An Information Security Interconnection Method for a Hybrid Space Network
By acquiring communication requirements in the space network, optimizing routing paths and encrypting operations, the problems of high latency and insufficient security in the space network are solved, and efficient and secure data transmission is achieved.
Patent Information
- Application Number
- CN202411381554.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-30
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2044-09-30
AI Technical Summary
The existing space networks have problems such as high time delay, poor overall communication efficiency and insufficient security in data transmission.
By obtaining the communication connection requirements requested by the user, querying the space network nodes based on the matching search model, generating the initial routing path, and optimizing the path through the routing optimization model, encrypting the target routing path using pre-created security policies, and batch-applying it to all routing paths.
Significantly reduce data transmission time delay, improve communication efficiency, enhance data transmission security, simplify management processes, improve system flexibility and adaptability, and optimize resource utilization.
Smart Images

Figure CN119210867B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of information security technology, and particularly to an information security interconnection method for a hybrid space network. Background Art
[0002] With the development of space technology and the increasing abundance of space resources, space networks have become an important infrastructure connecting the Earth and space. A hybrid space network refers to the combination of a terrestrial network and a space network to form a network architecture capable of efficiently and securely transmitting information. This network architecture can support various space activities and services, such as satellite communication, space station data exchange, deep space exploration, etc.
[0003] In a space network, a traditional routing algorithm based on the shortest path is usually adopted to plan the data transmission path. This algorithm considers the physical distance between nodes and attempts to find the shortest path from the source node to the destination node. And a fixed encryption key and encryption algorithm are used to protect the security of data during transmission. Although this method can provide a certain degree of security, its flexibility is relatively low.
[0004] In summary, the existing information security interconnection methods for space networks have problems such as high data transmission time delay, poor overall communication efficiency, and insufficient security when facing the increasing data transmission requirements. Therefore, developing a security interconnection method that can dynamically optimize the routing path and strengthen data encryption is of great significance for improving the overall performance and security of space networks. Summary of the Invention
[0005] The embodiments of the present application provide an information security interconnection method for a hybrid space network to solve the problems of high data transmission time delay and poor overall communication efficiency in the prior art.
[0006] In a first aspect, the embodiments of the present application provide an information security interconnection method for a hybrid space network, including:
[0007] Obtain the communication connection requirements requested by the user;
[0008] Based on the communication connection requirements, query multiple space network nodes that match the communication connection requirements from a pre-established set of space network nodes, and generate initial routing paths corresponding to the multiple space network nodes;
[0009] Perform optimization processing on the initial routing paths corresponding to the multiple space network nodes to generate target routing paths corresponding to the multiple space network nodes;
[0010] Perform an encryption operation on the target routing paths of the selected space network nodes using a pre-created security policy, and batch-apply the encryption operation to the target routing paths of the remaining multiple space network nodes.
[0011] Optionally, the optimizing the initial routing paths corresponding to the multiple space network nodes to generate the target routing paths of the multiple space network nodes includes:
[0012] Calculate the transmission delays between the space network nodes respectively according to the initial routing paths corresponding to each space network node.
[0013] Take the initial routing paths corresponding to the multiple space network nodes, the transmission delays between the multiple space network nodes, and the obtained location information of the multiple space network nodes as input information, and input them into a pre-trained routing optimization model to obtain the target routing paths of the multiple space network nodes output by the routing optimization model.
[0014] Optionally, the optimizing the initial routing paths corresponding to the multiple space network nodes to generate the target routing paths of the multiple space network nodes includes:
[0015] Obtain the bandwidth occupancy rate corresponding to the initial routing path of each space network node, and filter out the routing paths with a bandwidth occupancy rate higher than the preset occupancy rate to generate the target routing paths.
[0016] And / or, calculate the number of nodes involved in the initial routing path of each space network node, and filter out the routing paths with the number of nodes exceeding the preset number to generate the target routing paths.
[0017] Optionally, before taking the initial routing paths corresponding to the multiple space network nodes, the transmission delays between the multiple space network nodes, and the obtained location information of the multiple space network nodes as input information, and inputting them into a pre-trained routing optimization model to obtain the target routing paths of the multiple space network nodes output by the routing optimization model, it further includes:
[0018] Input the location information of the multiple space network nodes into a pre-trained location prediction model to obtain the predicted locations of the multiple space network nodes output by the location prediction model, and continue to perform the step of taking the initial routing paths corresponding to the multiple space network nodes, the transmission delays between the multiple space network nodes, and the obtained location information of the multiple space network nodes as input information, and inputting them into a pre-trained routing optimization model to obtain the target routing paths of the multiple space network nodes output by the routing optimization model.
