Low-orbit satellite communication guarantee method, device, electronic equipment and storage medium

By using quantum key encryption and deep learning models to monitor data transmission status, the problem of low security in low-Earth orbit satellite communication has been solved, achieving more efficient communication security.

CN117833978BActive Publication Date: 2025-10-28BEIJING GUODIAN GAOKE TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202311558048.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-11-21
Publication Date
2025-10-28
Estimated Expiration
2043-11-21

AI Technical Summary

Technical Problem

In traditional low-Earth orbit satellite communication methods, with the development of quantum computing and cryptography, the risk of identity authentication information being intercepted and cracked is gradually increasing, resulting in low communication security.

Method used

Quantum key encryption is used to encrypt target data, and a data flow monitoring model and an anomaly/malicious communication behavior detection model are used. Based on recurrent neural networks and variational autoencoder networks, the data transmission status is monitored and judged to ensure that data transmission occurs in the absence of anomalies and malicious behavior.

Benefits of technology

It improves the security of low-Earth orbit satellite communications, reduces the risk of abnormal and malicious communication behavior, and enhances user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117833978B_ABST
    Figure CN117833978B_ABST
Patent Text Reader

Abstract

This invention provides a method, apparatus, electronic device, and storage medium for ensuring low-Earth orbit (LEO) satellite communication, relating to the field of communication technology. The method includes: receiving encrypted data sent by a data transmitter and acquiring data transmission status information of the encrypted data. The data transmission status information describes the state of the data during data transmission. The encrypted data is obtained by encrypting target data, which includes data to be transmitted. Based on the data transmission status information, if it is determined that there is no abnormal or malicious communication behavior during the data transmission process, the encrypted data is sent to a data receiver. The LEO satellite communication security method, apparatus, electronic device, and storage medium provided by this invention can improve the communication security of LEO satellite communication, reduce the risk of abnormal and malicious communication behavior in LEO satellite communication, and improve user experience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication technology, and in particular to a method, apparatus, electronic device, and storage medium for ensuring low-Earth orbit satellite communication. Background Technology

[0002] Based on a globally covered constellation of low-Earth orbit (LEO) satellites, LEO satellite communication networks can provide communication services to users worldwide, especially to remote areas far from terrestrial communication network coverage. Therefore, LEO satellite communication networks have been widely used in aviation, maritime, military, and the Internet of Things (IoT) sectors.

[0003] To ensure the security of satellite communications, traditional low-Earth orbit (LEO) satellite communication methods can improve security by authenticating the data transmitters and receivers.

[0004] However, with the development of quantum computing and cryptography, the risk of interception and cracking of authentication information during data transmission and reception in low-Earth orbit (LEO) satellite communications is gradually increasing. Once the authentication information is intercepted and cracked, it means the exposure of the communication data. Therefore, the communication security of traditional LEO satellite communication methods is not high. Summary of the Invention

[0005] This invention provides a method, apparatus, electronic device, and storage medium for ensuring low-Earth orbit (LEO) satellite communication, thereby addressing the shortcomings of low-Earth orbit (LEO) satellite communication security in the prior art and improving the security of LEO satellite communication.

[0006] This invention provides a method for ensuring low-Earth orbit (LEO) satellite communication, applied to a LEO satellite communication support device. The method includes:

[0007] The system receives encrypted data sent by the data sender and obtains the data transmission status information of the encrypted data. The data transmission status information is used to describe the status of the data during the data transmission process. The encrypted data is obtained by encrypting the target data, and the target data includes the data to be transmitted.

[0008] If, based on the data transmission status information, it is determined that there is no abnormal or malicious communication behavior in the encrypted data during the data transmission process, the encrypted data is sent to the data receiving end, so that the data receiving end can obtain the target data by decrypting the encrypted data upon receiving it.

[0009] Wherein, if the data sending end is a ground terminal, the data receiving end is a low-Earth orbit satellite; and if the data sending end is a low-Earth orbit satellite, the data receiving end is a ground terminal.

[0010] According to a low-Earth orbit satellite communication assurance method provided by the present invention, the step of obtaining the data transmission status information of the encrypted data includes:

[0011] Based on the data flow monitoring model, the data transmission status information of the encrypted data is obtained;

[0012] The data transmission status information includes at least one of the data transmission rate, data transmission delay, and packet loss rate of the encrypted data; the data flow monitoring model is constructed based on a recurrent neural network.

[0013] According to a low-Earth orbit satellite communication assurance method provided by the present invention, based on the data transmission status information, it determines whether there is abnormal communication behavior in the encrypted data during data transmission, including:

[0014] The data transmission status information is input into the abnormal communication behavior detection model, and the abnormal communication behavior detection result of the encrypted data output by the abnormal communication behavior detection model is obtained.

[0015] The abnormal communication behavior detection result includes first information indicating the presence of abnormal communication behavior during data transmission, or second information indicating the absence of abnormal communication behavior during data transmission; the abnormal communication behavior detection model is constructed based on a variational autoencoder network and trained based on the data transmission status information of the sample data and the abnormal communication behavior detection result of the sample data.

[0016] According to a low-Earth orbit satellite communication protection method provided by the present invention, based on the data transmission status information, it is determined whether malicious communication behavior exists in the encrypted data during data transmission, including:

[0017] The data transmission status information is input into the malicious communication behavior detection model to obtain the malicious communication behavior detection result of the encrypted data output by the abnormal communication behavior detection model.

[0018] The malicious communication behavior detection result includes third information indicating the presence of malicious communication behavior during data transmission, or fourth information indicating the absence of malicious communication behavior during data transmission; the malicious communication behavior detection model is constructed based on a recurrent neural network, and is based on the data transmission status information of the sample data and the malicious communication behavior detection result of the sample data.

[0019] According to a method for ensuring low-Earth orbit satellite communication provided by the present invention, the target data further includes a target hash value, which is calculated based on the data to be transmitted and a target one-way hash function.

[0020] According to a method for ensuring low-Earth orbit satellite communication provided by the present invention, the encrypted data is obtained by encrypting the target data using quantum keys.

[0021] This invention also provides a method for ensuring low-Earth orbit satellite communication, applied at a data transmission end, the method comprising:

[0022] Based on the data to be transmitted and the target one-way hash function, the target hash value is calculated, and the data to be transmitted and the target hash value are determined as the target data;

[0023] Based on quantum key distribution, the target data is encrypted to obtain the encrypted data;

[0024] The encrypted data is sent to the low-Earth orbit satellite communication support device, so that the low-Earth orbit satellite communication support device can receive the encrypted data and obtain the data transmission status information of the encrypted data. If, based on the data transmission status information, it is determined that there is no abnormal or malicious communication behavior of the encrypted data during the data transmission process, the encrypted data is sent to the data receiving end.

[0025] The data transmission status information is used to describe the status of the data during the data transmission process; when the data sending end is a ground terminal, the data receiving end is a low-Earth orbit satellite; when the data sending end is a low-Earth orbit satellite, the data receiving end is a ground terminal.

[0026] This invention also provides a method for ensuring low-Earth orbit satellite communication, applied at a data receiving end, the method comprising:

[0027] The device receives encrypted data sent by the low-orbit satellite communication support device. The encrypted data is obtained by encrypting the target data using quantum key distribution. The target data includes data to be transmitted and a target hash value. The target hash value is calculated based on the data to be transmitted and a target one-way hash function.

[0028] Based on quantum key distribution, the encrypted data is decrypted to obtain the data to be transmitted and the target hash value.

[0029] Based on the target one-way hash function and the data to be transmitted, the verification hash value is calculated;

[0030] If the verification hash value and the target hash value are the same, the data to be transmitted is output.

[0031] The present invention also provides a low-Earth orbit satellite communication support device, comprising:

[0032] The monitoring module is used to receive encrypted data sent by the data sending end and obtain the data transmission status information of the encrypted data. The data transmission status information is used to describe the status of the data during the data transmission process. The encrypted data is obtained by encrypting the target data, and the target data includes the data to be transmitted.

[0033] The judgment module is used to send the encrypted data to the data receiving end when it is determined, based on the data transmission status information, that there is no abnormal or malicious communication behavior in the encrypted data during the data transmission process. This allows the data receiving end to obtain the target data by decrypting the encrypted data upon receiving it.

