A space-ground integrated identity authentication system and method thereof

CN122554112APending Publication Date: 2026-08-11玺信科技有限公司 +4
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-21
Publication Date
2026-08-11

AI Technical Summary

Technical Problem

[0009]第一,认证过程依赖中心化的认证服务器在线验证,在无地面网络覆盖区域虽然可通过卫星通信完成,但卫星链路的高延迟特性导致认证响应时间长、用户体验差,且认证服务器一旦出现故障或被攻击,整个区域的所有终端将完全丧失认证能力

Benefits of technology

[0054]通过芯片制造阶段一次性熔丝固化的全局ID(Global_ID)与物理不可克隆函数(PUF)动态派生的永不离开芯片的私钥作为硬件信任根,结合北斗短报文双向认证通道、动态可验证混淆IPv6地址派生算法以及集证通办认证管理确权应用单元,首次构建了一个在全球范围内完全脱离地面网络和实时CA查询的独立卫星认证闭环系统。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122554112A_ABST
    Figure CN122554112A_ABST
Patent Text Reader

Abstract

This invention discloses an integrated space-ground identity authentication system based on chip hardware root of trust and BeiDou short message bidirectional authentication, comprising: a chip hardware root of trust unit, which solidifies the Global_ID during the chip manufacturing stage and dynamically derives the chip private key; an IPv6 address derivation and binding unit, which generates an IPv6 address bound to the chip based on the chip Global_ID and the chip public key through a dynamic verifiable obfuscated address derivation algorithm; a BeiDou short message bidirectional authentication unit, which performs a challenge-response signing process through BeiDou short messages to achieve mutual identity authentication between the terminal and the authenticator; an end-to-end encrypted communication unit, which uses the derived session key to encrypt and transmit communication data identified by the IPv6 address; and a dual hash chain fragmentation and reassembly unit, which performs bidirectional verification fragmentation and out-of-order reassembly of the encrypted communication data based on forward hash chains and backward hash chains.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of information security technology, specifically relating to digital identity authentication technology. Background Technology

[0003] Current mainstream identity authentication schemes heavily rely on terrestrial internet infrastructure, such as IPv6-based Public Key Infrastructure (PKI) / Certificate Authority (CA) certificate authentication systems, Open Authentication (OAuth) authorization frameworks, and various centralized identity authentication services. These schemes all require terminal devices to be able to access the terrestrial network in real time to complete online certificate status queries, certificate revocation list checks, or interact with authentication servers.

[0004] However, when the terminal is located in areas without terrestrial network coverage, such as ocean-going vessels, polar research stations, desert hinterlands, high mountains and canyons, or war zones, the above authentication system becomes completely ineffective.

[0005] Although some existing technical solutions attempt to use satellite communication as a supplement, they mainly adopt one-way or simple two-way authentication protocols, lack hardware-level identity solidification protection, and are vulnerable to spoofing by fake satellite signals, replay attacks and man-in-the-middle attacks, and cannot meet the needs of high-security application scenarios.

[0006] In addition, China's BeiDou-3 system has global short message communication capabilities, with a single communication capacity of about 2,000 bytes and support for two-way authentication. However, existing technologies have not yet deeply integrated this capability with the chip hardware root of trust, and have failed to build a closed-loop trust system that is independent of the terrestrial network.

[0007] To address the aforementioned technical shortcomings, some improvements have been proposed in existing technologies. For example, existing technologies have proposed remote identity authentication methods based on satellite links, which typically involve the terminal sending its device serial number or digital certificate to an authentication center, which then verifies the certificate and returns the authentication result.

[0008] However, such solutions have the following fundamental problems.

[0009] First, the authentication process relies on centralized authentication servers for online verification. Although it can be completed via satellite communication in areas without terrestrial network coverage, the high latency of satellite links results in long authentication response times and poor user experience. Furthermore, if the authentication server malfunctions or is attacked, all terminals in the entire area will completely lose their authentication capabilities.

[0010] Second, existing technical solutions generally lack hardware-level root of trust protection. Device private keys or certificates are usually stored in general flash memory or ordinary encryption chips, resulting in a high risk of identity forgery and impersonation.

[0011] Third, existing technical solutions lack a strong cryptographic binding relationship between IPv6 addresses and device identities. They typically use static configuration or simple stateless address auto-configuration to generate IPv6 addresses, which allows third parties to track the movement of devices and seriously infringes on user privacy.

[0012] Fourth, regarding the injection of BeiDou short message credentials, existing technical solutions only support simple small-volume data transmissions. For digital credentials exceeding the capacity of a single short message (such as digital currency wallet certificates, electronic certificates, etc.), the packet loss rate and transmission failure rate are high in actual use, making them unsuitable for engineering applications.

[0013] Fifth, existing technical solutions do not consider the issue of asset migration after physical damage to the chip. When the terminal's security chip fails to function due to physical damage, the user's digital assets stored in the chip (such as wallet balance, electronic certificates, communication keys, etc.) will be permanently lost. The lack of a secure remote migration and recovery mechanism severely restricts the practical application and promotion of this type of technology.

[0014] Therefore, there is an urgent need for a new integrated space-ground identity authentication system and method that can fundamentally solve the above-mentioned technical defects.

[0015] It should be noted that the above description of the technical background is only for the purpose of providing a clear and complete explanation of the technical solutions of the present invention and facilitating understanding by those skilled in the art. It should not be assumed that the above technical solutions are known to those skilled in the art simply because they have been described in the background section of this invention. Summary of the Invention

[0016] The purpose of this invention is to overcome the shortcomings of the prior art and provide an integrated space-ground identity authentication system and method.

[0017] This invention discloses a space-ground integrated identity authentication system based on chip hardware root of trust and BeiDou short message bidirectional authentication, comprising: a chip hardware root of trust unit configured to solidify a global ID (Global_ID) (defined as a globally unique identifier) ​​through a one-time fuse during chip manufacturing, and dynamically derive a chip private key based on a Physically Unclonable Function (PUF) module. This chip private key never leaves the chip and is dynamically restored by hardware each time it is used; an IPv6 address derivation and binding unit configured to generate an IPv6 address bound to the chip based on the chip Global_ID and the chip public key using a dynamically verifiable obfuscated address derivation algorithm, and establish a cryptographic binding relationship between the chip Global_ID and the IPv6 address, wherein the dynamically verifiable obfuscated address derivation algorithm satisfies non-linkability; and a BeiDou short message bidirectional authentication unit configured to execute a challenge-response signature process via BeiDou short messages to achieve mutual identity authentication between the terminal and the authenticator, wherein each party uses its own private key. The system includes: a signature verification function for challenges from the other party; an end-to-end encrypted communication unit for encrypting and transmitting communication data identified by the IPv6 address using the derived session key after the above two-way authentication is successful; and a dual hash chain fragmentation and reassembly unit for performing bidirectional verification fragmentation and out-of-order reassembly of the encrypted communication data based on forward and backward hash chains under the condition of limited BeiDou short message length. The chip hardware trust root unit provides the signature private key required for authentication to the BeiDou short message two-way authentication unit, and the IPv6 address derivation unit generates an address based on the BeiDou week number and the same PUF root key and binds it to the chip hardware identity. These three units together constitute a closed-loop trust chain integrating space and ground facilities, independent of ground infrastructure.

[0018] Furthermore, in the aforementioned IPv6 address derivation and binding unit, the dynamic verifiable obfuscated address derivation algorithm is implemented in the following manner:

[0019] (Equation 1)

[0020] In the formula, Trunc is the truncation function to the IPv6 address length, H is the quantum-resistant hash function, ⊕ is the bitwise XOR operation, S is the digital identifier, K is the chip public key hash value, and N is the chip's unique serial number;

[0021] A t For dynamic IPv6 addresses, A0 is defined as This is used only for internal recursive calculations within the chip and is not publicly available.

[0022] T tThe BeiDou cycle number is obtained in real time by the terminal from the BeiDou satellite timing signal. The verification party can independently obtain the same T from the BeiDou satellite signal. t value;

[0023] For finite field multiplication, defined in GF(2 256 Prime number field, to implement T t With State t-1 Nonlinear confusion;

[0024] (Equation 2)

[0025] This is a hash of the chip's overall state at the previous moment, enabling a deep binding between the address and the chip's historical state;

[0026] (Equation 3)

[0027] Where ω is a preset chip-level confusion parameter, realizing the quantum confusion-resistant layer F ω ;

[0028] The above derived algorithm satisfies the condition that, given (S, K, N, ω), any historical address A can be verified. t The legitimacy of the chip state; due to the introduction of chip state. t-1 The chip-level obfuscation parameter ω causes the address sequence to exhibit strong unidirectionality and individual chip-specific variability, making it impossible to determine the address sequence from the current address A. t Reverse tracing of historical address A t-1 It is also impossible to predict the address sequence of another chip from the address sequence of one chip, thus achieving a dual security guarantee of non-linkability and non-cloning.

[0029] Furthermore, the two-way authentication process executed by the aforementioned BeiDou short message two-way authentication unit includes: the first terminal sending an authentication request to the second terminal via BeiDou short message, the authentication request carrying the first terminal's PUF-derived public key and a first random number; after receiving the authentication request, the second terminal generates a second random number, signs the first and second random numbers using the first terminal's PUF-derived public key, and returns the second terminal's PUF-derived public key and signature result via BeiDou short message; after verifying the signature result, the first terminal generates a session key, encrypts the session key using the second terminal's PUF-derived public key, and sends it to the second terminal via BeiDou short message; after decrypting the session key, the second terminal returns a confirmation message; wherein the aforementioned two-way authentication process does not rely on the online participation of a ground authentication system, and after successful authentication, both parties directly derive a session key for end-to-end encrypted communication without needing to return to any centralized authentication system for secondary verification; the purpose of the aforementioned authentication is to establish end-to-end encrypted communication credentials between terminals, rather than to obtain access rights to BeiDou satellite services.