[0019] Optionally, based on the communication connection requirements, querying multiple space network nodes that match the communication connection requirements from a pre-established set of space network nodes, and generating initial routing paths corresponding to the multiple space network nodes, includes:
[0020] Inputting the communication connection requirements and the pre-established set of space network nodes into a pre-trained matching and retrieval model, so as to query space network nodes that match the communication connection requirements through the matching and retrieval model, and generating initial routing paths corresponding to the multiple space network nodes;
[0021] Among them, the generation basis of the initial routing path is:
[0022]
[0023] Among them, P i represents the initial routing path of the i-th space network node; w j represents the j-th weight factor; d j (P) represents the distance of path P calculated according to the j-th weight factor; α is a balance factor; s k (P) represents the influence of the k-th security index on path P; n and m respectively represent the number of distances and security indexes.
[0024] Optionally, the pre-created security policies at least include: data encryption algorithms, key distribution mechanisms, authentication protocols, and access control policies.
[0025] Optionally, the data encryption algorithms, the key distribution mechanisms, the authentication protocols, and the access control policies include encryption modes and authentication modes. Among them, the encryption mode is used to encrypt data in the target routing path according to the corresponding encryption strength, and the authentication mode is used to perform identity authentication in the target routing path;
[0026] Among them, the basis for the encryption strength of the encryption mode is:
[0027] S enc = f(k, l, t, βlog(λ + 1))
[0028] Among them, S enc represents the encryption strength; k represents the key length; l represents the packet length; t represents the transmission time; β is a constant factor; λ represents the integrity metric of the packet.
[0029] Optionally, the location information of the space network node is the spatial location of the space network node.
[0030] Second aspect, an embodiment of the present application provides an information security interconnection device for a hybrid space network, including:
[0031] An acquisition module, configured to acquire the communication connection requirements requested by a user;
[0032] A generation module, configured to query, from a pre-established set of space network nodes, multiple space network nodes that match the communication connection requirements based on the communication connection requirements, and generate initial routing paths corresponding to the multiple space network nodes; perform an optimization process on the initial routing paths corresponding to the multiple space network nodes to generate target routing paths for the multiple space network nodes;
[0033] An encryption module, configured to perform an encryption operation on the target routing paths of the selected space network nodes using a pre-created security policy, and apply the encryption operation batchwise to the target routing paths of the remaining multiple space network nodes.
[0034] Third aspect, an embodiment of the present application provides a computing device, including a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are used to be called and executed by the processing component to implement the information security interconnection method for a hybrid space network as described in the first aspect above.
[0035] Fourth aspect, an embodiment of the present application provides a computer storage medium, storing a computer program, where when the computer program is executed by a computer, it implements the information security interconnection method for a hybrid space network as described in the first aspect above.
[0036] In an embodiment of the present application, the communication connection requirements requested by a user are acquired; based on the communication connection requirements, multiple space network nodes that match the communication connection requirements are queried from a pre-established set of space network nodes, and initial routing paths corresponding to the multiple space network nodes are generated; an optimization process is performed on the initial routing paths corresponding to the multiple space network nodes to generate target routing paths for the multiple space network nodes; an encryption operation is performed on the target routing paths of the selected space network nodes using a pre-created security policy, and the encryption operation is applied batchwise to the target routing paths of the remaining multiple space network nodes.
[0037] The method provided by the embodiment of the present application has the following beneficial effects:
[0038] Improve communication efficiency: By performing an optimization process on the initial routing paths, the time delay of data transmission can be significantly reduced, and the overall efficiency of space network communication can be improved.
[0039] Enhanced Security: Encrypting the target routing path through pre-created security policies can effectively prevent data from being eavesdropped or tampered with during transmission, ensuring the security of communication content.
[0040] Simplified Management Process: By applying encryption operations batchwise to all target routing paths, the security management process can be simplified and the operating costs can be reduced.
[0041] Strong Adaptability: This method can dynamically adjust the routing path and encryption policy according to different communication connection requirements, with high flexibility and adaptability.
[0042] Resource Optimization: The optimized routing path can utilize space network resources more efficiently, reducing unnecessary resource waste.
[0043] These aspects or other aspects of the present application will be more clearly understood in the following description of the embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0045] Figure 1 It is a flowchart of an information security interconnection method for a hybrid space network provided by an embodiment of the present application;
[0046] Figure 2 It is a schematic structural diagram of an information security interconnection device for a hybrid space network provided by an embodiment of the present application;
[0047] Figure 3 It is a schematic structural diagram of a computing device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0048] To enable those skilled in the art to better understand the solution of the present application, the following will clearly and completely describe the technical solutions in the embodiments of the present application in conjunction with the drawings in the embodiments of the present application.
[0049] In some of the processes described in the specification, claims, and the above-mentioned drawings of this application, a plurality of operations appear in a specific order. However, it should be clearly understood that these operations may not be executed in the order in which they appear herein or may be executed in parallel. The serial numbers of the operations, such as 101, 102, etc., are only used to distinguish different operations, and the serial numbers themselves do not represent any execution order. Additionally, these processes may include more or fewer operations, and these operations may be executed in sequence or in parallel. It should be noted that the descriptions such as "first" and "second" in this article are used to distinguish different messages, devices, modules, etc., do not represent a sequence, and do not limit that "first" and "second" are of different types.
