Satellite signal tamper-proofing method and system

Through the Hadamma integral segment algorithm and grayscale correlation analysis model, combined with the dynamic key parameter group, a dynamic jump segment block processing path is constructed, which solves the problem of difficult dynamic adjustment of block length and encryption path in the existing technology, and realizes efficient tamper-proof of satellite signals.

CN120201418AActive Publication Date: 2025-06-24GOLDEN SHIELD TESTING TECH CO LTD

Patent Information

Application Number
CN202510686601.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2025-06-24
Estimated Expiration
2045-05-27

AI Technical Summary

Technical Problem

The existing satellite signal anti-tampering technology relies on fixed blocking and static key sequences, making it difficult to dynamically adjust the block length and encryption path, and it cannot adaptively adjust in complex channel environments, which poses a risk of key leakage.

Method used

Non-equal segment block cutting is performed by Hadamama integrated segment algorithm, segment block index table is generated, and subkey sequences and exclusive OR parameters are extracted based on the main synchronous key group to construct a dynamic jump segment block processing path. Combining satellite real-time coordinates and timestamp sequences, the correlation between the segment block time window and the masking interval is calculated through the grayscale correlation analysis model, the risk of tampering is determined, and a re-encrypted key group is generated through the dynamic key parameter group.

Benefits of technology

Dynamic cutting and adaptive encryption paths are realized, which improves the identification and blocking ability of satellite signal multi-dimensional tampering attacks, and reduces the risk of key leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120201418A_ABST
    Figure CN120201418A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of communication security, in particular to a satellite signal tamper-proofing method and system.The satellite signal tamper-proofing method comprises the following steps that a current communication data frame is obtained through a satellite orbit number, a real-time position vector and a timestamp, the data frame is input into a Hadamard integral segment algorithm to execute non-equal-length segment block cutting, a segment block index table is generated, and the segment block index table is stored in a database; recording an initial address bit, a segment block length value and an initial weight bit value; according to the method, non-equal-length cutting is carried out on a data frame through a Hadamard integral segment algorithm, a segment block index table is generated, a weight bit value is recorded, sub-keys and XOR parameters are extracted based on a main key group to execute logic rotation, a dynamic jump path is constructed, the association degree of a shielding area is calculated by combining satellite coordinates and timestamps, risk coefficients are quantified, and risk segment blocks are positioned. A dynamic key is called to generate a re-encryption key through dual linear perturbation, local protection is enhanced through byte-by-byte XOR and complement mapping, and a dynamic cutting, path generation, risk perception and key updating closed-loop mechanism is formed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication security technology, and in particular to a method and system for preventing satellite signal tampering. Background Art

[0002] The field of communication security technology includes various technologies that ensure information is not subject to unauthorized access, tampering, destruction, or eavesdropping during transmission, exchange, and storage. The core content of this technical field includes communication encryption, identity authentication, data integrity verification, anti-tampering mechanisms, anti-jamming transmission, and key management. Communication security is widely applied in multiple scenarios such as wireless communication, the Internet, the Internet of Things, and satellite communication, and is the basis for building a trusted network environment and protecting data security. Systematically, the development of this technical field focuses on dual security protection mechanisms at the protocol layer and the channel layer, combined with technologies for dealing with various attack models in the information transmission path, to ensure the authenticity and consistency of communication content in the physical link, network path, and application interaction.

[0003] Among them, the method for preventing satellite signal tampering refers to a communication security technology based on encryption and verification mechanisms adopted in a satellite communication system to prevent signals from being maliciously tampered with during transmission. The technical matters targeted by this patent theme mainly include the verification of data integrity in the satellite signal transmission path, the authentication mechanism of signal sources, and the encryption processing of transmission content under specific communication protocols. The specific method includes digital signature processing of uplink and downlink signals, identity verification of both communication parties through key matching, and the introduction of a hash function to verify the consistency of the original data and the received data, so as to identify and block tampering during signal transmission. This technology is usually embedded in satellite communication data frames in the form of a protocol encapsulation layer, and an anti-tampering communication process is constructed through distributed authentication codes and multiple rounds of verification logic.

[0004] The existing technology relies on fixed blocks and static key sequences, and the block length and encryption path lack dynamic adjustment. Attackers can analyze the block pattern and key cycle through long-term traffic monitoring, reducing the anti-tampering intensity. Traditional data integrity verification uses one-way hashing or centralized authentication, without combining dynamic parameters of satellite positions. When signals naturally attenuate due to orbital drift or occlusion, normal fluctuations are easily misjudged as tampering behaviors. The existing anti-tampering logic mainly focuses on protocol layer encapsulation and does not integrate real-time environmental parameters such as physical layer channel shielding and multipath effects, resulting in the inability of risk determination and encryption strategies to adaptively adjust according to the channel state. For example, when a satellite communicates across polar regions, fixed verification thresholds may frequently trigger false alarms due to ionospheric interference. In addition, the traditional method has a fixed processing path for data frames, and attackers can reverse-derive the encryption logic by intercepting multiple groups of data, posing a systematic risk of key leakage. Summary of the Invention

[0005] The object of the present invention is to solve the disadvantages existing in the prior art, and to propose a satellite signal anti-tampering method and system.

[0006] To achieve the above object, the present invention adopts the following technical solutions: A satellite signal anti-tampering method, comprising the following steps: S1: Obtain the current communication data frame through the satellite orbit number, real-time position vector and timestamp, input the data frame into the Hadamard integral segment algorithm to perform non-uniform segment block cutting, generate a segment block index table, and record the starting address bit, segment block length value and initial weight bit value; S2: Based on the master synchronization key group, extract the sub-key sequence from the Nth bit to the N+Mth bit as the offset parameter, extract the last K bits as the shift XOR parameter, perform XOR operations on the index bit values of multiple items in the segment block index table, and perform a logical rotation operation on the operation result to generate a jump-type segment block processing path; S3: Based on the satellite three-axis coordinate parameters and the timestamp sequence, input the jump-type segment block processing path into the gray correlation analysis model, calculate the correlation degree between the segment block time window and the shielding interval, determine whether the segment block is in a tampering risk state according to the correlation degree threshold, and output the tampering risk coefficient and the risk segment block set.

[0007] As a further solution of the present invention, the jump-type segment block processing path includes a dynamic index bit, a rotation offset, and a segment block sequence identifier, the tampering risk coefficient includes a correlation degree threshold, a risk quantization value, and a period determination flag, and the risk segment block set includes a risk segment block number, a time window label, and a priority identifier.

[0008] As a further solution of the present invention, the matrix generation rule in the Hadamard integral segment algorithm is: when the data frame length is odd, round up the data frame length to the nearest and intercept the valid bits to construct a Hadamard orthogonal basis matrix with an order of half of the intercepted data frame length; 、 The value is dynamically determined by taking the modulo operation of the hash value of the satellite orbit number with respect to the total number of segment blocks; The correlation degree threshold is obtained by optimizing based on the historical tampering data set using the gradient descent method, and the value range is .

