A pre-decision method and device based on a switching path diagram

By generating a handover path map and combining it with EWM and TOPSIS assessments, the problem of frequent topology changes between satellite nodes in the integrated space-ground network was solved, achieving precision and optimization of secure handover, ensuring trust transfer and seamless handover, and improving network service quality.

CN116781604BActive Publication Date: 2026-04-17Chinese People's Liberation Army Cyberspace Force Information Engineering University
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Chinese People's Liberation Army Cyberspace Force Information Engineering University
Filing Date
2023-07-14
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

In integrated space-ground networks, existing technologies fail to effectively consider the complex topological relationships and movement between satellite nodes, resulting in frequent changes in network topology and affecting users' safe handover options. In particular, it is difficult to achieve the pre-transmission of handover authentication messages in the case of multi-satellite redundant coverage in three-dimensional network space.

Method used

A pre-decision method based on handover path maps is adopted. By acquiring the satellite's nadir trajectory and coverage, a safe handover path map is generated. Combined with EWM and TOPSIS evaluations, the optimal safe handover scheme is selected, providing a pre-decision device for safe handover.

Benefits of technology

It achieves precise and optimized service for secure handover in complex network environments, ensuring pre-delivery of trust and seamless handover, reducing network disturbances, and improving network service quality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116781604B_ABST
    Figure CN116781604B_ABST
Patent Text Reader

Abstract

This invention discloses a pre-decision method and apparatus based on a handover path map, comprising the following steps: Step S1, obtaining a handover path map of the target node for secure handover in a space-air-ground integrated network; Step S2, obtaining an effective secure handover path based on the node relationships in the handover path map; Step S3, comprehensively evaluating and scoring the effective secure handover path to select the optimal secure handover scheme. By employing this invention, a reference for selecting a secure handover target node is provided for users in complex network coverage situations, achieving accurate and optimized secure handover services.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of integrated space-ground network technology, and more specifically, to a pre-decision method and apparatus based on a switching path diagram. Background Technology

[0002] Current research on integrated space-ground network security handover largely addresses the pre-decision problem by directly selecting from a given set of candidate satellites and assuming message transmission between two satellite nodes, without considering the complex topological relationships and movement of these nodes. However, in real-world space scenarios, the high-speed movement of satellite access nodes in integrated space-ground networks leads to continuous changes in network topology, posing a significant challenge to trust transfer; moreover, in situations such as… Figure 1 In the three-dimensional cyberspace shown, the complex arrangement and wide distribution of satellites lead to redundant coverage by multiple satellites when users initiate secure handovers, severely impacting their handover choices. Therefore, how to pre-transmit handover authentication messages in this crisscrossing, dynamic three-dimensional cyberspace is a pressing problem that needs to be solved. Summary of the Invention

[0003] In view of the above problems, this application is proposed to provide a pre-decision method and apparatus based on a handover path map, which provides users in complex network coverage situations with a reference for selecting a safe handover target node, thereby achieving accurate and optimized safe handover services.

[0004] The specific plan is as follows:

[0005] A pre-decision method based on a switching path graph includes the following steps:

[0006] Step S1: Obtain the handover path diagram for users to securely switch target nodes in the integrated space-ground network;

[0007] Step S2: Obtain a valid and safe switching path based on the node relationships in the switching path diagram;

[0008] Step S3: Conduct a comprehensive evaluation and scoring of the effective and secure switching paths, and select the best secure switching scheme.

[0009] Preferably, step S1 includes:

[0010] Step 11: The user's currently accessed satellite obtains the nadir trajectory of other satellites by acquiring the ephemeris tables of other satellites in the region;

[0011] Step 12: Based on the aforementioned sub-satellite point trajectory, analyze the satellite coverage of the user's location in the future to obtain the user's safe handover path map.

[0012] Preferably, in step S2, an effective and secure switching path is obtained by pre-transmitting trust information between the current access node and the target node in the switching path diagram under intermittent link connectivity.

[0013] As a preferred option, in step S3, a performance evaluation based on EWM and TOPSIS is conducted, and the best safe handover scheme is selected based on the user's preference, using the fewest number of handovers or the best service quality as the selection criteria.

[0014] The present invention also provides a pre-decision device based on a switching path graph, comprising:

[0015] The acquisition module is used to acquire the switching path map of the target node for secure switching by users in the integrated space-ground network;

[0016] The first processing module is used to obtain a valid and safe switching path based on the node relationships in the switching path diagram.

[0017] The second processing module is used to comprehensively evaluate and score the effective and secure switching paths, and select the best secure switching scheme.

[0018] Preferably, the acquisition module includes:

[0019] The first processing unit is used to enable the user's currently accessed satellite to obtain the nadir trajectory of other satellites by acquiring the ephemeris tables of other satellites in the region;

[0020] The second processing unit is used to analyze the satellite coverage of the user's location in the future based on the nadir point trajectory, and obtain the user's safe handover path map.

