Global communication security interaction method, device, equipment, medium and program product
Patent Information
- Application Number
- CN202611146238.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-30
- Publication Date
- 2026-09-15
Smart Images

Figure CN122764516A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication security technology, and in particular to a method, apparatus, device, medium and program product for secure communication interaction across the entire domain. Background Technology
[0002] Rugged equipment is widely used in complex environments such as emergency rescue, public safety, energy inspection, mining operations, rail transportation, petrochemicals, and defense communications. During operation, it typically requires continuous communication across various heterogeneous networks, including satellite communications, public terrestrial networks, private networks, ad hoc networks, and shortwave, to ensure stable and secure transmission of on-site data, voice, and control commands. Because rugged equipment operates under complex conditions such as high temperature, low temperature, high humidity, strong vibration, and electromagnetic interference, and must also meet special requirements such as explosion-proof, dustproof, and waterproof capabilities, it demands not only strong cross-domain switching capabilities for communication links but also reliable device identity, secure keys, and the ability to dynamically configure communication resources according to different network environments. This ensures the reliability, security, and continuity of data transmission throughout the entire communication process.
[0003] Existing rugged devices typically employ pre-installed device certificates, fixed identity keys, or security chips for device authentication. After successful authentication, a communication session key is established, and network switching or link scheduling is achieved by combining different network communication protocols. Some solutions also utilize frequency hopping communication, authentication encryption, and dynamic routing technologies to enhance communication security. However, in most existing solutions, device authentication, key generation, network resource configuration, and cross-domain communication scheduling are usually implemented as independent functional modules. The key generated after device authentication is generally used directly for subsequent communication, while network switching and resource scheduling are mainly handled based on network quality, link status, or preset policies, lacking a collaborative mechanism between device physical identity, environmental status, and cross-domain resource configuration. Summary of the Invention
[0004] This application provides a secure interaction method, apparatus, device, medium, and program product for global communication to solve the problem of the lack of a unified data association link between device authentication, key establishment, and cross-domain communication resource scheduling.
[0005] In a first aspect, embodiments of this application provide a global communication secure interaction method, including: Extract the registered PUF response features of the tri-proof device, and perform association encoding based on the registered PUF response features and the received challenge association features to obtain a fused feature set; When the control center completes the identity authentication of the tri-proof device, it performs environmental disturbance compensation and fuzzy extraction based on the collected environmental state parameters and extracted session PUF response features to obtain stable response data, and performs key derivation processing based on the stable response data to obtain the session master key and locking credential. Two-way locking verification is performed based on the session master key and the locking credential, and security configuration processing is performed based on the session master key and preset global network information to obtain multi-domain mapping data and frequency hopping configuration data. Based on the multi-domain mapping data and the frequency hopping configuration data, cross-domain resource scheduling and secure interaction are performed on the communication data to be sent.
[0006] In an optional implementation, the step of extracting the registered PUF response features of the rugged device, and performing association encoding based on the registered PUF response features and the received challenge association features to obtain a fused feature set includes: The tri-proof device divides the integrated ring oscillator array into a preset number of oscillator pairs according to a preset array order, and compares the oscillation frequencies between the oscillators in the oscillator pairs to obtain the registered PUF response characteristics. The tri-proof device receives the challenge-related features issued by the preset control center, and performs a bitwise XOR operation between the registered PUF response features and the challenge-related features to obtain a fused feature set.
[0007] In an optional implementation, after obtaining the registered PUF response characteristics, the method further includes: The tri-proof device concatenates the registered PUF response feature with the fused feature set into a combined data block, and authenticates and encrypts the combined data block using a preset long-term key to obtain an encrypted data block and an authentication tag; The control center generates a verification tag based on the long-term key, preset initial parameters, and the encrypted data block; When the verification tag matches the authentication tag, the control center decrypts the encrypted data block using the long-term key to obtain the registered PUF response feature; The control center counts the number of bits that differ between the registered PUF response features and the preset baseline PUF response features to obtain the Hamming distance; When the Hamming distance is less than a preset fault tolerance threshold, the control center completes the authentication of the rugged device.
[0008] In an optional implementation, the step of performing environmental disturbance compensation and fuzzy extraction based on the collected environmental state parameters and extracted session PUF response features to obtain stable response data includes: The control center calculates the environmental disturbance offset data between the preset environmental reference parameters and the collected environmental state parameters, and performs norm calculation on the environmental disturbance offset data to obtain the environmental disturbance amplitude value. The control center determines the disturbance level of the current environment based on the disturbance amplitude value, and selects the corresponding level of error correction code parameters from the preset error correction code parameter table according to the disturbance level to obtain the environmental compensation parameters. The control center performs error correction coding and fuzzy extraction processing on the fused feature set according to the environmental compensation parameters, generates fuzzy extraction auxiliary data, and sends the fuzzy extraction auxiliary data and the environmental compensation parameters to the tri-proof device. The tri-proof device performs a bitwise XOR operation on the extracted session PUF response features and the challenge association features to obtain the current fused feature set, and locates and corrects the error bits of the current fused feature set according to the fuzzy extraction auxiliary data to obtain the number of errors of the error bits and optimize the fused feature set; When the number of errors is less than or equal to the number of correctable error bits in the environmental compensation parameters, the tri-proof device performs an XOR operation on the optimized fusion feature set and the challenge-related features to obtain stable response data.
[0009] In an optional implementation, the step of performing two-way locking verification based on the session master key and the locking credential, and performing security configuration processing based on the session master key and preset global network information to obtain multi-domain mapping data and frequency hopping configuration data includes: The control center performs key derivation processing based on preset baseline PUF response data and the challenge association features to obtain the center key; The control center calculates a verification credential based on the central key and the challenge association features, and compares the verification credential with the locking credential. When the verification credential matches the locking credential, the control center calculates the center locking credential based on the center key and the current fusion feature set, and performs authentication and encryption on the preset global network information based on the center key to generate an encryption mapping table, so as to send the center locking credential and the encryption mapping table to the rugged device. The tri-proof device decrypts the encrypted mapping table using the session master key to obtain multi-domain mapping data, and performs security configuration processing based on the central locking credential and the multi-domain mapping data to generate frequency hopping configuration data.
[0010] In an optional implementation, the step of performing cross-domain resource scheduling and secure interaction on the communication data to be transmitted based on the multi-domain mapping data and the frequency hopping configuration data includes: The tri-proof device determines the network domain code and the corresponding modulation order from the multi-domain mapping data based on the current positioning information, extracts the corresponding frequency hopping seed column from the frequency hopping configuration data based on the network domain code, and selects the current frequency hopping seed from the frequency hopping seed column based on the current frame number and time slot number generated in real time by the counter in the tri-proof device, so as to calculate the current frequency point index based on the current frequency hopping seed, the current frame number and the time slot number; The tri-proof device generates a time slot allocation table based on the session master key and the network domain code, determines the transmittable time slots according to the time slot allocation flags in the time slot allocation table, and performs block processing on the communication data to be transmitted according to the modulation order to generate a data symbol stream; The tri-proof device performs time allocation and frequency mapping on the generated data symbol stream based on the frequency domain resource information in the multi-domain mapping data and the current frequency point index, and generates a resource mapping table; The tri-proof device authenticates and encrypts the data symbol stream according to the session master key, generates a ciphertext symbol stream, and obtains the actual carrier frequency from the multi-domain mapping data according to the frequency point index in the resource mapping table, so as to perform a linear transformation on each ciphertext symbol value in the ciphertext symbol stream according to the actual carrier frequency to obtain the baseband signal. The tri-proof device splices the baseband signals into an encrypted frequency-hopping baseband signal stream according to the time sequence and the transmittable time slots, and sends the encrypted frequency-hopping baseband signal stream to the control center.
[0011] Secondly, embodiments of this application provide a global communication secure interaction device, including: The registration encoding module is used to extract the registration PUF response features of the rugged device, and perform association encoding based on the registration PUF response features and the received challenge association features to obtain a fused feature set; The session extraction module is used to perform environmental disturbance compensation and fuzzy extraction based on the collected environmental state parameters and extracted session PUF response features when the control center completes the identity authentication of the tri-proof device, so as to obtain stable response data. The session encryption module is used to perform key derivation processing based on the stable response data to obtain the session master key and locking credential. The resource configuration module is used to perform two-way locking verification based on the session master key and the locking credential, and to perform security configuration processing based on the session master key and preset global network information to obtain multi-domain mapping data and frequency hopping configuration data. The cross-domain interaction module is used to perform cross-domain resource scheduling and secure interaction on the communication data to be sent based on the multi-domain mapping data and the frequency hopping configuration data.