[0050] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present application.
[0051] Figure 1 The flowchart of an information security interconnection method for a hybrid space network provided by an embodiment of the present application is as Figure 1 shown, and the method includes:
[0052] 101. Obtain the communication connection requirements requested by the user;
[0053] In this step, obtaining the communication connection requirements requested by the user: This step involves the communication requests initiated by the user, including but not limited to the requirements for services such as data transmission, voice calls, or video conferencing. The communication connection requirements usually include information such as the starting node (source node), destination node (destination), required bandwidth, and quality of service (QoS) requirements.
[0054] In an embodiment of the present application, assume that a user wishes to send a set of high-definition video data from a certain point on the earth (source node A) to a space station in low-earth orbit (destination node B). The user submits the communication connection requirements through a dedicated application or interface, including:
[0055] Source node A: A fixed location on the earth, such as a data center or communication center.
[0056] Destination node B: A space station in low-earth orbit, serving as the destination for receiving high-definition video data.
[0057] Required bandwidth: According to the data volume and transmission rate of the high-definition video, the user specifies the required minimum bandwidth, such as 100 Mbps.
[0058] Quality of Service (QoS) requirements: The user also specifies the minimum quality of service standards, such as requiring a packet loss rate of less than 1% and a latency of no more than 500 milliseconds.
[0059] After the user submits these detailed requirements, the system will start the subsequent processing steps, including querying multiple space network nodes that match the communication connection requirements from a pre-established set of space network nodes, and generating initial routing paths corresponding to the multiple space network nodes.
[0060] In this embodiment, the communication connection requirements submitted by the user will trigger a series of automated processes to ensure that data can be efficiently and securely transmitted from the source node to the destination node.
[0061] 102. Based on the communication connection requirements, query multiple space network nodes that match the communication connection requirements from a pre-established set of space network nodes, and generate initial routing paths corresponding to the multiple space network nodes;
[0062] Optionally, in the embodiment of the present application, step 102 may specifically include: inputting the communication connection requirements and the pre-established set of space network nodes into a pre-trained matching retrieval model, so as to query space network nodes that match the communication connection requirements through the matching retrieval model, and generate initial routing paths corresponding to the multiple space network nodes;
[0063] Among them, the generation basis of the initial routing path is:
[0064]
[0065] Among them, P i represents the initial routing path of the i-th space network node; w j represents the j-th weight factor; d j (P) represents the distance of path P calculated according to the j-th weight factor; α is a balance factor; s k (P) represents the influence of the k-th security index on path P; n and m respectively represent the number of distances and security indexes.
[0066] In this step, based on the communication connection requirements, query multiple space network nodes that match the communication connection requirements from a pre-established set of space network nodes, and generate initial routing paths corresponding to the multiple space network nodes: This step is to find multiple space network nodes that can meet the requirements from the pre-established set of space network nodes according to the user's communication connection requirements, and generate corresponding initial routing paths for these nodes. The key concepts here include communication connection requirements, set of space network nodes, matching retrieval model, initial routing path, weight factor, distance, balance factor, and security index.
[0067] Communication connection requirements: including information such as source node, destination node, required bandwidth, and quality of service requirements.
[0068] Space network node set: refers to the set of all nodes that are pre - established and can be used to construct space network communication links.
[0069] Matching retrieval model: a pre - trained model used to find suitable nodes in the space network node set according to communication connection requirements.
[0070] Initial routing path: a preliminary path generated for each space network node according to the results of the matching retrieval model.
[0071] Weight factor: used to measure the importance of different path attributes.
[0072] Distance: an index to measure the path length.
[0073] Balance factor: used to balance the relationship between path distance and security index.
[0074] Security index: an index to measure the path security, such as signal interference degree, data leakage risk, etc.
[0075] In the embodiments of the present application, it is assumed that the user hopes to send high - definition video data from a data center on the earth (source node A) to a space station in low - earth orbit (destination node B). The required bandwidth is 100 Mbps, and the quality of service requirements are that the packet loss rate is less than 1% and the latency does not exceed 500 milliseconds. According to this information, the system queries multiple space network nodes that match the communication connection requirements through a pre - trained matching retrieval model and generates initial routing paths for these nodes.
[0076] Communication connection requirements: The user specifies source node A, destination node B, required bandwidth 100 Mbps, packet loss rate less than 1%, and latency not exceeding 500 milliseconds.
[0077] Matching retrieval model: The system uses a pre - trained matching retrieval model to find space network nodes that match the above requirements. These nodes include ground stations, satellite nodes, and space stations, etc.
[0078] Initial routing path: The system generates an initial routing path for each matching space network node. Suppose the system finds three candidate nodes C, D, and E. For node C, the initial routing path is from A to C and then to B; for node D, the path is from A to D and then to B; for node E, the path is from A to E and then to B.
