WO2024041261A1 - 一种甚高频数据交换系统用户身份双向验证方法及系统 - Google Patents

一种甚高频数据交换系统用户身份双向验证方法及系统 Download PDF

Info

Publication number
WO2024041261A1
WO2024041261A1 PCT/CN2023/107338 CN2023107338W WO2024041261A1 WO 2024041261 A1 WO2024041261 A1 WO 2024041261A1 CN 2023107338 W CN2023107338 W CN 2023107338W WO 2024041261 A1 WO2024041261 A1 WO 2024041261A1
Authority
WO
WIPO (PCT)
Prior art keywords
station
ship
verification
random number
ship station
Prior art date
Application number
PCT/CN2023/107338
Other languages
English (en)
French (fr)
Inventor
耿丹阳
艾云飞
封令隽
于东伟
姚国栋
朱柯锦
于综洋
邓蕾
佘绍一
秦齐
孙东冶
孙雨萌
Original Assignee
中交信息技术国家工程实验室有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中交信息技术国家工程实验室有限公司 filed Critical 中交信息技术国家工程实验室有限公司
Publication of WO2024041261A1 publication Critical patent/WO2024041261A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0869Network architectures or network communication protocols for network security for authentication of entities for achieving mutual authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/06Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols the encryption apparatus using shift registers or memories for block-wise or stream coding, e.g. DES systems or RC4; Hash functions; Pseudorandom sequence generators
    • H04L9/0618Block ciphers, i.e. encrypting groups of characters of a plain text message using fixed encryption transformation
    • H04L9/0631Substitution permutation network [SPN], i.e. cipher composed of a number of stages or rounds each involving linear and nonlinear transformations, e.g. AES algorithms
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0861Generation of secret information including derivation or calculation of cryptographic keys or passwords
    • H04L9/0869Generation of secret information including derivation or calculation of cryptographic keys or passwords involving random numbers or seeds

