A Satellite Link Data Transmission Method, Device, Equipment and Storage Medium
By performing two encapsulation and decryption processing on the satellite link, the TCP acceleration mechanism failure caused by IPSec VPN is solved, and the confidentiality and integrity of data transmission is achieved without reducing communication performance. It is suitable for wireless environments with large latency and high bit error rates.
Patent Information
- Application Number
- CN202411697595.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-26
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2044-11-26
AI Technical Summary
The deployment of IPSec VPN on satellite links in the prior art causes the TCP acceleration mechanism to fail, affecting service quality, and cannot ensure the confidentiality and integrity of data transmission without reducing the performance of TCP communications on the satellite link.
The initial packet is received through the intranet port of the preset encryption center, routing query and IP legality verification, policy matching and data encryption and encapsulation are used to use the Internet security protocol stack to perform encapsulation and decryption processing, and two encapsulation and decryption are achieved to ensure the confidentiality and integrity of data transmission.
Without destroying the TCP service characteristics, the link throughput and advanced flow control strategies of the satellite link are ensured, and the confidentiality and integrity of data transmission are ensured, and are suitable for wireless environments with large delays and high bit error rates.
Smart Images

Figure CN119182452B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of satellite communication, and particularly relates to a satellite link data transmission method, device, equipment and storage medium. Background Art
[0002] Currently, deploying a traditional IPSec VPN (IPSec, i.e., Internet Protocol Security; VPN, Virtual Private Network) on a communication link. Although this method ensures the confidentiality and integrity of data transmission and is also independent of user services, after the IPSec VPN encrypts and encapsulates the data, it will add an ESP (Encapsulate Security Payload) header and / or a UDP (User Datagram Protocol) header outside the original TCP (Transmission Control Protocol) packet, which causes the TCP acceleration mechanism on the link to fail and the service quality to seriously decline.
[0003] As can be seen from the above, how to ensure the confidentiality and integrity of data transmission without reducing the TCP communication performance of the satellite link is an urgent problem to be solved currently. Summary of the Invention
[0004] In view of this, the purpose of the present invention is to provide a satellite link data transmission method, device, equipment and storage medium, which can ensure the confidentiality and integrity of data transmission without reducing the TCP communication performance of the satellite link. The specific scheme is as follows:
[0005] In a first aspect, the present application provides a satellite link data transmission method, including:
[0006] Receiving an initial packet through the internal network port of a preset encryption center, querying the route for a target packet that meets the preset IP legal condition, and sending the target packet to the Internet security protocol stack based on the route query result;
[0007] Performing policy matching and data encryption and encapsulation on the data stream in the target packet based on the Internet security protocol stack to obtain an encapsulated security payload packet;
[0008] Establishing a TCP connection with the destination IP corresponding to the IP header in the encapsulated security payload packet by using the first TCP proxy center of the preset encryption center, and encapsulating the encapsulated security payload packet through the TCP connection to obtain an encapsulated packet;
[0009] The second TCP proxy center of the preset decryption center recursively processes the encapsulated message, decrypts the processed message through the Internet security protocol stack, and sends the obtained target message to the service terminal to complete the corresponding satellite link data transmission operation.
[0010] Optionally, receiving the initial message through the internal network port of the preset encryption center, performing a routing query on the target message that meets the preset IP legal conditions, and sending the target message to the Internet security protocol stack based on the routing query result includes:
[0011] Receiving the initial message through the internal network port of the preset encryption center, and performing IP legality verification on the initial message based on the preset cryptographic algorithm;
[0012] Obtaining the target message that meets the preset IP legal conditions through the verification result, performing a routing query on the target message to obtain the corresponding routing query result, and sending the target message to the Internet security protocol stack based on the routing query result.
[0013] Optionally, performing policy matching and data encryption encapsulation on the data stream in the target message based on the Internet security protocol stack to obtain an encapsulated security payload message includes:
[0014] Parsing the target message based on the Internet security protocol stack to obtain the corresponding message selector;
[0015] Performing policy matching and data encryption encapsulation on the data stream in the target message through the message selector to obtain the corresponding encapsulated security payload message.