[0009] As a further solution of the present invention, the steps for obtaining the jump-type segment block processing path are specifically as follows: S201: Based on the master synchronization key group, locate the starting bit of the Nth bit, intercept a continuous M-bit binary sequence, convert the binary sequence into a decimal value, extract the last K-bit binary sequence of the master synchronization key group, convert it into a hexadecimal value, and generate an offset parameter and an XOR parameter; The value of is the integer part of the logarithm to the base 2 of the total number of segments in the segment block index table, i.e., ; S202: Call the index bit values in the segment block index table, convert each index bit value into a binary bit stream, align the hexadecimal bit width of the XOR parameter, perform XOR operations bit by bit, shift the operation result left by K bits and then intercept the last M-bit binary sequence, and convert it into a decimal value to generate a processing path coefficient; S203: Add the offset parameter to the processing path coefficient, perform a modulo operation on the addition result with respect to the total number of segment blocks, map the remainder to the index bit values in the segment block index table, and rearrange the segment block index bits in the order of the remainder to generate a jump-type segment block processing path.

[0010] As a further solution of the present invention, the method further includes: S4: Call the dynamic key parameter group in the main synchronization key group, combine the tampering risk coefficient, perform a perturbation operation on the key displacement parameter through a double linear mapping function to generate a re-encryption key group, and perform byte-by-byte XOR, logical shift, and complement mapping operations on the risk segment block set.

[0011] As a further solution of the present invention, the re-encryption key group includes the perturbed displacement parameter, the XOR operation order, and the complement mapping rule; The dynamic key parameter group is generated by non-linear transformation of the main synchronization key group through an elliptic curve, satisfying , where is the base point, is a random integer, is a prime number.

[0012] As a further solution of the present invention, the specific steps for obtaining the re-encryption key group are as follows: S401: Call the dynamic key parameter group in the main synchronization key group, extract the tampering risk coefficient as a weight factor, multiply each parameter item in the dynamic key parameter group by the weight factor, calculate the modular feature of the product result as the input of the first linear transformation, perform the first-round linear superposition on the key displacement parameter based on the modular feature, and perform the second linear transformation with the square value of the weight factor to generate a perturbed key vector; The modular feature is calculated through the irreducible polynomial of the Galois field ; S402: Based on the perturbed key vector, traverse the byte stream of each segment in the risk segment block set, extract the binary value of each byte in the segment byte stream, perform an XOR operation on the byte value with the corresponding byte of the perturbed key vector, and perform a left shift or right shift operation on the XOR result according to the parity bit state of the current byte of the perturbed key vector to generate an intermediate encrypted segment block; S403: For the intermediate encrypted segment blocks, extract the complement mapping reference value of each byte, locate the mapping rule in the complement mapping table according to the reference value, perform bit-level superposition of the byte data and the mapping rule, and merge the superposition results of all segment blocks to generate a re-encryption key group; The complement mapping table is dynamically generated according to the Hamming weight parity of the dynamic key parameter group, satisfying , where is the original byte, is the Hamming weight.

[0013] A satellite signal anti-tampering system, which is used to execute the above satellite signal anti-tampering method. The system includes: A frame segment cutting module, which is used to obtain a communication data frame through the satellite orbit number and the real-time position vector, input the communication data frame into the Hadamard integral segment algorithm to perform non-uniform segment block cutting, generate a segment block index table, record the starting address bit, the segment block length value and the initial weight bit value, and transfer the segment block index table to the key path generation module; A key path generation module, which is used to extract the sub-key sequence from the Nth bit to the N+Mth bit of the main synchronization key group as the offset parameter, extract the last K bits as the shift XOR parameter, perform XOR operations on the starting address bit and the initial weight bit value in the segment block index table, and input them into the logical rotation function to generate a jumping segment block processing path, and transfer the jumping segment block processing path to the risk determination module; A risk determination module, which is used to input the jumping segment block processing path into the gray correlation analysis model through the satellite three-axis coordinate parameters and the timestamp sequence, calculate the correlation degree between the segment block time window and the shielding interval, judge whether the segment block is in a tampering risk state according to the preset correlation degree threshold, output the tampering risk coefficient and the risk segment block set, and transfer the tampering risk coefficient and the risk segment block set to the dynamic encryption module; A dynamic encryption module, which is used to call the dynamic key parameter group in the main synchronization key group, combine the tampering risk coefficient, perform perturbation operations on the key displacement parameter through the double linear mapping function to generate a re-encryption key group, and perform byte-by-byte XOR and logical displacement operations on the risk segment block set, and transfer the re-encryption key group to the satellite communication link for data encapsulation.

[0014] Compared with the prior art, the advantages and positive effects of the present invention are as follows: In the present invention, non-uniform cutting is performed on a data frame through the Hadamard integral segment algorithm to generate a segment block index table and record weight bit values, breaking the fixed block mode and making it difficult for attackers to infer the complete frame structure by intercepting fragments. Based on the master key group, a sub-key sequence and XOR parameters are extracted, and a logical rotation operation is performed on the index bit values to construct a dynamic jumping processing path, avoiding the regularity exposure caused by traditional sequential encryption. Combining the satellite's real-time coordinates and the timestamp sequence, the gray correlation model is used to calculate the correlation degree between the segment block time window and the shielding area, quantify the tampering risk coefficient, and locate the risk segment block, solving the problem of insufficient adaptability of static threshold determination in complex channel environments. The dynamic key parameter group is called to generate a re-encryption key through double linear mapping perturbation, realizing real-time update of the key with the channel state and blocking the key reuse attack. Byte-by-byte XOR and complement mapping are used to perform secondary encryption on the risk segment block, strengthening local protection while maintaining the overall transmission efficiency. The above steps form a closed-loop dynamic cutting-path generation-risk perception-key update mechanism, enhancing the real-time recognition and blocking ability against multi-dimensional tampering attacks on satellite signals. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 It is a schematic diagram of the working process of the present invention; Figure 2 It is a flowchart of the acquisition steps of the segment block index table of the present invention; Figure 3 It is a flowchart of the acquisition steps of the jumping segment block processing path of the present invention; Figure 4 It is a flowchart of the acquisition steps of S3 of the present invention; Figure 5 It is a flowchart of the acquisition steps of the re-encryption key group of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0016] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0017] In the description of the present invention, it should be understood that the orientation or positional relationship indicated by terms such as "length", "width", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc. is based on the orientation or positional relationship shown in the accompanying drawings, and is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be construed as limiting the present invention. In addition, in the description of the present invention, "a plurality of" means two or more, unless otherwise specifically defined.

[0018] Embodiment 1: Please refer to Figure 1 , the present invention provides a technical solution: a method for preventing satellite signal tampering, including the following steps: S1: Obtain the current communication data frame through the satellite orbit number, real-time position vector, and timestamp, input the data frame into the Hadamard integral segment algorithm to perform non-uniform segment block cutting, generate a segment block index table, and record the starting address bit, segment block length value, and initial weight bit value; S2: Based on the master synchronization key group, extract the sub-key sequence from the Nth bit to the N+Mth bit as the offset parameter, extract the last K bits as the shift XOR parameter, perform XOR operations on the index bit values of multiple items in the segment block index table, and perform a logical rotation operation on the operation result to generate a jumping segment block processing path; S3: Based on the satellite three-axis coordinate parameters and timestamp sequence, input the jumping segment block processing path into the gray correlation analysis model, calculate the correlation degree between the segment block time window and the shielding interval, determine whether the segment block is in a tampering risk state according to the correlation degree threshold, and output the tampering risk coefficient and the risk segment block set; S4: Invoke the dynamic key parameter group in the master synchronization key group, combine the tampering risk coefficient, perform a perturbation operation on the key displacement parameter through a double linear mapping function to generate a re-encryption key group, and perform byte-by-byte XOR, logical shift, and complement mapping operations on the risk segment block set.