[0012] Thirdly, embodiments of this application provide a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the above-described global communication secure interaction method.
[0013] Fourthly, embodiments of this application provide a readable storage medium storing a computer program that, when executed by a processor, implements the steps of the above-described global communication secure interaction method.
[0014] Fifthly, embodiments of this application provide a computer program product, which includes a computer program that, when executed by a processor, implements the steps of the above-described global communication secure interaction method.
[0015] In one of the solutions provided by the aforementioned secure interaction methods, devices, equipment, media, and programs for global communication, a trusted identity foundation is established using the device's own unclonable physical fingerprint. After identity verification, the device's real-time environmental state is coordinated with the physical fingerprint recovery process. This allows key generation to adapt to environmental fluctuations caused by changes in temperature, air pressure, humidity, and vibration. Two-way trusted verification is completed while ensuring key consistency. The generated session key is then used to uniformly protect and dynamically configure global network resources. Finally, cross-domain communication scheduling and secure transmission are achieved by combining multi-domain network resources. This application constructs physical identity authentication, environmentally adaptive key recovery, two-way trusted verification, and cross-domain communication resource scheduling into a continuous data processing link. This ensures that the session key established by both communicating parties originates from the unique physical characteristics of the device and remains stable despite changes in the actual environment. Furthermore, subsequent network resource configuration, frequency hopping parameter generation, and communication data transmission are all based on the verified trusted key, thereby avoiding security risks caused by device impersonation, environmental disturbances, or communication resource leakage. This achieves a synergistic improvement in identity trustworthiness, key stability, and cross-domain communication security during global communication. Attached Figure Description
[0016] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0017] Figure 1 This is a schematic diagram of the operating environment of the global communication secure interaction method in this embodiment of the invention; Figure 2 This is a flowchart illustrating the secure interaction method for global communication in an embodiment of the present invention; Figure 3 yes Figure 1 Functional module diagram of the all-domain communication security interactive device integrated into the China NBC (Nuclear, Biological, Chemical) defense communication system; Figure 4 This is a schematic diagram of the structure of the computer device in an embodiment of the present invention. Detailed Implementation
[0018] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0019] It should be understood that, when used in this specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components, and / or collections thereof. It should also be understood that, as used in this specification and the appended claims, the term "and / or" refers to any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.
[0020] Furthermore, in the description of this invention and the appended claims, the terms "first," "second," "third," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.
[0021] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of the invention include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.
[0022] It should be understood that the sequence number of each step in the following embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0023] To illustrate the technical solution of the present invention, specific embodiments are described below.
[0024] Rugged equipment is widely used in complex environments such as emergency rescue, public safety, energy inspection, mining operations, rail transportation, petrochemicals, and defense communications. During operation, it typically requires continuous communication across various heterogeneous networks, including satellite communications, public terrestrial networks, private networks, ad hoc networks, and shortwave, to ensure stable and secure transmission of on-site data, voice, and control commands. Because rugged equipment operates under complex conditions such as high temperature, low temperature, high humidity, strong vibration, and electromagnetic interference, and must also meet special requirements such as explosion-proof, dustproof, and waterproof capabilities, it demands not only strong cross-domain switching capabilities for communication links but also reliable device identity, secure keys, and the ability to dynamically configure communication resources according to different network environments. This ensures the reliability, security, and continuity of data transmission throughout the entire communication process.
[0025] Existing rugged devices typically employ pre-installed device certificates, fixed identity keys, or security chips for device authentication. After successful authentication, a communication session key is established, and network switching or link scheduling is achieved by combining different network communication protocols. Some solutions also utilize frequency hopping communication, authentication encryption, and dynamic routing technologies to enhance communication security. However, in most existing solutions, device authentication, key generation, network resource configuration, and cross-domain communication scheduling are usually implemented as independent functional modules. The key generated after device authentication is generally used directly for subsequent communication, while network switching and resource scheduling are mainly handled based on network quality, link status, or preset policies, lacking a collaborative mechanism between device physical identity, environmental status, and cross-domain resource configuration.
[0026] The most significant shortcoming of existing tri-proof devices' all-domain communication methods lies in the lack of a unified data link between device authentication, key establishment, and cross-domain communication resource scheduling. When changes occur in the device's operating environment, such as temperature, humidity, vibration, or electromagnetic interference, the stability of physical identity characteristics can be easily affected. Furthermore, subsequent key establishment and communication resource configuration still employ independent processing methods, making it impossible to coordinate the adjustment of key recovery and cross-domain communication parameters based on the actual environmental conditions of the device. This results in a lack of a continuous and consistent security mechanism between device identity credibility, session key stability, and cross-domain communication resource configuration, which can easily lead to decreased communication reliability and insufficient all-domain communication security protection capabilities in complex environments.
[0027] To address the aforementioned issues, this application proposes a secure interaction method, apparatus, device, medium, and program product for global communication. By utilizing the device's unique, non-clonable physical fingerprint to establish a trusted identity foundation, and after identity verification, the real-time environmental state of the device is collaboratively processed with the physical fingerprint recovery process. This allows key generation to adapt to fluctuations caused by environmental changes such as temperature, air pressure, humidity, and vibration. Two-way trusted verification is completed while ensuring key consistency. The generated session key is then used to uniformly protect and dynamically configure global network resources. Finally, cross-domain communication scheduling and secure transmission are achieved by combining multi-domain network resources. This application constructs physical identity authentication, environmentally adaptive key recovery, two-way trusted verification, and cross-domain communication resource scheduling into a continuous data processing link. This ensures that the session key established by both communicating parties originates from the unique physical characteristics of the device and remains stable despite changes in the actual environment. Furthermore, subsequent network resource configuration, frequency hopping parameter generation, and communication data transmission are all based on the verified trusted key, thereby avoiding security risks caused by device impersonation, environmental disturbances, or communication resource leakage. This achieves a synergistic improvement in identity trustworthiness, key stability, and cross-domain communication security during global communication.
[0028] The global communication secure interaction method provided in this embodiment of the invention can be applied to, for example... Figure 1The operating environment shown is a NBC (Nuclear, Biological, Chemical) protection communication system formed by connecting NBC protection equipment and a control center via a network. This network encompasses various heterogeneous subnets, including satellite links, ground base stations, shortwave communication, microwave line-of-sight communication, underwater acoustics, UAV relay, emergency self-organizing networks, and backup signaling, forming an integrated air-space-ground-sea all-domain coverage architecture. The NBC protection equipment, deployed as a frontline communication terminal in harsh environments such as strong electromagnetic interference, complex vibrations, high humidity and dust, and flammable and explosive materials, integrates a Physically Unclonable Function (PUF) module composed of a ring oscillator array to extract inherent random physical differences during the equipment's chip manufacturing process. The device uses a unique fingerprint as its identifier and is equipped with environmental sensors for temperature, air pressure, humidity, triaxial acceleration, and electromagnetic field strength, as well as explosion-proof safety monitoring modules for abnormal current monitoring and contact resistance monitoring. It continuously collects physical and explosion-proof parameters of the environment in which the device is located. The device receives challenge-related features from the control center via the network and transmits back an identity credential encrypted with associated encoding and a long-term key authentication. Cross-domain switching is triggered between network domains based on real-time link quality. The control center, as the core management node deployed in the secure area, is configured with a database storing the baseline PUF response vectors of each device and a true random number generator. The control center comprises a device assembly module, a challenge correlation feature generation module, an environmental disturbance compensation calculation module, a fuzzy extraction auxiliary data generation module, a key derivation and two-way locking verification module, and a full-domain network topology information storage and management module. Through this network, the control center sends challenge correlation features, environmental compensation parameters, fuzzy extraction auxiliary data, and an encrypted multi-domain topology mapping table to the rugged device. It also compares and verifies the identity authentication data reported by the rugged device and independently derives the session master key, thereby establishing a shared session master key with the rugged device and completing two-way identity mutual recognition. Two-way locking verification is completed between the rugged device and the control center through this network. After the security configuration is issued, the tri-proof device constructs a multi-domain frequency hopping seed matrix and a dynamic time slot allocation table based on the session master key and the multi-domain topology mapping table. It performs multi-level encryption and chirped spread spectrum modulation on the communication data to be transmitted, and sends the encrypted frequency hopping baseband signal stream to the control center through the network. At the same time, it continuously receives feedback information from the control center, including signal-to-noise ratio, bit error rate, synchronization offset, packet loss rate, and abnormal frequency point occupancy count, so as to dynamically adjust the frequency hopping configuration data. In this way, it completes a secure interaction integrating trusted identity authentication, anti-interference frequency hopping transmission, and explosion-proof safety monitoring in the air-space-ground-sea all-domain communication environment formed by the network.
