| 研究生: |
黃子傑 Huang, Tzu-Chieh |
|---|---|
| 論文名稱: |
基於立方衛星實驗平台之後量子韌體完整性驗證與安全開機監控機制研究 Post-Quantum Firmware Integrity Verification and Secure Boot Monitoring on a CubeSat Experimental Platform |
| 指導教授: |
莊智清
Juang, Jyh-Ching |
| 學位類別: |
碩士 Master |
| 系所名稱: |
電機資訊學院 - 智慧資訊安全碩士學位學程 M.S. Degree Program on Cyber-Security Intelligence |
| 論文出版年: | 2026 |
| 畢業學年度: | 114 |
| 語文別: | 英文 |
| 論文頁數: | 90 |
| 中文關鍵詞: | 立方衛星 、衛星電腦 、安全開機 、後量子密碼 |
| 外文關鍵詞: | CubeSat, On-Board Computer, Secure Boot, Post-Quantum Cryptography |
| 相關次數: | 點閱:87 下載:0 |
| 分享至: |
| 查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報 |
隨著立方衛星被廣泛應用於學術研究、技術驗證與新興太空產業,其資訊安全議題也日益受重視。除通訊鏈路安全外,衛星本身之韌體完整性與啟動階段安全性,也將直接影響任務可靠度。由於衛星發射後難以進行實體維護,一旦於開機階段載入遭竄改或非授權更新之韌體,可能造成任務流程異常、遙測資料失真、指令執行錯誤,甚至整體系統失效。此外,在量子計算技術持續發展的背景下,傳統韌體驗證機制所用之基於大數質因數分解或橢圓曲線離散對數問題的密碼系統,將面臨量子演算法攻擊風險。在此基礎上,針對具備長任務壽命之衛星系統,提出一套具抗量子特性之韌體驗證機制。
本研究以國內電腦廠商開發之立方衛星實驗平台為應用背景,結合衛星電腦、即時作業系統任務架構、通用非同步收發傳輸器及地面端韌體產製流程,設計安全開機模擬機制。所提方法將韌體映像檔、詮釋資料、公開金鑰與數位簽章納入驗證流程,並針對包含惡意竄改與太空環境單粒子翻轉之異常情境設計實驗以進行測試。在簽章演算法方面,本研究實作支援傳統橢圓曲線簽章與基於雜湊之後量子簽章的雙演算法系統,以進行驗證效能之評估與對照。
系統可依驗證結果輸出驗證通過、錯誤狀態或進入安全模式之判斷,方便觀察與後續分析。實驗結果顯示,所設計之機制可正確判斷韌體完整性,並防止系統在異常情況下進入任務運作模式。研究成果為未來立方衛星導入後量子技術提供可行之初步驗證與參考依據。
With the increasing adoption of CubeSats in academic research, technology validation, and the emerging space industry, their cybersecurity issues have received growing attention. In addition to communication-link security, firmware integrity and boot-time security directly affect mission reliability. Because physical maintenance is difficult after launch, loading tampered or unauthorized firmware during the boot phase may lead to abnormal mission behavior, corrupted telemetry data, erroneous command execution, or even complete system failure. Moreover, as quantum computing continues to advance, conventional firmware verification mechanisms based on prime factorization of large numbers or elliptic-curve discrete logarithm assumptions may face risks from quantum algorithms. For satellite systems with long mission lifetimes, firmware security must therefore consider post-quantum migration.
This thesis uses a CubeSat experimental platform developed by a domestic computer manufacturer as the application context. By integrating the satellite on-board computer, the Free Real-Time Operating System task architecture, universal asynchronous receiver/transmitter-based console interaction, and the ground-side firmware package generation flow, this thesis designs a secure boot simulation mechanism. The proposed method incorporates the firmware image, metadata, public key, and digital signature into the verification flow, and evaluates abnormal scenarios involving malicious tampering and bit flips caused by the space environment. With respect to signature algorithms, this thesis implements a dual-algorithm system supporting both a conventional elliptic-curve signature and a hash-based post-quantum signature, enabling comparative evaluation of signature authentication performance.
Based on the verification result, the system updates the boot decision and determines whether the platform can proceed to normal operation or should be restricted to a safe mode for further observation and analysis. Experimental results show that the proposed mechanism correctly detects firmware-integrity violations and prevents the system from entering the normal operating mode under abnormal conditions. The results provide preliminary evidence and a practical reference for introducing post-quantum techniques into future CubeSat systems.
[1] P. W. Shor, “Polynomial-Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum Computer,” SIAM J. Comput., vol. 26, no. 5, pp. 1484–1509, Oct. 1997, doi: 10.1137/S0097539795293172.
