Commercial satellite operations using a safety zone for payload operations
By generating and encrypting managed commands in the secure area of the satellite operations center, the problem of lack of privacy in resource allocation during satellite payload operations is solved. This achieves data isolation and dynamic resource allocation between the host and managed users, ensuring the privacy of managed users and the on-demand allocation of resources.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- THE BOEING CO
- Filing Date
- 2018-09-26
- Publication Date
- 2026-04-24
AI Technical Summary
In existing technologies, satellite payload operation lacks privacy in resource allocation, and all switching is controlled by a single satellite controller, making it impossible to achieve privacy allocation.
By receiving managed user requests through the secure zone of the host satellite operations center (SOC), generating and encrypting managed commands, using the COMSEC variant for encrypted transmission, and decrypting and reconfiguring the payload on the carrier, data isolation and privacy control between the host and managed users are achieved.
It enables the private sharing and dynamic allocation of satellite resources between the host and managed users, ensuring the privacy of managed users' data and operations, and providing on-demand resource allocation capabilities.
Smart Images

Figure CN115694899B_ABST
Abstract
Description
[0001] This application is a divisional application of Chinese patent application 201811121819.8, filed on September 26, 2018, entitled "Commercial satellite operation using a security zone for payload operation". Technical Field
[0002] This disclosure relates to payload operation. In particular, this disclosure relates to commercial satellite operation using a security zone designated for payload operation. Background Technology
[0003] Currently, typical payload operations for launch vehicles (e.g., satellites) are capable of performing input-to-output switching of the payload on the launch vehicle. All these switching operations on the payload are commanded and controlled by a single satellite controller, without any resource allocation privacy.
[0004] Therefore, an improved payload operation design is needed that allows for privacy in the allocation of resources on the payload. Summary of the Invention
[0005] This disclosure relates to methods, systems, and apparatus for commercial satellite operations utilizing a security zone for payload operations. In one or more embodiments, a method for payload operations includes: receiving, through a security zone of a host satellite operations center (SOC), at least one request from at least one hosted user, wherein each request includes a service specification of the hosted user associated with the request. The method further includes: generating an unencrypted hosted command for each request, based on the service specification of the request, through the security zone. Furthermore, the method includes: encrypting, through the security zone, for each request, the unencrypted hosted command by utilizing a corresponding Hosted Communications Security (COMSEC) variant of the hosted user associated with the request to produce an encrypted hosted command. Additionally, the method includes: encrypting the unencrypted host command by utilizing a host COMSEC variant, through the SOC operations portion of the host SOC, to produce an encrypted host command. Finally, the method includes: transmitting the encrypted host command and the encrypted hosted command to a carrier through the host SOC.
[0006] Furthermore, the method includes: decrypting encrypted host commands using a host COMSEC variant via a host communication security module on the carrier to generate unencrypted host commands. Additionally, the method includes: decrypting encrypted managed commands for each managed user using a corresponding managed communication security module on the carrier, using the corresponding managed COMSEC variant, to generate unencrypted managed commands. Furthermore, the method includes: reconfiguring the host / hosted payload on the carrier based on the unencrypted host commands and the unencrypted managed commands.
[0007] Furthermore, the method includes: generating unencrypted host telemetry and unencrypted managed telemetry via a host / managed payload. Furthermore, the method includes: encrypting the unencrypted host telemetry using a host COMSEC variant via a host communication security module to generate encrypted host telemetry. Furthermore, the method includes: encrypting the unencrypted managed telemetry for each managed user using a corresponding managed communication security module for each managed user, thereby generating encrypted managed telemetry. Additionally, the method includes: transmitting the encrypted host telemetry and encrypted managed telemetry to the host SOC via a carrier.
[0008] Additionally, the method includes: via the SOC operation section, decrypting encrypted host telemetry using a host COMSEC variant to generate unencrypted host telemetry. Additionally, the method includes: via a secure zone, decrypting encrypted managed telemetry for each managed user using the corresponding managed COMSEC variant to generate unencrypted managed telemetry for each managed user.
[0009] In one or more embodiments, the method further includes: generating unencrypted host commands according to the service specifications of the host user via the SOC operation section.
[0010] In at least one embodiment, the method further includes: transmitting host user data to a host user antenna and transmitting managed user data to a managed user antenna via a payload antenna on the carrier.
[0011] In one or more embodiments, encrypted host commands are transmitted from a host SOC to a carrier using at least one out-of-band frequency band and / or at least one in-band frequency band. In at least one embodiment, when transmitting encrypted host commands using at least one out-of-band frequency band, the encrypted host commands are transmitted from the host SOC to the carrier via the SOC antenna. In some embodiments, when transmitting encrypted host commands using at least one in-band frequency band, the encrypted host commands are transmitted from the host SOC to the carrier via a host gateway antenna.
[0012] In at least one embodiment, encrypted managed commands are transmitted from the host SOC to the carrier using at least one out-of-band frequency band and / or at least one in-band frequency band. In one or more embodiments, when encrypted managed commands are transmitted using at least one out-of-band frequency band, the encrypted managed commands are transmitted from the host SOC to the carrier via the SOC antenna. In some embodiments, when encrypted managed commands are transmitted using at least one in-band frequency band, the encrypted managed commands are transmitted from the host SOC to the carrier via the host gateway antenna.
[0013] In at least one embodiment, encrypted host telemetry is transmitted from the carrier to the host SOC using at least one out-of-band frequency band and / or at least one in-band frequency band. In some embodiments, when encrypted host telemetry is transmitted using at least one out-of-band frequency band, the encrypted host telemetry is transmitted from the carrier to the host SOC via the SOC antenna. In one or more embodiments, when encrypted host telemetry is transmitted using at least one in-band frequency band, the encrypted host telemetry is transmitted from the carrier to the host SOC via a host gateway antenna.
[0014] In at least one embodiment, encrypted managed telemetry is transmitted from the carrier to the host SOC using at least one out-of-band frequency band and / or at least one in-band frequency band. In one or more embodiments, when encrypted managed telemetry is transmitted using at least one out-of-band frequency band, the encrypted managed telemetry is transmitted from the carrier to the host SOC via the SOC antenna. In some embodiments, when encrypted managed telemetry is transmitted using at least one in-band frequency band, the encrypted managed telemetry is transmitted from the carrier to the host SOC via the host gateway antenna.
[0015] In one or more embodiments, the host / hosted payload is a digital payload or an analog payload. In some embodiments, reconfiguring the host / hosted payload includes adjusting: transponder power, transponder spectrum monitoring, transponder connectivity, transponder gain settings, transponder limiter settings, transponder automatic level control settings, transponder phase settings, internal gain generation, bandwidth of at least one beam, at least one frequency band of at least one beam, transponder beamforming settings, effective isotropic radiated power (EIRP) of at least one beam, transponder channels, and / or beam steering.
[0016] In at least one embodiment, reconfiguring the host / hosted payload includes reconfiguring the payload antenna, at least one analog-to-digital converter, at least one digital-to-analog converter, at least one beamformer, at least one digital channelizer, at least one demodulator, at least one modulator, at least one digital switch matrix, at least one digital combiner, and / or at least one analog switch matrix.
[0017] In one or more embodiments, the carrier is a satellite, aircraft, unmanned aerial vehicle (UAV), or spaceplane.
[0018] In at least one embodiment, a method for payload operation includes: receiving at least one request from at least one managed user through a security zone of a host satellite operations center (SOC), wherein each request includes a service specification of the managed user associated with the request. The method further includes: generating an unencrypted managed command for each request, according to the service specification of the request, through the security zone. Additionally, the method includes: encrypting the unencrypted managed command for each request through the security zone by utilizing a corresponding Managed Communications Security (COMSEC) variant of the managed user associated with the request to produce an encrypted managed command. Furthermore, the method includes: encrypting the unencrypted host command through a SOC operations portion of the host SOC by utilizing a host COMSEC variant to produce an encrypted host command. Finally, the method includes: transmitting the encrypted host command and the encrypted managed command to a carrier through the host SOC.
[0019] Furthermore, the method includes: decrypting encrypted host commands using a host COMSEC variant via a host communication security module on the carrier to generate unencrypted host commands. Additionally, the method includes: decrypting encrypted managed commands for each managed user using a corresponding managed communication security module on the carrier, using a corresponding managed COMSEC variant, to generate unencrypted managed commands. Furthermore, the method includes: reconfiguring the host payload on the carrier based on the unencrypted host commands. Furthermore, the method includes: commanding at least one managed payload on the carrier to open or close based on the unencrypted host commands. Finally, the method includes: reconfiguring at least one managed payload based on the unencrypted managed commands.
[0020] Additionally, the method includes: generating unencrypted host telemetry using a host payload. Additionally, the method includes: generating unencrypted managed telemetry using at least one managed payload. Furthermore, the method includes: encrypting the unencrypted host telemetry using a host COMSEC variant via a host communication security module to generate encrypted host telemetry. Additionally, the method includes: encrypting the unencrypted managed telemetry for each managed user using a corresponding managed communication security module for each managed user, thereby generating encrypted managed telemetry. Finally, the method includes: transmitting the encrypted host telemetry and the encrypted managed telemetry to the host SOC via a carrier.
[0021] Furthermore, the method includes: via the SOC operation section, decrypting encrypted host telemetry using a host COMSEC variant to generate unencrypted host telemetry. Additionally, the method includes: via a secure zone, decrypting encrypted managed telemetry for each managed user using the appropriate managed COMSEC variant to generate unencrypted managed telemetry for each managed user.
[0022] In one or more embodiments, the method further includes: generating unencrypted host commands according to the service specifications of the host user via the SOC operation section.
[0023] In at least one embodiment, the method further includes: transmitting host user data to a host user antenna via a host payload antenna on the carrier; and transmitting managed user data to a managed user antenna via a managed payload antenna on the carrier. In some embodiments, the host user antenna is a steerable reflector antenna or a phased array antenna, and the managed user antenna is a steerable reflector antenna or a phased array antenna.
[0024] In one or more embodiments, the host payload is a digital payload or an analog payload, and at least one managed payload is a digital payload or an analog payload.
[0025] In at least one embodiment, reconfiguring the host payload and / or at least one managed payload includes adjusting: transponder power, transponder spectrum monitoring, transponder connectivity, transponder gain settings, transponder limiter settings, transponder automatic level control settings, transponder phase settings, internal gain generation, bandwidth of at least one beam, at least one frequency band of at least one beam, transponder beamforming settings, effective isotropic radiated power (EIRP) of at least one beam, transponder channel and / or beam steering.
[0026] In one or more embodiments, reconfiguring the host payload and / or at least one managed payload includes reconfiguring: the host payload antenna, the managed payload antenna, at least one analog-to-digital converter, at least one digital-to-analog converter, at least one beamformer, at least one digital channelizer, at least one demodulator, at least one modulator, at least one digital switch matrix, at least one digital combiner, and / or at least one analog switch matrix.
[0027] In at least one embodiment, a system for payload operation includes: a secure zone of a host satellite operations center (SOC) that receives at least one request from at least one managed user, wherein each request includes a service specification of the managed user associated with the request. The system further includes: a secure zone that, for each request, generates an unencrypted managed command according to the service specification of the request, and, for each request, encrypts the unencrypted managed command by utilizing a corresponding Managed Communications Security (COMSEC) variant of the managed user associated with the request to produce an encrypted managed command. Furthermore, the system includes: a SOC operations portion of the host SOC that encrypts the unencrypted host command by utilizing a host COMSEC variant to produce an encrypted host command. Additionally, the system includes: a host SOC that transmits the encrypted host command and the encrypted managed command to a carrier.
[0028] In addition, the system includes: a host communication security module on the carrier that decrypts encrypted host commands using a host COMSEC variant to generate unencrypted host commands. Additionally, the system includes: a corresponding managed communication security module on the carrier for each managed user that decrypts encrypted managed commands for each managed user using the corresponding managed COMSEC variant to generate unencrypted managed commands. Furthermore, the system includes: a host / managed payload on the carrier configured to be reconfigured based on the unencrypted host commands and unencrypted managed commands, and generates unencrypted host telemetry and unencrypted managed telemetry.
[0029] Additionally, the system includes: a host communication security module that encrypts unencrypted host telemetry using a host COMSEC variant to generate encrypted host telemetry. Furthermore, the system includes: a corresponding managed communication security module for each managed user that encrypts unencrypted managed telemetry for each managed user using the corresponding managed COMSEC variant to generate encrypted managed telemetry. Additionally, the system includes: a carrier that transmits the encrypted host telemetry and encrypted managed telemetry to the host SOC.
[0030] In addition, the system includes: a SOC operation section that decrypts encrypted host telemetry using a host COMSEC variant to generate unencrypted host telemetry. Furthermore, the system includes: a security zone that decrypts encrypted managed telemetry for each managed user using a corresponding managed COMSEC variant to generate unencrypted managed telemetry for each managed user.
[0031] In one or more embodiments, a system for payload operation includes: a secure zone of a host satellite operations center (SOC) that receives at least one request from at least one managed user, wherein each request includes a service specification of the managed user associated with the request. The system further includes: a secure zone that, for each request, generates an unencrypted managed command according to the service specification of the request, and, for each request, encrypts the unencrypted managed command by utilizing a corresponding Managed Communications Security (COMSEC) variant of the managed user associated with the request to produce an encrypted managed command. Additionally, the system includes: a SOC operations portion of the host SOC that encrypts the unencrypted host command by utilizing a host COMSEC variant to produce an encrypted host command. Furthermore, the system includes: a host SOC that transmits the encrypted host command and the encrypted managed command to a carrier.
[0032] Additionally, the system includes: a host communication security module on the carrier that decrypts encrypted host commands using a host COMSEC variant to generate unencrypted host commands. Furthermore, the system includes: a corresponding managed communication security module on the carrier for each managed user that decrypts encrypted managed commands for each managed user using the corresponding managed COMSEC variant to generate unencrypted managed commands. Additionally, the system includes: a host payload on the carrier configured to be reconfigured according to unencrypted host commands and to generate unencrypted host telemetry. Additionally, the system includes: at least one managed payload on the carrier configured to be commanded to open or close according to unencrypted host commands, and to be reconfigured according to unencrypted managed commands and to generate unencrypted managed telemetry.
[0033] In addition, the system includes: a host communication security module that encrypts unencrypted host telemetry using a host COMSEC variant to generate encrypted host telemetry. Additionally, the system includes: a corresponding managed communication security module for each managed user that encrypts unencrypted managed telemetry for each managed user using the corresponding managed COMSEC variant to generate encrypted managed telemetry. Furthermore, the system includes: a carrier that transmits the encrypted host telemetry and encrypted managed telemetry to the host SOC.