[0079] Next, the system will optimize these initial routing paths according to the distance and security index of the paths.
[0080] Distance: The distances of paths A-C-B, A-D-B, and A-E-B are 5000 km, 6000 km, and 4500 km respectively.
[0081] Safety index: Assume that the safety index of path A-C-B is 0.8 (high), the safety index of path A-D-B is 0.6 (medium), and the safety index of path A-E-B is 0.9 (highest).
[0082] Weight factor: Assume that the weight factor of distance is 0.7 and the weight factor of safety index is 0.3.
[0083] Balancing factor: Set it to 0.5, which is used to balance the influence of distance and safety index.
[0084] Calculate the comprehensive score of each path according to the above formula:
[0085] For path A-C-B: P C = arg min P (0.7 × 5000 + 0.5 × 0.3 × 0.8);
[0086] For path A-D-B: P D = arg min P (0.7 × 6000 + 0.5 × 0.3 × 0.6);
[0087] For path A-E-B: P E = arg min P (0.7 × 4500 + 0.5 × 0.3 × 0.9);
[0088] By comparing the above calculation results, select the optimal initial routing path. In this example, path A-E-B is selected as the optimal path because it has the shortest distance and the highest safety.
[0089] 103. Optimize the initial routing paths corresponding to multiple said space network nodes to generate the target routing paths of multiple said space network nodes;
[0090] Optionally, in an embodiment of the present application, as a possible implementation solution, step 103 may specifically include: respectively calculate the transmission delay between the space network nodes according to the initial routing paths corresponding to each said space network node; use the initial routing paths corresponding to multiple said space network nodes, the transmission delays between multiple said space network nodes, and the obtained position information of multiple said space network nodes as input information, and input them into a pre-trained routing optimization model to obtain the target routing paths of multiple said space network nodes output by the routing optimization model.
[0091] As another possible implementation, step 103 may specifically include: obtaining the bandwidth occupancy rate corresponding to the initial routing path of each of the space network nodes, and filtering out the routing paths with a bandwidth occupancy rate higher than the preset occupancy rate to generate target routing paths.
[0092] As yet another possible implementation, step 103 may specifically include: calculating the number of nodes involved in the initial routing path of each of the space network nodes, and filtering out the routing paths with the number of nodes exceeding the preset number to generate target routing paths.
[0093] In this step, the initial routing paths corresponding to multiple space network nodes are optimized to generate the target routing paths of multiple space network nodes: This step aims to further optimize based on the initial routing paths to obtain the final target routing paths. Factors such as transmission delay, bandwidth occupancy rate, and the number of nodes involved are considered during the optimization process.
[0094] Transmission delay: The time required for a data packet to be transmitted from one node to another.
[0095] Location information: The geographical or spatial location of a space network node, including but not limited to longitude, latitude, and altitude, etc.
[0096] Routing optimization model: A pre-trained model used to optimize the initial routing path according to the transmission delay and location information.
[0097] Bandwidth occupancy rate: The usage of bandwidth resources on a specific path, usually expressed in percentage form.
[0098] Preset occupancy rate: The threshold of the bandwidth occupancy rate set by the system, and the paths exceeding this threshold will be regarded as infeasible.
[0099] Preset number: The threshold of the number of nodes set by the system, and the paths with the number of nodes involved exceeding this threshold are considered sub-optimal paths.
[0100] In the embodiment of the present application, the embodiment corresponding to the first possible implementation: Suppose we have three space network nodes C, D, and E, each having an initial routing path. We need to determine the target routing path through optimization. The system first calculates the transmission delay between each node and inputs the initial routing path, transmission delay, and location information into the pre-trained routing optimization model.
[0101] Transmission delay: Suppose the transmission delay of path C-D is 100 ms, path C-E is 80 ms, and path D-E is 120 ms.
[0102] Location Information: Assume that node C is located at 30°N, 120°E, with an altitude of 300 km, node D is located at 35°N, 115°E, with an altitude of 400 km, and node E is located at 32°N, 125°E, with an altitude of 350 km.
[0103] Initial Routing Path: The initial routing path from node C to the destination node B is C - E - B, the initial routing path from node D to the destination node B is D - E - B, and the initial routing path from node E to the destination node B is E - B.
[0104] Routing Optimization Model: The system uses a pre-trained routing optimization model to optimize the initial routing path based on transmission delay and location information. After optimization, we obtain the target routing paths: the target routing path for node C is C - E - B, the target routing path for node D is D - E - B, and the target routing path for node E is E - B.
[0105] Example Corresponding to the Second Possible Implementation Solution: Assume that we have three space network nodes C, D, and E, each with an initial routing path. We need to determine the target routing path through optimization. The system first obtains the bandwidth occupancy rate corresponding to the initial routing path of each node and filters out the paths with a bandwidth occupancy rate higher than the preset occupancy rate.
