A system, method, apparatus, device, and medium for resisting DDoS attacks

By using target data center servers and blockchain technology in satellite IoT, DDoS attack terminals can be identified and blocked, solving the problem of terminals occupying low-Earth orbit satellite resources and ensuring normal communication.

CN116261140BActive Publication Date: 2025-11-25AISINO CORPORATION
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202111502921.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-10
Publication Date
2025-11-25
Estimated Expiration
2041-12-10

AI Technical Summary

Technical Problem

Terminals in satellite IoT are vulnerable to becoming DDoS attack initiation devices, consuming low-Earth orbit satellite resources and affecting communication between other terminals and low-Earth orbit satellites.

Method used

The first UEID is received and broadcast by the target data center server. Other data center servers in the blockchain send it to other low-Earth orbit satellites in the communication. The management center server assigns a second UEID and identifies the low-Earth orbit satellite in the communication. The low-Earth orbit satellite identifies the DDoS attack terminal and adds its UEID to the blacklist, terminating its RRC process and avoiding resource consumption.

Benefits of technology

This effectively prevents DDoS attack terminals from occupying the channels and computing resources of low-Earth orbit satellites, ensuring normal communication between other terminals and satellites.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116261140B_ABST
    Figure CN116261140B_ABST
Patent Text Reader

Abstract

The embodiment of the application provides an anti-DDoS attack system, method, device, equipment and medium, a target data center server receives a first UEID corresponding to a first terminal launching a DDoS attack sent by a first low-orbit satellite, and then the target data center server and other data center servers in a block chain send the first UEID to other low-orbit satellites in communication, so that the other low-orbit satellites add the first UEID to a blacklist, and then all the low-orbit satellites in a satellite Internet of Things do not respond to an RRC request of the first terminal, so that the channel resources and the computing resources of the low-orbit satellites are prevented from being occupied by the first terminal, and the terminal launching the DDoS attack cannot affect the communication of other terminals and satellites.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information and communication technology, and in particular to a system, method, apparatus, device and medium for resisting Distributed Denial of Service (DDoS) attacks. Background Technology

[0002] With the development of communication technology, satellite IoT applications are highly vulnerable to DDoS attacks, which can paralyze the satellite IoT and prevent it from providing services. DDoS attacks typically utilize client / server technology to launch attacks against one or more targets. Attackers usually use an unauthorized user account to install a DDoS control program on a terminal. Within a set time period, this terminal sends a large number of Radio Resource Control (RRC) requests to the satellite IoT, consuming its communication and network resources and ultimately paralyzing its service provision.

[0003] Current DDoS attack mitigation solutions for satellite IoT are primarily deployed on the core network side. However, satellite IoT involves a large number of terminals deployed in a dispersed manner. Furthermore, low-Earth orbit (LEO) satellites in satellite IoT have short operating cycles and limited computing and channel resources, resulting in significant latency in satellite-to-ground uplink and downlink communication. Based on these characteristics, terminals are vulnerable to launching DDoS attacks against LEO satellites. When a terminal launches a DDoS attack, it consumes the LEO satellite's channel and computing resources, impacting communication between other terminals and the LEO satellite. Summary of the Invention

[0004] This application provides an anti-DDoS attack system, method, apparatus, device, and medium to solve the technical problem in the prior art where, after a terminal becomes a DDoS attack initiating device in the satellite Internet of Things, it occupies the resources of low-Earth orbit satellites and affects the communication between other terminals and low-Earth orbit satellites.

[0005] This application provides a system for resisting distributed denial-of-service (DDoS) attacks, the system comprising:

[0006] The target data center server is used to receive the first UEID sent by the first low-orbit satellite and broadcast the first UEID to other data center servers in the blockchain;

[0007] Any of the other data center servers is configured to receive the first UEID broadcast by the target data center server and then send the first UEID to other low-orbit satellites communicating with the other data center server.

[0008] Furthermore, the system also includes:

[0009] The service center server is used to receive the service identifier sent by the second terminal if a newly connected second terminal is identified, and to assign a second UEID to the second terminal, as well as the number of low-orbit satellites communicating with the second terminal, and to broadcast the service identifier of the second terminal, the second UEID and the number to the management center server in the blockchain.

[0010] The management center server is used to receive the service identifier, the second UEID, and the quantity broadcast by the service center server; determine the second low-orbit satellite that communicates with the second terminal based on the service identifier, the quantity, and the service range of each low-orbit satellite stored, and broadcast the correspondence between the second UEID and the second low-orbit satellite to each data center server in the blockchain;

[0011] Any of the data center servers is configured to receive and store the correspondence between the second UEID and the second low-Earth orbit satellite; if it is detected that communication with the second low-Earth orbit satellite is currently taking place, the second UEID is sent to the second low-Earth orbit satellite, so that the second low-Earth orbit satellite saves the second UEID to a designated terminal list.

[0012] Furthermore, the system also includes:

[0013] The first low-Earth orbit satellite is configured to, if it receives a Radio Resource Control (RRC) request from the first terminal and determines that the current RRC state of the first terminal is not the first preset RRC state in the saved RRC process list, determine that the first terminal is the terminal launching a DDoS attack; terminate the RRC process of the first terminal; send the first user terminal number (UEID) corresponding to the first terminal to the target data center server communicating with the first low-Earth orbit satellite; and add the first UEID to the blacklist.

[0014] Any of the other low-orbit satellites, upon receiving the first UEID sent by the other data center server, adds the first UEID to the blacklist.

[0015] Furthermore, the first low-orbit satellite is also used to receive the RRC completion command sent by the first terminal. If it is detected that the current RRC status of the first terminal is not the second preset RRC status in the saved RRC process list, the saved Network Attached Storage (NAS) data sent by the first terminal is sent to the target center server.

[0016] The target central server is also used to store the NAS data.

[0017] Furthermore, the first low-orbit satellite is also configured to, upon receiving an RRC request from the first terminal and determining that the current RRC status of the first terminal is a first preset RRC status, or upon receiving an RRC completion instruction sent by the first terminal and determining that the current RRC status of the first terminal is a second preset RRC status, determine whether the first UEID of the first terminal is in the saved blacklist, and if so, terminate the RRC process of the first terminal.

[0018] Furthermore, the first low-orbit satellite is also configured to determine whether the service identifier sent by the first terminal is in the designated service identifier list of the first low-orbit satellite if the first UEID is not in the blacklist stored by the first low-orbit satellite; if not, terminate the RRC process of the first terminal.

[0019] Furthermore, the first low-Earth orbit satellite is also configured to determine whether the first UEID is in the designated terminal list of the first low-Earth orbit satellite if the service identifier of the first terminal is in the designated service identifier list of the first low-Earth orbit satellite; if not, terminate the RRC process of the first terminal.