Definitions

  • the present disclosure relates to the technical field of satellite communications, and in particular to a method and system for two-way verification of user identity in a very high frequency data exchange system.
  • VDES VHF Data Exchange System
  • ASM Automatic Identification System
  • VHF Data Exchange VDE
  • VDES Very High Frequency Data Exchange System
  • ASM Application Special Message
  • VDE Broadband Very High Frequency Data Exchange
  • AIS devices can configure parameters. By configuring the corresponding parameters, AIS will automatically and regularly broadcast, sending AIS messages such as position information, ship information, navigation information, etc. All AIS terminals within range that can receive. The ship can manually set the ship's AIS parameters that it edits, set the device to ship-related AIS information, and send it through AIS messages.
  • AIS In the existing technology, because AIS equipment does not require a card and only relies on manual settings, AIS has a serious problem of fraud. Parameters on the device can be entered and edited at will, resulting in many errors on the AIS big data platform, which hinders the supervision center from monitoring illegal ships and affects the legitimate rights and interests of legal ships.
  • VDES terminal can only send registration information to the shore station for verification within the coverage of the shore station, which severely limits the use environment of the ship.
  • the invention provides a very high frequency data exchange system user identity two-way verification method and system, which can verify the authenticity and legality of the ship's VDES terminal and ensure the safety of maritime navigation.
  • a two-way verification method for user identity of a VHF data exchange system including the following steps:
  • the shore station sends a random number to the ship station; and performs advanced encryption standard AES encryption calculation based on the random number to obtain comparison data;
  • the ship station performs AES encryption calculation based on the random number to obtain response data and sends it to the shore station;
  • the shore station will compare the response data received from the ship station with the comparison data; when the response data is consistent with the comparison data, it is confirmed that the ship station has passed the verification.
  • the method also includes:
  • the ship station sends its own maritime mobile service identification code MMSI and the random number together with the response data to the shore station;
  • the shore station simultaneously compares the received MMSI of the ship station with the saved MMSI of the ship station. MMSI, the received random number sent by the ship station and the saved random number.
  • the method also includes:
  • the shore station sends the random number to the ship station when the ship station initiates registration.
  • the ship station Before initiating registration, the ship station monitors the time division multiplexing TDMA channel for 1 minute to determine channel activity, other participating member identification IDs, current slot allocation, locations reported by other users and possible ship station information;
  • the ship station When the registration conditions are met, the ship station initiates the registration process; otherwise, it enters the unregistered working mode.
  • the method also includes:
  • Each ship station is assigned a corresponding identity recognition module; the ship station performs identity verification based on the identity recognition module.
  • the method also includes:
  • the receiving ship station When identity verification occurs between two ship stations, the receiving ship station generates the random number and sends it to the verification initiating ship station;
  • the verification initiating ship station performs AES encryption calculation according to the random number to obtain response data and sends the verification receiving ship station;
  • the verification receiving ship station compares the received response data with the comparison data obtained by performing AES encryption calculation based on the random number; when the response data is consistent with the comparison data, it confirms that the verification initiating ship station The site is verified.
  • the data sent by the ship station includes but is not limited to: message identification ID, network access device type, registration retention time, its own MMSI; or channel quality, response data, and AES key;
  • the shore station feedback data includes but is not limited to: message identification ID, channel quality, and random numbers.
  • a VHF data exchange system user identity two-way verification system including a shore station and a ship station, wherein,
  • the shore station is used to send a random number to the ship station; and perform advanced The encryption standard AES encryption calculation is used to obtain the comparison data; the response data received from the ship station is compared with the comparison data; when the response data is consistent with the comparison data, it is confirmed that the ship station has passed the verification;
  • the ship station is configured to perform AES encryption calculation based on the random number to obtain response data and send it to the shore station.
  • the ship station is also configured to send its own maritime mobile service identification code MMSI and the random number together with the response data to the shore station;
  • the shore station is also configured to simultaneously compare the received MMSI of the ship station with the saved MMSI of the ship station, and the received random number sent by the ship station and the saved random number.
  • the ship station is also used to generate the random number by the receiving ship station during identity verification between the two ship stations and send it to the verification initiating ship station; the verification initiating ship station The station performs AES encryption calculation based on the random number to obtain the response data and sends the verification receiving ship station; the verification receiving ship station compares the received response data with the ratio obtained by performing AES encryption calculation based on the random number. Compare the data; when the response data is consistent with the comparison data, it is confirmed that the verification initiator ship station has passed the verification.
  • Adopting the technical solution of the present invention a two-way verification scheme of user identity of the VHF data exchange system is proposed, which is suitable for the VDES satellite system.
  • the shore station sends a random number to the ship station; and the advanced encryption standard AES is performed based on the random number. Encryption calculation is performed to obtain comparison data; the ship station performs AES encryption calculation according to the random number to obtain response data and sends it to the shore station; the shore station will receive the response data returned by the ship station and compare it with the comparison data. Data comparison; when the response data is consistent with the comparison data, it is confirmed that the ship station has passed the verification.
  • the solution proposed by the present invention by adding the two-way verification function and the verification function of the VDES terminal for the VSIM card, the three-in-one system of man, machine and card is ensured, and the risks caused by wrong and counterfeit cards are reduced.
  • the verification code is verified.
  • Figure 1 is a principle flow chart of a two-way verification method for user identity in a VHF data exchange system according to an exemplary embodiment
  • Figure 2 is a schematic diagram of the work flow after the device is turned on according to an exemplary embodiment
  • Figure 3 is a flow chart of automatic registration of a ship station according to an exemplary embodiment
  • Figure 4 is a flow chart of automatic registration at a shore station according to an exemplary embodiment
  • Figure 5 is a schematic structural diagram of a two-way user identity verification system of a VHF data exchange system according to an exemplary embodiment.
  • Figure 6 is a schematic structural diagram of a user equipment according to an exemplary embodiment.
  • first, second, third, etc. may be used to describe various information in the embodiments of the present disclosure, the information should not be limited to these terms. These terms are only used to distinguish information of the same type from each other.
  • first information may also be called second information, and similarly, the second information may also be called first information.
  • word “if” as used herein may be interpreted as "when” or "when” or "in response to determining.”
  • a VDES device with a two-way identity verification function and an implementation method are proposed.
  • the method adds the two-way verification function of the registration center and the VDES terminal to the virtual subscriber identity module (VSIM).
  • VSIM virtual subscriber identity module
  • the card verification function ensures that people, machines and cards are integrated into one, reducing the risks caused by wrong or fake cards.
  • the ship can still determine whether the other party's VSIM card information is authentic based on the algorithm even when leaving the shore station.
  • VSIM is Virtual-SIM, virtual SIM card technology. Specifically refers to a method that does not have a physical SIM card and relies entirely on the communication module's own software and hardware to achieve network connection.
  • FIG. 1 is a flow chart of two-way verification of user identity in the VHF data exchange system in Embodiment 1 of the present invention. As shown in Figure 1, the two-way user identity verification process of the VHF data exchange system includes the following steps:
  • Step 101 The shore station sends a random number to the ship station; and performs advanced encryption standard AES encryption calculation based on the random number to obtain comparison data.
  • the registration process will be initiated.
  • the ship station monitors the TDMA channel for 1 minute to determine channel activity, other participating member IDs, current slot assignments and locations reported by other users, and possible base stations. During this time, a dynamic catalog of all operating members in the system should be established. should be constructed A frame diagram reflecting time division multiple access channel activity. After one minute, it checks whether the registration conditions are met. If there is a suitable shore station, the ship station sends an ASM message to initiate the registration process; otherwise, it enters the unregistered working mode.
  • FIG 2 it is a schematic diagram of the work flow after the device is turned on in the embodiment of the present invention.
  • Figure 3 it is a flow chart of automatic registration of ships (ship stations) in the embodiment of the present invention.
  • each ship station is assigned a corresponding identity recognition module; the ship station performs identity verification based on the identity recognition module.
  • Step 102 The ship station performs AES encryption calculation based on the random number to obtain response data and sends it to the shore station.
  • the ship station sends its own maritime mobile service identification code MMSI and the random number together with the response data to the shore station;
  • the shore station simultaneously compares the received MMSI of the ship station with the saved MMSI of the ship station, and the received random number sent by the ship station and the saved random number.
  • the shore station sends the random number to the ship station when the ship station initiates registration.
  • the ship station before initiating registration, the ship station monitors the time division multiplexing TDMA channel for 1 minute to determine channel activity, other participating member identification IDs, current slot allocation, locations reported by other users and possible Existing ship station information;
  • the ship station When the registration conditions are met, the ship station initiates the registration process; otherwise, it enters the unregistered working mode.
  • Step 103 The shore station compares the response data returned by the ship station with the comparison data; when the response data is consistent with the comparison data, it is confirmed that the ship station has passed the verification.
  • the receiving ship station when identity verification occurs between two ship stations, the receiving ship station generates the random number and sends the verification initiating ship station;
  • the verification initiator ship station performs AES encryption calculation based on the random number to obtain response data. and send the verification to the receiving ship station;
  • the verification receiving ship station compares the received response data with the comparison data obtained by performing AES encryption calculation based on the random number; when the response data is consistent with the comparison data, it confirms that the verification initiating ship station The site is verified.
  • the data sent by the ship station includes but is not limited to: message identification ID, network access device type, registration retention time, its own MMSI; or channel quality, response data, and AES key;
  • the shore station feedback data includes but is not limited to: message identification ID, channel quality, and random numbers.
  • the embodiment of the present invention proposes a VDES device with two-way identity verification function and an implementation method.