[0021] Preferably, the first processing module pre-transmits information based on the trust between the current access node and the target node in the intermittent link connectivity environment in the switching path diagram to obtain an effective and secure switching path.

[0022] As a preferred option, the second processing module uses EWM and TOPSIS for performance evaluation and selects the best safe handover scheme based on user preferences, using the fewest handovers or the best service quality as selection criteria.

[0023] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0024] This invention employs three technical means—the generation of handover path diagrams, the generation of effective paths, and the evaluation of handover path benefits—to achieve the evaluation and selection of the optimal secure handover path, providing guidance for rapid, seamless, and secure handover while also pre-transmitting handover signaling. Attached Figure Description

[0025] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the scope of this application. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings:

[0026] Figure 1 A schematic diagram illustrating the pre-decision method for safe handover in complex orbital scenarios;

[0027] Figure 2 This is a schematic diagram of the basic framework of a pre-decision mechanism based on a switching path graph;

[0028] Figure 3 This is a schematic diagram of the pre-decision method based on switching path graph according to an embodiment of the present invention;

[0029] Figure 4 This is a schematic diagram showing the position of the satellite's nadir point on the sphere.

[0030] Figure 5 This is a schematic diagram illustrating the satellite's coverage radius for users.

[0031] Figure 6 This is a schematic diagram illustrating the time distribution of continuous coverage for users by access nodes;

[0032] Figure 7 Switch the path map for the user;

[0033] Figure 8 This is a schematic diagram illustrating the intermittent connectivity of inter-satellite links.

[0034] Figure 9 A diagram illustrating the lookup process for the trust transfer link, wherein, Figure 9 (a) Taking the selected optimal switching destination node as the starting point, find its position in (t) Start ,t End If any of the neighboring nodes within the time period (t) are the user's current access node, then for these neighboring nodes within the time period (t)... Start ,t End The process involves searching for neighboring nodes within the current node's range until the current node is found within the time and hop count range, and then determining a schematic diagram of the transmission link from the current node to the destination node based on the neighbor relationships. Figure 9 (b) If the current node is not found within the time period or the maximum search hop count, it means that there is no time interval (t) between the current node and the target node. Start ,t End The diagram illustrates how, if the transmission link within the candidate set cannot achieve the pre-transmission of the user's trusted identity, a suboptimal node is selected from the candidate set to continue searching for the link.

[0035] Figure 10A schematic diagram of the benefit evaluation process for switching path nodes;

[0036] Figure 11 A schematic diagram of the sorting process for selecting the benefits of switching paths. Detailed Implementation

[0037] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0038] This application provides a pre-decision method and apparatus based on a handover path map, which provides users in complex network coverage situations with a reference for selecting target nodes for secure handover, thereby achieving accurate and optimized secure handover services.

[0039] This invention provides a pre-decision method based on a switching path graph, aimed at meeting the need for advance prediction and analysis of user security events in the future. Figure 2As shown, this framework uses satellites in high Earth orbit as core nodes for regional division. Each core node satellite is responsible for assisting the ground control center in managing the numerous LEO satellite nodes it covers. It is also responsible for periodically updating and maintaining the status information of LEO satellites within its jurisdiction and providing services such as information querying and routing forwarding for LEO satellites and users. First, when a user initially accesses the coverage area of ​​a core node, the user reports their movement route or current direction of movement to the current access node. When the route or direction changes, it is reported to the current access node for correction. The access node can send a request to the core node to obtain information about other access satellite nodes that will pass through this area, such as ephemeris tables and attribute status. Since the user's movement speed is much lower than the movement speed of the LEO satellites, and the user moves along roads or predetermined routes, for ease of trajectory analysis, the user's movement path can be considered as one or more curves with relatively large curvature connected together. Secondly, by acquiring ephemeris tables of other satellites in the region, the current satellite being accessed by the user can predict the trajectories of other satellites. Combined with the user's movement data, the system analyzes the user's trajectory and the coverage of the accessed satellites over a future period, obtaining the coverage relationship between the satellites in the region and the user in the future. This generates a safe handover path map for the user. Based on the link establishment status between satellite nodes, effective safe handover paths are selected from the path map. Finally, the access satellite attribute information obtained from the core nodes and the coverage time information obtained from the user trajectory analysis are summarized for a multi-attribute comprehensive evaluation. Possible safe handover paths are comprehensively assessed and scored. Based on the user's preferences, the optimal safe handover scheme is selected using the fewest handovers or the best service quality as selection criteria.

