A key management method for an aviation broadband communication system based on a pre-shared key

CN122534434APending Publication Date: 2026-08-07CIVIL AVIATION UNIV OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CIVIL AVIATION UNIV OF CHINA
Filing Date
2026-05-14
Publication Date
2026-08-07

AI Technical Summary

Technical Problem

然而,在航空通信场景下,航空器节点计算资源和通信带宽受限,且存在高速移动、跨地面站频繁切换等特点,上述密钥管理方式需引入较大的计算开销并显著提高信令时延,难以满足航空通信对低时延和高可靠性的要求

Benefits of technology

[0053] This invention realizes the generation, distribution, dynamic updating and secure revocation of keys in aviation broadband communication systems by constructing a multi-level key management mechanism based on pre-shared keys, thereby reducing the computation and signaling overhead in key management and communication processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122534434A_ABST
    Figure CN122534434A_ABST
Patent Text Reader

Abstract

The application discloses a kind of based on pre-shared key's aviation broadband communication system key management method, it is related to information security and aviation communication technical field.The method includes: based on the generation of symmetric key of multistage key structure, based on pre-shared key's key distribution, based on the key storage of domestic cryptographic card, the key update of dynamic cross-domain scene-oriented and based on the key revocation of symmetric key.The application pre-sets root key by offline mode, and gradually derives master key and session key between aircraft node, ground safety gateway and ground station in combination with key derivation function, and adopts the cryptographic card that meets national commercial cryptographic standard to carry out encrypted storage and integrity protection to key.When switching across ground station, key update is triggered by ground safety gateway, and the dynamic replacement of master key and session key is realized.The application enhances the security and service continuity in cross-domain switching process, and realizes the whole life cycle management of key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of information security and aviation communication technology, and in particular relates to a key management method for aviation broadband communication systems based on pre-shared keys. Background Technology

[0002] In recent years, the scale and frequency of data interaction between aircraft and ground systems have been continuously increasing, thus posing challenges to communication security. As a fundamental supporting technology for ensuring the confidentiality, integrity, and availability of communication data, key management's reliability and real-time performance directly affect the secure operation of aviation communication systems.

[0003] In existing aviation communication systems, key management is typically implemented using asymmetric cryptography or centralized key distribution. In these schemes, key establishment and updates between aircraft nodes and ground systems usually require public key certificates, key negotiation protocols, or third-party key management centers. However, in aviation communication scenarios, aircraft nodes have limited computing resources and communication bandwidth, and are characterized by high-speed movement and frequent handovers across ground stations. The aforementioned key management methods introduce significant computational overhead and substantially increase signaling latency, making it difficult to meet the low latency and high reliability requirements of aviation communication.

[0004] Furthermore, existing key management schemes often rely on centralized key update or renegotiation mechanisms in dynamic cross-domain communication scenarios. When an aircraft switches between different ground stations, it is necessary to re-establish security associations or update keys, which complicates the key update process, increases the risk of communication interruption, and affects business continuity. Summary of the Invention

[0005] In view of this, the present invention aims to overcome the shortcomings of the above-mentioned problems in the prior art and proposes a key management method for aviation broadband communication systems based on pre-shared keys.

[0006] To achieve the above objectives, the technical solution of the present invention is implemented as follows:

[0007] A key management method for an aviation broadband communication system based on pre-shared keys is disclosed. The aviation broadband communication system includes a security gateway (SGW), an airborne terminal (AS), a ground station (GS), and a ground station controller (GSC). The airborne terminal (AS) and the ground station controller (GSC) both communicate with the ground station (GS), and the security gateway (SGW) communicates with the ground station controller (GSC). The key management method based on the above aviation broadband communication system includes the following steps:

[0008] Step 1: Symmetric key generation based on a multi-level key structure;

[0009] Step 2: Key distribution based on the pre-shared key;

[0010] Step 3: Key storage based on domestically produced cryptographic cards;

[0011] Step 4: Key update for dynamic cross-domain scenarios;

[0012] Step 5: Key revocation based on symmetric key.

[0013] Furthermore, step 1 includes:

[0014] Generate key, encryption key, root key K AS Master Key K AS-SGW and K AS-GS and session key;

[0015] Among them, the key encryption key and the root key K AS Generated using a hardware random number generator;

[0016] The encryption key is stored in a cryptographic card and is used to encrypt and protect the root key, master key, and session key.

