Satellite Session Key Distribution via Public-Key Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional satellite systems require a complex key management infrastructure to distribute new session keys, which can be vulnerable to unauthorized access if an unauthorized party obtains the session key, necessitating periodic key updates and secure distribution methods.
Innovation Solution
The method involves using public-key cryptography to transmit session keys between a satellite and a device, where the session key is protected based on the device's private key and the public key of the intended recipient, allowing secure distribution without a separate key management infrastructure, and includes replay detection information to prevent unauthorized reuse.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If symmetric encryption is used to secure satellite communications, then security against unauthorized access is improved, but a complex key management infrastructure is required to distribute session keys
Solution Approach 1:
The patent extracts the key management function from the satellite system by using public-key infrastructure. Each ground station has its own key pair, eliminating the need for a centralized key management system. The session key is encrypted with the ground station's public key and transmitted directly, removing the complexity of key distribution infrastructure.
Solution Approach 2:
The patent introduces public-key cryptography as an intermediary mechanism. Instead of directly distributing symmetric session keys through a complex infrastructure, the system uses public keys as intermediaries to securely transmit session keys. The session key is encrypted with the recipient's public key, allowing secure key distribution without direct infrastructure complexity.
2Reliability
If session keys are periodically expired and replaced, then security against unauthorized access is improved, but the need for secure key distribution increases
Solution Approach 1:
The patent removes the centralized key distribution system by enabling each ground station to independently receive and verify session keys. The session key is encrypted with the ground station's public key, allowing autonomous key reception without relying on a centralized distribution system, thus simplifying the architecture while maintaining periodic key rotation security.
3Reliability
If a trusted third-party key management system is used, then secure key distribution is achieved, but system complexity and dependency on external infrastructure increase
Solution Approach 1:
The patent extracts the key management functionality from the satellite system and distributes it to individual ground stations. Each ground station uses its own public-private key pair to independently receive and verify session keys. This eliminates the trusted third-party key management system while maintaining secure key distribution, reducing system architecture complexity and external dependencies.
4Device complexity
If public-key cryptography is used to transmit session keys, then the need for key management infrastructure is reduced, but computational overhead increases
Solution Approach 1:
The patent segments the cryptographic operations: public-key cryptography is used only for session key transmission, while symmetric cryptography is used for bulk data communication. This segmentation minimizes the use of computationally intensive public-key operations to only what is necessary for secure key distribution, reducing overall computational overhead while eliminating key management infrastructure.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
A satellite system comprises first and second devices, one of the first and second devices being a satellite and the other one of the first and second devices being a device arranged to send signals to the satellite and/or receive signals from the satellite. A session key can be distributed in the satellite system by obtaining the session key at the first device, protecting the session key at the first device, based on a private key of the first device and a public key of the second device, and transmitting the protected session key from the first device to the second device. The second device can receive the protected session key from the first device and obtain the session key from the protected session key based on a public key of the first device and a private key of the second device. Replay detection information can be transmitted with the protected session key, for determining whether the session key has been transmitted previously. The protected session key can be transmitted by inserting a predetermined number of bytes of the protected session key into each frame of a data stream, for example a telemetry (TM) data stream as defined in the Consultative Committee for Space Data Systems (CCSDS) TM protocol. Validity information can be transmitted with the protected session key, defining a period in which the session key is valid. The protected session key can be transmitted bonded to a command message, for example a telecommand (TC) as defined in the CCSDS TC protocol.