留言板

尊敬的读者、作者、审稿人, 关于本刊的投稿、审稿、编辑和出版的任何问题, 您可以本页添加留言。我们将尽快给您答复。谢谢您的支持!

姓名
邮箱
手机号码
标题
留言内容
验证码

基于TESLA协议的BDSBAS电文认证技术

陈潇 田翔 罗瑞丹 刘婷 宋佳慧 吴海涛

陈潇,田翔,罗瑞丹,等. 基于TESLA协议的BDSBAS电文认证技术[J]. 北京航空航天大学学报,2023,49(9):2289-2298 doi: 10.13700/j.bh.1001-5965.2021.0669
引用本文: 陈潇,田翔,罗瑞丹,等. 基于TESLA协议的BDSBAS电文认证技术[J]. 北京航空航天大学学报,2023,49(9):2289-2298 doi: 10.13700/j.bh.1001-5965.2021.0669
CHEN X,TIAN X,LUO R D,et al. Design of message authentication based on TESLA protocol for BDSBAS[J]. Journal of Beijing University of Aeronautics and Astronautics,2023,49(9):2289-2298 (in Chinese) doi: 10.13700/j.bh.1001-5965.2021.0669
Citation: CHEN X,TIAN X,LUO R D,et al. Design of message authentication based on TESLA protocol for BDSBAS[J]. Journal of Beijing University of Aeronautics and Astronautics,2023,49(9):2289-2298 (in Chinese) doi: 10.13700/j.bh.1001-5965.2021.0669

基于TESLA协议的BDSBAS电文认证技术

doi: 10.13700/j.bh.1001-5965.2021.0669
详细信息
    通讯作者:

    E-mail:liuting101015@aircas.ac.cn

  • 中图分类号: V19;X949

Design of message authentication based on TESLA protocol for BDSBAS

More Information
  • 摘要:

    星基增强系统(SBAS)能为航空、航海等生命安全领域提供完好性增强服务,针对SBAS服务的欺骗风险,面向北斗星基增强系统(BDSBAS)发展,提出基于中国商用密码标准算法的时间效应流丢失容错认证机制(TESLA)电文认证方案。阐述SBAS电文认证架构与TESLA认证原理,开展基于中国商用密码标准算法的BDSABS认证电文编排及空中密钥更新(OTAR)的电文播发设计,针对L5I与L5Q开展认证时间间隔和最大认证延迟等指标的理论分析,进一步从OTAR信息权重和解调错误率2方面仿真首次认证时间指标。仿真结果能为基于TESLA协议的BDSBAS电文认证提供一定的理论支持。

     

  • 图 1  加入电文认证后的SBAS系统构架

    Figure 1.  SBAS architecture after adding authentication

    图 2  基于TESLA的电文认证原理图

    Figure 2.  Message authentication principle of TESLA

    图 3  TESLA电文结构

    Figure 3.  TESLA message structure

    图 4  L5I TESLA电文结构

    Figure 4.  L5I TESLA message structure

    图 5  L5Q TESLA电文结构

    Figure 5.  L5Q TESLA message structure

    图 6  OTAR电文结构

    Figure 6.  OTAR message structure

    图 7  TESLA-I最大认证延迟和认证时间间隔

    Figure 7.  MAL and TBA of TESLA-I

    图 8  TESLA-Q最大认证延迟和认证时间间隔

    Figure 8.  MAL and TBA of TESLA-Q

    图 9  TESLA-I权重比影响分析

    Figure 9.  Impact analysis of weight ratio of TESLA-I

    图 10  TESLA-Q权重比影响分析

    Figure 10.  Impact analysis of weight ratio of TESLA-Q

    图 11  TESLA-I帧错误率影响分析

    Figure 11.  PER analysis of TESLA-I

    图 12  TESLA-Q帧错误率影响分析

    Figure 12.  PER analysis of TESLA-Q

    表  1  TESLA OTAR播发电文类型

    Table  1.   TESLA OTAR message type

    OTAR播发电文类型定义长度/bit
    OMT1 当前盐值、密钥链的根
    密钥或中间密钥
    30+115
    OMT2 当前盐值和根密钥的数字签名 512
    OMT3 当前系统公钥 512
    OMT4 当前系统公钥的CA数字签名 512
    OMT5 当前盐值/密钥链/系统公钥/
    认证机构公钥到期声明
    48
    OMT6 到期声明的CA数字签名 512
    OMT7 下一个盐值、密钥链的
    根密钥或中间密钥
    30+115
    OMT8 下一个盐值和根密钥或
    者中间密钥的数字签名
    512
    OMT9 下一个系统公钥 512
    OMT10 下一个系统公钥的CA数字签名 512
    OMT11 下一个认证机构公钥的3项签名证书 512*3
    下载: 导出CSV

