• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

计算机工程与科学 ›› 2023, Vol. 45 ›› Issue (03): 462-469.

• 计算机网络与信息安全 • 上一篇    下一篇

ADS-B中基于格的分层无证书消息可恢复认证方案

农强1,2,邵猛1,2,张棒棒1,2,刘梓禹1,2   

  1. (1.闽南师范大学计算机学院,福建 漳州 363000;
    2.数据科学与智能应用福建省高等学校重点实验室,福建 漳州 363000)
  • 收稿日期:2022-04-25 修回日期:2022-09-22 接受日期:2023-03-25 出版日期:2023-03-25 发布日期:2023-03-22
  • 基金资助:
    福建省自然科学基金(2019J01750,2019J01752)

A lattice-based hierarchical certificateless authentication scheme with message recovery for ADS-B

NONG Qiang1,2,SHAO Meng1,2,ZHANG Bang-bang1,2,LIU Zi-yu1,2   

  1. (1.College of Computer Science,Minnan Normal University,Zhangzhou 363000;2.Key Laboratory of Data Science and Intelligence Application,Fujian Province University,Zhangzhou 363000,China)
  • Received:2022-04-25 Revised:2022-09-22 Accepted:2023-03-25 Online:2023-03-25 Published:2023-03-22

摘要: 广播式自动相关监视 (ADS-B)作为新一代空中交通管制的关键技术,已部署在全球大部分空域。已有的ADS-B消息认证方案主要利用传统的公钥密码系统来保证数据安全,计算负担较重且无法抵御量子攻击。首次将基于格的密码体制用于ADS-B通信安全,提出一种同时支持消息可恢复和批量验证的分层无证书消息认证方案。ADS-B 机载设备不需要管理证书,也无密钥托管问题。ADS-B消息不需要与签名一起传输,可以在验证阶段进行恢复。利用拒绝采样和无陷门技术,该方案仅需执行计算复杂度较低的线性运算即可实现消息认证。在随机预言机模型和小整数解问题假设下,该方案是可证安全的。性能评价实验结果表明,在同等的比特安全级别下,该方案相比相关工作在节省计算开销方面有显著的提升,对于计算资源受限的航空电子设备十分适用。

关键词: 广播式自动相关监视, 基于格的密码体制, 分层无证书消息认证, 拒绝采样

Abstract: As the key technology of the new generation air traffic control, automatic dependent surveillance-broadcast (ADS-B) has been deployed in most airspace around the world. The existing ADS-B message authentication schemes mainly utilize traditional public key cryptosystem to achieve data security, which are complex for computation and vulnerable to the quantum attack. We apply lattice-based cryptography to ADS-B communication security for the first time, and propose a hierarchical certificateless message authentication scheme supporting message recovery and batch verification simultaneously. The ADS-B airborne equipments are not required to manage certificates, and there is no key escrow problem. The ADS-B messages do not need to be transmitted with the signature, but can be recovered during verification. By utilizing rejection sampling and trapdoor-free technology, the proposed scheme requires just some computationally simple linear operations to realize message authentication. Our scheme is provably secure in the random oracle model under the assumption of the small integer solution (SIS). Experimental results of performance evaluation indicate that this scheme has significant performance improvement in saving computing overhead compared with related works under the same bit security level. It is very suitable for typical aeronautic electronic devices with limited computational resources.

Key words: automatic dependent surveillance-broadcast (ADS-B), lattice-based cryptography, hierar-chical certificateless message authentication, rejection sampling