Satellite identity legality verification method and device of giant satellite base system
By using a CNN-LSTM deep learning model in the Giants constellation system, combined with TDoA, Doppler frequency offset, and average received power difference data, the problems of large data volume and high computational complexity in satellite identity verification were solved, achieving high-precision, real-time identity authentication and improving system security.
Patent Information
- Application Number
- CN202511232702.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-29
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2045-08-29
AI Technical Summary
The satellite identity verification scheme in the Giant Star system suffers from problems such as large data collection volume, high computational complexity, insufficient real-time authentication and accuracy, and difficulty in effectively defending against unauthorized access and deception attacks.
By employing a CNN-LSTM deep learning model and combining data such as TDoA, Doppler frequency deviation, and average received power difference of satellite signals, high-precision identification and classification of satellite identities can be achieved through model training and evaluation, reducing the amount of data collection and computational complexity.
It improves the accuracy and security of satellite identity authentication, reduces computational complexity, enhances the real-time performance and anti-interference capabilities of authentication, and is suitable for the demanding Giants constellation satellite system.
Smart Images

Figure CN120979528A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of satellite communications, and in particular to a method and apparatus for verifying the legitimacy of satellite identities in the Giants constellation system. Background Technology
[0002] As a crucial component of the 6th Generation Mobile Communication System (6G), satellite communication networks are expanding rapidly, with the number of Mega-Constellation satellite systems deployed globally growing rapidly. However, this surge in satellite numbers has also brought new security challenges. Unauthorized access and spoofing attacks not only affect the normal communication services of the Mega-Constellation system but may also pose serious threats to ground users and other spacecraft. On the other hand, as an effective extension and important supplement to terrestrial networks, mega-constellation systems provide global users with high-capacity, high-coverage, low-latency, all-weather, continuous communication services. Driven by the rapid evolution of navigation and remote sensing satellite technologies, the application scenarios of satellite communication continue to expand, gradually occupying a core position in global information infrastructure and increasingly becoming a key force for national strategic security. Examples include the US's Starlink and Europe's IRIS. 2Both the satellite communication system and China's "Thousand Sails" program aim to build a large-scale, independently controllable low-Earth orbit (LEO) constellation system to safeguard the nation's leading position in global communications and information security. However, satellite communications typically employ high-power, large-beam antenna designs to achieve wide-area coverage, but this design results in a signal leakage range far exceeding that of ground base stations, creating a wide-area radio frequency (RF) attack surface. Attackers do not need to approach the satellite itself; they can intercept, interfere with, forge, or tamper with the signal within the coverage area using ground equipment or drones. The downlink of satellite communication systems is particularly vulnerable to eavesdropping, interception, and even replay. Traditional terrestrial communication networks can rely on national borders to deploy firewalls and border gateways for protection. However, due to the orbital dynamics of satellites, physical protection boundaries are completely lost. Furthermore, the coverage area of satellite signals spans multiple national sovereign territories and the high seas, making the communication links inherently uncontrollable. The complexity of control has increased significantly, making it difficult to effectively isolate malicious nodes or limit potential attack traffic. The blurring of network boundaries forces satellite communication systems to confront more complex global dynamic attack surface management issues. With countries deploying numerous low-Earth orbit satellite constellations, orbital resources are becoming increasingly scarce. Data link interference, signal spoofing, and frequency contention can occur between giant satellite systems or even between individual satellites; satellites operating in adjacent or co-orbital orbits may cause collisions, signal interference, and resource contention. This is particularly true for military satellites with strategic functions, significantly increasing the risk of network warfare. Therefore, there is an urgent need to conduct in-depth research on satellite identity authentication methods to build a fundamental security mechanism for satellite communication networks. By implementing a complete identity authentication framework, not only can the verifiable access of satellite nodes be ensured, but also effective defense against spoofing attacks by illegal physical entities can be achieved, providing strong support for ensuring the information security of satellite communication systems.
[0003] Satellite identity authentication is a fundamental security mechanism for building satellite communication networks. By implementing a complete identity authentication framework, not only can verifiable access to satellite nodes be ensured, but also deception attacks by unauthorized physical entities can be effectively defended, providing reliable security for the operation of space information communication systems. Current research on satellite communication system security, particularly on identity authentication methods for the Giants constellation satellites, mainly focuses on physical layer (or radio frequency fingerprint) information authentication, identity registration information authentication (based on blockchain), and orbital prior information authentication schemes.
[0004] Regarding authentication methods based on physical layer (or radio frequency fingerprint) information, current research mainly involves collecting physical layer or radio frequency parameter information of the satellite system and then combining it with prior information for identity verification. Existing research includes a Physical-Layer Authentication (PLA)-based authentication scheme that maintains a high success rate and low false positive rate in both Fixed Satellite Service (FSS) and Mobile Satellite Service (MSS) scenarios. Furthermore, related research also involves a convolutional neural network structure based on in-phase quadrature (IQ) signals. Meanwhile, to enhance the security of satellite telemetry, tracking, and command (TT&C) links, some studies have proposed a ground station identification method based on radio frequency fingerprints.
[0005] In identity registration-based authentication, such methods typically rely on identity identifiers, key negotiation, and digital signature mechanisms within the communication protocol. They verify the identities of both communicating parties through challenge / response authentication and symmetric or asymmetric encryption techniques. Existing research includes certificate-free authentication models and identity authentication schemes based on blockchain and cryptocurrencies. Furthermore, for inter-constellation satellite communication scenarios, related research maintains communication credentials between satellites within each constellation using blockchain ledgers and introduces space digital tokens as the basis for mutual trust between satellite nodes.
[0006] Regarding authentication methods based on prior orbital information, current research mainly analyzes the orbital motion characteristics of satellites and uses their position and velocity parameters in space for authentication. Existing research has proposed an orbital authentication mechanism based on Time-Difference-of-Arrival (TDoA); other studies combine orbital dynamics models and observation models to establish orbit determination observation models and use the Kalman filter algorithm to estimate the satellite's orbital state; furthermore, some studies have fused multi-source measurement data from the satellite and used federated filtering algorithms to achieve high-precision determination of the satellite's attitude and orbit.
[0007] In summary, existing satellite identity verification schemes generally suffer from large data acquisition volumes and high computational complexity, limiting the real-time authentication performance of the system. Furthermore, the requirement for strict synchronization between multiple ground stations fails to fully exploit the spatiotemporal correlation of the data, thus restricting authentication accuracy. Against this backdrop, this application addresses the satellite identity authentication problem in the Giants constellation environment by designing a satellite identity authentication scheme based on ephemeris information (TLE data) and satellite-to-ground channel statistical prior information. This scheme integrates a deep learning model into the identity verification and authentication process of low-Earth orbit satellites, employing a periodic deep learning model update strategy based on an accuracy performance threshold. This reduces the data acquisition requirements and computational complexity, thereby improving the overall security of the Giants constellation satellite system while maintaining high authentication accuracy. Summary of the Invention
[0008] The purpose of this application is to provide a method, apparatus, device, and medium for verifying the legitimacy of satellite identities in the Giant Star system, which can achieve high-precision identification of satellite identities.
