Satellite communication encryption authentication method and system based on dynamic key

By predicting the network topology based on satellite orbit parameters and dividing time slices, generating dynamic key pools and encrypting subkey segments, combining pre-distribution path planning and blockchain hash verification, the problems of key synchronization delay and leakage in low-orbit satellite networks are solved, and the security and attack resistance of satellite communication are improved.

CN120499651AInactive Publication Date: 2025-08-15SHANDONG STAR NETWORK GAOFEN DATA IND CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510592926.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-09
Publication Date
2025-08-15
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

In the prior art, the high dynamics of low-orbit satellite networks make it difficult for traditional static key management and dynamic key distribution solutions to adapt to the fast switching of satellite nodes in real time, high key synchronization delay, easy to leak pre-distribution keys, and decentralized solutions such as blockchain are low in key distribution efficiency in high dynamic scenarios, which cannot meet the millisecond-level topological response requirements of low-orbit satellite networks.

Method used

By predicting the network topology based on satellite orbit parameters and dividing the time slices, a dynamic key pool is generated, and the key is split into subkey segments and then the forward correlation encryption method is used to build a collection of encryption key segments. Combining pre-distribution path planning and blockchain hash verification mechanism, it realizes trusted traceability of the key distribution path, dynamically decrypting the reorganization key and two-way authentication process.

Benefits of technology

Real-time optimization of key distribution is realized, the risk of single point leakage is reduced, the forward security and attack resistance of satellite communication links are improved, and the problems of high key synchronization delay and low verification efficiency are solved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120499651A_ABST
    Figure CN120499651A_ABST
Patent Text Reader

Abstract

The invention relates to a satellite communication encryption authentication method and system based on a dynamic key. According to the method, network topology is predicted based on satellite orbit parameters, time slices are divided to generate a dynamic key pool, a key is divided into sub-key segments, an encryption key segment set is constructed in a forward association encryption mode, and credible tracing of a key distribution path is realized in combination with pre-distribution path planning and a block chain hash verification mechanism. And the key is recombined through dynamic decryption, and a bidirectional authentication process is carried out. The problems of high key synchronization delay, easy leakage of the pre-distributed key and low verification efficiency in the high dynamic satellite network are solved, the real-time optimization of key distribution, single-point leakage risk isolation and lightweight security authentication are realized, and the forward security and anti-attack ability of a satellite communication link are significantly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of satellite communications, and in particular relates to a satellite communication encryption authentication method and system based on dynamic keys. Background Art

[0002] As a vital means of communication with global coverage, satellite communications play an irreplaceable role in emergency communications, military coordination, the Internet of Things, and other fields. However, with the large-scale deployment of low-orbit satellite networks, the high-speed mobility of satellite nodes leads to frequent changes in network topology, posing severe challenges to traditional static key management and dynamic key distribution solutions.

[0003] In existing technologies, centralized key management platforms have high response delays and are unable to adapt to the rapid switching of satellite nodes in real time, resulting in delayed key updates and security risks in communication links. Although the pre-filled key pool mechanism can alleviate the pressure of key synchronization, the long-term exposure of pre-distributed keys may cause global security threats once leaked.

[0004] In addition, decentralized solutions such as blockchain rely on a network-wide consensus mechanism, which results in low key distribution efficiency in highly dynamic intersatellite link scenarios and cannot meet the millisecond-level topological response requirements of low-orbit satellite networks.

[0005] To address the above issues, there is an urgent need for a new encryption and authentication method that can combine dynamic prediction of network topology, key segmentation protection and lightweight verification to reduce the computing and storage overhead of satellite nodes while ensuring forward security. Summary of the Invention

[0006] Based on this, it is necessary to provide a satellite communication encryption authentication method and system based on dynamic keys to address the above technical problems.

[0007] In a first aspect, the present application provides a satellite communication encryption authentication method based on a dynamic key, comprising:

[0008] S1: Predict the future satellite network topology based on satellite orbit parameters, divide the time slices according to the network topology and generate the corresponding dynamic key pool, split the key of the dynamic key pool of the current time slice into sub-key segments, and use the key of the previous time slice to encrypt the sub-key segments of the current time slice to generate an encrypted key segment set;

[0009] S2: Plan a pre-distribution path based on the network topology, and distribute the encryption key segment set to the target satellite node along the pre-distribution path through the inter-satellite link; generate a verification identifier based on the pre-distribution path and time slice identifier;

[0010] S3: Respond to the communication request sent by the terminal carrying the time slice identifier, extract the encryption key segment set from the target satellite node, decrypt and reconstruct the encryption key segment set using the key of the previous time slice to obtain the complete key of the current time slice; generate the session key based on the verification identifier and the complete key and return it to the terminal;

[0011] S4: The random number between the terminal and the target satellite node is encrypted and hashed using the session key to complete two-way authentication. Dynamic encrypted communication is triggered after authentication is passed.

[0012] In a second aspect, the present application also provides a satellite communication encryption authentication system based on dynamic keys, comprising:

[0013] The dynamic key pool generation module is used to predict the network topology of future satellites based on satellite orbit parameters, divide time slices according to the network topology and generate corresponding dynamic key pools, split the key of the dynamic key pool of the current time slice into sub-key segments, and use the key of the previous time slice to encrypt the sub-key segments of the current time slice to generate an encrypted key segment set;

[0014] The key distribution planning module is used to plan a pre-distribution path according to the network topology, distribute the encryption key segment set to the target satellite node through the inter-satellite link according to the pre-distribution path; generate a verification identifier based on the pre-distribution path and time slice identifier;

[0015] The session key generation module is used to respond to the communication request sent by the terminal with the time slice identifier, extract the encryption key segment set from the target satellite node, decrypt and reconstruct the encryption key segment set using the key of the previous time slice to obtain the complete key of the current time slice; generate the session key based on the verification identifier and the complete key and return it to the terminal;

[0016] The two-way authentication and communication module is used to encrypt and hash the random numbers between the terminal and the target satellite node through the session key to complete the two-way authentication, and trigger dynamic encrypted communication after the authentication is passed.

[0017] In a third aspect, the present application also provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, it implements a satellite communication encryption authentication method based on a dynamic key as in the first aspect.

[0018] In a fourth aspect, the present application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements a satellite communication encryption authentication method based on a dynamic key as in the first aspect.