[0019] The jumping segment block processing path includes a dynamic index bit, a rotation offset, and a segment block sequence identifier. The tampering risk coefficient includes a correlation degree threshold, a risk quantization value, and a period determination flag. The risk segment block set includes a risk segment block number, a time window label, and a priority identifier. The re-encryption key group includes a perturbed displacement parameter, an XOR operation order, and a complement mapping rule.

[0020] The matrix generation rule in the Hadamard integral segment algorithm is: when the data frame length is odd, round up the data frame length to the nearest and intercept the valid bits to construct a Hadamard orthogonal basis matrix with an order equal to half of the length of the intercepted data frame; 、 The value of is dynamically determined by taking the modulo operation of the hash value of the satellite orbit number with respect to the total number of segment blocks; The correlation degree threshold is obtained by optimizing the historical tampering data set based on the gradient descent method, and the value range is ; The dynamic key parameter group is generated by the master synchronization key group through an elliptic curve non-linear transformation, satisfying , where is the base point, is a random integer, is a prime number.

[0021] Please refer to Figure 2 , and the steps for obtaining the segment block index table are specifically as follows: S101: Obtain the real-time position vector and timestamp corresponding to the satellite orbit number, extract the binary communication data stream through the satellite communication link parsing protocol, parse the start byte and end byte fields in the protocol frame header identifier, locate the valid data segment according to the field length and checksum verification result, intercept the continuous data segment after the frame header identifier, and generate a communication data frame; First, the system obtains the orbit number of a specific satellite and queries the current real-time position vector and corresponding timestamp information of this satellite based on this number. A communication relay satellite with an orbit number of "CN_SAT_COMM_07" has an accurate position vector recorded at 10:00:00.000 seconds, May 8, 2025, Coordinated Universal Time (UTC) as , and the next recording point is at 10:00:00.120 seconds, May 8, 2025, UTC, and its position vector is updated to . These data are collected by the satellite's own sensors and transmitted through the downlink.

[0022] Next, extract the original binary communication data stream through the satellite communication link parsing protocol. This satellite communication link follows an internally defined binary transmission protocol, which details the encapsulation structure of the data frame specifically as follows: The frame start is marked by a 2-byte fixed identifier "0xBEEF", followed by a 2-byte data segment length field indicating the number of bytes in the subsequent valid data segment. After the data segment is a 1-byte cyclic redundancy check code (CRC-8), and finally, the frame end is marked by a 2-byte end identifier "0xCAFE". An actual received binary data stream fragment may be: “…0xBEEF00201A2B3C4D…5E6F7G8HCRCVAL0xCAFE…”, where “0x0020” indicates that the data segment contains 32 bytes. The system strictly parses this data stream according to the protocol: First, search for and locate the start byte sequence “0xBE” and “0xEF” to confirm the start of the frame, then read the two subsequent bytes “0x00” and “0x20”, and combine them to obtain a data segment length of 32 bytes. The system then extracts these 32 bytes of valid data, for example, the data is: “0x112233445566778899AABBCCDDEEFF00102030405060708090A0B0C0D0E0F”. After that, read 1 byte of the checksum, assumed to be “0x5B”. The system calculates according to the standard CRC-8 algorithm (for example, using the polynomial Calculate the 32-byte data segment to obtain a calculated checksum. If the calculation result is also "0x5B", the check passes. Finally, the system checks whether the end identifiers "0xCA" and "0xFE" exist at the end of the data segment. After all confirmations are correct, the 32-byte continuous data segment (i.e., "0x1122…0E0F") is completely intercepted to generate a communication data frame, and this communication data frame is the basic unit for subsequent processing.

[0023] S102: Invoke the matrix generation rule in the Hadamard integral segment algorithm to construct a Hadamard orthogonal basis matrix with an order equal to half of the data frame length. Convert the binary sequence of the communication data frame into a decimal numerical vector, perform element-by-element multiplication with the matrix row vector and accumulate the sum, calculate the standard deviation of adjacent accumulated values, and at the same time determine the segment block boundary based on the mutation points where the standard deviation change rate exceeds the preset threshold. Count the number of bits between the boundaries as the length value to generate the segment block segmentation parameter. The conversion method of the decimal numerical vector is: segment the binary sequence into normalized numerical values every 8 bits, satisfying , where is the binary bit value; Based on the communication data frame generated by S101, its length is 32 bytes, and when converted to a bit stream, it is bits. The system invokes the matrix generation rule in the Hadamard integral segment algorithm to construct a Hadamard orthogonal basis matrix with an order equal to half of the data frame length. Therefore, the order of the Hadamard matrix , and the system generates a standard Hadamard matrix , all of whose elements are or .

[0024] Subsequently, convert the binary sequence of the 256-bit communication data frame, with the specific sequence being "0001000100100010…11101111" (showing the binary form of the first and last bytes here), into a decimal numerical vector. The conversion rule is: divide this binary sequence into segments of 8 bits each, and convert each segment (one byte) into a decimal integer from 0 to 255. Then, normalize this integer through the formula , where is the value of the corresponding bit (0 or 1), so that each normalized value is between 0.0 and 1.0. For example, the decimal value of the first byte "00010001" is 17, and its normalized value is , and the decimal value of the second byte "00100010" is 34, and its normalized value is , and so on, finally forming a vector containing 256 normalized decimal values .

[0025] Due to the Hadamard matrix whose row vector length is 128, while the data vector has a length of 256, so the data vector is divided into two sub-vectors with a length of 128: and . The system multiplies each of these two sub-vectors element-wise with each row vector of the Hadamard matrix (where ranges from 1 to 128), and accumulates the product results to obtain two sequences of accumulated values and , where (X is A or B).

[0026] The system then calculates the standard deviation of adjacent accumulated values in these two sequences of accumulated values and . Specifically, for the sequence , calculate , , …, to obtain a sequence of standard deviations . Similarly, generates . Then, based on the mutation points where the change rate of these sequences of standard deviations exceeds a preset threshold, the boundaries of the segments are determined. The setting of this standard deviation change rate threshold is determined based on the statistical characteristics analysis of the change rate of the standard deviation at the stable data segments and the known segment boundaries in a large number of historical communication data. In the stable data segments, the change rate of the standard deviation usually remains in a relatively low range, such as 0.05 to 0.20, while at the segment boundaries where the data content or structure changes, this change rate will increase significantly, generally in the range of 0.60 to 1.20. To effectively distinguish between the two and reduce misjudgment, is set to a value that can provide good discrimination. The calculation process: collect 1000 samples of the change rate of the standard deviation for each of the stable segments and boundary points. The sample mean of the stable segments is 0.12, and the standard deviation is 0.04. The sample mean of the boundary points is 0.90, and the standard deviation is 0.10. Set to the stable segment mean + 5 times the standard deviation, that is, . At the same time, this value is much lower than the boundary point mean - 3 times the standard deviation ( ). Take the intermediate value . In actual calculation, if the current standard deviation is , and the previous standard deviation is ( ), then the rate of change , when , the time point is marked as a potential segment boundary. By this method, multiple boundary points are identified in the entire 256-bit data frame. For example, at the , , bits of the original bit stream, mutation points are identified, and these points are the boundaries of the segments. The system counts the number of bits between these boundaries as the length value of the corresponding segment. For example, the length of the first segment is 64 bits, the length of the second segment is bits, the length of the third segment is bits, and the length of the last segment is bits. Finally, segment segmentation parameters containing the start offset and length information of each segment are generated.