[0009] To achieve the above objectives, this application provides the following solution:
[0010] Firstly, this application provides a method for verifying the legitimacy of satellite identities in the Giants constellation system, including:
[0011] Obtain satellite datasets; the satellite data includes one or more of the following: time difference of arrival (TDoA), Doppler frequency offset (DoDFS), and average received power difference (DoRP), as well as corresponding identity legitimacy labels; the labels include legitimate, illegitimate, and attack.
[0012] The satellite dataset is divided into a training set and a test set;
[0013] Construct an identity verification model based on CNN-LSTM deep learning;
[0014] The identity verification model is trained based on the training set;
[0015] The legitimacy of satellites in the Giants constellation system is verified and classified based on a trained identity legitimacy verification model.
[0016] The accuracy of the trained identity verification model is evaluated. If the evaluation result is lower than a preset threshold, the identity verification model is retrained until convergence.
[0017] Optionally, obtaining the satellite dataset specifically includes the following steps:
[0018] Step 1: Import ephemeris TLE data of legitimate satellite constellations, ephemeris TLE data of simulating illegitimate satellite constellations, and drone flight path information simulating spoofing attacks;
[0019] Step 2: Traverse the ephemeris TLE data of the legitimate satellite constellation, the ephemeris TLE data of the simulated illegitimate satellite constellation, and the flight path information of the drone simulating a spoofing attack to filter candidate signal sources:
[0020] For legitimate signal sources, simulated illegal signal sources, and simulated deception drone signal sources, the ground station control center GS-CC generates a corresponding list of ground receiver coordinates and a list of measurement times based on the pre-set number of ground receivers and the number of measurements.
[0021] Step 3: Based on the ground receiver coordinate list and measurement time list, the ground station control center, based on the ephemeris TLE data of legitimate satellite constellations, the ephemeris TLE data of simulated illegal satellite constellations, and the UAV trajectory information of simulated deception attacks, calls the coordinate calculation function of the signal source to which the current class belongs, to obtain the coordinate information and index number of the current specific signal source;
[0022] Step 4: Perform a visibility check on the specific signal source. The specific check logic is as follows: if the specific signal source is visible to any receiver in the ground station receiver coordinate list under the selected measurement time list, then the specific signal source is selected as a candidate signal source and stored in the list; otherwise, the specific signal source is searched again until a preset number of candidate signal sources are successfully filtered and the process ends.
[0023] For each type of signal source, before screening the candidate signal sources, the corresponding identity legitimacy true label is known. When data of the corresponding legitimate constellation satellite is collected, it is marked with the "True" label; when data of the corresponding illegitimate constellation satellite is collected, it is marked with the "False" label; at the same time, when data of UAV signal source is collected, it is marked with the "Attacker" label. All satellites used to collect data of legitimate constellation satellites constitute a satellite whitelist.
[0024] Step 5: Calculate the root mean square error (RMSE) between the actual TDoA signature matrix and the theoretical TDoA signature matrix of all imported satellites for each candidate signal source in the three signal source categories; the RMSE between the actual Doppler frequency offset (DoDFS) signature matrix and the theoretical Doppler frequency offset (DoDFS) signature matrix of all imported satellites; and the RMSE between the actual average received power (DoRP) signature matrix and the theoretical average received power (DoRP) signature matrix of all imported satellites. These are denoted as the first RMSE, second RMSE, and third RMSE, respectively. The calculation of these three types of RMSE utilizes the extended rules of the broadcast mechanism. The resulting RMSE data for each type is a one-dimensional array, with the array length equal to the number of imported satellites. Each element in the array corresponds to the RMSE between a theoretical satellite and the actual candidate satellite. The authentication results for each specific candidate signal source are as follows:
[0025] Step 6: Select the satellite certification label with the smallest root mean square error as the first preliminary certification result for the satellite;
[0026] Step 7: Select the satellite certification label with the smallest second root mean square error as the second preliminary certification result for the satellite;
[0027] Step 8: Select the satellite certification label with the smallest third root mean square error as the third preliminary certification result of the satellite;
[0028] Step 9: Determine whether the first, second, and third preliminary authentication results of the satellite are in the satellite whitelist. If the first, second, and third preliminary authentication results of the satellite are found to be in the legitimate satellite whitelist after retrieval, then the first, second, and third preliminary authentication results of the satellite are determined to be legitimate satellite signal sources. At this time, a "True" label and coordinate data are returned for the satellite signal source. If not, then the first, second, and third preliminary authentication results of the satellite are determined to be illegitimate satellite signal sources. At this time, a "False" label and coordinate data are temporarily returned for the illegitimate satellite signal source.
[0029] Step 10: Based on the preliminary authentication results of the first, second, and third satellites in the previous step, the ground station control center further analyzes the legitimacy of the signal source: First, the ground station control center constructs a three-dimensional grid between the geometric center of the ground receiver and the current candidate signal source. The three-dimensional grid has a cubic structure, with the direction vector connecting the geometric center of the ground receiver and the current candidate signal source as the central axis. By applying spatial rotation and scaling to the local grid, it is made to accurately align with the central axis direction in space and cover all grid points to be tested along the line.
[0030] Step 11: Assuming that each grid point in the three-dimensional grid is a corresponding stationary signal source, calculate its corresponding theoretical TDoA signature matrix, DoDFS signature matrix, and DoRP signature matrix; the ground station control center then calculates the root mean square error (RMSE) between its theoretical TDoA signature matrix, DoDFS signature matrix, and DoRP signature matrix and the actual TDoA signature matrix, DoDFS signature matrix, and DoRP signature matrix of the candidate signal source.
[0031] Step 12: According to the judgment method of the first, second and third preliminary authentication results of the satellite mentioned above, the ground station control center finds the identity label corresponding to the grid point signal source with the minimum RMSE in the three categories as the preliminary authentication result of the candidate signal source, which is called the first, second and third preliminary authentication results of the grid point. This process is essentially to find the best matching grid point signal source in the above three-dimensional grid points.
[0032] Step 13: The ground station control center further analyzes the first, second, and third preliminary authentication results of the grid points. If the signal source altitude corresponding to the first, second, and third preliminary authentication results of the grid points is less than 100 kilometers and the residual improvement ratio is higher than the set value, then the candidate signal source is finally determined to be a spoofing attack, and the "Attacker" label and the grid coordinates of the corresponding first, second, and third preliminary authentication results of the grid points are returned. Otherwise, it is determined that there is no other unknown signal source more suitable than the first, second, and third preliminary authentication results of the satellite in the current time slot, and the first, second, and third preliminary authentication results of the satellite are returned, i.e., the "True" label or the "False" label, the satellite serial number index, and the corresponding coordinate data.
[0033] At this point, the identity authentication for the specific signal source is complete, and the final authentication results of TDoA, DoDFS, and DoRP are obtained. If two or more of the authentication results of TDoA, DoDFS, and DoRP are consistent, it means that the current candidate signal source data is valid and the corresponding data is stored; otherwise, the data is considered invalid and is discarded.
[0034] Repeat the above process until a sufficient amount of labeled data is obtained.