    表  2  TESLA-I权重比对比结果

    Table  2.   Comparison results of weight ratio for TESLA-I

    W1/Wrtave/stmax/stmin/sTave/s
    100235.555254873.4
    101161.2384541688.2
    102138.3378543973.5
    103132.73305411505.7
    104131.52525432457.2
    下载: 导出CSV

    表  3  TESLA-Q权重比对比结果

    Table  3.   Comparison results of weight ratio for TESLA-Q

    W1/Wrtave/stmax/stmin/sTave/s
    10039.2929145.6
    10126.9649281.3
    10223.1639662.2
    10322.15591917.6
    10421.94295409.5
    下载: 导出CSV

    表  4  TESLA-I帧错误率对比结果

    Table  4.   Comparison results of TESLA-I PER

    PERtave/stmax/stmin/sTave/s
    10−1239.71056546553.5
    10−2150.7594545004.1
    10−3139.5498543986.3
    10−4139.0384543985.6
    10−5139.2360543979.3
    下载: 导出CSV

    表  5  TESLA-Q帧错误率对比结果

    Table  5.   Comparison results of TESLA-Q PER

    PERtave/stmax/stmin/sTave/s
    10−140.616491087.3
    10−225.1989828.1
    10−323.3749663.3
    10−423.2659663.4
    10−523.2609663.8
    下载: 导出CSV

    表  6  基于ECDSA和TESLA方案的TBA和MAL指标

    Table  6.   TBA and MAL indicators based ECDSA and TESLA soulution

    方案认证方式数字签
    名长度/bit
    密钥长度/bitTBA/sMAL/s
    TESLA-IMAC30延迟密钥115611
    TESLA-QMAC30延迟密钥11511
    ECDSA-Q[11]数字签名512签名私钥25634
    公钥 512
    斯坦福
    TESLA-I[14]
    MAC30延迟密钥115611
    斯坦福
    ECDSA-Q [14]
    数字签名448签名私钥11222
    公钥224
    下载: 导出CSV

    表  7  首次认证时间性能指标

    Table  7.   TTFA performance indicators s

    方案 不接收OTAR
    电文时间
    tmax tmin tave Tave Tmin Tave
    TESLA-I 6~12 360 54 139.2 6000 2406 3979.3
    TESLA-Q 1~2 60 9 23.2 1000 401 663.9
    TESLA-I 6~12 264 66 134.2 6000 3858 4989.4
    下载: 导出CSV
  • [1] 谭述森. 北斗卫星导航系统的发展与思考[J]. 宇航学报, 2008, 29(2): 391-396. doi: 10.3873/j.issn.1000-1328.2008.02.001

    TAN S S. Development and thought of compass navigation satellite system[J]. Journal of Astronautics, 2008, 29(2): 391-396(in Chinese). doi: 10.3873/j.issn.1000-1328.2008.02.001
    [2] PSIAKI M L, HUMPHREYS T E. GNSS spoofing and detection[J]. Proceedings of the IEEE, 2016, 104(6): 1258-1270. doi: 10.1109/JPROC.2016.2526658
    [3] CHEN Y, GAO W G, CHEN X, et al. Advances of SBAS authentication technologies[J]. Satellite Navigation, 2021, 2(1): 1-7. doi: 10.1186/s43020-020-00033-9
    [4] DALLA CHIARA A, DA BROI G, POZZOBON O, et al. Authentication concepts for satellite-based augmentation systems[C]//Proceedings of the 29th International Technical Meeting of the Satellite Division of the Institute of Navigation. Manassas: Institute of Navigation, 2016: 3208-3221.
    [5] ENGE P, WALTER T. Digital message authentication for SBAS and APNT[C]//Proceedings of the 27th International Technical Meeting of the Satellite Division of The Institute of Navigation. Manassas: Institute of Navigation , 2014: 1328-1336.
    [6] SCOTT L. Anti-spoofing & authenticated signal architectures for civil navigation systems[C]//Proceedings of the 16th International Technical Meeting of the Satellite Division of The Institute of Navigation. Manassas: Institute of Navigation, 2003: 1543-1552.
    [7] FERNáNDEZ-HERNáNDEZ I. GNSS authentication: Design parameters and service concepts[C]//Proceedings of the European Navigation Conference. Alphen aan den Rijn: EUGIN, 2014.
    [8] NEISH A, WALTER T, POWELL J D. SBAS data authentication: a concept of operations[C]//Proceedings of the 32nd International Technical Meeting of the Satellite Division of The Institute of Navigation. Manassas: Institute of Navigation, 2019: 1812-1823.
    [9] DALLA CHIARA A, DA BROI G, POZZOBON O, et al. SBAS authentication proposals and performance assessment[C]//Proceedings of the 30th International Technical Meeting of the Satellite Division of the Institute of Navigation. Manassas: Institute of Navigation, 2017: 2106-2116.
    [10] FERNÁNDEZ-HERNÁNDEZ I, WALTER T, NEISH A M, et al. SBAS message authentication: A review of protocols, figures of merit and standardization plans[C]//Proceedings of the 2021 International Technical Meeting of the Institute of Navigation. Manassas: Institute of Navigation, 2021: 111-124.
    [11] 穆盛林, 陈颖, 刘婷, 等. 面向BDSBAS电文认证的OTAR播发策略设计[J]. 北京航空航天大学学报, 2021, 47(7): 1453-1461. doi: 10.13700/j.bh.1001-5965.2020.0222