[0020] Furthermore, the first low-orbit satellite is also configured to receive the RRC request and determine that the first UEID is in the designated terminal list of the first low-orbit satellite, and then update the current RRC status of the first terminal to a second preset RRC status; or receive the RRC completion instruction and determine that the first UEID is in the designated terminal list of the first low-orbit satellite, and then update the current RRC status of the first terminal to a first preset RRC status.

[0021] Furthermore, the first low-orbit satellite is also used to continue executing the RRC process of the first terminal.

[0022] Furthermore, the first low-orbit satellite is specifically used to, if it is determined that the first terminal is a terminal launching a DDoS attack, encrypt the first UEID corresponding to the first terminal, the preset first byte encoding and the current time, and send the encrypted information to the target data center server.

[0023] This application also provides a method for resisting DDoS attacks, applied to low-Earth orbit satellites, the method comprising:

[0024] Receive the Radio Resource Control (RRC) request sent by the first terminal;

[0025] If it is determined that the current RRC state of the first terminal is not the first preset RRC state in the saved RRC process list, then the first terminal is determined to be the terminal that launched the DDoS attack.

[0026] The RRC process of the first terminal is terminated, and the first user terminal number (UEID) corresponding to the first terminal is sent to the target data center server communicating with the first low-orbit satellite.

[0027] Add the first UEID to the blacklist.

[0028] Furthermore, the method also includes:

[0029] Receive the RRC completion instruction sent by the first terminal;

[0030] If it is detected that the current RRC status of the first terminal is not the second preset RRC status in the saved RRC process list, then the saved Network Attached Storage (NAS) data sent by the first terminal is sent to the target central server.

[0031] Furthermore, the method also includes:

[0032] If an RRC request is received from the first terminal and the current RRC status of the first terminal is determined to be a first preset RRC status, or if an RRC completion instruction is received from the first terminal and the current RRC status of the first terminal is determined to be a second preset RRC status, then it is determined whether the first UEID of the first terminal is in the saved blacklist. If so, the RRC process of the first terminal is terminated.

[0033] Furthermore, the method also includes:

[0034] If the first UEID is not in the blacklist stored by the first low-Earth orbit satellite, then the service identifier sent by the first terminal is used to determine whether the service identifier is in the designated service identifier list of the first low-Earth orbit satellite. If not, the RRC process of the first terminal is terminated.

[0035] Furthermore, the method also includes:

[0036] If the service identifier of the first terminal is in the designated service identifier list of the first low-Earth orbit satellite, then it is determined whether the first UEID is in the designated terminal list of the first low-Earth orbit satellite. If not, the RRC process of the first terminal is terminated.

[0037] Furthermore, the method also includes:

[0038] Upon receiving the RRC request and determining that the first UEID is in the designated terminal list of the first low-Earth orbit satellite, the current RRC status of the first terminal is updated to the second preset RRC status; or upon receiving the RRC completion instruction and determining that the first UEID is in the designated terminal list of the first low-Earth orbit satellite, the current RRC status of the first terminal is updated to the first preset RRC status.

[0039] Furthermore, the method also includes:

[0040] Continue executing the RRC procedure of the first terminal.

[0041] Further, sending the first UEID corresponding to the first terminal to the target data center server communicating with the first low-Earth orbit satellite includes:

[0042] If the first terminal is determined to be the terminal that launched the DDoS attack, the first UEID corresponding to the first terminal, the preset first byte encoding and the current time are encrypted, and the encrypted information is sent to the target data center server.

[0043] This application also provides an anti-DDoS attack device, the device comprising:

[0044] The receiving module is used to receive the Radio Resource Control (RRC) request sent by the first terminal;

[0045] The processing module is configured to determine that the first terminal is the terminal that launched the DDoS attack if it is determined that the current RRC state of the first terminal is not the first preset RRC state in the saved RRC process list; and terminate the RRC process of the first terminal.

[0046] The sending module is used to send the first user terminal number (UEID) corresponding to the first terminal to the target data center server that communicates with the first low-orbit satellite.

[0047] The processing module is also used to add the first UEID to the blacklist.

[0048] Furthermore, the receiving module is also configured to receive an RRC completion instruction sent by the first terminal;

[0049] The sending module is further configured to send the saved Network Attached Storage (NAS) data sent by the first terminal to the target central server if it is detected that the current RRC status of the first terminal is not the second preset RRC status in the saved RRC process list.

[0050] Furthermore, the processing module is also configured to, if it receives an RRC request from the first terminal and determines that the current RRC status of the first terminal is a first preset RRC status, or if it receives an RRC completion instruction sent by the first terminal and determines that the current RRC status of the first terminal is a second preset RRC status, determine whether the first UEID of the first terminal is in the saved blacklist, and if so, terminate the RRC process of the first terminal.

[0051] Furthermore, the processing module is also configured to, if the first UEID is not in the blacklist stored by the first low-orbit satellite, determine whether the service identifier sent by the first terminal is in the designated service identifier list of the first low-orbit satellite, and if not, terminate the RRC process of the first terminal.

[0052] Furthermore, the processing module is also configured to determine whether the first UEID is in the designated terminal list of the first low-orbit satellite if the service identifier of the first terminal is in the designated service identifier list of the first low-orbit satellite, and if not, terminate the RRC process of the first terminal.

[0053] Furthermore, the processing module is also configured to receive the RRC request and determine that the first UEID is in the designated terminal list of the first low-orbit satellite, then update the current RRC status of the first terminal to a second preset RRC status; or receive the RRC completion instruction and determine that the first UEID is in the designated terminal list of the first low-orbit satellite, then update the current RRC status of the first terminal to a first preset RRC status.

[0054] Furthermore, the processing module is also used to continue executing the RRC process of the first terminal.

[0055] Furthermore, the sending module is specifically used to, if it is determined that the first terminal is the terminal launching a DDoS attack, encrypt the first UEID corresponding to the first terminal, the preset first byte encoding and the current time, and send the encrypted information to the target data center server.

[0056] This application also provides an electronic device, which includes at least a processor and a memory, wherein the processor is configured to execute a computer program stored in the memory to implement the steps described above for resisting DDoS attacks.

[0057] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements any of the steps described above for resisting DDoS attacks.