[0034] Wherein, if the data sending end is a ground terminal, the data receiving end is a low-Earth orbit satellite; and if the data sending end is a low-Earth orbit satellite, the data receiving end is a ground terminal.

[0035] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement any of the low-Earth orbit satellite communication assurance methods described above.

[0036] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the low-Earth orbit satellite communication guarantee method as described above.

[0037] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements any of the low-Earth orbit satellite communication assurance methods described above.

[0038] The low-Earth orbit (LEO) satellite communication security method, apparatus, electronic device, and storage medium provided by this invention receive encrypted data sent by a data transmitter and obtain the data transmission status information of the encrypted data. Based on this data transmission status information, and if it is determined that there is no abnormal or malicious communication behavior during the data transmission process, the encrypted data is sent to a data receiver. Upon receiving the encrypted data, the data receiver decrypts it to obtain the target data, including the data to be transmitted. This improves the communication security of LEO satellite communication, reduces the risk of abnormal and malicious communication behavior, and enhances user experience. Attached Figure Description

[0039] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0040] Figure 1 This is a flowchart illustrating the low-Earth orbit satellite communication support method applied to a low-Earth orbit satellite communication support device provided by the present invention.

[0041] Figure 2 This is a schematic diagram of the process by which the data transmitter calculates the target hash value in the low-orbit satellite communication guarantee method provided by the present invention;

[0042] Figure 3 This is a flowchart illustrating the low-Earth orbit satellite communication guarantee method applied to the data transmission end provided by the present invention.

[0043] Figure 4 This is a flowchart illustrating the low-Earth orbit satellite communication guarantee method applied to the data receiving end provided by the present invention.

[0044] Figure 5 This is a schematic diagram of the low-orbit satellite communication support device provided by the present invention;

[0045] Figure 6 This is a data interaction diagram between the low-orbit satellite communication support device provided by the present invention and the data transmitting end and data receiving end;

[0046] Figure 7 This is a schematic diagram of the structure of the data sending end provided by the present invention;

[0047] Figure 8 This is a schematic diagram of the structure of the data receiving end provided by the present invention;

[0048] Figure 9 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation

[0049] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0050] In the description of the invention, it should be noted that, unless otherwise explicitly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection of two components. Those skilled in the art can understand the specific meaning of the above terms in this invention according to the specific circumstances.

[0051] In the description of this application, the terms "first," "second," etc., are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first," "second," etc., are generally of the same class, without limiting the number of objects; for example, a first object can be one or more. Furthermore, in the description of this application, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects have an "or" relationship.

[0052] It should be noted that low Earth orbit (LEO) satellites are artificial satellites that operate in orbits close to Earth, typically at an altitude of less than 1000 kilometers. Compared to high Earth orbit (HEO) satellites, LEO satellites offer advantages such as lower latency, global coverage, greater flexibility, and stronger resistance to interference.

[0053] Based on a globally covered constellation of low-Earth orbit (LEO) satellites, LEO satellite communication networks can provide faster and lower-latency communication services to users worldwide. Moreover, compared to high-Earth orbit (GEO) satellites, and even communication methods such as cables, copper wires, and 5G, LEO satellite communication networks can provide wider bandwidth.

[0054] Low Earth orbit (LEO) satellite networks can provide communication services to remote areas previously covered by terrestrial communication networks. Therefore, LEO satellite communication networks have found widespread application in fields such as aviation, maritime, military, and the Internet of Things (IoT). The communication services provided by LEO satellite networks can include voice calls and data transmission with the internet.

[0055] In related technologies, to ensure the security of low-Earth orbit (LEO) satellite communication, traditional LEO satellite communication methods can improve the security of LEO satellite communication by authenticating the identities of the data transmitter and receiver.

[0056] The methods for authenticating the data transmitters and receivers in low-Earth orbit satellite communications typically include two types: digital certificate authentication and shared key authentication.

[0057] When using digital certificate authentication, both the data sender and receiver can use digital certificates to prove the legitimacy of their identities. The data receiver can verify the legitimacy and validity of the data sender's digital certificate, ensuring the trustworthiness of both parties' identities.

[0058] When using shared key authentication, the data sender and the data receiver can use a pre-shared key for authentication. The two parties share a key in advance. The data sender uses this key for authentication when sending data, and the data receiver verifies the correctness of the key to confirm the identity of the data sender.

[0059] However, with the development of quantum computing and cryptography, the risk of interception and cracking of authentication information during data transmission and reception in low-Earth orbit (LEO) satellite communications is gradually increasing. Once the authentication information is intercepted and cracked, it means the exposure of the communication data. Therefore, the communication security of traditional LEO satellite communication methods cannot be guaranteed.

[0060] To address this issue, the present invention provides a method for ensuring low-Earth orbit (LEO) satellite communication. Based on the LEO satellite communication assurance method provided by the present invention, the communication security of LEO satellite communication can be improved, the risk of abnormal and malicious communication behavior in LEO satellite communication can be reduced, and the user experience can be enhanced.

[0061] Figure 1 This is a flowchart illustrating the low-Earth orbit (LEO) satellite communication support method applied to a LEO satellite communication support device provided by the present invention. The following is a summary of the process. Figure 1 This invention describes a method for ensuring low-Earth orbit satellite communication. For example... Figure 1 As shown, the method includes: step 101, receiving encrypted data sent by the data sending end and obtaining the data transmission status information of the encrypted data. The data transmission status information is used to describe the status of the encrypted data during the data transmission process. The encrypted data is obtained by encrypting the target data. The target data includes the data to be transmitted.

[0062] In the case where the data transmitting end is a ground terminal, the data receiving end is a low-Earth orbit satellite; and in the case where the data transmitting end is a low-Earth orbit satellite, the data receiving end is a ground terminal.

[0063] It should be noted that the implementing entity in this embodiment of the invention is a low-orbit satellite communication support device.

[0064] Understandably, related technologies can use low-Earth orbit satellites as relays to enable satellite communication between multiple ground terminals.

[0065] Specifically, in this embodiment of the invention, the data transmitting end and the data receiving end are connected through a low-orbit satellite communication support device, that is, the ground terminal, the low-orbit satellite communication support device and the low-orbit satellite terminal are connected in sequence, and / or the low-orbit satellite terminal, the low-orbit satellite communication support device and the ground terminal are connected in sequence.

[0066] After obtaining the data to be transmitted to the data receiver, the data sender can generate target data based on the data to be transmitted, and then encrypt the target data to obtain the encrypted data corresponding to the data to be transmitted.

[0067] It should be noted that when the data sending end is a user terminal, the data sending end can obtain the data to be transmitted to the low-Earth orbit satellite based on the user's input. The user's input can manifest as touch output on the user terminal, including but not limited to click input, swipe input, and press input. User input can also manifest as physical button input on the user terminal. The user's primary input can also be voice input. It is understood that the above-listed inputs are exemplary, meaning that the embodiments of this application include, but are not limited to, the inputs listed above. In actual implementation, the user's input can include any other possible inputs, which can be specifically determined according to actual usage needs, and this application embodiment does not limit this.

[0068] It should be noted that when the data transmitter is a low-Earth orbit satellite, the data transmitter can obtain the data to be transmitted to another user terminal based on the communication with the user terminal.

[0069] As an optional embodiment, the target data also includes a target hash value, which is calculated based on the data to be transmitted and a target one-way hash function.

[0070] Specifically, the data sender can calculate the target hash value corresponding to the data to be transmitted through numerical calculation based on the data to be transmitted and the target one-way hash function.

[0071] It should be noted that, in the embodiments of the present invention, the aforementioned target one-way hash function can be predefined based on prior knowledge and / or actual circumstances. The embodiments of the present invention do not impose specific limitations on the aforementioned target one-way hash function.