[0017] When an aircraft node connects to a ground security gateway, the aircraft node and the ground security gateway communicate based on the root key K. AS The master key K is generated by deriving key derivation parameters and key derivation functions. AS-SGW ;

[0018] The aircraft node and the ground security gateway are based on the master key K AS-SGW The master key K between the aircraft node and the ground station is derived. AS-GS And distributed to ground stations by the ground security gateway;

[0019] Aircraft nodes and ground stations are based on the master key K AS-GS At least one set of session keys is derived from the random number NONCE and the key type identifier for data encryption and / or integrity protection between the aircraft node and the ground station.

[0020] Furthermore, step 2 includes:

[0021] During the system initialization phase, the root key K is transmitted offline. AS Pre-installed on aircraft nodes and ground security gateways;

[0022] When an aircraft node connects to a ground security gateway, the aircraft node and the ground security gateway communicate based on the root key K. AS The master key K is generated by deriving key derivation parameters and key derivation functions. AS-SGW ;

[0023] The ground security gateway distributes the master key K, used for communication between the aircraft node and the ground station, to the corresponding ground station through a secure communication channel.AS-GS Or key derivation parameters;

[0024] The aircraft node and the ground station derive a session key locally based on the master key, and the session key is not distributed over the network.

[0025] Furthermore, step 3 includes:

[0026] The system uses cryptographic cards that conform to national commercial cryptography standards to store and manage the keys.

[0027] The key encryption key is generated and stored in the password card, and the root key K is then encrypted using the key encryption key. AS Master Key K AS-SGW K AS-GS The session key is encrypted and then stored.

[0028] The plaintext of the key exists only in the secure operating environment of the cryptographic card, while the key stored outside the cryptographic card is saved in encrypted form;

[0029] Perform integrity checks on the stored keys to prevent unauthorized tampering during storage and use.

[0030] Furthermore, step 4 includes:

[0031] In dynamic cross-domain scenarios where aircraft nodes undergo cross-ground station handover, key updates are triggered.

[0032] The ground security gateway sends a key update request to the aircraft node, the key update request carrying a random number NONCE for key update and the target ground station SAC_GS. T Logo;

[0033] The aircraft node is based on the currently valid master key K AS-GS The random number and the target ground station identifier are used to generate the updated master key K. AS-GS’ ;

[0034] The ground security gateway synchronously derives the updated master key K, which is consistent with the aircraft node. AS-GS’ The updated master key and the key materials used to derive the master key are then distributed to the target ground station via a secure communication channel.

[0035] The aircraft node and the target ground station derive new session keys locally based on the updated master key, and perform revocation processing on the original master key and session key.

[0036] Furthermore, step 5 includes:

[0037] When a key reaches its preset usage period or a risk of key leakage is detected, the corresponding key is revoked.

[0038] The revoked key is marked as invalid and is no longer used for new data encryption and message authentication code calculations;

[0039] Simultaneously perform revocation processing on the sub-keys derived from the revoked key;

[0040] The revoked key can only be used for decrypting historical data and verifying message authentication codes to complete the secure termination of the key's lifecycle.

[0041] Furthermore, the master key length supports 128 bits or 256 bits;

[0042] The session key includes the user data encryption key K. U-ENC and user data integrity protection key K U-INT .

[0043] Furthermore, the root key K AS Pre-set distribution is achieved using a password card as the distribution medium;

[0044] The master key K AS-SGW The distribution is completed during the secure access authentication process;

[0045] The master key K AS-GS Distribution is accomplished via the IPSec secure channel;

[0046] The session key is based on the master key K. AS-GS Derived locally.

[0047] Furthermore, the key is stored in ciphertext form in the key library, and the storage fields include key unique identifier id, key type key_type, owner, key ciphertext key_cipher, key length key_len, key encryption key ciphertext kek_cipher, initialization vector iv and its length iv_len, verification algorithm chck_algo, check value length check_len, and check value chck_value.

[0048] Furthermore, the key update process involves the target base station constructing a key update notification and sending it to the security gateway;

[0049] The key update notification includes the aircraft identifier SAC_AS and the source base station identifier SAC_GS. S and the unique identifier of the destination base station SAC_GS T ;

[0050] The key update request is sent from the ground security gateway to the aircraft node, and includes the key type (key_type) and the source base station identifier (SAC_GS). S Destination base station unique identifier SAC_GS T and random number NONCE;

[0051] The key update response is sent from the aircraft node to the ground security gateway and includes the key type key_type and the aircraft node's unique identifier SAC_AS.