[0035] Optionally, the expression for the TDoA signature matrix is as follows:
[0036]
[0037] Among them, M TDoA Represents the TDoA signature matrix. This represents the TDoA value of the nth ground station relative to the base station in the mth measurement. This indicates that the matrix has dimensions of m rows and n columns;
[0038] The expression for the DoDFS signature matrix is as follows:
[0039]
[0040] in, This represents the difference between the Doppler frequency offset value of the satellite under test measured by the nth ground station in the mth measurement and the Doppler frequency offset value of the satellite signal under test measured by the reference ground station;
[0041] The expression for the DoRP signature matrix is as follows:
[0042]
[0043] in, This represents the difference between the average received power of the satellite signal received by the nth ground station in the mth measurement and the average received power of the satellite signal received by the reference ground station.
[0044] Optionally, the satellite identity legitimacy verification method of the Giant Star system further includes, after the step of "adding labels to the hybrid signature matrix of the illegal satellite, the hybrid signature matrix of the attacking drone, and the hybrid signature matrix of the legitimate satellite to obtain the satellite dataset":
[0045] The hybrid signature matrix of the illegal satellite, the hybrid signature matrix of the attacking drone, and the hybrid signature matrix of the legitimate satellite are divided into multiple sub-matrices with fixed time steps along the time dimension using a sliding window.
[0046] Optionally, the identity verification model includes: a CNN part, an LSTM part, and a fully connected layer;
[0047] The CNN part, LSTM part, and fully connected layer are connected sequentially.
[0048] Optionally, training the identity legitimacy verification model based on the training set specifically includes the following steps:
[0049] The cross-entropy loss function is used as the optimization objective, and the Adam optimizer is used to update the weights of the identity verification model.
[0050] In each round of training, samples are loaded sequentially from the training set, and the identity verification model parameters are updated through the forward and backward propagation processes of the identity verification model.
[0051] Optionally, the accuracy of the trained identity verification model is evaluated. If the evaluation result is lower than a preset threshold, the identity verification model is retrained until convergence. This specifically includes the following steps:
[0052] The identity legitimacy verification model is validated using a test set, and the loss and accuracy of the identity legitimacy verification model on the validation set are calculated. Dropout regularization was not used during the training of the identity legitimacy verification model to ensure the integrity of temporal continuity.
[0053] If the current validation accuracy is better than the previous best model, then save the current model parameters;
[0054] Plot the loss curve and accuracy curve of the identity legitimacy verification model on the training set and test set, and calculate the authentication accuracy, false alarm rate and false alarm rate of the test set based on the confusion matrix;
[0055] If the authentication accuracy, false alarm rate, and missed alarm rate are lower than preset thresholds, the satellite dataset is updated, and the identity legitimacy verification model is retrained.
[0056] Secondly, this application provides a satellite identity verification device for the Giant Star system, comprising:
[0057] The satellite dataset acquisition module is used to acquire satellite datasets; the satellite data includes one or more of the following: time difference of arrival (TDoA), Doppler frequency offset (DoDFS), and average received power difference (DoRP), as well as corresponding identity legitimacy labels; the labels include legitimate, illegitimate, and attack.
[0058] The dataset partitioning module is used to divide the satellite dataset into a training set and a test set;
[0059] The identity legitimacy verification model building module is used to build an identity legitimacy verification model based on CNN-LSTM deep learning.
[0060] The training module is used to train the identity legitimacy verification model based on the training set;
[0061] The legitimacy verification and classification module is used to verify and classify the legitimacy of satellites in the Giants constellation system based on a trained identity legitimacy verification model.
[0062] The model evaluation module is used to evaluate the accuracy of the trained identity verification model. If the evaluation result is lower than a preset threshold, the identity verification model is retrained until convergence.
[0063] According to the specific embodiments provided in this application, this application has the following technical effects:
[0064] This application provides a method and apparatus for verifying the legitimacy of satellite identities in the Giants constellation system. It utilizes a CNN to extract local spatial features from a mixture matrix and further employs an LSTM to capture the deep spatiotemporal correlations between elements in the mixture matrix, achieving high-precision satellite identity determination. Simulation results show that the proposed scheme has advantages in accuracy, low complexity, and real-time performance compared to benchmark schemes. It also exhibits good generalization ability and robustness against interference. Compared to traditional methods that rely on calculating the root mean square error for matching, the proposed method demonstrates advantages in identity determination accuracy, model convergence speed, and runtime latency. Under the condition of reasonably selecting the number of ground stations and the combination of measurement parameters, using TDoA data as an example, the model achieves an authentication accuracy of 99.51% on the test set, making it particularly suitable for the Giants constellation satellite system, which has high requirements for real-time performance and security. The scheme designed in this application can provide a technical reference for the satellite identity authentication mechanism in the Giants constellation system. Attached Figure Description
[0065] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on the following drawings without creative effort.
[0066] Figure 1 A flowchart illustrating a satellite identity verification method for the Giants constellation system provided in an embodiment of this application;
[0067] Figure 2 A schematic diagram of a network model of a giant satellite communication system provided in one embodiment of this application;
[0068] Figure 3 A flowchart of a satellite identity authentication algorithm provided in an embodiment of this application;
[0069] Figure 4 A block diagram of an identity authentication system for a giant satellite communication system provided in one embodiment of this application;
[0070] Figure 5 A data processing and training framework diagram based on a CNN-LSTM satellite identity authentication framework is provided in one embodiment of this application;
[0071] Figure 6 Statistical performance graph of the satellite identity legitimacy verification method for the Giants constellation system provided in an embodiment of this application;
[0072] Figure 7 A schematic diagram of the structure of a satellite identity verification device for the Giants constellation system provided in an embodiment of this application. Detailed Implementation
[0073] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0074] To make the above-mentioned objectives, features and advantages of this application more apparent and understandable, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0075] To address the problems mentioned in the background art, and to improve the performance of satellite identity authentication systems while minimizing the amount of data required for authentication, thereby enhancing the real-time performance and response rate of satellite identity authentication systems, this application proposes a deep learning-based satellite identity authentication method for the Giants constellation system. This method mainly comprises three parts: data acquisition, model training, and authentication and classification decision-making. Specifically, firstly, based on satellite signal time-of-arrival (ToA) data, Doppler frequency offset, and average received signal power measured by ground stations for the Giants constellation system's satellite identity authentication system, a satellite dataset specific to the Giants constellation is constructed. Then, a deep learning model is trained using this dataset. Finally, the converged model, using the mixture matrix of the signal to be tested as input, is used to perform identity authentication and classification decisions for the satellite to be tested. Similarly, the model can also learn abnormal spatiotemporal correlation features from the mixture matrices corresponding to signals transmitted by illegitimate satellites, low-altitude drones, and other attackers, thereby achieving effective classification and identification of legitimate satellites, illegitimate satellites, and ground attack sources.
[0076] To achieve the above objectives, this application proposes a deep learning authentication scheme that combines Convolutional Neural Networks (CNN) and Long Short-Term Memory Networks (LSTM). It utilizes a mixed signature matrix data of TDoA, Doppler frequency offset, and average received power to train a deep learning model based on CNN and LSTM to capture the spatiotemporal correlation features in the data. This enables the model to autonomously determine the legitimacy of a satellite based on one or more of the calculated TDoA, Doppler frequency offset, and average received power measurements.
[0077] Specifically, the satellite identity verification method of the Giants constellation system in this application includes: a ground station, the satellite under test, a low-altitude drone, and a deep learning model based on CNN-LSTM.