[0072] Figure 2 This is a schematic diagram illustrating the process of calculating the target hash value at the data transmitting end in the low-Earth orbit satellite communication guarantee method provided by this invention. For example... Figure 2As shown, the data sending end calculates the target hash value corresponding to the data to be transmitted based on the data to be transmitted and the target one-way hash function, including the following steps: Step 21, divide the data to be transmitted into blocks according to a preset size to obtain multiple data blocks;

[0073] Step 22: Set the initial hash value as the hash value corresponding to the first iteration;

[0074] Step 23: In this iteration, a certain data block is copied multiple times, and padding bits are added to the above data block and the copied data block to expand the above data block and the copied data block into a longer data block. The expanded data block and the hash value corresponding to this iteration are compressed to generate the hash value corresponding to the next iteration.

[0075] Step 24: Repeat step 23 until all data blocks have undergone step 23. Then, determine the hash value generated in the last iteration as the target hash value corresponding to the data to be transmitted.

[0076] In this embodiment of the invention, the data sending end uses the data to be transmitted and the target hash value calculated based on the data to be transmitted and the target one-way hash function as the target data. After the data receiving end obtains the target data, it can calculate the verification hash value based on the target one-way hash function and the data to be transmitted in the same way. Then, by comparing whether the verification hash value and the target hash value are consistent, it can be determined whether the data to be transmitted has been tampered with during the data transmission process, which can further improve the security of low-orbit satellite communication.

[0077] This invention utilizes the fast computation characteristic of one-way hash functions, enabling both the data sender and receiver to calculate the target hash value and the verification hash value in a short time. This allows one-way hash function authentication to be used in real-time communication with low-Earth orbit satellites without affecting the real-time performance of such communication. Furthermore, one-way hash functions are irreversible, meaning that the data to be transmitted cannot be deduced from the hash value, making one-way hash function authentication more secure. Even if the hash value is intercepted, attackers cannot reconstruct the original data from the hash value.

[0078] As an optional embodiment, the encrypted data is obtained by encrypting the target data using a quantum key.

[0079] It's important to note that quantum key distribution is a technique that uses the principles of quantum mechanics to generate and share encryption keys. Traditional cryptography uses mathematical functions and complex algorithms to generate keys, but these keys are vulnerable to computer attacks. In contrast, quantum key distribution utilizes the uncertainty principle in quantum mechanics, making the generation and transmission of keys much more secure.

[0080] Quantum key distribution (QKD) is an important application of quantum key technology. Based on the principles of quantum physics, QKD generates a highly secure key by utilizing the properties of quantum states. QKD leverages the superposition principle and the no-cloning property of quantum states, making the transmission of the key detectable by any eavesdropper. Even if someone attempts to spy on the transmitted qubits, they will disrupt the quantum state, and the attempt will be immediately detected by both communicating parties.

[0081] Quantum key distribution technology allows two legitimate communicating parties to securely establish a shared key for encrypting and decrypting their communications. This key is uncrackable because, according to the principles of quantum mechanics, any observation of a quantum system will interfere with the system itself, thus ensuring the security of key transmission.

[0082] Specifically, when the data transmitter is a ground terminal, the data transmitter can receive the quantum key sent by the low-orbit satellite and encrypt the target data based on the quantum key to obtain the encrypted data corresponding to the data to be transmitted.

[0083] When the data transmitter is a low-Earth orbit satellite, the data transmitter can directly encrypt the target data based on the aforementioned quantum key to obtain the encrypted data corresponding to the data to be transmitted.

[0084] After obtaining the encrypted data, the data sending end can send the encrypted data to the low-orbit satellite communication support device.

[0085] The low-Earth orbit (LEO) satellite communication support device can receive the aforementioned encrypted data and obtain the data transmission status information of the encrypted data. This data transmission status information can be used to describe the status of the encrypted data during the data transmission process from the data sender to the LEO satellite communication support device. For example, the data transmission status information may include, but is not limited to, data transmission rate, data transmission delay, and packet loss rate.

[0086] It should be noted that the data transmission status information of the encrypted data can be obtained in various ways in the embodiments of the present invention. For example, network performance testing tools, deep learning technology, and numerical calculation methods can be used to obtain the data transmission status information of the encrypted data. The specific method for obtaining the data transmission status information of the encrypted data is not limited in the embodiments of the present invention.

[0087] The encrypted data in this embodiment of the invention is obtained by encrypting the target data using quantum keys, which can further improve the security of low-Earth orbit satellite communication.

[0088] As an optional embodiment, obtaining the data transmission status information of encrypted data includes: obtaining the data transmission status information of encrypted data based on a data flow monitoring model;

[0089] The data transmission status information includes at least one of the following: data transmission rate of encrypted data, data transmission delay, and packet loss rate; the data flow monitoring model is built based on a recurrent neural network.

[0090] It's important to note that a Recurrent Neural Network (RNN) is an artificial neural network capable of processing sequential data. Compared to traditional feedforward neural networks, RNNs introduce a circular recurrent structure. The neurons within the hidden layers are interconnected, allowing the network to store its internal state, including historical information about the sequence inputs. This enables the network to describe the dynamic behavior of time sequences, allowing it to recursively process the data and better capture temporal correlations. The core idea of ​​a RNN is to use the output of the previous time step as the input of the current time step. This recurrent structure allows the RNN to process each element in the sequence and retain its memory, making it widely applicable in fields such as natural language processing, speech recognition, and time series prediction.

[0091] Specifically, in this embodiment of the invention, a data flow monitoring model can be constructed based on a recurrent neural network.

[0092] After the data flow monitoring model is constructed, the encrypted data received by the low-orbit satellite communication support device at the current time step can be input into the aforementioned data flow monitoring model.

[0093] The aforementioned data stream monitoring model can connect the encrypted data received by the low-Earth orbit satellite communication support device at time step t with the hidden state information of the low-Earth orbit satellite communication support device when receiving encrypted data at time step t-1, to obtain the hidden state information of the low-Earth orbit satellite communication support device when receiving encrypted data at time step t. The specific formula is as follows:

[0094] h t =f(W ih x t +W hh h t-1 +b h )

[0095] Among them, h t This represents the hidden state information of the low-Earth orbit satellite communication support device when it receives encrypted data at time step t; h t-1This represents the hidden state information of the low-Earth orbit satellite communication support device when it receives encrypted data at time step t-1; x t W represents the encrypted data received by the low-Earth orbit satellite communication support device at time step t; ih W represents the weight matrix input to the hidden layer in the data flow monitoring model described above; hh This represents the weight matrix from hidden layer to hidden layer in the above data flow monitoring model; b h represents the bias vector of the hidden layer in the above data flow monitoring model; f() represents the activation function.

[0096] It is understandable that the hidden state information h of the low-Earth orbit satellite communication support device when receiving encrypted data at time step t is based on this. t It can capture the context information of encrypted data received by the low-orbit satellite communication support device at time step t.

[0097] Therefore, based on the hidden state information of the low-orbit satellite communication support device when receiving encrypted data at each time step, the data transmission status information of the encrypted data can be obtained.

[0098] This invention presents a data flow monitoring model based on a recurrent neural network. This model is used to model and analyze encrypted data. It utilizes the hidden state information of the low-Earth orbit (LEO) satellite communication support device when receiving encrypted data in the previous time step to influence the hidden state information of the LEO satellite communication support device when receiving encrypted data in the current time step. This allows the data flow monitoring model to fully utilize contextual information and more accurately obtain the data transmission status information of the encrypted data. Furthermore, because the recurrent neural network can handle variable-length input sequences, the presence of recurrent connections allows the data flow monitoring model to progressively process the encrypted data received by the LEO satellite communication support device and gradually generate outputs. Therefore, this data flow monitoring model is very suitable for handling encrypted data of different lengths. Simultaneously, since the recurrent neural network uses the same parameters at each time step, the number of parameters in the data flow monitoring model does not increase with the number of time steps. This characteristic makes the data flow monitoring model more efficient in processing long sequences of encrypted data, enabling it to obtain the data transmission status information of the encrypted data more flexibly and efficiently.

[0099] Step 102: Based on the data transmission status information, if it is determined that there is no abnormal or malicious communication behavior during the data transmission process, the encrypted data is sent to the data receiving end so that the data receiving end can obtain the target data by decrypting the encrypted data upon receiving it.

[0100] Specifically, after obtaining the data transmission status information of the encrypted data, it is possible to determine whether there are any abnormal or malicious communication behaviors during the data transmission process from the data sending end to the low-orbit satellite communication support device.