[0052] Compared with existing technologies, the key management method for aviation broadband communication systems based on pre-shared keys described in this invention has the following advantages:

[0053] This invention realizes the generation, distribution, dynamic updating and secure revocation of keys in aviation broadband communication systems by constructing a multi-level key management mechanism based on pre-shared keys, thereby reducing the computation and signaling overhead in key management and communication processes.

[0054] This invention combines dynamic cross-domain scenarios with the key security storage method of hardware cryptographic cards to form a complete key lifecycle management mechanism, which improves the security and service continuity of aviation broadband communication systems during cross-ground station handover. Attached Figure Description

[0055] The accompanying drawings, which form part of this invention, are used to provide a further understanding of the invention. The illustrative embodiments of the invention and their descriptions are used to explain the invention and do not constitute an undue limitation of the invention. In the drawings:

[0056] Figure 1 This is a diagram of the aviation broadband communication system environment to which this invention applies;

[0057] Figure 2 This is a diagram of the multi-level session key structure in an embodiment of the present invention;

[0058] Figure 3 This is a schematic diagram of the key derivation process in an embodiment of the present invention;

[0059] Figure 4 This is a flowchart of the key distribution process in an embodiment of the present invention;

[0060] Figure 5 This is a schematic diagram of key storage in an embodiment of the present invention;

[0061] Figure 6 This is a flowchart of the key update process in an embodiment of the present invention. Detailed Implementation

[0062] It should be noted that, unless otherwise specified, the embodiments and features described in the present invention can be combined with each other.

[0063] In the description of this invention, it should be understood that the terms "center," "longitudinal," "lateral," "upper," "lower," "front," "rear," "left," "right," "vertical," "horizontal," "top," "bottom," "inner," and "outer," etc., indicating orientations or positional relationships based on the orientations or positional relationships shown in the accompanying drawings, are only for the convenience of describing the invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of the invention. Furthermore, the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Thus, a feature defined with "first," "second," etc., may explicitly or implicitly include one or more of that feature. In the description of this invention, unless otherwise stated, "a plurality of" means two or more.

[0064] In the description of this invention, it should be noted that, unless otherwise explicitly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection of two components. Those skilled in the art will understand the specific meaning of the above terms in this invention based on the specific circumstances.

[0065] The present invention will now be described in detail with reference to the accompanying drawings and embodiments.

[0066] The aviation broadband communication system environment to which this invention is applicable is described in [reference needed]. Figure 1 The system consists of four terminals: a Security Gateway (SGW), an Airborne Assault Server (AS), a Ground Station (GS), and a Ground Station Controller (GSC). The R1 interface is the L-band wireless communication link between the AS and GS, supporting high-dynamic air-to-ground data transmission. The G1 and G2 interfaces are encrypted ground communication links; the G1 interface is used for information transmission between the GS and GSC, and the G2 interface is used for information sharing between GSs. The G3 interface is the ground security tunnel between the GSC and SGW, using IPSec encrypted control signaling. In the air-to-ground communication network, the AS prioritizes nearby GSs for bidirectional wireless communication via the L-band, connected through the R1 interface. In the ground network, the GS and GSC are connected through the G1 interface, with the GSC centrally managing all GSs. GSs are connected to each other through the G2 interface to share information and improve link reliability. The SGW connects directly to the GSC through the G3 interface, responsible for end-to-end security authentication of the aircraft and strict security management of information accessing the core network.

[0067] Based on the aforementioned aviation broadband communication system, this invention provides a key management method for aviation broadband communication systems based on pre-shared keys. This method enhances the security of the aviation broadband communication system, isolates risks, simplifies the key management process, and thus ensures the confidentiality and integrity of data. The multi-level session key structure for aviation broadband communication systems proposed in this invention is as follows: Figure 2 As shown, based on the key requirements of aviation broadband communication services and the characteristics of the cryptographic card itself, the keys related to the business logic are divided into three levels, from top to bottom: root key, master key, and session key. The key encryption key is used as the storage encryption key when storing the business logic related keys. The method specifically includes the following steps:

[0068] Step 1: Symmetric key generation based on a multi-level key structure;

[0069] When an AS connects to an SGW, the AS and SGW are based on the root key K. AS Key derivation parameters and PBKDF derived master key K AS-SGW To support the security needs of different user levels, the master key length supports 128 bits and 256 bits. Subsequently, AS and SGW are based on K... AS-SGW Derivation K from PBKDF AS-GS Distributed to GS via IPSec. AS and GS will then distribute K. AS-GS Using random numbers and key type as input parameters, K is derived. U-ENC K U-INT These two keys serve as session keys, used for encryption and integrity protection of user data between the AS and GS, respectively. See details for the key derivation process. Figure 3 As shown.