[0040] like Figure 3 As shown, this embodiment of the invention provides a pre-decision method based on a switching path graph, including the following steps:

[0041] Step S1: Obtain the handover path diagram for users to securely switch target nodes in the integrated space-ground network;

[0042] Step S2: Obtain a valid and safe switching path based on the node relationships in the switching path diagram;

[0043] Step S3: Conduct a comprehensive evaluation and scoring of the effective and secure switching paths, and select the best secure switching solution based on the user's preferences, using the fewest number of switching operations or the best service quality as the selection criteria.

[0044] As one embodiment of the present invention, step S1 includes:

[0045] Step 11: The user's currently accessed satellite obtains the nadir trajectory of other satellites by acquiring the ephemeris tables of other satellites in the region;

[0046] Step 12: Based on the aforementioned sub-satellite point trajectory, analyze the satellite coverage of the user's location in the future to obtain the user's safe handover path map.

[0047] Furthermore, to achieve satellite positioning and management in space, system administrators create an ephemeris for each satellite and update it regularly. The ephemeris contains crucial information such as the satellite's number, launch time, and orbital parameters. Using the orbital parameters provided in the ephemeris, important information such as the satellite's speed and azimuth at a future point in time can be calculated. Therefore, to enable pre-judgment of safe user handover, it is necessary to analyze satellite motion patterns and predict and analyze satellite coverage at the user's location in the future.

[0048] First, the network coverage of the user is analyzed. Within the user's mobile area, the nadir trajectory of satellites passing through that area is predicted. Based on the nadir point and coverage radius of the satellites, the start and end positions and time when a satellite provides coverage to the user are calculated. Furthermore, this embodiment of the invention also considers the influence of the Earth's rotation on the nadir trajectory and, combined with the orbital parameters provided by satellite ephemeris, proposes a method for calculating the nadir position of a satellite at any given time. The satellite orbital parameters and names used in this embodiment of the invention are shown in Table 1.

[0049] Table 1

[0050]

[0051] In such Figure 4 In the WGS-84 coordinate system shown, the satellite passes through the ascending node Ω0 at time t0 and its longitude is p0. S is the position of the satellite's nadir at time t and its latitude and longitude coordinates are (p, q). Ω is the ascending node after the satellite's orbit has shifted relative to the Earth from t0 to t. α is the intersection of the meridian passing through the nadir point S and the equator.

[0052] First, the average angular velocity ω of the satellite is calculated from the known parameters. s :

[0053]

[0054] Let Δt be the time it takes for the satellite to travel from Ω0 to S. Then Δt = t - t0, and we can determine the length of the path the satellite travels along its orbit during this time:

[0055] ΩS=ω s Δt (2)

[0056] The offset length of the ascending node is:

[0057] Ω0Ω=ω e Δt (3)

[0058] In the right-angled spherical triangle ΔΩSα, since ∠SΩα is the orbital inclination of the satellite, ∠SΩα=i, thus obtaining sinSα=sinΩSsini, that is:

[0059] sinq=sinω s Δtsini (4)

[0060] Therefore, the latitude of the sub-star point S is...

[0061] q = arcsin(sinω) s Δtsini) (5)

[0062] In the right-angled spherical triangle ΔΩ0Sα, we can obtain the following from the cosine formula for the sides and the formula for the first five elements:

[0063] cosSΩ0=cosΔpcosq (6)

[0064] sinSΩ0cos∠SΩ0α=sinΔpcosq (7)

[0065] Then, from equations (5) and (6) and the cosine relationship in the spherical triangle ΔΩ0ΩS, we can know that:

[0066]

[0067] Therefore, the longitude of point S beneath the star is:

[0068]

[0069] Therefore, the latitude and longitude coordinates S(p,q) of the satellite's nadir at time t can be represented by equations (1), (5), and (9).

[0070] Next, we will analyze the satellite's coverage radius for users, such as... Figure 5 This indicates the coverage of a user at altitude h by a satellite with altitude H and a ground coverage radius of R:

[0071] Figure 5 In this context, S is the nadir point of the satellite, O is the satellite's location, E is the satellite's Earth coverage boundary, S′ is the intersection of the user's plane and OS, and F is the intersection of the user's plane and OE. Therefore, ΔOSE ~ ΔOS'F, and thus the satellite's coverage radius over the user's plane is:

[0072]

[0073] Since the prediction of the nadir trajectory was achieved above, and this is combined with the analysis of the relative position of the satellite and the user, as well as the coverage radius, it is easy to know the satellite coverage situation for the user in the future. For example... Figure 6 As shown in the diagram, this illustrates a scenario where a user within the core node's jurisdiction is covered by multiple access nodes over a future period of time:

[0074] From the time distribution of continuous coverage for users by access nodes, it can be observed that multiple access nodes simultaneously provide coverage to users during certain time periods. The foundation for ensuring a safe handover for users lies in the simultaneous coverage by both the current access node and the target node. Therefore, two access nodes that can simultaneously provide coverage to a user within a certain time period can be considered as having the potential to support a safe handover for that user. However, in real-world scenarios, the successful execution of a safe handover is constrained by factors such as user needs, node performance, and the link status between nodes. To effectively depict the trajectory of a user's safe handover between access nodes, this embodiment of the invention uses a safe handover path graph to analyze the predicted user safe handover schemes. Furthermore, to ensure the safe handover path graph has practical reference value, the following definitions and rules are given for its generation:

[0075] Definition 1: Security Handover Graph: Each satellite that can provide coverage to a user can be represented by a vertex V in the graph. There is an edge E between two satellites that can provide coverage to a user at the same time. Therefore, the user's security handover graph can be represented as G = (V, E).