[0019] The above-mentioned satellite communication encryption and authentication method and system based on dynamic keys predicts the network topology based on satellite orbit parameters and divides it into time slices to generate a dynamic key pool. The key is then split into sub-key segments and constructed using forward-associative encryption. This method combines pre-distribution path planning with a blockchain hash verification mechanism to achieve trusted traceability of the key distribution path. Dynamic decryption is used to reconstruct the key and conduct a two-way authentication process. This method addresses the issues of high key synchronization latency, easy leakage of pre-distributed keys, and low verification efficiency in highly dynamic satellite networks. It achieves real-time optimization of key distribution, isolation of single-point leakage risks, and lightweight security authentication, significantly improving the forward security and anti-attack capabilities of satellite communication links. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following briefly introduces the drawings required for use in the embodiments or related technical descriptions. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0021] Figure 1 A schematic diagram of a flow chart of a satellite communication encryption authentication method based on dynamic keys provided by the present invention;

[0022] Figure 2 The present invention provides a structural diagram of a satellite communication encryption authentication system based on dynamic keys. DETAILED DESCRIPTION

[0023] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0024] refer to Figure 1 , which presents a flow chart of a satellite communication encryption authentication method based on dynamic keys provided by the present application, the method comprising the following steps:

[0025] S1: Predict the future satellite network topology based on satellite orbit parameters, divide the time slices according to the network topology and generate the corresponding dynamic key pool, split the key of the dynamic key pool of the current time slice into sub-key segments, and use the key of the previous time slice to encrypt the sub-key segments of the current time slice to generate an encrypted key segment set.

[0026] Specifically, by integrating data from multiple sources, such as satellite navigation systems and ground monitoring stations, precise satellite orbital parameters can be obtained in real time, including position, velocity, acceleration, orbital inclination, right ascension of the ascending node, and mean anomaly. These parameters, combined with satellite kinematic and dynamic models, can be used to predict the satellite network topology over time. Prediction algorithms can employ machine learning models based on historical data, such as long-short-term memory (LSTM) networks, to learn and predict satellite trajectories and relative position changes, outputting satellite network topology maps at different times.

[0027] Based on predicted changes in network topology, the future is divided into multiple consecutive time slices. The length of each time slice is determined by the severity of the network topology change. For example, shorter time slices (e.g., a few seconds to tens of seconds) are set in areas with frequent topological changes, while longer time slices (e.g., a few minutes) are set in areas with relatively stable topology. For each time slice, a corresponding dynamic key pool is generated. The key pool can be generated using a quantum random number generator or a security-proven pseudo-random number generation algorithm to ensure the randomness and unpredictability of the key. The key length is set according to the requirements of the encryption algorithm and the security level, such as 128 bits or 256 bits.

[0028] The key in the dynamic key pool for the current time slice is split into multiple sub-key segments according to preset rules, such as fixed-length or variable-length segmentation strategies. The sub-key segments for the current time slice are encrypted using the key from the previous time slice as the encryption key. A symmetric encryption algorithm, such as AES (Advanced Encryption Standard), can be used to ensure the efficiency and security of the encryption process, generating a set of encrypted key segments.

[0029] S2: Plan a pre-distribution path based on the network topology, and distribute the encryption key segment set to the target satellite node along the pre-distribution path through the inter-satellite link; generate a verification identifier based on the pre-distribution path and time slice identifier.

[0030] Specifically, a pre-distribution path for the encryption key segment set is planned based on the predicted network topology. This path planning comprehensively considers factors such as intersatellite link quality, bandwidth, latency, and the storage and computing capabilities of satellite nodes. It can employ graph theory-based shortest path algorithms (such as Dijkstra's algorithm) or multi-constraint path planning algorithms (such as the ant colony algorithm) to determine the optimal transmission path from the key generation center to the target satellite node, ensuring efficient and reliable key distribution.

[0031] The encryption key segments are transmitted to the target satellite node via intersatellite links along a pre-planned, pre-distributed path. During transmission, technologies such as forward error correction (FEC) are employed to enhance data transmission's anti-interference and fault tolerance, ensuring that the key segments reach the target node accurately despite the complex electromagnetic environment in space and link fluctuations caused by high-speed satellite movement.

[0032] A verification identifier is generated based on the pre-distribution path and time slice identifier. This identifier can be generated by using a hash function (such as SHA-3) to calculate the relevant parameters of the pre-distribution path (such as the satellite node sequence on the path, link transmission time, etc.) and the time slice identifier. A fixed-length hash value is obtained as the verification identifier, which is used to verify the legitimacy of subsequent communication requests. This ensures that only the key segment set along the correct pre-distribution path and corresponding to the correct time slice is considered valid.

[0033] S3: Respond to the communication request sent by the terminal carrying the time slice identifier, extract the encryption key segment set from the target satellite node, decrypt and reassemble the encryption key segment set using the key of the previous time slice to obtain the complete key of the current time slice; generate the session key based on the verification identifier and the complete key and return it to the terminal.

[0034] Specifically, the target satellite node receives a communication request from a terminal, carrying a timeslot identifier. This request includes the terminal's identity, the type of data being requested, and the service requirements. The satellite node then performs preliminary parsing and verification of the request, checking for basic elements such as correct formatting and the legitimacy of the terminal's identity.

[0035] Based on the timeslice identifier in the communication request, the corresponding set of encryption key segments is extracted from the key pool stored in the target satellite node. The encryption key segments are decrypted using the key from the previous timeslice as the decryption key. The decryption algorithm corresponds to the encryption algorithm in step S1, such as the AES decryption algorithm. The decrypted sub-key segments are reassembled according to a pre-defined sequence and rules to recover the complete key for the current timeslice.

[0036] The session key is generated by combining the verification identifier and the reconstructed full key through a specific key derivation function (KDF). The KDF can use a hash-based message authentication code (HMAC) or a key derivation algorithm (such as HKDF). The KDF takes the verification identifier and the full key as input parameters and, through a series of hashing and key extraction operations, generates a high-entropy and secure session key. The session key is returned to the terminal via a secure communication channel. This channel can use digital envelope technology based on public key cryptography or other secure transmission protocols suitable for satellite communications to ensure the confidentiality and integrity of the session key during transmission.

[0037] S4: The random number between the terminal and the target satellite node is encrypted and hashed using the session key to complete two-way authentication. Dynamic encrypted communication is triggered after authentication is passed.

[0038] Specifically, the terminal and target satellite node each use the session key to encrypt and hash the random numbers they send to each other. The specific steps are as follows: the terminal generates a random number, encrypts it using the session key (e.g., using the symmetric encryption algorithm AES), then calculates the hash value of the encrypted data (e.g., using SHA-3), and sends the encrypted data and hash value to the satellite node. Upon receiving the data, the satellite node decrypts the data using the session key to obtain the random number, recalculates the hash value, and compares it with the received hash value to verify the data integrity and authenticity. Simultaneously, the satellite node also generates a random number and authenticates the terminal using the same process. This two-way authentication mechanism ensures the authenticity of the communicating parties and the security of the communication link.