[0034] Additionally, the system includes: a SOC operation section that decrypts encrypted host telemetry using a host COMSEC variant to generate unencrypted host telemetry. Furthermore, the system includes: a security zone that decrypts encrypted managed telemetry for each managed user using a corresponding managed COMSEC variant to generate unencrypted managed telemetry for each managed user.
[0035] In at least one embodiment, a method for payload operation includes: generating managed commands according to service specifications of at least one managed user through the security zone of a host satellite operations center (SOC). The method further includes: generating host commands according to the service specifications of the host user through the SOC operations portion of the host SOC. Additionally, the method includes: transmitting the host commands and managed commands to a launch vehicle through the host SOC. Furthermore, the method includes: reconfiguring the host / managed payload on the launch vehicle based on the host commands and managed commands. Additionally, the method includes: generating host telemetry and managed telemetry using the host / managed payload. Furthermore, the method includes: transmitting the host telemetry and managed telemetry to the host SOC through the launch vehicle.
[0036] In one or more embodiments, a method for payload operation includes: generating a managed command, according to the service specifications of at least one managed user, through the security zone of a host satellite operations center (SOC). The method further includes: generating a host command, according to the service specifications of a host user, through the SOC operations portion of the host SOC. Additionally, the method includes: transmitting the host command and the managed command to a launch vehicle through the host SOC. Furthermore, the method includes: reconfiguring the host payload on the launch vehicle according to the host command. Additionally, the method includes: commanding at least one managed payload on the launch vehicle to turn on or off according to the host command. Furthermore, the method includes: reconfiguring at least one managed payload according to the managed command. Furthermore, the method includes: generating host telemetry through the host payload. Furthermore, the method includes: generating managed telemetry through at least one managed payload. Furthermore, the method includes: transmitting the host telemetry and the managed telemetry to the host SOC through the launch vehicle.
[0037] The features, functions, and advantages may be implemented independently in the various embodiments of this disclosure, or may be combined in other embodiments. Attached Figure Description
[0038] These and other features, aspects, and advantages of this disclosure will be better understood with reference to the following description and accompanying drawings, wherein:
[0039] Figures 1-3B Systems, methods, and apparatus for commercial satellite operations utilizing a security zone for payload operations, employing a launch vehicle with a single host / hosted payload.
[0040] Figure 1This is a diagram illustrating a system disclosed for commercial satellite operation using a security zone for payload operation, according to at least one embodiment of the present disclosure; wherein (1) the launch vehicle employs a digital host / hosted payload, and (2) host commands, hosted commands, host telemetry, and hosted telemetry are all transmitted out of band.
[0041] Figure 2 This is a diagram illustrating a system disclosed for commercial satellite operation using a security zone for payload operation, according to at least one embodiment of the present disclosure; wherein (1) the launch vehicle employs a digital host / hosted payload, and (2) host commands and host telemetry are transmitted out of band, and hosted commands and hosted telemetry are transmitted in-band.
[0042] Figure 3A and Figure 3B Together illustrated are at least one embodiment of the disclosed method for utilizing... Figure 1 and Figure 2 The flowchart shown is a method for operating commercial satellites within the safe zone of the system's payload operation.
[0043] Figures 4-7C Systems, methods, and apparatus for commercial satellite operations utilizing a security zone for payload operations are disclosed, employing a launch vehicle having a main payload and at least one separately hosted payload.
[0044] Figure 4 This is a diagram illustrating a system disclosed for commercial satellite operation using a security zone for payload operation, according to at least one embodiment of the present disclosure; wherein (1) the launch vehicle employs a digital host payload and at least one analog managed payload, and (2) host commands, managed commands, host telemetry and managed telemetry are all transmitted out of band.
[0045] Figure 5 This is a diagram illustrating a system disclosed for commercial satellite operation using a security zone for payload operation, according to at least one embodiment of the present disclosure; wherein (1) the launch vehicle employs a digital host payload and at least one analog managed payload, and (2) managed commands and managed telemetry are transmitted out of band, and host commands and host telemetry are transmitted in-band.
[0046] Figure 6 This is a diagram illustrating a system disclosed for commercial satellite operation using a security zone for payload operation, according to at least one embodiment of the present disclosure; wherein (1) the launch vehicle employs an analog host payload and at least one digital managed payload, and (2) host commands and host telemetry are transmitted out of band, and managed commands and managed telemetry are transmitted in-band.
[0047] Figure 7A , Figure 7B and Figure 7C Together illustrated are at least one embodiment of the disclosed method for utilizing... Figure 4 , Figure 5 and Figure 6 The flowchart shown is a method for operating commercial satellites within the safe zone of the system's payload operation.
[0048] Figure 8 This is an electronic data sheet illustrating possible combinations of host commands, host telemetry, managed commands, and managed telemetry transmissions (i.e., out-of-band or in-band transmissions) for a system for commercial satellite operations utilizing a security zone for payload operations, according to at least one embodiment of the present disclosure. Detailed Implementation
[0049] The methods and apparatus disclosed herein provide an operating system for commercial satellite operations utilizing a security zone for payload operation. The system of this disclosure allows launch vehicle operators (i.e., host users) to privately share launch vehicle resources (e.g., one or more satellite payloads) with customers (e.g., managed users). Specifically, the disclosed system employs a host satellite operations center (SOC) that separates data processing (e.g., command and telemetry) between the host user and managed users (one or more) by utilizing a security zone and an operating section of the SOC. The security zone section is a secure portion of the host SOC used for managed user data processing and allows managed users (one or more) to maintain the privacy of their data and operations from the host user. Therefore, the security zone provides complete autonomous control over a portion of a shared payload (e.g., host / managed payload) or a portion of at least one individual managed payload mounted on the satellite. The host SOC arrangement does not allow the host user to be aware of commands or telemetry from a portion of a shared payload (e.g., host / managed payload) used by (one or more) managed users or from a portion of at least one individual managed payload mounted on the satellite used by (one or more) managed users. The SOC operations section is used for host user data processing, and it maintains the privacy of host users.
[0050] As previously mentioned, typical payload operations for launch vehicles (e.g., satellites) currently perform input-to-output switching of the payload on the launch vehicle. All these switching operations on the payload are commanded and controlled by a single satellite controller, without any privacy in resource allocation. Public systems allow for private launch vehicle resource allocation and control, providing launch vehicle users with the ability to allocate resources (e.g., host / hosted payloads, host payloads, and / or hosted payloads) privately and dynamically on demand.
[0051] It should be noted that the host / managed payloads (i.e., shared payloads), host payloads, and / or at least one managed payload of the disclosed system for the allocation and control of private carrier resources can employ various types of repeaters. For example, various types of repeaters can be employed, including but not limited to various types of digital repeaters, various types of analog repeaters (e.g., conventional repeater-type repeaters), and various combinations of analog / digital repeaters.
[0052] Furthermore, it should be noted that in this disclosure, (one or more) in-band frequency bands refer to (one or more) frequency bands that are the same as (one or more) frequency bands used for transmitting payload data (e.g., host payload data and / or managed payload data); and (one or more) out-of-band frequency bands refer to (one or more) frequency bands that are different from (one or more) frequency bands used for transmitting payload data (e.g., host payload data). Additionally, it should be noted that in the disclosed system, all commands and telemetry can be executed via any combination of (one or more) in-band frequency bands and (one or more) out-of-band frequency bands. See also Figure 8 It illustrates possible combinations of host commands, host telemetry, managed commands, and managed telemetry transmissions (i.e., out-of-band or in-band transmissions) for the disclosed system.
[0053] In the following description, numerous details are set forth to provide a more comprehensive description of the system. However, it will be apparent to those skilled in the art that the disclosed system can be practiced without these specific details. In other instances, well-known features have not been described in detail to avoid unnecessarily obscuring the system.
[0054] Embodiments of this disclosure may be described herein in terms of functional and / or logical components and various processing steps. It should be understood that these components can be implemented by any number of hardware, software, and / or firmware components configured to perform the specified functions. For example, embodiments of this disclosure may employ various integrated circuit components (e.g., memory elements, digital signal processing elements, logic elements, lookup tables, etc.) that can perform various functions under the control of one or more processors, microprocessors, or other control devices. Furthermore, those skilled in the art will understand that embodiments of this disclosure can be practiced in combination with other components, and the system described herein is merely one example embodiment of this disclosure.
[0055] For the sake of brevity, conventional technologies and components related to satellite communication systems, as well as other functional aspects of the system (and its various operational components), may not be described in detail herein. Furthermore, the connecting lines shown in the various figures contained herein are intended to represent exemplary functional relationships and / or physical couplings between various elements. It should be noted that many alternative or additional functional relationships or physical connections may exist in the embodiments of this disclosure.
[0056] Figures 1-3B Systems, methods, and apparatus for commercial satellite operations utilizing a security zone for payload operations, employing a launch vehicle with a single host / hosted payload.
[0057] Figure 1 This is a diagram illustrating a system disclosed according to at least one embodiment of the present disclosure for commercial satellite operations using a secure area for payload operations; wherein (1) the launch vehicle employs a digital host / hosted payload 106, and (2) host commands, hosted commands, host telemetry, and hosted telemetry are all transmitted out of band. In this figure, launch vehicle 110 and host satellite operations center (SOC) 150 are shown. Various types of launch vehicles can be used for launch vehicle 110, including but not limited to air launch vehicles. Furthermore, various types of air launch vehicles can be used for launch vehicle 110, including but not limited to satellites, aircraft, unmanned aerial vehicles (UAVs), and spaceplanes.
[0058] When using a satellite for launch vehicle 110, it should be noted that the satellite typically includes computer-controlled systems. The satellite typically includes a bus and a payload (e.g., a shared host / hosted payload 106). The bus may include systems (which include components) for controlling the satellite. These systems perform tasks such as power generation and control, thermal control, telemetry, attitude control, orbit control, and other suitable operations.
[0059] The satellite's payload provides functionality to the satellite's users. The payload may include antennas, transponders, and other suitable equipment. For example, a payload in a satellite may be used to provide internet access, telephone communication, radio, television, and / or other types of communication, in relation to communications. Different entities may use different portions of the shared payload 106 on the satellite. For example, a host user (e.g., the satellite owner) may utilize a portion of the host / hosted payload 106, and a host user may lease different portions of the host / hosted payload 106 to hosting users (e.g., customers) for use.
[0060] Leasing a portion of (one or more) payloads (e.g., hosted / managed payload 106) to (one or more) customers (e.g., hosted users) can increase the revenue available to the satellite owner (e.g., the host user). Furthermore, customers can use a subset of the total resources in the satellite at a cost less than the cost of purchasing and operating the satellite, building and operating the satellite, or leasing the entire satellite.
[0061] During operation, managed users 160 (e.g., N managed users 160) (via a terrestrial link with an Internet Protocol Security (IPSec) Virtual Private Network (VPN)) transmit requests 130 to security zone 152 of Host Satellite Operations Center (SOC) 150, where each request includes the service specification of the managed user associated with the request. Various types of service specifications that can be transmitted include, but are not limited to, the area of antenna coverage, the effective isotropic radiated power (EIRP) of the antenna coverage, and the time period during which antenna coverage occurs. For example, managed user #1 160 may transmit 130: one or more requests including service specifications for a specific area on Earth to receive antenna coverage (e.g., by specifying the latitude and longitude coordinates, geocentric coordinates, and / or geodetic coordinates of the coverage area), the minimum EIRP level (of which it will be received for antenna coverage), and the time period during which antenna coverage occurs.
[0062] After receiving a request, security zone 152 generates an unencrypted managed command for each request according to the service specification associated with the request. The managed command is a command used to configure each of the host / managed payload 106 portions used by managed user 160. Security zone 152 then encrypts the unencrypted managed command for each request by utilizing the corresponding Managed Communications Security (COMSEC) variant for the managed user associated with the request, to produce an encrypted managed command. Therefore, for each managed user 160, a different managed COMSEC variant will be used to encrypt the managed commands associated with that managed user 160. Subsequently, for N managed users 106, N managed COMSEC variants will be used to encrypt the managed commands. However, it should be noted that for the encryption of managed user commands, COMSEC variants 2 to COMSEC variant N+1 will be used. For example, a managed command associated with one or more requests from managed user #1 160 will be encrypted using COMSEC variant 2, a managed command associated with one or more requests from managed user #2 160 will be encrypted using COMSEC variant 3, a managed command associated with one or more requests from managed user #3 160 will be encrypted using COMSEC variant 4, and so on, and a managed command associated with one or more requests from managed user #N 160 will be encrypted using COMSEC variant N+1. It should be noted that each managed COMSEC variant may include at least one encryption key and / or at least one algorithm (e.g., a type 1 encryption algorithm or a type 2 encryption algorithm). The secure zone 152 then transmits the encrypted managed command 131 to the satellite operations section 151 of the host SOC 150.
[0063] The satellite operations section 151 of the host SOC 150 generates unencrypted host commands based on the service specifications of the host user. Host commands are commands used to configure the host / hosted payload 106 used by the host user. Various types of service specifications can be specified by the host user, including but not limited to the area covered by the antenna, the effective isotropic radiated power (EIRP) of the antenna coverage, and the time period during which the antenna coverage occurs. The satellite operations section 151 then encrypts the unencrypted host commands using a host COMSEC variant (e.g., COMSEC variant 1) to produce encrypted host commands. It should be noted that the host COMSEC variant may include at least one encryption key and / or at least one algorithm (e.g., a type 1 encryption algorithm or a type 2 encryption algorithm).
[0064] The satellite operations section 151 of the host SOC 150 then transmits encrypted host commands and encrypted managed commands 115 to the ground SOC antenna 116 (via a terrestrial link with an IPSec VPN). The SOC antenna 116 then transmits the encrypted host commands and encrypted managed commands 120 to the command antenna 121 on the launch vehicle 110. The SOC antenna 116 utilizes one or more out-of-band frequencies (i.e., one or more frequency bands different from those used for transmitting payload data) to transmit the encrypted host commands and encrypted managed commands 120. The command antenna 121 on the launch vehicle 110 then transmits the encrypted host commands 122 to the command receiver 135.
[0065] Command receiver 135 then transmits the encrypted host command 153 to host communication security module 162. Host communication security module 162 uses a host COMSEC variant (e.g., COMSEC variant 1) to decrypt the encrypted host command to generate an unencrypted host command.
[0066] It should be noted that the host communication security module 162 may include one or more communication security modules (e.g., communication security module 1 and communication security module 2, wherein communication security module 2 is a redundant communication security module used in the event of a failure of communication security module 1), wherein the additional communication security module is a redundant communication security module used in the event of a failure of a communication security module. Additionally, the host communication security module 162 may include one or more processors.
[0067] Command receiver 135 also transmits encrypted managed commands 154 to managed communication security module 163. Managed communication security module 163 decrypts the encrypted managed commands using managed COMSEC variants (e.g., COMSEC variant 2 to COMSEC variant N+1) to generate unencrypted managed commands.