[0076] Definition 2: Start Node: The access node where a user is located when the security handover path map is generated. There is only one start node for each user.

[0077] Definition 3: Farthest Node: In the continuous coverage time distribution map generated for each user, the access node that is the latest to end coverage for the user may exist. There may be multiple farthest nodes.

[0078] Definition 4: Secure handover footprint (Step): The process by which a user switches from their current node to the next directly connected access node, represented as a directed edge E in the secure handover path graph.

[0079] Definition 5 Safe handover path: A path consisting of several safe handover footprints that can reach the farthest point from the starting point.

[0080] Define 6-node depth: The node depth is the shortest hop distance between each access node and the starting node on the handover path graph, where the depth of the starting node is 0.

[0081] Definition 7: Previous node: If access node j is directly pointed to by node i on the switching path graph, then i is called the previous node of j.

[0082] Definition 8: Next node: If access node i directly points to node j on the switching path graph, then j is called the next node of i.

[0083] Rule 1: Core nodes continuously monitor access nodes whose tracks pass through their jurisdiction. The rule is described as follows:

[0084] if Orbit(LEO i )cross Area x then

[0085] LEO i ∈Area x

[0086] Area x refresh State of LEO i periodically

[0087] else Ignore

[0088] end if

[0089] Rule 1 describes the method for defining which access nodes a core node should include under its jurisdiction. Because satellite movement is periodic, any access node that will pass through the jurisdiction of a core node, even if it is not currently within the coverage area of ​​that core node, may become the handover access target for users within the area during its transit. Simultaneously, to ensure the quality of users' pre-determined service, the core node in this region should periodically update the status information of these access nodes from other core nodes.

[0090] Rule 2 stipulates that two access nodes must simultaneously provide coverage to users within a certain period of time. This is a necessary condition for users to securely switch between the two nodes. The rule is described as follows:

[0091]

[0092] MN can execute handover from(LEO i →LEO j LEO j →LEO i )

[0093] else MN can not execute handover between LEOi and LEO j

[0094] end if

[0095] Rule 2 describes the method for determining whether a user can securely switch between two access nodes. For example... Figure 6 The denoted by represents the duration of continuous coverage for a user by a single access node. A prerequisite for a handover is that the user is simultaneously covered by both the previous and newer nodes during the handover process. Therefore, for satellite i before the handover and satellite j after the handover, it is necessary to ensure that the user is covered by j before the coverage of i ends, i.e., t. iB <t jB <t iE .

[0096] Rule 3: Once a user has connected to a satellite node, the user will not use that satellite node as a safe handover target again until the node leaves and re-enters the area. The rule is described as follows:

[0097] if LEO i is the previous node of MN then

[0098] MN handover to LEO i is forbidden

[0099] until LEO i Leave the Area x and return

[0100] end if

[0101] Rule 3 describes the ping-pong effect that may occur during a user's safe handover selection process and proposes a solution to avoid the problem of users reverting to their original access node when selecting a target. This is because in real-world scenarios, simply meeting the condition of simultaneous coverage is insufficient, as in... Figure 6 The coverage relationship between LEO5 and LEO6 for users satisfies t 6B <t 5B <t 6E However, due to t 5E <t 6E This means that if a user performs an operation to switch from LEO6 to LEO5, the time t at which the LEO5 coverage ends will be terminated. 5E It was earlier than the end of its coverage period at LEO6. 6E Furthermore, there's a possibility of being forced to switch back to LEO6, which clearly contradicts actual needs. Therefore, the condition in rule 2 should be elevated to t.iB <tj B <t iE <t jE Therefore, there is no loop from i→j→i (after the access node i finishes covering the user, it will re-analyze i when it returns via a loop).

[0102] Based on the above definitions and rules, the handover path graph generated by the access node based on the continuous coverage time relationship of users is a directed acyclic graph (DAG), and the handover path graph generation algorithm is as follows:

[0103]

[0104] Algorithm 1 pair Figure 2 The processing generates a switching path diagram as follows: Figure 7 In a handover path diagram, directed paths represent nodes that can simultaneously provide network coverage to the user, representing potential access targets. S represents the benefit of each handover footprint (Step). Without considering cost and benefit, any node pointed to by these paths could be a user's handover target node. However, in real-world scenarios, whether a node pointed to by an arrow on a path can become a user's handover target node depends not only on its coverage but also on factors such as node performance and user needs, in order to select the handover path that brings the best benefit to the user.