[0029] In one embodiment, such as Figure 2 As shown, a secure interaction method for global communication is provided, which is then applied to... Figure 1 Taking the runtime environment of [the system] as an example, the following steps are included: Step S1: Extract the registered PUF response features of the tri-proof device, and perform association encoding based on the registered PUF response features and the received challenge association features to obtain a fused feature set.
[0030] First, a dedicated security chip inside the rugged device extracts the device's physical unclonable characteristics. This chip contains an array of an even number of identical ring oscillators. Each ring oscillator is connected in series with an odd number of inverters to form a closed loop. When a supply voltage is applied to this loop, a continuously oscillating electrical signal is generated within it. The oscillation frequency is determined by the propagation delay time of the inverters. Due to random physical fluctuations in semiconductor manufacturing processes such as photolithography, doping, and etching, the actual propagation delay time of each inverter has a small but unique random difference. These differences cause each ring oscillator to generate its own unique oscillation frequency, which remains stable throughout the device's entire lifespan. This inherent physical characteristic forms the basis for the device's unclonable identity. The tri-proof device divides the integrated ring oscillator array into a preset number of oscillator pairs according to a preset array sequence. In this embodiment, the preset number is 128 pairs. The division method is to pair the ring oscillators sequentially according to their serial numbers, that is, the first pair is formed by the first number and the second number, the third pair is formed by the fourth number, and so on until the 255th and the 256th number form the 128th pair. For each pair of ring oscillators, the rugged device simultaneously connects the output signals of both oscillators to the two inputs of a high-speed comparator. In each measurement cycle, the comparator simultaneously reads the oscillation signals of both oscillators and compares their frequency magnitudes. If the oscillation frequency of the first oscillator is greater than that of the second oscillator, the comparator outputs a logic level "1"; if the oscillation frequency of the first oscillator is less than that of the second oscillator, the comparator outputs a logic level "0". This comparison mechanism is designed because the two oscillators are located on the same chip substrate, and fluctuations in the supply voltage and changes in ambient temperature affect both oscillators in the same direction and with approximately equal amplitude. Therefore, the frequency difference between the two oscillators is far less sensitive to environmental changes than the absolute frequency value of a single oscillator, thus ensuring that the logic level output by the comparator remains stable under environmental changes. To eliminate metastable outputs that may occur under boundary conditions, the rugged device performs three independent comparison measurements on each pair of oscillators and takes the value that appears at least twice out of the three measurements as the final response bit for that pair. This majority voting principle effectively eliminates occasional erroneous outputs caused by transient interference. After performing the above comparison operation on all 128 oscillator pairs in sequence, the tri-proof device obtains a 128-bit original PUF response vector. Each bit in the vector takes the value of 0 or 1. This binary sequence is the original PUF response feature of the device.During the device registration phase, the rugged device securely stores the original 128-bit PUF response vector as the device's baseline fingerprint information in the control center's database. This is known as the registered PUF response feature. Essentially, the registered PUF response feature is a 128-bit binary vector, each bit of which is determined by the comparison of the frequencies of the two ring oscillators in the corresponding oscillator pair. This feature reflects the inherent, non-clonable random physical differences in the device's chip manufacturing process and remains stable throughout the device's lifecycle. Its function is to serve as a unique identifier for the device's physical identity, providing an identity anchor for all subsequent secure operations.
[0031] After extracting and storing the registered PUF response features, the rugged device first sends an access request message to the control center each time it prepares to access the communication network. Upon receiving the access request, the control center generates a 128-bit random number sequence from its own true random number generator as a challenge-related feature and sends it to the rugged device through the established secure signaling channel. This challenge-related feature is designed as a dynamic factor that changes randomly each time it is authenticated, ensuring that the data returned by the device is different each time it is authenticated, thus effectively resisting replay attacks. After receiving the challenge-related feature from the control center, the rugged device performs a bitwise XOR operation with its extracted registered PUF response features. That is, it performs an XOR operation on each pair of bits in the same position of the two 128-bit vectors. The truth table rule for the XOR operation is that the output is 0 when the two input bits are the same and 1 when the two input bits are different. After this operation, a brand new 128-bit vector is obtained, which is the fused feature set. The challenge-related feature is not directly fed into the circuit input of the ring oscillator array as an excitation signal. Instead, it is combined with the output response of the PUF circuit at the encoding level as a mathematical correlation factor. This design is because each time the control center sends a different challenge-related feature, the fused feature set will exhibit a different numerical distribution. Even if an attacker intercepts the fused feature set in a current communication, they cannot reuse it in subsequent communications because the control center will generate a completely new challenge-related feature for the next authentication. Furthermore, the fused feature set is the result of mixing the challenge-related feature with the PUF response; attackers cannot separate the original PUF response value from the fused feature set, thus effectively protecting the confidentiality of the device's physical fingerprint. In the bitwise XOR operation described above, both the registered PUF response feature and the challenge-related feature have the same 128-bit length, and the output fused feature set also maintains a 128-bit length. Moreover, this operation is reversible; that is, the control center, knowing the challenge-related feature, can recover the original PUF response value from the fused feature set using the same XOR operation.
[0032] After obtaining the registered PUF response feature and the fused feature set, the rugged device concatenates these two vectors into a combined data block. Specifically, 128 bits of the registered PUF response feature are shifted high to the first half of the combined data block, and 128 bits of the fused feature set are shifted low to the second half, forming a 256-bit combined data block. This binds the device's original identity information and the derived information after challenge-associated encoding into a unified whole, facilitating subsequent unified encrypted transmission. The rugged device then uses a factory-preset long-term key to perform authentication and encryption processing on this combined data block. This long-term key is a 256-bit AES key. Each device has a unique long-term key, which is uniformly distributed by the control center at the time of device manufacture and securely written into the device's secure storage area. The authentication encryption algorithm adopts the AES-256-GCM mode. This mode generates an authentication tag using hash operations on the Galois field while performing AES encryption. This authentication tag can be used to detect whether the ciphertext has been tampered with during transmission. Specifically, the rugged device first generates a 96-bit random number as an initial vector. This initial vector, along with the long-term key and the combined data block, is input into the AES-256-GCM encryption algorithm. The algorithm outputs two results: an encrypted data block and an authentication tag. The encrypted data block is the ciphertext form of the combined data block, and the authentication tag is an integrity check value calculated based on the content of the encrypted data block and the long-term key. The rugged device concatenates the encrypted data block, the authentication tag, and the initial vector used for encryption into a transmission data packet, which is sent to the control center via a secure backhaul channel. This secure backhaul channel refers to a secure signaling channel pre-established using the long-term key. This channel itself only provides basic confidential transmission functions, while the AES-256-GCM mode further provides triple security protection at the application layer: data confidentiality protection, integrity verification, and source authenticity authentication.
[0033] After receiving the data packet from the rugged device, the control center first separates it into three components: an encrypted data block, an authentication tag, and an initialization vector (IPV). Then, using the device's corresponding long-term key and the received IPV, the control center decrypts the encrypted data block and verifies the authentication tag. This process simultaneously performs two operations: first, using the AES-256-GCM decryption algorithm to restore the encrypted data block to plaintext and obtain a combined data block; second, using Galois domain hashing to recalculate the integrity check value of the decrypted data and comparing it with the received authentication tag. When the integrity check value calculated by the control center completely matches the received authentication tag, it indicates that the encrypted data block has not been tampered with during transmission and was indeed sent by the rugged device holding the correct long-term key. At this point, the control center accepts the decryption result and extracts the registered PUF response feature and fused feature set from the combined data block. If the integrity check value does not match the authentication tag, the control center discards the data packet and records an alarm log, without further processing. This verification mechanism is designed to prevent attackers from tampering with authentication data or forging device identity through man-in-the-middle attacks.
