BDSec: Security authentication protocol for BeiDou-II civil navigation message

Wu Zhijun,Zhang Yuan,Yang Yiming,Wang Peng,Yue Meng
DOI: https://doi.org/10.23919/jcc.ja.2022-0368
2024-06-21
China Communications
Abstract:Due to the lack of authentication mechanism in BeiDou navigation satellite system (BDS), BD-II civil navigation message (BDII-CNAV) are vulnerable to spoofing attack and replay attack. To solve this problem, we present a security authentication protocol, called as BDSec, which is designed by using China's cryptography Shangyong Mima (SM) series algorithms, such as SM2/4/9 and Zu Chongzhi (ZUC) algorithm. In BDSec protocol, both of BDII-CNAV and signature information are encrypted using the SM4 algorithm (Symmetric encryption mechanism). The encrypted result is used as the subject authentication information. BDSec protocol applies SM9 algorithm (Identity-based cryptography mechanism) to protect the integrity of the BDII-CNAV, adopts the SM2 algorithm (Public key cryptosystem) to guarantee the confidentiality of the important session information, and uses the ZUC algorithm (Encryption and integrity algorithm) to verify the integrity of the message authentication serial number and initial information and the information in authentication initialization sub-protocol respectively. The results of the SVO logic reasoning and performance analysis show that BDSec protocol meets security requirements for the dual user identity authentication in BDS and can realize the security authentication of BDII-CNAV.
telecommunications
What problem does this paper attempt to address?