[0030] Furthermore, during the initial registration of the aforementioned terminal, a provisional ID (PID) is assigned by the root trust server. The mapping relationship between the PID and the chip public key is stored in the public mapping directory, and the Global_ID is not publicly disclosed. The aforementioned PID has a configurable validity period. When the terminal is in a state without terrestrial network and the PID is about to expire, it initiates an offline update request to the root trust server via BeiDou short message, carrying the current PID, chip signature and newly generated public key. After verification, the aforementioned root trust server returns a new PID and corresponding credentials via BeiDou short message.

[0031] Furthermore, when a chip is damaged and assets need to be migrated, the aforementioned root trust server issues an encrypted migration authorization certificate, which includes the new chip's public key, a list of migration contents, and a validity period. After the new chip decrypts the migration authorization certificate using its own private key, it requests encrypted asset data from the root trust server and updates the chip's root trust status after recovery is complete.

[0032] Furthermore, the aforementioned integrated space-ground identity authentication system also includes a unified authentication management and authorization application unit, configured to perform the following operations after the terminal has completed its initial registration and obtained an electronic signature (including electronic official seal, electronic private seal, electronic signature, handwritten signature, etc.) issued by the root trust server:

[0033] (a) The digital identity credentials of the end user, electronic signature information, public key hash value derived from the chip hardware trust root unit, and verifiable statement of the dynamic IPv6 address generated by the IPv6 address derivation and binding unit are encapsulated into a structured data packet according to a predetermined data format. After digitally signing the data packet with the chip private key, a QR code image is generated and stored on the blockchain in the blockchain distributed ledger or public mapping directory for verification parties to scan and read.

[0034] (b) In any scenario where identity authentication or business rights confirmation is required, the user displays the above QR code through the terminal. After scanning the code, the verifier obtains the corresponding digital identity certificate and electronic signature information from the blockchain, verifies the validity of the chip signature and the binding relationship between the dynamic IPv6 address and the chip identity. Once the verification is successful, the user is considered to have completed identity authentication and there is no need to execute the challenge-response two-way authentication process again.

[0035] (c) In scenarios where electronic signatures are required, users use their registered electronic signatures to digitally sign or stamp electronic documents. The aforementioned centralized certificate management and rights confirmation application unit automatically calls the private key derived from the chip hardware trust root unit to sign the document hash value and attaches the signature along with the current status proof of the dynamic IPv6 address to the document. After receiving the document, the verifier verifies the validity of the electronic signature and the authenticity of the signature through the blockchain. Once the verification is successful, the authentication is completed.

[0036] (d) After the terminal successfully completes its initial registration and obtains the electronic signature certificate issued by the root trust server, the certificate forms a permanent cryptographic binding with the Global_ID and PUF root key in the chip hardware trust root unit. Unless the chip is physically damaged or the certificate is explicitly revoked, the verifier can independently complete the verification by presenting the QR code or using the electronic signature for signing / sealing operations at any time and any place (including areas accessible by terrestrial networks and areas covered only by BeiDou short messages). There is no need to initiate a real-time online authentication request to the root trust server again. The dynamic IPv6 address mentioned above is updated in real time by the IPv6 address derivation and binding unit according to the BeiDou week number and the chip's historical status. Each signing or sealing operation is accompanied by a currently valid dynamic IPv6 address certificate, making each authentication operation unique in terms of time and network location, preventing the QR code from being intercepted and reused or impersonated.

[0037] Furthermore, the aforementioned centralized certificate processing authentication management and rights confirmation application unit further configures the aforementioned dynamic IPv6 address as a dynamic encrypted USB key, specifically including:

[0038] (e) The private key dynamically derived from the chip hardware trust root unit and the IPv6 address derivation are combined with the dynamically generated IPv6 address A in real time by the binding unit. t Together, they serve as the two core components of a dynamic encrypted USB key, with the dynamic IPv6 address A... t According to the BeiDou cycle number T t and chip history state t-1 The U-shield's external appearance, namely the publicly visible IPv6 address, changes periodically due to changes in the IPv6 address, while the internal root key, namely the PUF-derived private key, remains unchanged and never leaves the chip.

[0039] (f) When a high-security operation is required, the authenticator first obtains the terminal's current dynamic IPv6 address A. t , with A t As a dynamic challenge parameter, the terminal is required to use the chip's private key to test A. tThe signature is created by concatenating the hash value of the current operation content. After the terminal completes the signature within the chip's hardware trust root unit, it returns the result. The verifier verifies the signature using the chip's public key, and simultaneously verifies A. t Whether it is consistent with the expected value calculated based on the publicly available chip identity information and the current BeiDou cycle number, thus realizing the dynamic U-shield authentication mode of address as challenge and signature as response.

[0040] (g) Due to dynamic IPv6 address A t It changes irreversibly in a unidirectional direction over time or with the number of operations. Even if an attacker intercepts the signature value of a certain operation and the corresponding A... t It is also impossible to replay the signature at the current moment or on other terminals, because the verifier will check A. t Whether it matches the current BeiDou cycle number and the chip's historical status; at the same time, the anti-quantum hash function and chip-level confusion parameter ω introduced in the dynamic IPv6 address derivation algorithm enable the dynamic U-shield to resist quantum computing attacks.

[0041] (h) When the terminal is in an area without terrestrial network coverage, the above-mentioned dynamic encryption U-shield function is carried by the Beidou short message two-way authentication unit, and the terminal will send the current dynamic IPv6 address A t The signature of the operation content is encapsulated in a BeiDou short message and sent to the verifier. After receiving the BeiDou short message, the verifier independently obtains the current BeiDou cycle number from the BeiDou satellite signal to calculate the expected A. t The value is used to complete signature verification, thereby achieving dynamic U-shield authentication that is completely independent of the terrestrial network.

[0042] Furthermore, the aforementioned IPv6 address derivation and binding unit is also configured such that, when the terminal initiates registration with the root trust server for the first time or performs IPv6 terrestrial channel authentication for the first time, the terminal submits the current IPv6 address generated by its IPv6 address derivation and binding unit, as well as at least one set of trusted fixed IPv6 addresses pre-specified by the terminal user, to the root trust server through a secure channel. The aforementioned set of trusted fixed IPv6 addresses includes, but is not limited to, the terminal address under the IPv6 prefix of the home gateway, the terminal address under the IPv6 prefix of the enterprise office network, and IPv6 addresses in other trusted network environments manually configured by the user.

[0043] Before issuing temporary identity identifiers (PIDs) and digital identity certificates, or before the initial authentication is successful, the root trust server shall enforce at least one of the following verification procedures: (a) The root trust server confirms the authenticity and ownership of the trusted fixed IPv6 address set submitted by the end user. After confirmation, the trusted address set is cryptographically bound to the terminal's chip public key, and a trusted address binding certificate is generated in the form of a signature by the root trust server's private key and stored in a public mapping directory or a blockchain distributed ledger; (b) The root trust server requires that the terminal's initial authentication must be initiated from an address in the aforementioned trusted fixed IPv6 address set. If the IPv6 address currently used by the terminal does not belong to any pre-bound and verified trusted address, then the root trust server... (c) During the challenge-response process of the first authentication, in addition to verifying the terminal's chip private key signature, the root trust server also verifies whether the terminal's current IPv6 address matches any address in the trusted fixed IPv6 address set. If the match fails, a second out-of-band interaction confirmation is triggered, or the authentication process is terminated. The aforementioned trusted fixed IPv6 address set supports dynamic updates. When the terminal user needs to add, delete, or modify a trusted address, the update request must be signed using the original valid PID and chip private key and submitted to the root trust server through the Beidou short message bidirectional authentication unit or the ground security channel. After verifying the signature, the root trust server issues the updated trusted address binding certificate.

[0044] Furthermore, the aforementioned chip hardware trust root unit is configured to use the terminal device ID as the SM9 identifier. The Key Generation Center (KGC) pre-generates the corresponding SM9 encryption private key and signing private key for the terminal, and writes the private key into the chip hardware trust root unit via an on-chip fuse or a one-time programmable memory. When the terminal powers on and initiates authentication, the chip hardware trust root unit dynamically derives an unclonable temporary root key from the PUF. The temporary root key is used to decrypt the SM9 private key stored in the chip to obtain a usable SM9 signing private key. The SM9 signing private key is used to sign the BeiDou short message authentication request, and the signature result is sent to the peer or verification server via BeiDou short message. The SM9 private key is always in an encrypted form protected by the PUF in static storage. It is only obtained by decryption using the PUF dynamically derived temporary root key during authentication. Throughout the entire process, the SM9 private key is never transmitted or distributed through any secure channel or out-of-band method, fundamentally solving the key distribution problem when a secure channel is absent in extreme environments without terrestrial network coverage.

[0045] This invention also discloses an integrated space-ground identity authentication method, comprising the following steps:

[0046] S1. During the chip manufacturing stage, a global ID (Global_ID) is fixed by a one-time fuse. The chip private key is derived based on the Physically Unclonable Function (PUF). The chip private key never leaves the chip. At the same time, Global_ID is configured as the user identifier of the SM9 identification cryptographic algorithm.