[0034] After successfully decrypting and obtaining the registered PUF response feature, the control center retrieves the baseline PUF response vector stored during the device's factory registration phase from its own database. It then compares the received registered PUF response feature with this baseline PUF response vector bit by bit, counting the number of bits that differ in value at the same position. This count is the Hamming distance. The Hamming distance is calculated as follows: for two vectors, each 128 bits long, each pair of corresponding bits is checked. If the two bits differ, the count is incremented by 1; if the two bits are the same, the count remains unchanged. This count is obtained after traversing all 128 bits. The Hamming distance ranges from 0 to 128, where 0 indicates that the two vectors are identical, and 128 indicates that the two vectors are completely opposite. It should be understood that when the PUF response is repeatedly collected on the same rugged device, the frequency relationship of a very small number of oscillator pairs may temporarily flip due to physical factors such as ambient temperature, power supply voltage, and vibration. This results in a small bit difference between the two collection results, but the number of differences is usually much less than 128 bits. Therefore, by setting a fault tolerance threshold and judging whether the Hamming distance is less than the threshold, minor deviations caused by environmental factors can be tolerated without affecting the authentication result. The control center compares the calculated Hamming distance with the preset fault tolerance threshold. In the specific implementation, this fault tolerance threshold is set to 25, which is 20% of 128 bits, indicating that a maximum of 25 bits are allowed to flip due to environmental disturbances. When the Hamming distance is less than the fault tolerance threshold, the control center determines that the rugged device has passed the authentication, indicating that the device does indeed possess a physical fingerprint consistent with the registration benchmark, and that the device is a legitimate device and not a counterfeit. For example, a rugged device stores a baseline PUF response vector of "10101100…" during factory registration. When the device is reconnected in a high-temperature and high-humidity environment, the frequency of some ring oscillators shifts due to temperature changes, and the re-acquired and transmitted registration PUF response becomes "10101000…". The two differ by only 2 bits out of the total 128 bits, resulting in a Hamming distance of 2, which is much less than the fault tolerance threshold of 25. Therefore, the control center determines that the device has passed authentication. Conversely, if an attacker attempts to connect using a counterfeit device, the bit difference between the counterfeit device's PUF response and the baseline PUF response of the legitimate device is usually tens or even hundreds of bits, with a Hamming distance much greater than the fault tolerance threshold. Therefore, it is judged as an illegal device. After successful authentication, the control center saves the challenge-related features used in this authentication and the fusion feature set obtained by decryption as input data for subsequent fuzzy extraction processing and session key establishment. Then the entire method enters the environmental disturbance compensation and fuzzy extraction stage. The reason for this saving operation is that the subsequent steps need to use the challenge-related features and fusion feature set to calculate environmental compensation parameters, generate fuzzy extraction auxiliary data, and derive the session master key, forming a data chain from device authentication to secure communication establishment.
[0035] Step S2: When the control center completes the identity authentication of the tri-proof device, it performs environmental disturbance compensation and fuzzy extraction based on the collected environmental state parameters and extracted session PUF response features to obtain stable response data, and performs key derivation processing based on the stable response data to obtain the session master key and locking credential.
[0036] It should be understood that the environmental state parameters are derived from the environmental and explosion-proof state vector collected by the NBC (Nuclear, Biological, and Chemical) protection equipment. This environmental and explosion-proof state vector is collected by various sensors integrated within the NBC protection equipment. Specifically, it includes the temperature value measured by the thermocouple temperature sensor attached to the main circuit board, the air pressure value measured by the air pressure sensor installed inside the sealed housing, the relative humidity value measured by the humidity sensor installed inside the sealed cavity, the vibration intensity values in the X, Y, and Z axes measured by the triaxial MEMS accelerometer fixed to the main circuit board, the electromagnetic field intensity value measured by the electromagnetic field detection unit located near the radio frequency module, the number of abnormal current pulses accumulated by the abnormal current monitoring unit connected to the battery management system, and the contact resistance flag bit output by the contact resistance monitoring unit located at each connection interface. The control center extracts environmental parameters in seven dimensions—temperature, air pressure, humidity, triaxial vibration, and electromagnetic field intensity—from this environmental and explosion-proof state vector to construct the environmental state parameters. These environmental state parameters are the data source used by the control center when performing environmental disturbance compensation based on the collected environmental state parameters. The control center retrieves the initial environmental baseline parameters recorded during the equipment's factory registration phase from the database. These baseline parameters include the equipment's internal temperature, air pressure, humidity, triaxial vibration baseline values, and electromagnetic field strength baseline values at the time of registration, reflecting the standard environmental conditions at the time of registration. The control center calculates the differences between the environmental state parameters and the corresponding dimensions of the environmental baseline parameters one by one. Specifically, it subtracts the baseline temperature value from the current temperature value to obtain the temperature difference, subtracts the baseline air pressure value from the current air pressure value to obtain the air pressure difference, subtracts the baseline humidity value from the current humidity value to obtain the humidity difference, subtracts the baseline vibration value from the current vibration value of each axis to obtain the vibration difference of the three axes, and subtracts the baseline electromagnetic field strength value from the current electromagnetic field strength value to obtain the electromagnetic field strength difference. All the differences in the seven dimensions are combined into a seven-dimensional environmental disturbance offset data. Each component of this data represents the amount and direction of change of the environmental parameter in that dimension relative to the registration baseline conditions. This environmental disturbance offset data includes, but is not limited to, temperature difference, air pressure difference, humidity difference, vibration difference, and electromagnetic field strength difference. The control center performs norm calculation on the environmental disturbance offset data, which involves squaring each component of the environmental disturbance offset data, summing them up, and then taking the square root of the sum to obtain a scalar value as the environmental disturbance amplitude value. This amplitude value comprehensively reflects the degree to which the seven-dimensional environmental parameters deviate from the baseline conditions. Compared with relying on only a single temperature or humidity index, the multi-dimensional comprehensive assessment can more accurately reflect the total degree of environmental influence on the PUF response.
[0037] The control center compares the environmental disturbance amplitude with three preset disturbance level thresholds. The specific values of these three thresholds are determined based on a large amount of measured data, corresponding to four levels: low disturbance environment, medium disturbance environment, high disturbance environment, and extremely high disturbance environment. For example, when a 3D-proof device is connected in a normal temperature, humidity, and vibration-free laboratory environment, its current temperature differs from the reference temperature by less than 1 degree Celsius, the humidity difference is less than 2%, and the vibration value is close to zero. The calculated norm amplitude value is less than the low threshold, and the control center classifies the environment as low disturbance level. However, when the same device is connected in a high-temperature environment in a desert area, the temperature difference may reach more than 15 degrees Celsius, the humidity difference may exceed 10%, and there may be continuous vibration. The norm amplitude value may exceed the high threshold, and the control center classifies the environment as extremely high disturbance level. The control center selects the corresponding BCH error correction code parameter set from the preset error correction code parameter table based on the determined disturbance level. This parameter set contains three key values: total codeword length, information bit length, and number of correctable error bits. The total codeword length and information bit length together determine the redundancy of the error correction code, and the number of correctable error bits represents the maximum number of error bits that the error correction code can correct. The error correction code parameter table is designed according to the principle that the higher the perturbation level, the stronger the error correction capability. That is, a higher perturbation level corresponds to a larger number of correctable error bits, but the total codeword length also increases accordingly to accommodate more check bits. The specific parameter mapping relationship is as follows: low perturbation level uses a BCH code with a total length of 127 bits, an information bit length of 113 bits, and the ability to correct 2-bit errors; medium perturbation level uses a BCH code with a total length of 127 bits, an information bit length of 106 bits, and the ability to correct 3-bit errors; high perturbation level uses a BCH code with a total length of 255 bits, an information bit length of 207 bits, and the ability to correct 6-bit errors; and extremely high perturbation level uses a BCH code with a total length of 255 bits, an information bit length of 191 bits, and the ability to correct 8-bit errors. The control center uses the selected error correction code parameter set as an environmental compensation parameter. This parameter determines the strength and redundancy of the error correction code in the subsequent fuzzy extraction process, serving as a bridge between the degree of environmental perturbation and the error correction capability of fuzzy extraction.