[0058] In this application, the system includes: a target data center server, configured to receive the first UEID transmitted by a first low-Earth orbit (LEO) satellite and broadcast the first UEID to other data center servers in the blockchain; and any of the other data center servers, configured to receive the first UEID broadcast by the target data center server and then send the first UEID to other LEO satellites communicating with the other data center server, causing the other LEO satellites to add the first UEID to their blacklists. That is, in this application, the target data center server receives the first UEID corresponding to the first terminal launching a DDoS attack transmitted by the first LEO satellite, and then broadcasts the first UEID to other data center servers in the blockchain. The other data center servers then send the first UEID to other LEO satellites they are communicating with, causing the other LEO satellites to add the first UEID to their blacklists. This prevents all LEO satellites in the satellite IoT from responding to the first terminal's RRC requests, avoiding the first terminal occupying the channel and computing resources of the LEO satellites, and ensuring that the terminal launching the DDoS attack does not affect the communication between other terminals and satellites. Attached Figure Description

[0059] To more clearly illustrate the technical solutions of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0060] Figure 1 A schematic diagram of an anti-DDoS attack system structure provided in this application embodiment;

[0061] Figure 2 This is a schematic diagram of the structure of blockchain in satellite Internet of Things provided in the embodiments of this application;

[0062] Figure 3 A schematic diagram of an anti-DDoS attack process provided in an embodiment of this application;

[0063] Figure 4 This is a schematic diagram of the anti-DDoS attack device provided in the embodiments of this application;

[0064] Figure 5 This is a schematic diagram of an electronic device structure provided in an embodiment of this application. Detailed Implementation

[0065] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0066] To prevent terminals launching DDoS attacks from occupying the channel and computing resources of low-Earth orbit satellites, thus preventing other terminals from communicating with the low-Earth orbit satellites, this application provides an anti-DDoS attack system, method, apparatus, device, and medium.

[0067] Example 1:

[0068] Figure 1 This application provides a schematic diagram of an anti-DDoS attack system architecture, which includes: a target data center server 101 and other data center servers 102; wherein,

[0069] The target data center server 101 is used to receive the first UEID sent by the first low-orbit satellite and broadcast the first UEID to other data center servers in the blockchain;

[0070] Any of the other data center servers 102 is configured to, upon receiving the first UEID broadcast by the target data center server, send the first UEID to other low-orbit satellites communicating with the other data center server, so that the other low-orbit satellites add the first UEID to their blacklist.

[0071] This application provides an anti-DDoS attack system for satellite Internet of Things (IoT), wherein the satellite IoT includes at least a data center server and a terminal.

[0072] In this application, the satellite Internet of Things includes at least a data center server and a terminal. The terminal can communicate with the low-Earth orbit satellite in one direction or in two directions. However, this application only describes the process of one-way communication between the terminal and the low-Earth orbit satellite. That is, the terminal only sends an RRC request to the low-Earth orbit satellite to transmit data, and the low-Earth orbit satellite does not transmit data to the terminal.

[0073] In this application, when a first low-Earth orbit (LEO) satellite identifies a first terminal as initiating a DDoS attack, it adds the first terminal's first UEID to a blacklist and sends this first UEID to a target data center server currently communicating with the first LEO satellite. Upon receiving the first UEID, the target data center server broadcasts it to other data center servers in the blockchain via a blockchain smart contract. Each other data center server, upon receiving the first UEID, sends it to other LEO satellites communicating with it, ensuring that every LEO satellite in the satellite IoT receives the first UEID. Furthermore, the target data center server generates a digest of the first UEID using the SM3 algorithm and stores this digest in the blockchain for subsequent verification by technical personnel.

[0074] Furthermore, in this application, when the target data center server receives the first UEID of the first terminal launching the DDoS attack, it will also send the first UEID to the service server where the first UEID resides, enabling technicians to repair the first terminal in a timely manner. The service server will also broadcast the current status of the first terminal, such as waiting, recovery, and update status, to the management center server and data center server in the blockchain in real time via a blockchain smart contract. If the first terminal is currently in a waiting state, it means that the first terminal has not yet been repaired, and no operation is performed at this time. If the first terminal is currently in a recovery state, it means that the first terminal has been repaired and the key version number corresponding to the first UEID needs to be re-saved. That is, the service server sends the first UEID and key version number to each data center server based on the blockchain, and each data center server updates the key version number saved when decrypting the first UEID. If the first terminal is currently in an update state, the first terminal needs to re-enter the network based on the blockchain.

[0075] In this application, the target data center server receives the first UEID corresponding to the first terminal launching the DDoS attack from the first low-Earth orbit satellite. The target data center server then broadcasts the first UEID to other data center servers in the blockchain. The other data center servers then forward the first UEID to other low-Earth orbit satellites they are communicating with, causing the other low-Earth orbit satellites to add the first UEID to their blacklists. This prevents all low-Earth orbit satellites in the satellite IoT from responding to the first terminal's RRC requests, thus avoiding the first terminal occupying the low-Earth orbit satellite's channel and computing resources. As a result, the DDoS attack does not affect the communication between other terminals and satellites.

[0076] Example 2:

[0077] To manage the terminals and complete their network access operations, based on the above embodiments, the system in this application embodiment further includes:

[0078] The service center server is used to receive the service identifier sent by the second terminal if a newly connected second terminal is identified, and to assign a second UEID to the second terminal, as well as the number of low-orbit satellites communicating with the second terminal, and to broadcast the service identifier of the second terminal, the second UEID and the number to the management center server in the blockchain.

[0079] The management center server is used to receive the service identifier, the second UEID, and the quantity broadcast by the service center server; determine the second low-orbit satellite that communicates with the second terminal based on the service identifier, the quantity, and the service range of each low-orbit satellite stored, and broadcast the correspondence between the second UEID and the second low-orbit satellite to each data center server in the blockchain;

[0080] Any of the data center servers is configured to receive and store the correspondence between the second UEID and the second low-Earth orbit satellite; if it is detected that communication with the second low-Earth orbit satellite is currently taking place, the second UEID is sent to the second low-Earth orbit satellite.

[0081] The second low-orbit satellite is used to receive the second UEID sent by the data center server and save the second UEID to a designated terminal list.

[0082] In this application, when a second terminal is added to the satellite Internet of Things, the second terminal needs to complete the network access operation first, and then the second terminal can communicate one-way with the low-orbit satellite.

[0083] Specifically, in this application, when a second terminal is added to the satellite IoT, the service center server in the satellite IoT blockchain identifies the second terminal, obtains the service identifier of the second terminal from the second terminal, and assigns a second UEID and the number of low-Earth orbit satellites that can communicate with the second terminal. The service center server then broadcasts the service identifier, the second UEID, and the number to the management center server in the blockchain.

[0084] After receiving the service identifier, second UEID, and quantity of the second terminal broadcast by the service center server, the management center server determines candidate low-Earth orbit (LEO) satellites whose service range includes the service identifier of the first terminal, based on the pre-saved service range corresponding to each LEO satellite. It then selects the specified number of second LEO satellites from these candidate LEO satellites and designates them as the LEO satellites to communicate with the second terminal. Once the management center server has determined the second LEO satellite, it broadcasts the mapping between the second terminal's second UEID and the second LEO satellite to each data center server in the blockchain.

[0085] Specifically, in this application, after the management center server determines the candidate low-Earth orbit satellites, it selects the low-Earth orbit satellite with the smaller load as the first low-Earth orbit satellite to communicate with the first terminal, based on the number of terminals currently communicating with each low-Earth orbit satellite.