[0016] Optionally, further includes:
[0017] Before the encapsulated security payload message is sent out through the external network port, intercepting the encapsulated security payload message by using the first TCP proxy center to obtain the encapsulated security payload message.
[0018] Optionally, establishing a TCP connection between the first TCP proxy center of the preset encryption center and the destination IP corresponding to the IP header in the encapsulated security payload message, and encapsulating the encapsulated security payload message through the TCP connection to obtain the encapsulated message includes:
[0019] Parsing the IP header of the encapsulated security payload message by using the first TCP proxy center to obtain the destination IP;
[0020] Establishing a connection relationship between the first TCP proxy center and the destination IP through the TCP protocol;
[0021] Encapsulate the encapsulated secure payload message based on the connection relationship, calculate the checksum of the encapsulated IP header to obtain a new IP header, and obtain the encapsulated message based on the new IP header.
[0022] Optionally, the recursive processing of the encapsulated message by the second TCP proxy center of the preset decryption center includes:
[0023] After the second TCP proxy center receives the encapsulated message, verify the legality of the encapsulated message, and perform a stripping operation on the encapsulated message based on the verification result to obtain the corresponding encapsulated secure payload message;
[0024] Perform recursive processing on the encapsulated secure payload message based on the preset kernel protocol stack, routing query result, and preset message protocol, and send the processed message to the Internet security protocol stack.
[0025] Optionally, decrypt the processed message through the Internet security protocol stack, and send the obtained target message to the service terminal to complete the corresponding satellite link data transmission operation, including:
[0026] Perform corresponding security association lookup on the triple in the processed message through the Internet security protocol stack; decrypt the processed message based on the lookup result to obtain the corresponding target message;
[0027] Send the target message to the service terminal through the preset internal network port to complete the corresponding satellite link data transmission operation.
[0028] In a second aspect, the present application provides a satellite link data transmission device, including:
[0029] A routing query module, configured to receive an initial message through the internal network port of the preset encryption center, perform a routing query on a target message that meets the preset IP legal condition, and send the target message to the Internet security protocol stack based on the routing query result;
[0030] An encryption and encapsulation module, configured to perform policy matching and data encryption and encapsulation on the data stream in the target message based on the Internet security protocol stack to obtain an encapsulated secure payload message;
[0031] A message encapsulation module, configured to establish a TCP connection with the destination IP corresponding to the IP header in the encapsulated secure payload message by using the first TCP proxy center of the preset encryption center, and encapsulate the encapsulated secure payload message through the TCP connection to obtain an encapsulated message;
[0032] A recursive processing module, configured to recursively process the encapsulated message by using a second TCP proxy center of a preset decryption center, decrypt the processed message through an Internet security protocol stack, and send the obtained target message to a service terminal to complete a corresponding satellite link data transmission operation.
[0033] In a third aspect, the present application provides an electronic device, including:
[0034] A memory, configured to store a computer program;
[0035] A processor, configured to execute the computer program to implement the foregoing satellite link data transmission method.
[0036] In a fourth aspect, the present application provides a computer-readable storage medium, configured to store a computer program, wherein the computer program, when executed by a processor, implements the foregoing satellite link data transmission method.