[0038] The control center uses the fused feature set received and saved in step S1 as input material for the fuzzy extractor. This fused feature set is the result of a bitwise XOR operation between the registered PUF response vector and the challenge association vector. The encoding process of the fuzzy extractor is as follows: Based on the total length and information bit length determined in the environmental compensation parameters, the control center divides the fused feature set into blocks according to the information bit length. Since the total length of the fused feature set is 128 bits, and the information bit lengths corresponding to different disturbance levels are different, when the information bit length is greater than or equal to 128, the entire fused feature set is directly treated as an information block and zeros are padded to the end to the information bit length. When the information bit length is less than 128, the fused feature set is divided into multiple information blocks for separate processing. For each information block, the control center uses the selected BCH code encoding algorithm to map it into a codeword of a total length. The first part of the codeword is the original information bits, and the part after the total length minus the information bit length is the redundancy check bit calculated according to the BCH code generator polynomial. This redundancy check bit contains all the auxiliary information required for subsequent error correction decoding. The control center concatenates all codewords sequentially to obtain fuzzy extraction auxiliary data. This auxiliary data itself does not contain secret information that can directly recover the PUF response; instead, it records auxiliary verification information required for subsequent error correction and recovery. Even if an attacker intercepts this auxiliary data during transmission, they cannot recover any secret material related to the PUF response from it alone, because the auxiliary data only contains redundant verification information and not the original information bits themselves. The control center encrypts the fuzzy extraction auxiliary data along with environmental compensation parameters using a long-term key before sending it to the rugged device. This encryption is designed to ensure the integrity and confidentiality of the auxiliary data and parameters during transmission, preventing attackers from tampering with the error correction parameters and causing the device to fail to recover.
[0039] After receiving the fuzzy extraction auxiliary data and environmental compensation parameters from the control center, the rugged device uses a long-term key to decrypt and obtain plaintext data. It then initiates a re-acquisition process for the current PUF response. This re-acquisition process is identical to the one used during registration; all 128 ring oscillators within the device are compared using the same pairing rules and comparison methods to obtain a 128-bit PUF response vector for the current moment. This "session PUF response feature" is the re-acquisitioned PUF response vector for the current moment, defined as the extracted session PUF response feature in step S2. It should be noted that the environmental conditions of the rugged device may have changed significantly since the registration phase. For example, factors such as increased temperature, increased vibration, or power supply voltage fluctuations may cause a temporary reversal in the frequency relationship of some ring oscillator pairs. Therefore, there may be a difference of several bits between the session PUF response feature acquired at the current moment and the PUF response feature acquired during registration. The rugged device performs a bitwise XOR operation on the re-acquisitioned session PUF response feature and the challenge-related features received and saved in step S1 to obtain a current fused feature set. The tri-proof device inputs the current fused feature set and fuzzy extraction auxiliary data into the recovery module of the fuzzy extractor. The recovery module first divides the current fused feature set into multiple information blocks in the same block division method as the encoding at the control end, and then performs BCH decoding on each information block in combination with the corresponding redundant check bits in the fuzzy extraction auxiliary data.
[0040] The BCH decoder uses redundant check bits to calculate error location for each bit position within the current information block. Specifically, it calculates the syndrome based on the received information block value and the check bit value, determines the error location polynomial using the syndrome, and then solves for the root of this polynomial to accurately locate the erroneous bit position. After location, the corresponding bit is flipped to correct the error. The upper limit of the number of erroneous bits that can be corrected in this process is determined by the number of correctable erroneous bits in the environmental compensation parameters. After completing error correction for all information blocks, the recovery module counts the total number of corrected erroneous bits in the entire current fusion feature set; this count is the error count. Simultaneously, the error-corrected information blocks are sequentially concatenated into an optimized fusion feature set. When the counted error count does not exceed the number of correctable erroneous bits in the environmental compensation parameters, the recovery module successfully outputs the optimized fusion feature set. This optimized fusion feature set, after error correction processing, has eliminated all bit errors caused by environmental changes and is completely consistent with the fusion feature set used by the control center during encoding in step S1. The ruggedized device performs a bitwise XOR operation again on the optimized fusion feature set and the challenge-related features. Since the optimized fusion feature set is equal to the XOR result of the registered PUF response vector and the challenge-related features, and the second XOR operation is equivalent to performing another XOR operation on the challenge-related features, the challenge-related features are canceled out after the two XOR operations, thus recovering the original registered PUF response vector. This recovered result is the stable response data. This stable response data has undergone fuzzy extraction and error correction processing to remove all error bits introduced by environmental changes, and is numerically completely consistent with the baseline PUF response vector stored in the control center database during registration.
[0041] For example, a rugged device might collect a PUF response vector of "11001010…" during the registration phase. When re-collecting the response vector under high temperature and humidity conditions, temperature drift causes the 3rd and 17th bits to flip to "11101010…". The rugged device then XORs the re-collected session PUF response feature with the challenge-related feature to obtain the current fused feature set. After inputting the feature set into the recovery module, the BCH decoder locates the error in the 3rd and 17th bits and flips these two bits to correct it. The optimized fused feature set is then output and XORed with the challenge-related feature, finally obtaining a stable response data that is restored to "11001010…", which is exactly the same as the original response during the registration phase. The stable response data is then used by the input key derivation function to derive the session master key. The device concatenates the stable response data with the disturbance level as the input key material, and uses the public salt value formed by concatenating the device identification number, protocol version number, and protocol type identifier as the salt value. After two rounds of iterative calculation using the hash message authentication code algorithm, a 256-bit session master key is output. At the same time, the session master key is used as the key for the hash message authentication code algorithm, and the challenge association feature is used as the input message to calculate a 256-bit device-side locking credential. This locking credential will be used by the control center in subsequent steps to verify whether the device holds the correct session master key.
[0042] Step S3: Perform two-way locking verification based on the session master key and the locking credential, and perform security configuration processing based on the session master key and preset global network information to obtain multi-domain mapping data and frequency hopping configuration data.
[0043] The locking credential is a 256-bit hash value calculated by the rugged device using its own derived session master key as the key for the hash message authentication code algorithm and the challenge association feature issued by the control center as the input message for the algorithm. Because the hash message authentication code algorithm has key dependency and one-wayness, only an entity possessing both the correct session master key and the correct challenge association feature can calculate the correct locking credential value. Since the rugged device has recovered the correct stable response data and derived the correct session master key through fuzzy extraction in step S2, this locking credential serves as cryptographic proof that the rugged device holds the correct session master key. To verify the authenticity of this proof, the control center needs to independently recalculate the session master key and compare it with the session master key derived by the rugged device. For this purpose, the control center retrieves the 128-bit baseline PUF response data stored during the device's factory registration phase from the database. This baseline PUF response data is numerically identical to the stable response data recovered by the rugged device through fuzzy extraction in step S2, because the stable response data is obtained by restoring the currently collected PUF response to the original PUF response vector from the registration phase through error correction decoding. The control center concatenates the baseline PUF response data with the disturbance level determined in step S2 to form the input key material. It uses the public salt value, which is formed by concatenating the device identification number, protocol version number, and protocol type identifier, as the salt value input. It performs two rounds of hash message authentication code iteration calculation using the same key derivation function as the one used by the rugged device in step S2, and outputs a 256-bit value. This value is the central key independently derived by the control center. The central key is numerically identical to the session master key derived from the rugged device. Essentially, they are the corresponding representations of the same key material at the control center, but they are distinguished by the term "central key" to clarify that it is derived by the control center.
[0044] After obtaining the central key, the control center uses it as the key for the hash message authentication code algorithm. The challenge association feature, sent to the rugged device in step S1 and stored locally, is used as the input message for this algorithm. The control center performs the hash message authentication code operation to obtain a 256-bit verification credential. The calculation method for this verification credential is exactly the same as the method used by the rugged device to calculate the locking credential in step S2. Both use the session master key (corresponding to the central key at the control center) as the key and the same challenge association feature as the input message. Therefore, if the rugged device does indeed possess the correct session master key, the locking credential calculated by the rugged device will be identical to the verification credential calculated by the control center in every bit of the 256 bits. The control center compares the calculated verification credential with the locking credential sent by the rugged device bit by bit, checking each corresponding bit from the highest bit of both credentials to see if they match, and counting the matches across all 256 bits. The control center only considers the two-way locking verification successful when all 256 bits are completely equal. This is because the output of the hash message authentication code algorithm has an avalanche effect; any tiny difference in the input will cause about half of the bits in the output to change. Therefore, even if there is only a one-bit difference between the locking credential and the verification credential, it is sufficient to prove that the session master key held by the rugged device differs from the central key derived by the control center. This difference may be due to a failure in fuzzy extraction and recovery on the device side or the presence of a man-in-the-middle attack. When the verification credential and the locking credential match, the control center confirms that the rugged device has successfully recovered the correct stable response data and derived the correct session master key. At this point, the control center has completed the reverse authentication of the rugged device's identity, establishing a two-way locking trust relationship between the device and the control center. For example, in step S2, a rugged device correctly recovers stable response data and derives a session master key. Its calculated locking credential is "101010...". The control center recalculates the verification credential using the central key and also obtains "101010...". The two are completely consistent, and the two-way locking verification passes. Conversely, if an attacker attempts to tamper with the locking credential in the communication link, even if only one bit is flipped, the control center will detect the difference through bit-by-bit comparison and immediately terminate the subsequent process.