[0027] S103: Based on the start offset of the segment in the segment segmentation parameters, calculate the hexadecimal address bits according to the rule of 8 bits per byte. Divide the segment length value by 8 and round up to get the byte value. Extract the row index value of the Hadamard orthogonal basis matrix and map it as the weight coefficient. Integrate the address bits, byte value, and weight coefficient into a structured table to obtain the segment index table.

[0028] According to the segment segmentation parameters generated in step S102, which contain the start offset and length of each segment. The start offset of the first segment is defined as 0 bits, and its length is 64 bits; the start offset of the second segment is 64 bits, and its length is 56 bits; the start offset of the third segment is 120 bits, and its length is 72 bits; the start offset of the fourth segment is 192 bits, and its length is 64 bits. The system converts these start offsets in bits into hexadecimal address bits according to the rule of 8 bits per byte. The start offset of the first segment is 0 bits, and its byte offset is bytes, and the hexadecimal address is "0x0000". The start offset of the second segment is 64 bits, and its byte offset is bytes, and the hexadecimal address is "0x0008". The start offset of the third segment is 120 bits, and its byte offset is bytes, and the hexadecimal address is "0x000F". The start offset of the fourth segment is 192 bits, and its byte offset is bytes, and the hexadecimal address is "0x0018".

[0029] At the same time, divide the length value of each segment (in bits) by 8 and round up to get the value in bytes. The length of the first segment is 64 bits, and the number of bytes is bytes. The length of the second segment is 56 bits, and the number of bytes is bytes, the length of the third segment block is 72 bits, and the number of bytes is bytes, the length of the fourth segment block is 64 bits, and the number of bytes is bytes.

[0030] Next, the system extracts the row index values of the Hadamard orthogonal basis matrix used in step S102 and maps these row index values (or specific basis vector characteristics associated with the segment block partitioning process) to corresponding weight coefficients , and the setting of this weight coefficient is designed to reflect the contribution degree of the corresponding Hadamard basis vector when decomposing the segment block signal or its sensitivity to the segment block data pattern. The specific setting process: For the Hadamard basis vector with the strongest association with a certain segment block (for example, the basis vector that plays a decisive role in determining the boundary of the segment block in the integral segment algorithm, or the basis vector with the largest inner product with the segment block data content), calculate the absolute value of its inner product with the data segment , and the system maintains a maximum absolute value of the inner product observed in a large number of typical data analyses (for example, ), then the weight coefficient , and ensure that its value is within the interval (if the calculated value exceeds 1, take 1). For the first segment block, if the absolute value of the inner product calculated for the Hadamard basis vector with the strongest association (row index 5) is 127.5, then its weight coefficient , for the second segment block (associated row index 12), the absolute value of the inner product is 110.0, then , for the third segment block (associated row index 30), the absolute value of the inner product is 136.5, then , for the fourth segment block (associated row index 67), the absolute value of the inner product is 120.0, then .

[0031] Finally, the system integrates the unique number of each segment block, the calculated hexadecimal start address bits, the byte value length, and the mapped weight coefficient into a structured table to form a segment block index table.

[0032] Table 1 Segment Block Index Table ; As shown in Table 1, this table is a specific example of a segment block index table generated according to step S103, which contains information on four segment blocks. Each entry lists the unique number of the segment block, its hexadecimal start address in the original 32-byte data frame, the length in bytes, and a weight coefficient value between 0 and 1. Assume that the total number of segments in the segment block index table for subsequent processing is 60.

[0033] Please refer to Figure 3 , and the specific steps for obtaining the skip segment block processing path are as follows: S201: Based on the master synchronization key group, locate the Nth starting bit, intercept a continuous M-bit binary sequence, convert the binary sequence into a decimal value, extract the last K-bit binary sequence of the master synchronization key group, convert it into a hexadecimal value, and generate an offset parameter and an XOR parameter; The value of is the integer part of the logarithm base 2 of the total number of segments in the segment block index table, that is ; The system first accesses a preset master synchronization key group, which is a fixed string of binary sequences, set as "11111110110111001011101010011000011101100101010000110010000100001111111011011100101110101001100001110110010101000011001000010001" (this is an example of 24 bytes, 192 bits).

[0034] Parameter The value of is determined by the total number of segments in the segment block index table. The total number of segments is 60 (continuing the extended example in Table 1), calculate , and the system locates the 5th bit of the master synchronization key group as the starting bit accordingly (bit positions are counted from 0, that is, the 6th bit of the master synchronization key group. The original key sequence is "111111101101…", and the bold one is the 5th bit).

[0035] Starting from this 5th starting bit, the system intercepts a continuous bit binary sequence, set the parameter bits, so the intercepted 16-bit sequence is "1101101110010111" (corresponding to hexadecimal 0xDB97). Convert this 16-bit binary sequence "1101101110010111" into a decimal value, that is .

[0036] At the same time, the system extracts the last bit binary sequence of the master synchronization key group, set the parameter bits. The last 8 bits of the master synchronization key group are "00010001" (corresponding to the last part of the key sequence “…0011001000010001”). Convert it into a hexadecimal value, that is "0x11".

[0037] Thus, an offset parameter (decimal value 56215) and an XOR parameter (hexadecimal value "0x11") are generated.

[0038] S202: Call the index bit values in the segment block index table, convert each index bit value into a binary bit stream, align the hexadecimal bit width of the exclusive OR parameter, perform exclusive OR operations bit by bit, shift the operation result left by K bits and then intercept the last M-bit binary sequence, and convert it into a decimal value to generate a processing path coefficient. The index bit values in the segment block index table generated by system call S103 (as shown in Table 1, with a total of 60 segments), where the index bit value here is the segment block number. Taking the segment block number 1 as an example, its index bit value is 1. Convert this index bit value 1 into a binary bit stream with a fixed length. It is set to uniformly use 8-bit binary representation, so the 8-bit binary of 1 is "00000001".

[0039] Align the bit width (8 bits) of this binary bit stream "00000001" with the exclusive OR parameter "0x11" (its 8-bit binary is "00010001") generated in S201. After confirming that the bit widths are the same, perform exclusive OR (XOR) operations bit by bit: The operation result is binary "00010000" (i.e., hexadecimal 0x10).

[0040] Subsequently, perform a logical left shift bit operation on this operation result "00010000", where (from S201), perform it within a 16-bit operation space (high bits are shifted out and low bits are filled with 0). Shifting "0000000000010000" left by 8 bits gives "0001000000000000".

[0041] Finally, intercept the last bit binary sequence from the left-shifted result "0001000000000000", where (from S201), that is, intercept the entire "0001000000000000", convert it into a decimal value, , and this value is the processing path coefficient generated for the original index bit value 1. Perform the same calculation process for each index bit value (from 1 to 60) in the segment block index table to obtain their respective processing path coefficients.