[0101] It should be noted that, in this embodiment of the invention, various methods such as conditional judgment and deep learning techniques can be used to determine whether abnormal or malicious communication behavior exists during the data transmission process from the data sender to the low-Earth orbit satellite communication support device. This embodiment of the invention does not limit the specific method used to determine whether abnormal or malicious communication behavior exists during the data transmission process from the data sender to the low-Earth orbit satellite communication support device.

[0102] As an optional embodiment, determining whether there is abnormal communication behavior in the encrypted data during the data transmission process based on the data transmission status information includes: inputting the data transmission status information into the abnormal communication behavior detection model, and obtaining the abnormal communication behavior detection result of the encrypted data output by the abnormal communication behavior detection model;

[0103] The abnormal communication behavior detection results include first information indicating the presence of abnormal communication behavior during data transmission, or second information indicating the absence of abnormal communication behavior during data transmission. The abnormal communication behavior detection model is constructed based on a variational autoencoder network and trained based on the data transmission status information of the sample data and the abnormal communication behavior detection results of the sample data.

[0104] It's important to note that Variational Autoencoder (VAE) networks are a type of generative model. They combine the ideas of autoencoders and probabilistic inference to learn latent representations of data and generate new samples. VAE networks have wide applications in deep learning, particularly in unsupervised learning and generative models, where they have achieved significant success.

[0105] Variational autoencoder networks typically consist of an encoder and a decoder. The encoder maps the input data to latent variables in the latent space, while the decoder maps the latent variables back to the original data space. Unlike traditional autoencoders, variational autoencoder networks introduce a degree of randomness during the encoding process, making the distribution of latent variables more flexible and continuous, thus enabling them to better model the distribution of data.

[0106] Specifically, in this embodiment of the invention, after constructing the first initial model based on the variational autoencoder network, the data transmission status information of the sample data can be used as samples, and the abnormal communication behavior detection results of the above sample data can be used as sample labels to train the first initial model and obtain the abnormal communication behavior detection model.

[0107] It is understood that the number of sample data in the embodiments of the present invention can be multiple, and the number of sample data is positively correlated with the calculation accuracy of the abnormal communication behavior detection model.

[0108] It should be noted that the data transmission status information of the sample data can be used to describe the status of the sample data during the data transmission process from the sample data sender to the sample data receiver. For example, the data transmission status information may include, but is not limited to, data transmission rate, data transmission delay, and packet loss rate.

[0109] Where the sample data sending end is a ground terminal, the sample data receiving end can be a low-Earth orbit satellite; where the sample data sending end is a low-Earth orbit satellite, the sample data receiving end can be a ground terminal.

[0110] In this embodiment of the invention, the data transmission status information of the aforementioned sample data can be obtained in various ways. For example, network performance testing tools, deep learning techniques, and numerical calculation methods can be used to obtain the data transmission status information of the aforementioned sample data. This embodiment of the invention does not limit the specific method for obtaining the data transmission status information of the aforementioned sample data.

[0111] Optionally, in this embodiment of the invention, the data transmission status information of the sample data can be obtained based on the above-described data flow monitoring model. The specific steps for obtaining the data transmission status information of the sample data based on the above-described data flow monitoring model can be found in the descriptions of the above embodiments, and will not be repeated in this embodiment of the invention.

[0112] In this embodiment of the invention, abnormal communication behavior detection results of the above sample data can be obtained based on user input.

[0113] It should be noted that the abnormal communication behavior in the embodiments of the present invention may include the data transmission rate being outside the first preset range and / or the data packet size being outside the second preset range.

[0114] Optionally, if the abnormal communication behavior detection result includes the first information, the abnormal communication behavior detection result may also include the type and severity of the abnormal behavior.

[0115] After obtaining the abnormal communication behavior detection model, the data transmission status information of the encrypted data can be input into the abnormal communication behavior detection model.

[0116] The aforementioned abnormal communication behavior detection model can obtain and output the abnormal communication behavior detection results of the encrypted data based on the data transmission status information of the encrypted data.

[0117] It is understandable that after obtaining the abnormal communication behavior detection result of the encrypted data output by the above-mentioned abnormal communication behavior detection model, if the abnormal communication behavior detection result of the encrypted data includes the first information, it indicates that there is abnormal communication behavior in the data transmission process from the data sending end to the low-orbit satellite communication support device; if the abnormal communication behavior detection result of the encrypted data includes the second information, it indicates that there is no abnormal communication behavior in the data transmission process from the data sending end to the low-orbit satellite communication support device.

[0118] This invention provides an abnormal communication behavior detection model by constructing a variational autoencoder network, training it based on data transmission status information of sample data and abnormal communication behavior detection results of sample data, and then obtaining the abnormal communication behavior detection results of the encrypted data output by the abnormal communication behavior detection model by inputting the data transmission device information of encrypted information into the abnormal communication behavior detection model. This allows for more accurate and efficient acquisition of abnormal communication behavior detection results of encrypted data using deep learning technology.

[0119] As an optional embodiment, determining whether there is malicious communication behavior in the encrypted data during the data transmission process based on the data transmission status information includes: inputting the data transmission status information into the malicious communication behavior detection model, and obtaining the malicious communication behavior detection result of the encrypted data output by the abnormal communication behavior detection model;

[0120] The malicious communication behavior detection results include third information indicating the presence of malicious communication behavior during data transmission, or fourth information indicating the absence of malicious communication behavior during data transmission. The malicious communication behavior detection model is constructed based on a recurrent neural network, using data transmission status information of sample data and malicious communication behavior detection results of sample data.

[0121] It should be noted that a recursive neural network (RNN) is a neural network with a tree-like hierarchical structure in which network nodes recursively process input information according to their connection order.

[0122] Specifically, in this embodiment of the invention, after constructing the second initial model based on the recurrent neural network, the data transmission status information of the sample data can be used as samples, and the abnormal communication behavior detection results of the above sample data can be used as sample labels to train the second initial model and obtain a malicious communication behavior detection model.

[0123] It is understood that the number of sample data in the embodiments of the present invention can be multiple, and the number of sample data is positively correlated with the calculation accuracy of the malicious communication behavior detection model.

[0124] It should be noted that the specific steps for obtaining the data transmission status information of sample data in the embodiments of the present invention can be found in the above embodiments, and will not be repeated in the embodiments of the present invention.

[0125] It should be noted that, in this embodiment of the invention, the malicious communication behavior detection results of the above sample data can be obtained based on user input.

[0126] Optionally, if the malicious communication behavior detection results include third-party information, the malicious communication behavior detection results may also include the type and severity of the malicious behavior.

[0127] After obtaining the malicious communication behavior detection model, the data transmission status information of the encrypted data can be input into the malicious communication behavior detection model.

[0128] The aforementioned malicious communication behavior detection model can obtain and output the malicious communication behavior detection results of the encrypted data based on the data transmission status information of the encrypted data.

[0129] It is understandable that after obtaining the malicious communication behavior detection result of the encrypted data output by the malicious communication behavior detection model, if the malicious communication behavior detection result of the encrypted data includes the third information, it indicates that there is malicious communication behavior in the data transmission process from the data sending end to the low-orbit satellite communication support device; if the malicious communication behavior detection result of the encrypted data includes the fourth information, it indicates that there is no malicious communication behavior in the data transmission process from the data sending end to the low-orbit satellite communication support device.

[0130] This invention provides a malicious communication behavior detection model that is built based on a recurrent neural network, trained on data transmission status information of sample data and malicious communication behavior detection results of sample data, and then obtains the malicious communication behavior detection results of the encrypted data output by the malicious communication behavior detection model by inputting the data transmission device information of encrypted information into the malicious communication behavior detection model. This invention can utilize deep learning technology to obtain the malicious communication behavior detection results of encrypted data more accurately and efficiently.

[0131] If the low-Earth orbit satellite communication support device determines, based on the data transmission status information of the aforementioned encrypted data, that there are no abnormal or malicious behaviors during the data transmission process from the data sender to the low-Earth orbit satellite communication support device, it may send the aforementioned encrypted data to the data receiver.

[0132] After receiving the encrypted data, the data receiving end can decrypt the encrypted data to obtain the target data, including the data to be transmitted.