[0039] After two-way authentication is successful, the communication link between the terminal and the target satellite node is officially established, triggering dynamic encrypted communication. During the communication process, the session key is used to perform real-time encryption and decryption operations on the transmitted data according to the preset encryption strategy and algorithm. The encryption algorithm can select an appropriate symmetric encryption algorithm (such as AES), stream encryption algorithm (such as ChaCha20), or a combination thereof based on the data type and security requirements to ensure the confidentiality of the communication data. At the same time, to cope with changes in satellite network topology and potential security threats, the session key can be regularly updated during the communication process according to preset time intervals or data traffic thresholds. The new key is used for encrypted communication, further improving the security and anti-attack capabilities of communication and achieving the effect of dynamic encrypted communication.

[0040] The above-mentioned satellite communication encryption and authentication method based on dynamic keys predicts the network topology based on satellite orbit parameters and divides it into time slices to generate a dynamic key pool. The key is then split into sub-key segments and constructed using forward-associative encryption. This method combines pre-distribution path planning with a blockchain hash verification mechanism to achieve trusted traceability of the key distribution path. Dynamic decryption is then used to reconstruct the key and conduct a two-way authentication process. This method addresses the issues of high key synchronization latency, easy leakage of pre-distributed keys, and low verification efficiency in highly dynamic satellite networks. It achieves real-time optimization of key distribution, isolation of single-point leakage risks, and lightweight security authentication, significantly improving the forward security and anti-attack capabilities of satellite communication links.

[0041] In an optional embodiment, S1 includes the following steps:

[0042] S11: Collect the satellite's orbital altitude, inclination and ephemeris data as satellite orbit parameters.

[0043] Specifically, the satellite's orbital altitude, inclination, and ephemeris data are key satellite orbital parameters. Orbital altitude determines the distance between the satellite's circular or elliptical orbit and the Earth's surface, and can be accurately measured and recorded in kilometers (km). Inclination refers to the angle between the satellite's orbital plane and the Earth's equatorial plane, measured in degrees (°), which affects the satellite's coverage area and trajectory. Ephemeris data contains the satellite's position information at different times and can be obtained through astronomical observations and satellite navigation systems. It is used to accurately describe the satellite's motion in orbit.

[0044] The aforementioned orbital parameters are acquired using a variety of data collection methods. Satellite navigation systems, such as the Global Positioning System (GPS) and the BeiDou Navigation Satellite System (BDS), provide satellites with precise real-time position, velocity, and time information. This information is received and processed by the satellites' own receivers and serves as a crucial source of orbital parameters. Simultaneously, ground-based monitoring stations track and observe satellites using radar, optical, and other monitoring equipment, acquiring actual operational data to further supplement and improve orbital parameter information and ensure data accuracy and completeness.

[0045] S12: Based on the satellite orbit parameters, the prediction error of the satellite position is corrected through Kalman filtering to obtain the corrected satellite position; based on the corrected satellite position, the connectivity status of each satellite node in the future time window is output.

[0046] Specifically, the Kalman filter is a recursive minimum variance estimation algorithm that effectively processes noisy observation data to obtain an optimal estimate of the system state. In satellite position prediction, the satellite's orbital parameters are used as the system state vector. By establishing a dynamic model of satellite motion and an observation model, the Kalman filter algorithm is used to iteratively predict and correct the satellite's position.

[0047] First, a dynamic model of satellite motion is established based on the principles of satellite orbital mechanics. This model describes the temporal relationship between the satellite's state vector (including position, velocity, acceleration, etc.). Furthermore, the dynamic model is modified and improved to enhance prediction accuracy by accounting for various perturbations, such as the Earth's non-spherical gravity, atmospheric drag, and solar radiation pressure.

[0048] In terms of the observation model, satellite orbit parameters acquired through satellite navigation systems and ground monitoring stations are used as observation data. Combined with the dynamic model, the Kalman filter algorithm performs iterative calculations. At each time step, the Kalman gain is calculated based on the predicted satellite state and the observed data, and the prediction error is corrected to obtain a more accurate satellite position estimate.

[0049] Based on the corrected satellite positions, a connectivity model is constructed for each satellite node within a future time window. By calculating parameters such as the distance between different satellites, relative velocity, and communication beam coverage, it is determined whether communication links can be established between satellite nodes within a specific future time window. The connectivity status of each satellite node is then output. This connectivity status can be output in the form of a matrix, where each element of the matrix represents whether the corresponding satellite node is connected at a specific time. A value of 1 indicates connectivity, and a value of 0 indicates disconnection.

[0050] S13: Generate a topology relationship matrix based on the corrected satellite positions and connectivity states. The topology relationship matrix includes a set of communicable satellite nodes and link delay parameters as a network topology.

[0051] Specifically, a topology matrix is generated based on the corrected satellite positions and connectivity status. This matrix is a two-dimensional array, with rows and columns representing different satellite nodes. The elements in the matrix consist of two parts: one is the set of communicable satellite nodes. Based on the connectivity determination results, the numbers of the satellite nodes that can communicate with each other are recorded in the corresponding positions in the matrix; the other is the link delay parameter. By calculating the distance between satellites and combining it with the signal propagation speed (usually the speed of light), the signal propagation delay between satellite nodes is obtained. This delay is recorded in milliseconds in the matrix at the position corresponding to the communicable satellite node.

[0052] The topology relationship matrix plays a key role in network topology prediction and key distribution path planning. It not only clearly displays the communication relationship between satellite nodes, but also provides important topological information for subsequent key distribution, ensuring that keys can be transmitted along effective communication paths.

[0053] Due to the motion characteristics of satellites, the topology matrix is dynamically updated based on updates to satellite orbital parameters and changes in connectivity. The update cycle can be set based on the dynamic nature of the satellite network and actual application requirements. For example, in a low-orbit satellite network, where satellites move rapidly and topology changes frequently, the update cycle can be set to several minutes or even shorter. In a high-orbit satellite network, where satellites are relatively stationary and topology relationships are more stable, the update cycle can be appropriately extended.

[0054] S14: Divide the time slices according to the topological relationship matrix, and generate a corresponding dynamic key pool for each time slice, where the dynamic key pool includes multiple independent keys.

[0055] Specifically, the future time is divided into multiple consecutive time slices based on the network topology changes reflected in the topology relationship matrix. The length of the time slices is determined by comprehensively considering factors such as the severity of network topology changes, the required frequency of key updates, and the storage and computing capabilities of satellite nodes. In areas or time periods with frequent topology changes, shorter time slices are set to more precisely adapt to network topology changes. In areas or time periods with relatively stable topology, the time slice length is appropriately increased to reduce the frequency and overhead of key updates.