[0042] S203: Add the offset parameter to the processing path coefficient, perform a modulo operation on the added result with the total number of segment blocks, map the remainder to the index bit value of the segment block index table, and rearrange the segment block index bits in the order of the remainder to generate a jump-type segment block processing path.

[0043] Add the offset parameter (56215) obtained in S201 to the processing path coefficient calculated for a specific original index bit value in S202. For the original index bit value 1, its processing path coefficient is 4096, and the result of the addition is .

[0044] Perform a modulo operation on this addition result with the total number of segment blocks. The total number of segment blocks is 60 (from the calculation premise in S201 for ), then : The remainder is 11.

[0045] The system maps this remainder 11 to the index bit value in the segment block index table. This means that in the new skip processing path, the segment block with the original processing order of 1 now becomes the segment block represented by the index 11 in the processing order. Perform the calculation steps of S202 and S203 for all 60 original index bit values (1, 2,..., 60) in the segment block index table to obtain a sequence consisting of 60 new index bit values. The order of this sequence defines the skip segment block processing path. For example, if the original index 1 is mapped to the new index 11, the original index 2 is mapped to the new index 45 after calculation, the original index 3 is mapped to the new index 2, and so on. The finally generated skip segment block processing path is , replacing the original sequential processing path .

[0046] Please refer to Figure 4 . The specific acquisition steps of S3 are as follows: S301: Based on the satellite three-axis coordinate parameters and the timestamp sequence, detect the interval mutation points of adjacent timestamps in the skip segment block processing path. Use the mutation points as the time window boundaries, and cut the segment blocks at a fixed step size to generate a segment block time window sequence; Based on the skip segment block processing path generated by S203, the system retrieves the satellite three-axis coordinate parameters (X, Y, Z, unit: km) corresponding to each segment block in this path and the corresponding timestamp sequence (unit: second, accurate to millisecond), and obtains a time-ordered coordinate and timestamp data set: timestamp sequence coordinate sequence The specific values are: , , , , (The time interval changes here) , ,

[0047] The system detects whether there are mutation points in the interval of adjacent timestamps in this path and calculates the intervals of each adjacent timestamp: (Significantly greater than the previous interval) The mutation judgment criterion is: when a certain time interval simultaneously satisfies two conditions: 1) greater than the previous valid time interval by times, 2) itself is greater than a minimum reference interval , then it is considered that there is a mutation between and (or at the marker point ). The setting of the parameter refers to the volatility of the timestamp interval under normal communication conditions. Under normal circumstances, the ratio of usually fluctuates slightly between 0.8 and 1.2. To ensure that real transmission interruptions or interval mutations caused by delays can be detected, rather than normal scheduling jitters, the value is set to 3.0, and the minimum reference interval is set to (twice the normal maximum interval) to filter out small interval changes that do not constitute window segmentation. In the above data, , this value is greater than , and is greater than , so a time interval mutation point is determined between and (marker point ).

[0048] The system uses these identified mutation points as the natural boundaries of the time window and combines a fixed step size (set to twice the interval between two sampling points under normal circumstances) to cut the data segment and generate a sequence of segment time windows. The first window W1 contains data from to (duration ). Since a mutation is detected at , W1 ends here. The second window W2 starts from the first timestamp immediately following the mutation and contains data (duration ). Window W1 data: Window W2 data: .

[0049] S302: Invoke the gray relational analysis model, extract the three-axis coordinate parameters of each window in the segment block time window sequence, calculate the change rate of the coordinate parameters at adjacent timestamps within the window, synchronously extract the coordinate data corresponding to the timestamps in the shielding interval, calculate the difference in time series synchronization between the two, and perform cumulative integral difference analysis on the difference sequence through the gray absolute correlation degree algorithm to generate a correlation degree matrix; The calculation formula of the gray absolute correlation degree algorithm is: ; where is the change rate of the coordinates of the segment block time window, is the change rate of the coordinates of the shielding interval; The system invokes the gray relational analysis model to process the segment block time window sequence generated in S301, and analyzes the data within each window. Taking window W1 as an example, it contains data points , and the system calculates the change rate of the three-axis coordinate parameters within this window at adjacent timestamps to form a reference sequence . The change rate of the X-axis coordinate : ; ; Therefore, the X-axis reference sequence of window W1 is (unit: km / s). Similarly, calculate the change rates of the Y-axis and Z-axis: Y-axis: ; ; ; Z-axis: ; ; .

[0050] Meanwhile, the system extracts the satellite coordinate data corresponding to the timestamps under a predefined or model-predicted theoretical "shielding interval" (or interference-free ideal state), calculates its change rate, and forms a comparison sequence . The data of this comparison sequence is from the predicted values of the satellite orbit dynamics model under the assumption of no signal interference or tampering. For the two time sub-segments of window W1, the predicted X-axis coordinate change rate sequence is (unit: km / s), the Y-axis is , and the Z-axis is .

[0051] The system passes through the gray absolute correlation degree algorithm Compare the timing synchronization differences between these two sequences ( and ). Before applying this formula, to ensure comparability of each item and eliminate the influence of the absolute value magnitude, all rate-of-change values ( and ) are made dimensionless by dividing by a reference rate of change . This makes the constant '1' in the formula comparable to the processed rate-of-change values on the same scale. The conversion rule is: if the original rate of change is , then the dimensionless value used in the formula calculation is . For example, becomes the dimensionless value 0.50. Taking the first comparison point on the X-axis as an example: after dimensionless processing: , .

[0052] ; The second comparison point on the X-axis: after dimensionless processing: , .

[0053] ; The average X-axis correlation degree of window W1; Similarly, calculations are performed for the Y-axis and Z-axis: for the Y-axis : ; ; for the Y-axis : ; ; ; for the Z-axis : ; ; for the Z-axis : ; ; ; The comprehensive correlation degree of window W1 is the arithmetic mean of the average correlation degrees of the three axes: ; This calculation is performed for all time windows to form a sequence containing the comprehensive correlation degree values of each window, that is, the correlation degree matrix (here it is a one-dimensional vector). The advantage of the formula is that by comprehensively considering the numerical magnitudes and their differences of the reference sequence and the comparison sequence at corresponding points, it can quantitatively evaluate the morphological similarity of two time series. Even if there are slight deviations in their absolute values, it can effectively reflect the consistency of their dynamic change trends.

[0054] Table 2 Example of satellite coordinate change rate and correlation degree calculation ; As shown in Table 2, this table lists the data and results of the grey absolute correlation degree calculation for the X-axis coordinate change rate (after non-dimensionalization) of window W1 in step S302, including the change rate of the reference sequence, the change rate of the comparison sequence, and the point-by-point correlation degree obtained by calculation.

[0055] S303: Traverse the correlation degree values of each window in the correlation degree matrix, compare the values with the tampering determination threshold, record the window indices lower than the threshold, count the proportion of the indices, and extract the corresponding segment block numbers to generate the tampering risk coefficient and the set of risk segment blocks.