[0045] After successful two-way locking verification, the control center generates a central locking credential. Using the central key as the key for the hash message authentication code algorithm and the fusion feature set obtained from decryption in step S1 as the input message, a 256-bit central locking credential is calculated. This central locking credential is designed to provide the rugged device with a basis for verifying the authenticity of the control center's identity in subsequent stages. This credential can only be calculated by an entity possessing both the correct session master key (corresponding to the central key on the control center's side) and the correct fusion feature set. Since the control center holds both the central key and the fusion feature set, the rugged device can independently verify the credential using its own session master key and fusion feature set upon receiving it. If the verification is successful, the rugged device confirms that the communication peer is indeed a legitimate control center and not an imposter. While generating the central locking credential, the control center extracts the global network information stored locally and performs security configuration processing. This global network information is pre-stored in the control center's database in the form of a multi-domain topology mapping table, specifically comprising three parts: The first part is a list of available frequency domain resource pools. This list records the start frequency, end frequency, frequency step interval, and total number of available frequency points for each network domain. In the specific implementation plan, the total number of network domains is set to eight, corresponding to the satellite link domain, ground base station domain, shortwave communication domain, microwave line-of-sight domain, underwater acoustic domain, and UAV domain. The network consists of three main parts: a relay domain, an emergency self-organizing network domain, and a backup signaling domain. The second part is a time slot resource configuration table, which records the frame period duration, the number of time slots per frame, the duration of each time slot, and the maximum number of time slots that a device can currently occupy in that domain for each network domain. The third part is the inter-domain handover rules, which include a list of trigger conditions for inter-domain handover, the corresponding target handover domain, and the handover execution sequence. Trigger conditions include multiple consecutive measurements of the signal-to-noise ratio below a threshold, link interruption, coverage loss due to device geographical location movement, priority changes, and detection of specific types of attacks. The control center uses the central key as the key for the authentication encryption algorithm, and the frequency domain resource list and time slot resource configuration table from the overall network information as plaintext input. After generating a random 96-bit initial vector, it performs authentication encryption operations, outputting an encryption mapping table and a corresponding authentication tag. The encryption mapping table is the ciphertext form of the overall network information, while the authentication tag is used by the receiving end to verify the integrity of the ciphertext. The control center packages the central locking credential, encrypted mapping table, authentication tag, and initialization vector used for encryption into a secure configuration data packet, which is then sent to the rugged device through a secure signaling channel. This encryption operation ensures the confidentiality and integrity of network information throughout the transmission process. Even if an attacker intercepts the encrypted mapping table, they will not be able to decrypt it to obtain the frequency domain resources and time slot configuration information due to the lack of the central key (corresponding to the session master key on the rugged device), thus ensuring the security of subsequent frequency hopping communication parameters.
[0046] After receiving the security configuration data packet from the control center, the rugged device first extracts the central locking credential, encrypted mapping table, authentication tag, and initialization vector from the data packet. Then, it uses the session master key derived in step S2 as the key for the authentication decryption algorithm, and combines it with the received initialization vector to decrypt the encrypted mapping table and authentication tag, and perform integrity verification. During this process, the decryption algorithm performs two operations simultaneously: first, it restores the ciphertext of the encrypted mapping table to plaintext; second, it recalculates the integrity check value of the decrypted data using Galois domain hashing and compares it with the received authentication tag. When the integrity check value matches the authentication tag, the rugged device obtains the plaintext multi-domain mapping data, which fully contains the complete frequency domain resource list, time slot resource configuration table, and inter-domain switching rules preset by the control center. If the integrity check fails, the rugged device discards the data packet and triggers a re-request process, because the inconsistent authentication tags indicate that the data has been tampered with during transmission or the session master key does not match. After successfully decrypting and obtaining the multi-domain mapping data, the rugged device compares the received central locking credential with its own independently calculated central locking credential verification value. The rugged device uses its own session master key as the hash message authentication code key and the fusion feature set stored locally in step S1 as the input message to calculate a 256-bit verification value. This verification value is then compared bit by bit with the received central locking credential. When all 256 bits are completely equal, the rugged device confirms that the communication peer is indeed a legitimate control center, thus completing the verification of the control center's identity. This operation constitutes the reverse verification link initiated by the device in the two-way locking verification, which, together with the control center's verification of the locking credential mentioned above, forms a complete two-way mutual recognition mechanism. After completing the authentication with the control center, the rugged device performs the frequency hopping configuration data generation operation based on the session master key and multi-domain mapping data: For each network domain defined in the global network information, the rugged device uses the session master key as the initial key of the deterministic random bit generator, encodes the number of the network domain as an 8-bit binary value as the high-order part of the initial counter block, and fills the low-order part with zero values to form a 128-bit initial counter value. Then, it drives the deterministic random bit generator to continuously generate 128-bit random number blocks a predetermined number of times. Every two random number blocks are concatenated into a 256-bit frequency hopping seed value. After arranging them in order of frequency point number, the frequency hopping seed column corresponding to the domain is formed. After traversing all 8 network domains, all seed columns together form the multi-domain frequency hopping seed matrix, which is the frequency hopping configuration data. The generation of this frequency hopping configuration data depends entirely on the session master key as the initial seed. Therefore, only the rugged device and the control center that simultaneously possess the correct session master key (corresponding to the center key at the control center) can generate the exact same frequency hopping seed matrix. Any illegal device that does not possess the session master key cannot predict or deduce the frequency hopping sequence, thus ensuring the security of the frequency hopping mode in subsequent communications.
[0047] Step S4: Based on the multi-domain mapping data and the frequency hopping configuration data, perform cross-domain resource scheduling and secure interaction on the communication data to be sent.
[0048] First, based on the current location information, the network domain code and corresponding modulation order are determined from the multi-domain mapping data. This current location information is jointly provided by the satellite positioning module and signal strength detection module built into the rugged device, and includes the device's current geographic coordinates and signal coverage strength data of each available network domain. The rugged device matches this location information with the inter-domain switching rules in the multi-domain mapping data, and selects the network domain with the highest signal strength that meets the communication task requirements as the current working domain. The network domain code has a value range of 1 to 8, corresponding to one of the following: satellite link domain, ground base station domain, shortwave communication domain, microwave line-of-sight domain, underwater acoustic domain, UAV relay domain, emergency self-organizing network domain, and backup signaling domain. For example, when the location information of a rugged device shows that it is in an urban environment and the ground base station signal strength is higher than a preset threshold, the device determines the network domain code to be the ground base station domain and obtains the modulation order corresponding to this domain as 4 (corresponding to 16QAM modulation). When the location information of the device shows that it has entered a mountainous area, causing the ground base station signal to attenuate below the threshold, the device triggers a handover operation according to the inter-domain handover rules in the multi-domain mapping data, updates the network domain code to the satellite link domain, and obtains the modulation order corresponding to this domain as 2 (corresponding to QPSK modulation). After determining the current network domain code and the corresponding modulation order, the rugged device extracts the corresponding frequency hopping seed column from the frequency hopping configuration data according to the network domain code. This frequency hopping seed column contains the frequency hopping seed values corresponding to the total number of available frequency points in the domain, and each seed value is a 256-bit pseudo-random number.