[0056] Time slices can be divided into fixed-length or variable-length time slices. Fixed-length time slices are suitable for situations where network topology changes are periodic and regular. They divide time evenly by setting a fixed time interval (such as 10 seconds or 30 seconds). Variable-length time slices offer greater flexibility, dynamically adjusting the length of time slices based on the rate and degree of network topology change monitored in real time to better match the actual dynamic characteristics of the network.

[0057] For each divided time slice, a corresponding dynamic key pool is generated. This key pool ensures randomness and unpredictability, meeting the security requirements of encryption and authentication. A quantum random number generator can be used to generate high-quality random numbers as keys, leveraging the randomness of quantum physics phenomena. Alternatively, a rigorously security-verified pseudo-random number generation algorithm, combined with a seed key and specific algorithmic logic, can be used to generate a pseudo-random number sequence with sufficient entropy and randomness to serve as the key in the key pool.

[0058] The number and length of keys in the dynamic key pool should be appropriately configured based on actual communication requirements and security levels. For example, in high-security military communications scenarios, the key length can be set to 256 bits or even higher, and the key pool for each time slice can contain a large number of independent keys to meet the needs of large-scale data encryption and frequent key updates. In some IoT application scenarios with high real-time requirements and relatively small data volumes, the key length and number can be appropriately adjusted to balance security and efficiency.

[0059] S15: Split the independent key of the current time slice into sub-key segments, encrypt the sub-key segments of the current time slice using the independent key of the previous time slice, and generate an encrypted key segment set including the time slice identifier.

[0060] Specifically, the independent key for the current time slice is split into multiple sub-key segments according to preset rules. The splitting rules can be based on fixed-length splitting, where each independent key is evenly divided into several sub-key segments of equal length, for example, splitting a 256-bit key into four 64-bit sub-key segments. Alternatively, variable-length splitting can be used, where different lengths are set for different key segments based on the key's importance and usage scenario, to achieve more flexible key management and security control.

[0061] The split sub-key segments are identified and managed to ensure that they can be accurately identified and processed during subsequent encryption, transmission, and reassembly. Each sub-key segment can be given a unique identifier that records its position in the original key and the time slice it belongs to, so that it can be restored in the correct order during decryption and reassembly.

[0062] The subkey segment of the current time slice is encrypted using the independent key of the previous time slice. A symmetric encryption algorithm with high security and computational efficiency should be selected, such as the Advanced Encryption Standard (AES). During the encryption process, the subkey segment is input as plaintext, and the independent key of the previous time slice is used as the encryption key. The encryption is performed according to the AES algorithm's encryption process to obtain the encrypted ciphertext data, namely the encryption key segment.

[0063] To ensure the integrity and verifiability of the encryption process, a time slice identifier is included in the encrypted key segment set. This identifier can be encoded in a specific format to clearly indicate the time slice to which the encryption key segment set belongs. This allows accurate location and matching of the corresponding time slice during key distribution and decryption, avoiding decryption errors or security vulnerabilities caused by time slice confusion.

[0064] In an optional embodiment, S2 includes the following steps:

[0065] S21: Filter the satellite nodes that will be visible in the future according to the topological relationship matrix and generate a pre-distribution path list.

[0066] Specifically, based on the connectivity status of each satellite node within the future time window recorded in the topology relationship matrix, satellite nodes that can maintain continuous communication links during the current time slice and subsequent preset time periods are selected as the set of satellite nodes that will be visible in the future. This process analyzes the connectivity information of the corresponding time slice in the topology relationship matrix and eliminates satellite nodes that are about to experience communication interruption or have poor link quality, thus ensuring the reliability of the pre-distribution path.

[0067] To improve the accuracy of screening, visible satellite nodes can be further screened and sorted based on indicators such as link delay parameters and signal strength, giving priority to satellite nodes with lower link delay and higher signal strength to optimize the transmission efficiency and stability of the pre-distribution path.

[0068] Based on the set of satellite nodes visible in the future, a pre-distribution path list is generated, taking into account factors such as inter-satellite link bandwidth, transmission delay, node storage and computing capabilities, and key distribution security. This path list can be generated using various algorithms, such as the shortest path algorithm (Dijkstra algorithm) and the ant colony algorithm with multiple constraints, to find the optimal transmission path from the key generation center to the target satellite node.

[0069] When generating the pre-distribution path list, multiple backup paths can be set to cope with possible failures or congestion on the primary path, improving the fault tolerance and reliability of key distribution. At the same time, each path is assigned a corresponding weight or priority, and path selection and use are dynamically adjusted based on actual network conditions and transmission requirements.

[0070] S22: Transmit the encryption key segment set to the target satellite node according to the pre-distribution path list via the inter-satellite link, and record the transmission timestamp and node identifier.

[0071] Specifically, the encryption key segments are transmitted hop-by-hop from the source node to the destination satellite node, leveraging the intersatellite link's communication capabilities, following the path sequence specified in the pre-distributed path list. During the transmission process, each intermediate satellite node is responsible for receiving, caching, and forwarding the key segments to ensure data integrity and accuracy.

[0072] To adapt to link changes and signal interference caused by high-speed satellite movement, inter-satellite link transmission uses forward error correction (FEC) technology to encode the encryption key segment set, increase data redundancy, and enable the receiving end to automatically detect and correct some errors that occur during the transmission process, thereby improving the reliability of data transmission.

[0073] At the same time, the transmission process follows a specific communication protocol, including data frame format definition, synchronization signal insertion, error detection and retransmission mechanism, etc., to ensure that the encryption key segment set can be transmitted efficiently and stably in the complex space electromagnetic environment.

[0074] When each satellite node receives the encryption key segment set, it immediately records the current transmission timestamp and its own node ID. The timestamp can be provided by a high-precision clock chip, accurate to milliseconds or even microseconds, for subsequent analysis of the transmission process's temporal sequence and delay.

[0075] The node identifier contains information such as the satellite's unique number and orbital parameters, and is used to clearly identify each node that the key segment data passes through along the transmission path. This recorded information will serve as an important basis for the subsequent generation of the path information string and provide the basic data for the generation of the verification identifier.

[0076] S23: Concatenate the transmission timestamp and the node identifier to generate a path information string.

[0077] Specifically, the transmission timestamp and node identifier are concatenated in a preset order and format to generate a path information string. The concatenation order can be based on the actual order in which the key segments pass through the transmission path, with the node information that passes first being placed first, and the node information that passes later being placed in order.

[0078] During the concatenation process, specific delimiters (such as "#" and "@") can be used to distinguish the timestamp and node identifier, ensuring that the generated path information string has a clear structure and parsability. For example, the format of the path information string can be "node identifier 1#timestamp 1@node identifier 2#timestamp 2@...@node identifier n#timestamp n", where the node identifier and timestamp correspond to each node that the key segment set passes through on the transmission path and the corresponding transmission time, respectively.