[0086] For each data center server in the blockchain, after receiving the mapping relationship between the second UEID and the second low-Earth orbit satellite sent by the management center server, the data center server saves the mapping relationship. It then identifies whether a second low-Earth orbit satellite exists that communicates with the data center server; if so, it sends the second UEID to that satellite.

[0087] After receiving the second UEID from the data center server it is communicating with, the second low-Earth orbit (LEO) satellite saves the second UEID to a designated terminal list stored by the LEO satellite. This designated terminal list contains the UEIDs of terminals that the LEO satellite can communicate with. For terminals whose UEIDs are not in this designated terminal list, the LEO satellite will not respond to or process any data or requests received from those terminals, even if such terminals are not in the list. Once the LEO satellite saves the second terminal's second UEID to the designated terminal list stored by the LEO satellite, the second terminal completes the network access operation.

[0088] Furthermore, in this embodiment, the second terminal that needs to complete the network access operation may be a newly connected satellite IoT terminal, or it may be a terminal that has previously launched a DDoS attack on any low-orbit satellite in the satellite IoT, but whose data has been completely updated.

[0089] Example 3:

[0090] To prevent terminals launching DDoS attacks from consuming low-Earth orbit satellite channel and network resources, in addition to the above embodiments, the system in this application embodiment further includes:

[0091] The first low-Earth orbit satellite is configured to, if it receives a Radio Resource Control (RRC) request from the first terminal and determines that the current RRC state of the first terminal is not the first preset RRC state in the saved RRC process list, determine that the first terminal is the terminal launching a DDoS attack; terminate the RRC process of the first terminal; send the first user terminal number (UEID) corresponding to the first terminal to the target data center server communicating with the first low-Earth orbit satellite; and add the first UEID to the blacklist.

[0092] Any of the other low-orbit satellites, upon receiving the first UEID sent by the other data center server, adds the first UEID to the blacklist.

[0093] Based on this, when the first LEO satellite receives the RRC request sent by the first terminal, it will first determine whether the first terminal is the terminal launching a DDoS attack. If the first LEO satellite determines that the first terminal is the terminal launching a DDoS attack, it will add the first user terminal number (User Equipment Identification, UEID) corresponding to the first terminal to the blacklist, and based on the blockchain of the target data center server communicating with the first LEO satellite, send the first UEID to other LEO satellites in the satellite IoT, so that the other LEO satellites in the satellite IoT will also add the first UEID to their blacklists.

[0094] Specifically, in this application, the first low-Earth orbit satellite stores an RRC procedure list, which includes the current RRC status of each terminal that can communicate with the low-Earth orbit satellite. If the first low-Earth orbit satellite identifies that the RRC status of the first terminal in the RRC list is not a first preset RRC status, then it determines that the first terminal is a terminal launching a DDoS attack, wherein the first preset status is an RRC idle state.

[0095] In this application, when a first terminal sends an RRC request to a first low-Earth orbit satellite, if the first terminal is not the terminal initiating a DDoS attack, it should not initiate the RRC process. Therefore, the RRC status of the first terminal in the RRC list of the first low-Earth orbit satellite should be the first preset RRC status, i.e., the RRC idle status. If the current RRC status of the first terminal is not the first preset RRC status, it means that the first terminal has already initiated an RRC request but has initiated an RRC request again. In this case, it is considered that the first terminal is currently initiating a DDoS attack, i.e., the first terminal is the terminal initiating a DDoS attack.

[0096] In this application, when the first low-orbit satellite identifies the first terminal as a terminal launching a DDoS attack, it adds the first UEID of the first terminal to the blacklist and sends the first UEID to the target data center server that is currently communicating with the first low-orbit satellite.

[0097] For any other low-Earth orbit satellite in the satellite IoT, after receiving the first UEID, the other low-Earth orbit satellite adds the first UEID to the blacklist.

[0098] Example 4:

[0099] To prevent terminals launching DDoS attacks from occupying the channel and network resources of low-Earth orbit satellites, based on the above embodiments, in this embodiment of the application, the first low-Earth orbit satellite is further configured to, if it receives an RRC request from the first terminal and determines that the current RRC status of the first terminal is a first preset RRC status, or receives an RRC completion instruction sent by the first terminal and determines that the current RRC status of the first terminal is a second preset RRC status, determine whether the first UEID of the first terminal is in the stored blacklist, and if so, terminate the RRC process of the first terminal.

[0100] In this application, if a first low-Earth orbit (LEO) satellite receives an RRC request from a first terminal and determines that the first terminal's RRC status in the saved RRC process list is a first preset RRC status, i.e., the first terminal's RRC status in the saved RRC process list is an RRC idle status, theoretically, the first LEO satellite should not be performing an RRC process at this time. However, in order to further improve the accuracy of determining whether a DDoS-initiating terminal is involved, the first LEO satellite needs to further determine whether the first terminal is the terminal that initiated the DDoS attack. If it is determined that the first terminal is the terminal that sent the DDoS attack, then it means that the RRC request is a DDoS attack, and the first LEO satellite terminates the first terminal's RRC process.

[0101] Specifically, in order to further prevent terminals launching DDoS attacks from occupying the channel and computing resources of the first low-Earth orbit satellite, in this application, if it is determined that the RRC status of the first terminal in the saved RRC process list is RRC idle, then it is determined whether the first UEID corresponding to the first terminal is in the blacklist saved by the first low-Earth orbit satellite. If it is, then the first terminal is determined to be a terminal launching a DDoS attack, and the first low-Earth orbit satellite will terminate the RRC process of the first terminal.

[0102] The RRC process is the process by which the first terminal and the first low-Earth orbit satellite establish a connection through a channel. Only when the first terminal and the first low-Earth orbit satellite are in the RRC process can the first terminal transmit data to the first low-Earth orbit satellite through the channel. Terminating the RRC process of the first terminal means stopping the provision of a channel to the first terminal.

[0103] Example 5:

[0104] To prevent a first terminal whose service identifier is not within the service range of the first low-Earth orbit satellite from communicating with the first low-Earth orbit satellite and occupying the channel and computing resources of the first low-Earth orbit satellite, based on the above embodiments, in this embodiment of the application, the first low-Earth orbit satellite is further configured to, if the first UEID is not in the blacklist stored by the first low-Earth orbit satellite, determine whether the service identifier sent by the first terminal is in the designated service identifier list of the first low-Earth orbit satellite, and if not, terminate the RRC process of the first terminal.

[0105] In this application, if the first low-orbit satellite receives an RRC request from the first terminal, determines that the first terminal is in the first preset RRC state in the RRC process list of the first low-orbit satellite, that is, the first terminal is in the RRC idle state in the RRC process list, and identifies that the first UEID corresponding to the first terminal is not in the saved blacklist, then it means that the first terminal is not the terminal that launched the DDoS attack.