[0106] Bandwidth Occupancy Rate: Assume that the bandwidth occupancy rate of path C - E - B is 70%, the bandwidth occupancy rate of path D - E - B is 80%, and the bandwidth occupancy rate of path E - B is 60%.
[0107] Preset Occupancy Rate: Assume that the preset occupancy rate of the system is 75%.
[0108] Target Routing Path: According to the bandwidth occupancy rate, the bandwidth occupancy rate of path D - E - B exceeds the preset occupancy rate of 75%, so it is filtered out. The remaining paths C - E - B and E - B become the target routing paths.
[0109] Example Corresponding to the Third Possible Implementation Solution: Assume that we have three space network nodes C, D, and E, each with an initial routing path. We need to determine the target routing path through optimization. The system first calculates the number of nodes involved in the initial routing path of each node and filters out the paths with the number of nodes exceeding the preset number.
[0110] Number of Nodes: Assume that path C - E - B involves 3 nodes, path D - E - B also involves 3 nodes, and path E - B only involves 2 nodes.
[0111] Preset Number: Assume that the preset number of the system is 3.
[0112] Target routing paths: According to the number of nodes, the number of nodes involved in paths C-E-B and D-E-B is exactly equal to the preset number 3, so they are retained. Path E-B only involves 2 nodes and is also retained. Therefore, all the initial routing paths are retained as target routing paths.
[0113] The above is a detailed introduction to different implementation solutions and their embodiments for step 103.
[0114] 104. Use the pre-created security policy to encrypt the target routing paths of the selected space network nodes, and apply the encryption operation batchwise to the target routing paths of the remaining multiple space network nodes.
[0115] Optionally, in the embodiments of the present application, before step 104, it further includes: inputting the location information of the multiple space network nodes into a pre-trained location prediction model to obtain the predicted locations of the multiple space network nodes output by the location prediction model, and then continue to execute step 104.
[0116] In this step, the pre-created security policy: refers to a set of predefined rules or algorithms used to guide the security protection measures for communication between space network nodes, such as encryption methods, key management, etc.
[0117] Encryption operation: The process of encrypting the data on the target routing paths of space network nodes to protect the security of the data during transmission.
[0118] Location information: Refers to the geographical location information of space network nodes, including but not limited to latitude and longitude, altitude, etc.
[0119] Location prediction model: A machine learning model used to predict the node location at a future time point based on historical location information.
[0120] Predicted location: The expected location of a space network node at a future moment output by the location prediction model.
[0121] In the embodiments of the present application, assume that we have three space network nodes A, B, and C, each with a target routing path. We need to protect the data security on these paths through encryption operations and apply the encryption operations batchwise to all nodes. In addition, before performing the encryption operations, we also need to predict the future moving locations of these nodes.
[0122] Location information: Node A is currently located at 30°N, 120°E, and an altitude of 300 km; Node B is located at 35°N, 115°E, and an altitude of 400 km; Node C is located at 32°N, 125°E, and an altitude of 350 km.
[0123] Location Prediction Model: The system uses a pre-trained location prediction model to predict the future movement locations of nodes based on historical location information.
[0124] Predicted Locations: It is predicted that Node A will be located at 30.5°N, 120.5°E, and an altitude of 310 km after 1 hour; Node B will be located at 35.5°N, 115.5°E, and an altitude of 410 km after 1 hour; Node C will be located at 32.5°N, 125.5°E, and an altitude of 360 km after 1 hour.
[0125] Encryption Operation: Based on the predicted locations, use a pre-created security policy to encrypt the target routing paths of Nodes A, B, and C. Here, it is assumed that the security policy includes using the AES-256 encryption algorithm and changing the encryption key every 24 hours.
[0126] Batch Application: Apply the encryption operation batchwise to the target routing paths of all nodes. This means that once the encryption operation is completed on Node A, the same encryption policy and settings will be automatically applied to Nodes B and C.
[0127] The following is a specific example:
[0128] Step 1: Collect location information. The system records the current location information of Nodes A, B, and C.
[0129] Step 2: Predict locations. Use the location prediction model to predict the locations of the nodes after 1 hour.
[0130] Step 3: Develop a security policy. Based on the predicted locations, determine the encryption policy, such as selecting the encryption algorithm, key length, key update period, etc.
[0131] Step 4: Encryption operation. Encrypt the target routing path of Node A. Here, it is assumed that the AES-256 encryption algorithm is used and the encryption key is changed every 24 hours.
[0132] Step 5: Batch application. Extend the encryption operation to Nodes B and C to ensure that all target routing paths are protected at the same level.
[0133] Through the above embodiments, we can see how to combine location prediction and encryption operations to improve the security of space network communication. This not only ensures the security of data transmission but also takes into account the mobile characteristics of space network nodes, thereby improving the overall security and reliability of the system.
[0134] Furthermore, the pre-created security policy at least includes: data encryption algorithm, key distribution mechanism, authentication protocol, and access control policy.