[0047] S2. Based on the chip's Global_ID and public key, an IPv6 address bound to the chip is generated through a dynamic verifiable obfuscated address derivation algorithm. A cryptographic binding relationship between the chip's Global_ID and the IPv6 address is established, and the chip's private key signs the above binding relationship. The above derivation algorithm adopts a two-way coupling of BeiDou week number and chip historical state to achieve the unlinkability of address sequences.

[0048] S3. The terminal submits the Global_ID and chip public key to the root trust server through a secure channel. The root trust server assigns a temporary identity identifier (PID) and issues a digital identity certificate, which is pre-stored in the chip's secure storage area.

[0049] S4. Real-time detection of the ground network status. When the ground network is available, online authentication is performed through the IPv6 ground channel; when the ground network is unavailable and the continuous interruption time reaches a preset threshold, it automatically switches to the BeiDou short message authentication channel.

[0050] S5. The terminal and the verifier execute the challenge-response signing process via BeiDou short message. They can choose to use the traditional signature scheme with PUF derived private key or the SM9 identifier signature scheme. The terminal sends an authentication request carrying the PID and the first random number. The verifier returns the second random number and its own signature. The terminal signs the request in the chip and returns it. The verifier verifies the signature and completes the two-way mutual recognition.

[0051] S6. When the terminal is in an area without a terrestrial network and needs to inject digital credentials, it receives the fragmented credential packets through Beidou short messages, and uses a dual hash chain sliding window dynamic verification mechanism to perform out-of-order reordering, packet loss detection and integrity verification. After passing the verification, the credential packets are written into the chip security domain.

[0052] S7. When a chip is damaged, the asset is securely migrated from the old chip to the new chip using encrypted migration authorization credentials.

[0053] The core advantage of this invention lies in:

[0054] By using a global ID (Global_ID) that is permanently fixed by a fuse during the chip manufacturing stage and a private key that is dynamically derived from a physically unclonable function (PUF) and never leaves the chip as a hardware root of trust, combined with the BeiDou short message bidirectional authentication channel, a dynamically verifiable obfuscated IPv6 address derivation algorithm, and a certificate-based authentication management and rights confirmation application unit, an independent satellite authentication closed-loop system that is completely independent of terrestrial networks and real-time CA queries has been built for the first time globally.

[0055] Among them, the chip hardware trust root unit provides a physically unforgeable trust anchor for the entire system; the Beidou short message two-way authentication unit completes end-to-end two-way identity authentication without relying on any ground authentication system; the IPv6 address derivation and binding unit realizes strong cryptographic binding and non-linkability of chip identity and network address, thereby protecting the privacy of device movement trajectory; and the certificate-based authentication management and rights confirmation application unit configures the dynamic IPv6 address as a dynamic encrypted U-shield and combines it with QR code on-chain evidence storage to realize a one-time authentication and lifetime use mechanism of signature as authentication and stamp as authentication. This enables terminal devices in any area without ground network coverage, such as oceans, polar regions, deserts, and mountains, to complete hardware-level unforgeable two-way identity authentication, digital credential secure injection, dynamic U-shield authentication, and remote asset migration solely by relying on Beidou satellite short message service. This fundamentally solves the fundamental defect of existing IPv6 authentication schemes that are completely ineffective in network blind spots. At the same time, the integrated design of "identity as identifier, trust as address, and authentication as signature" realizes an end-to-end secure trust chain from the physical layer to the application layer.

[0056] The beneficial effects of this invention are as follows.

[0057] First, by using the Global ID (Global_ID) solidified once during the chip manufacturing stage and the private key dynamically derived from the Physically Unclonable Function (PUF) that never leaves the chip as a hardware root of trust, combined with the BeiDou short message bidirectional authentication channel and the SM9 identifier cryptographic algorithm, an independent satellite authentication closed-loop system that is completely independent of the ground network and real-time CA query is constructed for the first time globally, fundamentally solving the fundamental defect of existing IPv6 authentication schemes that completely fail in network blind spots.

[0058] Second, by using dynamic address derivation functions to achieve strong cryptographic binding and non-linkability between the chip's Global_ID and IPv6 address, the address sequence exhibits strong unidirectionality and chip-specific differences. Attackers cannot deduce historical addresses from the current address, nor can they predict the address sequence of another chip from the address sequence of one chip, thus effectively protecting the privacy of the device's movement trajectory.

[0059] Third, the integrated certificate management and rights confirmation application unit configures the dynamic IPv6 address as a dynamic encrypted U-shield, realizing a dynamic authentication mode of address as challenge and signature as response. It also encapsulates digital identity credentials and electronic signature information into QR codes for on-chain storage, realizing a one-time authentication and lifetime use mechanism of signature as authentication and stamp as authentication, which greatly improves efficiency in high-frequency authentication scenarios.

[0060] Fourth, a dual-hash chain sliding window reassembly protocol is adopted to achieve reliable fragmented transmission, out-of-order reassembly, packet loss detection, and anti-replay attack in the low-bandwidth, high-latency, and connectionless communication environment of BeiDou short messages, thus solving the problem of high packet loss rate and transmission failure rate of existing technical solutions in actual engineering.

[0061] Fifth, it supports encrypted migration authorization credentials to enable secure asset recovery after chip damage, as well as initial registration and offline PID updates in environments without terrestrial networks. Combined with seamless adaptive switching of the space-ground communication channel, it provides an end-to-end secure trust chain from the physical layer to the application layer for integrated space-ground applications such as digital currency, electronic certificates, and ocean communications. Attached Figure Description

[0062] Figure 1 This is a schematic diagram of an integrated space-ground identity authentication system according to an embodiment of the present invention.

[0063] Figure 2 This is a flowchart of an integrated space-ground identity authentication method according to an embodiment of the present invention.

[0064] The reference numerals in the above figures are as follows:

[0065] The system comprises the following components: a space-ground integrated identity authentication system 100, a chip hardware trust root unit 110, an IPv6 address derivation and binding unit 120, a Beidou short message bidirectional authentication unit 130, an end-to-end encrypted communication unit 140, a dual hash chain fragmentation and reassembly unit 150, a centralized certificate processing authentication management and rights confirmation application unit 160, and steps S1 to S7. Detailed Implementation

[0066] To better understand this invention, the following embodiments are provided in conjunction with the accompanying drawings. It should be understood that the embodiments of this invention are for illustrative purposes only and not for limiting the invention; the scope of protection of this invention is defined solely by the claims. The embodiments provided are merely preferred embodiments and are not intended to limit the invention in any way. Those skilled in the art can make changes, equivalent substitutions, or modifications based on the content of this invention, resulting in different implementation methods. However, any changes and modifications, or equivalent substitutions, made to the method of this invention without departing from the inventive concept are within the scope of protection of this invention.

[0067] It should be noted that the following detailed descriptions are exemplary and intended to provide further illustration of the invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains.

[0068] It should be noted that the terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the scope of exemplary embodiments according to the invention. As used herein, the singular form is intended to include the plural form as well, unless the context clearly indicates otherwise. Furthermore, it should be understood that when the terms “comprising” and / or “including” are used in this specification, they indicate the presence of features, steps, operations, and / or combinations thereof.

[0069] First, please refer to Figure 1 . Figure 1 This is a schematic diagram of an integrated space-ground identity authentication system 100 according to an embodiment of the present invention. Figure 1 As shown, the integrated space-ground identity authentication system 100 of the present invention includes a chip hardware trust root unit 110, an IPv6 address derivation and binding unit 120, a Beidou short message bidirectional authentication unit 130, an end-to-end encrypted communication unit 140, and a dual hash chain fragmentation and reassembly unit 150.

[0070] First, during the chip manufacturing stage, a globally unique identifier, Global_ID, is solidified inside the chip hardware trust root unit 110 through a one-time fuse process. The chip private key is dynamically derived based on the Physically Unclonable Function (PUF) module. This private key is only temporarily restored by the hardware when the chip is powered on and is automatically destroyed after use, never leaving the chip, thus establishing a physically unforgeable trust anchor for the entire system.

[0071] Secondly, the IPv6 address derivation and binding unit 120 is connected to the chip hardware trust root unit 110. The IPv6 address derivation and binding unit 120 reads the Global_ID and chip public key provided by the chip hardware trust root unit 110, generates an IPv6 address that is cryptographically bound to the chip through a dynamic verifiable obfuscated address derivation algorithm, establishes a binding relationship between the chip's Global_ID and the IPv6 address, and digitally signs the binding relationship with the private key derived by the chip hardware trust root unit 110 to ensure that the IPv6 address cannot be forged or tampered with. Moreover, the derivation algorithm satisfies the non-linkability requirement, making it impossible for attackers to deduce the chip's historical address or predict its future address from the currently publicly available IPv6 address.

[0072] Then, the BeiDou short message bidirectional authentication unit 130 is connected to the chip hardware trust root unit 110 and the IPv6 address derivation and binding unit 120, respectively. When the terminal is in an area without terrestrial network coverage, the BeiDou short message bidirectional authentication unit 130 executes the challenge-response signature process through the BeiDou satellite's Remote Device Service System (RDSS) short message service: The first terminal generates a first random number and sends an authentication request to the second terminal via BeiDou short message, carrying the first terminal's PUF derived public key and the first random number; after receiving the request, the second terminal generates a second random number, signs the first and second random numbers using the first terminal's PUF derived public key, and returns the second terminal's PUF derived public key and signature result via BeiDou short message; after verifying the signature result, the first terminal generates a session key, encrypts the session key using the second terminal's PUF derived public key, and sends it to the second terminal via BeiDou short message; after the second terminal decrypts and obtains the session key, it returns a confirmation message. At this point, both parties complete true mutual identity authentication, and the entire authentication process does not rely on any terrestrial authentication system.