[0105] As one embodiment of the present invention, in step S2, an effective and secure switching path is obtained by pre-transmitting trust information between the current access node and the switching target node in the switching path diagram under intermittent link connectivity.

[0106] To accurately analyze the relationships between nodes in the user switching path graph and extract valuable information, Figure 7 By analyzing the switching path diagram in the middle, we can obtain Figure 7 The connectivity relationships of the nodes in the table are shown in Table 2 below:

[0107] Table 2

[0108]

[0109] right Figure 7 After performing a depth-first search (DFS) traversal from the starting node to the farthest node, the following potential switching paths can be output:

[0110] Path 1: L1 = ①→②→⑤→⑦

[0111] Path 2: L2 = ①→②→⑥→⑦

[0112] Path 3: L3 = ①→②→④→⑤→⑦

[0113] Path 4: L4 = ①→②→⑤→⑥→⑦

[0114] Path 5: L5 = ①→②→④→⑤→⑥→⑦

[0115] Path 6: L6 = ①→③→②→⑤→⑦

[0116] Path 7: L7 = ①→③→②→⑥→⑦

[0117] Path 8: L8 = ①→③→④→⑤→⑦

[0118] Path 9: L9 = ①→③→②→④→⑤→⑦

[0119] Path 10: L 10 = ①→③→②→⑤→⑥→⑦

[0120] Path 11: L 11 = ①→③→④→⑤→⑥→⑦

[0121] Path 12: L 12 = ①→③→②→④→⑤→⑥→⑦

[0122] Analyzing the output paths, taking paths 1 and 6 as examples, path 1 allows a direct switch from node ① to node ②, while path 6 requires a switch from node ① to node ③ first, and then from node ③ to node ②. The subsequent switching footprints are the same for both paths. Considering the overhead of the switching process, the additional switching footprint via node ③ in path 6 compared to path 1 is unnecessary. As for paths 1 and 7, although path 7 has more switching footprints than path 1, potentially incurring additional switching overhead, the footprints of the two paths are different. While path 7 increases the number of switches, it may potentially provide users with better network service. Therefore, the paths output from the switching path graph can be further filtered using the following two rules:

[0123] Rule 4 retains valid paths and discards redundant paths. The rule is described as follows:

[0124] If {Step}X is a set of PathX, then

[0125] Keep PathA, delete pathB

[0126] end if

[0127] Rule 4 analyzes the method for distinguishing between valid paths and redundant paths. The specific implementation method is described as follows: Taking the connectivity relationship of access nodes in Table 2 as the description object, in order to extract valid paths and avoid meaningless switching, for i and j with the same Depth value, if i is the previous node of j, then when i and j are both the next node of node x, a valid path cannot be output with i as the footprint.

[0128] Rule 5 selects a safe handover path with the fewest handovers or the highest average benefit based on user preferences. The rule is described as follows:

[0129] if MN needs minimumhandover times then

[0130] select the Path with the fewest steps

[0131] else if MN needs maximumhandover benefit then

[0132] select the Path with the maximumaverage benefit

[0133] end if

[0134] Rule 5 describes the path evaluation and selection criteria determined by user preferences. To reduce network disturbances during handover, the criterion can be the minimum number of handovers; or to obtain better network service quality in the long term, the criterion can be the optimal handover path benefit.

[0135] According to rule 4, Figure 7 The 12 candidate paths obtained after line processing are filtered again, and the output is as follows:

[0136] Path 1: L1 = ①→②→⑤→⑦

[0137] Path 2: L2 = ①→②→⑥→⑦

[0138] Path 8: L8 = ①→③→④→⑤→⑦.

[0139] Since the above three switching paths are candidate paths selected through multiple rules, they better meet real-world needs and have practical reference value compared to other potential switching paths. Therefore, the paths obtained after selection can be called effective switching paths. The effective switching path generation algorithm is obtained by organizing the above rules and processes as follows:

[0140]

[0141] Due to the staggered distribution of satellite orbits, the spatiotemporal span between nodes is large and there is high-speed relative motion, so the links between satellites belonging to different orbits are usually intermittent.

[0142] Figure 8 The text describes a scenario that could lead to intermittent inter-satellite link connectivity. It describes a region of a space-based access network with three intersecting orbits, where satellite nodes B and C are at position t. a An inter-satellite link always exists, but because both satellites move at high speeds along their respective orbits, the distance between the nodes exceeds a certain limit, preventing the establishment of another inter-satellite link. Therefore, at t... b At time t, the inter-satellite link between nodes BC is disconnected; while the inter-satellite link between nodes A and D was originally at time t. a There is no inter-satellite link at any given time, but at t b When the positions of two nodes meet the conditions for establishing a link, a new link is established.