[0068] It should be noted that each of the managed communication security modules 163 may include one or more communication security modules (e.g., communication security module 1 and communication security module 2, wherein communication security module 2 is a redundant communication security module used in the event of a failure of communication security module 1), wherein the additional communication security module is a redundant communication security module used in the event of a failure of a communication security module. Additionally, each of the host communication security modules 163 may include one or more processors.
[0069] The host communication security module 162 then transmits unencrypted host commands 170 to the host / hosted payload 106. Furthermore, the hosted communication security module 163 then transmits unencrypted hosted commands 171 to the host / hosted payload 106. The host / hosted payload 106 is reconfigured based on the unencrypted host commands and the unencrypted hosted commands. The reconfiguration of the host / hosted payload 106 may include adjusting at least one of the following: transponder power, transponder spectrum monitoring, transponder connectivity, transponder gain settings, transponder limiter settings, transponder automatic level control settings, transponder phase settings, internal gain generation, bandwidth of at least one beam, at least one frequency band of at least one beam, transponder beamforming settings, effective isotropic radiated power (EIRP) of at least one beam, and transponder channel or beam steering. Additionally, reconfiguration of the host / hosted payload 106 may include reconfiguring at least one of the following: payload antenna 180, at least one analog-to-digital converter, at least one digital-to-analog converter, at least one beamformer, at least one digital channelizer, at least one demodulator, at least one modulator, at least one digital switch matrix, at least one digital combiner, or at least one analog switch matrix. In one or more embodiments, the host / hosted payload includes 106 with one or more processors.
[0070] After reconfiguring the host / hosted payload 106, the payload antenna 180 then transmits host user data (e.g., in one or more antenna beams 181) to the host user antenna 185 on the ground, and transmits hosted user data to the hosted user antenna 190 on the ground. It should be noted that in other embodiments, the host user antenna 185 and / or the hosted user antenna 190 may be in the air (e.g., located on an aircraft or satellite) or at sea (e.g., located on a ship) instead of... Figure 1 As shown on the ground (e.g., located on the ground).
[0071] Furthermore, it should be noted that, although in Figure 1 In this embodiment, antenna beam 181 is shown as comprising a single circular dot beam; however, in other embodiments, antenna beam 181 may comprise more than one such dot beam. Figure 1 The beam shown (e.g., antenna beam 181 may include multiple beams, and antenna beam 181 may include beams with...) Figure 1 The circular dot beam shown is compared to beams of different shapes (e.g., antenna beam 181 may include elliptical beams and / or various different shaped beams).
[0072] It should be noted that in one or more embodiments, the payload antenna 180 may include one or more reflector dishes, including but not limited to parabolic reflectors and / or shaped reflectors. Additionally, the payload antenna 180 may include one or more multi-feed antenna arrays.
[0073] Host / hosting payload 106 transmits unencrypted host telemetry (i.e., telemetry data associated with a portion of host / hosting payload 106 used by a host user) 109 to host communication security module 162. Host communication security module 162 then encrypts the unencrypted host telemetry using a host COMSEC variant (i.e., COMESEC variant 1) to generate encrypted host telemetry. Furthermore, host / hosting payload 106 transmits unencrypted hosting telemetry (i.e., telemetry data associated with a portion of host / hosting payload 106 used by a hosting user) 172 to hosting communication security module 163. Host communication security module 163 then encrypts the unencrypted hosting telemetry using hosting COMSEC variants (i.e., COMSEC variants 2 to COMSEC variant N+1) to generate encrypted hosting telemetry. Therefore, for each hosting user 160, a different hosting COMSEC variant is used to encrypt the unencrypted hosting telemetry associated with that hosting user 160.
[0074] The host communication security module 162 then transmits the encrypted host telemetry 193 to the telemetry transmitter 194. The managed communication security module 163 then transmits the encrypted managed telemetry 192 to the telemetry transmitter 194. The telemetry transmitter 194 then transmits the encrypted host telemetry and encrypted managed telemetry 195 to the telemetry antenna 123. The telemetry antenna 123 then transmits the encrypted host telemetry and encrypted managed telemetry 197 to the SOC antenna 116. The SOC antenna 116 then (via a terrestrial link with an IPSec VPN) transmits the encrypted host telemetry and encrypted managed telemetry 198 to the satellite operations section 151 of the host SOC 150. The satellite operations section 151 then decrypts the encrypted host telemetry using a host COMSEC variant (i.e., COMSEC variant 1) to produce unencrypted host telemetry.
[0075] Satellite operations unit 151 transmits encrypted managed telemetry data 132 to security zone 152 of host SOC 150. Security zone 152 decrypts the encrypted managed telemetry data using managed COMSEC variants (e.g., COMSEC variant 2 to COMSEC variant N+1) to generate unencrypted managed telemetry data. Security zone 152 then transmits the unencrypted managed telemetry data 133 to managed user 160 (via a terrestrial link with IPSec VPN), with the unencrypted telemetry data associated with that managed user 160.
[0076] Figure 2 This is a diagram illustrating a system disclosed according to at least one embodiment of the present disclosure for commercial satellite operations utilizing a security zone for payload operation; wherein (1) the launch vehicle employs a digital host / hosted payload 206, and (2) host commands and host telemetry are transmitted out of band, while hosted commands and hosted telemetry are transmitted in-band. In this figure, launch vehicle 210 and host satellite operations center (SOC) 250 are shown. Various types of launch vehicles can be used for launch vehicle 210, including but not limited to air launch vehicles. Furthermore, various types of air launch vehicles can be used for launch vehicle 210, including but not limited to satellites, aircraft, unmanned aerial vehicles (UAVs), and spaceplanes.
[0077] When using a satellite for launch vehicle 210, it should be noted that the satellite typically includes computer-controlled systems. A satellite typically includes a bus and a payload (e.g., a shared host / hosted payload 206). The bus may include systems (which include components) for controlling the satellite. These systems perform tasks such as power generation and control, thermal control, telemetry, attitude control, orbit control, and other suitable operations.
[0078] The satellite's payload provides functionality to the satellite's users. The payload may include antennas, transponders, and other suitable equipment. For example, a payload in a satellite may be used to provide internet access, telephone communication, radio, television, and / or other types of communication, in relation to communications. Different entities may use different portions of the shared payload 106 on the satellite. For example, a host user (e.g., the satellite owner) may utilize a portion of the host / hosted payload 206, and a host user may lease different portions of the host / hosted payload 206 to hosting users (e.g., customers) for use.
[0079] Leasing a portion of (one or more) payloads (e.g., hosted / managed payload 206) to (one or more) customers (e.g., hosted users) can increase the revenue available to the satellite owner (e.g., the host user). Furthermore, customers can use a subset of the total resources in the satellite at a cost less than the cost of purchasing and operating the satellite, building and operating the satellite, or leasing the entire satellite.
[0080] During operation, managed users 260 (e.g., N managed users 260) (via a terrestrial link with an Internet Protocol Security (IPSec) Virtual Private Network (VPN)) transmit requests 130 to security zone 252 of host satellite operations center (SOC) 250, where each request includes the service specification of the managed user associated with the request. Various types of service specifications that can be transmitted include, but are not limited to, the area of antenna coverage, the effective isotropic radiated power (EIRP) of the antenna coverage, and the time period during which antenna coverage occurs. For example, managed user #1 260 may transmit 230: one or more requests including service specifications for specific areas on Earth to receive antenna coverage (e.g., by specifying the latitude and longitude coordinates, geocentric coordinates, and / or geodetic coordinates of the coverage area), the minimum EIRP level (for those areas where it will be received for antenna coverage), and the time period during which antenna coverage occurs.
[0081] After receiving a request, security zone 252 generates an unencrypted managed command for each request according to the service specification associated with the request. The managed command is a command used to configure each of the host / managed payload 206 components used by managed user 260. Then, security zone 252 encrypts the unencrypted managed command for each request by utilizing the corresponding Managed Communications Security (COMSEC) variant associated with the managed user, to produce an encrypted managed command. Therefore, for each managed user 260, a different managed COMSEC variant will be used to encrypt the managed commands associated with that managed user 260. Subsequently, for N managed users 206, N managed COMSEC variants will be used to encrypt the managed commands. However, it should be noted that for the encryption of managed user commands, COMSEC variants 2 through N+1 will be used. For example, a managed command associated with one or more requests from managed user #1 260 will be encrypted using COMSEC variant 2, a managed command associated with one or more requests from managed user #2 260 will be encrypted using COMSEC variant 3, a managed command associated with one or more requests from managed user #3 260 will be encrypted using COMSEC variant 4, and so on, and a managed command associated with one or more requests from managed user #N 260 will be encrypted using COMSEC variant N+1. It should be noted that each managed COMSEC variant may include at least one encryption key and / or at least one algorithm (e.g., a type 1 encryption algorithm or a type 2 encryption algorithm). The secure zone 252 then transmits the encrypted managed command 231 to the satellite operations section 251 of the host SOC 250.
[0082] The satellite operations section 251 of the host SOC 250 generates unencrypted host commands based on the service specifications of the host user. Host commands are commands used to configure the host / hosted payload 206 used by the host user. Various types of service specifications can be specified by the host user, including but not limited to the area covered by the antenna, the effective isotropic radiated power (EIRP) of the antenna coverage, and the time period during which the antenna coverage occurs. The satellite operations section 251 then encrypts the unencrypted host commands using a host COMSEC variant (e.g., COMSEC variant 1) to produce encrypted host commands. It should be noted that the host COMSEC variant may include at least one encryption key and / or at least one algorithm (e.g., a type 1 encryption algorithm or a type 2 encryption algorithm).
[0083] The satellite operations section 251 of the host SOC 250 then transmits the encrypted host command 215 to the ground SOC antenna 216 (via a terrestrial link with an IPSec VPN). The SOC antenna 216 then transmits the encrypted host command 220 to the command antenna 221 on the launch vehicle 210. The SOC antenna 216 utilizes one or more out-of-band frequencies (i.e., one or more frequency bands different from those used for transmitting payload data) to transmit the encrypted host command 220. The command antenna 221 on the launch vehicle 210 then transmits the encrypted host command 222 to the command receiver 235.
[0084] Command receiver 235 then transmits the encrypted host command 253 to host communication security module 262. Host communication security module 262 uses a host COMSEC variant (e.g., COMSEC variant 1) to decrypt the encrypted host command to generate an unencrypted host command.
[0085] It should be noted that the host communication security module 262 may include one or more communication security modules (e.g., communication security module 1 and communication security module 2, wherein communication security module 2 is a redundant communication security module used in the event of a failure of communication security module 1), wherein the additional communication security module is a redundant communication security module used in the event of a failure of a communication security module. Additionally, the host communication security module 262 may include one or more processors.
[0086] The satellite operations section 251 of the host SOC 250 also transmits encrypted managed commands 234 to the ground host gateway antenna 227. The host gateway antenna 227 then transmits the encrypted managed commands 235 to the payload antenna 280 on the launch vehicle 210. The host gateway antenna 227 utilizes one or more in-band frequencies (i.e., the same one or more frequency bands used for transmitting payload data) to transmit the encrypted managed commands 235. The payload antenna 280 on the launch vehicle 210 then transmits the encrypted managed commands to the host / managed payload 206. The host / managed payload 206 transmits the encrypted managed commands 236 to the managed communications security module 263. The managed communications security module 263 decrypts the encrypted managed commands using managed COMSEC variants (e.g., COMSEC variant 2 to COMSEC variant N+1) to generate unencrypted managed commands.
[0087] It should be noted that each of the managed communication security modules 263 may include one or more communication security modules (e.g., communication security module 1 and communication security module 2, wherein communication security module 2 is a redundant communication security module used in the event of a failure of communication security module 1), wherein the additional communication security module is a redundant communication security module used in the event of a failure of a communication security module. Additionally, each of the host communication security modules 263 may include one or more processors.
[0088] The host communication security module 262 then transmits unencrypted host commands 270 to the host / hosted payload 206. Furthermore, the hosted communication security module 263 then transmits unencrypted hosted commands 271 to the host / hosted payload 206. The host / hosted payload 206 is reconfigured based on the unencrypted host commands and the unencrypted hosted commands. The reconfiguration of the host / hosted payload 206 may include adjusting at least one of the following: transponder power, transponder spectrum monitoring, transponder connectivity, transponder gain settings, transponder limiter settings, transponder automatic level control settings, transponder phase settings, internal gain generation, bandwidth of at least one beam, at least one frequency band of at least one beam, transponder beamforming settings, effective isotropic radiated power (EIRP) of at least one beam, and transponder channel or beam steering. Additionally, reconfiguration of the host / hosted payload 206 may include reconfiguring at least one of the following: payload antenna 280, at least one analog-to-digital converter, at least one digital-to-analog converter, at least one beamformer, at least one digital channelizer, at least one demodulator, at least one modulator, at least one digital switch matrix, at least one digital combiner, or at least one analog switch matrix. In one or more embodiments, the host / hosted payload includes 106 one or more processors.
[0089] After reconfiguring the host / hosted payload 206, the payload antenna 280 then transmits host user data (e.g., in one or more antenna beams 281) to the ground-based host user antenna 285 and transmits hosted user data to the ground-based hosted user antenna 290. It should be noted that in other embodiments, the host user antenna 285 and / or the hosted user antenna 290 may be in the air (e.g., located on an aircraft or satellite) or at sea (e.g., located on a ship) instead of... Figure 2 As shown on the ground (e.g., located on the ground).
[0090] Furthermore, it should be noted that, although in Figure 2 In this embodiment, antenna beam 281 is shown as comprising a single circular dot beam; however, in other embodiments, antenna beam 281 may comprise more than one such dot beam. Figure 2The beam shown (e.g., antenna beam 281 may include multiple beams, and antenna beam 281 may include beams with...) Figure 2 The circular dot beam shown is compared to beams of different shapes (e.g., antenna beam 281 may include elliptical beams and / or various different shaped beams).
[0091] It should be noted that in one or more embodiments, the payload antenna 280 may include one or more dish reflectors, including but not limited to parabolic reflectors and / or shaped reflectors. Additionally, the payload antenna 280 may include one or more multi-feed antenna arrays.
[0092] Host / hosting payload 206 transmits unencrypted host telemetry (i.e., telemetry data associated with a portion of host / hosting payload 206 used by the host user) 209 to host communication security module 262. Host communication security module 262 then encrypts the unencrypted host telemetry using a host COMSEC variant (i.e., COMESEC variant 1) to generate encrypted host telemetry. Furthermore, host / hosting payload 206 transmits unencrypted hosting telemetry (i.e., telemetry data associated with a portion of host / hosting payload 206 used by the hosting user) 272 to hosting communication security module 263. Host communication security module 263 then encrypts the unencrypted hosting telemetry using hosting COMSEC variants (i.e., COMSEC variant 2 to COMSEC variant N+1) to generate encrypted hosting telemetry. Therefore, for each hosting user 260, a different hosting COMSEC variant is used to encrypt the unencrypted hosting telemetry associated with that hosting user 260.