[0078] The ground stations are the sites located on the ground in the system that receive satellite signals. During the actual simulation, the positions of the ground receiving stations are regenerated at the start of each experiment: First, a center (reference ground station) is randomly selected from the 21 existing hard-coded positions in the program. After selecting the distribution diameter and the number of ground stations, the remaining n ground receiving stations are generated. The positions of the ground stations are evenly arranged on a circle centered on the reference ground station with a radius equal to the selected distribution diameter. The minimum number of ground stations is 4, and the maximum is 20; the distribution diameter is an integer between 1 km and 10 km (inclusive).
[0079] The satellites under test include both legitimate and illegitimate satellites of the Giants constellation system. They are all operating normally in their designated orbits and maintaining normal communication with ground stations or other communication equipment in the system.
[0080] The low-altitude drones are attackers seeking to infiltrate the target Giants constellation system. They mimic legitimate satellites within the atmosphere, sending forged authentication signals to ground stations.
[0081] In one exemplary embodiment, such as Figure 1 As shown, a method for verifying the legitimacy of satellite identities in the Giants constellation system is provided. This method is executed by computer equipment, specifically by a terminal or server alone, or by both a terminal and a server. A schematic diagram of the Giants constellation satellite communication system network model is shown below. Figure 2 As shown, the satellite network model of the proposed satellite authentication system mainly consists of three parts: the Giants constellation system composed of low-Earth orbit satellites (including legitimate and illegitimate satellites in the Giants constellation), attack drones located in the atmosphere, and a certain number of ground receiving stations (GS).
[0082] In this embodiment of the application, steps 101 to 105 are included. Wherein:
[0083] Step 101: Obtain satellite datasets, which include one or more of the following: time difference of arrival (TDoA), Doppler frequency offset (DoDFS), and average received power difference (DoRP), as well as corresponding identity legitimacy labels; the labels include legitimate, illegitimate, and attack.
[0084] Step 102: Divide the satellite dataset into a training set and a test set.
[0085] The construction of the dataset includes data collection, labeling, and data preprocessing. Details are as follows:
[0086] (a) Import other (illegal) satellite lists and attack drones, collect the signal arrival time, Doppler frequency offset and average signal received power of illegal satellites or attack drones, and establish corresponding TDoA, DoDFS and DoRP hybrid signature matrix data;
[0087] (b) Import the list of legal satellites, use the satellite's TLE data and channel statistical model to calculate the theoretical values of signal arrival time, Doppler frequency offset data and average received signal power, and establish the corresponding TDoA, DoDFS and DoRP hybrid matrices;
[0088] (c) Based on the known satellite authentication classification results, add labels to each of the above hybrid matrices: Valid True / Illegal False / Attack.
[0089] The specific classification results of satellite identity legitimacy verification are as follows:
[0090] The orbital parameters (TLE data) of legitimate satellites are known, so their theoretical position and velocity information at a specific moment can be obtained through orbit calculation methods. This information, combined with measurement data from signals received by ground stations, yields the corresponding mixing matrix. Since these mixing matrices originate from verified legitimate satellites, their corresponding labels are all marked "legitimate." The mixing matrices and their labels are stored in a key-value dictionary format (e.g., uniformly saved in a .npy format data file) for subsequent model training. Elements in each mixing matrix are collected sequentially over time, forming time-series data with fixed time intervals; therefore, all elements within the matrix share consistent spatiotemporal correlation characteristics. Mixing matrices constructed from satellites from other giant star systems, besides legitimate satellites, are processed in the same way and uniformly labeled "illegal." Mixing matrices obtained by simulating attack devices (such as low-altitude drones) emitting forged signals and measured by ground stations are uniformly labeled "attack."
[0091] Based on the known satellite identity legitimacy classification results, labels are added to each of the above hybrid matrices, specifically including:
[0092] Taking TDoA measurement as an example, after obtaining the TDoA signature matrix of the satellite under test, the system first loads a list containing TLE data for all satellites. Then, based on the reference time t0 and the time interval Δt, the specific execution period of this measurement is obtained. Afterward, the entire TLE data list of the satellite is traversed, and the specific positional changes of all satellites in the list are calculated within the measurement period to determine whether the satellites are visible during the measurement period, that is, whether the ground station can receive the signals transmitted by the satellites within the measurement period. In actual simulation, the elevation angle for measuring satellite visibility can be manually set, and then the maximum penalty is applied to invisible satellites. Then, using the TLE data of all satellites in the list, the theoretical TDoA signature matrix of the satellite at the measurement time is calculated. The TDoA of each satellite is subtracted from the TDoA of the satellite under test to calculate the root mean square error (RMSE) of each satellite. Then, the entire candidate satellite list is traversed to find the satellite with the smallest RMSE and its index. It is then determined whether the satellite belongs to the target constellation and a label of whether it is valid (True or False) is given. After that, by judging whether the altitude of the invalid satellite and the residual between the theoretical value and the calculated value are abnormal, it is evaluated whether the TDoA signature matrix is calculated by a fake authentication signal emitted by the UAV and a label of whether it is an attack signal (False or Attack) is given.
[0093] See Figure 3 The complete authentication algorithm process is as follows:
[0094] Step 1: Import ephemeris TLE data of legitimate satellite constellations, ephemeris TLE data of simulating illegitimate satellite constellations, and drone flight path information simulating spoofing attacks;
[0095] Step 2: Traverse the ephemeris TLE data of the legitimate satellite constellation, the ephemeris TLE data of the simulated illegitimate satellite constellation, and the flight path information of the drone simulating a spoofing attack to filter candidate signal sources:
[0096] For legitimate signal sources, simulated illegal signal sources, and simulated deception drone signal sources, the ground station control center GS-CC generates a corresponding list of ground receiver coordinates and a list of measurement times based on the pre-set number of ground receivers and the number of measurements.
[0097] Step 3: Based on the ground receiver coordinate list and measurement time list, the ground station control center, based on the ephemeris TLE data of legitimate satellite constellations, the ephemeris TLE data of simulated illegal satellite constellations, and the UAV trajectory information of simulated deception attacks, calls the coordinate calculation function of the signal source to which the current class belongs, to obtain the coordinate information and index number of the current specific signal source;
[0098] Step 4: Perform a visibility check on the specific signal source. The specific check logic is as follows: if the specific signal source is visible to any receiver in the ground station receiver coordinate list under the selected measurement time list, then the specific signal source is selected as a candidate signal source and stored in the list; otherwise, the specific signal source is searched again until a preset number of candidate signal sources are successfully filtered and the process ends.
[0099] For each type of signal source, before screening the candidate signal sources, the corresponding identity legitimacy true label is known. When data of the corresponding legitimate constellation satellite is collected, it is marked with the "True" label; when data of the corresponding illegitimate constellation satellite is collected, it is marked with the "False" label; at the same time, when data of UAV signal source is collected, it is marked with the "Attacker" label. All satellites used to collect data of legitimate constellation satellites constitute a satellite whitelist.