[0133] Optionally, if the encrypted data is obtained by encrypting the target data using a quantum key, and the data receiving end is a ground terminal, the data receiving end can decrypt the encrypted data based on the quantum key issued by the low-Earth orbit satellite to obtain the target data including the data to be transmitted; if the data receiving end is a low-Earth orbit satellite, the data receiving end can directly decrypt the encrypted data based on the quantum key to obtain the target data including the data to be transmitted.

[0134] Optionally, if the target data includes a target hash value, the data receiving end can obtain the target data including the data to be transmitted by decrypting the encrypted data, and then calculate the verification hash value based on the data to be transmitted and the target one-way hash function.

[0135] After the data receiving end calculates the above verification hash value, it can compare whether the above verification hash value is consistent with the above target hash value. If the above verification hash value is consistent with the above target hash value, it can be said that the above data to be transmitted has not been tampered with. If the above verification hash value is consistent with the above target hash value, it can be said that the above data to be transmitted has been tampered with.

[0136] If the data receiving end determines that the data to be transmitted has not been tampered with, it can output the data to be transmitted.

[0137] Optionally, the data receiving end may output the data to be transmitted if the data to be transmitted has not been tampered with.

[0138] It should be noted that, in the case of abnormal and / or malicious behavior occurring during the data transmission process of the encrypted data from the data sender to the receiver, the low-Earth orbit satellite communication protection device can respond based on the abnormal communication behavior detection results and / or malicious behavior detection results of the encrypted data, thereby further improving the security of low-Earth orbit satellite communication protection.

[0139] This invention, through receiving encrypted data sent by a data sender and obtaining the data transmission status information of the encrypted data, determines, based on the data transmission status information, that there is no abnormal or malicious communication behavior during the data transmission process. Then, the encrypted data is sent to a data receiver. Upon receiving the encrypted data, the data receiver decrypts it to obtain the target data, including the data to be transmitted. This improves the communication security of low-Earth orbit (LEO) satellite communication, reduces the risk of abnormal and malicious communication behavior in LEO satellite communication, and enhances user experience.

[0140] Figure 3 This is a flowchart illustrating the low-Earth orbit satellite communication guarantee method applied to the data transmission end provided by the present invention. The following is a summary of the process. Figure 3 This invention describes a method for ensuring low-Earth orbit satellite communication. For example... Figure 3 As shown, the method includes: step 301, calculating the target hash value based on the data to be transmitted and the target one-way hash function, and determining the data to be transmitted and the target hash value as the target data.

[0141] It should be noted that the execution entity in this embodiment of the invention is the data sending end.

[0142] It should be noted that when the data sending end is a ground terminal, the data receiving end is a low-Earth orbit satellite; and when the data sending end is a low-Earth orbit satellite, the data receiving end is a ground terminal.

[0143] In this embodiment of the invention, the data transmitting end and the data receiving end are connected through a low-orbit satellite communication support device, that is, the ground terminal, the low-orbit satellite communication support device and the low-orbit satellite terminal are connected in sequence, and / or the low-orbit satellite terminal, the low-orbit satellite communication support device and the ground terminal are connected in sequence.

[0144] Specifically, when the data sending end is a user terminal, the user terminal can obtain the data to be transmitted to the low-Earth orbit satellite based on the user's input; when the data sending end is a low-Earth orbit satellite, the data sending end can obtain the data to be transmitted to another user terminal based on the communication with the user terminal.

[0145] Based on the data to be transmitted and the target one-way hash function, the data sender can calculate the target hash value corresponding to the data to be transmitted through numerical calculation.

[0146] It should be noted that the specific steps for the data sender to calculate the target hash value corresponding to the data to be transmitted based on the data to be transmitted and the target one-way hash function can be found in [link to relevant documentation]. Figure 2 The contents of the above embodiments will not be repeated in the embodiments of the present invention.

[0147] Step 302: Based on quantum key distribution, encrypt the target data to obtain the encrypted data.

[0148] Specifically, when the data transmitter is a ground terminal, the data transmitter can receive the quantum key sent by the low-orbit satellite and encrypt the target data based on the quantum key to obtain the encrypted data corresponding to the data to be transmitted.

[0149] When the data transmitter is a low-Earth orbit satellite, the data transmitter can directly encrypt the target data based on the aforementioned quantum key to obtain the encrypted data corresponding to the data to be transmitted.

[0150] Step 303: Send the encrypted data to the low-Earth orbit satellite communication support device so that the low-Earth orbit satellite communication support device can receive the encrypted data and obtain the data transmission status information of the encrypted data. If it is determined based on the data transmission status information that there is no abnormal or malicious communication behavior during the data transmission process, send the encrypted data to the data receiving end.

[0151] Among them, the data transmission status information is used to describe the status of the data during the data transmission process; when the data sending end is a ground terminal, the data receiving end is a low-Earth orbit satellite; when the data sending end is a low-Earth orbit satellite, the data receiving end is a ground terminal.

[0152] Specifically, after the data sending end obtains the encrypted data corresponding to the data to be transmitted, it can send the encrypted data to the low-orbit satellite communication support device.

[0153] The low-orbit satellite communication support device can receive the encrypted data and obtain the data transmission status information of the encrypted data. Then, based on the data transmission status information of the encrypted data, if it is determined that there is no abnormal or malicious communication behavior during the data transmission process, the encrypted data is sent to the data receiving end. The data receiving end can then decrypt the encrypted data upon receiving it to obtain the data to be transmitted. The data transmission status information of the encrypted data is used to describe the status of the encrypted data during the data transmission process.

[0154] It should be noted that the specific steps of the low-Earth orbit satellite communication support device in implementing the low-Earth orbit satellite communication support method provided by the present invention can be found in the above embodiments, and will not be repeated in the embodiments of the present invention.

[0155] In this embodiment of the invention, the data sending end uses the data to be transmitted and the target hash value calculated based on the data to be transmitted and the target one-way hash function as the target data. After the data receiving end obtains the target data, it can calculate the verification hash value based on the target one-way hash function and the data to be transmitted in the same way. Then, by comparing whether the verification hash value and the target hash value are consistent, it can be determined whether the data to be transmitted has been tampered with during the data transmission process, which can further improve the security of low-orbit satellite communication.

[0156] This invention utilizes the fast computation characteristic of one-way hash functions, enabling both the data sender and receiver to calculate the target hash value and the verification hash value in a short time. This allows one-way hash function authentication to be used in real-time communication with low-Earth orbit satellites without affecting the real-time performance of such communication. Furthermore, one-way hash functions are irreversible, meaning that the data to be transmitted cannot be deduced from the hash value, making one-way hash function authentication more secure. Even if the hash value is intercepted, attackers cannot reconstruct the original data from the hash value.

[0157] Figure 4 This is a flowchart illustrating the low-Earth orbit satellite communication guarantee method applied to the data receiving end provided by the present invention. The following is a summary of the process. Figure 4 This invention describes a method for ensuring low-Earth orbit satellite communication. For example... Figure 4 As shown, the method includes: step 401, receiving encrypted data sent by a low-orbit satellite communication support device, wherein the encrypted data is obtained by encrypting the target data using a quantum key; the target data includes data to be transmitted and a target hash value, wherein the target hash value is calculated based on the data to be transmitted and a target one-way hash function.

[0158] It should be noted that the execution subject in this embodiment of the invention is the data receiving end.

[0159] It should be noted that when the data receiving end is a ground terminal, the data sending end is a low-Earth orbit satellite; and when the data receiving end is a low-Earth orbit satellite, the data sending end is a ground terminal.

[0160] In this embodiment of the invention, the data transmitting end and the data receiving end are connected through a low-orbit satellite communication support device, that is, the ground terminal, the low-orbit satellite communication support device and the low-orbit satellite terminal are connected in sequence, and / or the low-orbit satellite terminal, the low-orbit satellite communication support device and the ground terminal are connected in sequence.

[0161] It should be noted that the encrypted data sent by the low-Earth orbit satellite communication support device is obtained by encrypting the target data using a quantum key distribution method at the data sending end. The specific steps for the data sending end to obtain the encrypted data, the interaction between the data sending end and the low-Earth orbit satellite communication support device, and the specific steps for the low-Earth orbit satellite communication support device to send the encrypted data to the data receiving end can be found in the above embodiments, and will not be repeated in this embodiment.