[0093] The host communication security module 262 then transmits the encrypted host telemetry 293 to the telemetry transmitter 294. The telemetry transmitter 294 then transmits the encrypted host telemetry 295 to the telemetry antenna 223. The telemetry antenna 223 then transmits the encrypted host telemetry 297 to the SOC antenna 216. The SOC antenna 216 then (via a terrestrial link with IPSec VPN) transmits the encrypted host telemetry 298 to the satellite operations section 251 of the host SOC 250. The satellite operations section 251 then decrypts the encrypted host telemetry using a host COMSEC variant (i.e., COMSEC variant 1) to produce unencrypted host telemetry.
[0094] The managed communications security module 263 also transmits encrypted managed telemetry 237 to the host / managed payload 206. The host / managed payload 206 then transmits the encrypted managed telemetry to the payload antenna 280. The payload antenna 280 then transmits the encrypted managed telemetry 238 to the host gateway antenna 227. The host gateway antenna 227 then (via a terrestrial link with IPSec VPN) transmits the encrypted managed telemetry 239 to the satellite operations section 251 of the host SOC 250.
[0095] Satellite operations section 251 transmits encrypted managed telemetry data 232 to security zone 252 of host SOC 250. Security zone 252 decrypts the encrypted managed telemetry data using managed COMSEC variants (e.g., COMSEC variant 2 to COMSEC variant N+1) to generate unencrypted managed telemetry data. Security zone 252 then transmits the unencrypted managed telemetry data 233 to managed user 260 (via a terrestrial link with IPSec VPN), with the unencrypted telemetry data associated with that managed user 260.
[0096] Figure 3A and Figure 3B Together illustrating the disclosed method for utilizing at least one embodiment of the present disclosure. Figure 1 and Figure 2 The flowchart illustrates a method for commercial satellite operations performed by the security zone of the system's payload operation. At the beginning of the method 300, the security zone of the host satellite operations center (SOC) receives at least one request from at least one managed user, each request including a service specification 305 associated with the managed user. The security zone then generates an unencrypted managed command 310 for each request based on the service specification. The security zone then encrypts the unencrypted managed command for each request by utilizing a corresponding Managed Communications Security (COMSEC) variant associated with the managed user, producing an encrypted managed command 315. The SOC operations portion of the host SOC generates an unencrypted host command 320 based on the host user's service specification. The SOC operations portion then encrypts the unencrypted host command by utilizing a host COMSEC variant, producing an encrypted host command 325. The host SOC then transmits the encrypted host command and the encrypted managed command to the carrier 330.
[0097] Then, the host communication security module on the carrier decrypts the encrypted host command using a host COMSEC variant to generate an unencrypted host command 335. For each managed user, the corresponding managed communication security module on the carrier decrypts the encrypted managed command for each managed user using the corresponding managed COMSEC variant to generate an unencrypted managed command 340. Based on the unencrypted host command and the unencrypted managed command, the host / managed payload on the carrier is reconfigured 345. The payload antenna on the carrier then transmits host user data to the host user antenna and managed user data to the managed user antenna 350. The host / managed payload then generates unencrypted host telemetry and unencrypted managed telemetry 355. The host communication security module then encrypts the unencrypted host telemetry using a host COMSEC variant to generate encrypted host telemetry 360. For each of the managed users, the corresponding managed communications security module then encrypts the unencrypted managed telemetry for each managed user by utilizing the corresponding managed COMSEC variant, to produce encrypted managed telemetry 365. The carrier then transmits the encrypted host telemetry and the encrypted managed telemetry to the host SOC 370.
[0098] The SOC operations section then decrypts the encrypted host telemetry using a host COMSEC variant to produce unencrypted host telemetry 375. The secure zone then decrypts the encrypted managed telemetry for each managed user using the appropriate managed COMSEC variant to produce unencrypted managed telemetry for each managed user 380. The method then ends 385.
[0099] Figures 4-7C Systems, methods, and apparatus for commercial satellite operations utilizing a security zone for payload operations are disclosed, employing a launch vehicle having a main payload and at least one separately hosted payload.
[0100] Figure 4 This is a diagram illustrating a system disclosed according to at least one embodiment of the present disclosure for commercial satellite operations using a secure zone for payload operations; wherein (1) the launch vehicle employs a digital host payload 406 and at least one analog managed payload 407, and (2) host commands, managed commands, host telemetry, and managed telemetry are all transmitted out of band. In this figure, launch vehicle 410 and host satellite operations center (SOC) 450 are shown. Various types of launch vehicles can be used for launch vehicle 410, including but not limited to air launch vehicles. Furthermore, various types of air launch vehicles can be used for launch vehicle 410, including but not limited to satellites, aircraft, unmanned aerial vehicles (UAVs), and spaceplanes.
[0101] When a satellite is used for launch vehicle 410, it should be noted that the satellite typically includes computer-controlled systems. A satellite typically includes a bus and (one or more) payloads (e.g., a main payload 406 and / or (one or more) managed payloads 407). The bus may include systems (which include components) for controlling the satellite. These systems perform tasks such as power generation and control, thermal control, telemetry, attitude control, orbit control, and other suitable operations.
[0102] The satellite's payload provides functionality to the satellite's users. The payload may include antennas, transponders, and other suitable equipment. For example, a payload in a satellite may be used to provide internet access, telephone communication, radio, television, and / or other types of communication, in relation to communications. Different entities may use different payloads on the satellite (i.e., host payload 406 and (one or more) managed payloads 407). For example, a host user (e.g., the satellite owner) may utilize host payload 406, and a host user may lease at least one managed payload 407 to managed users (e.g., customers) for use.
[0103] Leasing (one or more) payloads (e.g., (one or more) managed payloads 407) to (one or more) customers (e.g., (one or more) managed users) can increase the revenue available to the satellite owner (e.g., the host user). Furthermore, customers can use a subset of the total resources in the satellite at a cost less than the cost of purchasing and operating the satellite, building and operating the satellite, or leasing the entire satellite.
[0104] During operation, managed users 460 (e.g., N managed users 460) (via a terrestrial link with an Internet Protocol Security (IPSec) Virtual Private Network (VPN)) transmit requests 430 to security zone 452 of host satellite operations center (SOC) 450, where each request includes the service specification of the managed user associated with the request. Various types of service specifications that can be transmitted include, but are not limited to, the area of antenna coverage, the effective isotropic radiated power (EIRP) of the antenna coverage, and the time period during which antenna coverage occurs. For example, managed user #1 460 may transmit 430: one or more requests including service specifications for a specific area on Earth to receive antenna coverage (e.g., by specifying the latitude and longitude coordinates, geocentric coordinates, and / or geodetic coordinates of the coverage area), the minimum EIRP level (of which it will be received for antenna coverage), and the time period during which antenna coverage occurs.
[0105] After receiving a request, security zone 452 generates an unencrypted managed command for each request according to the service specification associated with the request. The managed command is a command used to configure one or more managed payloads 407 used by managed user 460. Security zone 452 then encrypts the unencrypted managed command for each request by utilizing the corresponding Managed Communications Security (COMSEC) variant associated with the managed user, to produce an encrypted managed command. Therefore, for each managed user 460, a different managed COMSEC variant will be used to encrypt the managed command associated with that managed user 460. Then, for N managed users 406, N managed COMSEC variants will be used to encrypt the managed commands. However, it should be noted that for the encryption of managed user commands, COMSEC variants 2 to COMSEC variant N+1 will be used. For example, a managed command associated with one or more requests from managed user #1 460 will be encrypted using COMSEC variant 2, a managed command associated with one or more requests from managed user #2 460 will be encrypted using COMSEC variant 3, a managed command associated with one or more requests from managed user #3 460 will be encrypted using COMSEC variant 4, and so on, and a managed command associated with one or more requests from managed user #N 460 will be encrypted using COMSEC variant N+1. It should be noted that each managed COMSEC variant may include at least one encryption key and / or at least one algorithm (e.g., a type 1 encryption algorithm or a type 2 encryption algorithm). The secure zone 452 then transmits the encrypted managed command 431 to the satellite operations section 451 of the host SOC 450.
[0106] The satellite operations section 451 of the host SOC 450 generates unencrypted host commands based on the service specifications of the host user. These host commands are used to configure the host payload 406 used by the host user. Various types of service specifications can be specified by the host user, including but not limited to the area covered by the antenna, the effective isotropic radiated power (EIRP) of the antenna coverage, and the time period during which the antenna coverage occurs. The satellite operations section 451 then encrypts the unencrypted host commands using a host COMSEC variant (e.g., COMSEC variant 1) to produce encrypted host commands. It should be noted that the host COMSEC variant may include at least one encryption key and / or at least one algorithm (e.g., a type 1 encryption algorithm or a type 2 encryption algorithm).
[0107] The satellite operations section 451 of the host SOC 450 then transmits encrypted host commands and encrypted managed commands 415 to the ground SOC antenna 416 (via a terrestrial link with an IPSec VPN). The SOC antenna 416 then transmits the encrypted host commands and encrypted managed commands 420 to the command antenna 421 on the launch vehicle 410. The SOC antenna 416 utilizes one or more out-of-band frequencies (i.e., one or more frequency bands different from those used for transmitting payload data) to transmit the encrypted host commands and encrypted managed commands 420. The command antenna 421 on the launch vehicle 410 then transmits the encrypted host commands 422 to the command receiver 435.
[0108] Command receiver 435 then transmits the encrypted host command 454 to host communication security module 462. Host communication security module 462 uses a host COMSEC variant (e.g., COMSEC variant 1) to decrypt the encrypted host command to generate an unencrypted host command.
[0109] It should be noted that the host communication security module 462 may include one or more communication security modules (e.g., communication security module 1 and communication security module 2, wherein communication security module 2 is a redundant communication security module used in the event of a failure of communication security module 1), wherein the additional communication security module is a redundant communication security module used in the event of a failure of a communication security module. Additionally, the host communication security module 462 may include one or more processors.
[0110] Command receiver 435 also transmits encrypted managed commands 453 to managed communication security module 463. Managed communication security module 463 decrypts the encrypted managed commands using managed COMSEC variants (e.g., COMSEC variant 2 to COMSEC variant N+1) to generate unencrypted managed commands.
[0111] It should be noted that each of the managed communication security modules 463 may include one or more communication security modules (e.g., communication security module 1 and communication security module 2, wherein communication security module 2 is a redundant communication security module used in the event of a failure of communication security module 1), wherein the additional communication security module is a redundant communication security module used in the event of a failure of a communication security module. Additionally, each of the host communication security modules 463 may include one or more processors.
[0112] The host communication security module 462 then transmits unencrypted host commands 470 to the host payload 406 and transmits on / off commands 464 to at least one managed payload 407. Furthermore, the managed communication security module 463 transmits unencrypted managed commands 471 to (one or more) managed payloads 407.
[0113] Reconfigure the host payload 406 according to the unencrypted host command. Command (one or more) managed payloads 407 according to the on / off command. Note that (one or more) managed payloads 407 can be commanded to be turned off later according to another on / off command. After (one or more) managed payloads 407 are commanded to be turned on, reconfigure (one or more) managed payloads 407 according to the unencrypted managed command.
[0114] Reconfiguration of the host payload 406 and / or (one or more) managed payloads 407 may include adjusting at least one of the following: transponder power, transponder spectrum monitoring, transponder connectivity, transponder gain settings, transponder limiter settings, transponder automatic level control settings, transponder phase settings, internal gain generation, bandwidth of at least one beam, at least one frequency band of at least one beam, transponder beamforming settings, effective isotropic radiated power (EIRP) of at least one beam, transponder channel, or beam steering. Additionally, reconfiguration of the host payload 406 and / or (one or more) managed payloads 407 may include reconfiguring at least one of the following: host payload antenna 480, managed payload antenna 482, at least one analog-to-digital converter, at least one digital-to-analog converter, at least one beamformer, at least one digital channelizer, at least one demodulator, at least one modulator, at least one digital switch matrix, at least one digital combiner, or at least one analog switch matrix. In one or more embodiments, the host payload 406 and / or (one or more) managed payloads 407 include one or more processors.
[0115] After reconfiguring the host payload 406, the host payload antenna 180 then transmits host user data (e.g., in one or more antenna beams 181) to the host user antenna 485 on the ground. And, after reconfiguring (one or more) the managed payload 407 (e.g., the managed payload antenna 482 is rotated or oriented to radiate to a specific area on Earth), the managed payload antenna 482 transmits managed user data (e.g., in one or more antenna beams 408) to the managed user antenna 490 on the ground. It should be noted that in other embodiments, the host user antenna 485 and / or the managed user antenna 490 may be in the air (e.g., located on an aircraft or satellite) or at sea (e.g., located on a ship) instead of... Figure 4 As shown on the ground (e.g., located on the ground).
[0116] Furthermore, it should be noted that, although in Figure 4 In this embodiment, antenna beam 481 and antenna beam 408 are each shown as comprising a single circular dot beam; however, in other embodiments, antenna beam 481 and antenna beam 408 may each comprise more than one circular dot beam. Figure 4 The beams shown (e.g., antenna beam 481 and / or antenna beam 408 may each include multiple beams, and antenna beam 481 and / or antenna beam 408 may each include beams related to...) Figure 4 The circular dot beam shown is different from beams of different shapes (e.g., antenna beam 481 and / or antenna beam 408 may each include elliptical beams and / or various different shaped beams).
[0117] It should be noted that in one or more embodiments, the host payload antenna 480 and / or the managed payload antenna 482 may each include one or more dish reflectors, including but not limited to parabolic reflectors and / or shaped reflectors. Additionally, the host payload antenna 480 and / or the managed payload antenna 482 may each include one or more multi-feed antenna arrays.
[0118] Host payload 406 transmits unencrypted host telemetry (i.e., telemetry data associated with host payload 406 used by the host user) 409 to host communication security module 462. Host communication security module 462 then encrypts the unencrypted host telemetry using a host COMSEC variant (i.e., COMESEC variant 1) to generate encrypted host telemetry.
[0119] Furthermore, (one or more) managed payloads 407 transmit unencrypted managed telemetry (i.e., telemetry data associated with (one or more) managed payloads 407 used by (one or more) managed users) 472 to the managed communications security module 463. The managed communications security module 463 then encrypts the unencrypted managed telemetry using managed COMSEC variants (i.e., COMSEC variant 2 to COMSEC variant N+1) to generate encrypted managed telemetry. Therefore, for each managed user 460, a different managed COMSEC variant will be used to encrypt the unencrypted managed telemetry associated with that managed user 460.