[0100] Step 5: Calculate the root mean square error (RMSE) between the actual TDoA signature matrix and the theoretical TDoA signature matrix of all imported satellites for each candidate signal source in the three signal source categories; the RMSE between the actual Doppler frequency offset (DoDFS) signature matrix and the theoretical Doppler frequency offset (DoDFS) signature matrix of all imported satellites; and the RMSE between the actual average received power (DoRP) signature matrix and the theoretical average received power (DoRP) signature matrix of all imported satellites. These are denoted as the first RMSE, second RMSE, and third RMSE, respectively. The calculation of these three types of RMSE utilizes the extended rules of the broadcast mechanism. The resulting RMSE data for each type is a one-dimensional array, with the array length equal to the number of imported satellites. Each element in the array corresponds to the RMSE between a theoretical satellite and the actual candidate satellite. The authentication results for each specific candidate signal source are as follows:
[0101] Step 6: Select the satellite certification label with the smallest root mean square error as the first preliminary certification result for the satellite;
[0102] Step 7: Select the satellite certification label with the smallest second root mean square error as the second preliminary certification result for the satellite;
[0103] Step 8: Select the satellite certification label with the smallest third root mean square error as the third preliminary certification result of the satellite;
[0104] Step 9: Determine whether the first, second, and third preliminary authentication results of the satellite are in the satellite whitelist. If the first, second, and third preliminary authentication results of the satellite are found to be in the legitimate satellite whitelist after retrieval, then the first, second, and third preliminary authentication results of the satellite are determined to be legitimate satellite signal sources. At this time, a "True" label and coordinate data are returned for the satellite signal source. If not, then the first, second, and third preliminary authentication results of the satellite are determined to be illegitimate satellite signal sources. At this time, a "False" label and coordinate data are temporarily returned for the illegitimate satellite signal source.
[0105] Step 10: Based on the preliminary authentication results of the first, second, and third satellites in the previous step, the ground station control center further analyzes the legitimacy of the signal source: First, the ground station control center constructs a three-dimensional grid between the geometric center of the ground receiver and the current candidate signal source. The three-dimensional grid has a cubic structure, with the direction vector connecting the geometric center of the ground receiver and the current candidate signal source as the central axis. By applying spatial rotation and scaling to the local grid, it is made to accurately align with the central axis direction in space and cover all grid points to be tested along the line.
[0106] Step 11: Assuming that each grid point in the three-dimensional grid is a corresponding stationary signal source, calculate its corresponding theoretical TDoA signature matrix, DoDFS signature matrix, and DoRP signature matrix; the ground station control center then calculates the root mean square error (RMSE) between its theoretical TDoA signature matrix, DoDFS signature matrix, and DoRP signature matrix and the actual TDoA signature matrix, DoDFS signature matrix, and DoRP signature matrix of the candidate signal source.
[0107] Step 12: According to the judgment method of the first, second and third preliminary authentication results of the satellite mentioned above, the ground station control center finds the identity label corresponding to the grid point signal source with the minimum RMSE in the three categories as the preliminary authentication result of the candidate signal source, which is called the first, second and third preliminary authentication results of the grid point. This process is essentially to find the best matching grid point signal source in the above three-dimensional grid points.
[0108] Step 13: The ground station control center further analyzes the first, second, and third preliminary authentication results of the grid points. If the signal source altitude corresponding to the first, second, and third preliminary authentication results of the grid points is less than 100 kilometers and the residual improvement ratio is higher than the set value, then the candidate signal source is finally determined to be a spoofing attack, and the "Attacker" label and the grid coordinates of the corresponding first, second, and third preliminary authentication results of the grid points are returned. Otherwise, it is determined that there is no other unknown signal source more suitable than the first, second, and third preliminary authentication results of the satellite in the current time slot, and the first, second, and third preliminary authentication results of the satellite are returned, i.e., the "True" label or the "False" label, the satellite serial number index, and the corresponding coordinate data.
[0109] At this point, the identity authentication for the specific signal source is complete, and the final authentication results of TDoA, DoDFS, and DoRP are obtained. If two or more of the authentication results of TDoA, DoDFS, and DoRP are consistent, it means that the current candidate signal source data is valid and the corresponding data is stored; otherwise, the data is considered invalid and is discarded.
[0110] Repeat the above process until a sufficient amount of labeled data is obtained.
[0111] The above process details the complete method for satellite identification, legitimacy assessment, and attack signal detection based on the TDoA signature matrix. It is important to emphasize that the system uses the same logical framework to process both Doppler frequency offset and average received power measurement data: first, load TLE data; second, determine the measurement period; third, traverse the satellite list for visibility assessment and penalties; fourth, calculate the theoretical signature matrix; fifth, compare it with the measured signature matrix to obtain the RMSE; sixth, filter candidate satellites with the lowest RMSE; seventh, assess constellation legitimacy; and finally, evaluate whether it is an attack signal. The specific steps will be described below for Doppler frequency offset measurement data and average received power measurement data, respectively.
[0112] The TDoA signature matrix, DoDFS signature matrix, and DoRP signature matrix will be introduced in detail below:
[0113] (1) TDoA Signature Matrix:
[0114] First, design the distance d between the satellite and a certain ground station. g Given the speed of light c, the time it takes for a signal to travel from the satellite to the ground station can be calculated, i.e., the time of flight (ToF).
[0115]
[0116] Secondly, if the satellite under test sends an authentication signal to ground station A at time t0, then the time when the signal arrives at ground station A, i.e., ToA, can be calculated based on Time of Flight (ToF).
[0117]
[0118] Similarly, when other ground stations in the system receive the authentication signal sent by the satellite under test, they can obtain the corresponding Time of Arrival (ToA). Subtracting the ToA obtained by ground station A from that of ground station B yields the Time of Arrival (TDoA) between ground station A and ground station B. gg′ :
[0119]
[0120] Then, subtract the ToA of all other ground stations from the ToA of the reference ground station to obtain the TDoA of the reference ground station and all other ground stations. Next, arrange the corresponding TDoA values in a row according to the order in which the ground stations received the satellite signals, thus obtaining a TDoA row vector for the satellite under test at measurement time t0. Let the time interval (time step) between each measurement be Δt; then, a similar TDoA row vector can be obtained every Δt.
[0121] The expression for the TDoA row vector is:
[0122]
[0123] Therefore, after setting the number of measurements, a TDoA signature matrix for the satellite under test can be obtained. The elements in a TDoA signature matrix are m·n measurement data generated from the orbital positions of n+1 ground receiving stations relative to m transmitting satellites, where m is the number of rows in the TDoA matrix, representing the number of measurements of the satellite signal by the ground stations, and n+1 is the number of columns in the TDoA matrix, representing the number of ground stations.
[0124] The TDoA signature matrix expression is:
[0125]
[0126] in, This represents the TDoA value of the nth ground station relative to the base station in the mth measurement.
[0127] It should be noted that after obtaining the ToA of each ground station, the data format needs to be converted from Coordinated Universal Time (UTC) to Julian Day (JD). This time format is mostly used by astronomers. This conversion converts the time format into floating-point numbers, which facilitates subsequent calculations.
[0128] (2) DoDFS signature matrix:
[0129] Doppler frequency offset calculation in satellite signal authentication systems is based on the classical Doppler effect principle:
[0130] The system first calculates the geometric vector pointing from each ground station to the satellite. And normalize it to a unit vector To indicate the direction of signal propagation, where This represents the position vector from the Earth's center to the satellite in the True Equator Mean Equinox (TEME) coordinate system. This represents the position vector from the Earth's center to the ground station in the TEE coordinate system.