[0162] Step 402: Based on quantum key distribution, decrypt the encrypted data to obtain the data to be transmitted and the target hash value.

[0163] Specifically, when the data receiving end is a ground terminal, the data receiving end can decrypt the above-mentioned encrypted data based on the quantum key issued by the low-orbit satellite to obtain the target data including the data to be transmitted and the target hash value.

[0164] When the data receiving end is a low-Earth orbit satellite, the data receiving end can directly decrypt the encrypted data based on the aforementioned quantum key to obtain the target data, which includes the data to be transmitted and the target hash value.

[0165] Step 403: Calculate the verification hash value based on the target one-way hash function and the data to be transmitted.

[0166] Specifically, after the data receiving end obtains the target data, which includes the data to be transmitted and the target hash value, it can calculate the verification hash value based on the data to be transmitted and the target one-way hash function.

[0167] It should be noted that the specific steps for the data receiving end to calculate the verification hash value based on the aforementioned data to be transmitted and the aforementioned target one-way hash function can be found in [link to relevant documentation]. Figure 2 The contents of the above embodiments will not be repeated in the embodiments of the present invention.

[0168] Step 404: If the verified hash value and the target hash value are the same, output the data to be transmitted.

[0169] After the data receiving end calculates the above verification hash value, it can compare whether the above verification hash value is consistent with the above target hash value.

[0170] If the verification hash value and the target hash value are consistent, it indicates that the data to be transmitted has not been tampered with; if the verification hash value and the target hash value are consistent, it indicates that the data to be transmitted has been tampered with.

[0171] If the data receiving end determines that the data to be transmitted has not been tampered with, it can output the data to be transmitted.

[0172] In this embodiment of the invention, the data sending end uses the data to be transmitted and the target hash value calculated based on the data to be transmitted and the target one-way hash function as the target data. After the data receiving end obtains the target data, it can calculate the verification hash value based on the target one-way hash function and the data to be transmitted in the same way. Then, by comparing whether the verification hash value and the target hash value are consistent, it can be determined whether the data to be transmitted has been tampered with during the data transmission process, which can further improve the security of low-orbit satellite communication.

[0173] Figure 5 This is a structural schematic diagram of the low-orbit satellite communication support device provided by the present invention. The following is in conjunction with... Figure 5 The low-Earth orbit (LEO) satellite communication support device provided by this invention is described below. The LEO satellite communication support device described below can be referred to in correspondence with the LEO satellite communication support method provided by this invention described above. For example... Figure 5 As shown, the low-orbit satellite communication support device 500 includes: a monitoring module 501 and a judgment module 502.

[0174] The monitoring module 501 is used to receive encrypted data sent by the data sending end and obtain the data transmission status information of the encrypted data. The data transmission status information is used to describe the status of the data during the data transmission process. The encrypted data is obtained by encrypting the target data, and the target data includes the data to be transmitted.

[0175] The judgment module 502 is used to send the encrypted data to the data receiving end when it is determined, based on the data transmission status information, that there is no abnormal or malicious communication behavior in the encrypted data during the data transmission process, so that the data receiving end can obtain the target data by decrypting the encrypted data upon receiving it.

[0176] Wherein, if the data sending end is a ground terminal, the data receiving end is a low-Earth orbit satellite; and if the data sending end is a low-Earth orbit satellite, the data receiving end is a ground terminal.

[0177] Specifically, the monitoring module 501 and the judgment module 502 are electrically connected.

[0178] Optionally, the monitoring module 501 is specifically used to obtain data transmission status information of the encrypted data based on a data flow monitoring model; wherein, the data transmission status information includes at least one of the data transmission rate, data transmission delay, and packet loss rate of the encrypted data; the data flow monitoring model is constructed based on a recurrent neural network.

[0179] Optionally, the judgment module 502 may include an abnormal communication behavior detection unit and a malicious communication behavior detection unit.

[0180] The abnormal communication behavior detection unit can be used to input the data transmission status information into the abnormal communication behavior detection model and obtain the abnormal communication behavior detection result of the encrypted data output by the abnormal communication behavior detection model; wherein, the abnormal communication behavior detection result includes first information indicating that abnormal communication behavior exists during data transmission, or second information indicating that abnormal communication behavior does not exist during data transmission; the abnormal communication behavior detection model is constructed based on a variational autoencoder network and trained based on the data transmission status information of the sample data and the abnormal communication behavior detection result of the sample data.

[0181] The malicious communication behavior detection unit can be used to input the data transmission status information into the malicious communication behavior detection model and obtain the malicious communication behavior detection result of the encrypted data output by the malicious communication behavior detection model; wherein, the malicious communication behavior detection result includes third information indicating that malicious communication behavior exists during data transmission, or fourth information indicating that malicious communication behavior does not exist during data transmission; the malicious communication behavior detection model is constructed based on a recurrent neural network, and is constructed based on the data transmission status information of the sample data and the malicious communication behavior detection result of the sample data.

[0182] Figure 6 This is a data interaction diagram between the low-Earth orbit satellite communication support device provided by this invention and the data transmitting and receiving ends. (See diagram for example.) Figure 6 As shown, the output of the data transmitter 601 is connected to the input of the monitoring module 501 in the low-orbit satellite communication support device 500.

[0183] The data transmitter 601 can send encrypted data, which is obtained by encrypting the target data, including the data to be transmitted and the target hash value, based on the quantum key pair, to the monitoring module 501.

[0184] The output of the monitoring module 501 is connected to the input of the abnormal communication behavior detection unit 602 and the input of the malicious communication behavior detection unit 603 in the judgment module 502, respectively.

[0185] After the monitoring module 501 obtains the data transmission status information of the encrypted data, it can send the data transmission status information of the encrypted data and the encrypted data to the abnormal communication behavior detection unit 602 and the malicious communication behavior detection unit 603, respectively.

[0186] The output terminals of the abnormal communication behavior detection unit 602 and the malicious communication behavior detection unit 603 are respectively connected to the input terminal of the data receiving terminal 604.

[0187] Based on the data transmission status information of the encrypted data, the abnormal communication behavior detection unit 602 and the malicious communication behavior detection unit 603 determine that there is no abnormal or malicious communication behavior in the process of data transmission, and then send the encrypted data to the data receiving end 604.

[0188] After receiving the encrypted data, the data receiver 604 can decrypt the encrypted data based on the quantum key and verify the data to be transmitted based on the target hash value.

[0189] The low-Earth orbit (LEO) satellite communication protection device in this embodiment of the invention receives encrypted data sent by a data transmitter and obtains the data transmission status information of the encrypted data. Based on the data transmission status information, if it is determined that there is no abnormal or malicious communication behavior during the data transmission process, the encrypted data is sent to a data receiver. Upon receiving the encrypted data, the data receiver decrypts it to obtain the target data, including the data to be transmitted. This improves the communication security of LEO satellite communication, reduces the risk of abnormal and malicious communication behavior in LEO satellite communication, and enhances user experience.

[0190] Figure 7 This is a schematic diagram of the data transmitting end provided by the present invention. The following is in conjunction with… Figure 7 The data transmitting end provided by this invention is described below, and the data transmitting end described below can be referred to in correspondence with the low-Earth orbit satellite communication guarantee method provided by this invention described above. For example... Figure 7 As shown, the data sending end includes: a first calculation module 701, a data encryption module 702, and a data sending module 703.

[0191] The first calculation module 701 is used to calculate the target hash value based on the data to be transmitted and the target one-way hash function, and to determine the data to be transmitted and the target hash value as the target data.

[0192] The data encryption module 702 is used to encrypt the target data based on quantum keys to obtain encrypted data;

[0193] The data transmission module 703 is used to send the encrypted data to the low-orbit satellite communication support device, so that the low-orbit satellite communication support device can receive the encrypted data and obtain the data transmission status information of the encrypted data. If, based on the data transmission status information, it is determined that there is no abnormal communication behavior or malicious communication behavior of the encrypted data during the data transmission process, the encrypted data is sent to the data receiving end.