[0135] Among them, the data encryption algorithm, the key distribution mechanism, the authentication protocol, and the access control policy include an encryption mode and an authentication mode. Among them, the encryption mode is used to encrypt data in the target routing path according to the corresponding encryption strength, and the authentication mode is used to perform identity authentication in the target routing path;
[0136] Among them, the basis for the encryption strength of the encryption mode is:
[0137] S enc = f(k, l, t, βlog(λ + 1))
[0138] Among them, S enc represents the encryption strength; k represents the key length; l represents the data packet length; t represents the transmission time; β is a constant factor; λ represents the integrity metric of the data packet.
[0139] In this step, the pre-created security policy: refers to a set of predefined rules or algorithms used to guide the security protection measures for communication between space network nodes, such as data encryption algorithms, key distribution mechanisms, authentication protocols, and access control policies, etc.
[0140] Data encryption algorithm: used to encrypt data to protect its security during transmission.
[0141] Key distribution mechanism: ensures that the keys used in the encryption and decryption processes can be securely transmitted between space network nodes.
[0142] Authentication protocol: used to verify the identities of both communication parties to ensure that only legitimate users can access the network.
[0143] Access control policy: specifies which users can access specific data or services.
[0144] Encryption mode: the working mode of the encryption algorithm, which determines how to use the key to encrypt data.
[0145] Authentication mode: used to verify the authenticity and integrity of data to ensure that the data has not been tampered with during transmission.
[0146] Encryption strength: an indicator to measure the security of the encryption algorithm, usually related to factors such as key length, data packet length, transmission time, and data packet integrity metric.
[0147] Key length: the number of bits of the key used in the encryption algorithm. The longer the key length, the greater the difficulty of cracking.
[0148] Data packet length: the size of the transmitted data packet.
[0149] Transmission time: the time required for data to travel from the sender to the receiver.
[0150] Constant factor: Used to adjust the relative importance of each term in the encryption strength calculation formula.
[0151] Integrity metric of data packet: An indicator to measure whether the data packet remains intact and untampered during transmission.
[0152] In the embodiments of this application, assume that we have a space network node A that needs to communicate securely with another space network node B. We need to use a pre-created security policy to protect the communication between these two nodes. The specific steps are as follows:
[0153] Data encryption algorithm: Select the AES-256 encryption algorithm as the data encryption algorithm.
[0154] Key distribution mechanism: Use the Diffie-Hellman key exchange protocol to securely distribute keys.
[0155] Authentication protocol: Adopt digital certificates and public key infrastructure (PKI) for authentication.
[0156] Access control policy: Set up an access control list (ACL) to only allow nodes with specific IP addresses to access the network.
[0157] Encryption strength calculation: Determine the encryption strength according to the encryption strength calculation formula.
[0158] Key length: 256 bits.
[0159] Data packet length: Assume the average data packet length is 1024 bytes.
[0160] Transmission time: Assume the average transmission time is 200 milliseconds.
[0161] Constant factor: Set to 2.
[0162] Integrity metric of data packet: Assume the integrity metric is 0.95 (indicating a high integrity of the data packet).
[0163] Encryption strength calculation:
[0164] Encryption mode and authentication mode: Select appropriate encryption mode and authentication mode to protect the data according to the calculated encryption strength.
[0165] Encryption mode: Use the CBC (Cipher Block Chaining) mode for encryption.
[0166] Authentication mode: Use HMAC (Hash Message Authentication Code) for data integrity check.
[0167] The following is a specific example:
[0168] Step 1: Determine the encryption algorithm. Select AES-256 as the encryption algorithm.
[0169] Step 2: Key distribution. Use the Diffie-Hellman key exchange protocol to distribute keys.
[0170] Step 3: Authentication. Perform authentication through digital certificates and PKI.
[0171] Step 4: Access control. Set up ACL to restrict access to nodes with specific IP addresses only.
[0172] Step 5: Encryption strength calculation. Calculate the encryption strength according to the formula.
[0173] Step 6: Encryption mode and authentication mode. Select the encryption mode (CBC) and authentication mode (HMAC) according to the encryption strength.
[0174] Step 7: Data encryption and authentication. Encrypt and authenticate the data using the selected encryption mode and authentication mode.
[0175] Step 8: Data transmission. Send the encrypted data to the destination node through the target routing path.
[0176] Through the above embodiments, we can see how to combine encryption algorithms, key distribution, authentication, and access control to protect the communication security in the space network, and dynamically adjust the encryption policy through the encryption strength calculation formula to ensure the security and integrity of the data during transmission.
[0177] Figure 2 The following is a schematic structural diagram of an information security interconnection device for a hybrid space network provided by an embodiment of the present application. As Figure 2 shown, the device includes:
[0178] An acquisition module 21, configured to acquire the communication connection requirements requested by the user;
[0179] A generation module 22, configured to query multiple space network nodes matching the communication connection requirements from a pre-established set of space network nodes based on the communication connection requirements, and generate initial routing paths corresponding to the multiple space network nodes; perform optimization processing on the initial routing paths corresponding to the multiple space network nodes to generate target routing paths corresponding to the multiple space network nodes;
[0180] An encryption module 23, configured to perform an encryption operation on the target routing path of the selected space network node using a pre-created security policy, and batch-apply the encryption operation to the target routing paths of the remaining multiple space network nodes.