[0131] Next, the relative velocity vector of the satellite with respect to the ground station is calculated. The speed of the ground station has already taken into account the effect of the Earth's rotation.
[0132] Finally, the radial velocity component is extracted using vector dot product: The only component affecting Doppler frequency shift is the velocity component. The final formula for calculating Doppler frequency shift is:
[0133]
[0134] Where f0 is the carrier frequency (1575.42MHz), c is the speed of light, and the negative sign is used to ensure a negative frequency offset when the satellite is far from the receiver.
[0135] The system employs vectorized computation to simultaneously process multiple receivers, multiple measurement times, and multiple candidate satellites, forming a complete Doppler "fingerprint" matrix. By comparing the measured frequency offset with the theoretical frequency offset of all satellites in the database, the system can identify the best-matching satellite and detect potential spoofing attacks.
[0136] The DoDFS signature matrix expression is:
[0137]
[0138] in, This represents the difference between the Doppler frequency offset value of the satellite under test measured by the nth ground station in the mth measurement and the Doppler frequency offset value of the satellite signal under test measured by the reference ground station.
[0139] (3) DoRP signature matrix:
[0140] Distance Calculation: The system first calculates the Euclidean distance between the receiver location and the satellite location. Given the receiver location rec... pos(x,y,z) and satellite position sat pos (x, y, z) (all in meters), the distance calculation formula is:
[0141]
[0142] Free Space Path Loss Calculation: The system uses the standard Free Space Path Loss (FSPL) model to calculate the power attenuation of the signal propagating in a vacuum. The formula is:
[0143] FSPL(dB) = 20 × log 10 (d meters )+20×log 10 (f Hz -147.55(9)
[0144] Where d is the propagation distance (meters), f Hz This is the signal frequency (the system uses a frequency of 1.57542 GHz), and the constant term 147.55 comes from... The calculation results.
[0145] Received power calculation: According to the link budget principle, received power equals transmitted power minus path loss: P received (dBW) = EIRP(dBW) - FSPL(dB), where EIRP (equivalent isotropic radiated power) is set to a typical value of 14.3dBW for satellites.
[0146] Importing the error model: To simulate measurement uncertainties in real-world environments, the system superimposes an error model onto the calculated theoretical power value. This model typically employs a Gaussian or log-normal power error: P measured =P theoretical -error(dB).
[0147] The expression for the DoRP signature matrix is:
[0148]
[0149] in, This represents the difference between the average received power of the signal from the satellite under test received by the nth ground station in the mth measurement and the average received power of the signal from the satellite under test received by the reference ground station.
[0150] The above calculation method is based on the ideal free space propagation assumption. Although it ignores complex factors such as atmospheric attenuation and multipath effects, it is sufficiently effective for comparing the relative power characteristics in satellite signal authentication and can provide a reliable theoretical basis for subsequent signal authenticity determination.
[0151] Finally, in actual measurements, considering the potential inconsistencies in satellite legitimacy and attack signal labels generated based on the TDoA, DoDFS, and DoRP signature matrices under identical conditions, a fusion strategy was adopted for the final determination: if all three types of labels can be obtained simultaneously, two or more consistent labels are adopted; if all three types of labels are different, the data set is discarded and considered invalid. Similarly, if only any two types of labels can be obtained, the data is adopted only if they are completely consistent; otherwise, it is discarded and marked as invalid data. This rule enhances the robustness and reliability of the final determination in complex environments and adversarial scenarios by cross-validating the three independent physical quantities of TDoA, DoDFS, and DoRP, and by utilizing the majority consensus principle.
[0152] Step 103: Construct an identity verification model based on CNN-LSTM deep learning.
[0153] The identity legitimacy verification model consists of two parts: the first part is a CNN, which is used to extract local spatial features in the sliding window submatrix; the second part is an LSTM, which is used to model the time series output of the CNN to capture feature dependencies across time steps.
[0154] The fully connected layer classifies the input submatrix into its category and outputs a validity label.
[0155] Step 104: Train the identity legitimacy verification model based on the training set.
[0156] See Figure 4 and Figure 5 The training process of the model is as follows:
[0157] During model training, the labels are encoded using integers: 0 for attacking drones, 1 for legitimate satellites, and 2 for illegitimate satellites. The mixture matrix is divided into multiple sub-matrices with fixed time steps along the time dimension using a sliding window to enhance the model's ability to learn local temporal changes.
[0158] The cross-entropy loss function is used as the optimization objective, and the Adam optimizer is used to update the model weights.
[0159] In each round of training, samples are loaded sequentially from the training set, and the network parameters are updated through the forward and backward propagation processes of the CNN-LSTM network.
[0160] After each training round, the model is validated using a test set, and the loss and accuracy of the model on the validation set are calculated. No regularization methods such as Dropout are used during model training to ensure the integrity of temporal continuity.
[0161] If the current validation accuracy is better than the previous best model, then save the current model parameters;
[0162] Step 105: Verify and classify the legitimacy of satellites in the Giants constellation system based on the trained identity legitimacy verification model.
[0163] Collect ToA, Doppler frequency offset, and received power data of the satellite signal under test, construct a hybrid matrix of the corresponding data, use the model trained in step 104 to directly determine the legitimacy of the satellite's identity, and finally take corresponding response actions based on the classification results.
[0164] The expression for the mixing matrix is:
[0165]
[0166] To make the local temporal correlation features of the hybrid signature matrix more apparent, after obtaining the hybrid signature matrix data of the satellite under test, the matrix is first divided again along the time sequence using a sliding window. The time step between each adjacent window is one, meaning that a sub-matrix is collected using a sliding window for every other row. In this process, the spatiotemporal correlation in a hybrid signature matrix is amplified, effectively improving the model's training performance. The sub-matrices after division still have the labels of the original matrix added, and are stored in the .npy data file in dictionary form.
[0167] This application establishes an authentication system for the Giants satellite communication system. The system's inputs are signal arrival time, Doppler frequency offset, and average received signal power measured by multiple ground stations. The output is a three-class label authenticated by the system. After obtaining the signal arrival time, Doppler frequency offset, and average received signal power, the ground stations subtract these parameters from those of the reference ground station to obtain a hybrid signature matrix. This data is then input into a deep learning model, which captures the spatiotemporal correlations within the data. Finally, the model outputs an authenticated satellite legitimacy label.
[0168] Step 106: Evaluate the accuracy of the trained identity verification model. If the evaluation result is lower than a preset threshold, retrain the identity verification model until it converges.
[0169] After training, the loss curve and accuracy curve of the model on the training set and test set are plotted. Based on the confusion matrix, the authentication accuracy, false alarm rate and false alarm rate of the test set are calculated to monitor the accuracy and timeliness of the trained model. If the performance index is lower than the performance threshold, the original training dataset needs to be updated (especially as the spatial environment changes, the spatiotemporal correlation features contained in the received power data may change), and then the identity verification model is retrained.