  • This method can verify the authenticity of the ship's VDES terminal offline by allowing the ship to perform calculations using the AES encryption algorithm and random numbers at sea. and legality verification, ensuring the safety of maritime navigation to a certain extent.
  • the ship station needs to send registration information to the shore station, and the shore station will feedback a random number to the ship station.
  • the ship station will perform a 16-bit key Advanced Encryption Standard (AES) encryption algorithm based on the random number.
  • AES Advanced Encryption Standard
  • the response data is calculated by calculating the ship's own Maritime Mobile Service Identify (MMSI) and the random number sent by the shore station and sending it to the shore station.
  • MMSI Maritime Mobile Service Identify
  • the shore station will also compare the response data sent by the ship based on the ship's MMSI, the random number sent and the calculated response data. When the response data calculated by the two are the same, the ship's VSIM card is a genuine card, and the registration is determined to be successful.
  • the shore station will forward the ship station's registration information to the registration center and save it.
  • the sender ship sends the registration information to the receiver ship, and the receiver will send a random The machine number is returned to the sender.
  • the sender needs to use the 16-bit key AES encryption algorithm to calculate a new response data based on this random number and the relevant information of the ship itself, and send the response data and the ship's own information to the receiver together.
  • the data that the registrant needs to provide includes: message ID, network access device type, registration retention time, and International Mobile Subscriber Identification Number (IMSI).
  • the feedback data received by the registrant includes: message ID, channel quality, and random data.
  • the verification data returned by the ship includes: message ID, channel quality, response data, and key.
  • the message ID must correspond to be recognized as the corresponding registration and feedback message.
  • FIG. 4 it is a flow chart for automatic registration of a shore station provided by an embodiment of the present invention.
  • the technical solution of the present invention also provides a two-way verification system for the user identity of the VHF data exchange system.
  • the two-way verification system for the user identity of the VHF data exchange system includes a shore station 21 and a ship station 22. in,
  • the shore station 21 is used to send a random number to the ship station; and perform advanced encryption standard AES encryption calculation according to the random number to obtain comparison data; and compare the response data received from the ship station 22 with the comparison data. Compare the data; when the response data is consistent with the comparison data, it is confirmed that the ship station 22 has passed the verification;
  • the ship station 22 is configured to perform AES encryption calculation based on the random number to obtain response data and send it to the shore station 21 .
  • the ship station 22 is also configured to send its own maritime mobile service identification code MMSI and the random number together with the response data to the shore station 21;
  • the shore station 21 is also used to simultaneously compare the received MMSI of the ship station 22 with the saved The MMSI of the ship station 22, the received random number sent by the ship station 22 and the saved random number.
  • the ship station 22 is also used to generate the random number by the receiving ship station 22 during identity verification between the two ship stations 22, and send it to the verification initiating ship station 22;
  • the verification initiating ship station 22 performs AES encryption calculation according to the random number to obtain the response data and sends it to the verification receiving ship station 22;
  • the verification receiving ship station 22 compares the received response data with its own according to the random number. Compare the comparison data obtained by AES encryption calculation; when the response data is consistent with the comparison data, it is confirmed that the verification initiator ship station 22 has passed the verification.
  • the technical solution of the present invention proposes a two-way verification scheme for the user identity of the VHF data exchange system, and proposes a two-way verification scheme for the user identity of the VHF data exchange system, which is suitable for VDES satellite systems, shore
  • the station sends a random number to the ship station; and performs advanced encryption standard AES encryption calculation based on the random number to obtain comparison data; the ship station performs AES encryption calculation based on the random number to obtain response data and sends it to the shore station;
  • the shore station will compare the response data received from the ship station with the comparison data; when the response data is consistent with the comparison data, it is confirmed that the ship station has passed the verification.
  • the solution proposed by the present invention by adding the two-way verification function and the verification function of the VDES terminal for the VSIM card, the three-in-one system of man, machine and card is ensured, and the risks caused by wrong and counterfeit cards are reduced.
  • the verification code is verified.
  • Figure 6 is a block diagram of a user equipment 8000 according to an exemplary embodiment.
  • the user device 8000 may be a mobile phone, a computer, a digital broadcast terminal, a messaging device, a game console, a tablet device, a medical device, a fitness device, a personal digital assistant, or the like.
  • user equipment 8000 may include one or more of the following components: a processing component 8002, memory 8004, power supply component 8006, multimedia component 8008, audio component 8010, input/output (I/O) interface 8012, sensor component 8014, and communication component 8016.
  • Processing component 8002 generally controls the overall operations of user device 8000, such as operations associated with display, phone calls, data communications, camera operations, and recording operations.
  • the processing component 8002 may include one or more processors 8020 to execute instructions to complete all or part of the steps of the above method.
  • processing component 8002 may include one or more modules that facilitate interaction between processing component 8002 and other components.
  • processing component 8002 may include a multimedia module to facilitate interaction between multimedia component 8008 and processing component 8002.
  • Memory 8004 is configured to store various types of data to support operations at device 8000. Examples of such data include instructions for any application or method operating on the user device 8000, contact data, phonebook data, messages, pictures, videos, etc.
  • Memory 8004 may be implemented by any type of volatile or non-volatile storage device, or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EEPROM), Programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic or optical disk.
  • SRAM static random access memory
  • EEPROM electrically erasable programmable read-only memory
  • EEPROM erasable programmable read-only memory
  • EPROM Programmable read-only memory
  • PROM programmable read-only memory
  • ROM read-only memory
  • magnetic memory flash memory, magnetic or optical disk.
  • Power supply component 8006 provides power to various components of user equipment 8000.
  • Power supply components 8006 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to user device 8000.
  • Multimedia component 8008 includes a screen that provides an output interface between user device 8000 and the user.
  • the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen may be implemented as a touch screen to receive input signals from the user.
  • the touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. A touch sensor can not only sense the boundaries of a touch or swipe action, but also detect the duration and pressure associated with the touch or swipe action.
  • multimedia component 8008 includes a front-facing camera and/or a rear-facing camera. When device 8000 is in In operating modes, such as shooting mode or video mode, the front camera and/or rear camera can receive external multimedia data.
  • Each front-facing camera and rear-facing camera can be a fixed optical lens system or have a focal length and optical zoom capabilities.
  • Audio component 8010 is configured to output and/or input audio signals.
  • audio component 8010 includes a microphone (MIC) configured to receive external audio signals when user device 8000 is in operating modes, such as call mode, recording mode, and speech recognition mode. The received audio signal may be further stored in memory 8004 or sent via communications component 8016 .
  • audio component 8010 also includes a speaker for outputting audio signals.
  • the I/O interface 8012 provides an interface between the processing component 8002 and a peripheral interface module.
  • the peripheral interface module may be a keyboard, a click wheel, a button, etc. These buttons may include, but are not limited to: Home button, Volume buttons, Start button, and Lock button.
  • Sensor component 8014 includes one or more sensors that provide various aspects of status assessment for user device 8000 .
  • the sensor component 8014 can detect the open/closed state of the device 8000, the relative positioning of components, such as the display and keypad of the user device 8000, and the sensor component 8014 can also detect the position of the user device 8000 or a component of the user device 8000. changes, the presence or absence of user contact with user device 8000, user device 8000 orientation or acceleration/deceleration and temperature changes of user device 8000.
  • Sensor component 8014 may include a proximity sensor configured to detect the presence of nearby objects without any physical contact.
  • Sensor assembly 8014 may also include a light sensor, such as a CMOS or CCD image sensor, for use in imaging applications.
  • the sensor component 8014 may also include an acceleration sensor, a gyroscope sensor, a magnetic sensor, a pressure sensor, or a temperature sensor.
  • the communication component 8016 is configured to facilitate wired or wireless communication between the user device 8000 and other devices.
  • User equipment 8000 may access a wireless network based on a communication standard, such as Wi-Fi, 2G or 3G, or a combination thereof.
  • the communication component 8016 receives broadcast signals or broadcast related information from an external broadcast management system via a broadcast channel. in a display
  • communications component 8016 also includes a near field communications (NFC) module to facilitate short-range communications.
  • NFC near field communications
  • the NFC module can be implemented based on radio frequency identification (RFID) technology, infrared data association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology and other technologies.
  • RFID radio frequency identification
  • IrDA infrared data association
  • UWB ultra-wideband
  • Bluetooth Bluetooth
  • user equipment 8000 may be configured by one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable Programming gate array (FPGA), controller, microcontroller, microprocessor or other electronic components are implemented for executing the steps of the above information indication method.
  • ASICs application specific integrated circuits
  • DSPs digital signal processors
  • DSPDs digital signal processing devices
  • PLDs programmable logic devices
  • FPGA field programmable Programming gate array
  • controller microcontroller, microprocessor or other electronic components are implemented for executing the steps of the above information indication method.
  • non-transitory computer-readable storage medium including instructions, such as a memory 8004 including instructions, which can be executed by the processor 8020 of the user device 8000 to complete the steps of the above information indicating method is also provided.
  • non-transitory computer-readable storage media may be ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, optical data storage device, etc.
  • An embodiment of the present disclosure also describes a network device, which includes a processor, a transceiver, a memory, and an executable program stored in the memory and capable of being run by the processor.
  • a network device which includes a processor, a transceiver, a memory, and an executable program stored in the memory and capable of being run by the processor.
  • the processor runs the executable program.
  • the information of the preceding embodiments indicates the steps of the method.
  • An embodiment of the present disclosure also describes a user equipment, which includes a processor, a transceiver, a memory, and an executable program stored in the memory and capable of being run by the processor. When the processor runs the executable program, it is executed.
  • the information of the preceding embodiments indicates the steps of the method.
  • Embodiments of the present disclosure also record a storage medium on which an executable program is stored, and the executable program is executed by a processor in the steps of the information indicating method of the foregoing embodiments.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本发明公开了一种甚高频数据交换系统用户身份双向验证方法及系统,该方法适用于VDES卫星系统,岸站向船站发送一个随机数;并根据所述随机数进行高级加密标准AES加密计算得到比对数据;所述船站根据所述随机数进行AES加密计算得到响应数据并发送所述岸站;所述岸站将接收到所述船站返回的响应数据与所述比对数据对比;当所述响应数据与比对数据一致时,确认所述船站通过验证。本发明提出的方案中,通过让船舶在海上通过AES加密算法和随机数进行计算,可以在离线情况下对船舶VDES终端的真实性和合法性进行验证,一定程度上保障了海上航行的安全。