[0037] This application receives an initial message through the internal network port of a preset encryption center, performs a routing query on target messages that meet the preset IP legal conditions, and sends the target messages to an Internet security protocol stack based on the routing query results; performs policy matching and data encryption encapsulation on the data stream in the target messages based on the Internet security protocol stack to obtain an encapsulated security payload message; uses the first TCP proxy center of the preset encryption center to establish a TCP connection with the destination IP corresponding to the IP header in the encapsulated security payload message, and encapsulates the encapsulated security payload message through the TCP connection to obtain an encapsulated message; uses the second TCP proxy center of a preset decryption center to perform recursive processing on the encapsulated message, decrypts the processed message through the Internet security protocol stack, and sends the obtained target message to a service terminal to complete the corresponding satellite link data transmission operation. As can be seen from the above, this application first receives an initial message through the internal network port of a preset encryption center, performs a routing query on target messages that meet the preset IP legal conditions, and sends the target messages to an Internet security protocol stack based on the routing query results. Then, it performs the first encapsulation on the target messages through the Internet security protocol stack to obtain an encapsulated security payload message. Next, it uses the first TCP proxy center of the preset encryption center to establish a TCP connection with the destination IP corresponding to the IP header in the encapsulated security payload message, and completes the secondary encapsulation based on the TCP connection to obtain an encapsulated message. After the preset decryption center receives the encapsulated message, it uses the TCP proxy center and the Internet security protocol stack in the preset decryption center to perform recursive processing and decryption processing on the encapsulated message to obtain the target message. Finally, it sends the target message to a service terminal to complete the corresponding satellite link data transmission operation. Based on the Internet security protocol stack and the TCP proxy center, the destination message is encapsulated twice without destroying the original TCP service characteristics, ensuring that the link throughput in the TCP acceleration environment and the advanced flow control policy at the link exit are not affected by encryption. While adapting to the TCP acceleration link, it also ensures the confidentiality and integrity of the transmitted data. Brief Description of the Drawings
[0038] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.
[0039] Figure 1 It is a flowchart of a satellite link data transmission method disclosed in this application;
[0040] Figure 2A data processing flow chart provided for this application;
[0041] Figure 3 A schematic structural diagram of a satellite link data transmission device disclosed for this application;
[0042] Figure 4 A structural diagram of an electronic device disclosed for this application. Detailed implementation manners
[0043] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0044] Currently, the method of deploying a traditional IPSec VPN on a communication link can not only ensure the confidentiality and integrity of data transmission, but also be irrelevant to user services. However, after the IPSec VPN encrypts and encapsulates the data, an ESP header and / or a UDP header will be added outside the original TCP packet, which causes the TCP acceleration mechanism on the link to fail and the service quality to seriously decline. For this reason, this application provides a satellite link data transmission method, which performs two encapsulations on the destination packet based on the Internet security protocol stack and the TCP proxy center, without destroying the original TCP service characteristics, ensuring that the link throughput in the TCP acceleration environment and the advanced flow control strategy at the link exit are not affected by encryption, while adapting to the TCP acceleration link, and also ensuring the confidentiality and integrity of the transmitted data.
[0045] See Figure 1 As shown, an embodiment of the present invention discloses a satellite link data transmission method, including:
[0046] Step S11: Receive an initial packet through the internal network interface of a preset encryption center, perform a routing query on a target packet that meets the preset IP legal condition, and send the target packet to the Internet security protocol stack based on the routing query result.
[0047] In this embodiment, a domestic cryptographic algorithm is used to perform identity authentication and integrity verification on the received initial message to obtain a corresponding target message, and route query is performed on the target message. The target message is sent to the Internet security protocol stack based on the transmission path queried by the route query result, so as to perform Internet security protocol processing on the target message through the Internet security protocol stack. Specifically, receiving the initial message through the internal network port of the preset encryption center, performing route query on the target message that meets the preset IP legal condition, and sending the target message to the Internet security protocol stack based on the route query result includes: receiving the initial message through the internal network port of the preset encryption center, and performing IP legality verification on the initial message based on the preset cryptographic algorithm; obtaining the target message that meets the preset IP legal condition through the verification result, performing route query on the target message to obtain a corresponding route query result, and sending the target message to the Internet security protocol stack based on the route query result. It is worth mentioning that the domestic cryptographic algorithm can be one of SM2 / 3 / 4 (SM2 is an asymmetric encryption algorithm; SM3 is a hash algorithm; SM4 is a symmetric encryption algorithm), and no specific limitation is made here.
[0048] Step S12: Perform policy matching and data encryption encapsulation on the data stream in the target message based on the Internet security protocol stack to obtain an encapsulated security payload message.