[0056] The system traverses the comprehensive correlation degree values of each window in the correlation degree sequence calculated in S302. Suppose the comprehensive correlation degree of window W1 is 0.9891, the comprehensive correlation degree of window W2 obtained through similar calculation is 0.7850, the comprehensive correlation degree of window W3 is 0.9725, and so on. A total of correlation degree values of windows are obtained.

[0057] The system compares these correlation degree values one by one with a preset tampering determination threshold . This is set based on the statistical analysis of a large amount of historical data: collect real data segments without interference under the paths of mature satellites, calculate their correlation degrees with the predictions of the ideal orbit model, obtain a normal distribution, with a mean of , a standard deviation of . Then collect groups of data segments known to be slightly to moderately interfered or simulated tampered, calculate their correlation degrees, obtain another distribution, with a mean of , a standard deviation of . In order to effectively distinguish normal data from potential risk data and at the same time control the false alarm rate and the missed alarm rate, is set in the critical region of the two distributions, with a specific value of . At the same time, , considering comprehensively, select As a determination threshold, this threshold is higher than the correlation degrees of most of the interfered data and lower than the correlation degrees of the vast majority of the normal data.

[0058] Compare the correlation degree 0.9891 of window W1 with ; , and determine it as normal; compare the correlation degree 0.7850 of window W2 with ; , determine it as a risk, and record the index of window W2; compare the correlation degree 0.9725 of window W3 with ; , and determine it as normal. The system counts all windows, and the number of windows with a correlation degree lower than . Assume that in addition to W2, the correlation degrees of two other windows, W8 and W15, are also lower than 0.920. Then a total of 3 windows are marked as risk windows, and the indexes of these windows are recorded.

[0059] Based on this, the system calculates the tampering risk coefficient, which is defined as the ratio of the number of windows lower than the threshold to the total number of windows, that is . This 0.15 is the tampering risk coefficient obtained from this analysis. At the same time, the system extracts the original segment block numbers corresponding to these risk windows (the mapping relationship between segment blocks and windows has been established when generating time windows in S301) to form a risk segment block set. Assume that window W2 corresponds to segment block DB015, window W8 corresponds to segment block DB042, and window W15 corresponds to segment block DB058. Then the risk segment block set is {DB015, DB042, DB058}. This result indicates that the data of these three segment blocks have significant differences from the expected satellite behavior and have a high suspicion of tampering or interference.

[0060] Please refer to Figure 5 , and the specific steps for obtaining the re-encryption key group are as follows: S401: Call the dynamic key parameter group in the main synchronization key group, extract the tampering risk coefficient as a weight factor, multiply each parameter item in the dynamic key parameter group by the weight factor, calculate the modular feature of the product result as the input of the first-level linear transformation, perform the first-round linear superposition on the key displacement parameter based on the modular feature, and perform the second-level linear transformation with the square value of the weight factor to generate a perturbed key vector; The modular feature is calculated through the irreducible polynomial of the Galois field ; The system calls a dynamic key parameter group stored internally in the main synchronization key group (from S201). This parameter group contains several integer parameter items, which are set as: . The system extracts the tampering risk coefficient calculated in S303 as the weight factor.

[0061] Multiply each parameter item in the dynamic key parameter group by this weight factor to obtain weighted parameters: ; ; For subsequent Galois field operations, round these floating-point results down to the nearest integer: .

[0062] The system calculates the modular characteristics of these weighted parameters (in integer form), which are generated through operations within the Galois field , with the selected irreducible polynomial being (standard AES polynomial). Take as the coefficients of the polynomial , that is , and calculate the value of this polynomial in (for example, treat 22, 12, 31 as field elements and perform the corresponding field multiplications and additions). After the operation, an 8-bit modular characteristic is obtained. The specific calculation is , where represents multiplication, and represents exclusive OR (i.e., addition). Let the operation result be (decimal 163).

[0063] The system uses a preset key displacement parameter vector , whose length is the same as the length of the perturbation key vector to be generated. Set (with a length of 8). Based on the modular characteristic , perform the first-round linear superposition on each element of the key displacement parameter according to the transformation rule , where the system constant . For : ; For : ; … (and so on to obtain ).

[0064] Subsequently, perform a second-round linear transformation on the displacement parameter after the first-round transformation and the square value of the weight factor to generate each element of the final perturbation key vector ​​​ , the square value of the weight factor is . To make it participate in integer operations, multiply it by a scaling factor of 1000 and take the integer part: ; The second linear transformation rule is , where the system constant . For : ; For : ; For : ; For : ; For : ; For : ; For : ; For : ; The finally generated perturbed key vector is (decimal byte value).

[0065] Table 3 Example of the generation process of the perturbed key vector part ; As shown in Table 3, this table outlines the partial key parameter calculation process for generating the perturbed key vector in step S401, showing the weighted processing of dynamic parameters, the introduction of the modular characteristics of comprehensive calculations, and some intermediate values and final results of two rounds of linear transformation.

[0066] S402: Based on the perturbed key vector, traverse the byte stream of each block in the risk block set, extract the binary value of each byte in the block byte stream, perform an exclusive OR operation on the byte value with the corresponding byte of the perturbed key vector, and perform a left shift or right shift operation on the exclusive OR result according to the parity bit status of the current byte of the perturbed key vector to generate an intermediate encrypted block; The system uses the perturbed key vector generated in S401 (8 bytes in length), traverse each segment block in the set of risk segment blocks {DB015, DB042, DB058} determined in S303. Taking the risk segment block DB015 as an example, its original byte stream (extracted from the corresponding position in the original communication data frame) is set to (assuming the length of DB015 is 8 bytes, which is the same as the length of the perturbation key vector; if not, the perturbation key vector is used cyclically or aligned according to specific rules).

[0067] The system extracts each byte in the byte stream of segment block DB015 and performs an exclusive OR operation on its binary value with the corresponding byte of the perturbation key vector (if the length of the segment block is greater than the length of the key vector, the key vector is used cyclically). Then, according to the parity state of the least significant bit (LSB) of the current byte of the perturbation key vector, a cyclic shift operation is performed on the exclusive OR result. The rule is: if the LSB is 0 (even), the exclusive OR result is cyclically shifted left by 1 bit; if the LSB is 1 (odd), the exclusive OR result is cyclically shifted right by 1 bit.

[0068] For the first byte of segment block DB015 (decimal 26): corresponding to the perturbation key byte (binary ). Exclusive OR operation: (0xA4). , its LSB is 0 (even), so the exclusive OR result 164 ( ) is cyclically shifted left by 1 bit: (0x49). The first byte of the intermediate encrypted segment block is 0x49.

[0069] For the second byte of segment block DB015 (decimal 63): corresponding to the perturbation key byte (binary ). Exclusive OR operation: (0xFA). , its LSB is 1 (odd), so the exclusive OR result 250 ( ) is cyclically shifted right by 1 bit: (0x7D). The second byte of the intermediate encrypted segment block is 0x7D.

[0070] For the third byte of segment block DB015 (decimal 136): corresponding to the perturbation key byte (binary ). Exclusive OR operation: (0x34). , its LSB is 0 (even), so the exclusive OR result 52 ( ) is cyclically shifted left by 1 bit: (0x68). The third byte of the middle encrypted segment block is 0x68.