[0079] To ensure the integrity and accuracy of the path information string, after the string is generated, a check code can be calculated on it, such as using a cyclic redundancy check (CRC) or other check algorithm to generate a corresponding check value, and the check value is appended to the end of the path information string.

[0080] When the path information string is subsequently used, the checksum is recalculated and compared with the additional checksum to verify whether the string has been tampered with or damaged during transmission and storage, thereby ensuring the reliability of the path information.

[0081] S24: Perform a hash operation on the path information character string to obtain a first hash value.

[0082] Specifically, a hash algorithm with excellent security and collision resistance, such as SHA-3 (Secure Hash Algorithm-3), is selected to perform a hash operation on the generated path information string. The hash algorithm converts input data (path information string) of any length into a fixed-length hash value. This hash value is unique and can uniquely identify the input path information string.

[0083] During the hashing process, the path information string is segmented, expanded, and compressed according to the hash algorithm specifications. After multiple rounds of iterative calculations, the first hash value is ultimately obtained. The length of the first hash value is typically 256 bits, 512 bits, etc., depending on the parameters of the selected hash algorithm.

[0084] The first hash value is irreversible and collision-resistant. This means the original path information string cannot be deduced from the hash value, and it is virtually impossible to find two different path information strings with the same hash value. This property allows the first hash value to serve as a unique summary of the path information. In subsequent verification, the integrity and authenticity of the path information can be quickly and accurately verified by comparing the hash values, ensuring the security of key distribution.

[0085] S25: Bind the first hash value to the time slice identifier to generate a binding data block.

[0086] Specifically, the first hash value is bound to the time slice identifier to generate a binding data block. The binding method can be simple data splicing or combining the two using a specific structured data format, such as JSON (JavaScript Object Notation) format or XML (eXtensible Markup Language) format.

[0087] In the binding data block, clearly distinguish the fields for the first hash value and the time slice identifier to ensure that they can be accurately identified and parsed. For example, in JSON format, this can be defined as "{"hash":"first hash value","time_slice_id":"time slice identifier"}", clearly expressing the relationship between the two in the form of a key-value pair.

[0088] To prevent the binding data block from being tampered with during subsequent transmission and storage, the binding data block can be digitally signed. The binding data block is signed using the private key in the asymmetric encryption algorithm to generate a digital signature value, which is then appended to the end of the binding data block.

[0089] At the receiving end, the digital signature is verified using the corresponding public key to ensure the integrity and authenticity of the bound data block and prevent security risks caused by malicious data tampering.

[0090] S26: Write the binding data block into the transaction node of the Tangle blockchain and generate a unique address index for the transaction node.

[0091] Specifically, Tangle is a distributed ledger technology based on a directed acyclic graph (DAG). Compared with the traditional blockchain structure, it has the advantages of no mining, fast transaction confirmation, and good scalability. It is particularly suitable for highly dynamic and low-latency key distribution scenarios in low-orbit satellite networks.

[0092] In the Tangle blockchain, each transaction node represents a transaction record, forming a growing DAG structure through reference relationships with other transaction nodes. This structure enables transactions to be processed in parallel, improving the throughput and efficiency of the entire system and meeting the needs of fast writing and storage of large numbers of key distribution records in satellite communications.

[0093] The bound data block is written as transaction data to the transaction node of the Tangle blockchain. During the writing process, according to the Tangle consensus mechanism and data storage specifications, the appropriate parent node is selected for the transaction node to reference, and the relevant verification and confirmation processes are completed.

[0094] When a transaction node is successfully written into the Tangle blockchain, the system will generate a unique address index for the transaction node. The address index is usually a hash value, which is calculated by a specific hash algorithm based on the content of the transaction node (including the binding data block and related metadata, such as transaction time, trader information, etc.). It can uniquely identify the location of the transaction node in the Tangle blockchain, facilitating subsequent query and retrieval.

[0095] S27: Combine the unique address index and the time slice identifier to obtain a verification identifier.

[0096] Specifically, the unique address index and the time slice identifier are combined to obtain a verification identifier. This combination can be a simple string concatenation or a specific encoding or encryption algorithm to generate a verification identifier with a specific format and meaning.

[0097] The structure of the verification identifier should ensure its uniqueness and resolvability, so that the corresponding Tangle blockchain transaction node and time slice information can be quickly and accurately located through the verification identifier. For example, the verification identifier can use the format of "unique address index_time slice identifier", and connect the two with an underscore or other special characters to form a complete identification string.

[0098] In the subsequent communication request verification process, the terminal device will send the verification identifier to the satellite node. After receiving the verification identifier, the satellite node first parses the unique address index and time slice identifier, and then queries the corresponding transaction node in the Tangle blockchain based on the unique address index to obtain the first hash value and time slice identifier in the binding data block.

[0099] The obtained timeslice identifier is compared with the timeslice identifier in the communication request to ensure consistency. Simultaneously, a hash value of the path information string is regenerated based on the first hash value and compared with the first hash value to verify the integrity and authenticity of the path information. Only when all verifications pass is the communication request considered legitimate, and subsequent key decryption and communication processes proceed, ensuring the security and reliability of the entire satellite communication encryption and authentication process.

[0100] In an optional embodiment, S3 includes the following steps:

[0101] S31: Receive a communication request sent by the terminal, locate the encryption key segment set stored in the target satellite node by parsing the time slice identifier carried in the communication request, and obtain the encryption key segment set.

[0102] Specifically, the target satellite node receives a communication request signal sent by the terminal device through its communication module. The communication request adopts a predefined communication protocol format, which explicitly includes a time slice identification field for identifying the time slice corresponding to the current communication request.

[0103] The satellite node parses the received communication request grammatically and semantically, extracting time slot identification information and other relevant parameters, such as terminal identity information, the type of data requested, and service requirements. The parsing process strictly adheres to the communication protocol specifications to ensure the accuracy of the extracted information.

[0104] Based on the parsed timeslice identifier, the satellite node quickly locates the encryption key segment set corresponding to that timeslice in its local storage module. The local storage module uses an efficient data index structure, such as a hash table or B-tree, to quickly find the storage location of the corresponding key segment set based on the timeslice identifier.

[0105] The encryption key segment set data is read from the storage location and verified for integrity and accuracy to ensure that the key segment set has not been damaged or lost during storage and transmission. This verification method can use a data check code (such as a CRC check code) or compare the key segment set metadata information (such as data length, generation time, etc.).

[0106] S32: Decrypt the encrypted key segment set using the key of the previous time slice to obtain decrypted data; reconstruct the decrypted data to obtain the complete key of the current time slice.

[0107] Specifically, the satellite node obtains the key for the previous time slice from its key management module. The key is stored in the satellite node's local secure storage area in encrypted or plain text form to ensure its security and availability.