[0049] In this embodiment, after the Internet security protocol stack receives the target message, the selector (i.e., message selector) of the target message is obtained by parsing the target message through the Internet security protocol stack, and policy matching and data encryption encapsulation are performed on the data stream in the target message based on the message selector to obtain an ESP message (i.e., encapsulated security payload message). Specifically, performing policy matching and data encryption encapsulation on the data stream in the target message based on the Internet security protocol stack to obtain an encapsulated security payload message includes: parsing the target message based on the Internet security protocol stack to obtain a corresponding message selector; performing policy matching and data encryption encapsulation on the data stream in the target message through the message selector to obtain a corresponding encapsulated security payload message. It is worth mentioning that the data encryption encapsulation is to perform encryption encapsulation on the target message using an ESP tunnel.
[0050] Step S13: Establish a TCP connection with the destination IP corresponding to the IP header in the encapsulated security payload message using the first TCP proxy center of the preset encryption center, and perform encapsulation on the encapsulated security payload message through the TCP connection to obtain an encapsulated message.
[0051] In this embodiment, before the encapsulated security payload packet is sent to the external network, the first TCP proxy center of the preset encryption center captures the encapsulated security payload packet at the POSTROUTING (i.e., egress translation) point. Specifically, before the encapsulated security payload packet is sent out through the external network port, the first TCP proxy center intercepts the encapsulated security payload packet to obtain the encapsulated security payload packet.
[0052] It can be understood that after the first TCP proxy center obtains the encapsulated security payload packet, the destination IP is obtained by parsing the IP header of the encapsulated security payload packet, and a TCP connection is established between the first TCP proxy center and the destination IP. Based on the IP header of the encapsulated security payload packet, the encapsulated security payload packet is encapsulated into a new TCP packet, and the IP checksum is recalculated to obtain the encapsulated packet. Specifically, establishing a TCP connection between the first TCP proxy center of the preset encryption center and the destination IP corresponding to the IP header in the encapsulated security payload packet, and encapsulating the encapsulated security payload packet through the TCP connection to obtain the encapsulated packet includes: parsing the IP header of the encapsulated security payload packet by the first TCP proxy center to obtain the destination IP; establishing a connection relationship between the first TCP proxy center and the destination IP through the TCP protocol; encapsulating the encapsulated security payload packet based on the connection relationship, calculating the checksum of the encapsulated IP header to obtain a new IP header, and obtaining the encapsulated packet based on the new IP header.
[0053] Step S14: Use the second TCP proxy center of the preset decryption center to perform recursive processing on the encapsulated packet, decrypt the processed packet through the Internet security protocol stack, and send the obtained target packet to the service terminal to complete the corresponding satellite link data transmission operation.
[0054] In this embodiment, after the second TCP proxy center of the preset decryption center receives the encapsulated message, it first performs a legality check on the encapsulated message, then strips the IP header and TCP header of the encapsulated message to obtain the encapsulated security payload message, reassembles the IP header and the encapsulated security payload message to obtain an IP message, and sends the IP message to the preset kernel protocol stack. The preset kernel protocol stack is used to perform recursive processing on the IP message, and the processed message is delivered to the Internet security protocol stack. Specifically, the recursive processing of the encapsulated message by the second TCP proxy center of the preset decryption center includes: after the second TCP proxy center receives the encapsulated message, performing a legality check on the encapsulated message, and based on the check result, performing a stripping operation on the encapsulated message to obtain the corresponding encapsulated security payload message; performing recursive processing on the encapsulated security payload message based on the preset kernel protocol stack, the routing query result, and the preset message protocol, and sending the processed message to the Internet security protocol stack.
[0055] It can be understood that the Internet security protocol stack and the triple (i.e., destination address, protocol, SPI (Service Provider Interface)) are used to perform a security association search and message decryption on the processed message to obtain the original data packet (i.e., the target message), and the target message is sent to the service terminal through the internal network port. Specifically, the decryption of the processed message by the Internet security protocol stack and the sending of the obtained target message to the service terminal to complete the corresponding satellite link data transmission operation include: performing a corresponding security association search on the triple in the processed message through the Internet security protocol stack; decrypting the processed message based on the search result to obtain the corresponding target message; sending the target message to the service terminal through the preset internal network port to complete the corresponding satellite link data transmission operation.