[0070] Step 2: Key distribution based on pre-shared key

[0071] The key distribution process in an aviation broadband communication system requires the distribution of the root key, master key, and session key. Root key K AS Key distribution is performed using a cryptographic card as the distribution medium, pre-configured before the initialization of the aviation broadband communication system. The root key is shared one-to-one between the AS and SGW, and the master key K... AS-SGW The distribution is completed during the secure access authentication process, with the master key K... AS-GS Distribution is accomplished via an IPSec secure channel, using the point-to-point session key K. U-ENC K U-INT K C-ENC K C-INT All based on K AS-GS Derivation is performed locally.

[0072] The distribution process of the master key and session key is as follows: Figure 4As shown, the process consists of three steps: SGW distributing key materials to AS, AS confirming the key with SGW, and SGW distributing the key to GS. These three steps are respectively carried by the aircraft authentication request response message AUC_RESP, the authentication key confirmation message AUC_KEY_EXC, and the key distribution message KEY_TRANSPORT during the security gateway authentication and key negotiation processes.

[0073] The security gateway generates shared information, and inputs the root key and shared information into the KDF to derive K. AS-SGW Then, construct the AUC_RESP message and use K AS-SGW Perform a MAC operation on the message to obtain the checksum m. SGW The key material AUC_RESP message and m SGW Send to AS.

[0074] After receiving the key materials, AS extracts the shared information and key length, and derives the master key K from the root key and shared information. AS-SGW Using this key, perform a MAC operation on the AUC_RESP packet to obtain m. SGW ´, compared to m SGW Is it with m? SGW If they are the same, it means that AS and SGW have derived the same master key K. AS-SGW .

[0075] Master Key K AS-SGW After successful verification, AS generates a random number N3 and constructs a key confirmation message AUC_KEY_EXC, using K AS-SGW The MAC value of this message is calculated to obtain m. AS Using random number N3, and the master key K between AS and SGW. AS-SGW And the unique identifier SAC_GS of GS is used to derive the master key K between AS and GS. AS-GS Based on master key K AS-GS The session key K is derived from the random number N3. U-INT and K U-ENC The AS then sends a key confirmation message AUC_KEY_EXC and m to the security gateway. AS .

[0076] After receiving the key confirmation message, the security gateway uses the master key K AS-SGW Calculate m by performing MAC on AUC_KEY_EXC AS ´, compared with the received m AS To verify local K AS-SGW Consistency with the AS-side key.

[0077] After verification, based on random numbers N3, K AS-SGWAnd the unique identifier SAC_GS of GS is used to derive the master key K between AS and GS. AS-GS K AS-GS N3 and N3 send a key distribution message to GS.

[0078] After receiving the key distribution message, GS uses the master key K. AS-GS The session key K is derived from the random number N3. U-INT and K U-ENC At this point, the session key between AS and GS has been successfully established.

[0079] Step 3: Key storage based on domestically produced cryptographic cards:

[0080] The goal of key storage is to prevent unauthorized disclosure, modification, or replacement of keys and to provide key separation functionality. The key encryption key is stored in a cryptographic card, while the root key, master key, and session key are encrypted with the key encryption key and then exported to a key store. Message verification codes are used to protect the integrity of the keys.

[0081] like Figure 5 As shown, the key storage function consists of a cryptographic card and a key store. The cryptographic card has a long-term storage area for storing the key (.kek), and a temporary storage area for temporarily storing the key during key export and import; the key cache is automatically cleared upon power failure. The key is encrypted using the .kek on the cryptographic card and then exported to the key store. The key store stores the encrypted key, which is imported from the key store to the cryptographic card and decrypted using the .kek. The plaintext key exists only in the temporary storage area of ​​the cryptographic card, protected by the cryptographic card hardware, effectively preventing the leakage of plaintext keys.