    MU S L, CHEN Y, LIU T, et al. Design of message authentication and OTAR broadcast strategy for BDSBAS[J]. Journal of Beijing University of Aeronautics and Astronautics, 2021, 47(7): 1453-1461(in Chinese). doi: 10.13700/j.bh.1001-5965.2020.0222
    [12] NEISH A, WALTER T, ENGE P. Parameter selection for the TESLA keychain[C]//Proceedings of the 31st International Technical Meeting of the Satellite Division of the Institute of Navigation. Manassas: Institute of Navigation, 2018: 2155-2171.
    [13] NEISH A, WALTER T, ENGE P. Quantum-resistant authentication algorithms for satellite-based augmentation systems[J]. Navigation, 2019, 66(1): 199-209. doi: 10.1002/navi.287
    [14] NEISH A, WALTER T, POWELL J D. Design and analysis of a public key infrastructure for SBAS data authentication[C]//Proceedings of the ION 2019 Pacific PNT Meeting. Manassas: Institute of Navigation, 2019: 964-988.
    [15] PERRIG A, CANETTI R, TYGAR J D, et al. Efficient authentication and signing of multicast streams over lossy channels[C]//Proceeding 2000 IEEE Symposium on Security and Privacy. Piscataway: IEEE Press, 2002: 56-73.
    [16] 中华人民共和国国家质量监督检查检验检疫总局, 中国国家标准化管理委员会. SM3密码杂凑算法: GB/T 32905—2016. [S]. 北京: 中国标准出版社, 2017.

    General Administration of Quality Supervision, Inspection and Quarantine of the People's Republic of China, Standardization Administration of the People’s Republic of China. Information security techniques—SM3 cryptographic hash algorithm: GB/T 32905—2016 [S]. Beijing: Standards Press of China, 2017(in Chinese)
    [17] Satellite Based Augmentation System Interoperability Working Group. SBAS L5 DFMC interface control document [S]. Montreal: SBAS IWG, 2015
    [18] FERNÁNDEZ-HERNÁNDEZ I, CHÂTRE E, DALLA CHIARA A, et al. Impact analysis of SBAS authentication[J]. Navigation, 2018, 65(4): 517-532. doi: 10.1002/navi.267
    [19] 结城浩著. 图解密码技术[M]. 周自恒译. 第3版. 北京: 人民邮电出版社, 2016.

    HIROSHI Y K. Graphic cryptography technology[M]. ZHOU Z H translated. 3rd ed. Beijing: Posts & Telecom Press, 2016 (in Chinese).
    [20] NEISH A. Establishing trust through authentication in satellite based augmentation systems[D]. Stanford: Stanford University, 2020.
  • 加载中
图(12) / 表(7)
计量
  • 文章访问数:  212
  • HTML全文浏览量:  28
  • PDF下载量:  29
  • 被引次数: 0
出版历程
  • 收稿日期:  2021-11-05
  • 录用日期:  2022-03-27
  • 网络出版日期:  2022-04-08
  • 整期出版日期:  2023-10-01

目录

    /

    返回文章
    返回
    常见问答