Description

一种甚高频数据交换系统用户身份双向验证方法及系统 技术领域
本公开涉及卫星通信技术领域,特别涉及一种甚高频数据交换系统用户身份双向验证方法系统。
背景技术
甚高频数据交换系统(VHF Data Exchange System,VDES)是船舶自动识别系统(Automatic Identification System,AIS)加强和升级版系统,集成现有AIS功能,并增加了特殊应用报文(Application-specific messages,ASM)和宽带甚高频数据交换(VHF Data Exchange,VDE)功能,可有效缓解现有AIS数据通信的压力,满足船对船、船对岸、船对卫星、岸对卫星相互之间的所有数据交换服务的需要,属于第三代海事通信系统。
随着水上数据通信需求的不断提升,AIS也逐渐承担起船岸数据通信的任务。AIS在VHF频段通信需求增加导致AIS可使用频段内非常拥挤,许多繁忙港口已经达到对频段50%以上占用率。国际电信联盟2015年世界无线电通信大会(WRC—15)决定在水上移动业务领域引入甚高频数据交换系统(VDES)。VDES集成了AIS、特殊应用报文(ASM)和宽带甚高频数据交换(VDE)三项功能,能在保护现有AIS功能的基础上,通过引入ASM和VDE全面强化船舶通信的数据传输能力。
中国是海洋大国,90%的进出口货物通过海上运输,因此海上交通的安全和通信至关重要。在海上通信过程中,只满足于一定范围内的短距离通信是不够的,能够建立出一个海上基站通信网络的需求越来越明确。
AIS设备可以配置参数。通过配置相应的参数,AIS将会自动的、定期的进行广播,发送诸如位置信息、船舶信息、航行信息等AIS报文消息给 范围内全部可以接收的AIS终端。船舶可以手动设置自己编辑的船舶AIS参数,将该设备设置为船舶相关AIS信息,并通过AIS报文发送。
现有技术中,由于AIS设备不需要卡,仅靠手动设置,因此AIS存在很严重的造假问题。在设备上的参数是可以任意输入并编辑的,导致在AIS大数据平台上存在很多错误情况,妨碍了监管中心对非法船只的监控,同时影响了合法船只的合法权益。
即便是将数据写入终端,在离开港口岸站的覆盖范围之后,也很难做到验证卡的真实性与合法性。现有的VDES终端只能在岸站覆盖的范围内,通过将注册信息发送至岸站进行校验,严重限制了船舶的使用环境。
发明内容
本发明提供一种甚高频数据交换系统用户身份双向验证方法及系统,能够对船舶VDES终端的真实性和合法性进行验证,保障了海上航行的安全。
根据本发明的一个方面,提供了一种甚高频数据交换系统用户身份双向验证方法,包括以下步骤:
岸站向船站发送一个随机数;并根据所述随机数进行高级加密标准AES加密计算得到比对数据;
所述船站根据所述随机数进行AES加密计算得到响应数据并发送所述岸站;
所述岸站将接收到所述船站返回的响应数据与所述比对数据对比;当所述响应数据与比对数据一致时,确认所述船站通过验证。
所述方法还包括:
所述船站将自身的水上移动业务标识码MMSI、所述随机数随同所述响应数据一同发送所述岸站;
所述岸站同时比对接收到的所述船站的MMSI与保存的所述船站的 MMSI、接收到的所述船站发送的随机数与保存的随机数。
所述方法还包括:
所述岸站在所述船站发起注册时向所述船站发送所述随机数。
所述船站在发起注册前,监测时分复用TDMA信道1分钟,确定信道活动、其它参与的成员标识ID、当前插槽分配、其它用户报告的位置及可能存在的船站信息;
当具备注册条件时,所述船站发起注册流程;否则,进入未注册工作模式。
所述方法还包括:
为每个所述船站分配对应的身份识别模块;所述船站根据所述身份识别模块进行身份验证。
所述方法还包括:
当两个所述船站之间身份验证时,由其中的验接收方船站生成所述随机数,并发送所述验证发起方船站;
所述验证发起方船站根据所述随机数进行AES加密计算得到响应数据并发送所述验证接收方船站;
所述验证接收方船站将接收到的响应数据与自身根据所述随机数进行AES加密计算得到的比对数据对比;当所述响应数据与比对数据一致时,确认所述验证发起方船站通过验证。
所述船站发送数据包括但不限于:消息标识ID、入网设备类型、注册保持时间、自身的MMSI;或信道质量、响应数据、AES密钥;
所述岸站反馈数据包括但不限于:消息标识ID、信道质量、随机数。
根据本发明的另一个方面,提供了一种甚高频数据交换系统用户身份双向验证系统,包括岸站和船站,其中,
所述岸站,用于向船站发送一个随机数;并根据所述随机数进行高级 加密标准AES加密计算得到比对数据;将接收到所述船站返回的响应数据与所述比对数据对比;当所述响应数据与比对数据一致时,确认所述船站通过验证;
所述船站,用于根据所述随机数进行AES加密计算得到响应数据并发送所述岸站。
所述船站还用于将自身的水上移动业务标识码MMSI、所述随机数随同所述响应数据一同发送所述岸站;
所述岸站还用于同时比对接收到的所述船站的MMSI与保存的所述船站的MMSI、接收到的所述船站发送的随机数与保存的随机数。
所述船站还用于当两个所述船站之间身份验证时,由其中的验接收方船站生成所述随机数,并发送所述验证发起方船站;所述验证发起方船站根据所述随机数进行AES加密计算得到响应数据并发送所述验证接收方船站;所述验证接收方船站将接收到的响应数据与自身根据所述随机数进行AES加密计算得到的比对数据对比;当所述响应数据与比对数据一致时,确认所述验证发起方船站通过验证。
采用本发明的技术方案,提出了一种甚高频数据交换系统用户身份双向验证方案,适用于VDES卫星系统,岸站向船站发送一个随机数;并根据所述随机数进行高级加密标准AES加密计算得到比对数据;所述船站根据所述随机数进行AES加密计算得到响应数据并发送所述岸站;所述岸站将接收到所述船站返回的响应数据与所述比对数据对比;当所述响应数据与比对数据一致时,确认所述船站通过验证。
本发明提出的方案中,通过加入双向验证功能和VDES终端对VSIM卡的验证功能,保证了人、机、卡三合一,降低了错卡、假卡带来的风险。通过将全部VDES终端的加入AES加密算法,并通过随机数和船舶信息进行加密运算得到验证码,对验证码进行校验。通过让船舶在海上通过AES 加密算法和随机数进行计算,可以在离线情况下对船舶VDES终端的真实性和合法性进行验证,一定程度上保障了海上航行的安全。
下面通过附图和实施例,对本发明的技术方案做进一步的详细描述。
附图说明
此处的附图被并入说明书中并构成本说明书的一部分,示出了符合本发明实施例,并与说明书一起用于解释本发明实施例的原理。
图1是根据一示例性实施例示出的甚高频数据交换系统用户身份双向验证方法原理流程图;
图2是根据一示例性实施例示出的设备开机后的工作流程示意图;
图3是根据一示例性实施例示出的船站自动注册流程图;
图4是根据一示例性实施例示出的岸站自动注册流程图;
图5是根据一示例性实施例示出的甚高频数据交换系统用户身份双向验证系统结构示意图。
图6是根据一示例性实施例示出的一种用户设备的组成结构示意图。
具体实施方式
这里将详细地对示例性实施例进行说明,其示例表示在附图中。下面的描述涉及附图时,除非另有表示,不同附图中的相同数字表示相同或相似的要素。以下示例性实施例中所描述的实施方式并不代表与本公开实施例相一致的所有实施方式。相反,它们仅是与如所附权利要求书中所详述的、本公开实施例的一些方面相一致的装置和方法的例子。