[0181] Optionally, in the embodiments of the present application, the generating module 22 is specifically configured to calculate the transmission delay between the space network nodes according to the initial routing paths corresponding to each of the space network nodes; use the initial routing paths corresponding to the multiple space network nodes, the transmission delays between the multiple space network nodes, and the obtained position information of the multiple space network nodes as input information, and input the input information into a pre-trained routing optimization model to obtain the target routing paths of the multiple space network nodes output by the routing optimization model.
[0182] Optionally, in the embodiments of the present application, the generating module 22 is specifically configured to obtain the bandwidth occupancy rate corresponding to the initial routing path of each of the space network nodes, and filter out the routing paths with a bandwidth occupancy rate higher than a preset occupancy rate to generate the target routing path;
[0183] And / or, calculate the number of nodes involved in the initial routing path of each of the space network nodes, and filter out the routing paths with the number of nodes exceeding a preset number to generate the target routing path.
[0184] Optionally, in the embodiments of the present application, the obtaining module 21 is further configured to input the position information of the multiple space network nodes into a pre-trained position prediction model to obtain the predicted positions of the multiple space network nodes output by the position prediction model, and the obtaining module 21 continues to execute the step of using the initial routing paths corresponding to the multiple space network nodes, the transmission delays between the multiple space network nodes, and the obtained position information of the multiple space network nodes as input information, and input the input information into a pre-trained routing optimization model to obtain the target routing paths of the multiple space network nodes output by the routing optimization model.
[0185] Optionally, in the embodiments of the present application, the generating module 22 is specifically configured to input the communication connection requirement and a pre-established set of space network nodes into a pre-trained matching and retrieval model, and query, through the matching and retrieval model, the space network nodes matching the communication connection requirement, and generate the initial routing paths corresponding to the multiple space network nodes;
[0186] Wherein, the generation basis of the initial routing path is:
[0187]
[0188] Where P i represents the initial routing path of the i-th space network node; w j represents the j-th weight factor; d j (P) represents the distance of path P calculated according to the j-th weight factor; α is a balance factor; s k(P) represents the impact of the k-th security metric on path P; n and m represent the number of distances and security metrics respectively.
[0189] Optionally, in the embodiments of the present application, the pre-created security policies at least include: data encryption algorithms, key distribution mechanisms, authentication protocols, and access control policies.
[0190] Optionally, in the embodiments of the present application, the data encryption algorithm, the key distribution mechanism, the authentication protocol, and the access control policy include encryption modes and authentication modes. Among them, the encryption mode is used to encrypt data in the target routing path according to the corresponding encryption strength, and the authentication mode is used to perform identity authentication in the target routing path;
[0191] Among them, the basis for the encryption strength of the encryption mode is:
[0192] S enc = f(k, l, t, βlog(λ + 1))
[0193] Among them, S enc represents the encryption strength; k represents the key length; l represents the packet length; t represents the transmission time; β is a constant factor; λ represents the integrity metric of the packet.
[0194] Figure 2 The information security interconnection device of the hybrid space network can execute Figure 1 the information security interconnection method of the hybrid space network described in the embodiments shown. The implementation principle and technical effects will not be elaborated here. For the information security interconnection device of the hybrid space network in the above embodiments, the specific ways for each module and unit to execute operations have been described in detail in the embodiments related to the method, and will not be elaborated here.
[0195] In a possible design, Figure 2 the information security interconnection device of the hybrid space network shown in the embodiments can be implemented as a computing device. As Figure 3 shown, the computing device can include a storage component 31 and a processing component 32;
[0196] The storage component 31 stores one or more computer instructions, and among them, the one or more computer instructions are called and executed by the processing component 32.
[0197] The processing component 32 is used for: obtaining the communication connection requirements requested by the user; based on the communication connection requirements, querying multiple space network nodes matching the communication connection requirements from a pre-established set of space network nodes, and generating initial routing paths corresponding to the multiple space network nodes; performing optimization processing on the initial routing paths corresponding to the multiple space network nodes to generate target routing paths for the multiple space network nodes; using a pre-created security policy to encrypt the target routing paths of the selected space network nodes, and batch-applying the encryption operation to the target routing paths of the remaining multiple space network nodes.
[0198] Among them, the processing component 32 may include one or more processors to execute computer instructions to complete all or part of the steps in the above method. Of course, the processing component may also be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors or other electronic components for executing the above method.
[0199] The storage component 31 is configured to store various types of data to support the operation of the terminal. The storage component can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk.
[0200] Of course, the computing device may also necessarily include other components, such as input / output interfaces, display components, communication components, etc.