[0056] As can be seen from the above, in this application, the initial message is first received through the internal network port of the preset encryption center, and the target message that meets the preset IP legal condition is routed and queried, so as to send the target message to the Internet security protocol stack based on the routing query result. Then, the target message is first encapsulated by the Internet security protocol stack to obtain an encapsulated security payload message. Next, the first TCP proxy center of the preset encryption center is used to establish a TCP connection with the destination IP corresponding to the IP header in the encapsulated security payload message, and the secondary encapsulation is completed based on the TCP connection to obtain an encapsulated message. After the preset decryption center receives the encapsulated message, the TCP proxy center and the Internet security protocol stack in the preset decryption center are used to perform recursive processing and decryption processing on the encapsulated message to obtain the target message. Finally, the target message is sent to the service terminal to complete the corresponding satellite link data transmission operation. Based on the Internet security protocol stack and the TCP proxy center, the destination message is encapsulated twice, without destroying the original TCP service characteristics, ensuring that the link throughput in the TCP acceleration environment and the advanced flow control strategy at the link exit are not affected by encryption. While adapting to the TCP acceleration link, it also ensures the confidentiality and integrity of the transmitted data.
[0057] As can be seen from the above embodiments, in this application, the data transmission on the satellite link is performed by encapsulating the destination message twice based on the Internet security protocol stack and the TCP proxy center. Therefore, the data processing process during data transmission is described.
[0058] Further, as shown in Figure 2 the embodiment of the present invention provides a data processing flow chart, including:
[0059] First, the initial message of the TCP Client (i.e., TCP client) is obtained through the internal network port of the preset encryption center. The initial message includes payload data, a TCP header, and an IP header, and the initial message is sent to the IPSec protocol stack (i.e., Internet security protocol stack). The IPSec protocol stack is used to perform the first message encapsulation on the target message that meets the preset IP legal condition to obtain an ESP message (i.e., encapsulated security payload message). Then, the first TCP proxy center intercepts and performs the second message encapsulation on the ESP message to obtain an encapsulated message. The encapsulated message is sent to the TCP acceleration channel through the external network port, and the encapsulated message is received by the second TCP proxy center of the preset decryption center. The second TCP proxy center performs legality verification and recursive processing on the processed message, and the IPSec protocol stack is used to perform recursive and decryption processing on the processed message to obtain a processed message. The processed message is restored to the original data packet and sent to the TCP Server (i.e., TCP server) through the internal network port.
[0060] As can be seen from the above, by using the TCP proxy technology to encapsulate the packets twice, the IP of the real communication device at the backend is hidden, the original TCP service characteristics are not damaged, the identities of both communication parties are ensured to be reliable, and the confidentiality and integrity of the communication data are ensured, so that the security of satellite link communication is guaranteed. Using IPSec VPN to protect the data transmission of the satellite link, without any adjustment to the user service, the service is encrypted without the user's awareness, and it can be applied to other wireless environments with large latency and high bit error rate.
[0061] Correspondingly, as shown in Figure 3 the present application also provides a satellite link data transmission device, including:
[0062] A routing query module 11, configured to receive an initial packet through the internal network interface of a preset encryption center, perform a routing query on a target packet that meets the preset IP legal condition, and send the target packet to an Internet security protocol stack based on the routing query result;
[0063] An encryption encapsulation module 12, configured to perform policy matching and data encryption encapsulation on the data stream in the target packet based on the Internet security protocol stack to obtain an encapsulated security payload packet;
[0064] A packet encapsulation module 13, configured to establish a TCP connection with the destination IP corresponding to the IP header in the encapsulated security payload packet by using the first TCP proxy center of the preset encryption center, and encapsulate the encapsulated security payload packet through the TCP connection to obtain an encapsulated packet;
[0065] A recursive processing module 14, configured to perform recursive processing on the encapsulated packet by using the second TCP proxy center of a preset decryption center, decrypt the processed packet through the Internet security protocol stack, and send the obtained target packet to a service terminal to complete the corresponding satellite link data transmission operation.