在本公开实施例使用的术语是仅仅出于描述特定实施例的目的,而非旨在限制本公开实施例。在本公开实施例和所附权利要求书中所使用的单数形式的“一种”、“所述”和“该”也旨在包括多数形式,除非上下文清楚地表示其他含义。还应当理解,本文中使用的术语“和/或”是指并包含 一个或多个相关联的列出项目的任何或所有可能组合。
应当理解,尽管在本公开实施例可能采用术语第一、第二、第三等来描述各种信息,但这些信息不应限于这些术语。这些术语仅用来将同一类型的信息彼此区分开。例如,在不脱离本公开实施例范围的情况下,第一信息也可以被称为第二信息,类似地,第二信息也可以被称为第一信息。取决于语境,如在此所使用的词语“如果”可以被解释成为“在……时”或“当……时”或“响应于确定”。
本发明各个实施例中,提出了一种具备身份双向验证功能的VDES设备及实现方法,该方法通过加入注册中心的双向验证功能和VDES终端对虚拟用户身份识别模块(virtual Subscriber Identity Module,VSIM)卡的验证功能,保证了人、机、卡三合一,降低了错卡、假卡带来的风险。通过加入虚拟用户身份识别模块(virtual Subscriber Identity Module,VSIM)卡内部验真算法,使得在离开岸站的环境下,船舶依然可以根据算法判断对方的VSIM卡信息是否为真。
VSIM即Virtual-SIM,虚拟SIM卡技术。特指没有实体SIM卡,完全靠通信模块的自身软硬件实现网络连接的方式。
图1为本发明实施例一中甚高频数据交换系统用户身份双向验证流程图。如图1所示,该甚高频数据交换系统用户身份双向验证流程包括以下步骤:
步骤101、岸站向船站发送一个随机数;并根据所述随机数进行高级加密标准AES加密计算得到比对数据。
在本发明的一个实施例中,VSIM卡插入VDES设备终端并上电开机后,将会发起注册流程。船站会监测TDMA信道1分钟,以确定信道活动、其他参与的成员ID、当前插槽分配和其他用户报告的位置,以及可能存在的基站。在此期间,应该建立系统中所有操作成员的动态目录。应该构造 一个反映时分多址信道活动的帧图。一分钟后,检测是否具备注册条件,若存在合适的岸站,则船站发送ASM消息发起注册流程;否则进入未注册工作模式。
如图2所示,为本发明实施例中设备开机后的工作流程示意图。如图3所示,为本发明实施例中船舶(船站)自动注册流程图。
在本发明的一个实施例中,为每个所述船站分配对应的身份识别模块;所述船站根据所述身份识别模块进行身份验证。
步骤102,所述船站根据所述随机数进行AES加密计算得到响应数据并发送所述岸站。
在本发明的一个实施例中,所述船站将自身的水上移动业务标识码MMSI、所述随机数随同所述响应数据一同发送所述岸站;
所述岸站同时比对接收到的所述船站的MMSI与保存的所述船站的MMSI、接收到的所述船站发送的随机数与保存的随机数。
在本发明的一个实施例中,所述岸站在所述船站发起注册时向所述船站发送所述随机数。
在本发明的一个实施例中,所述船站在发起注册前,监测时分复用TDMA信道1分钟,确定信道活动、其它参与的成员标识ID、当前插槽分配、其它用户报告的位置及可能存在的船站信息;
当具备注册条件时,所述船站发起注册流程;否则,进入未注册工作模式。
步骤103,岸站将接收到所述船站返回的响应数据与所述比对数据对比;当所述响应数据与比对数据一致时,确认所述船站通过验证。
在本发明的一个实施例中,当两个所述船站之间身份验证时,由其中的验接收方船站生成所述随机数,并发送所述验证发起方船站;
所述验证发起方船站根据所述随机数进行AES加密计算得到响应数据 并发送所述验证接收方船站;
所述验证接收方船站将接收到的响应数据与自身根据所述随机数进行AES加密计算得到的比对数据对比;当所述响应数据与比对数据一致时,确认所述验证发起方船站通过验证。
所述船站发送数据包括但不限于:消息标识ID、入网设备类型、注册保持时间、自身的MMSI;或信道质量、响应数据、AES密钥;
所述岸站反馈数据包括但不限于:消息标识ID、信道质量、随机数。
具体的,本发明实施例提出了具备身份双向验证功能的VDES设备及实现方法,该方法通过让船舶在海上通过AES加密算法和随机数进行计算,可以在离线情况下对船舶VDES终端的真实性和合法性进行验证,一定程度上保障了海上航行的安全。
在注册过程中,船站需要给岸站发送注册信息,岸站会反馈给船站一个随机数,船站根据随机数进行16位密钥的高级加密标准(Advanced Encryption Standard,AES)加密算法,将船舶自己水上移动通信业务标识码(Maritime Mobile Service Identify,MMSI)、岸站发送的随机数和计算得出响应数据并发送给岸站。同时,岸站也会根据该船舶MMSI、发送的随机数和计算得出的响应数据与船舶发送的响应数据进行对比。当两者计算得出的响应数据一样时,则该船舶的VSIM卡为真卡,判断为注册成功,岸站将船站的注册信息转发至注册中心并保存。
当船舶在大海上,无法与岸站建立通信的时候,两艘船舶相遇,将会互相发送注册信息给对方。先发送注册信息的船舶将会被视为设置为船站,后发送注册消息的船舶则会被视为岸站,将船-船之间通信等价为船-岸之间通信,不同的是这些注册信息不会发送给注册中心,仅用来进行船舶之间的通信。
发送方船舶将注册信息发送至接收方船舶,这时接收方会发送一个随 机数返回给发送方。发送方需要根据这个随机数及船舶本身的相关信息,使用16位密钥AES加密算法,计算出一个新的响应数据,并将响应数据和船舶本身信息一同发送给接收方。接收方船舶得到信息后,根据发送方船舶提供的船舶信息、随机数,根据AES加密算法计算出响应数据,并通过对两个响应数据的比较,判断是否一致。如果一致,则认为对方船舶合法,可以使用VDES功能。如果不一致,则认为对方船舶卡为非法卡,不可使用这些VDES功能。
注册时,注册方需要提供的数据包括:消息ID、入网设备类型、注册保持时间、国际用户识别码(International Mobile Subscriber Identification Number,IMSI)。注册方接收到的反馈数据包括:消息ID、信道质量、随机数据。船舶回复的验证数据包括:消息ID、信道质量、响应数据、密钥。其中消息ID必须对应才会被识别为对应的注册及反馈消息。
如图4所示,为本发明实施例提供的岸站自动注册流程图。
为了实现上述流程,本发明技术方案还提供甚高频数据交换系统用户身份双向验证系统,如图5所示,该甚高频数据交换系统用户身份双向验证系统包括岸站21和船站22,其中,
所述岸站21,用于向船站发送一个随机数;并根据所述随机数进行高级加密标准AES加密计算得到比对数据;将接收到所述船站22返回的响应数据与所述比对数据对比;当所述响应数据与比对数据一致时,确认所述船站22通过验证;
所述船站22,用于根据所述随机数进行AES加密计算得到响应数据并发送所述岸站21。
所述船站22还用于将自身的水上移动业务标识码MMSI、所述随机数随同所述响应数据一同发送所述岸站21;
所述岸站21还用于同时比对接收到的所述船站22的MMSI与保存的 所述船站22的MMSI、接收到的所述船站22发送的随机数与保存的随机数。
所述船站22还用于当两个所述船站22之间身份验证时,由其中的验接收方船站22生成所述随机数,并发送所述验证发起方船站22;所述验证发起方船站22根据所述随机数进行AES加密计算得到响应数据并发送所述验证接收方船站22;所述验证接收方船站22将接收到的响应数据与自身根据所述随机数进行AES加密计算得到的比对数据对比;当所述响应数据与比对数据一致时,确认所述验证发起方船站22通过验证。