[2] Y.-R. Yang, “Development of a Function-Oriented Flight Software Framework for CubeSats,” M.S. thesis, Dept. Electr. Eng., National Cheng Kung Univ., Tainan, Taiwan, Jul. 2021. [Online]. Available: https://hdl.handle.net/11296/7yey67.
[3] D. Evans, “Covert Control: Unveiling Vulnerabilities in TT&C to Cyber Attacks,” Hack CYSAT 2023, YouTube video, May 22, 2023. [Online]. Available: https://www.youtube.com/watch?v=sXGQWLJ8904.
[4] D. Evans et al., “Operational Challenges and Achievements of the OPS-SAT-1 Mission,” in Proc. 2025 IEEE Aerosp. Conf., Big Sky, MT, USA, Mar. 2025, pp. 1–10, doi: 10.1109/AERO63441.2025.11068410.
[5] National Aeronautics and Space Administration, “8.0 Small Spacecraft Avionics,” in State-of-the-Art of Small Spacecraft Technology, May 19, 2026. [Online]. Available: https://www.nasa.gov/smallsat-institute/sst-soa/small-spacecraft-avionics/. Accessed: Jul. 9, 2026.
[6] European Space Agency, “Radiation: Satellites’ unseen enemy,” Jul. 4, 2011. [Online]. Available: https://www.esa.int/Enabling_Support/Space_Engineering_Technology/Radiation_satellites_unseen_enemy. Accessed: Jul. 9, 2026.
[7] National Aeronautics and Space Administration, “South Atlantic Anomaly: 2015 through 2025,” NASA Scientific Visualization Studio, Aug. 17, 2020. [Online]. Available: https://svs.gsfc.nasa.gov/4840/. Accessed: Jul. 9, 2026.
[8] European Cooperation for Space Standardization, “Space engineering—Engineering techniques for radiation effects mitigation in ASICs and FPGAs handbook,” ECSS-E-HB-20-40A, Oct. 11, 2023. [Online]. Available: https://ecss.nl/wp-content/uploads/2023/10/ECSS-E-HB-20-40A%2811October2023%29.pdf. Accessed: Jul. 9, 2026.
[9] W. A. Arbaugh, D. J. Farber, and J. M. Smith, “A Secure and Reliable Bootstrap Architecture,” in Proc. IEEE Symp. Security and Privacy, Oakland, CA, USA, May 1997, pp. 65–71, doi: 10.1109/SECPRI.1997.601317.
[10] National Institute of Standards and Technology, “Secure Hash Standard (SHS),” FIPS PUB 180-4, Aug. 2015, doi: 10.6028/NIST.FIPS.180-4.
[11] National Institute of Standards and Technology, “Digital Signature Standard (DSS),” FIPS PUB 186-5, Feb. 2023, doi: 10.6028/NIST.FIPS.186-5.
[12] J. Breitner and N. Heninger, “Biased Nonce Sense: Lattice Attacks against Weak ECDSA Signatures in Cryptocurrencies,” in Financial Cryptography and Data Security, I. Goldberg and T. Moore, Eds., ser. Lecture Notes in Computer Science, vol. 11598. Cham, Switzerland: Springer, 2019, pp. 3–20, doi: 10.1007/978-3-030-32101-7_1.
[13] S. Josefsson and I. Liusvaara, “Edwards-Curve Digital Signature Algorithm (EdDSA),” RFC 8032, Jan. 2017, doi: 10.17487/RFC8032.
[14] National Security Agency, “Announcing the Commercial National Security Algorithm Suite 2.0,” ver. 1.0, PP-22-1338, Sep. 2022. [Online]. Available: https://media.defense.gov/2025/May/30/2003728741/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS.PDF. Accessed: Jul. 9, 2026.
[15] National Institute of Standards and Technology, “Post-Quantum Cryptography,” Jan. 3, 2017. [Online]. Available: https://csrc.nist.gov/projects/post-quantum-cryptography. Accessed: Jul. 9, 2026.
[16] National Institute of Standards and Technology, “Module-Lattice-Based Digital Signature Standard,” FIPS PUB 204, Aug. 2024, doi: 10.6028/NIST.FIPS.204.
[17] National Institute of Standards and Technology, “Stateless Hash-Based Digital Signature Standard,” FIPS PUB 205, Aug. 2024, doi: 10.6028/NIST.FIPS.205.
[18] R. Perlner, “FIPS 206: FN-DSA (Falcon),” presented at the Sixth PQC Standardization Conf., Sep. 25, 2025. [Online]. Available: https://csrc.nist.gov/presentations/2025/fips-206-fn-dsa-falcon. Accessed: Jul. 9, 2026.