[0082] When storing keys in the database, the `id` serves as the unique identifier and index. The `key_type` and `owner` fields record the key type and owner. Key types include root key, master key, and session key. `key_cipher` and `key_len` record the key ciphertext and key length, while `kek_len` and `kek_cipher` record the key's encryption length and ciphertext. To decrypt a key, `kek` is first imported into the cryptographic card to obtain a handle, and then this handle is used to decrypt `key_cipher`. The initialization vector `iv` and its length `iv_len` are necessary parameters for encrypting and decrypting the plaintext key. The verification algorithm `chck_algo`, checksum length `check_len`, and checksum `chck_value` are used to verify the integrity of the key during key usage.

[0083] Step 4: Key Update for Dynamic Cross-Domain Scenarios

[0084] After SGW and AS complete authentication, a master key K is generated. AS-SGWIf the root key is leaked, all encrypted communications will be compromised; therefore, it is crucial to use K directly. AS-SGW Encrypting data with a key poses a potential risk. To enhance security, K... AS-SGW The key is replaced by a negotiated key. This method allows each communication session to use an independent key, so when the airborne station crosses domains, the master key between the ground station and the airborne station can be replaced without re-authentication. Figure 6 K is triggered for GS switching AS-GS Update process.

[0085] When a base station handover is imminent, the target base station sends a key update notification to the security gateway, which includes the aircraft identifier SAC_AS and the source base station identifier SAC_GS. S and the unique identifier of the destination base station SAC_GS T .

[0086] The gateway obtains the AS identifier of the base station to be switched from the packet and sends a key update request to it. This request includes the key type (key_type) and the source and destination GS identifiers (SAC_GS). S SAC_GS T The AS receives the message and, based on the GS identifier and key type, locates the key that needs to be updated, derives NH, and generates a new master key K. AS-GS Using K AS-GS NONCE is used as input to PBKDF to update the local session key. A key update response packet is constructed and sent to the security gateway, which includes the key type key_type and the AS unique identifier SAC_AS.

[0087] After receiving the key update response, the SGW synchronizes the NH and calculates the new K. AS-GS Construct a key distribution message and send it to the target GS, which includes: key type (key_type) and master key (K). AS-GS , and the random number NONCE.

[0088] After receiving the key distribution message, GS stores the master key K. AS-GS Using K AS-GS NONCE is used as input to PBKDF to update the local session key.

[0089] Step 5: Key revocation based on symmetric key

[0090] Key revocation falls into two categories: The first is normal revocation, which occurs automatically when the key reaches its expiration date. For example, a session key should be revoked immediately upon the end of the session. The second is emergency revocation, which occurs when the key has been compromised or is at risk of being compromised. For encryption keys stored on a cryptographic card, the card's automatic key destruction mechanism can be used. For keys stored outside the cryptographic card, the key administrator manually terminates the key's lifecycle prematurely.

[0091] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A key management method for an aviation broadband communication system based on pre-shared keys, characterized in that: The aviation broadband communication system includes a security gateway (SGW), an airborne terminal (AS), a ground station (GS), and a ground station controller (GSC). Both the airborne AS and the ground station controller (GSC) communicate with the ground station (GS), and the security gateway (SGW) communicates with the ground station controller (GSC). The key management method based on the above aviation broadband communication system includes the following steps: Step 1: Symmetric key generation based on a multi-level key structure; Step 2: Key distribution based on the pre-shared key; Step 3: Key storage based on domestically produced cryptographic cards; Step 4: Key update for dynamic cross-domain scenarios; Step 5: Key revocation based on symmetric key.

2. The key management method for an aviation broadband communication system based on a pre-shared key according to claim 1, characterized in that: Step 1 includes: Generate key, encryption key, root key K AS Master Key K AS-SGW and K AS-GS and session key; Among them, the key encryption key and the root key K AS Generated using a hardware random number generator; The encryption key is stored in a cryptographic card and is used to encrypt and protect the root key, master key, and session key. When an aircraft node connects to a ground security gateway, the aircraft node and the ground security gateway communicate based on the root key K. AS The master key K is generated by deriving key derivation parameters and key derivation functions. AS-SGW ; The aircraft node and the ground security gateway are based on the master key K AS-SGW The master key K between the aircraft node and the ground station is derived. AS-GS And distributed to ground stations by the ground security gateway; Aircraft nodes and ground stations are based on the master key K AS-GS At least one set of session keys is derived from the random number NONCE and the key type identifier for data encryption and / or integrity protection between the aircraft node and the ground station.