[0071] Process all bytes of DB015 and all bytes of other segment blocks (DB042, DB058) in the risk segment block set in this way, and combine all the processed bytes in the original order to form their respective middle encrypted segment blocks. For example, the middle encrypted segment block generated by segment block DB015 .

[0072] S403: For the middle encrypted segment block, extract the complement mapping reference value of each byte, locate the mapping rule in the complement mapping table according to the reference value, perform bit-level superposition on the byte data and the mapping rule, and combine the superposition results of all segment blocks to generate the re-encrypted key group; The complement mapping table is dynamically generated according to the Hamming weight parity of the dynamic key parameter group, satisfying , where is the original byte, is the Hamming weight.

[0073] The system processes the byte stream of each middle encrypted segment block generated by S402. Take the first byte of the middle encrypted segment block as an example.

[0074] The system extracts the complement mapping reference value of this byte. In this embodiment, the complement mapping reference value directly takes the byte value itself, that is .

[0075] According to this reference value locate the mapping rule in a dynamically generated complement mapping table. The generation of this complement mapping table is related to the parity of the Hamming weight of the dynamic key parameter group in S401. First, calculate the binary representation of each parameter and its Hamming weight: , , , Total Hamming weight . Since the total Hamming weight 10 is even, the system selects or generates a complement mapping table designed for even Hamming weights . This mapping table maps the reference value (0x00 - 0xFF) to a specific 8-bit mapping rule byte . A fragment of is defined as follows (for example only): - Reference value range [0x00 - 0x0F] -> mapping rule -Reference value range [0x40 - 0x4F] -> Mapping rule -…(covering the entire range of 0x00 - 0xFF) For the reference value , which falls within the range of [0x40 - 0x4F], look up the table to obtain the corresponding mapping rule .

[0076] The system will perform bit-level superposition on the byte data of the intermediate encrypted segment block and the obtained mapping rule . The bit-level superposition operation here is defined as an exclusive OR operation, according to the formula (here is the intermediate encrypted byte, is the final re-encrypted byte): Re-encrypted byte .

[0077] For all other bytes of the intermediate encrypted segment block ( , ,…), as well as all intermediate encrypted bytes of other risk segment blocks (DB042, DB058), perform the same operation of "extracting the reference value -> looking up the mapping rule in the table -> bit-level superposition".

[0078] Merge the byte sequences obtained after the above final superposition processing of all risk segment blocks, in their original segment block order and the byte order within the segment block, to form the final re-encrypted key group. This key group is a string of continuous byte data, and its content is the result of multiple encryption transformations on the original risk data segment, which is used for subsequent security applications or to replace the original risk data. In this method, the complement mapping table is dynamically generated or selected according to the Hamming weight parity of the dynamic key parameter group, ensuring the variability of the mapping rule itself and enhancing security.

[0079] A satellite signal anti-tampering system, which is used to execute the above satellite signal anti-tampering method. The system includes: A frame segment cutting module, which is used to obtain a communication data frame through the satellite orbit number and the real-time position vector, input the communication data frame into the Hadamard integral segment algorithm to perform non-uniform segment block cutting, generate a segment block index table, record the starting address bit, the segment block length value, and the initial weight bit value, and transfer the segment block index table to the key path generation module; A key path generation module, which is used to extract the sub-key sequence from the Nth bit to the N + Mth bit of the main synchronization key group as the offset parameter, extract the last K bits as the shift exclusive OR parameter, perform an exclusive OR operation on the starting address bit and the initial weight bit value in the segment block index table, and input it into the logical rotation function to generate a jumping segment block processing path, and transfer the jumping segment block processing path to the risk determination module; A risk determination module, which is used to input the jump-type block processing path into the gray correlation analysis model through satellite three-axis coordinate parameters and timestamp sequences, calculate the correlation degree between the block time window and the shielding interval, determine whether the block is in a tampering risk state according to a preset correlation degree threshold, output a tampering risk coefficient and a set of risk blocks, and transmit the tampering risk coefficient and the set of risk blocks to the dynamic encryption module; A dynamic encryption module, which is used to call the dynamic key parameter group in the main synchronization key group, combine the tampering risk coefficient, perform a perturbation operation on the key displacement parameter through a double linear mapping function to generate a re-encryption key group, and perform a byte-by-byte exclusive OR and logical shift operation on the set of risk blocks, and transmit the re-encryption key group to the satellite communication link for data encapsulation.

[0080] The above are only the preferred embodiments of the present invention, and do not limit the present invention in other forms. Any person skilled in the art may use the technical content disclosed above to make changes or modifications into equivalent embodiments with equivalent changes and apply them to other fields. However, as long as it does not depart from the technical solution content of the present invention, any simple modification, equivalent change and modification made to the above embodiments based on the technical essence of the present invention still fall within the protection scope of the technical solution of the present invention.

Claims

1. A method for preventing satellite signal tampering, characterized in that, It includes the following steps: S1: Obtain the current communication data frame through the satellite orbit number, real-time position vector and timestamp, input the data frame into the Hadamard integral segment algorithm to perform non-uniform segment block cutting, generate a segment block index table, and record the starting address bit, segment block length value and initial weight bit value; S2: Based on the master synchronization key group, extract the sub-key sequence from the Nth bit to the N+Mth bit as the offset parameter, extract the last K bits as the shift XOR parameter, perform XOR operations on the index bit values of multiple items in the segment block index table, and perform a logical rotation operation on the operation result to generate a jumping segment block processing path; S3: Based on the satellite three-axis coordinate parameters and timestamp sequence, input the jumping segment block processing path into the gray correlation analysis model, calculate the correlation degree between the segment block time window and the shielding interval, determine whether the segment block is in a tampering risk state according to the correlation degree threshold, and output the tampering risk coefficient and the risk segment block set.

2. The satellite signal anti-tampering method according to claim 1, characterized in that, The jumping segment block processing path includes a dynamic index bit, a rotation offset, and a segment block sequence identifier. The tampering risk coefficient includes a correlation degree threshold, a risk quantization value, and a period determination flag. The risk segment block set includes a risk segment block number, a time window label, and a priority identifier.

3. The satellite signal anti-tampering method according to claim 2, wherein The matrix generation rule in the Hadamard integral segment algorithm is as follows: when the data frame length is odd, round up the data frame length to the nearest and intercept the valid bits to construct a Hadamard orthogonal basis matrix with the order being half of the intercepted data frame length; The said and The value is dynamically determined by taking the modulus operation of the total number of segment blocks according to the hash value of the satellite orbit number; The correlation threshold is obtained by optimizing based on the historical tampering data set using the gradient descent method, and its value range is .