[0049] The rugged device's internal frame counter and time slot counter operate continuously in real time. The frame counter increments by 1 based on the frame period duration corresponding to the network domain, completing one frame period at a time. The time slot counter increments from 0 within each frame until the total number of time slots in that frame is reduced by 1, at which point it resets to zero. The current frame number and time slot number together identify the precise position of the current moment in the time dimension. The rugged device selects the current frequency hopping seed from the frequency hopping seed list based on the current frame number and time slot number. Specifically, the frame number and time slot number are combined into an index value, which is then modulo the length of the frequency hopping seed list to obtain the seed index. The 256-bit frequency hopping seed value at this index position is then taken as the current frequency hopping seed. The rugged device calculates the current frequency point index based on the current frequency hopping seed, current frame number, and time slot number. This calculation involves concatenating the current frequency hopping seed, current frame number, and time slot number and inputting the result into a deterministic pseudo-random number generator. The generator outputs an integer within the total number of available frequency points as the current frequency point index. The rugged device simultaneously generates a time slot allocation table based on the session master key and the current network domain code. This table is generated by using the session master key as the initial key for a deterministic random bit generator and the current network domain code as the high-order bits of a counter block. This drives the generation of a bit sequence with a length equal to the total number of time slots per frame for that network domain. Each bit in this sequence corresponds to a time slot position; a bit value of 1 indicates that the time slot is allocated to the current rugged device for data transmission, while a bit value of 0 indicates that the time slot is not allocated to the current rugged device. The rugged device then adjusts the generated bit sequence by referring to the maximum number of time slots that the current rugged device can occupy in that domain, as specified in the time slot resource configuration table of the multi-domain mapping data. Specifically, it counts the total number of bits with a value of 1 in the bit sequence. If this total exceeds the maximum number of available time slots, it selects the time slots with the lowest signal-to-noise ratio from the time slots with values of 1 and changes their flags to 0, until the constraints are met. Finally, this bit sequence becomes the time slot allocation table for the current frame. The rugged device determines the transmittable time slots based on the time slot allocation flags in the time slot allocation table; time slots with a time slot allocation flag of 1 are transmittable, while those with a flag of 0 are non-transmittable. The rugged device then divides the raw communication data to be transmitted into blocks according to the modulation order corresponding to the current network domain. Specifically, it divides the bit stream of the raw communication data into groups of L bits, where L equals the modulation order. For example, with a modulation order of 4, each block consists of 4 bits. After division, several symbol blocks are obtained. If the last symbol block has fewer than L bits, zeros are padded to the end to make all symbol blocks of uniform length. The rugged device treats each symbol block's L bits as a binary value and converts it to a decimal integer. This integer is the symbol value corresponding to the symbol block, ranging from 0 to 2^L - 1. All symbol values are then arranged in their original order to obtain the data symbol stream.
[0050] The tri-proof equipment uses the frequency domain resource information and current frequency index from the multi-domain mapping data to map each symbol in the data symbol stream to a specified frequency and time slot, generating a resource mapping table. Specifically, for the m-th symbol in the data symbol stream, firstly, the time slot index with the next time slot allocation flag set to 1 is selected sequentially from the time slot allocation table as the time slot position for that symbol. Then, the current frequency index is used as the frequency position for that symbol, and the symbol's value is recorded, forming a quadruple entry containing the symbol index, time slot index, frequency index, and symbol value. This process is repeated for all symbols to obtain the complete resource mapping table. This resource mapping table determines the transmission time in the time domain and the transmission frequency in the frequency domain for each symbol to be transmitted, serving as the basis for subsequent modulation processing instructions. Rugged devices use the session master key as the key for the authentication encryption algorithm and the concatenated value of the current frame number and timeslot number as the initial vector to perform authentication encryption processing on all symbol values in the data symbol stream. Each ciphertext symbol value in the encrypted output ciphertext symbol stream still maintains the same numerical range as the original symbol, but its value itself has been obfuscated and diffused by the encryption algorithm, presenting a pseudo-random distribution. The rugged device obtains the actual carrier frequency from the frequency domain resource pool of the multi-domain mapping data according to the frequency point index in the resource mapping table. Specifically, it obtains the absolute frequency value corresponding to the frequency point index by multiplying the frequency point index by the frequency point step interval and adding the starting frequency.
[0051] The ruggedized device performs a linear transformation on each ciphertext symbol value in the ciphertext symbol stream to obtain the baseband signal. Specifically, this linear transformation maps the ciphertext symbol value from its value space to a frequency offset interval. The mapping method involves dividing the ciphertext symbol value by the maximum possible value, subtracting 0.5 to obtain a normalized deviation, and then multiplying this by twice the maximum permissible frequency offset to obtain the corresponding frequency offset. This maximum permissible frequency offset is set to 0.8 times the current domain frequency step to avoid interference caused by the signal crossing adjacent frequency points. The ruggedized device then generates a chirped baseband signal as the baseband signal output. This signal starts at the actual carrier frequency minus the frequency offset within the symbol period and linearly scans at a constant rate to the actual carrier frequency plus the frequency offset, forming a broadband spread spectrum signal whose frequency changes linearly with time. The instantaneous phase of this signal waveform is the integral of the frequency, and the actual output baseband signal is in complex exponential form. The reason for designing this chirped baseband signal is that when ruggedized devices operate in environments with strong electromagnetic interference or complex multipath propagation, traditional single-frequency modulation signals are easily blocked by interference sources or experience frequency-selective fading due to multipath effects. The chirped signal, however, extends the symbol energy to a wider frequency band. Even if a frequency component is interfered with at a certain instant, other frequency components may remain intact. The receiver can detect the complete chirped signal in the noise through matched filtering. The ruggedized device sequentially splices the baseband signals corresponding to all symbols in time according to the time slot order (i.e., transmittable time slots) and frequency order specified in the resource mapping table. A guard interval is inserted between every two adjacent symbols, with a duration of one-eighth of the symbol period, to absorb inter-symbol interference caused by multipath propagation. After splicing, an encrypted frequency-hopping baseband signal stream is obtained. The encrypted frequency-hopping baseband signal stream presents as a continuous baseband waveform sequence in the time domain. The center frequency of each symbol period jumps between different frequency points according to the frequency-hopping seed indicated in the frequency-hopping configuration data. At the same time, each symbol contains a broadband chirped structure that linearly scans from the start frequency to the end frequency, forming a three-dimensional signal structure of "continuous in the time domain, frequency-hopping, and broadband spread spectrum within the symbol". The ruggedized device sends the encrypted frequency-hopping baseband signal stream to the control center. After receiving the encrypted frequency-hopping baseband signal stream, the control center performs demodulation processing that is the reverse of the modulation process, including chirped matched filtering despreading, frequency point synchronization tracking, authentication decryption, and symbol demapping, thereby recovering the original communication data.
[0052] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0053] In one embodiment, a global communication secure interaction device 2 is provided, which corresponds one-to-one with the global communication secure interaction method described in the above embodiments. For example... Figure 3 As shown, the global communication security interaction device 2 may include: a registration encoding module 21, a session extraction module 22, a session encryption module 23, a resource configuration module 24, and a cross-domain interaction module 25. Detailed descriptions of each functional module are as follows: Registration encoding module 21 is used to extract the registration PUF response features of the tri-proof device, and perform association encoding based on the registration PUF response features and the received challenge association features to obtain a fused feature set; The session extraction module 22 is used to perform environmental disturbance compensation and fuzzy extraction based on the collected environmental state parameters and extracted session PUF response features when the control center completes the identity authentication of the tri-proof device, so as to obtain stable response data. Session encryption module 23 is used to perform key derivation processing based on the stable response data to obtain the session master key and locking credential; The resource configuration module 24 is used to perform two-way locking verification based on the session master key and the locking credential, and to perform security configuration processing based on the session master key and preset global network information to obtain multi-domain mapping data and frequency hopping configuration data. The cross-domain interaction module 25 is used to perform cross-domain resource scheduling and secure interaction on the communication data to be sent based on the multi-domain mapping data and the frequency hopping configuration data.
[0054] It should be noted that the information interaction and execution process between the above-mentioned devices / units are based on the same concept as the method embodiments of this application. For details on their specific functions and technical effects, please refer to the method embodiments section, and they will not be repeated here.
[0055] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is merely an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. Furthermore, the specific names of the functional units and modules are only for easy differentiation and are not intended to limit the scope of protection of this application. The specific working process of the units and modules in the above system can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0056] This application also provides a computer device, such as... Figure 4 As shown, the computer device includes: at least one processor 32, a memory 31, and a computer program stored in the memory 31 and executable on the at least one processor 32. When the processor 32 executes the computer program, it implements the steps in any of the above method embodiments, or when the processor 32 executes the computer program, it implements the functions of each module / unit in the above device embodiments.
[0057] For example, the computer program may be divided into one or more modules / units, which are stored in the memory 31 and executed by the processor 32 to complete this application. The one or more modules / units may be a series of computer program instruction segments capable of performing a specific function, which describe the execution process of the computer program in the computer device.
[0058] Those skilled in the art will understand that Figure 4 The computer device described is merely an example and does not constitute a limitation on the computer device. It may include more or fewer components than shown, or combine certain components, or different components. For example, the computer device may also include input / output devices, network access devices, buses, etc.