[0073] Next, after the end-to-end encrypted communication unit 140 is authenticated by the Beidou short message bidirectional authentication unit 130, it uses the session key negotiated by both parties to encrypt and transmit the communication data identified by the IPv6 address generated by the IPv6 address derivation and binding unit 120, so as to ensure the confidentiality and integrity of the communication content.

[0074] Meanwhile, under the condition of limited BeiDou short message length (approximately 2000 bytes per message), the dual-hash chain fragmentation and reassembly unit 150 performs the following operations on the encrypted communication data to be transmitted:

[0075] The original data is split into multiple fragments, and the forward hash chain value is calculated for each fragment.

[0076] (Equation 4)

[0077] and backward hash chain value

[0078] (Equation 5)

[0079] Each shard carries both forward and backward hash chain values;

[0080] The terminal maintains a sliding window buffer. After receiving fragments, it confirms the order by matching the forward hash chain and performs reverse verification by the backward hash chain, forming a two-way confirmation mechanism. When a missing fragment is detected, a selective retransmission request is immediately sent. If the fragment is not fully received within the timeout period, a whole retransmission is requested.

[0081] After collecting all fragments, verify the integrity check conditions.

[0082] (Equation 6)

[0083] and

[0084] (Equation 7)

[0085] After passing the test, the data will be reorganized.

[0086] Finally, the aforementioned chip hardware trust root unit 110 provides the signature private key required for authentication to the Beidou short message bidirectional authentication unit 130. The IPv6 address derivation and binding unit 120 generates an address based on the Beidou week number and the same PUF root key and binds it to the chip hardware identity. The dual hash chain fragmentation and reassembly unit 150 ensures reliable data transmission on low-bandwidth, high-latency satellite links. The three core units together form a closed-loop trust chain that is completely independent of ground facilities, enabling terminal devices in any area without ground network coverage, such as oceans, polar regions, and deserts, to complete hardware-level bidirectional identity authentication and secure data transmission solely by relying on the Beidou satellite short message service.

[0087] The IPv6 address derivation and binding unit 120 mentioned above uses an algorithm to generate dynamically verifiable obfuscated addresses. The specific implementation of this algorithm is as follows.

[0088] The input chip's digital identifier S, chip public key hash value K, chip unique serial number N, and preset chip-level obfuscation parameter ω are used. ω is written to each chip using a one-time fuse during the chip manufacturing stage and is unique to each chip.

[0089] First, the chip hardware trust root unit 110 provides the chip's overall state hash from the previous moment.

[0090] (Equation 2)

[0091] This value contains the chip's globally unique identifier (Global_ID), public key information (K), and the previous IPv6 address (A). t-1 And the previous BeiDou cycle number T t-1 Deep binding is performed, and the terminal obtains the current BeiDou week number T from the BeiDou timing module. t , in GF(2 256 Performing finite field multiplication on a prime field This achieves nonlinear bidirectional coupling between BeiDou time and chip historical state, and then calculates the first hash component. With the second hash component Then calculate the anti-quantum confusion layer

[0092] (Equation 8)

[0093] After performing a bitwise XOR operation on the above three components, the result is input into the quantum-resistant hash function H, and finally the lower 128 bits are truncated by the Trunc truncation function to be used as the IPv6 address A at the current moment. t , where the initial address

[0094] (Equation 9)

[0095] It is used only for recursive calculations within the chip and is not disclosed to the public.

[0096] Using the algorithm described above, the verifier receives the IPv6 address A claimed by the terminal. t Later, due to the number of cycles T of Beidou t It can be independently acquired from BeiDou satellite signals. t-1 A can be obtained recursively from the address verified in the previous time step, and the verifier can independently calculate and verify A. t The legitimacy of A is questionable, but due to the introduction of a chip-level unique obfuscation parameter ω and the one-way hashing characteristic in the recursive structure, attackers cannot obtain it from the currently publicly available A. t Reverse derivation of A t-1 It is also impossible to predict the address sequence of another chip from the address sequence of one chip, thus achieving dual security guarantees of non-linkability and non-cloning.

[0097] The specific implementation of the two-way authentication process executed by the BeiDou short message two-way authentication unit 130 is as follows: First, the first terminal sends an authentication request to the second terminal via BeiDou short message, the request carrying the first terminal's PUF-derived public key and a first random number; second, after receiving the authentication request, the second terminal generates a second random number, signs the first and second random numbers using the first terminal's PUF-derived public key, and returns the second terminal's PUF-derived public key and signature result via BeiDou short message; then, after verifying the signature result, the first terminal generates a session key, encrypts the session key using the second terminal's PUF-derived public key, and sends it to the second terminal via BeiDou short message; finally, the second terminal decrypts the session key and returns a confirmation message.

[0098] The core feature of this process is that the entire two-way authentication process does not rely on the online participation of the ground authentication system. After the authentication is successful, both parties directly derive the session key for end-to-end encrypted communication without returning to any centralized authentication system for secondary verification. Moreover, the fundamental purpose of this authentication is to establish end-to-end encrypted communication credentials between terminals, rather than to obtain access rights to BeiDou satellite services, thus forming a fundamental difference from existing technical solutions that rely on centralized authentication.

[0099] It is worth noting that, in one embodiment of the present invention, when the terminal device is manufactured for the first time or connected to the system for the first time, the terminal submits the Global_ID hash value and the chip public key from the chip hardware trust root unit 110 to the root trust server through a secure terrestrial network channel. After verifying the authenticity of the terminal's identity, the root trust server assigns a temporary identity identifier (PID) to the terminal. A one-to-one mapping relationship is established between the PID and the chip public key, and the mapping relationship is stored in a public mapping directory. This public mapping directory can use blockchain distributed storage to ensure transparency and immutability, while the actual chip Global_ID is never disclosed, thereby protecting the chip's physical identity privacy. The root trust server also issues a digital identity certificate for the PID, including the PID, the corresponding chip public key, the validity period (configurable to 30 days), and the digital signature of the root trust server. This certificate is pre-stored in the chip's secure storage area through a secure channel. When a terminal is in an area without terrestrial network coverage and its current PID is about to expire (e.g., less than 7 days remaining), the terminal initiates an offline update request to the root trust server via the BeiDou short message bidirectional authentication unit 130. This request carries the current PID, a signature of the current PID and the request timestamp derived from the chip hardware trust root unit 110, and a newly generated public key pair from the terminal. Upon receiving the request, the root trust server verifies the validity of the signature and the matching relationship between the current PID and the chip public key. After confirmation, it generates a new PID and a corresponding new digital identity credential, which is then returned to the terminal via point-to-point encryption using BeiDou short messages. After receiving the new credential, the terminal updates it to the chip's secure storage area and replaces the old PID with the new PID for subsequent authentication processes. The entire PID offline update process does not require terrestrial network participation and relies entirely on BeiDou short messages, ensuring that the terminal can continuously obtain a valid temporary identity in areas with long-term lack of terrestrial network coverage, such as oceans, deserts, and polar regions, thereby maintaining uninterrupted authentication services.

[0100] It is worth noting that, in one embodiment of the present invention, when the chip in the aforementioned chip hardware trust root unit 110 can no longer function normally due to physical damage, electrical overload, or expiration of its lifespan, the user submits chip damage proof documents and user identity verification materials to the root trust server through a trusted terrestrial network channel or through the BeiDou short message bidirectional authentication unit 130. After verifying the authenticity of the user's identity and the legal ownership of the original chip, the root trust server generates an encrypted migration authorization certificate. This certificate includes the public key of the target new chip to be migrated, a list of assets to be migrated (such as digital wallet certificates, electronic certificates, communication keys, etc.), and the validity period of the authorization certificate. The root trust server uses the public key of the new chip to encrypt and encapsulate the above information and attaches its own digital signature to ensure the integrity and authenticity of the certificate. The root trust server transmits the encrypted migration authorization certificate through a secure channel (if a terrestrial network is available) or through BeiDou short message... The two-way authentication unit 130 sends the document to the user's new terminal device in a fragmented transmission manner. After receiving the migration authorization certificate, the new terminal's chip hardware trust root unit 110 decrypts the certificate using the new chip's own private key, verifies the signature of the root trust server and the validity period of the certificate. After confirming that everything is correct, the new chip sends an asset recovery request to the root trust server. This request carries the migration serial number in the migration authorization certificate and the signature of the new chip. After the root trust server verifies the request, it sends the encrypted asset data associated with the old chip (encrypted using the temporary key negotiated in the migration authorization certificate) to the new terminal. After receiving the encrypted asset data, the new terminal decrypts it inside the chip and writes it into the secure storage area, completing the complete secure migration of assets from the old chip to the new chip. Throughout the process, the private key of the old chip and sensitive asset data are always transmitted in encrypted form. The migration authorization certificate has an expiration period and is bound to the public keys of the old and new chips to prevent the authorization certificate from being intercepted and used for asset recovery of other unauthorized chips.

[0101] It is worth noting that, in one embodiment of the present invention, the centralized certificate access authentication management and rights confirmation application unit 160 is connected to the chip hardware trust root unit 110, the IPv6 address derivation and binding unit 120 and the Beidou short message bidirectional authentication unit 130 respectively, and its specific implementation is as follows.