4. The satellite signal anti-tampering method according to claim 3, wherein The specific steps for obtaining the segment block index table are as follows: S101: Obtain the real-time position vector and timestamp corresponding to the satellite orbit number, extract the binary communication data stream through the satellite communication link parsing protocol, parse the start byte and end byte fields in the protocol frame header identifier, locate the valid data segment according to the field length and checksum verification result, and intercept the continuous data segment after the frame header identifier to generate a communication data frame; S102: Call the matrix generation rule in the Hadamard integral segment algorithm to construct a Hadamard orthogonal basis matrix with an order of half of the data frame length, convert the binary sequence of the communication data frame into a decimal numerical vector, perform element-by-element multiplication with the matrix row vector and accumulate the sum, calculate the standard deviation of adjacent accumulated values, and at the same time determine the segment block boundary based on the mutation point where the standard deviation change rate exceeds the preset threshold, and count the number of bits between the boundaries as the length value to generate segment block segmentation parameters; The conversion method of the decimal numerical value vector is: segment the binary sequence by every 8 bits and convert it into a normalized numerical value, satisfying , where is the binary bit value; S103: Based on the segment block starting offset in the segment block segmentation parameters, calculate the hexadecimal address bit according to the rule of 8 bits per byte, divide the segment block length value by 8 and round up to get the byte value, extract the row index value of the Hadamard orthogonal basis matrix and map it as the weight coefficient, and integrate the address bit, byte value and weight coefficient into a structured table to obtain the segment block index table.

5. The satellite signal anti-tampering method according to claim 4, characterized in that, The specific steps for obtaining the jumping segment block processing path are as follows: S201: Based on the master synchronization key group, locate the starting bit of the Nth bit, intercept the continuous M-bit binary sequence, convert the binary sequence into a decimal numerical value, extract the last K-bit binary sequence of the master synchronization key group, and convert it into a hexadecimal numerical value to generate the offset parameter and the XOR parameter; The value of is the integer part of the logarithm to the base 2 of the total number of segments in the segment block index table, that is ; S202: Call the index bit values in the segment block index table, convert each index bit value into a binary bit stream, align the hexadecimal bit width of the exclusive-or parameter, perform exclusive-or operations bit by bit, shift the operation result left by K bits and then intercept the last M-bit binary sequence, convert it into a decimal value, and generate a processing path coefficient; S203: Add the offset parameter to the processing path coefficient, perform a modulo operation on the addition result with respect to the total number of segment blocks, map the remainder to the index bit value of the segment block index table, and rearrange the segment block index bits in the order of the remainder to generate a skip-type segment block processing path.

6. The satellite signal anti-tampering method according to claim 5, wherein The acquisition steps of S3 are specifically as follows: S301: Based on the satellite three-axis coordinate parameters and the timestamp sequence, detect the interval mutation points of adjacent timestamps in the skip-type segment block processing path, use the mutation points as the boundaries of the time window, and cut the segment blocks at a fixed step length to generate a segment block time window sequence; S302: Call the gray correlation analysis model, extract the three-axis coordinate parameters of each window in the segment block time window sequence, calculate the change rate of adjacent timestamps of the coordinate parameters within the window, synchronously extract the coordinate data corresponding to the timestamps in the occlusion interval, calculate the difference in their temporal synchronization, and perform cumulative integral difference analysis on the difference sequence through the gray absolute correlation degree algorithm to generate a correlation degree matrix; The calculation formula of the gray absolute correlation degree algorithm is: ; Among them is the coordinate change rate of the segment block time window, is the coordinate change rate of the shielding interval; S303: Traverse the correlation degree values of each window in the correlation degree matrix, compare the values with the tampering determination threshold, record the window indexes lower than the threshold, count the proportion of the indexes and extract the corresponding segment block numbers to generate a tampering risk coefficient and a risk segment block set.

7. The satellite signal anti-tampering method according to claim 6, characterized in that, The method further includes: S4: Call the dynamic key parameter group in the main synchronization key group, combine the tampering risk coefficient, perform a perturbation operation on the key displacement parameter through a double linear mapping function to generate a re-encryption key group, and perform byte-by-byte exclusive-or, logical shift, and complement mapping operations on the risk segment block set.

8. The satellite signal anti-tampering method according to claim 7, wherein The re-encryption key group includes the perturbed displacement parameter, the exclusive-or operation order, and the complement mapping rule; The dynamic key parameter group is generated by non-linearly transforming the master synchronization key group through an elliptic curve and satisfies , where is the base point, is a random integer, is a prime number.

9. The satellite signal anti-tampering method according to claim 8, characterized in that, The acquisition steps of the re-encryption key group are specifically as follows: S401: Call the dynamic key parameter group in the main synchronization key group, extract the tampering risk coefficient as a weight factor, multiply each parameter item in the dynamic key parameter group by the weight factor, calculate the modulo characteristic of the product result as the input of the first linear transformation, perform the first-round linear superposition on the key displacement parameter based on the modulo characteristic, and perform the second linear transformation with the square value of the weight factor to generate a perturbed key vector; The modularity feature is calculated and generated through an irreducible polynomial of the Galois field ; ​ S402: Based on the perturbed key vector, traverse the byte stream of each segment block in the risk segment block set, extract the binary value of each byte in the segment block byte stream, perform an exclusive-or operation on the byte value and the corresponding byte of the perturbed key vector, and perform a left shift or right shift operation on the exclusive-or result according to the parity bit state of the current byte of the perturbed key vector to generate an intermediate encrypted segment block; S403: For the intermediate encrypted segment block, extract the complement mapping reference value of each byte, locate the mapping rule in the complement mapping table according to the reference value, perform bit-level superposition of the byte data and the mapping rule, and merge the superposition results of all segment blocks to generate a re-encryption key group; The complement mapping table is dynamically generated according to the Hamming weight parity of the dynamic key parameter group, satisfying , where is the original byte is the Hamming weight 10. A satellite signal anti-tampering system, characterized in that, The system is used to implement the satellite signal anti-tampering method described in any one of claims 1-9. The system includes: A frame segment cutting module, which is used to obtain a communication data frame through the satellite orbit number and the real-time position vector, input the communication data frame into the Hadamard integral segment algorithm to perform non-uniform segment block cutting, generate a segment block index table, record the starting address bit, the segment block length value, and the initial weight bit value, and transfer the segment block index table to the key path generation module; A key path generation module, which is used to extract the sub-key sequence from the Nth bit to the N+Mth bit in the master synchronization key group as the offset parameter, extract the last K bits as the shift XOR parameter, perform an XOR operation on the starting address bit and the initial weight bit value in the segment block index table, and input it into the logical rotation function to generate a jumping segment block processing path, and transfer the jumping segment block processing path to the risk determination module; A risk determination module, which is used to input the jumping segment block processing path into the gray correlation analysis model through the satellite three-axis coordinate parameters and the timestamp sequence, calculate the correlation degree between the segment block time window and the shielding interval, judge whether the segment block is in a tampering risk state according to the preset correlation degree threshold, output the tampering risk coefficient and the risk segment block set, and transfer the tampering risk coefficient and the risk segment block set to the dynamic encryption module; A dynamic encryption module, which is used to call the dynamic key parameter group in the master synchronization key group, combine the tampering risk coefficient, perform a perturbation operation on the key displacement parameter through the double linear mapping function to generate a re-encryption key group, and perform byte-by-byte XOR and logical shift operations on the risk segment block set, and transfer the re-encryption key group to the satellite communication link for data encapsulation.

Citation Information

Patent Citations

  • Data transmission method and system based on Beidou satellite

    CN118300672A

  • Aviation data bus signal encryption method and system based on FPGA

    CN119420580A

  • On-orbit safety identification method

    CN119863714A

  • Satellite internet traffic security protection method and system

    CN119997005A

  • Location management for satellite systems

    US20200213000A1

Cited By

  • Satellite safety communication method and system

    CN121037106A

  • Satellite secure communication method and system

    CN121037106B