[0108] Using the key obtained from the previous time slice, each encrypted key segment in the encrypted key segment set is decrypted in sequence. The decryption algorithm corresponds to the encryption algorithm. For example, if the AES decryption algorithm is used, the encryption algorithm is inversely calculated to convert the encrypted key segment into the original sub-key segment plaintext data.

[0109] According to the pre-set subkey segment reassembly rules, the decrypted subkey segments are concatenated and integrated in the correct order to form the complete key for the current time slice. The reassembly rules can be based on the subkey segment number, its order within the set of encrypted key segments, or other identifying information to ensure that the subkey segments can be accurately restored to the original complete key.

[0110] During the reorganization process, the integrity of the sub-key segment data is checked to verify whether the number of bits, format, etc. of each sub-key segment meet the requirements, so as to prevent the failure of the entire key reorganization due to damage or loss of individual sub-key segments.

[0111] S33: Based on the verification identifier, the integrity of the pre-distribution path in the blockchain is verified. If the verification passes, a session key is generated based on the complete key and the session key is returned to the terminal.

[0112] Specifically, the satellite node extracts the verification identifier from the communication request and parses it to separate the unique address index and time slice identifier. The parsing process is performed according to the verification identifier generation rules and format specifications to ensure that these two key pieces of information can be accurately restored.

[0113] Based on the unique address index, the satellite node establishes a connection with the Tangle blockchain network through its integrated blockchain client module and prepares to query the corresponding transaction node data. The blockchain client module has the ability to interact with the Tangle blockchain and follows the communication protocol and data access specifications of the blockchain network.

[0114] Satellite nodes use the blockchain client module to locate and obtain the transaction node data corresponding to the unique address index in the Tangle blockchain. The transaction node data contains the binding data block and related metadata information, such as transaction time, trader information, etc.

[0115] Verify the integrity and authenticity of the acquired transaction node data to ensure it has not been tampered with or damaged. This verification method can use technologies such as digital signature verification and hash value comparison to verify the credibility of the transaction node data.

[0116] Extract the binding data block from the transaction node data and further separate the first hash value and time slice identifier. Compare the separated time slice identifier with the time slice identifier in the communication request to verify whether the two are consistent, ensuring that the verification process targets the correct time slice.

[0117] Based on the first hash value, a hash value of the path information string is regenerated by concatenating the recorded transmission timestamp and node identifier according to a preset rule to generate a path information string, and then performing a hash operation on the string using the same hash algorithm as in step S24 to obtain a new hash value.

[0118] Compare the newly generated hash value with the first hash value to see if they are the same. If they are the same, the integrity verification of the pre-distribution path has passed, the key segment set has not been tampered with during transmission, and the path information is authentic and reliable. If they are different, the verification has failed, indicating that the key segment set or path information may have been tampered with, and the communication request has a security risk. In this case, the satellite node will reject subsequent communication processes.

[0119] Once the pre-distribution path integrity verification passes, the satellite node uses the complete key for the current time slice to generate a session key using a specific key derivation function (KDF). KDF algorithms are selected and implemented based on security standards and encryption protocols, such as the HKDF (Hashed Key Derivation Function) algorithm, to ensure high entropy and good security for the session key.

[0120] The generated session key is returned to the terminal device via a secure communication channel. During the return process, an encrypted transmission mechanism, such as digital envelope technology based on public key encryption or other secure transmission protocols suitable for satellite communications, is used to encrypt and protect the session key. This prevents the session key from being stolen or tampered with during transmission, ensuring that the session key reaches the terminal device securely and accurately.

[0121] In an optional embodiment, S4 includes the following steps:

[0122] S41: Use the session key to encrypt the first random number to generate a first ciphertext, and send the first ciphertext to the target satellite node.

[0123] Specifically, the terminal device's built-in random number generator uses a high-quality random number generation algorithm, such as a true random number generation algorithm based on hardware noise or a security-verified pseudo-random number generation algorithm, to generate a first random number. The length of this random number is set based on the requirements of the encryption algorithm and the security level, for example, 128 bits or 256 bits, to ensure sufficient entropy and unpredictability.

[0124] The generated first random number is encrypted using the established session key. A symmetric encryption algorithm, such as the Advanced Encryption Standard (AES), is used. The encryption process involves grouping the plaintext (the first random number) into blocks of size and converting it into ciphertext through multiple rounds of iterative transformation and key expansion, ensuring data confidentiality during transmission.

[0125] The encrypted first ciphertext is sent to the target satellite node via a satellite communication link. During transmission, the predefined communication protocol, including data frame format, synchronization signals, and error detection and correction mechanisms, is adhered to to ensure that the first ciphertext reaches the target satellite node accurately. Furthermore, the transmitted data is subpacketized, and the packet sequence number and total number of packets are recorded so that the receiving end can fully reconstruct the ciphertext data.

[0126] S42: The target satellite node decrypts the first ciphertext to obtain a first random number, generates a second random number and performs a hash operation on the first random number to generate a second hash value, encrypts the second hash value using the session key, generates a second ciphertext, and returns the second ciphertext to the terminal.

[0127] Specifically, after receiving the first ciphertext, the target satellite node decrypts it using the same session key and a symmetric decryption algorithm (such as the AES decryption algorithm). The decryption process is the inverse of the encryption process. Through key expansion and multiple rounds of iterative transformation, the ciphertext data is restored to the original first random number plaintext data, ensuring data integrity and accuracy.

[0128] The target satellite node generates a second random number in a similar manner to the first, using a high-quality random number generation algorithm to ensure randomness and unpredictability. The first and second random numbers are then concatenated to form a new data string.

[0129] A hash operation is performed on the concatenated data string, using a secure hash algorithm such as SHA-3 (Secure Hash Algorithm-3). Through multiple rounds of iteration and message compression, the input data of any length is converted into a fixed-length hash value, the second hash value. This hash value is unique and irreversible, and can uniquely identify the input data string.

[0130] The generated second Hash value is encrypted using the session key to obtain a second ciphertext. The encryption process is the same as the encryption process in step S41, ensuring the confidentiality and integrity of the second Hash value during transmission.

[0131] The second ciphertext is returned to the terminal device via a satellite communication link, also following the predefined communication protocol and data transmission mechanism to ensure reliable data transmission. During the transmission process, necessary error detection and correction are performed on the data to ensure that the terminal device can accurately receive the second ciphertext.

[0132] S43: Decrypt the second ciphertext to obtain a second hash value, verify the consistency of the second hash value with the local hash value, and complete two-way authentication if they are consistent. After the authentication is passed, dynamic encrypted communication is triggered.