[0120] The host communication security module 462 then transmits the encrypted host telemetry 493 to the telemetry transmitter 494. The managed communication security module 463 then transmits the encrypted managed telemetry 492 to the telemetry transmitter 494. The telemetry transmitter 494 then transmits the encrypted host telemetry and encrypted managed telemetry 495 to the telemetry antenna 423. The telemetry antenna 423 then transmits the encrypted host telemetry and encrypted managed telemetry 497 to the SOC antenna 416. The SOC antenna 416 then (via a terrestrial link with an IPSec VPN) transmits the encrypted host telemetry and encrypted managed telemetry 498 to the satellite operations section 451 of the host SOC 450. The satellite operations section 451 then decrypts the encrypted host telemetry using a host COMSEC variant (i.e., COMSEC variant 1) to produce unencrypted host telemetry.
[0121] Satellite operations section 451 transmits encrypted managed telemetry data 432 to security zone 452 of host SOC 450. Security zone 452 decrypts the encrypted managed telemetry data using managed COMSEC variants (e.g., COMSEC variant 2 to COMSEC variant N+1) to generate unencrypted managed telemetry data. Security zone 452 then transmits the unencrypted managed telemetry data 433 to managed user 460 (via a terrestrial link with IPSec VPN), with the unencrypted telemetry data associated with managed user 460.
[0122] Figure 5This is a diagram illustrating a system disclosed according to at least one embodiment of the present disclosure for commercial satellite operations using a security zone for payload operations; wherein (1) the launch vehicle employs a digital host payload 506 and at least one analog managed payload 507, and (2) managed commands and managed telemetry are transmitted out of band, while host commands and host telemetry are transmitted in-band. In this figure, launch vehicle 510 and host satellite operations center (SOC) 550 are shown. Various types of launch vehicles can be used for launch vehicle 510, including but not limited to air launch vehicles. Furthermore, various types of air launch vehicles can be used for launch vehicle 510, including but not limited to satellites, aircraft, unmanned aerial vehicles (UAVs), and spaceplanes.
[0123] When using a satellite for launch vehicle 510, it should be noted that the satellite typically includes computer-controlled systems. The satellite typically includes a bus and (one or more) payloads (e.g., a main payload 506 and / or (one or more) managed payloads 507). The bus may include systems (which include components) for controlling the satellite. These systems perform tasks such as power generation and control, thermal control, telemetry, attitude control, orbit control, and other suitable operations.
[0124] The satellite's payload provides functionality to the satellite's users. The payload may include antennas, transponders, and other suitable equipment. For example, a payload in a satellite may be used to provide internet access, telephone communication, radio, television, and / or other types of communication, in relation to communications. Different entities may use different payloads on the satellite (i.e., host payload 506 and (one or more) managed payloads 507). For example, a host user (e.g., the satellite owner) may utilize host payload 506, and a host user may lease at least one managed payload 507 to managed users (e.g., customers) for use.
[0125] Leasing (one or more) payloads (e.g., (one or more) managed payloads 507) to (one or more) customers (e.g., (one or more) managed users) can increase the revenue available to the satellite owner (e.g., the host user). Furthermore, customers can use a subset of the total resources in the satellite at a cost less than the cost of purchasing and operating the satellite, building and operating the satellite, or leasing the entire satellite.
[0126] During operation, managed users 560 (e.g., N managed users 560) (via a terrestrial link with an Internet Protocol Security (IPSec) Virtual Private Network (VPN)) transmit requests 530 to security zone 552 of the Host Satellite Operations Center (SOC) 550, where each request includes the service specification of the managed user associated with the request. Various types of service specifications that can be transmitted include, but are not limited to, the area of antenna coverage, the effective isotropic radiated power (EIRP) of the antenna coverage, and the time period during which antenna coverage occurs. For example, managed user #1 560 may transmit 530: one or more requests including service specifications for a specific area on Earth to receive antenna coverage (e.g., by specifying the latitude and longitude coordinates, geocentric coordinates, and / or geodetic coordinates of the coverage area), the minimum EIRP level (of which it will be received for antenna coverage), and the time period during which antenna coverage occurs.
[0127] After receiving a request, security zone 552 generates an unencrypted managed command for each request according to the service specification associated with the request. The managed command is a command used to configure one or more managed payloads 507 used by managed user 560. Security zone 552 then encrypts the unencrypted managed command for each request by utilizing the corresponding Managed Communications Security (COMSEC) variant associated with the managed user, to produce an encrypted managed command. Therefore, for each managed user 560, a different managed COMSEC variant will be used to encrypt the managed command associated with that managed user 560. Then, for N managed users 506, N managed COMSEC variants will be used to encrypt the managed commands. However, it should be noted that for the encryption of managed user commands, COMSEC variants 2 to COMSEC variant N+1 will be used. For example, a managed command associated with one or more requests from managed user #1 560 will be encrypted using COMSEC variant 2, a managed command associated with one or more requests from managed user #2 560 will be encrypted using COMSEC variant 3, a managed command associated with one or more requests from managed user #3 560 will be encrypted using COMSEC variant 4, and so on, and a managed command associated with one or more requests from managed user #N 560 will be encrypted using COMSEC variant N+1. It should be noted that each managed COMSEC variant may include at least one encryption key and / or at least one algorithm (e.g., a type 1 encryption algorithm or a type 2 encryption algorithm). The secure area 552 then transmits the encrypted managed command 531 to the satellite operations section 551 of the host SOC 550.
[0128] The satellite operations section 551 of the host SOC 550 generates unencrypted host commands based on the service specifications of the host user. These host commands are used to configure the host payload 506 used by the host user. Various types of service specifications can be specified by the host user, including but not limited to the area covered by the antenna, the effective isotropic radiated power (EIRP) of the antenna coverage, and the time period during which the antenna coverage occurs. The satellite operations section 551 then encrypts the unencrypted host commands using a host COMSEC variant (e.g., COMSEC variant 1) to produce encrypted host commands. It should be noted that the host COMSEC variant may include at least one encryption key and / or at least one algorithm (e.g., a type 1 encryption algorithm or a type 2 encryption algorithm).
[0129] The satellite operations section 551 of the host SOC 550 then transmits the encrypted managed command 515 to the ground SOC antenna 516 (via a terrestrial link with an IPSec VPN). The SOC antenna 516 then transmits the encrypted managed command 520 to the command antenna 521 on the launch vehicle 510. The SOC antenna 516 utilizes one or more out-of-band frequencies (i.e., one or more frequency bands different from those used for transmitting payload data) to transmit the encrypted managed command 520. The command antenna 521 on the launch vehicle 510 then transmits the encrypted managed command 522 to the command receiver 535.
[0130] Command receiver 535 then transmits the encrypted managed command 553 to managed communication security module 563. Managed communication security module 563 decrypts the encrypted managed command using managed COMSEC variants (e.g., COMSEC variant 2 to COMSEC variant N+1) to generate an unencrypted managed command.
[0131] It should be noted that each of the managed communication security modules 563 may include one or more communication security modules (e.g., communication security module 1 and communication security module 2, wherein communication security module 2 is a redundant communication security module used in the event of a failure of communication security module 1), wherein the additional communication security module is a redundant communication security module used in the event of a failure of a communication security module. Additionally, each of the host communication security modules 563 may include one or more processors.
[0132] The satellite operations section 551 of the host SOC 550 also transmits encrypted host commands 534 to the ground host gateway antenna 527. The host gateway antenna 527 then transmits the encrypted host commands 535 to the host payload antenna 580 on the launch vehicle 510. The host gateway antenna 527 uses one or more in-band frequencies (i.e., the same one or more frequency bands used for transmitting payload data) to transmit the encrypted managed commands 535. The host payload antenna 580 on the launch vehicle 510 then transmits the encrypted host commands to the host payload 506. The host payload 506 transmits the encrypted host commands 554 to the host communications security module 562. The host communications security module 562 decrypts the encrypted host commands using a host COMSEC variant (e.g., COMSEC variant 1) to generate unencrypted host commands.
[0133] It should be noted that the host communication security module 562 may include one or more communication security modules (e.g., communication security module 1 and communication security module 2, wherein communication security module 2 is a redundant communication security module used in the event of a failure of communication security module 1), wherein the additional communication security module is a redundant communication security module used in the event of a failure of a communication security module. Additionally, the host communication security module 562 may include one or more processors.
[0134] The host communication security module 562 then transmits unencrypted host commands 570 to the host payload 506 and transmits on / off commands 564 to at least one managed payload 507. Furthermore, the managed communication security module 563 then transmits unencrypted managed commands 571 to (one or more) managed payloads 507.
[0135] Reconfigure the host payload 506 according to the unencrypted host command. Command (one or more) managed payloads 507 according to the on / off command. Note that (one or more) managed payloads 507 can be commanded to be turned off later according to another on / off command. After (one or more) managed payloads 507 are commanded to be turned on, reconfigure (one or more) managed payloads 507 according to the unencrypted managed command.
[0136] Reconfiguration of the host payload 506 and / or (one or more) managed payloads 507 may include adjusting at least one of the following: transponder power, transponder spectrum monitoring, transponder connectivity, transponder gain settings, transponder limiter settings, transponder automatic level control settings, transponder phase settings, internal gain generation, bandwidth of at least one beam, at least one frequency band of at least one beam, transponder beamforming settings, effective isotropic radiated power (EIRP) of at least one beam, transponder channel or beam steering. Additionally, reconfiguration of the host payload 506 and / or (one or more) managed payloads 507 may include reconfiguring at least one of the following: host payload antenna 580, managed payload antenna 582 (e.g., by antenna steering), at least one analog-to-digital converter, at least one digital-to-analog converter, at least one beamformer, at least one digital channelizer, at least one demodulator, at least one modulator, at least one digital switch matrix, at least one digital combiner, or at least one analog switch matrix. In one or more embodiments, the host payload 506 and / or (one or more) managed payloads 507 include one or more processors.
[0137] After reconfiguring the host payload 506, the host payload antenna 580 then transmits host user data (e.g., in one or more antenna beams 581) to the host user antenna 585 on the ground. And, after reconfiguring (one or more) the managed payload 507 (e.g., the managed payload antenna 582 is rotated or turned to radiate to a designated area on Earth), the managed payload antenna 582 transmits managed user data (e.g., in one or more antenna beams 508) to the managed user antenna 590 on the ground. It should be noted that in other embodiments, the host user antenna 585 and / or the managed user antenna 590 may be in the air (e.g., located on an aircraft or satellite) or at sea (e.g., located on a ship) instead of... Figure 5 As shown on the ground (e.g., located on the ground).
[0138] Furthermore, it should be noted that, although in Figure 5 In this embodiment, antenna beam 581 and antenna beam 508 are each shown as comprising a single circular dot beam; however, in other embodiments, antenna beam 581 and antenna beam 508 may each comprise more than one circular dot beam. Figure 5 The beams shown (e.g., antenna beam 581 and / or antenna beam 508 may each include multiple beams, and antenna beam 581 and / or antenna beam 508 may each include beams related to...) Figure 5The circular dot beam shown is different from beams of different shapes (e.g., antenna beam 581 and / or antenna beam 508 may each include elliptical beams and / or various different shaped beams).
[0139] It should be noted that in one or more embodiments, the host payload antenna 580 and / or the managed payload antenna 582 may each include one or more dish reflectors, including but not limited to parabolic reflectors and / or shaped reflectors. Additionally, the host payload antenna 580 and / or the managed payload antenna 582 may each include one or more multi-feed antenna arrays.
[0140] Host payload 506 transmits unencrypted host telemetry (i.e., telemetry data associated with host payload 506 used by the host user) 509 to host communication security module 562. Host communication security module 562 then encrypts the unencrypted host telemetry using a host COMSEC variant (i.e., COMESEC variant 1) to generate encrypted host telemetry.
[0141] Furthermore, one or more managed payloads 507 transmit unencrypted managed telemetry (i.e., telemetry data associated with one or more managed payloads 507 used by one or more managed users) 572 to the managed communications security module 563. The managed communications security module 563 then encrypts the unencrypted managed telemetry using managed COMSEC variants (i.e., COMSEC variant 2 to COMSEC variant N+1) to generate encrypted managed telemetry. Thus, for each managed user 560, a different managed COMSEC variant will be used to encrypt the unencrypted managed telemetry associated with that managed user 560.
[0142] The managed communications security module 563 then transmits the encrypted managed telemetry data 593 to the telemetry transmitter 594. The telemetry transmitter 594 then transmits the encrypted managed telemetry data 595 to the telemetry antenna 523. The telemetry antenna 523 then transmits the encrypted managed telemetry data 597 to the SOC antenna 516. The SOC antenna 516 then (via a terrestrial link with an IPSec VPN) transmits the encrypted managed telemetry data 598 to the satellite operations section 551 of the host SOC 550.
[0143] The satellite operations section 551 transmits encrypted managed telemetry data 532 to the security zone 552 of the host SOC 550. The security zone 552 decrypts the encrypted managed telemetry data using managed COMSEC variants (e.g., COMSEC variant 2 to COMSEC variant N+1) to generate unencrypted managed telemetry data. The security zone 552 then (via a terrestrial link with an IPSec VPN) transmits the unencrypted managed telemetry data 533 to managed user 560, with the unencrypted telemetry data associated with managed user 560.
[0144] The host communication security module 562 also transmits encrypted host telemetry 596 to the host payload 506. The host payload 506 then transmits the encrypted host telemetry to the host payload antenna 580. The host payload antenna 580 then transmits the encrypted host telemetry 538 to the host gateway antenna 527. The host gateway antenna 527 then (via a terrestrial link with IPSec VPN) transmits the encrypted host telemetry 539 to the satellite operations section 551 of the host SOC 550. The satellite operations section 551 then decrypts the encrypted host telemetry using a host COMSEC variant (i.e., COMSEC variant 1) to generate unencrypted host telemetry.
[0145] Figure 6 This is a diagram illustrating a system disclosed according to at least one embodiment of the present disclosure for commercial satellite operations utilizing a security zone for payload operation; wherein (1) the launch vehicle employs an analog host payload 606 and at least one digital managed payload 607, and (2) host commands and host telemetry are transmitted out of band, and managed commands and managed telemetry are transmitted in-band. In this figure, launch vehicle 610 and host satellite operations center (SOC) 650 are shown. Various types of launch vehicles can be used for launch vehicle 610, including but not limited to air launch vehicles. Furthermore, various types of air launch vehicles can be used for launch vehicle 610, including but not limited to satellites, aircraft, unmanned aerial vehicles (UAVs), and spaceplanes.