[0102] After the terminal has completed its initial registration and the root trust server has issued an electronic signature certificate, the centralized certificate management and authorization application unit 160 first performs the certificate encapsulation and QR code generation operations: the centralized certificate management and authorization application unit 160 reads the Global_ID hash value and chip public key embedded in the chip hardware trust root unit 110, and reads the current dynamic IPv6 address A generated in real time by the IPv6 address derivation and binding unit 120. tIts verifiable claims, and will include the end user's digital identity credentials, electronic signature information, chip public key hash value, and dynamic IPv6 address A. t The verifiable statement is encapsulated into a structured data packet according to a predetermined data format. Then, the data packet is digitally signed using a private key derived from the chip hardware trust root unit 110. The signed data packet is encoded to generate a QR code image. Finally, the data packet corresponding to the QR code and its signature are submitted to the blockchain distributed ledger or public mapping directory for storage through the uplink port built into the centralized certificate management and rights confirmation application unit 160. This allows any verifier to scan the code and independently verify it offline.

[0103] In any scenario requiring identity authentication or business authorization, such as when a user logs into a government service website, signs an electronic contract, or activates a digital currency wallet, the user displays a generated QR code on their terminal screen. The verifier, using a scanning device, reads the QR code and first retrieves the digital identity credential and electronic signature information associated with the QR code from the blockchain. Then, they verify the authenticity of the chip signature and simultaneously verify the dynamic IPv6 address A carried in the QR code. t Whether it matches the expected value calculated by the algorithm of the binding unit 120 through IPv6 address derivation of the chip public key of the chip hardware trust root unit 110 and the current Beidou week number, after all the above verifications are passed, it is considered that the user has completed identity authentication, and there is no need to execute the challenge-response two-way authentication process again, thereby realizing signature as authentication.

[0104] In scenarios requiring electronic signatures, such as when a user electronically signs a PDF procurement contract, the centralized authentication management and rights confirmation application unit 160 automatically calls the private key derived from the chip hardware trust root unit 110 to digitally sign the hash value of the contract document. Simultaneously, it obtains the current dynamic IPv6 address A from the IPv6 address derivation and binding unit 120. t The current state proof is attached to the contract's signature attributes, forming a complete electronic signature packet. Upon receiving the contract, the recipient verifies the validity of the electronic signature credential and the authenticity of the chip signature via blockchain, while also verifying the dynamic IPv6 address A. t The binding relationship between the chip identity and the current timestamp is verified, and the authentication is completed upon successful verification, thus realizing authentication by stamping.

[0105] The integrated authentication and management rights confirmation application unit 160 also incorporates a one-time authentication for lifelong use mechanism: after the terminal successfully completes its initial registration and obtains an electronic signature certificate issued by the root trust server, this electronic signature certificate is permanently bound to the Global_ID and PUF root key in the chip hardware trust root unit 110 through a cryptographic hash chain. Unless the chip is physically damaged or the certificate is explicitly revoked by the root trust server, the user can present the QR code or use the electronic signature for signing or stamping at any time and any place (including areas accessible by terrestrial networks and areas covered only by BeiDou short messages). The verifier can independently complete the verification through the publicly stored and tamper-proof certificate information on the blockchain without needing to initiate a real-time online authentication request to the root trust server again. Simultaneously, due to the dynamic IPv6 address A... t IPv6 address derivation and binding unit 120 based on BeiDou week number T t and chip history state t-1 Real-time updates; each signature or stamp operation includes proof of a currently valid dynamic IPv6 address, ensuring that even if the QR code is intercepted, the IPv6 address at the time of interception will be recognized. t Address A at the time of actual user use t+1 Unlike other methods, the verifier will find a mismatch between the expected address calculated by comparing the current BeiDou cycle number and the address encapsulated in the QR code, thus rejecting the verification. This naturally prevents the QR code from being reused or misused, achieving a dynamic QR code security mechanism that is valid only once and has a unique key.

[0106] Building upon the existing QR code-based authentication management and rights confirmation application unit 160, which has already implemented a mechanism for QR code-based on-chain rights confirmation and one-time authentication for lifetime use, the aforementioned authentication management and rights confirmation application unit 160 further integrates the dynamic IPv6 address A generated in real-time by the IPv6 address derivation and binding unit 120. t Together with the private key dynamically derived from the chip hardware trust root unit 110, it is configured into a software-based encrypted U-shield with dynamic update capability. The specific implementation method is as follows.

[0107] First, the centralized certificate management and authorization application unit 160 performs the U-shield function mapping: the private key dynamically derived from the PUF in the chip hardware trust root unit 110 and never leaving the chip is used as the static root key of the U-shield; the IPv6 address derivation and binding unit 120 are then mapped according to the BeiDou week number T. t and chip history state t-1 A dynamically generated IPv6 address in real time using an algorithm t As a variable external identifier for the U-shield, the two together constitute the two core factors of a dynamic encrypted U-shield, among which the dynamic IPv6 address A tThe change cycle can be configured by the system security policy to change once every Beidou week, i.e., once a week, once a day, or once for each authentication operation. This makes the publicly visible IPv6 address of the U-shield continuously and irreversibly change in one direction, while the internal PUF derived root key remains unchanged and cannot be read by any attacker from outside the chip. This upgrades the traditional hardware U-shield's "fixed PIN code + fixed key" mode to a new U-shield architecture of "dynamic address challenge + static root key signature".

[0108] Secondly, in high-security operation scenarios, such as when a user initiates a digital RMB transfer exceeding 100,000 yuan or signs an important electronic contract with legal effect, the verification party first obtains the current dynamic IPv6 address A of the terminal where the centralized certificate processing authentication management and rights confirmation application unit 160 is located through the Beidou short message two-way authentication unit 130 or the ground network channel. t , and the A t As a dynamic challenge parameter, the terminal is required to use the private key derived from the chip hardware trust root unit 110 to pair A. t The digital signature is created by concatenating the hash value of the current operation content with the digital signature. After the terminal completes the signing operation within the chip hardware trust root unit 110, it returns the signature value to the verifier through the centralized certificate management and authorization application unit 160. Upon receiving the signature, the verifier verifies the authenticity of the signature using the terminal's chip public key and, based on the terminal's public chip identity information and the current BeiDou week number T independently obtained from the BeiDou satellite signal... t The expected dynamic IPv6 address A is independently recalculated through the algorithm used by the IPv6 address derivation and binding unit 120. t ', and compare with A t 'With A used as a challenge parameter t Whether they match or not, subsequent operations can only proceed after both have been verified, thus realizing the dynamic U-shield authentication mode of "address is challenge, signature is response".

[0109] The centralized authentication management and rights confirmation application unit 160 simultaneously utilizes the inherent time-varying characteristics of dynamic IPv6 addresses to enhance replay attack prevention: due to the dynamic IPv6 address A t According to the BeiDou cycle number T t Or the number of operations changes irreversibly in one direction, even if an attacker intercepts the signature value of a legitimate operation and the corresponding A through eavesdropping. t It is also impossible to replay the signature at the current moment or on other terminals because the verifier recalculates the expected address A at the current moment when performing verification. t ', The attacker intercepted the old address A t Compared with the current BeiDou cycle number A t'It is inherently different. The verifier can detect replay attacks and reject the authentication by comparing addresses. At the same time, because the dynamic IPv6 address derivation algorithm introduces a quantum-resistant hash function H such as SHAKE-128 and a chip-level unique confusion parameter ω, the dynamic U-shield has the ability to resist future quantum computer attacks. Even if the attacker has quantum computing capabilities, he will not be able to reverse-engineer the chip's root key or predict the address value at the next moment from a continuous address sequence.'

[0110] Finally, when the terminal is in an area with no terrestrial network coverage, such as an ocean-going vessel, the heart of a desert, or a polar research station, the dynamic encrypted U-shield function configured in the integrated certificate management and rights confirmation application unit 160 is carried out through the Beidou short message bidirectional authentication unit 130: the terminal will use the dynamic IPv6 address A obtained from the IPv6 address derivation and binding unit 120 at the current moment. t And the private key derived from the chip hardware trust root unit 110 for A t The signature, concatenated with the hash value of the operation content, is encapsulated in the data payload of a BeiDou short message and sent to the verifier. After receiving the request through the BeiDou short message two-way authentication unit 130, the verifier independently obtains the current BeiDou week number T from the BeiDou satellite signal. t To calculate the expected dynamic IPv6 address A t The system completes signature verification and address comparison. The entire authentication process does not require any terrestrial network participation, enabling the terminal to combine its own chip's physical identity with dynamically changing network location proof even in extreme environments completely detached from terrestrial infrastructure. This achieves dynamic authentication capabilities that are equivalent to or even superior to the security level of traditional hardware USB tokens.

[0111] Please see Figure 1 When a terminal in one embodiment of the present invention initiates registration with the root trust server for the first time or performs IPv6 terrestrial channel authentication for the first time, the first-time authentication control of the trusted IPv6 address is triggered, and the following specific implementation process is executed:

[0112] First, the terminal submits its current IPv6 address generated by the IPv6 address derivation and binding unit 120, along with a set of trusted fixed IPv6 addresses pre-specified by the user, to the root trust server via a secure channel. This set of trusted fixed IPv6 addresses includes, but is not limited to, terminal addresses under the IPv6 prefix of the user's home gateway, terminal addresses under the IPv6 prefix of the enterprise office network, and IPv6 addresses in other trusted network environments manually configured by the user. For example, a user logs into the root trust server portal via a secure webpage using a computer at home, enters their home broadband-assigned IPv6 address 2001:db8:1::100 and the enterprise network-assigned IPv6 address 2001:db8:2::200, and submits a request to bind it to the chip's public key.