[0133] Specifically, after receiving the second ciphertext, the terminal device uses the session key and the corresponding decryption algorithm to decrypt the second ciphertext to obtain the second hash value plaintext data. The decryption process strictly follows the inverse process of the encryption algorithm to ensure the accuracy and reliability of the decryption.

[0134] The terminal device regenerates a local hash value based on the first random number sent previously and the second random number generated by itself (if any), in the same splicing order and hash algorithm as the satellite node.

[0135] The decrypted second hash value is compared with the locally generated hash value. If the two match, bidirectional authentication succeeds, indicating that the identities of both parties are authentic and reliable, and the communication link has not been tampered with or subjected to a man-in-the-middle attack. If the two do not match, authentication fails, the communication link presents a security risk, and the terminal device will reject subsequent communication requests.

[0136] After two-way authentication is successful, the communication link between the terminal device and the target satellite node is officially established, triggering dynamic encrypted communication. During subsequent communications, both parties use the session key to perform real-time encryption and decryption of transmitted data, ensuring the confidentiality and integrity of the communication data.

[0137] According to the pre-set key update policy, session keys are updated periodically or on demand to address potential security threats and changes in network topology, further improving communication security and anti-attack capabilities. Updated session keys are distributed and synchronized through a secure key update mechanism, ensuring that both parties always use the same, latest key for encrypted communications.

[0138] The above-mentioned satellite communication encryption and authentication method based on dynamic keys divides time slices and generates an associated dynamic key pool by building a dynamic topology prediction model based on satellite orbit parameters. The method then splits the key into sub-key segments and uses forward-associative encryption to generate a segmented encryption key set. The method combines pre-distribution path planning with a lightweight blockchain path hash verification mechanism to achieve trusted traceability of key distribution. The method uses dynamic decryption to reassemble the key and a two-way authentication process based on random number concatenation and hash operations. This method addresses the issues of high key synchronization latency, high risk of single-point leakage of pre-distributed keys, and low blockchain verification efficiency in highly dynamic satellite networks. It achieves real-time dynamic adaptation of key distribution, forward security against single-point leakage, lightweight path verification, and two-way trusted authentication against replay attacks, comprehensively improving the security and adaptability of satellite communications in high-speed mobile scenarios.

[0139] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above can include multiple steps or multiple stages, and these steps or stages are not necessarily executed and completed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of steps or stages in other steps.

[0140] Based on the same inventive concept, embodiments of the present application also provide a system for implementing the aforementioned dynamic key-based satellite communication encryption authentication method. The solution provided by this system is similar to the solution described in the aforementioned method. Therefore, the specific limitations of one or more embodiments of the dynamic key-based satellite communication encryption authentication system provided below can be found in the above-mentioned limitations of the dynamic key-based satellite communication encryption authentication method, and will not be further elaborated here.

[0141] In an exemplary embodiment, Figure 2 As shown, a satellite communication encryption authentication system 20 based on dynamic keys is provided, comprising:

[0142] The dynamic key pool generation module 21 is used to predict the network topology of future satellites based on satellite orbit parameters, divide time slices according to the network topology and generate corresponding dynamic key pools, split the key of the dynamic key pool of the current time slice into sub-key segments, and use the key of the previous time slice to encrypt the sub-key segments of the current time slice to generate an encrypted key segment set.

[0143] The key distribution planning module 22 is used to plan a pre-distribution path according to the network topology, distribute the encryption key segment set to the target satellite node through the inter-satellite link according to the pre-distribution path; and generate a verification identifier based on the pre-distribution path and the time slice identifier.

[0144] The session key generation module 23 is used to respond to the communication request sent by the terminal with the time slice identifier, extract the encryption key segment set from the target satellite node, decrypt and reassemble the encryption key segment set using the key of the previous time slice to obtain the complete key of the current time slice; and generate a session key based on the verification identifier and the complete key and return it to the terminal.

[0145] The two-way authentication and communication module 24 is used to encrypt and hash the random numbers between the terminal and the target satellite node through the session key to complete the two-way authentication, and trigger dynamic encrypted communication after the authentication is passed.

[0146] Optionally, the dynamic key pool generation module 21 includes:

[0147] The orbit parameter acquisition unit 211 is used to acquire the satellite's orbit altitude, inclination and ephemeris data as satellite orbit parameters.

[0148] The position prediction and correction unit 212 is used to correct the prediction error of the satellite position based on the satellite orbit parameters through Kalman filtering to obtain the corrected satellite position; based on the corrected satellite position, it outputs the connectivity status of each satellite node in the future time window.

[0149] The topology relationship generating unit 213 is configured to generate a topology relationship matrix according to the corrected satellite positions and connectivity states. The topology relationship matrix includes a set of communicable satellite nodes and link delay parameters as a network topology.

[0150] The time slice and key pool management unit 214 is used to divide the time slices according to the topology relationship matrix and generate a corresponding dynamic key pool for each time slice. The dynamic key pool contains multiple independent keys.

[0151] The key splitting and encryption unit 215 is used to split the independent key of the current time slice into sub-key segments, encrypt the sub-key segments of the current time slice using the independent key of the previous time slice, and generate an encrypted key segment set including the time slice identifier.

[0152] Optionally, the key distribution planning module 22 includes:

[0153] The pre-distribution path planning unit 221 is configured to screen satellite nodes that will be visible in the future according to the topological relationship matrix and generate a pre-distribution path list.

[0154] The key distribution and recording unit 222 is used to transmit the encryption key segment set to the target satellite node according to the pre-distribution path list through the inter-satellite link, and record the transmission timestamp and node identifier.

[0155] The path information processing unit 223 is configured to concatenate the transmission timestamp and the node identifier to generate a path information character string.

[0156] The hash operation unit 224 is configured to perform a hash operation on the path information character string to obtain a first hash value.

[0157] The data binding unit 225 is configured to bind the first hash value to the time slice identifier to generate a binding data block.

[0158] The blockchain storage unit 226 is used to write the bound data block into the transaction node of the Tangle blockchain and generate a unique address index for the transaction node.

[0159] The verification identifier generating unit 227 is configured to combine the unique address index and the time slice identifier to obtain a verification identifier.

[0160] Optionally, the session key generation module 23 includes:

[0161] The communication request processing unit 231 is configured to receive a communication request sent by a terminal, locate the encryption key segment set stored in the target satellite node by parsing the time slice identifier carried in the communication request, and obtain the encryption key segment set.

[0162] The key decryption and reassembly unit 232 is configured to decrypt the encryption key segment set using the key of the previous time slice to obtain decrypted data; and reassemble the decrypted data to obtain the complete key of the current time slice.

[0163] The session key generation and return unit 233 is used to verify the integrity of the pre-distribution path in the blockchain based on the verification identifier. If the verification is successful, a session key is generated based on the complete key and the session key is returned to the terminal.