[0066] As can be seen from the above, in this application, the initial message is first received through the internal network port of the preset encryption center, and the target message that meets the preset IP legal condition is routed and queried, so as to send the target message to the Internet security protocol stack based on the routing query result. Then, the target message is first encapsulated by the Internet security protocol stack to obtain an encapsulated security payload message. Next, the first TCP proxy center of the preset encryption center is used to establish a TCP connection with the destination IP corresponding to the IP header in the encapsulated security payload message, and the second encapsulation is completed based on the TCP connection to obtain an encapsulated message. After the preset decryption center receives the encapsulated message, the encapsulated message is recursively processed and decrypted by the TCP proxy center and the Internet security protocol stack in the preset decryption center to obtain the target message. Finally, the target message is sent to the service terminal to complete the corresponding satellite link data transmission operation. Based on the Internet security protocol stack and the TCP proxy center, the destination message is encapsulated twice without destroying the original TCP service characteristics, ensuring the link throughput in the TCP acceleration environment and the advanced flow control policy at the link exit are not affected by encryption. While adapting to the TCP acceleration link, it also ensures the confidentiality and integrity of the transmitted data.
[0067] In some specific embodiments, the routing query module 11 may specifically include:
[0068] The legality verification unit is configured to receive the initial message through the internal network port of the preset encryption center and perform IP legality verification on the initial message based on a preset cryptographic algorithm;
[0069] The routing query unit is configured to obtain the target message that meets the preset IP legal condition through the verification result, perform routing query on the target message to obtain a corresponding routing query result, and send the target message to the Internet security protocol stack based on the routing query result.
[0070] In some specific embodiments, the encryption and encapsulation module 12 may specifically include:
[0071] The message parsing unit is configured to parse the target message based on the Internet security protocol stack to obtain a corresponding message selector;
[0072] The data encryption unit is configured to perform policy matching and data encryption and encapsulation on the data stream in the target message through the message selector to obtain a corresponding encapsulated security payload message.
[0073] In some specific embodiments, the satellite link data transmission device may further specifically include:
[0074] A message interception unit, configured to intercept the encapsulated security payload message by using the first TCP proxy center before the encapsulated security payload message is sent out through the external network interface, so as to obtain the encapsulated security payload message.
[0075] In some specific embodiments, the message encapsulation module 13 may specifically include:
[0076] An IP header parsing unit, configured to parse the IP header of the encapsulated security payload message by using the first TCP proxy center to obtain the destination IP;
[0077] A connection relationship establishment unit, configured to establish a connection relationship between the first TCP proxy center and the destination IP through the TCP protocol;
[0078] A message encapsulation completion unit, configured to encapsulate the encapsulated security payload message based on the connection relationship, calculate the checksum of the encapsulated IP header to obtain a new IP header, and obtain the encapsulated message based on the new IP header.
[0079] In some specific embodiments, the recursive processing module 14 may specifically include:
[0080] A message stripping unit, configured to, after the second TCP proxy center receives the encapsulated message, verify the legitimacy of the encapsulated message, and perform a stripping operation on the encapsulated message based on the verification result to obtain the corresponding encapsulated security payload message;
[0081] A message recursive unit, configured to perform recursive processing on the encapsulated security payload message based on a preset kernel protocol stack, a routing query result, and a preset message protocol, and send the processed message to the Internet security protocol stack.
[0082] In some specific embodiments, the recursive processing module 14 may specifically include:
[0083] A triple lookup unit, configured to perform a corresponding security association lookup on the triple in the processed message through the Internet security protocol stack; decrypt the processed message based on the lookup result to obtain the corresponding target message;
[0084] A message sending unit, configured to send the target message to the service terminal through a preset internal network interface to complete the corresponding satellite link data transmission operation.