[0146] When using a satellite for launch vehicle 610, it should be noted that the satellite typically includes computer-controlled systems. A satellite typically includes a bus and (one or more) payloads (e.g., a main payload 606 and / or (one or more) managed payloads 607). The bus may include systems (which include components) for controlling the satellite. These systems perform tasks such as power generation and control, thermal control, telemetry, attitude control, orbit control, and other suitable operations.
[0147] The satellite's payload provides functionality to the satellite's users. The payload may include antennas, transponders, and other suitable equipment. For example, a payload in a satellite may be used to provide internet access, telephone communication, radio, television, and / or other types of communication, in relation to communications. Different entities may use different payloads on the satellite (i.e., host payload 606 and (one or more) managed payloads 607). For example, a host user (e.g., the satellite owner) may utilize host payload 606, and a host user may lease at least one managed payload 607 to managed users (e.g., customers) for use.
[0148] Leasing (one or more) payloads (e.g., (one or more) managed payloads 607) to (one or more) customers (e.g., (one or more) managed users) can increase the revenue available to the satellite owner (e.g., the host user). Furthermore, customers can use a subset of the total resources in the satellite at a cost less than the cost of purchasing and operating the satellite, building and operating the satellite, or leasing the entire satellite.
[0149] During operation, managed users 660 (e.g., N managed users 660) (via a terrestrial link with an Internet Protocol Security (IPSec) Virtual Private Network (VPN)) transmit request 630 to security zone 652 of host satellite operations center (SOC) 650, where each request includes the service specification of the managed user associated with the request. Various types of service specifications that can be transmitted include, but are not limited to, the area of antenna coverage, the effective isotropic radiated power (EIRP) of the antenna coverage, and the time period during which antenna coverage occurs. For example, managed user #1 660 may transmit 630: one or more requests including service specifications for a specific area on Earth to receive antenna coverage (e.g., by specifying the latitude and longitude coordinates, geocentric coordinates, and / or geodetic coordinates of the coverage area), the minimum EIRP level (of which it will be received for antenna coverage), and the time period during which antenna coverage occurs.
[0150] After receiving a request, security zone 652 generates an unencrypted managed command for each request according to the service specification associated with the request. The managed command is a command used to configure one or more managed payloads 607 used by managed user 560. Security zone 652 then encrypts the unencrypted managed command for each request by utilizing the corresponding Managed Communications Security (COMSEC) variant for the managed user associated with the request, to produce an encrypted managed command. Therefore, for each managed user 660, a different managed COMSEC variant will be used to encrypt the managed command associated with that managed user 660. Then, for N managed users 606, N managed COMSEC variants will be used to encrypt the managed commands. However, it should be noted that for the encryption of managed user commands, COMSEC variants 2 to COMSEC variant N+1 will be used. For example, a managed command associated with one or more requests from managed user #1 660 will be encrypted using COMSEC variant 2, a managed command associated with one or more requests from managed user #2 660 will be encrypted using COMSEC variant 3, a managed command associated with one or more requests from managed user #3 660 will be encrypted using COMSEC variant 4, and so on, and a managed command associated with one or more requests from managed user #N 660 will be encrypted using COMSEC variant N+1. It should be noted that each managed COMSEC variant may include at least one encryption key and / or at least one algorithm (e.g., a type 1 encryption algorithm or a type 2 encryption algorithm). The secure area 652 then transmits the encrypted managed command 631 to the satellite operations section 651 of the host SOC 650.
[0151] The satellite operations section 651 of the host SOC 650 generates unencrypted host commands based on the service specifications of the host user. These host commands are used to configure the host payload 606 used by the host user. Various types of service specifications can be specified by the host user, including but not limited to the area covered by the antenna, the effective isotropic radiated power (EIRP) of the antenna coverage, and the time period during which the antenna coverage occurs. The satellite operations section 651 then encrypts the unencrypted host commands using a host COMSEC variant (e.g., COMSEC variant 1) to produce encrypted host commands. It should be noted that the host COMSEC variant may include at least one encryption key and / or at least one algorithm (e.g., a type 1 encryption algorithm or a type 2 encryption algorithm).
[0152] The satellite operations section 651 of the host SOC 650 then transmits the encrypted host command 615 to the ground SOC antenna 616 (via a terrestrial link with an IPSec VPN). The SOC antenna 616 then transmits the encrypted host command 620 to the command antenna 621 on the launch vehicle 610. The SOC antenna 616 utilizes one or more out-of-band frequencies (i.e., one or more frequency bands different from those used for transmitting payload data) to transmit the encrypted host command 620. The command antenna 621 on the launch vehicle 610 then transmits the encrypted host command 622 to the command receiver 635.
[0153] Command receiver 635 then transmits the encrypted host command 653 to host communication security module 662. Host communication security module 662 uses a host COMSEC variant (e.g., COMSEC variant 1) to decrypt the encrypted host command to generate an unencrypted host command.
[0154] It should be noted that the host communication security module 662 may include one or more communication security modules (e.g., communication security module 1 and communication security module 2, wherein communication security module 2 is a redundant communication security module used in the event of a failure of communication security module 1), wherein the additional communication security module is a redundant communication security module used in the event of a failure of a communication security module. Additionally, the host communication security module 662 may include one or more processors.
[0155] The satellite operations section 651 of the host SOC 650 also transmits encrypted managed commands 634 to the ground host gateway antenna 627. The host gateway antenna 627 then transmits the encrypted managed commands 635 to the managed payload antenna 680 on the launch vehicle 610. The host gateway antenna 627 uses one or more in-band frequencies (i.e., the same one or more frequency bands used for transmitting payload data) to transmit the encrypted host commands 635. The managed payload antenna 680 on the launch vehicle 610 then transmits the encrypted managed commands to the managed payload 607. The managed payload 607 transmits the encrypted managed commands 654 to the managed communications security module 663. The managed communications security module 663 decrypts the encrypted managed commands using managed COMSEC variants (e.g., COMSEC variant 2 to COMSEC variant N+1) to generate unencrypted managed commands.
[0156] It should be noted that each of the managed communication security modules 663 may include one or more communication security modules (e.g., communication security module 1 and communication security module 2, wherein communication security module 2 is a redundant communication security module used in the event of a failure of communication security module 1), wherein the additional communication security module is a redundant communication security module used in the event of a failure of a communication security module. Additionally, each of the host communication security modules 663 may include one or more processors.
[0157] The host communication security module 662 then transmits unencrypted host commands 670 to the host payload 606 and transmits on / off commands 664 to at least one managed payload 607. Furthermore, the managed communication security module 663 transmits unencrypted managed commands 671 to (one or more) managed payloads 607.
[0158] The host payload 606 is reconfigured according to an unencrypted host command. One or more managed payloads 607 are commanded to be on / off according to an on / off command. It should be noted that one or more managed payloads 607 can later be commanded to be off according to another on / off command. After one or more managed payloads 607 are commanded to be on, the managed payloads 607 are reconfigured according to an unencrypted managed command.
[0159] Reconfiguration of the host payload 606 and / or (one or more) managed payloads 607 may include adjusting at least one of the following: transponder power, transponder spectrum monitoring, transponder connectivity, transponder gain settings, transponder limiter settings, transponder automatic level control settings, transponder phase settings, internal gain generation, bandwidth of at least one beam, at least one frequency band of at least one beam, transponder beamforming settings, effective isotropic radiated power (EIRP) of at least one beam, transponder channel or beam steering. Additionally, reconfiguration of the host payload 606 and / or (one or more) managed payloads 607 may include reconfiguring at least one of the following: managed payload antenna 680, host payload antenna 682 (e.g., by antenna steering), at least one analog-to-digital converter, at least one digital-to-analog converter, at least one beamformer, at least one digital channelizer, at least one demodulator, at least one modulator, at least one digital switch matrix, at least one digital combiner, or at least one analog switch matrix. In one or more embodiments, the host payload 606 and / or (one or more) managed payloads 607 include one or more processors.
[0160] After reconfiguring the host payload 606 (e.g., the host payload antenna 682 is rotated or turned to radiate to a designated area on Earth), the host payload antenna 682 then transmits host user data (e.g., in one or more antenna beams 608) to the host user antenna 685 on the ground. And, after reconfiguring (one or more) the managed payload 607, the managed payload antenna 680 transmits managed user data (e.g., in one or more antenna beams 681) to the managed user antenna 690 on the ground. It should be noted that in other embodiments, the host user antenna 685 and / or the managed user antenna 690 may be in the air (e.g., located on an aircraft or satellite) or at sea (e.g., located on a ship) instead of... Figure 6 As shown on the ground (e.g., located on the ground).
[0161] Furthermore, it should be noted that, although in Figure 6 In this embodiment, antenna beam 681 and antenna beam 608 are shown as each comprising a single circular dot beam; however, in other embodiments, antenna beam 681 and antenna beam 608 may each comprise more than one circular dot beam. Figure 6 The beams shown (e.g., antenna beam 681 and / or antenna beam 608 may each include multiple beams, and antenna beam 681 and / or antenna beam 608 may each include beams related to...) Figure 6 The circular dot beam shown is different from beams of different shapes (e.g., antenna beam 681 and / or antenna beam 608 may each include elliptical beams and / or various different shaped beams).
[0162] It should be noted that in one or more embodiments, the host payload antenna 682 and / or the managed payload antenna 680 may each include one or more dish reflectors, including but not limited to parabolic reflectors and / or shaped reflectors. Additionally, the host payload antenna 682 and / or the managed payload antenna 680 may each include one or more multi-feed antenna arrays.
[0163] Host payload 606 transmits unencrypted host telemetry (i.e., telemetry data associated with host payload 606 used by the host user) 609 to host communication security module 662. Host communication security module 662 then encrypts the unencrypted host telemetry using a host COMSEC variant (i.e., COMESEC variant 1) to generate encrypted host telemetry.
[0164] Furthermore, (one or more) managed payloads 607 transmit unencrypted managed telemetry (i.e., telemetry data associated with (one or more) managed payloads 607 used by (one or more) managed users) 672 to the managed communications security module 663. The managed communications security module 663 then encrypts the unencrypted managed telemetry using managed COMSEC variants (i.e., COMSEC variant 2 to COMSEC variant N+1) to generate encrypted managed telemetry. Therefore, for each managed user 660, a different managed COMSEC variant will be used to encrypt the unencrypted managed telemetry associated with that managed user 660.
[0165] The host communication security module 662 then transmits the encrypted host telemetry 693 to the telemetry transmitter 694. The telemetry transmitter 694 then transmits the encrypted host telemetry 695 to the telemetry antenna 623. The telemetry antenna 623 then transmits the encrypted host telemetry 697 to the SOC antenna 616. The SOC antenna 616 then (via a terrestrial link with an IPSec VPN) transmits the encrypted host telemetry 698 to the satellite operations section 251 of the host SOC 650. The satellite operations section 651 then decrypts the encrypted host telemetry using a host COMSEC variant (i.e., COMSEC variant 1) to generate unencrypted host telemetry.
[0166] The managed communications security module 663 also transmits encrypted managed telemetry 696 to the managed payload 607. The managed payload 607 then transmits the encrypted managed telemetry to the managed payload antenna 680. The managed payload antenna 680 then transmits the encrypted managed telemetry 638 to the host gateway antenna 627. The host gateway antenna 627 then (via a terrestrial link with IPSec VPN) transmits the encrypted managed telemetry 639 to the satellite operations section 651 of the host SOC 650.
[0167] Satellite operations unit 651 transmits encrypted managed telemetry data 632 to security zone 652 of host SOC 650. Security zone 652 decrypts the encrypted managed telemetry data using managed COMSEC variants (e.g., COMSEC variant 2 to COMSEC variant N+1) to generate unencrypted managed telemetry data. Security zone 652 then transmits the unencrypted managed telemetry data 633 to managed user 660 (via a terrestrial link with IPSec VPN), with the unencrypted telemetry data associated with managed user 660.
[0168] Figure 7A , Figure 7B and Figure 7C Together illustrating the disclosed method for utilizing at least one embodiment of the present disclosure. Figure 4 , Figure 5 and Figure 6 The flowchart illustrates a method for commercial satellite operations performed by the security zone of a system's payload operation. At the beginning of the method at 700, the security zone of the host satellite operations center (SOC) receives at least one request from at least one managed user, each request including a service specification 705 associated with the managed user. The security zone then generates an unencrypted managed command 710 for each request based on the service specification. The security zone then encrypts the unencrypted managed command for each request by utilizing a corresponding Managed Communications Security (COMSEC) variant associated with the managed user, producing an encrypted managed command 715. The SOC operations portion of the host SOC generates an unencrypted host command 720 based on the host user's service specification. The SOC operations portion then encrypts the unencrypted host command by utilizing a host COMSEC variant, producing an encrypted host command 725. The host SOC then transmits the encrypted host command and the encrypted managed command to the carrier 730.
[0169] Then, the host communication security module on the carrier decrypts the encrypted host command using a host COMSEC variant to generate an unencrypted host command 735. Furthermore, for each managed user, the corresponding managed communication security module on the carrier decrypts the encrypted managed command for each managed user using the corresponding managed COMSEC variant to generate an unencrypted managed command 740. Then, based on the unencrypted host command, the host payload on the carrier is reconfigured 745. Furthermore, based on the unencrypted host command, at least one managed payload on the carrier is commanded to be turned on or off 750. Additionally, based on the unencrypted managed command, at least one managed payload is reconfigured 755. Then, the host payload antenna on the carrier transmits host user data to the host user antenna 760. Furthermore, the managed payload antenna on the carrier transmits managed user data to the managed user antenna 765. Then, the host payload generates unencrypted host telemetry 770. Furthermore, at least one managed payload generates unencrypted managed telemetry 775. The host communication security module then encrypts the unencrypted host telemetry using a host COMSEC variant to produce encrypted host telemetry 780. Furthermore, for each of the managed users, the corresponding managed communication security module encrypts the unencrypted managed telemetry for each managed user using the corresponding managed COMSEC variant to produce encrypted managed telemetry 785.
[0170] The carrier then transmits the encrypted host telemetry and encrypted managed telemetry to the host SOC 790. The SOC operation section then decrypts the encrypted host telemetry using a host COMSEC variant to produce unencrypted host telemetry 795. Furthermore, the secure zone decrypts the encrypted managed telemetry for each managed user using the corresponding managed COMSEC variant to produce unencrypted managed telemetry for each managed user 796. The method then ends 797.
[0171] Figure 8 This is an electronic data sheet 800 illustrating possible combinations of transmissions (i.e., out-of-band or in-band transmissions) of host commands, host telemetry, managed commands, and managed telemetry for a system disclosed according to at least one embodiment of this disclosure for commercial satellite operations utilizing a security zone for payload operation. In this figure, for a carrier comprising a single host / managed payload or one host payload and (one or more) managed payloads, the electronic data sheet indicates possible frequency bands for transmitting associated telemetry and command signals. For example, the combination of digit (NO.) 1 indicates that all signals (i.e., host commands, host telemetry, managed commands, and managed telemetry) will be transmitted at out-of-band frequencies. As another example, the combination of digit (NO.) 4 indicates that host-related signals (i.e., host commands and host telemetry) will be transmitted at out-of-band frequencies, and managed-related signals (i.e., managed commands and managed telemetry) will be transmitted at in-band frequencies.