[0106] However, at this point, the first LEO satellite cannot respond to the first terminal's RRC request and initiate the RRC process. This is because the RRC request might be caused by a misoperation of the first terminal; that is, the first terminal might have planned to send the RRC request to other LEO satellites, but due to the rotation and revolution of the LEO satellites, the first LEO satellite received the RRC request instead. Therefore, the first LEO satellite also needs to determine whether the first terminal's RRC request was intended for it. When making this determination, the first LEO satellite can first check whether its stored list of designated service identifiers includes the first terminal's service identifier.

[0107] Specifically, in this application, when the first terminal sends an RRC request to the first low-Earth orbit satellite, the first terminal also simultaneously sends its corresponding service identifier to the first low-Earth orbit satellite. If the first low-Earth orbit satellite determines that the first terminal is not the terminal launching a DDoS attack, then the first low-Earth orbit satellite determines whether the service identifier sent by the first terminal is within its service range. The first low-Earth orbit satellite stores its service range through a designated service identifier list; that is, the service identifiers stored in the designated service identifier list constitute the service range of the first low-Earth orbit satellite. If the first low-Earth orbit satellite detects that the service identifier of the first terminal is not included in the designated service identifier list, it determines that the service corresponding to the first terminal is not within the service range of the first low-Earth orbit satellite, and the first low-Earth orbit satellite terminates the RRC process for the first terminal.

[0108] Example 6:

[0109] To avoid situations where the low-Earth orbit satellite communicating with the first terminal is not the first low-Earth orbit satellite, but the first low-Earth orbit satellite provides services to it, thus occupying the channel and computing resources of the first low-Earth orbit satellite, based on the above embodiments, in this embodiment of the application, the first low-Earth orbit satellite is further configured to determine whether the first UEID is in the designated terminal list of the first low-Earth orbit satellite if the service identifier of the first terminal is in the designated service identifier list of the first low-Earth orbit satellite; if not, the RRC process of the first terminal is terminated.

[0110] In this application, in the satellite Internet of Things, after the first low-Earth orbit satellite determines that the first terminal sending the RRC request is not a terminal launching a DDoS attack, and that the service identifier of the first terminal is in the designated service identifier list of the first low-Earth orbit satellite, it also needs to determine whether the first low-Earth orbit satellite is the low-Earth orbit satellite designated by the management center server for the first terminal to communicate with.

[0111] Specifically, in this application, when the first terminal performs a network access operation, the low-Earth orbit (LEO) satellite designated by the management center server to communicate with the first terminal will save the first UEID corresponding to the first terminal to the instruction terminal list. Therefore, when the first LEO satellite determines whether it is the LEO satellite designated by the management center server for communication with the first terminal, it can identify whether the first UEID is included in the designated terminal list stored in the first LEO satellite. If the first UEID is not included in the designated terminal list, it is determined that the first LEO satellite is not the LEO satellite designated by the management center server for communication with the first terminal, and the first LEO satellite terminates the RRC process of the first terminal.

[0112] Example 7:

[0113] In order to enable the first low-Earth orbit satellite to execute the RRC process of the first terminal, based on the above embodiments, in this embodiment of the application, the first low-Earth orbit satellite is further configured to receive the RRC request and determine that the first UEID is in the designated terminal list of the first low-Earth orbit satellite, and then update the current RRC status of the first terminal to a second preset RRC status; or receive the RRC completion instruction and determine that the first UEID is in the designated terminal list of the first low-Earth orbit satellite, and then update the current RRC status of the first terminal to a first preset RRC status.

[0114] In order to enable the first low-Earth orbit satellite to execute the RRC process of the first terminal, based on the above embodiments, in this embodiment of the application, the first low-Earth orbit satellite is further used to continue executing the RRC process of the first terminal.

[0115] In this application, when the first low-Earth orbit (LEO) satellite receives an RRC request from the first terminal, if it determines that the first terminal is not the terminal launching a DDoS attack, and the service identifier corresponding to the first terminal is in the designated service identifier list of the first LEO satellite, and the first terminal is in the designated terminal list of the first LEO satellite, then the RRC request is determined to be an RRC request to be executed by the first LEO satellite. The first LEO satellite updates the current RRC status of the first terminal in the saved RRC process list to a second preset RRC status and executes the RRC request. The second preset RRC status is an RRC waiting state, indicating that the first LEO satellite has received the RRC request sent by the first terminal and is in the process of RRC processing, that is, the first terminal is sending data to the first LEO satellite.

[0116] Example 8:

[0117] In order to enable the first low-orbit satellite to send the UEID of the terminal launching the DDoS attack to the target data center server, based on the above embodiments, in this embodiment of the application, the first low-orbit satellite is specifically used to, if it is determined that the first terminal is the terminal launching the DDoS attack, encrypt the first UEID corresponding to the first terminal, the preset first byte encoding and the current time, and send the encrypted information to the target data center server.

[0118] In this application, when a first low-Earth orbit (LEO) satellite identifies the first terminal sending the RRC request as the terminal launching a DDoS attack, the first LEO satellite needs to send the first terminal's first UEID to other LEO satellites to prevent other LEO satellites from responding to the first terminal. However, LEO satellites cannot communicate with each other; therefore, the first LEO satellite needs to forward the first UEID to other LEO satellites based on each data center server in the blockchain.

[0119] Specifically, in this application, when a first low-Earth orbit satellite receives an RRC request from a first terminal and determines that the first terminal is the one launching a DDoS attack, the first low-Earth orbit satellite will encrypt the first UEID corresponding to the first terminal, along with a preset first byte encoding and the current time, to obtain encrypted information, and then send the encrypted information to the target data center server. In this application, the preset first byte encoding is the byte encoding corresponding to "RRC request DDoS attack," and the encryption algorithm used during encryption can be the SM9 algorithm, etc.

[0120] Example 9:

[0121] In order to complete the data transmission between the terminal and the low-orbit satellite, based on the above embodiments, in this application, the first low-orbit satellite is also used to receive the RRC completion instruction sent by the first terminal. If it is detected that the current RRC status of the first terminal is not the second preset RRC status in the saved RRC process list, the saved Network Attached Storage (NAS) data sent by the first terminal is sent to the target center server.

[0122] The target central server is also used to store the NAS data.

[0123] In this application, if a first low-Earth orbit (LEO) satellite receives an RRC completion command from a first terminal, the first LEO satellite determines whether the RRC status corresponding to the first terminal is in a second preset state in the saved RRC process list, i.e., whether the current RRC status of the first terminal is an RRC waiting state. If not, i.e., the current RRC status of the first terminal is an RRC idle state, it means that the first terminal has not received an RRC request before. The first LEO satellite then sends the saved Network Attached Storage (NAS) data sent by the first terminal to the target data center server communicating with the first LEO satellite, so that the target data center server saves the NAS data. When the first LEO satellite sends the NAS data to the target data center server, it encrypts and sends the first UEID corresponding to the first terminal, a preset second byte encoding, the NAS data, and the current time. In this application, the preset second byte encoding is the byte encoding corresponding to "RRC completed DDoS attack," and the encryption algorithm used during encryption can be any encryption algorithm, such as the SM4 algorithm.