[0085] Furthermore, an embodiment of the present application also discloses an electronic device, Figure 4It is a structural diagram of an electronic device 20 shown according to an exemplary embodiment. The content in the figure should not be considered as any limitation on the scope of use of this application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. Among them, the memory 22 is used to store a computer program, and the computer program is loaded and executed by the processor 21 to implement the relevant steps in the satellite link data transmission method disclosed in any of the foregoing embodiments. Additionally, the electronic device 20 in this embodiment may specifically be an electronic computer.
[0086] In this embodiment, the power supply 23 is used to provide operating voltages for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and no specific limitation is imposed on it here; the input / output interface 25 is used to obtain external input data or output data to the outside, and its specific interface type can be selected according to specific application requirements, and no specific limitation is made here.
[0087] In addition, as a carrier for resource storage, the memory 22 can be a read-only memory, a random access memory, a magnetic disk, or an optical disc, etc. The resources stored thereon can include an operating system 221, a computer program 222, etc., and the storage method can be temporary storage or permanent storage.
[0088] Among them, the operating system 221 is used to manage and control each hardware device and the computer program 222 on the electronic device 20, and it can be Windows Server, Netware, Unix, Linux, etc. The computer program 222, in addition to including a computer program capable of completing the satellite link data transmission method executed by the electronic device 20 disclosed in any of the foregoing embodiments, may further include a computer program capable of completing other specific tasks.
[0089] Furthermore, this application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the satellite link data transmission method disclosed above. For the specific steps of this method, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details will not be repeated here.
[0090] In this specification, each embodiment is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the description of the method part.
[0091] Those skilled in the art may further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0092] The steps of the methods or algorithms described in combination with the embodiments disclosed herein can be directly implemented by hardware, software modules executed by a processor, or a combination of the two. The software modules can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the technical field.
[0093] Finally, it should also be noted that in this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variation thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.
[0094] The technical solutions provided in this application have been introduced in detail above. Specific examples have been used in this article to elaborate on the principles and implementation manners of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to this application.
Claims
1. A satellite link data transmission method, characterized in that, Including: Receiving an initial message through the internal network port of a preset encryption center, performing a routing query on a target message that meets the preset IP legal conditions, and sending the target message to an Internet security protocol stack based on the routing query result; Performing policy matching and data encryption encapsulation on the data stream in the target message based on the Internet security protocol stack to obtain an encapsulated security payload message; Establishing a TCP connection between the first TCP proxy center of the preset encryption center and the destination IP corresponding to the IP header in the encapsulated security payload message, and encapsulating the encapsulated security payload message through the TCP connection to obtain an encapsulated message; Performing recursive processing on the encapsulated message by the second TCP proxy center of a preset decryption center, decrypting the processed message through the Internet security protocol stack, and sending the obtained target message to a service terminal to complete the corresponding satellite link data transmission operation; Among them, the step of establishing a TCP connection between the first TCP proxy center of the preset encryption center and the destination IP corresponding to the IP header in the encapsulated security payload message, and encapsulating the encapsulated security payload message through the TCP connection to obtain an encapsulated message includes: Parsing the IP header of the encapsulated security payload message by using the first TCP proxy center to obtain the destination IP; Establishing a connection relationship between the first TCP proxy center and the destination IP through the TCP protocol; Encapsulating the encapsulated security payload message based on the connection relationship, calculating the checksum of the encapsulated IP header to obtain a new IP header, and obtaining the encapsulated message based on the new IP header; Among them, the step of performing recursive processing on the encapsulated message by the second TCP proxy center of a preset decryption center includes: After the second TCP proxy center receives the encapsulated message, verifying the legality of the encapsulated message, and performing a stripping operation on the encapsulated message based on the verification result to obtain a corresponding encapsulated security payload message; Performing recursive processing on the encapsulated security payload message based on a preset kernel protocol stack, a routing query result, and a preset message protocol, and sending the processed message to the Internet security protocol stack.