[0164] Optionally, the two-way authentication and communication module 24 includes:

[0165] The terminal random number encryption and sending unit 241 is configured to encrypt a first random number using a session key to generate a first ciphertext, and send the first ciphertext to a target satellite node.

[0166] The satellite node decryption and hash operation unit 242 is used for the target satellite node to decrypt the first ciphertext to obtain a first random number, generate a second random number and perform a hash operation on the first random number to generate a second hash value, encrypt the second hash value using the session key, generate a second ciphertext, and return the second ciphertext to the terminal.

[0167] The terminal authentication and communication triggering unit 243 is used to decrypt the second ciphertext to obtain a second hash value, verify the consistency of the second hash value with the local hash value, and complete two-way authentication if they are consistent. After the authentication is passed, dynamic encrypted communication is triggered.

[0168] An embodiment of the present application further provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps in the above-mentioned method embodiments when executing the computer program.

[0169] An embodiment of the present application further provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.

[0170] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to the partial description of the method embodiments. The device embodiments described above are merely illustrative, wherein the components described as separate parts may or may not be physically separated, and the parts displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the disclosed solution. A person of ordinary skill in the art can understand and implement it without expending creative work.

[0171] The above-described embodiments merely represent several implementation methods of the embodiments of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the patent application. It should be noted that a person skilled in the art may make various modifications and improvements without departing from the concept of the embodiments of the present application, and these modifications and improvements fall within the scope of protection of the embodiments of the present application.

Claims

1. A satellite communication encryption authentication method based on dynamic keys, characterized in that: The method comprises: S1: Predicting the future satellite network topology based on satellite orbit parameters, dividing time slices according to the network topology and generating a corresponding dynamic key pool, splitting the key of the dynamic key pool for the current time slice into sub-key segments, and encrypting the sub-key segments of the current time slice using the key of the previous time slice to generate an encrypted key segment set; S2: planning a pre-distribution path according to the network topology, distributing the encryption key segment set to a target satellite node via an inter-satellite link along the pre-distribution path; generating a verification identifier based on the pre-distribution path and a time slice identifier; S3: Responding to a communication request sent by the terminal carrying a time slice identifier, extracting the encryption key segment set from the target satellite node, decrypting and reassembling the encryption key segment set using the key of the previous time slice to obtain a complete key for the current time slice; generating a session key based on the verification identifier and the complete key and returning it to the terminal; S4: Encrypt and hash the random number between the terminal and the target satellite node using the session key to complete two-way authentication, and trigger dynamic encrypted communication after the authentication is successful.

2. The method according to claim 1, characterized in that Said S1 comprises: S11: Collecting the satellite's orbital altitude, inclination, and ephemeris data as the satellite's orbital parameters; S12: Based on the satellite orbit parameters, iteratively correct the prediction error of the satellite position through Kalman filtering to obtain a corrected satellite position; based on the corrected satellite position, output the connectivity status of each satellite node in the future time window; S13: generating a topology relationship matrix according to the corrected satellite position and the connectivity state, wherein the topology relationship matrix includes a set of communicable satellite nodes and a link delay parameter as the network topology; S14: Divide the time slices according to the topological relationship matrix, and generate a corresponding dynamic key pool for each time slice, wherein the dynamic key pool includes multiple independent keys; S15: Split the independent key of the current time slice into the subkey segments, use the independent key of the previous time slice to encrypt the subkey segments of the current time slice, and generate the encrypted key segment set containing the time slice identifier.

3. The method according to claim 2, characterized in that The S2 includes: S21: Filtering satellite nodes that will be visible in the future according to the topological relationship matrix to generate a pre-distribution path list; S22: Transmitting the encryption key segment set to the target satellite node according to the pre-distribution path list via an intersatellite link, and recording a transmission timestamp and a node identifier; S23: Concatenate the transmission timestamp and the node identifier to generate a path information string; S24: Performing a hash operation on the path information character string to obtain a first hash value; S25: Bind the first hash value to the time slice identifier to generate a binding data block; S26: Write the binding data block into the transaction node of the Tangle blockchain and generate a unique address index for the transaction node; S27: Combine the unique address index and the time slice identifier to obtain the verification identifier.

4. The method according to claim 3, characterized in that The S3 includes: S31: receiving the communication request sent by the terminal, locating the encryption key segment set stored in the target satellite node by parsing the time slice identifier carried in the communication request, and obtaining the encryption key segment set; S32: Decrypt the encryption key segment set using the key of the previous time slice to obtain decrypted data; reconstruct the decrypted data to obtain the complete key of the current time slice; S33: Verify the integrity of the pre-distribution path in the blockchain according to the verification identifier. If the verification passes, generate a session key based on the complete key and return the session key to the terminal.

5. The method according to any one of claims 1 to 4, characterized in that The S4 includes: S41: Using the session key to encrypt a first random number to generate a first ciphertext, and sending the first ciphertext to the target satellite node; S42: The target satellite node decrypts the first ciphertext to obtain a first random number, generates a second random number, performs a hash operation on the first random number, generates a second hash value, encrypts the second hash value using the session key, generates a second ciphertext, and returns the second ciphertext to the terminal; S43: Decrypt the second ciphertext to obtain the second hash value, verify the consistency of the second hash value with the local hash value, and complete two-way authentication if they are consistent. After the authentication is passed, the dynamic encrypted communication is triggered.

6. A satellite communication encryption authentication system based on dynamic keys, characterized in that: The system comprises: A dynamic key pool generation module is configured to predict the network topology of future satellites based on satellite orbit parameters, divide time slices according to the network topology and generate corresponding dynamic key pools, split the key of the dynamic key pool for the current time slice into sub-key segments, and encrypt the sub-key segments of the current time slice using the key of the previous time slice to generate an encrypted key segment set; a key distribution planning module, configured to plan a pre-distribution path according to the network topology, distribute the encryption key segment set to a target satellite node via an intersatellite link along the pre-distribution path; and generate a verification identifier based on the pre-distribution path and a time slice identifier; a session key generation module, configured to respond to a communication request sent by a terminal carrying a time slice identifier, extract the encryption key segment set from the target satellite node, decrypt and reconstruct the encryption key segment set using the key of the previous time slice to obtain a complete key for the current time slice, and generate a session key based on the verification identifier and the complete key and return it to the terminal; The two-way authentication and communication module is used to encrypt and hash the random numbers between the terminal and the target satellite node through the session key to complete the two-way authentication, and trigger dynamic encrypted communication after the authentication is passed.

7. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the method according to any one of claims 1 to 5 is implemented.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 5 is implemented.

Citation Information

Cited By

  • Accurate key binding distribution method based on demand-driven strategy

    CN120825336A

  • Network communication security protection method and system based on plaintext data

    CN120825343A