[19] National Institute of Standards and Technology, “Recommendation for Stateful Hash-Based Signature Schemes,” NIST SP 800-208, Oct. 2020, doi: 10.6028/NIST.SP.800-208.
[20] A. Wagner, F. Oberhansl, and M. Schink, “Extended version—to be, or not to be stateful: post-quantum secure boot using hash-based signatures,” J. Cryptogr. Eng., vol. 14, no. 4, pp. 631–648, Nov. 2024, doi: 10.1007/s13389-024-00362-4.
[21] I. Sünter et al., “Firmware Updating Systems for Nanosatellites,” IEEE Aerosp. Electron. Syst. Mag., vol. 31, no. 5, pp. 36–43, May 2016, doi: 10.1109/MAES.2016.150162.
[22] J. Sobreira, W. Silva, C. Oliveira, M. Bezerra, and J. Silveira, “Case Study: A Robust Bootloader System with Support for Over-the-Air Firmware Updates in CubeSat Payloads,” in Proc. 2026 IEEE 27th Latin Amer. Test Symp. (LATS), Florianópolis, Brazil, Mar. 2026, pp. 1–2, doi: 10.1109/LATS70329.2026.11480316.
[23] N. Webb, M. Johnson, and P. Saenz, “Enhancing Satellite Cybersecurity through FPGA-Based Secure Boot,” in Proc. 2025 IEEE Aerosp. Conf., Big Sky, MT, USA, Mar. 2025, pp. 1–7, doi: 10.1109/AERO63441.2025.11068623.
[24] S. Marzougui and J. Krämer, “Post-Quantum Cryptography in Embedded Systems,” in Proc. 14th Int. Conf. on Availability, Reliability and Security (ARES), Canterbury, U.K., Aug. 2019, Art. no. 48, pp. 1–7, doi: 10.1145/3339252.3341475.
[25] W.-T. Lin, “System Integration Testing and Mission Simulation Based on a CubeSat Experimental Platform,” M.S. thesis, Inst. Space Syst. Eng., National Cheng Kung Univ., Tainan, Taiwan, Jul. 2025. [Online]. Available: https://hdl.handle.net/11296/39rha6.
[26] ELITEGROUP, “EliteOBC,” 2025. [Online]. Available: https://www.ecs.com.tw/tw/Product/CubeSat/EliteOBC-Flight/overview. Accessed: Jul. 9, 2026.
[27] Python Software Foundation, “hashlib — Secure hashes and message digests,” Python 3 Documentation. [Online]. Available: https://docs.python.org/3/library/hashlib.html. Accessed: Jul. 9, 2026.
[28] The Python Cryptographic Authority, “Ed25519 signing,” cryptography Documentation. [Online]. Available: https://cryptography.io/en/latest/hazmat/primitives/asymmetric/ed25519/. Accessed: Jul. 9, 2026.
[29] C. Xu, “SLH-DSA,” PyPI. [Online]. Available: https://pypi.org/project/SLH-DSA/. Accessed: Jul. 9, 2026.
[30] Monocypher, “Ed25519,” Monocypher Manual. [Online]. Available: https://monocypher.org/manual/ed25519. Accessed: Jul. 9, 2026.
[31] slh-dsa Project, “slhdsa-c: A portable C implementation of SLH-DSA,” GitHub Repository. [Online]. Available: https://github.com/slh-dsa/slhdsa-c/. Accessed: Jul. 9, 2026.
[32] FreeRTOS, “uxTaskGetStackHighWaterMark, uxTaskGetStackHighWaterMark2,” FreeRTOS Documentation. [Online]. Available: https://www.freertos.org/Documentation/02-Kernel/04-API-references/03-Task-utilities/04-uxTaskGetStackHighWaterMark. Accessed: Jul. 9, 2026.
[33] Arm Limited, “Cycle Count register, DWT_CYCCNT,” in ARMv7-M Architecture Reference Manual, ARM DDI 0403D. [Online]. Available: https://developer.arm.com/documentation/ddi0403/d/Debug-Architecture/ARMv7-M-Debug/The-Data-Watchpoint-and-Trace-unit/Cycle-Count-register--DWT-CYCCNT. Accessed: Jul. 9, 2026.
[34] Arm Limited, “CYCCNT cycle counter and related timers,” in ARMv7-M Architecture Reference Manual, ARM DDI 0403D. [Online]. Available: https://developer.arm.com/documentation/ddi0403/d/Debug-Architecture/ARMv7-M-Debug/The-Data-Watchpoint-and-Trace-unit/CYCCNT-cycle-counter-and-related-timers. Accessed: Jul. 9, 2026.