[0194] The data transmission status information is used to describe the status of the data during the data transmission process; when the data sending end is a ground terminal, the data receiving end is a low-Earth orbit satellite; when the data sending end is a low-Earth orbit satellite, the data receiving end is a ground terminal.

[0195] Specifically, the first calculation module 701, the data encryption module 702, and the data transmission module 703 are electrically connected.

[0196] Figure 8 This is a schematic diagram of the data receiving end provided by the present invention. The following is in conjunction with... Figure 8 The data receiving end provided by this invention is described below, and the data receiving end described below can be referred to in correspondence with the low-Earth orbit satellite communication guarantee method provided by this invention described above. For example... Figure 8 As shown, the data receiving end includes: a data receiving module 801, a data decryption module 802, a second calculation module 803, and a data verification module 804.

[0197] The data receiving module 801 is used to receive encrypted data sent by the low-orbit satellite communication support device. The encrypted data is obtained by encrypting the target data based on quantum key distribution. The target data includes data to be transmitted and a target hash value. The target hash value is calculated based on the data to be transmitted and a target one-way hash function.

[0198] The data decryption module 802 is used to decrypt the encrypted data based on quantum key distribution to obtain the data to be transmitted and the target hash value.

[0199] The second calculation module 803 is used to calculate the verification hash value based on the target one-way hash function and the data to be transmitted;

[0200] The data verification module 804 is used to output the data to be transmitted if the verification hash value and the target hash value are the same.

[0201] Specifically, the data receiving module 801, the data decryption module 802, the second calculation module 803, and the data verification module 804 are electrically connected.

[0202] Figure 9An example of a physical structure diagram of an electronic device is shown below. Figure 9 As shown, the electronic device may include a processor 910, a communications interface 920, a memory 930, and a communications bus 940. The processor 910, communications interface 920, and memory 930 communicate with each other via the communications bus 940. The processor 910 can call logical instructions in the memory 930 to execute a low-Earth orbit (LEO) satellite communication method. This method includes: receiving encrypted data sent by a data transmitter and obtaining data transmission status information of the encrypted data. The data transmission status information describes the state of the data during data transmission. The encrypted data is obtained by encrypting target data, which includes the data to be transmitted. If, based on the data transmission status information, it is determined that there is no abnormal or malicious communication behavior during the data transmission, the encrypted data is sent to a data receiver. The data receiver, upon receiving the encrypted data, decrypts it to obtain the target data. Where the data transmitter is a ground terminal, the data receiver is a LEO satellite terminal; where the data transmitter is a LEO satellite terminal, the data receiver is a ground terminal. The method further includes: calculating a target hash value based on the data to be transmitted and a target one-way hash function, and determining the data to be transmitted and the target hash value as the target data; encrypting the target data based on quantum key distribution to obtain encrypted data; sending the encrypted data to a low-Earth orbit satellite communication support device for the device to receive the encrypted data and obtain the data transmission status information; and, based on the data transmission status information, determining that there is no abnormal or malicious communication behavior during the data transmission process, sending the encrypted data to the data receiving end; wherein, the data transmission status information is used to describe the state of the data during the data transmission process; when the data sending end is a ground terminal, the data receiving end is a low-Earth orbit satellite end; and when the data sending end is a low-Earth orbit satellite end, the data receiving end is a ground terminal. The method further includes: receiving encrypted data sent by a low-Earth orbit satellite communication support device, wherein the encrypted data is obtained by encrypting target data using a quantum key, and the target data includes data to be transmitted and a target hash value, wherein the target hash value is calculated based on the data to be transmitted and a target one-way hash function; decrypting the encrypted data using a quantum key to obtain the data to be transmitted and the target hash value; calculating a verification hash value based on the target one-way hash function and the data to be transmitted; and outputting the data to be transmitted if the verification hash value and the target hash value are the same.

[0203] Furthermore, the logical instructions in the aforementioned memory 930 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0204] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the low-Earth orbit satellite communication method provided by the above methods. The method includes: receiving encrypted data sent by a data transmitter and obtaining data transmission status information of the encrypted data. The data transmission status information is used to describe the state of the data during data transmission. The encrypted data is obtained by encrypting target data, and the target data includes data to be transmitted. If, based on the data transmission status information, it is determined that there is no abnormal or malicious communication behavior during the data transmission of the encrypted data, the encrypted data is sent to a data receiver so that the data receiver can obtain the target data by decrypting the encrypted data upon receiving it. Wherein, when the data transmitter is a ground terminal, the data receiver is a low-Earth orbit satellite terminal; when the data transmitter is a low-Earth orbit satellite terminal, the data receiver is a ground terminal. The method further includes: calculating a target hash value based on the data to be transmitted and a target one-way hash function, and determining the data to be transmitted and the target hash value as the target data; encrypting the target data based on quantum key distribution to obtain encrypted data; sending the encrypted data to a low-Earth orbit satellite communication support device for the device to receive the encrypted data and obtain the data transmission status information; and, based on the data transmission status information, determining that there is no abnormal or malicious communication behavior during the data transmission process, sending the encrypted data to the data receiving end; wherein, the data transmission status information is used to describe the state of the data during the data transmission process; when the data sending end is a ground terminal, the data receiving end is a low-Earth orbit satellite end; and when the data sending end is a low-Earth orbit satellite end, the data receiving end is a ground terminal. The method further includes: receiving encrypted data sent by a low-Earth orbit satellite communication support device, wherein the encrypted data is obtained by encrypting target data using a quantum key, and the target data includes data to be transmitted and a target hash value, wherein the target hash value is calculated based on the data to be transmitted and a target one-way hash function; decrypting the encrypted data using a quantum key to obtain the data to be transmitted and the target hash value; calculating a verification hash value based on the target one-way hash function and the data to be transmitted; and outputting the data to be transmitted if the verification hash value and the target hash value are the same.

[0205] In another aspect, the present invention also provides a non-transitory computer-readable storage medium storing a computer program thereon. When executed by a processor, the computer program is implemented to perform the low-Earth orbit satellite communication method provided by the above methods. The method includes: receiving encrypted data sent by a data transmitter and obtaining data transmission status information of the encrypted data, wherein the data transmission status information describes the state of the data during data transmission, the encrypted data is obtained by encrypting target data, and the target data includes data to be transmitted; and, based on the data transmission status information, determining that there is no abnormal or malicious communication behavior during the data transmission of the encrypted data, sending the encrypted data to a data receiver, so that the data receiver can obtain the target data by decrypting the encrypted data upon receiving it; wherein, when the data transmitter is a ground terminal, the data receiver is a low-Earth orbit satellite terminal; and when the data transmitter is a low-Earth orbit satellite terminal, the data receiver is a ground terminal. The method further includes: calculating a target hash value based on the data to be transmitted and a target one-way hash function, and determining the data to be transmitted and the target hash value as the target data; encrypting the target data based on quantum key distribution to obtain encrypted data; sending the encrypted data to a low-Earth orbit satellite communication support device for the device to receive the encrypted data and obtain the data transmission status information; and, based on the data transmission status information, determining that there is no abnormal or malicious communication behavior during the data transmission process, sending the encrypted data to the data receiving end; wherein, the data transmission status information is used to describe the state of the data during the data transmission process; when the data sending end is a ground terminal, the data receiving end is a low-Earth orbit satellite end; and when the data sending end is a low-Earth orbit satellite end, the data receiving end is a ground terminal. The method further includes: receiving encrypted data sent by a low-Earth orbit satellite communication support device, wherein the encrypted data is obtained by encrypting target data using a quantum key, and the target data includes data to be transmitted and a target hash value, wherein the target hash value is calculated based on the data to be transmitted and a target one-way hash function; decrypting the encrypted data using a quantum key to obtain the data to be transmitted and the target hash value; calculating a verification hash value based on the target one-way hash function and the data to be transmitted; and outputting the data to be transmitted if the verification hash value and the target hash value are the same.

[0206] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0207] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, or of course, by hardware. Based on this understanding, the essence of the above technical solution or the part that contributes to the existing technology can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or certain parts of the embodiments.