[0124] In this application, if the first low-Earth orbit satellite receives an RRC completion instruction sent by the first terminal and determines that the current RRC status of the first terminal is the second preset RRC status, then it determines whether the first terminal is a terminal that launches a DDoS attack against other low-Earth orbit satellites, that is, it determines whether the first UEID corresponding to the first terminal is in the blacklist stored by the first low-Earth orbit satellite. If it is, then it is determined that the first terminal is a terminal that launches a DDoS attack against other low-Earth orbit satellites, and the first low-Earth orbit satellite terminates the RRC request of the first terminal.

[0125] If it is determined that the first terminal is not the terminal that launched the DDoS attack to other low-Earth orbit satellites, then it is determined whether the service identifier corresponding to the first terminal is in the designated service identifier list of the first low-Earth orbit satellite. That is, it is determined whether the designated service list of the first low-Earth orbit satellite includes the service identifier sent by the first terminal. If it is not included, then it is determined that the service identifier corresponding to the first terminal is not in the designated service identifier list of the first low-Earth orbit satellite, and the RRC process of the first terminal is terminated.

[0126] If the service identifier corresponding to the first terminal is determined to be in the designated service identifier list of the first low-Earth orbit satellite, then it is determined whether the first low-Earth orbit satellite is the low-Earth orbit satellite designated by the management center server for communication with the first terminal. That is, it is determined whether the designated terminal list stored by the first low-Earth orbit satellite includes the first UEID corresponding to the first terminal. If it does not include it, then it is determined that the first low-Earth orbit satellite is not the low-Earth orbit satellite designated by the management center server for communication with the first terminal, and the first low-Earth orbit satellite terminates the RRC process of the first terminal. If the designated terminal list stored by the first low-Earth orbit satellite includes the first UEID corresponding to the first terminal, then the first low-Earth orbit satellite determines that the currently received RRC completion instruction is not a mistake by the first terminal, and completes the RRC process of the first terminal according to the RRC completion instruction, and updates the current RRC status corresponding to the first terminal in the stored RRC process list to the first preset RRC status, that is, updates the current RRC status corresponding to the first terminal to the RRC idle status.

[0127] Figure 2 This is a schematic diagram of the structure of blockchain in satellite Internet of Things provided in the embodiments of this application, as shown in the figure. Figure 2 As shown, the blockchain includes at least a data center server, a management center server, a business center server, and a business-side server.

[0128] Example 10:

[0129] Figure 3 This application provides a schematic diagram of an anti-DDoS attack process, which includes the following steps:

[0130] S301: Receive the Radio Resource Control (RRC) request sent by the first terminal.

[0131] S302: If it is determined that the current RRC state of the first terminal is not the first preset RRC state in the saved RRC process list, then the first terminal is determined to be the terminal that launched the DDoS attack.

[0132] S303: Terminate the RRC process of the first terminal and send the first user terminal number (UEID) corresponding to the first terminal to the target data center server communicating with the first low-orbit satellite.

[0133] S304: Add the first UEID to the blacklist.

[0134] In one possible implementation, the method further includes:

[0135] Receive the RRC completion instruction sent by the first terminal;

[0136] If it is detected that the current RRC status of the first terminal is not the second preset RRC status in the saved RRC process list, then the saved Network Attached Storage (NAS) data sent by the first terminal is sent to the target central server.

[0137] In one possible implementation, the method further includes:

[0138] If an RRC request is received from the first terminal and the current RRC status of the first terminal is determined to be a first preset RRC status, or if an RRC completion instruction is received from the first terminal and the current RRC status of the first terminal is determined to be a second preset RRC status, then it is determined whether the first UEID of the first terminal is in the saved blacklist. If so, the RRC process of the first terminal is terminated.

[0139] In one possible implementation, the method further includes:

[0140] If the first UEID is not in the blacklist stored by the first low-Earth orbit satellite, then the service identifier sent by the first terminal is used to determine whether the service identifier is in the designated service identifier list of the first low-Earth orbit satellite. If not, the RRC process of the first terminal is terminated.

[0141] In one possible implementation, the method further includes:

[0142] If the service identifier of the first terminal is in the designated service identifier list of the first low-Earth orbit satellite, then it is determined whether the first UEID is in the designated terminal list of the first low-Earth orbit satellite. If not, the RRC process of the first terminal is terminated.

[0143] In one possible implementation, the method further includes:

[0144] Upon receiving the RRC request and determining that the first UEID is in the designated terminal list of the first low-Earth orbit satellite, the current RRC status of the first terminal is updated to the second preset RRC status; or upon receiving the RRC completion instruction and determining that the first UEID is in the designated terminal list of the first low-Earth orbit satellite, the current RRC status of the first terminal is updated to the first preset RRC status.

[0145] In one possible implementation, the method further includes:

[0146] Continue executing the RRC procedure of the first terminal.

[0147] In one possible implementation, sending the first UEID corresponding to the first terminal to the target data center server communicating with the first low-Earth orbit satellite includes:

[0148] If the first terminal is determined to be the terminal that launched the DDoS attack, the first UEID corresponding to the first terminal, the preset first byte encoding and the current time are encrypted, and the encrypted information is sent to the target data center server.

[0149] Example 11:

[0150] Figure 4 This is a schematic diagram of the anti-DDoS attack device provided in the embodiments of this application, as shown below. Figure 4 As shown, the device includes:

[0151] The receiving module 401 is used to receive a Radio Resource Control (RRC) request sent by the first terminal;

[0152] The processing module 402 is configured to determine that the first terminal is the terminal that launched the DDoS attack if it is determined that the current RRC state of the first terminal is not the first preset RRC state in the saved RRC process list; and terminate the RRC process of the first terminal.

[0153] The sending module 403 is used to send the first user terminal number (UEID) corresponding to the first terminal to the target data center server that communicates with the first low-orbit satellite.

[0154] The processing module 402 is further configured to add the first UEID to the blacklist.

[0155] In one possible implementation, the receiving module 401 is further configured to receive an RRC completion instruction sent by the first terminal;

[0156] The sending module 403 is further configured to send the saved Network Attached Storage (NAS) data sent by the first terminal to the target central server if it is detected that the current RRC status of the first terminal is not the second preset RRC status in the saved RRC process list.

[0157] In one possible implementation, the processing module 402 is further configured to, if it receives an RRC request from the first terminal and determines that the current RRC status of the first terminal is a first preset RRC status, or if it receives an RRC completion instruction sent by the first terminal and determines that the current RRC status of the first terminal is a second preset RRC status, determine whether the first UEID of the first terminal is in the saved blacklist, and if so, terminate the RRC process of the first terminal.