[0170] This application uses CNN to extract local spatial features from the mixture matrix and further captures the deep spatiotemporal correlations between elements in the mixture matrix through LSTM, achieving high-precision satellite identity determination. Simulation results show that the proposed scheme has advantages over the benchmark scheme in terms of accuracy, low complexity, and real-time performance, and exhibits good generalization ability and robustness against interference. Compared with traditional methods that rely on calculating the root mean square error for matching judgment, the method in this application shows advantages in identity determination accuracy, model convergence speed, and runtime latency. Under the condition of reasonably selecting the number of ground stations and the combination of measurement parameters, taking TDoA data as an example, the model achieves an authentication accuracy of 99.51% on the test set, which is particularly suitable for the Giantsat satellite system with high requirements for real-time performance and security. The scheme designed in this application can provide a technical reference for the satellite identity authentication mechanism in the Giantsat system.
[0171] Figure 6 The statistical performance graphs for satellite identity verification based on TDoA data and a CNN-LSTM deep learning-based identity verification model are shown, illustrating the changes in test set authentication accuracy, false alarm rate, and false negative rate with the TDoA window size. Accuracy exhibits a trend of first increasing and then decreasing with window size: as the window size gradually increases from 1 to 5, the accuracy steadily improves, reaching its highest value of 99.51% at window size 5, indicating that the model performs best in identifying samples at this size. Subsequently, as the window size continues to increase, the accuracy begins to decrease, suggesting that excessively large window sizes may negatively impact model performance. This may be because increasing the window size increases the number of time slots in the TDoA matrix, thus preventing the model from accurately capturing the internal relationships within the data. At a window size of 1, the false alarm rate is as high as 4.0%, and the false negative rate is 1.47%. With increasing window size, the false alarm rate generally decreases, reaching its lowest value of approximately 0.4% at window size 5; simultaneously, the false negative rate also decreases, reaching its lowest point of 0.18% at window size 5. However, as the window size increases beyond 5, both the false alarm rate and the false alarm rate begin to rise. When the window size is 8, the false alarm rate rises to approximately 2.71%, and the false alarm rate rises to 1.61%. Combining the three curves, it can be seen that when the window size is 5, the model achieves a good balance between accuracy, false alarm rate, and false alarm rate, making it a superior parameter choice.
[0172] Based on the same inventive concept, this application also provides a satellite identity verification device for the Giant Star system to implement the satellite identity verification method for the Giant Star system described above. The solution provided by this device is similar to the solution described in the above method. Therefore, the specific limitations of one or more embodiments of the satellite identity verification device for the Giant Star system provided below can be found in the limitations of the satellite identity verification method for the Giant Star system described above, and will not be repeated here.
[0173] In one exemplary embodiment, such as Figure 7 As shown, a satellite identity verification device for the Giants constellation system is provided, comprising:
[0174] Satellite dataset acquisition module 201 is used to acquire satellite datasets; the satellite data includes one or more of satellite signal time difference of arrival (TDoA), Doppler frequency offset (DoDFS), and average received power difference (DoRP), as well as corresponding identity legitimacy labels; the labels include legitimate, illegitimate, and attack;
[0175] The dataset partitioning module 202 is used to partition the satellite dataset into a training set and a test set;
[0176] The identity legitimacy verification model construction module 203 is used to construct an identity legitimacy verification model based on CNN-LSTM deep learning;
[0177] Training module 204 is used to train the identity legitimacy verification model based on the training set;
[0178] The legitimacy verification and classification module 205 is used to verify and classify the legitimacy of satellites in the Giants constellation system based on a trained identity legitimacy verification model.
[0179] The model evaluation module 206 is used to evaluate the accuracy of the trained identity verification model. If the evaluation result is lower than a preset threshold, the identity verification model is retrained until convergence.
[0180] This document uses specific examples to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the methods and core ideas of this application. Furthermore, those skilled in the art will recognize that, based on the ideas of this application, there are variations in the specific implementation methods and application scope. Therefore, the content of this specification should not be construed as a limitation of this application.
Claims
1. A method for verifying the legitimacy of satellite identities in the Giants constellation system, characterized in that, The satellite identity verification method of the Giants constellation system includes: Obtain satellite datasets; the satellite data includes one or more of the following: time difference of arrival (TDoA), Doppler frequency offset (DoDFS), and average received power difference (DoRP), as well as corresponding identity legitimacy labels; the labels include legitimate, illegitimate, and attack. The satellite dataset is divided into a training set and a test set; Construct an identity verification model based on CNN-LSTM deep learning; The identity verification model is trained based on the training set; The legitimacy of satellites in the Giants constellation system is verified and classified based on a trained identity legitimacy verification model. The accuracy of the trained identity verification model is evaluated. If the evaluation result is lower than a preset threshold, the identity verification model is retrained until convergence.
2. The satellite identity verification method for the Giants constellation system according to claim 1, characterized in that, The acquisition of the satellite dataset specifically includes the following steps: Step 1: Import ephemeris TLE data of legitimate satellite constellations, ephemeris TLE data of simulating illegitimate satellite constellations, and drone flight path information simulating spoofing attacks; Step 2: Traverse the ephemeris TLE data of the legitimate satellite constellation, the ephemeris TLE data of the simulated illegitimate satellite constellation, and the flight path information of the drone simulating a spoofing attack to filter candidate signal sources: For legitimate signal sources, simulated illegal signal sources, and simulated deception drone signal sources, the ground station control center GS-CC generates a corresponding list of ground receiver coordinates and a list of measurement times based on the pre-set number of ground receivers and the number of measurements. Step 3: Based on the ground receiver coordinate list and measurement time list, the ground station control center, based on the ephemeris TLE data of legitimate satellite constellations, the ephemeris TLE data of simulated illegal satellite constellations, and the UAV trajectory information of simulated deception attacks, calls the coordinate calculation function of the signal source to which the current class belongs, to obtain the coordinate information and index number of the current specific signal source; Step 4: Perform a visibility check on the specific signal source. The specific check logic is as follows: if the specific signal source is visible to any receiver in the ground station receiver coordinate list under the selected measurement time list, then the specific signal source is selected as a candidate signal source and stored in the list; otherwise, the specific signal source is searched again until a preset number of candidate signal sources are successfully filtered and the process ends. For each type of signal source, before screening the candidate signal sources, their corresponding identity legitimacy labels are known. When data from a legitimate constellation satellite is collected, it is marked as "True"; when data from an illegitimate constellation satellite is collected, it is marked as "False"; and when data from a drone signal source is collected, it is marked as "Attacker". All satellites used to collect data from legitimate constellation satellites constitute a legitimate satellite whitelist. Step 5: Calculate the root mean square error (RMSE) between the actual TDoA signature matrix and the theoretical TDoA signature matrix of all imported satellites for each candidate signal source in the three signal source categories; the RMSE between the actual Doppler frequency offset (DoDFS) signature matrix and the theoretical Doppler frequency offset (DoDFS) signature matrix of all imported satellites; and the RMSE between the actual average received power (DoRP) signature matrix and the theoretical average received power (DoRP) signature matrix of all imported satellites. These are denoted as the first RMSE, second RMSE, and third RMSE, respectively. Each type of RMSE data is a one-dimensional array, with the array length equal to the number of imported satellites. Each element in the array corresponds to the RMSE between a theoretical satellite and the actual candidate satellite. The authentication results for each specific candidate signal source are as follows: Step 6: Select the satellite certification label with the smallest root mean square error as the first preliminary certification result for the satellite; Step 