[0113] Secondly, the root trust server enforces address controllability verification before issuing temporary identity identifiers (PIDs) and digital identity certificates: the root trust server confirms the authenticity and ownership of the trusted fixed IPv6 address set submitted by the end user through out-of-band verification. Specifically, the root trust server can send an SMS message containing a verification code to the user's pre-registered mobile phone number, requiring the user to enter the verification code to prove that they are the legitimate user of the home network IPv6 address, or send a confirmation link to the user's corporate email address, requiring the user to click to confirm that they are the legitimate user of the corporate network IPv6 address. After successful confirmation, the root trust server cryptographically binds the trusted address set with the terminal's chip public key and generates a trusted address binding certificate in the form of a signature with the root trust server's private key, storing it in a public mapping directory or a blockchain distributed ledger. For example, the hash value of the PID and the trusted address set, along with the root trust server's signature, can be recorded on the chain for subsequent verification.

[0114] Then, the root trust server enforces the geographical and network constraints of the initial authentication, requiring the terminal's initial authentication to be initiated from an address in the aforementioned set of trusted fixed IPv6 addresses. If the IPv6 address currently used by the terminal does not belong to any pre-bound and verified trusted address, for example, if the terminal is currently located under a public Wi-Fi hotspot and its IPv6 address is 2001:db8:3::300, and this address is not registered in the set of trusted addresses, the root trust server will refuse to issue the PID and digital identity credentials, and will record an abnormal attempt log including the terminal's chip public key, attempt time, and source IPv6 address for security auditing.

[0115] Meanwhile, in the challenge-response process of initial authentication, in addition to verifying the terminal's chip private key signature, the root trust server also performs enhanced anti-man-in-the-middle attack verification with fixed address assistance. Specifically, the root trust server verifies whether the terminal's current IPv6 address matches any address in the set of trusted fixed IPv6 addresses. If the match is successful, the initial authentication is completed normally and a digital certificate is issued. If the match fails, a secondary out-of-band interaction confirmation is triggered. For example, the root trust server sends a one-time confirmation code to the user via SMS and requests the terminal to send back the confirmation code through the Beidou Short Message Two-Way Authentication Unit 130 to prove its identity legitimacy; otherwise, the authentication process is aborted.

[0116] In addition, the trusted IPv6 address initial authentication control supports dynamic updates of the trusted fixed IPv6 address set. When an end user needs to add, delete, or modify a trusted address, for example, if a user changes their home broadband provider due to moving and obtains a new home IPv6 address prefix, the terminal uses its original valid PID and chip private key to sign the update request and submits it to the root trust server through the Beidou short message bidirectional authentication unit 130 or the ground security channel. After verifying the signature, the root trust server issues an updated trusted address binding certificate, ensuring that the user's address change will not cause subsequent authentication failures.

[0117] Finally, the aforementioned trusted IPv6 address initial authentication control works in conjunction with the chip hardware trust root unit 110, IPv6 address derivation and binding unit 120, and Beidou short message bidirectional authentication unit 130. When the terminal establishes a trust relationship for the first time, the root trust server of the authenticator implements active address control. This ensures that even if an attacker obtains the terminal's chip public key through some means and attempts to forge a registration request, the root trust server will refuse to issue digital identity credentials because the source IPv6 address cannot be verified through the user's pre-bound trusted home or company address. This effectively prevents attackers from stealing the chip public key and subsequent digital identity credentials during the initial registration stage by using forged IPv6 addresses or man-in-the-middle attacks. This achieves a multi-factor initial authentication security defense that binds the terminal's physical identity, temporary identity, and trusted location at the network layer.

[0118] It is worth noting that, in one embodiment of the present invention, when a terminal device that has never been registered is directly deployed in an area with no terrestrial network coverage, such as the ocean, desert, polar regions, or mountainous areas, after the terminal is powered on for the first time, its chip hardware trust root unit 110 has already solidified the global ID (Global_ID) during the manufacturing stage and derived the chip private key based on the Physically Unclonable Function (PUF). The terminal actively initiates the registration process through the Beidou short message bidirectional authentication unit 130:

[0119] First, the chip's serial number (SN) is extracted, the hash value H(Global_ID) of the Global_ID is calculated, and the chip's public key is obtained. Then, the chip's SN, Global_ID hash value, and chip's public key are assembled into a registration request message. Next, the private key derived from the chip's hardware trust root unit 110 is used to digitally sign the request message. Finally, the registration request is sent to the root trust server in the form of a BeiDou short message through the BeiDou short message bidirectional authentication unit 130.

[0120] After receiving a registration request, the root trust server first verifies the validity of the signature to confirm that the request does indeed come from a legitimate chip that holds the private key corresponding to the Global_ID. Then, it checks whether the hash value of the Global_ID matches the expected value in the chip SN association record. After successful verification, the root trust server generates a unique temporary identity identifier (PID) and a corresponding digital identity credential for the terminal. The digital identity credential includes the PID, the chip public key, the validity period, and the digital signature of the root trust server.

[0121] Since the terminal does not yet possess any valid communication credentials, the root trust server uses the chip public key reported by the terminal to encrypt the PID and credentials, and sends the encrypted data back to the terminal via BeiDou short message point-to-point. After receiving the encrypted response, the terminal uses the chip private key within the chip hardware trust root unit 110 to decrypt, extract the PID and digital identity credentials, and store them in the chip's secure storage area, completing the initial registration.

[0122] Afterward, the terminal can use the obtained PID and credentials to perform secure identity authentication with other verifiers in the system according to the above two-way authentication process. This enables the terminal to complete its initial identity registration and credential distribution solely based on BeiDou short messages, even without any terrestrial network pre-registration conditions, thus completely solving the problem of initial trust establishment in extreme deployment environments.

[0123] The chip Global_ID in the aforementioned chip hardware trust root unit 110 can be directly used as the user identifier for the SM9 identification cryptographic algorithm. The Key Generation Center (KGC) pre-generates the corresponding SM9 encryption private key and signing private key for the terminal, and writes these private keys into the chip hardware trust root unit 110 via an on-chip fuse or a one-time programmable memory. When the terminal powers on and initiates authentication, the chip hardware trust root unit 110 dynamically derives an unclonable temporary root key from the PUF. This temporary root key is used to decrypt the SM9 private key stored in the chip to obtain a usable SM9 signing private key. Then, the SM9 signing private key is used to sign the BeiDou short message authentication request, and the signing result is sent to the peer or verification server via BeiDou short message.

[0124] The core feature of this configuration is that the SM9 private key is always in an encrypted form protected by PUF in static storage. It is only obtained by decryption during authentication using a PUF dynamically derived temporary root key. Throughout the entire process, the SM9 private key is never transmitted or distributed through any secure channel or out-of-band method. This fundamentally solves the key distribution problem when a secure channel does not exist in extreme environments without terrestrial networks, and achieves a deep integration of the chip's physical identity and the SM9 cryptographic identity.

[0125] Please refer to Figure 2 . Figure 2This is a flowchart of an integrated space-ground identity authentication method according to an embodiment of the present invention. Figure 2 As shown, the above-mentioned integrated space-ground identity authentication method includes the following steps:

[0126] S1. Chip Identity Validation Steps: During the chip manufacturing stage, a global ID (Global_ID) is validated using a one-time fuse. A chip private key is derived based on a Physically Unclonable Function (PUF), and this chip private key never leaves the chip. At the same time, the Global_ID is configured as a user identifier for the SM9 identifier cryptographic algorithm.

[0127] S2. IPv6 Address Derivation and Binding Steps: Based on the chip's Global_ID and public key, a dynamically verifiable obfuscated address derivation algorithm is used to generate an IPv6 address bound to the chip. A cryptographic binding relationship is established between the chip's Global_ID and the IPv6 address, and this binding relationship is signed using the chip's private key. The derivation algorithm employs a two-way coupling of BeiDou week numbers and the chip's historical state to achieve the unlinkability of address sequences.

[0128] S3. Temporary Identity Assignment Steps: The terminal submits the Global_ID and chip public key to the root trust server through a secure channel. The server assigns a temporary identity identifier (PID) and issues a digital identity credential, which is pre-stored in the chip's secure storage area.

[0129] S4. Authentication Channel Selection Steps: Real-time detection of the ground network status. When the ground network is available, online authentication is performed through the IPv6 ground channel. When the ground network is unavailable and the continuous interruption time reaches a preset threshold, the system automatically switches to the BeiDou short message authentication channel.

[0130] S5. Beidou Short Message Two-Way Authentication Steps: The terminal and the verifier execute a challenge-response signature process via Beidou short message. They can choose to use the traditional signature scheme with PUF derived private key or the SM9 identifier signature scheme. The terminal sends an authentication request carrying the PID and the first random number. The verifier returns the second random number and its own signature. The terminal signs the request in the chip and returns it. The verifier verifies the signature to complete the two-way mutual recognition.

[0131] S6. Credential Injection Steps: When the terminal is in an area without a terrestrial network and needs to inject digital credentials, it receives fragmented credential packets via BeiDou short message service. It then uses a dual hash chain sliding window dynamic verification mechanism to perform out-of-order reassembly, packet loss detection, and integrity verification. After passing the verification, the credential packets are written into the chip security domain.

[0132] S7. Asset Migration and Recovery Steps: When a chip is damaged, the asset is securely migrated from the old chip to the new chip using an encrypted migration authorization certificate.

[0133] Example 1: Beidou two-way authentication for ocean-going cargo ships and remote injection of digital currency into digital wallets

[0134] A Chinese-flagged ocean-going cargo ship, the "Yuanyang," sailed to a sea area in the South Pacific Ocean where there were no ground cellular base station signals or Wi-Fi network coverage. Crew member Zhang needed to complete identity authentication for his digital currency hard wallet and receive a new wallet certificate injected by the bank's backend. The entire process was carried out according to steps S1 to S7 mentioned above.

