method type; The initiator's credential reference identifier and the base station signature or base station message authentication code are encrypted to generate an authentication completion message.
5. The method for backhaul link security protection according to claim 3, characterized in that, The initial request information also includes a cryptographic suite, which is used by the gateway station to authenticate the legitimacy of the satellite base station's algorithm and identity.
6. A method for security protection of a backhaul link, characterized in that, Applied to gateway stations, including: Receive initial request information sent by the satellite base station, the initial request information including the method type and the initiator's temporary public key; A parameter response message is generated based on the initial request information. The parameter response message includes a gateway signature or gateway message authentication code, a responder's temporary public key, and a responder's credential reference identifier. Send the parameter response message to the satellite base station; The system receives an authentication completion message sent by the satellite base station. The authentication completion message includes an initiator credential reference identifier and a base station signature or base station message authentication code.
7. The method for backhaul link security protection according to claim 6, characterized in that, The method further includes: After authenticating the identity of the satellite base station based on the authentication completion message, a key ready message is generated; the key ready message is then sent to the satellite base station.
8. The method for backhaul link security protection according to claim 6, characterized in that, The step of generating a parameter response message based on the initial request information includes: Generate a gateway signature or gateway message authentication code based on the Method type; The shared key is obtained based on the responder's temporary public key and the initiator's temporary public key; Based on the shared key, the gateway signature or gateway message authentication code and the responder credential reference identifier are encrypted to obtain encrypted data; The encrypted data and the responder's temporary public key are concatenated and encoded to obtain the parameter response message.
9. The method for backhaul link security protection according to claim 6, characterized in that, The initial request information also includes a cryptographic suite, which includes an encryption algorithm type and an RFID fingerprint. Correspondingly, the method further includes: The legitimacy of the satellite base station's algorithm is verified based on the encryption algorithm type. The identity and legitimacy of the satellite base station are authenticated based on the radio frequency fingerprint.
10. The method for backhaul link security protection according to claim 6, characterized in that, The Method type includes the RPK method.
11. A device for backhaul link security protection, characterized in that, Applications in satellite base stations include: The first acquisition module is used to acquire initial request information, which includes the Method type and the initiator's temporary public key. The first sending module is used to send the initial request information to the gateway station; The first receiving module is used to receive the parameter response message sent by the gateway station. The parameter response message includes the gateway station signature or gateway station message authentication code, the responder's temporary public key, and the responder's credential reference identifier. The first authentication module is used to authenticate the identity of the gateway station according to the parameter response message and then generate an authentication completion message. The authentication completion message includes the initiator credential reference identifier and the base station signature or base station message authentication code.
12. A device for backhaul link security protection, characterized in that, Applied to gateway stations, including: The second receiving module is used to receive initial request information sent by the satellite base station, the initial request information including the method type and the initiator's temporary public key; The response module is used to generate a parameter response message based on the initial request information. The parameter response message includes a gateway signature or gateway message authentication code, a responder's temporary public key, and a responder's credential reference identifier. The second sending module is used to send the parameter response message to the satellite base station; The second authentication module is used to receive an authentication completion message sent by the satellite base station. The authentication completion message includes an initiator credential reference identifier and a base station signature or base station message authentication code.
13. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the method for backhaul link security protection as described in claims 1-5, or the method for backhaul link security protection as described in any one of claims 6-10.
14. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the method for backhaul link security protection as described in claims 1-5, or the method for backhaul link security protection as described in any one of claims 6-10.
15. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the method for backhaul link security protection as described in claims 1-5, or the method for backhaul link security protection as described in any one of claims 6-10.