综上所述,本发明的技术方案,提出了一种甚高频数据交换系统用户身份双向验证方案,提出了一种甚高频数据交换系统用户身份双向验证方案,适用于VDES卫星系统,岸站向船站发送一个随机数;并根据所述随机数进行高级加密标准AES加密计算得到比对数据;所述船站根据所述随机数进行AES加密计算得到响应数据并发送所述岸站;所述岸站将接收到所述船站返回的响应数据与所述比对数据对比;当所述响应数据与比对数据一致时,确认所述船站通过验证。
本发明提出的方案中,通过加入双向验证功能和VDES终端对VSIM卡的验证功能,保证了人、机、卡三合一,降低了错卡、假卡带来的风险。通过将全部VDES终端的加入AES加密算法,并通过随机数和船舶信息进行加密运算得到验证码,对验证码进行校验。通过让船舶在海上通过AES加密算法和随机数进行计算,可以在离线情况下对船舶VDES终端的真实性和合法性进行验证,一定程度上保障了海上航行的安全。
图6是根据一示例性实施例示出的一种用户设备8000的框图。例如,用户设备8000可以是移动电话,计算机,数字广播终端,消息收发设备,游戏控制台,平板设备,医疗设备,健身设备,个人数字助理等。
参照图6,用户设备8000可以包括以下一个或多个组件:处理组件 8002,存储器8004,电源组件8006,多媒体组件8008,音频组件8010,输入/输出(I/O)的接口8012,传感器组件8014,以及通信组件8016。
处理组件8002通常控制用户设备8000的整体操作,诸如与显示,电话呼叫,数据通信,相机操作和记录操作相关联的操作。处理组件8002可以包括一个或多个处理器8020来执行指令,以完成上述的方法的全部或部分步骤。此外,处理组件8002可以包括一个或多个模块,便于处理组件8002和其他组件之间的交互。例如,处理组件8002可以包括多媒体模块,以方便多媒体组件8008和处理组件8002之间的交互。
存储器8004被配置为存储各种类型的数据以支持在设备8000的操作。这些数据的示例包括用于在用户设备8000上操作的任何应用程序或方法的指令,联系人数据,电话簿数据,消息,图片,视频等。存储器8004可以由任何类型的易失性或非易失性存储设备或者它们的组合实现,如静态随机存取存储器(SRAM),电可擦除可编程只读存储器(EEPROM),可擦除可编程只读存储器(EPROM),可编程只读存储器(PROM),只读存储器(ROM),磁存储器,快闪存储器,磁盘或光盘。
电源组件8006为用户设备8000的各种组件提供电力。电源组件8006可以包括电源管理系统,一个或多个电源,及其他与为用户设备8000生成、管理和分配电力相关联的组件。
多媒体组件8008包括在用户设备8000和用户之间的提供一个输出接口的屏幕。在一些实施例中,屏幕可以包括液晶显示器(LCD)和触摸面板(TP)。如果屏幕包括触摸面板,屏幕可以被实现为触摸屏,以接收来自用户的输入信号。触摸面板包括一个或多个触摸传感器以感测触摸、滑动和触摸面板上的手势。触摸传感器可以不仅感测触摸或滑动动作的边界,而且还检测与触摸或滑动操作相关的持续时间和压力。在一些实施例中,多媒体组件8008包括一个前置摄像头和/或后置摄像头。当设备8000处于 操作模式,如拍摄模式或视频模式时,前置摄像头和/或后置摄像头可以接收外部的多媒体数据。每个前置摄像头和后置摄像头可以是一个固定的光学透镜系统或具有焦距和光学变焦能力。
音频组件8010被配置为输出和/或输入音频信号。例如,音频组件8010包括一个麦克风(MIC),当用户设备8000处于操作模式,如呼叫模式、记录模式和语音识别模式时,麦克风被配置为接收外部音频信号。所接收的音频信号可以被进一步存储在存储器8004或经由通信组件8016发送。在一些实施例中,音频组件8010还包括一个扬声器,用于输出音频信号。
I/O接口8012为处理组件8002和外围接口模块之间提供接口,上述外围接口模块可以是键盘,点击轮,按钮等。这些按钮可包括但不限于:主页按钮、音量按钮、启动按钮和锁定按钮。
传感器组件8014包括一个或多个传感器,用于为用户设备8000提供各个方面的状态评估。例如,传感器组件8014可以检测到设备8000的打开/关闭状态,组件的相对定位,例如组件为用户设备8000的显示器和小键盘,传感器组件8014还可以检测用户设备8000或用户设备8000一个组件的位置改变,用户与用户设备8000接触的存在或不存在,用户设备8000方位或加速/减速和用户设备8000的温度变化。传感器组件8014可以包括接近传感器,被配置用来在没有任何的物理接触时检测附近物体的存在。传感器组件8014还可以包括光传感器,如CMOS或CCD图像传感器,用于在成像应用中使用。在一些实施例中,该传感器组件8014还可以包括加速度传感器,陀螺仪传感器,磁传感器,压力传感器或温度传感器。
通信组件8016被配置为便于用户设备8000和其他设备之间有线或无线方式的通信。用户设备8000可以接入基于通信标准的无线网络,如Wi-Fi,2G或3G,或它们的组合。在一个示例性实施例中,通信组件8016经由广播信道接收来自外部广播管理系统的广播信号或广播相关信息。在一个示 例性实施例中,通信组件8016还包括近场通信(NFC)模块,以促进短程通信。例如,在NFC模块可基于射频识别(RFID)技术,红外数据协会(IrDA)技术,超宽带(UWB)技术,蓝牙(BT)技术和其他技术来实现。
在示例性实施例中,用户设备8000可以被一个或多个应用专用集成电路(ASIC)、数字信号处理器(DSP)、数字信号处理设备(DSPD)、可编程逻辑器件(PLD)、现场可编程门阵列(FPGA)、控制器、微控制器、微处理器或其他电子元件实现,用于执行上述信息指示方法的步骤。
在示例性实施例中,还提供了一种包括指令的非临时性计算机可读存储介质,例如包括指令的存储器8004,上述指令可由用户设备8000的处理器8020执行以完成上述信息指示方法的步骤。例如,非临时性计算机可读存储介质可以是ROM、随机存取存储器(RAM)、CD-ROM、磁带、软盘和光数据存储设备等。
本公开实施例还记载了一种网络设备,包括处理器、收发器、存储器及存储在存储器上并能够由所述处理器运行的可执行程序,所述处理器运行所述可执行程序时执行前述实施例的信息指示方法的步骤。
本公开实施例还记载了一种用户设备,包括处理器、收发器、存储器及存储在存储器上并能够由所述处理器运行的可执行程序,所述处理器运行所述可执行程序时执行前述实施例的信息指示方法的步骤。
本公开实施例还记载了一种存储介质,其上存储由可执行程序,所述可执行程序被处理器执行前述实施例的信息指示方法的步骤。
本领域技术人员在考虑说明书及实践这里公开的发明后,将容易想到本发明实施例的其它实施方案。本申请旨在涵盖本发明实施例的任何变型、用途或者适应性变化,这些变型、用途或者适应性变化遵循本发明实施例的一般性原理并包括本公开实施例未公开的本技术领域中的公知常识或惯用技术手段。说明书和实施例仅被视为示例性的,本发明实施例的真正范 围和精神由下面的权利要求指出。
应当理解的是,本公开实施例并不局限于上面已经描述并在附图中示出的精确结构,并且可以在不脱离其范围进行各种修改和改变。本公开实施例的范围仅由所附的权利要求来限制。