2. The satellite link data transmission method according to claim 1, wherein The step of receiving an initial message through the internal network port of a preset encryption center, performing a routing query on a target message that meets the preset IP legal conditions, and sending the target message to an Internet security protocol stack includes: Receiving an initial message through the internal network port of a preset encryption center, and performing IP legality verification on the initial message based on a preset cryptographic algorithm; Obtaining a target message that meets the preset IP legal conditions through the verification result, performing a routing query on the target message to obtain a corresponding routing query result, and sending the target message to the Internet security protocol stack based on the routing query result.
3. The satellite link data transmission method according to claim 1, characterized in that The step of performing policy matching and data encryption encapsulation on the data stream in the target message based on the Internet security protocol stack to obtain an encapsulated security payload message includes: Parse the target packet based on the Internet security protocol stack to obtain a corresponding packet selector; Perform policy matching and data encryption encapsulation on the data stream in the target packet through the packet selector to obtain a corresponding encapsulated security payload packet.
4. The satellite link data transmission method according to claim 1, characterized in that, It further includes: Before the encapsulated security payload packet is sent out through the external network port, intercept the encapsulated security payload packet by using the first TCP proxy center to obtain the encapsulated security payload packet.
5. The satellite link data transmission method according to claim 1, characterized in that Decrypt the processed packet through the Internet security protocol stack, and send the obtained target packet to the service terminal to complete the corresponding satellite link data transmission operation, including: Perform corresponding security association lookups on the triples in the processed packet through the Internet security protocol stack; decrypt the processed packet based on the lookup result to obtain a corresponding target packet; Send the target packet to the service terminal through a preset internal network port to complete the corresponding satellite link data transmission operation.
6. A satellite link data transmission device, characterized in that, It includes: A routing query module, configured to receive an initial packet through the internal network port of a preset encryption center, perform a routing query on a target packet that meets the preset IP legal condition, and send the target packet to the Internet security protocol stack based on the routing query result; An encryption encapsulation module, configured to perform policy matching and data encryption encapsulation on the data stream in the target packet based on the Internet security protocol stack to obtain an encapsulated security payload packet; A packet encapsulation module, configured to establish a TCP connection with the destination IP corresponding to the IP header in the encapsulated security payload packet by using the first TCP proxy center of the preset encryption center, and encapsulate the encapsulated security payload packet through the TCP connection to obtain an encapsulated packet; A recursive processing module, configured to perform recursive processing on the encapsulated packet by using the second TCP proxy center of a preset decryption center, decrypt the processed packet through the Internet security protocol stack, and send the obtained target packet to the service terminal to complete the corresponding satellite link data transmission operation; Among them, the packet encapsulation module is specifically configured to parse the IP header of the encapsulated security payload packet by using the first TCP proxy center to obtain the destination IP; establish a connection relationship between the first TCP proxy center and the destination IP through the TCP protocol; encapsulate the encapsulated security payload packet based on the connection relationship, calculate the checksum of the encapsulated IP header to obtain a new IP header, and obtain the encapsulated packet based on the new IP header; Among them, the recursive processing module is specifically configured to, after the second TCP proxy center receives the encapsulated packet, verify the legitimacy of the encapsulated packet, and perform a stripping operation on the encapsulated packet based on the verification result to obtain a corresponding encapsulated security payload packet; perform recursive processing on the encapsulated security payload packet based on a preset kernel protocol stack, a routing query result, and a preset packet protocol, and send the processed packet to the Internet security protocol stack.
7. An electronic device, characterized in that, It includes: A memory, configured to store a computer program; A processor for executing the computer program to implement the satellite link data transmission method according to any one of claims 1 to 5.
8. A computer-readable storage medium, characterized in that, For storing a computer program, wherein when the computer program is executed by a processor, the satellite link data transmission method according to any one of claims 1 to 5 is implemented.
Citation Information
Patent Citations
Outbound message processing method and device based on power gateway
CN111614691A
Business data processing method and device, electronic equipment and storage medium
CN116489244A