[0143] Therefore, to achieve the pre-transfer of user trust in a secure handover scheme, it is necessary not only to study the coverage relationship between users and access nodes, but also to consider the pre-transfer of trust between the current access node and the handover target node in an environment of intermittent link connectivity. Since this chapter implements trajectory prediction for satellite nodes, the ground control center can formulate a plan based on the temporal and spatial distribution of each satellite node, specifying the objects to which nodes will establish inter-satellite links and the start and end times, thus forming an inter-satellite adjacency link timetable, as shown in Table 3.

[0144] Table 3

[0145]

[0146] Using a pre-defined inter-satellite adjacency link timetable, a trusted recommended message forwarding link is found from the current access node to the switching destination node. The search method is as follows:

[0147] Let t Start and t End These represent the earliest start time and latest end time of the user's safe handover preparation phase, respectively, and the average single-hop latency on the network is T. Hop Then in (t) Start ,t End During this period, the furthest number of hops required to achieve one-way propagation from the current node to the target node is:

[0148]

[0149] N here HopThis is an ideal value, obtained by rounding down the ratio of the total preparation phase time to the average single-hop latency. Since link establishment between nodes may involve waiting time, in real-world scenarios, the furthest one-way propagation hops from the current node to the target node are often less than N. Hop Therefore, with N Hop As the maximum number of search hops, it can effectively determine the search range of the transmission link.

[0150] like Figure 9 As shown, the optimal switching destination node is selected as the starting point, and its position in (t) is searched. Start ,t End If any of the neighboring nodes within the time period (t) are the user's current access node, then for these neighboring nodes within the time period (t)... Start ,t End The process involves searching for neighboring nodes within a given range until the current node is found within the time and hop count range. Based on the neighbor relationships, the propagation path from the current node to the destination node is determined. This process is as follows: Figure 9 As shown in (a); if the current node is not found within the time period or the maximum search hop count, it means that there is no time interval (t) between the current node and the target node. Start ,t End If the transmission link within the current node cannot achieve the pre-transmission of the user's trusted identity, then a suboptimal node is selected from the candidate set to continue searching for the link. Figure 9 As shown in (b).

[0151] The inter-node forwarding link lookup algorithm obtained by the above method is expressed as follows:

[0152]

[0153] As one embodiment of the present invention, in step S3, performance evaluation is performed based on EWM and TOPSIS, and the best security handover scheme is selected based on the user's preference, using the fewest number of handovers or the best service quality as the selection criteria.

[0154] Furthermore, in order to evaluate the path options and select the most suitable switching path for the user, the user's needs are usually reflected in the following aspects:

[0155] (1) Network performance: Commonly used indicators to directly describe the performance of satellite wireless networks include bandwidth, signal strength, maximum elevation angle, packet loss rate, and transmission delay.

[0156] (2) Communication Retention: To avoid the impact of frequent network handovers, users need to ensure a relatively long continuous coverage period from each satellite. This refers to the remaining service time between when a user enters a satellite and when they leave its coverage area, which is related to their relative location when switching to the satellite's coverage area. From the previous... Figure 6 Based on the distribution of continuous coverage time for users by the access node, it can be seen that for the same handover destination node, the remaining service time is different for users entering from different previous nodes.

[0157] (3) External Evaluation: User satisfaction with network services directly reflects the security capabilities of a satellite node. Therefore, the rating records of the node by users in this region are selected as a reference. At the same time, in order to ensure the secure implementation of user services in the network, it is necessary to understand the security risks existing on the network nodes in a timely manner. Therefore, the network risk level of the access node is included in the evaluation attribute set.

[0158] Therefore, bandwidth, signal strength, maximum elevation angle, user satisfaction, and remaining service time are categorized as benefit-type attributes; higher values ​​for these attributes indicate better performance. Packet loss rate, transmission latency, resource utilization, and security risk level are classified as cost-type attributes because they can negatively impact users, and their values ​​should be kept as low as possible. Based on the above analysis, the handover footprint performance evaluation task is solved as a multi-attribute decision problem, and the following suggestions are proposed: Figure 10 The benefit evaluation process for nodes on the switching path is shown.

[0159] When evaluating a target solution based on its performance across multiple attributes, issues often arise such as inconsistent attribute measurement methods, significant numerical fluctuations, and difficulty in weighing the importance of attributes, affecting the objectivity and rationality of the decision-making process. To address this, this invention employs a method combining EWM and TOPSIS to evaluate the effectiveness of the handover footprint.