Claims (13)

  1. 一种甚高频数据交换系统用户身份双向验证方法,包括以下步骤:
    岸站向船站发送一个随机数;并根据所述随机数进行高级加密标准AES加密计算得到比对数据;
    所述船站根据所述随机数进行AES加密计算得到响应数据并发送所述岸站;
    所述岸站将接收到所述船站返回的响应数据与所述比对数据对比;当所述响应数据与比对数据一致时,确认所述船站通过验证。
  2. 根据权利要求1所述的一种甚高频数据交换系统用户身份双向验证方法,所述方法还包括:
    所述船站将自身的水上移动业务标识码MMSI、所述随机数随同所述响应数据一同发送所述岸站;
    所述岸站同时比对接收到的所述船站的MMSI与保存的所述船站的MMSI、接收到的所述船站发送的随机数与保存的随机数。
  3. 根据权利要求1所述的一种甚高频数据交换系统用户身份双向验证方法,所述方法还包括:
    所述岸站在所述船站发起注册时向所述船站发送所述随机数。
  4. 根据权利要求3所述的一种甚高频数据交换系统用户身份双向验证方法,所述船站在发起注册前,监测时分复用TDMA信道1分钟,确定信道活动、其它参与的成员标识ID、当前插槽分配、其它用户报告的位置及可能存在的船站信息;
    当具备注册条件时,所述船站发起注册流程;否则,进入未注册工作模式。
  5. 根据权利要求1所述的一种甚高频数据交换系统用户身份双向验证 方法,所述方法还包括:
    为每个所述船站分配对应的身份识别模块;所述船站根据所述身份识别模块进行身份验证。
  6. 根据权利要求1所述的一种甚高频数据交换系统用户身份双向验证方法,所述方法还包括:
    当两个所述船站之间身份验证时,由其中的验接收方船站生成所述随机数,并发送所述验证发起方船站;
    所述验证发起方船站根据所述随机数进行AES加密计算得到响应数据并发送所述验证接收方船站;
    所述验证接收方船站将接收到的响应数据与自身根据所述随机数进行AES加密计算得到的比对数据对比;当所述响应数据与比对数据一致时,确认所述验证发起方船站通过验证。
  7. 根据权利要求1所述的一种甚高频数据交换系统用户身份双向验证方法,所述船站发送数据包括但不限于:消息标识ID、入网设备类型、注册保持时间、自身的MMSI;或信道质量、响应数据、AES密钥;
    所述岸站反馈数据包括但不限于:消息标识ID、信道质量、随机数。
  8. 一种甚高频数据交换系统用户身份双向验证系统,包括岸站和船站,其中,
    所述岸站,用于向船站发送一个随机数;并根据所述随机数进行高级加密标准AES加密计算得到比对数据;将接收到所述船站返回的响应数据与所述比对数据对比;当所述响应数据与比对数据一致时,确认所述船站通过验证;
    所述船站,用于根据所述随机数进行AES加密计算得到响应数据并发送所述岸站。
  9. 根据权利要求8所述的一种甚高频数据交换系统用户身份双向验证 系统,所述船站还用于将自身的水上移动业务标识码MMSI、所述随机数随同所述响应数据一同发送所述岸站;
    所述岸站还用于同时比对接收到的所述船站的MMSI与保存的所述船站的MMSI、接收到的所述船站发送的随机数与保存的随机数。
  10. 根据权利要求8所述的一种甚高频数据交换系统用户身份双向验证系统,所述船站还用于当两个所述船站之间身份验证时,由其中的验接收方船站生成所述随机数,并发送所述验证发起方船站;所述验证发起方船站根据所述随机数进行AES加密计算得到响应数据并发送所述验证接收方船站;所述验证接收方船站将接收到的响应数据与自身根据所述随机数进行AES加密计算得到的比对数据对比;当所述响应数据与比对数据一致时,确认所述验证发起方船站通过验证。
  11. 一种网络设备,包括处理器、收发器、存储器及存储在存储器上并能够由所述处理器运行的可执行程序,所述处理器运行所述可执行程序时执行如权利要求1至7任一项所述的信息指示方法的步骤。
  12. 一种用户设备,包括处理器、收发器、存储器及存储在存储器上并能够由所述处理器运行的可执行程序,所述处理器运行所述可执行程序时执行如权利要求1至7任一项所述的信息指示方法的步骤。
  13. 一种存储介质,其上存储由可执行程序,所述可执行程序被处理器执行时实现如求1至7任一项所述的信息指示方法的步骤。
PCT/CN2023/107338 2022-08-25 2023-07-13 一种甚高频数据交换系统用户身份双向验证方法及系统 WO2024041261A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202211028678.1 2022-08-25
CN202211028678.1A CN115412334A (zh) 2022-08-25 2022-08-25 一种甚高频数据交换系统用户身份双向验证方法及系统