[0172] As previously described above, the host / hosted payloads (i.e., shared payloads), host payloads, and / or at least one hosted payload of the disclosed system used for the allocation and control of private carrier resources can employ various types of repeaters. For example, various types of repeaters can be employed, including but not limited to various types of digital repeaters, various types of analog repeaters (e.g., conventional repeater-type repeaters), and various combinations of analog / digital repeaters. It should be noted that in one or more embodiments, when a payload (e.g., a host / hosted payload, a host payload, and / or a hosted payload) employs an analog repeater (e.g., a conventional repeater-type repeater), the payload will only utilize out-of-band frequencies for the transmission of its associated telemetry signals and the reception of its associated command signals (i.e., the payload cannot be configured to utilize in-band frequencies for the transmission of telemetry signals and the reception of command signals).
[0173] The following paragraphs describe illustrative, non-exclusive examples of the inventive subject matter according to this disclosure:
[0174] Example A1. A method for payload operation, the method comprising:
[0175] Through the security zone of the Host Satellite Operations Center (SOC), receive at least one request from at least one managed user, wherein each request includes the service specifications of the managed user associated with the request;
[0176] Through the secure zone, generate unencrypted managed commands for each item in the request, according to the requested service specifications;
[0177] By utilizing the appropriate Managed Communications Security (COMSEC) variant of the managed user associated with the request, the unencrypted managed commands in each request are encrypted to produce encrypted managed commands.
[0178] By utilizing the host SOC's SOC operation section and leveraging a host COMSEC variant, unencrypted host commands are encrypted to produce encrypted host commands.
[0179] Encrypted host commands and encrypted managed commands are transmitted to the carrier via the host SOC.
[0180] By using the host communication security module on the carrier and exploiting a host COMSEC variant, encrypted host commands are decrypted to produce unencrypted host commands.
[0181] By utilizing the corresponding managed communication security module on the carrier for each managed user, and by leveraging the corresponding managed COMSEC variant, the encrypted managed command is decrypted for each managed user to produce an unencrypted managed command.
[0182] Reconfigure the host / managed payload on the carrier based on unencrypted host commands and unencrypted managed commands;
[0183] Generate unencrypted host telemetry and unencrypted managed telemetry using host / managed payloads;
[0184] By using the host communication security module and leveraging the host COMSEC variant, unencrypted host telemetry is encrypted to generate encrypted host telemetry.
[0185] By utilizing the corresponding managed communication security module for each managed user, and by leveraging the corresponding managed COMSEC variant, unencrypted managed telemetry is encrypted for each managed user to produce encrypted managed telemetry.
[0186] The carrier transmits encrypted host telemetry and encrypted managed telemetry to the host SOC.
[0187] Through the SOC operation section, encrypted host telemetry is decrypted using a host COMSEC variant to generate unencrypted host telemetry; and
[0188] By utilizing the appropriate managed COMSEC variant within the secure zone, encrypted managed telemetry is decrypted for each managed user to generate unencrypted managed telemetry for each managed user.
[0189] Example A2. The method according to Example A1, wherein the method further includes: generating an unencrypted host command according to the service specifications of the host user through the SOC operation section.
[0190] Example A3. The method according to Example A1, wherein the method further includes: transmitting host user data to a host user antenna and transmitting managed user data to a managed user antenna via a payload antenna on a carrier.
[0191] Example A4. The method according to Example A1, wherein encrypted host commands are transmitted from the host SOC to the carrier using at least one of the following: at least one out-of-band frequency band or at least one in-band frequency band.
[0192] Example A5. According to the method of Example A4, wherein when an encrypted host command is transmitted using at least one out-of-band frequency band, the encrypted host command is transmitted from the host SOC to the carrier via the SOC antenna.
[0193] Example A6. According to the method of Example A4, wherein when an encrypted host command is transmitted using at least one in-band frequency band, the encrypted host command is transmitted from the host SOC to the carrier via the host gateway antenna.
[0194] Example A7. The method according to Example A1, wherein encrypted managed commands are transmitted from the host SOC to the carrier using at least one of the following: at least one out-of-band frequency band or at least one in-band frequency band.
[0195] Example A8. The method according to Example A7, wherein when an encrypted managed command is transmitted using at least one out-of-band frequency band, the encrypted managed command is transmitted from the host SOC to the carrier via the SOC antenna.
[0196] Example A9. The method according to Example A7, wherein when an encrypted managed command is transmitted using at least one in-band frequency band, the encrypted managed command is transmitted from the host SOC to the carrier via the host gateway antenna.
[0197] Example A10. The method according to Example A1, wherein encrypted host telemetry is transmitted from the carrier to the host SOC using at least one of the following: at least one out-of-band frequency band or at least one in-band frequency band.
[0198] Example A11. The method according to Example A10, wherein when encrypted host telemetry is transmitted using at least one out-of-band frequency band, the encrypted host telemetry is transmitted from the carrier to the host SOC via the SOC antenna.
[0199] Example A12. The method according to Example A10, wherein when encrypted host telemetry is transmitted using at least one in-band frequency band, the encrypted host telemetry is transmitted from the carrier to the host SOC via the host gateway antenna.
[0200] Example A13. The method according to Example A1, wherein encrypted managed telemetry is transmitted from the carrier to the host SOC using at least one of the following: at least one out-of-band frequency band or at least one in-band frequency band.
[0201] Example A14. The method according to Example A13, wherein when encrypted managed telemetry is transmitted using at least one out-of-band frequency band, the encrypted managed telemetry is transmitted from the carrier to the host SOC via the SOC antenna.
[0202] Example A15. The method according to Example A13, wherein when encrypted managed telemetry is transmitted using at least one in-band frequency band, the encrypted managed telemetry is transmitted from the carrier to the host SOC via the host gateway antenna.
[0203] Example A16. The method according to Example A1, wherein the host / hosted payload is one of a digital payload or an analog payload.
[0204] Example A17. The method according to Example A1, wherein reconfiguring the host / hosted payload includes adjusting at least one of the following: transponder power, transponder spectrum monitoring, transponder connectivity, transponder gain settings, transponder limiter settings, transponder automatic level control settings, transponder phase settings, internal gain generation, bandwidth of at least one beam, at least one frequency band of at least one of at least one beam, transponder beamforming settings, effective isotropic radiated power (EIRP) of at least one of at least one beam, transponder channel or beam steering.
[0205] Example A18. The method according to Example A1, wherein reconfiguring the host / hosted payload includes reconfiguring at least one of the following: payload antenna, at least one analog-to-digital converter, at least one digital-to-analog converter, at least one beamformer, at least one digital channelizer, at least one demodulator, at least one modulator, at least one digital switch matrix, at least one digital combiner, or at least one analog switch matrix.
[0206] Example A19. The method according to Example A1, wherein the carrier is one of the following: a satellite, an aircraft, a drone (UAV), or a spaceplane.
[0207] Example B1. A method for payload operation, the method comprising:
[0208] Through the security zone of the Host Satellite Operations Center (SOC), receive at least one request from at least one managed user, wherein each request includes the service specifications of the managed user associated with the request;
[0209] Through the secure zone, generate unencrypted managed commands for each item in the request, according to the requested service specifications;
[0210] By utilizing the appropriate Managed Communications Security (COMSEC) variant of the managed user associated with the request, the unencrypted managed commands in each request are encrypted to produce encrypted managed commands.
[0211] By utilizing the host SOC's SOC operation section and leveraging a host COMSEC variant, unencrypted host commands are encrypted to produce encrypted host commands.
[0212] Encrypted host commands and encrypted managed commands are transmitted to the carrier via the host SOC.
[0213] By using the host communication security module on the carrier and exploiting a host COMSEC variant, encrypted host commands are decrypted to produce unencrypted host commands.
[0214] By utilizing the corresponding managed communication security module on the carrier for each managed user, and by leveraging the corresponding managed COMSEC variant, the encrypted managed command is decrypted for each managed user to produce an unencrypted managed command.
[0215] Reconfigure the host payload on the launcher based on unencrypted host commands;
[0216] According to the unencrypted managed command, at least one managed payload on the command vehicle is either on or off;
[0217] Reconfigure a managed payload based on an unencrypted managed command;
[0218] Generate unencrypted host telemetry using the host payload;
[0219] Generate unencrypted managed telemetry using at least one managed payload;
[0220] By using the host communication security module and leveraging the host COMSEC variant, unencrypted host telemetry is encrypted to generate encrypted host telemetry.
[0221] By utilizing the corresponding managed communication security module for each managed user, and by leveraging the corresponding managed COMSEC variant, unencrypted managed telemetry is encrypted for each managed user to produce encrypted managed telemetry.
[0222] The carrier transmits encrypted host telemetry and encrypted managed telemetry to the host SOC.
[0223] Through the SOC operation section, encrypted host telemetry is decrypted using a host COMSEC variant to generate unencrypted host telemetry; and
[0224] By utilizing the appropriate managed COMSEC variant within the secure zone, encrypted managed telemetry is decrypted for each managed user to generate unencrypted managed telemetry for each managed user.
[0225] Example B2. The method according to Example B1, wherein the method further includes: generating an unencrypted host command according to the service specifications of the host user through the SOC operation section.
[0226] Example B3. The method according to Example B1, wherein the method further includes: transmitting host user data to a host user antenna via a host payload antenna on a carrier; and
[0227] Managed user data is transmitted to the managed user antenna via the managed payload antenna on the carrier.
[0228] Example B4. The method according to Example B3, wherein the host user antenna is one of a steerable reflector antenna or a phased array antenna, and the managed user antenna is one of a steerable reflector antenna or a phased array antenna.
[0229] Example B5. The method according to Example B1, wherein encrypted host commands are transmitted from the host SOC to the carrier using at least one of the following: at least one out-of-band frequency band or at least one in-band frequency band.
[0230] Example B6. According to the method of Example B5, wherein when an encrypted host command is transmitted using at least one out-of-band frequency band, the encrypted host command is transmitted from the host SOC to the carrier via the SOC antenna.
[0231] Example B7. According to the method of Example B5, wherein when an encrypted host command is transmitted using at least one in-band frequency band, the encrypted host command is transmitted from the host SOC to the carrier via the host gateway antenna.
[0232] Example B8. The method according to Example B1, wherein encrypted managed commands are transmitted from the host SOC to the carrier using at least one of the following: at least one out-of-band frequency band or at least one in-band frequency band.
[0233] Example B9. The method according to Example B8, wherein when an encrypted managed command is transmitted using at least one out-of-band frequency band, the encrypted managed command is transmitted from the host SOC to the carrier via the SOC antenna.
[0234] Example B10. The method according to Example B8, wherein when an encrypted managed command is transmitted using at least one in-band frequency band, the encrypted managed command is transmitted from the host SOC to the carrier via the host gateway antenna.
[0235] Example B11. The method according to Example B1, wherein encrypted host telemetry is transmitted from the carrier to the host SOC using at least one of the following: at least one out-of-band frequency band or at least one in-band frequency band.
[0236] Example B12. The method according to Example B11, wherein when encrypted host telemetry is transmitted using at least one out-of-band frequency band, the encrypted host telemetry is transmitted from the carrier to the host SOC via the SOC antenna.
[0237] Example B13. The method according to Example B11, wherein when encrypted host telemetry is transmitted using at least one in-band frequency band, the encrypted host telemetry is transmitted from the carrier to the host SOC via the host gateway antenna.
[0238] Example B14. The method according to Example B1, wherein encrypted managed telemetry is transmitted from the carrier to the host SOC using at least one of the following: at least one out-of-band frequency band or at least one in-band frequency band.
[0239] Example B15. The method according to Example B14, wherein when encrypted managed telemetry is transmitted using at least one out-of-band frequency band, the encrypted managed telemetry is transmitted from the carrier to the host SOC via the SOC antenna.
[0240] Example B16. The method according to Example B14, wherein when encrypted managed telemetry is transmitted using at least one in-band frequency band, the encrypted managed telemetry is transmitted from the carrier to the host SOC via the host gateway antenna.
[0241] Example B17. The method according to Example B1, wherein the host payload is one of a digital payload or an analog payload; and wherein at least one managed payload is one of a digital payload or an analog payload.
[0242] Example B18. The method according to Example B1, wherein reconfiguring the host payload or at least one of the managed payloads includes adjusting at least one of the following: transponder power, transponder spectrum monitoring, transponder connectivity, transponder gain setting, transponder limiter setting, transponder automatic level control setting, transponder phase setting, internal gain generation, bandwidth of at least one beam, at least one frequency band of at least one of the at least one beam, transponder beamforming setting, effective isotropic radiated power (EIRP) of at least one of the at least one beam, transponder channel or beam steering.
[0243] Example B19. The method according to Example B1, wherein reconfiguring at least one of the host payload or at least one managed payload includes reconfiguring at least one of the following: host payload antenna, managed payload antenna, at least one analog-to-digital converter, at least one digital-to-analog converter, at least one beamformer, at least one digital channelizer, at least one demodulator, at least one modulator, at least one digital switch matrix, at least one digital combiner, or at least one analog switch matrix.
[0244] Example B20. The method according to Example B1, wherein the carrier is one of the following: a satellite, an aircraft, a drone (UAV), or a spaceplane.
[0245] Although specific embodiments have been shown and described, it should be understood that the foregoing discussion is not intended to limit the scope of these embodiments. While embodiments and variations of many aspects of the invention have been disclosed and described herein, such disclosure is provided for purposes of explanation and illustration only. Therefore, various changes and modifications may be made without departing from the scope of the claims.
[0246] When the above method instructs certain events to occur in a certain order, those skilled in the art who benefit from this disclosure will recognize that the ordering can be modified and such modifications conform to variations of this disclosure. Furthermore, where possible, portions of the method can be executed simultaneously and sequentially in parallel processing. Additionally, more or fewer portions of the method can be executed.
[0247] Therefore, the embodiments are intended to illustrate alternatives, modifications, and equivalents that may fall within the scope of the claims.
[0248] Although certain illustrative embodiments and methods have been disclosed herein, it will be apparent from the foregoing disclosure that those skilled in the art can make variations and modifications to these embodiments and methods without departing from the true spirit and scope of the disclosed technology. Many other examples of the disclosed technology exist, each differing from the others only in detail. Therefore, the disclosed technology is intended to be limited to the scope required by the appended claims and the rules and principles of applicable law.