[0208] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for ensuring low-Earth orbit satellite communication, characterized in that, The method, applied to low-Earth orbit satellite communication support devices, includes: The system receives encrypted data sent by the data sender and obtains the data transmission status information of the encrypted data. The data transmission status information is used to describe the status of the data during the data transmission process. The encrypted data is obtained by encrypting the target data. The target data includes the data to be transmitted and the target hash value. The target hash value is calculated based on the data to be transmitted and the target one-way hash function. If, based on the data transmission status information, it is determined that there is no abnormal or malicious communication behavior in the encrypted data during the data transmission process, the encrypted data is sent to the data receiving end, so that the data receiving end can obtain the target data by decrypting the encrypted data upon receiving it. Wherein, if the data transmitting end is a ground terminal, the data receiving end is a low-Earth orbit satellite; and if the data transmitting end is a low-Earth orbit satellite, the data receiving end is a ground terminal. The target hash value is calculated based on the following steps: Step 21: Divide the data to be transmitted into blocks according to a preset size to obtain multiple data blocks; Step 22: Set the initial hash value as the hash value corresponding to the first iteration; Step 23: In this iteration, any data block is copied multiple times, and padding bits are added to the data block and the copied data block to expand the data block and the copied data block into a longer data block. The expanded data block and the hash value corresponding to this iteration are compressed to generate the hash value corresponding to the next iteration. Step 24: Repeat step 23 until all data blocks have undergone step 23. Then, determine the hash value generated in the last iteration as the target hash value corresponding to the data to be transmitted.

2. The low-Earth orbit satellite communication guarantee method according to claim 1, characterized in that, The step of obtaining the data transmission status information of the encrypted data includes: Based on the data flow monitoring model, the data transmission status information of the encrypted data is obtained; The data transmission status information includes at least one of the data transmission rate, data transmission delay, and packet loss rate of the encrypted data; the data flow monitoring model is constructed based on a recurrent neural network.

3. The method for ensuring low-Earth orbit satellite communication according to claim 1, characterized in that, Based on the data transmission status information, determine whether there is any abnormal communication behavior in the encrypted data during data transmission, including: The data transmission status information is input into the abnormal communication behavior detection model, and the abnormal communication behavior detection result of the encrypted data output by the abnormal communication behavior detection model is obtained. The abnormal communication behavior detection result includes first information indicating the presence of abnormal communication behavior during data transmission, or second information indicating the absence of abnormal communication behavior during data transmission; the abnormal communication behavior detection model is constructed based on a variational autoencoder network and trained based on the data transmission status information of the sample data and the abnormal communication behavior detection result of the sample data.

4. The low-Earth orbit satellite communication guarantee method according to claim 1, characterized in that, Based on the data transmission status information, determining whether the encrypted data exhibits malicious communication behavior during data transmission includes: The data transmission status information is input into the malicious communication behavior detection model to obtain the malicious communication behavior detection result of the encrypted data output by the abnormal communication behavior detection model. The malicious communication behavior detection result includes third information indicating the presence of malicious communication behavior during data transmission, or fourth information indicating the absence of malicious communication behavior during data transmission; the malicious communication behavior detection model is constructed based on a recurrent neural network, and is based on the data transmission status information of the sample data and the malicious communication behavior detection result of the sample data.

5. The method for ensuring low-Earth orbit satellite communication according to claim 1, characterized in that, The encrypted data is obtained by encrypting the target data using quantum keys.

6. A method for ensuring low-Earth orbit satellite communication, characterized in that, Applied to the data sending end, the method includes: Based on the data to be transmitted and the target one-way hash function, the target hash value is calculated, and the data to be transmitted and the target hash value are determined as the target data; Based on quantum key distribution, the target data is encrypted to obtain the encrypted data; The encrypted data is sent to the low-Earth orbit satellite communication support device, so that the low-Earth orbit satellite communication support device can receive the encrypted data and obtain the data transmission status information of the encrypted data. If, based on the data transmission status information, it is determined that there is no abnormal or malicious communication behavior of the encrypted data during the data transmission process, the encrypted data is sent to the data receiving end. Wherein, the data transmission status information is used to describe the status of the data during the data transmission process; when the data sending end is a ground terminal, the data receiving end is a low-Earth orbit satellite; when the data sending end is a low-Earth orbit satellite, the data receiving end is a ground terminal. The target hash value is calculated based on the following steps: Step 21: Divide the data to be transmitted into blocks according to a preset size to obtain multiple data blocks; Step 22: Set the initial hash value as the hash value corresponding to the first iteration; Step 23: In this iteration, any data block is copied multiple times, and padding bits are added to the data block and the copied data block to expand the data block and the copied data block into a longer data block. The expanded data block and the hash value corresponding to this iteration are compressed to generate the hash value corresponding to the next iteration. Step 24: Repeat step 23 until all data blocks have undergone step 23. Then, determine the hash value generated in the last iteration as the target hash value corresponding to the data to be transmitted.

7. A method for ensuring low-Earth orbit satellite communication, characterized in that, The method, applied at a data receiving end, includes: The system receives encrypted data sent by the low-Earth orbit satellite communication support device. The encrypted data is obtained by encrypting target data using quantum key distribution. The target data includes data to be transmitted and a target hash value, which is calculated based on the data to be transmitted and a target one-way hash function. Upon receiving the encrypted data sent by the data sender, the low-Earth orbit satellite communication support device obtains the data transmission status information of the encrypted data. Based on the data transmission status information, if it is determined that there is no abnormal or malicious communication behavior during the data transmission process, the system sends the encrypted data to the data receiver. The data transmission status information describes the state of the data during the data transmission process. Based on quantum key distribution, the encrypted data is decrypted to obtain the data to be transmitted and the target hash value, wherein the target hash value is calculated based on the data to be transmitted and the target one-way hash function. Based on the target one-way hash function and the data to be transmitted, the verification hash value is calculated; If the verification hash value and the target hash value are the same, the data to be transmitted is output. The target hash value is calculated based on the following steps: Step 21: Divide the data to be transmitted into blocks according to a preset size to obtain multiple data blocks; Step 22: Set the initial hash value as the hash value corresponding to the first iteration; Step 23: In this iteration, any data block is copied multiple times, and padding bits are added to the data block and the copied data block to expand the data block and the copied data block into a longer data block. The expanded data block and the hash value corresponding to this iteration are compressed to generate the hash value corresponding to the next iteration. Step 24: Repeat step 23 until all data blocks have undergone step 23. Then, determine the hash value generated in the last iteration as the target hash value corresponding to the data to be transmitted.

8. A low-orbit satellite communication support device, characterized in that, include: The monitoring module is used to receive encrypted data sent by the data sending end and obtain the data transmission status information of the encrypted data. The data transmission status information is used to describe the status of the data during the data transmission process. The encrypted data is obtained by encrypting the target data. The target data includes the data to be transmitted and the target hash value. The target hash value is calculated based on the data to be transmitted and the target one-way hash function. The judgment module is used to send the encrypted data to the data receiving end when it is determined, based on the data transmission status information, that there is no abnormal or malicious communication behavior in the encrypted data during the data transmission process. This allows the data receiving end to obtain the target data by decrypting the encrypted data upon receiving it. Wherein, if the data transmitting end is a ground terminal, the data receiving end is a low-Earth orbit satellite; and if the data transmitting end is a low-Earth orbit satellite, the data receiving end is a ground terminal. The target hash value is calculated based on the following steps: Step 21: Divide the data to be transmitted into blocks according to a preset size to obtain multiple data blocks; Step 22: Set the initial hash value as the hash value corresponding to the first iteration; Step 23: In this iteration, any data block is copied multiple times, and padding bits are added to the data block and the copied data block to expand the data block and the copied data block into a longer data block. The expanded data block and the hash value corresponding to this iteration are compressed to generate the hash value corresponding to the next iteration. Step 24: Repeat step 23 until all data blocks have undergone step 23. Then, determine the hash value generated in the last iteration as the target hash value corresponding to the data to be transmitted.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the low-Earth orbit satellite communication guarantee method as described in any one of claims 1 to 7.

10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the low-Earth orbit satellite communication guarantee method as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Encrypted traffic classification system based on data packets

    CN114866486A

  • Method and device for detecting malicious traffic and electronic equipment

    CN115632801A

  • Satellite data transmission method and device, electronic equipment and storage medium

    CN115664511A