中国空间科学技术

• 论文 •    下一篇

一种基于可验证技术的卫星可信接入与传输机制

丁毅1,王阳1,郭文昕1,程子敬2,李洁1,靳军1,*   

  1. 1.北京物资学院 信息学院,北京101149
    2.航天恒星科技有限公司,北京100094
  • 收稿日期:2025-02-24 修回日期:2025-05-30 录用日期:2025-06-06 发布日期:2025-08-05 出版日期:2025-08-05

A trusted satellite access and transmission mechanism based on verification technology

DING Yi1,WANG Yang1,GUO Wenxin1,CHENG Zijing2,LI Jie1,JIN Jun1,*   

  1. 1.School of Information, Beijing Wuzi University, Beijing 101149, China
    2.Space Star Technology Co., Ltd., Beijing 100094, China
  • Received:2025-02-24 Revision received:2025-05-30 Accepted:2025-06-06 Online:2025-08-05 Published:2025-08-05

摘要: 卫星通信是现代通信网络的重要组成部分,其可信性对于保障信息的可靠、准确传输至关重要。面向卫星通信系统中的信道资源分配与关键信息传输领域,提出了一套可信的卫星接入与数据传输机制。首先,针对卫星信道资源稀缺带来的分配结果的信任问题,基于可验证技术构建信道分配策略执行验证模型,用以验证策略是否被正确实施;其次,针对遥感图像、导航定位等关键信息在传输过程中可能面临的篡改与攻击风险,基于可验证技术、加密与分布式安全传输等方法设计数据传输验证模型,加强传输数据的完整性与真实性。在模型设计的基础上,探索面向卫星通信系统的实例化设计,即:卫星信道分配系统和卫星数据安全传输系统,前者用于保障信道分配的公开透明与可验证性,后者则用于保障数据传输的安全性与准确性。安全性分析与试验结果表明,该机制能在仅增加少量计算开销的基础上有效抵御信道策略篡改、数据窃听、欺骗攻击等威胁,可以满足实际应用对安全性和效率的双重要求,为构建可信的卫星通信网络提供理论依据与实践示范。

关键词: 卫星通信, 可验证随机函数, 信道分配, 数据传输, 双重验证方法

Abstract: Satellite communication is an indispensable part of modern communication network, and its trustworthiness is essential to ensure the reliable and accurate transmission. This paper proposes a trusted satellite access and data transmission mechanism, aiming at the area of channel resource allocation and the transmission of critical information within satellite communication system. Firstly, to address the challenge of trust related to channel allocation caused by the scarcity of satellite resources, a verification model for the execution of channel allocation policy is constructed based on verifiable technology to verify whether the policy is executed correctly. Secondly, to mitigate the risks of tampering and attacks during the transmission of vital information such as remote sensing images and navigation data, a verifiable data transmission model is designed by using the methods of verifiable technology, encryption and distributed secure transmission, etc., thereby enhancing the integrity and authenticity of the transmitted data. On the basis of these models, instance designs for satellite communication system are explored: a satellite channel allocation system and a secure satellite data transmission system. The former ensures openness, transparency and verifiability of the channel allocation, while the latter ensures the security and accuracy of data transmission. Security analysis and experimental results show that the proposed mechanism can effectively detect such threats as policy tampering, data eavesdropping, and spoofing attacks, with only minimal computational overhead. The mechanism meets the dual requirements of security and efficiency in practical applications, providing both theoretical support and practical demonstration for building a trusted satellite communication network.

Key words: satellite communication, verifiable random function, channel allocation, data transmission, double verification method