[0158] In one possible implementation, the processing module 402 is further configured to, if the first UEID is not in the blacklist stored by the first low-orbit satellite, determine whether the service identifier sent by the first terminal is in the designated service identifier list of the first low-orbit satellite, and if not, terminate the RRC process of the first terminal.

[0159] In one possible implementation, the processing module 402 is further configured to determine whether the first UEID is in the designated terminal list of the first low-Earth orbit satellite if the service identifier of the first terminal is in the designated service identifier list of the first low-Earth orbit satellite, and if not, terminate the RRC process of the first terminal.

[0160] In one possible implementation, the processing module 402 is further configured to: receive the RRC request and determine that the first UEID is in the designated terminal list of the first low-orbit satellite, then update the current RRC status of the first terminal to a second preset RRC status; or receive the RRC completion instruction and determine that the first UEID is in the designated terminal list of the first low-orbit satellite, then update the current RRC status of the first terminal to a first preset RRC status.

[0161] In one possible implementation, the processing module 402 is further configured to continue executing the RRC process of the first terminal.

[0162] In one possible implementation, the sending module 403 is specifically used to encrypt the first UEID corresponding to the first terminal, the preset first byte encoding and the current time if it is determined that the first terminal is the terminal that launched the DDoS attack, and then send the encrypted information to the target data center server.

[0163] Example 12:

[0164] Figure 5 This application provides a schematic diagram of an electronic device structure. Based on the above embodiments, this application also provides an electronic device, such as... Figure 5 As shown, it includes: processor 501, communication interface 502, memory 503 and communication bus 504, wherein processor 501, communication interface 502 and memory 503 communicate with each other through communication bus 504.

[0165] The memory 503 stores a computer program, which, when executed by the processor 501, causes the processor 501 to perform the following steps:

[0166] Receive the Radio Resource Control (RRC) request sent by the first terminal;

[0167] If it is determined that the current RRC state of the first terminal is not the first preset RRC state in the saved RRC process list, then the first terminal is determined to be the terminal that launched the DDoS attack.

[0168] The RRC process of the first terminal is terminated, and the first user terminal number (UEID) corresponding to the first terminal is sent to the target data center server communicating with the first low-orbit satellite.

[0169] Add the first UEID to the blacklist.

[0170] In one possible implementation, the method further includes:

[0171] Receive the RRC completion instruction sent by the first terminal;

[0172] If it is detected that the current RRC status of the first terminal is not the second preset RRC status in the saved RRC process list, then the saved Network Attached Storage (NAS) data sent by the first terminal is sent to the target central server.

[0173] In one possible implementation, the method further includes:

[0174] If an RRC request is received from the first terminal and the current RRC status of the first terminal is determined to be a first preset RRC status, or if an RRC completion instruction is received from the first terminal and the current RRC status of the first terminal is determined to be a second preset RRC status, then it is determined whether the first UEID of the first terminal is in the saved blacklist. If so, the RRC process of the first terminal is terminated.

[0175] In one possible implementation, the method further includes:

[0176] If the first UEID is not in the blacklist stored by the first low-Earth orbit satellite, then the service identifier sent by the first terminal is used to determine whether the service identifier is in the designated service identifier list of the first low-Earth orbit satellite. If not, the RRC process of the first terminal is terminated.

[0177] In one possible implementation, the method further includes:

[0178] If the service identifier of the first terminal is in the designated service identifier list of the first low-Earth orbit satellite, then it is determined whether the first UEID is in the designated terminal list of the first low-Earth orbit satellite. If not, the RRC process of the first terminal is terminated.

[0179] In one possible implementation, the method further includes:

[0180] Upon receiving the RRC request and determining that the first UEID is in the designated terminal list of the first low-Earth orbit satellite, the current RRC status of the first terminal is updated to the second preset RRC status; or upon receiving the RRC completion instruction and determining that the first UEID is in the designated terminal list of the first low-Earth orbit satellite, the current RRC status of the first terminal is updated to the first preset RRC status.

[0181] In one possible implementation, the method further includes:

[0182] Continue executing the RRC procedure of the first terminal.

[0183] In one possible implementation, sending the first UEID corresponding to the first terminal to the target data center server communicating with the first low-Earth orbit satellite includes:

[0184] If the first terminal is determined to be the terminal that launched the DDoS attack, the first UEID corresponding to the first terminal, the preset first byte encoding and the current time are encrypted, and the encrypted information is sent to the target data center server.

[0185] Since the principle behind the problem-solving of the above-mentioned electronic devices is similar to the method of resisting DDoS attacks, the implementation of the above-mentioned electronic devices can refer to the above embodiments, and the repeated parts will not be described again.

[0186] The communication bus mentioned in the above-mentioned electronic device can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into address bus, data bus, control bus, etc. For ease of representation, only one thick line is used in the figure, but this does not indicate that there is only one bus or one type of bus. Communication interface 502 is used for communication between the above-mentioned electronic device and other devices. The memory can include random access memory (RAM), or non-volatile memory (NVM), such as at least one disk storage device. Optionally, the memory can also be at least one storage device located remotely from the aforementioned processor. The aforementioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processing unit (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.

[0187] Example 13:

[0188] Based on the above embodiments, this application also provides a computer-readable storage medium storing a computer program executable by a processor. When the program is run on the processor, the processor executes the following steps:

[0189] Receive the Radio Resource Control (RRC) request sent by the first terminal;

[0190] If it is determined that the current RRC state of the first terminal is not the first preset RRC state in the saved RRC process list, then the first terminal is determined to be the terminal that launched the DDoS attack.

[0191] The RRC process of the first terminal is terminated, and the first user terminal number (UEID) corresponding to the first terminal is sent to the target data center server communicating with the first low-orbit satellite.

[0192] Add the first UEID to the blacklist.

[0193] In one possible implementation, the method further includes:

[0194] Receive the RRC completion instruction sent by the first terminal;

[0195] If it is detected that the current RRC status of the first terminal is not the second preset RRC status in the saved RRC process list, then the saved Network Attached Storage (NAS) data sent by the first terminal is sent to the target central server.

[0196] In one possible implementation, the method further includes:

[0197] If an RRC request is received from the first terminal and the current RRC status of the first terminal is determined to be a first preset RRC status, or if an RRC completion instruction is received from the first terminal and the current RRC status of the first terminal is determined to be a second preset RRC status, then it is determined whether the first UEID of the first terminal is in the saved blacklist. If so, the RRC process of the first terminal is terminated.

[0198] In one possible implementation, the method further includes:

[0199] If the first UEID is not in the blacklist stored by the first low-Earth orbit satellite, then the service identifier sent by the first terminal is used to determine whether the service identifier is in the designated service identifier list of the first low-Earth orbit satellite. If not, the RRC process of the first terminal is terminated.

[0200] In one possible implementation, the method further includes:

[0201] If the service identifier of the first terminal is in the designated service identifier list of the first low-Earth orbit satellite, then it is determined whether the first UEID is in the designated terminal list of the first low-Earth orbit satellite. If not, the RRC process of the first terminal is terminated.