[0135] S1 Chip Identity Authentication Steps: The maritime handheld terminal device used by crew member Zhang has a built-in integrated space-ground identity authentication system 100. During the manufacturing stage, the Global_ID was permanently fixed as "0x7F3A8E..." through a one-time fuse of the chip hardware trust root unit 110, and the chip private key was dynamically derived based on the PUF module. This private key never leaves the chip. At the same time, the Global_ID is configured as the user identifier ID_device of the SM9 identification cryptographic algorithm.

[0136] S2 IPv6 Address Derivation and Binding Steps: At the factory, the terminal has already generated an IPv6 address A bound to the chip based on an algorithm through the IPv6 address derivation and binding unit 120. t A cryptographic binding relationship between the Global_ID and the IPv6 address was established, and the binding relationship was signed by the chip's private key.

[0137] S3 Temporary Identity Assignment Steps: Before departure, the terminal has completed its initial registration via the terrestrial network. The root trust server assigns it a PID of "PID_YZH_202605" and issues a digital identity credential valid for 30 days, which is pre-stored in the chip's secure storage area.

[0138] S4 authentication channel selection steps: When a cargo ship leaves China's territorial waters and enters the high seas, the terminal detects that the continuous interruption time of the ground network exceeds 30 minutes, reaching the preset threshold, and automatically switches the authentication channel from the ground IPv6 channel to the Beidou short message authentication channel. The switching process is completely transparent to the upper-layer digital currency applications.

[0139] S5 Beidou Short Message Two-Way Authentication Steps: Crew member Zhang initiates a digital currency wallet activation request. The Beidou Short Message Two-Way Authentication Unit 130 executes the two-way authentication process: The terminal sends an authentication request to the bank's backend verification party via Beidou short message, carrying the PID "PID_YZH_202605", the current Beidou positioning information, and the first random number Req_nonce; The bank's backend verification party retrieves the terminal's chip public key from the public mapping directory using the PID, generates the second random number Chal_nonce, signs it with its own private key, and returns it to the terminal along with the verification party's PID and short-term certificate; After verifying the verification party's signature and certificate validity, the terminal uses the PUF-derived private key to sign Chal_nonce, Req_nonce, and the Beidou timestamp within the chip hardware trust root unit 110, and returns it to the verification party; The verification party passes the signature verification, the two-way authentication is completed, and both parties negotiate a session key. The entire process takes 8 seconds through three Beidou short message interactions.

[0140] S6 credential injection steps: After two-way authentication, the bank's backend needs to inject a new digital currency wallet certificate (approximately 4KB in size) into the terminal. Since the capacity of a single BeiDou short message is only 2000 bytes, the system initiates a fragmented transmission mechanism. The bank's backend splits the certificate into 3 fragments, calculates the forward hash chain and the backward hash chain, and sends the first fragment sequentially via BeiDou short messages after embedding a globally unique one-time random number (nonce). The terminal maintains a sliding window buffer. Upon receiving fragments arriving out of order, it verifies the correct order through the two-way hash chain. After detecting no packet loss, it receives all fragments within 50 seconds. After verifying the integrity of the forward and backward hash chains, it verifies the overall digital signature of the certificate. After successful verification, the reconstructed digital currency wallet certificate is written to the chip's security domain.

[0141] S7 Asset Migration and Recovery Steps: Three months later, the maritime handheld terminal was accidentally dropped, resulting in physical damage to the chip hardware trust root unit 110. Crew member Zhang applied for asset migration to the bank's back office through the Beidou short message two-way authentication unit 130. After verifying Zhang's identity, the bank's back office issued an encrypted migration authorization certificate. Zhang's new terminal decrypted the certificate through the chip hardware trust root unit 110 and requested encrypted asset data from the bank, successfully migrating the balance and certificate in the original digital currency wallet to the new terminal.

[0142] One embodiment of the present invention was successfully implemented in a remote ocean environment with no terrestrial network coverage, realizing a complete closed loop of integrated land-ground identity authentication from two-way identity authentication to digital credential injection and asset migration.

[0143] The above-described embodiment of the present invention can be implemented in various hardware, software codes, or combinations thereof. For example, an embodiment of the present invention can also be program code executing the above-described method in a Digital Signal Processor (DSP). The present invention can also relate to various functions executed by a computer processor, digital signal processor, microprocessor, or Field Programmable Gate Array (FPGA). The processor described above can be configured to perform specific tasks according to the present invention, which are accomplished by executing machine-readable software code or firmware code defining the specific methods disclosed in the present invention. The software code or firmware code can be developed into different programming languages ​​and different formats or forms. The software code can also be compiled for different target platforms. However, the different code styles, types, and languages ​​of the software code performing tasks according to the present invention and other types of configuration code do not depart from the spirit and scope of the present invention.

Claims

1. A space-ground integrated identity authentication system based on chip hardware root of trust and BeiDou short message bidirectional authentication, comprising: A chip hardware trust root unit is configured to solidify the Global_ID through a one-time fuse during the chip manufacturing stage and dynamically derive the chip private key based on a physically unclonable function module. The chip private key never leaves the chip and is dynamically restored by hardware each time it is used. An IPv6 address derivation and binding unit is configured to generate an IPv6 address bound to the chip based on the chip's Global_ID and chip public key using a dynamic verifiable obfuscated address derivation algorithm, and establish a cryptographic binding relationship between the chip's Global_ID and the IPv6 address, wherein the dynamic verifiable obfuscated address derivation algorithm satisfies the non-linkability requirement. A Beidou short message two-way authentication unit is configured to execute a challenge-response signing process through Beidou short messages to achieve mutual identity authentication between the terminal and the verifier, wherein each party uses its own private key to sign and verify the challenge of the other party. An end-to-end encrypted communication unit is used to encrypt and transmit communication data identified by an IPv6 address using a derived session key after the two-way authentication is successful. A dual hash chain fragmentation and reassembly unit is used to perform bidirectional verification fragmentation and out-of-order reassembly of encrypted communication data based on forward hash chain and backward hash chain under the condition of limited BeiDou short message length. Among them, the chip hardware trust root unit provides the signature private key required for authentication to the Beidou short message bidirectional authentication unit, and the IPv6 address derivation and binding unit generates an address based on the Beidou week number and the same PUF root key and binds it to the chip hardware identity. The three units together constitute a space-ground integrated closed-loop trust chain that does not rely on ground facilities.

2. The integrated space-ground identity authentication system according to claim 1, characterized in that, The chip hardware trust root unit is also configured as follows: The terminal device ID is used as the SM9 identifier. The key generation center pre-generates the corresponding SM9 encryption private key and signature private key for the terminal, and writes the private key into the chip hardware trust root unit via on-chip fuse or one-time programmable memory. When the terminal powers on and initiates authentication, the chip hardware trust root unit dynamically derives an unclonable temporary root key from the PUF, and uses the temporary root key to decrypt the SM9 private key stored in the chip to obtain a usable SM9 signature private key. The SM9 signature private key is used to sign the BeiDou short message authentication request, and the signature result is sent to the peer or verification server via BeiDou short message. The SM9 private key is always in an encrypted form protected by PUF in static storage. It is only obtained by decryption using a PUF dynamically derived temporary root key during authentication. Throughout the entire process, the SM9 private key is never transmitted or distributed through any secure channel or out-of-band method.

3. The integrated space-ground identity authentication system according to claim 1, characterized in that, In the IPv6 address derivation and binding unit, the dynamically verifiable obfuscated address derivation algorithm is implemented in the following way. In the formula, Trunc is the truncation function to the IPv6 address length, H is the quantum-resistant hash function, ⊕ is the bitwise XOR operation, S is the digital identifier, K is the chip public key hash value, and N is the chip's unique serial number; A t For dynamic IPv6 addresses, A0 is defined as This is used only for internal recursive calculations within the chip and is not publicly available. T t is the number of weeks of the BeiDou, which is obtained by the terminal from the BeiDou satellite time signal in real time, and the verification party can independently obtain the same T t value from the BeiDou satellite signal; For finite field multiplication, defined in GF(2 256 Prime number field, to implement T t With State t-1 Nonlinear confusion; This is a hash of the chip's overall state at the previous moment, enabling a deep binding between the address and the chip's historical state; Wherein, ω is a preset chip-level confusion parameter, and the anti-quantum confusion layer F is implemented ω ; The dynamic verifiable obfuscated address derivation algorithm satisfies: given (S, K, N, ω), the legality of verifiable arbitrary history address A t ; due to the introduction of chip state State t-1 and chip-level obfuscation parameter ω, the address sequence presents strong unidirectionality and chip individual difference, and the history address A t cannot be reversely deduced from the current address A t-1 , and the address sequence of another chip cannot be predicted from the address sequence of one chip, realizing double security guarantee of unlinkability and unclonability.