[0059] The processor 32 mentioned above can be a Central Processing Unit (CPU), or it can be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), or field-programmable gate arrays (FPGAs). Programmable Gate Array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor 32 can be a microprocessor or any conventional processor, etc.
[0060] The memory 31 can be an internal storage unit of the computer device, such as a hard drive or memory. The memory 31 can also be an external storage device of the computer device, such as a plug-in hard drive, Smart Media Card (SMC), Secure Digital (SD) card, or Flash Card. Furthermore, the memory 31 can include both internal and external storage units of the computer device.
[0061] This application also provides a readable storage medium storing a computer program that, when executed by a processor, implements the steps described in the various method embodiments above.
[0062] This application provides a computer program product that, when run on an electronic device, enables the electronic device to perform the steps described in the various method embodiments above.
[0063] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of this application can be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include at least: any entity or device capable of carrying computer program code to a photographing device / terminal device, a recording medium, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium. Examples include USB flash drives, portable hard drives, magnetic disks, or optical disks. In some jurisdictions, according to legislation and patent practice, computer-readable media cannot be electrical carrier signals or telecommunication signals.
[0064] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0065] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0066] In the embodiments provided in this application, it should be understood that the disclosed apparatus / devices and methods can be implemented in other ways. For example, the apparatus / device embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0067] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0068] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.
Claims
1. A method for secure interaction of a global communication, applied to a tri-proof communication system, the tri-proof communication system comprising a tri-proof device and a control center, characterized in that, The method includes: Extract the registered PUF response features of the tri-proof device, and perform association encoding based on the registered PUF response features and the received challenge association features to obtain a fused feature set; When the control center completes the identity authentication of the tri-proof device, it performs environmental disturbance compensation and fuzzy extraction based on the collected environmental state parameters and extracted session PUF response features to obtain stable response data, and performs key derivation processing based on the stable response data to obtain the session master key and locking credential. Two-way locking verification is performed based on the session master key and the locking credential, and security configuration processing is performed based on the session master key and preset global network information to obtain multi-domain mapping data and frequency hopping configuration data. Based on the multi-domain mapping data and the frequency hopping configuration data, cross-domain resource scheduling and secure interaction are performed on the communication data to be sent.
2. The global communication secure interaction method as described in claim 1, characterized in that, The process involves extracting the registered PUF response features of the ruggedized device, and then performing association encoding based on these registered PUF response features and the received challenge association features to obtain a fused feature set, including: The tri-proof device divides the integrated ring oscillator array into a preset number of oscillator pairs according to a preset array order, and compares the oscillation frequencies between the oscillators in the oscillator pairs to obtain the registered PUF response characteristics. The tri-proof device receives the challenge-related features issued by the preset control center, and performs a bitwise XOR operation between the registered PUF response features and the challenge-related features to obtain a fused feature set.
3. The global communication secure interaction method as described in claim 1, characterized in that, After obtaining the registered PUF response characteristics, the method further includes: The tri-proof device concatenates the registered PUF response feature with the fused feature set into a combined data block, and authenticates and encrypts the combined data block using a preset long-term key to obtain an encrypted data block and an authentication tag; The control center generates a verification tag based on the long-term key, preset initial parameters, and the encrypted data block; When the verification tag matches the authentication tag, the control center decrypts the encrypted data block using the long-term key to obtain the registered PUF response feature; The control center counts the number of bits that differ between the registered PUF response features and the preset baseline PUF response features to obtain the Hamming distance; When the Hamming distance is less than a preset fault tolerance threshold, the control center completes the authentication of the rugged device.
4. The global communication secure interaction method as described in claim 1, characterized in that, The process of performing environmental disturbance compensation and fuzzy extraction based on the collected environmental state parameters and extracted session PUF response features to obtain stable response data includes: The control center calculates the environmental disturbance offset data between the preset environmental reference parameters and the collected environmental state parameters, and performs norm calculation on the environmental disturbance offset data to obtain the environmental disturbance amplitude value. The control center determines the disturbance level of the current environment based on the disturbance amplitude value, and selects the corresponding level of error correction code parameters from the preset error correction code parameter table according to the disturbance level to obtain the environmental compensation parameters. The control center performs error correction coding and fuzzy extraction processing on the fused feature set according to the environmental compensation parameters, generates fuzzy extraction auxiliary data, and sends the fuzzy extraction auxiliary data and the environmental compensation parameters to the tri-proof device. The tri-proof device performs a bitwise XOR operation on the extracted session PUF response features and the challenge association features to obtain the current fused feature set, and locates and corrects the error bits of the current fused feature set according to the fuzzy extraction auxiliary data to obtain the number of errors of the error bits and optimize the fused feature set; When the number of errors is less than or equal to the number of correctable error bits in the environmental compensation parameters, the tri-proof device performs an XOR operation on the optimized fusion feature set and the challenge-related features to obtain stable response data.
5. The global communication secure interaction method as described in claim 1, characterized in that, The step of performing two-way locking verification based on the session master key and the locking credential, and performing security configuration processing based on the session master key and preset global network information to obtain multi-domain mapping data and frequency hopping configuration data includes: The control center performs key derivation processing based on preset baseline PUF response data and the challenge association features to obtain the center key; The control center calculates a verification credential based on the central key and the challenge association features, and compares the verification credential with the locking credential. When the verification credential matches the locking credential, the control center calculates the center locking credential based on the center key and the current fusion feature set, and performs authentication and encryption on the preset global network information based on the center key to generate an encryption mapping table, so as to send the center locking credential and the encryption mapping table to the rugged device. The tri-proof device decrypts the encrypted mapping table using the session master key to obtain multi-domain mapping data, and performs security configuration processing based on the central locking credential and the multi-domain mapping data to generate frequency hopping configuration data.
6. The global communication secure interaction method as described in claim 1, characterized in that, The step of performing cross-domain resource scheduling and secure interaction on the communication data to be transmitted based on the multi-domain mapping data and the frequency hopping configuration data includes: The tri-proof device determines the network domain code and the corresponding modulation order from the multi-domain mapping data based on the current positioning information, extracts the corresponding frequency hopping seed column from the frequency hopping configuration data based on the network domain code, and selects the current frequency hopping seed from the frequency hopping seed column based on the current frame number and time slot number generated in real time by the counter in the tri-proof device, so as to calculate the current frequency point index based on the current frequency hopping seed, the current frame number and the time slot number; The tri-proof device generates a time slot allocation table based on the session master key and the network domain code, determines the transmittable time slots according to the time slot allocation flags in the time slot allocation table, and performs block processing on the communication data to be transmitted according to the modulation order to generate a data symbol stream; The tri-proof device performs time allocation and frequency mapping on the generated data symbol stream based on the frequency domain resource information in the multi-domain mapping data and the current frequency point index, and generates a resource mapping table; The tri-proof device authenticates and encrypts the data symbol stream according to the session master key, generates a ciphertext symbol stream, and obtains the actual carrier frequency from the multi-domain mapping data according to the frequency point index in the resource mapping table, so as to perform a linear transformation on each ciphertext symbol value in the ciphertext symbol stream according to the actual carrier frequency to obtain the baseband signal. The tri-proof device splices the baseband signals into an encrypted frequency-hopping baseband signal stream according to the time sequence and the transmittable time slots, and sends the encrypted frequency-hopping baseband signal stream to the control center.
7. A global communication secure interaction device, applied to the global communication secure interaction method according to claim 1, characterized in that, The device includes: The registration encoding module is used to extract the registration PUF response features of the rugged device, and perform association encoding based on the registration PUF response features and the received challenge association features to obtain a fused feature set; The session extraction module is used to perform environmental disturbance compensation and fuzzy extraction based on the collected environmental state parameters and extracted session PUF response features when the control center completes the identity authentication of the tri-proof device, so as to obtain stable response data. The session encryption module is used to perform key derivation processing based on the stable response data to obtain the session master key and locking credential. The resource configuration module is used to perform two-way locking verification based on the session master key and the locking credential, and to perform security configuration processing based on the session master key and preset global network information to obtain multi-domain mapping data and frequency hopping configuration data. The cross-domain interaction module is used to perform cross-domain resource scheduling and secure interaction on the communication data to be sent based on the multi-domain mapping data and the frequency hopping configuration data.
8. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the global communication secure interaction method as described in any one of claims 1 to 6.
9. A readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the steps of the global communication secure interaction method as described in any one of claims 1 to 6.
10. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the steps of the global communication secure interaction method as described in any one of claims 1 to 6.