[0202] In one possible implementation, the method further includes:

[0203] Upon receiving the RRC request and determining that the first UEID is in the designated terminal list of the first low-Earth orbit satellite, the current RRC status of the first terminal is updated to the second preset RRC status; or upon receiving the RRC completion instruction and determining that the first UEID is in the designated terminal list of the first low-Earth orbit satellite, the current RRC status of the first terminal is updated to the first preset RRC status.

[0204] In one possible implementation, the method further includes:

[0205] Continue executing the RRC procedure of the first terminal.

[0206] In one possible implementation, sending the first UEID corresponding to the first terminal to the target data center server communicating with the first low-Earth orbit satellite includes:

[0207] If the first terminal is determined to be the terminal that launched the DDoS attack, the first UEID corresponding to the first terminal, the preset first byte encoding and the current time are encrypted, and the encrypted information is sent to the target data center server.

[0208] Since the principle of solving the problem using the computer-readable medium provided above is similar to the method for resisting DDoS attacks, the steps implemented after the processor executes the computer program in the computer-readable medium can be referred to the above embodiments, and the repeated parts will not be described again.

[0209] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0210] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0211] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0212] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0213] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. A system for resisting distributed denial-of-service (DDoS) attacks, characterized in that, The system includes: The first low-Earth orbit satellite is configured to, upon receiving a Radio Resource Control (RRC) request from a first terminal and determining that the current RRC state of the first terminal is not a first preset RRC state in the saved RRC process list, identify the first terminal as a terminal launching a DDoS attack; terminate the RRC process of the first terminal; send the first user terminal number (UEID) corresponding to the first terminal to the target data center server communicating with the first low-Earth orbit satellite; and add the first UEID to the blacklist; wherein, the first preset RRC state is an RRC idle state. The target data center server is used to receive the first UEID corresponding to the first terminal that launched the DDoS attack, which is sent by the first low-orbit satellite, and broadcast the first UEID to other data center servers in the blockchain. Any of the other data center servers is configured to, upon receiving the first UEID broadcast by the target data center server, send the first UEID to other low-Earth orbit satellites communicating with the other data center server, so that the other low-Earth orbit satellites add the first UEID to their blacklist.

2. The system according to claim 1, characterized in that, The system also includes: The service center server is used to receive the service identifier sent by the second terminal if a newly connected second terminal is identified, and to assign a second UEID to the second terminal, as well as the number of low-orbit satellites communicating with the second terminal, and to broadcast the service identifier of the second terminal, the second UEID and the number to the management center server in the blockchain. The management center server is used to receive the service identifier, the second UEID, and the quantity broadcast by the service center server; determine the second low-orbit satellite that communicates with the second terminal based on the service identifier, the quantity, and the service range of each low-orbit satellite stored, and broadcast the correspondence between the second UEID and the second low-orbit satellite to each data center server in the blockchain; Any of the data center servers is configured to receive and store the correspondence between the second UEID and the second low-Earth orbit satellite; if it is detected that communication with the second low-Earth orbit satellite is currently taking place, the second UEID is sent to the second low-Earth orbit satellite, so that the second low-Earth orbit satellite saves the second UEID to a designated terminal list.

3. The system according to claim 1, characterized in that, The system also includes: Any of the other low-orbit satellites, upon receiving the first UEID sent by the other data center server, adds the first UEID to the blacklist.

4. The system according to claim 1, characterized in that, The first low-orbit satellite is also used to receive the RRC completion command sent by the first terminal. If it is detected that the current RRC status of the first terminal is not the second preset RRC status in the saved RRC process list, the saved Network Attached Storage (NAS) data sent by the first terminal is sent to the target center server. The target central server is also used to store the NAS data.

5. The system according to claim 1 or 4, characterized in that, The first low-orbit satellite is further configured to, if it receives an RRC request from the first terminal and determines that the current RRC status of the first terminal is a first preset RRC status, or if it receives an RRC completion instruction sent by the first terminal and determines that the current RRC status of the first terminal is a second preset RRC status, determine whether the first UEID of the first terminal is in the saved blacklist, and if so, terminate the RRC process of the first terminal.

6. The system according to claim 5, characterized in that, The first low-orbit satellite is further configured to, if the first UEID is not in the blacklist stored by the first low-orbit satellite, determine whether the service identifier sent by the first terminal is in the designated service identifier list of the first low-orbit satellite, and if not, terminate the RRC process of the first terminal.

7. The system according to claim 6, characterized in that, The first low-Earth orbit satellite is further configured to determine whether the first UEID is in the designated terminal list of the first low-Earth orbit satellite if the service identifier of the first terminal is in the designated service identifier list of the first low-Earth orbit satellite; if not, terminate the RRC process of the first terminal.

8. The system according to claim 7, characterized in that, The first low-orbit satellite is also configured to receive the RRC request and, if it determines that the first UEID is in the designated terminal list of the first low-orbit satellite, update the current RRC status of the first terminal to a second preset RRC status. If the RRC completion instruction is received and it is determined that the first UEID is in the designated terminal list of the first low-orbit satellite, then the current RRC status of the first terminal is updated to the first preset RRC status.

9. The system according to claim 8, characterized in that, The first low-orbit satellite is also used to continue executing the RRC process of the first terminal.

10. The system according to claim 3, characterized in that, The first low-orbit satellite is specifically used to encrypt the first UEID, the preset first byte encoding, and the current time corresponding to the first terminal if it is determined that the first terminal is the terminal that launched the DDoS attack, and then send the encrypted information to the target data center server.

11. A method for resisting DDoS attacks, characterized in that, The method includes: The first low-Earth orbit satellite is configured to, upon receiving a Radio Resource Control (RRC) request from a first terminal and determining that the current RRC state of the first terminal is not a first preset RRC state in the saved RRC process list, identify the first terminal as a terminal launching a DDoS attack; terminate the RRC process of the first terminal; send the first user terminal number (UEID) corresponding to the first terminal to the target data center server communicating with the first low-Earth orbit satellite; and add the first UEID to the blacklist; wherein, the first preset RRC state is an RRC idle state. The target data center server is used to receive the first UEID corresponding to the first terminal that launched the DDoS attack, which is sent by the first low-orbit satellite, and broadcast the first UEID to other data center servers in the blockchain. Any of the other data center servers is configured to, upon receiving the first UEID broadcast by the target data center server, send the first UEID to other low-Earth orbit satellites communicating with the other data center server, so that the other low-Earth orbit satellites add the first UEID to their blacklist.

12. An electronic device, characterized in that, The electronic device includes at least a processor and a memory, wherein the processor is used to implement the steps of the anti-DDoS attack method of claim 11 when executing a computer program stored in the memory.

13. A computer-readable storage medium, characterized in that, It stores a computer program that, when executed by a processor, implements the steps of the anti-DDoS attack method as described in claim 11.