Publications (1)

Publication Number Publication Date
WO2024041261A1 true WO2024041261A1 (zh) 2024-02-29

Family

ID=84160567

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2023/107338 WO2024041261A1 (zh) 2022-08-25 2023-07-13 一种甚高频数据交换系统用户身份双向验证方法及系统

Country Status (2)

Country Link
CN (1) CN115412334A (zh)
WO (1) WO2024041261A1 (zh)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN115412334A (zh) * 2022-08-25 2022-11-29 中交信息技术国家工程实验室有限公司 一种甚高频数据交换系统用户身份双向验证方法及系统

Citations (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101719250A (zh) * 2009-12-10 2010-06-02 中国联合网络通信集团有限公司 支付认证方法、平台和系统
CN107104484A (zh) * 2017-05-19 2017-08-29 上海掌门科技有限公司 一种通过充电装置对用户设备进行充电的方法与设备
US20170356996A1 (en) * 2016-06-14 2017-12-14 Electronics And Telecommunications Research Institute System and method for monitoring vessel traffic information
CN109495494A (zh) * 2018-12-07 2019-03-19 中国运载火箭技术研究院 一种vdes数据传输的帧结构配置方法、传输装置及系统
CN113221136A (zh) * 2021-04-25 2021-08-06 亿海蓝(北京)数据技术股份公司 Ais数据传输方法、装置、电子设备和存储介质
CN113781842A (zh) * 2021-09-30 2021-12-10 海南超船电子商务有限公司 一种船舶识别控制方法
CN113992450A (zh) * 2021-12-28 2022-01-28 威晟汽车科技(宁波)有限公司 一种基于lin总线的高可靠性数据传输方法
CN115412334A (zh) * 2022-08-25 2022-11-29 中交信息技术国家工程实验室有限公司 一种甚高频数据交换系统用户身份双向验证方法及系统

Patent Citations (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101719250A (zh) * 2009-12-10 2010-06-02 中国联合网络通信集团有限公司 支付认证方法、平台和系统
US20170356996A1 (en) * 2016-06-14 2017-12-14 Electronics And Telecommunications Research Institute System and method for monitoring vessel traffic information
CN107104484A (zh) * 2017-05-19 2017-08-29 上海掌门科技有限公司 一种通过充电装置对用户设备进行充电的方法与设备
CN109495494A (zh) * 2018-12-07 2019-03-19 中国运载火箭技术研究院 一种vdes数据传输的帧结构配置方法、传输装置及系统
CN113221136A (zh) * 2021-04-25 2021-08-06 亿海蓝(北京)数据技术股份公司 Ais数据传输方法、装置、电子设备和存储介质
CN113781842A (zh) * 2021-09-30 2021-12-10 海南超船电子商务有限公司 一种船舶识别控制方法
CN113992450A (zh) * 2021-12-28 2022-01-28 威晟汽车科技(宁波)有限公司 一种基于lin总线的高可靠性数据传输方法
CN115412334A (zh) * 2022-08-25 2022-11-29 中交信息技术国家工程实验室有限公司 一种甚高频数据交换系统用户身份双向验证方法及系统

Also Published As

Publication number Publication date
CN115412334A (zh) 2022-11-29

Similar Documents

Publication Publication Date Title
EP3054717B1 (en) Methods and apparatuses for binding with device
US9769667B2 (en) Methods for controlling smart device
US9819652B2 (en) Information interaction methods and devices
US11485320B2 (en) Method and apparatus for vehicle function control, and storage medium
US8050658B2 (en) Method for signaling voice call of mobile terminal
EP3200421B1 (en) Method, apparatus and system for accessing wireless local area network
US8340637B2 (en) Securely establishing presence on telecommunication devices
US10313870B2 (en) Identity verification method and apparatus, and storage medium
CN109039860B (zh) 发送和展示消息的方法及装置、身份认证的方法及装置
WO2024041261A1 (zh) 一种甚高频数据交换系统用户身份双向验证方法及系统
CN110049062B (zh) 验证码校验方法、装置、系统、服务器、电子设备及存储介质
EP3407278A1 (en) Method and apparatus for reporting loss of card or device associated with account number or stolen of account number
CN105491250A (zh) 来电号码真伪的识别方法、装置及设备
CN113407427A (zh) 校验信息处理方法及装置、终端设备及存储介质
CN106375350B (zh) 刷机验证方法和装置
CN112636402A (zh) 充电方法及装置、电子设备
US11818583B2 (en) Method and device for unlocking communication, and computer storage medium
WO2015106513A1 (zh) 一种保护用户数据的方法、终端和计算机存储介质
CN111786719A (zh) 卫星通信方法、装置、设备及存储介质
CN114221788B (zh) 登录方法、装置、电子设备及存储介质
CN113225691B (zh) 音频处理方法、装置及存储介质
WO2023245519A1 (zh) 语音设备组网方法、装置及存储介质
US20220104003A1 (en) Random access method and apparatus, and computer readable storage medium
WO2024044994A1 (zh) 接入网络的方法、装置及可读存储介质
CN111010481B (zh) 来电监听方法、来电监听装置及计算机存储介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 23856351

Country of ref document: EP

Kind code of ref document: A1