7: Select the satellite certification label with the smallest second root mean square error as the second preliminary certification result for the satellite; Step 8: Select the satellite certification label with the smallest third root mean square error as the third preliminary certification result of the satellite; Step 9: Determine whether the first, second, and third preliminary authentication results of the satellite are in the legal satellite whitelist. If the first, second, and third preliminary authentication results of the satellite are found to be in the legal satellite whitelist after retrieval, then the first, second, and third preliminary authentication results of the satellite are determined to be legal satellite signal sources. At this time, a "True" label and coordinate data are returned for the satellite signal source. If not, then the first, second, and third preliminary authentication results of the satellite are determined to be illegal satellite signal sources. At this time, a "False" label and coordinate data are temporarily returned for the illegal satellite signal source. Step 10: Based on the preliminary authentication results of the first, second, and third satellites in the previous step, the ground station control center further analyzes the legitimacy of the signal source: First, the ground station control center constructs a three-dimensional grid between the geometric center of the ground receiver and the current candidate signal source. The three-dimensional grid has a cubic structure, with the direction vector connecting the geometric center of the ground receiver and the current candidate signal source as the central axis. By applying spatial rotation and scaling to the local grid, it is made to accurately align with the central axis direction in space and cover all grid points to be tested along the line. Step 11: Assuming that each grid point in the three-dimensional grid is a corresponding stationary signal source, calculate its corresponding theoretical TDoA signature matrix, DoDFS signature matrix, and DoRP signature matrix; the ground station control center then calculates the root mean square error (RMSE) between its theoretical TDoA signature matrix, DoDFS signature matrix, and DoRP signature matrix and the actual TDoA signature matrix, DoDFS signature matrix, and DoRP signature matrix of the candidate signal source. Step 12: According to the judgment method of the first, second and third preliminary authentication results of the satellite mentioned above, the ground station control center finds the identity label corresponding to the grid point signal source with the minimum RMSE in the three categories as the preliminary authentication result of the candidate signal source, which is called the first, second and third preliminary authentication results of the grid point. This process is essentially to find the best matching grid point signal source in the above three-dimensional grid points. Step 13: The ground station control center further analyzes the first, second, and third preliminary authentication results of the grid points. If the signal source altitude corresponding to the first, second, and third preliminary authentication results of the grid points is less than 100 kilometers and the residual improvement ratio is higher than the set value, then the candidate signal source is finally determined to be a spoofing attack, and the "Attacker" label and the grid coordinates of the corresponding first, second, and third preliminary authentication results of the grid points are returned. Otherwise, it is determined that there is no other unknown signal source more suitable than the first, second, and third preliminary authentication results of the satellite in the current time slot, and the first, second, and third preliminary authentication results of the satellite are returned, i.e., the "True" label or the "False" label, the satellite serial number index, and the corresponding coordinate data. At this point, the authentication of the specific signal source is complete, and the final authentication results of TDoA, DoDFS, and DoRP are obtained. If two or more of the authentication results of TDoA, DoDFS, and DoRP are consistent, it means that the current candidate signal source data is valid and the corresponding data is stored; otherwise, the data is considered invalid and is discarded. Repeat the above process until a sufficient amount of labeled data is obtained.
3. The satellite identity verification method for the Giants constellation system according to claim 2, characterized in that, The expression for the TDoA signature matrix is as follows: Among them, M TDoA Represents the TDoA signature matrix. This represents the TDoA value of the nth ground station relative to the base station in the mth measurement. This indicates that the matrix has dimensions of m rows and n columns; The expression for the DoDFS signature matrix is as follows: in, This represents the difference between the Doppler frequency offset value of the satellite under test measured by the nth ground station in the mth measurement and the Doppler frequency offset value of the satellite signal under test measured by the reference ground station; The expression for the DoRP signature matrix is as follows: in, This represents the difference between the average received power of the satellite signal received by the nth ground station in the mth measurement and the average received power of the satellite signal received by the reference ground station.
4. The satellite identity verification method for the Giant Scorpius system according to claim 2, characterized in that, The satellite identity legitimacy verification method for the Giant Star system further includes the following steps after "adding labels to the hybrid signature matrix of the illegal satellite, the hybrid signature matrix of the attacking drone, and the hybrid signature matrix of the legitimate satellite to obtain the satellite dataset": The hybrid signature matrix of the illegal satellite, the hybrid signature matrix of the attacking drone, and the hybrid signature matrix of the legitimate satellite are divided into multiple sub-matrices with fixed time steps along the time dimension using a sliding window.
5. The satellite identity verification method for the Giant Scorpius system according to claim 4, characterized in that, The identity verification model includes: a CNN part, an LSTM part, and a fully connected layer; The CNN part, LSTM part, and fully connected layer are connected sequentially.
6. The satellite identity verification method for the Giant Pisces system according to claim 1, characterized in that, Training the identity legitimacy verification model based on the training set specifically includes the following steps: The cross-entropy loss function is used as the optimization objective, and the Adam optimizer is used to update the weights of the identity verification model. In each round of training, samples are loaded sequentially from the training set, and the identity verification model parameters are updated through the forward and backward propagation processes of the identity verification model.
7. The satellite identity verification method for the Giants constellation system according to claim 1, characterized in that, The accuracy of the trained identity verification model is evaluated. If the evaluation result is lower than a preset threshold, the identity verification model is retrained until convergence. This specifically includes the following steps: The identity legitimacy verification model is validated using a test set, and the loss and accuracy of the identity legitimacy verification model on the validation set are calculated. Dropout regularization was not used during the training of the identity legitimacy verification model to ensure the integrity of temporal continuity. If the current validation accuracy is better than the previous best model, then save the current model parameters; Plot the loss curve and accuracy curve of the identity legitimacy verification model on the training set and test set, and calculate the authentication accuracy, false alarm rate and false alarm rate of the test set based on the confusion matrix; If the authentication accuracy, false alarm rate, and missed alarm rate are lower than preset thresholds, the satellite dataset is updated, and the identity legitimacy verification model is retrained.
8. A satellite identity verification device for the Giants constellation system, characterized in that, The satellite identity verification device of the Giant Star system includes: The satellite dataset acquisition module is used to acquire satellite datasets; the satellite data includes one or more of the following: time difference of arrival (TDoA), Doppler frequency offset (DoDFS), and average received power difference (DoRP), as well as corresponding identity legitimacy labels; the labels include legitimate, illegitimate, and attack. The dataset partitioning module is used to divide the satellite dataset into a training set and a test set; The identity legitimacy verification model building module is used to build an identity legitimacy verification model based on CNN-LSTM deep learning. The training module is used to train the identity legitimacy verification model based on the training set; The legitimacy verification and classification module is used to verify and classify the legitimacy of satellites in the Giants constellation system based on a trained identity legitimacy verification model. The model evaluation module is used to evaluate the accuracy of the trained identity verification model. If the evaluation result is lower than a preset threshold, the identity verification model is retrained until convergence.
Citation Information
Patent Citations
Load prediction method for low earth orbit satellite internet of things
CN116170066A
Individual identification method under satellite variable modulation based on multi-task decoupling learning
CN119025991A
Satellite communication authentication integration method and device
CN119743756A
Network verified user device position in a wireless communication network
US20240284396A1