[0201] The input / output interface provides an interface between the processing component and the peripheral interface module, and the above peripheral interface module may be an output device, an input device, etc.
[0202] The communication component is configured to facilitate communication between the computing device and other devices in a wired or wireless manner, etc.
[0203] Among them, the computing device may be a physical device or an elastic computing host provided by a cloud computing platform, etc. At this time, the computing device may refer to a cloud server, the above processing component, storage component, etc., or may also be basic server resources leased or purchased from a cloud computing platform.
[0204] The embodiment of the present application also provides a computer storage medium storing a computer program, and when the computer program is executed by a computer, it can implement the above Figure 1Information security interconnection method for the hybrid space network of the illustrated embodiment.
[0205] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.
[0206] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative labor.
[0207] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to enable a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0208] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, and are not intended to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of each embodiment of the present application.
Claims
1. An information security interconnection method for a hybrid space network, characterized in that Including: Obtain the communication connection requirements requested by the user; Based on the communication connection requirements, query multiple space network nodes that match the communication connection requirements from a pre-established set of space network nodes, and generate initial routing paths corresponding to the multiple space network nodes; Perform optimization processing on the initial routing paths corresponding to the multiple space network nodes to generate target routing paths for the multiple space network nodes; Use a pre-created security policy to encrypt the target routing paths of the selected space network nodes, and batch-apply the encryption operation to the target routing paths of the remaining multiple space network nodes; The performing optimization processing on the initial routing paths corresponding to the multiple space network nodes to generate target routing paths for the multiple space network nodes includes: Calculate the transmission delay between the space network nodes respectively according to the initial routing paths corresponding to each space network node; Use the initial routing paths corresponding to the multiple space network nodes, the transmission delay between the multiple space network nodes, and the obtained location information of the multiple space network nodes as input information, and input them into a pre-trained routing optimization model to obtain the target routing paths of the multiple space network nodes output by the routing optimization model; The based on the communication connection requirements, querying multiple space network nodes that match the communication connection requirements from a pre-established set of space network nodes, and generating initial routing paths corresponding to the multiple space network nodes includes: Input the communication connection requirements and a pre-established set of space network nodes into a pre-trained matching and retrieval model, so as to query space network nodes that match the communication connection requirements through the matching and retrieval model, and generate initial routing paths corresponding to the multiple space network nodes; Wherein, the generation basis of the initial routing path is: ; Among them, represents the initial routing path of the i-th space network node; represents the j-th weight factor; represents the distance of path P calculated according to the j-th weight factor; is the balance factor; represents the influence of the k-th security index on path P; n and m respectively represent the numbers of distance and security index.
2. The method according to claim 1, wherein The performing optimization processing on the initial routing paths corresponding to the multiple space network nodes to generate target routing paths for the multiple space network nodes includes: Obtain the bandwidth occupancy rate corresponding to the initial routing path of each space network node, and filter out the routing paths with a bandwidth occupancy rate higher than the preset occupancy rate to generate target routing paths; And / or, calculate the number of nodes involved in the initial routing path of each space network node, and filter out the routing paths with the number of nodes exceeding the preset number to generate target routing paths.
3. The method according to claim 2, wherein Before the using the initial routing paths corresponding to the multiple space network nodes, the transmission delay between the multiple space network nodes, and the obtained location information of the multiple space network nodes as input information, and inputting them into a pre-trained routing optimization model to obtain the target routing paths of the multiple space network nodes output by the routing optimization model, it further includes: Input the location information of multiple said space network nodes into a pre-trained location prediction model to obtain the predicted locations of multiple said space network nodes output by the location prediction model, and continue to execute the step of inputting the initial routing paths corresponding to multiple said space network nodes, the transmission delays between multiple said space network nodes, and the obtained location information of multiple said space network nodes as input information into a pre-trained routing optimization model to obtain the target routing paths of multiple said space network nodes output by the routing optimization model.
4. The method according to any one of claims 1 to 3, characterized in that, The pre-created security policy at least includes: a data encryption algorithm, a key distribution mechanism, an authentication protocol, and an access control policy.
5. The method according to claim 4, wherein The data encryption algorithm, the key distribution mechanism, the authentication protocol, and the access control policy include an encryption mode and an authentication mode. Among them, the encryption mode is used to encrypt data in the target routing path according to the corresponding encryption strength, and the authentication mode is used to perform identity authentication in the target routing path; Among them, the basis for the encryption strength of the encryption mode is: ; wherein, represents the encryption strength; k represents the key length; l represents the data packet length; t represents the transmission time; β is a constant factor; λ represents the integrity metric of the data packet.
6. The method according to claim 5, wherein The location information of the space network node is the spatial location of the space network node.
Citation Information
Patent Citations
Traffic grooming method and device based on quantum security, and electronic equipment
CN116488798A
Power distribution communication network routing path determination method and related equipment
CN118282916A