[0160] The Entropy Weight Method (EWM) is a relatively ideal objective weighting method. This method is based on the concept of information entropy, where entropy represents the degree of disorder in a system. The higher the entropy value, the more disordered the system, and the more information it reflects, thus giving it a higher weight in the overall evaluation. Therefore, the weight of an attribute in the comprehensive evaluation can be determined by calculating the numerical dispersion of that attribute. The Technique for Order Preference by Similarity to an Ideal Solution (TOPSIS) selects the optimal and worst values ​​of each attribute to form ideal solutions. The best solution is selected based on the principle that the evaluated object is as close as possible to the optimal solution and as far away as possible from the worst solution. This invention employs an access node performance evaluation method based on a combination of EWM and TOPSIS, with the following specific steps:

[0161] Step 1: Collection and organization of raw data. Assuming there are m edges (safe handover footprints) on the safe handover path graph and n evaluation attributes, the raw indicator data can be represented by a matrix as follows:

[0162]

[0163] Where, x i,j Let j represent the value of the j-th attribute of the i-th safe switching footprint, where i = 1, 2, ..., m and j = 1, 2, ..., n.

[0164] Step 2: For the j-th attribute, calculate the proportion of that attribute in the i-th switching footprint sample:

[0165]

[0166] Step 3: Calculate the entropy value of the j-th attribute:

[0167]

[0168] Among them, e j ∈[0,1], and the redundancy of the information entropy can be obtained as:

[0169] d j =1-e j (15)

[0170] Step 4: The weight of attribute j can be further determined from the information entropy redundancy:

[0171]

[0172] Step 5: Since the attribute set includes cost-related attributes such as packet loss rate (PL), transmission delay (TD), resource utilization (RU), and risk level (SR), lower values ​​for these attributes are generally better. They cannot be processed simultaneously with benefit-related attributes such as bandwidth (BD) and signal strength (SI). Therefore, cost-related attributes need to be processed separately (x max The -x) operation is then performed, followed by normalization:

[0173]

[0174] Step 6: The weighting matrix can then be obtained from equations (5) and (6):

[0175]

[0176] Step 7: Find the optimal and worst solutions from matrix K:

[0177]

[0178]

[0179] Step 8: Calculate the distance between each of the i switching options and the optimal and worst solutions respectively:

[0180]

[0181]

[0182] Step 9: Since the goal of the TOPSIS method is to move as far away from the worst solution as possible and as close to the optimal solution as possible, the performance evaluation value of the safe switching footprint can be represented by the degree of proximity to the optimal solution:

[0183]

[0184] As can be seen from equation (24), the range of the evaluation value is [0,1].

[0185] Finally, the final safe handover path is selected according to rule 5. Let path L be... i The number of switching times is N(L) i The benefit of switching footprints is S. i .

[0186] If the user's preference is the minimum number of handovers, then select two paths with the fewest handovers, 1 and 2, and then substitute the handover footprint evaluation value in equation (23) into each safe handover footprint on each path to score and rank the benefits of paths 1 and 2. If the user's preference is the best service quality, first calculate and rank the benefits of key handover paths, and here use the average efficiency of all footprints forming the path to represent the benefit performance B(L) of the path.i ):

[0187]

[0188] The path with the highest efficiency score can be considered the optimal switching path. When paths have the same efficiency score, the path with the fewest switching operations is selected first. Furthermore, if a user encounters a situation where their selected switching path cannot be pre-switched due to network failure, a replacement path can be selected promptly based on path scores in a progressive manner. The process for selecting the optimal switching path is as follows: Figure 11 As shown:

[0189] By constructing a handover path map and evaluating the information on the map, users in the integrated space-ground network can be provided with more accurate and efficient decision-making solutions. Simultaneously, this pre-decision method provides the necessary prerequisites for secure handovers. Users can leverage the handover path map and the performance of each path to overcome the adverse effects of the highly dynamic and complex network environment in space-ground nodes. Before the next handover, users can pre-initiate requests to the optimal target satellite node, reserving resources and pre-transmitting authentication information, ensuring a seamless handover process and providing secure and sustainable network services.

[0190] The embodiments of the present invention have the following technical effects:

[0191] (1) Under the secure handover architecture based on predictable trust transmission, the space-based network nodes were divided. Based on the functions and responsibilities of the nodes, a secure handover pre-judgment mechanism framework was constructed to realize the control of access satellite and access user status information, and to provide support for space-based network dynamic topology prediction and handover node selection.

[0192] (2) To address the problem of unpredictable handover targets caused by the time-varying topology of satellite networks, a scheme is proposed to generate a handover path graph based on the time relationship between satellite coverage and user coverage, transforming the user handover problem into a graph theory problem within the control area of ​​the core node. Considering the actual needs of the integrated space-ground network handover scenario, a selection criterion for effective paths in the handover path graph is proposed. Furthermore, considering the intermittent connectivity of links, a trust-transferring link search algorithm is proposed, effectively ensuring the implementation of pre-transferring trust.