4. The integrated space-ground identity authentication system according to claim 1, characterized in that, The IPv6 address derivation and binding unit is further configured to, when the terminal initiates registration with the root trust server for the first time or performs IPv6 terrestrial channel authentication for the first time, submit the current IPv6 address generated by its IPv6 address derivation and binding unit and at least one set of trusted fixed IPv6 addresses pre-specified by the terminal user to the root trust server through a secure channel. The set of trusted fixed IPv6 addresses includes the terminal address under the IPv6 prefix of the home gateway, the terminal address under the IPv6 prefix of the enterprise office network, and IPv6 addresses in other trusted network environments manually configured by the user. Before issuing the temporary identity identifier (PID) and digital identity credential, or before the initial authentication is successful, the root trust server enforces at least one of the following verification procedures: a) The root trust server communicates with end users to verify the authenticity and ownership of the trusted fixed IPv6 address set they submit. After verification, the trusted address set is cryptographically bound to the terminal's chip public key, and a trusted address binding certificate is generated in the form of a signature by the root trust server's private key and stored in a public mapping directory or a blockchain distributed ledger. b) The root trust server requires that the terminal's first authentication must be initiated from one of the above trusted fixed IPv6 addresses. If the IPv6 address currently used by the terminal does not belong to any pre-bound and verified trusted address, the root trust server will refuse to issue PID and digital identity credentials and record the abnormal attempt log. c) During the challenge-response process of the initial authentication, in addition to verifying the chip private key signature of the terminal, the root trust server also verifies whether the terminal's current IPv6 address matches any address in the set of trusted fixed IPv6 addresses. If the match fails, a second out-of-band interaction confirmation is triggered, or the authentication process is terminated. The set of trusted fixed IPv6 addresses supports dynamic updates. When an end user needs to add, delete, or modify a trusted address, the update request must be signed using the original valid PID and chip private key, and submitted to the root trust server through the Beidou short message bidirectional authentication unit or the ground security channel. After verifying the signature, the root trust server issues an updated trusted address binding certificate.

5. The integrated space-ground identity authentication system according to claim 1, characterized in that, The two-way authentication process executed by the BeiDou short message two-way authentication unit includes: The first terminal sends an authentication request to the second terminal via BeiDou short message service. The authentication request carries the first terminal's PUF-derived public key and a first random number. After receiving the authentication request, the second terminal generates a second random number, signs the first random number and the second random number using the PUF-derived public key of the first terminal, and returns the PUF-derived public key and the signature result of the second terminal via BeiDou short message. After verifying the signature result, the first terminal generates a session key, encrypts the session key using the PUF-derived public key of the second terminal, and sends it to the second terminal via BeiDou short message. After the second terminal decrypts and obtains the session key, it returns a confirmation message; Once authentication is successful, both parties directly derive session keys for end-to-end encrypted communication without needing to return to any centralized authentication system for secondary verification. The purpose of the authentication is to establish end-to-end encrypted communication credentials between terminals, rather than to obtain access permissions for BeiDou satellite services.

6. The integrated space-ground identity authentication system according to claim 1, characterized in that, When the terminal registers for the first time, the root trust server assigns a PID, and the public mapping directory stores the mapping relationship between the PID and the chip public key. The Global_ID is not publicly disclosed. The PID has a configurable validity period. When the terminal is in a state without a terrestrial network and the PID is about to expire, it initiates an offline update request to the root trust server via Beidou short message, carrying the current PID, chip signature and newly generated public key. After verification, the root trust server returns the new PID and corresponding credentials via Beidou short message.

7. The integrated space-ground identity authentication system according to claim 1, characterized in that: When a chip is damaged and assets need to be migrated, an encrypted migration authorization certificate is issued by a trusted server. The certificate includes the new chip's public key, a list of migration items, and a validity period. After the new chip decrypts the migration authorization certificate using its own private key, it requests encrypted asset data from the root trust server and updates the chip's trust root state after recovery is complete.

8. The integrated space-ground identity authentication system according to any one of claims 1 to 7, characterized in that, The system also includes a unified authentication management and authorization application unit, configured to perform the following operations after the terminal has completed its initial registration and obtained an electronic signature certificate issued by the root trust server: a) The digital identity credentials of the end user, electronic signature information, public key hash value derived from the chip hardware trust root unit, and verifiable statement of the dynamic IPv6 address generated by the IPv6 address derivation and binding unit are encapsulated into a structured data packet according to a predetermined data format. After digitally signing the data packet with the chip private key, a QR code image is generated and stored on the blockchain distributed ledger or public mapping directory for verification parties to scan and read. b) In any scenario requiring identity authentication or business rights confirmation, the user displays the QR code on the terminal. After scanning the code, the verifier obtains the corresponding digital identity certificate and electronic signature information from the blockchain, verifies the validity of the chip signature and the binding relationship between the dynamic IPv6 address and the chip identity. Once the verification is successful, the user is considered to have completed identity authentication and there is no need to execute the challenge-response two-way authentication process again. c) In scenarios where electronic signatures are required, users use their registered electronic signatures to digitally sign or stamp electronic documents. The centralized certificate management and rights confirmation application unit automatically calls the private key derived from the chip hardware trust root unit to sign the document hash value, and attaches the signature along with the current status proof of the dynamic IPv6 address to the document. After receiving the document, the verifier verifies the validity of the electronic signature and the authenticity of the signature through the blockchain. Once the verification is successful, the authentication is completed. d) After the terminal successfully completes its first registration and obtains the electronic signature certificate issued by the root trust server, the certificate forms a permanent cryptographic binding with the Global_ID and PUF root key in the chip hardware trust root unit. Unless the chip is physically damaged or the certificate is explicitly revoked, the verifier can independently complete the verification through the certificate information publicly stored on the blockchain when the user presents the QR code or uses the electronic signature to sign / stamp at any time and place, without having to initiate a real-time online authentication request to the root trust server again. The dynamic IPv6 address is updated in real time by the IPv6 address derivation and binding unit based on the BeiDou week number and the chip's historical status. Each signature or stamping operation is accompanied by proof of the currently valid dynamic IPv6 address.

9. The integrated space-ground identity authentication system according to claim 8, characterized in that, The centralized authentication management and authorization application unit further performs the following operations: configures the dynamic IPv6 address as a dynamic encrypted USB key: e) Combine the private key dynamically derived from the chip hardware trust root unit and the IPv6 address derived from it with the dynamically generated IPv6 address A in real time by the binding unit. t Together, they serve as the two core components of a dynamic encrypted USB key, with the dynamic IPv6 address A... t According to the BeiDou cycle number T t and chip history state t-1 The U-shield changes periodically due to changes in IPv6 address, which is publicly visible, while the internal root key, the PUF-derived private key, remains unchanged and never leaves the chip. f) When a high-security operation is required, the authenticator first obtains the terminal's current dynamic IPv6 address A. t , with A t As a dynamic challenge parameter, the terminal is required to use the chip's private key to test A. t The signature is created by concatenating the hash value of the current operation content. After the terminal completes the signature within the chip's hardware trust root unit, it returns the result. The verifier verifies the signature using the chip's public key, and simultaneously verifies A. t Whether it is consistent with the expected value calculated based on the publicly available chip identity information and the current BeiDou cycle number, thus realizing the dynamic U-shield authentication mode of address as challenge and signature as response; g) Due to dynamic IPv6 address A t It changes irreversibly in a unidirectional direction over time or with the number of operations. Even if an attacker intercepts the signature value of a certain operation and the corresponding A... t It is also impossible to replay the signature at the current moment or on other terminals, because the verifier will check A. t Whether it matches the current BeiDou week number and the chip's historical status; at the same time, the anti-quantum hash function and chip-level confusion parameter ω introduced in the dynamic IPv6 address derivation algorithm enable the dynamic U-shield to resist quantum computing attacks; h) When the terminal is in an area without terrestrial network coverage, the dynamic encryption U-shield function is carried out through the Beidou short message two-way authentication unit, and the terminal transmits its current dynamic IPv6 address A. t The signature of the operation content is encapsulated in a BeiDou short message and sent to the verifier. After receiving the BeiDou short message, the verifier independently obtains the current BeiDou cycle number from the BeiDou satellite signal to calculate the expected A. t The value is used to complete signature verification, thereby achieving dynamic U-shield authentication that is completely independent of the terrestrial network.

10. A ground-space integrated identity authentication method based on the ground-space integrated identity authentication system according to any one of claims 1 to 9, comprising the following steps: S1. During the chip manufacturing stage, the Global_ID is solidified by a one-time fuse, and the chip private key is derived based on a physically non-cloning function. The chip private key never leaves the chip. At the same time, the Global_ID is configured as a user identifier of the SM9 identifier cryptographic algorithm. S2. Based on the chip's Global_ID and public key, an IPv6 address bound to the chip is generated through a dynamic verifiable obfuscated address derivation algorithm, establishing a cryptographic binding relationship between the chip's Global_ID and the IPv6 address, and the binding relationship is signed by the chip's private key; the dynamic verifiable obfuscated address derivation algorithm adopts a two-way coupling of BeiDou week number and chip historical state to achieve the unlinkability of address sequences; S3. The terminal submits the Global_ID and chip public key to the root trust server through a secure channel. The root trust server assigns the PID and issues digital identity credentials, which are pre-stored in the chip's secure storage area. S4. Real-time detection of the ground network status. When the ground network is available, online authentication is performed through the IPv6 ground channel. When the ground network is unavailable and the continuous interruption time reaches a preset threshold, it automatically switches to the BeiDou short message authentication channel. S5. The terminal and the verifier execute the challenge-response signature process via BeiDou short message. They can choose to use the traditional signature scheme with PUF derived private key or the SM9 identifier signature scheme. The terminal sends an authentication request carrying the PID and the first random number. The verifier returns the second random number and its own signature. The terminal signs the request in the chip and returns it. The verifier verifies the signature and completes the two-way mutual recognition. S6. When the terminal is in an area without a terrestrial network and needs to inject digital credentials, it receives the fragmented credential packets through Beidou short messages, and uses a dual hash chain sliding window dynamic verification mechanism to perform out-of-order reassembly, packet loss detection and integrity verification. After passing the verification, the credential packets are written into the chip security domain. S7. When a chip is damaged, the asset is securely migrated from the old chip to the new chip using encrypted migration authorization credentials.