Claims
1. A system for payload operation, the system comprising: The security zone of the host satellite operation center, namely the security zone (452) of the host SOC (450), receives at least one request from at least one managed user (460), wherein each of the requests includes the service specifications of the managed user (460) associated with the request. For each of the requests, the security zone (452) generates an unencrypted managed command according to the service specification of the request, and for each of the requests, encrypts the unencrypted managed command by utilizing the corresponding managed communication security variant of the managed user associated with the request, i.e., the corresponding managed COMSEC variant, to produce an encrypted managed command. The SOC operation section (451) of the host SOC (450) generates encrypted host commands by encrypting unencrypted host commands using a host COMSEC variant. The host SOC (450) transmits the encrypted host command and the encrypted managed command to the carrier (410); The host communication security module (462) on the carrier (410) generates the unencrypted host command by decrypting the encrypted host command using the host COMSEC variant; For each of the managed users (460), the corresponding managed communication security module (463) on the carrier (410) decrypts the encrypted managed command for each of the managed users (460) by utilizing the corresponding managed COMSEC variant to produce the unencrypted managed command; The host / hosted payloads (406, 407) on the carrier (410) are configured to be reconfigured according to the unencrypted host command and the unencrypted hosted command, and to generate unencrypted host telemetry and unencrypted hosted telemetry. The host communication security module (462) generates encrypted host telemetry by encrypting the unencrypted host telemetry using the host COMSEC variant; The corresponding managed communication security module (463) for each of the managed users encrypts the unencrypted managed telemetry for each of the managed users by utilizing the corresponding managed COMSEC variant to produce the encrypted managed telemetry; The carrier (410) transmits the encrypted host telemetry and the encrypted managed telemetry to the host SOC (450); The SOC operation section (451) generates the unencrypted host telemetry by decrypting the encrypted host telemetry using the host COMSEC variant. and The security zone (452) decrypts the encrypted managed telemetry for each of the managed users (460) by utilizing the corresponding managed COMSEC variant, to generate the unencrypted managed telemetry for each of the managed users (460). in: The encrypted host command is transmitted from the host SOC (450) to the carrier (410) using at least one out-of-band frequency band; The encrypted managed command is transmitted from the host SOC (450) to the carrier (410) using at least one out-of-band frequency band; The encrypted host telemetry is transmitted from the carrier (410) to the host SOC (450) using at least one out-of-band frequency band; The encrypted managed telemetry is transmitted from the carrier (410) to the host SOC (450) using at least one out-of-band frequency band; and The host communication security module (462) is configured to transmit on / off commands to the managed payload (407).
2. The system of claim 1, wherein the host / hosted payload is one of a digital payload or an analog payload.
3. The system according to claim 1 or 2, wherein the host / hosted payload (406, 407) is reconfigured by adjusting at least one of the following: transponder power, transponder spectrum monitoring, transponder connection, transponder gain setting, transponder limiter setting, transponder automatic level control setting, transponder phase setting, internal gain generation, bandwidth of at least one beam, at least one frequency band of at least one of the at least one beam, transponder beamforming setting, effective isotropic radiated power (EIRP) of at least one of the at least one beam, transponder channel or beam steering.
4. The system according to claim 1 or 2, wherein the host / hosted payload (406, 407) is reconfigured by reconfiguring at least one of the following: payload antenna (480), at least one analog-to-digital converter, at least one digital-to-analog converter, at least one beamformer, at least one digital channelizer, at least one demodulator, at least one modulator, at least one digital switch matrix, at least one digital combiner, or at least one analog switch matrix.
5. The system according to claim 1 or 2, wherein the carrier (410) is one of a satellite, aircraft, unmanned aerial vehicle (UAV) or spaceplane.
6. The system according to claim 1 or 2, wherein the SOC operation section (451) generates the unencrypted host command according to the service specifications of the host user.
7. The system according to claim 1 or 2, wherein the SOC operation section (451) transmits the encrypted managed command to the ground SOC antenna (416) via a ground link.
8. The system of claim 7, wherein the terrestrial link uses an Internet Protocol Secure Virtual Private Network, i.e., an IPSec VPN.
9. A method for payload operation, the method comprising: Through the security zone (452) of the host satellite operation center, i.e. the security zone (450) of the host SOC (450), an unencrypted managed command is generated according to the service specifications of at least one managed user (460), and for each of the requests, the unencrypted managed command is encrypted by utilizing the corresponding managed communication security variant, i.e. the corresponding managed COMSEC variant, of the managed user (460) associated with the request to produce an encrypted managed command. The host SOC's SOC operation section (451) generates unencrypted host commands according to the host user's service specifications. Encrypted host commands are produced by encrypting unencrypted host commands using a host COMSEC variant. The host commands and the managed commands are transmitted to the carrier (410) via the host SOC (450); The unencrypted host command is generated by decrypting the encrypted host command using the host COMSEC variant. By utilizing the corresponding managed COMSEC variant, the encrypted managed command is decrypted for each of the managed users (460) to produce the unencrypted managed command; Based on the unencrypted host command and the unencrypted managed command, reconfigure the host / managed payload (406, 407) on the carrier (410); Using the host / hosted payloads (406, 407), generate unencrypted host telemetry and unencrypted hosted telemetry; Encrypted host telemetry is generated by encrypting the unencrypted host telemetry using the host COMSEC variant. By utilizing the corresponding managed COMSEC variant, the unencrypted managed telemetry is encrypted for each of the managed users (460) to produce the encrypted managed telemetry; The encrypted host telemetry and the encrypted managed telemetry are transmitted to the host SOC (450) via the carrier (410); The unencrypted host telemetry is generated by decrypting the encrypted host telemetry using the host COMSEC variant. and By utilizing the corresponding managed COMSEC variant, the encrypted managed telemetry is decrypted for each of the managed users (460) to generate the unencrypted managed telemetry for each of the managed users; The encrypted host commands are transmitted from the host SOC (450) to the carrier (410) using at least one out-of-band frequency band. The encrypted managed command is transmitted from the host SOC (450) to the carrier (410) using at least one out-of-band frequency band; The encrypted host telemetry is transmitted from the carrier (410) to the host SOC (450) using at least one out-of-band frequency band; and The encrypted managed telemetry is transmitted from the carrier (410) to the host SOC (450) using at least one out-of-band frequency band, and the method further includes The host communication security module (462) transmits on / off commands to the managed payload.
10. The method of claim 9, wherein the method further comprises: Host user data is transmitted to the host user antenna and managed user data is transmitted to the managed user antenna via the payload antenna (480) on the carrier (410).
11. The method according to claim 9 or 10, wherein the host command is transmitted from the host SOC (450) to the carrier (410) via the SOC antenna (416).
12. The method according to claim 9 or 10, wherein the managed command is transmitted from the host SOC (450) to the carrier (410) via the host gateway antenna (427).
13. The method according to claim 9 or 10, further comprising the SOC operation section (451) transmitting the encrypted managed command to the ground SOC antenna (416) via a ground link.
14. The method of claim 13, wherein the terrestrial link uses an Internet Protocol Secure Virtual Private Network, i.e., an IPSec VPN.
15. A method for payload operation, the method comprising: The host satellite operations center (SOC) receives at least one request from at least one hosted user, each of the at least one request including the service specifications of the hosted user associated with the request. Through the security zone of the host SOC, for each of the at least one request, an unencrypted managed command is generated according to the service specification; Through the security zone, for each of the at least one request, the unencrypted managed command is encrypted by utilizing the corresponding managed communication security variant, i.e., the corresponding managed COMSEC variant, of the managed user associated with the request, to produce an encrypted managed command; The host SOC's SOC operation section uses a host COMSEC variant to encrypt unencrypted host commands to generate encrypted host commands. The encrypted host commands and the encrypted managed commands are transmitted to the carrier via the host SOC. The unencrypted host command is generated by decrypting the encrypted host command using the host COMSEC variant via the host communication security module on the carrier. For each of the managed users, the corresponding managed communication security module on the carrier decrypts the encrypted managed command for each of the managed users by utilizing the corresponding managed COMSEC variant to generate the unencrypted managed command; The host payload / managed payload on the carrier is reconfigured based on the unencrypted host command and the unencrypted managed command, and unencrypted host telemetry and unencrypted managed telemetry are generated from the host payload / managed payload. Encrypted host telemetry is generated by encrypting the unencrypted host telemetry using the host COMSEC variant via the host communication security module on the carrier. By utilizing the corresponding managed communication security module for each of the managed users, and by employing the corresponding managed COMSEC variant, the unencrypted managed telemetry is encrypted for each of the managed users to produce the encrypted managed telemetry. The encrypted host telemetry and the encrypted managed telemetry are transmitted to the host SOC via the carrier. The SOC operation section decrypts the encrypted host telemetry using the host COMSEC variant to generate unencrypted host telemetry. and Through the secure zone, the encrypted managed telemetry is decrypted for each of the at least one managed user by utilizing the corresponding managed COMSEC variant to produce unencrypted managed telemetry.
16. The method of claim 15, wherein the encrypted host command is transmitted from the host SOC to the carrier using at least one of the following: at least one out-of-band frequency band or at least one in-band frequency band.
17. The method of claim 15, wherein the encrypted managed command is transmitted from the host SOC to the carrier using at least one of the following: at least one out-of-band frequency band or at least one in-band frequency band.
18. The method of claim 15, wherein the encrypted host telemetry is transmitted from the carrier to the host SOC using at least one of the following: at least one out-of-band frequency band or at least one in-band frequency band.
19. The method of claim 15, wherein the encrypted managed telemetry is transmitted from the carrier to the host SOC using at least one of the following: at least one out-of-band frequency band or at least one in-band frequency band.
20. The method of claim 15, wherein the host / hosted payload is a digital payload.
21. The method of claim 15, wherein the host / hosted payload is a simulated payload.
22. The method of claim 15, wherein the host / hosted payload is reconfigured by adjusting at least one of the following: transponder power, transponder spectrum monitoring, transponder connectivity, transponder gain setting, transponder limiter setting, transponder automatic level control setting, transponder phase setting, internal gain generation, bandwidth of at least one beam, at least one frequency band of at least one of the at least one beam, transponder beamforming setting, effective isotropic radiated power (EIRP) of at least one of the at least one beam, transponder channel or beam steering.
23. The method of claim 15, wherein the host / hosted payload is reconfigured by reconfiguring at least one of the following: a payload antenna, at least one analog-to-digital converter, at least one digital-to-analog converter, at least one beamformer, at least one digital channelizer, at least one demodulator, at least one modulator, at least one digital switch matrix, at least one digital combiner, or at least one analog switch matrix.
24. The method of claim 15, wherein the carrier is one of a satellite, an aircraft, a drone (UAV), or a spaceplane.
25. A method for payload operation, the method comprising: The host satellite operations center (SOC) receives at least one request from at least one hosted user, each of the at least one request including the service specifications of the hosted user associated with the request. Through the security zone of the host SOC, for each of the at least one request, an unencrypted managed command is generated according to the service specification; Through the security zone, for each of the at least one request, the unencrypted managed command is encrypted by utilizing the corresponding managed communication security variant, i.e., the corresponding managed COMSEC variant, of the managed user associated with the request, to produce an encrypted managed command; The host SOC's SOC operation section uses a host COMSEC variant to encrypt unencrypted host commands to generate encrypted host commands. The encrypted host commands and the encrypted managed commands are transmitted to the carrier via the host SOC. The unencrypted host command is generated by decrypting the encrypted host command using the host COMSEC variant via the host communication security module on the carrier. For each of the managed users, the corresponding managed communication security module on the carrier decrypts the encrypted managed command for each of the managed users by utilizing the corresponding managed COMSEC variant to generate the unencrypted managed command; The host payload on the carrier is reconfigured according to the unencrypted host command, and unencrypted host telemetry is generated from the host payload; Encrypted host telemetry is generated by encrypting the unencrypted host telemetry using the host COMSEC variant via the host communication security module on the carrier. According to the unencrypted host command, at least one managed payload on the carrier is commanded to be turned on or off; after the at least one managed payload is commanded to be turned on, the at least one managed payload is reconfigured according to the unencrypted managed command, and unencrypted managed telemetry is generated through the at least one managed payload; For each of the managed users, the corresponding managed communication security module encrypts the unencrypted managed telemetry for each of the managed users by utilizing the corresponding managed COMSEC variant, to produce the encrypted managed telemetry. The encrypted host telemetry and the encrypted managed telemetry are transmitted to the host SOC via a carrier. The SOC operation section decrypts the encrypted host telemetry using the host COMSEC variant to generate unencrypted host telemetry. and Through the secure zone, the encrypted managed telemetry is decrypted for each of the at least one managed user by utilizing the corresponding managed COMSEC variant to produce unencrypted managed telemetry.
26. The method of claim 25, wherein the encrypted host command is transmitted from the host SOC to the carrier using at least one of the following: at least one out-of-band frequency band or at least one in-band frequency band.
27. The method of claim 25, wherein the encrypted managed command is transmitted from the host SOC to the carrier using at least one of the following: at least one out-of-band frequency band or at least one in-band frequency band.
28. The method of claim 25, wherein the encrypted host telemetry is transmitted from the carrier to the host SOC using at least one of the following: at least one out-of-band frequency band or at least one in-band frequency band.
29. The method of claim 25, wherein the encrypted managed telemetry is transmitted from the carrier to the host SOC using at least one of the following: at least one out-of-band frequency band or at least one in-band frequency band.
30. The method of claim 25, wherein the host payload is one of a digital payload or an analog payload.
31. The method of claim 25, wherein the at least one managed payload is a digital payload or an analog payload.
32. The method of claim 25, wherein the host payload or the at least one managed payload is reconfigured by adjusting at least one of the following: transponder power, transponder spectrum monitoring, transponder connectivity, transponder gain setting, transponder limiter setting, transponder automatic level control setting, transponder phase setting, internal gain generation, bandwidth of at least one beam, at least one frequency band of at least one of the at least one beam, transponder beamforming setting, effective isotropic radiated power (EIRP) of at least one of the at least one beam, transponder channel, or beam steering.
33. The method of claim 25, wherein the host payload or the at least one managed payload is reconfigured by reconfiguring at least one of the following: a host payload antenna, a managed payload antenna, at least one analog-to-digital converter, at least one digital-to-analog converter, at least one beamformer, at least one digital channelizer, at least one demodulator, at least one modulator, at least one digital switch matrix, at least one digital combiner, or at least one analog switch matrix.
34. The method of claim 25, wherein the carrier is one of a satellite, an aircraft, an unmanned aerial vehicle (UAV), or a spaceplane.
Citation Information
Patent Citations
Multi-operator system for accessing satellite resources
EP2573956A2
Satellite communication system transmitting frequency hopped signals with a plurality of gateways and non processing satellites
WO2013130812A1