3. The key management method for an aviation broadband communication system based on a pre-shared key according to claim 2, characterized in that: Step 2 includes: During the system initialization phase, the root key K is transmitted offline. AS Pre-installed on aircraft nodes and ground security gateways; When an aircraft node connects to a ground security gateway, the aircraft node and the ground security gateway communicate based on the root key K. AS The master key K is generated by deriving key derivation parameters and key derivation functions. AS-SGW ; The ground security gateway distributes the master key K, used for communication between the aircraft node and the ground station, to the corresponding ground station through a secure communication channel. AS-GS Or key derivation parameters; The aircraft node and the ground station derive a session key locally based on the master key, and the session key is not distributed over the network.

4. The key management method for an aviation broadband communication system based on a pre-shared key according to claim 2, characterized in that: Step 3 includes: The system uses cryptographic cards that conform to national commercial cryptography standards to store and manage the keys. The key encryption key is generated and stored in the password card, and the root key K is then encrypted using the key encryption key. AS Master Key K AS-SGW K AS-GS The session key is encrypted and then stored. The plaintext of the key exists only in the secure operating environment of the cryptographic card, while the key stored outside the cryptographic card is saved in encrypted form; Perform integrity checks on the stored keys to prevent unauthorized tampering during storage and use.

5. The key management method for an aviation broadband communication system based on a pre-shared key according to claim 2, characterized in that: Step 4 includes: In dynamic cross-domain scenarios where aircraft nodes undergo cross-ground station handover, key updates are triggered. The ground security gateway sends a key update request to the aircraft node, the key update request carrying a random number NONCE for key update and the target ground station SAC_GS. T Logo; The aircraft node is based on the currently valid master key K AS-GS The random number and the target ground station identifier are used to generate the updated master key K. AS-GS’ ; The ground security gateway synchronously derives the updated master key K, which is consistent with the aircraft node. AS-GS’ The updated master key and the key materials used to derive the master key are then distributed to the target ground station via a secure communication channel. The aircraft node and the target ground station derive new session keys locally based on the updated master key, and perform revocation processing on the original master key and session key.

6. The method of claim 1, wherein the method further comprises: Step 5 includes: When a key reaches its preset usage period or a risk of key leakage is detected, the corresponding key is revoked. The revoked key is marked as invalid and is no longer used for new data encryption and message authentication code calculations; Simultaneously perform revocation processing on the sub-keys derived from the revoked key; The revoked key can only be used for decrypting historical data and verifying message authentication codes to complete the secure termination of the key's lifecycle.

7. A key management method for an aviation broadband communication system based on a pre-shared key according to claim 2, characterized in that: The master key length supports 128 bits or 256 bits; The session key includes the user data encryption key K. U-ENC and user data integrity protection key K U-INT .

8. The key management method for an aviation broadband communication system based on a pre-shared key according to claim 3, characterized in that: The root key K AS Pre-set distribution is achieved using a password card as the distribution medium; The master key K AS-SGW The distribution is completed during the secure access authentication process; The master key K AS-GS Distribution is accomplished via the IPSec secure channel; The session key is based on the master key K. AS-GS Derived locally.

9. The key management method for an aviation broadband communication system based on a pre-shared key according to claim 4, characterized in that: The key is stored in the key store in ciphertext form. The storage fields include key unique identifier id, key type key_type, owner, key ciphertext key_cipher, key length key_len, key encryption key ciphertext kek_cipher, initialization vector iv and its length iv_len, verification algorithm chck_algo, check value length check_len, and check value chck_value.

10. The method of claim 5, wherein the key update procedure is constructed by the target base station to send a key update reminder to the security gateway; and the key update response is sent by the aircraft node to the ground security gateway, including a key type key_type and a unique identification of the aircraft node SAC_AS. ​ The key update notification includes the aircraft identifier SAC_AS and the source base station identifier SAC_GS. S and the unique identifier of the destination base station SAC_GS T ; The key update request is sent from the ground security gateway to the aircraft node, and includes the key type (key_type) and the source base station identifier (SAC_GS). S Destination base station unique identifier SAC_GS T and random number NONCE; ​