[0193] (3) To address the issue of candidate handover schemes being constrained by multiple attributes, a comprehensive evaluation method for the security handover performance combining EWM and TOPSIS is proposed. Ultimately, the optimal handover path is selected by combining the evaluation results with user preferences, thereby providing feasibility support for the pre-transmission of handover signaling.

[0194] This invention also provides a pre-decision device based on a switching path graph, comprising:

[0195] The acquisition module is used to acquire the switching path map of the target node for secure switching by users in the integrated space-ground network;

[0196] The first processing module is used to obtain a valid and safe switching path based on the node relationships in the switching path diagram.

[0197] The second processing module is used to comprehensively evaluate and score the effective and secure switching paths, and select the best secure switching scheme.

[0198] As one embodiment of the present invention, the acquisition module includes:

[0199] The first processing unit is used to enable the user's currently accessed satellite to obtain the nadir trajectory of other satellites by acquiring the ephemeris tables of other satellites in the region;

[0200] The second processing unit is used to analyze the satellite coverage of the user's location in the future based on the nadir point trajectory, and obtain the user's safe handover path map.

[0201] As one embodiment of the present invention, the first processing module obtains an effective and secure switching path by pre-transmitting trust information between the current access node and the switching target node in the switching path diagram under the intermittent link connectivity environment.

[0202] As one embodiment of the present invention, the second processing module performs performance evaluation based on EWM and TOPSIS, and selects the best security handover scheme based on the user's preference, using the fewest number of handovers or the best service quality as the selection criteria.

[0203] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0204] The various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The various embodiments can be combined as needed, and the same or similar parts can be referred to each other.

[0205] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for pre-decision based on switching path map, characterized in that, Includes the following steps: Step S1: The user's currently accessed satellite obtains the nadir trajectory of other satellites by acquiring their ephemeris tables. Specifically, S represents the nadir position of the satellite at time t, with its latitude and longitude coordinates at that time being (p, q). , ,in, The average angular velocity of the satellite. For satellites in Passing through the rising node longitude, For satellite from The time elapsed to reach S The inclination of the satellite orbit; Based on the satellite trajectory, the satellite coverage of the user's location in the future is analyzed to obtain a switching path map that allows the user to safely switch target nodes. The switching path map is a directed acyclic graph generated based on the continuous coverage time relationship between the access node and the user. The nodes of the switching path map correspond to the satellites that can provide coverage for the user, and the edges correspond to the simultaneous coverage relationship between two satellites for the user. Step S2: Based on the trust pre-transmission information between the current access node and the target node in the intermittent link connectivity environment in the handover path diagram, eliminate redundant paths containing handover footprints to obtain an effective and secure handover path. Step S3: Conduct a comprehensive evaluation and scoring of the effective and secure switching paths, and select the best secure switching scheme.

2. The pre-decision method based on switching path graph as described in claim 1, characterized in that, In step S3, a performance evaluation based on EWM and TOPSIS is conducted, and the best safe handover scheme is selected based on the user's preference, using the fewest handovers or the best service quality as the selection criteria.

3. A pre-decision device based on a switching path map, characterized in that, include: The acquisition module is used to acquire the switching path map of the target node for secure switching by users in the integrated space-ground network; The first processing module is used to obtain a valid and safe switching path based on the node relationships in the switching path diagram. The second processing module is used to comprehensively evaluate and score the effective safe switching paths and select the best safe switching scheme. The acquisition module includes: The first processing unit is used to enable the user's currently accessed satellite to obtain the nadir trajectory of other satellites by acquiring the ephemeris tables of other satellites in the local area. Specifically, S is the nadir position of the satellite at time t, and its latitude and longitude coordinates at this time are (p, q). , ,in, The average angular velocity of the satellite. For satellites in Passing through the rising node longitude, For satellite from The time elapsed to reach S The inclination of the satellite orbit; The second processing unit is used to analyze the satellite coverage of the user's location in the future time based on the satellite point trajectory, and obtain a switching path map that enables the user to safely switch target nodes. The switching path map is a directed acyclic graph generated based on the continuous coverage time relationship between the access node and the user. The nodes of the switching path map correspond to the satellites that can provide coverage for the user, and the edges correspond to the simultaneous coverage relationship between two satellites for the user. The first processing module pre-transmits trust information between the current access node and the target node in the intermittent link connectivity environment in the switching path diagram, eliminates redundant paths containing switching footprints, and obtains an effective and secure switching path.

4. The pre-decision device based on switching path diagram as described in claim 3, characterized in that, The second processing module uses EWM and TOPSIS for performance evaluation and selects the best safe handover scheme based on user preferences, using the fewest handovers or the best service quality as selection criteria.