Two-Phase Access Authentication for Space-Air-Ground Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional access authentication schemes in space-air-ground integrated networks (SAGINs) face challenges such as high delay, service instability, and vulnerability to key information interception, particularly due to the use of satellites as transparent forwarding nodes and reliance on public key infrastructure-based authentication.

Innovation Solution

A two-phase access authentication method is introduced, which integrates spatial-temporal features. This method involves an initializing phase, device registration, primary authentication, and continued authentication, utilizing a ground network control center to assist in the authentication process and ensuring secure access by leveraging spatial-temporal features.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional public key infrastructure-based authentication is used in SAGINs, then authentication can be performed, but the system becomes vulnerable to key information interception and decryption

Engineering Contradiction:
Improveauthentication securityVSAvoidvulnerability to key interception
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the authentication process into two distinct phases: primary authentication using identity identifiers and continued authentication using spatial-temporal features. This segmentation prevents reliance on a single authentication mechanism, thereby reducing vulnerability to key interception while maintaining authentication reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the authentication parameters from static public key infrastructure to dynamic spatial-temporal features (position, velocity, time). These parameters are continuously changing and difficult to intercept or replicate, thereby enhancing security while maintaining authentication functionality.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If ground network control center authentication scheme is used, then authentication can be performed, but greater delay and service instability occur

Engineering Contradiction:
Improveauthentication capabilityVSAvoidauthentication delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent divides authentication into two phases where primary authentication is performed locally between user equipment and satellite using identity identifiers, avoiding ground control center involvement for routine authentication. This reduces delay while maintaining security through continued authentication phase when needed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces satellite as an intermediary authentication entity that can perform primary authentication locally, reducing reliance on ground control center for every authentication event. This intermediary role minimizes delay while ground control center remains available for continued authentication when service stability needs verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Area of stationary object

If satellites are used as transparent forwarding nodes, then network coverage is extended, but authentication security is compromised

Engineering Contradiction:
Improvenetwork coverageVSAvoidauthentication security
Core Design Contradiction:
Area of stationary objectVSReliability

Solution Approach 1:

The patent transforms satellites from single-function transparent forwarding nodes to multi-functional entities that can perform both signal forwarding and primary authentication. This universal role allows extended coverage while improving security, as satellites actively verify user identities rather than merely relaying signals.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent enables satellites to perform self-service authentication functions by verifying user identity identifiers and spatial-temporal features locally. This self-service capability eliminates the need for ground control center involvement in routine authentication, reducing delay while maintaining security across extended coverage areas.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12289157B2Two-phase access authentication method integrating spatial-temporal features in space-air-ground integrated networks
Publication Date: 2025.04.29 ZHEJIANG LAB
  • US12289157B2 patent drawing
  • US12289157B2 patent drawing

AI summary

Disclosed is a two-phase access authentication method integrating spatial-temporal features in space-air-ground integrated networks. In the method, an access authentication is divided into two phases: a primary authentication phase and a continued authentication phase. In the primary authentication phase, a user equipment and a satellite are respectively initialized and registered through a ground network control center. In the authentication phase, a fast and secure access is achieved by using a user ID, facial features, and other authentication factors. In the continued authentication phase, data of a user flow and behavior features are acquired, and feature comparison is performed by using historical user data; and a security level and an authentication decision are output. According to the disclosure, the spatial-temporal features are integrated to perform access authentication on a satellite-ground communication network, the authentication not only achieves a fast access, but also continuously ensures the system security in a service phase.